Open-source project
bol-van/zapret avatar
bol-van/zapret

zapret: A Serverless DPI Bypass Tool for OpenWrt, Linux, Windows, and BSD

DPI bypass multi platform

16,203 stars1,127 forksCLicense varies

At a glance

What is it?
zapret is an open-source tool for bypassing Deep Packet Inspection on Linux, OpenWrt routers, FreeBSD, OpenBSD, Windows, and partially macOS without routing traffic through a third-party server. This repository is in EOL mode with no new features planned; the active development has moved to zapret2.
Who is it for?
zapret is for users on Linux, OpenWrt, FreeBSD, or Windows who need to bypass ISP-level DPI filtering without routing traffic through a third-party server. The tool requires low-level system access (iptables or nftables on Linux, kernel queue hooks), and selecting the correct parameters for a specific ISP requires testing with blockcheck.sh.
Can I use it commercially?
Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
Is it still maintained?
Yes. The repository last received commits 12 days ago.
What is it written in?
Mainly C, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

Editorial analysis

DPI Bypass Without a Third-Party Server

zapret is an autonomous tool for countering Deep Packet Inspection. The README describes it as working without connecting to any external servers. This is the defining difference from a VPN or a proxy: where a VPN routes all traffic through a remote server, zapret manipulates the local TCP stream to prevent DPI from triggering in the first place.

The README states that the tool can help bypass blocks or slowdowns of HTTP(S) websites, and can counter signature-based analysis of TCP and UDP protocols (for example, blocking of VPN traffic by signature detection). It is not a solution for every type of censorship; it targets DPI-based filtering specifically.

The primary target hardware is low-power embedded devices: routers running OpenWrt. The README explicitly names this as the main use case. Traditional Linux systems, FreeBSD, OpenBSD, and Windows are also supported. macOS support is described as partial.

This repository is in EOL mode. The README states clearly that this version of zapret is no longer under development and is receiving only bugfixes. Pull requests with new features are not accepted. Active development continues in the zapret2 repository at github.com/bol-van/zapret2. The last push to this repository was on 2026-09-18.

How DPI Bypass Works: Passive and Active DPI

The README describes two categories of DPI that zapret addresses.

A passive DPI system reads a copy of the traffic stream. It cannot block packets directly. When it detects a prohibited request, it injects a TCP RST packet (and sometimes an HTTP redirect) to terminate the connection. Because the RST is injected rather than blocking the real packet, the original packet still reaches its destination. One approach is to use iptables rules to drop incoming RST packets from the ISP side, working around the consequences of the DPI trigger. zapret aims further: it prevents the trigger from firing at all.

An active DPI system is placed in-line on the network path. It can drop packets directly and can track entire TCP streams to block any packet belonging to a flagged flow. Active DPI cannot be defeated by iptables RST-dropping alone.

The strategy against both types is to send traffic that the DPI algorithm does not recognize. The README gives concrete examples of techniques that work against some DPI implementations: splitting a GET request across two TCP segments so the Host header is not in the first segment, changing the case of the Host header (host: instead of Host:), adding an extra space after the HTTP method, or appending a trailing dot to the hostname.

More advanced techniques operate at the packet level: sending fake packets with incorrect checksums or TTL values that the DPI processes but the destination server ignores, overlapping TCP sequence numbers, IP fragmentation, and SYNACK or SYNDATA desync modes. The README gives detailed section headings for all of these in the nfqws component.

The Two Main Tools: nfqws and tpws

zapret provides two primary traffic-handling tools alongside two utilities.

nfqws is the Linux-specific component. It works by hooking into the Linux kernel's NFQUEUE (netfilter queue) mechanism via iptables or nftables rules. Traffic is redirected into the queue, where nfqws inspects and modifies packets before they continue to their destination. This approach operates at the packet level and enables all of the desync techniques described in the README, including fake packet injection, TCP segmentation, and sequence number manipulation.

tpws is a transparent proxy. It intercepts TCP connections and proxies them, applying techniques such as TCP record splitting, TLSREC (TLS record splitting), MSS (Maximum Segment Size) manipulation, and several other desynchronization methods. tpws works on Linux (via iptables/nftables), FreeBSD, OpenBSD, macOS, and Windows, making it the cross-platform option where nfqws is unavailable.

The Makefile shows which tools are built for each platform. The standard Linux build compiles nfq (which contains nfqws), tpws, ip2net, and mdig. The macOS build target (make mac) excludes nfq because macOS does not have NFQUEUE:

bash
make

For BSD targets:

bash
make bsd

For Android:

bash
make android

Built binaries are placed in binaries/my/. The systemd target (make systemd) produces variants with systemd notification support.

Quick Start and Parameter Selection

The README points to two quick start documents: quick_start.md for Linux and OpenWrt, and quick_start_windows.md for Windows. These are separate files in the repository and are not reproduced in the README itself.

