This question has a new answer every month, because China's filtering system (the one the world calls the Great Firewall) is not a static wall — it is a deep-packet-inspection system that learns and blocks new techniques continuously. That is why this article carries a date in its title and gets updated on our measurement cycles: everything below comes from testing on real devices on real networks inside China, not from theory.
Our latest measurements: which protocols survive, which die
What we observed from real hardware on Chinese mobile and broadband networks:
- Plain WireGuard: dead. Connections are identified and cut by DPI almost immediately. This is not a defect in WireGuard itself — the project states plainly that evading network filters is a non-goal — but it means a VPN that only offers WireGuard or OpenVPN is close to useless in China in practice.
- VLESS+Reality: connects. In our measurements it established within roughly five seconds on the same networks where WireGuard was killed. The reason is how Reality disguises itself: it presents a real website's TLS handshake to the inspector, making the traffic indistinguishable from ordinary HTTPS browsing — and even an active probe hitting the server directly finds a real website.
- The trade-off, said plainly: nothing guarantees the future. The filtering system adapts constantly, and next cycle's measurements may differ — which is exactly why our app runs several protocol families (VLESS+Reality / Hysteria2 / WireGuard-AmneziaWG) and switches automatically when the current one gets blocked. Betting on a single protocol is a risk a user should not have to carry.
For the mechanics of each protocol family, the plain-language protocol guide covers all three.
The one rule that matters more than everything else: install before you fly
The chicken-and-egg problem people actually hit in China: most VPN providers' websites — including the signup and download pages of nearly every brand — are unreachable from inside China in the first place. If you land first and plan to subscribe later, it may already be too late.
Before boarding:
- Finish signing up and installing the app from your home country.
- Connect at least once so the app has fetched and cached its latest configuration on the device.
- Keep an escape hatch: note a support contact that doesn't require reaching the main website.
What about travel eSIMs? An honest answer
A popular piece of advice lately says tourists can skip the VPN entirely and use a travel eSIM (roaming through a foreign network). That is partly true, and worth stating completely: a foreign eSIM's roaming traffic exits the internet in the SIM's home country, so blocked services work without any VPN — for a short tourist trip it genuinely is the convenient option.
Where the eSIM cannot help: whenever you are on Wi-Fi (hotels, offices, universities — Wi-Fi traffic does not ride the roaming path), when a longer stay makes roaming costs unreasonable, when you need the full speed of a local network, or when you carry a Chinese SIM for local apps and SMS. Those cases come back to a VPN that has been tested to actually work. For long stays the practical setup is both: the eSIM as an emergency exit, the VPN for daily work on Wi-Fi.
Before you travel
- Plain protocols (bare WireGuard/OpenVPN) barely function in China — you need an obfuscated family such as VLESS+Reality.
- Install and test-connect before you fly — most signup pages are unreachable from inside.
- Trust no one's 100% guarantee — the filter changes constantly; what actually works is running several protocols with automatic switching.
- A travel eSIM covers the tourist-on-mobile case, but not Wi-Fi, and not long stays.
TukTukVPN runs VLESS+Reality as its lead protocol for heavily filtered networks, and the app switches protocols automatically when one is blocked. Your first purchase carries a 30-day money-back guarantee — finish signing up and testing before boarding.
