The Best Free Windows Firewall | Portmaster Guide

  Рет қаралды 27,216

Ken Harris

Ken Harris

Күн бұрын

Portmaster is a free open source firewall for Windows and of all the firewalls I've tested for Windows, it is the cream of the crop. This guide will show you how to set it up and use it.
Timestamps:
00:00 Network Activity Screen
02:02 Apps Settings
02:43 Safing Privacy Network (SPN)
04:20 Encrypted DNS
05:28 Website Loading Issues (⚠️IMPORTANT⚠️)
06:38 DNS Options
10:00 Filter Lists
10:43 Website Loading Issues (Continued - Filter List Blocks)
11:24 Portmaster vs. other firewalls
12:35 Outro
Article about DNS filter testing:
techblog.nexxwave.be/public-d...
Portmaster Firewall:
safing.io/
github.com/safing/portmaster
Background Songs:
Floof - Jobii
Smithereens - Jobii
Laundry List - Dylan Sitts
Cold Leftovers - Dylan Sitts
👉 kenharris.io 👈 Check out my learning platform here!🏫 It's an ever expanding website that covers technology in-depth. I also have some other useful sections on there such as book recommendations.📘

Пікірлер: 83
@pabloqp7929
@pabloqp7929 8 ай бұрын
Great video! Your channel seems to be a goldmine for networking/security content. Hope it becomes more popular 🎉
@KenHarrisio
@KenHarrisio 8 ай бұрын
Thanks for the support! 🍻
@handler007
@handler007 3 ай бұрын
You're absolutely right to be skeptical about Portmaster's "free" claim, especially coupled with their non-transparent installation process. Here's how to unpack that and why "free" software often needs further scrutiny: How "Free" Software Makes Money: Adware: The software incorporates advertising. This can degrade user experience and sometimes presents subtle security concerns. Limited Features: A "free" version may be severely limited, pushing users to purchase a paid tier to access essential functionality. Data Collection: User data from a "free" service can be highly valuable. Your browsing habits, connections, and device behavior could be sold to third parties. Bundling: The installer might package unwanted additional software (this is less common now but still seen sometimes). In Portmaster's specific case: Since their website doesn't clearly outline their business model alongside the "free" claim, it raises reasonable suspicion. Here are ways they might monetize: Premium Plans: They may offer a limited free version and push users towards paid subscriptions with more features or control. User Data: Without explicit clarification, they could generate revenue by collecting and selling anonymized user networking behavior data. Strategic Partnerships: Unseen bundling of some type or partnerships with other, less reputable products cannot be ruled out with their current lack of installer transparency. The "Plate on the Table" Problem: "How do they bring the plate on the table" (i.e., how do they stay in business) becomes especially relevant when a security-focused product's business model isn't clearly explained. Here's why that transparency is vital: Potential Conflicts: If there are undisclosed ways they profit, this could create scenarios where a focus on your security and privacy may not be their only priority. Trustworthiness: If there's ambiguity around their revenue generation, it's much harder to establish trust as a user, especially given the critical nature of firewall software. Your Best Course of Action: Sticking with your paid firewall is, undoubtedly, the most secure choice for now. While there might be a legitimate explanation within Portmaster, their 'free' claim in combination with the installer raises enough red flags.
@shanevickers1654
@shanevickers1654 2 ай бұрын
Thankyou for introducing me to Portmaster and taking the time to explain its functions..
@mremeyse
@mremeyse 2 күн бұрын
Thanks a lot for the tour and the explanation!
@the_2663
@the_2663 9 ай бұрын
Thank you Ken for the informative content. Keep up the good work.
@KenHarrisio
@KenHarrisio 9 ай бұрын
Thank you!
@Maria_Ahmad
@Maria_Ahmad 9 ай бұрын
Thnaks explanation amazing
@nubfaceforthelose
@nubfaceforthelose Ай бұрын
Thanks for this, another great video from you I have stumbled upon.
@KenHarrisio
@KenHarrisio Ай бұрын
Thanks for the support!
@shuvamsky
@shuvamsky 6 ай бұрын
Great video.Btw Do you know anyway to exclude certain apps from portmaster for e.g steam ,spotify etc?
