# NetGuard: a no-root Android firewall that filters per app over the VPN service

> NetGuard blocks internet access per application and per address on Android 5.1 and later without root, by routing traffic through the Android VPN service. It is free, GPL-3.0, and installs from GitHub or Google Play, but it cannot run next to another VPN and has known limits on work profiles, wired connections and some ROMs.

**M66B/NetGuard** — A simple way to block access to the internet per app

- Repository: https://github.com/M66B/NetGuard
- Website: http://www.netguard.me/
- Stars: 3,905 · Forks: 362
- Language: Java
- License: GPL-3.0
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/m66b-netguard

## What NetGuard blocks, and for whom

NetGuard is a firewall for Android that works per application and per address. The README frames the goal as reducing data usage, saving battery and increasing privacy by denying apps access to the internet. The unit of control is the app: each entry in the list gets separate Wi-Fi and mobile toggles, so a chat client can be allowed on Wi-Fi and denied on cellular, or the reverse.

The target user is someone on a stock or lightly modified phone who does not want to root it. Root firewalls like the iptables-based tools require superuser access; NetGuard's README states it is the first free and open source no-root firewall for Android, and that it works on rooted devices too. The README also claims it offers more features than most root firewalls, which is a marketing statement rather than a verified comparison.

The project is GPL-3.0, written in Java, and the repository ships the app module, a fastlane directory for store metadata, and a tools directory alongside the usual Gradle files. Releases are tagged on GitHub, with 2.337 pushed on 2026-08-01, so the codebase is still receiving commits.

## How the VPN service becomes a firewall

Android has no per-app network permission that a normal app can toggle. The only mechanism available without root is the VPN service: an app declares a VpnService, and Android routes the device's traffic through it. NetGuard uses that slot to inspect and drop packets instead of tunneling them to a remote server. The README states plainly that this is the only way to build a no-root firewall on Android.

That design decision produces the project's most important constraint. Android does not allow chaining VPN services, so NetGuard cannot run at the same time as another VPN app. The README links to its own FAQ on the subject rather than pretending otherwise. A user who needs a commercial VPN and a firewall has to choose, or find a VPN client that includes filtering.

Filtering happens on IPv4 and IPv6, TCP and UDP, and the README lists tethering as supported. Optional behaviours include allowing access while the screen is on, blocking while roaming, blocking system applications, forwarding ports to external addresses, notifying on access, and recording usage per app per address. Several of those, including port forwarding and hosts-file ad blocking, are marked as unavailable in the Play Store build, which is a distribution difference rather than a code difference.

## Installing NetGuard from GitHub and making a first rule

The README points to two download locations: the GitHub releases page and Google Play under the package eu.faircode.netguard. It also publishes certificate fingerprints (MD5, SHA1 and SHA256) so a user can confirm the APK they install is the one the project signed. If you install from GitHub rather than Play, you will not get Play's automatic updates, and you will need to sideload each new release yourself.

There is no build-from-source tutorial in the README, but the repository root contains gradlew and settings.gradle along with an app module, which is the standard Android Gradle layout. Building locally would require the Android SDK; the README does not document the build steps, so treat that path as unsupported by the documentation.

After installing, the README's usage section is short and concrete. The firewall is turned on with the switch in the action bar, and each app's Wi-Fi and mobile access is set with the icons on the right side of the list:

```text
Enable the firewall using the switch in the action bar
Allow/deny Wi-Fi/mobile internet access using the icons along the right side of the application list
```

Colour is the state indicator. Red, orange, yellow or amber means internet access is denied; teal, blue, purple or grey means it is allowed. The settings menu switches between blacklist mode (allow everything, then block chosen apps) and whitelist mode (block everything, then allow chosen apps). Most people start in blacklist mode, block a handful of noisy apps, and only move to whitelist mode when they want a stricter default.

The README also documents a recovery command for one specific failure. If the package com.android.vpndialogs has been disabled, NetGuard will not work or will crash, and the package can be re-enabled over ADB:

```bash
adb shell pm enable --user 0 com.android.vpndialogs
```

That command requires a working ADB connection to the device. It is the only shell command the README gives for NetGuard itself.

## Where NetGuard fails or is the wrong tool

The compatibility section is unusually honest, and it should be read before installing rather than after. NetGuard is not supported for apps in a work profile, in Samsung's Secure Folder, as a second instance on MIUI, as a Parallel app on OnePlus, or as a Xiaomi dual app. The reason given is that the Android VPN service does not work correctly in those contexts and the problem cannot be fixed from inside NetGuard.

Wired connections are out too. Ethernet and USB internet connections are not supported because the Android VPN service often does not behave properly there. Incoming connections are also impossible: Android does not allow them and the VPN service has no support for them, so running a server on the phone and managing its inbound traffic is not something NetGuard can do.

