Features

Main Features

  1. Easy setup of a small but efficient "Personal Firewall".

  2. Nice overview of the configuration.

  3. Import/Export of rule sets to ease the setup of large networks.

  4. Easy-to-use GUI interface for most common setups.

  5. An advanced interface for complex rule sets as needed by routers

  6. Preconfigured rulesets for most common setups.

  7. Integrated Install scripts for automatic execution during booting.

  8. Plugin framowork that allows easy and fast development of new features.

  9. Plugin framowork that allows easy and fast development of new features.

Generic Interface

  1. Zone/Host based rule creation.

  2. No portnumbers need to be known.

  3. NAT and simple network router support.

  4. Support for special hosts e.g. trusted banned etc.

  5. Rule inheritance can be enabled/disabled for nested notwork zones.

  6. Operating system and backend independet. (Currently only Linux is supported but OpenBSD should follow soon)

IPTables Interface

  1. XML based iptables command generation engine that allows to be extended by plugins providing a description about the new option.

  2. State full packet filtering.

  3. IP, MAC, Protocol, ROS and Interface based filtering

  4. Limiting packet matches (avoids DoS attacks)

  5. Logging of dropped packets

  6. View running IP Tables configuration

  7. NAT (SNAT, DNAT) configuration (Masquerading)

  8. User defined Chains

  9. MANGLE configuration

  10. Undo/Redo