{"id":484698,"date":"2026-06-19T02:33:13","date_gmt":"2026-06-19T02:33:13","guid":{"rendered":"https:\/\/www.newsbeep.com\/nz\/484698\/"},"modified":"2026-06-19T02:33:13","modified_gmt":"2026-06-19T02:33:13","slug":"i-tried-3-free-apps-to-see-what-was-using-my-internet-connection-but-only-one-let-me-take-control","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/nz\/484698\/","title":{"rendered":"I tried 3 free apps to see what was using my internet connection, but only one let me take control"},"content":{"rendered":"<p>I started looking at network-monitoring tools because my home network has become more crowded than I realized. This isn&#8217;t just one desktop plugged into a router anymore. I have multiple <a href=\"https:\/\/www.howtogeek.com\/your-roku-is-tracking-more-than-you-think-heres-how-to-limit-it\/\" target=\"_blank\" rel=\"nofollow noopener\">Roku TVs<\/a>, an Xbox, an Alexa speaker, <a href=\"https:\/\/www.howtogeek.com\/your-fire-tv-collects-more-than-just-watch-history-heres-how-to-stop-it\/\" target=\"_blank\" rel=\"nofollow noopener\">a Fire TV Stick<\/a>, several iPads and phones, and around four PCs online at any given time. I also have a Mac I use for music production that can download updates and content in the background. Add in music gear like my Kemper Player, and there are a lot of things in the house that may have a reason to be using my internet connection.<\/p>\n<p>That doesn&#8217;t automatically mean anything shady is happening. Most of it is probably normal: updates, sync services, app checks, streaming devices refreshing content, and background services doing what they were designed to do. But that&#8217;s also why I wanted a better look. When <a href=\"https:\/\/www.howtogeek.com\/stop-trusting-your-every-device-wi-fi-segmentation-can-save-your-network\/\" target=\"_blank\" rel=\"nofollow noopener\">so many devices and apps are connected<\/a>, &#8220;something is using the internet&#8221; is not a useful answer.<\/p>\n<p>That&#8217;s what sent me looking for a network-monitoring tool in the first place, but I didn&#8217;t just want another dashboard full of activity graphs. I wanted something I could actually understand without becoming a network engineer, and I wanted more than a passive list of connections. If an app or device was talking to the internet, I wanted to know what was making the connection, where it was going, and whether I had any control over it.<\/p>\n<p>                        Wireshark showed me everything, but it was too much<\/p>\n<p>            Powerful packet capture is not the same as an easy answer<\/p>\n<p><a href=\"https:\/\/www.wireshark.org\/download.html\" target=\"_blank\" rel=\"nofollow noopener\">Wireshark<\/a> was the first tool I tried because it has a great reputation, and it did exactly what I expected it to do. It showed me network traffic in incredible detail. I could see packets, protocols, addresses, ports, timing, and more low-level information than I could reasonably process. That is the strength of Wireshark, but it was also the problem for me.<\/p>\n<p>I wasn&#8217;t trying to become a network analyst. I just wanted to understand what was using my internet connection and whether anything deserved a closer look. Wireshark gave me all of the raw data, but turning that data into a simple answer took more effort than I wanted to spend. If you already know how to read packet captures, it is an excellent tool. But if you are looking for an easy, app-friendly way to see what is talking to the internet, you may end up in the same boat I did: impressed by how much Wireshark can show you, but overwhelmed by how much work it takes to make sense of it.<\/p>\n<p>\t\t<img class=\"vq-logo\" src=\"https:\/\/static0.howtogeekimages.com\/assets\/images\/htg-logo-full-colored-dark.svg?v=3.6\" alt=\"How-To Geek\" height=\"22\" width=\"130\" loading=\"lazy\" decoding=\"async\"\/>Quiz<\/p>\n<p>\t\t&#13;<br \/>\n\t\t\t8 Questions \u00b7 Test Your Knowledge<br \/>\n\t\t\t\tNetwork monitoring fundamentals<br \/>Trivia challenge<\/p>\n<p class=\"vq-intro-sub\">From packet sniffers to SNMP traps \u2014 find out how much you really know about&#13;<br \/>\n\t\t\t\t\t\tkeeping networks healthy.<\/p>\n<p>&#13;<br \/>\n\t\t\t\t\t\tProtocolsToolsSecurityConceptsPerformance&#13;\n\t\t\t\t\t<\/p>\n<p>Begin<\/p>\n<p>\t\t\t&#13;<\/p>\n<p>\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p class=\"vq-qtext\">Which protocol is most commonly used by network monitoring tools to collect device&#13;<br \/>\n\t\t\t\t\tstatistics like CPU load, bandwidth usage, and interface status?<\/p>\n<p>\t\t\t&#13;<\/p>\n<p>&#13;<br \/>\n\t\t\t\tAICMPBSNMPCSMTPDDHCP&#13;\n\t\t\t<\/p>\n<p>&#13;<\/p>\n<p>Correct! SNMP (Simple Network Management Protocol) is the backbone of&#13;<br \/>\n\t\t\t\tnetwork monitoring. It allows management systems to poll devices and receive traps \u2014 unsolicited alerts&#13;<br \/>\n\t\t\t\t\u2014 when something goes wrong.<\/p>\n<p>&#13;<\/p>\n<p>Not quite. The correct answer is SNMP (Simple Network Management&#13;<br \/>\n\t\t\t\tProtocol). While ICMP is used for basic ping tests, SNMP is the industry-standard protocol for&#13;<br \/>\n\t\t\t\tcollecting detailed device metrics and receiving event notifications.<\/p>\n<p>&#13;<\/p>\n<p>Continue<\/p>\n<p>&#13;<\/p>\n<p>\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p class=\"vq-qtext\">What does the popular open-source tool Wireshark primarily do?<\/p>\n<p>\t\t\t&#13;<\/p>\n<p>&#13;<br \/>\n\t\t\t\tAMaps network topology automaticallyBMonitors server uptime and sends alertsCCaptures and analyzes network packet data in real timeDScans for open ports across a subnet&#13;\n\t\t\t<\/p>\n<p>&#13;<\/p>\n<p>Correct! Wireshark is a packet analyzer that captures live traffic and&#13;<br \/>\n\t\t\t\tlets you inspect individual frames in detail. It supports hundreds of protocols and is an essential tool&#13;<br \/>\n\t\t\t\tfor troubleshooting and security analysis.<\/p>\n<p>&#13;<\/p>\n<p>Not quite. Wireshark is a packet capture and analysis tool. It lets&#13;<br \/>\n\t\t\t\tnetwork engineers dissect traffic at the frame level, making it invaluable for diagnosing connectivity&#13;<br \/>\n\t\t\t\tissues, spotting malicious traffic, and understanding protocol behavior.<\/p>\n<p>&#13;<\/p>\n<p>Continue<\/p>\n<p>&#13;<\/p>\n<p>\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p class=\"vq-qtext\">In network monitoring, what does the term &#8216;baseline&#8217; refer to?<\/p>\n<p>\t\t\t&#13;<\/p>\n<p>&#13;<br \/>\n\t\t\t\tAThe minimum bandwidth guaranteed by an ISPBA snapshot of normal network behavior used as a reference for detecting anomaliesCThe lowest firmware version supported by a managed switchDThe default VLAN assigned to untagged traffic&#13;\n\t\t\t<\/p>\n<p>&#13;<\/p>\n<p>Correct! Establishing a baseline means recording what &#8216;normal&#8217; looks&#13;<br \/>\n\t\t\t\tlike \u2014 typical traffic volumes, latency ranges, error rates, and more. When metrics deviate&#13;<br \/>\n\t\t\t\tsignificantly from the baseline, it signals a potential problem worth investigating.<\/p>\n<p>&#13;<\/p>\n<p>Not quite. A baseline is a recorded profile of normal network behavior&#13;<br \/>\n\t\t\t\tover time. Without one, it is very difficult to distinguish a genuine performance problem from ordinary&#13;<br \/>\n\t\t\t\tfluctuations in traffic patterns.<\/p>\n<p>&#13;<\/p>\n<p>Continue<\/p>\n<p>&#13;<\/p>\n<p>\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p class=\"vq-qtext\">Which metric measures the delay between a data packet being sent and its arrival at&#13;<br \/>\n\t\t\t\t\tthe destination?<\/p>\n<p>\t\t\t&#13;<\/p>\n<p>&#13;<br \/>\n\t\t\t\tAJitterBThroughputCLatencyDPacket loss&#13;\n\t\t\t<\/p>\n<p>&#13;<\/p>\n<p>Correct! Latency is the end-to-end travel time of a packet, typically&#13;<br \/>\n\t\t\t\tmeasured in milliseconds. High latency is especially problematic for real-time applications like VoIP&#13;<br \/>\n\t\t\t\tand video conferencing, where delays are immediately noticeable.<\/p>\n<p>&#13;<\/p>\n<p>Not quite. The answer is latency. Jitter refers to the variation in&#13;<br \/>\n\t\t\t\tlatency over time, throughput is the actual data transfer rate, and packet loss is the percentage of&#13;<br \/>\n\t\t\t\tpackets that never reach their destination \u2014 all important but distinct metrics.<\/p>\n<p>&#13;<\/p>\n<p>Continue<\/p>\n<p>&#13;<\/p>\n<p>\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p class=\"vq-qtext\">What is the purpose of ICMP in network monitoring?<\/p>\n<p>\t\t\t&#13;<\/p>\n<p>&#13;<br \/>\n\t\t\t\tAEncrypting management traffic between devicesBAssigning IP addresses dynamically to hostsCSending error messages and performing connectivity tests like pingDSynchronizing time across network devices&#13;\n\t\t\t<\/p>\n<p>&#13;<\/p>\n<p>Correct! ICMP (Internet Control Message Protocol) is used for&#13;<br \/>\n\t\t\t\tdiagnostics and error reporting. The familiar &#8216;ping&#8217; command relies on ICMP echo requests and replies to&#13;<br \/>\n\t\t\t\ttest whether a host is reachable and measure round-trip time.<\/p>\n<p>&#13;<\/p>\n<p>Not quite. ICMP handles error reporting and connectivity testing. Time&#13;<br \/>\n\t\t\t\tsynchronization is handled by NTP, IP address assignment is done by DHCP, and management traffic&#13;<br \/>\n\t\t\t\tencryption is typically handled by SSH or TLS \u2014 not ICMP.<\/p>\n<p>&#13;<\/p>\n<p>Continue<\/p>\n<p>&#13;<\/p>\n<p>\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p class=\"vq-qtext\">Which type of monitoring focuses specifically on detecting unusual or malicious&#13;<br \/>\n\t\t\t\t\ttraffic patterns within a network?<\/p>\n<p>\t\t\t&#13;<\/p>\n<p>&#13;<br \/>\n\t\t\t\tABandwidth monitoringBNetwork traffic analysis (NTA)CConfiguration managementDUptime monitoring&#13;\n\t\t\t<\/p>\n<p>&#13;<\/p>\n<p>Correct! Network traffic analysis examines flows and packet data to&#13;<br \/>\n\t\t\t\tidentify anomalies that could indicate intrusions, malware, or data exfiltration. Tools in this category&#13;<br \/>\n\t\t\t\toften use behavioral baselines and machine learning to flag suspicious activity.<\/p>\n<p>&#13;<\/p>\n<p>Not quite. Network traffic analysis (NTA) is the discipline focused on&#13;<br \/>\n\t\t\t\tidentifying malicious or abnormal behavior in traffic patterns. Bandwidth monitoring tracks utilization,&#13;<br \/>\n\t\t\t\tuptime monitoring checks availability, and configuration management audits device settings \u2014 all useful,&#13;<br \/>\n\t\t\t\tbut not security-focused by nature.<\/p>\n<p>&#13;<\/p>\n<p>Continue<\/p>\n<p>&#13;<\/p>\n<p>\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p class=\"vq-qtext\">What does the acronym &#8216;SNMP trap&#8217; describe in a network monitoring context?<\/p>\n<p>\t\t\t&#13;<\/p>\n<p>&#13;<br \/>\n\t\t\t\tAA firewall rule that blocks unauthorized SNMP queriesBAn unsolicited alert sent from a monitored device to a management system when an event occursCA scheduled poll sent by a monitoring server to check device healthDA method of encrypting SNMP community strings&#13;\n\t\t\t<\/p>\n<p>&#13;<\/p>\n<p>Correct! Unlike SNMP polling where the manager asks the device for data,&#13;<br \/>\n\t\t\t\ta trap is pushed by the device itself when a specific condition is met \u2014 such as a link going down or a&#13;<br \/>\n\t\t\t\ttemperature threshold being exceeded. This enables faster alerting without constant polling.<\/p>\n<p>&#13;<\/p>\n<p>Not quite. An SNMP trap is a proactive, unsolicited message sent by a&#13;<br \/>\n\t\t\t\tdevice to notify the monitoring system of an event. This is the opposite of polling, where the&#13;<br \/>\n\t\t\t\tmonitoring server initiates the data request on a schedule.<\/p>\n<p>&#13;<\/p>\n<p>Continue<\/p>\n<p>&#13;<\/p>\n<p>\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p class=\"vq-qtext\">What does &#8216;NetFlow&#8217; technology allow network administrators to do?