Zapret Game Filter and IPSet Filter Conflicts: Avoiding Double Routing in Flowseal/zapret-discord-youtube

Enabling both the Game Filter and IPSet Filter simultaneously in Flowseal/zapret-discord-youtube causes traffic to be processed twice by winws.exe, leading to over-blocking, protocol mismatches, and hard-to-diagnose connection drops.

The Flowseal/zapret-discord-youtube repository provides two independent traffic filtering mechanisms for DPI bypass. While the Game Filter routes connections by port range and the IPSet Filter routes by IP address, running both together creates overlapping filter criteria that break Discord voice, game connections, and other services.

How the Filters Work

Game Filter Mechanics

The Game Filter routes all TCP and UDP traffic on ports 1024-65535 (the default range above 1023) through the Zapret bypass (winws.exe). This is handled in service.bat within the :game_switch_status and :game_switch functions, with the menu displaying current states on lines 74-76. This filter is designed for games and services that utilize dynamic high-port numbers.

IPSet Filter Mechanics

The IPSet Filter loads a list of IP addresses and subnets from lists/ipset-all.txt, forcing every connection whose remote IP matches the list to be processed by Zapret regardless of destination port. The filter operates in three states: none, loaded, or any, as shown in the status display on lines 75-76 of service.bat.

Four Critical Conflicts When Combining Filters

1. Over-Blocking of Traffic

The Game Filter already forces all high-port traffic through Zapret. When the IPSet Filter is simultaneously active, it adds a second condition: any remote IP matching lists/ipset-all.txt is forced through the bypass regardless of port. If the IP set contains addresses belonging to services that should bypass Zapret—such as Discord's voice servers or certain CDN endpoints—those connections are intercepted twice, breaking the service entirely.

2. Port-Mask Mismatch

Game Filter operates by port range (1024-65535), while IPSet Filter operates strictly by IP address. Services like Discord voice use a mix of low- and high-port connections. Forcing them through both filters causes protocol-specific DPI-desync options to be applied twice, resulting in malformed packets and connection drops.

3. Inconsistent Strategy Arguments

Strategy scripts such as general.bat embed Game Filter values into the --wf-tcp and --wf-udp arguments (see line 16). When IPSet is simultaneously active, the same --filter-tcp and --filter-udp arguments are passed a second time, effectively stacking the filters. Some strategies expect a single filter and may ignore or misinterpret the second set, causing unexpected routing behavior.

4. Diagnostic False-Positives

The built-in diagnostics in service.bat (accessed via :service_diagnostics) only checks for service-level conflicts, not filter overlap. When both filters are enabled, the diagnostics may report a clean system status while actual traffic is being double-filtered, masking the root cause of connectivity issues.

Official Recommendation from the README

According to the repository documentation, the safe configuration requires mutual exclusivity. The README.md explicitly warns: "Make sure that in service.bat the Game Filter is disabled and the IPSet Filter is none. Otherwise this may affect the availability of resources you did not expect." This guidance appears in lines 59-66 of the README.

How to Configure Filters via service.bat

Use the interactive menu in service.bat to toggle these settings safely.

Disable both filters to rule out routing conflicts:

service.bat
:: Choose menu option 4 → 0 (disable Game Filter)
:: Choose menu option 5 → 0 (set IPSet to none)

Enable only Game Filter for games using dynamic high ports:

service.bat
:: 4 → 1 (all)
:: 5 → 0 (IPSet none)

Enable only IPSet Filter for Discord/YouTube specific fixes:

service.bat
:: 4 → 0 (Game Filter disabled)
:: 5 → 2 (IPSet loaded)
:: Edit lists/ipset-all.txt to customize IP ranges

Key Source Files

Understanding these files helps diagnose conflicts:

  • service.bat: Central UI for toggling Game Filter and IPSet Filter, plus status display (lines 74-76).
  • general.bat: Strategy script that embeds filter values into WinDivert arguments (line 16).
  • lists/ipset-all.txt: IP definitions consulted when IPSet Filter is active.
  • README.md: Contains the canonical warning about filter mutual exclusivity (lines 59-66).

Summary

  • Game Filter (port 1024-65535) and IPSet Filter (IP list matching) serve different routing purposes but conflict when used simultaneously.
  • Double-filtering causes over-blocking, port-mask mismatches, and malformed packets that break Discord voice and game connections.
  • Strategy scripts in general*.bat stack --wf-tcp and --filter-tcp arguments unpredictably when both filters are active.
  • The service.bat diagnostics do not detect filter overlap, creating false-positives during troubleshooting.
  • Keep filters mutually exclusive: disable Game Filter when using IPSet Filter, and vice versa.

Frequently Asked Questions

Can I use Game Filter and IPSet Filter together?

No. The Flowseal/zapret-discord-youtube source code is not designed for simultaneous use. Both filters force traffic through winws.exe using different criteria (ports versus IPs), resulting in double-processing that breaks connectivity for services like Discord voice and certain game servers.

What ports does the Game Filter affect?

By default, the Game Filter routes all TCP and UDP traffic on ports 1024 through 65535 (all ports greater than 1023). This is defined in the filter logic within service.bat and passed to winws.exe via the --wf-tcp and --wf-udp arguments in strategy scripts like general.bat.

Why does Discord voice break when both filters are enabled?

Discord voice servers use specific IP addresses that may appear in lists/ipset-all.txt, while also utilizing high-port UDP connections. With both filters active, these packets get processed twice by different DPI-desync strategies, causing malformed headers and connection drops due to the port-mask mismatch between the two filtering mechanisms.

How do I check which filter is currently active?

Run service.bat and observe the status display. The Game Filter status appears on lines 74-76, showing whether it is disabled or set to "all" (TCP+UDP). The IPSet Filter status appears immediately after, indicating none, loaded, or any state. However, note that service.bat does not detect conflicts between the two filters—diagnostics only check for service installation issues.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →