If your VPN has been acting up lately — connections dropping, speeds crawling to a halt, when everything used to work fine — you're not alone. Russia is in the middle of an ongoing wave of VPN blocking through 2025-2026, and it's hit pretty much every popular service out there.
Here's what's actually happening, which protocols still hold up, and what you can do to get a stable connection back.
What is TSPU
TSPU (ТСПУ, "technical measures to counter threats") is Russia's deep packet inspection (DPI) system, installed on ISP equipment nationwide since 2021. It analyzes traffic in real time and can block specific types of connections as they pass through.
TSPU can:
- Fingerprint VPN protocols by their signatures (even encrypted traffic has telltale characteristics)
- Block IP addresses from Roskomnadzor's lists
- Throttle traffic to specific services
- Apply blocks selectively by region
For a long time, TSPU was used surgically — against specific sites and services. Since 2024, it's been turned on VPNs at scale.
Timeline of VPN blocking in Russia
2023 — targeted blocks
Individual VPN services were blocked on Roskomnadzor's request. Most users didn't notice much — switching to another service was usually enough.
Spring 2024 — WireGuard gets blocked
WireGuard, one of the most popular protocols around, started getting blocked by TSPU at scale. This was the first time users noticed their VPN breaking not because of the service itself, but because of their ISP.
Summer 2024 — AmneziaWG arrives
In response to the WireGuard block, the Amnezia team released AmneziaWG, a fork with traffic obfuscation built in. It gave thousands of users a workaround, at least for a while.
2025 — the blocking expands
TSPU learned to recognize OpenVPN (even with TLS obfuscation), IKEv2, and L2TP. For a stretch, only VLESS (part of the XRay ecosystem) and AmneziaWG kept working.
Early 2026 — mass blocking
Spring 2026 brought waves of blocking that reached even obfuscated protocols. OpenVPN barely functions at all now. But the blocking also became far more piecemeal and ISP-dependent: WireGuard, VLESS, and Shadowsocks drop on some providers while running fine on others. There's no longer a single nationwide picture — it comes down to your specific carrier.
Which protocols still work
Protocol status as of summer 2026:
| Protocol | Status | Notes |
|---|---|---|
| AmneziaWG | ✅ Working | Recommended — the most consistently stable |
| WireGuard | ✅ Working | Recommended, but depends on your ISP |
| VLESS (XRay) | ✅ Working | Recommended, but depends on your ISP |
| Shadowsocks | ✅ Working | Recommended, but depends on your ISP |
| OpenVPN | ❌ Blocked | Barely functional |
| IKEv2/IPSec | ❌ Blocked | Signature has long been known to TSPU |
| L2TP/IPSec | ❌ Blocked | Outdated, easily detected |
| PPTP | ❌ Don't use it | Insecure and blocked |
The situation shifts every few weeks. A protocol that works today can be blocked tomorrow. Your best strategy is to pick a service that updates its protocols quickly and keeps adding new ways around the blocks.
It all depends on your ISP
Here's the key thing to understand: whether a given protocol works depends heavily on your internet provider and your region. TSPU isn't configured uniformly — what's blocked on one carrier runs fine on another, sometimes on the same street. One user's WireGuard drops every five minutes while their neighbor on a different ISP runs the exact same protocol without a hitch.
So there's no single "right" protocol. The practical approach is to try a few — AmneziaWG, WireGuard, VLESS, Shadowsocks — and stick with whichever stays stable for you. If it starts faltering a week later, switch to another. All four are viable; the only question is which one your provider leaves alone.
Why now, specifically
The crackdown has intensified for a few reasons:
1. TSPU hardware upgrades Russian ISPs have upgraded their DPI equipment to newer generations that are much better at recognizing obfuscated protocols.
2. VPN use has gone mainstream Estimates put VPN usage among active Russian internet users as high as 30%. That's too large a share to block selectively — so the approach has shifted to blocking at scale.
3. Regulatory pressure Since 2024, advertising VPN services has been banned, and a number of VPN apps have been pulled from RuStore. At the same time, Roskomnadzor keeps pressuring foreign providers to block VPN traffic.
4. The political climate Blocking intensifies during periods of political tension, elections, and major public events. It eases up somewhat the rest of the time.
What you can do
1. Try different protocols
AmneziaWG, WireGuard, VLESS (XRay), and Shadowsocks all work in Russia, but how stable each one is depends on your ISP. Start with AmneziaWG — it's obfuscated and holds up the best — and if it doesn't work out for some reason, try the others and keep whichever stays stable for you.
What is AmneziaWG and how to set it up →
2. Pick a server location closer to Russia
Servers in countries with normal traffic exchange with Russia — Turkey, Kazakhstan, Armenia, Finland, Georgia — tend to be more stable than servers in Europe or the US.
3. Try different ports
VPNs typically use standard ports (51820 for WireGuard, 1194 for OpenVPN), and those are the first thing TSPU blocks. Servers running on nonstandard ports (443, 53, or randomized ones) tend to last longer.
4. Don't rely on a single VPN for everything
If your one server gets blocked, you're stuck with no backup. It's better to keep 2-3 different VPN connections going — from different providers, or to different locations.
5. Keep an eye on the news
Follow channels that track blocking activity. If your VPN suddenly stops working, word usually spreads within a day about which protocols got hit and what to do about it.
What doesn't work
A few popular tips that don't actually help, or don't work the way people expect:
"Switch your DNS to 1.1.1.1" — this only helps if the problem is DNS-level blocking. For VPN issues, it's usually not the fix.
"Use mobile data instead of Wi-Fi" — mobile carriers run TSPU too, and often a more aggressive version of it.
"Use a free proxy" — free proxies are unsafe (they log your traffic), slow, and among the first things to get blocked.
"Tor without obfs4" — gets blocked at the entry nodes. You need obfs4 bridges or another pluggable transport.
The long-term strategy
Blocking is only going to get more aggressive. That's a fact you need to plan around. Here's the long-term playbook:
- Use a VPN service under active development — services like this adapt to new blocks faster
- Always have a backup — a second VPN from a different provider, a VLESS subscription, or a self-hosted VPN on your own server
- Stay informed — follow Telegram channels covering blocking news, user communities, and specialized resources
- Help the people around you — parents, friends — they run into the same problems, but tend to give up more easily
Bottom line
VPN blocking in Russia isn't a temporary measure. It's the new normal, and it's here to stay. But the situation isn't hopeless — modern obfuscated protocols still work, and with the right tools, the internet remains accessible.
RuSolv runs on WireGuard and AmneziaWG. We respond to blocking quickly — updating configurations, adding servers in regions that stay stable, and testing new obfuscation methods as they emerge.




