Repository navigation
Fort Firewall User Guide
Applies to Fort Firewall 3.20.1.
Fort Firewall is a firewall for Windows 7 and later. It allows or blocks network access per program. It can also filter by address, port, protocol, direction, network area and network profile, and limit bandwidth.
Fort uses its own Windows Filtering Platform (WFP) driver; it does not configure Windows Defender Firewall.
Getting started
How it works
Features
Reference
Help
Tip
Most windows open from the tray menu (right-click the Fort icon). Most windows also have three buttons in the top-right corner:
- a cog button, which opens Options;
- a chart button, which opens Traffic; its arrow opens the Statistics menu (Traffic, Connections, Filter Simulator);
- a menu button, which opens the tray menu.
Fort identifies the program behind every connection by its executable path. It then decides whether to allow or block the connection: see How Fort decides.
- Per-program Allow / Block / Kill Process.
- Wildcard paths and rules inheritance from parent processes.
- Per-service filtering for
svchost.exe. - Groups, Speed Limits and Time Periods (schedules).
- Zones: address lists, including downloadable block lists.
- Text-based Rules.
- Traffic statistics, a connection log with block reasons, and a live Traffic Graph.
- A Filter Simulator, which shows how Fort would decide on a connection.
- Password protection and a command line.
| Component | Role |
|---|---|
Driver (fortfw.sys) |
Makes every allow/block decision and shapes traffic. |
Windows Service (FortFirewallSvc) |
Recommended. Owns the driver and databases, and keeps filtering when no one is signed in. |
User interface (FortFirewall.exe) |
The tray icon and windows. A client of the service when the service is installed. |

Download the installer from Releases:
| Installer | Windows | CPU |
|---|---|---|
FortFirewall-<version>-windows10-x86_64.exe |
10 (1809+), 11 | x64 |
FortFirewall-<version>-windows10-arm64.exe |
10 on ARM (2004+), 11 on ARM | ARM64 |
FortFirewall-<version>-windows-x86.exe |
7 SP1, 8, 8.1, 10, 11 | x86 or x64 |
You also need:
-
Microsoft Visual C++ Redistributable for the installer's architecture: x64 · x86 · ARM64.
- The x86 installer needs the x86 redistributable, even on 64-bit Windows.
- Only the x86 installer checks for it, on a new install. If it is missing, the installer offers the download and exits.
- The x64 and ARM64 installers do not check, so install the redistributable first.
- Windows 10 and later: Memory integrity (HVCI) must be off. See below.
-
Windows 7: update KB4474419, for SHA-2 driver signatures.
- On a new install, the x86 installer checks whether Windows can verify the driver's signature.
- If it cannot, the installer points you to KB4474419.
- Administrator rights to install the driver. Without the Windows Service, Fort must also run as Administrator.
Note
The installer's Windows-version, HVCI, VC++ and KB4474419 checks run only on a new install, not on an upgrade.
The Fort driver is a signed loader. It loads the verified driver image into memory that is both writable and executable, which Windows Memory integrity (HVCI) forbids.
On a new install, the installer stops with "This program is not compatible with HVCI (Core Isolation)." if HVCI is on. Fort itself does not check HVCI later.
To turn it off:
- Open Windows Security (Windows 11: Settings ▸ Privacy & security ▸ Windows Security).
- Go to Device security ▸ Core isolation details.
- Set Memory integrity to Off.
- Restart Windows.
The HVCI wiki page has the details.
Caution
Turning Memory integrity off removes a layer of kernel protection. If your organization's policy requires HVCI, get approval first.
| Task | Default | Effect |
|---|---|---|
| Create a desktop shortcut | On | Adds a desktop shortcut. |
| Windows Explorer integration | On | Adds Fort Firewall ... to the right-click menu of .exe files. See Programs. |
| Windows Service | On | Installs and starts FortFirewallSvc. On a new install it also sets Auto-run: to For all users. Recommended. |
| Portable | Off | Portable mode. See below. |
You can change the service, Explorer integration and auto-run later in My Fort.
- Turn off Memory integrity (Windows 10+). Install with Windows Service on.
- Fort starts in Auto-Learn mode: every new program is allowed and added to the list.
- Auto-Learn lasts for Auto-learn seconds: (1 minute by default) after the service starts.
- Start your usual Internet programs now.
- Then Fort switches to Block, if not allowed. Programs not in the list are blocked and marked as alerts.
- Open Programs. Allow the programs you trust and block the rest.
- If something doesn't work, check Connections. See Troubleshooting.
- Optional: enable update checks. See Updating.
Fort keeps its data in a Data folder next to FortFirewall.exe. It recognizes portable mode by a README.portable file in the same folder. The driver still needs Administrator rights.
A portable copy can use the Windows Service too: My Fort ▸ Windows Service ▸ Install also installs the driver, and then Fort runs without Administrator rights. Remove removes both.
There is no uninstaller. To remove portable Fort:
- Run Fort as Administrator and use My Fort ▸ Portable ▸ Uninstall.
- Choose Quit from the tray menu and wait for Fort to exit.
- Delete the folder.
- In Options ▸ Schedule, enable Fort Firewall Update Checker. It is off by default; the interval is daily.
- When a release is found, a "New version vX.Y.Z available!" notification opens My Fort ▸ About.
- There, use Download, then Install. Check for update checks right away.
Options ▸ Options ▸ Auto Update has three switches, all off by default:
| Option | Effect |
|---|---|
| Auto-download new version | Downloads a new release when it is found. |
| Auto-install after download | Installs it silently after downloading. |
| Keep current version | Keeps the current release available in About for download or reinstall when no newer release exists, and keeps its downloaded installer. |
| Setup | Configuration, programs, statistics | Per-user UI settings |
|---|---|---|
| With the Windows Service | %ProgramData%\Fort Firewall |
%LOCALAPPDATA%\Fort Firewall |
| Without the service | %LOCALAPPDATA%\Fort Firewall |
same folder |
| Portable |
Data next to FortFirewall.exe
|
same folder |
To move these folders:
-
-p <folder>moves the main profile. Statistics and cache follow it; per-user UI settings do not. - To move each folder separately, set these keys in
FortFirewall.exe.ininext to the executable:global/profileDirglobal/statDirglobal/cacheDirglobal/userDir
Use Windows Settings ▸ Apps, or the Start-menu uninstall shortcut.
- At the end, the uninstaller asks Delete config & data files?. The default answer is No.
-
Yes deletes
%ProgramData%\Fort Firewalland your%LOCALAPPDATA%\Fort Firewall. - With Check password on Uninstall, the installer and uninstaller ask for the Fort password. See Security.
| Icon | Meaning |
|---|---|
| Teal | Normal. |
| Gray | Filtering is off, or the driver is not available. |
| Orange | Internet or LAN traffic is blocked. |
| Red | Internet and LAN traffic are blocked. |
| Black with red F | All traffic is blocked, except broadcast while Filter Local Addresses is off. |
| Yellow triangle overlay | A new program was alerted. It clears when you open Programs or the alert window. |
Default clicks (change them in Options ▸ Interface ▸ Tray):
| Click | Action |
|---|---|
| Single Click | Show Programs Or Alert Window |
| Ctrl + Single Click | Show Options |
| Middle Click | Show Traffic |
| Right Click | Show Tray Menu |
| Item | Description |
|---|---|
| My Fort, Programs | Open these windows. |
| Options ▸ | The Options, Rules, Zones, Groups, Speed Limits, Time Periods and Services windows. |
| Statistics ▸ | The Traffic, Connections and Filter Simulator windows. |
| Traffic Graph | Shows or hides the graph. |
| Filter Enabled | The master switch for network filtering. |
| Snooze Alerts | Stops the alert window from opening automatically. |
| Block Traffic ▸ | The global block modes. |
| Filter Mode ▸ | See Filter modes. |
| Group and Rule items | Toggle Groups, and Rules that have Tray Menu set. |
| Quit | Closes the UI. |
Notes on the menu:
- Services needs admin rights or the Windows Service.
- Kill Process and Kill child processes keep working while Filter Enabled is off.
- With Snooze Alerts on, notifications and sounds still occur.
- Block Traffic offers No Block, Block Internet Traffic, Block LAN Traffic, Block Internet and LAN Traffic and Block All Traffic.
- After Quit, filtering continues if the service is installed. Without the service, Fort's program settings stop applying.
- While Fort is locked by its password, or while Options is open, these items are disabled: Filter Enabled, Snooze Alerts, Block Traffic, Filter Mode and the Group items.
The My Fort page has four sections:
| Section | Contents |
|---|---|
| Driver | Status, Reinstall, and Remove (shown only without the service). |
| Windows Service | Install or Remove. Without Administrator rights, Windows asks for them (UAC). |
| Portable | Uninstall (portable mode only). |
| Integration | Windows Explorer integration, Control Panel: Sounds integration, Auto-run: (Disabled / For current user / For all users). |
The About page shows the version and updates.
Also in the window:
- Footer links: Profile, Logs, Service Logs, Releases and Help.
- Lock / Unlock: shown if a password is set.
- Admin-only controls: the driver, portable and all-users controls require Administrator rights.
- Without the service and Administrator rights, Fort cannot access the driver: at startup it offers to install the Windows Service.
The driver checks each new connection (inbound or outbound, IPv4 or IPv6) in this order. The first step that decides wins. The Reason column in Connections shows which step decided. The Filter Simulator shows it for a connection you describe, without making it.
| # | Step | Configure in | Reason shown |
|---|---|---|---|
| 1 | Loopback and broadcast are allowed (see note 1) | Options ▸ IP Addresses | not logged |
| 2 | Filter Enabled off: allow everything | Tray, Options | not logged |
| 3 | Block Traffic modes (see note 2) | Tray, Options | not logged |
| 4 | LAN addresses are allowed unless Filter Local Network is on | Options ▸ IP Addresses | not logged |
| 5 | Addresses in Block Addresses: are blocked for every program | Options ▸ IP Addresses | Internet address |
| 6 | Global Rules, applied before App Rules (see note 3) | Rules | Global Rule before App Rules |
| 7 | Unknown program: the Filter Mode decides (see note 4) | Filter modes | Filter Mode |
| 8 | The program's action is Block or Kill Process | Programs | Program's action |
| 9 | Block: Inbound, for inbound connections | Edit Program | Block Inbound |
| 10 | Block: Internet, for non-LAN addresses | Edit Program | LAN only |
| 11 | None of the program's Groups is active (see note 5) | Groups | App. Group |
| 12 | The program's Zones (see note 6) | Zones | Zone |
| 13 | The Rules of the program's active Groups, then its own Rule (see note 7) | Rules | Rule |
| 14 | Global Rules, applied after App Rules | Rules | Global Rule after App Rules |
| 15 | Nothing decided: the program is allowed | — | Program's action |
Notes
-
Loopback and broadcast: they are allowed unless Filter Local Addresses is on.
- Block All Traffic blocks loopback, but not broadcast. To block broadcast too, turn on Filter Local Addresses.
- The LAN block modes block broadcast.
- Internet: in the Block Traffic modes, "Internet" means any address not in Local Network Addresses:.
- Ignore mode: unknown programs in Ignore mode skip step 6 and every later step.
- Unknown programs: the Filter Mode either blocks them here, or allows them; in that case only step 14 still applies.
- Groups: if the program has exclusive Groups, only those count. This step requires Block traffic for disabled Groups.
-
Zones:
- An address in a rejected zone is blocked.
- An address in an accepted zone is allowed.
- Once accepted zones are set, any other address is blocked.
- Group Rules: they run in ascending Group ID order. The first rule that decides wins.
Important
-
LAN traffic is not filtered by default. Step 4 allows it before programs, Groups and Rules are checked, and it is not speed-limited.
127.0.0.0/8and255.255.255.255are in the default LAN list too. - A Global Rule applied before App Rules can override a program's Block.
- An allowed program can still be blocked by steps 9–14.
The Filter Mode decides only about programs that are not yet in the Programs list.
| Mode | Unknown programs are… | Added to the list as |
|---|---|---|
| Auto-Learn (default) | allowed | allowed, with an alert mark |
| Ask to Connect | listed, but not available in this version | — |
| Block, if not allowed | blocked | blocked, with an alert mark |
| Allow, if not blocked | allowed | allowed, with an alert mark |
| Ignore, if not blocked or allowed | left to other WFP filters, e.g. Windows Defender Firewall | not added, not logged |
You can set the mode in the tray Filter Mode menu, in Options ▸ Options, or with -c filter-mode.
How the mode behaves:
-
Auto-Learn timer:
- Auto-Learn ends after Auto-learn seconds: and switches to Block, if not allowed.
- The timer starts when Auto-Learn is turned on, and again at every service start while Auto-Learn is still active.
- Disabled keeps Auto-Learn on indefinitely.
-
Adding programs:
- In Block and Allow modes, programs are added only when Collect New Programs is on.
- Connections decided before step 6 of How Fort decides, e.g. LAN traffic, never add a program.
- Alerts: by default, Fort shows the alert window, a "New program detected!" notification and a sound in Block and Allow modes, but not in Auto-Learn. You can change this in Options ▸ Interface ▸ Programs.
A program entry holds:
- an action: Allow, Block or Kill Process;
- optional network filters, Groups, a schedule, logging flags, notes and an icon.
Kill Process stops the program from starting, even while Filter Enabled is off. It normally also terminates running instances.
| Control | Description |
|---|---|
| Allow / Block / Remove | Act on the selected programs. |
| Search / | Searches name, path and notes. A leading / searches by regular expression. |
| Filters button | Shows only Alerts, Wildcard Paths, Parked, Kill Process or Obsolete programs, or those in selected Groups. |
| Counters | Click the allowed, blocked or alerted counter to sort those programs to the top. |
| Edit menu | The commands below. Also available on right-click. |
| Edit menu command | Shortcut | Effect |
|---|---|---|
| Timer ▸ | — | Allow now and block after the chosen time. Disable blocks now. |
| Allow / Block / Kill Process | Alt+A / Alt+B / Ctrl+Alt+K | Set the action. |
| Add / Add Wildcard | Ctrl+N / Ctrl+Shift+N | Add a program entry or a wildcard entry. |
| Edit / Remove | Enter / Del | Edit or remove the selected programs. |
| Copy Path / Open Folder | Ctrl+Shift+C / Ctrl+Shift+O | Copy the path, or open the folder. |
| Review Alerts, Clear Alerts, Remove Alerted Programs | — | Work through the alert marks. |
| Purge Obsolete | Ctrl+Alt+P | Removes programs whose file is gone. Keeps Parked programs, wildcard entries and service entries. |
The columns are:
- Name: struck through if the file is missing.
- Zones, Rule, Groups, Speed Limits, Scheduled: icons showing what is set.
- Action: a yellow triangle marks alerted programs.
- File Path, Creation Time.
- Notes: hidden by default.
You can also drag an .exe onto the window to add it.
Warning
Edit with several programs selected writes all of the current program's settings to every selected program, including Notes, icon and Rule. Only each program's path and name are kept.
The title is Edit Program, or Edit Wildcard for wildcard entries.
| Control | Description |
|---|---|
| File Path: / Wildcard Paths: | The program path, or patterns one per line (see the editing rules below). |
| Name:, Notes, icon | Display information. |
| Rules inheritance: | How settings pass between parent and child processes. See Rules inheritance. |
| Groups | The Groups this program belongs to. |
| Allow / Block / Kill Process | The action. |
| Schedule | Run Block, Allow, Remove or Kill Process In: N minutes or At: a date and time. |
| Quick buttons | Shown while Schedule is off (see below). |
Editing rules for the path fields:
- File Path: is editable only when adding an entry.
- Wildcard Paths: stay editable.
- Neither can be edited when several programs are selected.
The quick buttons switch the action now, switch it for N minutes, or remove the entry after N minutes. They save at once.
Available only when the action is Allow.
| Control | Description |
|---|---|
| Download: / Upload: | Assign a Speed Limit. |
| Block: Inbound | Block incoming connections. |
| Block: Internet | Allow the LAN only. |
| Zones | See Zones. |
| Rule | See Rules. |
| Option | Default | Description |
|---|---|---|
| Kill child processes | Off | Stops this program from starting new child processes (see the note below). |
| Parked | Off | Never purge this program as obsolete. |
| Collect Traffic Statistics | On | Records this program's traffic. |
| Collect allowed connections | On | Logs this program's allowed connections, if the global switch in Options ▸ Statistics is also on. |
| Collect blocked connections | On | Logs this program's blocked connections, if the global switch is also on. |
Note
Kill child processes works even while Filter Enabled is off. Children that are already running are not terminated. Restart the program after changing this option: a running instance keeps its previous behavior.
Shows this program's logged connections.
The Alert Program window is the Edit Program dialog for the newest alerted program.
- Choose an action and click OK, or use a quick button. The window then moves on to the next alert.
- Programs you skip stay alerted; find them with Review Alerts.
Create wildcard entries with Add Wildcard, or with Switch Wildcard in the dialog. Wildcards work only in wildcard entries.
- One pattern per line.
- A line beginning with
#is a comment. Comments at the end of a line are not supported. - Matching is case-insensitive.
/and\both work.
| Pattern | Matches |
|---|---|
C:\Dl\*.exe |
.exe files directly in C:\Dl. |
C:\Dl\*\*.exe |
.exe files exactly one folder below. |
C:\Dl\** |
Everything in C:\Dl and its subfolders. |
C:\Dl\**\*.exe |
.exe files in C:\Dl and all its subfolders. |
**\app.exe |
app.exe anywhere. |
?:\Dl\** |
Any drive. |
[CD]:\Dl\** |
Drive C: or D:. |
[!C]:\Dl\** |
Any drive except C:. |
^C:\Dl\app[12].exe |
A leading ^ forces wildcard matching when the line has no * or ?. |
C:\Dl\app.exe |
A line without wildcards is an exact path. |
Matching rules:
-
*,?and[...]never cross\.**crosses folders only as a whole path segment. -
\is never an escape character. - Lookup order:
- exact paths;
- wildcard patterns, where the alphabetically first match wins;
- trailing-
**prefixes, where the longest wins.
Environment variables in wildcard entries:
- Variables such as
%SystemRoot%, and the built-in%FORTHOME%(Fort's folder), are expanded only in wildcard entries. - With the Windows Service, they resolve as Local System. For example,
%USERPROFILE%becomesC:\Windows\System32\config\systemprofile.
Rules inheritance: has three options:
| Option | Effect |
|---|---|
| Propagate to all child processes | Child processes, recursively, are treated as this program. |
| Propagate to designated child processes | Only children set to Receive from the parent process inherit. |
| Receive from the parent process | This program takes its settings from a parent that propagates them. |
How changes apply:
- Changes apply to processes started afterwards.
- A child that inherits its parent's network settings still keeps its own Kill Process setting.
Many services share one svchost.exe process. Options ▸ Services lists them. It is available when the Windows Service is installed, or when Fort runs as Administrator.
| Command | Effect |
|---|---|
| Make Trackable | Runs the service in its own process, so Fort sees it as \SvcHost\<ServiceName>. Fort offers to restart the service or the computer if needed. |
| Revert Changes | Restores the original service configuration. |
| Restart Service / Refresh | Restarts the service / reloads the list. |
| Add Program | Opens Edit Program for \SvcHost\<ServiceName>. |
Notes:
- If Windows Update resets a trackable service, Fort makes it trackable again at startup.
- On Windows 10+, many services already run separately, so Make Trackable is rarely needed.
Right-click an .exe and choose Fort Firewall ... to open Edit Program for that file.
- On Windows 11 it is under Show more options.
- The integration is per user.
- It does not work when Disable command line management is on.
A Group is a shared on/off switch for programs, optionally on a Time Period. Open it from the tray: Options ▸ Groups.
Each program joins Groups in Edit Program ▸ General ▸ Groups; a program can be in several.
| Field | Meaning |
|---|---|
| Enabled | Turns the Group on or off. You can also use the tray menu or a hotkey. |
| Exclusive | Programs with exclusive Groups are enabled only while one of those Groups is active. |
| Rule: | Applied to the Group's programs before their own Rule, while the Group is active. |
| Time Period: | The Group is active only during this period. |
How Groups work:
- A program whose Groups are all inactive is blocked, provided Block traffic for disabled Groups is on (the default).
- Programs without Groups are unaffected.
- If a program is in several active Groups, their Rules run in ascending Group ID order (the number shown in the Groups window). The first Rule that decides wins.
A Speed Limit caps bandwidth in one direction. Open it from the tray: Options ▸ Speed Limits. Assign limits per program in Edit Program ▸ Network Filters.
| Field | Meaning |
|---|---|
| Download / Upload | The direction. It can be set only when the limit is created. |
| Speed: | In Kb/s (1 Kb = 1024 bits). The minimum is 1. |
| Latency: / Packet Loss: | Optional delay and simulated packet loss. |
| Buffer Size: | Queue size in bytes. 0 means unlimited. Packets that overflow are dropped. |
| Time Period: | The limit is active only during this period. |
How limits behave:
- Programs that use the same Speed Limit share its bandwidth.
- Limits work only while Filter Enabled and Speed Limiter Enabled are on.
- The window's Queue and Dropped columns show the limiter at work.
- A limit with speed 0 can only come from an older configuration. It is ignored, including its latency and packet loss.
A Time Period is a weekly schedule used by Groups and Speed Limits. Open it from the tray: Options ▸ Time Periods.
- A period is active during any of its intervals.
- A new period starts with one interval, 09:00–18:00 on all days. Add Interval adds another with the same defaults.
- An interval with the same start and end time lasts 24 hours.
- If the start time is later than the end time, the interval runs past midnight. The week days are the days on which the interval starts.
- A disabled period never restricts anything. An enabled period with no intervals is never active.
- Fort checks periods every minute.
A Zone is a named address list. Open it from the tray: Options ▸ Zones.
| Source: | Notes |
|---|---|
| Addresses from Inline Text | Addresses typed into the dialog. |
| Addresses from Local File | Put the file path in URL:. |
| WindowsSpyBlocker | Downloaded list. |
| FireHOL Level-1 | Downloaded list of attack sources. |
| TAS-IX Addresses | Downloaded list. |
Custom URL overrides a source's URL: and Form Data:.
Addresses are loaded only when the Zones Downloader runs. It runs:
- when you click Update Zones in the Zones window;
- when you answer Update Zones? after editing a zone;
- on its schedule, if enabled in Options ▸ Schedule.
Until then, a new zone is empty. At startup, Fort uses the last download.
The zone selector has three states:
| State | Meaning |
|---|---|
| Checked | Accepted |
| Unchecked | Rejected |
| Partially checked (default) | Not used |
| Place | Effect |
|---|---|
| Edit Program ▸ Network Filters | A rejected zone is blocked. An accepted zone is allowed right away, skipping the program's Rules. Once accepted zones are set, all other addresses are blocked. |
| Edit Rule | Without Inline Zones: the rule matches if its zones match or its text matches. With Inline Zones: zones are tested only through the zones filter. |
| Options ▸ IP Addresses | Treat as LAN, or block for all programs. |
Warning
-
Zones and rule text are combined with OR, not AND. For example, an Allow Rule with an accepted zone and the text
tcp(443)allows any port to that zone, plus TCP 443 to any address. To require both, turn on Inline Zones and writezones:tcp(443). - Accepted zones restrict even when they cannot match. Only enabled zones with downloaded addresses match. If a program's accepted zones are disabled or empty, its connections that reach the zone check are blocked. To remove the restriction, set the zone back to partially checked.
Open the Rules window from the tray: Options ▸ Rules. It groups rules by type:
| Type | Applied to |
|---|---|
| Application Rules | Programs and Groups that select the rule; each can select one. |
| Global Rules, applied before App Rules | All connections, at step 6 of How Fort decides. |
| Global Rules, applied after App Rules | Connections that are still undecided, at step 14. |
| Preset Rules | Building blocks that you add to other rules. |
| Field | Meaning |
|---|---|
| Name: | Global Rules run in case-insensitive alphabetical order of their names. Use 01 …, 02 … prefixes. |
| Enabled / Tray Menu | Turn the rule on or off; show it as a tray toggle. |
| Allow / Block | The action when the rule matches. |
| Exclusive | Allow rules only. The rule's own condition must match before its presets are checked. |
| Zones / Inline Zones | See Zones. |
| Rule text | The condition. See Rule syntax. Right-click ▸ Help opens the wiki. |
| Preset rules | Sub-rules, tried in the listed order. Use Add Preset Rule, Move Up and Move Down. |
| Terminating Rule: | If nothing matched, apply Allow or Block (optionally with Alert) anyway. |
| Collect allowed connections / Collect blocked connections | On by default. Untick to stop logging what this rule decides (see the note below). |
Note
Logging exceptions:
- A matching line with
opt(log)still logs;opt(nolog)never logs. - When a Preset Rule decides, its own checkboxes count too. A preset with logging on still logs. A preset with logging off suppresses logging, even if the containing rule's box is ticked.
- The global and per-program logging switches still apply.
| Element | Meaning | Example |
|---|---|---|
new line or |
|
OR |
1.1.1.1 ⏎ 8.8.8.8
|
: or a space |
AND | 1.1.1.1:53 |
name(a, b) |
Filter with OR'ed values | tcp(80, 443) |
a-b |
Range | port(1024-65535) |
/n |
Network mask | ip(10.0.0.0/8) |
[ ] |
Required around every IPv6 address | [2001:db8::1]:443 |
{ } |
Nested group of lines | see below |
! |
NOT | !ip(10.0.0.0/8) |
= |
Local value equals remote value | tcp(21)=local_port:dir(in) |
# |
Comment | # DNS |
Unnamed values:
- An unnamed value at the start of a line is
ip. - An unnamed value right after
ip,areaorzonesisport. - Any other unnamed value is an error.
| Filter (alias) | Matches |
|---|---|
ip, port
|
Remote address and port. |
local_ip, local_port
|
Local address and port. |
proto (protocol) |
tcp, udp, icmp, … or a number. |
tcp(...), udp(...)
|
The protocol and the remote port. A bare tcp is ignored; use proto(tcp). |
ip_ver (ip_version) |
4, 6
|
dir (direction) |
in, out
|
area |
localhost, lan, inet
|
profile |
public, private, domain. One value per filter. |
zones |
The rule's zones: no value or result, accepted, rejected. Needs Inline Zones. |
icmp_type, icmp_code
|
ICMP type and code. |
act (action) |
allow, block, drop for this line. One value. |
opt (option) |
log, nolog, alert. log overrides the rule's unticked logging checkbox. |
Examples:
# DNS to two resolvers
ip(1.1.1.1, 8.8.8.8):udp(53)
# Outgoing DNS to the Internet
area(inet):udp(53):dir(out)
# Inbound RDP from the LAN (needs "Filter Local Network" on)
area(lan):proto(tcp):local_port(3389):dir(in)
# Always block this address, whatever the rule's action
1.2.3.4:act(block)
# Nested group: outgoing web or DNS
dir(out):{
tcp(80)
udp(53)
}
Tip
- In Connections, right-click a row and choose Copy as Filter to get rule text for that connection. For more examples, see the Rules wiki page.
- To check a rule, describe a connection in the Filter Simulator: it shows the deciding Rule:.
- To edit a rule's text in a file, use
-c rule get-textand-c rule set-text. See Command line.
These windows open from the tray Statistics ▸ menu, or from the chart button in the top-right corner of most windows.
Open it from the tray: Statistics ▸ Traffic (or Middle Click on the tray icon).
The Traffic window shows per-program Download and Upload in Hourly, Daily, Monthly and Total views.
- The All row is the sum of all programs.
-
Search / filters the programs. A leading
/searches by regular expression. - Units: sets the units of the values: Adaptive, Bytes, KB … PB.
- The Edit menu has Add Program, Remove Application, Reset Total and Clear All.
- Ctrl + double-click a view's tab to make it the active one when the window opens.
Open it from the tray: Statistics ▸ Connections.
The Connections window is the connection log. Hover the Reason icon to see which step of How Fort decides decided, and which Rule: or Zone:.
Search / filters the connections:
- Space-separated words must all be found, case-insensitively. A leading
/searches by regular expression. - It searches the program's file name and name, the process ID, the protocol, the local and remote IP addresses and ports (also by service names, e.g.
https), the direction, the action and the reason with its rule or zone name. - It does not search the host names and the time.
| Columns | Notes |
|---|---|
| Program, Process ID, Protocol | — |
| Local Host Name, Local IP, Local Port | Local IP is hidden by default. |
| Remote Host Name, Remote IP, Remote Port | Remote IP is hidden by default. |
| Direction, Action, Reason, Time | Action has an overlay for alerted connections. |
The right-click menu has:
- Copy as Filter, Copy and Lookup IP;
- Add Program;
- Filter Simulator, which opens the Filter Simulator for this connection;
- Remove, which removes the row and all older rows;
- Clear All.
The Options button has Auto scroll and Show host names.
Important
What gets logged:
- By default, only blocked connections are logged.
- The log is cleared when the Fort service restarts, because Clear connections on exit (reduce disk writes) is on.
- Connections decided at steps 1–4, and unknown programs in Ignore mode, are never logged.
The Filter Simulator shows what Fort would decide on a connection, without making it. Open it from the tray: Statistics ▸ Filter Simulator, or from a row's right-click menu in Connections, which fills in that connection and simulates it at once.
| Connection | Description |
|---|---|
| Program Path: | The program's executable. The button next to it selects a file. |
| Direction: | Out or In. |
| Protocol: | A name, e.g. TCP, or a number. |
| Remote IP:, Port: | The remote address and port. An IPv6 address may be written in [ ]. |
| Local IP:, Port: | The local address and port. An empty Local IP: means any. |
| Loopback | A connection to an address of this computer. 127.0.0.0/8 and ::1 are always loopback. |
| Network Profile: |
Public, Private or Domain, for the rules' profile filter. |
Click Simulate to see the Result:
| Result | Description |
|---|---|
| Action: | Allowed, Blocked, Ask to Connect, or Ignored: other firewalls decide (the Ignore mode). |
| Reason: | The step of How Fort decides, as in Connections. |
| Rule:, Zone: | The deciding Rule or Zone, if any. |
| Program: | The program entry found for the path, or Not found: then the Filter Mode decides. |
The simulation uses the current options, programs, Rules, active Groups and the last downloaded Zones.
Note
- The program is checked by its path only: the settings propagated from a parent process (see Rules inheritance) aren't taken into account.
- Nothing is logged, and no program is added to the list.
The tray Traffic Graph item toggles a small live graph of download and upload speed. Appearance settings are in Options ▸ Traffic Graph.
| Mouse | Effect |
|---|---|
| Left-drag | Move |
| Right-drag | Resize |
| Double-click | Maximize |
| Right-click | Tray menu |
Open the window from the tray: Options ▸ Options. Every default value in this guide is listed here.
The buttons at the bottom:
| Button | Choices |
|---|---|
| Backup | Export, Import, Import new programs (see below). |
| Default | Reset to default all options, Reset to default current tab. |
| — | OK, Apply (Ctrl+S), Cancel. |
Warning
Backup choices:
- Export saves the configuration, settings and statistics to a folder.
- Import replaces all options and programs with the backup. The windows are restored by the backup's settings too.
-
Import new programs only adds programs whose path is not yet in the list, and leaves existing entries unchanged.
- The added programs keep basic flags, such as the Allow/Block action, and are marked as alerts.
- They lose their Groups, Zones, Rule, Speed Limits and custom icon. Review and reassign those.
| Option | Default | Notes |
|---|---|---|
| Filter Enabled | On | The master switch. |
| Block Traffic: | No Block | The global block modes. |
| Filter Mode: | Auto-Learn | See Filter modes. |
| Block traffic for disabled Groups | On | See Groups. |
| Speed Limiter Enabled | On | See Speed Limits. |
| Filter Off seconds: | Disabled | Turns filtering back on this long after you turn it off. |
| Auto-learn seconds: | 1 minute | The length of Auto-Learn. |
| Block traffic when Fort Firewall is not running | Off | See Security. |
| Stealth mode (Prevent port scanning) | Off | See Security. |
| Disable Service controls | Off | See Security. |
| Disable command line management | Off | See Security. |
| Check password on Uninstall | Off | See Security. |
| Password: | none | See Security. |
| Collect New Programs | On | Adds unknown programs in Block and Allow modes. |
| Remove alerted programs on Auto-Learn Off | Off | Deletes still-alerted programs when Auto-Learn ends. |
| Purge Obsolete only on mounted drives | Off | Skips unmounted drives when purging. |
| Keep current version | Off | See Updating. |
| Auto-download new version | Off | See Updating. |
| Auto-install after download | Off | See Updating. |
| Log debug messages | Off | For diagnostics. |
| Show log messages in console | Off | For diagnostics. |
| Trace Driver Events | Off | For diagnostics. |
| Section | Option | Default |
|---|---|---|
| Global | Language: | system |
| Theme: | System | |
| Style: | Fusion | |
| Use System Regional Settings | On | |
| Exclude from screen capture | Off | |
| Hot Keys | Enabled | Off |
| Global | On | |
| Filter Enabled | Ctrl+Alt+Shift+F | |
| Group Modifier | Ctrl+Alt+Shift (+ F1–F12 for the first 12 Groups in the tray menu) | |
| Rule Modifier | none | |
| My Fort | Auto-Show Window | On |
| Auto-Show Menu | Off | |
| Show Splash screen on startup | On | |
| Show window icons as in tray icon | Off | |
| Programs | Use System Notifications for New Programs | On |
| Auto-Show Alert Window for New Programs | On (see below) | |
| Alert Window is Always on top | On | |
| Alert Window is auto-active | Off | |
| Auto-Clear alerts on window close | Off | |
| Sound Alert | On | |
| Snooze Alerts | Off | |
| Tray | Show Icon, Show Alert Icon, Animate Alert Icon | On |
| Maximum count of Groups in menu: | 16 | |
| Event: / Action: | The click actions | |
| Switch Window visibility | Off | |
| Action Confirmations | Operations from Tray Menu | Off |
| Quit | On |
The button next to Auto-Show Alert Window for New Programs picks the filter modes that alert:
| Mode | Default |
|---|---|
| Auto-Learn | Off |
| Block, if not allowed | On |
| Allow, if not blocked | On |
| Option | Default | Notes |
|---|---|---|
| Filter Local Addresses (127.0.0.0/8, 255.255.255.255) | Off | Filters loopback and broadcast (see the note below). |
| Filter Local Network | Off | While off, LAN traffic is allowed, unlogged and not speed-limited. |
| Local Network Addresses: | built-in list | Addresses treated as LAN. Zones can be added. |
| Block Addresses: | empty | Blocked for all programs. Zones can be added. |
Note
- With the default LAN list, per-program filtering of loopback and broadcast also requires Filter Local Network. The Block Traffic modes have specific exceptions for these addresses; see note 1 in How Fort decides.
