How to Exclude Specific IP Addresses from Zapret’s DPI-Bypass Interception

To exclude specific IP addresses from Zapret’s DPI-bypass interception, add CIDR-formatted ranges to lists/ipset-exclude-user.txt, run the "Update IPSet List" option in service.bat, and ensure the IPSet Filter is set to loaded before launching your strategy.

Zapret, an open-source DPI circumvention tool from the Flowseal/zapret-discord-youtube repository, intercepts traffic by matching destinations against the aggregated ipset-all.txt list. When you need to prevent the tool from inspecting connections to internal servers, VPN gateways, or specific trusted hosts, you can define exclusions that the winws.exe wrapper passes directly to the WinDivert driver.

Understanding Zapret’s IP Exclusion Architecture

Zapret filters traffic using IP sets. The engine loads ipset-all.txt to determine which connections require DPI-desync processing. However, the launch scripts support exclusion lists that remove specific CIDR blocks from this active set before the WinDivert driver begins packet inspection.

According to the source code in general.bat (lines 17-22), the startup command includes dual exclusion parameters:

--ipset-exclude="%LISTS%ipset-exclude.txt" --ipset-exclude="%LISTS%ipset-exclude-user.txt"

The winws.exe wrapper reads both files, combines their entries into a single exclusion set, and instructs the driver to ignore any packet whose destination IP matches an entry in that set.

Built-In vs. User-Defined Exclusion Mechanisms

Built-In Private Network Exclusions

The repository maintains a static list of private-network ranges in lists/ipset-exclude.txt. This file prevents obvious internal traffic—such as 192.168.0.0/16, 10.0.0.0/8, and 172.16.0.0/12—from being processed by the DPI-bypass engine. These exclusions are hardcoded in the repository and update only when the maintainer changes the upstream file.

User-Defined Custom Exclusions

For persistent, user-controlled exemptions, Zapret creates lists/ipset-exclude-user.txt automatically on the first run. This file accepts any CIDR notation (e.g., 203.0.113.113/32 or 198.51.100.0/24), with one entry per line. Because this file resides in the lists/ directory and is referenced by all general*.bat launch scripts, your custom exclusions persist across updates to ipset-all.txt.

Runtime Filter Controls in service.bat

The service.bat script (lines 112-118) provides an IPSet Filter menu that controls how exclusions are applied:

  • none: Disables the IP set filter entirely; all traffic is processed regardless of destination.
  • loaded: Applies exclusions only to IPs present in ipset-all.txt (recommended for most users).
  • any: Forces the DPI-bypass logic to evaluate all traffic, though exclusions are still respected.

Step-by-Step Guide to Excluding Specific IPs

Follow this procedure to exempt specific addresses from interception:

  1. Open the user exclusion file

    Navigate to the Zapret directory and open lists/ipset-exclude-user.txt in a text editor. If the file does not exist, run any general*.bat script once to trigger its automatic creation, or create it manually in the lists/ folder.

  2. Add CIDR-formatted IP ranges

    Enter one CIDR block per line. Use standard IPv4 notation with the subnet mask:

    # Custom exclusions - add one CIDR per line
    
    203.0.113.113/32
    198.51.100.0/24
    10.50.0.0/16
  3. Update the IP set list

    Run service.bat and select Update IPSet List. This command pulls the latest ipset-all.txt from the upstream repository and reapplies your exclusions against the refreshed list.

  4. Configure the IPSet Filter

    In the same service.bat menu, select IPSet Filter → loaded. This ensures that the exclusion lists are active and that only traffic destined for IPs in ipset-all.txt (minus your exclusions) is intercepted.

  5. Launch your strategy

    Execute your preferred strategy script, such as general (FAKE TLS AUTO).bat. Because these scripts already include the --ipset-exclude flags pointing to both exclusion files, your specified IPs will be omitted from DPI processing immediately.

Verifying Exclusion Configuration

To confirm that your exclusions are active, check the launch output of any general*.bat script. The command window should display the loaded exclusion files without errors. If winws.exe fails to parse ipset-exclude-user.txt, it typically logs an invalid CIDR format warning before exiting.

You can also test connectivity to your excluded IP using a packet capture tool; packets destined for excluded ranges will not trigger the desynchronization counters or tampering signatures characteristic of Zapret’s active filtering.

Summary

  • Exclusions are CIDR-based: Use lists/ipset-exclude-user.txt with one CIDR block per line to define IPs that bypass DPI inspection.
  • Two-tier exclusion system: Combine built-in private ranges (ipset-exclude.txt) with your custom list (ipset-exclude-user.txt) for comprehensive coverage.
  • Runtime activation required: Set the IPSet Filter to loaded in service.bat and run Update IPSet List to refresh the active IP database.
  • Automatic integration: All general*.bat scripts reference both exclusion files via --ipset-exclude parameters passed to winws.exe, requiring no manual editing of launch commands.

Frequently Asked Questions

What is the correct format for entries in ipset-exclude-user.txt?

Each line must contain a single CIDR notation, such as 192.168.100.0/24 for a subnet or 203.0.113.45/32 for a specific host. Do not include domain names, comments (except lines starting with #), or port numbers. Invalid formats will cause winws.exe to fail on startup with a parse error.

Does excluding an IP address block traffic to that destination?

No. Excluding an IP address prevents Zapret from applying DPI-desync techniques to that traffic. The connection proceeds normally without interception, tampering, or modification by the WinDivert driver. It does not function as a firewall rule; packets are allowed to pass through untouched rather than being dropped.

How do I temporarily disable all IP exclusions?

Open service.bat and navigate to the IPSet Filter menu. Select none to disable the filter entirely, which causes Zapret to process all traffic regardless of destination IP. Alternatively, you can empty the contents of lists/ipset-exclude-user.txt (keeping the file present) and restart your strategy.

Can I exclude domain names instead of IP addresses?

No. Zapret’s exclusion mechanism operates at the IP layer via the WinDivert driver and winws.exe. The --ipset-exclude parameter accepts only IP ranges and CIDR blocks. To exclude a domain, you must first resolve its IP addresses and add those specific IPs to lists/ipset-exclude-user.txt.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →