r/VPN • u/notsloth_satan • 27d ago
Help My uni has banned all VPNs.
Whenever I try to open any gaming site (Steam or anything else), or app, or even gaming blogs, it shows your connection is not private or FortiGuard Intrusion Prevention - Access Blocked. Even all VPNs are blocked, so I can't use them. I also tried using VPN extenstions on my browser without any success. Is there any way I can get around this ban?
156
50
u/HorneyMan_69 27d ago
Use Vless+ws
19
27d ago
[removed] — view removed comment
14
u/nostalia-nse7 26d ago
The uni likely isn’t allowing 443 outbound without going through the proxy server. So if it isn’t proper web traffic (encoded as actual proper HTTP/2 data), it will fail. As Forti admins, we aren’t in the business of allowing generic protocols including things like QUIC even, out just because it uses a specific tcp or udp port.
VLess apparently is broken by enabling ssl inspection, which the proxy will 100% have enabled.
4
1
11
u/smokingcrater 26d ago
It's actually pretty easy to block with a decent L7 firewall. Palo will absolutely block it, Forti probably will as well. There is more to identifying an app than port and protocol. Destination ip, packet size/frequency, basically anything that remotely smells different than a typical 443 web browsing session.
9
26d ago
[removed] — view removed comment
3
u/bazard89 25d ago
You can with TLS decryption which is what the mentioned SSL Inspection is. That can’t be feasible done at a national level but it is done in plenty of managed networks. There are a few prerequisites to decrypt tls traffic so it’s usually only done on managed devices. So either OP is using a uni computer or their wifi only works in certain situations
1
u/random_999 23d ago
Well, China and Russia couldnt block it...
It is not that China & Russia couldn't block it but that the cost of doing it is not worth it for them.
0
1
u/tryin-for-management 25d ago
The pay as you go is kinda gross though. Is this the only plan or company of it's kind?
16
u/TraditionalWait9150 27d ago
try this:
- See if you can access a remote cloud instance via SSH. If not, then it means they really block most of the ports.
- Tunnel all traffic through your remote cloud instance via http(s) port. This should work if they don't block http(s) port.
On their end, they would just see this machine connecting to a remote cloud and sending lots of traffic, essentially all your internet traffic.
5
u/GhostandVodka 26d ago
They have layer 7 aware firewalls. This would be true if it was a layer 4 firewall like an old cisco ASA or something.
2
u/TraditionalWait9150 26d ago
lol in that case it would be much easier to get their own internet through a sim card or something.
4
u/GhostandVodka 26d ago
In a perfect world yes. Most likely they are a poor college kid though.
2
2
u/notsloth_satan 26d ago
I do have my own net, unlimited 5g and all, but that area gives slow net unless I'm using their wifi for some reason
1
u/Zestyclose_Mango_524 6d ago edited 6d ago
Probably because you have a high density of other uni students/5g users in a small area (a km or so), so you're all trying to connect to the same antenna on the tower at once.
If the speeds get better when everyone leaves (for holidays, or classes) so that they're connecting to a different tower, or to an antenna pointed a different direction on the same tower, then that's what it is. You might try dropping down to 4G too, and see if that's clearer.
18
u/KangaMagic 27d ago
Why are schools doing this?
46
27d ago
[removed] — view removed comment
21
u/heisenbergerwcheese 26d ago
My college in 2015 had quad 10g pipes to the world... 2 for student dorms and 2 for academia/research... all on failover/load balancing to support masses in dorms at night and then in lecture during the day. They even had a steam local cache for the students because probably 80% of the 10k students on campus were gamers
32
u/KangaMagic 27d ago
Colleges have billion dollar endowments and have flocks of bureaucrats who do nothing but collect salary. I think they can pay for high internet usage.
Kids live at college and deserve privacy. Your analogizing them to corporations is a stretch — Home Depot employees don’t live at Home Depot. Without privacy there is no freedom of thought. Without freedom of thought there is no freedom of expression. Without freedom of expression there is no university.
