最後更新: 2014-02-11 20:40


Zorp is a proxy firewall suite with its core architecture is built around today's security demands: it uses application level proxies, is modular and component based, uses a script language to describe policy decisions, makes it possible to monitor encrypted traffic, lets you override client actions, and lets you protect your servers with its built in IDS capabilities.

最後更新: 2012-12-31 22:06


Devil-Linux is a special secure Linux distribution which is used for firewalls, routers, gateways, and servers. The goal of Devil-Linux is to have a small, customizable, and secure Linux system. Configuration is saved on a floppy disk or USB stick, and it has several optional packages. Devil-Linux boots from CD, but can be stored on CF cards or USB sticks.

最後更新: 2011-07-13 20:55


m0n0wall is an all-in-one firewall software
package that is based on FreeBSD. It is geared
towards embedded PCs, but it also works on
standard PCs. It includes an easy-to-use Web
interface like commercial firewall boxes do. PHP
is used instead of shell scripts, and the entire
system configuration is stored in a single
XML-formatted file. There is support for VPN,
traffic shaping, captive portal, VLANs, and more.

最後更新: 2008-01-02 13:29

Bandwidth Management Tools

Bandwidth Management Tools is a total bandwidth
management solution for Linux and can be used for firewalling, traffic graphing, and shaping. It is not based on any currently-available bandwidth management software and supports packet queues, bursting, complex traffic flow hierarchies, flow groups, traffic logging, and a simple real-time monitoring front-end.

最後更新: 2013-11-18 22:45


Dante is a free implementation of the proxy protocols SOCKS version 4 and SOCKS version 5 (RFC 1928). It can be used as a firewall between networks, controlling outgoing traffic. The package consists of two parts: a socks server and a proxy client that supports socks, HTTP proxies, and UPnP. RFC 1961 (GSSAPI) is supported in both the client and the server. Commercial support is available.

最後更新: 2009-08-17 17:48

Shoreline Firewall

Shorewall is an iptables-based firewall for Linux Systems. Its configuration is very flexible, allowing it to be used in a wide range of firewall/gateway/router and VPN environments.

最後更新: 2014-02-05 23:33


fwsnort translates snort rules into an equivalent
iptables ruleset. By making use of the iptables
string match module, fwsnort can detect
application layer signatures which exist in many
snort rules. fwsnort adds a --hex-string option to
iptables, which allows snort rules that contain
hex characters to be input directly into iptables
rulesets without modification. In addition,
fwsnort makes use of the IPTables::Parse Perl
module in order to (optionally) restrict the snort
rule translation to only those rules that specify
traffic that could potentially be allowed through
an existing iptables policy.

最後更新: 2010-08-13 14:40


NuFW is an authenticating firewall. It adds strict and secure identity-based filtering capabilities to enterprise-grade firewalls. It can also set quality of service on a per-user basis and log user activities into an SQL database. Furthermore, it can use multiple external authentication sources via PAM and be the key of a Single Sign On solution.

最後更新: 2013-11-27 22:28


The Userspace Logging Daemon (ulogd) is a flexible framework for extensive logging of packets on a firewall machine. ulogd uses the ULOG target of iptables/netfilter, the packet filtering framework of Linux 2.4 and 2.6. It supports binary plugins for adding packet interpreters and output-targets (e.g., for logging into databases, user-defined filetypes, etc.).

最後更新: 2007-08-22 06:36


SmoothWall Express is a network firewall, designed
with home and small business users in mind. It is
based upon a security-hardened subset of the
GNU/Linux operating system and is completely free
to use, download, and distribute. SmoothWall
Express offers facilities and features normally
only seen in expensive commercial offerings.

最後更新: 2011-03-17 04:37



最後更新: 2014-06-03 08:32


AMaViS (A Mail Virus Scanner) scans e-mail
attachments for viruses using third-party virus
scanners available for UNIX environments. It
resides on a UNIX (Linux) machine and looks
through the attached files arriving via e-mail,
generates reports when a virus is found and sets
the delivery on hold.

最後更新: 2011-07-17 19:37


ferm is a tool to maintain and setup complicated firewall rules. It allows one to reduce the tedious task of carefully inserting rules and chains, thus enabling the firewall administrator to spend more time on developing good rules, and less time on the proper implementation of those rules. These rules will be executed by the preferred kernel interface, such as ipchains and iptables, and in one pass. Firewall rules can also be split into different files and loaded at will.

最後更新: 2014-04-14 13:17


nftables aims to replace the existing {ip,ip6,arp,eb}tables framework. It provides a new packet filtering framework, a new userspace utility, and a compatibility layer for {ip,ip6}tables. nftables is built upon the building blocks of the Netfilter infrastructure such as the existing hooks, the connection tracking system, the userspace queueing component, and the logging subsystem.

最後更新: 2004-08-23 05:33

Linux FreeS/WAN

Linux FreeS/WAN provides IPSEC (IP Security, which is both encryption and authentication) kernel extensions and an IKE (Internet Key Exchange, keying and encrypted routing daemon) as well as various rc scripts and documentation. It is known to interoperate with other IPSEC and IKE system already deployed by other vendors such as OpenBSD, Cisco, or CheckPoint. It also features Opportunistic Encryption, subnet extrusion, and with the appropriate patches interops nicely with Microsoft Windows XP/2000 using X.509 certificates.

