ipflow package is intended to help network administartors log, analyze account and monitor traffic in their routing domain or particular host. Both plaintext and syslog facilities will be used for that as well as MySQL support. There will be PHP web inter
IPKungFu is an iptables-based Linux firewall. The primary design goals are security, ease of use, and performance, in that order. It takes advantage of advanced features of iptables, tcpwrappers, and the Linux kernel.
You do a command like this...
iptables-port-forward.sh eth0 200.200.200.200 80 eth1 192.168.0.1 80
And all request that came to you over eth0/ip 200.200.200.200 will be user-transparent forwarded to 192.168.0.1:80 via eth1
A Java implementation of a NAT-PMP client. At the project's inception, there was not a well-known NAT-PMP client library for Java. This project intends to fill the gap.
jRouter is a Web-based Linux router management system. It's designed to be a simple all-in-one router setup and management utility. Allows configuration of network interfaces, dhcpd, iptables, port forwarding, IP/MAC address filters.
janus watcher - Dynamic DNS watcher for FreeS/WAN & forks. Perl script that watches dynamic DNS hosts and replaces the connection when the IP address changes.
jennifer is an educational (albiet oddly named) firewall/NAT script generator, written in python, targetted at linux+iptables systems. It is intended to both (a) generate practical and useful configurations, and (b) demonstrate the concepts involved in TO
JWall is not just a java gui for iptables. JWall is a multi firewall management client. A secure rulebase can be built with graphical objects. Rulesets can be pushed to remote firewalls (via ssh). The remote firewall just needs to be Linux with sshd
l2tpknock is an add-on plugin for l2tpns servers or clusters and is intended to perform the rule of the port knocking idea, but with l2tp vpns, specifically, the l2tpns project.
Libconnect is a simple library wrapper written in
assembly language that intercepts the calls
applications make to establish TCP connections and
transparently proxies them as necessary.
links2world Firewall is a simple tool writen in C, that helps you generate iptables rules for Linux 2.4.x and newer kernels. Very easy to configure, it is designed to run on hosts with one or more network interfaces.
The LR101 Projects aim is to develop a real Linux Hardware Router supporting all major protocols / routing protocols with VPN (FreeS/WAN) and VPN/ISP Failover support.
Log2table allows you to continuously monitor your logfiles. You can trigger actions when a specific message comes in your audited logfiles or when a specific number of occurences are present.
Loggrep greps kernel logfiles on ipchains and iptables firewall log entries and features the ability to filter against given entries (date, IP, port, ..).
It also features quasi-detection of protscanning, line count
and html output.
macf is a MAC-based packet filter. It can be on a machine acting as a firewall, router, bridge, or even a server, and allows operators to "check out" MACs which may then be used for a period of time. Right now, it's on hold for lack of interest.
myNetWatchman Perl Agent is a program that is designed to capture rejected packet information from various firewall logs and forward this attack information to central analysis servers at myNetWatchman.com.
Net-Policy is a highly-scalable, role-and-policy based network management system. Net-Policy aims to be an easy-to-use, full-fledged management station capable of configuration, monitoring, and notification collection and aggregation via the use of SNMP
nf_quota is an ip-based traffic accounting project. IPs can be added to users. It provides a kernel module that hooks onto netfilter and counts every packet passing a specified interface. If the quota for a ip/user is exceeded, the packet is dropped.
This programs provisions a sensible secure network firewall with one LAN interface and one WAN interface. All from the built in tools in a stock install of OpenBSD.