Golden Shield Project Firewalls China
Posted by Matt Buck on March 13th, 2009
Before I start, please understand that this is not a politically motivated post. I’m purely interested in the mechanics behind the Golden Shield Project or what’s known as the Great Firewall of China.
Since 2003, the Chinese government has imposed a mass censorship program on china’s internet activity; essentially cherry-picking and blocking communications in and out of the country. Unfortunately, this series of firewalls stand between China and the rest of the Internet.
RatwareUK first met this problem some time ago, when one of our customers who deal with China were experiencing some serious and unexplained email lagging. On inspection, it’s reported that China uses various censorship methods, such as:
- Access to certain IP addresses denied. This causes issues, for example, where a blocked website resides on a virtual hosting server, all websites on that server are blocked. Quickly you’ve got a lot of blocked sites!
- DNS filtering and redirection (to prevent IP addresses from being found).
- URL filtering (to prevent access to websites with a specific domain name).
- Packet filtering (terminate packets with a specific keyword contained within).
- Connection blocking (if a previous TCP connection is blocked, future attempts from both sides are blocked for a period of time).
Chinese users can get around these issues, by using proxies, VPNs and other encryption methods. However, it does make the average user in China completely restricted to the authorities’ prescribed information.
You can see whether your website/domain name is outright blocked in China by using this handy tool – http://www.websitepulse.com/help/testtools.china-test.html . If it’s not blocked though, don’t be surprised if any communications with China are slow, as your data is filtered through some serious hardware!

Recent Comments