[5.0+][ROOT][3.6.0] AFWall+ IPTables Firewall [28 AUG 2023]

Search This thread

Atomic Lutin

Member
Apr 2, 2007
18
1
Hi !

Is there a way to edit the IPTables manually file and add restriction to trackers domain names ( avoir connexion to graphlytics or graph.facebook... for example)?

Thank you
 

PoochyX

Senior Member
Oct 23, 2016
2,170
425
Hi !



Is there a way to edit the IPTables manually file and add restriction to trackers domain names ( avoir connexion to graphlytics or graph.facebook... for example)?



Thank you
Your messenger won't work without graph facebook.. Like you won't be able to access your shared content...

([emoji3590]09-09-18[emoji813])
 

Atomic Lutin

Member
Apr 2, 2007
18
1
I don't have facebook account...

And if not graph.facebook there are a lot of other trackers....

For the moment graph.facebook is blocked by netguard and everything works well...
 

amg314

Senior Member
Feb 7, 2017
543
225
Kharkov
Vivo X60 Pro
Last edited:

birkita

New member
Dec 17, 2011
1
0
Xiaomi and Second Space

Anybody using AFWall+ paid and SecondSpace on MIUI Xiaomi? All activity from SecondSpace is flagged and blocked by AFWall+. The blocked apps from SecondSpace show up in the log with UID prefaced by 101. When Dual App option is enabled, apps such as the Chrome browser which is installed in both partitions, get listed in the app list with a 999 UID prefix. Is there anyway I can change it to 101?
If I select all apps then the Internet works normally for SecondSpace, but I cannot find any single specific application to allow to get SecondSpace traffic through the firewall.

Has anyone managed to solve this problem yet?
 

Betelstar

New member
Aug 22, 2019
1
0
Internet by bluetooth

Hello. Please add the ability to block the Internet received by bluetooth, this function would be very useful.
 

markd89

Senior Member
Jul 26, 2007
129
26
Blocking Google, best practices?

I used this script to make a list of all Google IPs to block with AFWall+

https://notabug.org/maloe/ASN_IPFire_Script/wiki

Code:
asn_ipfire.sh  --afwall google

that then becomes a custom script. It works well. In a way too well.

There are some websites I want to visit (i.e. homedepot.com) which is hosted at *.googleusercontent.com and is blocked by one of the IP Ranges.

I thought of what I thought was a clever workaround - use the TOR browser. That didn't work because homedepot.com detects my IP as being from some strange land.

I'm looking for suggestions on how to block the most of Google while still being able to access a few sites hosted on googleusercontent.com

I'm on LOS with no GAPPS. I'm mostly concerned about privacy the automatic connections which still occur to Google by the guts of Android. I'm not concerned about adblocking as I have that covered with uBlock Origin in Firefox.

Thanks,
Mark
 
Afwall is blocking google play downloads on wifi under android 8.x

After spending a good half an hour with various keywords I wasnt able to find any posts that details my rather bizarre issue, Afwall is blocking google play downloads on wifi under android 8.x -
  • Google play is able to download under data just fine
  • if I temporarily unblock application ID [1000], Google play is able to download under data just fine
  • Under the wifi section after first connecting where it says checking the quality of your internet connection - I get the message directly below the wifi icon " your internet may not be available", but again if I temp unblock the above that message goes away.
Even updating to the Afwall+ beta didn't fix the issue and as I not comfortable allowing a core OS application/s (with a list as long as your arm of functions) access to the internet, My work around is to do updates in google play via data. So my question is why does it work just fine over data with the firewall enabled but not over wifi..?
 
Last edited:

Portgas D. Ace

Inactive Recognized Contributor
Jun 12, 2014
4,354
3,160
Bergisches Land
Nexus 7
Google Pixel 6
After spending a good half an hour with various keywords I wasnt able to find any posts that details my rather bizarre issue, Afwall is blocking google play downloads on wifi under android 8.x -
  • Google play is able to download under data just fine
  • if I temporarily unblock application ID [1000], Google play is able to download under data just fine
  • Under the wifi section after first connecting where it says checking the quality of your internet connection - I get the message directly below the wifi icon " your internet may not be available", but again if I temp unblock the above that message goes away.
Evening update to the Afwall+ beta didn't fix the issue and as I not comfortable allowing a core OS application/s (with a list as long as your arm of functions) access to the internet, My work around is to do updates in google play via data. So my question is why does it work just fine over data with the firewall enabled but not over wifi..?

Please ensure that you have granted network permission for "media storage, download manager, downloads, MTP host" (UID 10009) within AFWall.
 

Oswald Boelcke

Senior Moderator / Moderator Committee
Staff member
DNS Proxy (and IpTables fyi) was set to auto as per the default setting, setting it to enabled made no difference.

Is there a way or app that test NETD..? or am I barking up the wrong tree.
Please search the thread for the keyword "netd". I remember I've made some posts in that respect but also in this thread.
 

