Overview
Developed by Rem01Gaming, Net Switch is a systemless firewall utility designed to isolate individual Android applications from accessing mobile data and Wi-Fi networks.
Many Android apps transmit telemetry, analytics, and background ads even when not in active use. While conventional firewalls rely on Android’s VpnService—which drains battery, increases latency, and prevents concurrent VPN usage—Net Switch applies native Linux iptables drop chains directly at the kernel network boundary.
Technical Architecture & How It Works
UID-Based Iptables Filtering
Net Switch operates at the Linux packet-filtering layer:
- UID Group Resolution: Every Android application runs under a unique Linux User ID (UID). Net Switch maps packages to their assigned UIDs.
- Iptables Chain Injection: Creates custom filter chains (
OUTPUT -m owner --uid-owner <UID> -j DROP) to discard outgoing socket requests from isolated apps immediately. - Instant Rule Switching: Changes applied in the WebUI take effect instantly in kernel memory without requiring device reboots.
Installation & Setup
- Download the latest
Net-Switch-*.ziprelease. - Flash the module in Magisk, KernelSU, or APatch.
- Reboot your device.
- Launch the WebUI (from KernelSU/APatch manager or via MMRL on Magisk).
Configuration & Usage
Inside the Net Switch WebUI:
- Application Toggles: Tap any installed application to toggle its internet connectivity.
- Profiles: Group apps into profiles (e.g. “Work Mode”, “Offline Games”) to switch firewall policies with a single tap.
- Backup & Restore: Export your isolation rules as JSON to restore them after ROM flashes.
Troubleshooting & Common Issues
- Isolated App Still Connecting: Ensure you have selected all auxiliary helper packages associated with the app (e.g. companion media downloaders or sync daemons).
Frequently Asked Questions
Why is Net Switch better than VPN-based firewalls like AFWall+?
AFWall+ and standard firewall apps often run a continuous local VPN service or background daemon that consumes battery, adds processing overhead, and blocks you from connecting to authentic VPNs. Net Switch applies raw Linux iptables drop rules directly to application UIDs, operating with zero battery overhead.
How do I access the Net Switch interface on Magisk?
Since official Magisk lacks an embedded WebUI viewer in its manager, you can open Net Switch's WebUI using standalone WebUI hosts such as MMRL or KsuWebUIStandalone.
