Firewall that can route application and not per ip.

Necuno

Court Jester
Joined
Sep 27, 2005
Messages
58,566
Reaction score
3,437
I'm looking for a firewall were I can setup rules which would allow me to set for example firefox to use network adapter A instead of B or gateway A instead of B. I know earlier firewalls could do this, but that was a long time ago and mostly these days it seems the are just bloat over what is actually required. I really am not looking for zomg-all-in one thing, but rather one which can do as I described (application route rules).

This can obviously be achieved with using cmd line and routing tables, but I would however like to do it via a gui on application basis and not per ip. Unless of course there is a software front to do this.

:windows 7
 
Last edited:
I'm looking for a firewall were I can setup rules which would allow me to set for example firefox to use network adapter A instead of B or gateway A instead of B. I know earlier firewalls could do this, but that was a long time ago and mostly these days it seems the are just bloat over what is actually required. I really am not looking for zomg-all-in one thing, but rather one which can do as I described (application route rules).

This can obviously be achieved with using cmd line and routing tables, but I would however like to do it via a gui on application basis and not per ip. Unless of course there is a software front to do this.

:windows 7

Well firstly I'm sure you mean router (firewall is usually a feature of routing software).
On Windows, you are limited. The one piece of software I recall having loads of features on Windows was Wingate. Long time since I've used it.
 
If you want to route by application you're going to have to use a software firewall that runs on the actual machine that runs whatever app you want to route. You're not going to be able to do this on a separate router because the router will have no way of knowing what application initiated the traffic it must route. All the router will see is TCP/IP traffic, but it has no way of knowing what app sent that traffic to it. For example, if an independent router sees traffic coming from a machine destined for port 80, it can't tell whether that traffic was sent from Chrome or Firefox or whatever browser.
 
If you want to route by application you're going to have to use a software firewall that runs on the actual machine that runs whatever app you want to route. You're not going to be able to do this on a separate router because the router will have no way of knowing what application initiated the traffic it must route. All the router will see is TCP/IP traffic, but it has no way of knowing what app sent that traffic to it. For example, if an independent router sees traffic coming from a machine destined for port 80, it can't tell whether that traffic was sent from Chrome or Firefox or whatever browser.
Wingate has client software that handles that information and sends it to the router so you could probably use it for this very thing.
 
What is the application you want to bind to a network adapter?

To give an example:

I would like to vpn to work and still being able to download using steam. Now I would like to set steam to a gateway and interface, this I've done to just route one ip to an interface that is not the vpn client. However what If the application uses multiple unkown IPs like for example browsing.

The actual use would be dialing secure vpn and just using that for browsing while all other traffic is filtered to another interface so that it's not " passed over " the vpn.

I know this is quite easy with setting up a SSH Socks Proxy, but would have wanted to rather use a vpn instead of the SSH Socks.

This is why I thought that one could do per application routing to an interface instead of per ip as with routing tables. As I've said I was quite able to do this years back by just using a certain filewall which I just can't remember which one it was.
 
To give an example:

I would like to vpn to work and still being able to download using steam. Now I would like to set steam to a gateway and interface, this I've done to just route one ip to an interface that is not the vpn client. However what If the application uses multiple unkown IPs like for example browsing.

The actual use would be dialing secure vpn and just using that for browsing while all other traffic is filtered to another interface so that it's not " passed over " the vpn.

I know this is quite easy with setting up a SSH Socks Proxy, but would have wanted to rather use a vpn instead of the SSH Socks.

This is why I thought that one could do per application routing to an interface instead of per ip as with routing tables. As I've said I was quite able to do this years back by just using a certain filewall which I just can't remember which one it was.
here you go
http://www.raymond.cc/blog/archives...to-specific-network-adapter-with-forcebindip/
 
Top
Sign up to the MyBroadband newsletter
X