IPSec shutdown in China: alternatives

How companies continue to securely connect their locations

IPSEC shutdown in China

The Chinese government is increasingly restricting IPSec VPNs. As a result, companies are losing secure access to servers and services abroad. SAVECALL shows alternatives for stable and legal site connections.

In a nutshell:

  • Background: The Great Firewall blocks international IPSEC ports
  • Affected: VPN and Cross Border Tunnels between China and abroad
  • Allowed: Only regulated carrier lines such as MPLS or SD WAN
  • Solution: China Telecom SD WAN with POPs in Beijing, Shenzhen and Guangzhou
  • Advantage: Fast provision from 10 Mbit, low latency, cheaper than MPLS

The solution: SAVECALL securely connects German companies with China via regulated SD WAN solutions in cooperation with China Telecom.

What this article covers: This article explains why China is shutting down IPSec VPNs, what the official regulation says, and how the China Telecom SD-WAN platform works as an alternative. The core question: How secure is your company’s connection to China at the moment?










Why China is shutting down IPSec VPNs

The IPSec shutdown in China refers to the gradual blocking of cross-border IPSec VPN tunnels by Chinese authorities, which means companies with sites in China lose their usual site connection abroad.

Many German companies maintain VPNs to China in order to connect their sites there to the corporate network. The Chinese cyber security authorities want to control internet usage in China and block international websites in particular. This is done through the “Great Firewall of China”. All internet traffic must pass through this and be filtered there. In the past, Internet users in China were able to bypass this firewall using international IPSec VPN tunnel services. For a monthly fee, you could use unregulated, open Internet access with an online service provider, and a huge gray market developed. With China’s Cybersecurity Law of 2017, this gray market was systematically eliminated, and offenders have since been subject to severe prison sentences. German companies are also affected by this, as they usually grant their employees access to the international Internet and their own servers and services abroad. Technically, this is realized by means of IPSec tunnels or MPLS VPN.

The official Chinese regulation

The official Chinese government policy on this is as follows:

  • Any business entity and individual who set up or rent lines (including VPN services) for the purpose of cross-border transaction or activities is strictly prohibited without authorization from the Chinese Telecom Management Authority.
  • The Cloud Service Provider who owns service infrastructure in China and requires connection to foreign country networks shall establish the connection through authorized international internet access service providers approved by the Ministry of Industry and Information Technology (MIIT). Leased lines, VPNs and any unstated self-invented network communication channels are strictly prohibited.
  • CDN and SD-WAN operation, including cross-border data transmission, shall comply with the above rules for future management.

In practice, this means that ports 80, 443, 8080, as well as IPSec/S2S VPN, are blocked by the Chinese authorities. IPSec technically uses the ports 50, 51, 500, 4500 and so on, without there being an official document that specifically addresses these ports. Nevertheless, all cross-country IPSec ports are gradually being blocked. Only pure China-domestic IPSec connections are not affected. What alternatives do companies then have to connect their Chinese locations to their international branches or foreign servers? Carrier MPLS connections are not affected by the shutdowns, as they are subject to different regulation. Since they are so expensive, the Chinese authorities are not concerned that these lines will be used en masse for surfing the unregulated Internet. For many companies, however, an MPLS connection to China is too expensive. Therefore, China Telecom now offers a regulated, reliable and cheaper alternative to MPLS.

The China Telecom SD-WAN platform

Technical sketch of SD-WAN High Speed Network: Site Connectivity between branches in China and international branches via CGW and optimized Internet.

Here, an existing local Internet connection is used to switch a connection via a pre-configured China Telecom SD-WAN box via China Telecom’s business user backbone, which is located outside the Great Firewall of China and also offers far better performance. The traffic is routed via SD-WAN POPs in Beijing, Shenzhen and Guangzhou to the low-latency CTG DCI-Net and then forwarded internationally via a gateway in Hong Kong. The traffic can then be transferred to the Internet in Frankfurt, for example. SAVECALL has designed such a solution together with China Telecom and has already put it into operation for many German companies. We offer connections from 10 Mbit, which are delivered ready for operation within approximately 14 days, a reliable solution that is far cheaper than an MPLS VPN.




