OpenSnitch
An interactive application firewall for Linux that asks before letting any program make an outbound connection.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About OpenSnitch
OpenSnitch is the Linux answer to Little Snitch. It intercepts outbound connections and prompts you: this program wants to connect to this host, allow once, allow always, or deny. Over time you build a rule set that makes it obvious when something starts phoning home that did not before.
It also blocks ad, tracker and malware domains system-wide, can configure the system nftables firewall from its interface including input policy and inbound services, manages multiple nodes from one centralised interface, and integrates with SIEM systems.
Packages are published as deb and rpm, and the interface is a separate Python package alongside the daemon.
Strengths
- Prompts on every new outbound connection, so unexpected traffic becomes visible
- Blocks ad, tracker and malware domains system-wide
- Configures the system nftables firewall, including inbound policy, from the interface
- Manages multiple machines from one centralised interface, with SIEM integration
Limitations
- Linux only
- The first days are a stream of prompts until your rules settle
- The daemon and the interface are separate packages, which complicates installation
- The last release is from December 2025
Details
- Pricing
- FreeFree and open source under the GPL.
- License
- GPL-3.0
- Developer
- OpenSnitch
- Platforms
- Linux
- How it runs
- Downloadable app
- Account
- Not required
- Works offline
- Yes
- Best suited for
- Seeing and controlling which programs on a Linux machine talk to the internet
- Categories
- Security tools
- Last verified
- Added
- Provenance
- Selected from the TechWalrus downloads catalog (Security); facts checked against the developer's own pages, 2 sources on file.
Alternatives to OpenSnitch
Compare allSoftware that can replace OpenSnitch for an important use case, and what changes if you switch.
Portmaster
Shows every connection each application makes and lets you block any of them, with sensible defaults already set.
Portmaster runs on Windows and Linux with tracker blocking and secure DNS preset, while network history search and bandwidth figures are paid.
LuLu
Control outbound application connections on macOS.
LuLu is an open-source GPL-3.0 outbound firewall like OpenSnitch, but it runs on macOS instead of Linux.
Little Snitch
macOS application firewall that prompts on outgoing connections.
Little Snitch prompts on outbound connections on macOS with a network monitor, but is closed source with a one-time paid licence.
simplewall
Puts a plain list of programs in front of the Windows Filtering Platform, so you decide what is allowed online.
simplewall runs on Windows using a plain allow and block list instead of prompts, with a portable build under a megabyte.
GlassWire
Network monitor and firewall with a visual traffic history.
GlassWire works on Windows and Android with a visual traffic history, is closed source, and puts longer history behind a paid licence.
NetGuard
No-root Android firewall that blocks internet access per app.
NetGuard blocks internet access per app on Android without root, but occupies the VPN slot so it cannot run alongside a VPN.
AFWall+
iptables firewall for rooted Android with per-app rules.
AFWall+ is an open-source iptables firewall for rooted Android with per-network rules, and it does not use the VPN slot.
Similar software
Related functionality, not necessarily a direct replacement.
Fail2ban
Log-watching daemon that bans addresses after repeated authentication failures.
CrowdSec
Detect suspicious behavior in server logs and web traffic.
IPFire
A hardened Linux-based firewall distribution with VPN support, network segmentation and a web management console.
OPNsense
An open-source firewall and routing platform based on FreeBSD that you install on your own hardware.