- Local Network Addresses: contains private, loopback, link-local, CGNAT, multicast/broadcast and IPv6 special-purpose ranges. Right-click ▸ Add Local Networks appends the list.
- Block Addresses: are not applied to LAN addresses while Filter Local Network is off.
- The built-in LAN list includes Teredo (
2001::/32), 6to4 (2002::/16) and NAT64 (64:ff9b::/96), which can reach the Internet. Remove them if you filter IPv6. - The 3.15.0 ChangeLog announced that these fields will move to Global Rules. Prefer a Global Rule for blocking addresses.
| Option | Default |
|---|---|
| Collect Traffic Statistics | On |
| Collect Traffic, when Filter Disabled | On |
| Active time period: | Off |
| Month starts on: | 1 |
| Keep data for 'Hourly': | 3 months |
| Keep data for 'Daily': | 1 year |
| Keep data for 'Monthly': | 3 years |
| Day's Quota: / Month's Quota: | Disabled |
| Block Internet traffic when quota exceeds | Off |
| Collect allowed connections | Off |
| Collect blocked connections | On |
| Alerted only | Off |
| Clear connections on exit (reduce disk writes) | On |
| Keep count for connections: | 10K |
How these interact:
- Active time period: limits when traffic is stored and when quotas count. The live graph keeps running outside the period.
- Quotas count only downloaded traffic that Fort tracks. When a quota is exceeded, Fort shows a Quota Alert.
- If Block Internet traffic when quota exceeds is on, Fort also turns on Internet blocking. You must undo it yourself.
- Turning off Collect Traffic Statistics stops the history but not the quota checks. To stop those, set the quota to Disabled.
| Option | Default |
|---|---|
| Always on top | On |
| Hide on close, Frameless, Click through, Hide on hover, Show speed | Off |
| Opacity: / Hover opacity: | 90 / 95 |
| Tick label size: | 9 |
| Max seconds: | 500 |
| Fixed speed: | Auto-scale |
| Units: | b/s |
The tab also sets Colors (Light | Dark).
| Task | Default |
|---|---|
| Fort Firewall Update Checker | Off, daily |
| Zones Downloader | Off, daily |
| Purge Obsolete Programs | Off, daily |
To configure a task:
- Tick a task to enable it, and choose its interval: from Each 5 minutes to Monthly, or Custom in minutes. The list shows it as e.g.
1d 6h 30m. - The Options button sets Run On Startup and retries.
- Run runs the selected task now; Abort stops it.
Set it in Options ▸ Options ▸ Password:.
It protects:
- the Programs, Options, Rules, Zones, Groups, Speed Limits, Time Periods, Services, Traffic, Connections and Filter Simulator windows;
- the alert window;
- command-line commands, except
home show,graphandconf update-driver.
Unlock till: has these choices:
| Choice | How long Fort stays unlocked |
|---|---|
| Window closed | Until all open protected windows are closed, not just the first one. |
| Session lockout | Until Windows is locked. Already-open protected windows stay usable, and another protected window can be opened from them without the password. |
| Program exit | Until Fort exits. |
| 5 minutes, 10 minutes, 30 minutes, 1 hour | For this time. |
To force a new password prompt, close the protected windows and click Lock in My Fort. With a choice other than Window closed, Options ▸ Options also shows a Lock the password (unlocked till "…") button below Password:.
| Option | Effect |
|---|---|
| Block traffic when Fort Firewall is not running | Adds boot-time and persistent block filters. |
| Stealth mode (Prevent port scanning) | Silently drops inbound packets that Windows would reject. |
| Disable Service controls | The service refuses Stop and Pause. |
| Disable command line management |
-c commands fail with "Command line disabled", except home show and conf update-driver. This also disables Explorer integration. |
| Check password on Uninstall | The installer and uninstaller ask for the password. Silent auto-updates skip this. |
Warning
When Block traffic when Fort Firewall is not running is off (the default), Fort filters nothing while it is stopped.
- Allow only programs you recognize, and check the path first.
- Remember that LAN traffic is unfiltered by default.
- Remember that Ignore mode hands unknown programs to other firewalls.
- Treat Fort as one layer of defense, alongside updates, backups and endpoint protection.
FortFirewall.exe -c <command> controls the running Fort instance.
| Command | Description |
|---|---|
home show |
Shows My Fort. |
filter on|off|report |
Filtering on/off. |
filter-mode learn|ask|block|allow|ignore|report |
The Filter Mode (ask has no effect). |
block no|inet|lan|inet-lan|all|report |
Block Traffic. |
prog allow|block|kill|add|del|report <path> |
A program. add opens Edit Program, without the Programs window. |
group on|off|report <group-id> |
A Group, by the number shown in the Groups window. |
rule on|off|report <rule-name> |
Enables or disables a Rule, by its exact name (case-sensitive). |
rule get-text|set-text <rule-name> <file> |
Saves the Rule's text to a file, or replaces it by the file's text. The text is checked first. |
zone update |
Runs the Zones Downloader. |
graph show|hide|switch |
Shows, hides or toggles the Traffic Graph. |
backup export|import <folder> |
Configuration, settings and statistics. |
conf update-driver |
Resends the configuration to the driver. |
A relative <file> of rule get-text|set-text is resolved against the command's current folder. Give backup a full <folder> path.
| Code | Meaning |
|---|---|
| 0 | Success. |
| 70 + n | A report result: n is the value's position in the command's list, e.g. allow = 70, block = 71, kill = 72; for rule report, on = 70, off = 71. |
| 99 |
prog report: the program is not in the list. group: no Group with that ID. rule: no Rule with that name, or several. |
| 2 | Any other failure, e.g. prog del for a program that is not in the list, or an invalid rule text for rule set-text. |
| Switch | Effect |
|---|---|
--lang <code> |
The default language, used at first start. |
-p <folder> |
The main profile folder. See Where Fort stores its data. |
--no-splash |
No splash screen. |
-i service|auto-run|explorer|portable|boot-filter |
Install a component. Must be the first argument. In portable mode, -i service also installs the driver. |
-u |
Remove the service, Explorer integration, auto-run and boot filter, but not the driver. Must be the first argument. |
-u service |
Remove only the service (in portable mode, also the driver). |
-u explorer |
Remove only the Explorer integration. |
Each task ends with a check.
Tip
To test a new program, copy curl.exe to C:\Temp\curl-test.exe. The copy is unknown to Fort only if:
- no exact, wildcard or prefix entry covers that path;
- you start it from a parent that does not propagate its rules (e.g. a plain Command Prompt).
- In Programs, select the program and click Allow or Block.
- Check: retry the program. A block appears in Statistics ▸ Connections with Program's action.
- In Programs, use Filters ▸ Alerts, or Edit ▸ Review Alerts.
- Allow or block each program; this clears its mark.
- In Programs, use Edit ▸ Timer ▸ 1 hour.
- Check: the Scheduled column shows an icon.
- In Programs, use Edit ▸ Add Wildcard and enter
C:\Games\**. - Choose the action and click OK.
- Add the address to Options ▸ IP Addresses ▸ Block Addresses: and click Apply or OK.
- Check: connect to the address again; the reason shown is Internet address.
- In Speed Limits, choose Edit ▸ Add.
- Enter a Name:, select Download, set Speed:, leave Enabled ticked, and click OK.
- In the program's Network Filters tab, tick Download:, choose the limit, and click OK.
- Check: watch the Traffic Graph.
- In Time Periods, choose Edit ▸ Add and enter a Name:. A new period already has one interval, 09:00–18:00 on all days.
- Edit that interval; don't add a second one.
- Set both times to
00:00, which means a whole day. - Select only Saturday and Sunday, then click OK.
- In Groups, choose Edit ▸ Add and enter a Name:. Tick Exclusive and Time Period:, choose the period, and click OK.
- In each game's General ▸ Groups, tick the Group and click OK.
- Make sure the game is in no other Exclusive Group that is active outside the weekend; any active Exclusive Group enables it.
- Keep Block traffic for disabled Groups on.
- Check: a game connects during the period and is blocked (reason App. Group) outside it.
Note
The schedule applies only to connections that reach the Group check. LAN traffic and Global Rules applied before App Rules are not affected. See How Fort decides.
- Reproduce the problem.
- Open Statistics ▸ Connections and hover over Reason.
- Fix only the setting from that step of How Fort decides.
- Exception: Old connection is not caused by a setting; see Troubleshooting.
-
Check: right-click the row and choose Filter Simulator. It shows the new decision without a retry.
- A connection that isn't logged, e.g. LAN traffic, can be described there by hand.
Click a problem to expand it.
A new program has no Internet access
Expected in Block, if not allowed mode. Allow it in Programs; look for the yellow triangle.
An allowed program is still blocked
- Check Statistics ▸ Connections ▸ Reason. It usually tells you which step decided.
- Find that step in How Fort decides; its row shows where to fix it.
- To check the fix, use the Filter Simulator.
Old connection is the exception: it is not caused by a setting. The driver could not associate or track the connection. This can happen:
- when an open connection is re-authorized;
- with resource errors on new connections.
Retry with a new connection. If it persists, check Logs and turn on Trace Driver Events.
A program lost access after a zone was disabled
The program's accepted zones still restrict it. Either:
- re-enable the zone;
- update the zone;
- or set it back to partially checked in Network Filters.
Nothing appears in Connections
Possible causes:
- a Block Traffic mode is on (possibly set by a quota);
- the logging switches are off, globally or for the program;
- Alerted only is on;
- the log was cleared at restart.
Unknown programs are not added
Possible causes:
- Ignore mode;
- Collect New Programs is off;
- the traffic is LAN-only, or decided at steps 1–5.
No alert popups
- This is expected in Auto-Learn mode; see Options ▸ Interface ▸ Programs.
- Check whether Snooze Alerts is on.
LAN traffic is not filtered
This is the default. Turn on Filter Local Network, or use Block LAN Traffic.
An environment variable doesn't match
Variables work only in wildcard entries. With the service installed, they resolve as Local System.
Speed Limits have no effect
Check that:
- Speed Limiter Enabled and Filter Enabled are on;
- the limit is enabled, in its period, and its speed is above 0;
- it is assigned to the program;
- the traffic is not LAN traffic.
A program set to Kill Process is still running
This is expected after a wildcard change, or a change to more than 7 programs at once. Close the running instances; new starts are blocked.
A program won't start
Check:
- its Kill Process action;
- Kill child processes on the program that launches it.
Both work even while filtering is off. After changing Kill child processes, restart the parent program.
The installer says "not compatible with HVCI"
Turn off Memory integrity, then restart. See HVCI / Memory integrity.
The driver is not working
- Use My Fort ▸ Driver ▸ Reinstall (needs admin rights).
- Without the service, run Fort as Administrator.
| Item | Maximum |
|---|---|
| Groups | 32 |
| Speed Limits | 32 |
| Zones | 32 |
| Time Periods | 64 |
| Rules (total) | 1024 |
| Rules per Global category | 64 |
| Preset rules per rule | 32 |
| Preset nesting depth | 8 |
{ } nesting in rule text |
7 |
| Groups in the tray menu | 16 |
| Rules in the tray menu | 8 |
| Topic | Link |
|---|---|
| Rule syntax and examples | Rules wiki |
| HVCI details | HVCI wiki |
| Frequently asked questions | FAQ |
| Downloads | Releases |
| Bug reports | Issues |
| Questions and ideas | Discussions |