Safing Portmaster: An Open Source Application Firewall

Safing Portmaster is a free, open source application firewall for Windows and Linux. What it does well, what the paid plans add, and where it falls short.

Share
Safing Portmaster: An Open Source Application Firewall

Safing Portmaster is an open source application firewall for Windows and Linux. It sits between your programs and the network, shows you every connection they make, and lets you block what you do not want leaving the machine. I have been running it on my own desktop for a while, and this is an honest look at what it does well and where it still falls short.

The project is maintained by IVPN, which acquired Safing in December 2024. Development is active: version 2.2.3 shipped in August 2026, and the 2.2.1 release added split tunneling. If you last looked at Portmaster in 2023, the interface and the pricing have both moved on.

Why an application firewall helps

Most desktop operating systems let any program open a connection to anywhere. You get little visibility and almost no control. Portmaster takes a host-based approach: it runs on the device, watches traffic at the network layer, and attributes each connection to the process that started it. That is a different job from a VPN, which moves your traffic but does not tell you what each app is doing.

Portmaster covers a few practical gaps:

  • Visibility. You can see which processes are talking to which domains and IPs, in real time.
  • Tracker and ad blocking. Curated filter lists are applied system-wide, not just in the browser.
  • Encrypted DNS. Lookups go over DNS over TLS by default.
  • Per-app rules. You can cut one program off from the internet while leaving everything else alone.
  • Incoming connections. Portmaster blocks unsolicited incoming traffic by default.

Network activity monitoring

Open the Network Monitor and you get a live list of connections grouped by process. Each row shows the domain, the IP address, the protocol and the direction. Click a process to expand it and see every connection it has open, with the resolved country and the ASN that owns each IP.

To dig into a specific program:

  1. Open Portmaster from the system tray.
  2. Go to the Network Monitor tab.
  3. Click the application you want to inspect.
  4. Review the connection list, then use the search and filter controls to narrow it by domain, IP or country.

On the free tier the live monitor is available. The searchable record of past connections, called Network History, is not. It is one of the features reserved for the paid plans, which I get to below.

Automatic ad and tracker blocking

Out of the box Portmaster blocks known trackers, ad hosts and malware domains system-wide. It uses the same kind of public filter lists that browsers and extensions use, so the lists get updated as the upstream projects change them. Because the filtering happens at the network layer, it also applies to programs that have no browser extension support at all.

You can swap or extend the lists, turn whole categories on and off, or add individual domains to a custom list. The defaults are the part most people will leave alone, and that is fine.

Encrypted DNS

Portmaster takes over DNS resolution on the device and sends lookups over DNS over TLS. It ships with a set of pre-configured encrypted resolvers, including Cloudflare, Quad9, AdGuard and Foundation for Applied Privacy, and you can point it at your own. The DNS privacy basics are worth reading if this part is new to you.

One thing to know: because Portmaster replaces the system resolver, a second tool that does the same thing will fight it. The NextDNS client, for example, wants to be the resolver itself. You can still use NextDNS with Portmaster, but you do it by adding NextDNS servers as a custom upstream inside Portmaster rather than by running both at once.

Per-app controls

Each application gets its own profile. From there you can allow or block internet access, allow or block local network access, and apply filtering rules just to that program. A common use is cutting a game launcher or an updater off from the internet while leaving the browser untouched, or keeping a program on the LAN but off the WAN.

Profiles survive updates because Portmaster identifies apps by a fingerprint rather than by file path alone. That is a small thing that saves a lot of re-configuring.

Custom rules

When per-app toggles are not enough, Portmaster has a rules system. Rules are defined as JSON and can match on a domain, an IP range, a country, an ASN or a port, with a priority and an action. They are evaluated from the top down and stop at the first match, so order matters.

If you have used a traditional firewall you will recognize the shape. The difference is that you get a usable default set first and only reach for hand written rules when you actually need them.

