[5.0+][ROOT][3.6.0] AFWall+ IPTables Firewall [28 AUG 2023]

Search This thread

eriol1

Senior Member
Feb 16, 2015
218
157
I have these blocked, and practically all other system apps as well.
I can see lots of stuff getting blocked in the logs, but everything works fine
 

Attachments

  • Screenshot_20210208-230733_AFWall+.png
    Screenshot_20210208-230733_AFWall+.png
    49.1 KB · Views: 133
  • Like
Reactions: twiice

iunlock

Senior Member
May 22, 2010
2,005
976
Galaxy
Hello fellow AFWall+ users, I'm having VPN connectivity issues with AFWall+ enabled with Android 11. I tried everything. I've since rolled back to Android 10 and I'm having the same issues. It's driving me crazy.

With AFWall+ Enabled and with VPN connected, browsers work, but apps like Playstore does not work.

It's nothing that I have blocked either in AFWall+ I made sure of it.. in fact, I tested it by unchecking everything but one random non related thing to anything and the problem persists.

I was using the v3.5.0 beta and thought it had something to do with it being beta, but I've also tested on v3.4.0 and it's having the same issues.

Q: In Preferences-> Binaries ->

Iptables binary: Should this be set to Auto or choose one System or Built-in?

BusyBox binary: Should this be selected on Built-In or System?

Thanks for your help.
 
Last edited:

temporarium

Senior Member
Hello fellow AFWall+ users, I'm having VPN connectivity issues with AFWall+ enabled with Android 11. I tried everything. I've since rolled back to Android 10 and I'm having the same issues. It's driving me crazy.

With AFWall+ Enabled and with VPN connected, browsers work, but apps like Playstore does not work.

It's nothing that I have blocked either in AFWall+ I made sure of it.. in fact, I tested it by unchecking everything but one random non related thing to anything and the problem persists.

I was using the v3.5.0 beta and thought it had something to do with it being beta, but I've also tested on v3.4.0 and it's having the same issues.

Q: In Preferences-> Binaries ->

Iptables binary: Should this be set to Auto or choose one System or Built-in?

BusyBox binary: Should this be selected on Built-In or System?

Thanks for your help.
Try the whitelist method, only allowing what you need.

Also, it may be Google is sensing that you're using very different IPs to connect and is blocking your VPN. Try Aurora Store.
 
  • Like
Reactions: IronTechmonkey

iunlock

Senior Member
May 22, 2010
2,005
976
Galaxy
Try the whitelist method, only allowing what you need.

Also, it may be Google is sensing that you're using very different IPs to connect and is blocking your VPN. Try Aurora Store.

Thanks for your response. Regarding the binaries and any other specifics settings that's recommended to use:

Q: In Preferences-> Binaries ->

Iptables binary: Should this be set to Auto or choose one System or Built-in?

BusyBox binary: Should this be selected on Built-In or System?

Thanks for your help.
 

n0j0e

Senior Member
hi, is the AFWall Xposed extension still functional for A11? Do we still need it for more security. I'm switched to the LSPosed Xposed variante and AFWall (still) didn't support the new app scope feature like GravityBox.
Which apps needs to be enabled in LSPosed for the AFWall module?
 
Last edited:

SilentDevGuy

Senior Member
Feb 10, 2021
81
24
That's dangerous advice. When it comes to Android system, LineageOS, and Google stuff, how do you define "everything"? If you block everything some phones might brick on boot or just stop working.

Meanwhile the AFWall+ FAQ referenced above recommends leaving almost all system & google apps unblocked or risk restricted operation.
Blocking stuff in afwall+ will never cause a brick on boot or your phone to stop working, thats ludicrous. Iptables is reset on boot.
 

eriol1

Senior Member
Feb 16, 2015
218
157
Is it safe to disable all connections on gps?
I use GPS in what used to be called "device only" mode, and it still works when blocked.
Maybe high accuracy mode which uses also bluetooth/wifi/cell won't work? Haven't tried.

Anyway I'm guessing results might be different on other device/os combinations, so just try blocking and see if it works for you. If not simply change it back, no harm done.
 
  • Like
Reactions: IronTechmonkey

IronTechmonkey

Recognized Contributor
Feb 12, 2013
10,055
18,112
Is it safe to disable all connections on gps?

I use GPS in what used to be called "device only" mode, and it still works when blocked.
Maybe high accuracy mode which uses also bluetooth/wifi/cell won't work? Haven't tried.

Anyway I'm guessing results might be different on other device/os combinations, so just try blocking and see if it works for you. If not simply change it back, no harm done.

Safe? Yes absolutely, you won't damage anything by blocking GPS. Also, regarding a recent concern that was expressed about blocking everything, it is safe to block just about any app or service. Some things may not work but they won't break. If they did we sure would have trouble when disconnected from the internet.

As to functionality, to @eriol1's point, "device only" GPS does not seem to require any data connection even for the GPS service on the device. That being said, there are some 3rd party GPS utilities which will download a file possibly containing a list of satellites or other data but those request seemed to be made by the app which can be blocked. Another consideration is Google's ongoing attempt to obfuscate our granular control of location services. For instance, in newer versions of Android we can no longer simply enable “device only” mode. We must now manually disable the internet based location services. LOL, pardon that rant but this is one of my pet peeves about Google and one of the reasons I use Afwall+
 
Last edited:

temporarium

Senior Member
Safe? Yes absolutely, you won't damage anything by blocking GPS. Also, regarding a recent concern that was expressed about blocking everything, it is safe to block just about any app or service. Some things may not work but they won't break. If they did we sure would have trouble when disconnected from the internet.

As to functionality, to @eriol1's point, "device only" GPS does not seem to require any data connection even for the GPS service on the device. That being said, there are some 3rd party GPS utilities which will download a file possibly containing a list of satellites or other data but those request seemed to be made by the app which can be blocked. Another consideration is Google's ongoing attempt to obfuscate our granular control of location services. For instance, in newer versions of Android we can no longer simply enable “device only” mode. We must now manually disable the internet based location services. LOL, pardon that rant but this is one of my pet peeves about Google and one of the reasons Afwall+
<OT> There is also microG with alternative geolocation backends. </OT>
 

savelbys

Member
Mar 9, 2020
34
9
Hello,

does anyone know how I can remove the x/no internet connection possible at the WLAN icon in Android 11 LineageOS 18.1?
I assume this has something to do with the captive portal check.
To solve the problem in the short term, you have to disable the firewall, turn WLAN off/on and enable it again. However, after a reboot the problem still persists.

I have already tried the following which unfortunately does nothing, but worked on Android 10:

su
setenforce 0
settings put global captive_portal_mode 0
setenforce 1

and

su
su
pm disable com.android.captiveportallogin
settings put global captive_portal_detection_enabled 0
settings put global captive_portal_server localhost
settings put global captive_portal_mode 0
reboot
 

Hiroo Onoda

Member
Apr 22, 2019
49
24
Hello,

does anyone know how I can remove the x/no internet connection possible at the WLAN icon in Android 11 LineageOS 18.1?
I assume this has something to do with the captive portal check.
To solve the problem in the short term, you have to disable the firewall, turn WLAN off/on and enable it again. However, after a reboot the problem still persists.

I have already tried the following which unfortunately does nothing, but worked on Android 10:

su
setenforce 0
settings put global captive_portal_mode 0
setenforce 1

and

su
su
pm disable com.android.captiveportallogin
settings put global captive_portal_detection_enabled 0
settings put global captive_portal_server localhost
settings put global captive_portal_mode 0
reboot

It's been a while since I set AFWall up on my Android 11, so I can't tell you exactly. Also, I don't have Lineage, just stock Android 11. I have allowed connection on the following system apps and got the x to go away, so I believe they may be related:

[-11] Linux kernel
[1073] Tethering, Cell Broadcast Service, Network manager, com.android.server.NetworkPermissionConfig
 

q1nt

Member
Apr 26, 2020
20
6
For AFW+ to work, do I need to leave super user access enabled (using Magisk) aways? Or can I disable su access after setting up AF+ the first time? Reason is I prefer to leave su disabled for a bit more security when I'm out running around.

Background: I'm rooted but now using Netguard. Considering switching to AFW+ so I can use another VPN.
 

starbright_

Senior Member
Apr 11, 2010
1,471
262
My knowledge becomes a bit outdated after switch to Android 11 (debloated Stock with microG).

From system side I blocked everything except Download Manager. But I found that Network manager is required to use Aurora (Playstore replacement).
Is this ok? Other things I have to take into account?
 

SilentDevGuy

Senior Member
Feb 10, 2021
81
24
My knowledge becomes a bit outdated after switch to Android 11 (debloated Stock with microG).

From system side I blocked everything except Download Manager. But I found that Network manager is required to use Aurora (Playstore replacement).
Is this ok? Other things I have to take into account?
What happens to aurora store if you have network manager blocked?
 

greatestandroidfan

Senior Member
Aug 12, 2010
89
26
Not on Github, therefore here: 1+8 with crDroid 7.4 (A11). After every boot, firewall enables with rules error. Need to wait like 2min, then disable and re-enable firewall again to get it running w/o errors.
Yes, could set the boot delay option, but I want protection even while booting.
 

Top Liked Posts

  • There are no posts matching your filters.
  • 404
    Welcome to official support page for AFWall+

    Disclaimer - As Usual. I'll not take any responsible if something goes wrong when using AFWall+

    Introduction
    AFWall+ is an improved version of DroidWall(front-end application for the powerful iptables Linux firewall). It allows you to restrict which applications are permitted to access your data networks (2G/3G/4G/LTE and/or Wi-Fi and while in roaming).Since the original author of Droidwall
    discontinued the project, I decided to keep the app instead of Avast Firewall. I'll continue to add more features as I can.


