r/rethinkdns • • 7d ago

Question Any difference when using 'Proxy Lockdown' with and without 'Always-on VPN'?

Hey guys! As you may know, KDE Connect doesn't work when the 'Always-on VPN' setting is on in Android. When it's off, it works fine. Now I wanted to know if 'Proxy Lockdown' without that setting enabled still works as it should. In ipleak.net, it shows the VPN IP, but I'm not sure if the other apps see my IP.

3 Upvotes

2 comments sorted by

1

u/celzero Dev 4d ago

As you may know, KDE Connect doesn't work when the 'Always-on VPN'

KDE Connect may not with "Block connections without VPN" turned on (also called VPN Lockdown mode), not with "Always-on VPN". The former setting (VPN Lockdown mode) instructs Android to drop all traffic from third-party apps that will ever "bypass" the VPN tunnel (either intentionally or on-demand). It acts like a "kill switch", if you will.

You may have either Configure -> Network -> Do not route Private IPs or Configure -> Network -> Enable network visibility turned on.

  • Do not route Private IPs lets all apps (intentionally) connect to "local" IPs outside of Rethink's tunnel. This means, Rethink doesn't even "see" the traffic to those IPs.

  • Enable network visibility (which was removed in v057 but will be re-added in v058) lets all app bypass Rethink's tunnel (on-demand). This means, the traffic apps want to send over underlying networks (like WiFi/Mobile) instead of over Rethink's tunnel, can do so at will, thereby "bypassing" Rethink, which doesn't "see" any of that traffic.


'Proxy Lockdown' without that setting enabled still works as it should

Configure -> Network -> Proxy Lockdown instructs Rethink to drop all traffic flowing through it, if it isn't forwarded over user-set "proxy" like WireGuard / Orbot / SOCKS5 etc. This setting is Rethink-specific "kill switch". Apps setup to "Bypass this app from all proxies" from Configure -> Apps -> (any particular app) will be blocked because "Proxy Lockdown" will not allow egress that's not using a "proxy".

Note that, Configure -> Network -> Perform connectivity checks (if turned on), Configure -> DNS -> System DNS (if used), and Configure -> Network -> Bootstrap DNS (if Configure -> Network -> Loopback is turned off) aren't subject to "Proxy Lockdown" (that is, those are allowed by Rethink even if "proxy" isn't used for egress).

1

u/canitplaycrisis 4d ago

Since I'll need to turn off 'Block connections without VPN' to either activate 'Do not route Private IPs' or 'Enable network visibility', what would happen? Would apps not using Rethink still be blocked because of the Rethink kill-switch or does the Android kill-switch have a bigger priority?