Mac firewall comparison

Outbound vs LuLu

Pick LuLu if you want a free, open-source firewall with alerts, endpoint rules, profiles and block lists, available now. Pick Outbound if you need a command line, an MDM rule feed and exportable audit logs, and can accept closed source and a one-time price with no trial.

Updated

Published by Outbound, one of the products compared. This is a feature and workflow comparison, not an independent ranking or performance benchmark.

At a glance

CriterionOutboundLuLu
Price and licenceClosed source; personal $39 USD one time ($29 for the first 50 licences), family $59 USD for 5 MacsFree and open source (GPL-3.0)
Per-app rulesSigned app by team and signing ID, or an exact pathRules per process; signed programs identified by code signing identifier, so rules survive moves and updates
Host, domain and port rulesHost, domain, IP, CIDR, local network, plus ports and protocolEndpoint and port rules; rule scope can be the remote endpoint, and addresses or domains can be regular expressions
Temporary decisionsSix fixed lifetimes: Once, Until Quit, Until Logout, Until Restart, For 1 Hour, ForeverTimed and process-lifetime rules
Alert behaviourAsk mode alert names the app, its developer from the signing certificate, port and protocol, and quotes an app’s Internet Access Policy when one is shipped (apps signed by a developer team or Apple). The rule can cover only this port, any port, or any port and protocol. Unanswered: allowed after 8 s (UDP) or 60 s (TCP) by default; TCP wait adjustable from 15 to 120 s, or block insteadAlert for outgoing connections no rule covers, with code signing, process hierarchy and VirusTotal buttons. By default, Apple and already-installed programs are allowed. What happens to an unanswered alert: Not stated by the vendor
Silent modesLearn allows unmatched connections and adds them to Review; Strict blocks them. Your rules apply in every modePassive mode runs without alerts and allows or denies new connections as you choose; Block mode blocks all traffic routed through LuLu except destinations on your allow list
Network monitorNetwork Monitor grouped by app, with Sent, Received and Last Seen columns, exact bytes per destination once a connection closes, a traffic chart where you can select a time window, search scoped by app, host, port, protocol, country, direction or rule, and a map of server locationsObjective-See’s Netiquette monitor, packaged into LuLu
BlocklistsHosts, domain or CIDR lists over HTTPS, up to 200,000 entries per listAllow and block lists of hosts or IP addresses, local or from a remote URL; remote lists reload once a day
ProfilesProfiles, switched with outboundctl; no SSID-based switching in v1Profiles since v4.0, each with its own rules and settings
Command line and rule exportoutboundctl export/import of user rules, plus status, profiles and blocklistsExport/import in the Rules menu. Firewall command line: Not stated by the vendor. The bundled Netiquette monitor has a command line and JSON export
Managed deploymentSample MDM profiles, managed preferences, HTTPS rule feed (up to 50,000 rules, optional SHA-256 pin), JSON Lines audit exportNot stated by the vendor
macOS and release statusmacOS 14 or later, Apple silicon or Intel. Version 1.0, public downloadv4.5.1, public download; macOS 10.15 or later, and at least macOS 15.3 on Sequoia

Competitor details: LuLu official product documentation, retrieved October 4, 2026.

Price and licence

Free, as listed by Objective-See. No purchase price is required for LuLu, and its source is on GitHub under the GPL-3.0 licence. Seller’s page.

Outbound personal is $39 USD one time ($29 for the first 50 licences) with all 1.x and 2.x updates. Family is $59 USD for 5 Macs. Personal covers 2 Macs; there is no trial. Outbound is closed source.

Where LuLu is the better choice

LuLu costs nothing, its source is open under GPL-3.0, and you can install it today. It runs on macOS 10.15 or later, so it covers older Macs that Outbound’s macOS 14 requirement does not. It already has endpoint and port rules, timed rules, a Passive mode, profiles, allow and block lists, and a bundled network monitor.

Is a free firewall like LuLu enough?

For many personal Macs, yes. LuLu alerts on new outgoing connections and lets you scope a rule to one destination and port, so the old idea that free means process-only no longer holds. Look further if you need things the vendor does not state for LuLu, such as a firewall command line, MDM rule delivery or audit logs you can send to a collector. Each has its own hostname limits: LuLu says browsers such as Chrome only support IP address blocking in its lists, and Outbound can only show and match an address when an app connects without a host name.

Correcting an older comparison

It is no longer accurate to describe the current LuLu documentation as process-level only. Evaluate the current product before switching. Older forum requests can describe a real historical problem without describing the present release.

Why consider Outbound?

Evaluate Outbound if the combination of an HTTPS managed feed, optional SHA-256 pinning, JSON Lines audit export and command line control fits your setup. Its rule store keeps the previous version as a backup, and its Network Monitor groups connections by app, with exact bytes per destination for closed connections, a traffic chart with time selection, scoped search and a map. Managed preferences can lock rule editing for users.

LuLu versus Little Snitch

LuLu is free, while Little Snitch is sold commercially. Little Snitch offers a traffic map and DNS encryption. Review those needs independently from Outbound’s managed-deployment features.

Switching is a manual task

Export your current rules from LuLu’s Rules menu for reference; you can choose to export only the rules you created. Then re-create a small set in the destination product and test it. Outbound cannot import LuLu’s rule format, and release compatibility results are not published yet.

What you give up

Outbound is not free and is not open source. If inspectable source and a zero-cost licence are requirements, LuLu is the more natural starting point. We do not claim that paid or closed-source software is inherently safer.

Comparing the other two directly? Read Little Snitch vs LuLu.

Little Snitch feature source: Objective Development’s product page.

Before you switch

  1. Export your existing policy for reference.
  2. Choose a small set of essential app connections and re-create them in the new product.
  3. Test on your macOS build, with your VPN and required management software.
  4. Keep the old policy and removal instructions available until you have tested the new setup.