Jump to content

Shorewall

From Wikipedia, the free encyclopedia

This is an old revision of this page, as edited by 194.126.21.12 (talk) at 10:05, 19 October 2014. The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

Shorewall
Developer(s)Thomas M. Eastep
Stable release
4.6.4.2[1] / October 18, 2014; 10 years ago (2014-10-18)[2]
Written inPerl
Operating systemLinux
Available inEnglish
LicenseGPLv2+[3]
WebsiteShorewall Homepage

Shorewall (more appropriately the Shoreline Firewall) is an open source firewall tool for Linux that builds upon the Netfilter (iptables/ipchains) system built into the Linux kernel, making it easier to manage more complex configuration schemes by providing a higher level of abstraction for describing rules using text files.

Configuration

It is not a daemon since it does not run continuously, but rather configures rules in the kernel that allow and disallow traffic through the system. Shorewall is configured through a group of plain-text configuration files and does not have a graphical user interface, though a Webmin module is available separately. A monitoring utility packaged with Shorewall can be used to watch the status of the system as it operates and assist in testing.

Use

Shorewall is mainly used in network installations[citation needed] (as opposed to a personal computer firewall), since most of its strength lies in its ability to work with "zones"[citation needed], such as the DMZ or a 'net' zone. Each zone would then have different rules, making it easy to have for example relaxed rules on the company intranet, yet clamp down on traffic coming in from the Internet.

The plain-text configuration files are usually well-commented and easy to use, though Shorewall may be more difficult for new users to handle than other firewall systems with graphical front-ends.[citation needed]

Current version

The most recent stable version is 4.6.0. Starting with version 4, Shorewall uses also a Perl-based compiler frontend; previously it used only a shell-based compiler frontend. Also, IPv6 is supported starting in version 4.4.3. From version 4.4.3, Shorewall-shell has been removed and Shorewall-perl has been combined with Shorewall-common [4]

References