Shorewall!

Current Stable Release .1.1 elease Notes pub/shorewall/5.1/shorewall-5.1.1/releasenotes.txt nown Problems pub/shorewall/5.1/shorewall-5.1.1/known_problems.txt --- Prior Stable Release .0.15.3 elease Notes pub/shorewall/5.0/shorewall-5.0.15/releasenotes.txt nown Problems pub/shorewall/5.0/shorewall-5.0.15/known_problems.txt Development Release | pub/shorewall/development/5.1/shorewall-5.1.1-RC1/releasenotes.txt Read about the Shorewall 5.0 and 5.1 releases here! Get them from the download sites Shorewall is a gateway/firewall configuration tool for GNU/Linux. For a high level description of Shorewall, see the Introduction to Shorewall . To review Shorewall functionality, see the Features Page . New to Shorewall? Download the current Stable version (see above then select the

Shorewall alternatives

  • Firewall Builder

  • Firewall Builder is Open Source multi-platform firewall management software that supports Linux iptables, FreeBSD ipfilter and ipfw, OpenBSD pf, CIsco PIX and Cisco IOS Access Lists.

    tags: Discontinued firewall protection system-administration configuration
  • Advanced Policy Firewall

  • Advanced Policy Firewall (APF) is an iptables(netfilter) based firewall system designed around the essential needs of today’s Linux servers. The configuration is designed to be very informative and easy to follow. The management on a day-to-day basis is conducted from the command line with the ‘apf’ command, which includes detailed usage information on all the features.The technical side of APF is such that it utilizes the latest stable features from the iptables (netfilter) project to provide a very robust and powerful firewall. The filtering performed by APF is three fold:1) Static rule based policies (not to be confused with a “static firewall”)2) Connection based stateful policies3) Sanity based policiesThe first, static rule based policies, is the most traditional method of firewalling. This is when the firewall has an unchanging set of instructions (rules) on how traffic should be handled in certain conditions. An example of a static rule based policy would be when you allow/deny an address access to the server with the trust system or open a new port with conf.apf. So the short of it is rules that infrequently or never change while the firewall is running.The second, connection based stateful policies, is a means to distinguish legitimate packets for different types of connections. Only packets matching a known connection will be allowed by the firewall; others will be rejected. An example of this would be FTP data transfers, in an older era of firewalling you would have to define a complex set of static policies to allow FTA data transfers to flow without a problem. That is not so with stateful policies, the firewall can see that an address has established a connection to port 21 then “relate” that address to the data transfer portion of the connection and dynamically alter the firewall to allow the traffic.... and much much more. See site for further details. »

    tags: firewall iptables netfilter mod-security application-firewall
  • ferm

  • ferm is a tool to maintain complex firewalls, without having the trouble to rewrite the complex rules over and over again. ferm allows the entire firewall rule set to be stored in a separate file, and to be loaded with one command. The firewall configuration resembles structured programming-like language, which can contain levels and lists.

    tags: firewall
  • iptablesbuild

  • iptablesbuild is effectively a configuration manager for iptables. It is intended to manage iptables configurations in a centralized location for multiple systems.

    tags: Discontinued firewall server-management firewall-rules iptables
  • HeatShield

  • HeatShield is a network firewall management service for Linux servers. A firewall configured by HeatShield prevents unauthorized access to services running on your servers, such as SSH and MySQL. Using HeatShield, you can easily restrict access to these services so that only IP addresses you trust are allowed to communicate with your servers.

    tags: firewall server-management firewall-management bruteforce iptables