Before choosing parameters, zapret includes a blockcheck.sh script at the top level of the repository. The README refers to a parameter selection section, which instructs users to run blockcheck.sh to identify which techniques work against their specific ISP. The README explains that ISP DPI implementations vary: a technique that breaks one DPI may have no effect on another, and some ISPs run multiple DPI systems simultaneously that all need to be bypassed at once.

The repository includes install_easy.sh and install_prereq.sh for automated setup, along with systemd unit files in init.d/ for persistent deployment. An uninstall_easy.sh script handles removal. For OpenWrt, there is a documented installation path for space-constrained devices.

The config.default file at the repository root is the starting point for configuration. The files/ directory contains additional configuration assets, and ipset/ contains tools for working with lists of blocked IP addresses.

For IP list management, zapret includes the ip2net utility (which computes minimal IP prefixes from a list of individual addresses) and mdig (a multithreaded DNS lookup tool for resolving large domain lists). These support the autohostlist filtering mode, which automatically builds a list of hosts to apply bypass rules to based on observed connection behavior.

When zapret Will Not Work

The README is candid about the failure conditions.

If a passive DPI sends RST packets to both the client and the server simultaneously, zapret cannot help. The goal is to prevent the DPI trigger from firing; if the server's connection is disrupted by an injected RST before the legitimate response can arrive, there is no client-side mitigation available.

zapret works by confusing the DPI's packet recognition. If an ISP runs a DPI that successfully reassembles all segmented TCP streams and processes HTTP regardless of Host header capitalization, the techniques will have no effect. The README describes ISP-specific variation explicitly: what works for one provider may be entirely ineffective for another.

The tool has no effect on IP address blocking without protocol analysis. If an IP address or subnet is simply dropped at the router level without any DPI inspection, TCP manipulation has nothing to interact with. IP-level blocks require IP-level workarounds such as routing through a different exit point.

On Windows, the README notes that most of the functionality works. It does not claim complete feature parity with the Linux implementation. macOS support is described as partial, and the Makefile confirms that nfqws (the most capable component for active DPI bypass) is excluded from the macOS build target because NFQUEUE is a Linux kernel feature.

EOL Status, Licensing, and the Move to zapret2

This repository is in End-of-Life mode. The README states this at the top: no new features will be developed, only bugfixes are accepted, and pull requests with new features are rejected. The current active version is zapret2, available at github.com/bol-van/zapret2.

The README also includes a notice about fraud. Because zapret is free and open-source, any party that demands payment, exclusive download rights, or threatens copyright takedowns over zapret files is acting against the license. The README does not quote the license terms. The license is not identified in the repository, and the LICENSE.txt file is present but its terms are not stated in the README.

The most recent release tagged in this repository is v72.13, published on 2026-07-21. Prior to that, v72.12 was released on 2026-03-12 and v72.10 on 2026-02-24. The release cadence and EOL status together indicate that v72.13 is likely the final feature release for this codebase.

For anyone evaluating zapret for a new deployment, the migration path is to zapret2. For existing deployments on this codebase, bugfixes will continue, but no architectural changes or new bypass techniques will be added.

Editorial conclusion

zapret is for users on Linux, OpenWrt, FreeBSD, or Windows who need to bypass ISP-level DPI filtering without routing traffic through a third-party server. The tool requires low-level system access (iptables or nftables on Linux, kernel queue hooks), and selecting the correct parameters for a specific ISP requires testing with blockcheck.sh. This repository is in EOL mode per its own README: no new features will be added and pull requests with new features are not accepted. Anyone starting a new deployment should evaluate zapret2 (github.com/bol-van/zapret2) instead, as that is the version where active development continues.

Frequently asked questions

Is there zapret for Linux?

Yes; Linux is the primary supported platform. The default make target builds nfqws (which uses Linux's NFQUEUE via iptables or nftables), tpws, ip2net, and mdig. Quick start instructions are in quick_start.md in the repository root.

How do I use zapret?

After building with make (Linux) or the appropriate platform target, run blockcheck.sh to identify which bypass techniques work against your ISP, then configure the parameters in config.default and deploy using install_easy.sh or the systemd unit files in init.d/. The README points to quick_start.md for Linux and OpenWrt and quick_start_windows.md for Windows.

How do I install zapret?

Clone the repository and run make to build the binaries for Linux (or make bsd, make android, or make mac for other platforms). Binaries are placed in binaries/my/. Use install_easy.sh for automated system installation and install_prereq.sh for prerequisites; note that this repository is in EOL mode and zapret2 is the current development version.

Official sources

  1. bol-van/zapret on GitHub
  2. Issues
  3. README
  4. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/bol-van-zapret.svg)](https://hysenlabs.com/projects/bol-van-zapret)