What we saw
On 26 September 2026, from two consumer connections in Russia — one of them a mobile network — connections to a server at a Dutch hosting provider (AS215439) only ever delivered the first TCP segment of the TLS / REALITY ClientHello, about 1,400 bytes. The rest of the handshake was dropped, so the connection never completed.
- Trojan (TLS) connections stalled after exactly 1,400 bytes as well — both to that server and to a server in Turkey.
- VLESS Reality to the Turkish server, from the same clients, worked.
- Moving the service to port 443 did not help.
What Colitu did
Colitu stopped offering that server to its apps the same day. The server is still running, for tests.
How we read it
From two connections we cannot tell whether the behaviour is per network (only some access networks do it), per destination range (only some hosting networks are affected) or temporary.
What it means for the lab
This is exactly the kind of result the lab is built to catch continuously rather than by chance. A plain TCP connection to the server's port succeeds — the address is not blocked — while the tunnel through the same port fails. The probes run both tests side by side every round (reach and tunnel tests), and the network fingerprint turns the gap between them into the signal “TCP transports fail although the port answers” (fingerprint). Repeated from probes on home and mobile networks, the same comparison would show whether such a stall is per network, per destination or temporary.
Limitations
- Two client connections, on one day. That is a field note, not a series of measurements, and it says nothing about how widespread the behaviour is.
- One affected hosting network for VLESS Reality; for Trojan, two server locations. Other hosting networks were not compared systematically.
- We do not name the client networks or the servers, and we publish no addresses.
- The interpretation above is one explanation that fits what we saw; it is not proof of a specific filtering system.