# Recommended Zapret Strategies for General Internet Access: Complete Setup Guide

> Learn recommended Zapret strategies for general internet access. Use ALT.bat for broad access, then try FAKE TLS AUTO or other ALT variants for stubborn blocks. Complete setup guide.

- Repository: [Flowseal/zapret-discord-youtube](https://github.com/Flowseal/zapret-discord-youtube)
- Tags: how-to-guide
- Published: 2026-05-02

---

**Start with `general (ALT).bat` for the widest compatibility, then escalate to `general (FAKE TLS AUTO).bat` or iterate through ALT variants if specific sites remain blocked.**

The Flowseal/zapret-discord-youtube repository provides ready-to-run batch scripts that implement different **recommended Zapret strategies for general internet access** on Windows. These strategies launch the `winws.exe` traffic redirector with specific DPI-evasion arguments to bypass network restrictions and restore access to services like YouTube and Discord.

## Understanding Zapret Strategy Architecture

Zapret strategies are not monolithic applications but specialized **batch scripts** that invoke `winws.exe` with distinct `--dpi-desync` parameter sets. Intercepting packets via the **WinDivert** driver, these scripts rewrite DPI-sensitive fields—such as TLS client-hello or QUIC headers—according to their configured flags. All strategies share a common service infrastructure through `service.bat`, which handles Windows service installation, host list loading, and game filter toggles.

## Recommended Strategy Hierarchy

The repository organizes strategies by aggressiveness and specificity. Follow this hierarchy to find a working configuration for your network environment.

### General (ALT) — The Primary Strategy

**`general (ALT).bat`** is the recommended starting point for most users. According to the source code in `general (ALT).bat`, this strategy applies `--dpi-desync=fake` combined with a broad port filter (`--wf-tcp=80,443,2053,2083,2087,2096,8443`) and the standard host list from [`lists/list-general.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/lists/list-general.txt). It automatically respects the Game Filter and IPSet toggles managed by `service.bat`, making it the most balanced option for general browsing.

### General (FAKE TLS AUTO) — TLS Handshake Obfuscation

When DPI systems inspect TLS handshakes to identify blocked services, use **`general (FAKE TLS AUTO).bat`**. This strategy extends the ALT base by adding `--dpi-desync-fake-tls`, which masquerades the TLS client-hello packet. As implemented in the repository, this is particularly effective for Cloudflare-protected endpoints and strict corporate firewalls that analyze encrypted traffic patterns.

### General (SIMPLE FAKE) — Lightweight Testing

**`general (SIMPLE FAKE).bat`** provides a stripped-down configuration that enables generic fake DPI-desynchronization without extensive TCP/UDP port filtering. Use this on low-resource machines or when troubleshooting conflicts with other network software, as it minimizes the WinDivert filter complexity while still providing basic circumvention.

### ALT Variants (ALT2 through ALT11) — Fallback Iterations

The repository includes a family of **`general (ALT # X).bat`** scripts (ALT2, ALT3, up to ALT11). Each variant tweaks the ordering of ports and filter sets in the `--wf-tcp` and `--wf-udp` arguments. If your ISP updates their DPI signatures and the primary ALT strategy stops working, iterating through these alternatives often restores connectivity without requiring manual parameter tuning.

## How to Deploy Recommended Strategies

Follow this workflow to establish reliable general internet access:

1. **Enable Secure DNS** (DoH or DoT) in your browser or OS settings—this is required for Zapret to resolve correct IP addresses.
2. **Run `general (ALT).bat`** by double-clicking or executing from command line.
3. **If sites fail to load**, terminate the script (Ctrl+C) and test **`general (FAKE TLS AUTO).bat`**.
4. **If problems persist**, systematically try `general (ALT2).bat`, `general (ALT3).bat`, etc.
5. **Once you find a working strategy**, install it permanently using the service helper.

```bat
:: Test the primary recommended strategy
.\general (ALT).bat

:: Escalate to TLS obfuscation if sites remain blocked
.\general (FAKE TLS AUTO).bat

:: Install a working strategy as a persistent Windows service
.\service.bat Install Service

```

## Customizing Strategy Parameters

You can manually edit any strategy file to adjust port ranges or desync behavior. For example, to add port 8080 to the ALT strategy filter:

1. Open `general (ALT).bat` in a text editor.
2. Locate the `start` command containing `--wf-tcp` (typically lines 16-25).
3. Append your port to the comma-separated list:

```bat
--wf-tcp=80,443,2053,2083,2087,2096,8443,8080,%GameFilterTCP%

```

Save the file and rerun the script (or reinstall the service) to apply changes. The `%GameFilterTCP%` variable references additional ports loaded by `service.bat` when game filters are enabled.

## Key Files and Configuration Data

All recommended strategies consume data from the following repository locations:

- **[`lists/list-general.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/lists/list-general.txt)** — Primary host allow-list targeting blocked sites.
- **[`lists/list-exclude.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/lists/list-exclude.txt)** — Domains explicitly excluded from interception.
- **[`lists/ipset-all.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/lists/ipset-all.txt)** — IP ranges for DPI evasion.
- **`bin/`** — Contains binary payloads (QUIC/TLS templates) referenced by `--dpi-desync-fake-tls` arguments.
- **`service.bat`** — Central utility for `load_game_filter`, `load_user_lists`, and service lifecycle management (`Install Service`, `Remove Service`).

## Summary

- **Start with `general (ALT).bat`** as the baseline strategy for general internet access.
- **Escalate to `general (FAKE TLS AUTO).bat`** when facing TLS-inspecting DPI.
- **Iterate through ALT2-ALT11 variants** if ISP countermeasures block the primary strategies.
- **Use `service.bat Install Service`** to persist a working configuration across reboots.
- **Customize port filters** by editing the `--wf-tcp` arguments in each batch file.

## Frequently Asked Questions

### What is the difference between ALT and FAKE TLS AUTO strategies?

The **ALT** strategy uses `--dpi-desync=fake` to fragment and confuse generic deep packet inspection on standard web ports. **FAKE TLS AUTO** adds `--dpi-desync-fake-tls` to specifically masquerade the TLS client-hello handshake, defeating firewalls that analyze encrypted connection signatures. Use ALT for general browsing; escalate to FAKE TLS AUTO only when accessing HTTPS sites that remain blocked.

### Can I run multiple Zapret strategies simultaneously?

No. Each strategy launches `winws.exe` with its own WinDivert filter driver instance. Running multiple strategies creates conflicting packet interceptors that will break connectivity. Always stop the current script (Ctrl+C) or uninstall the existing service before testing an alternative strategy.

### Where are the blocked site lists configured for these strategies?

The strategies automatically read from the **`lists/`** directory, specifically [`list-general.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/list-general.txt) for target hosts and [`ipset-all.txt`](https://github.com/Flowseal/zapret-discord-youtube/blob/main/ipset-all.txt) for IP ranges. You can augment these files with custom domains, and Zapret will pick them up on the next run without reinstalling the service.

### Why does Secure DNS need to be enabled before running these strategies?

Zapret operates at the packet level using WinDivert to modify DPI-sensitive fields, but it does not handle DNS resolution. If your ISP returns blocked or redirected IP addresses for DNS queries, the traffic interception cannot reach the intended destination. Secure DNS (DNS-over-HTTPS or DNS-over-TLS) ensures you receive genuine IP addresses, allowing Zapret's packet manipulation to function correctly.