{"id":36043,"date":"2019-10-31T22:09:19","date_gmt":"2019-10-31T19:09:19","guid":{"rendered":"https:\/\/prohoster.info\/blog\/kak-my-probivali-velikij-kitajskij-faervol-ch-3\/"},"modified":"2019-10-31T22:09:19","modified_gmt":"2019-10-31T19:09:19","slug":"kak-my-probivali-velikij-kitajskij-faervol-ch-3","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-my-probivali-velikij-kitajskij-faervol-ch-3","title":{"rendered":"How we breached the Great Chinese Firewall (part 3)","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Hello!<br \/>\nAll good stories come to an end. And our story about how we devised a solution for quickly bypassing the Chinese Firewall is no exception. So I'm eager to share with you the final part. <strong>the concluding part<\/strong> on this topic.<\/p>\n<p><\/p>\n<p>In the previous part, we talked about the numerous test setups we came up with and the results they yielded. We concluded that it would be good to add <strong>CDN!<\/strong> for cohesion in our scheme.<\/p>\n<p><\/p>\n<p>I will tell you how we tested Alibaba Cloud CDN, Tencent Cloud CDN, and Akamai, and which one we ultimately chose. And of course, we will summarize.<\/p>\n<p>\n<img decoding=\"async\" alt=\"How we breached the Great Chinese Firewall (part 3)\" src=\"\/wp-content\/uploads\/2019\/07\/36f7d82cfee454fafa1b1528fc36c730.jpg\" style=\"display:block;margin: 0 auto;\" \/><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2 id=\"alibaba-cloud-cdn\">Alibaba Cloud CDN<\/h2>\n<p><\/p>\n<p>We are hosted on Alibaba Cloud, using IPSEC and CEN from them as well. It makes sense to first try their solutions.<\/p>\n<p><\/p>\n<p>Alibaba Cloud has two types of products that might suit us: <strong>CDN<\/strong> and <strong>DCDN<\/strong>. The first option is a classic CDN for a specific domain (subdomain). The second option stands for <em>Dynamic Route for CDN<\/em> (which I call dynamic CDN), it can be activated in Full-site mode (for wildcard domains), it also caches static content and accelerates dynamic content, meaning the dynamic aspects of the page will also load through the provider's fast networks. This is important for us, as our website is mostly dynamic, using numerous subdomains, and it's easier to configure CDN once for a wildcard \u2014 *.semrushchina.cn.<\/p>\n<p><\/p>\n<p>We have already seen this product in earlier stages of our Chinese project, but at that time it wasn't functional, and the developers promised that the product would soon be available to all customers. And it has become available.<\/p>\n<p><\/p>\n<p>With DCDN, you can:<\/p>\n<p><\/p>\n<ul>\n<li>set up SSL termination with your certificate,<\/li>\n<li>enable dynamic content acceleration,<\/li>\n<li>flexibly configure caching for static files,<\/li>\n<li>perform cache purges,<\/li>\n<li>support web sockets,<\/li>\n<li>enable compression, and even HTML Beautifier.<\/li>\n<\/ul>\n<p><\/p>\n<p>In general, everything is like with mature, large CDN providers.<\/p>\n<p><\/p>\n<p>After specifying the Origin (the place where CDN edge servers will go), you then need to create a CNAME for the wildcard that points to <em>all.semrushchina.cn.w.kunluncan.com<\/em> (this CNAME was obtained in the Alibaba Cloud console), and the CDN will function. <\/p>\n<p><\/p>\n<p>Based on the test results, this CDN has helped us significantly. The statistics are provided below.<\/p>\n<p><\/p>\n<p>Solution<br \/>\nUptime<br \/>\nMedian<br \/>\n75th Percentile<br \/>\n95th Percentile<\/p>\n<p>Cloudflare<br \/>\n86.6<br \/>\n18s<br \/>\n30s<br \/>\n60s<\/p>\n<p>IPsec<br \/>\n99.79<br \/>\n18s<br \/>\n21s<br \/>\n30s<\/p>\n<p>CEN<br \/>\n99.75<br \/>\n16s<br \/>\n21s<br \/>\n27s<\/p>\n<p>CEN\/IPsec + GLB<br \/>\n99.79<br \/>\n13s<br \/>\n16s<br \/>\n25s<\/p>\n<p><strong>Ali CDN + CEN\/IPsec + GLB<\/strong><br \/>\n<strong>99.75<\/strong><br \/>\n<strong>10s<\/strong><br \/>\n<strong>12.8s<\/strong><br \/>\n<strong>17.3s<\/strong><\/p>\n<p><\/p>\n<p>These are very good results, especially when compared to the figures we had at the beginning. However, we knew that the browser test of the American version of our website www.semrush.com averages around 8.3s (a rough estimate) from the US. There's still room for improvement. Moreover, there were additional CDN providers that we were interested in testing.<\/p>\n<p><\/p>\n<p>So we smoothly transition to another giant in the Chinese market \u2014 <strong>Tencent<\/strong>.<\/p>\n<p><\/p>\n<h2 id=\"tencent-cloud\">Tencent Cloud<\/h2>\n<p><\/p>\n<p>Tencent is still developing its cloud \u2014 this is evident from the limited number of products. During its use, we wanted to test not only their CDN but also the overall network infrastructure:<\/p>\n<p><\/p>\n<ul>\n<li>do they have something similar to CEN?<\/li>\n<li>how does their IPSEC work? Is it fast, what is the uptime?<\/li>\n<li>do they have Anycast?<\/li>\n<\/ul>\n<p>\n<img decoding=\"async\" alt=\"How we breached the Great Chinese Firewall (part 3)\" src=\"\/wp-content\/uploads\/2019\/07\/a0af3f5cff85056cb322e0a64ae079b5.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>We will address these questions separately.<\/p>\n<p><\/p>\n<h4 id=\"analog-cen\">CEN Analog<\/h4>\n<p><\/p>\n<p>Tencent has a product <strong>Cloud Connect Network<\/strong> (<noindex><a rel=\"nofollow\" href=\"https:\/\/intl.cloud.tencent.com\/product\/ccn\">CCN<\/a><\/noindex>), which allows connecting VPCs from different regions, including regions within and outside China. The product is currently in internal beta, and you need to create a ticket requesting access. From support, we learned that global accounts (not referring to Chinese citizens or legal entities) cannot participate in the beta testing program and generally cannot connect a region inside China with a region outside. 1-0 in favor of Ali Cloud.<\/p>\n<p><\/p>\n<h4 id=\"ipsec\">IPSEC<\/h4>\n<p><\/p>\n<p>The southernmost region for Tencent is <em>Guangzhou<\/em>. We set up a tunnel and connected it to the Hong Kong region in GCP (at that point the region was already available). We also launched a second tunnel to Ali Cloud from Shenzhen to Hong Kong. It turned out that over Tencent's network, latency to Hong Kong was overall better (10ms) than from Shenzhen to Hong Kong in Ali (120ms \u2014 what?). However, this did not accelerate the website's performance aimed at running through Tencent and this tunnel, which is itself an astonishing fact and once again proved the following: latency \u2014 for China this is not a metric to really pay attention to when developing a solution for bypassing the Chinese firewall.<\/p>\n<p><\/p>\n<h4 id=\"anycast-internet-acceleration\">Anycast Internet Acceleration<\/h4>\n<p><\/p>\n<p>Another product that allows working through anycast IP is <noindex><a rel=\"nofollow\" href=\"https:\/\/intl.cloud.tencent.com\/product\/aia\">AIA<\/a><\/noindex>. However, it is also not available for global accounts, so I won't elaborate on it, but knowing that such a product exists might be useful.<\/p>\n<p><\/p>\n<p>The CDN test yielded quite interesting results. Tencent's CDN cannot be enabled for full-site use, only for specific domains. We set up domains and directed traffic to them:<\/p>\n<p>\n<img decoding=\"async\" alt=\"How we breached the Great Chinese Firewall (part 3)\" src=\"\/wp-content\/uploads\/2019\/07\/a4931750f0cb79fbae7ec1217eab4fac.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>It turned out that this CDN has the following feature: <strong>Cross Border Traffic Optimization<\/strong>. This feature should reduce costs when passing traffic through the Chinese firewall. As an example, <em>Origin<\/em> the IP address of Google's GLB (GLB anycast) was specified. Thus, we aimed to simplify the project's architecture.<\/p>\n<p><\/p>\n<p>The results were very good \u2014 on par with Ali Cloud CDN, and in some cases even better. This is surprising because if the tests are successful, it would allow us to eliminate a significant part of the infrastructure, tunnels, CEN, virtual machines, etc. <\/p>\n<p><\/p>\n<p>Our joy was short-lived, as a problem emerged: tests in Catchpoint failed for the Internet provider China Mobile. From any location, we received timeouts through Tencent's CDN. Correspondence with technical support led to nothing. For about a day, we attempted to resolve this issue, but to no avail. <\/p>\n<p><\/p>\n<p>At that moment, I was in China, but I couldn't find public Wi-Fi in this provider's network to verify the issue personally. Everything else seemed fast and good.<br \/>\nHowever, due to the fact that China Mobile is among the top three largest operators, we were forced to revert the traffic to Ali CDN.<br \/>\nOverall, it was quite an interesting solution that deserves longer testing and troubleshooting of this problem.<\/p>\n<p><\/p>\n<h2 id=\"akamai\">Akamai<\/h2>\n<p><\/p>\n<p>The last CDN provider we tested was <strong>Akamai<\/strong>. This is a large provider that has its own network in China. Of course, we couldn't overlook it.<\/p>\n<p>\n<img decoding=\"async\" alt=\"How we breached the Great Chinese Firewall (part 3)\" src=\"\/wp-content\/uploads\/2019\/07\/34657ab2d5da8509285f5c99401b7603.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>From the very beginning, we agreed with Akamai on a trial period so we could switch the domain and see how it would perform on their network. I will describe the results of all the testing in terms of 'What I liked' and 'What I didn't like', as well as provide the test results.<\/p>\n<p><\/p>\n<p><strong>What I liked:<\/strong><\/p>\n<p><\/p>\n<ul>\n<li>The guys from Akamai were very helpful with all our questions and supported us at all stages of testing. They were constantly trying to improve something on their end and provided good technical advice.<\/li>\n<li>Akamai works about 10-15% slower than our solution through Ali Cloud CDN. It\u2019s impressive that for Akamai's Origin, we specified the GLB IP address, meaning the traffic did not go through our solution (potentially allowing us to eliminate part of the infrastructure). However, the test results showed that this solution was worse than our current one (comparative results below).<\/li>\n<li>Both Origin GLB and Origin in China were tested. Both options are approximately the same.<\/li>\n<li>There is <em>Sure Route<\/em> (automatic routing optimization). You can place a test object on Origin, and Akamai Edge servers will attempt to fetch it (standard GET). The speed and other metrics for these requests are measured, based on which the Akamai network optimizes routes to ensure traffic flows faster for our site, demonstrating that enabling this feature significantly impacts website speed.<\/li>\n<li>Versioning configuration in the web interface is great. You can do a Compare for versions, view the diff, and check previous versions.<\/li>\n<li>You can deploy a new version first only on the Akamai Staging network \u2014 the same network as production, but this path does not affect real users. For this test, DNS record spoofing needs to be done on the local machine.<\/li>\n<li>Very fast loading speed through their network for large static files, as well as apparently any other files. A file from the 'cold' cache is retrieved much faster than the same file from the 'cold' cache of Ali CDN. From the 'hot' cache, the speed is more or less the same.<\/li>\n<\/ul>\n<p><\/p>\n<p><strong>Ali CDN test:<\/strong><\/p>\n<p><\/p>\n<pre><code class=\"bash\">root@shenzhen1:~# curl -o \/dev\/null -w@curl_time https:\/\/en.semrushchina.cn\/my_reports\/build\/scripts\/simpleInit.js?v=1551879212\n  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current\n                                 Dload  Upload   Total   Spent    Left  Speed\n100 5757k    0 5757k    0     0   513k      0 --:--:--  0:00:11 --:--:--  526k\ntime_namelookup:  0.004286\ntime_connect:  0.030107\ntime_appconnect:  0.117525\ntime_pretransfer:  0.117606\ntime_redirect:  0.000000\ntime_starttransfer:  0.840348\n----------\ntime_total:  11.208119\n----------\nsize_download:  5895467 Bytes\nspeed_download:  525999.000B\/s<\/code><\/pre>\n<p><\/p>\n<p><strong>Akamai test:<\/strong><\/p>\n<p><\/p>\n<pre><code class=\"bash\">root@shenzhen1:~# curl -o \/dev\/null -w@curl_time https:\/\/www.semrushchina.cn\/my_reports\/build\/scripts\/simpleInit.js?v=1551879212\n  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current\n                                 Dload  Upload   Total   Spent    Left  Speed\n100 5757k    0 5757k    0     0  1824k      0 --:--:--  0:00:03 --:--:-- 1825k\ntime_namelookup:  0.509005\ntime_connect:  0.528261\ntime_appconnect:  0.577235\ntime_pretransfer:  0.577324\ntime_redirect:  0.000000\ntime_starttransfer:  1.327013\n----------\ntime_total:  3.154850\n----------\nsize_download:  5895467 Bytes\nspeed_download:  1868699.000B\/s<\/code><\/pre>\n<p><\/p>\n<p>We noticed that the situation from the example above depends on various factors. At the time of writing this point, I conducted the test again. The results for both platforms turned out to be approximately the same. This tells us that the internet in China behaves differently from time to time, even for large operators and cloud providers.<\/p>\n<p><\/p>\n<p>Adding a big plus for Akamai to the previous point: while Ali shows such bursts of high performance and very low latency (this applies to both Ali CDN, Ali CEN, and Ali IPSEC), every time I test Akamai's network, everything works consistently.<br \/>\nAkamai really has extensive coverage in China and works through many providers.<\/p>\n<p><\/p>\n<p><strong>What we didn't like:<\/strong><\/p>\n<p><\/p>\n<ul>\n<li>I don't like the web interface and the way it operates \u2014 it's very rudimentary. But in principle, you get used to it (probably).<\/li>\n<li>Test results are worse than our platform.<\/li>\n<li>There are more errors in the tests than on our platform (uptime is lower).<\/li>\n<li>They do not have their own DNS servers in China. This leads to many test errors due to DNS resolve timeout.<\/li>\n<li>They do not provide their IP ranges -&gt; there is no way to write them down correctly. <em>set_real_ip_from<\/em> on our servers.<\/li>\n<\/ul>\n<p><\/p>\n<p>Metrics (~3626 runs; all metrics except Uptime in ms; statistics over a single time interval):<\/p>\n<p><\/p>\n<p>CDN Provider<br \/>\nMedian<br \/>\n75%<br \/>\n95%<br \/>\nResponse<br \/>\nWebpage Response<br \/>\nUptime<br \/>\nDNS<br \/>\nConnect<br \/>\nWait<br \/>\nLoad<br \/>\nSSL<\/p>\n<p>Ali CDN<br \/>\n9195<br \/>\n10749<br \/>\n17489<br \/>\n1,715<br \/>\n10,745<br \/>\n99.531<br \/>\n57<br \/>\n17<br \/>\n927<br \/>\n479<br \/>\n200<\/p>\n<p>Akamai<br \/>\n9783<br \/>\n11887<br \/>\n19888<br \/>\n2,352<br \/>\n11,550<br \/>\n98.980<br \/>\n424<br \/>\n91<br \/>\n1408<br \/>\n381<br \/>\n50<\/p>\n<p><\/p>\n<p>Distribution by Percentile (in ms):<\/p>\n<p><\/p>\n<p>Percentile<br \/>\nAkamai<br \/>\nAli CDN<\/p>\n<p>10<br \/>\n7,092<br \/>\n6,942<\/p>\n<p>20<br \/>\n7,775<br \/>\n7,583<\/p>\n<p>30<br \/>\n8,446<br \/>\n8,092<\/p>\n<p>40<br \/>\n9,146<br \/>\n8,596<\/p>\n<p>50<br \/>\n9,783<br \/>\n9,195<\/p>\n<p>60<br \/>\n10,497<br \/>\n9,770<\/p>\n<p>70<br \/>\n11,371<br \/>\n10,383<\/p>\n<p>80<br \/>\n12,670<br \/>\n11,255<\/p>\n<p>90<br \/>\n15,882<br \/>\n13,165<\/p>\n<p>100<br \/>\n91,592<br \/>\n91,596<\/p>\n<p><\/p>\n<p>The conclusion is this: the option with Akamai is viable but does not provide the same stability and speed metrics as our own solution combined with Ali CDN.<\/p>\n<p><\/p>\n<h2 id=\"malenkie-zametki\">Little notes<\/h2>\n<p><\/p>\n<p>Some points did not make it into the narrative, but I would also like to write about them.<\/p>\n<p><\/p>\n<h3 id=\"pekin--tokio-i-gonkong\">Beijing + Tokyo and Hong Kong<\/h3>\n<p><\/p>\n<p>As I mentioned earlier, we tested the IPSEC tunnel to Hong Kong (HK). But we also tested CEN to HK. It costs a little less, and it was interesting to see how it would perform between cities separated by ~100km. Interestingly, the latency between these cities was 100ms higher than in our original option (to Taiwan). The speed and stability were also better for Taiwan. In the end, we left HK as a backup IPSEC region.<\/p>\n<p><\/p>\n<p>In addition, we tried to implement such an installation:<\/p>\n<p><\/p>\n<ul>\n<li>terminating clients in Beijing,<\/li>\n<li>IPSEC and CEN to Tokyo,<\/li>\n<li>in Ali CDN specified as the origin server in Beijing.<\/li>\n<\/ul>\n<p><\/p>\n<p>This setup was not as stable, although in terms of speed it was generally not inferior to our solution. Regarding the tunnel, I observed periodic drops even for CEN, which was supposed to be stable. Therefore, we reverted to the old setup and dismantled this staging.<\/p>\n<p><\/p>\n<p>Below is the latency statistics between different regions over different channels. Perhaps someone will find it interesting.<\/p>\n<p><\/p>\n<p><em>IPsec<\/em><br \/>\nAli cn-beijing  GCP asia-northeast1 \u2014 193ms<br \/>\nAli cn-shenzhen  GCP asia-east2 \u2014 91ms<br \/>\nAli cn-shenzhen  GCP us-east4 \u2014 200ms<\/p>\n<p><\/p>\n<p><em>CEN<\/em><br \/>\nAli cn-beijing  Ali ap-northeast-1 \u2014 54ms (!)<br \/>\nAli cn-shenzhen  Ali cn-hongkong \u2014 6ms (!)<br \/>\nAli cn-shenzhen  Ali us-east1 \u2014 216ms<\/p>\n<p><\/p>\n<h3 id=\"obschaya-informaciya-pro-internet-v-kitae\">General Information about the Internet in China<\/h3>\n<p><\/p>\n<p>As an addition to the internet issues mentioned at the very beginning, in the first part of the article.<\/p>\n<p><\/p>\n<ul>\n<li>The internet in China works quite fast domestically.\n<ul>\n<li>The conclusion is based on testing public Wi-Fi networks in various locations where these networks are used by a large number of people.<\/li>\n<li>The download and upload speeds to servers inside China were about 20 Mbps and 5-10 Mbps, respectively.<\/li>\n<li>The speed to servers outside China is simply negligible, less than 1 Mbps.<\/li>\n<\/ul>\n<\/li>\n<li>The internet in China is not very stable.\n<ul>\n<li>Sometimes websites may load quickly, sometimes slowly (at the same time of day on different days), provided that the configuration does not change. We observed this with semrushchina.cn. This can be attributed to Ali CDN, which also operates sporadically depending on the time of day, position of the stars, etc.<\/li>\n<\/ul>\n<\/li>\n<li>Mobile internet is practically everywhere 4G or 4G+. It works in subways, elevators \u2014 basically, everywhere.<\/li>\n<li>The belief that Chinese users only trust domains in the .cn zone is a myth. We verified this directly with users.\n<ul>\n<li>You can see how <noindex><a rel=\"nofollow\" href=\"http:\/\/baidu.cn\">http:\/\/baidu.cn<\/a><\/noindex> redirects to www.baidu.com (also in mainland China).<\/li>\n<\/ul>\n<\/li>\n<li>Many resources are indeed blocked. Simply put: google.com, Facebook, Twitter. But many Google resources work (of course, not on all Wi-Fi and VPN is not used (on the router side too, that\u2019s for sure).<\/li>\n<li>Many \"technical\" domains of blocked corporations also work. This means that one should not recklessly eliminate all seemingly blocked Google and other resources. A list of banned domains should be sought.<\/li>\n<li>They have only three major internet operators: China Unicom, China Telecom, China Mobile. There are smaller ones, but their market share is insignificant.<\/li>\n<\/ul>\n<p><\/p>\n<h3 id=\"bonus-itogovaya-shema-resheniya\">Bonus: Final solution scheme<\/h3>\n<p>\n<img decoding=\"async\" alt=\"How we breached the Great Chinese Firewall (part 3)\" src=\"\/wp-content\/uploads\/2019\/07\/ec9c09dbbad1c3f002920d875a5079d7.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<h2 id=\"itog\">Summary<\/h2>\n<p><\/p>\n<p>A year has passed since the start of the project. We started with the fact that our site simply refused to work properly from China, and a simple GET curl took 5.5 seconds. <\/p>\n<p><\/p>\n<p>Then, with such indicators at the first solution (Cloudflare):<\/p>\n<p><\/p>\n<p>Solution<br \/>\nUptime<br \/>\nMedian<br \/>\n75th Percentile<br \/>\n95th Percentile<\/p>\n<p>Cloudflare<br \/>\n86.6<br \/>\n18s<br \/>\n30s<br \/>\n60s<\/p>\n<p><\/p>\n<p>Eventually, we reached the following results (statistics for the last month):<\/p>\n<p><\/p>\n<p>Solution<br \/>\nUptime<br \/>\nMedian<br \/>\n75th Percentile<br \/>\n95th Percentile<\/p>\n<p>Ali CDN + CEN\/IPsec + GLB<br \/>\n99.86<br \/>\n8.8s<br \/>\n9.5s<br \/>\n13.7s<\/p>\n<p><\/p>\n<p>As you can see, achieving 100% uptime has not yet been possible, but we will think of something, and then we will share the results with you in a new article :)<\/p>\n<p><\/p>\n<p>Respect to those who read all three parts to the end. I hope you found it as interesting as I did while creating this.