# Software Firewall for Windows?

**URL:** https://discuss.privacyguides.net/t/software-firewall-for-windows/13859
**Category:** Questions
**Tags:** software
**Created:** 2023-09-05T20:29:09Z
**Posts:** 106

## Post 1 by @Average_Joe — 2023-09-05T20:29:09Z

Good morning,

I’ve been researching this topic for a long, long time and I still haven’t been able to find a good answer. I’ve read all about people using old PC’s to install a “Firewall Linux Distro” and this sounds great in theory but how is this helpful if a Windows PC on the network has installed an App that has a trojan attached with it that can send information about the Windows user like every keystroke that the user enters to the trojan’s author online?

It seems like so much work to build a hardware device like a Firewall Linux Distro or a specially configured router if it only takes one malicious App on a Windows PC to destroy everything.

I use the inbuilt Windows Firewall, but this rarely seems to work as even when I have set it to block VLC from connecting to the internet VLC still seems to be able to get updates and the Christmas icon appears when it comes close to Christmas… Adobe Acrobat Reader is also able to get updates even though I’ve blocked it in the inbuilt Windows Firewall.

It seems VERY important to install a trustworthy software firewall on all Windows’ PC’s?

How is this not discussed more?

Thank you for reading my question.

---

## Post 2 by @anon86237473 — 2023-09-05T22:15:42Z

I personally use Simplewall ([https://www.henrypp.org/product/simplewall](https://www.henrypp.org/product/simplewall)) which is, like the name implies, a simple to use firewall. It’s great and I often have problems with programs not working until rember I might need to give them internet access.

Another, more “modern”, alternative I’m watching but haven’t tried yet is Portmaster ([https://safing.io/](https://safing.io/)). It does things a bit differently as I understand it but I haven’t looked into it much yet.

Maybe one or the other will be of use to ya.

---

## Post 3 by @Average_Joe — 2023-09-05T22:53:56Z

I appreciate your reply!

I’ve been looking at this for a long time and it seems like the best software firewall available for Windows PC’s.

(Forgive me if I’m not supposed to post URL’s: [GlassWire Network Security Monitor & Firewall Tool Features](https://www.glasswire.com/features/))

---

## Post 4 by @3QVvxrhnYZ — 2023-09-06T01:27:03Z

I recommend you to natively manage Windows Firewall. Windows Firewall is based on Windows Filtering Platform, and simplewall is based on Windows Filtering Platform, too. So, basically, what you are doing is just replacing Windows’s native firewall, Windows Firewall, with simplewall. Replacing one firewall with another.  
Sure, simplewall is much better [than that miserable and crippled Windows Firewall], but what’s even better is to manage the already existing Windows Firewall natively. This eliminates any potential interference that may arise due to having two firewalls (I personally never had any interferences or problems using simplewall, but I’m unaware if there could be problems in some use-cases, for example), and it’s just a “clean” approach.

Best tool to manage Windows Firewall natively is [Windows Firewall Control](https://www.binisoft.org/wfc). It is just as lightweight and simple as simplewall. There are no other decent solutions for managing Windows Firewall natively. The app I linked is closed-source, however the developer is very active on this forum:  
[Windows Firewall Control (WFC) by BiniSoft.org | Wilders Security Forums](https://www.wilderssecurity.com/threads/windows-firewall-control-wfc-by-binisoft-org.347370/)

There are some little controversies with simplewall. Online virus scans detect some malware, however highly likely they are just false positives:

[VirusTotal](https://www.virustotal.com/gui/file/19b842988b5f9680f55c4a4e42dc1bb00b29ae5db342fb30acf3735391c2c07f) scan of simpewall  
[Hybrid Analysis](https://hybrid-analysis.com/sample/02b4f48506bc441a5eb1528d6ff976b323b07484a7322caf1236f5f5b02b4854) scan of simplewall

Moreover, [simplewall still doesn’t have any digital signature](https://github.com/henrypp/simplewall/issues/211), and the developer doesn’t have knowledge how to sign their software, while this information is publicly accessible. Lack of a certificate is not very important, though desirable.

I also dislike the developer’s attitude, and hence dislike the developer himself:

[1](https://github.com/henrypp/simplewall/issues/1489#issuecomment-1659553095)  
[2](https://github.com/henrypp/simplewall/issues/1488#issuecomment-1658909675)  
[3](https://github.com/henrypp/simplewall/issues/1459#issuecomment-1655131023)

I get it that a lot of people created issues asking about malware (which are highly likely just false positives) in his GitHub simplewall project throughout the years, but it is his duty and responsibility to explain to _the users of his project_ that simplewall doesn’t have any malware and that malware detections are false positives. If he has grown sick and tired of having to deal with all these malware-related GitHub issues, the solution would be for the developer to take his time to explain everything in detail and thoroughly _only once_, in one of these malware-related issues, and then, in the future, when some user creates a yet another malware-related issue, the developer could just put a link to their explanation and close the issue. No problems. He didn’t do that, however.

By answering with “i dont care” you basically say that “I don’t give a single f\*\*\* about you, the user of my application”. It is unprofessional, unethical, disrespectful to the user, negligent, and, after all — rude. I personally don’t want to use a software from such a developer. I like his firewall, however. It’s very light on resources and very simple. Windows Firewall Control is very light and simple, as well. Both are good programs. But I recommend Windows Firewall Control for the reasons I mentioned in my first paragraph.

And I partially disagree with [anon82677111](https://discuss.privacyguides.net/t/windows-guide/250/12). They said:

> Simplewall does not add anything new that cannot be done with the standard Windows firewall.

Windows Firewall lacks the most important usability feature which almost all people expect from a software firewall: the ability to manage connections interactively, that is: the ability to block everything by default _and_ have Windows Firewall prompt you to allow/block connections on the first connection [of an application]. Windows Firewall can’t do that without relying on a third-party software.

---

## Post 5 by @3QVvxrhnYZ — 2023-09-06T01:32:44Z

> [@anon86237473](#):
>
> Portmaster

I have tested Portmaster in the past and it took lots of resources, is very feature-full, and if OP just wants a simple firewall — Portmaster is a bad option. It is bothersome and takes a lot of time to manage, and it has lots of advanced features which the OP may not need. One can use Portmaster if they have an explicit need for Portmaster’s advanced features.

---

## Post 6 by @RevealedInWords — 2023-09-06T03:39:27Z

Thanks, I wasn’t aware of Windows Firewall Control. I’ll have to check it out. I’ve been using TinyWall for a couple years and find it simple and effective, but perhaps I’m missing something? Perhaps there are some concerns with it or the developer similar to Simplewall that I’m not aware of?

---

## Post 7 by @3QVvxrhnYZ — 2023-09-06T05:12:36Z

> [@RevealedInWords](#):
>
> Perhaps there are some concerns with it or the developer similar to Simplewall that I’m not aware of?

No, his app is good, so go ahead if you want to use it. Both Windows Firewall Control and simplewall are good, so use what you prefer. I don’t think simplewall has malware, but I just don’t like the developer’s harsh attitude and maladjusted, maybe even sociopathic behavior:

[1](https://github.com/henrypp/simplewall/issues/1528#issuecomment-1694246415)  
[2](https://github.com/henrypp/simplewall/issues/1526#issuecomment-1691256992)  
[3](https://github.com/henrypp/simplewall/issues/1524#issuecomment-1687600528)  
[4](https://github.com/henrypp/simplewall/issues/1521#issuecomment-1685672630) and [5](https://github.com/henrypp/simplewall/issues/1521#issuecomment-1707432621)  
[6](https://github.com/henrypp/simplewall/issues/1515#issuecomment-1676415181)  
…and so it goes.

I’ve used simplewall myself before I settled on Windows Firewall Control, because I prefer to manage the native firewall that Windows already has, not replace it.

---

## Post 8 by @user1 — 2023-09-06T07:04:25Z

I had used some software firewall in the past but I found them not very user friendly and it was easy to mess with the entire windows system firewall.

