- Beginner
- 7 min read
- Updated 2026-10-09
When protection will not start
A scan-down checklist for the usual reasons ClearDeck's tunnel will not come up or quietly stops filtering, ordered from most likely cause to least, with a check for each one.
Protection failing to start is almost never one problem. It is a short list of ordinary ones, and it pays to check them in order — from the most likely to the least. Each section below gives you a symptom to recognise, a way to confirm it, and what to do about it.
1. Another VPN app is holding the connection
Symptom. You tap Start protection and nothing sticks. The button snaps back, or the key icon that appears belongs to something else.
Confirm. Android allows exactly one active VPN at a time. Look through your installed apps for anything else that runs a VPN or a firewall, and open Android’s Settings → Network → VPN to see what is listed and connected there. The status-bar key icon is shared: it does not name the app behind it, so match it against whatever else you have installed.
Fix. Disconnect or stop the other VPN, then start protection again. This is a platform rule, not a ClearDeck limitation — ClearDeck will not fight another app for the slot, and if another VPN holds it, ClearDeck cannot filter anything while that is true.
2. There is no key icon in the status bar
Symptom. The app looks open and normal, but you are not sure anything is actually happening.
Confirm. This is the single clearest signal you have. When the tunnel is up, Android shows a persistent key icon in the status bar. No key icon means the tunnel is not up — and if the tunnel is not up, nothing is being filtered, no matter what the app’s screens show.
Fix. If the icon is genuinely absent, treat it as “protection is off” and work through the causes below. A useful cross-check is the dashboard’s main button: it reads Stop protection while running and Start protection while stopped.
3. “Protection could not start”
Symptom. You get the app’s own failure message:
Protection could not start. Please try again.
Or the engine message, which carries a reason:
Can’t reach the protection engine (%1$s). Live data will come back on its own.
Confirm. The %1$s is one of five causes the app distinguishes, and each
points somewhere different:
| Cause shown | What it usually means |
|---|---|
| blocked by a system policy | Something on the phone — a work profile, an MDM policy, or a security suite — is refusing the VPN |
| sign-in rejected | The local control handshake failed |
| connection refused | The engine is listening but rejected the connection |
| no response | The engine process did not answer in time |
| unknown cause | None of the above could be established |
Fix. The last three are all the same underlying situation: the local control channel is unreachable, which usually means the engine process died. The first thing to try is simply starting protection again — that respawns the engine. If it repeats, force-stop ClearDeck from the app’s info screen, reopen it, and try once more. A “blocked by a system policy” result is different: that one is the phone refusing, and restarting will not change it.
4. It worked, then stopped while the screen was off
Symptom. Protection runs fine while you use the phone, but after the screen has been off for a while it is gone — no key icon, blocked counts frozen.
Confirm. This is the phone’s battery manager killing ClearDeck’s foreground service. It is the manufacturer’s behaviour, not a ClearDeck bug: many OEM ROMs — Huawei, Xiaomi, OPPO and others — aggressively end background services to save power, and the menu names differ from brand to brand.
Fix. Three settings, in roughly this order of importance:
- Allow ClearDeck to autostart or run in the background.
- Exclude ClearDeck from battery optimisation (sometimes called “no restrictions” or “don’t optimise”).
- Don’t force-stop it from the recents screen — swiping it away can stop the service on some ROMs.
The per-OEM detail is in keep protection running.
5. The blocked count stays at zero
Symptom. The dashboard numbers for connections and traffic move, but Blocked never does.
Confirm and fix, in order:
- Which button is on the dashboard — Stop protection (running) or Start protection (not running)? If it says Start protection, nothing is filtered yet.
- Open Modules and check the module switches. If they have all been turned off, nothing will be blocked. Domain modules block for every app; a module that is switched off blocks nothing.
- The two deep modules do nothing until deep inspection is on and the certificate is installed. That is expected, not a fault (see section 7).
- It may simply be that your normal usage is not generating blocked requests. Try loading a few ad-heavy news sites and watch the count — if it climbs, everything is working and your everyday apps were just quiet.
6. One specific app cannot reach the internet
Symptom. Everything else works, but a single app times out or shows no connection.
Confirm. Open that app’s access log from the app list and look at the Result column. A rule can only interfere in one of two ways: an over-broad Allow rule is not the problem here, but a block rule that matches too much is. Check the app’s own rule list, and the shared My block & allow list, for anything that matches this app’s traffic.
Fix. In the access log, find the record you want and tap Allow; choose This app only or All apps in the Apply to… sheet. Remove any stale block rule for this app from the rule list. If you only want one host reachable, allow that host rather than the whole app.
7. Deep inspection will not work
Symptom. Deep inspection shows a state that is not plain On.
Confirm and fix. There are three distinct states, and each has one answer:
- “Not working yet: the ClearDeck certificate is not installed.” The certificate is missing. Tap Install certificate and follow the steps — the file is saved to Downloads and Android’s certificate page opens. The “untrusted source” warning you will see is normal; it is ClearDeck’s own certificate. Details are in deep inspection.
- Paused. Power saving is on, and it pauses deep inspection by design. Turn off Power saving in Settings to bring it back.
- “Couldn’t prepare the certificate. Restart protection once, then try again.” Do exactly that: stop and start protection, then retry the install once.
8. It feels like DNS is broken, not blocking
Symptom. Whole sites fail to resolve across many apps, rather than ads simply going missing.
Confirm. Blocking and DNS failure look different. Blocking shows up in the access log as a record with Result = Blocked. A DNS problem looks like broad resolution failures with no matching blocked record. To test the DNS side, open Settings → Encrypted DNS: change the address, or turn the switch off briefly, and try again.
Fix. If turning encrypted DNS off restores the connection, the configured resolver was the problem — set a different address. If nothing changes, the issue is not DNS, and you are back to section 6.
Before you ask for help
Gather two things first, so a report can actually be answered:
- Export the access log as CSV while protection is still running — see export the access log. It is the evidence, and it is cleared the moment protection stops.
- Note the app version from About, and your phone model and Android version.
Those three facts — the export, the version, and the ROM — answer most of the questions anyone would have to ask before helping.
This guide is also available in 简体中文