GitHub ↗

The idea

A firewall you edit over the network can lock you out of the machine you are editing it on. easywall makes that recoverable by default.

State machine: editing leads to Staged, applying leads to Live, confirming within the window leads to Confirmed, and letting the window expire leads to Rolled back, from where the staged edits are still available. State machine: editing leads to Staged, applying leads to Live, confirming within the window leads to Confirmed, and letting the window expire leads to Rolled back, from where the staged edits are still available.

Editing changes nothing. Applying changes everything — for 120 seconds. Not confirming — whether by choice or because you can no longer reach the page — is what brings the old rules back.

What it is made of

   
Two processes the web interface runs unprivileged and has no path to the kernel
netlink, not a shell rules are Go structs, so there is no command line to inject into
Three rule sets Staged, Current, Backup — editing and enforcing are separate
Audit log every change records what moved and when, in one JSON object per line
Coexists with Docker easywall owns table inet easywall and touches nothing else
English, Deutsch, Français switchable in the interface, including before you sign in — and a partial translation renders English for what it is missing

How it works →

The order rules are evaluated

The one thing worth knowing before you write a rule. An allowlisted address reaches every port; a blocklisted one is dropped before the allowlist is ever consulted.

Decision flow for an incoming packet: the fragment drop first, when it is on; then loopback, the IPv6 mode, ping and reset rate limits, established connections and neighbour discovery, the other protection modules, Docker bridge networks, blocklist, allowlist, the feeds you switched on, pings when answered, open ports, custom rules, chain policy drops. Decision flow for an incoming packet: the fragment drop first, when it is on; then loopback, the IPv6 mode, ping and reset rate limits, established connections and neighbour discovery, the other protection modules, Docker bridge networks, blocklist, allowlist, the feeds you switched on, pings when answered, open ports, custom rules, chain policy drops.

Where to start

You want to Go to
Install on Debian or Ubuntu — amd64 or arm64 .deb package
Run it in a container Docker
Build from source Manual install
Try it without installing anything Live demo · Demo mode
Know what the setup page is asking First run
Put rules into the kernel, safely Applying rules
Understand the design Architecture · Security
See what is planned Roadmap
Contribute or ask Contributing · Discord