# How Zapret's Game Filter Mode Bypasses DPI for Games and UDP Applications

> Learn how Zapret's Game Filter mode bypasses DPI for games and UDP apps. Discover its WinDivert technique for intercepting traffic before the Windows network stack.

- Repository: [Flowseal/zapret-discord-youtube](https://github.com/Flowseal/zapret-discord-youtube)
- Tags: how-to-guide
- Published: 2026-05-02

---

**Zapret's Game Filter mode captures all TCP and UDP traffic on high-numbered ports (1024-65535) using WinDivert, forcing game traffic through a user-space filter that circumvents Deep Packet Inspection (DPI) by intercepting packets before the Windows networking stack processes them.**

The **Flowseal/zapret-discord-youtube** repository provides a Windows implementation of the zapret DPI bypass tool, featuring a specialized **Game Filter** configuration designed specifically for UDP-heavy gaming applications. This mode enables the `winws.exe` binary to intercept dynamic high-port connections that traditional DPI systems often fail to inspect, effectively creating a transparent tunnel for game traffic.

## What Is Game Filter Mode?

Game Filter is a traffic capture configuration managed through `service.bat` that directs the bypass engine to handle all connections on ephemeral ports. When activated, the script creates a persistence flag at `utils\game_filter.enabled` containing one of three values: `all`, `tcp`, or `udp`. These values determine whether the service intercepts both protocols or isolates a specific transport layer, with the configuration persisting across system restarts until explicitly disabled.

## How Game Filter Bypasses DPI

The bypass mechanism operates through three coordinated stages that redirect packets around network inspection points.

### Port Range Selection

The activation logic resides in `service.bat` within the *Game Switch* block (lines **71-83** and **91-119**). When a user selects Game Filter from the interactive menu, the script evaluates the choice and sets environment variables accordingly:

- **Mode `all`**: Sets `GameFilter=1024-65535` for both TCP and UDP
- **Mode `tcp`**: Sets `GameFilterTCP=1024-65535` for TCP only  
- **Mode `udp`**: Sets `GameFilterUDP=1024-65535` for UDP only

These variables are stored in `utils\game_filter.enabled` and parsed during service initialization to determine which port ranges WinDivert should capture.

### Argument Injection

During service installation (`service_install` section, lines **302-308**), `service.bat` performs placeholder substitution on the strategy file. The script replaces `%%GameFilter%%`, `%%GameFilterTCP%%`, and `%%GameFilterUDP%%` tokens with the numeric ranges defined in the previous stage. The resulting arguments are appended to the service creation command:

```bat
sc create zapret binPath= "\"%BIN_PATH%winws.exe\" !ARGS!" start= auto

```

This injection occurs at lines **49-52** of `service.bat`, ensuring the WinDivert driver captures the specified port ranges immediately upon service startup.

### WinDivert Packet Interception

The `winws.exe` binary utilizes the **WinDivert** driver to operate at the Windows filtering platform layer, intercepting raw packets before they reach the standard networking stack. By supplying the high-port range arguments (1024-65535), the tool captures all traffic on dynamic ports commonly used by online games. Because DPI implementations typically monitor standard ports (80, 443) and struggle with high-volume UDP streams, diverting these packets through user-space processing effectively removes them from the ISP's inspection path.

## Enabling Game Filter Mode

Activation requires running `service.bat` and navigating the interactive menu system defined at lines **94-98**, with the *game_switch* routine handling input at lines **443-473**.

1. Execute `service.bat` and select **4. Game Filter**
2. Choose the desired mode:
   - **0**: Disable Game Filter
   - **1**: Enable TCP and UDP (full coverage)
   - **2**: Enable TCP only
   - **3**: Enable UDP only (optimal for most games)
3. Confirm the selection to write the flag to `utils\game_filter.enabled`
4. Restart the Zapret service to apply the new port filters

## Technical Configuration Examples

Manual configuration follows the same variable substitution pattern used by the automated installer. Setting the full Game Filter mode requires defining the environment variables before service creation:

```bat
:: Enable full TCP and UDP filtering
set "GameFilter=1024-65535"
set "GameFilterTCP=1024-65535" 
set "GameFilterUDP=1024-65535"

:: Build argument string with placeholders replaced
set "ARGS=--port=%GameFilter% --tcp-port=%GameFilterTCP% --udp-port=%GameFilterUDP%"

:: Create and start the service
sc create zapret binPath= "\"%~dp0bin\winws.exe\" %ARGS%" start= auto
sc start zapret

```

The flag file contents correspond directly to menu selections:

```text
:: TCP and UDP mode
all

:: UDP only mode  
udp

:: TCP only mode
tcp

```

## Summary

- **Game Filter** redirects high-port traffic (1024-65535) through WinDivert by configuring `winws.exe` with dynamic port-range arguments injected via `service.bat`.
- The mode persists configurations in `utils\game_filter.enabled`, supporting three operational states: TCP only, UDP only, or both protocols simultaneously.
- Bypass occurs at the packet level: WinDivert intercepts raw traffic before Windows processes it, preventing DPI systems from analyzing game data flows.
- Most effective for UDP-based games that utilize dynamic high ports rather than standard HTTP/HTTPS channels.

## Frequently Asked Questions

### What port ranges does Game Filter mode affect?

Game Filter captures all traffic on ports **1024 through 65535**, covering the entire ephemeral port range used by modern multiplayer games and peer-to-peer applications. Standard service ports (0-1023) remain unaffected, ensuring system stability while gaming traffic receives DPI bypass treatment.

### Why is Game Filter more effective for games than standard bypass modes?

Traditional DPI concentrates inspection efforts on well-known ports like 80 and 443, while many games utilize dynamic high ports and UDP protocol for real-time communication. Game Filter specifically targets these overlooked traffic patterns by forcing **WinDivert** to intercept packets on the exact ports games actually use, creating a tunnel that circumvents shallow packet inspection techniques.

### How do I completely disable Game Filter after enabling it?

Navigate to `service.bat` and select **4. Game Filter**, then choose option **0** to disable. This removes the port range arguments from the service configuration during the next restart. Alternatively, delete the `utils\game_filter.enabled` flag file manually and restart the Zapret service to return to standard filtering behavior.

### Does Game Filter impact system performance or other applications?

Because Game Filter captures traffic across the entire high-port spectrum (1024-65535), it may intercept non-gaming applications that utilize these ports, such as voice chat software or torrent clients. The performance impact remains minimal due to WinDivert's kernel-level efficiency, but users may notice the bypass affecting traffic characteristics for any application using high-numbered ports while the mode is active.