Culvert VPN

How to set up a VPN on Android in two minutes

Install a VPN app from Google Play, tap connect, accept Android's one-time connection request and check the exit IP. Full steps for Android 8 and up.

Android how-tos · 4 min read · By Culvert VPN

Setting up a VPN on Android takes three taps: install the app from Google Play, tap connect, and accept the system Connection request dialog that Android shows the first time any VPN app runs. A key icon appears in the status bar and every app on the phone now sends its traffic through the tunnel. For a consumer VPN app there is no server address to type, no protocol to choose and, with some apps, no account to create.

Before you start

Two checks save most of the trouble people run into later. First, if another VPN app is installed and connected, disconnect it. Android allows only one active VPN at a time, and a second app taking over is what many "my VPN keeps dropping" reports turn out to be. Second, if you are on hotel, campus or café Wi-Fi, open a browser and make sure you have got past the network's sign-in page. A VPN cannot connect through a captive portal you have not accepted yet.

Setting it up

  1. Open Google Play, find the app and install it. Look at the developer name and the permissions it asks for. A VPN needs network access and the VPN permission, and not much else.
  2. Open the app. Some apps ask you to create an account first; others let you connect straight away.
  3. Tap the connect button, or tap a country. In apps with a location picker, tapping a country usually connects you to its best city, and tapping a city gives you that city.
  4. Android shows a dialog titled Connection request. It says the app "wants to set up a VPN connection that allows it to monitor network traffic" and asks you to accept only if you trust the source. Tap OK. This is Android's own consent step; it appears once per app, not on every connect. What the prompt means explains the wording.
  5. Wait for the app to report that it is connected. A key icon appears at the top of the screen and a persistent notification from the app appears in the shade.
  6. Check the exit IP. A good app shows the address the internet now sees for you on its connect screen. If that address belongs to the VPN server, the tunnel is carrying your traffic.

That is the whole setup. Everything below is optional.

Making it stay on

By default a VPN runs until you disconnect it, the phone restarts, or Android stops the app to save power. If you want the tunnel up whenever the phone is, turn on Always-on VPN:

  1. Go to Settings > Network & internet > VPN. On Samsung phones the path is Settings > Connections > More connection settings > VPN; on Xiaomi it is Settings > Connection & sharing > VPN. Other manufacturers move it around, so searching Settings for "VPN" is quickest.
  2. Tap the gear icon next to the app's name.
  3. Turn on Always-on VPN. Android will now start the VPN when the phone boots and restart it if it stops.
  4. Optionally, turn on Block connections without VPN. This is Android's kill switch: while it is on, no app can reach the internet unless the tunnel is up.

The always-on explainer covers what changes on the phone once these are on, including the one case where the block gets in your way, which is signing in to a new Wi-Fi network.

Keeping some apps outside

Some apps behave better outside a VPN: a banking app that treats an unfamiliar address as suspicious, or an app that talks to a printer or a speaker on your home network. On Android the VPN app controls this, not the system settings. Look in the app's own settings for split tunnelling or excluded apps and add the ones you want left outside. Apps you install later stay inside the tunnel, which is the safe default. Which apps to exclude has a short list of the usual candidates.

If it will not connect

Work down this list in order:

  • The connection request never appeared, or you tapped Cancel. Disconnect and connect again. Android shows the dialog again until you accept it.
  • Another VPN app is set as always-on. Only one app can hold that setting. Turn it off for the other app under the same gear icon.
  • The Wi-Fi blocks VPN protocols. Some office and campus networks filter the ports VPNs use. An app that tries several connection methods in turn will usually find one that works, but that can take a minute rather than a second.
  • Connected, but nothing loads. Usually DNS. Check Settings > Network & internet > Private DNS. If a specific provider hostname is set there and it cannot be reached through the tunnel, no name resolves. Switching it to Automatic is the quick test.

Checking it is working

The key icon means a VPN session exists. It does not by itself prove that traffic is going through it. The check that does is the exit IP: the address a server on the internet sees when your phone talks to it. Compare it with the address the app says it connected to; if they match, you are done. How to check your VPN is working covers DNS and IPv6 as well.

Culvert VPN connects with one tap and no account on the free tier, shows the exit IP it verified through the tunnel on the connect screen, and is on Google Play.

Questions people also ask

Do I need to type in a server address?

Not with a consumer VPN app; it carries its own server list and picks one for you. The "+" button in Android's VPN settings is for manual corporate profiles and most people never need it.

Why does Android say the app can monitor my network traffic?

Because that is literally what a VPN does, so Android shows the same warning for every VPN app. It is a reason to check who makes the app, not a sign that something is wrong.

Can I run two VPN apps at the same time?

No. Android allows one active VPN at a time, and connecting a second app disconnects the first. If a VPN keeps dropping, a second VPN app on the phone is worth ruling out.