VPS IP Blocked in Mainland China or by a Third Party? How to Test It and JUSTG IP Policy
If your VPS IP address suddenly becomes unreachable from mainland China, or a third party such as a country-level firewall, an email blocklist or another network starts blocking it, you need to find out what is really happening before taking action. This guide explains JUSTG's IP policy for blocked addresses, shows how to test whether an IP is reachable with ping, tcping and mtr from different networks, what options you have if the IP is blocked, and how to prevent it. The commands work on Debian/Ubuntu, CentOS/Rocky/AlmaLinux and Windows.
JUSTG IP policy for blocked addresses
- Every JUSTG cloud server is delivered with a new, clean IPv4 address.
- If an IP is blocked by mainland China, a third-party country or a third-party firewall because of how the customer used it, JUSTG does not replace the IPv4 address for free. Such blocks cause lasting damage to our IP ranges.
- You can order one more IPv4 address at any time through the upgrade options of your VPS in the client area.
- All cloud servers include free IPv6, which you can keep using for SSH, RDP or other management access.
Step 1: Make sure the server itself is running
A blocked IP and a crashed service look the same from the outside. Log in over IPv6 (replace with your own address) and check that the system and your services are up:
ssh -6 root@2001:db8::10
uptime
ss -tlnp
ss -tlnp lists listening TCP ports. If your web server or application is not listed, the problem is the service, not the IP.
Step 2: Check your own firewall
A firewall rule added by mistake is a common cause. Review it before assuming a block:
# Debian / Ubuntu
ufw status verbose
# CentOS / Rocky / AlmaLinux
firewall-cmd --list-all
On Windows Server, run Get-NetFirewallRule -Enabled True -Direction Inbound in PowerShell.
Step 3: Test reachability from different networks
Run the same tests from at least two places: a network in the region that reports the problem (for example mainland China) and a network elsewhere (for example Europe, or another JUSTG server). Use the IP address of your VPS (here 203.0.113.30):
# ICMP
ping -c 20 203.0.113.30
# TCP port test (Linux)
nc -zv -w 5 203.0.113.30 22
# TCP path test with mtr (Linux, as root)
mtr -T -P 443 -rwc 30 203.0.113.30
On Windows, use ping -n 20 203.0.113.30, Test-NetConnection 203.0.113.30 -Port 443 in PowerShell, or the third-party tool tcping.
Step 4: Interpret the results
| What you see | Likely cause |
|---|---|
| Fails from every network, IPv6 also fails | Server, network configuration or firewall problem; open a ticket |
| Fails from every network over IPv4, IPv6 works | IPv4 configuration or firewall problem on the server |
| Works from abroad, fails only from one country or network, mtr stops at that network's border | The IP is blocked or filtered by that network |
| Ping fails but TCP ports respond | ICMP is filtered somewhere; the service is reachable |
For email delivery problems, also look up the IP on the public blocklists that the receiving mail server reports in its bounce message.
Step 5: Choose a solution if the IP is blocked
If the block was caused by the use of the server, you can:
- Log in to the client area → My Products & Services → select the VPS → open the upgrade options and order an additional IPv4 address. If you cannot find the option, submit a ticket.
- Bind the new IP inside the operating system and move your services and DNS records to it.
- Keep using the free IPv6 address for SSH or RDP management in the meantime.
Step 6: Prevent future blocks
- Do not use the server for spam, port scanning, attacks or content that violates the law or the terms of service.
- Keep the operating system, control panels and applications patched, so that the server cannot be hijacked for abuse.
- Use SSH keys or strong passwords and a tool such as fail2ban to stop brute-force attempts.
- Watch outbound traffic with
iftoporvnstatand investigate unexpected spikes.
FAQ
Will JUSTG replace my blocked IP for free?
No. When the block is caused by the customer's own use, the IPv4 address is not changed free of charge. You can buy an additional IPv4 through the upgrade options and use the free IPv6 for management.
How can I still log in to a VPS whose IPv4 is blocked?
Connect over IPv6, for example ssh -6 root@2001:db8::10, from a network that supports IPv6.
What if I believe the block is not caused by my usage?
Collect the ping, tcping and mtr results from Step 3 and send them in a ticket, so our team can review the case.
If you still have problems after following this guide, submit a ticket and the JUSTG technical support team will help you.