Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

VPN blocked on my school Wi-Fi — I’ve tried everything, nothing works

2»

Comments

  • Ultrasurf...

  • Did you install a certificate to your device? Which certificate authority you see when you connecto to Google or lowendtalk?

    Thanked by 1vonunov
  • @srch07 said:

    @rcy026 said:
    I find it highly unlikely that any top antivirus or spamware company would allow unfiltered ssh to everywhere in the world, that is just absurd.
    Top companies in the world implies thousands or even tens of thousands of employees, to allow every one of them to ssh everywhere would be tremendously stupid, there is no way any administrator on that level would do that.

    Well either you are too smart, or the admin team from both (out of top 3) antivirus companies were too dumb, that they allowed it?

    Doubt it. Top 3 companies requires a certain level of experience, and you do not get to that level if you are that stupid.

    You know which side I would bet on. :)

    Well, there is a third option, but you are probably not betting on that.

  • Have you tried turning it off and on again?

  • raindog308raindog308 Administrator, Veteran

    @MannDude said: Mobile hotspot.

    @buggedout said: mobile data

    This really is the best answer.

    @TimboJones said: Any sort of locked down environment has ssh blocked.

    This has been my experience working in multiple F500 companies as well. You can ssh out on the internal network but not to random Internet IPs.

    Thanked by 1Xrmaddness
  • @tulepera33 said:
    Hey everyone, I’m having a problem with my school Wi-Fi that completely blocks any kind of VPN traffic.

    I’ve tried almost every method I could find: OpenVPN (from VPNBook with UDP25000, UDP53, TCP443, TCP80), WireGuard, Outline, Psiphon, and WARP by Cloudflare. In all cases, the VPN connects successfully — but once it does, the Wi-Fi stops working. No apps or websites load at all.

    I also tested manual DNS changes (1.1.1.1, 8.8.8.8, etc.), but that didn’t help either.
    When using WARP, the “1.1.1.1” mode (DNS only) works fine, but the full VPN mode doesn’t. So it’s clear the firewall is blocking encrypted VPN traffic entirely, probably through deep packet inspection (DPI).

    I’ve also tried Psiphon Pro and Outline, which can connect at the same time as Wi-Fi, but again — no traffic goes through once connected.

    So far, nothing has worked.
    It seems my school’s network allows only HTTPS traffic and blocks anything that looks like a tunnel.

    Does anyone know of a method, proxy, or tool that can bypass this kind of restriction? I’m open to advanced configurations or stealth protocols, as long as they can work on iPhone.
    Any help or ideas would be super appreciated 🙏

    been there, same problems
    even wireguard on 443/80 didnt work
    but here is what DID work

    netbird + rdp
    proton stealth vpn (mac)
    https://github.com/jlesage/docker-firefox browser in browser or similar
    i just bought a 120gb data plan as the wifi with whichever method was just terrible
    now i dont go to school anymore, but it's not worth it downgrading (yes i can) so i kept it (my usage is like 20gb)

  • s0n1cs0n1c Member
    edited November 2025

    For me, selfhosted AmneziaVPN worked using the xray protocol.

    Surprisingly Tailscale with exit node enabled also worked? Maybe try that too

  • Would ask if a RDP session is available.

  • conceptconcept Member
    edited November 2025

    @s0n1c said:

    Surprisingly Tailscale with exit node enabled also worked? Maybe try that too

    Yep, Tailscale has the ability to get through Firewalls and NAT (CGNAT)
    The deep dive blog post if interested.
    https://tailscale.com/blog/how-nat-traversal-works

  • FourplexFourplex Member, Host Rep
    edited November 2025

    I use ocserv as my go-to VPN server, using openconnect as my client.

    While nowhere as popular as WireGuard I prefer it for some reason, namely for using PAM-based authentication and dynamic IPs.

  • Shadowsocks and vless work well for me

  • Didn't realize there's so many ways to circumvent the firewall. This thread has certainly taught me a lot. Thanks all!

  • I'm betting OP's issue is PEBKAC and DNS related. Schools don't tend to have better firewalls than China.

    Thanked by 1stable_genius
  • try windscribe for commercial vpn, they got openvpn over tls and websockets,
    amnezia for self hosted, their custom wg can bypass china firewall

    https://windscribe.com/
    https://amnezia.org/

  • As a last resort, you can always set up a neko-browser / guacamole / kasm workspace service and use these browser based remote desktop.

  • LordSpockLordSpock Member, Host Rep
    edited November 2025

    @TimboJones said:
    I'm betting OP's issue is PEBKAC and DNS related. Schools don't tend to have better firewalls than China.

    It depends(tm). There are some relatively off the shelf solutions for schools/colleeges in the UK at least that are incredibly comprehensive, I've done some ad-hoc work for UK schools and have usually been pretty impressed by their firewall.

    The regulations surrounding Keeping Children Safe In Education put a lot of the onus of the consequences of any filter bypass directly on the school's leadership and as such there is a pretty reasonable investment in to the filtering solution.

    (I've also done some work in US schools and have been a LOT less impressed, fwiw).

  • @TimboJones said:
    I'm betting OP's issue is PEBKAC and DNS related. Schools don't tend to have better firewalls than China.

    Actually, schools are probably both the worst and among the best I've seen.
    A lot of schools buy security as a service, and some of those guys are pretty good. Everything gets routed trough a dc somewhere with ngfw's, proxies, dpi, 802.1x etc.

  • Get a student's special discounted SIM card.

    Thanked by 1stable_genius
  • Try hysteria2 with and without obfuscation password

  • awhite20awhite20 Member
    edited November 2025

    Use Xray Reailty protocol, fairly easy to setup
    Amneziawg is another option with a too easy one click server setup and tries to obfuscate the tunnel traffic as quic, so you maybe able to get past any DPI

  • SIM card and hotspot or fight a losing battle, you choose.

  • if ping is available ,try using vpn over icmp

  • @rcy026 said:

    @TimboJones said:
    I'm betting OP's issue is PEBKAC and DNS related. Schools don't tend to have better firewalls than China.

    Actually, schools are probably both the worst and among the best I've seen.
    A lot of schools buy security as a service, and some of those guys are pretty good. Everything gets routed trough a dc somewhere with ngfw's, proxies, dpi, 802.1x etc.

    I'm mostly going by the lack of meaningful troubleshooting, but if the VPN is connecting but not passing traffic, that's a weird fucking filter.

    I don't care enough to fly to UK and walk into a public school and connect back to my home.

  • Download "UltraSurf" and run it.

Sign In or Register to comment.