AI summary
VPN and network routing tool with visual flow diagnostics. Supports multiple proxy protocols including VLESS, VMess, Trojan, Shadowsocks, WireGuard and OpenVPN, plus subscription imports. Features rule-based routing, group policies with latency and failover modes, granular DNS controls, and a live Flow Scanner for connection monitoring.
Generated by AI. May contain inaccuracies.
About this app
Visual Route & Flow Scanner – Android app with a unified system VPN, clear routing rules, and local diagnostics.
ViRouteFS contains no ads, analytics, telemetry, trackers, or automatic log sending.
General Operation
- Network control works without a mandatory VPN profile. - By default, all traffic goes through System (your phone's regular mobile data or Wi-Fi). - User-defined rules can selectively route specific apps, domains, IPs, or CIDR networks to a specific VPN/proxy, to Block, or to TCP/TLS Compatibility mode.
Profiles & Validation
- Profiles are saved only after successful structure and configuration validation. - Changing settings while network control is active: the new config is tested separately first. If invalid, the current route stays active. A successful change restarts the VPN/TUN (causing a brief reconnect). - Import formats: VLESS (including v2rayNG VLESS/XHTTP exports), VMess, Trojan, Shadowsocks, Hysteria2, TUIC, SOCKS5, HTTP(S), sing-box JSON, OpenVPN (.ovpn), and WireGuard (.conf). - Import methods: Paste from clipboard, choose a file, scan a QR code with the camera, or use the Android Share menu (text/links). Camera frames are never saved or transmitted. - Before saving, a preview is shown with secrets hidden. Duplicates can be skipped, replaced, or saved as a copy. All new profiles are imported disabled. - WireGuard PostUp/PreDown commands are never executed. - Connectivity check: 3 clear stages – config structure, server address reachability (TCP check), and a separate HTTPS request via the selected outbound (run manually with a button). The final stage shows the measured latency in milliseconds. - XHTTP compatibility: Old v2rayNG XHTTP profiles with allowInsecure: true are compatible with Xray 26.6.1. The obsolete field is removed, and the certificate is pinned locally via SHA-256 (TOFU) on first connection. - OpenVPN: After importing .ovpn, you can separately enter a login/password and select PEM files for the CA, client certificate, and private key. The certificate and key are validated as a pair. All secrets are encrypted in local storage.
Subscriptions
- Added manually and updated only over HTTPS via a manual refresh button. - Supports URI lists, common Base64 wrappers, sing-box JSON, and a safe subset of Clash YAML (Shadowsocks, VMess, VLESS, Trojan, Hysteria2, TUIC, HTTP). - Limited to 2 MB and 512 profiles. Local/private addresses and unsafe redirects are rejected. - Before applying, you see a diff: new, changed, and removed profiles. - New servers are added disabled; existing ones keep their stable ID, state, and user routes. Removed targets stay disabled (they are not automatically deleted from rules). No background updates.
Backup
- Export a sanitized diagnostic JSON (no secrets) or a full .vrfs backup file. - Full backups are encrypted with AES-256-GCM using a user-provided password. - Before restoring, the app shows the backup contents, validates the config, and does not change current settings until you explicitly confirm.
Rules & Routing Logic
- If a rule points to a disabled, incomplete, or unavailable profile, its traffic goes to Block – no hidden fallback to System or another VPN. - Rules are shown in actual application order. Up/Down buttons adjust visible priorities. - Any rule can be further restricted by protocol (TCP/UDP) and a specific port or port range (e.g., 443, 8000-8100). - App-based rules require Android 10 or newer. On older Android versions, the VPN will not start if such rules are enabled (protects against silent misrouting).
Groups (Routing Policies)
- Rules and the main route can point to a group of profiles. - Group modes: Manual (no auto-fallback), Lowest latency, Ordered failover, and Round-robin (new connections only). - Auto modes test only explicitly listed connections via a specified HTTPS address. System is not added automatically. - Failover: selects the first available participant from top to bottom, and reverts to the restored primary when available. - Round-robin: switches the local selector per new connection (existing connections are not interrupted). - If one profile belongs to several auto-groups, their HTTPS check addresses must match.
DNS Policies
- Each rule and VPN profile can have its own DNS policy. - Options: System DNS, plain UDP/TCP DNS, DNS-over-TLS, DNS-over-QUIC, DNS-over-HTTPS (including HTTP/3), sending DNS through the selected VPN/proxy/compatibility profile or group, multiple servers with explicit priority order, optional sequential fallback with per-server timeout, and local hosts overrides. - Unavailable DNS or DNS set to Block is rejected (no hidden fallback to system DNS). - If fallback is enabled: a normal response (including NXDOMAIN) is returned immediately; the next server is used only on timeout or network error.
Flow Scanner (Live Diagnostics)
- Displays real connection events from the local engine: app/process, destination address, domain, protocol, chosen route, matching rule, traffic volume, and state. - Compares the actual outbound with the local rule calculation and explicitly shows any mismatches. - Pre-select any installed app for observation via search. - Filters: address/domain/package/route, TCP/UDP/ICMP, active/completed states, allow/block, IPv4/IPv6, and start time. - For completed flows: shows end time and duration. If the engine did not report a close reason, the interface clearly states that. - Export filtered visible metadata to CSV via the Android system menu. - Displays local app icons. Packet payloads are never logged, and HTTPS is never decrypted.
Readiness Center
- Displays the overall network status alongside a local native validation check of the current full configuration.
Compatibility Mode (TCP/TLS)
- A separate local routing option for networks where intermediate equipment interferes with standard TCP/TLS transmission. - Activated only via a manual toggle. Can be the target of any rule. - This is not a VPN: it does not encrypt all traffic or hide your IP address. - If the process fails to start or stops, associated routes remain fail-closed.
Privacy
- No ads, analytics SDKs, or trackers. - No hidden background scanning. - No packet payload logging. - The installed app list is read locally only for rule selection and Flow Scanner filtering, and is never sent anywhere. - No automatic log or PCAP export. - Camera is activated only on the explicit QR import screen; frames are processed locally, immediately closed, not saved or transmitted. - All configuration and secrets are stored locally and encrypted. - Android backup is disabled for sensitive data. - Updates are checked only after explicit user action.
Purpose
ViRouteFS is not intended or promoted as a censorship circumvention tool. Its purpose is legitimate VPN routing, diagnostics, and control of your own network traffic.
License
GNU General Public License v3.0
What's new
Fixed VLESS/XHTTP connections in the Xray runtime. - Added password-protected PKCS#12 (.p12, .pfx) certificate support for OpenVPN profiles.
About this version
- Version
- 0.14.0-beta.8 (14008)
- Size
- 48.63 MB
- Requires Android
- 8.0
- Target SDK
- 26
- Architecture
- arm64-v8a
- Downloads
- 22
- Updated
- Aug 10, 2026
- Package
- dev.vifs.viroutefs
Similar apps
Ratings & reviews
- 50
- 40
- 30
- 20
- 10