Windows firewall options, compared honestly.
You’re probably comparing this against what already ships with Windows, and maybe against Portmaster if privacy tooling is your thing. Here’s where each one actually stands — no invented benchmarks, no claims we can’t back.
| Windows Defender Firewall | Ferrite | Portmaster | |
|---|---|---|---|
| Cost | Free, built into Windows | Free forever, Pro from CA$99/yr | Free / paid SPN add-on |
| Per-app connection visibility | Rule-based only — no live “what's connecting now” view for most users | Live dashboard, every edition | Live per-app view |
| DNS-over-HTTPS bypass detection | None — doesn't monitor DNS usage | Every edition, on by default | DNS filtering, different mechanism |
| Deep packet inspection / protocol ID | None | 120+ identified, 30+ deep-inspected (Pro) | Not its focus |
| Rule management | Advanced settings or PowerShell — not built for daily use | In-app, per-app / IP / port / domain / time / country | In-app, per-app + network rules |
| Connection history / forensics | None | 90-day retention, SQL analytics, timeline replay (Pro) | Limited history |
| Primary design goal | Baseline OS protection | Full visibility + control for one machine, operator-grade | Privacy + anti-tracking, broader scope (includes its own VPN/SPN) |
Windows Defender Firewall
It’s already on every Windows machine, it’s free, and it does real, system-level filtering — that’s not nothing. But it was built as baseline OS protection, not a tool you’re meant to interact with daily: there’s no live view of what’s actually connecting right now, per-app rules live in an advanced-settings panel most users never open, and it has no concept of DNS-layer bypass detection or payload inspection at all. If you’ve never configured it beyond the default, you’re not missing a hidden feature — that’s the intended experience.
Portmaster
Portmaster (Safing) is a real, capable option with a genuinely different posture — it’s built around broader privacy and anti-tracking goals, including its own optional VPN-like network (SPN), alongside per-app connection control. That’s a different design center than Ferrite’s: Ferrite is scoped tightly to being the most capable host firewall for one machine — deep protocol identification, DNS-bypass detection, and forensics depth are where it specifically invests. Neither approach is strictly better; they’re optimizing for different things, and which one fits depends on whether you want a firewall that goes deep, or a broader privacy suite that includes one.
Where Ferrite specifically differentiates
- DNS-bypass detection. Chrome, Firefox, and Edge default to encrypted DNS that routes around whatever resolver you configured — parental controls, ad-blocking DNS, and VPN split-DNS included. Ferrite catches this in every edition; see the full explainer.
- Deep packet inspection. 120+ protocols identified, 30+ deep-inspected with TLS/HTTP fingerprinting (JA3/JA4), so an app hiding on port 443 is still classified for what it actually is.
- Forensics. 90-day retention and real SQL analytics (DuckDB) over your own connection history, entirely local.
- Zero telemetry, either way. Nothing about your connections leaves your machine, on Free or Pro — see how to check that yourself.