Recommended Zapret Strategies for General Internet Access: Complete Setup Guide
Start with general (ALT).bat for the widest compatibility, then escalate to general (FAKE TLS AUTO).bat or iterate through ALT variants if specific sites remain blocked.
The Flowseal/zapret-discord-youtube repository provides ready-to-run batch scripts that implement different recommended Zapret strategies for general internet access on Windows. These strategies launch the winws.exe traffic redirector with specific DPI-evasion arguments to bypass network restrictions and restore access to services like YouTube and Discord.
Understanding Zapret Strategy Architecture
Zapret strategies are not monolithic applications but specialized batch scripts that invoke winws.exe with distinct --dpi-desync parameter sets. Intercepting packets via the WinDivert driver, these scripts rewrite DPI-sensitive fields—such as TLS client-hello or QUIC headers—according to their configured flags. All strategies share a common service infrastructure through service.bat, which handles Windows service installation, host list loading, and game filter toggles.
Recommended Strategy Hierarchy
The repository organizes strategies by aggressiveness and specificity. Follow this hierarchy to find a working configuration for your network environment.
General (ALT) — The Primary Strategy
general (ALT).bat is the recommended starting point for most users. According to the source code in general (ALT).bat, this strategy applies --dpi-desync=fake combined with a broad port filter (--wf-tcp=80,443,2053,2083,2087,2096,8443) and the standard host list from lists/list-general.txt. It automatically respects the Game Filter and IPSet toggles managed by service.bat, making it the most balanced option for general browsing.
General (FAKE TLS AUTO) — TLS Handshake Obfuscation
When DPI systems inspect TLS handshakes to identify blocked services, use general (FAKE TLS AUTO).bat. This strategy extends the ALT base by adding --dpi-desync-fake-tls, which masquerades the TLS client-hello packet. As implemented in the repository, this is particularly effective for Cloudflare-protected endpoints and strict corporate firewalls that analyze encrypted traffic patterns.
General (SIMPLE FAKE) — Lightweight Testing
general (SIMPLE FAKE).bat provides a stripped-down configuration that enables generic fake DPI-desynchronization without extensive TCP/UDP port filtering. Use this on low-resource machines or when troubleshooting conflicts with other network software, as it minimizes the WinDivert filter complexity while still providing basic circumvention.
ALT Variants (ALT2 through ALT11) — Fallback Iterations
The repository includes a family of general (ALT # X).bat scripts (ALT2, ALT3, up to ALT11). Each variant tweaks the ordering of ports and filter sets in the --wf-tcp and --wf-udp arguments. If your ISP updates their DPI signatures and the primary ALT strategy stops working, iterating through these alternatives often restores connectivity without requiring manual parameter tuning.
How to Deploy Recommended Strategies
Follow this workflow to establish reliable general internet access:
- Enable Secure DNS (DoH or DoT) in your browser or OS settings—this is required for Zapret to resolve correct IP addresses.
- Run
general (ALT).batby double-clicking or executing from command line. - If sites fail to load, terminate the script (Ctrl+C) and test
general (FAKE TLS AUTO).bat. - If problems persist, systematically try
general (ALT2).bat,general (ALT3).bat, etc. - Once you find a working strategy, install it permanently using the service helper.
:: Test the primary recommended strategy
.\general (ALT).bat
:: Escalate to TLS obfuscation if sites remain blocked
.\general (FAKE TLS AUTO).bat
:: Install a working strategy as a persistent Windows service
.\service.bat Install Service
Customizing Strategy Parameters
You can manually edit any strategy file to adjust port ranges or desync behavior. For example, to add port 8080 to the ALT strategy filter:
- Open
general (ALT).batin a text editor. - Locate the
startcommand containing--wf-tcp(typically lines 16-25). - Append your port to the comma-separated list:
--wf-tcp=80,443,2053,2083,2087,2096,8443,8080,%GameFilterTCP%
Save the file and rerun the script (or reinstall the service) to apply changes. The %GameFilterTCP% variable references additional ports loaded by service.bat when game filters are enabled.
Key Files and Configuration Data
All recommended strategies consume data from the following repository locations:
lists/list-general.txt— Primary host allow-list targeting blocked sites.lists/list-exclude.txt— Domains explicitly excluded from interception.lists/ipset-all.txt— IP ranges for DPI evasion.bin/— Contains binary payloads (QUIC/TLS templates) referenced by--dpi-desync-fake-tlsarguments.service.bat— Central utility forload_game_filter,load_user_lists, and service lifecycle management (Install Service,Remove Service).
Summary
- Start with
general (ALT).batas the baseline strategy for general internet access. - Escalate to
general (FAKE TLS AUTO).batwhen facing TLS-inspecting DPI. - Iterate through ALT2-ALT11 variants if ISP countermeasures block the primary strategies.
- Use
service.bat Install Serviceto persist a working configuration across reboots. - Customize port filters by editing the
--wf-tcparguments in each batch file.
Frequently Asked Questions
What is the difference between ALT and FAKE TLS AUTO strategies?
The ALT strategy uses --dpi-desync=fake to fragment and confuse generic deep packet inspection on standard web ports. FAKE TLS AUTO adds --dpi-desync-fake-tls to specifically masquerade the TLS client-hello handshake, defeating firewalls that analyze encrypted connection signatures. Use ALT for general browsing; escalate to FAKE TLS AUTO only when accessing HTTPS sites that remain blocked.
Can I run multiple Zapret strategies simultaneously?
No. Each strategy launches winws.exe with its own WinDivert filter driver instance. Running multiple strategies creates conflicting packet interceptors that will break connectivity. Always stop the current script (Ctrl+C) or uninstall the existing service before testing an alternative strategy.
Where are the blocked site lists configured for these strategies?
The strategies automatically read from the lists/ directory, specifically list-general.txt for target hosts and ipset-all.txt for IP ranges. You can augment these files with custom domains, and Zapret will pick them up on the next run without reinstalling the service.
Why does Secure DNS need to be enabled before running these strategies?
Zapret operates at the packet level using WinDivert to modify DPI-sensitive fields, but it does not handle DNS resolution. If your ISP returns blocked or redirected IP addresses for DNS queries, the traffic interception cannot reach the intended destination. Secure DNS (DNS-over-HTTPS or DNS-over-TLS) ensures you receive genuine IP addresses, allowing Zapret's packet manipulation to function correctly.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →