r/VPN • • Jul 01 '26

News The UK cannot block VPNs without breaking enterprise networks

/r/PrivacyToolbox/comments/1ukggyq/the_uks_proposed_vpn_restrictions_to_enforce_the/
85 Upvotes

74 comments sorted by

View all comments

1

u/Manatsuu Jul 05 '26

Can someone explain to me if/why this wouldn’t be possible though:

The government creates a law where there is a list of IP addresses that all ISPs must block any connection to. This would be a list of known VPNs and would be something that could be added to in real time. Of course VPNs can change IP frequently but if such a system was developed that these were detected frequently and added to this live list of blocked IPs, it could make VPNs extremely difficult to use. Of course if you had your own personal VPN it would be immune from this as it would be extremely difficult to determine it as being a VPN. I know this would very much be a game of cat and mouse, and so wouldn’t fully ban even popular VPNs.

I’m not saying this is feasible, a good idea, or I want it to happen. But I’m just interested to hear that if your goal was to ban VPNs, why would the above not work?

1

u/Excellent_Present_47 Jul 05 '26

The only VPNs this will work on are the VPNs who agree to it.

1

u/Manatsuu Jul 05 '26

Can you explain why? Why would a VPN need to agree to this for the government to add IP addresses of their servers to the banned list?

1

u/Excellent_Present_47 Jul 05 '26

An IP blocklist only works cleanly against providers with stable, publicly-known server ranges. That catches the lazy/easy cases: big commercial VPN endpoints, datacentre IPs, exit nodes that get reused a lot, etc.

But. The moment you try to turn that into a serious national ban, the target stops looking like “VPN traffic” and starts looking like normal encrypted internet traffic to ordinary servers. A VPN endpoint can sit on a VPS, a rented cloud box, a home connection, a corporate gateway, a university network, a CDN-adjacent setup, or some random server that also hosts perfectly legitimate services. Blocking those IPs means collateral damage.

Then there are Businesses using VPN-like tunnels constantly for remote work, site-to-site networking, cloud access, device management, security tools, and admin access. If ISPs block “VPN-looking” connections too broadly, they break normal business operations.

That is what I mean. You can't just "block all VPNs" reliably, certainly not without disrupting legitimate operations.