CGNAT's Sticky IP and Türk Telekom's DPI: The Zapret Fix

A few days ago I needed to access a Cloudflare R2 bucket from home and the TLS handshake kept breaking with: 1 * ssl_handshake returned: (-0x7200) SSL - An invalid SSL record was received I walked through every workaround I could think of on my OpenWrt router, and most of what the internet recommends turned out to be useless. Here’s what happened and what the actual fix is. The setup Router: OpenWrt on a Raspberry Pi 5, PPPoE WAN on eth0.35 ISP: Türk Telekom WAN address from PPPoE: 100.112.3.164 Public IP from ipify: 78.190.232.58 Zapret installed and running in autohostlist mode The first thing that matters: 100.112.3.164 is not your public IP. It’s an address inside Türk Telekom’s carrier-grade NAT pool. When client-side attacks didn’t work, I checked this and realized most advice about “getting a new IP” doesn’t apply here. ...

August 14, 2026 · 4 min · 702 words · Okan Binli