UDP blocked: what it means for your VPN and Hysteria2
Why some networks block UDP and QUIC, what that does to Hysteria2, and how Colitu's Adaptive Connect falls back to TCP transports without your help.
Most of the internet runs on two transport protocols. TCP delivers a reliable, ordered stream: web pages, downloads, email. UDP sends independent datagrams with no built-in delivery guarantees: DNS, voice and video calls, online games and, more and more, the web itself, because HTTP/3 runs over QUIC and QUIC runs over UDP. A VPN protocol built on UDP inherits UDP's fate on every network it meets.
Why some networks block or limit UDP
UDP is not blocked because it is "bad". Networks restrict it for a handful of practical reasons:
- Simple firewall policies. Many corporate, school and hotel firewalls allow only web traffic over TCP plus DNS, and drop everything else.
- Less visibility. QUIC encrypts almost all of its headers. Equipment that inspects or optimises traffic sees much less than with TCP, so some operators block QUIC, knowing that browsers will fall back to TCP.
- Abuse protection. UDP can be abused for amplification attacks, so some networks rate-limit UDP or allow it only to well-known services.
- Filtering. Some filtering systems treat QUIC to unfamiliar destinations separately, slowing or dropping it.
- NAT behaviour. Home routers and operator-grade NAT keep UDP mappings for a limited time; an idle UDP flow can lose its mapping and stop working.
The QUIC standards expect this: RFC 9308 tells applications that UDP may be blocked and that they need a fallback.
How to recognise a UDP problem
- The VPN connects on one network but takes much longer, or fails, on another.
- Video calls stutter or drop on that network even without the VPN.
- It happens on a specific type of network: office Wi-Fi, a hotel, a particular mobile operator.
A slower first connection on such a network is often the visible sign of fallback in action: the app first tried the UDP transport, saw that no traffic passed, and moved on.
What it means for Hysteria2
Hysteria2 runs over QUIC with TLS 1.3 and its own congestion control, which keeps its pace on lossy links. That is what makes it the fastest Colitu transport on mobile networks and long routes. But all of this depends on UDP getting through:
- UDP fully blocked: Hysteria2 cannot connect at all.
- UDP throttled: it connects but runs slowly or unevenly.
- UDP dropped after a while: it works for some minutes, then stops carrying traffic.
No congestion control can help when the network deliberately discards the packets. The answer is a different transport, and that is what Adaptive Connect is for.
How Adaptive Connect falls back to TCP
Every Colitu server offers five transports. Hysteria2 uses UDP; the other four connect over TCP:
| Transport | How it travels |
|---|---|
| VLESS Reality | TCP, TLS 1.3 with Reality camouflage |
| VLESS XHTTP | TCP, an HTTP-like stream of separate up and down requests over Reality |
| Trojan | TCP, TLS that looks like HTTPS |
| Shadowsocks 2022 | TCP, AEAD encryption with replay protection |
Adaptive Connect chooses between them for you; there is no manual protocol setting:
- Order. On Android and iOS the app tries Hysteria2, then VLESS Reality, VLESS XHTTP, Trojan and Shadowsocks 2022. On Windows and Linux it tries Hysteria2 first, then the TCP transports sorted by how quickly a TCP connection to the server opens; unreachable ones go last.
- Real traffic, not just a handshake. A transport counts only when real traffic passes a check (about 12 seconds on Android, about 9 seconds on iOS). A UDP-blocked network fails this check, and the app moves on.
- Memory. A transport that carried nothing is pushed back: for 10 minutes on Windows and Linux, marked as stalled on Android, given a penalty on iOS. Android also remembers the last working transport for each server.
- Watching while connected. The Windows app checks every two seconds whether the tunnel still carries traffic and reconnects if it stops, which covers networks that drop UDP after a while.
Apps also report which transports worked to the panel in aggregate, so defaults improve over time. You never have to configure anything.
The trade-offs of TCP
Falling back keeps you online, but TCP behaves differently. Under packet loss it slows down to recover, and one lost packet can hold up everything behind it. On a clean office network you will hardly notice; on a weak mobile signal TCP transports can feel slower than Hysteria2 would on a network that allows UDP.
What you can do
- Usually nothing: wait for the app to finish connecting instead of cancelling and retrying.
- If speed matters and you have a choice, use a network that passes UDP, for example home internet instead of hotel Wi-Fi.
- On a work or school network, follow the organisation's IT rules; the network owner decides what is allowed.
- If no transport connects on a network, try another location, then write to support with the type of network and your region. More checks are in the help centre: connection problems and speed optimisation.
Related reading: VPN works on Wi-Fi but not on mobile data and VPN blocked by DPI.
Sources
- RFC 768: User Datagram Protocol
- RFC 9000: QUIC, a UDP-based multiplexed and secure transport
- RFC 9114: HTTP/3
- RFC 9308: Applicability of the QUIC transport protocol
- RFC 9312: Manageability of the QUIC transport protocol
- CISA: UDP-based amplification attacks
- Hysteria 2 documentation
- Project X (Xray) documentation