Android Always-on VPN: how to enable and test lockdown | NetGuardVPN
GuideNetGuardVPN8 min read

Always-on VPN on Android: automatic connection and lockdown

Learn what Android Always-on VPN and “Block connections without VPN” do, how to turn them on, and how to troubleshoot lost internet access.

Updated:

What Android Always-on VPN does

You can start a VPN manually from its app or Android’s network settings. If you want Android to start the VPN service after a reboot and keep it available without repeated taps, look for Always-on VPN. Android can launch the selected VPN service when the device starts and restart it if the service stops. The feature is available from Android 7.0, but its availability and menu labels depend on the Android version, device maker, and VPN app.

Always-on controls the service lifecycle; it does not guarantee that the VPN can reach a server. The app still needs a valid configuration, internet access, and a working tunnel. For example, the tunnel may need to reconnect when your phone moves from Wi-Fi to mobile data. The app and network determine how that transition goes. Check the app’s status or Android’s VPN indicator instead of treating the setting as proof of a continuous connection.

A related option is Block connections without VPN, sometimes described as lockdown. It tells Android not to let apps use the regular network when traffic is not going through the VPN. If the tunnel is down, apps may lose internet access until it reconnects. The two settings have different jobs: Always-on tries to keep the VPN service running; lockdown prevents apps from bypassing it.

Always-on versus lockdown

Think of Always-on as automatic startup. After a reboot, Android launches the VPN service and can try to restart it if it stops. If ordinary network access is still allowed, apps may be able to use Wi-Fi or mobile data directly when the VPN cannot connect.

Lockdown adds a stricter rule: Android blocks network connections that do not use the VPN. When the tunnel disconnects, apps may no longer load websites, messages, updates, or other online content. That can be the intended result, not a fault with your phone.

On some managed devices, an administrator can also define which apps are allowed or disallowed from using the VPN. Those lists interact with lockdown: an app that is not permitted to use the VPN may lose network access when non-VPN connections are blocked. A personal phone’s standard VPN settings may not offer these managed-app controls. Don’t assume every app is routed the same way; check both the VPN app and Android settings.

Neither feature protects a device from every online risk. A VPN changes network routing; it does not patch app vulnerabilities, replace software updates, or correct a misconfigured client. For a broader connection check, see how to check a VPN connection.

Before you enable the settings

First, confirm that the VPN works when you connect manually. Open the VPN app, select a working profile, and wait for it to show an active connection. If that basic connection fails, Always-on will not fix the cause—it will only ask Android to start the VPN service again.

Next, make sure you know how to find the Android VPN settings and temporarily disable lockdown. If the VPN app is removed, its profile is broken, or the server is unavailable, blocking non-VPN connections can leave the phone offline. Find the settings menu before enabling the feature. On a work- or school-managed device, an administrator may control these options; ask them before changing a managed configuration.

Check for other apps that use Android’s VPN connection. Android generally has one active VPN connection per user or device profile. Another VPN client, traffic-filtering app, or security feature with its own VPN profile may conflict with the one you want to use. Turn off another tool only if you understand what it does.

Turn on Always-on VPN

Menu names and locations vary across Pixel, Samsung, and other Android devices. A common route is:

  1. Open Settings and look for Network & internet, Connections, or a similar section.
  2. Tap VPN. You may need to open Advanced or More connection settings first.
  3. Find the VPN app or profile you want and tap its gear icon.
  4. Turn on Always-on VPN.
  5. Confirm the change if Android displays a warning.
  6. Return to the VPN app, confirm that it connects, and test the apps you use most.

If there is no Always-on switch, make sure you selected the VPN app rather than a different saved profile. The app may not support the feature, an administrator may restrict it, or the device maker may have changed the interface. Update Android and the VPN app from a trusted source, then consult instructions for your device model. Don’t install an unfamiliar app just to make the switch appear.