<\/p>\n<p>\t\t\t&#13;<\/p>\n<p>&#13;<br \/>\n\t\t\t\tARemotely reboot network switches and routersBAutomatically assign VLANs based on device typeCCollect and analyze metadata about IP traffic flows passing through a deviceDPush firmware updates to managed network devices&#13;\n\t\t\t<\/p>\n<p>&#13;<\/p>\n<p>Correct! Originally developed by Cisco, NetFlow collects metadata about&#13;<br \/>\n\t\t\t\ttraffic flows \u2014 including source, destination, port numbers, and byte counts \u2014 without capturing the&#13;<br \/>\n\t\t\t\tfull packet payload. It gives administrators visibility into who is talking to whom and how much&#13;<br \/>\n\t\t\t\tbandwidth is being consumed.<\/p>\n<p>&#13;<\/p>\n<p>Not quite. NetFlow is a traffic flow telemetry protocol that records&#13;<br \/>\n\t\t\t\tmetadata about IP conversations traversing a router or switch. It is widely used for bandwidth analysis,&#13;<br \/>\n\t\t\t\tcapacity planning, and detecting unusual traffic patterns without the overhead of full packet capture.&#13;\n\t\t\t<\/p>\n<p>&#13;<\/p>\n<p>See My Score<\/p>\n<p>&#13;<\/p>\n<p>\t\t&#13;<br \/>\n\t\t\tChallenge Complete<br \/>\n\t\t\t\tYour Score<\/p>\n<p>\/ 8<\/p>\n<p class=\"vq-result-msg\">Thanks for playing!<\/p>\n<p>Try Again&#13;\n\t\t\t\t<\/p>\n<p>\t\t\t&#13;<\/p>\n<p>The other issue was control. Wireshark showed me what was happening, but it didn&#8217;t give me a simple way to do anything about it. That&#8217;s not a knock against Wireshark. It&#8217;s just not what the tool is built for. I wanted more than a window into my network traffic. I wanted something that could help me decide what should be allowed to keep talking to the internet.<\/p>\n<p>                        GlassWire made the activity much easier to understand<\/p>\n<p>            A cleaner view still wasn&#8217;t the same as simple control<\/p>\n<p><a href=\"https:\/\/www.anrdoezrs.net\/links\/3607085\/type\/dlg\/sid\/UUhtgUeUpU2025300\/https:\/\/www.glasswire.com\/\" class=\"norewrite noskim\" rel=\"sponsored nofollow noopener\" target=\"_blank\">GlassWire<\/a> was a much better fit for what I was trying to do at first. Instead of throwing me into a wall of packet data, it gave me a visual timeline that made the activity easier to grasp. I could see when my connection got busy, which apps were involved, and how much data they were using. The app-based breakdown was especially helpful because it moved the question from &#8220;what are all these packets?&#8221; to &#8220;which program is actually doing this?&#8221;<\/p>\n<p>                                                                                                                            <a href=\"https:\/\/www.howtogeek.com\/423709\/how-to-see-all-devices-on-your-network-with-nmap-on-linux\/\" rel=\"nofollow noopener\" target=\"_blank\"><br \/>\n                        <img width=\"440\" height=\"248\" loading=\"lazy\" decoding=\"async\" alt=\"Ping running in a Linux terminal. \" data-img-url=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2026\/06\/52848912564_6cae6ce5f4_o.jpg\" src=\"https:\/\/www.newsbeep.com\/nz\/wp-content\/uploads\/2026\/06\/52848912564_6cae6ce5f4_o.jpg\"\/><\/p>\n<p>                    <\/a><\/p>\n<p>                    Related<\/p>\n<p>\t\t<a href=\"https:\/\/www.howtogeek.com\/423709\/how-to-see-all-devices-on-your-network-with-nmap-on-linux\/\" title=\"How to See All Devices on Your Network With nmap on Linux\" target=\"_blank\" rel=\"nofollow noopener\"><br \/>\n\t\t\tHow to See All Devices on Your Network With nmap on Linux<br \/>\n\t\t<\/a><\/p>\n<p class=\"display-card-excerpt\">It isn&#8217;t as intuitive as a user interface, but it is more powerful. <\/p>\n<p>That was a big improvement over Wireshark, but it still wasn&#8217;t quite what I was looking for. <a href=\"https:\/\/www.howtogeek.com\/premium-windows-apps-i-dont-regret-paying-for\/\" target=\"_blank\" rel=\"nofollow noopener\">GlassWire<\/a> does have blocking abilities, so this isn&#8217;t a case where it only shows you traffic and stops there. For me, though, it still felt more like a monitoring tool first. I wanted something where control felt more central. I wanted a tool that made it simple to decide which apps should be allowed to keep talking to the internet and which ones needed a closer look.<\/p>\n<p>                        Portmaster didn&#8217;t just show connections, it let me control them<\/p>\n<p>            The cool part was getting from &#8220;what is this?&#8221; to &#8220;should I allow it?&#8221;<\/p>\n<p><a href=\"https:\/\/safing.io\/download\/\" target=\"_blank\" rel=\"nofollow noopener\">Portmaster<\/a> was the tool that felt closest to what I was looking for. It still showed me which apps were reaching out to the internet, but the difference was what I could do next. I could look at an individual app, see the destinations it was connecting to, and start making decisions instead of just staring at activity. That app-based approach made the whole process feel more practical. I wasn&#8217;t just asking, &#8220;what is this connection?&#8221; I was asking, &#8220;does this app need to be allowed to make it?&#8221;<\/p>\n<p>The per-app rules are <a href=\"https:\/\/www.howtogeek.com\/how-i-block-specific-apps-from-internet-access-with-this-free-open-source-tool\/\" target=\"_blank\" rel=\"nofollow noopener\">what made Portmaster stand out for me<\/a>. Instead of treating network activity as one big stream of traffic, it let me think about it app by app. Not every app needs the same level of access. Portmaster made it easier to block or allow connections based on the app and destination, which is the kind of control I was looking for from the start.<\/p>\n<p>That said, Portmaster is not necessarily the easiest option for everyone. It asks you to be more involved, and that can be a good or bad thing depending on what you want. Blocking connections randomly is also a great way to break things, especially with apps that rely on background services, authentication, updates, or cloud sync. For me, that tradeoff was worth it because I wanted control, not just visibility. But if all you want is a simple graph of what used data today, GlassWire is probably the easier place to start.<\/p>\n<p>            Portmaster is the one I&#8217;m leaving installed<\/p>\n<p>Wireshark was the most powerful tool I tried, and GlassWire made network activity much easier to understand, but Portmaster was the one that best matched what I was looking for. I didn&#8217;t just want to see that apps were using my connection. I wanted a practical way to look at those connections, understand where they were going, and decide what should be allowed. Portmaster is more hands-on than the others, and that won&#8217;t be the right fit for everyone, but for me, that extra control is exactly why it\u2019s the <a href=\"https:\/\/www.howtogeek.com\/192654\/how-to-monitor-your-internet-bandwidth-usage-and-avoid-exceeding-data-caps\/\" target=\"_blank\" rel=\"nofollow noopener\">network-monitoring<\/a> tool I&#8217;m keeping.<\/p>\n","protected":false},"excerpt":{"rendered":"I started looking at network-monitoring tools because my home network has become more crowded than I realized. This&hellip;\n","protected":false},"author":2,"featured_media":484699,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16],"tags":[342,111,139,69,145],"class_list":["post-484698","post","type-post","status-publish","format-standard","has-post-thumbnail","category-mobile","tag-mobile","tag-new-zealand","tag-newzealand","tag-nz","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/484698","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/comments?post=484698"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/484698\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media\/484699"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media?parent=484698"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/categories?post=484698"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/tags?post=484698"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}