Currently it seems that no firewall alone unaided can defeat all the leak tests out there. The best one currently seems to be Outpost Pro, though it misses the DNStester (which can be handled if you are willing to take the trouble of allowing DNS requests for each process indidivually) Do you think it's important that your firewall can handle these leak tests? Or is it just a matter of bragging rights? Maybe you think you would rather vendors focus on other things like True SPI maybe? Or do you think it's critical that firewalls block these leak tests? After all they make a joke out of the premise that personal firewalls can handle outbound connections. Poll follows.