VPNGeek
Purchase
Guides VPN APPS

Android: always-on VPN and kill switch

Android 12+VPNGeek app v3+ 6 min · Updated Jun 2026

Keep the VPNGeek tunnel always on and block traffic whenever it drops on Android.

Android has a built-in always-on VPN feature that starts your chosen VPN at boot and keeps it running, plus a companion block connections without VPN setting that acts as a system-level kill switch. Combined with the VPNGeek app's own protections, this ensures your device never sends traffic in the clear. This guide walks through both the app side and the Android system side.

Before you start

  • An active VPNGeek subscription, signed in on the app.
  • Android 12 or newer (the exact menu labels vary slightly by manufacturer — Samsung, Pixel, and others word things a little differently).
  • You must connect through the VPNGeek app at least once before Android will let you set it as always-on.

1. Connect once through the app

Open the VPNGeek app, sign in, and tap Connect. Approve the Android VPN permission prompt when it appears. This first connection registers VPNGeek as a VPN provider, which is what makes it selectable in the system always-on list. Once you see the key icon in the status bar, you can close the app.

2. Set VPNGeek as always-on

Open Android Settings > Network & internet > VPN (on Samsung: Settings > Connections > More connection settings > VPN). Tap the gear icon next to VPNGeek, then enable Always-on VPN. Android will now start the tunnel automatically after every reboot and keep it alive in the background.

3. Block connections without VPN

On the same settings screen, enable Block connections without VPN. This is the system kill switch: if the tunnel is down for any reason — reconnecting, switching networks, or a crash — Android drops all traffic instead of letting it leak over the open network. Nothing leaves the device until the VPN is back up.

Note. The VPNGeek app also has its own kill switch under Settings > Kill switch. The Android system setting is the more robust of the two because it survives the app being killed, but enabling both does no harm.

4. Exempt battery optimization

Aggressive battery optimization is the most common reason an "always-on" tunnel silently stops. Open Settings > Apps > VPNGeek > Battery and set it to Unrestricted (on some phones this is worded as "Don't optimize" or "Allow background activity"). This stops the OS from suspending the app and tearing down the tunnel to save power.

Warning. Some manufacturer skins (MIUI, One UI, ColorOS) have extra "app hibernation" or "deep sleep" lists separate from the standard battery menu. If the tunnel keeps dropping overnight, remove VPNGeek from those lists too.

Troubleshooting

Always-on is greyed out

You have not connected through the app yet, or you upgraded and the VPN provider registration was lost. Open the app and connect once, then return to the VPN settings.

The tunnel drops when the screen is off

Battery optimization is suspending the app. Set VPNGeek to Unrestricted and check any manufacturer-specific sleep or hibernation lists.

No internet at all after enabling the kill switch

"Block connections without VPN" is working but the tunnel cannot connect. Open the app, switch to another location, and reconnect; once the tunnel is healthy, traffic flows again.

Did this guide get you connected?