I actually use Portmaster now and contrary to @3QVvxrhnYZ I find it a nice and easy option that just works. It is user friendly from basic to advance use if you need advance features, also it doesn’t mess with windows firewall settings.  
The block lists can prevent microsoft telemetry too.  
I don’t find it resource hungry, it’s just not a minimalist firewall and it’s open source and actively developed.

---

## Post 9 by @anon86237473 — 2023-09-06T08:38:51Z

Thank you for the links and info. The guy is indeed a rude asshole. And looks like it’s time to start looking over the firewall options more thoroughly.

Thanks y’all!

---

## Post 10 by @3QVvxrhnYZ — 2023-09-06T09:50:02Z

> [@user1](#):
>
> I don’t find it resource hungry

I’ve just re-installed Portmaster, and you’re right: it’s doesn’t take 10-15% of my CPU as it was long ago. When idling, it’s 0%, as should be. Seems like they’ve fixed it, good. Anyway yeah — it’s not a minimalist firewall at all, it has too many additional features I don’t need. Account, subscriptions, SPN, some network monitoring features (like, from which country does the connection come), and the UI is too cluttered (some network graphs/charts, lots of sorting options) — just “ugh”. It’s not only a firewall, but a network monitoring tool + a firewall, and Portmaster’s landing page mentions that it’s a network monitoring tool, too. It’s quite advanced though, but I don’t like that it wants to be several tools at once. Especially when some of their features are locked behind a paywall. There are better tools for network monitoring, for example. Not for me. I personally need a dumb “yes/no” firewall. Windows Control Firewall and simplewall are both perfect for that.

> [@user1](#):
>
> it was easy to mess with the entire windows system firewall

It’s not possible to mess with WF via simplewall, because they don’t interact with each other. As for Windows Control Firewall, I don’t think it’s possible too, and _even_ if anything happens, you can just reset all the settings via the application itself. You can even restore the state of WF as it was before the installation of Windows Control Firewall.

---

## Post 11 by @Raphty — 2023-09-06T11:13:18Z

Thanks for the recommendation, I just today created an account and saw that this is the latest topic :smiley:

i understand what @3QVvxrhnYZ is saying that Portmaster comes with a lot of features, but it is designed to not be opened and just run on its own - with regular filter list updates and so on.

yes we do offer advanced features behind a pay wall, but everything privacy is free for everyone!  
and a good business model is important to keep the software actively developed and aligned with the users.

What i don’t like about windows firewall UI applications like simple wall is that they can’t restrict apps, as you said its an yes/no per app, not an yes but without trackers or Facebook or…

and the addition of secure DNS is a plus in my book :smiley:

I of course am biased here :sweat_smile: so take my comment with a grain of :salt:

I would love to see Portmaster listed on PG in the secure DNS section

---

## Post 12 by @RevealedInWords — 2023-09-06T16:13:08Z

Checking out Windows Firewall Control and it looks like it has been acquired by Malwarebytes who states: “…not to worry—we will maintain, support, and keep Binisoft products free for everyone in the short term.” Ah well. [https://www.binisoft.org/](https://www.binisoft.org/)

---

## Post 13 by @3QVvxrhnYZ — 2023-09-06T17:39:25Z

> [@Raphty](#):
>
> so take my comment with a grain of :salt:

No, everything you’ve said is valid x)

> [@Raphty](#):
>
> not an yes but without trackers or Facebook or…

As for the browser, blocking trackers can be achieved simply by setting a DNS like NextDNS or AdGuard.  
As for the desktop apps— I agree, that’s where Portmaster can help. If one has some desktop app installed which comes with _commonly_ used trackers, then Portmaster’s filters can block them, without blocking the app’s connection entirely. It’s not my use-case, however, as I don’t have any apps that have trackers, and I entirely block internet access for the apps that ask for it but don’t need it to function. + I have a DNS with filtering set in the router, so filtering happens on the router level for all devices (another home solution for tech-savvy tinkerers is to use Pi-hole), so Portmaster’s local filtering is redundant for me.  
As I said, one can use Portmaster if they need its advanced features, and not a dumb “yes/no” firewall, as Windows Firewall Control or simplewall.

---

## Post 14 by @3QVvxrhnYZ — 2023-09-06T18:39:48Z

That whole Malwarebytes acquisition case, and telemetry-concerns related to it, have been addressed by the developer:

[1](https://www.wilderssecurity.com/threads/windows-firewall-control-wfc-by-binisoft-org.347370/page-178#post-2772683)  
[2](https://www.wilderssecurity.com/threads/windows-firewall-control-wfc-by-binisoft-org.347370/page-186#post-2789051)  
[3](https://www.wilderssecurity.com/threads/windows-firewall-control-wfc-by-binisoft-org.347370/page-177#post-2772461)  
[4](https://www.wilderssecurity.com/threads/windows-firewall-control-wfc-by-binisoft-org.347370/page-203#post-2841107)

And a quote from [here](https://www.wilderssecurity.com/threads/windows-firewall-control-wfc-by-binisoft-org.347370/page-244#post-3001127):

> WFC is on GitHub but on a private repository, not available to public.

As for the minimal telemetry: WFC can be blocked from accessing the internet [when it asks for it for the first time] by WFC itself, so no telemetry is possible:  
 ![wtc](//forum-uploads.privacyguidesusercontent.com/original/2X/9/94b0594c4f35e49992045e93016cda4576e03d07.png)  
I decided _not_ to block it, because the developer said regarding the telemetry:

> The following data is sent once a day to Malwarebytes: program version, os version, os architecture (x64, x86), os language (english, german, etc), filesystem (ntfs, fat32), process run as administrator or not, computer is joined into a domain or not, machine id. No personal data is collected. These are used for statistics data to see how many users of WFC exist. Depending on the number of existing users, WFC will continue to receive new features or not. A reduced number of installations will probably stop the development of WFC, a large number will probably continue the development.

---

## Post 15 by @prosperina — 2023-09-06T18:51:57Z

I second Simplewall, it’s quite effective and really easy to use. I was not aware of the attitude of the developer but I don’t think we should be making decisions based on that. If the product works and is getting maintained properly, that’s all that matters.

For example, the folks at Portmaster have been extremely nice and patient with their users. I got the Pro subscription way back when it was in the kickstarter phase, but unfortunately I never really liked it for similar reasons that @3QVvxrhnYZ mentioned: awkward interface hard to make sense of, needs a lot of setup and tuning, random connection issues, etc. Sorry @Raphty :frowning:

---

## Post 16 by @anon63378630 — 2023-09-06T19:05:33Z

It should be noted that Simplewall wrongly breaks Windows Update by default.  
Be sure to enable it again: [GitHub - henrypp/simplewall: Simple tool to configure Windows Filtering Platform (WFP) which can configure network activity on your computer.](https://github.com/henrypp/simplewall#q-how-to-fix-windows-update-internet-access)

edit: apparently fixed

edit edit: maybe not, double check it

---

## Post 17 by @3QVvxrhnYZ — 2023-09-06T19:54:04Z

No, by default simplewall doesn’t interfere with Windows Update. Recently I’ve done several fresh Windows installations, and likewise several fresh simplewall installations. By default everything works normally. If there was such an issue in the past — it got fixed most likely.

---

## Post 18 by @4hjp7l9mt — 2023-09-06T19:58:53Z

> [@3QVvxrhnYZ](#):
>
> As I said, one can use Portmaster if they need its advanced features, and not a dumb “yes/no” firewall, as Windows Firewall Control or simplewall

This is my setup here.  
I have Simplewall as a simple whitelist program to allow programs to access the Internet if needed. It’s really fast and light.  
I have Portmaster running as a more advanced filter similar to how Glasswire or Adguard Desktop works. I can see which websites or IP addresses programs send info to and shut them off from there. However, Portmaster really is resource-heavy, and has some funky behavior with Hyper-V VMs. Have had to restart my PC many times after shutting down and starting up Portmaster again due to the network adapter just going kaput

---

## Post 19 by @3QVvxrhnYZ — 2023-09-06T20:02:10Z

Why use two firewalls? Why just not use Portmaster (as you need its features) for blocking internet access for apps?

