FORUMS
Remove All Ads from XDA

[5.0+][ROOT][3.2.0-BETA-2] AFWall+ IPTables Firewall [16 OCT 2019]

1,428 posts
Thanks Meter: 4,782
 
By ukanth, Recognized Developer on 26th October 2012, 05:41 PM
Post Reply Email Thread
30th August 2019, 06:49 PM |#5511  
Senior Member
Thanks Meter: 17
 
More
Quote:
Originally Posted by Ramihyn

For once, I have to confirm an issue which has been reported before by others on the net:

Since I upgraded my OP6 to Android Pie, I have an issue when using the phone as tethering hotspot for my work notebook by WiFi.
Apparently the DNS resolution does not work any longer despite the usual commonly known rules. At github the issue has been discussed since end of 2018 but is still unresolved. That thread mentioned UID 1052 (some strange unknown app uid) as being blocked by AFWall+, filling up the logfile with the DNS requests of my notebook. At some reddit forum I learned that UID 1052 indeed is dnsmasqd in Android Pie, so I applied some custom script, and voilà, DNS resolution suddenly works again through tethering.

Some side checks (disabling the firewall completely as well as trying "nslookup targetdomain.com 8.8.8.8" without that custom script) confirmed without any doubt that AFWall+ is the culprit here, because UID 1052 does not show up in the apps list, and in whitelist mode this results clearly in these blocking of the DNS requests from the tethering clients.
At the same time, though, DNS lookups work fine directly on the OP6 at any time.

It would be great if you could please post the script that resolved this for you.

Thanks!
The Following User Says Thank You to markd89 For This Useful Post: [ View ] Gift markd89 Ad-Free
30th August 2019, 07:53 PM |#5512  
Member
Thanks Meter: 20
 
More
This:
Code:
#!/system/bin/sh

IPTABLES=/system/bin/iptables
IP6TABLES=/system/bin/ip6tables

$IPTABLES -I afwall-wifi-tether -p udp -m owner --uid-owner 1052 -m udp --sport 67 --dport 68 -j RETURN
$IPTABLES -I afwall-wifi-tether -p udp -m owner --uid-owner 1052 -m udp --sport 53 -j RETURN
$IPTABLES -I afwall-wifi-tether -p tcp -m owner --uid-owner 1052 -m tcp --sport 53 -j RETURN

$IP6TABLES -I afwall-wifi-tether -p udp -m owner --uid-owner 1052 -m udp --sport 67 --dport 68 -j RETURN
$IP6TABLES -I afwall-wifi-tether -p udp -m owner --uid-owner 1052 -m udp --sport 53 -j RETURN
$IP6TABLES -I afwall-wifi-tether -p tcp -m owner --uid-owner 1052 -m tcp --sport 53 -j RETURN
Source: Github dicussion thread for AFWall+

Btw: I have recognized that this issue has been discussed in this thread in early march this year alreay, but strangely with neither an identification of the UID 1052 nor a proper solution for the issue. The custom script does not count as solution either, it is merely a workaround for me until AFWall+ fixes this properly.

Edit, further info: apparently the issue rises the very moment that one disables netd and allow internet access to root apps (to get control of the DNS requests). So the proper solution should be simple: as soon as netd is disabled, AFWall+ has to automatically apply these additional rules I quoted above.
The Following 3 Users Say Thank You to Ramihyn For This Useful Post: [ View ] Gift Ramihyn Ad-Free
4th September 2019, 10:19 AM |#5513  
Member
Flag sesto fiorentino
Thanks Meter: 1
 
More
Hi,
Do somebody know if carrier service app should be enabled for working properly or can be disabled?
Thanks
Attached Thumbnails
Click image for larger version

Name:	IMG_20190904_111531.jpg
Views:	290
Size:	9.7 KB
ID:	4815006  
9th September 2019, 05:06 PM |#5514  
Senior Member
Flag BC
Thanks Meter: 23
 
