AI summary
Advanced VPN routing and flow diagnostics tool with unified system VPN, granular traffic rules, and local-only processing. Supports importing VLESS, VMess, Trojan, Shadowsocks, Hysteria2, WireGuard, OpenVPN and other proxy formats via clipboard, file, QR scan, or Android Share.
Generated by AI. May contain inaccuracies.
About this app
Visual Route & Flow Scanner – Android app with a unified system VPN, clear routing rules, and local diagnostics.
ViRouteFS contains no ads, analytics, telemetry, trackers, or automatic log sending.
General Operation
- Network control works without a mandatory VPN profile. - By default, all traffic goes through System (your phone's regular mobile data or Wi-Fi). - User-defined rules can selectively route specific apps, domains, IPs, or CIDR networks to a specific VPN/proxy, to Block, or to TCP/TLS Compatibility mode.
Profiles & Validation
- Profiles are saved only after successful structure and configuration validation. - Changing settings while network control is active: the new config is tested separately first. If invalid, the current route stays active. A successful change restarts the VPN/TUN (causing a brief reconnect). - Import formats: VLESS (including v2rayNG VLESS/XHTTP exports), VMess, Trojan, Shadowsocks, Hysteria2, TUIC, SOCKS5, HTTP(S), sing-box JSON, OpenVPN (.ovpn), and WireGuard (.conf). - Import methods: Paste from clipboard, choose a file, scan a QR code with the camera, or use the Android Share menu (text/links). Camera frames are never saved or transmitted. - Before saving, a preview is shown with secrets hidden. Duplicates can be skipped, replaced, or saved as a copy. All new profiles are imported disabled. - WireGuard PostUp/PreDown commands are never executed. - Connectivity check: 3 clear stages – config structure, server address reachability (TCP check), and a separate HTTPS request via the selected outbound (run manually with a button). The final stage shows the measured latency in milliseconds. - XHTTP compatibility: Old v2rayNG XHTTP profiles with allowInsecure: true are compatible with Xray 26.6.1. The obsolete field is removed, and the certificate is pinned locally via SHA-256 (TOFU) on first connection. - OpenVPN: After importing .ovpn, you can separately enter a login/password and select PEM files for the CA, client certificate, and private key. The certificate and key are validated as a pair. All secrets are encrypted in local storage.
Subscriptions
- Added manually and updated only over HTTPS via a manual refresh button. - Supports URI lists, common Base64 wrappers, sing-box JSON, and a safe subset of Clash YAML (Shadowsocks, VMess, VLESS, Trojan, Hysteria2, TUIC, HTTP). - Limited to 2 MB and 512 profiles. Local/private addresses and unsafe redirects are rejected. - Before applying, you see a diff: new, changed, and removed profiles. - New servers are added disabled; existing ones keep their stable ID, state, and user routes. Removed targets stay disabled (they are not automatically deleted from rules). No background updates.
Backup
- Export a sanitized diagnostic JSON (no secrets) or a full .vrfs backup file. - Full backups are encrypted with AES-256-GCM using a user-provided password. - Before restoring, the app shows the backup contents, validates the config, and does not change current settings until you explicitly confirm.
Rules & Routing Logic
- If a rule points to a disabled, incomplete, or unavailable profile, its traffic goes to Block – no hidden fallback to System or another VPN. - Rules are shown in actual application order. Up/Down buttons adjust visible priorities. - Any rule can be further restricted by protocol (TCP/UDP) and a specific port or port range (e.g., 443, 8000-8100). - App-based rules require Android 10 or newer. On older Android versions, the VPN will not start if such rules are enabled (protects against silent misrouting).
Groups (Routing Policies)
- Rules and the main route can point to a group of profiles. - Group modes: Manual (no auto-fallback), Lowest latency, Ordered failover, and Round-robin (new connections only). - Auto modes test only explicitly listed connections via a specified HTTPS address. System is not added automatically. - Failover: selects the first available participant from top to bottom, and reverts to the restored primary when available. - Round-robin: switches the local selector per new connection (existing connections are not interrupted). - If one profile belongs to several auto-groups, their HTTPS check addresses must match.
DNS Policies
- Each rule and VPN profile can have its own DNS policy. - Options: System DNS, plain UDP/TCP DNS, DNS-over-TLS, DNS-over-QUIC, DNS-over-HTTPS (including HTTP/3), sending DNS through the selected VPN/proxy/compatibility profile or group, multiple servers with explicit priority order, optional sequential fallback with per-server timeout, and local hosts overrides. - Unavailable DNS or DNS set to Block is rejected (no hidden fallback to system DNS). - If fallback is enabled: a normal response (including NXDOMAIN) is returned immediately; the next server is used only on timeout or network error.
Flow Scanner (Live Diagnostics)
- Displays real connection events from the local engine: app/process, destination address, domain, protocol, chosen route, matching rule, traffic volume, and state. - Compares the actual outbound with the local rule calculation and explicitly shows any mismatches. - Pre-select any installed app for observation via search. - Filters: address/domain/package/route, TCP/UDP/ICMP, active/completed states, allow/block, IPv4/IPv6, and start time. - For completed flows: shows end time and duration. If the engine did not report a close reason, the interface clearly states that. - Export filtered visible metadata to CSV via the Android system menu. - Displays local app icons. Packet payloads are never logged, and HTTPS is never decrypted.
Readiness Center
- Displays the overall network status alongside a local native validation check of the current full configuration.
Compatibility Mode (TCP/TLS)
- A separate local routing option for networks where intermediate equipment interferes with standard TCP/TLS transmission. - Activated only via a manual toggle. Can be the target of any rule. - This is not a VPN: it does not encrypt all traffic or hide your IP address. - If the process fails to start or stops, associated routes remain fail-closed.
Privacy
- No ads, analytics SDKs, or trackers. - No hidden background scanning. - No packet payload logging. - The installed app list is read locally only for rule selection and Flow Scanner filtering, and is never sent anywhere. - No automatic log or PCAP export. - Camera is activated only on the explicit QR import screen; frames are processed locally, immediately closed, not saved or transmitted. - All configuration and secrets are stored locally and encrypted. - Android backup is disabled for sensitive data. - Updates are checked only after explicit user action.
Purpose
ViRouteFS is not intended or promoted as a censorship circumvention tool. Its purpose is legitimate VPN routing, diagnostics, and control of your own network traffic.
License
GNU General Public License v3.0
What's new
https://github.com/Vifsvifsvifs/viroutefs/compare/v0.14.0-beta.6...v0.14.0-beta.7/
About this version
- Version
- 0.14.0-beta.7 (14007)
- Size
- 48.63 MB
- Requires Android
- 8.0
- Target SDK
- 26
- Architecture
- arm64-v8a
- Downloads
- 35
- Updated
- Aug 3, 2026
- Package
- dev.vifs.viroutefs
Similar apps
Ratings & reviews
- 50
- 40
- 30
- 20
- 10