# How to Exclude Specific IP Addresses from Zapret’s DPI-Bypass Interception

> Learn how to exclude specific IP addresses from Zapret's DPI bypass interception. Easily add CIDR ranges to your exclude list and update Zapret's IPSet for seamless network control.

- Repository: [Flowseal/zapret-discord-youtube](https://github.com/Flowseal/zapret-discord-youtube)
- Tags: how-to-guide
- Published: 2026-05-02

---

**To exclude specific IP addresses from Zapret’s DPI-bypass interception, add CIDR-formatted ranges to [`lists/ipset-exclude-user.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/lists/ipset-exclude-user.txt), run the "Update IPSet List" option in `service.bat`, and ensure the IPSet Filter is set to `loaded` before launching your strategy.**

Zapret, an open-source DPI circumvention tool from the Flowseal/zapret-discord-youtube repository, intercepts traffic by matching destinations against the aggregated [`ipset-all.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/ipset-all.txt) list. When you need to prevent the tool from inspecting connections to internal servers, VPN gateways, or specific trusted hosts, you can define exclusions that the `winws.exe` wrapper passes directly to the WinDivert driver.

## Understanding Zapret’s IP Exclusion Architecture

Zapret filters traffic using **IP sets**. The engine loads [`ipset-all.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/ipset-all.txt) to determine which connections require DPI-desync processing. However, the launch scripts support exclusion lists that remove specific CIDR blocks from this active set before the WinDivert driver begins packet inspection.

According to the source code in `general.bat` (lines 17-22), the startup command includes dual exclusion parameters:

```bat
--ipset-exclude="%LISTS%ipset-exclude.txt" --ipset-exclude="%LISTS%ipset-exclude-user.txt"

```

The `winws.exe` wrapper reads both files, combines their entries into a single exclusion set, and instructs the driver to ignore any packet whose destination IP matches an entry in that set.

## Built-In vs. User-Defined Exclusion Mechanisms

### Built-In Private Network Exclusions

The repository maintains a static list of private-network ranges in **[`lists/ipset-exclude.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/lists/ipset-exclude.txt)**. This file prevents obvious internal traffic—such as `192.168.0.0/16`, `10.0.0.0/8`, and `172.16.0.0/12`—from being processed by the DPI-bypass engine. These exclusions are hardcoded in the repository and update only when the maintainer changes the upstream file.

### User-Defined Custom Exclusions

For persistent, user-controlled exemptions, Zapret creates **[`lists/ipset-exclude-user.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/lists/ipset-exclude-user.txt)** automatically on the first run. This file accepts any CIDR notation (e.g., `203.0.113.113/32` or `198.51.100.0/24`), with one entry per line. Because this file resides in the `lists/` directory and is referenced by all `general*.bat` launch scripts, your custom exclusions persist across updates to [`ipset-all.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/ipset-all.txt).

### Runtime Filter Controls in service.bat

The **`service.bat`** script (lines 112-118) provides an **IPSet Filter** menu that controls how exclusions are applied:

- **none**: Disables the IP set filter entirely; all traffic is processed regardless of destination.
- **loaded**: Applies exclusions only to IPs present in [`ipset-all.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/ipset-all.txt) (recommended for most users).
- **any**: Forces the DPI-bypass logic to evaluate all traffic, though exclusions are still respected.

## Step-by-Step Guide to Excluding Specific IPs

Follow this procedure to exempt specific addresses from interception:

1. **Open the user exclusion file**

   Navigate to the Zapret directory and open [`lists/ipset-exclude-user.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/lists/ipset-exclude-user.txt) in a text editor. If the file does not exist, run any `general*.bat` script once to trigger its automatic creation, or create it manually in the `lists/` folder.

2. **Add CIDR-formatted IP ranges**

   Enter one CIDR block per line. Use standard IPv4 notation with the subnet mask:

   ```text
   # Custom exclusions - add one CIDR per line

   203.0.113.113/32
   198.51.100.0/24
   10.50.0.0/16
   ```

3. **Update the IP set list**

   Run `service.bat` and select **`Update IPSet List`**. This command pulls the latest [`ipset-all.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/ipset-all.txt) from the upstream repository and reapplies your exclusions against the refreshed list.

4. **Configure the IPSet Filter**

   In the same `service.bat` menu, select **`IPSet Filter`** → **`loaded`**. This ensures that the exclusion lists are active and that only traffic destined for IPs in [`ipset-all.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/ipset-all.txt) (minus your exclusions) is intercepted.

5. **Launch your strategy**

   Execute your preferred strategy script, such as `general (FAKE TLS AUTO).bat`. Because these scripts already include the `--ipset-exclude` flags pointing to both exclusion files, your specified IPs will be omitted from DPI processing immediately.

## Verifying Exclusion Configuration

To confirm that your exclusions are active, check the launch output of any `general*.bat` script. The command window should display the loaded exclusion files without errors. If `winws.exe` fails to parse [`ipset-exclude-user.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/ipset-exclude-user.txt), it typically logs an invalid CIDR format warning before exiting.

You can also test connectivity to your excluded IP using a packet capture tool; packets destined for excluded ranges will not trigger the desynchronization counters or tampering signatures characteristic of Zapret’s active filtering.

## Summary

- **Exclusions are CIDR-based**: Use [`lists/ipset-exclude-user.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/lists/ipset-exclude-user.txt) with one CIDR block per line to define IPs that bypass DPI inspection.
- **Two-tier exclusion system**: Combine built-in private ranges ([`ipset-exclude.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/ipset-exclude.txt)) with your custom list ([`ipset-exclude-user.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/ipset-exclude-user.txt)) for comprehensive coverage.
- **Runtime activation required**: Set the IPSet Filter to `loaded` in `service.bat` and run `Update IPSet List` to refresh the active IP database.
- **Automatic integration**: All `general*.bat` scripts reference both exclusion files via `--ipset-exclude` parameters passed to `winws.exe`, requiring no manual editing of launch commands.

## Frequently Asked Questions

### What is the correct format for entries in ipset-exclude-user.txt?

Each line must contain a single CIDR notation, such as `192.168.100.0/24` for a subnet or `203.0.113.45/32` for a specific host. Do not include domain names, comments (except lines starting with `#`), or port numbers. Invalid formats will cause `winws.exe` to fail on startup with a parse error.

### Does excluding an IP address block traffic to that destination?

No. Excluding an IP address prevents Zapret from applying DPI-desync techniques to that traffic. The connection proceeds normally without interception, tampering, or modification by the WinDivert driver. It does not function as a firewall rule; packets are allowed to pass through untouched rather than being dropped.

### How do I temporarily disable all IP exclusions?

Open `service.bat` and navigate to the **IPSet Filter** menu. Select **`none`** to disable the filter entirely, which causes Zapret to process all traffic regardless of destination IP. Alternatively, you can empty the contents of [`lists/ipset-exclude-user.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/lists/ipset-exclude-user.txt) (keeping the file present) and restart your strategy.

### Can I exclude domain names instead of IP addresses?

No. Zapret’s exclusion mechanism operates at the IP layer via the WinDivert driver and `winws.exe`. The `--ipset-exclude` parameter accepts only IP ranges and CIDR blocks. To exclude a domain, you must first resolve its IP addresses and add those specific IPs to [`lists/ipset-exclude-user.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/lists/ipset-exclude-user.txt).