<\/p>\n<p><\/p>\n<h3 id=\"ps-predyduschie-chasti\">P.S. Previous Parts<\/h3>\n<p><\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/semrush\/blog\/458602\/\">Part 1<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/semrush\/blog\/458840\/\">Part 2<\/a><\/noindex><\/p>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/semrush\/blog\/459024\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u0438\u0432\u0435\u0442! \u041b\u044e\u0431\u044b\u0435 \u0445\u043e\u0440\u043e\u0448\u0438\u0435 \u0438\u0441\u0442\u043e\u0440\u0438\u0438 \u0437\u0430\u043a\u0430\u043d\u0447\u0438\u0432\u0430\u044e\u0442\u0441\u044f. \u0418 \u043d\u0430\u0448\u0430 \u0438\u0441\u0442\u043e\u0440\u0438\u044f \u043f\u0440\u043e \u0442\u043e, \u043a\u0430\u043a \u043c\u044b \u043f\u0440\u0438\u0434\u0443\u043c\u044b\u0432\u0430\u043b\u0438 \u0440\u0435\u0448\u0435\u043d\u0438\u0435 \u0431\u044b\u0441\u0442\u0440\u043e\u0433\u043e \u043f\u0440\u043e\u0445\u043e\u0434\u0430 \u041a\u0438\u0442\u0430\u0439\u0441\u043a\u043e\u0433\u043e \u0424\u0430\u0435\u0440\u0432\u043e\u043b\u0430, \u043d\u0435 \u0438\u0441\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435. \u041f\u043e\u044d\u0442\u043e\u043c\u0443 \u0441\u043f\u0435\u0448\u0443 \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f \u0441 \u0432\u0430\u043c\u0438 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0435\u0439, \u0437\u0430\u0432\u0435\u0440\u0448\u0430\u044e\u0449\u0435\u0439 \u0447\u0430\u0441\u0442\u044c\u044e \u043d\u0430 \u044d\u0442\u0443 \u0442\u0435\u043c\u0443. \u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0447\u0430\u0441\u0442\u0438 \u0431\u044b\u043b\u043e \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u0430\u043d\u043e \u043f\u0440\u043e \u043c\u043d\u043e\u0436\u0435\u0441\u0442\u0432\u043e \u0442\u0435\u0441\u0442\u043e\u0432\u044b\u0445 \u0441\u0442\u0435\u043d\u0434\u043e\u0432, \u043f\u0440\u0438\u0434\u0443\u043c\u0430\u043d\u043d\u044b\u0445 \u043d\u0430\u043c\u0438, \u0438 \u043a\u0430\u043a\u0438\u0435 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u043e\u043d\u0438 \u0434\u0430\u043b\u0438. \u0418 \u043c\u044b \u043e\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u043b\u0438\u0441\u044c \u043d\u0430 \u0442\u043e\u043c, \u0447\u0442\u043e \u043d\u0435\u043f\u043b\u043e\u0445\u043e \u0431\u044b\u043b\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":26947,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-36043","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0440\u0438\u0432\u0435\u0442! \u041b\u044e\u0431\u044b\u0435 \u0445\u043e\u0440\u043e\u0448\u0438\u0435 \u0438\u0441\u0442\u043e\u0440\u0438\u0438 \u0437\u0430\u043a\u0430\u043d\u0447\u0438\u0432\u0430\u044e\u0442\u0441\u044f. \u0418 \u043d\u0430\u0448\u0430 \u0438\u0441\u0442\u043e\u0440\u0438\u044f \u043f\u0440\u043e \u0442\u043e, \u043a\u0430\u043a \u043c\u044b \u043f\u0440\u0438\u0434\u0443\u043c\u044b\u0432\u0430\u043b\u0438 \u0440\u0435\u0448\u0435\u043d\u0438\u0435 \u0431\u044b\u0441\u0442\u0440\u043e\u0433\u043e \u043f\u0440\u043e\u0445\u043e\u0434\u0430 \u041a\u0438\u0442\u0430\u0439\u0441\u043a\u043e\u0433\u043e \u0424\u0430\u0435\u0440\u0432\u043e\u043b\u0430, \u043d\u0435 \u0438\u0441\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-my-probivali-velikij-kitajskij-faervol-ch-3\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0430\u043a \u043c\u044b \u043f\u0440\u043e\u0431\u0438\u0432\u0430\u043b\u0438 \u0412\u0435\u043b\u0438\u043a\u0438\u0439 \u041a\u0438\u0442\u0430\u0439\u0441\u043a\u0438\u0439 \u0424\u0430\u0435\u0440\u0432\u043e\u043b (\u0447.3) | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0440\u0438\u0432\u0435\u0442! \u041b\u044e\u0431\u044b\u0435 \u0445\u043e\u0440\u043e\u0448\u0438\u0435 \u0438\u0441\u0442\u043e\u0440\u0438\u0438 \u0437\u0430\u043a\u0430\u043d\u0447\u0438\u0432\u0430\u044e\u0442\u0441\u044f. \u0418 \u043d\u0430\u0448\u0430 \u0438\u0441\u0442\u043e\u0440\u0438\u044f \u043f\u0440\u043e \u0442\u043e, \u043a\u0430\u043a \u043c\u044b \u043f\u0440\u0438\u0434\u0443\u043c\u044b\u0432\u0430\u043b\u0438 \u0440\u0435\u0448\u0435\u043d\u0438\u0435 \u0431\u044b\u0441\u0442\u0440\u043e\u0433\u043e \u043f\u0440\u043e\u0445\u043e\u0434\u0430 \u041a\u0438\u0442\u0430\u0439\u0441\u043a\u043e\u0433\u043e \u0424\u0430\u0435\u0440\u0432\u043e\u043b\u0430, \u043d\u0435 \u0438\u0441\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-my-probivali-velikij-kitajskij-faervol-ch-3\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:09:19+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:09:19+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47How We Bypassed the Great Firewall of China (Part 3) | ProHoster","description":"Hello! Every good story comes to an end. Our story about how we developed a solution for bypassing the Great Firewall of China is no exception.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-my-probivali-velikij-kitajskij-faervol-ch-3","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0430\u043a \u043c\u044b \u043f\u0440\u043e\u0431\u0438\u0432\u0430\u043b\u0438 \u0412\u0435\u043b\u0438\u043a\u0438\u0439 \u041a\u0438\u0442\u0430\u0439\u0441\u043a\u0438\u0439 \u0424\u0430\u0435\u0440\u0432\u043e\u043b (\u0447.3) | ProHoster","og:description":"\u041f\u0440\u0438\u0432\u0435\u0442! \u041b\u044e\u0431\u044b\u0435 \u0445\u043e\u0440\u043e\u0448\u0438\u0435 \u0438\u0441\u0442\u043e\u0440\u0438\u0438 \u0437\u0430\u043a\u0430\u043d\u0447\u0438\u0432\u0430\u044e\u0442\u0441\u044f. \u0418 \u043d\u0430\u0448\u0430 \u0438\u0441\u0442\u043e\u0440\u0438\u044f \u043f\u0440\u043e \u0442\u043e, \u043a\u0430\u043a \u043c\u044b \u043f\u0440\u0438\u0434\u0443\u043c\u044b\u0432\u0430\u043b\u0438 \u0440\u0435\u0448\u0435\u043d\u0438\u0435 \u0431\u044b\u0441\u0442\u0440\u043e\u0433\u043e \u043f\u0440\u043e\u0445\u043e\u0434\u0430 \u041a\u0438\u0442\u0430\u0439\u0441\u043a\u043e\u0433\u043e \u0424\u0430\u0435\u0440\u0432\u043e\u043b\u0430, \u043d\u0435 \u0438\u0441\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-my-probivali-velikij-kitajskij-faervol-ch-3","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:09:19+00:00","article:modified_time":"2019-10-31T19:09:19+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"36043","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 01:46:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:51:23","updated":"2026-01-22 01:46:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/36043","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=36043"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/36043\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/26947"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=36043"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=36043"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=36043"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}