Security

Shorewall – gateway/firewall configuration tool

The Shoreline Firewall, more commonly known as “Shorewall”, is an open source firewall tool that builds upon the Netfilter (iptables/ipchains) system built into the Linux kernel, making it easier to manage more complex configuration schemes.

Shorewall reads configuration files and with the help of the iptables utility, Shorewall then configures Netfilter to match your requirements.

Once Shorewall has configured the Linux networking subsystem, its job is complete and there is no Shorewall process left running on your system.

Key Features

  • Uses Netfilter’s connection tracking facilities for stateful packet filtering.
  • Can be used in a wide range of router/firewall/gateway applications:
    • Completely customizable using configuration files.
    • No limit on the number of network interfaces.
    • Allows you to partition the network into zones and gives you complete control over the connections permitted between each pair of zones.
    • Multiple interfaces per zone and multiple zones per interface permitted.
    • Supports nested and overlapping zones.
  • A Graphical User Iinterface is available via Webmin 1.060 and later.
  • Extensive documentation is available in both Docbook XML and HTML formats.
  • Flexible address management/routing support (and you can use all types in the same firewall):
    • Masquerading/SNAT.
    • Port Forwarding (DNAT).
    • One-to-one NAT.
    • Proxy ARP.
    • NETMAP (requires a 2.6 kernel or a patched 2.4 kernel).
    • Multiple ISP support.
  • Blacklisting of individual IP addresses and subnetworks is supported.
  • Operational Support:
    • Commands to start, stop and clear the firewall.
    • Supports status monitoring with an audible alarm when an “interesting” packet is detected.
    • Wide variety of informational commands.
  • VPN Support
    • IPSEC, GRE, IPIP and OpenVPN Tunnels.
    • PPTP clients and Servers.
  • Support for Traffic Control/Shaping.
  • Media Access Control (MAC) Address Verification.
  • Traffic Accounting.
  • Bridge/Firewall support.

Website: shorewall.org
Support: QuickStart Guides
Developer: Thomas M. Eastep
License: GNU General Public License v2.0

Shorewall is written in Perl. Learn Perl with our recommended free books and free tutorials.


Related Software

Firewalls
OpenSnitchInteractive application firewall
nftablesProvides a new in-kernel packet classification framework
FirewalldDynamically managed firewall with support for network/firewall zones
PortmasterApplication firewall that does the heavy lifting
iptablesConfigure the Linux 2.4.x and later packet filtering ruleset
ufwUncomplicated Firewall. This is software for managing a netfilter firewall
ShorewallHigh-level tool for configuring Netfilter
gufwEasy, intuitive, way to manage your Linux firewall
VuurmuurUncomplicated Firewall, manage a netfilter firewall
awallFirewall configuration tool, providing various benefits over plain iptables
FoomuuriMultizone bidirectional nftables firewall
bgpipeBGP reverse proxy and firewall

Read our verdict in the software roundup.


Best Free and Open Source Software Explore our comprehensive directory of recommended free and open source software. Our carefully curated collection spans every major software category.

This directory is part of our ongoing series of informative articles for Linux enthusiasts. It features hundreds of detailed reviews, along with open source alternatives to proprietary solutions from major corporations such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk.

You’ll also find interesting projects to try, hardware coverage, free programming books and tutorials, and much more.

Know a useful open source Linux program that we haven’t covered yet? Let us know by completing this form.
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments