Why block internet access for an app
Cutting network access for a single app isn't an edge case — it's a practical privacy tool. Here are five common situations.
- An offline-first app (flashlight, calculator, document scanner) quietly sends analytics and telemetry — it doesn't need the network to function, but its developer does to collect data.
- An APK installed from outside the app store, or a cracked version of a paid app — risky to let it reach the internet until you've confirmed it isn't "phoning home."
- You cancelled a subscription inside an app, but it keeps checking your payment status and pushing reminders — cutting network access is simpler than fighting its settings.
- Games on a kid's phone that are meant to stay offline-only — no access to stores, chats, or in-game ad networks.
- On roaming or a capped data plan, you need to temporarily cut off data-heavy apps — streaming, cloud sync — while keeping messaging and maps working.
A related reason is auditing permissions you already granted: even if an app legitimately requested camera or microphone access, that doesn't mean it needs network access right now. We covered which permissions carry the most risk and how to audit them in our guide to dangerous app permissions.
What Android can do on its own, no third-party apps
Before installing a firewall, check the built-in settings first — for many of the scenarios above, they're all you need.
Disable background data
Settings → Apps → the app in question → Mobile data & Wi-Fi (or "Data usage") → turn off "Background data." This doesn't block the network entirely: while the app is open and active on screen, it still gets network access. The moment you minimize it or lock the screen, its network access disappears. For most of the scenarios above (background telemetry, phoning home after a cancelled subscription), this is enough and needs no third-party tools.
Data Saver
The global toggle (usually under "Data usage" or "Network & internet") limits background data exchange for all apps at once, but lets you add exceptions for specific ones. Useful when you want to save data overall rather than block one app outright — closer to the roaming scenario than a targeted block.
Samsung One UI: allowed networks per app
Samsung devices have a more granular setting: Settings → Connections → Data usage → the allowed-networks section for apps (depending on the One UI version, the exact label may vary, something like "Mobile data only" or similar). There you can choose Wi-Fi, mobile data, both, or neither for each app — and "neither" is a full network block for that specific app, straight from system settings, no firewall involved.
Xiaomi and HyperOS: per-app network access
On Xiaomi, the equivalent lives in Security → Data transfer (or "Network connections" on HyperOS) → a list of apps with separate Wi-Fi and mobile data toggles. The exact wording shifts between MIUI/HyperOS versions, but the underlying logic — choosing network access per app — has stayed consistent for several generations.
The caveat applies to "stock" Android — Pixel, for example: there's no per-app network kill switch at all, only background data and the general Data Saver mode above. A full network block for an arbitrary app on such a device is only possible via a firewall, covered next.
No-root firewalls on Android: how they work, and why they clash with your VPN
Firewalls like NetGuard, NoRoot Firewall, or RethinkDNS don't require root — which means they technically can't intercept traffic at the kernel level the way a classic Linux firewall does. Instead, they use the public VpnService system API: the app registers itself as a local VPN tunnel, all device traffic logically routes through it, and the firewall decides whether to pass or drop packets from a given app. Nothing leaves to an external server — it's not a proxy or a real VPN, just the mechanism Android exposes for local interception. While such a firewall is active, you'll see the key icon in the status bar — the same indicator a real active VPN shows.
The limitation is baked into the platform itself: Android supports only one active VpnService at a time. Turn on NetGuard's firewall, and it occupies that slot; connect LiMP VPN (or any other VPN client), and the system revokes the firewall and switches to the VPN, or vice versa. You cannot keep both services active simultaneously — that's not a bug in either app, it's an architectural limit of Android. If the firewall runs in Always-On mode, trying to start a VPN client at the same time can cause "flapping," with the two services repeatedly stealing the slot back from each other.
If you still need such a firewall — say, for granular visibility into which apps have network access at all — which one you install matters. Stick to open-source options (NetGuard's code is public on GitHub and auditable) or well-reviewed apps from Google Play with a clear track record. A separate risk is apps that disguise themselves as a "privacy firewall" while actually intercepting and forwarding your traffic to a third-party server — exactly the threat we covered in our piece on malicious VPN apps; the mechanism is the same, just with a firewall wearing the disguise instead of a VPN. RethinkDNS is a more interesting case here: besides per-app blocking, it can route traffic through its own WireGuard configuration, effectively combining a firewall and a VPN client in one app — an option for people comfortable with manual setup, not a universal solution.
If you keep your VPN running at all times (for example in Always-On mode, which we covered separately), installing a VpnService-based firewall alongside it doesn't make sense — the two simply can't run in parallel. In that case, a targeted block for a single app is better handled with the system settings described above.
How to block a program's internet access on Windows 10 and 11
On a PC the situation is simpler: there's no VPN conflict, because the VPN client and a firewall rule are two independent mechanisms at the Windows level, not a shared slot like on Android.
Via Windows Defender Firewall
- Open "Windows Defender Firewall with Advanced Security" — fastest via
Win+R→wf.msc. - In the left pane, select "Outbound Rules."
- In the right pane, click "New Rule."
- Choose rule type "Program" and point it to the full path of the .exe file.
- On the action step, select "Block the connection."
- Check the profiles the rule applies to — Domain, Private, Public (you usually want all three, otherwise the program stays online when the network profile changes).
- Give the rule a clear name and save — the block takes effect immediately, no reboot needed.
One command in PowerShell
You can get the same result without the GUI, with a PowerShell command run as administrator:
New-NetFirewallRule -DisplayName "Block App" -Direction Outbound -Program "C:\Path\app.exe" -Action Block
Or the classic netsh command, which has worked since much older Windows versions:
netsh advfirewall firewall add rule name="Block App" dir=out program="C:\Path\app.exe" action=block
Both create an outbound rule — in practice the program can't establish any connection out at all, but technically it's described as blocking outbound connections.
Pitfalls to watch for
Many programs run more than one .exe: the main process, a background updater, a helper process. Block only the main file, and the updater keeps reaching the network anyway — check all of the program's processes in Task Manager and create a rule for each .exe separately.
For apps from the Microsoft Store (UWP), the .exe path often doesn't apply — those are blocked by package identity rather than by file, through a separate rule type or the app's own privacy settings.
An inbound rule doesn't substitute for an outbound one: if you only block inbound connections, the program can still freely reach out to the internet on its own — a full block requires the outbound rule specifically.
And the key point for this article: a firewall rule behaves identically whether your VPN is on or off. Just don't accidentally block the VPN client's own executable — it needs to stay allowed, or the VPN will stop connecting. For a full walkthrough of setting up a VPN on a desktop, see our guide to VPN for Windows, and you can grab the desktop client itself from the LiMP VPN apps page.
These rules don't touch Windows' own system telemetry (as opposed to individual programs) — if that's your goal, see our guide on disabling Windows 11 telemetry.
Blocking method vs. VPN compatibility
| Platform and method | What it blocks | Full block? | Works alongside a VPN |
|---|---|---|---|
| Android: background data | only background traffic; active-screen use keeps network access | No | Yes |
| Android: Data Saver | background data for all apps, with exceptions | No | Yes |
| Android: allowed networks (Samsung/Xiaomi) | Wi-Fi and/or mobile data for a specific app | Yes, with the "no network" option | Yes |
| Android: VpnService-based firewall (NetGuard and similar) | any traffic from the chosen apps | Yes | No — occupies the VPN slot |
| Windows: outbound firewall rule | all outbound traffic from the program | Yes | Yes |
| Router: device-level block | the entire device, not one app | Yes (for the device) | Not applicable to a single app |
| DNS filtering | requests to specific domains, not the whole app | No | Yes (if the VPN doesn't override DNS) |
How to combine a network block with your VPN
Which method to use depends on what matters more at a given moment — keeping the VPN running continuously, or guaranteeing a full block on one app.
If the VPN needs to stay on all the time — say, you often work from public Wi-Fi or connect to work resources — use Android's system-level restrictions: disabling background data, or picking allowed networks on Samsung/Xiaomi. They don't occupy the VPN slot and keep working while the VPN is active. If you need finer control over which apps go through the VPN at all versus which bypass it, that's a different job — split tunneling on the VPN client's own side, covered in detail in our guide to configuring a VPN for individual apps. That's a distinct task: split tunneling decides where an allowed app's traffic goes, not whether it gets network access at all.
If you need a guaranteed full block on one specific app and that matters more than the VPN at that exact moment, turn on the VpnService-based firewall, knowing the VPN will be disconnected while it runs. For many of the scenarios from the start of this article (checking an offline app, temporarily cutting off a suspicious APK), that's a one-off operation lasting a few minutes, after which you can turn the VPN back on.
On a PC there's no such tradeoff to make — the firewall rule and the VPN client run in parallel with no conflict, which makes Windows simpler in this respect. On top of per-app blocking, you can also encrypt your DNS queries — it doesn't replace a firewall, but it closes off leaks via unencrypted DNS requests; more in our guide to DoH and DoT.
If you're on Android and regularly need to balance privacy controls against an always-on VPN, it's worth looking at LiMP VPN for Android — split tunneling for the apps that need it is handled there without switching back and forth between the VPN and a firewall every time.
How to verify the block is actually working
After setting up any of these methods, it's worth confirming the app is genuinely cut off rather than just appearing to be at first glance.
On Android, the most reliable check is opening the app in airplane mode and comparing its behavior with the block active but airplane mode off: if the result is the same — the app fails to load data and shows a network error — the block is working. A second check: after some time, go to Settings → Apps → the app → "Data usage" and confirm its traffic counter isn't growing — it should normally sit at 0 bytes since the block was applied. If you're using a firewall like NetGuard, it keeps its own log showing every attempt the app made to reach the network and whether it was allowed or blocked.
On Windows, it's worth turning on logging of dropped packets in the firewall itself (under the profile's properties, in the "Logging" section; the file is usually called pfirewall.log) — it will show the specific blocked connection attempts, including the program and the destination address.
There's a flip side worth checking too: after you turn the Android firewall off (to get the VPN back), confirm the VPN actually reconnected rather than sitting in a disconnected state — otherwise you might assume you're protected when traffic is actually going out over the open network. A step-by-step check for that status is in our guide on how to verify your VPN is working correctly.
Checklist: what to do right now
- List the apps that don't actually need network access to function (calculator, offline games, local utilities).
- Disable background data for those apps in Android's system settings.
- On Samsung or Xiaomi, go through the allowed-networks section and explicitly set "no network" where it makes sense.
- On a PC, create a separate firewall rule for every .exe of the program you want isolated from the network, including its helper processes.
- Never block Android system components (Google Play Services) or the VPN client's own process — that breaks notifications, updates, and the VPN connection respectively.
- If you install an Android firewall, pick an open-source or well-reviewed Google Play app, not the first result you find online.
- Periodically check "Data usage" per app to spot unexpected traffic before it becomes a problem.
- A suspicious app (a sketchy APK, a cracked version) is better removed outright than just network-blocked — blocking doesn't remove the risk if the app already has access to files or data on the device.




