Ferm is a tool for maintaining and installing complex firewall rules. It allows you to reduce the monotonous task of embedding rules and chains, allowing the firewall administrator to spend more time developing good rules and reducing the appropriate implementation time for these rules. These rules will be the preferred kernel interfaces executed, like IPChains and iptables. Firewall rules can also be split into different files and loaded.
Ferm 2.1 This version can better support the ipv4/http://www.aliyun.com/zixun/aggregation/9485.html ">ipv6 blending rules, the detailed update log is as follows:
-new functions @basename, @dirname, @ipfilter
-add Automatic variables $FILENAME, $LINE
-updated NetFilter Modules:
* Pkg-type:support Negation
* Set: "--match set" support for newer iptables
-updated ebtables Support:
* Use Per-protocol Options
* Add support for-p ARP--arp-gratuitous
* Support Abbreviations in arguments
* Add support for matching IPV6
* Add support for "among" match
* Add support for the "limit" match
-honor--noflush in fast mode
-discard previous specifications when @if fails
-use the--domain argument as the default domain
-keep track of line numbers within custom function calls
Download Address: http://ferm.foo-projects.org/download/2.1/ferm-2.1.tar.gz