Earlier quoted context omitted.
They drop all encrypted connections. This means no https, no IMAP over TLS and no SSH connections. (Im in Iran)
How do they distinguish an encrypted connection from a non-encrypted connection? How do they know those indecipherable bits are an encrypted message vs. a part of an image or video? I suspect they just block domains and IPs and common ports or they sniff for common handshakes and key exchanges and kill those.
They also shape the bandwidth of encrypted connections. My guess is that they use something like L7 to guess the type-of-connection using different patterns.