"You can get all current and future NetGuard pro features (including updates) without Google Play services for the GitHub or F-Droid version by a one time donation of € 0.10 or more. If you donate 7 euros or more, you can activate the pro features on all Android devices you personally own, else you can activate the pro features one time only."
An alternative android root only option is afwall+ which allows blocking on lte, WiFi, lan, and VPN separately, and script access to iptables. Not sure how actively developed it is, but it seems to work ok.
*edit: Seems to still be active, open source, and available on fdroid too.
NetGuard is simply awesome. The piece of mind when I know which servers the apps are contacting, and being able to block their access to the net by default, is just great. The rules could be made a bit more easily adjustable (it would be nice if I could block `*.firebaseinstallations.googleapis.com` everywhere, even if other traffic is allowed for the app), but I'm just nitpicking now. Highly recommend it.
Without root only VPN solutions like Adguard are available.
EDIT: if you want neat stats: Glasswire has an Android version. I have only used the beta so I have no idea about its current state. Might be worth checking out though.
> Sadly all real firewalls need root
What do you mean by a "real" firewall? It is very much possible to build a userspace firewall in Android using the VPN APIs.
On Android, ROMs like GrapheneOS, Lineage, and CalyxOS have firewalls built-in.
> Glasswire has an Android version
Note though, Glasswire was recently acquired by another company: https://archive.is/KW2R3
Ah that's why the premium stuff is now free. I was wondering. Let's hope it's not the first sign of enshittification.
> What do you mean by a "real" firewall?
In my experience the "block all non VPN traffic" options in Android don't work reliably. iptables does however.
It's a sad state that you cannot even set a static IPv6 on Android without root.
Both (iptables/nftables and VPN APIs) have to be enforced by the Linux Kernel, which is subject to the same "Androidisms", if that makes sense.
root, in fact, opens up a gaping hole in that, it totally compromises Android's security model. IMO, it isn't worth to root Android just to run iptables (just because it seems like iptables is what makes a firewall).
I think device you don't have root on isn't really yours and should be treated as a lease.
But you are right, when Wifi/Data is on at boot even the -tables might not get updated fast enough so stuff might get through.
Would you mind elaborating?
I appreciate you trying to add to the discussion but in this case you leave me with way more questions than I started out with which I personally perceive as an unwanted mental overhead.
What I mean is by watching the IPs, I see a lot of cross-border ingress/egress when it shouldn't be necessary. It's not proof, but an indicator of probability to me, that echelon style mechanisms are being used.
If you are unaware of echelon and related programs, essentially, since it's illegal for the US (officially at least) to spy on it's own citizens without a warrant, instead they let an "ally" country like the UK spy on Americans and then "share the data", essentially another abuse of third party doctrine.
I hope that helps clarify.
Switched to it from NetGuard mentioned above.
Doesn't stop direct IP connections, but it's good enough.
I also have the CLI installed on OpnSense so DoH is enforced for all devices on my LAN as well.