Zapret: обсуждение

Why did you only test TLS 1.2? As far as I know, TLS 1.3 is not blocked in Russia, and upstream curl doesn’t support encrypted client hello, the HTTPS DNS record (type 65) of discord.com doesn’t even contain an ech field.

Moreover, I would rather use Zapret or other similar tools for all websites than disable encrypted client hello.
Could you try

nfqws --qnum 0 --dpi-desync=fakeddisorder --dpi-desync-autottl=1:1-10 --dpi-desync-autottl6=1:1-10 \
--dpi-desync-fooling=md5sig --dpi-desync-split-pos=2 \
--dpi-desync-fakedsplit-pattern=0x474554202f20485454502f312e310d0a486f73743a2031302e302e302e310d0a0d0a

Lastly, I think “fakeddisorder” mode can be simpler:
fake 2nd segment, 2nd segment, fake 2nd segment, fake 1st segment, 1st segment, fake 1st segment
---->
fake 1st segment, 2nd segment, 1st segment or fake 1st segment, fake 2nd segment, 2nd segment, 1st segment