Mac firewall comparison
Outbound vs LuLu
Pick LuLu if you want a free, open-source firewall with alerts, endpoint rules, profiles and block lists, available now. Pick Outbound if you need a command line, an MDM rule feed and exportable audit logs, and can accept closed source and a one-time price with no trial.
Updated
Published by Outbound, one of the products compared. This is a feature and workflow comparison, not an independent ranking or performance benchmark.
At a glance
| Criterion | Outbound | LuLu |
|---|---|---|
| Price and licence | Closed source; personal $39 USD one time ($29 for the first 50 licences), family $59 USD for 5 Macs | Free and open source (GPL-3.0) |
| Per-app rules | Signed app by team and signing ID, or an exact path | Rules per process; signed programs identified by code signing identifier, so rules survive moves and updates |
| Host, domain and port rules | Host, domain, IP, CIDR, local network, plus ports and protocol | Endpoint and port rules; rule scope can be the remote endpoint, and addresses or domains can be regular expressions |
| Temporary decisions | Six fixed lifetimes: Once, Until Quit, Until Logout, Until Restart, For 1 Hour, Forever | Timed and process-lifetime rules |
| Alert behaviour | Ask mode alert names the app, its developer from the signing certificate, port and protocol, and quotes an app’s Internet Access Policy when one is shipped (apps signed by a developer team or Apple). The rule can cover only this port, any port, or any port and protocol. Unanswered: allowed after 8 s (UDP) or 60 s (TCP) by default; TCP wait adjustable from 15 to 120 s, or block instead | Alert for outgoing connections no rule covers, with code signing, process hierarchy and VirusTotal buttons. By default, Apple and already-installed programs are allowed. What happens to an unanswered alert: Not stated by the vendor |
| Silent modes | Learn allows unmatched connections and adds them to Review; Strict blocks them. Your rules apply in every mode | Passive mode runs without alerts and allows or denies new connections as you choose; Block mode blocks all traffic routed through LuLu except destinations on your allow list |
| Network monitor | Network Monitor grouped by app, with Sent, Received and Last Seen columns, exact bytes per destination once a connection closes, a traffic chart where you can select a time window, search scoped by app, host, port, protocol, country, direction or rule, and a map of server locations | Objective-See’s Netiquette monitor, packaged into LuLu |
| Blocklists | Hosts, domain or CIDR lists over HTTPS, up to 200,000 entries per list | Allow and block lists of hosts or IP addresses, local or from a remote URL; remote lists reload once a day |
| Profiles | Profiles, switched with outboundctl; no SSID-based switching in v1 | Profiles since v4.0, each with its own rules and settings |
| Command line and rule export | outboundctl export/import of user rules, plus status, profiles and blocklists | Export/import in the Rules menu. Firewall command line: Not stated by the vendor. The bundled Netiquette monitor has a command line and JSON export |
| Managed deployment | Sample MDM profiles, managed preferences, HTTPS rule feed (up to 50,000 rules, optional SHA-256 pin), JSON Lines audit export | Not stated by the vendor |
| macOS and release status | macOS 14 or later, Apple silicon or Intel. Version 1.0, public download | v4.5.1, public download; macOS 10.15 or later, and at least macOS 15.3 on Sequoia |
Competitor details: LuLu official product documentation, retrieved October 4, 2026.
Price and licence
Free, as listed by Objective-See. No purchase price is required for LuLu, and its source is on GitHub under the GPL-3.0 licence. Seller’s page.
Outbound personal is $39 USD one time ($29 for the first 50 licences) with all 1.x and 2.x updates. Family is $59 USD for 5 Macs. Personal covers 2 Macs; there is no trial. Outbound is closed source.
Where LuLu is the better choice
LuLu costs nothing, its source is open under GPL-3.0, and you can install it today. It runs on macOS 10.15 or later, so it covers older Macs that Outbound’s macOS 14 requirement does not. It already has endpoint and port rules, timed rules, a Passive mode, profiles, allow and block lists, and a bundled network monitor.
Is a free firewall like LuLu enough?
For many personal Macs, yes. LuLu alerts on new outgoing connections and lets you scope a rule to one destination and port, so the old idea that free means process-only no longer holds. Look further if you need things the vendor does not state for LuLu, such as a firewall command line, MDM rule delivery or audit logs you can send to a collector. Each has its own hostname limits: LuLu says browsers such as Chrome only support IP address blocking in its lists, and Outbound can only show and match an address when an app connects without a host name.
Correcting an older comparison
It is no longer accurate to describe the current LuLu documentation as process-level only. Evaluate the current product before switching. Older forum requests can describe a real historical problem without describing the present release.
Why consider Outbound?
Evaluate Outbound if the combination of an HTTPS managed feed, optional SHA-256 pinning, JSON Lines audit export and command line control fits your setup. Its rule store keeps the previous version as a backup, and its Network Monitor groups connections by app, with exact bytes per destination for closed connections, a traffic chart with time selection, scoped search and a map. Managed preferences can lock rule editing for users.
LuLu versus Little Snitch
LuLu is free, while Little Snitch is sold commercially. Little Snitch offers a traffic map and DNS encryption. Review those needs independently from Outbound’s managed-deployment features.
Switching is a manual task
Export your current rules from LuLu’s Rules menu for reference; you can choose to export only the rules you created. Then re-create a small set in the destination product and test it. Outbound cannot import LuLu’s rule format, and release compatibility results are not published yet.
What you give up
Outbound is not free and is not open source. If inspectable source and a zero-cost licence are requirements, LuLu is the more natural starting point. We do not claim that paid or closed-source software is inherently safer.
Comparing the other two directly? Read Little Snitch vs LuLu.
Little Snitch feature source: Objective Development’s product page.
Before you switch
- Export your existing policy for reference.
- Choose a small set of essential app connections and re-create them in the new product.
- Test on your macOS build, with your VPN and required management software.
- Keep the old policy and removal instructions available until you have tested the new setup.