HardWall Firewall: Is an iptables script that does the following:- Port Forwarding, Packet Filtering, Statefull Packet Inspection, Port Redirection, Masqurade, SNAT, DNAT, NAT & Bridging- Functions as both a Workstation and IP Forwarding Firewall
Be the first to post a text review of HardWall Firewall. Rate and review a project by clicking thumbs up or thumbs down in the right column.
Pre-15-Stable - 15/10/2004 Updated: The Reserved IP Address list in the main config file Added: Example Bridge (rc) startup script in the contrib directory Pre1-15-Stable - 22/10/2004 Fixed: Source / Destination port Combo for DHCPC in OUTEXT Fixed: Silly mistake in syntax that Enables IP Forwading (inherited from hwfirewall-15-pre13) Pre2-15-Stable - 01/11/2004 Fixed: Inital permissions of quotafwd-only.hosts Added: New Option to HwFw Main-Config that allows you to block almost all peer-2-peer traffic like kazza & edonkey. Added: rc.quota script into the 'contrib' directory Allows you to dynamicly add hosts with or w/o quotas. Pre3-15-Stable - 08/12/2004 Updated: the 'readme.txt' help file. Changed: ip-up.local's logic to suit wierd dsl setups. Pre4-15-Stable - 22/12/2004 Removed: Not needed syntax from the main script Pre5-15-Stable - 05/01/2005 Added: A check to see if the 'which' package is available Removed: More Not needed syntax from the main script Pre6-15-Stable - 26/01/2005 Fixed: The way the main script loaded modules for IRC & FTP Removed: More Not needed syntax from the main script Pre7-15-Stable - 27/01/2005 Added: A Packet Queuing Script to the Contrib Directory Removed: Not needed syntax from the scripts in Contrib Updated: Main Script and Config File to support Packet Queuing Pre8-15-Stable - 13/02/2005 Added: New NOTRACK Option in Main Config & Script Updated: Main Script handling of flushing / resetting tables. Pre9-15-Stable - 06/03/2005 Fixed: Syntax problems in main script for emule and game server Fixed: Syntax for just about all of the Contrib Scripts (Sorry) Added: New Net Test Script to the contrib directory. 15-Stable - 17/05/2005 Added: A check to see if user is 'root' or 'Super User' 15-ReStable - 19/05/2005 Fixed: Uncommented Test at bottom of main script. Added: Check to see if destination is going to be usefull to squid 15-Stable-1 - 10/07/2005 Changed: Logging to Suit IPtables log analizer. Changed: the way the Drop Chains work to suit setups where you are bridging on the lan side. Changed: the way Strcit Local Ports work for better use. Changed: the way IP to MAC Security works also to suit Bridges. Updated: the denied ports lists in DOWNSPAM and UPSPAM Added: Logging Feature to Samba in the HwFw Main Conf file. Added: The ability not to Log traffic with destination of local lan. (This Release has gone though a 4 week Closed Testing Period to ensure it doesnt break anything for anyone that is using 15-Stable) 15-Stable-2 - 03/09/2005 Added: Long needed commenting to the Main Firewall Script Changed: some of the code at the start of the main Script Added: SNORT Active IDS Guardian Support in the Contrib Dir (This Release has gone though a 4 week Closed Testing Period to ensure it doesnt break anything for anyone that is using 15-Stable-1) CVS Updated - 04/09/2005 (4:25 pm EST +10) 15-Stable-3 - 12/02/2006 Added: the ability to forward (steathed or normal) ident requests to a local or lan host in main config file Added: the ability to allow just allow local ports to be open for outbound (not inbound) in main config file Added: the ability to drop and add bad traffic to RECENT list with Outbound Traffic ... Added: the ability to fine tune the port scan detector options via the Main Config Added: the ability to use the iprange module for RESERVED_NET via the Main Config Added: the ability to enable / disable STP via the Contrib Script rc.bridge Added: the ability to Redirect HTTP to a squid server on the Local Lan Changed: Logging Tables Rules to be a bit smarter depending on configuration Changed: EXT SSH ACCESS rules to be more flexible in main config file Changed: ipp2p filtering ability to filter more traffic on inbound and outbound Changed: UPTCP rules to be allot more admin freindly by LOG(ing) whats going on Changed: RFC Private Address Range Checking in UPSPAM / DOWNSPAM based on Firewall Config Changed: Connlimit to be allot more flexible based on firewall config Changed: the packet shaper (queue) in Contrib to allow more traffic by default ... (People Upgrading from previous versions will need to also update there main.config file as well as the main script) (This Release has gone though a 4 week Closed Testing Period to ensure it doesnt break anything for anyone that is using 15-Stable-2) 15-Stable-4 - 12/03/2006 Fixed: DNAT --to PORT for SSH in Hosting (Main Config) Fixed: QUICK_IDENT TCP-Reset Doesnt work bug in EXTOUT Updated: IANA Reserved IPv4 blocked host list in Main Config 15-ReStable-4 - 14/03/2006 Fixed: Problem created with 15-Stable-3 with SQUID accounting rule in the User Table LOCOUT. 15-Stable-5 - 30/04/2006 Changed: The way TTL STEATH'ing worked in the Mangle Tables. Changed: TCP Clamp too PMTU, to now use the Mangle Tables. Changed: DOWNLOAD & EXTIN State rules to be more effecient. Added: Ability to just load the IRC and / or FTP modules. 15-Stable-6 - 03/09/2006 Fixed: the PEER_GW_INTERNAL Option inside the Main Script. Updated: FTP & IRC IPTables Module Config in Main Config. Updated: Scripts and Config files in the Contrib Directory. Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: Hosting Section in the Main Config to help with people trying to setup port forwarding. 15-Stable-7 - 01/04/2007 Updated: PEER_GW_INTERNAL code inside the Main Script. Updated: QUICK_IDENT Code inside of the Main Script. Updated: DISABLE_P2P Code inside of the Main Script. Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: EXT_SSH_ACCESS Code to allow for DMZ or Multihomed. Updated: SQUID_LOCAL_LAN Code to allow for DMZ or Multihomed Updated: ICMPUP & ICMPDOWN Code to make better use of P2P. Updated: UPTCP & DOWNTCP Code to make better use of P2P. Fixed: Forward Rule for HTTPS only (no HTTP) in Main Script. Added: SMTP_Allow list to Control Outbound SMTP connections. Added: RESERVED_BOGONS to Allow Reserved Private IP control. Added: ALLOW_ALL_BOGONS to Allow use of IANA Reserved IP's. Added: Configurable Sysctl options via the Main Config file. rp_filter / log_martians / TCP Conntrack Timeouts. 15-Stable-8 - 29/08/2007 Updated: TTL_STEALTH Code to work with Source Routing. Updated: SMTPUP to Allow for ISP Mail Server Redirection. Updated: EXT_SSH_ACCESS Code to work with Source Routing. Updated: Comments & Examples in the Config / Script Files. Updated: HwFw Main Config File with Source Routing Options. Updated: NAT Code in the Main Script to allow Source Routing Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: Contrib Directory with new Config / Script Versions Fixed: Example Creation in Main Script for Forwarding Rules. Added: More Sysctl Option Support in the Main Config. Added: TCP & ICMP Rate Limit options in the Main Config. Added: SRC Routing HowTo Files to the HwFirewall Package. Added: New Scripts & Config Files to the Contrib Directory. Added: A Set of Rule & Host Files to the HwFirewall Package. 15-ReStable-8 - 01/09/2007 Fixed: SRC Routing Code in Main Script to Include the required Forward Rules to make it allot easier to use. 15-Stable-9 - 21/06/2008 Updated: Comments & Examples in the Contrib Directory. Updated: Comments & Examples in the Config / Script Files. Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: Contrib Directory with new Config / Script Versions Added: Code to support BGP Multihop Loadbalance / Failover Added: 802.11x Wireless PEAP / EAP Security Examples. Added: PopTop VPN & FreeRadius Configuration Examples. Added: More code to help support multiple Wan Connections. Added: New Scripts & Config Files to the Contrib Directory.
Pre-15-Stable - 15/10/2004 Updated: The Reserved IP Address list in the main config file Added: Example Bridge (rc) startup script in the contrib directory Pre1-15-Stable - 22/10/2004 Fixed: Source / Destination port Combo for DHCPC in OUTEXT Fixed: Silly mistake in syntax that Enables IP Forwading (inherited from hwfirewall-15-pre13) Pre2-15-Stable - 01/11/2004 Fixed: Inital permissions of quotafwd-only.hosts Added: New Option to HwFw Main-Config that allows you to block almost all peer-2-peer traffic like kazza & edonkey. Added: rc.quota script into the 'contrib' directory Allows you to dynamicly add hosts with or w/o quotas. Pre3-15-Stable - 08/12/2004 Updated: the 'readme.txt' help file. Changed: ip-up.local's logic to suit wierd dsl setups. Pre4-15-Stable - 22/12/2004 Removed: Not needed syntax from the main script Pre5-15-Stable - 05/01/2005 Added: A check to see if the 'which' package is available Removed: More Not needed syntax from the main script Pre6-15-Stable - 26/01/2005 Fixed: The way the main script loaded modules for IRC & FTP Removed: More Not needed syntax from the main script Pre7-15-Stable - 27/01/2005 Added: A Packet Queuing Script to the Contrib Directory Removed: Not needed syntax from the scripts in Contrib Updated: Main Script and Config File to support Packet Queuing Pre8-15-Stable - 13/02/2005 Added: New NOTRACK Option in Main Config & Script Updated: Main Script handling of flushing / resetting tables. Pre9-15-Stable - 06/03/2005 Fixed: Syntax problems in main script for emule and game server Fixed: Syntax for just about all of the Contrib Scripts (Sorry) Added: New Net Test Script to the contrib directory. 15-Stable - 17/05/2005 Added: A check to see if user is 'root' or 'Super User' 15-ReStable - 19/05/2005 Fixed: Uncommented Test at bottom of main script. Added: Check to see if destination is going to be usefull to squid 15-Stable-1 - 10/07/2005 Changed: Logging to Suit IPtables log analizer. Changed: the way the Drop Chains work to suit setups where you are bridging on the lan side. Changed: the way Strcit Local Ports work for better use. Changed: the way IP to MAC Security works also to suit Bridges. Updated: the denied ports lists in DOWNSPAM and UPSPAM Added: Logging Feature to Samba in the HwFw Main Conf file. Added: The ability not to Log traffic with destination of local lan. (This Release has gone though a 4 week Closed Testing Period to ensure it doesnt break anything for anyone that is using 15-Stable) 15-Stable-2 - 03/09/2005 Added: Long needed commenting to the Main Firewall Script Changed: some of the code at the start of the main Script Added: SNORT Active IDS Guardian Support in the Contrib Dir (This Release has gone though a 4 week Closed Testing Period to ensure it doesnt break anything for anyone that is using 15-Stable-1) CVS Updated - 04/09/2005 (4:25 pm EST +10) 15-Stable-3 - 12/02/2006 Added: the ability to forward (steathed or normal) ident requests to a local or lan host in main config file Added: the ability to allow just allow local ports to be open for outbound (not inbound) in main config file Added: the ability to drop and add bad traffic to RECENT list with Outbound Traffic ... Added: the ability to fine tune the port scan detector options via the Main Config Added: the ability to use the iprange module for RESERVED_NET via the Main Config Added: the ability to enable / disable STP via the Contrib Script rc.bridge Added: the ability to Redirect HTTP to a squid server on the Local Lan Changed: Logging Tables Rules to be a bit smarter depending on configuration Changed: EXT SSH ACCESS rules to be more flexible in main config file Changed: ipp2p filtering ability to filter more traffic on inbound and outbound Changed: UPTCP rules to be allot more admin freindly by LOG(ing) whats going on Changed: RFC Private Address Range Checking in UPSPAM / DOWNSPAM based on Firewall Config Changed: Connlimit to be allot more flexible based on firewall config Changed: the packet shaper (queue) in Contrib to allow more traffic by default ... (People Upgrading from previous versions will need to also update there main.config file as well as the main script) (This Release has gone though a 4 week Closed Testing Period to ensure it doesnt break anything for anyone that is using 15-Stable-2) 15-Stable-4 - 12/03/2006 Fixed: DNAT --to PORT for SSH in Hosting (Main Config) Fixed: QUICK_IDENT TCP-Reset Doesnt work bug in EXTOUT Updated: IANA Reserved IPv4 blocked host list in Main Config 15-ReStable-4 - 14/03/2006 Fixed: Problem created with 15-Stable-3 with SQUID accounting rule in the User Table LOCOUT. 15-Stable-5 - 30/04/2006 Changed: The way TTL STEATH'ing worked in the Mangle Tables. Changed: TCP Clamp too PMTU, to now use the Mangle Tables. Changed: DOWNLOAD & EXTIN State rules to be more effecient. Added: Ability to just load the IRC and / or FTP modules. 15-Stable-6 - 03/09/2006 Fixed: the PEER_GW_INTERNAL Option inside the Main Script. Updated: FTP & IRC IPTables Module Config in Main Config. Updated: Scripts and Config files in the Contrib Directory. Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: Hosting Section in the Main Config to help with people trying to setup port forwarding. 15-Stable-7 - 01/04/2007 Updated: PEER_GW_INTERNAL code inside the Main Script. Updated: QUICK_IDENT Code inside of the Main Script. Updated: DISABLE_P2P Code inside of the Main Script. Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: EXT_SSH_ACCESS Code to allow for DMZ or Multihomed. Updated: SQUID_LOCAL_LAN Code to allow for DMZ or Multihomed Updated: ICMPUP & ICMPDOWN Code to make better use of P2P. Updated: UPTCP & DOWNTCP Code to make better use of P2P. Fixed: Forward Rule for HTTPS only (no HTTP) in Main Script. Added: SMTP_Allow list to Control Outbound SMTP connections. Added: RESERVED_BOGONS to Allow Reserved Private IP control. Added: ALLOW_ALL_BOGONS to Allow use of IANA Reserved IP's. Added: Configurable Sysctl options via the Main Config file. rp_filter / log_martians / TCP Conntrack Timeouts. 15-Stable-8 - 29/08/2007 Updated: TTL_STEALTH Code to work with Source Routing. Updated: SMTPUP to Allow for ISP Mail Server Redirection. Updated: EXT_SSH_ACCESS Code to work with Source Routing. Updated: Comments & Examples in the Config / Script Files. Updated: HwFw Main Config File with Source Routing Options. Updated: NAT Code in the Main Script to allow Source Routing Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: Contrib Directory with new Config / Script Versions Fixed: Example Creation in Main Script for Forwarding Rules. Added: More Sysctl Option Support in the Main Config. Added: TCP & ICMP Rate Limit options in the Main Config. Added: SRC Routing HowTo Files to the HwFirewall Package. Added: New Scripts & Config Files to the Contrib Directory. Added: A Set of Rule & Host Files to the HwFirewall Package. 15-ReStable-8 - 01/09/2007 Fixed: SRC Routing Code in Main Script to Include the required Forward Rules to make it allot easier to use. 15-Stable-9 - 21/06/2008 Updated: Comments & Examples in the Contrib Directory. Updated: Comments & Examples in the Config / Script Files. Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: Contrib Directory with new Config / Script Versions Added: Code to support BGP Multihop Loadbalance / Failover Added: 802.11x Wireless PEAP / EAP Security Examples. Added: PopTop VPN & FreeRadius Configuration Examples. Added: More code to help support multiple Wan Connections. Added: New Scripts & Config Files to the Contrib Directory.
Pre-15-Stable - 15/10/2004 Updated: The Reserved IP Address list in the main config file Added: Example Bridge (rc) startup script in the contrib directory Pre1-15-Stable - 22/10/2004 Fixed: Source / Destination port Combo for DHCPC in OUTEXT Fixed: Silly mistake in syntax that Enables IP Forwading (inherited from hwfirewall-15-pre13) Pre2-15-Stable - 01/11/2004 Fixed: Inital permissions of quotafwd-only.hosts Added: New Option to HwFw Main-Config that allows you to block almost all peer-2-peer traffic like kazza & edonkey. Added: rc.quota script into the 'contrib' directory Allows you to dynamicly add hosts with or w/o quotas. Pre3-15-Stable - 08/12/2004 Updated: the 'readme.txt' help file. Changed: ip-up.local's logic to suit wierd dsl setups. Pre4-15-Stable - 22/12/2004 Removed: Not needed syntax from the main script Pre5-15-Stable - 05/01/2005 Added: A check to see if the 'which' package is available Removed: More Not needed syntax from the main script Pre6-15-Stable - 26/01/2005 Fixed: The way the main script loaded modules for IRC & FTP Removed: More Not needed syntax from the main script Pre7-15-Stable - 27/01/2005 Added: A Packet Queuing Script to the Contrib Directory Removed: Not needed syntax from the scripts in Contrib Updated: Main Script and Config File to support Packet Queuing Pre8-15-Stable - 13/02/2005 Added: New NOTRACK Option in Main Config & Script Updated: Main Script handling of flushing / resetting tables. Pre9-15-Stable - 06/03/2005 Fixed: Syntax problems in main script for emule and game server Fixed: Syntax for just about all of the Contrib Scripts (Sorry) Added: New Net Test Script to the contrib directory. 