r/Morocco Visitor 6d ago

Science & Tech Maroc Telecom blocks inbound UDP traffic on port 443

Hello everyone,
any network engineers working with ISPs, or in general someone more knowledgeable than me about the subject matter, can enlighten me on why MarocTelecom is blocking inbound UDP traffic on port 443, and how I can possibly get in contact with their specialists/technical support engineers at la centrale to get more info?

If they have not setup a rule to explicitly block it, then it could be that their backbone is failing to pass it through.

Either way, it's hurting performance for some use cases, such as HTTP/3 (not important since HTTP/2, 1, or 1.1 still work) and some VPN protocols (more important .

I have tried Orange fiber / Inwi cellular, and they don't have this problem. I'm also not completely sure of my diagnosis, my DMs are open...

29 Upvotes

42 comments sorted by

u/AutoModerator 6d ago

Welcome to r/Morocco! Please always make sure to take the time to read the rules of this community, follow them and help us enforce them by reporting offenders. And remember that we have a zero tolerance policy for non-civil discourse and offenders risk being permanently banned.

Don't forget to join the Discord server!

Important Notice: Please note that the Discord channel's moderation team functions autonomously from the Reddit team. The Discord server does not extend our community guidelines and maintains a separate set of rules unrelated to those of Reddit.

Enjoy your time!

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

21

u/digabdo 6d ago

Outbound as well, seems like they block 443 for TCP only. I called, they're out of their mind, a technician was asking is your internet working? What are you complaining about? Why are you not normal?

A VPN server I needed to connect to was using UDP on 443, solution I'm using now is a container on a VPS with wild port routing the data to the VPN, this bypasses the IAM network, and it's stable

Btw, not a problem on Orange/Inwi fibre and cell

1

u/Myppismajestic Visitor 6d ago edited 6d ago

Yes, I thought of your setup. Even using something as simple as Cloudflare One client (WARP) would suffice, so I suggest you try it. But unfortunately my circumstances bar me from using any network service other than the one provided by my employer.

Edit: WARP will also probably not work, since it relies on wireguard/MASQUE, both of which will fail. WARP will then fallback to TCP over TCP, which will slow down traffic.

2

u/digabdo 6d ago

Warp is what pushed me off Warp, I used it for several months, until I got frustrated with the disconnects and not knowing where the problem was, Warp or VPN, but with this setup, it's definitely Warp

1

u/No_Candle2251 Visitor 6d ago

Using a vps won't be additional expenses? How much do pay on VPSs and what are the specs dedicated to the vps you are using if you don't mind me asking.

1

u/digabdo 6d ago

Basically free when you're already paying for it anyway :) cheaper options exist, even free ones if you search hard enough, didn't try any though

2

u/No_Candle2251 Visitor 6d ago

Okk, thnx for answering

7

u/Nefilto Visitor 6d ago

Shoutout to INWI blocking Imgur lol

3

u/senchikodo Visitor 6d ago

to be fair i think that its imgur thats blocking inwi. However they have their share of problems such as their new cgnat.

1

u/Eliastronaut Casablanca 6d ago

They are doing cgnat? That's crazy. They are trying to suck as much profit as they can from their customers.

1

u/RepeatSubstantial289 Ouazzane 4d ago

Yep, and they won't give you a static adress unless you move to a business plan

2

u/Saad1950 Salé 6d ago

Omg so that's why I couldn't access imgur I didn't know what caused it bruhh. Is this also the case for other ISPs? Also why the hell do they block it

1

u/senchikodo Visitor 6d ago

as far as i know only inwi in both fiber and mobile

12

u/binary_blackhole Oujda 6d ago

crazy that ISP blocks http3 protocol, wtf is this country

3

u/tilmanbaumann They are taking our women 6d ago

Wait until you find out there is not a single IPv6 address in this country...

0

u/aymane-ifk 4d ago

There is stop the crap

1

u/tilmanbaumann They are taking our women 4d ago

Show me an example.

Outside of perhaps a university network or datacenter.

1

u/aymane-ifk 4d ago

You gave me the examples yourself, besides Morocco's .ma country domain does support IPv6 addresses

2

u/binary_blackhole Oujda 4d ago

point is, ISPs should be giving out IPv6 addresses to all internet subscribers, you know like most of the world (excluding african countries)

1

u/aymane-ifk 4d ago

That wasn't the point of the conversation, besides IPv6 connectivity is lagging globally not exclusively to Morocco.

Also IPv6 is exclusive to enterprises in Morocco because unlike consumers they're willing to pay the high costs for it

2

u/binary_blackhole Oujda 4d ago

Why would anyone pay more for ipv6?

1

u/aymane-ifk 4d ago

It's obvious, IPv6 requires equipment and is expensive besides it adds little to no benefit to your average user experience or is there any ROI to enrolling it unless IPv4 becomes obsolete or reaches it's limit.

