this post was submitted on 11 Feb 2025
44 points (86.7% liked)

Privacy

37671 readers
714 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

Using Rethink DNS app btw, I want to use a firewall and VPN at the same time on Android. Wtf?!?

So my IP has somehow just been leaking all this time...

Edit: Typo

all 34 comments
sorted by: hot top controversial new old
[–] wizrad@lemmy.ca 31 points 2 months ago (5 children)

you are doing nothing wrong. To my knowledge, there is no effective firewall app for android that doesn't occupy the VPN connection. From my understanding, you either have a VPN or a firewall. I have found no work around for both that was effective.

[–] ReversalHatchery@beehaw.org 4 points 2 months ago* (last edited 2 months ago)

yes, but actually no.

there are apps (like rethink DNS) that pack multiple functions in the app. if an app is being used to handle a VPN connection, it gets to process all your network traffic, see for each packet which app does it belong to, and can do both firewalling, split tunneling by app or type of traffic, and can also filter packets. most VPN apps just don't bother with it because its a complex task, and most users wouldn't use it anyway.

There's also AFWall+ that can configure the kernel's firewall with root permissions, without setting itself up to handle a V0N connection.

both of these apps are available on f-droid

[–] eager_eagle@lemmy.world 3 points 2 months ago

Same, that's why I stopped using rethink a while ago, even though I loved it.

[–] marcie@lemmy.ml 3 points 2 months ago* (last edited 2 months ago)

Invizible Pro is the best option here. Uses Tor not a VPN though. Does firewall, i2p, and DNS. Is on FDroid

[–] cyberpunk007@lemmy.ca 1 points 2 months ago* (last edited 2 months ago)

I use tasker. Is SSID name "my home SSID name"?

Yes: disable wireguard

No: enable wireguard

Always on vpn. I have no need to use these other VPNs like everyone else is, but if I were I'd set that up on my opnsense firewall at home. That way everything in my network, and my phone's when away from home, are all tunnelled through the VPN provider. Opnsense does all the content filtering and security stuff well enough for my needs.

[–] GravitySpoiled@lemmy.ml 19 points 2 months ago* (last edited 2 months ago) (2 children)

Did you activate "block connections without vpn" aka kill switch?

There's only one vpn slot on android. How do you tunnel the connection without a second device?

Did you activate "always on vpn"?

[–] merde@sh.itjust.works 2 points 2 months ago* (last edited 2 months ago)

must be firewall > socks > wireguard > vpn

2nd question on netGuard FAQ https://github.com/M66B/NetGuard/blob/master/FAQ.md

[–] psyklax@lemmy.dbzer0.com 6 points 2 months ago (1 children)

Oh, you got to use the always-on vpn setting on android. I don't even trust that not to leak, but it's a must.

[–] merde@sh.itjust.works 4 points 2 months ago (1 children)

are you using DNS-over-TLS?

i don't use nextDNS app. Is nextDNS app using nextDNS by default?

i had to try different configurations to get what you're trying to get (firewall + vpn without leaks)

[–] Maiq@lemy.lol 4 points 2 months ago (1 children)
[–] Artemis@lemmy.ml 3 points 2 months ago

I have this exact same issue with Proton VPN using RethinkDNS...my Wireguard proxy works for a while but then randomly cuts out (on my second user profile). In my case it looks like there's a kill switch when that happens at least but still...can't find any reason why it keeps dropping.

[–] Hiro8811@lemmy.world 3 points 2 months ago (1 children)

You want two VPN connection at the same time? I'm not sure it's possible

[–] Johannes@programming.dev 1 points 2 months ago* (last edited 2 months ago)

You can configure Rethink to use always on VPN inside the app.