bk99.de entertain the web since 1997

OpenSnitch: an interactive firewall for Linux

Summary

OpenSnitch brings the principle of an interactive, application-based outbound firewall to GNU/Linux. OpenSnitch consists of a Go daemon and a Python user interface. The project is inspired by Little Snitch for macOS.

Ideas

  • A daemon observes outgoing connection attempts and maps them to processes.
  • Users can allow new connections once or permanently.
  • Rules combine programs, destinations, ports, protocols and users.
  • A graphical interface shows activity and manages decisions.
  • Several nodes can be monitored from a central interface.

Insights

  • Process context answers different questions from classic packet-based firewall rules.
  • Interactive rules encourage visibility but can lose effect through dialogue fatigue.
  • Outbound control complements hardening and segmentation but replaces neither.

Facts

  • Rules can be saved permanently and built from different attributes.

Recommendations

  • Start in observation mode and group expected connections before blocking strictly.
  • Back up rules and review them after application or system updates.

References

Read the original article

Search the Web Archive