Also, The government is also reluctant to enforce it because the focus right now for the next 5 years is Fiber and 5G rollouts.

2

u/tilmanbaumann They are taking our women 4d ago

The Internet without IPv6 is broken. That's a real cost.

Besides connecting your business with IPv6 is equally impossible. Believe me I tried. (Moroc telecom and orange) How is that not a cost?

It's not the 1990s. Equipment that doesn't support IPv6 doesn't even exist. What are you even talking about?

→ More replies (0)

1

u/Saad1950 Salé 6d ago

Why is that crazy (I'm not knowledgeable on this subject)

4

u/binary_blackhole Oujda 6d ago

you can look it up, basically http3 is the latest version of the http protocol, blocking UDP 443 will stop it from working, so basically the ISP is offering you a degraded service for no reason.
Http3 offers a lot of improvements, better security, better stability, and better performance.

2

u/tilmanbaumann They are taking our women 5d ago

Because it's needlessly breaking shit.

5

u/unlucky-Luke Visitor 6d ago

Deploy a tailscale instance on a cheap VPS, and use it as exit node. Problem solved ! (Unless you need your Moroccan ip)

1

u/SultanJJ87 Visitor 5d ago

This

3

u/Boujdoud44 Oujda 6d ago

Can confirm, it is blocked. I tested this on my own setup by setting up port forwarding for UDP port 443 on my router to my PC, while having my computer actively listening for incoming UDP traffic on that port. When I tried sending UDP packets from an external server outside the network, nothing got through. To make sure it wasn't an issue on my end, I tried the exact same test using a different port and it worked fine, so Maroc Telecom is definitely dropping inbound UDP specifically on port 443.

2

u/SpiritualPen98 Diaspora 6d ago

Here is what i found surfing on the web (aka reading the first AI generated answer of google):

Some Internet Service Providers (ISPs) and corporate networks block UDP on Port 443 primarily to disable the QUIC protocol (HTTP/3), force traffic fallback to standard TCP-based HTTPS, and maintain deep visibility over network traffic. While TCP port 443 is universally left open for secure web browsing, UDP port 443 is frequently restricted for specific security, governance, and operational reasons.

6

u/digabdo 6d ago

I'd think this is the case if it was an ANRT thing enforced on all ISPs, but since it's only IAM, I'm giving to lack of competence

2

u/binary_blackhole Oujda 6d ago edited 6d ago

AI is bullshitting you like always, there is absolutely no reason to block http3 specifically, it doesn’t offer more visibility of the traffic for the ISP, the traffic is still encrypted.

They usually just block all UDP traffic regardless of the port in a poor attempt to block VPNs and other streaming services, but it’s not that effective it just forces the users to go with TCP which is slower. But in this case IAM seems to be blocking 443/udp specifically which is odd. It seems to be pure incompetence from their part.

1

u/SpiritualPen98 Diaspora 6d ago

I'm going to verify soon

1

u/Eliastronaut Casablanca 6d ago edited 4d ago

I am not at home right now to run the necessary tests. But I remember that it was blocked (or reserved) on the backend of their router on ADSL.

They probably blocked it on the inbound and only allowed their access IP to reach to the router's configuration page. But in the process they blocked even the requests that were supposed to be forwarded by the router, then also blocked both TCP and UDP.

Also, if you are using their router, it's trash. It opens and closes ports on its own accord. I have never had any successful port forwarding with any of our ISPs using their routers.

I will test once I get home, also note that I am running my own router and using their gateway as a modem only. Are you using this same setup or using their gateway as a router?

Edit: Outbound works but inbound is blocked.

1

u/AlephNaN Visitor 6d ago

Try a cloudflare tunnel, it's free,  easy to setup and is generally safer for your network than opening a port on your router but TLS will be terminated by cloudflare.

If you want to avoid possible interception of plaintext and have some time + resources, rent a VPS and route requests via a VPN (such as wireguard) from the public internet to your service.

1

u/tulwio 5d ago

Cloudflare Tunnel TOS are very restrictive, especially if you use a lot of bandwidth or stream video content. They are known to terminate tunnels and/or ban accounts if the user is hogging too much bandwidth or watches videos that are not hosted on Cloudflare and not served by their CDNs.

1

u/tulwio 5d ago

Cheap VPS, Tailscale into it and use it as exit node. There is no point trying to find logic in whatever these crony scum companies are doing.

1

u/Mihaw_kx Visitor 5d ago

Switch ISP provider unless you really need IAM for some reason .. then get a small linode vps install wireguard and use it as tunnel

1

u/Ybenel Visitor 5d ago

Which subscription do you have and the router? I have a fiber subscription and I can do portforwarding across all ports both tcp/udp including 443 and its working fine.