Guides
6 min read
How to use Always-on VPN on Android 14, 15, and 16
Key takeaways
Android’s Always-on VPN setting can keep a selected VPN service running. The optional Block connections without VPN setting blocks network traffic that is not using that VPN. Availability, menu names, and behavior can vary by device manufacturer, Android version, work profile, and the VPN app’s configuration.
Android provides two related system controls for supported VPN apps. They are useful when you want the operating system to treat one VPN as the default network path, but they are not the same control.
Google’s Android VPN documentation describes Always-on VPN as a system feature that can start a VPN service when Android starts and keep it running. The VPN app remains responsible for establishing and maintaining its connection to the gateway.
Always-on VPN and traffic blocking
Always-on VPN
Designates one supported VPN service for Android to keep active. Android can start the service after a reboot and restart it when necessary; the app still manages the tunnel connection.
Block connections without VPN
When available and enabled, Android blocks network traffic that is not using the selected VPN. This can also affect captive portals and services that the VPN configuration intentionally excludes.
Always-on VPN improves service persistence. It does not, by itself, mean that non-VPN traffic is blocked. That stricter behavior comes from the separate blocking setting, sometimes called VPN lockdown in Android documentation.
How to find the settings
On many Android 14, 15, and 16 devices:
- Open Settings.
- Open Network & internet, Connections, or the equivalent network menu.
- Select VPN.
- Open the settings icon beside TuxlerVPN.
- Enable Always-on VPN if it is available.
- Optionally enable Block connections without VPN after considering the trade-offs below.
On Samsung devices, the path may appear under Settings > Connections > More connection settings > VPN. Other manufacturers use different labels. Android enterprise administrators can also control whether these options are available in a managed profile.
If TuxlerVPN does not appear in the VPN list, open the app and complete Android’s VPN permission prompt first. If a setting is absent or disabled, confirm that the installed app version and device configuration support it.
What happens during a network change
Moving between Wi-Fi and mobile data changes the outer network path used by the VPN. WireGuard is designed to accept authenticated packets from a peer’s updated network endpoint, but the application, Android, and the new network still determine how quickly service resumes.
Always-on VPN tells Android to keep the selected VPN service active or restart it as needed. It is not a promise that every handoff will be instantaneous or that an unreachable gateway can maintain connectivity.
Captive portals on hotels and public Wi-Fi
Hotels, airports, and cafés often require a browser sign-in before they provide internet access. Block connections without VPN may prevent that local sign-in page from loading because the network has not yet granted ordinary internet access.
A practical sequence is:
- Join the Wi-Fi network.
- If the sign-in page does not appear, temporarily turn off Block connections without VPN.
- Complete the network’s captive-portal sign-in.
- Connect TuxlerVPN.
- Re-enable the blocking setting if you want Android to block non-VPN traffic.
Only use a captive portal you recognize as belonging to the venue or network operator. HTTPS remains the primary protection for website content and credentials, including when a VPN is active.
Battery settings and background restrictions
Some manufacturers apply additional battery restrictions to background apps. If the VPN service stops unexpectedly, check Settings > Apps > TuxlerVPN > Battery and review the available background-use options. Allowing unrestricted background use can improve persistence on some devices, but it may also increase battery consumption.
This setting is device-specific. It does not change the encryption protocol or guarantee a particular connection duration.
Which configuration should you use?
| Configuration | What Android does | Important trade-off |
|---|---|---|
| VPN app only | The app manages its own service lifecycle | Behavior during reboot or background restrictions depends on the app and device |
| Always-on VPN | Android keeps the selected VPN service active or restarts it | Non-VPN traffic is not necessarily blocked |
| Always-on + Block connections without VPN | Android also blocks traffic outside the selected VPN | Captive portals and intentionally excluded traffic may stop working |
Choose the configuration that fits your network and device. If internet access stops, confirm the VPN is connected, temporarily review the blocking setting, and check Android’s Private DNS and battery settings.
TuxlerVPN Mobile uses Android’s VpnService and WireGuard to create an encrypted connection to TuxlerVPN Mobile VPN gateways.
Related articles
-
Guides
Hotel Wi-Fi security on Android: a practical connection sequence
Use the hotel’s legitimate captive portal, keep HTTPS enabled, connect the VPN, and understand how Android’s optional traffic-blocking setting affects sign-in.
August 18, 2026 · 6 min read
-
Engineering
WireGuard vs OpenVPN on Android: a technical comparison
WireGuard and OpenVPN can both secure Android traffic, but their protocol design, transport choices, and operational behavior differ.
August 18, 2026 · 7 min read
-
Guides
How to change your IP address on Android
A connected VPN changes the public network address seen by services for traffic routed through its gateway. It does not change GPS, accounts, or browser identifiers.
August 18, 2026 · 6 min read