Application Firewalls: Complete Multi-Platform Guide on Windows, Linux, BSD and macOS

Application Firewalls: Complete Multi-Platform Guide

🚀 Introduction to Application Firewalls

SafeITExperts offers this comprehensive guide, a multi-platform analysis (Windows, Linux, BSD, macOS) and practical implementations for IT admins and security devs. Application firewalls (Web Application Firewalls, WAF) are essential to protect web applications against modern cyberattacks. Unlike classic network firewalls, which operate at layers 3 (network, IP) and 4 (transport, TCP/UDP) of the OSI model, WAFs perform deep inspection of data content at layer 7 (application, HTTP/HTTPS).

OWASP Top 10 Vulnerabilities: Focus on Injections

WAFs protect against SQL injections, XSS, DDoS, and other OWASP Top 10 vulnerabilities. This table presents the most common injections, their mechanism, and their risk level according to the OWASP ranking.

Injection TypeDescriptionExampleRiskOWASP Source
SQL Injection (SQLi)Insertion of malicious SQL code into a request to manipulate the database.' OR '1'='1Unauthorized access, data deletion.A03: Injection
Cross-Site Scripting (XSS)Injection of JavaScript scripts to execute code in the browser.<script>alert('XSS')</script>Cookie theft, malicious redirection.A03: Injection
Command InjectionExecution of arbitrary system commands via user input.; rm -rf /Complete server compromise.A03: Injection
LDAP InjectionManipulation of LDAP requests to bypass authentication.*)(uid=*Sensitive data leakage.A03: Injection
XML External Entity (XXE)Injection of external entities into XML to read files or SSRF.<!ENTITY xxe SYSTEM "file:///etc/passwd">File exposure, DoS.A04: Insecure Design
Path TraversalManipulation of paths to access unauthorized files.../../etc/passwdAccess to sensitive files.A01: Broken Access Control

Source: OWASP Top 10 2021-2025 (OWASP).

⚙️ Architecture and Operation

WAFs use Deep Packet Inspection (DPI), application filtering, and contextual inspection to secure traffic. Here is a flow example:

🌐Web TrafficHTTP / HTTPS
Application Firewall
L7 Deep Inspection
🖥️Protected AppWeb & DB Server
Allowed
➔
➔
➔
Blocked
➔
➔
🚫
🟢 Green arrows: Allowed traffic | 🔴 Red arrows: Blocked traffic
🔐
Updates
Apply the latest security updates for your OS and WAF.
📋
Rule Audit
Review your filtering rules monthly with OWASP ZAP.
📊
Logging
Enable detailed logs and integrate with a SIEM like ELK Stack.

📚 The OSI Model: Understanding Network Layers

The OSI (Open Systems Interconnection) model divides network operation into 7 layers. Each layer has a specific role, like a team in a factory passing work to the next team. This table presents each layer with its role, concrete examples, and a simplified explanation.

LayerNameRoleExampleExplanation for Beginners
1PhysicalTransmission of raw bits via hardwareEthernet cables, Wi-FiLike wires carrying electricity in a house.
2Data LinkManages communication between neighbor devicesMAC, switchesLike ensuring two neighbors speak the same language.
3NetworkDefines paths for data (routing)IP, routersLike a GPS guiding data to the right address.
4TransportEnsures reliable data deliveryTCP, UDPLike a delivery service checking that everything arrives intact.
5SessionManages sessions between applicationsNetBIOS, RPCLike organizing a conversation between two programs.
6PresentationFormats and translates dataSSL, JPEGLike translating text so it is understandable.
7ApplicationInteracts directly with the userHTTP, FTPWhat you see, like a website or an app.

OSI Layers and Associated Protocols Table

The OSI (Open Systems Interconnection) model is a theoretical and conceptual model that describes the 7 layers of network communication. It is crucial to understand that the OSI model itself is not a protocol; it is a roadmap that helps to standardize and categorize the functions of different protocols.

Actual protocols used on the Internet (such as TCP, IP, HTTP, etc.) most often follow the TCP/IP (4 or 5 layers) model, which is a practical implementation of the OSI model. The table below associates real protocols and technologies with the OSI layers to which they functionally correspond.

OSI LayerN°NameMain Protocols & TechnologiesMain Role and Function
7ApplicationApplication LayerHTTP, HTTPS, FTP, SMTP, POP3, IMAP, DNS, DHCP, SNMP, TelnetInterface between user and network. Provides network services to applications (web browsing, email, file transfer).
6PresentationPresentation LayerSSL, TLS, JPEG, MPEG, GIF, ASCII, EncryptionTranslation, encryption, and compression of data. Ensures application layer data is understood by the other system.
5SessionSession LayerNetBIOS, RPC (Remote Procedure Call), PPTP, SocketsEstablishes, manages, and terminates connections (sessions) between applications. Manages synchronization and dialogue.
4TransportTransport LayerTCP (Transmission Control Protocol), UDP (User Datagram Protocol)Ensures complete data delivery. Manages flow control, segmentation, and data reassembly. TCP is reliable (with acknowledgement), UDP is faster but unreliable.
3NetworkNetwork LayerIP (Internet Protocol - IPv4/IPv6), ICMP, IPsec, OSPF, BGP, RoutersLogical addressing (IP addresses) and routing packets through the network (from one network to another). Determines the best path.
2Data LinkData Link LayerEthernet, PPP, Switch, Bridge, MAC (Media Access Control), VLAN, Frame RelayPhysical addressing (MAC addresses). Manages frame transmission on physical media. Error detection and correction.
1PhysicalPhysical LayerRJ45 Cable, Fiber optic, Hub, Repeater, Wi-Fi (IEEE 802.11), Electrical/optical signalsRaw bit transmission (0 and 1) on the physical medium (cable, radio). Defines electrical, mechanical, and functional characteristics.

Relationship with the TCP/IP Model (Internet Model)

It is very important to note the correspondence between the OSI (7-layer) model and the TCP/IP (4-layer) model that is actually used:

TCP/IP ModelOSI ModelKey Protocols
Application (Layer 4)Application (7)
Presentation (6)
Session (5)
HTTP, FTP, DNS, SMTP
Transport (Layer 3)Transport (4)TCP, UDP
Internet (Layer 2)Network (3)IP, ICMP, Routing
Network Access (Layer 1)Data Link (2)
Physical (1)
Ethernet, Wi-Fi, PPP

In summary: The OSI model is a perfect pedagogical and conceptual tool to understand and learn network operation. When you implement or troubleshoot a network, you work primarily with TCP/IP suite protocols.

🖥️ Overview by Operating System

🐧 Linux

Linux solutions offer flexibility and performance with open source and commercial options.

  • OpenSnitch: Mature and active solution for all distributions
  • BunkerWeb: Modern WAF for containerized environments
  • Endian Firewall: Complete UTM with dedicated Linux distribution
🍎 macOS

macOS offers elegant solutions with native integration into the Apple ecosystem.

  • Little Snitch: Reference commercial solution since 2003
  • LuLu: Free alternative by Objective-See, very active
🪟 Windows

Windows offers robust integration with native and third-party solutions.

  • Windows Defender Firewall: Integrated, basic application capabilities
  • Comodo Internet Security: Complete suite with advanced HIPS
👹 BSD

BSD systems distinguish themselves by their robustness and innovative approach.

  • Zenarmor: Commercial plugin for OPNsense with advanced DPI

🔍 Detailed Analysis by Solution

💡 Click or tap each card to reveal detailed analysis and technical specifications on the back.

OpenSnitch
Linux application firewall
🔄 Click to reveal
Created: April 2017
Latest version: v1.7.2 (August 2025)
Type: Outbound Application L7
License: GPL v3 (free)
Maintenance: Very active
Key features: Interactive outbound connection filtering, malicious domain blocking, SIEM integration
🔄 Click to return
BunkerWeb
Modern WAF
🔄 Click to reveal
Created: 2019
Latest version: v1.5.x (active)
Type: WAF L7
License: AGPL v3 (free)
Maintenance: Very active
Key features: ModSecurity integration with OWASP rules, adaptive anti-bot protection, automated SSL/TLS certificate management
🔄 Click to return
Little Snitch
macOS firewall
🔄 Click to reveal
Created: 2003
Latest version: v6.2.2 (March 2025)
Type: Bidirectional Firewall L7
License: Commercial ($45)
Maintenance: Active
Key features: Real-time global connection map, automatic network profiles, TLS inspection
🔄 Click to return
Zenarmor
BSD Solution
🔄 Click to reveal
Created: ~2019
Latest version: 2025 updates
Type: NGFW + Application Control L7
License: Commercial / Freemium
Maintenance: Active
Key features: Deep Packet Inspection, cloud signature database, real-time threat intelligence
🔄 Click to return

📊 Complete Comparison Matrix

SolutionTarget OSFirst VersionCurrent VersionFirewall TypeLicense2025 Maintenance
OpenSnitchLinux (all distros)April 2017v1.7.2 (August 2025)Outbound App L7GPL v3 (free)✅ Very active
BunkerWebLinux / Docker / Kubernetes2019v1.5.x (active)WAF L7AGPL v3 (free)✅ Very active
ZenarmorFreeBSD / OPNsense~20192025 updatesNGFW + App Control L7Commercial / Freemium✅ Active
Endian FirewallLinux (own distro)2003–2005Active (commercial)Complete UTM L3–L7Hybrid GPL / Commercial✅ Active (commercial)
Little SnitchmacOS2003v6.2.2 (March 2025)Bidirectional Firewall L7Commercial ($45)✅ Active
LuLumacOS 10.15+~2018v3.1.5 (April 2025)Outbound App L7Free (open source)✅ Active
Windows Defender FirewallWindows (integrated)2001 (XP SP2)Integrated Windows 11Network L3–L4 + Basic AppIntegrated Microsoft✅ Maintained by Microsoft
Comodo Internet SecurityWindows~2008v12.2.x (active)Bidirectional Firewall L7Freemium / Commercial✅ Active

🔮 Future Trends

In 2025, WAFs are evolving with the integration of AI and Zero Trust architectures. Here are the main trends:

🤖 AI and Machine Learning

WAFs use AI to detect anomalies in real time (e.g., CrowdSec with ML).

🔒 Zero Trust

Continuous verification of identity and devices, integrated into modern WAFs.

☁️ Cloud and Containers

WAFs like BunkerWeb adapt to Kubernetes and cloud-native environments.

SolutionAI/MLZero TrustCloud-NativeExample Use Case
CrowdSecBehavioral analysisOkta integrationDocker, KubernetesDDoS attack detection
Cloudflare WAFHeuristic detectionZscaler compatibleServerlessMalicious bot blocking
FortiWebML for XSS/SQLiMulti-factor authAWS, AzureREST API protection

🧠 AI Monitoring

🛡️ Modern WAFs (Web Application Firewalls) increasingly integrate advanced monitoring tools based on Artificial Intelligence (AI) and Machine Learning (ML). This evolution is radically transforming their ability to detect and counter cyberthreats in a proactive and adaptive manner.

🤖 How AI strengthens WAF monitoring
  1. Behavioral detection and anomaly analysis: Unlike traditional WAFs, which rely mainly on pre-established signatures to identify known threats, modern WAFs use ML algorithms to establish a baseline of normal behavior for an application or user.
  2. Drastic reduction of false positives: Contextual and behavioral analysis allows better distinction between legitimate traffic (even if unusual) and truly malicious activity.
  3. Predictive and proactive analysis: By analyzing massive volumes of traffic data in real time, AI algorithms can anticipate attack trends.
Traditional WAF FunctionImprovement brought by AI
Detection via known threat signaturesBehavioral detection of new and unknown (zero-day) threats
Static and manual security rulesDynamic, self-adaptive, and self-learning security rules
High false positive rate alerting incorrectly on legitimate trafficMassive reduction of false positives thanks to contextual analysis

🛠 Technical Challenges and Solutions

Modern WAFs must overcome several challenges to remain effective:

⚡ Performance

WAFs must minimize latency while inspecting massive volumes of data. Solution: Optimization via asynchronous DPI.

🧩 Complexity

Rule management can become complex. Solution: GUI interfaces and automation via scripts.

⚠️ False Positives

WAFs can block legitimate requests. Solution: Threshold adjustment with ML.

📈 Case Studies and Benchmarks

Here are two concrete use cases for WAFs:

🛒 E-Commerce on Linux with BunkerWeb

An e-commerce platform deployed BunkerWeb to protect its REST APIs against SQL injections. Results: 99.9% of attacks blocked, average latency of 1 ms under 10k req/s.

🏢 Enterprise BSD with Zenarmor

An enterprise used Zenarmor on OPNsense to block social networks during working hours, reducing bandwidth usage by 30%.

🏠 Special Use Case: qBittorrent Configuration

A user installs qBittorrent on their machine and wants to authorize or restrict its connections via various application firewalls. Here are the detailed steps for each solution.

OpenSnitch (Linux)

  1. Start the daemon and interface: sudo systemctl start opensnitchd and opensnitch-ui &
  2. Start qBittorrent and generate the rule request window.
  3. In the OpenSnitch popup: Allow or Deny and set the duration.
  4. Refine the rule (optional): Edit the rule to filter by port (e.g., 6881) or protocol.

LuLu (macOS)

  1. Install LuLu from Objective-See and launch the application.
  2. Open qBittorrent: an alert appears "App qbittorrent wants network access".
  3. In the LuLu notification: Select "Allow" for permanent access, or "Block" if you want to deny.
  4. To customize: Open LuLu → Rules tab → find qbittorrent → edit permissions.

Comodo Internet Security (Windows)

  1. Launch Comodo Internet Security and go to Firewall → Application Rules.
  2. Click Add and navigate to C:\Program Files\qBittorrent\qbittorrent.exe.
  3. In the rule creation window: Access: "Allow", Direction: "Both".
  4. Ports & Protocols tab: Add TCP port 6881 and/or UDP 6881.

Zenarmor (OPNsense)

  1. From the OPNsense interface, install and activate the Zenarmor plugin.
  2. Go to Zenarmor → Policies → Application Control.
  3. Click Add New Rule: Application "qBittorrent", Action: "Allow".
  4. Save and Apply Policy.

Windows Defender Firewall (Windows)

  1. Open Control Panel → System and Security → Windows Defender Firewall → Allow an app or feature.
  2. Click Change settings, then Allow another app….
  3. Browse to C:\Program Files\qBittorrent\qbittorrent.exe.
  4. Check Private and/or Public boxes depending on the network used.

📚 Application Firewall Glossary

Discover the essential terms to master WAFs in 2025

WAF
Click to discover
Web Application Firewall, a firewall operating at layer 7 to protect web applications.
Click to return
DPI
Click to discover
Deep Packet Inspection, detailed analysis of network packets to detect threats.
Click to return
Zero Trust
Click to discover
Security model requiring continuous identity and device verification.
Click to return
SQLi
Click to discover
SQL Injection, an attack aimed at manipulating a database via malicious queries.
Click to return
XSS
Click to discover
Cross-Site Scripting, injection of scripts into a web page to compromise users.
Click to return
OWASP
Click to discover
Open Web Application Security Project, an organization defining web security standards.
Click to return

🧠 Application Firewall Quiz

Test your knowledge of application firewall technologies

1
At which OSI layer do WAFs operate?
Click to return
Layer 7 (Application)
Click to return
2
Which Linux tool uses NGINX for WAF?
Click to return
BunkerWeb
Click to return
3
What is the main advantage of Zenarmor on BSD?
Click to return
SSL/TLS inspection and granular control
Click to return
4
Which macOS tool is open source?
Click to return
LuLu
Click to return
5
Which protocol secures communications on Windows?
Click to return
IPsec
Click to return
6
What is the role of AI in modern WAFs?
Click to return
Real-time anomaly detection
Click to return
7
What is the Zero Trust model?
Click to return
Continuous identity verification
Click to return
8
Which attack type aims to overload a server?
Click to return
DDoS
Click to return
9
Which tool analyzes security logs?
Click to return
SIEM
Click to return
10
What is the role of ModSecurity?
Click to return
Rule engine for WAF
Click to return

You have finished the quiz!

🖼️ Reference Architecture Diagrams

Below are the comprehensive reference diagrams illustrating the 7-layer OSI model architecture, network protocols, and application firewall inspection levels.

Detailed 7-Layer OSI Model Architecture
Figure 1: Detailed 7-Layer OSI Model Architecture and Data Flow
OSI Model and TCP/IP Protocol Correspondence
Figure 2: Correspondence Between the OSI Model and TCP/IP Protocol Suite
Firewall Filtering Levels Across OSI Layers
Figure 3: Firewall Filtering Levels Across OSI Layers (from packet filtering to application WAF)

🌟 Conclusion

The Future of Application Firewalls

Application firewalls are essential tools for securing web applications in 2025. Windows offers robust integration with Defender and AppLocker, Linux excels in flexibility with BunkerWeb, BSD distinguishes itself by the performance of Zenarmor, and macOS combines elegance and efficiency with Little Snitch and LuLu. Trends like AI, Zero Trust, and cloud-native deployments are redefining modern WAFs.

To stay protected, adopt a proactive approach: update your systems, audit your rules, and integrate advanced monitoring solutions.

📚 Official Sources

Find here all the sources and references used for writing this guide, categorized.

🔐 Security and Firewall

Official pfSense FreeBSD documentation for stateful packet filtering and L3-L7 rule management.

Linux kernel packet classification and firewall framework replacing legacy iptables.

Global cybersecurity reports and research on web application attack vectors and WAF mitigations.

Authoritative awareness document detailing the top 10 critical security risks for web applications.

🖥️ Specific Platforms

Microsoft technical documentation on Windows integrated network security and application rules.

Apple official support guide for configuring application-level socket filtering on macOS.

Technical community discussions and implementation guidelines for application firewalls on BSD.

In-depth engineering comparison between FreeBSD packet filters (PF, IPFW) and Linux firewalls.

🤖 AI and Zero Trust

Conferences and technical whitepapers on AI-driven cloud infrastructure and threat mitigation.

Deep dive into specialized application firewalls designed to guard generative AI and LLMs.

Technical runtime documentation on monitoring, securing, and defending enterprise AI deployments.

Adaptive edge security and WAF defenses shielding AI workloads from automated abuse.

Comprehensive primer on SASE architecture, zero-trust network access, and continuous verification.

🛠️ Tools and Software

Official open-source repository of the interactive application firewall for Linux desktops and servers.

Next-generation open-source Web Application Firewall built on NGINX with container support.

Layer 7 application control and deep packet inspection engine for OPNsense and FreeBSD.

Unified Threat Management (UTM) platform combining open-source routing, firewall, and VPN.

Premium macOS network monitoring utility and interactive bidirectional application firewall.

Free, open-source macOS outbound firewall designed to detect and block unauthorized traffic.

Modular application interceptor and connection filter tailored for macOS environments.

📊 Reports and Studies

Authoritative research, vulnerability analysis, and real-time telemetry on worldwide cyber threats.

🌐Cloudflare WAF Learning Hub

Educational resource explaining Web Application Firewall architecture and DDoS protection.

Technical exploration of behavioral inspection and attack pattern matching within modern WAFs.

Whitepaper analyzing emerging threats and multi-vector defenses required for WAAP architectures.

👥 Comments

Comment on this article