you are doing nothing wrong. To my knowledge, there is no effective firewall app for android that doesn't occupy the VPN connection. From my understanding, you either have a VPN or a firewall. I have found no work around for both that was effective.
Privacy
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
much thanks to @gary_host_laptop for the logo design :)
yes, but actually no.
there are apps (like rethink DNS) that pack multiple functions in the app. if an app is being used to handle a VPN connection, it gets to process all your network traffic, see for each packet which app does it belong to, and can do both firewalling, split tunneling by app or type of traffic, and can also filter packets. most VPN apps just don't bother with it because its a complex task, and most users wouldn't use it anyway.
There's also AFWall+ that can configure the kernel's firewall with root permissions, without setting itself up to handle a V0N connection.
both of these apps are available on f-droid
Same, that's why I stopped using rethink a while ago, even though I loved it.
Invizible Pro is the best option here. Uses Tor not a VPN though. Does firewall, i2p, and DNS. Is on FDroid
I use tasker. Is SSID name "my home SSID name"?
Yes: disable wireguard
No: enable wireguard
Always on vpn. I have no need to use these other VPNs like everyone else is, but if I were I'd set that up on my opnsense firewall at home. That way everything in my network, and my phone's when away from home, are all tunnelled through the VPN provider. Opnsense does all the content filtering and security stuff well enough for my needs.
Did you activate "block connections without vpn" aka kill switch?
There's only one vpn slot on android. How do you tunnel the connection without a second device?
Did you activate "always on vpn"?
must be firewall > socks > wireguard > vpn
2nd question on netGuard FAQ https://github.com/M66B/NetGuard/blob/master/FAQ.md
Oh, you got to use the always-on vpn setting on android. I don't even trust that not to leak, but it's a must.
are you using DNS-over-TLS?
i don't use nextDNS app. Is nextDNS app using nextDNS by default?
i had to try different configurations to get what you're trying to get (firewall + vpn without leaks)
I have this exact same issue with Proton VPN using RethinkDNS...my Wireguard proxy works for a while but then randomly cuts out (on my second user profile). In my case it looks like there's a kill switch when that happens at least but still...can't find any reason why it keeps dropping.
You want two VPN connection at the same time? I'm not sure it's possible
You can configure Rethink to use always on VPN inside the app.