Ramihyn

Member
Aug 5, 2012
43
24
OnePlus Nord
For once, I have to confirm an issue which has been reported before by others on the net:

Since I upgraded my OP6 to Android Pie, I have an issue when using the phone as tethering hotspot for my work notebook by WiFi.
Apparently the DNS resolution does not work any longer despite the usual commonly known rules. At github the issue has been discussed since end of 2018 but is still unresolved. That thread mentioned UID 1052 (some strange unknown app uid) as being blocked by AFWall+, filling up the logfile with the DNS requests of my notebook. At some reddit forum I learned that UID 1052 indeed is dnsmasqd in Android Pie, so I applied some custom script, and voilà, DNS resolution suddenly works again through tethering.

Some side checks (disabling the firewall completely as well as trying "nslookup targetdomain.com 8.8.8.8" without that custom script) confirmed without any doubt that AFWall+ is the culprit here, because UID 1052 does not show up in the apps list, and in whitelist mode this results clearly in these blocking of the DNS requests from the tethering clients.
At the same time, though, DNS lookups work fine directly on the OP6 at any time.
 

markd89

Senior Member
Jul 26, 2007
129
26
For once, I have to confirm an issue which has been reported before by others on the net:

Since I upgraded my OP6 to Android Pie, I have an issue when using the phone as tethering hotspot for my work notebook by WiFi.
Apparently the DNS resolution does not work any longer despite the usual commonly known rules. At github the issue has been discussed since end of 2018 but is still unresolved. That thread mentioned UID 1052 (some strange unknown app uid) as being blocked by AFWall+, filling up the logfile with the DNS requests of my notebook. At some reddit forum I learned that UID 1052 indeed is dnsmasqd in Android Pie, so I applied some custom script, and voilà, DNS resolution suddenly works again through tethering.

Some side checks (disabling the firewall completely as well as trying "nslookup targetdomain.com 8.8.8.8" without that custom script) confirmed without any doubt that AFWall+ is the culprit here, because UID 1052 does not show up in the apps list, and in whitelist mode this results clearly in these blocking of the DNS requests from the tethering clients.
At the same time, though, DNS lookups work fine directly on the OP6 at any time.

It would be great if you could please post the script that resolved this for you.

Thanks!
 
  • Like
Reactions: IronTechmonkey

Top Liked Posts

  • 1
    I was intrigued by this as I automatically whitelist Android Auto for wifi and mibile data - wifi to talk to the head unit in the car and data to pull maps info etc. This article seems to suggest that my thinking is/was correct but who knows. When I get time I might have a play...

  • 2
    What is needed to be enabled to use Android Auto in my car?
    I had to enable traffic for a bunch of XIAOMI system "apps" (they bundle a bunch of apps together so that you don't disable them) that disabled network if they didn't phone home successfully after a couple of minutes. Never buying anything from that underhanded manufacturer EVER AGAIN.
    1
    What is needed to be enabled to use Android Auto in my car?
    I'm not sure what you're asking, but AFWall is meant to block traffic based on certain rules. Why would you want to use AFWall in order to enable AA? Are you rooted? Custom ROM? What's your environment? Are you currently able to use AA in your car?
    1
    I'm not sure what you're asking, but AFWall is meant to block traffic based on certain rules. Why would you want to use AFWall in order to enable AA? Are you rooted? Custom ROM? What's your environment? Are you currently able to use AA in your car?

    Perhaps they are having trouble using Android auto with the Firewall, e.g., maybe AFwall is blocking Android Auto.

    +1 to your question/suggestion about whether or not Android Auto works okay when AFwall is not enabled.
    1
    What is needed to be enabled to use Android Auto in my car?
    this sounds like you are using afwall in whitelist mode (blocks everything, and you select what gets access)?

    if you run it in the recommended blacklist mode (allows everything, and you select what gets blocked) you should not have this issue - assuming you don't of course block android auto or some crucial system app.
    1
    What is needed to be enabled to use Android Auto in my car?
    What device you are using? OS and app version? What the default filtering mode? There's any logs while your device try to attempt any connection? More info please.
  • 404
    Welcome to official support page for AFWall+

    Disclaimer - As Usual. I'll not take any responsible if something goes wrong when using AFWall+

    Introduction
    AFWall+ is an improved version of DroidWall(front-end application for the powerful iptables Linux firewall). It allows you to restrict which applications are permitted to access your data networks (2G/3G/4G/LTE and/or Wi-Fi and while in roaming).Since the original author of Droidwall
    discontinued the project, I decided to keep the app instead of Avast Firewall. I'll continue to add more features as I can.


