FireHOL

As of 2014-02-08, this project may now be found at http://firehol.org/.

5.0 Stars (3)
1 Download (This Week)
Last Update:
Download firehol-1.273.tar.bz2
Browse All Files
BSD Linux

Description

Please see http://firehol.org/ for up-to-date releases and information. FireHOL is a stateful iptables packet filtering firewall configurator. It is abstracted, extensible, easy and powerful. It can handle any kind of firewall, but most importantly, it gives you the means to configure it, the same way you think of it.

FireHOL Web Site

Features

  • stateful packet filtering via netfilter (iptables) connection tracking
  • bidirectional firewall (protects you from outside but also enforces policy for internet usage to your clients)
  • high level configuration - you write does the obvious, the rest are handled by firehol
  • unlimited number of firewalling rules
  • unlimited number of interfaces
  • unlimited number of firewalling zones, which can be defined using a dynamic set of criteria (including nested ones)
  • supports all kinds of NAT (MASQ, SNAT, DNAT, REDIRECT, etc)
  • supports transparent proxies (which can be applied on all or subsets of the clients, the servers, or the local machine users)
  • cooperates with VPN software (GRE, IPIP, IPSEC, OpenVPN) and allows PPTP clients and servers
  • extensible via plugin modules
  • firewalling rules can use any matching criteria (IPs, ports, protocols, etc), including any netfilter module available

Update Notifications





User Ratings

★★★★★
★★★★
★★★
★★
3
0
0
0
0
ease 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5 0 / 5
features 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5 0 / 5
design 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5 0 / 5
support 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5 0 / 5
Write a Review

User Reviews

  • oid-3377281
    1 of 5 2 of 5 3 of 5 4 of 5 5 of 5

    Best way to manage IP tables bar none with great developer support.

    Posted 05/10/2011
  • pavelkrejci
    1 of 5 2 of 5 3 of 5 4 of 5 5 of 5

    Easy to configure, statefull - great!

    Posted 11/15/2010
  • devlaam
    1 of 5 2 of 5 3 of 5 4 of 5 5 of 5

    Great product, much simpler than directly working with iptables. But, it is not trivial. If you use the examples (there are a lot) its easy, but if you have to come up with your own solution, you still need to understand the concept of routing quite well.

    Posted 10/07/2010
Read more reviews

Additional Project Details

Screenshots can attract more users to your project.
Features can attract more users to your project.

Icons must be PNG, GIF, or JPEG and less than 1 MiB in size. They will be displayed as 48x48 images.