How to Run ByeDPI in Docker to Bypass Deep Packet Inspection (DPI) and Throttling
Is your ISP throttling YouTube, Discord, or specific websites using Deep Packet Inspection (DPI)? Here is how to run ByeDPI inside Docker as a local SOCKS5 proxy to fragment TCP packets and bypass ISP censorship without a slow VPN.
Internet Service Providers (ISPs) and network operators increasingly employ Deep Packet Inspection (DPI) middleboxes to throttle or block traffic to services like YouTube, Discord, Telegram, and cloud providers.
Unlike basic DNS blocking or IP blacklisting, DPI devices inspect the unencrypted Server Name Indication (SNI) field inside the initial TLS ClientHello handshake packet. When the DPI middlebox detects a restricted domain in the SNI, it injects fake TCP Reset (RST) packets or silently drops subsequent traffic.
You don’t need to route all your traffic through a high-latency commercial VPN server in another country to bypass this. ByeDPI is a local SOCKS5 proxy that manipulates TCP segments—fragmenting packets and scrambling TLS handshakes—so dumb DPI middleboxes fail to parse the SNI while the actual remote server reassembles the stream transparently.
Here is how to deploy ByeDPI in Docker using the tazihad/byedpi container.
How ByeDPI Defeats DPI Without a VPN
When your browser connects to an HTTPS website, it sends a TLS ClientHello containing the domain name in plaintext.
ByeDPI intercepts this outbound connection and applies TCP-level evasions:
-
TCP Packet Splitting (
--split): Splits the TLSClientHelloacross multiple TCP packets at an offset before or inside the SNI extension. DPI devices buffer a limited window of bytes and cannot reconstruct the segmented hostname. -
Out-of-Order Delivery (
--disorder): Sends the second half of the handshake packet before the first half, setting TCP sequence numbers appropriately. The destination server buffers and re-orders the stream correctly, while the DPI device assumes the packets are invalid and ignores them. - Fake Headers & Hop Limit: Injects a dummy packet with a low Time-To-Live (TTL) that reaches and confuses the DPI box before expiring, preventing it from reaching the actual server.
Because you are communicating directly with the destination server and not through a proxy middleman, your connection retains 100% of your native internet speed and low ping.
Deploying ByeDPI with Docker Compose
Using Docker makes running and updating ByeDPI completely painless on Linux, macOS, or home servers (such as a Raspberry Pi or Home Assistant box).
Create a working directory and a docker-compose.yml file:
1
2
mkdir -p ~/services/byedpi && cd ~/services/byedpi
nano docker-compose.yml
Paste the following configuration:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
services:
byedpi:
image: tazihad/byedpi:latest
container_name: byedpi
restart: unless-stopped
ports:
- "1080:1080"
command:
- "--ip"
- "0.0.0.0"
- "--port"
- "1080"
- "--split"
- "1"
- "--disorder"
- "3"
- "--auto"
- "torst"
Start the container in detached mode:
1
docker compose up -d
Verify that the proxy service is running and listening on port 1080:
1
docker compose logs -f
Tuning Evasion Parameters for Your ISP
Different DPI hardware (such as Cisco, Huawei, or Sandvine appliances) responds to different packet manipulation flags. If the default parameters don’t unblock your target site, test these common presets in your command configuration:
Profile A: Aggressive TLS SNI Splitting (Best for YouTube / Discord)
1
command: ["--ip", "0.0.0.0", "--port", "1080", "--split", "2", "--disorder", "1"]
Profile B: Mid-SNI Splitting (--split-sni)
1
command: ["--ip", "0.0.0.0", "--port", "1080", "--split-sni", "--auto", "torst"]
Profile C: Fake Packet Injection (--fake)
1
command: ["--ip", "0.0.0.0", "--port", "1080", "--fake", "-1", "--ttl", "8"]
Configuring Your System or Browser
Once ByeDPI is running on 127.0.0.1:1080, point your client to it as a SOCKS5 proxy.
1. Test via Terminal (cURL)
Verify that the proxy routes traffic and resolves DNS remotely:
1
curl --socks5-hostname 127.0.0.1:1080 -I https://www.youtube.com
You should see a successful HTTP/2 200 response.
2. Browser Setup (Firefox / Chromium)
Rather than proxying your whole machine, use browser extension rules so only blocked domains go through ByeDPI:
- Install ZeroOmega or FoxyProxy in your browser.
- Add a new proxy:
-
Protocol:
SOCKS5 -
Server:
127.0.0.1(or your local server’s LAN IP if running on a home server) -
Port:
1080
-
Protocol:
- In Proxy rules, configure Auto-switch:
- Send
*.youtube.com,*.googlevideo.com, and*.discord.comto the ByeDPI SOCKS5 proxy. - Send all other traffic to direct connection.
- Send
Running on an OpenWrt Router (Network-Wide)
If you have an OpenWrt router, you can route all network devices through your Dockerized ByeDPI instance without configuring individual devices.
Install redsocks on OpenWrt to transparently redirect outbound TCP port 443 traffic destined for blocked IP ranges to the ByeDPI SOCKS5 port:
1
2
opkg update
opkg install redsocks iptables-mod-nat-extra
Point redsocks configuration to your Docker host’s IP at port 1080, and every device on your home Wi-Fi—including smart TVs and mobile phones—will bypass DPI restrictions automatically.
