The very first connection your laptop makes is to a highly vetted, high-bandwidth server known as an Entry Guard.
- Exposure Isolation: This is the only node in the entire 4-hop chain that physically sees your vpn/socks address. The China (CN) Infrastructure Collapse:
If your vpn/socks address originates from an extreme surveillance zone
like China, connecting directly to an offshore guard relay will fail.
The Great Firewall (GFW) uses Deep Packet Inspection (DPI) to
immediately flag and drop the distinct Curve... TLS fingerprint. The Obfs4 Masking Layer (Hop 0):
To bypass local network blocks, you must activate an Obfs4 bridge layer
before Hop 1. This scrambles your data with randomized padding, making
it look like an ordinary, unblocked Clearnet video stream or HTTPS
session. Offshore Lockdown: Once the bridge pushes your
data through the firewall, your machine selects a guard relay located
exclusively within an independent Offshore Zone like offshore zone. Cryptographic Weld: Your host establishes a secure handshake using asymmetric encryption inside your machine. Legal Fortress:
Because the offshore jurisdiction has strict privacy laws, your
vpn/socks address is completely shielded from automated tracking by the bad eyes.
Hop 2: The Middle Relay (The Blind Spot)
Once the connection to the offshore Guard is welded, your machine extends the tunnel through a second server called the Middle Relay.
TheHop 3: The Exit Node (The Gateway)
Middle Relay is completely blind. Due to the layered encryption design,
its memory tables only know that it received encrypted traffic from
your offshore Guard, and that it must forward it to Hop 3. It has
absolutely no idea who you are, what your vpn/socks address is, or what
payload you are carrying.
The final hop in this client-side routing lifecycle is the Exit Node, which serves as the bridge connecting your encrypted tunnel to the public internet.
- The Public Face: When you scan a target or visit a forum, the destination server only sees the vpn/socks address of this Exit Node. Offshore Exit Enforcement:
Your configuration forces the selection of Exit Nodes located strictly
within non-bad eye neutral boundaries to prevent Western intelligence
agencies from monitoring your unencrypted exit traffic. - The Final Unwrapping: This node strips away the final layer of encryption and pushes the raw payload to the target destination.
Live Circuit Routing Analytics
Routing StageTechnical NameJurisdictional StatusVisibility & ExposureOrigin PointYour vpn/socks (CN IP)Local Machine NetworkCompletely blocked by DPI firewall unless Obfs4 obfuscation is active.Hop 1Entry GuardPure Offshore ZoneSees your masked vpn/socks address, but cannot see your target destination.Hop 2Middle RelayNeutral Global PoolCompletely blind; knows nothing about origin or destination.Hop 3Exit NodeOffshore / NeutralSees the Target Destination, but cannot see your vpn/socks address.