    Features
    - Supports 5.x to 13.x
    - Import/Export Rules to external storage
    - Search Applications
    - Multiple Profiles with custom names
    - Tasker/Locale support
    - Select All/None/Invert/Clear applications with single click
    - Revamped Rules/Logs Viewer with copy/export to external storage
    - Ability to view the network interfaces
    - Highlight system applications with custom color
    - Notify on new installations
    - Ability to hide application icons( faster loading )
    - Use LockPattern for application protection.
    - Show/Hide application ID.
    - Roaming Control for 3G/Edge
    - VPN Control
    - LAN Control
    - Tether Control
    - IPV6 Control
    - Tor Control
    - Choose able languages
    - Choose able iptables/busybox binary
    - Supports MIPS/x86/ARM
    - DNS Hostname

    Changelog - See third Post
    Current Version - 3.6.0

    To get Unlocker without Google services - Please follow the instructions here

    AFWall+ BETA Program
    1) AFWall+ opt-in for beta program
    2) Install AFWall+ and If you have any issues, just send email from (Menu -> Firewall Rules - > Send error report)

    Source Code/Wiki/FAQ
    AFWall+ is an free & opensource application
    Github
    Log an issue
    Frequently Asked Questions
    Many Thanks to @CHEF-KOCH

    Translations
    Translations - Please help me with translations in your language.
    http://crowdin.net/project/afwall

    Thanks To/Credits
    - German translations by chef@xda & user_99@xda & Gronkdalonka@xda
    - French translations by GermainZ@xda & Looki75@xda
    - Russian translations by Kirhe@xda & YaroslavKa78
    - Spanish translations by spezzino@crowdin
    - Dutch translations by DutchWaG@crowdin
    - Japanese translation by nnnn@crowdin
    - Ukrainian translation by andriykopanytsia@crowdin
    - Slovenian translation by bunga bunga@crowdin
    - Chinese Simplified translation by tianchaoren@crowdin
    - Polish translations by tst,Piotr Kowalski@crowdin
    - Swedish translations by CreepyLinguist@crowdin
    - Greek Translations by mpqo@crowdin
    - Portuguese translations by lemor2008@xda
    - Chinese Traditional by shiuan@crowdin
    - Chinese Simplified by wuwufei,tianchaoren @ crowdin
    - Italian translations by benzo@crowdin
    - Romanian tranlations by mysterys3by-facebook@crowdin
    - Czech translations by Syk3s

    Cheers,
    ukanth

    XDA:DevDB Information
    AFWall+ [ IPTables Firewall ], App for the Android General

    Contributors
    ukanth
    Source Code: https://github.com/ukanth/afwall


    Version Information
    Status:
    Stable
    Current Stable Version: 3.5.3
    Stable Release Date: 2022-06-28
    Current Beta Version:
    3.5.3
    Beta Release Date: 2022-06-28

    Created 2013-12-03
    Last Updated 2020-09-05
    70
    Version 3.0.1

    * Fix: Status toggle widget 1x1
    * Fix: Ability to hide ongoing notification (Stop firewall and restart to hide after disable it in preferences)
    * Fix: Firewall error notification on oreo and above
    * Security: Tile toggle checks for password
    * User reported crashes
    * Updated translations

    Previous version 3.0.0

    Features:
    * Better support for nougat/oreo and pie.
    * Firewall toggle tile
    * Adaptive Icons
    * Notification channels
    * Tor support

    Bugs:
    * General bug fixes and crash reports.
    * Language selection bug
    * Filter selection bug
    * Compatible with magisk 17.x
    * Better handling of background process
    * Drops support for 4.x devices
    * Update languages
    * Updated libraries

    Complete Changelog

    41
    Hello All,

    After careful analysis and testing, I decided not to rewrite the way rules are being applied due to lot of under hood changes required. Instead added few enhancements. Now applying rules from menu will show how many rules are getting applied with progress status. Also when adding/removing few rules , it will apply only those related rules instead of full apply.

    Also fixed couple of bugs and enhancements. You can get the full changelog from https://github.com/ukanth/afwall/blob/beta/Changelog.md

    This is BETA Version which is not released on playstore. I have been using this for past week and it's stable. But there might be bugs which I haven't encountered. Please test it and report it in case of any issues.

    Also I have been following XPrivacy thread on the decision by it's author. Just as FYI, I might fix it for my own usage when I update to nougat, I will share it here if anybody uses it here.

    BETA Link - https://www.dropbox.com/s/isvi413qyx6vb4d/AFWall+ 2.9.7-BETA-TESTER.apk?dl=0
    40
    Hello everyone,

    I have released 3.0.0 stable on playstore today. It's been a crazy month so far. After going through lot of dilemma of whether to support the existing afwall or write a new one from scratch, finally able to pull myself and release stable version of afwall with lots of bug fixes and new features along with pie support. Since I don't do full time Android development, it was hard to keep track of what's going on with sdk level changes.

    Thank you all for your support in AFWall+ development. Without your support it would simply not possible to pull through this.

    I will be out for couple of days ( taking off to spend time with my family ) and hopefully will be able to reply to questions once back.

    Thanks again and have a great day.
    35
    Hello everyone,

    I have released stable version of 3.1.0 to playstore and github. Its live on playstore. You can find the changelog along with md5/sha here

    https://github.com/ukanth/afwall/releases/tag/v3.1.0

    Thank you all for your continuous support in AFWall+ development.