<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
             
  <meta http-equiv="Content-Language" content="en-us">
             
  <meta http-equiv="Content-Type"
 content="text/html; charset=windows-1252">
             
  <meta name="GENERATOR" content="Microsoft FrontPage 5.0">
             
  <meta name="ProgId" content="FrontPage.Editor.Document">
  <title>Shorewall Features</title>
</head>
  <body>
        
<table border="0" cellpadding="0" cellspacing="0"
 style="border-collapse: collapse;" bordercolor="#111111" width="100%"
 id="AutoNumber1" bgcolor="#400169" height="90">
      <tbody>
       <tr>
        <td width="100%">                          
      <h1 align="center"><font color="#ffffff">Shorewall Features</font></h1>
        </td>
      </tr>
             
  </tbody>   
</table>
       
<ul>
      <li>Uses Netfilter's connection tracking facilities for stateful packet 
    filtering.</li>
      <li>Can be used in a <b> wide range of router/firewall/gateway applications</b>.
                   
    <ul>
        <li>Completely customizable using configuration files.</li>
        <li>No limit on the number of network interfaces.</li>
        <li>Allows you to partitions the network into <i><a
 href="Documentation.htm#Zones">zones</a></i>         and gives you complete 
 control over the connections permitted between         each pair of zones.</li>
        <li>Multiple interfaces per zone and multiple zones per interface 
        permitted.</li>
        <li>Supports nested and overlapping zones.</li>
                     
    </ul>
      </li>
      <li> <a href="shorewall_quickstart_guide.htm">QuickStart Guides (HOWTOs)</a> 
to  help    get your first firewall up and running quickly</li>
  <li>A <b>GUI</b> is available via Webmin 1.060 and later (<a
 href="http://www.webmin.com">http://www.webmin.com</a>)<br>
  </li>
      <li>Extensive <b> <a
 href="shorewall_quickstart_guide.htm#Documentation">documentation</a>   
  </b>   included in the .tgz and .rpm downloads.</li>
      <li><b>Flexible address management/routing support</b> (and you can 
use  all     types in the same firewall):                  
    <ul>
        <li><a href="Documentation.htm#Masq">Masquerading/SNAT</a></li>
        <li><a href="Documentation.htm#PortForward">Port Forwarding (DNAT)</a>.</li>
        <li><a href="Documentation.htm#NAT">     Static NAT</a>.</li>
        <li><a href="Documentation.htm#ProxyArp">     Proxy ARP</a>.</li>
        <li>Simple host/subnet Routing</li>
                     
    </ul>
      </li>
      <li><a href="blacklisting_support.htm"><b>Blacklisting</b></a> of individual
      IP addresses and subnetworks is supported.</li>
      <li><b><a href="starting_and_stopping_shorewall.htm">Operational support</a></b>:
                   
    <ul>
        <li>Commands to start, stop and clear the firewall</li>
        <li>Supports status             monitoring      with an audible alarm 
 when an             "interesting" packet is detected.</li>
        <li>Wide variety of informational commands.</li>
                     
    </ul>
      </li>
      <li><b>VPN Support</b>                  
    <ul>
        <li><a href="Documentation.htm#Tunnels">IPSEC, GRE,� IPIP     and 
OpenVPN Tunnels</a>.</li>
        <li><a href="PPTP.htm">PPTP </a> clients and Servers.</li>
                     
    </ul>
      </li>
      <li>Support for <a href="traffic_shaping.htm"><b>Traffic Control/Shaping</b></a>
      integration.</li>
      <li>Wide support for different <b>GNU/Linux Distributions</b>.    
             
    <ul>
        <li><a href="Install.htm#Install_RPM"><b>RPM</b></a> and <a
 href="http://security.dsi.unimi.it/%7Elorenzo/debian.html"><b>Debian</b></a>
          packages available.</li>
        <li>Includes <a href="Install.htm"><b>automated install, upgrade, 
fallback          and uninstall facilities</b></a> for users who can't use 
or choose  not         to use the RPM or Debian packages.</li>
        <li>Included as a standard part of<b> <a
 href="http://leaf.sourceforge.net/devel/jnilo">     LEAF/Bering</a> </b>(router/firewall
 on a floppy, CD or compact flash).</li>
                     
    </ul>
     </li>
     <li><a href="MAC_Validation.html">Media Access Control (<b>MAC</b>)
Address      <b>Verification</b><br>
       </a><br>
      </li>
       
</ul>
       
<p><font size="2">Last updated 2/5/2003 - <a href="support.htm">Tom Eastep</a></font></p>
       
<p align="left"><font face="Trebuchet MS"><a href="copyright.htm"> <font
 size="2">Copyright</font> � <font size="2">2001-2003 Thomas M. Eastep.</font></a></font><br>
  </p>
  <br>
 <br>
</body>
</html>