 | Can be used in a wide range of router/firewall/gateway applications.
 | Completely customizable using configuration files. |
 | No limit on the number of network interfaces. |
 | Allows you to partitions the network into zones
and gives you complete control over the connections permitted between
each pair of zones. |
 | Multiple interfaces per zone and multiple zones per interface
permitted. |
 | Supports nested and overlapping zones. |
|
 | Parameterized
sample configurations
for easy configuration in common setups.
 | Standalone Linux System |
 | Linux System with two network interfaces (internet and local network) |
 | Linux System with three network interfaces (internet, local network
and DMZ) |
 | All sample configurations provide support for running servers. |
|
 | Extensive documentation |
 | Flexible address management/routing support (and you can use all
types in the same firewall):
|
 | Blacklisting of individual
IP addresses and subnetworks is supported. |
 | Operational support:
 | Commands to start, stop and clear the firewall |
 | Supports status monitoring
with an audible alarm when an "interesting" packet is detected. |
 | Wide variety of informational commands. |
|
 | VPN Support
|
 | Support for Traffic Control/Shaping
integration. |
 | Wide support for different Linux Distributions.
|