Portmaster Review: A Powerful Open-Source Firewall and Privacy Tool for Windows



Most people think of a firewall as something that sits quietly in the background and blocks suspicious incoming connections.

That is still an important part of network security, but modern applications communicate with the internet constantly. A program may connect to dozens or even hundreds of different domains for updates, analytics, telemetry, advertisements, cloud services and other purposes.

Knowing which applications are communicating with the internet and where they are connecting can therefore be just as important as blocking unsolicited incoming traffic.

This is where Portmaster from Safing takes a different approach.

Portmaster is a free and open-source application firewall for Windows and Linux that combines firewall controls with network monitoring, system-wide tracker and malware filtering, encrypted DNS and extensive per-application rules.

Instead of simply asking whether a connection is allowed or blocked, Portmaster gives you considerably more information about what is happening on your computer.

What Is Portmaster?

Portmaster is essentially a privacy-focused application firewall.

It monitors network connections made by applications on your computer and allows you to control what those applications are permitted to do.

For example, you can see that a particular application is connecting to several domains and then decide whether those connections should be allowed, blocked or handled differently.

You can also create rules on a per-application basis.

This makes Portmaster particularly useful for people who want more control over outbound network activity than the standard Windows Firewall interface provides.

At the same time, Portmaster includes privacy features that go beyond traditional firewall functionality.

Out of the box, it can block trackers and malware hosts, encrypt DNS queries using DNS-over-TLS and block incoming connections.

Why Use an Application Firewall?

Traditional firewalls are often focused primarily on controlling network connections based on IP addresses, ports, protocols and applications.

That is useful, but it does not necessarily tell you why an application is communicating with a particular server.

Portmaster provides considerably more visibility.

Suppose you install a free application and discover that it regularly connects to several advertising and analytics domains.

With Portmaster, you can inspect those connections and create rules to block them without necessarily blocking the entire application.

This is one of the application's biggest strengths.

Network Activity Monitoring

Portmaster provides a real-time view of network activity generated by applications.

You can see which applications are communicating with the internet and inspect the destinations involved.

This makes it much easier to discover unexpected network activity.

For example, an application that appears to perform one simple task might communicate with several third-party services in the background.

Portmaster can make that activity visible.

For privacy-conscious users, this is extremely useful because you no longer have to blindly trust that an application is only communicating with the servers you expect.

Per-Application Rules

This is arguably the most important feature in Portmaster.

Every application can have its own network configuration.

You can control whether an application is allowed to access:

  • The internet
  • Your local network
  • Specific connection types
  • Specific destinations
  • Specific countries
  • Specific domains

You can therefore take a much more granular approach than simply allowing or blocking an application.

For example, you might allow an application to communicate with its own servers while blocking known advertising and tracking domains.

Alternatively, you can completely cut an application off from the internet.

Block an Application Completely

If you have an application that should never access the internet, Portmaster makes this extremely easy.

You can create a rule that prevents the application from accessing the internet altogether.

This is useful for offline applications that unexpectedly attempt to contact remote servers.

It is also useful for software that you simply do not trust with network access.

Instead of relying on the application to provide its own privacy controls, you can enforce the restriction externally.

System-Wide Tracker Blocking

Portmaster is not merely a firewall.

It also includes a system-wide privacy filter that can block advertisements, trackers and known malware hosts.

Unlike a browser extension, this filtering applies across applications.

That means an application displaying advertisements or contacting a known tracking service can potentially be filtered even though there is no browser extension involved.

This makes Portmaster particularly useful for software that cannot be controlled using traditional browser-based content blockers.

DNS Filtering

Portmaster also handles DNS resolution.

By default, DNS queries are routed over DNS-over-TLS, protecting them from being transmitted as plain DNS traffic.

You can choose the DNS provider you want to use and configure additional filtering behavior.

This provides another layer of privacy because DNS queries can reveal which domains your device is trying to access.