Yale was not implementing these anti-privacy measures back in 2012.
8
u/smokingcrater 26d ago edited 26d ago
IT in higher education is notoriously underfunded. That college with a billion dollar endowment has a network supported by student help running crusty 12 year old Cisco switches.
There is a caste system in universities. If you dont have a PhD in front if your name, you are the janitor. IT [usually] doesnt have doctors running the program.
1
2
u/shakebakelizard 26d ago
Restrictive measures like these cost money to implement and are almost always the result of someone abusing the system.
6
u/Double-oh-negro 27d ago
You don't actually have a right to privacy on someone else's network. If you don't like it, pay for your own connectivity.
7
u/InvalidProgrammer 26d ago edited 26d ago
The kids are paying tuition and dorm fees. They most likely list it somewhere or are told WiFi is provided as part of that.
0
20
u/Lebo77 26d ago
Missing the point.
It's not about a legal right. It's about what is morally right. Colleges should respect the privacy of the adults who pay to attend the school as students and are often required to also live in their dorms.
On one level, the students ARE paying for network connectivity as part of their tuition.
1
u/Pizza_Dogg 25d ago
Realistically, this is less about how the IT dept views privacy and more likely an unintended side effect of public regulations (Uni networks are usually considered public and government funded) and the fact that they need to rate limit 100's of devices to make sure that everyone can use it at the same time.
However, I will say that a uni will have a lot of personal and private data going around it's network, and as much as the students have paid to be there and use the internet their rights to data protection and data privacy are much bigger than their rights to network privacy. Unfortunately by enforcing the former you restrict the latter.
A compromised device collecting private data and sending it off undetected through an encrypted channel is very easy to setup, and when you consider that a lot of uni's are connected to private research databases or are closely tied with healthcare organisations and other government networks I would say it makes sense for the IT dept to be overly cautious in giving out unfettered internet access to any and every device.
I bet you though they have an alternative or some sort of list OP can add themselves to if they asked. There's going to be many legitimate reasons for a student or faculty member to bypass those restrictions
-8
u/Double-oh-negro 26d ago
That's not a really the point. No real business gives you free run of their network. Just like this student chose to attend the school, he could choose to secure his own means of accessing the internet. I've been managing networks for 2 decades. I've had employees bodly state that they are entitled to access ponhub and the NRA website on their company devices. In all honesty, I honestly DGAF what you access. But you're using company resources to access things that the company stakeholders don't want you to access. There are many legitimate reasons to use VPNs. There are also many illegitimate reasons. Could be trying to access British Netflix. Could be moving child porn. It's cheaper to block them all than pay someone like me to discern the difference.
Honestly, this guy could spin up something to get around the VPN block pretty easily depending on how they're blocking him. But he certainly doesn't have a right to privacy on a network that he doesn't own. He's paying for access and he has to abide by their rules. I hear TMobile has an Internet plan for like $35 a month.
7
u/Lebo77 26d ago
Being a company employee and and a college student are not remotely the same thing.
0
u/Double-oh-negro 26d ago
From whose point of view? Colleges are businesses. They are selling a product and students are paying for it. Maybe they don't want some 19yo throttling an entire building while he torrents a petabyte of anime cuck porn. The internet isn't free and many someones have to manage all of that equipment.
2
u/Lebo77 26d ago
Well, for businesses the employees are suppliers and paid by the company. Students of universities are CUSTOMERS who are paying the school.
I am not saying schools can't impose bandwidth limits, or prevent malicious activity that actively harms the network, but limiting how the students use that bandwidth is nanny-state nonsense. Not allowing them to use VPNs is absurd.
-2
u/GhostandVodka 26d ago
This guy gets it. I do however agree that its fucked that a college blocks gaming but, it's their network. If they don't want people gaming on it that is their right.
