# Zapret Strategy Variants: Differences Between General, FAKE, and ALT

> Uncover Zapret strategy variants. Learn the key differences between General, FAKE, and ALT strategies and how each bypasses DPI filters using unique methods and payloads.

- Repository: [Flowseal/zapret-discord-youtube](https://github.com/Flowseal/zapret-discord-youtube)
- Tags: deep-dive
- Published: 2026-05-02

---

**Both FAKE and ALT Zapret strategies launch `winws.exe` with DPI-desynchronisation options, but FAKE relies on high-repeat classic fake-TLS payloads while ALT introduces fake-split segmentation, diversified binary files, and extended protocol coverage to evade advanced DPI filters.**

The **Flowseal/zapret-discord-youtube** repository provides Windows Batch wrappers that configure the `winws.exe` engine to circumvent Deep Packet Inspection (DPI) blocking. Understanding the **differences between Zapret strategy variants**—General, FAKE, and ALT—is essential for selecting the optimal obfuscation pattern for your specific network restrictions.

## Shared Foundation Across All Variants

All strategy variants execute from the same initialization logic defined in `service.bat` and share common networking parameters. They target identical TCP and UDP port whitelists (`--wf-tcp=80,443,2053,2083,2087,2096,8443…`) and reference the same binary payloads stored in the `bin/` directory. Both variants load IP-set filters from [`lists/ipset-all.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/lists/ipset-all.txt) and apply Windows Filtering Platform (WFP) rules through `winws.exe` to intercept traffic before it reaches the ISP's inspection points.

## General FAKE Strategy: Classic Desynchronisation

The **FAKE** variant focuses on straightforward fake-TLS injection with minimal pattern variation and high repetition rates.

### High-Repeat Fake Mode

In `general (FAKE TLS AUTO).bat`, the primary desync method uses `--dpi-desync=fake` with `--dpi-desync-repeats=11`. This elevated repeat count sends nearly double the fake packets compared to ALT variants, overwhelming simpler DPI state tracking mechanisms that rely on session continuity checks.

### TLS Payload Configuration

The strategy loads `tls_clienthello_max_ru.bin` for HTTP fake payloads and passes a dummy TLS value (`0x00000000`) combined with override flags (`^!`). It primarily targets QUIC traffic using `--dpi-desync-fake-quic` with Google-specific binaries, applying multidisorder modes only to select TCP rules rather than the entire rule set.

```bat
start "zapret: %~n0" /min "%BIN%winws.exe" ^
  --wf-tcp=80,443,2053,2083,2087,2096,8443,%GameFilterTCP% ^
  --wf-udp=443,19294-19344,50000-50100,%GameFilterUDP% ^
  --filter-udp=443 ^
  --hostlist="%LISTS%list-general.txt" ^
  --dpi-desync=fake ^
  --dpi-desync-repeats=11 ^
  --dpi-desync-fake-quic="%BIN%quic_initial_www_google_com.bin" ^
  --dpi-desync-fake-tls=0x00000000 --dpi-desync-fake-tls=^! ^
  --dpi-desync-fake-tls-mod=rnd,dupsid,sni=www.google.com ^
  --dpi-desync-fake-http="%BIN%tls_clienthello_max_ru.bin"

```

## General ALT Strategy: Advanced Obfuscation

The **ALT** variant introduces **fake-split** technology and payload diversification to counter DPI systems that recognize and filter single-pattern fake handshakes.

### Dual-Mode Desynchronisation

`general (ALT).bat` replaces the single fake mode with `--dpi-desync=fake,fakedsplit` and reduces repeats to `--dpi-desync-repeats=6`. It adds `--dpi-desync-fakedsplit-pattern=0x00` to split packet streams at null-byte boundaries, disrupting signature matching that expects continuous TLS handshakes across the full session duration.

### Diversified Binary Payloads

Instead of relying on a single TLS binary, ALT alternates between `tls_clienthello_www_google_com.bin`, `stun.bin`, and `tls_clienthello_max_ru.bin` across different rule blocks. This payload rotation prevents DPI filters from blacklisting a specific fake signature after observing it repeatedly, distributing the obfuscation footprint across multiple recognizable patterns.

### Extended Protocol Coverage

Beyond standard QUIC fakes, ALT enables `--dpi-desync-fake-discord`, `--dpi-desync-fake-stun`, and `--dpi-desync-fake-unknown-udp` for application-specific UDP checks. It applies `--dpi-desync-any-protocol=1` on final game-filter rules, expanding the interception scope beyond predefined Layer-7 filters to catch proprietary gaming protocols.

```bat
start "zapret: %~n0" /min "%BIN%winws.exe" ^
  --wf-tcp=80,443,2053,2083,2087,2096,8443,%GameFilterTCP% ^
  --wf-udp=443,19294-19344,50000-50100,%GameFilterUDP% ^
  --filter-udp=443 ^
  --hostlist="%LISTS%list-general.txt" ^
  --dpi-desync=fake,fakedsplit ^
  --dpi-desync-repeats=6 ^
  --dpi-desync-fakedsplit-pattern=0x00 ^
  --dpi-desync-fake-tls="%BIN%stun.bin" ^
  --dpi-desync-fake-tls="%BIN%tls_clienthello_www_google_com.bin" ^
  --dpi-desync-fake-http="%BIN%tls_clienthello_max_ru.bin"

```

## Key Technical Differences

| Feature | General FAKE | General ALT |
|---------|--------------|-------------|
| **Primary desync mode** | `--dpi-desync=fake` | `--dpi-desync=fake,fakedsplit` |
| **Repeat count** | 11 cycles | 6 cycles |
| **Fake-split pattern** | Not implemented | `0x00` byte pattern |
| **TLS binaries** | `tls_clienthello_max_ru.bin` (primary) | Multiple: `stun.bin`, `tls_clienthello_www_google_com.bin`, `tls_clienthello_max_ru.bin` |
| **UDP protocols** | QUIC only | QUIC, Discord, STUN, unknown-UDP |
| **Multidisorder** | Limited TCP rules | Extensive across rule set |

## Summary

- **General FAKE** provides a simpler, high-repetition fake-TLS approach suitable for networks with basic DPI implementation that relies on volume-based evasion.
- **General ALT** offers sophisticated **fake-split** segmentation and payload rotation, making it more resilient against adaptive DPI filters that blacklist single-pattern obfuscation.
- Both variants execute `winws.exe` from the shared `bin/` directory and respect the whitelist definitions established in `service.bat`.
- The **ALT** variant trades higher configuration complexity for broader protocol support and lower network overhead through reduced repeat counts.

## Frequently Asked Questions

### Which Zapret strategy variant should I use for Discord?

The **ALT** variant typically outperforms FAKE for Discord traffic because it includes `--dpi-desync-fake-discord` and `--dpi-desync-fake-stun` parameters specifically targeting Discord's voice (UDP) and chat infrastructure. The fake-split segmentation also better handles Discord's aggressive connection pinning that basic fake-TLS repetition struggles to circumvent.

### What is the fake-split pattern in the ALT variant?

The `--dpi-desync-fakedsplit-pattern=0x00` setting instructs `winws.exe` to segment packet streams at null-byte boundaries, creating discontinuities in the data flow. This fragmentation forces DPI systems to reassemble packets before inspection, often exceeding their state table limits or buffering timeouts, which causes them to allow the traffic through uninspected.

### Why does the FAKE strategy use more repeats than ALT?

**FAKE** compensates for its singular desync method by overwhelming DPI state tables with repetition (`--dpi-desync-repeats=11`). The **ALT** variant achieves equivalent reliability through technique diversity rather than volume, using fewer repeats (`--dpi-desync-repeats=6`) to minimize packet overhead while maintaining effectiveness through complementary fakedsplit diversification.

### Can I combine FAKE and ALT strategy settings?

Yes, advanced users can create hybrid configurations by borrowing parameters from both `general (FAKE TLS AUTO).bat` and `general (ALT).bat`. Avoid applying conflicting `--dpi-desync` modes to identical hostlist matches; instead, combine ALT's fakedsplit patterns with FAKE's specific TLS binaries on separate filter rules to create layered obfuscation without command-line collisions.