@KenHarrisio
@KenHarrisio 6 ай бұрын
I don't think there's a way to exclude certain programs. I took a look through settings to confirm and didn't see an option to do it.
@naofacadieta5066
@naofacadieta5066 8 ай бұрын
Hello! Great content; Would IPFIRE be a good firewall for home network security, or do you have any other open source suggestions?
@KenHarrisio
@KenHarrisio 8 ай бұрын
Thanks! Yes, IPFire is a solid choice. If you want two alternatives, pfSense and OPNsense would be two other great options. OPNsense is my personal favorite for open source firewalls.
@ridley674
@ridley674 6 ай бұрын
Ive been using this since the suggestion from pc security channel and it hasnt failed. I use comodo firewall on top of this and comodo has auto containment for apps which is good.
@Andrea_Bassi
@Andrea_Bassi 5 ай бұрын
Is comodo not updated anymore?
@Barncore
@Barncore 5 ай бұрын
Interesting. How would you say it compares to the Malwarebytes WFC? In what ways is one better than the other? And should they work in tandem or instead of each other?
@KenHarrisio
@KenHarrisio 4 ай бұрын
Malwarebytes makes good software. I think their WFC is more similar to Simplewall than it is to Portmaster. If you want something to just be able to do something like auto block internet, then MB would work just fine. PM has more advanced features like encrypted DNS with malware and tracker filtering. The two could probably run fine together. I've used Simplewall and Portmaster together and they work well with each other.
@Barncore
@Barncore 4 ай бұрын
Yeah WFC is basically like Simplewall, in the sense that it's a 3rd party front-end for the factory windows defender firewall. Question, have you stopped using Simplewall and Portmaster together? And if so, which one do you use now?@@KenHarrisio
@KenHarrisio
@KenHarrisio 4 ай бұрын
I'm still running both together for the time being. I really like how Simplewall handles app connection requests.
@Barncore
@Barncore 4 ай бұрын
Yeah same. I'm using WFC for prompting and Portmaster on default mode for the extra filtering@@KenHarrisio
@jkbobful
@jkbobful 3 ай бұрын
I'm surprised how easy it was to set up
@senritsujumpsuit6021
@senritsujumpsuit6021 7 ай бұрын
do you have a more detailed experience with Postmaster Pros SPN alternative to VPN am curious since no one else on youtube really talks about it XD
@KenHarrisio
@KenHarrisio 6 ай бұрын
I've actually been testing SPN and a VPN side by side a lot recently. I'm planning the video right now to cover the differences of each and how they work. It'll probably be out in about two weeks.
@blackrookgaming
@blackrookgaming 10 ай бұрын
I tried Portmaster once and then removed it again. There are just too many settings, and I don't know what connections can be blocked and which can go through. I am using Avast's free firewall that is bundled with the antivirus program, for now.
@KenHarrisio
@KenHarrisio 10 ай бұрын
If you want something that is a plug and play solution, then going with a 3rd party suite is the way to go. That being said, like the previous commenter mentioned, Avast has a peppered history and it might be a good idea to choose a different provider.
@hamim8029
@hamim8029 6 ай бұрын
Choose anything but Avast
@NewsHeadlines-2023
@NewsHeadlines-2023 6 ай бұрын
I have used Avast Free Antivirus for more than ten years without any problems. Why shouldn't I use it, and what else do you suggest?@@hamim8029
@tahaaminmazumder8869
@tahaaminmazumder8869 2 ай бұрын
Don't use any free antivirus. If you don't know your machine, you've a learning curve to follow. Better use Linux than Windows. My personal favorite for beginners: Linux Mint, got a retro Win look, but a power house for all kinda users. You can learn the best with Mint Cinnamon or Zorin OS, which you can customize in any way you want. Here comes Zorin OS, for which you'll ve to pay for all the features, while Mint has a huge dedicated community. For typical Windows users, Zonealarm free version is the only way out for those who don't want a firewall that might seem complicated. You'll get a notofication often, just get used to its UI, and it's buttery, but of course not the way Portmaster or Stacer-like applications can do it, well, if your country allows it, mine doesn't.
@Sam-rz3rd
@Sam-rz3rd 7 ай бұрын
How can I set a default, that I get popup asking to allow or deny access to a given app as it tries to acess the internet? ..and how can I create a "local loop" rule (allow -> 127.0.0.1 Block range -> 127.0.0.2 - 255.255.255.255)? Thanks
@KenHarrisio
@KenHarrisio 7 ай бұрын
For a specific app, you can select the app that you want to add that rule to. It's the four boxes button on the middle left side of the app. Select the app that you're looking for, click on the settings tab, and you'll see a dropdown option on "default network action" where you can change it to prompt. As for the second part, you can make custom rules in the settings page. The button is just below the apps button on the left hand side of the app. By default, Portmaster only shows options to make outgoing rules. If you want to make incoming rules, you'll need to go to the top right and change from simple interface to advanced interface. The option to set rules is just above the filter lists section.
@Sam-rz3rd
@Sam-rz3rd 7 ай бұрын
@@KenHarrisioThanks so much!
@peterg902
@peterg902 3 ай бұрын
Seems like a great tool. Thank you for the video. Comodo free firewall has been suggested to be adequate, but can Portmaster compare to it and other known paid products - it would be good with your expertise if possible if you could test this? Thanks again.
@KenHarrisio
@KenHarrisio 3 ай бұрын
Good idea, thanks for suggesting! I'll add it to my video list. To give you a quick answer now, I definitely prefer Portmaster to any other Windows firewall for the time being.
@peterg902
@peterg902 3 ай бұрын
Thanks.
@davesanders4381
@davesanders4381 3 ай бұрын
How do you configure it to support SMB file sharing in a home network using Windows 10?
@KenHarrisio
@KenHarrisio 3 ай бұрын
That's a good question. I'll reach out to the devs to find out.
@ZenEagle
@ZenEagle 3 ай бұрын
The firewall looks good, and it offers a fairly easy interface but it HAS to work. My problem is that it will not connect to my NAS local network storage/backup device. Using Windows 11 Explorer connecting to the NAS first and then enabling the PortMaster firewall the connection will be maintained until the Explorer is shut down. Afterwards reenabling the explorer and logging to the NAS will be blocked. I have tried numerous other Firewalls all connect to NAS without problem.
@KenHarrisio
@KenHarrisio 3 ай бұрын
Thanks for letting me know. I'll let the devs know to see if they can come up with a solution for this.
@SBL972-one
@SBL972-one 3 ай бұрын
hello the best firewall?? while this one does not indicate in which direction this one blocks. if this one is blocked in 1 direction only, then this one is not a good one!
@ReheatedDonut
@ReheatedDonut 6 ай бұрын
It looks cool and seems good on the outside but it caused me more problems than it's worth (blocking certain websites and links I wanted to visit but they had "tracking" scripts or whatever, slowing down my internet speed, and being too resource intensive). I really wanted to like it and use it but couldn't. Back to ole simplewall.
@marcusnascimento2235
@marcusnascimento2235 11 ай бұрын
Good video and solution....but......Can I use it as a network firewall?
@KenHarrisio
@KenHarrisio 11 ай бұрын
Sadly, no. The best option for an open source network firewall is OPNSense. There are a lot of people that recommend pfSense, but there has been a lot of controversy with Netgate. If you want to get about 80% of the way there regarding threat blocking, you can use a good DNS provider. The amount of filtering you get from DNS these days is really damn good. dns0 and Quad9 are excellent free options that don't require a user account and most routers should let you point to DNS servers of your choice. If you're fine with giving up some element of privacy, you could set up an account with ControlD or NextDNS and create your own filter lists. What kind of hardware do you have to work with?
@marcusnascimento2235
@marcusnascimento2235 11 ай бұрын
@@KenHarrisio Wow! Very good explanation! Thanks. I currently work with the Ubiquiti Unifi USG Pro.
@KenHarrisio
@KenHarrisio 10 ай бұрын
@@marcusnascimento2235 USG Pro is a good piece of hardware! What you could do is a piecemeal solution for securing the network. You can enable the intrusion prevention system with deep packet inspection if you haven't done so already. There might also be an option for the USG to enable a honey pot. Keep in mind that IPS and DPI takes a lot of processing power to work. The older USG models will cap out at around 80 mbps and the newer ones at around 250 mbps if you turn those features on, so if you have fast internet, it'll be slowed down somewhat. I don't know if the USG has a way to monitor network activity, but if it doesn't, you could use Portmaster on your computer and use the activity monitor on there. It's a roundabout way to do it, but if a device with malware or an intruder is on the network, you will usually see odd connection requests show up on the activity screen since they will look for more devices to infect.
@marcusnascimento2235
@marcusnascimento2235 10 ай бұрын
@@KenHarrisio Thank you so much for this protection lesson! I have some of these features enabled in the USG. I really like Ubiquiti solutions, and they are improving in terms of security. I'm looking to further protect my work network.
@jackburton5085
@jackburton5085 7 ай бұрын
Does it have an anti telemetry win option by default like Simplewall?
@KenHarrisio
@KenHarrisio 7 ай бұрын
Yup! You can find the specific option in the global settings page > filters list > ads & trackers > telemetry. As soon as it starts, you can see MS connections being blocked in the network activity screen. That said, if you have Group Policy, or if you only have Home edition and use something like Chris Titus Tech's tool to block telemetry, you can stop 95% of it without having to rely on a blocklist.
@jackburton5085
@jackburton5085 7 ай бұрын
@@KenHarrisio Tnx Really kind of you. I use LTSC, and I've already manually deleted some stuff,. Soon i switch to Linux, but unfortunately at least in VM I will still have to deal with Win, so regoing manually everything every time, it's tedious. I take this opportunity to congratulate you on the excellent channel, to which I'm subscribed, which I hope will grow quickly. You have a particular way of explaining, very in-depth unlike many other video tutorials/reviews, i can see that you put passion into it.
@KenHarrisio
@KenHarrisio 7 ай бұрын
@@jackburton5085 Thanks, I appreciate the support! 🍻
@tunnsie
@tunnsie 6 ай бұрын
Unfortunately I had to uninstal as I ran into many issues with my local LAN and DNS. Problem # 1 and it's a big one is the subnetting in the configuration. For local LAN the mouse-over example shows a /24 with the example of 192.168.0.1/24
@SL1PSTAR
@SL1PSTAR 3 ай бұрын
Unfortunately, I'm unable to use Portmaster. For reasons beyond my understanding, a PowerShell script would constantly loop, resulting in frequent CPU usage and the PC fans ramping up and down. I even went as far as formatting with a fresh install of Windows 10, installing Portmaster, yet the issue with the PowerShell script looping persisted. I'm genuinely disappointed and if anyone comes across this same issue with a fix, please drop me a reply. 🤞
@iseptimus
@iseptimus 6 ай бұрын
Its lack of compatibility with newer VPN connectivity is a downside. It’s like they are pushing SPN by forcing DNS locking.
@KenHarrisio
@KenHarrisio 6 ай бұрын
I don't think they are trying to push SPN. It depends on how the settings in the VPN app are used, which like you said, is because of DNS. I've used several different VPNs and it works fine with Portmaster running as long as the VPN DNS isn't enabled. If one wanted to just use an incompatible VPN temporarily, they could also just turn Portmaster off.
@alifsheikh4237
@alifsheikh4237 9 ай бұрын
is comodo firewall good?
@KenHarrisio
@KenHarrisio 9 ай бұрын
It's an okay firewall, though I don't think it's great. One of the biggest issues with it is the massive amount of popups of stuff trying to connect.
@alifsheikh4237
@alifsheikh4237 9 ай бұрын
@@KenHarrisio i put it in safe mode, and it say that chromes tries to connect to the internet and no more, i think i am safe or it doesnt work (sorry for my bad english). Is kaspersky better?
@KenHarrisio
@KenHarrisio 9 ай бұрын
No worries, your English is really good. If you want to block Chrome from having an internet connection and it doesn't work anymore, then yes, it's working. The amount of popups that it throws out makes it hard to really understand what needs to be allowed and what need to be blocked. As for Kaspersky, it's been one of the highest rated security suites for quite a few years. If I had to pick Comodo or Kaspersky, I would definitely take Kaspersky.@@alifsheikh4237
@iewauhedoc9970
@iewauhedoc9970 6 ай бұрын
It's okay ...
@alifsheikh4237
@alifsheikh4237 5 ай бұрын
@@iewauhedoc9970 now i use kaspersky free plan+proton vpn+ some chrome extension (i am thinking to switch to firefox, but idk for all things happening with yt)
@biswajit4134
@biswajit4134 3 ай бұрын
Unfortunately, it's making my connection slow 😢
@ZUKOKBG
@ZUKOKBG 9 ай бұрын
What about zonealarm free firewall
@KenHarrisio
@KenHarrisio 9 ай бұрын
Zonealarm used to be top shelf back in the mid and late 2000's when I first got into this stuff, but I haven't used it in recent years. I was looking at some reviews and it sounds like it has fallen off compared to a lot of other options. Since I haven't used it in so long, I can't give you a good personal opinion on it.
8 ай бұрын
I'll tell you my experience. I've been using it for years. I know that it uses a lot of resources but it was always my go-to firewall. For the last few years, it had something running in the background and it was not only slowing my computer every 10th time, it was getting worse and worse the more time passed by. My RAM and my motherboard were suffering so much, it killed them both. How do I know? I bought a new mobo, new RAM. Top of the line. In less than two weeks, my PC started acting again. Luckily, I manage to figure out that it is only acting when one process from ZoneAlarm was going in endless loop, stressing my whole PC utterly. I deinstalled Zonealarm and not once today did the sluggishness appear. Just installed this firewall and it looks promising. ZoneAlarm is free yet in the end, was costing me 280€. I know, sound silly - firewall destroyed my motherboard haha you must be joking me, right? I am telling you, I've spend counteless hours trying to figure out what is wrong with my PC. After replacing mobo and RAM, I was determined to find out what IS the problem becuase it was driving me crazy. This was only explanation since PC was sluggish ONLY when that process was runnign in the loop in the background, starting / stopping endlesly. Hope this helps. Writing this only becuase I am flabbergasted by the fact that random software in the background was stresing hardware to the maximun so that the hardware finally stopped working. New motherboard and RAM were working for three years like this, until it finally got fried. Only very noticeable last few months, it was sluggish from the beginning but never noticed since it could barely be felt at the very beginnings. Cheers. Sorry for long text. p.s. I love PC hardware, I've assembled more than 50 PCs in my life, it's my hobby, had my own company for repairing computers and that is my hobby since I was 14. I am 45 now. Just saying, I am not a random kid that thinks he knows hardware and saying that XYZ program destroyed my PC is really a bold statement, I know how it sounds but that is the only explanation. Everything, hardware related, in my system is top notch - best components etc. It was a huge suprirse to me that mobo stopped working after only 3 years, that is just ridicilous... But now I know and what ever some one out there could say (haha software killed the mobo haha), I am sure that I am right. Take care.
@KenHarrisio
@KenHarrisio 7 ай бұрын
@ Wow, I didn't know the software had been going that far downhill. Back in the mid 2000s, ZA used to get top reviews and was at the top of their game. It's interesting to see the changes in the cyber world. Panda was another one that used to be top tier and it seems like they've fallen off somewhat as well, and now it's companies like ESET and Kaspersky that are leading the pack. I'm sure in another 10 years, there will be different companies taking those places. And in case anyone doubts what you say, software is absolutely capable of destroying hardware. I've had some close calls with some of my hardware in the past, though fortunately didn't have any of it get fried.
@victorbarboza9373
@victorbarboza9373 Ай бұрын
I think that program asks for another video with a more detailed vison of him 😅
@tahaaminmazumder8869
@tahaaminmazumder8869 3 ай бұрын
It doesn't work in India nowadays, not even on Linux...I used to use this on both Win nd Linux, but this fascist police state blocks it entirely since they started implemented the new IT rules. Could you suggest any measures on the way in India to use it on Airtel, Reliance Jio broadband connections?
@KenHarrisio
@KenHarrisio 3 ай бұрын
Damn, that sucks. I had no idea they were blocking this. I'm guessing it might have something to do with the encrypted DNS? The most immediate thing I can think of that might work instead is to try a VPN with v2ray or a similar obfuscation method to mask the VPN traffic.
