OpenSnitch
Interactive GNU/Linux application-level firewall alerting on outgoing network connections.
Why consider OpenSnitch?
OpenSnitch is an open-source application-level firewall for Linux. It monitors outbound process connections, displaying instant interactive prompts to allow or block network traffic per executable, port, domain name, or IP range.
Learn OpenSnitch by building
Practical setup notes, real use cases, and copy-ready examples in one focused guide.
In this guide2 sections
Overview of OpenSnitch
OpenSnitch alerts you whenever an application attempts to make outbound internet connections from your Linux desktop.
Quickstart
# On Debian / Ubuntusudo apt install opensnitchsudo systemctl enable --now opensnitchopensnitch-uiWhenever an app initiates a connection, an alert pops up allowing you to grant permanent, temporary, or blocked rules.
OpenSnitch is licensed under the GNU General Public License v3.0.
Related tools
More options with a similar category or technology profile.
boringproxy
Simple, self-hosted reverse proxy and tunnel manager for exposing private web services securely.
OWASP ModSecurity
Open-source Web Application Firewall (WAF) engine providing cross-platform HTTP security inspection.
OpenCTI
Open-source platform for managing cyber threat intelligence knowledge and STIX2 relationships.
Maltrail
Malicious traffic detection system utilizing public blacklists and heuristic traffic behavior analysis.