Since October 2017,it seems that the GFW deployed a new policy that it analyzed the name of certification from the ACK of server.
If it contained like google.com ,then sent RST to server and dropped all packages from the client to that IP address.
Someone said that it needed to wait for tls1.3 online that encrypted the certification name.
So,does this tool still work?