Documentation menu

App firewall

NetworkTuna's app firewall decides which apps on this PC can use the network. It works alongside Microsoft Defender Firewall or your preferred Windows firewall and does not change that firewall's rules. It is an addition, not a replacement.

You find the app firewall in three places in the sidebar of the NetworkTuna window:

  • The NetworkTuna firewall switch at the top turns it on or off.
  • Apps opens the Apps page, which lists every app with its firewall setting and the apps that are waiting for your decision.
  • Settings › Security › Firewall holds the firewall settings.
The NetworkTuna sidebar with the NetworkTuna firewall switch, Apps and Settings highlighted

Why an app firewall

Microsoft Defender Firewall lets every app on your PC connect out by default. Any app can reach the Internet and your local network without asking you. Incoming connections are blocked by default, but a program installed with administrator rights, as most installers are, can add its own firewall rules and accept incoming connections too. A new app can start to communicate as soon as it is installed, and you may never notice.

NetworkTuna's app firewall notices every app the first time it uses the network, for incoming and outgoing connections alike, and lets you decide which apps may connect. New apps appear on the Apps page. For an app you have not decided about yet, the default is:

  • An app with a valid digital signature is allowed, and NetworkTuna saves Allow for it. You can still see and change the setting on the Apps page.
  • An unsigned app, or an app whose signature is invalid or could not be checked, is stopped. NetworkTuna holds its connection and asks you whether it may connect. While the NetworkTuna app is closed, the connection is let through by default and the app waits for your decision. See Don't hold connections while the client is closed.

To be asked about more apps, change Automatically allow signed apps in Settings: allow only apps signed by Microsoft, or have NetworkTuna ask about every new app.

Firewall settings

Every app has one firewall setting, which applies to both incoming and outgoing connections:

SettingWhat happens
NoneYou have not chosen yet. NetworkTuna handles new connections automatically: it can allow signed apps, or it asks you.
AllowThe app can connect.
AskNetworkTuna asks you whenever the app makes a new connection.
BlockThe app cannot connect.

You see and change these settings mostly on the Apps page. Every row there shows the app's current setting at its right end. Click it and choose Allow, Ask or Block.

Two rows of the app list with the firewall setting at the right end
Two rows of the Apps page. The icon at the right end of a row is the app's firewall setting.
The firewall settings popover with Allow, Ask and Block

You can also change the setting on the Realtime page, in the app details window, or when NetworkTuna asks you.

The Allow, Ask and Block buttons in the app details window
The firewall setting in the app details window. The arrow next to Allow offers temporary access.

Apps without a setting

When an app without a setting tries to connect, NetworkTuna checks its signature. Depending on Automatically allow signed apps, it allows a signed app on its own. Otherwise, it holds the connection and asks you.

Temporary access

Allow for allows an app for a limited time: 5, 15 or 30 minutes, 1, 3, 6 or 12 hours, or until the app exits. When the time is up, the app's saved setting applies again. You find Allow for in the app actions on the Apps page, and behind the arrow next to Allow in the app details window and in connection requests.

Temporary access ends early when the NetworkTuna service restarts, when the PC restarts, or when the app firewall is turned off and on again.

On the Apps page, an app with temporary access shows a timer instead of its firewall icon. Click the timer to see how much time is left, change the duration or switch the app to Ask.

The firewall settings popover of an app that is allowed for 1 hour
Google Chrome is allowed for 1 hour and goes back to Ask when the time is up.

What the app firewall does not control

  • Connections within this PC (loopback) are never blocked and never cause a prompt.
  • Traffic of Windows itself (System) cannot have its own firewall setting.

Turning the app firewall off

Use the NetworkTuna firewall switch at the top of the sidebar, or Enable NetworkTuna firewall in Settings.

The NetworkTuna firewall and Emergency stop switches
The NetworkTuna firewall and Emergency stop switches at the top of the sidebar.

While the app firewall is off, NetworkTuna does not apply app firewall settings. Your saved settings are restored when you turn it back on.

Turning the app firewall off does not stop security monitoring.

Emergency stop

Emergency stop, directly below the NetworkTuna firewall switch in the sidebar, blocks all network traffic of this PC, including apps that are allowed. It stays on after a restart until you resume traffic.

In this section