OpenSnitch: an interactive firewall for Linux
Summary
OpenSnitch brings the principle of an interactive, application-based outbound firewall to GNU/Linux. OpenSnitch consists of a Go daemon and a Python user interface. The project is inspired by Little Snitch for macOS.
Ideas
- A daemon observes outgoing connection attempts and maps them to processes.
- Users can allow new connections once or permanently.
- Rules combine programs, destinations, ports, protocols and users.
- A graphical interface shows activity and manages decisions.
- Several nodes can be monitored from a central interface.
Insights
- Process context answers different questions from classic packet-based firewall rules.
- Interactive rules encourage visibility but can lose effect through dialogue fatigue.
- Outbound control complements hardening and segmentation but replaces neither.
Facts
- Rules can be saved permanently and built from different attributes.
Recommendations
- Start in observation mode and group expected connections before blocking strictly.
- Back up rules and review them after application or system updates.
References
Links to the original source and the Web Archive open in a new tab.