---

## Post 20 by @anon86237473 — 2023-09-06T20:09:18Z

> [@prosperina](#):
>
> but I don’t think we should be making decisions based on that. If the product works and is getting maintained properly, that’s all that matters

If the product doesn’t have an equivalent and it is something which is needed, then yes it probably shouldn’t affect the decision of whether to use it or not.

But when there _are_ similar tools available and the developer’s response to “hey why does your program show up as a virus” is literally"i don’t care", then it sure as hell is a factor. It is unprofessional and erodes the users trust in the developer. Which in the case of FLOSS is everything for people like me that know next to nothing about programming.

@anon63378630  
Just to be clear, it was turned off on my (up to-date) version, so should I turn it on or not?

---

## Post 21 by @anon63378630 — 2023-09-06T20:14:15Z

@anon86237473  
yes you want Windows Update working, your system will turn to swiss cheese otherwise

---

## Post 22 by @3QVvxrhnYZ — 2023-09-06T20:17:13Z

> [@anon86237473](#):
>
> Just to be clear, it was turned off on my (up to-date) version, so should I turn it on or not?

Here’s how you should have it:

 ![simplewall](//forum-uploads.privacyguidesusercontent.com/original/2X/8/8b4785a5b5308fcb90c1c7f7d0f2c7721ce01fd8.png)

“Disable” means _not_ that the connections to Windows Update are blocked, it’s the other way around: it means that simplewall’s rules won’t apply to Windows Update. It’s just that the developer is really bad at English.

---

## Post 23 by @anon63378630 — 2023-09-06T20:18:38Z

@3QVvxrhnYZ  
are you sure about that? It sounds like it will actually disable the components.

Windows update should be enabled and unblocked.

edit: I just dug into the source and there appear to be two different mechanisms at play here:

- application based firewall (allow/block) rules
- and a domain blocklist system which can be disabled, allowed, or blocked

your picture is only covering the blocklist part, not whether the actual program is blocked or not.

---

## Post 24 by @anon86237473 — 2023-09-06T20:28:41Z

> Open main window menu `Settings` → `Rules` → `Allow Windows Update`

Yeah, just enabled this setting and boy do I have a lot of missing updates. I’ve basically been running around with my pants around my ankles for over a year…

Thanks guys!

---

## Post 25 by @3QVvxrhnYZ — 2023-09-06T20:29:22Z

Yeah it’s confusing, but in short: a rule has 3 states: allowed, blocked, and disabled. Disabled means that the rule itself is disabled, that is — it’s not active/it doesn’t apply to a connection. [See this](https://github.com/henrypp/simplewall/issues/512)

Anyway, regarding @anon86237473’s question, they can either “Disable (recommended)” or “Allow” Windows Update. To be on the safe side, I guess it’s best to “Allow”. I personally didn’t have any problems with Windows Update when it was “Disable (recommended)”.

---

## Post 26 by @anon63378630 — 2023-09-06T20:55:07Z

Again there are two different ways for Windows Update to be broken by it.  
For WU to work it must be:

- Set to `Disable` or `Allow` in `Blocklist` settings \< the default here is fine.
- `Allow Windows Update` enabled in `Rules` settings \< this is the important one.

---

## Post 27 by @prosperina — 2023-09-06T21:32:02Z

> [@anon86237473](#):
>
> It is unprofessional and erodes the users trust in the developer. Which in the case of FLOSS is everything for people like me that know next to nothing about programming.

Not that I enjoy being treated like trash when asking genuine questions, but for me the trust with the developer comes from whether work is getting done or not i.e., product is regularly being updated with security patches and bug fixes, new features being added (when applicable), etc… After all, you don’t have to interact with the developer to use the product. I for one have been using Simplewall for years and never even knew the guy was such a jerk.

I think is more important that there’s an active community or large user base so that you can receive support from other members as well, instead of relying from the developer(s) directly. But anyway this is already off-topic.

---

## Post 28 by @3QVvxrhnYZ — 2023-09-07T07:07:36Z

> [@anon63378630](#):
>
> `Allow Windows Update` enabled in `Rules` settings \< this is the important one.

Oh, I totally forgot about it. On GitHub it says: “Open main window menu `Settings` → `Rules` → `Allow Windows Update` .” I thought that `Settings` is to click the cog icon on the toolbar (which is how I’ve always been accessing simplewall’s settings; I’ve never been doing anything via `Settings` on the ribbon), not the `Settings` button on the ribbon. In `Settings` via the cog icon, there’s no option related to Windows Update. So I thought that the info on GitHub is outdated and the issue was fixed, or something like that. Well, can’t blame me: to put two options related to Windows Update into two completely different places is bad UI. Anyway, I had `Allow Windows Update` unchecked all that time and had no problems with Windows Update.

---

## Post 29 by @Average_Joe — 2023-09-19T13:40:41Z

I appreciate all of your replies!!!

I’m looking through all of the links posted in this thread.

Could someone please help me with my question regarding:  
**“If I have a Windows 10 PC connected to a hardware firewall device like a specialised Firewall Linux Distro, will the Firewall Linux Distro still be work if I have an installed on the Windows 10 PC that contains a trojan that’s sending data back to an author on the Internet?”**

---

## Post 30 by @user1 — 2023-09-19T15:35:26Z

If your pc is infected with a trojan you should consider your computer as compromised, the firewall can’t really help.

---

## Post 31 by @Average_Joe — 2023-09-19T16:59:57Z

Yes of course, I’ll try to explain it in another way:

**Let’s forget the idea of a trojan. Let’s just say that an App installed on a Windows 10 PC contacts the Internet and sends personal and private data about the user to someone on the Internet. This App didn’t ask you for permission, but just does this transfer of data as “normal functioning”.**

In the above situation, how does a Linux firewall installed on a hardware device protect the Windows 10 PC?

---

## Post 32 by @user1 — 2023-09-19T20:25:29Z

Well, i’m not and expert but firewalls usually block only addresses so I don’t think it makes any difference if it’s some app or some malicious code, if they have access to the internet they can send and receive data unless the address they’re connecting to is blocked. If you block the connections of an app who needs that to work, it will probably stop working.

---

## Post 33 by @Average_Joe — 2023-10-03T16:18:18Z

> [@user1](#):
>
> Well, i’m not and expert but firewalls usually block only addresses so I don’t think it makes any difference if it’s some app or some malicious code, if they have access to the internet they can send and receive data unless the address they’re connecting to is blocked. If you block the connections of an app who needs that to work, it will probably stop working.

I appreciate your reply!

However, it should be simple to block for a firewall to block a particular app from accessing the Internet.

**Like I said, in the Windows 10 Pro built-in firewall I’ve blocked VLC media player from accessing the Internet, but it’s still able to “Check for updates” and it can update itself if an update has been released… :cry: :cry: :cry:**

It’s incredibly important that a firewall can actually block an app from accessing the Internet…

---

## Post 34 by @anon39565454 — 2023-10-04T08:30:23Z

Do you plan on creating an offline installer? An online only installer really hogs bandwidth on multi-machine installation. And the lack of offline installer means no distro packaged/flatpak integration. This limits us to your mirror which is a lot of times (at least for me) quite slow

---

## Post 35 by @Raphty — 2023-10-05T09:29:22Z

Offline will come in the future, but it is not a high priority.

The issue with Flatpak is the level of Integration that is required for a firewall, Sand boxing and deep system integration does not go well together :smiley:

---

## Post 36 by @anon39565454 — 2023-10-06T05:22:35Z

> [@Raphty](#):
>
> Offline will come in the future, but it is not a high priority.

Why is it not? It goes against the standard application distribution norm and hurts adoption for people with less than stellar internet, it’s also annoying that the linux distribution method consists of downloading files from a website (which is not the standard method and definitely increases the risk of fake websites etc) . It not being able to be properly packaged also means that it depends on safing server when there is absolutely no reason to.

And “will come in the future” only goes so far when it has already been 4 years since the feature was asked

> <https://github.com/safing/portmaster/issues/13>
>
> For people with difficult internet-access (censorship, bad internet, expensive i…nternet), an offline installer and the ability to upgrade from a different location (local mirror of updates.safing.io inside a company, USB drive, ...) would be great.

---

## Post 37 by @Average_Joe — 2023-10-13T11:05:43Z

Okay so in built-in Windows 10 Pro Firewall I’ve got VLC Player App blocked from accessing the Internet and VLC released an update today and there were no problems with the VLC Player App downloading the update. I just completed the update 5 minutes ago…

It seems like I’ll need to install another firewall App because the built-in Windows 10 firewall isn’t even doing something as basic as blocking an App from contacting the Internet.

Does anyone have experience with the Windows 11 built-in firewall?

---

## Post 38 by @3QVvxrhnYZ — 2023-10-13T17:14:18Z

You may have configured your blocking rules incorrectly. You need to create outbound rules to block an app.

> [@Average_Joe](#):
>
> I’ll need to install another firewall

> [@3QVvxrhnYZ](#):
>
> Best tool to manage Windows Firewall natively is [Windows Firewall Control](https://www.binisoft.org/wfc)

---

## Post 39 by @Average_Joe — 2023-10-13T22:57:43Z

I appreciate your reply!

I’ve spent a lot of time trying to configure the Windows 10 Pro’s built-in firewall, but I just can’t seem to get it to do the basic task of blocking apps from contacting the Internet like the VLC Player App…

Does anyone have experience with Glasswire?

The list of features is staggering and the price is decent at $3 per month per device:

> **[Free Network Monitor Software by GlassWire](https://www.glasswire.com/pricing/)**
>
> GlassWire free firewall software and network monitor can detect threats other miss. Download GlassWire free firewall now to protect your computer.

---

## Post 40 by @Average_Joe — 2023-10-27T20:02:16Z

I’m still researching this as it seems like such an extremely important question that needs to be answered.

From everything I’ve looked at it still seems like Glasswire has the best features.

I’m also looking into the firewall from Bitdefender as this is extremely popular from the reviews I’ve been reading: [Bitdefender Security Software Solutions for Home Users](https://www.bitdefender.com/solutions/)

Norton seems like a bad choice since it uses up so much resources and many seem to question their customer privacy.

Edit:  
I mean what’s the point of having an advanced router/Linux distribution hardware firewall when you have a single Windows 10/11 App that’s leaking your personal data…

---

## Post 41 by @anon39565454 — 2023-10-28T06:34:38Z

Just use simplewall or safing portmaster, no point of getting bitdefender when the reviews are mostly SEO spam and they’ll likely kept trying to upsell you to their AV. And no point paying for glasswire when simplewall/portmaster works perfectly fine

---

## Post 42 by @Andell — 2023-10-31T23:20:07Z

This is a topic I am very much interested in. Frankly, I am convinced I must be searching for a unicorn, since I haven’t really been satisfied with any of the firewalls I’ve tried.

I feel like I could talk at length about it, but my impressions boil down to:

**SimpleWall** : What I use now, small, lean, and effective, but with a poor UI and somewhat confusing settings.

**Glasswire** : Excellent UI for its network monitor component and handy extra features, but with a concerning [privacy policy](https://www.glasswire.com/privacy/) and seemingly watered down firewall compared to SW.

**NetLimiter** : The rule system seemed kind of complicated and I think the notification system was worse than SimpleWall’s. I prefer a “default block all and ask me” approach, but it failed to register some apps and would block them not only without asking me, but without even registering them in the UI for me to apply rules to manually.

**TinyWall** : This could be good, but the “block without asking” approach is the opposite of what I want.

**Comodo Firewall** : Bloated with nonsense. This could be user error on my part. But I followed the link people said to use if you want only the firewall and not the antivirus bundled with it, and even then, when I opened the firewall, it still came with a quarantine and other entirely unnecessary things.

**Fort Firewall** : I really wanted to try this one, but you have to disable core isolation :frowning:

**Windows Firewall Control:** I briefly tried this. Honestly it seemed like a pretty good option, but I didn’t like it _more_ than SimpleWall. It’s also closed source, and although you can block it, it sends some usage data back once a day.

**Portmaster** : Honestly, this was by far my favorite in many ways. But every time I ran it I had crippling performance issues. I participated for a while in a GitHub issue about it, but I ultimately lost hope it would be fixed (I say this with all due respect to the very talented devs who work on it!). Moreover, that’s before I even began to try to make it work with ProtonVPN, which ultimately I would have to do. And I also do not want it to touch my DNS settings, as I would prefer to blend in with other ProtonVPN users as someone using Proton’s DNS. I am aware as to this last point you can force Portmaster to use system default DNS, but the other issues preclude getting to this point.

That last bit is also what basically rules out DNS based solutions for me too, like NextDNS type stuff.

In an ideal world, I’d like to see something (1) open source (2) with a SimpleWall-like firewall (3) and a GlassWire-like UI (4) that doesn’t send back telemetry. I would not mind paying for a good option though, even a subscription fee. Its nice seeing what others have to say on the topic though, and I can only hope more options arrive and existing options continue to improve.

And don’t even get me started on the downright **ABYSMAL** options for a firewall on Android…

---

## Post 43 by @Average_Joe — 2023-11-07T12:56:57Z

> [@Andell](#):
>
> This is a topic I am very much interested in. Frankly, I am convinced I must be searching for a unicorn, since I haven’t really been satisfied with any of the firewalls I’ve tried.
> 
> I feel like I could talk at length about it, but my impressions boil down to:
> 
> **SimpleWall** : What I use now, small, lean, and effective, but with a poor UI and somewhat confusing settings.
> 
> **Glasswire** : Excellent UI for its network monitor component and handy extra features, but with a concerning [privacy policy](https://www.glasswire.com/privacy/) and seemingly watered down firewall compared to SW.
> 
> **NetLimiter** : The rule system seemed kind of complicated and I think the notification system was worse than SimpleWall’s. I prefer a “default block all and ask me” approach, but it failed to register some apps and would block them not only without asking me, but without even registering them in the UI for me to apply rules to manually.
> 
> **TinyWall** : This could be good, but the “block without asking” approach is the opposite of what I want.
> 
> **Comodo Firewall** : Bloated with nonsense. This could be user error on my part. But I followed the link people said to use if you want only the firewall and not the antivirus bundled with it, and even then, when I opened the firewall, it still came with a quarantine and other entirely unnecessary things.
> 
> **Fort Firewall** : I really wanted to try this one, but you have to disable core isolation :frowning:
> 
> **Windows Firewall Control:** I briefly tried this. Honestly it seemed like a pretty good option, but I didn’t like it _more_ than SimpleWall. It’s also closed source, and although you can block it, it sends some usage data back once a day.
> 
> **Portmaster** : Honestly, this was by far my favorite in many ways. But every time I ran it I had crippling performance issues. I participated for a while in a GitHub issue about it, but I ultimately lost hope it would be fixed (I say this with all due respect to the very talented devs who work on it!). Moreover, that’s before I even began to try to make it work with ProtonVPN, which ultimately I would have to do. And I also do not want it to touch my DNS settings, as I would prefer to blend in with other ProtonVPN users as someone using Proton’s DNS. I am aware as to this last point you can force Portmaster to use system default DNS, but the other issues preclude getting to this point.
> 
> That last bit is also what basically rules out DNS based solutions for me too, like NextDNS type stuff.
> 
> In an ideal world, I’d like to see something (1) open source (2) with a SimpleWall-like firewall (3) and a GlassWire-like UI (4) that doesn’t send back telemetry. I would not mind paying for a good option though, even a subscription fee. Its nice seeing what others have to say on the topic though, and I can only hope more options arrive and existing options continue to improve.
> 
> And don’t even get me started on the downright **ABYSMAL** options for a firewall on Android…

I appreciate your reply!