Encrypting those queries prevents the local network from simply reading them as ordinary unencrypted DNS traffic.

Custom Filtering Rules

One of Portmaster's strongest features is its rule system.

The defaults are designed to work for most users, but advanced users can create their own rules.

Rules can be applied globally or to individual applications.

You can create rules based on domains, IP addresses, networks, countries, ports, protocols and other connection properties.

This gives Portmaster considerably more flexibility than a basic firewall.

Incoming Connections

Portmaster also provides control over incoming connections.

By default, it blocks incoming connections, providing protection against unsolicited inbound traffic.

If an application needs to accept incoming connections, you can adjust its settings accordingly.

For applications that require more precise control, Portmaster supports incoming rules that can specify exactly which connections should be permitted.

This is particularly useful for applications such as peer-to-peer software, local servers and other programs that legitimately need to listen for incoming connections.

Important: If you change the default incoming-connection behavior, make sure you understand what the application needs to receive and from whom. An overly broad allow rule can expose a service unnecessarily.

Network History

Portmaster can also provide historical information about network activity.

This is useful when you want to investigate what an application has been doing over a period of time rather than watching it in real time.

Instead of having to keep the Portmaster interface open while an application is running, historical information can help you investigate connections afterward.

Some of the more advanced investigative features are available through Portmaster's paid tiers.

Bandwidth Visibility

Portmaster can also provide visibility into network usage.

This can help identify applications that are transferring unexpectedly large amounts of data.

For example, if a program that should normally use very little bandwidth suddenly starts transferring significant amounts of data, Portmaster can make that activity easier to investigate.

Again, the deeper investigative functionality is part of the paid Portmaster tiers, while the core firewall and privacy features remain available in the free version.

Portmaster Free

The free version is surprisingly capable.

You get the core features that make Portmaster useful as a privacy-focused firewall:

  • Application firewall
  • Per-application rules
  • Incoming connection protection
  • System-wide tracker blocking
  • Malware-domain blocking
  • Encrypted DNS
  • Network activity monitoring
  • Custom rules

This makes the free version suitable for users who primarily want to regain control over what applications can access on the internet.

Safing itself describes the free version as suitable for users who want better privacy without needing the deeper investigative features.

Portmaster Plus

Portmaster Plus is aimed more at users who want to investigate their network activity in greater detail.

It adds features such as deeper network history, bandwidth visibility and weekly reports.

If you frequently find yourself opening the Portmaster interface to investigate what applications are doing, Plus is the tier aimed at that use case.

The important point is that the paid tier is not required simply to get the core firewall and privacy functionality.

Portmaster Pro and the Safing Privacy Network

The top-tier Portmaster package adds access to Safing's Privacy Network (SPN).

The SPN is a privacy-focused overlay network that is somewhat comparable to Tor in concept while being designed to work more like a VPN from the user's perspective.

Traffic that you choose to route through the SPN is sent through a network of nodes using layered encryption.

The system supports different routing profiles that prioritize different combinations of speed and privacy.

For example, the balanced routing mode uses at least two hops so that no single node knows both where your connection originated and where it is ultimately going.

More privacy-focused routing can use additional hops.

This makes the SPN considerably different from simply changing your DNS provider.

Important: The SPN is an optional paid service. Portmaster itself does not require the SPN, and the free version remains useful without it.

Per-Application SPN Controls

One of the interesting aspects of the SPN integration is that it can be configured on a per-application basis.

You do not necessarily have to route everything through the SPN.

You can choose which applications should use it and create rules controlling which destinations should be routed through the privacy network.

This provides much more flexibility than a traditional VPN kill switch that simply routes the entire device through one VPN connection.

Split Tunneling

Portmaster 2.2.1 introduced split tunneling, allowing specific applications or connections to use a different network interface from the one normally selected by the operating system.

This can be useful if you use a VPN or the SPN but want certain applications to bypass it.

For example, you might want:

  • A browser to use a VPN
  • A game to use the normal internet connection
  • A work application to use a specific network interface
  • A streaming application to bypass a VPN exit node

Portmaster can apply these routing decisions automatically according to the configured application and domain rules.

Keep in mind: Traffic that bypasses the VPN or SPN also bypasses the privacy protection provided by that tunnel and can expose your normal public IP address. Split tunneling should therefore be configured deliberately.

Country-Based Rules

Portmaster also provides geographic filtering controls.

You can create rules that restrict connections based on the destination country.

This can be useful when an application has no legitimate reason to communicate with certain regions or when you want to restrict where particular applications are allowed to connect.

Country-based rules are particularly interesting when combined with per-application policies.

Application Profiles

Portmaster's application-centric design makes it much easier to think about firewall rules in terms of programs rather than individual IP addresses.

Instead of manually maintaining a large collection of IP addresses, you can configure a policy for an application and let Portmaster handle its network connections.

This is much more practical for modern software, where server infrastructure and IP addresses can change frequently.

Privacy vs Security

Portmaster sits at the intersection of privacy and security.

Its tracker and malware filtering can help prevent connections to known unwanted or malicious destinations, while its firewall functionality allows you to restrict application network access.

However, it should not be considered a replacement for an antivirus or endpoint-security product.

A firewall can control network communication, but it does not automatically detect every malicious file or exploit.

Portmaster works best as another layer in a broader security setup.

Open Source

One of Portmaster's biggest advantages is that it is open source.

The source code is publicly available, allowing technically inclined users to inspect how the application works and how its network filtering is implemented.

For a privacy application that sits directly in the network stack, this transparency is particularly valuable.

You are not required to blindly trust a completely closed-source application that has privileged access to your network traffic.

Performance

Any application firewall that monitors network activity introduces some additional processing.

Portmaster is designed to operate continuously in the background, so resource usage naturally depends on how much network activity the computer generates and which features are enabled.

For normal desktop use, the overhead is generally reasonable for the amount of functionality provided.

However, users running several network-filtering applications simultaneously should be aware that they can interact with one another.

Running Portmaster alongside another firewall, VPN, DNS filter and traffic-inspection application can create unnecessary complexity and may sometimes lead to compatibility or connectivity problems.

Portmaster vs Windows Firewall

Windows already includes a capable firewall, so why install another one?

The answer is visibility and usability.

Windows Firewall Portmaster
Built into Windows Third-party application
Traditional firewall controls Application-focused firewall controls
Limited everyday visibility Detailed network activity view
Manual rule management can be complicated Per-application settings are easier to manage
No built-in tracker filtering System-wide tracker and malware filtering
DNS configuration is separate Built-in encrypted DNS controls
No integrated privacy network Optional SPN integration

Windows Firewall remains an important part of Windows security, and Portmaster does not make it obsolete.

Instead, Portmaster provides a much more user-friendly layer for users who want to understand and control application network activity.

Portmaster vs a Traditional Firewall

Traditional third-party firewalls often focus primarily on deciding whether an executable should be allowed to communicate.

Portmaster goes further by combining firewall rules with domain filtering, DNS protection, tracker blocking and network visibility.

This makes it closer to a privacy-aware network control center than a traditional firewall alone.

What I Like About Portmaster

The biggest advantage is the amount of information it provides.

Instead of wondering what an application is doing in the background, you can actually inspect its network activity.

The per-application configuration is another major strength.

You can block an application completely, restrict it to specific destinations, block trackers while allowing legitimate connections, or configure different behavior for different applications.

The system-wide filtering is also useful because it extends privacy protection beyond the browser.

And unlike many commercial privacy products, the core Portmaster application is free and open source.

What Could Be Better?

Portmaster's biggest weakness is also one of its strengths: there is a lot to configure.

A beginner can install it and use the default configuration, but understanding all of the available rules, network settings, DNS options and application policies can take time.

The application is much more approachable than manually configuring complex firewall rules, but it is still a serious networking tool.

Another issue is compatibility.

If you already use a VPN, another DNS filtering application, a third-party firewall or other software that intercepts network traffic, troubleshooting can become more complicated.

The SPN is also a paid service, so users looking for a completely free VPN-like privacy network will need to look elsewhere.

Finally, Portmaster's advanced investigative features are divided between the free and paid tiers. The free version is capable, but users wanting detailed historical analysis and reporting need Plus or Pro.

Who Should Use Portmaster?

I would particularly recommend Portmaster to:

  • Users who want more control over application network access
  • Privacy-conscious Windows and Linux users
  • People who want system-wide tracker blocking
  • Users who want encrypted DNS without configuring it separately
  • People who want to inspect application network activity
  • Users who want per-application firewall rules
  • Advanced users who want detailed networking controls
  • Users who prefer open-source security software
  • People who want optional VPN-like privacy through the SPN

If you simply want a traditional firewall that runs quietly in the background and requires minimal configuration, Portmaster may be more than you need.

Is Portmaster Worth Using?

Yes, particularly if you care about understanding what your applications are doing online.

The free version already provides a strong combination of firewall functionality, network monitoring, tracker blocking, malware filtering and encrypted DNS.

That makes it considerably more useful than simply installing another conventional firewall.

The paid tiers are more specialized. Plus is aimed at users who want deeper investigation and reporting, while Pro adds the Safing Privacy Network.

This tiered approach is actually quite reasonable because the core firewall and privacy functions remain available without a subscription.

Final Verdict

Portmaster is one of the more interesting firewall applications available for Windows.

Instead of treating the firewall as a collection of obscure rules that you configure once and forget about, it makes network activity visible and understandable.

You can see what applications are connecting to, block unwanted destinations, restrict individual programs, filter trackers and malware system-wide, and encrypt DNS queries.

Advanced users get an impressive rule system, while users who simply want better privacy can install Portmaster and use its defaults.

The optional SPN adds another dimension by providing a privacy-focused overlay network, while the newer split-tunneling functionality makes it easier to integrate Portmaster with existing VPN and networking setups.

It is not a replacement for antivirus software, and it is not necessarily the simplest firewall for beginners. But for users who want visibility, control and privacy at the application level, Portmaster is an excellent tool.

Rating: 4.7/5

Pros

  • Free core version
  • Open source
  • Powerful per-application firewall
  • Detailed network activity monitoring
  • System-wide tracker blocking
  • Malware-domain blocking
  • DNS-over-TLS by default
  • Extensive custom rules
  • Incoming connection controls
  • Country-based filtering
  • Optional Privacy Network
  • Per-application SPN controls
  • Split tunneling
  • Works beyond the browser
  • Available for Windows and Linux

Cons

  • Can be overwhelming for beginners
  • Advanced investigative features require a paid tier
  • SPN requires Portmaster Pro
  • Can conflict with other VPN, DNS and firewall software
  • Requires some networking knowledge for advanced configuration
  • Not a replacement for antivirus software

Bottom line: Portmaster is an excellent choice for anyone who wants more than a traditional firewall. Its combination of application-level network control, real-time visibility, system-wide tracker blocking, encrypted DNS and open-source development makes it one of the most capable privacy-focused firewall solutions available for Windows and Linux.

Download Portmaster

Portmaster is available as a free download for Windows, Debian/Ubuntu and Fedora. The core application is free and open source, with optional paid Plus and Pro tiers for users who need additional investigative features or the Safing Privacy Network.

Download Portmaster from Safing →

You can also inspect the source code and follow the development of the project on GitHub.

View Portmaster on GitHub →

Boruah

Tech, privacy, software, and everything I find interesting along the way.

Post a Comment (0)
Previous Post Next Post