    Features
    - Supports 5.x to 13.x
    - Import/Export Rules to external storage
    - Search Applications
    - Multiple Profiles with custom names
    - Tasker/Locale support
    - Select All/None/Invert/Clear applications with single click
    - Revamped Rules/Logs Viewer with copy/export to external storage
    - Ability to view the network interfaces
    - Highlight system applications with custom color
    - Notify on new installations
    - Ability to hide application icons( faster loading )
    - Use LockPattern for application protection.
    - Show/Hide application ID.
    - Roaming Control for 3G/Edge
    - VPN Control
    - LAN Control
    - Tether Control
    - IPV6 Control
    - Tor Control
    - Choose able languages
    - Choose able iptables/busybox binary
    - Supports MIPS/x86/ARM
    - DNS Hostname

    Changelog - See third Post
    Current Version - 3.6.0

    To get Unlocker without Google services - Please follow the instructions here

    AFWall+ BETA Program
    1) AFWall+ opt-in for beta program
    2) Install AFWall+ and If you have any issues, just send email from (Menu -> Firewall Rules - > Send error report)

    Source Code/Wiki/FAQ
    AFWall+ is an free & opensource application
    Github
    Log an issue
    Frequently Asked Questions
    Many Thanks to @CHEF-KOCH

    Translations
    Translations - Please help me with translations in your language.
    http://crowdin.net/project/afwall

    Thanks To/Credits
    - German translations by chef@xda & user_99@xda & Gronkdalonka@xda
    - French translations by GermainZ@xda & Looki75@xda
    - Russian translations by Kirhe@xda & YaroslavKa78
    - Spanish translations by spezzino@crowdin
    - Dutch translations by DutchWaG@crowdin
    - Japanese translation by nnnn@crowdin
    - Ukrainian translation by andriykopanytsia@crowdin
    - Slovenian translation by bunga bunga@crowdin
    - Chinese Simplified translation by tianchaoren@crowdin
    - Polish translations by tst,Piotr Kowalski@crowdin
    - Swedish translations by CreepyLinguist@crowdin
    - Greek Translations by mpqo@crowdin
    - Portuguese translations by lemor2008@xda
    - Chinese Traditional by shiuan@crowdin
    - Chinese Simplified by wuwufei,tianchaoren @ crowdin
    - Italian translations by benzo@crowdin
    - Romanian tranlations by mysterys3by-facebook@crowdin
    - Czech translations by Syk3s

    Cheers,
    ukanth

    XDA:DevDB Information
    AFWall+ [ IPTables Firewall ], App for the Android General

    Contributors
    ukanth
    Source Code: https://github.com/ukanth/afwall


    Version Information
    Status:
    Stable
    Current Stable Version: 3.5.3
    Stable Release Date: 2022-06-28
    Current Beta Version:
    3.5.3
    Beta Release Date: 2022-06-28

    Created 2013-12-03
    Last Updated 2020-09-05
    70
    Version 3.0.1

    * Fix: Status toggle widget 1x1
    * Fix: Ability to hide ongoing notification (Stop firewall and restart to hide after disable it in preferences)
    * Fix: Firewall error notification on oreo and above
    * Security: Tile toggle checks for password
    * User reported crashes
    * Updated translations

    Previous version 3.0.0

    Features:
    * Better support for nougat/oreo and pie.
    * Firewall toggle tile
    * Adaptive Icons
    * Notification channels
    * Tor support

    Bugs:
    * General bug fixes and crash reports.
    * Language selection bug
    * Filter selection bug
    * Compatible with magisk 17.x
    * Better handling of background process
    * Drops support for 4.x devices
    * Update languages
    * Updated libraries

    Complete Changelog

    41
    Hello All,

    After careful analysis and testing, I decided not to rewrite the way rules are being applied due to lot of under hood changes required. Instead added few enhancements. Now applying rules from menu will show how many rules are getting applied with progress status. Also when adding/removing few rules , it will apply only those related rules instead of full apply.

    Also fixed couple of bugs and enhancements. You can get the full changelog from https://github.com/ukanth/afwall/blob/beta/Changelog.md

    This is BETA Version which is not released on playstore. I have been using this for past week and it's stable. But there might be bugs which I haven't encountered. Please test it and report it in case of any issues.

    Also I have been following XPrivacy thread on the decision by it's author. Just as FYI, I might fix it for my own usage when I update to nougat, I will share it here if anybody uses it here.

    BETA Link - https://www.dropbox.com/s/isvi413qyx6vb4d/AFWall+ 2.9.7-BETA-TESTER.apk?dl=0
    40
    Hello everyone,

    I have released 3.0.0 stable on playstore today. It's been a crazy month so far. After going through lot of dilemma of whether to support the existing afwall or write a new one from scratch, finally able to pull myself and release stable version of afwall with lots of bug fixes and new features along with pie support. Since I don't do full time Android development, it was hard to keep track of what's going on with sdk level changes.

    Thank you all for your support in AFWall+ development. Without your support it would simply not possible to pull through this.

    I will be out for couple of days ( taking off to spend time with my family ) and hopefully will be able to reply to questions once back.

    Thanks again and have a great day.
    35
    Hello everyone,

    I have released stable version of 3.1.0 to playstore and github. Its live on playstore. You can find the changelog along with md5/sha here

    https://github.com/ukanth/afwall/releases/tag/v3.1.0

    Thank you all for your continuous support in AFWall+ development.