I have experience with Netlimiter Pro from a few years ago and it worked great at monitoring my download and upload speeds and limiting the speeds but I’m not sure if it would work well as a dedicated firewall?

The inbuilt Windows 10 Firewall still doesn’t work for me even when I block VLC from contacting the Internet, VLC was still able to download the most recent update… :disappointed_relieved: :disappointed_relieved:

To me, Glasswire seems like the best option?

Edited:  
I’m still hoping somone can help me with how effective a Linux firewall hardware device is when there’s a Windows 10 PC on the network that has a trojan installed and is sending personal information back to someone on the Internet???

---

## Post 44 by @pinkandwhite — 2023-11-07T13:16:32Z

> [@Average_Joe](#):
>
> The inbuilt Windows 10 Firewall still doesn’t work for me even when I block VLC from contacting the Internet, VLC was still able to download the most recent update

I’m not sure how that’s possible, unless you misconfigured the built-in firewall – I just did a test blocking all outbound connections for the vlc executable and it just errored out when checking for updates without downloading anything until I removed the rule blocking it

---

## Post 45 by @Average_Joe — 2023-11-07T13:39:13Z

> [@pinkandwhite](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/average_joe/48/6_2.png) Average\_Joe:
> 
> > The inbuilt Windows 10 Firewall still doesn’t work for me even when I block VLC from contacting the Internet, VLC was still able to download the most recent update
> 
> I’m not sure how that’s possible, unless you misconfigured the built-in firewall – I just did a test blocking all outbound connections for the vlc executable and it just errored out when checking for updates without downloading anything until I removed the rule blocking it

I’ve tried using the inbuilt Windows Firewall and it just doesn’t work for me. I’m running a genuine copy of Windows 10 Pro.

Perhaps it’s better in Windows 11 Pro???

---

## Post 46 by @Average_Joe — 2023-11-07T13:44:00Z

Regarding Net Limiter:

I had a great experience with this App but I’m not sure it will be restrictive enough to work as an effective firewall.

I’m writing an email to the developers now.

I’ll report back here.

---

## Post 47 by @pinkandwhite — 2023-11-08T00:51:40Z

> **Screenshots of the rule**
>
> ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/d/de38cdf6a6e770ed1f4aaaf6171a693a7ff2fd92.png)  
> ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/1/15550fbc60e55ac622c45b4d978aa3a5fcf3ecf1.png)  
> ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/3/33741440b813c6ee06177ac377cded2ec1e25b79.png)

Is your rule exactly like the above? The screenshots are from win11 enterprise/edu but fundamentally, later versions of win10 are very similar to win11 so I wouldn’t expect the firewall to be dramatically different

---

## Post 48 by @cromagnonymous — 2023-11-22T07:44:55Z

I think your issue might be something else that hasn’t been properly identified yet. VLC shouldn’t update automatically, it should _prompt_ you to update when you open it, but you can reject the prompt. In fact, in the preferences menu you can disable update checks completely.

Your comments make me wonder if you have some 3rd party software managing your apps like a Microsoft Azure domain, an installation manager like Chocolatey (or some other update manager program), or if you installed VLC through the Microsoft Store (in which case it would be updated by the MS Store’s connections, which would explain why blocking vlc.exe in your firewall has had no effect.)

Also, if it’s the little Christmasy things that bother you, those are probably built directly into the VLC app and get activated at certain times of year, _not_ triggered through app updates. Try putting your PC in airplane mode and setting your system clock to Dec 25th to see if it appears (or conversely, set it to sometime in June to see if it goes away).

---

## Post 49 by @RChadwick — 2023-12-25T02:19:28Z

I’ve switched between Tinywall and Simplewall for years, if not a decade. I originally liked that simplewall had a pop-up (I think), but apparently that’s gone. Simplewall, without a popup, is more confusing than Tinywall. I like that Tinywall blocks by default so that something bad doesn’t get an opportunity. I thought simplewall was the same, but apparently not. I installed Creality Print and was surprised it could access the Internet easily. I then tried creating a rule, unsuccessfully. I then posted it on their Github and I can confirm the developer is a class A asshole. If I can’t trust a developer, can I trust their firewall? I’ve permanently removed simplewall from memory and eventually all my computers. Now it’s between Tinywall and Portmaster. It seems Portmaster is still having some growing pains but I’m very happy with Tinywall. Unlike simplewall, you can actually see a list of connections, and blocked apps. If an app isn’t working, you can easily find it in the list and unblock it. Finding a particular app in simplewall is a nightmare.

---

## Post 50 by @Average_Joe — 2024-01-22T19:11:02Z

> [@pinkandwhite](#):
>
> Is your rule exactly like the above? The screenshots are from win11 enterprise/edu but fundamentally, later versions of win10 are very similar to win11 so I wouldn’t expect the firewall to be dramatically different

I appreciate your reply!

This issue is really serious and remains unsolved so I’m going to retry the in-built Windows 10 firewall on my Windows 10 Pro PC.

---

## Post 51 by @Average_Joe — 2024-01-22T20:17:49Z

> [@cromagnonymous](#):
>
> I think your issue might be something else that hasn’t been properly identified yet. VLC shouldn’t update automatically, it should _prompt_ you to update when you open it, but you can reject the prompt. In fact, in the preferences menu you can disable update checks completely.

I appreciate your reply!

You’re correct that my VLC doesn’t automatically update, but since it’s able to check for updates that means that it can access the Internet otherwise it would give an error like “Not connected to internet”.

> [@](#):
>
> Your comments make me wonder if you have some 3rd party software managing your apps like a Microsoft Azure domain, an installation manager like Chocolatey (or some other update manager program), or if you installed VLC through the Microsoft Store (in which case it would be updated by the MS Store’s connections, which would explain why blocking vlc.exe in your firewall has had no effect.)

I don’t have any 3rd party software managing my Apps as I’ve tried to keep my Windows 10 PC as lean as possible.

I’m 99% sure I didn’t install VLC from the MS Store but I installed VLC so many years ago now…

Also, if it’s the little Christmasy things that bother you, those are probably built directly into the VLC app and get activated at certain times of yea  
[/quote]

Okay I see!

I just assumed that VLC was accessing the Internet and being told to add that “Christmas thingy” to my VLC App!

---

## Post 52 by @Average_Joe — 2024-01-23T06:19:44Z

I really used to think having a dedicated Linux distro firewall would be a great guardian, but now I know that it would only take one single app on one of my Windows PC’s to have a backdoor that connected to someone on the Internet to destroy the security of my whole home network.

It just seems so easy for a Windows app to send off a user’s personal information to the Internet…

---

## Post 53 by @sha123 — 2024-01-23T13:05:44Z

> [@Average_Joe](#):
>
> It just seems so easy for a Windows app to send off a user’s personal information to the Internet…

That’s a general problem with unsandboxed apps. On Linux it’s not different. If you use a sudo account for everyday use, it’s even easier for malicious apps to manipulate firewall rules than on Windows.

---

## Post 54 by @Average_Joe — 2024-02-16T14:20:07Z

> [@sha123](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/average_joe/48/6_2.png) Average\_Joe:
> 
> > It just seems so easy for a Windows app to send off a user’s personal information to the Internet…
> 
> That’s a general problem with unsandboxed apps. On Linux it’s not different. If you use a sudo account for everyday use, it’s even easier for malicious apps to manipulate firewall rules than on Windows.

I appreciate your reply!

**What’s the best way to sandbox an App in Windows 10 Pro?**

This may be helpful for others: It’s worth paying extra for Windows 10/11 Pro over Home Edition because it gives the user more control over what data is sent to Microsoft.

Edited:

I’m looking at this now but I’m not sure this is what Privacy Guides Community recommends: [Windows Sandbox | Microsoft Learn](https://learn.microsoft.com/en-us/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-overview)

---

## Post 55 by @exaCORE — 2024-02-16T17:44:24Z

> [@Average_Joe](#):
>
> I’m looking at this now but I’m not sure this is what Privacy Guides Community recommends:

Not using Windows.

