in addition to the features described in my previous post here Suggestion - Option to disable Hardware Resources - #3 by Kels I would suggest to add the support for IP-based blocklists and ads / tracker domains blocklists, similar to Little Snitch Network Monitor and Firewall (one-time purchase software for macOS and Linux only).
Summarizing, according to my personal order of priority:
Domains allow / block per-app and possibly globally.
Support for IP-based blocklists and ads / tracker domains blocklists.
Use of wildcards characters in executables folders paths.
On / Off option to auto allow digitally signed executables.
I would like to strongly advocate for the addition of several crucial network-filtering features that I believe are essential for the software’s competitiveness and overall security utility.
I have ranked these features by personal priority—and I urge you to view the first two as non-negotiable for power users:
Per-app and global domain allow/block rules.
Users must have granular control to permit or deny domains on a per-application basis, alongside system-wide overrides.
Full support for IP-based blocklists and ad/tracker domain blocklists.
This is vital for modern privacy and security. Importing community-maintained lists (e.g., EasyList, StevenBlack, or custom IP sets) is a standard expectation for any robust network monitoring tool.
Support for wildcard characters in executable folder paths.
An on/off toggle to auto-allow digitally signed executables.
While convenient, this must remain an opt-in feature, as security-conscious users often prefer to scrutinize even signed binaries.
Why this is critical: Without these additions, the software risks being perceived as a basic connection viewer rather than a proactive firewall. Implementing these features would not only satisfy advanced users but also directly compete with established paid alternatives.
I sincerely hope you will treat this request with the seriousness it deserves and consider adding these capabilities in the next major release.