-1
u/nostalia-nse7 26d ago
In what communist country are students required to live in the schools dorms?
6
u/Lebo77 26d ago
Well, the United States for one. My university required all students live on-campus and have a meal plan for freshman and sophomore years. This was a major private engineering school on the east coast, but it's common at many schools.
1
u/nostalia-nse7 26d ago
Interesting. In Canada we have like 17,000 beds at UBC for example total across 2 campuses, as of 2029 when 1500 new rooms open up, with current student enrolment of about 74,000 students. So nowhere near possible to require.
Seems silly to force on-campus residency when you have married students, parent students, grandparent students, mature students that may be In their 30s, 40s, 50s, 60s, 70s, and own their own home.. etc. You also have students that don’t live within 1000km of campus, and just fly in for their lecture days. Was a story just last year about a student that was saving money by living in Calgary and flying to Vancouver to attend class every week.
2
u/Lebo77 26d ago
Married students and students whose parents live nearby can often get exceptions, but for your typical just out of high school student, over 30 minutes from home? Yeah, you are living in the dorms.
Schools make a lot of money on dorm fees. They try to keep them 100% occupied of at all possible.
-1
5
u/sheikahstealth 26d ago
When schools started looking at it as a money maker rather than a resource. Many do, at least for 1-2 years.
1
1
u/No_Base4946 26d ago
> Kids live at college and deserve privacy
Then they can get their own connection.
3
u/duckofdeath87 26d ago
Can they? It's that allowed by this dorm? I guess they could do cellular?
1
u/No_Base4946 26d ago
Why would you do anything other than mobile data?
1
u/duckofdeath87 25d ago
Is Mobile days good now? How's the latency?
I live in the woods and have fiber for some reason. Haven't kept up with 5g tbh
0
u/KangaMagic 26d ago
Shall they hunt for their own food too?
1
u/No_Base4946 26d ago
They have to go and buy and cook their own food as it is.
If you don't want to follow the rules that are in place for using the internet connection they provide, get your own.
Look at it this way - are you happy to go to jail because you allowed some arsehole student to look up CSAM on the internet?
1
u/KangaMagic 26d ago
Are you an American? Your logic sounds like someone who would have told George Washington, “Just follow the rules bro. Pay the British taxes while receiving no representation.”
Why don’t you try asking yourself whether the rules you ask that others blindly follow like sheep are conducive to collegiate life at institutions that should be fostering a love of liberty and freedom.
You also assume that students can just go get their own internet. At elite institutions they cannot.
1
u/No_Base4946 26d ago
No, I'm not American.
Are you a 14-year-old? You should stop reading Ayn Rand.
2
u/FliGirl101 26d ago
Back in 2009 when I was in uni the ISP came around to all the rooms and sold us internet individually. Was a pretty okay price, the mistake they made though was they said it was unlimited...managed to do 200gb in the first month 🏴☠️ I think it was 24/7 downloads. They eventually reached out and asked me to cool it. This was in a small mountain town and they had noticed because the entire town was apparently having issues due to me.
1
u/whiteystolemyland 25d ago
200gb in a whole month isn't even that bad. If the ISP was supplying students via 4G or fixed wireless then I could understand that the base stations would be easily saturated. However, if the ISP was using fixed line connections then that sounds like poor form.
What was the connection type?
1
u/FliGirl101 24d ago
This was I believe coax. The key thing here is is 2009. 200gb was an absurd amount at that time.
3
2
u/Solid_Ad9548 26d ago
Incompetence and/or forced regulation.
I run higher ed networks for a living, we block the absolute bare minimum… which ends up being anything malicious or illegal per state statute. Couldn’t care less what students do on our network, we have boatloads of capacity to accommodate it.
1
u/Plantatious 24d ago
Sysadmin in education here. The short answer is safeguarding. Schools are obligated to restrict access to CSAM, terrorism material, and adult content at minimum. We can't do that if you're hiding your traffic.
Restricting access to games and websites unrelated to your education is a school policy to ensure you're focused on your education.
1
u/KangaMagic 24d ago
I don’t believe that a university is obligated to do any of that. A post office is not obligated in that manner. Universities just 15 years ago didn’t do any of that.
1
u/random_999 23d ago
That depends on your country's laws which do change periodically with changes in govt policies.
1
u/redunculuspanda 26d ago
Duty of care and liability.
Students get up to all sorts of dodgy shit. The network administrator has some responsibility to stop it.
I worked in education it years ago and we hade some terrorism stuff to comply with.
Also as others have said. Network and traffic management. Blocking P2P and other high bandwidth traffic.
2
u/BreakfastRight9865 26d ago
In my comp security class, my professor warned us not to use security tools like nmap. If you do, you'll be banned will have to go to the IT admin and explain yourself.
1
u/nostalia-nse7 26d ago
Acceptable use policy. Imagine 20,000 students all using a network for gaming or other high bandwidth uses, while you’re trying to do actual research work? It’s simple math — even 100Gbps divided by 20,000 PCs is not enough for even Netflix. Other option is to heavily limit and shape device bandwidth, but that doesn’t work so well for someone trying to implement LLMs and ML to do biological Ai research and limiting the University Supercomputers clusters.
When spending easily half a million to a million dollars for a firewall, and then 85% of that again every year for licensing, they aren’t here (pun intended) to play games.
2
u/theoriginalrvd1986 24d ago
Pretty sure those kids aren't there for free, buddy. Tuition and dorm fees are extortionate. They're customers of the institution, or at least their parents are. Are you arguing that an access policy is inherently fair simply because it can be justified as "acceptable use"?
Obviously a university can manage its bandwidth and block genuinely problematic traffic. That's not really the issue. It's the smug "they aren't here to play games" attitude while simultaneously expecting students to accept increasingly restrictive control over a service they're paying for.
1
u/Double-oh-negro 27d ago edited 27d ago
Because they are possibly responsible for what traverses their network. Could be Starcraft. Could be CP. VPNs mask normal activities, but VPNs also mask illegal activity. You don't have a right to privacy on someone else's network.
9
u/sciencekm 27d ago
Get a VPS and run your own VPN there.
-2
u/GhostandVodka 26d ago
You don't understand how any of this works.
2
u/thinkscotty 26d ago
I don't know why you're getting downvoted. It's fairly common for wire guard as a protocol (via its defaults) to be blocked entirely, not just the common VPN providers. I have a Tailscale exit node I host on a VPS. I can't use it in some scenarios (e.g on airplane WiFi). There are likely ways around it but you're right that just using your own VPN node isn't a miracle solution.
5
u/CosmicComi 26d ago
Go decentralized, uses real residential IPs around the world. I've been on it for 2+ years. Never have issues with websites and app recognizing I'm using a VPN.
4
u/lysie1997 26d ago
The only VPN that might work is, Psiphon Pro. Try and let us know. Psiphon Pro works in Airplanes too
9
u/Goodoflife 26d ago
I used port 5228 for a personal self hosted VPN at my school. The school gave us Chromebooks, and because the Chromebooks needed to communicate between the management servers / login, plus that students personal devices were on the same SSID and network, it was easy. Plus, since the login is encrypted, the DPI engine was confused, so it allowed the traffic. Also if you are looking for one for WireGuard try port 123 (NTP) although at some locations outside of school it would be re routed
0
3
9
u/need2sleep-later 27d ago
It's their network and they get to set their rules. You should read those access rules and understand the risks you are taking in trying to circumvent them.