---

## Post 57 by @Average_Joe — 2024-02-16T22:36:47Z

> [@exaCORE](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/average_joe/48/6_2.png) Average\_Joe:
> 
> > I’m looking at this now but I’m not sure this is what Privacy Guides Community recommends:
> 
> Not using Windows.

I appreciate your reply!

Woah, I just checked the recommendations for ‘Operating Systems’ and you’re right! There’s a recommendation for all the major OS’ except for Windows!

Edit:

Is the official sandbox App from Microsoft not even worth using???

---

## Post 58 by @exaCORE — 2024-02-16T22:59:36Z

> [@Average_Joe](#):
>
> Woah, I just checked the recommendations for ‘Operating Systems’ and you’re right! There’s a recommendation for all the major OS’ except for Windows

The only official recommendations are Linux and Android (GrapheneOS, DivestOS), however there are knowledge base articles about other OSes. A windows one might be coming soon based on the work of a few users on this forum. However, I would recommend using Linux, as many things are compatible nowadays or can be run using Wine. If you still need windows, you could always dual boot and Distros like Fedora make Linux easy and painless to use.

---

## Post 59 by @Average_Joe — 2024-02-16T23:07:38Z

> [@exaCORE](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/average_joe/48/6_2.png) Average\_Joe:
> 
> > Woah, I just checked the recommendations for ‘Operating Systems’ and you’re right! There’s a recommendation for all the major OS’ except for Windows
> 
> The only official recommendations are Linux and Android (GrapheneOS, DivestOS), however there are knowledge base articles about other OSes. A windows one might be coming soon based on the work of a few users on this forum. However, I would recommend using Linux, as many things are compatible nowadays or can be run using Wine. If you still need windows, you could always dual boot and Distros like Fedora make Linux easy and painless to use.

I appreciate your reply.

I’m just really surprised that there is no sandbox recommendation for Windows since it has by far the highest market share.

Keeping inline with staying with Microsoft products, the sandbox App/Feature from Microsoft must be the best for Windows?

Edit:

Does anyone have experience with the Microsoft Sandbox App?

Is it safe for me to install that Microsoft Sandbox App located here?: [Windows Sandbox | Microsoft Learn](https://learn.microsoft.com/en-us/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-overview)

---

## Post 60 by @monkeylove — 2024-05-03T06:54:31Z

According to this,

> **[The 5 Different Types of Firewalls Explained](https://www.techtarget.com/searchsecurity/feature/The-five-different-types-of-firewalls)**
>
> Read up on the advantages and disadvantages of five different types of firewalls, plus three firewall deployment models and firewall placement options.

there are different types of firewalls, but forum members are comparing them as if they were alike, or that a simple firewall is as good (“it just works”) as the opposite.

Some allow or deny apps, etc., from accessing the net or other devices. Others look at the data passed and then drop those that don’t meet certain criteria, and so on.

If it’s simply default-deny, and you have to figure out what to allow, then how do you know that you’re doing the right thing? If it checks things like digital signatures, then how do you know that approved apps aren’t passing along malware?

---

## Post 61 by @Average_Joe — 2024-05-09T04:09:33Z

> [@monkeylove](#):
>
> According to this,
> 
> [The 5 Different Types of Firewalls Explained](https://www.techtarget.com/searchsecurity/feature/The-five-different-types-of-firewalls)
> 
> there are different types of firewalls, but forum members are comparing them as if they were alike, or that a simple firewall is as good (“it just works”) as the opposite.
> 
> Some allow or deny apps, etc., from accessing the net or other devices. Others look at the data passed and then drop those that don’t meet certain criteria, and so on.
> 
> If it’s simply default-deny, and you have to figure out what to allow, then how do you know that you’re doing the right thing? If it checks things like digital signatures, then how do you know that approved apps aren’t passing along malware?

I appreciate your reply!

Welcome to the community!

**I’m examining Glasswire again and they now offer their Android software firewall for free with all the premium features:**

> <https://play.google.com/store/apps/details?id=com.glasswire.android&hl=en_US&gl=US>
>
> Protection from data usage overages, bandwidth wasting apps, and more...

---

## Post 62 by @anon63378630 — 2024-05-09T09:44:31Z

@Average_Joe  
why would you use a proprietary firewall app?

see instead maybe NetGuard or RethinkDNS

---

## Post 63 by @iamnotamonk — 2024-05-09T20:06:56Z

A simple way: VPN kill switch mode and apply it to all apps that you dont want to connect to internet. Works also in android

---

## Post 64 by @Average_Joe — 2024-05-13T20:52:38Z

> [@anon63378630](#):
>
> @Average_Joe  
> why would you use a proprietary firewall app?
> 
> see instead maybe NetGuard or RethinkDNS

I appreciate your reply!

However, my number 1 concern by far and away is a software firewall for a Windows PC. The links you gave are for Android OS.

I posted that Android link from Glasswire because it was free and included premium features so I thought it’d be useful for this community.

**I desperately need to choose a software firewall for my Windows PC so any help you could offer would be greatly appreciated!**

---

## Post 65 by @Average_Joe — 2024-05-13T21:41:03Z

Portmaster is looking like a great choice.

They’re open source but they also have a premium product with more features:

> **[Safing Portmaster - Pricing](https://safing.io/pricing/)**
>
> Portmaster is a free and open-source application that puts you back in charge over all your computer's network connections. Increase your privacy and security. Get peace of mind.

I just came across some great guides here where it directly compares itself to the most popular software firewalls available:

> **[What Makes Portmaster A Great Alternative to GlassWire](https://safing.io/blog/2022/08/17/portmaster-vs-glasswire/)**
>
> Portmaster is a free and open-source application that puts you back in charge over all your computer's network connections. Increase your privacy and security. Get peace of mind.

> **[What Makes Portmaster A Great Alternative to Simplewall](https://safing.io/blog/2022/04/11/portmaster-vs-simplewall/)**
>
> Portmaster is a free and open-source application that puts you back in charge over all your computer's network connections. Increase your privacy and security. Get peace of mind.

> **[What Makes Portmaster A Great Alternative to Pi-hole](https://safing.io/blog/2021/12/09/portmaster-vs-pi-hole/)**
>
> Portmaster is a free and open-source application that puts you back in charge over all your computer's network connections. Increase your privacy and security. Get peace of mind.

It still seems like I’ve got a lot of research to do!

**I’ll keep posting to this thread whenever I find valuable information because I think a Software Firewall is the cornerstone of maintaining user privacy on a Windows PC.**

> [@iamnotamonk](#):
>
> A simple way: VPN kill switch mode and apply it to all apps that you dont want to connect to internet. Works also in android

I appreciate your reply!

I’m not really sure why you brought up a VPN? I don’t see how a VPN would prevent an app like a PDF reader from sending data back to someone on the Internet?

---

## Post 66 by @iamnotamonk — 2024-05-13T22:52:30Z

It’s not it main purpose nor it is designed to do specifically that. However, at least on Android, if you active Always On VPN and Block Connections with VPN, and if you have an option to select which apps to route through VPN and which don’t, you can exclude apps from the VPN as if you would wanting them to don’t connect through the VPN. However, because you have Block All Connections without VPN activated, apps of which the traffic is supposedly being not send through the VPN, can’t in fact connect to internet (because they are excluded from VPN and you prohibited non-VON connections).

---

## Post 67 by @mika — 2024-05-14T02:39:18Z

> [@Average_Joe](#):
>
> Portmaster is looking like a great choice.
> 
> They’re open source but they also have a premium product with more features:

I used Portmaster a few years ago and I found it powerful, but also buggy and dogged with a very confusing UI/UX. I see that they’ve done lots of updates since then, so hopefully those issues no longer apply.

If you try it please report back on what your experience is.

