AudionAudion

Audion DPI Manager — user guide

USER_GUIDE_EN.md

Audion DPI Manager — user guide

Contents

Audion DPI Manager is one window for the programs that get round traffic blocking. The main one is Zapret (the Flowseal/zapret-discord-youtube package). Beside it: zapret2 (bol-van) and ByeDPI (romanvht/ByeDPIManager).

The window works with the same files, services and registry entries as Flowseal's bat files. The service.bat menu and this window can be used alternately: they always agree.

Starting

Start Start.exe. Windows asks for permission (UAC): without administrator rights the WinDivert driver cannot be loaded, a service cannot be installed, and DNS and the hosts file cannot be changed. If you decline, nothing starts and nothing changes. The prompt comes at every start: through Start.exe, and when App\AudionDpiManager.exe is opened directly. If the program still ends up without rights (started outside the usual way and the prompt was impossible), the status line says so, and the bypass, the service and DNS will not work.

The language is taken from the system at the first start (Russian on a Russian Windows, English on any other); after RU | EN is pressed the choice is remembered. RU | EN at the top right switches the language, the moon and sun buttons the theme, a | A | A+ the font size.

How the window is built

The top row — one row of three dark pieces: the name of the program and its version on the left, the DPI tool switches in the middle, the language, the theme, the font and the tray glyph on the right. The height of the window is the scarcest thing the pages have, so what used to be two rows (the title, then a band of switches) is one.

The tray. While the program runs, its icon stands in the Windows tray. The glyph with an arrow down at the right end of the top row hides the window in the tray: the program and the bypass go on. A click on the tray icon brings the window back. The menu of the icon (right button; each line has its icon, the chosen tool is marked with a tangerine dot): Show the window, Start and Stop for the tool chosen on top, the switches ZAPRET, ZAPRET 2, BYEDPI, and Exit. The cross of the window still closes the program. A second start of the program from the same folder does not open a second copy: it shows the window of the one that runs.

The three big switches in the middle — ZAPRET, ZAPRET 2, BYEDPI — are not settings but a full switch of the DPI tool under the window: each has its own files, its own connection and its own meaning of the UPDATE and START buttons below. The colour of the line under the header shows which one is chosen (Zapret — blue, zapret2 — amber, ByeDPI — green). The indication is on the buttons themselves: under the name a light and the version ("what is installed": green — the version is the latest, amber — not installed or GitHub has a newer one, "1.10.3 → 1.10.4", gray — GitHub did not answer), and a green triangle by the name means "working now". All three may run at once, but the two interception bypasses (Zapret and zapret2) get in each other's way, so the program will not start the second one.

The bottom bar — permanent buttons. On the left the tools: CONFIGS, TUNE, DNS, LISTS, JOURNAL, DIAGNOSTICS, ABOUT. Press one and the tool opens in place of the application page; press it again (or Esc) to go back. On the right UPDATE | START act on the application chosen on top. A button with nothing to do is gray: UPDATE is gray when there is nothing to update, START when the application is not installed. While the application runs, START turns into STOP.

The status line above the buttons shows the last message (for 14 seconds) and, during a long operation, its name, a progress bar and STOP. JOURNAL (Ctrl+J) and F1 DOCS are beside it.

The journal records everything the program does and the output of winws.exe. One file per day in ._runtime\logs.

First start

  1. Choose ZAPRET on top. If the package is missing it says "not installed" — press UPDATE: the program downloads the latest Flowseal release and installs it into the Tools\zapret-discord-youtube folder next to itself (an installed package in the old place, zapret-discord-youtube at the root, keeps working).
  2. In the STRATEGY card pick a strategy. If you do not know which, general (FAKE TLS AUTO) is usually a good start.
  3. Press START. The bypass runs: the "Bypass" line turns green.
  4. Does not work? Open TUNE, the mode READY, press START: the program checks all strategies and shows which ones open more sites.
  5. A working strategy can be installed as a Windows service with AS SERVICE — then the bypass starts with the system.

Also useful: turn on a secure DNS in the DNS section — without it the provider substitutes the addresses of blocked sites and no bypass helps.

ZAPRET

STATE. The Zapret folder (another can be chosen), the version on disk and on GitHub, what runs and whether a service exists. STOP stops winws.exe (and the service if it runs); REMOVE SERVICE removes the service and the WinDivert driver completely. Under the install button stands a row of buttons that take all this down: the same STOP and REMOVE SERVICE, STOP SERVICE (the service stays installed), STOP DRIVER, REMOVE DRIVER and REMOVE ZAPRET. The WinDivert driver is shared by Zapret and zapret2: the bypasses that hold it (winws.exe, winws2.exe, the service) are stopped first, and the driver loads again at the next start (WinDivert registers itself for as long as it is loaded, so a stopped driver mostly disappears by itself). REMOVE ZAPRET stops the bypass and the service, removes the service and the driver and deletes the folder Tools\zapret-discord-youtube with your *-user.txt lists - after a question; a folder outside the program is not deleted (only the service and the driver are removed).

The update (UPDATE) works like the old Audion Zapret Updater: "the folder is there — update it, it is not — install". The archive is downloaded while Zapret still runs (without the driver GitHub may not open); then the service, winws.exe and the driver are removed; your lists\*-user.txt lists, the game filter setting, the IPSet mode and the update-check flag are carried into the new version; the old files are cleared and the new ones put in place. If the driver will not unload, the replacement is prepared for the next Windows boot. The names in the archive are checked before unpacking: a path that leads out ("..", a drive, a network path), a device name or an NTFS stream rejects the whole archive.

STRATEGY. Switch buttons, one per general*.bat file. Under them: RUN (winws.exe with all the lists, without a console window), AS SERVICE (autostart), TO THE CONFIGURATION FIELD (the parameters go to the CONFIGS section), COMMAND (the full command line, can be copied).

FILTERS. The same as the items of service.bat: Game Filter (OFF, TCP + UDP, TCP, UDP and the ports — in versions from 1.10), IPSet (NONE, LIST, ALL), the update check in the bat files. The changes take effect after the bypass is restarted — a RESTART THE BYPASS button appears beside them.

CONFIGS

CONFIGURATION FIELD. The parameters of winws.exe as text, a profile (everything up to --new) on its own line. The variables %BIN%, %LISTS%, %GameFilterTCP%, %GameFilterUDP% are filled in at the start: the configuration works from any folder and follows the game filter. Buttons: RUN, AS SERVICE, SAVE TO CACHE, CHECK (shows the command line and the missing files, starting nothing), NEW. Below are the buttons of the ready strategies: press one and its parameters land in the field. The DNS before the start chips tie a DNS mode to the configuration; it is applied before the start.

CONFIGURATION CACHE. Up to 200 entries. Everything you ran, saved or tested in TUNE lands here. When the room runs out, the entry not used for the longest time goes. A star pins an entry — a pinned one never goes. If all 200 are pinned, a new one will not fit: the program says so, and you unpin or delete one. The cross deletes an entry (a pinned one after a question). CLEAR UNPINNED removes everything except the pinned ones. The search looks through the title, the strategy and the parameters. A click on a row puts it in the field, ▶ runs it at once.

The cache is kept in config\history\configs.json.

Size. The configuration field stretches with the height of the window: what is around it (the name, DNS, the buttons, the strategies) takes its own room and everything left goes to the field. The window opens at 1280 × 860, where all buttons of the section are in view, and on a smaller screen it is made to fit the working area. The window can be dragged larger or smaller; if it is very low the section scrolls instead of cutting buttons off.

TUNE

Parameter tuning: the program tries the variants by itself and shows which one opens more of the sites of utils\targets.txt (Discord, YouTube, Google and others). Before the tuning it counts how many sites open with no bypass at all, so that the result reads as "of the blocked ones this many opened".

Modes (What to change):

Base — a strategy from ZAPRET or the text of the CONFIGS field. Check: QUICK (one site from each group, up to eight, no ping) or FULL (all sites and ping). The number of variants: 8, 16, 24 or 48.

While the tuning runs, the bypass is started and stopped for every variant — the internet may drop for seconds. A bypass that was running comes back after the tuning. STOP stops after the current variant.

The results are sorted: more sites opened, and with a tie a shorter response time. Every row has TO FIELD, RUN, AS SERVICE and a star. Every variant checked goes to the cache with its score (in the READY mode the five best, not all twenty).

An honest limit: the check goes over HTTPS sites. The Discord voice and UDP games are not checked by it.

DNS

A bypass is powerless while the provider substitutes the DNS answers. Modes: GOOGLE, CLOUDFLARE, QUAD9, ADGUARD (AdGuard's "default" servers, 94.140.14.14 and 94.140.15.15: they also block ads, trackers and phishing sites; the servers without filters, 94.140.14.140 and 94.140.14.141, can be typed into OWN) and OWN. APPLY sets the servers (IPv4 and IPv6) on all connected adapters that have a way to the internet and turns on the encryption of the queries (DoH) if Windows can (Windows 11). Before the first change the state of the adapters is saved; RESTORE brings it back exactly: servers set by hand return (IPv4 and IPv6 each on its own), automatic ones become automatic again; DoH entries that were not there are taken out, the earlier ones get their values back. The adapter is found by its GUID, not by its number. An adapter that appeared between two changes is saved too (with its state at that moment). If something did not come back the program says so and keeps it in the backup: the button can be pressed again. A failed write is a failure: "DNS changed" appears only when the adapter really shows the new servers; if DoH encryption did not turn on, that is said too.