@tahaaminmazumder8869
@tahaaminmazumder8869 3 ай бұрын
@@KenHarrisio when ur govt literally attacks, you can hardly do anything. I just got a sudden power interruption yesterday and now one of my Win PC's gone and a power inverter. This happened coz am one of the folks who're organizing this campaign against EVMs in the country, plus I write against this fascist regime and am an athiest+communist in a country where fanatics are the rulers. I'm currently using probably world's most secure-and-privacy friendly VPNs but since the Indian govt made this rule for all VPN providers operating within the territory to give away all user logs for 5 years, Open VPN is the only option remaining, or a reliable Open VPN client. But by the time they connect, at least Windows PCs and Android phones already broadcast your IP. Another interesting thing for more than a year I've been noticing now that no private DNS works on certain telecom/ISPs. You can't download torrents on some ISPs, on others, you've download without VPN. Maybe you can search Central Monitoring System or Aadhaar issues, both political and privacy-related stuff. Unfortunately, nobody writes aganist the digital crime+Gestapo hub this nation's become, thanks to BJP's Narendra Modi govt's media muzzling rules and laws.
@lollubrick
@lollubrick 5 ай бұрын
ok why use a "free firewall" when windows has one built in and you can write a PowerShell script to make it work to suit your particular level of inconvenience or you can even use the built in windows gui with the windows key and R to open the run window (win+r -> "control" -> small icons view -> firewall settings button OR win+r -> "firewall.cpl" -> advanced settings)
@KenHarrisio
@KenHarrisio 5 ай бұрын
Because some people like to have other options and capabilities in a program.
@Barncore
@Barncore 5 ай бұрын
Not everyone knows how to write a Powershell script lol
@lollubrick
@lollubrick 5 ай бұрын
why@@Barncore
@phantom6009
@phantom6009 4 ай бұрын
@@lollubrick apparently being able to write powershell scripts stopped your brain from working
@IOD_
@IOD_ 2 ай бұрын
Its decent but the MAJOR issues with 3rd party software like this is it blocks darn near anything, at random, sometimes even when youre not on the pc. If you're a gamer then prepare your anus because you wont be playing games long before its blocked. And finding what exactly got blocked can take you a long long time to sort thru. I had portmaster, i liked it up until it destroyed my DNS, blocked steam games and random software. Even unblocking something can lead to it being blocked again, or another aspect of the software will be blocked making the entire process not worth it. you will spend more time sorting out wtf is wrong with your pc than utilizing it for your benefit.
@DaemonJax
@DaemonJax 2 ай бұрын
This firewall program is way too simplistic. It doesn't actually have the features that are needed in a firewall. The best I've used is Malwarebyte's Windows Firewall Control. Portmaster seems to want to compete against browser extensions like uBlock Origin with its builtin ip address and domain lists. Useless.
EXCELLENT FREE WINDOWS FIREWALL | Simplewall Guide
26:43
Ken Harris
Рет қаралды 9 М.
This Malware Will Hijack Your Bank Account And Gmail
22:50
Ken Harris
Рет қаралды 286 М.
ПЕЙ МОЛОКО КАК ФОКУСНИК
00:37
Masomka
Рет қаралды 10 МЛН
Be kind🤝
00:22
ISSEI / いっせい
Рет қаралды 20 МЛН
The Anti-Virus Tier List
9:38
Chris Titus Tech
Рет қаралды 799 М.
Secure Your Self-Hosted Network with Wazuh
21:49
Techdox
Рет қаралды 84 М.
Portmaster Intro #3: Overview / Tour
11:43
Safing
Рет қаралды 8 М.
German State Is Ditching Windows For Linux
30:23
Ken Harris
Рет қаралды 72 М.
Free Security Tools Everyone Should Use
13:15
The PC Security Channel
Рет қаралды 1 МЛН
VPN vs DNS - Which Keeps You The Safest?
10:14
Techlore
Рет қаралды 29 М.
12 Privacy & Security Tools I Use EVERY DAY
6:14
All Things Secured
Рет қаралды 65 М.
AI Firewalls are here! (Can your firewall do this?)
42:18
David Bombal
Рет қаралды 95 М.
55 Most Useful FREE SOFTWARE Everyone Should Know!
48:30
Brett In Tech
Рет қаралды 1,4 МЛН
как спасти усилитель?
0:35
KS Customs
Рет қаралды 514 М.
Топ-3 суперкрутых ПК из CompShop
1:00
CompShop Shorts
Рет қаралды 321 М.