---

## Post 68 by @haso — 2024-05-15T10:57:15Z

I had the same experience a few years ago and recently tried it. But sadly no.. I don’t know how but it’s still buggy and the interface is still the same. Maybe even worse because some of the time the interface takes like 20s to load.

If the devs see this, they should take a look at the Glasswire Interface. Especially the “Traffic Monitor” Tab. If they could somehow replicate that and clean up the UI so it doesn’t feel so unorganised and straight up bad, I might at least consider switching to it in the future. After installing and removing portmaster at least 5 times I’m starting to give up but maybe they’ll listen to people somehow idk i’m trying not to lose hope here.

Here is how the Glasswire “Traffic Monitor” Tab looks for comparison:

 ![2024-05-15_12-32-44](//forum-uploads.privacyguidesusercontent.com/original/2X/6/64dfbfe1cabd55225cceae65d1f085ee2be07a22.png)

1. Very clean and nice looking UI without any unnecessary information or bad looking UI elements
2. no information overload
3. very responsive
4. you can select a custom time stamp and look at how many MB a specific application uploaded/downloaded
5. you can select a custom time stamp, and look at which hosts/domains the application connected to and how many MB they exchanged between each other (upload and download)
6. I could go on and on why I prefer this 100x to portmaster

What I’m trying to say is that portmaster’s interface just feels so much worse in comparison to competitors. I know glasswire doesn’t do all the privacy stuff with filtering and so on. You can still setup a custom dns server though and will at least get 70% of portmasters filtering without having to deal with a buggy software, even worse UI/interface and sometimes the internet just not working on your pc.

I like portmasters idea and I really appreciate that some people are at least working on this. But the product is honestly so bad I don’t even feel at ease recommending it to anyone or installing it on a pc of my friends or family. Maybe this will be a wake up call to them or at least understand why people don’t like it. **Hopefully..** Or they just read this and say “ohh right. This is just the personal opinion of this one person so who cares”. Not knowing that 90% of users are thinking the same thing. idk what more to say honestly. This text got much bigger than i expected and I put more time to it then I wanted. But maybe it will help portmaster to identify their problems and fix them. Maybe and hopefully!

---

## Post 69 by @ignoramous — 2024-06-19T21:35:08Z

> [@Average_Joe](#):
>
> I posted that Android link from Glasswire because it was free and included premium features so I thought it’d be useful for this community.

Glasswire has been sold by its founders to an Italian firm. Prudent to re-calibrate your choice.

---

## Post 70 by @Average_Joe — 2024-06-24T22:10:54Z

> [@ignoramous](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/average_joe/48/6_2.png) Average\_Joe:
> 
> > I posted that Android link from Glasswire because it was free and included premium features so I thought it’d be useful for this community.
> 
> Glasswire has been sold by its founders to an Italian firm. Prudent to re-calibrate your choice.

I appreciate your reply!

Maybe an open source firewall is the best way to go?

The built-in Windows 10 firewall just seems to be lacking so much functionality.

---

## Post 71 by @Average_Joe — 2024-07-02T01:14:14Z

> [@ignoramous](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/average_joe/48/6_2.png) Average\_Joe:
> 
> > 
> 
> Glasswire has been sold by its founders to an Italian firm. Prudent to re-calibrate your choice.

I’ve been doing some more research and [safing.io](http://safing.io) seems like the best option from everything I’ve seen and wow, I have sure seen a lot of different software firewalls for Windows PC’s:

This gives a really clear list of comparing:

> **[Safing Portmaster - Pricing](https://safing.io/pricing/#comparison)**
>
> Portmaster is a free and open-source application that puts you back in charge over all your computer's network connections. Increase your privacy and security. Get peace of mind.

---

## Post 72 by @ph00lt0 — 2024-07-02T20:15:39Z

For dns filtering sure. If you really rely on it you better also configure the build in one. It surely woll be offering the most security.

---

## Post 73 by @Average_Joe — 2024-12-23T19:12:02Z

> [@ph00lt0](#):
>
> For dns filtering sure. If you really rely on it you better also configure the build in one. It surely woll be offering the most security.

I appreciate your reply!

The more research I do the more it seems like PortMaster Firewall is the best available option.

**What really gets me is that even if I build a dedicated Linux firewall device for my home network the Windows 10 devices could still leak data if there’s one App on the Windows 10 devices that has a trojan for example.**

**It just seems necessary to have a Windows software firewall.**

Here’s a link for a list of features: [Safing Portmaster - Pricing](https://safing.io/pricing/#comparison)

---

## Post 74 by @Bhaelros — 2024-12-24T08:59:58Z

Portmaster seems to have a nice UI compared to others but if you are planning to use VPNs, you are going to have a bad time. I tried with Proton and Windscribe and PM cut my internet connection completely.

---

## Post 75 by @Average_Joe — 2025-01-31T12:49:37Z

> [@Bhaelros](#):
>
> Portmaster seems to have a nice UI compared to others but if you are planning to use VPNs, you are going to have a bad time. I tried with Proton and Windscribe and PM cut my internet connection completely.

I appreciate your reply!

Wow, there are so many variables!

---

## Post 76 by @win11.shading291 — 2025-03-30T19:29:23Z

I just read this whole thread and there doesn’t seem to be a clear contender following Bhaelros’s comment.

Safing Portmaster and simplewall are definitely the most recommended, but Portmaster doesn’t work well with a VPN.

Is this also the case with Simplewall?

If so, would the recommendation just to use Windows Firewall even if the UI isn’t great?

---

## Post 77 by @Julie — 2025-03-30T19:34:03Z

The issue with windows firewall is that it’s terrible with outbound connections.

---

## Post 78 by @win11.shading291 — 2025-03-30T19:35:00Z

Could you develop further? :slight_smile:

---

## Post 79 by @Julie — 2025-03-30T20:42:55Z

By default, windows (10,11) firewall is inbound only.

If you configure it to block outbound connections, it will block them without any notifications.

---

## Post 81 by @Average_Joe — 2025-04-08T04:23:58Z

> [@win11.shading291](#):
>
> I just read this whole thread and there doesn’t seem to be a clear contender following Bhaelros’s comment.
> 
> Safing Portmaster and simplewall are definitely the most recommended, but Portmaster doesn’t work well with a VPN.
> 
> Is this also the case with Simplewall?
> 
> If so, would the recommendation just to use Windows Firewall even if the UI isn’t great?

I appreciate your reply!

What’s crazy to me is how much work and effort and hardware is required in setting up a dedicated Linux firewall distro on a piece of hardware like a mini-PC when these Linux firewall distros can be so easily bypassed by a trojan on a Windows PC…

---

## Post 82 by @mika — 2025-04-08T15:07:39Z

> [@win11.shading291](#):
>
> Is this also the case with Simplewall?

SimpleWall works just fine with a VPN. I’m still using it until a viable replacement comes along :slightly_frowning_face:

---

## Post 83 by @win11.shading291 — 2025-04-08T16:12:34Z

Thanks! So SimpleWall or Windows Firewall I guess!

Why did you put a sad emoji for SimpleWall?

---

## Post 84 by @anon86365830 — 2025-04-08T18:58:34Z

The inbuilt firewall in WIndows (on your local PC, virtual machine, local server that you control etc) is very good.

But, to get the full feature set (on your local machine), especially if you are running Hyper-V VMs, WSL distros (and/or the Windows Sandbox), search the net, and be comfortable with powershell.

For anything “outside” the PC/machine running WIndows, go network protection.

---

## Post 85 by @mika — 2025-04-08T20:21:41Z

Well I was under the impression that it had been archived, but looking now there was an update last week. Regardless it’s what I’m presently using, it works just fine.

---

## Post 86 by @Julie — 2025-04-19T15:15:20Z

How do you use windows firewall to monitor outbound connections ?  
What your solution to this issue ?

