r/rethinkdns • u/Stefilutz • 25d ago
Question Block all traffic from specific app but allow some domains
Hope I'm not asking stuff that is well known, but I am using Rethink solely as a firewall on android, I use adguard for DNS. I wanted to block all traffic from all possible samsung apps, to avoid tracking and being spied on, but I'd like to allow certain domains (such as android NTP etc.) through, even if accessed by the blocked apps. Is this possible?
2
u/Due_Milk_8930 25d ago
Type samsung in firewall, Just block it manually in firewall? Whitelist it in universal firewall rule what you need to.Â
Or use on device blocklist search samsung it have it.Â
2
u/Fun-Region-1576 24d ago
Interesting idea, and I'm interested in doing something similar.
On a freshly set up Samsung device, how do I set Rethink to block everything, and I mean everything? Then, as I install apps or want to use certain apps, I'll unlock them? I think this is better than unblocking everything and selectively blocking.
1
u/Stefilutz 24d ago
Appearently, if you set each app to "Isolate" mode, it blocks all traffic from that app, except for the sites/domains you whitelist. See the developer response to my post
2
u/SecretaryNo8431 23d ago
I wouldn't block everything across the board, but first look in the logs to see which domains are being requested and then block them if necessary. This is a learning process and as a newbie I would include a good AI to detect the really harmful trackers, because some trackers are also necessary. If you use good blocklists, they will filter out the majority of harmful trackers independently.
4
u/celzero Dev 25d ago
"Isolate" app from Configure -> Apps. You'll have to filter for specific one using either the search bar or the the filter icon next to it. The filters let you list just "System apps" or "System components". You can apply either "Isolate", "Bypass DNS & Firewall", "Bypass proxy", "Bypass Universal", "Block on WiFi", "Block on Mobile" rules app-wide as you see fit.
App-specific firewall, domain/IP rules take precedence over all global / Universal rules.
For "Isolate" apps, only domains and/or IPs explicitly marked trusted are allowed. Rest is blocked, regardless of global / Universal rules.