Skip to content

About

Firewall plugin for Ervisio: ufw, firewalld, nftables and iptables rules, firewall logs, fail2ban bans and an SSH guard

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

Firewall, an Ervisio plugin

Manage the firewall of a Linux server from Ervisio: ufw, firewalld, nftables and iptables, plus fail2ban bans. Built with Ervisio/plugin-sdk 0.2; needs Ervisio 0.5.0 or later.

Page What it does
Overview Which firewalls are installed and running, whether SSH stays reachable, the ports programs listen on and whether the firewall lets them in.
Rules The rules of the managed firewall: add, delete (one or many), turn the firewall on and off, default policies. ufw: logging level, application profiles. firewalld: zones, services, ports, sources, rich rules, port forwards, masquerading, runtime or permanent view, reload. nftables: tables, base and regular chains, policies, rules by handle. iptables: IPv4 and IPv6, every table, chain policies.
Logs The packets the firewall logged (kernel journal or a syslog file): counts, a timeline, most blocked addresses and most hit ports, filters, live view, CSV export, "Block" on any address.
Bans fail2ban jails with their banned addresses; ban and unban.
Activity The changes made through the plugin, from Ervisio's activity log.
Settings The managed firewall, the SSH guard, how changes are applied and saved, the log source and a background check.

A dashboard widget shows the firewall state without asking for administrator rights.

Safety

  • SSH guard (on by default). The plugin refuses a new rule, a deletion, a default policy or a new nftables chain that would close the SSH port for every address. It follows jumps between chains, so the rules ufw keeps in ufw-user-input count when you look at iptables. The port is the one sshd listens on, or the one set in Settings.
  • Confirm by typing to turn a firewall off or delete an nftables table.
  • Command preview. The rule dialog shows the exact commands Ervisio will run.
  • Tables and chains written by other tools (ufw, firewalld, Docker, fail2ban, Kubernetes) are marked, folded away and left out of the rule dialog.

How it talks to the system

Everything goes through the 47 commands declared in plugin/manifest.json, generated by scripts/gen-manifest.mjs. The daemon checks every argument against a regular expression that matches the whole value: actions, addresses, ports, zones, chain names, file paths. No user input reaches a shell: the few sh -c scripts are fixed text and read only positional parameters from an enumerated list (ufw, iptables, /etc/nftables.conf...). Commands that change the firewall are admin: Ervisio asks for administrator rights when you need them. Log commands are adminUnlessGroup: "adm", so members of adm read logs as themselves.

Area Commands
Detection detect (versions, systemd units, ufw.conf, time zone; no admin), listening (ss -tulnp), state
ufw ufw-status, ufw-enable, ufw-disable, ufw-reload, ufw-default, ufw-logging, ufw-delete, ufw-apps, 8 rule forms (port, port for TCP and UDP, addresses, profile, with interface, before the others)
firewalld fwd-info, fwd-change, fwd-rich, fwd-forward (each runtime or --permanent), fwd-default-zone, fwd-reload, fwd-persist, fwd-log-denied
nftables nft-list, nft-rule, nft-delete-rule, nft-table, nft-chain, nft-base-chain, nft-policy, nft-save
iptables ipt-list, ipt-port, ipt-host, ipt-delete, ipt-policy, ipt-save (one command for iptables and ip6tables)
fail2ban f2b-status, f2b-set
Logs log-journal, log-journal-follow, log-file, log-file-follow

Settings live in ~/.config/ervisio/plugins/firewall/settings.json. The background check is a job (watchdog) that runs state and sends a notification when the result changes; it reads the firewall as root, so an administrator approves it once in Settings › Plugin jobs.

Build

npm install
npm test          # parsers, translations, SSH guard, strings
npm run build     # manifest check, typecheck, bundle to dist/firewall/, copy plugin/*
npm run pack      # dist/firewall-<version>.tar.gz and .sha256

Load dist/firewall from Ervisio › Plugins › Developer (developer mode on). After changing a command, run npm run manifest and commit the new plugin/manifest.json.

Testing against real firewalls

test/integration.test.ts runs the translated commands against real firewalls in Docker containers, through the manifest argv as the daemon would:

docker run -d --privileged --name fwtest ubuntu:24.04 sleep infinity
docker exec fwtest bash -c 'apt-get update && apt-get install -y ufw nftables iptables fail2ban iproute2'
FW_UBUNTU=fwtest npm test

For firewalld, a Fedora container with dbus-daemon and firewalld --nofork (set IPv6_rpfilter=no and NftablesTableOwner=no in /etc/firewalld/firewalld.conf inside Docker Desktop), then FW_FEDORA=<name>. node scripts/try.mjs <container> <command> [args...] runs a single manifest command the same way.

License

MIT, see LICENSE.

About

Firewall plugin for Ervisio: ufw, firewalld, nftables and iptables rules, firewall logs, fail2ban bans and an SSH guard

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages