this post was submitted on 19 Aug 2025
39 points (100.0% liked)

Linux

65368 readers
484 users here now

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

founded 7 years ago
MODERATORS
 

Is there a firewall solution for Linux that will notify me of any connections that other processes try to establish, and let me allow/deny each connection manually?

I would like to get more concious about which tools are connecting to the internet, and how often.

top 8 comments
sorted by: hot top controversial new old
[–] zer0@programming.dev 28 points 9 months ago (1 children)

If you're looking for outgoing requests, check out OpenSnitch. It should do exactly what you're looking for.

[–] myotheraccount@lemmy.world 3 points 9 months ago

Thank you! Exactly what I'm looking for.

[–] boredsquirrel@slrpnk.net 5 points 9 months ago

You are looking for an outbound firewall

Like the others recommended

OpenSnitch has multiple detection ways, eBPF might require activation in the kernel, there are others too, 4 in total

For me on NixOS it worked in eBPF and proc mode. NixOS' weird binary placement makes rules less secure I guess as it can only check commands (if it were nix-native it could use a function for that)

And I had tons of "unknown process"es which I needed to allow to not break things, which kinda makes the thing useless

[–] markus@hubzilla.markusgarlichs.de 4 points 9 months ago (1 children)
[–] myotheraccount@lemmy.world 3 points 9 months ago

Thanks 🙏 Opensnitch is exactly what I'm looking for

[–] redlemace@lemmy.world 1 points 9 months ago (1 children)

You could drop all and use the log function to see all traffic denied

[–] myotheraccount@lemmy.world 2 points 9 months ago (1 children)

Thanks, I'm aware, but I'm looking for an interactive application that lets me create rules on the fly. I don't want to have a one-time session where I check which tools connect to what, but rather something that interrupts me throughout the day...

If such a thing doesn't exist, tipps on how to build it are welcome too though.

[–] redlemace@lemmy.world 1 points 9 months ago

Script that monitors the logs and uses notify-send to throw a popup? Not yet fully interactive but could be a start