共享移动热点时如何保持noroot firewall运行并让好友正常上网?
Hey there, let's break down why Noroot Firewall is blocking your friend's hotspot traffic and how to fix it, or find alternatives if needed.
Noroot Firewall works by creating a local VPN on your device to intercept and filter traffic originating from your phone. When a friend connects to your hotspot, their traffic routes through your phone's network stack—but since their device isn't part of the VPN tunnel, Noroot Firewall doesn't recognize it as "allowed" traffic by default. It silently drops these packets, which is why you don't see any logs (the firewall only logs traffic from your own device, not connected hotspot clients).
Try these steps in order to get Noroot Firewall and your hotspot working together:
1. Allow Your Hotspot Subnet in Noroot Firewall
First, you need to tell the firewall to let traffic from your hotspot's IP range pass through:
- Find your hotspot's subnet: Go to your phone's Settings > Network & Internet > Hotspot & Tethering > Wi-Fi Hotspot. Look for the "AP IP address" (usually something like
192.168.43.1). The subnet will be[AP IP prefix].0/24—so if your AP IP is192.168.43.1, the subnet is192.168.43.0/24. - Open Noroot Firewall, tap the menu icon (three dots) and go to Settings > Advanced > Allowed IPs.
- Add your hotspot subnet (e.g.,
192.168.43.0/24) to the list. This tells the firewall to allow all traffic from devices on that subnet. - Check if there's an option for Allow Packet Forwarding in the advanced settings—enable it if present.
2. Fix Your Friend's Network Settings
Your earlier attempts had incorrect subnet masks and gateways. Here's the correct setup for their device:
- IP Address: Pick an address in the same subnet as your hotspot's AP IP (e.g.,
192.168.43.100—make sure it's not already used by another device). - Subnet Mask:
255.255.255.0(this is standard for most home/hotspot networks). - Gateway: Your phone's AP IP (e.g.,
192.168.43.1—not192.168.1.0, which is a network address, not a gateway). - DNS: Keep using
8.8.8.8and4.2.2.2—those are fine.
3. Verify IP Forwarding on Your Android Device
Android sometimes disables IP forwarding by default, which prevents hotspot traffic from reaching the internet. If you have root access, you can enable it via terminal:
- Open a terminal emulator (like Termux) and run:
su echo 1 > /proc/sys/net/ipv4/ip_forward
If you don't have root, some custom ROMs or newer Android versions let you enable this via developer options—look for "IP Forwarding" or "Allow Packet Forwarding" under hotspot settings.
If the above steps don't work, here are other options:
- Switch to a Root Firewall: Apps like AFWall+ (for rooted devices) give you full control over traffic rules, including explicit permissions for hotspot subnets. You can create a rule to allow all traffic from your hotspot's IP range to the internet, which won't interfere with your own device's firewall rules.
- Use a Third-Party Hotspot App: Some apps like Portable Wi-Fi Hotspot with Firewall let you manage access for connected devices independently of your main firewall. You can set up whitelists/blacklists for hotspot clients without turning off Noroot Firewall.
- Automate Firewall Toggling: Use an automation app like Tasker to automatically disable Noroot Firewall when you turn on your hotspot, and re-enable it when you turn the hotspot off. This is a quick workaround if configuration isn't possible.
内容的提问来源于stack exchange,提问作者VeganEye