Your own DNS. The "Own DNS" field takes one line: the IP addresses of the servers (IPv4 and IPv6) and, if needed, a DoH address (https://…), separated by spaces or commas. For example: 1.1.1.1, 1.0.0.1, https://cloudflare-dns.com/dns-query. How it is understood:

The mode OWN is also in CONFIGS among the "DNS before start" modes: a cache entry keeps its servers whole and does not depend on what the field says today.

If you have a Keenetic router, turn on "Request transit" in it.

LISTS

LISTS FROM GITHUB. Zapret bypasses blocking only for the sites and addresses in its lists. Here ready large lists for Russia are connected; they are published on GitHub and updated every day or more often, and the program downloads them straight from there (only from raw.githubusercontent.com):

SetWhat it isEntries
runetfreedom · ru-blocked-communityaddresses from community.antifilter.download: blocked ones that users reportedabout 900
runetfreedom · ru-blockedall blocked addresses and subnets (antifilter.download)about 88 thousand
runetfreedom · re-filter (IP)addresses of the re:filter projectabout 25 thousand
runetfreedom · Telegram, Twitter, Facebooksubnets of the three servicesabout 150
Discord (subnets)Discord voice servers: itdoginfo/allow-domains and re:filterabout 2,300
itdoginfo · Russia inside (domains)domains that need bypassing inside Russiaabout 1,200
Re:filter · community (domains)popular and blocked domainsabout 700
Re:filter · domains_all (domains)the full re:filter domain listabout 80 thousand

The lists of runetfreedom/russia-blocked-geoip are rebuilt every 6 hours from antifilter.download and re:filter (GPL-3.0). The two large sets (ru-blocked and domains_all) carry a warning in their tooltip: they make the lists much longer, and winws reads them at every start.

How it works: the ON chip of a set is the whole gesture. An enabled set is written into the lists of the DPI tools chosen with the Write into: chips (ZAPRET, ZAPRET 2, BYEDPI; ZAPRET is on by default). For Zapret it goes as a block between two marker lines of this program (# >>> Audion DPI Manager: name | entries | date … # <<< Audion DPI Manager: name): domains go into list-general-user.txt, addresses into the real IPSet list (ipset-all.txt, or, while the IPSet mode is NONE or ALL, into its copy ipset-all.txt.backup, where the list waits). Your own lines beside them are never touched, and the blocks come out by the markers: switch a set off and the file is back byte for byte as it was. How the other two DPI tools are served is below, in "Lists for zapret2 and ByeDPI".

Lists for zapret2 and ByeDPI. The same sets can be written into the other two DPI tools: turn their chips on in "Write into:". The DPI tool must be installed; if not, the program says so and makes nothing up for it (it writes after the installation). Each DPI tool reads its lists in its own way, so it is arranged differently:

DPI toolWhere it is writtenHow it is used
ZAPRETlist-general-user.txt and the IPSet list of the package, as blocks by markersas before; addresses only in the IPSet mode LIST
ZAPRET 2domains — Tools\zapret2\lists\list-user.txt, addresses — Tools\zapret2\lists\ipset-user.txt, as blocks by markers (zapret2 lists take # comments)domains work at once: the profiles of the sample select traffic by list-user.txt. Addresses need profiles with --ipset: the PROFILES FOR ADDRESSES chip in the ZAPRET 2 section. winws2 reloads a changed list by itself
BYEDPITools\ByeDPI\lists\hosts.txt and ipset.txt, whole, entries only (ciadpi has no comments, markers in its files would become "domains")only when the mode "by lists" is on in the BYEDPI section

Names ciadpi does not understand (for example with an underscore) do not go into the ByeDPI file: the program says how many. An empty ipset-user.txt of zapret2 would mean "any address", so it always keeps one safe line 203.0.113.113/32 — like the mode NONE of Flowseal.

OWN LISTS · IMPORT AND EXPORT.

Entries are checked like this: an address is four dotted numbers or IPv6, with a mask length or without; /0, 0.x.x.x, 127.x.x.x, 224 and above are dropped (they do only harm in an ipset). A domain is a name with a dot; case, *. and dots at the ends are removed. The sets are kept in config\history\lists\.

Flowseal's own lists: OWN DOMAINS (list-general-user.txt), EXCEPTIONS, IP EXCEPTIONS — editable; the others lie in the package and open read-only. Looking never creates files: a user list that does not exist yet shows the text service.bat would put in it.

IPSET. UPDATE IPSET LIST downloads a fresh ipset-all.txt (the sets with addresses are written into it again afterwards).

HOSTS. The hosts file fixes the web version of Telegram and the Discord voice chat. CHECK compares it with Flowseal's reference; WRITE TO HOSTS appends a block between two marker lines of this program (a copy is made in ._runtime first); REMOVE BLOCK removes exactly our block by the markers, the rest is not touched.

JOURNAL

The live journal of the DPI tools: the lines winws.exe, winws2.exe and ciadpi.exe print as the program starts them, together with the events of their start and stop, from the start of the program. It is the journal of the dock at the bottom (Ctrl+J), sorted by DPI tool: the chips ALL, ZAPRET, ZAPRET 2, BYEDPI. MANAGER shows the journal ByeDPI Manager keeps in its own file (Tools\ByeDPI\logs\bdmanager_date.log) as it grows. FOLLOW scrolls to the new lines, COPY puts what is shown into the clipboard, CLEAR SCREEN empties the screen (the files stay), JOURNAL FILE opens the file of the day in Notepad. The output of the service and of programs that were not started by this window cannot be read: Windows does not give it out.

DIAGNOSTICS

The Run Diagnostics item of service.bat as a table: the Base Filtering Engine service, the system proxy, TCP timestamps, Adguard, Killer, Intel Connectivity, Check Point, SmartByte, the bypass files (an antivirus often removes the driver), VPN, the secure DNS, hosts, a path with Cyrillic or in OneDrive, a stray WinDivert driver, the services of other bypasses. Green — fine, blue — a tip, amber — a remark, orange — a problem. Where the program can fix it there is a button. CLEAR DISCORD CACHE closes Discord and deletes its cache (you do not have to sign in again).

Looking changes nothing. The one exception is the same as in service.bat: the program turns TCP timestamps on by itself when it starts the bypass.

ZAPRET 2

The second-generation DPI tool by bol-van: its strategies are Lua programs, winws2.exe only intercepts the traffic. UPDATE (or INSTALL in the section) downloads the release and takes out of it only what Windows needs: winws2.exe, the WinDivert driver, lua\, files\fake\, the filter samples. It all lies in Tools\zapret2. An update checks the archive and unpacks it aside, then moves the old files out of the way and puts the new ones in; if a file is in use, the previous version comes back whole. Beside the install button stand DISCONNECT, STOP DRIVER, REMOVE DRIVER (the WinDivert driver is shared with Zapret) and REMOVE ZAPRET 2: the folder Tools\zapret2 is deleted with the lists, the preset in config\zapret2 stays.

The release has no ready strategies for Windows. There is one PRESET here — the "http, https, quic" example from the zapret2 documentation — in a field you edit; it works on the domain list DOMAINS (initially YouTube and Discord). The sets from GitHub (LISTS section, the ZAPRET 2 chip) are appended to this file as blocks: here you see and edit only your own lines.

The PROFILES FOR ADDRESSES chip adds, next to every preset profile that selects traffic by list-user.txt, a twin that selects it by lists\ipset-user.txt — LISTS puts the addresses of the sets there. The twins stand after the originals: a name from the list of domains wins, an address catches what has no name (QUIC, calls). Only the profile part (--filter-…, --lua-desync…) is copied; the global options (--lua-init, --blob, --wf-…) stay in one copy. The preset is saved at once; switch the chip off and the twins are removed, the preset is back byte for byte. CHECK shows the command line and the missing files. %Z2% in the text is the Tools\zapret2 folder. START starts winws2.exe with the preset from the field (even an unsaved one; it is saved at the start). The strategy for zapret2 is picked by hand: blockcheck2 is not shipped in the Windows release.

BYEDPI

UPDATE installs the ByeDPI Manager "All in One" package into Tools\ByeDPI: the management window, ciadpi.exe, ProxiFyre and the installers of dependencies. The Manager's settings (config) and the check lists (proxytest) are not touched by an update. The archive is checked and unpacked aside first; then the files are replaced, and if one is held by another program, everything is put back as it was and the version stays the old one. Beside it stand DISCONNECT and REMOVE BYEDPI: the connection is taken down, the system proxy is put back, the Manager window and ProxiFyre of this folder are closed, the folder Tools\ByeDPI is deleted. ByeDPI has no driver (it is a proxy); Windows Packet Filter from the redist folder, if you installed it for ProxiFyre, stays in Windows - it is removed in "Apps".

