I'm surprised that not only is there no application firewall for any of the BSDs, there doesn't even seem to be any need for it. There is OpenSnitch, but only for Linux.
SELinux can be somewhat classified as an app firewall but it's a policy framework after all and that suited for that.