15-Stable - 17/05/2005 Added: A check to see if user is 'root' or 'Super User' 15-ReStable - 19/05/2005 Fixed: Uncommented Test at bottom of main script. Added: Check to see if destination is going to be usefull to squid 15-Stable-1 - 10/07/2005 Changed: Logging to Suit IPtables log analizer. Changed: the way the Drop Chains work to suit setups where you are bridging on the lan side. Changed: the way Strcit Local Ports work for better use. Changed: the way IP to MAC Security works also to suit Bridges. Updated: the denied ports lists in DOWNSPAM and UPSPAM Added: Logging Feature to Samba in the HwFw Main Conf file. Added: The ability not to Log traffic with destination of local lan. (This Release has gone though a 4 week Closed Testing Period to ensure it doesnt break anything for anyone that is using 15-Stable) 15-Stable-2 - 03/09/2005 Added: Long needed commenting to the Main Firewall Script Changed: some of the code at the start of the main Script Added: SNORT Active IDS Guardian Support in the Contrib Dir (This Release has gone though a 4 week Closed Testing Period to ensure it doesnt break anything for anyone that is using 15-Stable-1) CVS Updated - 04/09/2005 (4:25 pm EST +10) 15-Stable-3 - 12/02/2006 Added: the ability to forward (steathed or normal) ident requests to a local or lan host in main config file Added: the ability to allow just allow local ports to be open for outbound (not inbound) in main config file Added: the ability to drop and add bad traffic to RECENT list with Outbound Traffic ... Added: the ability to fine tune the port scan detector options via the Main Config Added: the ability to use the iprange module for RESERVED_NET via the Main Config Added: the ability to enable / disable STP via the Contrib Script rc.bridge Added: the ability to Redirect HTTP to a squid server on the Local Lan Changed: Logging Tables Rules to be a bit smarter depending on configuration Changed: EXT SSH ACCESS rules to be more flexible in main config file Changed: ipp2p filtering ability to filter more traffic on inbound and outbound Changed: UPTCP rules to be allot more admin freindly by LOG(ing) whats going on Changed: RFC Private Address Range Checking in UPSPAM / DOWNSPAM based on Firewall Config Changed: Connlimit to be allot more flexible based on firewall config Changed: the packet shaper (queue) in Contrib to allow more traffic by default ... (People Upgrading from previous versions will need to also update there main.config file as well as the main script) (This Release has gone though a 4 week Closed Testing Period to ensure it doesnt break anything for anyone that is using 15-Stable-2) 15-Stable-4 - 12/03/2006 Fixed: DNAT --to PORT for SSH in Hosting (Main Config) Fixed: QUICK_IDENT TCP-Reset Doesnt work bug in EXTOUT Updated: IANA Reserved IPv4 blocked host list in Main Config 15-ReStable-4 - 14/03/2006 Fixed: Problem created with 15-Stable-3 with SQUID accounting rule in the User Table LOCOUT. 15-Stable-5 - 30/04/2006 Changed: The way TTL STEATH'ing worked in the Mangle Tables. Changed: TCP Clamp too PMTU, to now use the Mangle Tables. Changed: DOWNLOAD & EXTIN State rules to be more effecient. Added: Ability to just load the IRC and / or FTP modules. 15-Stable-6 - 03/09/2006 Fixed: the PEER_GW_INTERNAL Option inside the Main Script. Updated: FTP & IRC IPTables Module Config in Main Config. Updated: Scripts and Config files in the Contrib Directory. Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: Hosting Section in the Main Config to help with people trying to setup port forwarding. 15-Stable-7 - 01/04/2007 Updated: PEER_GW_INTERNAL code inside the Main Script. Updated: QUICK_IDENT Code inside of the Main Script. Updated: DISABLE_P2P Code inside of the Main Script. Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: EXT_SSH_ACCESS Code to allow for DMZ or Multihomed. Updated: SQUID_LOCAL_LAN Code to allow for DMZ or Multihomed Updated: ICMPUP & ICMPDOWN Code to make better use of P2P. Updated: UPTCP & DOWNTCP Code to make better use of P2P. Fixed: Forward Rule for HTTPS only (no HTTP) in Main Script. Added: SMTP_Allow list to Control Outbound SMTP connections. Added: RESERVED_BOGONS to Allow Reserved Private IP control. Added: ALLOW_ALL_BOGONS to Allow use of IANA Reserved IP's. Added: Configurable Sysctl options via the Main Config file. rp_filter / log_martians / TCP Conntrack Timeouts. 15-Stable-8 - 29/08/2007 Updated: TTL_STEALTH Code to work with Source Routing. Updated: SMTPUP to Allow for ISP Mail Server Redirection. Updated: EXT_SSH_ACCESS Code to work with Source Routing. Updated: Comments & Examples in the Config / Script Files. Updated: HwFw Main Config File with Source Routing Options. Updated: NAT Code in the Main Script to allow Source Routing Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: Contrib Directory with new Config / Script Versions Fixed: Example Creation in Main Script for Forwarding Rules. Added: More Sysctl Option Support in the Main Config. Added: TCP & ICMP Rate Limit options in the Main Config. Added: SRC Routing HowTo Files to the HwFirewall Package. Added: New Scripts & Config Files to the Contrib Directory. Added: A Set of Rule & Host Files to the HwFirewall Package. 15-ReStable-8 - 01/09/2007 Fixed: SRC Routing Code in Main Script to Include the required Forward Rules to make it allot easier to use. 15-Stable-9 - 21/06/2008 Updated: Comments & Examples in the Contrib Directory. Updated: Comments & Examples in the Config / Script Files. Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: Contrib Directory with new Config / Script Versions Added: Code to support BGP Multihop Loadbalance / Failover Added: 802.11x Wireless PEAP / EAP Security Examples. Added: PopTop VPN & FreeRadius Configuration Examples. Added: More code to help support multiple Wan Connections. Added: New Scripts & Config Files to the Contrib Directory.
Pre-15-Stable - 15/10/2004 Updated: The Reserved IP Address list in the main config file Added: Example Bridge (rc) startup script in the contrib directory Pre1-15-Stable - 22/10/2004 Fixed: Source / Destination port Combo for DHCPC in OUTEXT Fixed: Silly mistake in syntax that Enables IP Forwading (inherited from hwfirewall-15-pre13) Pre2-15-Stable - 01/11/2004 Fixed: Inital permissions of quotafwd-only.hosts Added: New Option to HwFw Main-Config that allows you to block almost all peer-2-peer traffic like kazza & edonkey. Added: rc.quota script into the 'contrib' directory Allows you to dynamicly add hosts with or w/o quotas. Pre3-15-Stable - 08/12/2004 Updated: the 'readme.txt' help file. Changed: ip-up.local's logic to suit wierd dsl setups. Pre4-15-Stable - 22/12/2004 Removed: Not needed syntax from the main script Pre5-15-Stable - 05/01/2005 Added: A check to see if the 'which' package is available Removed: More Not needed syntax from the main script Pre6-15-Stable - 26/01/2005 Fixed: The way the main script loaded modules for IRC & FTP Removed: More Not needed syntax from the main script Pre7-15-Stable - 27/01/2005 Added: A Packet Queuing Script to the Contrib Directory Removed: Not needed syntax from the scripts in Contrib Updated: Main Script and Config File to support Packet Queuing Pre8-15-Stable - 13/02/2005 Added: New NOTRACK Option in Main Config & Script Updated: Main Script handling of flushing / resetting tables. Pre9-15-Stable - 06/03/2005 Fixed: Syntax problems in main script for emule and game server Fixed: Syntax for just about all of the Contrib Scripts (Sorry) Added: New Net Test Script to the contrib directory. 15-Stable - 17/05/2005 Added: A check to see if user is 'root' or 'Super User' 15-ReStable - 19/05/2005 Fixed: Uncommented Test at bottom of main script. Added: Check to see if destination is going to be usefull to squid 15-Stable-1 - 10/07/2005 Changed: Logging to Suit IPtables log analizer. Changed: the way the Drop Chains work to suit setups where you are bridging on the lan side. Changed: the way Strcit Local Ports work for better use. Changed: the way IP to MAC Security works also to suit Bridges. Updated: the denied ports lists in DOWNSPAM and UPSPAM Added: Logging Feature to Samba in the HwFw Main Conf file. Added: The ability not to Log traffic with destination of local lan. (This Release has gone though a 4 week Closed Testing Period to ensure it doesnt break anything for anyone that is using 15-Stable) 15-Stable-2 - 03/09/2005 Added: Long needed commenting to the Main Firewall Script Changed: some of the code at the start of the main Script Added: SNORT Active IDS Guardian Support in the Contrib Dir (This Release has gone though a 4 week Closed Testing Period to ensure it doesnt break anything for anyone that is using 15-Stable-1) CVS Updated - 04/09/2005 (4:25 pm EST +10) 15-Stable-3 - 12/02/2006 Added: the ability to forward (steathed or normal) ident requests to a local or lan host in main config file Added: the ability to allow just allow local ports to be open for outbound (not inbound) in main config file Added: the ability to drop and add bad traffic to RECENT list with Outbound Traffic ... Added: the ability to fine tune the port scan detector options via the Main Config Added: the ability to use the iprange module for RESERVED_NET via the Main Config Added: the ability to enable / disable STP via the Contrib Script rc.bridge Added: the ability to Redirect HTTP to a squid server on the Local Lan Changed: Logging Tables Rules to be a bit smarter depending on configuration Changed: EXT SSH ACCESS rules to be more flexible in main config file Changed: ipp2p filtering ability to filter more traffic on inbound and outbound Changed: UPTCP rules to be allot more admin freindly by LOG(ing) whats going on Changed: RFC Private Address Range Checking in UPSPAM / DOWNSPAM based on Firewall Config Changed: Connlimit to be allot more flexible based on firewall config Changed: the packet shaper (queue) in Contrib to allow more traffic by default ... (People Upgrading from previous versions will need to also update there main.config file as well as the main script) (This Release has gone though a 4 week Closed Testing Period to ensure it doesnt break anything for anyone that is using 15-Stable-2) 15-Stable-4 - 12/03/2006 Fixed: DNAT --to PORT for SSH in Hosting (Main Config) Fixed: QUICK_IDENT TCP-Reset Doesnt work bug in EXTOUT Updated: IANA Reserved IPv4 blocked host list in Main Config 15-ReStable-4 - 14/03/2006 Fixed: Problem created with 15-Stable-3 with SQUID accounting rule in the User Table LOCOUT. 15-Stable-5 - 30/04/2006 Changed: The way TTL STEATH'ing worked in the Mangle Tables. Changed: TCP Clamp too PMTU, to now use the Mangle Tables. Changed: DOWNLOAD & EXTIN State rules to be more effecient. Added: Ability to just load the IRC and / or FTP modules. 15-Stable-6 - 03/09/2006 Fixed: the PEER_GW_INTERNAL Option inside the Main Script. Updated: FTP & IRC IPTables Module Config in Main Config. Updated: Scripts and Config files in the Contrib Directory. Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: Hosting Section in the Main Config to help with people trying to setup port forwarding. 15-Stable-7 - 01/04/2007 Updated: PEER_GW_INTERNAL code inside the Main Script. Updated: QUICK_IDENT Code inside of the Main Script. Updated: DISABLE_P2P Code inside of the Main Script. Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: EXT_SSH_ACCESS Code to allow for DMZ or Multihomed. Updated: SQUID_LOCAL_LAN Code to allow for DMZ or Multihomed Updated: ICMPUP & ICMPDOWN Code to make better use of P2P. Updated: UPTCP & DOWNTCP Code to make better use of P2P. Fixed: Forward Rule for HTTPS only (no HTTP) in Main Script. Added: SMTP_Allow list to Control Outbound SMTP connections. Added: RESERVED_BOGONS to Allow Reserved Private IP control. Added: ALLOW_ALL_BOGONS to Allow use of IANA Reserved IP's. Added: Configurable Sysctl options via the Main Config file. rp_filter / log_martians / TCP Conntrack Timeouts. 15-Stable-8 - 29/08/2007 Updated: TTL_STEALTH Code to work with Source Routing. Updated: SMTPUP to Allow for ISP Mail Server Redirection. Updated: EXT_SSH_ACCESS Code to work with Source Routing. Updated: Comments & Examples in the Config / Script Files. Updated: HwFw Main Config File with Source Routing Options. Updated: NAT Code in the Main Script to allow Source Routing Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: Contrib Directory with new Config / Script Versions Fixed: Example Creation in Main Script for Forwarding Rules. Added: More Sysctl Option Support in the Main Config. Added: TCP & ICMP Rate Limit options in the Main Config. Added: SRC Routing HowTo Files to the HwFirewall Package. Added: New Scripts & Config Files to the Contrib Directory. Added: A Set of Rule & Host Files to the HwFirewall Package. 15-ReStable-8 - 01/09/2007 Fixed: SRC Routing Code in Main Script to Include the required Forward Rules to make it allot easier to use. 15-Stable-9 - 21/06/2008 Updated: Comments & Examples in the Contrib Directory. Updated: Comments & Examples in the Config / Script Files. Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: Contrib Directory with new Config / Script Versions Added: Code to support BGP Multihop Loadbalance / Failover Added: 802.11x Wireless PEAP / EAP Security Examples. Added: PopTop VPN & FreeRadius Configuration Examples. Added: More code to help support multiple Wan Connections. Added: New Scripts & Config Files to the Contrib Directory.
Pre-15-Stable - 15/10/2004 Updated: The Reserved IP Address list in the main config file Added: Example Bridge (rc) startup script in the contrib directory Pre1-15-Stable - 22/10/2004 Fixed: Source / Destination port Combo for DHCPC in OUTEXT Fixed: Silly mistake in syntax that Enables IP Forwading (inherited from hwfirewall-15-pre13) Pre2-15-Stable - 01/11/2004 Fixed: Inital permissions of quotafwd-only.hosts Added: New Option to HwFw Main-Config that allows you to block almost all peer-2-peer traffic like kazza & edonkey. Added: rc.quota script into the 'contrib' directory Allows you to dynamicly add hosts with or w/o quotas. Pre3-15-Stable - 08/12/2004 Updated: the 'readme.txt' help file. Changed: ip-up.local's logic to suit wierd dsl setups. Pre4-15-Stable - 22/12/2004 Removed: Not needed syntax from the main script Pre5-15-Stable - 05/01/2005 Added: A check to see if the 'which' package is available Removed: More Not needed syntax from the main script Pre6-15-Stable - 26/01/2005 Fixed: The way the main script loaded modules for IRC & FTP Removed: More Not needed syntax from the main script Pre7-15-Stable - 27/01/2005 Added: A Packet Queuing Script to the Contrib Directory Removed: Not needed syntax from the scripts in Contrib Updated: Main Script and Config File to support Packet Queuing Pre8-15-Stable - 13/02/2005 Added: New NOTRACK Option in Main Config & Script Updated: Main Script handling of flushing / resetting tables. Pre9-15-Stable - 06/03/2005 Fixed: Syntax problems in main script for emule and game server Fixed: Syntax for just about all of the Contrib Scripts (Sorry) Added: New Net Test Script to the contrib directory. 15-Stable - 17/05/2005 Added: A check to see if user is 'root' or 'Super User' 15-ReStable - 19/05/2005 Fixed: Uncommented Test at bottom of main script. Added: Check to see if destination is going to be usefull to squid 15-Stable-1 - 10/07/2005 Changed: Logging to Suit IPtables log analizer. Changed: the way the Drop Chains work to suit setups where you are bridging on the lan side. Changed: the way Strcit Local Ports work for better use. Changed: the way IP to MAC Security works also to suit Bridges. Updated: the denied ports lists in DOWNSPAM and UPSPAM Added: Logging Feature to Samba in the HwFw Main Conf file. Added: The ability not to Log traffic with destination of local lan. (This Release has gone though a 4 week Closed Testing Period to ensure it doesnt break anything for anyone that is using 15-Stable) 15-Stable-2 - 03/09/2005 Added: Long needed commenting to the Main Firewall Script Changed: some of the code at the start of the main Script Added: SNORT Active IDS Guardian Support in the Contrib Dir (This Release has gone though a 4 week Closed Testing Period to ensure it doesnt break anything for anyone that is using 15-Stable-1) CVS Updated - 04/09/2005 (4:25 pm EST +10) 15-Stable-3 - 12/02/2006 Added: the ability to forward (steathed or normal) ident requests to a local or lan host in main config file Added: the ability to allow just allow local ports to be open for outbound (not inbound) in main config file Added: the ability to drop and add bad traffic to RECENT list with Outbound Traffic ... Added: the ability to fine tune the port scan detector options via the Main Config Added: the ability to use the iprange module for RESERVED_NET via the Main Config Added: the ability to enable / disable STP via the Contrib Script rc.bridge Added: the ability to Redirect HTTP to a squid server on the Local Lan Changed: Logging Tables Rules to be a bit smarter depending on configuration Changed: EXT SSH ACCESS rules to be more flexible in main config file Changed: ipp2p filtering ability to filter more traffic on inbound and outbound Changed: UPTCP rules to be allot more admin freindly by LOG(ing) whats going on Changed: RFC Private Address Range Checking in UPSPAM / DOWNSPAM based on Firewall Config Changed: Connlimit to be allot more flexible based on firewall config Changed: the packet shaper (queue) in Contrib to allow more traffic by default ... (People Upgrading from previous versions will need to also update there main.config file as well as the main script) (This Release has gone though a 4 week Closed Testing Period to ensure it doesnt break anything for anyone that is using 15-Stable-2) 15-Stable-4 - 12/03/2006 Fixed: DNAT --to PORT for SSH in Hosting (Main Config) Fixed: QUICK_IDENT TCP-Reset Doesnt work bug in EXTOUT Updated: IANA Reserved IPv4 blocked host list in Main Config 15-ReStable-4 - 14/03/2006 Fixed: Problem created with 15-Stable-3 with SQUID accounting rule in the User Table LOCOUT. 15-Stable-5 - 30/04/2006 Changed: The way TTL STEATH'ing worked in the Mangle Tables. Changed: TCP Clamp too PMTU, to now use the Mangle Tables. Changed: DOWNLOAD & EXTIN State rules to be more effecient. Added: Ability to just load the IRC and / or FTP modules. 15-Stable-6 - 03/09/2006 Fixed: the PEER_GW_INTERNAL Option inside the Main Script. Updated: FTP & IRC IPTables Module Config in Main Config. Updated: Scripts and Config files in the Contrib Directory. Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: Hosting Section in the Main Config to help with people trying to setup port forwarding. 15-Stable-7 - 01/04/2007 Updated: PEER_GW_INTERNAL code inside the Main Script. Updated: QUICK_IDENT Code inside of the Main Script. Updated: DISABLE_P2P Code inside of the Main Script. Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: EXT_SSH_ACCESS Code to allow for DMZ or Multihomed. Updated: SQUID_LOCAL_LAN Code to allow for DMZ or Multihomed Updated: ICMPUP & ICMPDOWN Code to make better use of P2P. Updated: UPTCP & DOWNTCP Code to make better use of P2P. Fixed: Forward Rule for HTTPS only (no HTTP) in Main Script. Added: SMTP_Allow list to Control Outbound SMTP connections. Added: RESERVED_BOGONS to Allow Reserved Private IP control. Added: ALLOW_ALL_BOGONS to Allow use of IANA Reserved IP's. Added: Configurable Sysctl options via the Main Config file. rp_filter / log_martians / TCP Conntrack Timeouts. 15-Stable-8 - 29/08/2007 Updated: TTL_STEALTH Code to work with Source Routing. Updated: SMTPUP to Allow for ISP Mail Server Redirection. Updated: EXT_SSH_ACCESS Code to work with Source Routing. Updated: Comments & Examples in the Config / Script Files. Updated: HwFw Main Config File with Source Routing Options. Updated: NAT Code in the Main Script to allow Source Routing Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: Contrib Directory with new Config / Script Versions Fixed: Example Creation in Main Script for Forwarding Rules. Added: More Sysctl Option Support in the Main Config. Added: TCP & ICMP Rate Limit options in the Main Config. Added: SRC Routing HowTo Files to the HwFirewall Package. Added: New Scripts & Config Files to the Contrib Directory. Added: A Set of Rule & Host Files to the HwFirewall Package. 15-ReStable-8 - 01/09/2007 Fixed: SRC Routing Code in Main Script to Include the required Forward Rules to make it allot easier to use. 15-Stable-9 - 21/06/2008 Updated: Comments & Examples in the Contrib Directory. Updated: Comments & Examples in the Config / Script Files. Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: Contrib Directory with new Config / Script Versions Added: Code to support BGP Multihop Loadbalance / Failover Added: 802.11x Wireless PEAP / EAP Security Examples. Added: PopTop VPN & FreeRadius Configuration Examples. Added: More code to help support multiple Wan Connections. Added: New Scripts & Config Files to the Contrib Directory.
Pre-15-Stable - 15/10/2004 Updated: The Reserved IP Address list in the main config file Added: Example Bridge (rc) startup script in the contrib directory Pre1-15-Stable - 22/10/2004 Fixed: Source / Destination port Combo for DHCPC in OUTEXT Fixed: Silly mistake in syntax that Enables IP Forwading (inherited from hwfirewall-15-pre13) Pre2-15-Stable - 01/11/2004 Fixed: Inital permissions of quotafwd-only.hosts Added: New Option to HwFw Main-Config that allows you to block almost all peer-2-peer traffic like kazza & edonkey. Added: rc.quota script into the 'contrib' directory Allows you to dynamicly add hosts with or w/o quotas. Pre3-15-Stable - 08/12/2004 Updated: the 'readme.txt' help file. Changed: ip-up.local's logic to suit wierd dsl setups. Pre4-15-Stable - 22/12/2004 Removed: Not needed syntax from the main script Pre5-15-Stable - 05/01/2005 Added: A check to see if the 'which' package is available Removed: More Not needed syntax from the main script Pre6-15-Stable - 26/01/2005 Fixed: The way the main script loaded modules for IRC & FTP Removed: More Not needed syntax from the main script Pre7-15-Stable - 27/01/2005 Added: A Packet Queuing Script to the Contrib Directory Removed: Not needed syntax from the scripts in Contrib Updated: Main Script and Config File to support Packet Queuing Pre8-15-Stable - 13/02/2005 Added: New NOTRACK Option in Main Config & Script Updated: Main Script handling of flushing / resetting tables. Pre9-15-Stable - 06/03/2005 Fixed: Syntax problems in main script for emule and game server Fixed: Syntax for just about all of the Contrib Scripts (Sorry) Added: New Net Test Script to the contrib directory. 15-Stable - 17/05/2005 Added: A check to see if user is 'root' or 'Super User' 15-ReStable - 19/05/2005 Fixed: Uncommented Test at bottom of main script. Added: Check to see if destination is going to be usefull to squid 15-Stable-1 - 10/07/2005 Changed: Logging to Suit IPtables log analizer. Changed: the way the Drop Chains work to suit setups where you are bridging on the lan side. Changed: the way Strcit Local Ports work for better use. Changed: the way IP to MAC Security works also to suit Bridges. Updated: the denied ports lists in DOWNSPAM and UPSPAM Added: Logging Feature to Samba in the HwFw Main Conf file. Added: The ability not to Log traffic with destination of local lan. (This Release has gone though a 4 week Closed Testing Period to ensure it doesnt break anything for anyone that is using 15-Stable) 15-Stable-2 - 03/09/2005 Added: Long needed commenting to the Main Firewall Script Changed: some of the code at the start of the main Script Added: SNORT Active IDS Guardian Support in the Contrib Dir (This Release has gone though a 4 week Closed Testing Period to ensure it doesnt break anything for anyone that is using 15-Stable-1) CVS Updated - 04/09/2005 (4:25 pm EST +10) 15-Stable-3 - 12/02/2006 Added: the ability to forward (steathed or normal) ident requests to a local or lan host in main config file Added: the ability to allow just allow local ports to be open for outbound (not inbound) in main config file Added: the ability to drop and add bad traffic to RECENT list with Outbound Traffic ... Added: the ability to fine tune the port scan detector options via the Main Config Added: the ability to use the iprange module for RESERVED_NET via the Main Config Added: the ability to enable / disable STP via the Contrib Script rc.bridge Added: the ability to Redirect HTTP to a squid server on the Local Lan Changed: Logging Tables Rules to be a bit smarter depending on configuration Changed: EXT SSH ACCESS rules to be more flexible in main config file Changed: ipp2p filtering ability to filter more traffic on inbound and outbound Changed: UPTCP rules to be allot more admin freindly by LOG(ing) whats going on Changed: RFC Private Address Range Checking in UPSPAM / DOWNSPAM based on Firewall Config Changed: Connlimit to be allot more flexible based on firewall config Changed: the packet shaper (queue) in Contrib to allow more traffic by default ... (People Upgrading from previous versions will need to also update there main.config file as well as the main script) (This Release has gone though a 4 week Closed Testing Period to ensure it doesnt break anything for anyone that is using 15-Stable-2) 15-Stable-4 - 12/03/2006 Fixed: DNAT --to PORT for SSH in Hosting (Main Config) Fixed: QUICK_IDENT TCP-Reset Doesnt work bug in EXTOUT Updated: IANA Reserved IPv4 blocked host list in Main Config 15-ReStable-4 - 14/03/2006 Fixed: Problem created with 15-Stable-3 with SQUID accounting rule in the User Table LOCOUT. 15-Stable-5 - 30/04/2006 Changed: The way TTL STEATH'ing worked in the Mangle Tables. Changed: TCP Clamp too PMTU, to now use the Mangle Tables. Changed: DOWNLOAD & EXTIN State rules to be more effecient. Added: Ability to just load the IRC and / or FTP modules. 15-Stable-6 - 03/09/2006 Fixed: the PEER_GW_INTERNAL Option inside the Main Script. Updated: FTP & IRC IPTables Module Config in Main Config. Updated: Scripts and Config files in the Contrib Directory. Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: Hosting Section in the Main Config to help with people trying to setup port forwarding. 15-Stable-7 - 01/04/2007 Updated: PEER_GW_INTERNAL code inside the Main Script. Updated: QUICK_IDENT Code inside of the Main Script. Updated: DISABLE_P2P Code inside of the Main Script. Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: EXT_SSH_ACCESS Code to allow for DMZ or Multihomed. Updated: SQUID_LOCAL_LAN Code to allow for DMZ or Multihomed Updated: ICMPUP & ICMPDOWN Code to make better use of P2P. Updated: UPTCP & DOWNTCP Code to make better use of P2P. Fixed: Forward Rule for HTTPS only (no HTTP) in Main Script. Added: SMTP_Allow list to Control Outbound SMTP connections. Added: RESERVED_BOGONS to Allow Reserved Private IP control. Added: ALLOW_ALL_BOGONS to Allow use of IANA Reserved IP's. Added: Configurable Sysctl options via the Main Config file. rp_filter / log_martians / TCP Conntrack Timeouts. 15-Stable-8 - 29/08/2007 Updated: TTL_STEALTH Code to work with Source Routing. Updated: SMTPUP to Allow for ISP Mail Server Redirection. Updated: EXT_SSH_ACCESS Code to work with Source Routing. Updated: Comments & Examples in the Config / Script Files. Updated: HwFw Main Config File with Source Routing Options. Updated: NAT Code in the Main Script to allow Source Routing Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: Contrib Directory with new Config / Script Versions Fixed: Example Creation in Main Script for Forwarding Rules. Added: More Sysctl Option Support in the Main Config. Added: TCP & ICMP Rate Limit options in the Main Config. Added: SRC Routing HowTo Files to the HwFirewall Package. Added: New Scripts & Config Files to the Contrib Directory. Added: A Set of Rule & Host Files to the HwFirewall Package. 15-ReStable-8 - 01/09/2007 Fixed: SRC Routing Code in Main Script to Include the required Forward Rules to make it allot easier to use. 15-Stable-9 - 21/06/2008 Updated: Comments & Examples in the Contrib Directory. Updated: Comments & Examples in the Config / Script Files. Updated: IANA Reserved IPv4 blocked host list in Main Config Updated: Contrib Directory with new Config / Script Versions Added: Code to support BGP Multihop Loadbalance / Failover Added: 802.11x Wireless PEAP / EAP Security Examples. Added: PopTop VPN & FreeRadius Configuration Examples. Added: More code to help support multiple Wan Connections. Added: New Scripts & Config Files to the Contrib Directory.
Be the first person to add a text review.
Copyright © 2009 Geeknet, Inc. All rights reserved. Terms of Use
Thanks for your rating!
Would you also like to write a review?