OPEN MANAGER starts its window (strategy picking, the ProxiFyre mode for separate programs). DEPENDENCIES opens the redist folder — Windows Packet Filter and Visual C++ 2022 are needed only for ProxiFyre.

CONNECTION is a simple one: ciadpi.exe on a local port plus the Windows system proxy (socks5://127.0.0.1:port). TAKE FROM MANAGER takes the parameters and the port from its settings. On disconnect the previous proxy comes back unless another program changed it in the meantime. The default strategy is -d1 -d3+s -s6+s -d9+s -s12+s -d15+s -s20+s -d25+s -s30+s -d35+s -r1+s -S -a1 -As -d1 -d3+s -s6+s -d9+s -s12+s -d15+s -s20+s -d25+s -s30+s -d35+s -S -a1: two groups of splits and disorders at the SNI, the second (after -As) works when TLS breaks. -S (md5sig) exists only on Linux, so the program leaves it out of the command line, as ByeDPI Manager does on Windows. A settings file that still holds the default of earlier versions takes the new one; a strategy you wrote yourself is never touched.

BY LISTS — OFF, BY DOMAINS, BY ADDRESSES. ByeDPI can limit the strategy to a list: --hosts file (only these domains, subdomains included) or --ipset file (only these addresses); other traffic passes as it is. The lists are the sets from LISTS (the BYEDPI chip): the files Tools\ByeDPI\lists\hosts.txt and ipset.txt. How the program inserts the limit: ciadpi cuts its options into groups at every --auto (-A) and tests the limits of each group separately, so --hosts/--ipset is put at the head of every group — otherwise a group without the limit would keep working for all sites. A strategy that already has its own --hosts/--ipset stays as you wrote it. Domains and addresses cannot be combined: the conditions of one group add up (AND), so one mode is chosen. If the mode has no entry at all, the connection does not start and says why (ciadpi with an empty list would apply nothing). COMMAND shows the resulting command line and finds obstacles without starting anything.

Command line

Two commands run with no window, for the builder of a release (they need no administrator rights and show no UAC prompt; they end with the exit code 0 when everything asked for is done, 1 when something failed, 2 when the command is not understood):

In the builder these are the step [06] INSTALL APPS of builder_main.cmd and the first thing cleanup_project.cmd does; the cleanup also removes config\settings.json (the program starts in Russian and the dark theme by its defaults), the history, the logs and the build folders. The cleanup installs nothing, and neither command builds the program.

ByeDPI: the parameters and the settings of the Manager

PARAMETERS… opens the list of all the options of ciadpi.exe, in the groups of its manual (connection, scope, automatic mode, bypass tricks, Linux only), each with a short explanation and the button INSERT, which puts a ready template of the option at the end of the field of parameters. The search narrows the list by a name or a word. The options that exist only on Linux are shown too, marked "does not work on Windows": the program drops them from the command line, as ByeDPI Manager does.

MANAGER SETTINGS shows and changes the settings file of ByeDPI Manager (Tools\ByeDPI\config\settings.json), the same the tabs of its window show: the routing (OFF, PROXIFYRE, SYSTEM PROXY), the LAN, the list of programs for ProxiFyre (a process name, an exe or a folder per line; the buttons FILE… and FOLDER… add them), and what its window does (connect at start, start minimized, minimize to tray). SAVE TO MANAGER writes only these keys, everything else in the file (language, hotkey, history of strategies) stays. GIVE TO MANAGER in the connection card writes the parameters and the port from the fields into the same file; TAKE FROM MANAGER does the opposite. The Manager reads its file when it starts and writes it when it closes, so its window must be closed while you save here: the program refuses to write while it is open. The connection of this section does not use the routing settings; running programs through ProxiFyre, picking strategies and the autostart with Windows are done by the Manager window itself (OPEN MANAGER).

What the program changes on the machine

All of it is written to the journal. Nothing runs on the Windows scheduler. The program goes to the network only for versions, releases and lists on GitHub and — on your CHECK button in the DNS section — to the servers you named yourself. Once a day, while the window is open, it downloads the enabled sets of lists again; the ONCE A DAY chip in LISTS turns that off.

Where things are

Licence and trademark

Audion DPI Manager © 2026 Tensionix is distributed under the Apache License 2.0 (the full text is the file LICENSE, the notice is NOTICE; both open from buttons in the ABOUT section). "Audion" and the Audion mark are trademarks of the author: the Apache 2.0 licence (section 6) does not give the right to use this name and mark, and a copy or a changed version of the program must not be presented as Audion. Third-party programs (Flowseal, zapret2, ByeDPI, WinDivert) and their lists are downloaded from GitHub by your button and stay under their own licences.

If something is wrong

All projects