Skip to content

Fort Firewall User Guide

Nodir Temirkhodjaev edited this page Oct 7, 2026 · 4 revisions

Fort Firewall User Guide

Applies to Fort Firewall 3.20.1.

Fort Firewall is a firewall for Windows 7 and later. It allows or blocks network access per program. It can also filter by address, port, protocol, direction, network area and network profile, and limit bandwidth.

Fort uses its own Windows Filtering Platform (WFP) driver; it does not configure Windows Defender Firewall.

Contents

Getting started

How it works

Features

Reference

Help

Tip

Most windows open from the tray menu (right-click the Fort icon). Most windows also have three buttons in the top-right corner:

  • a cog button, which opens Options;
  • a chart button, which opens Traffic; its arrow opens the Statistics menu (Traffic, Connections, Filter Simulator);
  • a menu button, which opens the tray menu.

Overview

Fort identifies the program behind every connection by its executable path. It then decides whether to allow or block the connection: see How Fort decides.

2026-10-05_150758

Main features

  • Per-program Allow / Block / Kill Process.
  • Wildcard paths and rules inheritance from parent processes.
  • Per-service filtering for svchost.exe.
  • Groups, Speed Limits and Time Periods (schedules).
  • Zones: address lists, including downloadable block lists.
  • Text-based Rules.
  • Traffic statistics, a connection log with block reasons, and a live Traffic Graph.
  • A Filter Simulator, which shows how Fort would decide on a connection.
  • Password protection and a command line.

Components

Component Role
Driver (fortfw.sys) Makes every allow/block decision and shapes traffic.
Windows Service (FortFirewallSvc) Recommended. Owns the driver and databases, and keeps filtering when no one is signed in.
User interface (FortFirewall.exe) The tray icon and windows. A client of the service when the service is installed.

Installation

Step by step guide to install the software

fort_installation

Requirements

Download the installer from Releases:

Installer Windows CPU
FortFirewall-<version>-windows10-x86_64.exe 10 (1809+), 11 x64
FortFirewall-<version>-windows10-arm64.exe 10 on ARM (2004+), 11 on ARM ARM64
FortFirewall-<version>-windows-x86.exe 7 SP1, 8, 8.1, 10, 11 x86 or x64

You also need:

  • Microsoft Visual C++ Redistributable for the installer's architecture: x64 · x86 · ARM64.
    • The x86 installer needs the x86 redistributable, even on 64-bit Windows.
    • Only the x86 installer checks for it, on a new install. If it is missing, the installer offers the download and exits.
    • The x64 and ARM64 installers do not check, so install the redistributable first.
  • Windows 10 and later: Memory integrity (HVCI) must be off. See below.
  • Windows 7: update KB4474419, for SHA-2 driver signatures.
    • On a new install, the x86 installer checks whether Windows can verify the driver's signature.
    • If it cannot, the installer points you to KB4474419.
  • Administrator rights to install the driver. Without the Windows Service, Fort must also run as Administrator.

Note

The installer's Windows-version, HVCI, VC++ and KB4474419 checks run only on a new install, not on an upgrade.

HVCI / Memory integrity

The Fort driver is a signed loader. It loads the verified driver image into memory that is both writable and executable, which Windows Memory integrity (HVCI) forbids.

On a new install, the installer stops with "This program is not compatible with HVCI (Core Isolation)." if HVCI is on. Fort itself does not check HVCI later.

To turn it off:

  1. Open Windows Security (Windows 11: Settings ▸ Privacy & security ▸ Windows Security).
  2. Go to Device security ▸ Core isolation details.
  3. Set Memory integrity to Off.
  4. Restart Windows.

The HVCI wiki page has the details.

2026-10-05_151154

Caution

Turning Memory integrity off removes a layer of kernel protection. If your organization's policy requires HVCI, get approval first.

Installer options

Task Default Effect
Create a desktop shortcut On Adds a desktop shortcut.
Windows Explorer integration On Adds Fort Firewall ... to the right-click menu of .exe files. See Programs.
Windows Service On Installs and starts FortFirewallSvc. On a new install it also sets Auto-run: to For all users. Recommended.
Portable Off Portable mode. See below.

You can change the service, Explorer integration and auto-run later in My Fort.

2026-10-05_151323

Quick start

  1. Turn off Memory integrity (Windows 10+). Install with Windows Service on.
  2. Fort starts in Auto-Learn mode: every new program is allowed and added to the list.
    • Auto-Learn lasts for Auto-learn seconds: (1 minute by default) after the service starts.
    • Start your usual Internet programs now.
  3. Then Fort switches to Block, if not allowed. Programs not in the list are blocked and marked as alerts.
  4. Open Programs. Allow the programs you trust and block the rest.
  5. If something doesn't work, check Connections. See Troubleshooting.
  6. Optional: enable update checks. See Updating.

Portable mode

Fort keeps its data in a Data folder next to FortFirewall.exe. It recognizes portable mode by a README.portable file in the same folder. The driver still needs Administrator rights.

A portable copy can use the Windows Service too: My Fort ▸ Windows Service ▸ Install also installs the driver, and then Fort runs without Administrator rights. Remove removes both.

There is no uninstaller. To remove portable Fort:

  1. Run Fort as Administrator and use My Fort ▸ Portable ▸ Uninstall.
  2. Choose Quit from the tray menu and wait for Fort to exit.
  3. Delete the folder.

Updating

  1. In Options ▸ Schedule, enable Fort Firewall Update Checker. It is off by default; the interval is daily.
  2. When a release is found, a "New version vX.Y.Z available!" notification opens My Fort ▸ About.
  3. There, use Download, then Install. Check for update checks right away.

Options ▸ Options ▸ Auto Update has three switches, all off by default:

Option Effect
Auto-download new version Downloads a new release when it is found.
Auto-install after download Installs it silently after downloading.
Keep current version Keeps the current release available in About for download or reinstall when no newer release exists, and keeps its downloaded installer.
2026-10-05_151527

Where Fort stores its data

Setup Configuration, programs, statistics Per-user UI settings
With the Windows Service %ProgramData%\Fort Firewall %LOCALAPPDATA%\Fort Firewall
Without the service %LOCALAPPDATA%\Fort Firewall same folder
Portable Data next to FortFirewall.exe same folder

To move these folders:

  • -p <folder> moves the main profile. Statistics and cache follow it; per-user UI settings do not.
  • To move each folder separately, set these keys in FortFirewall.exe.ini next to the executable:
    • global/profileDir
    • global/statDir
    • global/cacheDir
    • global/userDir

Uninstalling

Use Windows Settings ▸ Apps, or the Start-menu uninstall shortcut.

  • At the end, the uninstaller asks Delete config & data files?. The default answer is No.
  • Yes deletes %ProgramData%\Fort Firewall and your %LOCALAPPDATA%\Fort Firewall.
  • With Check password on Uninstall, the installer and uninstaller ask for the Fort password. See Security.

Getting around: tray icon and My Fort

Tray icon

Icon Meaning
Teal Normal.
Gray Filtering is off, or the driver is not available.
Orange Internet or LAN traffic is blocked.
Red Internet and LAN traffic are blocked.
Black with red F All traffic is blocked, except broadcast while Filter Local Addresses is off.
Yellow triangle overlay A new program was alerted. It clears when you open Programs or the alert window.

Default clicks (change them in Options ▸ Interface ▸ Tray):

Click Action
Single Click Show Programs Or Alert Window
Ctrl + Single Click Show Options
Middle Click Show Traffic
Right Click Show Tray Menu

Tray menu

Item Description
My Fort, Programs Open these windows.
Options ▸ The Options, Rules, Zones, Groups, Speed Limits, Time Periods and Services windows.
Statistics ▸ The Traffic, Connections and Filter Simulator windows.
Traffic Graph Shows or hides the graph.
Filter Enabled The master switch for network filtering.
Snooze Alerts Stops the alert window from opening automatically.
Block Traffic ▸ The global block modes.
Filter Mode ▸ See Filter modes.
Group and Rule items Toggle Groups, and Rules that have Tray Menu set.
Quit Closes the UI.

Notes on the menu:

  • Services needs admin rights or the Windows Service.
  • Kill Process and Kill child processes keep working while Filter Enabled is off.
  • With Snooze Alerts on, notifications and sounds still occur.
  • Block Traffic offers No Block, Block Internet Traffic, Block LAN Traffic, Block Internet and LAN Traffic and Block All Traffic.
  • After Quit, filtering continues if the service is installed. Without the service, Fort's program settings stop applying.
  • While Fort is locked by its password, or while Options is open, these items are disabled: Filter Enabled, Snooze Alerts, Block Traffic, Filter Mode and the Group items.
2026-10-05_151911

My Fort window

The My Fort page has four sections:

Section Contents
Driver Status, Reinstall, and Remove (shown only without the service).
Windows Service Install or Remove. Without Administrator rights, Windows asks for them (UAC).
Portable Uninstall (portable mode only).
Integration Windows Explorer integration, Control Panel: Sounds integration, Auto-run: (Disabled / For current user / For all users).

The About page shows the version and updates.

Also in the window:

  • Footer links: Profile, Logs, Service Logs, Releases and Help.
  • Lock / Unlock: shown if a password is set.
  • Admin-only controls: the driver, portable and all-users controls require Administrator rights.
  • Without the service and Administrator rights, Fort cannot access the driver: at startup it offers to install the Windows Service.
2026-10-05_152052

How Fort decides

The driver checks each new connection (inbound or outbound, IPv4 or IPv6) in this order. The first step that decides wins. The Reason column in Connections shows which step decided. The Filter Simulator shows it for a connection you describe, without making it.

# Step Configure in Reason shown
1 Loopback and broadcast are allowed (see note 1) Options ▸ IP Addresses not logged
2 Filter Enabled off: allow everything Tray, Options not logged
3 Block Traffic modes (see note 2) Tray, Options not logged
4 LAN addresses are allowed unless Filter Local Network is on Options ▸ IP Addresses not logged
5 Addresses in Block Addresses: are blocked for every program Options ▸ IP Addresses Internet address
6 Global Rules, applied before App Rules (see note 3) Rules Global Rule before App Rules
7 Unknown program: the Filter Mode decides (see note 4) Filter modes Filter Mode
8 The program's action is Block or Kill Process Programs Program's action
9 Block: Inbound, for inbound connections Edit Program Block Inbound
10 Block: Internet, for non-LAN addresses Edit Program LAN only
11 None of the program's Groups is active (see note 5) Groups App. Group
12 The program's Zones (see note 6) Zones Zone
13 The Rules of the program's active Groups, then its own Rule (see note 7) Rules Rule
14 Global Rules, applied after App Rules Rules Global Rule after App Rules
15 Nothing decided: the program is allowed — Program's action

Notes

  1. Loopback and broadcast: they are allowed unless Filter Local Addresses is on.
    • Block All Traffic blocks loopback, but not broadcast. To block broadcast too, turn on Filter Local Addresses.
    • The LAN block modes block broadcast.
  2. Internet: in the Block Traffic modes, "Internet" means any address not in Local Network Addresses:.
  3. Ignore mode: unknown programs in Ignore mode skip step 6 and every later step.
  4. Unknown programs: the Filter Mode either blocks them here, or allows them; in that case only step 14 still applies.
  5. Groups: if the program has exclusive Groups, only those count. This step requires Block traffic for disabled Groups.
  6. Zones:
    • An address in a rejected zone is blocked.
    • An address in an accepted zone is allowed.
    • Once accepted zones are set, any other address is blocked.
  7. Group Rules: they run in ascending Group ID order. The first rule that decides wins.

Important

  • LAN traffic is not filtered by default. Step 4 allows it before programs, Groups and Rules are checked, and it is not speed-limited. 127.0.0.0/8 and 255.255.255.255 are in the default LAN list too.
  • A Global Rule applied before App Rules can override a program's Block.
  • An allowed program can still be blocked by steps 9–14.

Filter modes

The Filter Mode decides only about programs that are not yet in the Programs list.

Mode Unknown programs are… Added to the list as
Auto-Learn (default) allowed allowed, with an alert mark
Ask to Connect listed, but not available in this version —
Block, if not allowed blocked blocked, with an alert mark
Allow, if not blocked allowed allowed, with an alert mark
Ignore, if not blocked or allowed left to other WFP filters, e.g. Windows Defender Firewall not added, not logged

You can set the mode in the tray Filter Mode menu, in Options ▸ Options, or with -c filter-mode.

How the mode behaves:

  • Auto-Learn timer:
    • Auto-Learn ends after Auto-learn seconds: and switches to Block, if not allowed.
    • The timer starts when Auto-Learn is turned on, and again at every service start while Auto-Learn is still active.
    • Disabled keeps Auto-Learn on indefinitely.
  • Adding programs:
    • In Block and Allow modes, programs are added only when Collect New Programs is on.
    • Connections decided before step 6 of How Fort decides, e.g. LAN traffic, never add a program.
  • Alerts: by default, Fort shows the alert window, a "New program detected!" notification and a sound in Block and Allow modes, but not in Auto-Learn. You can change this in Options ▸ Interface ▸ Programs.

Programs

A program entry holds:

  • an action: Allow, Block or Kill Process;
  • optional network filters, Groups, a schedule, logging flags, notes and an icon.

Kill Process stops the program from starting, even while Filter Enabled is off. It normally also terminates running instances.

Programs window

Control Description
Allow / Block / Remove Act on the selected programs.
Search / Searches name, path and notes. A leading / searches by regular expression.
Filters button Shows only Alerts, Wildcard Paths, Parked, Kill Process or Obsolete programs, or those in selected Groups.
Counters Click the allowed, blocked or alerted counter to sort those programs to the top.
Edit menu The commands below. Also available on right-click.
Edit menu command Shortcut Effect
Timer ▸ — Allow now and block after the chosen time. Disable blocks now.
Allow / Block / Kill Process Alt+A / Alt+B / Ctrl+Alt+K Set the action.
Add / Add Wildcard Ctrl+N / Ctrl+Shift+N Add a program entry or a wildcard entry.
Edit / Remove Enter / Del Edit or remove the selected programs.
Copy Path / Open Folder Ctrl+Shift+C / Ctrl+Shift+O Copy the path, or open the folder.
Review Alerts, Clear Alerts, Remove Alerted Programs — Work through the alert marks.
Purge Obsolete Ctrl+Alt+P Removes programs whose file is gone. Keeps Parked programs, wildcard entries and service entries.

The columns are:

  • Name: struck through if the file is missing.
  • Zones, Rule, Groups, Speed Limits, Scheduled: icons showing what is set.
  • Action: a yellow triangle marks alerted programs.
  • File Path, Creation Time.
  • Notes: hidden by default.

You can also drag an .exe onto the window to add it.

Warning

Edit with several programs selected writes all of the current program's settings to every selected program, including Notes, icon and Rule. Only each program's path and name are kept.

2026-10-05_1507581

Edit Program dialog

The title is Edit Program, or Edit Wildcard for wildcard entries.

General tab

Control Description
File Path: / Wildcard Paths: The program path, or patterns one per line (see the editing rules below).
Name:, Notes, icon Display information.
Rules inheritance: How settings pass between parent and child processes. See Rules inheritance.
Groups The Groups this program belongs to.
Allow / Block / Kill Process The action.
Schedule Run Block, Allow, Remove or Kill Process In: N minutes or At: a date and time.
Quick buttons Shown while Schedule is off (see below).

Editing rules for the path fields:

  • File Path: is editable only when adding an entry.
  • Wildcard Paths: stay editable.
  • Neither can be edited when several programs are selected.

The quick buttons switch the action now, switch it for N minutes, or remove the entry after N minutes. They save at once.

Network Filters tab

Available only when the action is Allow.

Control Description
Download: / Upload: Assign a Speed Limit.
Block: Inbound Block incoming connections.
Block: Internet Allow the LAN only.
Zones See Zones.
Rule See Rules.

More tab

Option Default Description
Kill child processes Off Stops this program from starting new child processes (see the note below).
Parked Off Never purge this program as obsolete.
Collect Traffic Statistics On Records this program's traffic.
Collect allowed connections On Logs this program's allowed connections, if the global switch in Options ▸ Statistics is also on.
Collect blocked connections On Logs this program's blocked connections, if the global switch is also on.

Note

Kill child processes works even while Filter Enabled is off. Children that are already running are not terminated. Restart the program after changing this option: a running instance keeps its previous behavior.

Connections tab

Shows this program's logged connections.

2026-10-05_152846

Alerts

The Alert Program window is the Edit Program dialog for the newest alerted program.

  • Choose an action and click OK, or use a quick button. The window then moves on to the next alert.
  • Programs you skip stay alerted; find them with Review Alerts.
2026-10-05_153211

Wildcard paths

Create wildcard entries with Add Wildcard, or with Switch Wildcard in the dialog. Wildcards work only in wildcard entries.

  • One pattern per line.
  • A line beginning with # is a comment. Comments at the end of a line are not supported.
  • Matching is case-insensitive. / and \ both work.
Pattern Matches
C:\Dl\*.exe .exe files directly in C:\Dl.
C:\Dl\*\*.exe .exe files exactly one folder below.
C:\Dl\** Everything in C:\Dl and its subfolders.
C:\Dl\**\*.exe .exe files in C:\Dl and all its subfolders.
**\app.exe app.exe anywhere.
?:\Dl\** Any drive.
[CD]:\Dl\** Drive C: or D:.
[!C]:\Dl\** Any drive except C:.
^C:\Dl\app[12].exe A leading ^ forces wildcard matching when the line has no * or ?.
C:\Dl\app.exe A line without wildcards is an exact path.

Matching rules:

  • *, ? and [...] never cross \. ** crosses folders only as a whole path segment.
  • \ is never an escape character.
  • Lookup order:
    1. exact paths;
    2. wildcard patterns, where the alphabetically first match wins;
    3. trailing-** prefixes, where the longest wins.

Environment variables in wildcard entries:

  • Variables such as %SystemRoot%, and the built-in %FORTHOME% (Fort's folder), are expanded only in wildcard entries.
  • With the Windows Service, they resolve as Local System. For example, %USERPROFILE% becomes C:\Windows\System32\config\systemprofile.

Rules inheritance

Rules inheritance: has three options:

Option Effect
Propagate to all child processes Child processes, recursively, are treated as this program.
Propagate to designated child processes Only children set to Receive from the parent process inherit.
Receive from the parent process This program takes its settings from a parent that propagates them.

How changes apply:

  • Changes apply to processes started afterwards.
  • A child that inherits its parent's network settings still keeps its own Kill Process setting.

Windows services

Many services share one svchost.exe process. Options ▸ Services lists them. It is available when the Windows Service is installed, or when Fort runs as Administrator.

Command Effect
Make Trackable Runs the service in its own process, so Fort sees it as \SvcHost\<ServiceName>. Fort offers to restart the service or the computer if needed.
Revert Changes Restores the original service configuration.
Restart Service / Refresh Restarts the service / reloads the list.
Add Program Opens Edit Program for \SvcHost\<ServiceName>.

Notes:

  • If Windows Update resets a trackable service, Fort makes it trackable again at startup.
  • On Windows 10+, many services already run separately, so Make Trackable is rarely needed.
2026-10-05_153503

Windows Explorer integration

Right-click an .exe and choose Fort Firewall ... to open Edit Program for that file.

  • On Windows 11 it is under Show more options.
  • The integration is per user.
  • It does not work when Disable command line management is on.
2026-10-05_153700

Groups

A Group is a shared on/off switch for programs, optionally on a Time Period. Open it from the tray: Options ▸ Groups.

Each program joins Groups in Edit Program ▸ General ▸ Groups; a program can be in several.

Field Meaning
Enabled Turns the Group on or off. You can also use the tray menu or a hotkey.
Exclusive Programs with exclusive Groups are enabled only while one of those Groups is active.
Rule: Applied to the Group's programs before their own Rule, while the Group is active.
Time Period: The Group is active only during this period.

How Groups work:

  • A program whose Groups are all inactive is blocked, provided Block traffic for disabled Groups is on (the default).
  • Programs without Groups are unaffected.
  • If a program is in several active Groups, their Rules run in ascending Group ID order (the number shown in the Groups window). The first Rule that decides wins.
2026-10-05_153906

Speed Limits

A Speed Limit caps bandwidth in one direction. Open it from the tray: Options ▸ Speed Limits. Assign limits per program in Edit Program ▸ Network Filters.

Field Meaning
Download / Upload The direction. It can be set only when the limit is created.
Speed: In Kb/s (1 Kb = 1024 bits). The minimum is 1.
Latency: / Packet Loss: Optional delay and simulated packet loss.
Buffer Size: Queue size in bytes. 0 means unlimited. Packets that overflow are dropped.
Time Period: The limit is active only during this period.

How limits behave:

  • Programs that use the same Speed Limit share its bandwidth.
  • Limits work only while Filter Enabled and Speed Limiter Enabled are on.
  • The window's Queue and Dropped columns show the limiter at work.
  • A limit with speed 0 can only come from an older configuration. It is ignored, including its latency and packet loss.
2026-10-05_154015

Time Periods

A Time Period is a weekly schedule used by Groups and Speed Limits. Open it from the tray: Options ▸ Time Periods.

  • A period is active during any of its intervals.
  • A new period starts with one interval, 09:00–18:00 on all days. Add Interval adds another with the same defaults.
  • An interval with the same start and end time lasts 24 hours.
  • If the start time is later than the end time, the interval runs past midnight. The week days are the days on which the interval starts.
  • A disabled period never restricts anything. An enabled period with no intervals is never active.
  • Fort checks periods every minute.
2026-10-05_154120

Zones

A Zone is a named address list. Open it from the tray: Options ▸ Zones.

Source: Notes
Addresses from Inline Text Addresses typed into the dialog.
Addresses from Local File Put the file path in URL:.
WindowsSpyBlocker Downloaded list.
FireHOL Level-1 Downloaded list of attack sources.
TAS-IX Addresses Downloaded list.

Custom URL overrides a source's URL: and Form Data:.

When addresses are loaded

Addresses are loaded only when the Zones Downloader runs. It runs:

  • when you click Update Zones in the Zones window;
  • when you answer Update Zones? after editing a zone;
  • on its schedule, if enabled in Options ▸ Schedule.

Until then, a new zone is empty. At startup, Fort uses the last download.

Where Zones are used

The zone selector has three states:

State Meaning
Checked Accepted
Unchecked Rejected
Partially checked (default) Not used
Place Effect
Edit Program ▸ Network Filters A rejected zone is blocked. An accepted zone is allowed right away, skipping the program's Rules. Once accepted zones are set, all other addresses are blocked.
Edit Rule Without Inline Zones: the rule matches if its zones match or its text matches. With Inline Zones: zones are tested only through the zones filter.
Options ▸ IP Addresses Treat as LAN, or block for all programs.

Warning

  • Zones and rule text are combined with OR, not AND. For example, an Allow Rule with an accepted zone and the text tcp(443) allows any port to that zone, plus TCP 443 to any address. To require both, turn on Inline Zones and write zones:tcp(443).
  • Accepted zones restrict even when they cannot match. Only enabled zones with downloaded addresses match. If a program's accepted zones are disabled or empty, its connections that reach the zone check are blocked. To remove the restriction, set the zone back to partially checked.
2026-10-05_154229

Rules

Open the Rules window from the tray: Options ▸ Rules. It groups rules by type:

Type Applied to
Application Rules Programs and Groups that select the rule; each can select one.
Global Rules, applied before App Rules All connections, at step 6 of How Fort decides.
Global Rules, applied after App Rules Connections that are still undecided, at step 14.
Preset Rules Building blocks that you add to other rules.

Edit Rule dialog

Field Meaning
Name: Global Rules run in case-insensitive alphabetical order of their names. Use 01 …, 02 … prefixes.
Enabled / Tray Menu Turn the rule on or off; show it as a tray toggle.
Allow / Block The action when the rule matches.
Exclusive Allow rules only. The rule's own condition must match before its presets are checked.
Zones / Inline Zones See Zones.
Rule text The condition. See Rule syntax. Right-click ▸ Help opens the wiki.
Preset rules Sub-rules, tried in the listed order. Use Add Preset Rule, Move Up and Move Down.
Terminating Rule: If nothing matched, apply Allow or Block (optionally with Alert) anyway.
Collect allowed connections / Collect blocked connections On by default. Untick to stop logging what this rule decides (see the note below).

Note

Logging exceptions:

  • A matching line with opt(log) still logs; opt(nolog) never logs.
  • When a Preset Rule decides, its own checkboxes count too. A preset with logging on still logs. A preset with logging off suppresses logging, even if the containing rule's box is ticked.
  • The global and per-program logging switches still apply.
2026-10-05_154901

Rule syntax

Element Meaning Example
new line or | OR 1.1.1.1 ⏎ 8.8.8.8
: or a space AND 1.1.1.1:53
name(a, b) Filter with OR'ed values tcp(80, 443)
a-b Range port(1024-65535)
/n Network mask ip(10.0.0.0/8)
[ ] Required around every IPv6 address [2001:db8::1]:443
{ } Nested group of lines see below
! NOT !ip(10.0.0.0/8)
= Local value equals remote value tcp(21)=local_port:dir(in)
# Comment # DNS

Unnamed values:

  • An unnamed value at the start of a line is ip.
  • An unnamed value right after ip, area or zones is port.
  • Any other unnamed value is an error.
Filter (alias) Matches
ip, port Remote address and port.
local_ip, local_port Local address and port.
proto (protocol) tcp, udp, icmp, … or a number.
tcp(...), udp(...) The protocol and the remote port. A bare tcp is ignored; use proto(tcp).
ip_ver (ip_version) 4, 6
dir (direction) in, out
area localhost, lan, inet
profile public, private, domain. One value per filter.
zones The rule's zones: no value or result, accepted, rejected. Needs Inline Zones.
icmp_type, icmp_code ICMP type and code.
act (action) allow, block, drop for this line. One value.
opt (option) log, nolog, alert. log overrides the rule's unticked logging checkbox.

Examples:

# DNS to two resolvers
ip(1.1.1.1, 8.8.8.8):udp(53)

# Outgoing DNS to the Internet
area(inet):udp(53):dir(out)

# Inbound RDP from the LAN (needs "Filter Local Network" on)
area(lan):proto(tcp):local_port(3389):dir(in)

# Always block this address, whatever the rule's action
1.2.3.4:act(block)

# Nested group: outgoing web or DNS
dir(out):{
tcp(80)
udp(53)
}

Tip

  • In Connections, right-click a row and choose Copy as Filter to get rule text for that connection. For more examples, see the Rules wiki page.
  • To check a rule, describe a connection in the Filter Simulator: it shows the deciding Rule:.
  • To edit a rule's text in a file, use -c rule get-text and -c rule set-text. See Command line.

Traffic, connections and Filter Simulator

These windows open from the tray Statistics ▸ menu, or from the chart button in the top-right corner of most windows.

Traffic

Open it from the tray: Statistics ▸ Traffic (or Middle Click on the tray icon).

The Traffic window shows per-program Download and Upload in Hourly, Daily, Monthly and Total views.

  • The All row is the sum of all programs.
  • Search / filters the programs. A leading / searches by regular expression.
  • Units: sets the units of the values: Adaptive, Bytes, KB … PB.
  • The Edit menu has Add Program, Remove Application, Reset Total and Clear All.
  • Ctrl + double-click a view's tab to make it the active one when the window opens.
2026-10-05_155002

Connections

Open it from the tray: Statistics ▸ Connections.

The Connections window is the connection log. Hover the Reason icon to see which step of How Fort decides decided, and which Rule: or Zone:.

Search / filters the connections:

  • Space-separated words must all be found, case-insensitively. A leading / searches by regular expression.
  • It searches the program's file name and name, the process ID, the protocol, the local and remote IP addresses and ports (also by service names, e.g. https), the direction, the action and the reason with its rule or zone name.
  • It does not search the host names and the time.
Columns Notes
Program, Process ID, Protocol —
Local Host Name, Local IP, Local Port Local IP is hidden by default.
Remote Host Name, Remote IP, Remote Port Remote IP is hidden by default.
Direction, Action, Reason, Time Action has an overlay for alerted connections.

The right-click menu has:

  • Copy as Filter, Copy and Lookup IP;
  • Add Program;
  • Filter Simulator, which opens the Filter Simulator for this connection;
  • Remove, which removes the row and all older rows;
  • Clear All.

The Options button has Auto scroll and Show host names.

Important

What gets logged:

  • By default, only blocked connections are logged.
  • The log is cleared when the Fort service restarts, because Clear connections on exit (reduce disk writes) is on.
  • Connections decided at steps 1–4, and unknown programs in Ignore mode, are never logged.
2026-10-05_155111

Filter Simulator

The Filter Simulator shows what Fort would decide on a connection, without making it. Open it from the tray: Statistics ▸ Filter Simulator, or from a row's right-click menu in Connections, which fills in that connection and simulates it at once.

Connection Description
Program Path: The program's executable. The button next to it selects a file.
Direction: Out or In.
Protocol: A name, e.g. TCP, or a number.
Remote IP:, Port: The remote address and port. An IPv6 address may be written in [ ].
Local IP:, Port: The local address and port. An empty Local IP: means any.
Loopback A connection to an address of this computer. 127.0.0.0/8 and ::1 are always loopback.
Network Profile: Public, Private or Domain, for the rules' profile filter.

Click Simulate to see the Result:

Result Description
Action: Allowed, Blocked, Ask to Connect, or Ignored: other firewalls decide (the Ignore mode).
Reason: The step of How Fort decides, as in Connections.
Rule:, Zone: The deciding Rule or Zone, if any.
Program: The program entry found for the path, or Not found: then the Filter Mode decides.

The simulation uses the current options, programs, Rules, active Groups and the last downloaded Zones.

Note

  • The program is checked by its path only: the settings propagated from a parent process (see Rules inheritance) aren't taken into account.
  • Nothing is logged, and no program is added to the list.

Traffic Graph

The tray Traffic Graph item toggles a small live graph of download and upload speed. Appearance settings are in Options ▸ Traffic Graph.

Mouse Effect
Left-drag Move
Right-drag Resize
Double-click Maximize
Right-click Tray menu
2026-10-05_155259

Options reference

Open the window from the tray: Options ▸ Options. Every default value in this guide is listed here.

The buttons at the bottom:

Button Choices
Backup Export, Import, Import new programs (see below).
Default Reset to default all options, Reset to default current tab.
— OK, Apply (Ctrl+S), Cancel.

Warning

Backup choices:

  • Export saves the configuration, settings and statistics to a folder.
  • Import replaces all options and programs with the backup. The windows are restored by the backup's settings too.
  • Import new programs only adds programs whose path is not yet in the list, and leaves existing entries unchanged.
    • The added programs keep basic flags, such as the Allow/Block action, and are marked as alerts.
    • They lose their Groups, Zones, Rule, Speed Limits and custom icon. Review and reassign those.

Options tab

Option Default Notes
Filter Enabled On The master switch.
Block Traffic: No Block The global block modes.
Filter Mode: Auto-Learn See Filter modes.
Block traffic for disabled Groups On See Groups.
Speed Limiter Enabled On See Speed Limits.
Filter Off seconds: Disabled Turns filtering back on this long after you turn it off.
Auto-learn seconds: 1 minute The length of Auto-Learn.
Block traffic when Fort Firewall is not running Off See Security.
Stealth mode (Prevent port scanning) Off See Security.
Disable Service controls Off See Security.
Disable command line management Off See Security.
Check password on Uninstall Off See Security.
Password: none See Security.
Collect New Programs On Adds unknown programs in Block and Allow modes.
Remove alerted programs on Auto-Learn Off Off Deletes still-alerted programs when Auto-Learn ends.
Purge Obsolete only on mounted drives Off Skips unmounted drives when purging.
Keep current version Off See Updating.
Auto-download new version Off See Updating.
Auto-install after download Off See Updating.
Log debug messages Off For diagnostics.
Show log messages in console Off For diagnostics.
Trace Driver Events Off For diagnostics.
2026-10-05_155411

Interface tab

Section Option Default
Global Language: system
Theme: System
Style: Fusion
Use System Regional Settings On
Exclude from screen capture Off
Hot Keys Enabled Off
Global On
Filter Enabled Ctrl+Alt+Shift+F
Group Modifier Ctrl+Alt+Shift (+ F1–F12 for the first 12 Groups in the tray menu)
Rule Modifier none
My Fort Auto-Show Window On
Auto-Show Menu Off
Show Splash screen on startup On
Show window icons as in tray icon Off
Programs Use System Notifications for New Programs On
Auto-Show Alert Window for New Programs On (see below)
Alert Window is Always on top On
Alert Window is auto-active Off
Auto-Clear alerts on window close Off
Sound Alert On
Snooze Alerts Off
Tray Show Icon, Show Alert Icon, Animate Alert Icon On
Maximum count of Groups in menu: 16
Event: / Action: The click actions
Switch Window visibility Off
Action Confirmations Operations from Tray Menu Off
Quit On

The button next to Auto-Show Alert Window for New Programs picks the filter modes that alert:

Mode Default
Auto-Learn Off
Block, if not allowed On
Allow, if not blocked On

IP Addresses tab

Option Default Notes
Filter Local Addresses (127.0.0.0/8, 255.255.255.255) Off Filters loopback and broadcast (see the note below).
Filter Local Network Off While off, LAN traffic is allowed, unlogged and not speed-limited.
Local Network Addresses: built-in list Addresses treated as LAN. Zones can be added.
Block Addresses: empty Blocked for all programs. Zones can be added.

Note

  • With the default LAN list, per-program filtering of loopback and broadcast also requires Filter Local Network. The Block Traffic modes have specific exceptions for these addresses; see note 1 in How Fort decides.
  • Local Network Addresses: contains private, loopback, link-local, CGNAT, multicast/broadcast and IPv6 special-purpose ranges. Right-click ▸ Add Local Networks appends the list.
  • Block Addresses: are not applied to LAN addresses while Filter Local Network is off.
  • The built-in LAN list includes Teredo (2001::/32), 6to4 (2002::/16) and NAT64 (64:ff9b::/96), which can reach the Internet. Remove them if you filter IPv6.
  • The 3.15.0 ChangeLog announced that these fields will move to Global Rules. Prefer a Global Rule for blocking addresses.
2026-10-05_155512

Statistics tab

Option Default
Collect Traffic Statistics On
Collect Traffic, when Filter Disabled On
Active time period: Off
Month starts on: 1
Keep data for 'Hourly': 3 months
Keep data for 'Daily': 1 year
Keep data for 'Monthly': 3 years
Day's Quota: / Month's Quota: Disabled
Block Internet traffic when quota exceeds Off
Collect allowed connections Off
Collect blocked connections On
Alerted only Off
Clear connections on exit (reduce disk writes) On
Keep count for connections: 10K

How these interact:

  • Active time period: limits when traffic is stored and when quotas count. The live graph keeps running outside the period.
  • Quotas count only downloaded traffic that Fort tracks. When a quota is exceeded, Fort shows a Quota Alert.
  • If Block Internet traffic when quota exceeds is on, Fort also turns on Internet blocking. You must undo it yourself.
  • Turning off Collect Traffic Statistics stops the history but not the quota checks. To stop those, set the quota to Disabled.

Traffic Graph tab

Option Default
Always on top On
Hide on close, Frameless, Click through, Hide on hover, Show speed Off
Opacity: / Hover opacity: 90 / 95
Tick label size: 9
Max seconds: 500
Fixed speed: Auto-scale
Units: b/s

The tab also sets Colors (Light | Dark).

Schedule tab

Task Default
Fort Firewall Update Checker Off, daily
Zones Downloader Off, daily
Purge Obsolete Programs Off, daily

To configure a task:

  • Tick a task to enable it, and choose its interval: from Each 5 minutes to Monthly, or Custom in minutes. The list shows it as e.g. 1d 6h 30m.
  • The Options button sets Run On Startup and retries.
  • Run runs the selected task now; Abort stops it.
2026-10-05_154618

Security

Password

Set it in Options ▸ Options ▸ Password:.

It protects:

  • the Programs, Options, Rules, Zones, Groups, Speed Limits, Time Periods, Services, Traffic, Connections and Filter Simulator windows;
  • the alert window;
  • command-line commands, except home show, graph and conf update-driver.

Unlock till: has these choices:

Choice How long Fort stays unlocked
Window closed Until all open protected windows are closed, not just the first one.
Session lockout Until Windows is locked. Already-open protected windows stay usable, and another protected window can be opened from them without the password.
Program exit Until Fort exits.
5 minutes, 10 minutes, 30 minutes, 1 hour For this time.

To force a new password prompt, close the protected windows and click Lock in My Fort. With a choice other than Window closed, Options ▸ Options also shows a Lock the password (unlocked till "…") button below Password:.

2026-10-05_155643

Self-protection options

Option Effect
Block traffic when Fort Firewall is not running Adds boot-time and persistent block filters.
Stealth mode (Prevent port scanning) Silently drops inbound packets that Windows would reject.
Disable Service controls The service refuses Stop and Pause.
Disable command line management -c commands fail with "Command line disabled", except home show and conf update-driver. This also disables Explorer integration.
Check password on Uninstall The installer and uninstaller ask for the password. Silent auto-updates skip this.

Warning

When Block traffic when Fort Firewall is not running is off (the default), Fort filters nothing while it is stopped.

Good practice

  • Allow only programs you recognize, and check the path first.
  • Remember that LAN traffic is unfiltered by default.
  • Remember that Ignore mode hands unknown programs to other firewalls.
  • Treat Fort as one layer of defense, alongside updates, backups and endpoint protection.

Command line

FortFirewall.exe -c <command> controls the running Fort instance.

Command Description
home show Shows My Fort.
filter on|off|report Filtering on/off.
filter-mode learn|ask|block|allow|ignore|report The Filter Mode (ask has no effect).
block no|inet|lan|inet-lan|all|report Block Traffic.
prog allow|block|kill|add|del|report <path> A program. add opens Edit Program, without the Programs window.
group on|off|report <group-id> A Group, by the number shown in the Groups window.
rule on|off|report <rule-name> Enables or disables a Rule, by its exact name (case-sensitive).
rule get-text|set-text <rule-name> <file> Saves the Rule's text to a file, or replaces it by the file's text. The text is checked first.
zone update Runs the Zones Downloader.
graph show|hide|switch Shows, hides or toggles the Traffic Graph.
backup export|import <folder> Configuration, settings and statistics.
conf update-driver Resends the configuration to the driver.

A relative <file> of rule get-text|set-text is resolved against the command's current folder. Give backup a full <folder> path.

Exit codes

Code Meaning
0 Success.
70 + n A report result: n is the value's position in the command's list, e.g. allow = 70, block = 71, kill = 72; for rule report, on = 70, off = 71.
99 prog report: the program is not in the list. group: no Group with that ID. rule: no Rule with that name, or several.
2 Any other failure, e.g. prog del for a program that is not in the list, or an invalid rule text for rule set-text.

Other switches

Switch Effect
--lang <code> The default language, used at first start.
-p <folder> The main profile folder. See Where Fort stores its data.
--no-splash No splash screen.
-i service|auto-run|explorer|portable|boot-filter Install a component. Must be the first argument. In portable mode, -i service also installs the driver.
-u Remove the service, Explorer integration, auto-run and boot filter, but not the driver. Must be the first argument.
-u service Remove only the service (in portable mode, also the driver).
-u explorer Remove only the Explorer integration.

