fiaif for Debian
FIAIF is an Intelligent Firewall
The Goal of FIAIF is to provide a highly customizable script for setting up an iptables based firewall.
Unlike many other scripts, FIAIF can be truly customized allowing multiple interfaces (or rather zones). There is no limit on the number of zones. All configuration is done through configuration files. No need to understand the script behind it all.
The script makes heavy use of state-full firewalling, and all RELATED and ESTABLISHED packets are accepted on all chains. If you which to block something out, don't accept it in the first place.
The script is written in BASH. Though this is not the optimal program to use, it means that you do not need to install extra interpreters on your firewall. This allows you to have a minimalistic installation on your firewall.The iptables package consists of a set of powerful packet filtering
Beware. The tools can easily be misused, causing enormous amounts of grief by completely cripple network access to a computer system. It is not terribly uncommon for a remote system administrator to accidentally lock themself out of a system hundreds or thousands of miles away. One can even manage to lock himself out of a computer who's keyboard is under his fingers. Please, use due caution.
More documentation and some examples can be found in /usr/share/doc/fiaif/ and at http://www.fiaif.net/.
Anders P. Fugmann <anders@fugmann.net>, Sat, 30 May 2002 20:54:16 -0200
