App Firewall: Network Monitor Help & FAQ

See every app on your Mac that reaches the internet, block the ones that should not, and track how much data each of them uses - with all analysis happening on your own machine.

App Firewall: Network Monitor app icon App Firewall: Network Monitor View product page →

Frequently asked questions

What does App Firewall do?

It shows every app on your Mac that opens a network connection, and lets you allow or block each one. Alongside the per-app list you get a live monitor of connections as they happen, a map of where traffic is going, and a breakdown of how much data each app has sent and received.

How is this different from the firewall built into macOS?

The macOS firewall mainly controls incoming connections - what can reach your Mac from outside. App Firewall focuses on outgoing traffic: which of your own apps are reaching out, where they are going, and how much they are sending. Those are complementary, and most surprises live on the outgoing side.

What permission does it need on first launch?

macOS requires you to approve a network filter before any app can inspect or block traffic. On first launch you will be asked to allow App Firewall to filter network content, and the approval is confirmed in System Settings. Until you approve it, the app can show you nothing, because the system does not route traffic through it.

How do I block an app from the internet?

Find the app in the per-app list and switch it to blocked. The rule takes effect immediately for new connections and persists across restarts and app updates, so a blocked app stays blocked until you change your mind.

Will blocking an app break it?

It depends on the app. Something whose whole purpose is online will stop working as expected, while an app that only phones home for analytics usually carries on fine. Blocking is reversible, so the practical approach is to block, use the app normally, and unblock if something you rely on stops working.

What does the connection map show?

It plots the destinations your traffic reaches on a world map, based on the IP addresses your apps connect to. It is the fastest way to spot something unexpected - an app you assumed was local talking to a server on the other side of the world stands out immediately.

Does it inspect the contents of my traffic?

No. App Firewall works with connection metadata - which app, which destination, which port, how much data - not the contents of your encrypted traffic. It does not install a certificate, does not decrypt anything, and does not act as a man-in-the-middle.

Does any of my data leave the Mac?

No. All monitoring and rule evaluation happen locally. The app does not require an account, does not upload logs, and does not send telemetry. What it observes about your network stays on your machine.

Will it slow down my Mac or my connection?

The filter is designed to sit in the connection path with minimal overhead, so normal browsing and streaming feel unchanged. Very high-throughput transfers are the workload most likely to show any measurable difference.

Does it work alongside a VPN?

Yes, in most setups. Rules still apply to the app making the connection. Note that when a VPN is active, destinations can appear as the VPN exit rather than the true endpoint, so the connection map reflects where traffic leaves the tunnel.

How does per-app data usage work?

App Firewall totals the bytes each app sends and receives over time, so you can see which apps are actually consuming bandwidth. It is particularly useful on tethering or a metered plan, where a background sync can quietly use an allowance.

Can I get told when something connects for the first time?

Yes. Turn on connection alerts and you will be notified when an app reaches the network for the first time, so you can decide about it right then rather than discovering it months later in a log.

What can I do from the menu bar?

The menu bar view shows current network activity at a glance and lets you cut off an app without opening the main window - handy when you notice something uploading in the middle of a call.

What version of macOS do I need?

App Firewall requires macOS 14.0 or later and runs natively on Apple Silicon and Intel Macs.

App Firewall: Network Monitor

Get App Firewall: Network Monitor

Per-app network monitor and outgoing connection blocker for macOS, with live traffic, a connection map, and data usage.

How-to guides

How to stop an app from connecting to the internet

Block a single app without uninstalling it or editing any configuration files.

  1. Approve the network filter when App Firewall asks on first launch - nothing is visible until you do.
  2. Open the per-app list and let it populate while you use your Mac normally for a few minutes.
  3. Find the app you want to stop and switch it to blocked.
  4. Use the app as usual and confirm the parts you care about still work.
  5. If something you need breaks, switch the same entry back to allowed - the change applies right away.

Block one app at a time. If you block a batch at once and something stops working, you have no quick way to tell which rule caused it.

Try this in App Firewall: Network Monitor →

How to find what is using your bandwidth

Turn "the internet feels slow" into the name of an app.

  1. Open the live monitor and watch which apps are opening connections right now.
  2. Switch to data usage to see totals per app rather than a moment-in-time view.
  3. Sort by data sent or received to bring the heaviest app to the top.
  4. Check the connection map if a destination looks unfamiliar for that app.
  5. Block or pause the offender temporarily, and see whether your connection recovers.

Large background uploads are often backup or photo-sync tools catching up. Those are usually worth pausing rather than blocking permanently.

Try this in App Firewall: Network Monitor →

Related guides

Still need help?

Our support team usually replies within one business day.

Download App Firewall: Network Monitor Contact support