I like the idea of Portmaster, but it didn't work with dynamically assigned VPN IPs when I used it a couple years ago. It's also not easy to temporarily switch off; iirc, I had to uninstall everything to get my VPN to work again.
Unless they've figured out how to fix that issue, it's a caveat anyone with a VPN should know about.
It's probably still a good option if you don't have a VPN, though.
...or they should just move to Linux, kill two birds and all that.