Subject: Intermittent connection failures on www.tzxstar.cn — one anycast IP (216.198.79.65) resets TLS (SNI), plus intermittent connection refused windows We operate a production site www.tzxstar.cn on Vercel. Since 2026-09-21 ~23:45 (UTC+8) we have observed two persistent edge-level issues from networks in mainland China (multiple ISPs tested; our local network is healthy — vercel.com and other sites respond 200 throughout): One anycast IP resets TLS handshakes. www.tzxstar.cn rotates between 64.29.17.65 and 216.198.79.65. Connections to 64.29.17.65 succeed (HTTP 200). Connections to 216.198.79.65 are reset during the TLS handshake (SNI-based reset, curl exits with code 35 / "Connection reset by peer"), consistently across 2026-09-23 22:2x to 2026-09-24 08:0x (UTC+8). Intermittent connection-refused windows on the healthy IP. Example windows (all UTC+8): 2026-09-23 22:26–23:00 — 17 consecutive probes failed (curl exit 000); 2026-09-24 07:28 — recovery flicker (000 then 200×3); 2026-09-24 09:48 — 1 of 5 probes to a static asset (/scene-assets/observe_mosquito_v2.png) failed. During these windows vercel.com remains reachable from the same machine, so this is not client-side. Additionally, our apex domain tzxstar.cn (resolved to 8.148.71.94, a pre-routing layer) has been refusing connections throughout the same period; previously it 301-redirected to www. We would like to confirm whether any edge configuration change on Vercel's side could be related. Impact: end users in mainland China intermittently fail to load pages or static assets; failed asset loads degrade the user experience (we have since added client-side retry as mitigation). Requests: Investigate the TLS/SNI reset behavior on edge IP 216.198.79.65. Reconcile the intermittent connection-refused windows against any edge configuration deployments or incidents on your side between 2026-09-21 and 2026-09-24 (UTC+8). Advise on the expected behavior for apex-domain redirect handling during such windows. We can provide full probe logs (timestamps, curl exit codes, per-IP results) on request.