COLITU LABProbes starting

Research note · Russia · Trojan · VLESS Reality · field note

TLS connections that stop after the first 1,400 bytes

From two consumer connections in Russia, TLS-based transports to one Dutch hosting network delivered only the first TCP segment of the handshake. The same clients connected normally elsewhere.

Observed 26 Sept 2026

What we saw

On 26 September 2026, from two consumer connections in Russia — one of them a mobile network — connections to a server at a Dutch hosting provider (AS215439) only ever delivered the first TCP segment of the TLS / REALITY ClientHello, about 1,400 bytes. The rest of the handshake was dropped, so the connection never completed.

  • Trojan (TLS) connections stalled after exactly 1,400 bytes as well — both to that server and to a server in Turkey.
  • VLESS Reality to the Turkish server, from the same clients, worked.
  • Moving the service to port 443 did not help.

What Colitu did

Colitu stopped offering that server to its apps the same day. The server is still running, for tests.

How we read it

Interpretation, not a finding. The pattern is consistent with filtering that inspects the first segments of large TLS handshakes towards certain hosting ranges. Modern ClientHellos that carry post-quantum key shares no longer fit into one TCP segment, so a filter that holds back everything after the first segment stops the handshake at exactly this point.

From two connections we cannot tell whether the behaviour is per network (only some access networks do it), per destination range (only some hosting networks are affected) or temporary.

What it means for the lab

This is exactly the kind of result the lab is built to catch continuously rather than by chance. A plain TCP connection to the server's port succeeds — the address is not blocked — while the tunnel through the same port fails. The probes run both tests side by side every round (reach and tunnel tests), and the network fingerprint turns the gap between them into the signal “TCP transports fail although the port answers” (fingerprint). Repeated from probes on home and mobile networks, the same comparison would show whether such a stall is per network, per destination or temporary.

Limitations

  • Two client connections, on one day. That is a field note, not a series of measurements, and it says nothing about how widespread the behaviour is.
  • One affected hosting network for VLESS Reality; for Trojan, two server locations. Other hosting networks were not compared systematically.
  • We do not name the client networks or the servers, and we publish no addresses.
  • The interpretation above is one explanation that fits what we saw; it is not proof of a specific filtering system.