<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <meta http-equiv="Content-Language" content="en-us"> <meta http-equiv="Content-Type" content="text/html; charset=windows-1252"> <meta name="GENERATOR" content="Microsoft FrontPage 5.0"> <meta name="ProgId" content="FrontPage.Editor.Document"> <title>Shorewall Features</title> </head> <body> <table border="0" cellpadding="0" cellspacing="0" style="border-collapse: collapse;" bordercolor="#111111" width="100%" id="AutoNumber1" bgcolor="#3366ff" height="90"> <tbody> <tr> <td width="100%"> <h1 align="center"><font color="#ffffff">Shorewall Features</font></h1> </td> </tr> </tbody> </table> <ul> <li>Uses Netfilter's connection tracking facilities for stateful packet filtering.</li> <li>Can be used in a <b> wide range of router/firewall/gateway applications</b>. <ul> <li>Completely customizable using configuration files.</li> <li>No limit on the number of network interfaces.</li> <li>Allows you to partitions the network into <i><a href="Documentation.htm#Zones">zones</a></i> and gives you complete control over the connections permitted between each pair of zones.</li> <li>Multiple interfaces per zone and multiple zones per interface permitted.</li> <li>Supports nested and overlapping zones.</li> </ul> </li> <li> <a href="shorewall_quickstart_guide.htm">QuickStart Guides (HOWTOs)</a> to help get your first firewall up and running quickly</li> <li>A <b>GUI</b> is available via Webmin 1.060 and later (<a href="http://www.webmin.com">http://www.webmin.com</a>)<br> </li> <li>Extensive <b> <a href="shorewall_quickstart_guide.htm#Documentation">documentation</a> </b> included in the .tgz and .rpm downloads.</li> <li><b>Flexible address management/routing support</b> (and you can use all types in the same firewall): <ul> <li><a href="Documentation.htm#Masq">Masquerading/SNAT</a></li> <li><a href="Documentation.htm#PortForward">Port Forwarding (DNAT)</a>.</li> <li><a href="Documentation.htm#NAT"> Static NAT</a>.</li> <li><a href="Documentation.htm#ProxyArp"> Proxy ARP</a>.</li> <li>Simple host/subnet Routing</li> </ul> </li> <li><a href="blacklisting_support.htm"><b>Blacklisting</b></a> of individual IP addresses and subnetworks is supported.</li> <li><b><a href="starting_and_stopping_shorewall.htm">Operational support</a></b>: <ul> <li>Commands to start, stop and clear the firewall</li> <li>Supports status monitoring with an audible alarm when an "interesting" packet is detected.</li> <li>Wide variety of informational commands.</li> </ul> </li> <li><b>VPN Support</b> <ul> <li><a href="Documentation.htm#Tunnels">IPSEC, GRE,� IPIP and OpenVPN Tunnels</a>.</li> <li><a href="PPTP.htm">PPTP </a> clients and Servers.</li> </ul> </li> <li>Support for <a href="traffic_shaping.htm"><b>Traffic Control/Shaping</b></a> integration.</li> <li>Wide support for different <b>GNU/Linux Distributions</b>. <ul> <li><a href="Install.htm#Install_RPM"><b>RPM</b></a> and <a href="http://security.dsi.unimi.it/%7Elorenzo/debian.html"><b>Debian</b></a> packages available.</li> <li>Includes <a href="Install.htm"><b>automated install, upgrade, fallback and uninstall facilities</b></a> for users who can't use or choose not to use the RPM or Debian packages.</li> <li>Included as a standard part of<b> <a href="http://leaf.sourceforge.net/devel/jnilo"> LEAF/Bering</a> </b>(router/firewall on a floppy, CD or compact flash).</li> </ul> </li> <li><a href="MAC_Validation.html">Media Access Control (<b>MAC</b>) Address <b>Verification</b><br> </a><br> </li> </ul> <p><font size="2">Last updated 2/5/2003 - <a href="support.htm">Tom Eastep</a></font></p> <p align="left"><font face="Trebuchet MS"><a href="copyright.htm"> <font size="2">Copyright</font> � <font size="2">2001-2003 Thomas M. Eastep.</font></a></font><br> </p> <br> <br> <br> </body> </html>