Common tasks

Each task ends with a check.

Tip

To test a new program, copy curl.exe to C:\Temp\curl-test.exe. The copy is unknown to Fort only if:

  • no exact, wildcard or prefix entry covers that path;
  • you start it from a parent that does not propagate its rules (e.g. a plain Command Prompt).

Allow or block a program

  1. In Programs, select the program and click Allow or Block.
  2. Check: retry the program. A block appears in Statistics ▸ Connections with Program's action.

Review new programs

  1. In Programs, use Filters ▸ Alerts, or Edit ▸ Review Alerts.
  2. Allow or block each program; this clears its mark.

Allow a program temporarily

  1. In Programs, use Edit ▸ Timer ▸ 1 hour.
  2. Check: the Scheduled column shows an icon.

Control a whole folder

  1. In Programs, use Edit ▸ Add Wildcard and enter C:\Games\**.
  2. Choose the action and click OK.

Block one Internet address for everyone

  1. Add the address to Options ▸ IP Addresses ▸ Block Addresses: and click Apply or OK.
  2. Check: connect to the address again; the reason shown is Internet address.

Limit download speed

  1. In Speed Limits, choose Edit ▸ Add.
  2. Enter a Name:, select Download, set Speed:, leave Enabled ticked, and click OK.
  3. In the program's Network Filters tab, tick Download:, choose the limit, and click OK.
  4. Check: watch the Traffic Graph.

Allow games only at weekends

  1. In Time Periods, choose Edit ▸ Add and enter a Name:. A new period already has one interval, 09:00–18:00 on all days.
    • Edit that interval; don't add a second one.
    • Set both times to 00:00, which means a whole day.
    • Select only Saturday and Sunday, then click OK.
  2. In Groups, choose Edit ▸ Add and enter a Name:. Tick Exclusive and Time Period:, choose the period, and click OK.
  3. In each game's General ▸ Groups, tick the Group and click OK.
    • Make sure the game is in no other Exclusive Group that is active outside the weekend; any active Exclusive Group enables it.
  4. Keep Block traffic for disabled Groups on.
  5. Check: a game connects during the period and is blocked (reason App. Group) outside it.

Note

The schedule applies only to connections that reach the Group check. LAN traffic and Global Rules applied before App Rules are not affected. See How Fort decides.

Find out why something was blocked

  1. Reproduce the problem.
  2. Open Statistics ▸ Connections and hover over Reason.
  3. Fix only the setting from that step of How Fort decides.
    • Exception: Old connection is not caused by a setting; see Troubleshooting.
  4. Check: right-click the row and choose Filter Simulator. It shows the new decision without a retry.
    • A connection that isn't logged, e.g. LAN traffic, can be described there by hand.

Troubleshooting

Click a problem to expand it.

A new program has no Internet access

Expected in Block, if not allowed mode. Allow it in Programs; look for the yellow triangle.

An allowed program is still blocked
  1. Check Statistics ▸ Connections ▸ Reason. It usually tells you which step decided.
  2. Find that step in How Fort decides; its row shows where to fix it.
  3. To check the fix, use the Filter Simulator.

Old connection is the exception: it is not caused by a setting. The driver could not associate or track the connection. This can happen:

  • when an open connection is re-authorized;
  • with resource errors on new connections.

Retry with a new connection. If it persists, check Logs and turn on Trace Driver Events.

A program lost access after a zone was disabled

The program's accepted zones still restrict it. Either:

  • re-enable the zone;
  • update the zone;
  • or set it back to partially checked in Network Filters.
Nothing appears in Connections

Possible causes:

  • a Block Traffic mode is on (possibly set by a quota);
  • the logging switches are off, globally or for the program;
  • Alerted only is on;
  • the log was cleared at restart.
Unknown programs are not added

Possible causes:

  • Ignore mode;
  • Collect New Programs is off;
  • the traffic is LAN-only, or decided at steps 1–5.
No alert popups
  • This is expected in Auto-Learn mode; see Options ▸ Interface ▸ Programs.
  • Check whether Snooze Alerts is on.
LAN traffic is not filtered

This is the default. Turn on Filter Local Network, or use Block LAN Traffic.

An environment variable doesn't match

Variables work only in wildcard entries. With the service installed, they resolve as Local System.

Speed Limits have no effect

Check that:

  • Speed Limiter Enabled and Filter Enabled are on;
  • the limit is enabled, in its period, and its speed is above 0;
  • it is assigned to the program;
  • the traffic is not LAN traffic.
A program set to Kill Process is still running

This is expected after a wildcard change, or a change to more than 7 programs at once. Close the running instances; new starts are blocked.

A program won't start

Check:

  • its Kill Process action;
  • Kill child processes on the program that launches it.

Both work even while filtering is off. After changing Kill child processes, restart the parent program.

The installer says "not compatible with HVCI"

Turn off Memory integrity, then restart. See HVCI / Memory integrity.

The driver is not working
  • Use My Fort ▸ Driver ▸ Reinstall (needs admin rights).
  • Without the service, run Fort as Administrator.

Limits

Item Maximum
Groups 32
Speed Limits 32
Zones 32
Time Periods 64
Rules (total) 1024
Rules per Global category 64
Preset rules per rule 32
Preset nesting depth 8
{ } nesting in rule text 7
Groups in the tray menu 16
Rules in the tray menu 8

Further documentation

Topic Link
Rule syntax and examples Rules wiki
HVCI details HVCI wiki
Frequently asked questions FAQ
Downloads Releases
Bug reports Issues
Questions and ideas Discussions

Clone this wiki locally