Turn on “Block connections without VPN”

On supported devices, this switch is usually in the settings for the selected VPN profile, near Always-on VPN. Enable it only after confirming the VPN works and understanding what happens if it disconnects. Android may warn that internet access will be blocked until the VPN connects.

For an initial test, pick a time when losing connectivity briefly won’t interrupt anything important. Keep the VPN connected and open a few regular apps. Then disconnect the VPN from the app or Android settings and check whether the apps can fetch new content. Reconnect the VPN and check access again. Don’t use a sensitive account or an urgent task as your test.

The test may look different across Android versions and device makers. An app may continue to display information it already downloaded, and some local device features do not need internet access. A page remaining visible on screen does not prove that the network is available. Try loading a new page or refreshing content instead.

What to check after setup

After a reboot: Restart your phone at a convenient time. Unlock it, allow services to start, and check the VPN notification, status-bar indicator, or the app’s connection status. The first connection can take a little while. If lockdown is enabled, internet access may remain unavailable until the VPN connects; that can be expected.

When changing networks: If you use both Wi-Fi and cellular data, test the transition between them. The VPN may briefly disconnect while the network changes. Check whether the app reconnects and whether your apps can reach the internet afterward. Don’t judge the setup based on one Wi-Fi network alone.

If the server is unavailable: With lockdown enabled, apps may have no internet access if the VPN cannot connect. Check the service status and app settings first. If you need to troubleshoot, temporarily turn off lockdown to restore ordinary access. Don’t treat the switch as a fix for a broken connection.

For individual apps: Find out whether each app is supposed to use the VPN. The VPN client may have app-exclusion or per-app routing controls. Their labels and logic vary: some send only selected apps through the VPN, while others exclude listed apps from it. If Android is also blocking connections outside the VPN, an app excluded from the tunnel may lose network access.

Troubleshooting: Android has no internet

Work through these steps in order:

  1. Check that the VPN app is installed, opens normally, and has a usable profile.
  2. Try a different familiar network, or test Wi-Fi and mobile data separately.
  3. Open Android’s VPN settings and temporarily turn off Block connections without VPN. Leave Always-on enabled if the issue appears to be service startup rather than connectivity.
  4. Open the VPN app and connect manually. If it still fails, check the service and profile settings in the app.
  5. Once the connection works, decide whether to re-enable lockdown. If drops continue, investigate them rather than relying on the switch to resolve them.

If the menu looks different, search the Settings app for “VPN” or “Always-on.” For a work profile, contact the administrator first: organization policies may control the connection and which apps are permitted. Don’t remove an organization-managed profile to troubleshoot without approval.

Common limitations and inconveniences

Lockdown can make it harder to join networks with a sign-in page, such as hotel or public Wi-Fi. The sign-in page may need to load before the network provides regular internet access, while strict blocking can prevent that step. If this happens, temporarily turn off lockdown, complete the Wi-Fi sign-in, then reconnect the VPN and restore the settings you want. Be cautious with unfamiliar sign-in pages and avoid entering passwords on suspicious ones.

Another cause of interruptions can be a conflict with an app using Android’s VPN interface or a device maker’s battery-management settings. If the VPN stops in the background, check the battery and background-activity settings for that VPN app. Menu names vary, so avoid disabling battery restrictions for every app; change only the relevant setting and observe the result.

A persistent VPN connection can also affect battery use and app routing. The impact depends on the device, network, app, and how you use the phone; there is no universal figure. Test it in your own conditions and use lockdown when preventing direct connections matters more to you than keeping internet access available at all times.

Is this setup right for you?

Always-on is useful if you often forget to connect manually and want Android to start the VPN service after a reboot. Lockdown is for situations where you would rather apps lose network access than connect outside the VPN if it fails. For travel, unreliable connections, or networks with sign-in pages, you might prefer automatic startup without lockdown until you have checked that the stricter setting works for your needs.

Recheck the settings after an Android update, VPN app reinstall, device change, or profile change. Switch names and behavior can vary by device. Visit our Android platform page for device and client information, or see the Xray client guide for an overview of clients on other platforms.

Sources