More
I have an issue with some installed apps not showing in latest afwall Donate. (Google Photos, Gboard and others) I have looked and searched in All, Core, System and User just to be sure. I uninstalled and reinstalled afwall, same.
Pixel 2 XL Pie 9 COSP MicroG
9th September 2019, 06:43 PM |#5515  
Senior Member
Thanks Meter: 17
 
More
Quote:
Originally Posted by Brenneke

I have an issue with some installed apps not showing in latest afwall Donate. (Google Photos, Gboard and others) I have looked and searched in All, Core, System and User just to be sure. I uninstalled and reinstalled afwall, same.
Pixel 2 XL Pie 9 COSP MicroG

Do you have xPrivacy LUA installed? I initially had this problem and realized that I had forgotted to give AFWall Read Applications rights.
9th September 2019, 08:36 PM |#5516  
Senior Member
Flag BC
Thanks Meter: 23
 
More
Quote:
Originally Posted by markd89

Do you have xPrivacy LUA installed? I initially had this problem and realized that I had forgotted to give AFWall Read Applications rights.

I do not have xprivacy intalled. Afwall has all permissions. I uninstalled and reinstalled again, same. I uninstalled Photos app and reinstalled, still not showing in afwall.
10th September 2019, 03:31 AM |#5517  
Senior Member
Flag BC
Thanks Meter: 23
 
More
I have mixed progress to report - turned "Enable notifications" in afwall on, reinstalled Gboard and Photos - afwall detected the installations. I then reinstalled another app (multiple times) that was not showing and afwall just does not see it.
I then installed Netguard, it sees all the apps.
I will continue using Netguard unless a resolution to this can be found. I do prefer afwall however.

---------- Post added at 03:31 AM ---------- Previous post was at 03:25 AM ----------

Just realized that the other app that will not show in afwall does not ask for network permission - could this be why afwall does not ahow it?
10th September 2019, 05:25 AM |#5518  
Recognized Contributor
Thanks Meter: 3,246
 
More
Quote:
Originally Posted by Brenneke

. . .

Just realized that the other app that will not show in afwall does not ask for network permission - could this be why afwall does not ahow it?

Yes. If the app has no ability to access the network it won't show in afwall
10th September 2019, 05:35 AM |#5519  
Senior Member
Flag BC
Thanks Meter: 23
 
More
Quote:
Originally Posted by jcmm11

Yes. If the app has no ability to access the network it won't show in afwall

Still does not explain why Google Photos and Gboard were not showing. I just checked my second indentical phone with same setup, those two apps also not showing- was able to do same routine to fix.
10th September 2019, 06:50 AM |#5520  
amg314's Avatar
Senior Member
Flag Kharkov
Thanks Meter: 166
 
More
Quote:
Originally Posted by Brenneke

Still does not explain why Google Photos and Gboard were not showing. I just checked my second indentical phone with same setup, those two apps also not showing- was able to do same routine to fix.

I use AFWall+ v.2.9.9(Donate). It show Photos in menu (Gboard was removed).

Thus, this is your device problem))
Attached Thumbnails
Click image for larger version

Name:	Screenshot_20190910-084705.png
Views:	724
Size:	194.2 KB
ID:	4817555  
10th September 2019, 08:01 AM |#5521  
rottenwheel's Avatar
Senior Member
Thanks Meter: 398
 
Donate to Me
More
I am running AFWall+ along with its unlock tiny apk since that is the way I got the paid version of AFWall+ on an Android 9 (Pie) stock ROM, unlocked bootloader, rooted with magisk. Unfortunately, I've been running into some strange issues with APN and WiFi: WiFi says No Internet connection despite of the fact I can stream media and chat in instant messaging applications without a problem, of course it has the classic X icon that tells you it is not communicating with Google's servers as intended. Mobile data works on/off albeit I double checked APN values with my carrier. What could it be? I imported the rules from a Nougat set-up.

Edit: fixed by allowing 'Google'.
Attached Thumbnails
Click image for larger version

Name:	x.jpg
Views:	716
Size:	59.4 KB
ID:	4817565  
Post Reply Subscribe to Thread

Tags
block internet, droidwall, firewall, iptables, security

Guest Quick Reply (no urls or BBcode)
Message:
Previous Thread Next Thread
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes