NekoBox TUN Mode Setup on Android: A Beginner’s Guide

What TUN mode does on Android

NekoBox TUN mode creates a virtual network interface and routes selected phone traffic through it. Instead of asking every browser or application to understand a manual proxy setting, Android sends traffic to the VPN interface first, and NekoBox decides whether that traffic should go through a proxy, connect directly, or be blocked by a rule. This is why TUN mode can cover applications that ignore ordinary HTTP or SOCKS proxy settings.

On Android, the word “VPN” does not necessarily mean that NekoBox provides a separate VPN subscription. Android uses the VPN permission and interface as a traffic-capture mechanism. Your actual connection still depends on the node or outbound profile that you import into NekoBox. If the selected node is unavailable, TUN mode cannot repair it; it only changes how applications reach the client.

TUN mode is useful when a browser works but another application does not, when an app has no proxy settings, or when you want a more consistent system-wide routing experience. It also adds more variables than a simple proxy setting: Android VPN permission, battery restrictions, per-app rules, DNS behavior, routing mode, and conflicts with other VPN applications. A careful first setup is therefore more reliable than immediately changing every advanced option.

Check the profile and phone before enabling TUN

Start with a working NekoBox installation and at least one imported profile. A profile may come from a subscription, a QR code, or a share link such as vmess://, vless://, trojan://, or ss://. Import the profile through the correct NekoBox entry point, select it, and confirm that its details are complete. Missing server addresses, ports, identities, or transport settings should be fixed before you investigate TUN mode.

Update NekoBox from a trusted source and use a build compatible with your Android version and CPU architecture. Avoid testing a modified APK and a new TUN configuration at the same time; if something fails, you will not know whether the package or the settings caused it. Also remove or pause other VPN applications, firewall tools, ad blockers, and network accelerators while testing. Android normally allows only one active VPN service, and another app may silently prevent NekoBox from starting.

Before changing routing, record your baseline. With TUN disabled, select a known profile and test one ordinary website. If the profile already fails without TUN, check the server, subscription, network, and system time first. A reliable baseline makes later troubleshooting much easier because you can separate a node problem from a traffic-capture problem.

Grant Android VPN permission

Open NekoBox, choose the profile you want to test, and tap the connect or start control. The first time TUN mode starts, Android should display a VPN connection request. Read the system dialog and approve it. This permission is required because NekoBox needs to create the local VPN interface and receive traffic for routing. It is not the same as allowing the app to send notifications or access files.

After approval, Android usually shows a VPN indicator in the status bar or quick settings area. NekoBox may also display a connected state, traffic counters, or a stop button. Check both signs when possible. A client screen that says “running” while Android shows no VPN indicator can point to a startup failure, a permission issue, or a service that stopped immediately.

If the permission dialog never appears, stop the service and start it again. Look under Android Settings, then Network and internet, VPN, or a similarly named network section. The exact label differs between Android versions and phone manufacturers. Remove an old NekoBox VPN entry only if you understand that it may reset the permission state, then return to NekoBox and request access again.

Some devices ask whether the VPN should remain active when the phone restarts, whether traffic should be blocked without VPN, or whether the app may run in the background. Do not enable a permanent kill switch during the first test unless you are prepared for all network traffic to stop when NekoBox disconnects. First prove that the profile and routing work; add stricter protection afterward.

Choose a routing mode that matches your goal

NekoBox commonly presents routing choices such as global proxy, rule-based routing, and direct or bypass behavior. Names can differ slightly between releases, but the decision is the same: decide whether all captured traffic should use the selected proxy or whether rules should determine the path.

Global proxy is the clearest mode for a first TUN test. Captured traffic is generally sent through the selected proxy, subject to internal exclusions and technical limitations. It helps answer one simple question: can NekoBox carry traffic from the phone through this profile? Use it temporarily to reduce the number of routing rules involved. If the browser and the previously failing app both work in global mode, the node and VPN permission are probably fine, and a rule is more likely to be responsible for later failures.

Rule-based routing is better for daily use when you want some destinations to go through the proxy and others to connect directly. Rules may be based on domain, IP range, application, region, or a routing list. The advantage is efficiency and control. The disadvantage is that a rule can send an important request down the wrong path. A domain may also use several hostnames, a content delivery network, or an IP address that is not obvious from the app’s visible name.

Direct or bypass behavior is useful for local services, banking applications, home devices, and destinations that work better without the proxy. However, a direct rule does not mean that the application is completely outside NekoBox. It may still be captured by the VPN interface and then released according to the routing decision. This distinction matters when an application detects a VPN or when local network discovery stops working.

For a beginner, use the following order:

  1. Choose global proxy for the first short connection test.
  2. Open a browser and confirm that a normal website loads.
  3. Test the application that previously ignored ordinary proxy settings.
  4. Switch to rule-based routing only after the global test succeeds.
  5. Add bypass rules one at a time and retest after each meaningful change.

Start the tunnel and verify real traffic

After selecting a profile and routing mode, start the TUN service from NekoBox. Keep the application open for the first test instead of immediately locking the screen or launching many apps. Watch whether the connection state remains active for at least a minute. If NekoBox connects and disconnects repeatedly, capture the sequence of events before changing settings. Repeated restarts may indicate a profile failure, a permission problem, or Android stopping the background service.

Test in layers rather than opening ten applications at once. First load a simple website in your browser. Next try a service that requires a different connection pattern, such as an application with its own API requests. Finally test the app that motivated you to enable TUN. This sequence tells you whether the tunnel works generally, whether only certain traffic types fail, or whether one application has special restrictions.

Check the difference between a DNS failure, a connection timeout, and an application login error. A page that cannot resolve a hostname may point to DNS or routing rules. A timeout may involve the node, transport, network, or firewall. A login error after the page loads may come from the application server, account security, certificate pinning, or a region check. Do not treat every error as proof that TUN is broken.

When the test succeeds, turn off global mode and move to your intended daily configuration. Keep the number of rules small at first. Save a note of the working profile, routing mode, and any applications that need direct access. That record is valuable after an Android update or when you change phones.

Review per-app, DNS, and battery behavior

Per-app routing can override your expectations. Depending on the NekoBox version, you may be able to include only selected applications or exclude specific apps from the VPN path. Check whether your browser and test application are both included. If the list is set to “selected apps only” and you forgot to add the application, the app may continue using its normal network even though TUN appears connected.

Also check whether the Android system itself is configured to use a different VPN profile, private DNS provider, or always-on VPN. Private DNS and proxy routing are separate layers, but an incompatible DNS configuration can make an otherwise healthy tunnel look broken. For a clean test, use Android’s automatic private DNS setting unless you have a specific reason to use a custom provider. Once the tunnel works, you can evaluate DNS behavior deliberately rather than changing it during the first diagnosis.

Battery optimization is a frequent Android-specific cause of sudden disconnections. Open the system battery settings for NekoBox and allow the app to run in the background, or select an unrestricted battery mode where the device provides that option. Some manufacturers add their own auto-start, background cleanup, or sleeping-app controls. If the tunnel stops after the screen is locked, after several minutes of inactivity, or when another app opens, these controls deserve attention.

Do not grant every permission offered by unrelated utility apps just to make a tunnel work. NekoBox normally needs VPN access and any permissions required for importing local files or showing notifications. Keep notification access enabled if it helps you see the connection state, but distinguish that from the VPN permission that actually captures traffic.

Troubleshoot common TUN failures

The VPN permission is denied. Return to Android’s VPN settings and remove any stale approval for NekoBox if necessary. Then start the service again and approve the request. If another VPN is active, disconnect it first. Work-profile or enterprise-managed phones may restrict VPN usage, in which case the device administrator’s policy can override the application.

NekoBox says connected, but no app can access the internet. Stop TUN and test the selected profile without it if the client supports that workflow. Recheck the node, subscription update time, and server reachability. Then start again in global proxy mode. If global mode also fails, the problem is probably not a per-app rule. If the browser works but one app fails, inspect that app’s inclusion, bypass rules, DNS requests, and special network behavior.

The browser works, but one application still fails. Confirm that the application is included in the TUN scope. Remove its domain from a direct rule temporarily and test again. Some apps use separate login, media, push, or analytics domains, so allowing only the visible main domain may be insufficient. Applications with certificate pinning or their own VPN-like network service may reject proxied connections even when ordinary browsing works.

Local devices cannot be reached. Rule-based routing may be sending private IP ranges through the proxy, or the proxy path may not support local network access. Add an appropriate direct or bypass decision for your local network only when you understand the rule syntax. Also check Android’s local network behavior and whether the destination device is awake. TUN does not automatically guarantee that printers, routers, or smart-home devices remain discoverable.

The connection drops after the screen is locked. Review battery optimization, background restrictions, auto-start controls, and notification settings. Keep NekoBox excluded from aggressive cleanup. If the phone has a manufacturer-specific power manager, search its settings for sleeping apps or background activity. Test again after changing one setting at a time so you can identify the setting that mattered.

Only some websites fail. Compare global and rule-based modes. A wrong domain rule, unavailable DNS route, MTU issue, or node-side restriction may affect only particular destinations. Try another profile if available. If every profile has the same symptom, inspect routing and DNS before repeatedly importing the subscription.

Build a stable daily configuration

Once the basic tunnel is confirmed, choose a routing mode based on your real usage instead of copying someone else’s configuration. Global proxy is simple and predictable, but it may add latency to local services and consume more proxy bandwidth. Rule-based routing can be faster for domestic or local destinations, but it requires maintenance when domains and applications change. Neither mode is universally best.

Keep one known-good profile available while experimenting. Export or back up settings if NekoBox provides that function, and write down the changes you make. When a new subscription update or Android system update causes a problem, you can compare the current configuration with the last working one instead of starting from zero.

Use the kill switch or “block connections without VPN” behavior only after you understand its consequence. It can prevent accidental direct connections, but it can also make the phone appear offline when NekoBox stops, when the node expires, or when Android revokes the service. If you enable it, make sure you know how to disable it from Android VPN settings and keep an alternative network path for recovery.

Finally, avoid enabling TUN merely because it sounds more powerful. If ordinary proxy behavior already covers your applications, the simpler mode may be easier to maintain. TUN is most valuable when you need broader application coverage and are willing to check permissions, routing, DNS, and battery behavior as part of normal maintenance.

NekoBox TUN mode FAQ

Does TUN mode require a separate VPN account? No. Android’s VPN interface is used to capture and route traffic locally. You still need a working NekoBox profile, node, or subscription for the actual outbound connection. TUN mode changes traffic handling; it does not create a server account.

Should I use global proxy or rule-based routing first? Use global proxy for the first short test because it reduces routing variables. After the browser and target application work, switch to rules if you need direct access for local or selected destinations. Add exceptions gradually.

Why does Android show a VPN icon when the selected node is not working? The icon normally confirms that NekoBox created a VPN interface, not that the remote node is reachable. Test the profile itself, inspect connection logs when available, and try another network or profile before changing every TUN option.

Can I run NekoBox TUN mode together with another VPN? Usually not in the normal Android VPN workflow. Two applications cannot generally own the same VPN service at the same time. Disconnect the other VPN, firewall, or traffic-filtering app while testing, then decide which tool should manage the phone’s VPN interface.