Device support is narrower than the Android version range suggests. NetGuard requires a true-colour screen, so televisions and car head units are excluded, which rules out the common idea of installing it on a Fire TV stick. Some older Samsung Android builds have a buggy VPN implementation that refuses to start the service when there is no connectivity yet or when it demands manual approval again; the README says NetGuard tries a workaround and removes the error message if it succeeds, otherwise the user is out of luck. Some LineageOS versions have a broken VPN implementation that blocks all traffic, and on GrapheneOS the Always-On VPN sub option Block connections without VPN is enabled by default and will block everything.

Calls are a separate failure mode. Wi-Fi or IP calling will not work when the carrier uses IPsec to encrypt calls, SMS or MMS, unless the project has added an exception for that carrier. The README names T-Mobile and Verizon as current exceptions and asks for MCC, MNC and IP ranges to add more. The alternative offered is the Disable on call option, available since version 2.113. Finally, filtering mode cannot be used on CopperheadOS.

## NetGuard against a root firewall or a filtering VPN

The obvious alternative is a root firewall built on iptables or nftables, which can filter without occupying the VPN slot because it operates in the kernel rather than through a userspace service. That difference matters: a root firewall leaves the VPN slot free for a real VPN, and it can handle wired interfaces that the VPN service does not. The cost is root, which many users will not grant, and the README argues NetGuard offers more features than most root firewalls even on rooted devices.

The second alternative is a commercial VPN client that includes its own split tunneling or per-app blocking. That keeps one app in the VPN slot, but split tunneling in those clients is usually a simple allow or deny list without per-address rules, logging, PCAP export or hosts-file ad blocking. NetGuard's PRO features, which include logging all outgoing traffic, searching and filtering access attempts, exporting PCAP files, per-address rules per app, a network speed graph and five extra themes, have no direct equivalent in a typical VPN client.

A third option is a DNS-based blocker, which filters by domain rather than by app and therefore cannot stop an app from talking to a hardcoded IP address. NetGuard's ad blocking uses a hosts file per the linked ADBLOCKING.md, and that file is not available in the Play Store build, so the GitHub release is the one to use if hosts-file blocking is the reason you are installing it.

## Licence, maintenance and upgrade cost

NetGuard is GPL-3.0. For an end user installing the APK, the practical effect is that the source must remain available under the same licence, which it is on GitHub. For anyone embedding NetGuard's code in another product, GPL-3.0 carries copyleft obligations that a permissive licence would not; that is a question for a lawyer, not for this article.

The repository is not archived and the last push was on 2026-08-01, with releases 2.337, 2.336 and 2.335 in the months before. That is a maintained project by any reasonable reading, but the README's own claim of being actively developed is a claim, not a guarantee, and the release cadence is the thing to check if you are deciding today.

The upgrade cost depends on the channel. Play Store installs update automatically. GitHub installs do not, so a user on the sideloaded build has to watch releases and reinstall, and has to re-verify the certificate fingerprint if they care about that. The PRO features are unlocked in the Play build; the README notes that port forwarding and hosts-file ad blocking are not available there, so a user who wants those has to stay on the GitHub build and accept manual updates. That trade-off is the main ongoing cost of running NetGuard.

## Conclusion

NetGuard suits Android users who want per-app internet control without root and who are willing to give up the single VPN slot. Skip it if you rely on another VPN at the same time, use a work profile or Secure Folder, or need to filter an ethernet or USB connection, because the README states those setups are not supported. Before installing, verify the certificate fingerprint listed in the README against the build you download, and check the compatibility notes for your Android version, since some Samsung and LineageOS builds have broken VPN implementations.

## FAQ

### What is NetGuard used for?

NetGuard blocks access to the internet per application on Android, with separate Wi-Fi and mobile toggles for each app, and can also block addresses. The README says this helps reduce data usage, save battery and increase privacy.

### Is the NetGuard app free?

The README describes NetGuard as the first free and open source no-root firewall for Android, and the repository is licensed GPL-3.0. Some features are labelled PRO, and port forwarding and hosts-file ad blocking are not available in the Play Store build.

### How do I install NetGuard on Android?

Downloads are listed for GitHub releases and for Google Play under the package eu.faircode.netguard, and the README requires Android 5.1 or later. The README also publishes MD5, SHA1 and SHA256 certificate fingerprints so the installed build can be checked.

### How do I use NetGuard to block ads?

The README lists blocking ads using a hosts file as an optional feature and links to ADBLOCKING.md for it. That feature is not available if NetGuard is installed from the Play Store, so the GitHub build is the one to use.

### Can I use NetGuard together with a VPN?

No. Android does not allow chaining of VPN services, and the README states that NetGuard therefore cannot be used together with other VPN based applications.

### Does NetGuard work on a Fire TV stick?

The README says NetGuard is supported on phones and tablets with a true-colour screen only, and not on other device types such as a television or a car. A Fire TV stick is not covered by that support statement.

## Sources

- [License: GPL-3.0](https://github.com/M66B/NetGuard/blob/master/LICENSE)
- [M66B/NetGuard on GitHub](https://github.com/M66B/NetGuard)
- [Project website](http://www.netguard.me/)
- [README](https://github.com/M66B/NetGuard/blob/master/README.md)
- [Releases](https://github.com/M66B/NetGuard/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/m66b-netguard