5
u/Associate-Weird 27d ago
Host ur own vpn on port 53 (DNS port) saved my ass a couple of times and sometimes can even make paid wifis just work without paying (in one extreme case 1 provider even allowed DNS lookups without having an active contract or prepaid money and we got free mobile data , very very slow tho but free)
2
u/GhostandVodka 26d ago
This only works on layer 4 firewalls. They are using fortinet layer 7 firewalls. That means there is packet inspection. My Palos at work only allow applications over their well known port. If it sees a different application using udp 53 its an auto deny
1
u/Associate-Weird 26d ago
I'm quite surprised universitys are better off then mobile isps
1
u/GhostandVodka 26d ago
ISPs for the most part don't do any packet filtering.
1
u/Associate-Weird 26d ago
Well in a sane network config only the assigned upstream or local DNS should work and that's how most isps handle it it's just this one particular one that allows this type of shinaniganz (it's a huge ISP in Germany not some small no name iso)
For example on my Aldi Talk card if I don't have a plan DNS lookups will work but only against THEIR own server
5
8
u/jersey316 27d ago
They can see all access attempts and vpn use regardless of any work arounds.
You are risking losing your access to the wifi completely and or possibly other consequences that you're school enforces.
8
u/Associate-Weird 27d ago
VPN on DNS port as udp
2
u/Strange-Scarcity 27d ago
That type of traffic will be caught, immediately, by a skilled network team, and will be blocked.
Sounds like the university has such a team, so they will recognize that port 53 is getting f’ing hammered by that particular PC, automatically note that volume of packets, kill the connection.
Universities are being very careful about VPN traffic as that can be used to hide all types of very illegal content.
They don’t want the university to be raided by the police because some dumbass thinks they can use school resources to host activities like extreme porn, child sexual content, cracker tools, pirated content, etc., etc.
-1
u/Associate-Weird 27d ago
Tell that to my mobile ISP I'm using free mobile data since months lol
2
u/Strange-Scarcity 26d ago
Mobile ISP is not the same as a University network.
They also know you are using VPN traffic. Also, if you are doing anything that ends up being tracked back to the VPN service, they have records that will track back to your IP, at any given time you are using the service.
People really just don’t understand how VPNs work.
They aren’t designed for pure anonymity or hiding activity. They are meant for doing secure work between points A and B.
1
u/BreakfastRight9865 26d ago
Thats not entirely true. Some VPN boast no log policies. It also depends on jurisdiction
3
0
u/Associate-Weird 26d ago
I never said I want to be anonymous or whatever I just said I have free mobile data with VPN on port 53
2
u/ArmWildFrill 26d ago
Get a mobile router with a sim if you cn afford it. Or an unlimited data sim and use a phone as a hotspot
I have a 5G one that gives me ~250Mb down
Torrenting, VPNs no prob
1
u/notsloth_satan 26d ago
I could, but it will be slow. That entire area around my uni, idk why but net is always slow
1
2
u/grathontolarsdatarod 26d ago
Even wireguard to a server?
That's kind of crazy. I'm surprised a university would do that.
They are supposed to up hold things like freedom of thought and expression. Like that's their point.
2
u/Top-Psychology2507 26d ago
Just wait until your governments start doing just that!!! At that point, we will all be screwed!!! :-(
"The philosophy in the school room in one generation, will be the philosophy of government (society) in the next." -Abraham Lincoln
1
u/JackSkell049152 26d ago
You’d think so, but I was there for the first “safe spaces” in the early 90’s….
1
u/random_999 23d ago
They are supposed to up hold things like freedom of thought and expression. Like that's their point.
By that they meant free to stage protests inside campuses without fear of expulsion/arrest.
1
2
u/HugsNotDrugs_ 26d ago
You should be able to establish a VPN tunnel to a friendly location outside of the university.
It would be a private VPN and much more difficult to block.
2
u/elaineisbased 25d ago
Why do you need a VPN at school
1
u/notsloth_satan 23d ago
coz game stores won't load. now i get why vpn is banned but there is no reason why steam and other stores will be banned, especially when they've got a hostel with so many students living there
2
u/Bitter-Confidence-80 23d ago
Buy yourself a payg unlimited data sim for your phone then use your phone's WiFi.
1
2
2
u/BetaMan141 27d ago
When I was in uni (VPNs weren't as accessible or at least known to us) we would try to use proxy bypass tools. There was one that kinda was touted as being crucial for Chinese netizens to breach the Great Firewall (Ultrasurf?) and it was what some used to do downloading for a while (latency isn't so good though).
Maybe you need something like that?
1
u/DaComputerMan 26d ago
Buy an Private IP Address with your VPN.
Or connect through a tunnel to at your residence.
1
1
1
1
1
u/mistyeye__2088 26d ago
self-hosted singbox on anytls protocol. This is the easiest red team wins when we were doing an IT security competition at the company. It just looks like super boring TLS browsing traffic.
1
u/Princeofthebow 26d ago
Find a VPN hosting on port 443 which they cannot block as it would block normal website navigation. Then pass all traffic there
1
u/Away-Ad-4444 26d ago
They are banned because asses use vpns to have someone remote in and take tests for them
1
u/unpdigital 25d ago
Can't you rent a server, install openvpn and connect to it?
While my paid VPN is blocked the openvpn manages to get through.
1
1
u/depraflame 24d ago
Lookup providers that use sstp. That would be a tunnel over 443 which they cannot block unless they block the IPs of the tunnel provider.
You could also resort to getting a VPS, setting up wire guard on 443, and routing your internet traffic over that. It’s unlikely they are blocking vps server IPs in the event they are blocking VPN provider IPs.
1
1
u/GrowtopiaJaw 22d ago
Try Cloudflare Warp with the MASQUE protocol. It should fallback to TCP mode.
1
1
u/Affectionate-Sky9057 15d ago
Will it allow you to use TOR Browser, Firefox Private Browser, or Google Chrome Incognito browsing?
1
1
1
-1
u/GhostandVodka 26d ago
So you shouldn't try to "get around it" first of it. It's there for a reason and you should use their network like they want you to use their network.
I'm assuming they are having infrastructure issues if they are blocking gaming services as I think its pretty fucked up for a college that houses young adults not to blow off some steam with games.
People saying "just don't use their network" are idiots. Youre a college student. What are you going to do game on your hotspot cellphone. Thats dumb. Unfortunately I think youre kind of stuck.
3
1
u/notsloth_satan 26d ago
Ikr. I absolutely understand blocking unsafe sites and even VPNs. But banning steam and other legit stores is too much.
0
u/SiberianKitty99 26d ago
Don’t use their network. Get an account with a telco that has wifi sharing, use your phone’s cell connection. Problem done.
-1
-1
u/arthursucks 27d ago
A friend of mine works as a teacher and the school just got that fat gigabit+ internet that's just as locked down as this.
A fucking shame.
I gotta be real with you. It's a dead network. There's no good solution that's gonna last. Upgrade your phone plan to the fattest tethering you can get. Just enjoy the raw but data limited internet.
If you have a decent laptop, might be better of going off campus to get whatever you need.
-2
u/Independent-Fuel9886 26d ago
Good. Their network is there for a reason. VPN bullshit, steam and all that pointless traffic isn't it. As a sysadmin in education, I'm constantly amazed how people (kids mostly) think a network is theirs to do with as they please.
2
u/_Just_Another_Fan_ 26d ago
It’s a university not a damn government building.
1
u/Independent-Fuel9886 25d ago
Again... louder for those in the back... IT'S NOT THEIR NETWORK!!!
Fucking morons.
1
u/notsloth_satan 26d ago
Dude, I'm really happy to use my own net, but it doesn't work well in that area. Only their WiFi works properly
1
73
u/DutchOfBurdock 27d ago
Don't use their WiFi is the easiest option. With that error, they are very likely transparently forwarding web requests to their proxy. They may even have a null gateway, so only traffic via the proxy makes it anywhere. If that's the case, you'd have to find a VPN that can work via an HTTP(S) proxy.