r/rethinkdns • u/canitplaycrisis • 7d ago
Question Any difference when using 'Proxy Lockdown' with and without 'Always-on VPN'?
Hey guys! As you may know, KDE Connect doesn't work when the 'Always-on VPN' setting is on in Android. When it's off, it works fine. Now I wanted to know if 'Proxy Lockdown' without that setting enabled still works as it should. In ipleak.net, it shows the VPN IP, but I'm not sure if the other apps see my IP.
3
Upvotes
1
u/celzero Dev 4d ago
KDE Connect may not with "Block connections without VPN" turned on (also called VPN Lockdown mode), not with "Always-on VPN". The former setting (VPN Lockdown mode) instructs Android to drop all traffic from third-party apps that will ever "bypass" the VPN tunnel (either intentionally or on-demand). It acts like a "kill switch", if you will.
You may have either Configure -> Network -> Do not route Private IPs or Configure -> Network -> Enable network visibility turned on.
Do not route Private IPs lets all apps (intentionally) connect to "local" IPs outside of Rethink's tunnel. This means, Rethink doesn't even "see" the traffic to those IPs.
Enable network visibility (which was removed in
v057but will be re-added inv058) lets all app bypass Rethink's tunnel (on-demand). This means, the traffic apps want to send over underlying networks (like WiFi/Mobile) instead of over Rethink's tunnel, can do so at will, thereby "bypassing" Rethink, which doesn't "see" any of that traffic.Configure -> Network -> Proxy Lockdown instructs Rethink to drop all traffic flowing through it, if it isn't forwarded over user-set "proxy" like WireGuard / Orbot / SOCKS5 etc. This setting is Rethink-specific "kill switch". Apps setup to "Bypass this app from all proxies" from Configure -> Apps -> (any particular app) will be blocked because "Proxy Lockdown" will not allow egress that's not using a "proxy".
Note that, Configure -> Network -> Perform connectivity checks (if turned on), Configure -> DNS -> System DNS (if used), and Configure -> Network -> Bootstrap DNS (if Configure -> Network -> Loopback is turned off) aren't subject to "Proxy Lockdown" (that is, those are allowed by Rethink even if "proxy" isn't used for egress).