The SPN and what it costs

The paid plans add the Safing Privacy Network, or SPN. Instead of sending all your traffic through one exit like a VPN, the SPN routes each connection through its own path and gives it a separate exit IP. It is onion routed, inspired by Tor, and the source is on GitHub. Safing had the cryptographic core, Jess, audited by Cure53.

It is worth being clear about what the SPN is not. It hides your IP per connection, but it does not stop browser fingerprinting, and it does not stop a service from recognizing you when you are logged in. Safing says as much on its own pricing page. It is one layer, not a cloak of invisibility.

Pricing as of February 2026, after Safing cut the Pro price:

TierPriceWhat you get
Portmaster FreeFreePrivacy Filter, Secure DNS, Network Monitor, community support
Portmaster Plus40 euros per yearEverything in Free, plus Network History and Bandwidth Visibility
Portmaster Pro8 euros per month or 80 euros per yearEverything in Plus, plus SPN access

Portmaster Pro was 99 euros per year and 9.90 euros per month before February 2026, so the current prices are lower than they were. The free tier still exists and still covers the core firewall and DNS features. Payment is by card, PayPal, Bitcoin, Monero or cash.

Installation

Portmaster runs on Windows and Linux. There is no macOS or mobile build, and there has not been one for years. Safing has said macOS and mobile are planned but not available, and the mobile status page is blunt that a store would be unlikely to accept an ad blocking firewall anyway. If you are on a Mac, this is not the tool for you.

On Linux you can install the package directly once you have downloaded it:

# Debian or Ubuntu
sudo apt install ./Portmaster_2.2.3_amd64.deb

# Fedora
sudo dnf install ./Portmaster-2.2.3-1.x86_64.rpm

On Windows, run the installer from safing.io. Version 2 added offline installers, which is useful if you want to set it up on a machine that should not touch the internet before the firewall is in place.

Portmaster runs as a background service and adds a tray icon. On Linux it hooks into Netfilter through nfqueue; on Windows it uses a kernel driver built on the Windows Filtering Platform. Both are the reason it can see traffic at the process level.

Usability and documentation

The interface is split into a simple view and an advanced view. The simple view is readable and hard to break. The advanced view exposes the profiles, rules and filter settings. Switching between them is a toggle, so beginners are not buried in options they did not ask for.

Documentation lives on the Safing community wiki and the older docs site, which is being folded into the wiki. There is also an active Discord. In practice the wiki answers most configuration questions, and GitHub issues are where you go for bugs.

Open source

Portmaster is GPL-3.0 and the code is on GitHub. That matters for a tool that sees every connection your machine makes. You can read exactly what it does with your traffic, and the SPN network code is public too. Being open source is not a guarantee of quality, but it does mean you are not asked to take the vendor's word for it.

Where it falls short

A fair review has to list the rough edges:

  • No macOS, no Android, no iOS. This has been planned for years and is still not here.
  • The deeper investigation features, Network History and Bandwidth Visibility, sit behind the paid tier. On the free plan you get the live monitor but not the searchable record.
  • The Windows kernel driver has had crash and packet handling bugs fixed as recently as 2026. It is stable now, but this is a component that touches the network stack, so regressions are possible.
  • There is no scripting layer documented for rules anymore. If you need arbitrary logic, you are writing JSON rules or looking elsewhere.

None of these are deal breakers for the free tier. They are the reasons I would not call it a fit for every machine.

Conclusion

Portmaster is one of the better free options for seeing and controlling what your Windows or Linux machine does on the network. The defaults are sensible, the free tier is genuinely usable, and the per-app controls and DNS handling cover most of what a home or small office desktop needs. The paid SPN is a niche addition for people who specifically want per-connection IP separation, not a general VPN replacement.

If you are on Windows or Linux and want visibility you can act on, install the free version and watch it for a week. If you are on a Mac, or you want the same tool on your phone, it is not there yet.

## Convertkit Newsletter