Per-application network control without the firewall console
simplewall is a small front end for the Windows Filtering Platform, the filtering layer that Windows itself uses for network traffic. Instead of replacing the built-in firewall or editing its rules, it creates its own filters and presents them as a plain list of applications with an allow or block decision next to each one. The result is closer to the firewall prompts people remember from older systems: when an unknown program tries to connect, you decide once, and the decision is remembered until you change it.
Where the filters live and how rules work
The tool is not a management interface for Windows Firewall and does not touch its rules; it installs its own filters through the same platform, and its window lists installed applications alongside those it has seen on the network. Rules can be created by hand, and an internal blocklist aimed at Windows telemetry is included for those who want it. Activity is visible as notification messages when packets are dropped, with optional logging of dropped traffic on Windows 7 and later and of allowed traffic on newer releases. Windows services, Store applications and the Windows Subsystem for Linux are handled as separate cases, which is important because blocking the wrong system component can break updates or networking in ways that are not obvious from the application list.
Living with an allowlist
The common configuration is blocking by default, so nothing communicates until it is approved. That is effective but demanding: every application update, every new helper process and every background service has to be reviewed, and the prompts arrive when you are busy. The alternative is allowing by default and blocking selectively, which is quieter but only catches what you think to block. Either way, the first session after installation deserves attention, because a machine that has been running unattended for years will announce a lot of connections at once.
Recovery, permissions and limits
simplewall requires administrator rights, and portable mode can be enabled by placing its configuration file next to the executable. Because filters hook deep into the network stack, an over-aggressive rule set can leave a machine with no connectivity, and the tool provides ways to disable its filters so the previous state can be restored before uninstalling. It filters by application and not by domain name, so it cannot express rules like blocking a specific website; it also does not inspect content, provide intrusion detection or replace antivirus software. Windows Update, driver installation and some enterprise management tools depend on network access, so they should be considered deliberately rather than blocked by reflex.
When simplewall is the wrong tool
Users who want a firewall with ready-made profiles and no decisions to make will find this too hands-on. Environments with central policy, logging requirements or compliance rules need a managed firewall rather than a desktop utility. simplewall is for people who want to see and control exactly which local programs talk to the network, and who are willing to spend an hour on the initial rule set to get there.
- Best for
- Advanced Windows users who want per-application outbound control, notification when unknown programs connect, and the option to block telemetry without leaving the built-in firewall.
- Good to know
- It configures Windows Filtering Platform, not Windows Firewall. Blocking system services or update components can break networking or patching, so review those entries carefully and use the option to disable filters before uninstalling.
simplewall puts a plain application list in front of the Windows Filtering Platform.
How to get started
- Run the installer, then start simplewall with administrator rights; it needs them to create filters.
- Choose the filtering mode before anything else: blocking by default is stricter, allowing by default is quieter.
- Work through the application list and enable the programs that genuinely need network access, leaving updates and printing alone for now.
- Turn on notifications so dropped packets are reported while you use the machine normally.
- Add a rule by hand for any application that needs a different decision later, for example allowing only the updater.
- If connectivity breaks, disable the filters from the menu before uninstalling so the previous state is restored.
Questions & answers
Does this replace Windows Firewall?
No. simplewall creates its own Windows Filtering Platform filters and does not read or modify Windows Firewall rules, so both can be active at once.
Why did an application stop working after blocking a rule?
Its traffic is being dropped. Re-enable the entry, or create a narrower rule that allows only the component it actually needs.
Can I block by website or domain?
No. Rules are based on applications and ports, not on domain names, so site-specific blocking belongs in a browser extension or a DNS filter.