---

## Post 87 by @Average_Joe — 2025-04-22T14:53:14Z

> [@Average_Joe](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/win11.shading291/48/15_2.png) win11.shading291:
> 
> > I just read this whole thread and there doesn’t seem to be a clear contender following Bhaelros’s comment.
> > 
> > Safing Portmaster and simplewall are definitely the most recommended, but Portmaster doesn’t work well with a VPN.
> > 
> > Is this also the case with Simplewall?
> > 
> > If so, would the recommendation just to use Windows Firewall even if the UI isn’t great?
> 
> What’s crazy to me is how much work and effort and hardware is required in setting up a dedicated Linux firewall distro on a piece of hardware like a mini-PC when these Linux firewall distros can be so easily bypassed by a trojan on a Windows PC…

Can anyone clarify this for me?

I feel like it may need its own thread because it has such serious implications… :cry::cry::cry::cry::cry:

---

## Post 88 by @anon79740302 — 2025-04-22T18:21:14Z

OP, you don’t seem to understand what a firewall is or does.

Conventional firewalls deal only with lower-level things like IP addresses, protocols, and ports; they do not handle connections at the application level. Not to mention that such a firewall running on standalone hardware simply wouldn’t “know” what applications are running on your PC.

What you’re looking for is a so-called [personal firewall](https://en.wikipedia.org/wiki/Personal_firewall), which is largely a Windows thing. Speaking of which, if you really care about your privacy, you shouldn’t be using Windows for anything sensitive to begin with.

---

## Post 89 by @Average_Joe — 2025-04-22T21:23:40Z

> [@anon79740302](#):
>
> Conventional firewalls deal only with lower-level things like IP addresses, protocols, and ports; they do not handle connections at the application level. Not to mention that such a firewall running on standalone hardware simply wouldn’t “know” what applications are running on your PC.
> 
> What you’re looking for is a so-called [personal firewall](https://en.wikipedia.org/wiki/Personal_firewall), which is largely a Windows thing. Speaking of which, if you really care about your privacy, you shouldn’t be using Windows for anything sensitive to begin with.

I appreciate your reply!

I’m still unsure of how hardware firewalls are all that important if you have Windows PC’s connected and these Windows PC’s have trojans or some other kind of malicious backdoors/telemetry installed??

I’m moving away from proprietary software in general but I do need to keep my current devices as secure as possible…:cry:

---

## Post 90 by @anon79740302 — 2025-04-22T22:08:36Z

As I said, conventional firewalls do not deal with applications at all. The point of a “hardware firewall” (say, a router) would often be to protect your local network from unsolicited _incoming_ connection attempts, e.g., a script kiddie from the PRC trying to gain remote access to your PC via [SSH](https://en.wikipedia.org/wiki/Secure_Shell) to turn it into his personal proxy server, and whatnot.

Dealing with malware like trojans, on the other hand, is the job of an antivirus and/or an [intrusion-detection system](https://en.wikipedia.org/wiki/Intrusion_detection_system). I hear that Windows Defender is plenty good these days, but don’t quote me on that.

> [@Average_Joe](#):
>
> I’m moving away from proprietary software in general but I do need to keep my current devices as secure as possible…

An up-to-date Windows installation with Defender Antivirus and Firewall enabled, and the latter blocking or dropping all incoming connections should be reasonably secure. Just keep in mind that security =/= privacy.

---

## Post 91 by @Average_Joe — 2026-02-21T23:16:28Z

> [@anon79740302](#):
>
> An up-to-date Windows installation with Defender Antivirus and Firewall enabled, and the latter blocking or dropping all incoming connections should be reasonably secure. Just keep in mind that security =/= privacy.

I appreciate your reply!

It just seems like a great idea to have an open source firewall app running on a Windows 11 PC just as a further line of protection from trojans and other apps that send out too much user telemetry?

---

## Post 92 by @kissu — 2026-02-22T00:04:03Z

Honestly, I doubt there is a good firewall on Windows that does the job well without sending EXTRA more telemetry than Windows already does. :face_exhaling:

Not sure if there is a way to fix all the leaks from that OS given all the daily sloppy releases… :melting_face:

---

## Post 93 by @Blackbird — 2026-02-22T00:09:13Z

Yes, there is. Simplewall.

---

## Post 94 by @kissu — 2026-02-22T00:19:22Z

The room’s mood, damn…

> **[GitHub - henrypp/simplewall: Simple tool to configure Windows Filtering...](https://github.com/henrypp/simplewall?tab=readme-ov-file#reviews-of-idiots)**
>
> Simple tool to configure Windows Filtering Platform (WFP) which can configure network activity on your computer.

---

## Post 95 by @Blackbird — 2026-02-22T00:27:17Z

This has been mentioned here before—it’s definitely not a good match if you aren’t able to learn how to use it independently.

---

## Post 96 by @Average_Joe — 2026-02-22T01:08:50Z

> [@Blackbird](#):
>
> Yes, there is. Simplewall.

I appreciate your reply!

However, Simplewall hasn’t had any updates since July 2025… I don’t think it’s something that we can rely upon…

---

## Post 97 by @monkeylove — 2026-02-22T02:54:18Z

According to the pricing list, only the paid version of Portmaster offers compatibility with VPN.

---

## Post 98 by @Average_Joe — 2026-02-22T03:51:04Z

> [@monkeylove](#):
>
> According to the pricing list, only the paid version of Portmaster offers compatibility with VPN.

I appreciate your reply!

I’m really starting to think that having a software firewall app for Windows PC’s is non negotiable… It’s just so easy for an app to send user data back to a malicious person on the internet… Even if you have the most up to date Windows security updates and a secure router it only takes one app to send telemetry to someone on the Internet.. which destroys user privacy…

---

## Post 99 by @Blackbird — 2026-02-22T06:19:27Z

It scarcely demands an extraordinary effort when one blocks everything by default and permits only that which is essential. And maintains the use of reason.

---

## Post 100 by @faxe — 2026-02-22T13:39:30Z

Don’t know why they state it there, but the free portmaster works well with protonvpn in my case.

---

## Post 101 by @win11.shading291 — 2026-02-22T16:25:40Z

I’m using simplewall as of now. Even though the developper is kind of… ish… The software works well on what it is supposed to do.

I’m surprised that I receive connection request from single player games.

I feel simplewall gives me back control.

If true that it hasn’t been updated since July 2025, not great though.

---

## Post 102 by @monkeylove — 2026-02-23T07:59:17Z

My problem is that when I used default-deny, I couldn’t figure out what was needed and what wasn’t, so I ended up breaking the system several times when I disallowed something that was actually needed.

---

## Post 103 by @Average_Joe — 2026-02-26T17:37:26Z

> [@Blackbird](#):
>
> It scarcely demands an extraordinary effort when one blocks everything by default and permits only that which is essential. And maintains the use of reason.

> [@win11.shading291](#):
>
> If true that it hasn’t been updated since July 2025, not great though.

I appreciate your replies!

Only installing the bare minimum apps seems like a good way to keep a Windows PC secure from sending telemetry to a malicious person online. **However, having a top notch firewall would make me feel much safer…**

Using something that hasn’t been updated in 2 years is probably a bad idea…

These are the best options I’ve been able to find:

> **[NymVPN: The World's Most Private Decentralized VPN | Nym](https://nym.com/)**
>
> NymVPN is a decentralized VPN with mixnet technology and zero-knowledge proofs. Protects your metadata, not just your IP. Anonymous signup. Try free.

Portmaster from [https://safing.io/](https://safing.io/)  
[https://nym.com/](https://nym.com/)

---

## Post 104 by @Blackbird — 2026-03-07T10:46:08Z

My appreciation for IVPN pushed me to give Portmaster another try yesterday. Now that I’ve learned the ropes, the UI actually feels okay. It is a huge shift from Simplewall, but I think I’ll stick with it for now.

---

## Post 105 by @win11.shading291 — 2026-03-07T19:07:42Z

Do you need to pay for it to be any good? Or is that only for SPN?

---

## Post 106 by @Blackbird — 2026-03-07T19:47:22Z

No. I just use it with a VPN.