How SAVECALL connects your China sites

SAVECALL securely connects German companies with China via regulated SD-WAN solutions in cooperation with China Telecom. Get in touch with us, we will be happy to advise you free of charge and without obligation on the right alternative for your site connectivity.

Conclusion on the IPSec shutdown in China

Whether carrier MPLS or China Telecom SD-WAN: both paths are unaffected by the IPSec shutdown and offer companies a compliant site connection to China. MPLS remains the more expensive but established option, SD-WAN the faster to provision and more affordable alternative. How secure is your company’s connection to China at the moment?

Frank Frommknecht, Key Account Consultant bei SAVECALL

Written by

Frank Frommknecht

Key Account Consultant, SAVECALL

Has supported companies for over 20 years in selecting and optimizing their connectivity solutions. His focus: making complex telecommunications understandable from the customer’s perspective and strategically finding the right solution.

Why

Selection & operation of worldwide connectivity & cloud infrastructure. Without vendor risk & unnecessary costs.

Sources

Frequently asked questions about the IPSec shutdown in China

Why does China block IPSec VPN connections abroad?

China regulates cross-border internet traffic through the Great Firewall of China and requires international connections to run via authorized access providers. China’s Cybersecurity Law of 2017 explicitly prohibits self-set-up VPN lines and unauthorized cross-border connections for companies and individuals. The aim was to close the gray market of unofficial IPSec tunnels that had grown over the years, which many German companies also used to connect their China sites. In practice, all cross-border IPSec ports have since been gradually blocked.

Which ports and connections are specifically affected?

Chinese authorities block, among others, ports 80, 443 and 8080, as well as site-to-site IPSec VPN connections. IPSec technically uses ports 50, 51, 500 and 4500, without there being an official document that specifically names these ports. Only cross-border IPSec connections are affected, purely domestic Chinese IPSec connections remain untouched. For companies with international connectivity, this means a growing risk of sudden connection outages.

Are MPLS connections to China also affected by the shutdown?

No, carrier MPLS connections are subject to different regulation and are not affected by the IPSec shutdowns. Since MPLS connections are comparatively expensive, Chinese authorities do not fear they will be used as mass access to the unregulated internet. MPLS therefore remains a reliable, if cost-intensive, alternative. For many companies, however, a dedicated MPLS line to China is too expensive, which is why China Telecom offers a cheaper, equally regulated alternative via SD-WAN.

How does the China Telecom SD-WAN platform work?

The solution uses an existing local internet connection, to which a pre-configured China Telecom SD-WAN box is attached. Traffic runs via China Telecom’s business user backbone, which sits outside the Great Firewall and offers significantly better performance. Traffic is routed via SD-WAN POPs in Beijing, Shenzhen and Guangzhou into China Telecom’s low-latency DCI network and forwarded internationally via a gateway in Hong Kong, for example to be handed off in Frankfurt.

How long does it take to provision the SD-WAN solution to China?

According to SAVECALL, connections from 10 Mbit can be made operational within around 14 days. This is significantly faster than a classic MPLS line to China, which often requires several months of lead time. The short provisioning time results from the solution building on an existing local internet line rather than requiring a new physical connection. SAVECALL coordinates the implementation together with China Telecom.

What does an SD-WAN connection cost compared to an MPLS line to China?

Based on SAVECALL’s experience, a China Telecom SD-WAN connection is significantly cheaper than a dedicated MPLS line to China, which can quickly reach a five-figure monthly amount. Since the SD-WAN solution builds on existing internet lines, the high cost of a dedicated leased line is avoided. The exact price depends on bandwidth, location and contract term. SAVECALL compares both options neutrally and calculates which solution pays off for your company.

You might also be interested in

What drives you forward – & what drives

Book a free expert consultation