this post was submitted on 12 Jun 2024
38 points (100.0% liked)

Free and Open Source Software

17911 readers
54 users here now

If it's free and open source and it's also software, it can be discussed here. Subcommunity of Technology.


This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

founded 2 years ago
MODERATORS
 

I've used Windows Firewall for my whole life but I'm curious if anyone has any recommendations for a solid FOSS replacement. I do still use Windows on one of my systems on a daily basis but I always try to replace as much as possible with FOSS alternatives.

Any suggestions for a good FOSS alternative for Windows Firewall (and not at the router level)?

No, "just use Linux" is not a suggestion. I already do use Linux, but there are some things I do have to use Windows for.

top 16 comments
sorted by: hot top controversial new old
[–] Moonrise2473@feddit.it 9 points 4 months ago

Complete alternative to windows firewall or a nice GUI for that?

Nicer GUI there's https://github.com/wokhan/WFN

Full firewall I think you would need to run openwrt or opnsense in a VM in hyperv set to run automatically in background at boot

[–] Templa@beehaw.org 8 points 4 months ago (1 children)
[–] ChallengeApathy@infosec.pub 1 points 4 months ago (1 children)

I hadn't, my apologies for missing that.

[–] Templa@beehaw.org 4 points 4 months ago* (last edited 4 months ago)

I just wanted to point out, no need to apologize! Hopefully you find something suitable for you.

[–] flappy@lemm.ee 7 points 4 months ago (1 children)
[–] LiveLM@lemmy.zip 2 points 4 months ago

Seconding Simplewall, it really just works.

[–] sic_semper_tyrannis 6 points 4 months ago
[–] Oisteink@feddit.nl 5 points 4 months ago (1 children)

How many FOSS Linux firewalls are there? Let’s see, we have iptables and there’s nftables.

[–] Barzaria@lemmy.dbzer0.com 2 points 4 months ago

Uncomplicated firewall is a nice frontend for up tables.

[–] LiveLM@lemmy.zip 4 points 4 months ago

I like Simplewall.
By default, it blocks everything and shows you a popup whenever an app or service tries to make a connection, similar to LittleSnitch for MacOS if you're familiar with that.
The first few minutes can be a bit annoying as you figure out just how many background services in Windows are trying to phone home, but after that, great peace of mind knowing nothing will talk to the internet without you knowing.
Definitely overkill for most users, but if you don't mind the initial burden, highly recommend.

[–] Dark_Arc@social.packetloss.gg 3 points 4 months ago (1 children)

If you're going to use Windows ... just use Windows firewall. There's no real reason that I can think of anyways to replace that one component with something FOSS.

[–] ChallengeApathy@infosec.pub 1 points 4 months ago (1 children)

I suppose there's not really a crucial reason but I just like to do so when I can. More peace of mind that way.

[–] Dark_Arc@social.packetloss.gg 2 points 4 months ago* (last edited 4 months ago)

AFAIK, Windows firewall is perfectly fine, usable in commercial spaces, etc. You're probably going to be getting into more "hobbyist" firewalls even if you do find one ... and a firewall isn't something you particularly want that with. You want something that's well designed and well maintained.

(I say this as a guy that has run Linux on basically everything for ... over a decade)

[–] Daqu@lemm.ee 1 points 4 months ago (1 children)

Just disable the services you do not want to expose. Windows firewalls are a security risk with no real benefits.

[–] Oisteink@feddit.nl 11 points 4 months ago (1 children)
[–] Templa@beehaw.org 6 points 4 months ago

Source: [REDACTED]