Manage the firewall of a Linux server from Ervisio: ufw, firewalld, nftables and iptables, plus fail2ban bans. Built with Ervisio/plugin-sdk 0.2; needs Ervisio 0.5.0 or later.
| Page | What it does |
|---|---|
| Overview | Which firewalls are installed and running, whether SSH stays reachable, the ports programs listen on and whether the firewall lets them in. |
| Rules | The rules of the managed firewall: add, delete (one or many), turn the firewall on and off, default policies. ufw: logging level, application profiles. firewalld: zones, services, ports, sources, rich rules, port forwards, masquerading, runtime or permanent view, reload. nftables: tables, base and regular chains, policies, rules by handle. iptables: IPv4 and IPv6, every table, chain policies. |
| Logs | The packets the firewall logged (kernel journal or a syslog file): counts, a timeline, most blocked addresses and most hit ports, filters, live view, CSV export, "Block" on any address. |
| Bans | fail2ban jails with their banned addresses; ban and unban. |
| Activity | The changes made through the plugin, from Ervisio's activity log. |
| Settings | The managed firewall, the SSH guard, how changes are applied and saved, the log source and a background check. |
A dashboard widget shows the firewall state without asking for administrator rights.
- SSH guard (on by default). The plugin refuses a new rule, a deletion, a default policy or a new nftables chain
that would close the SSH port for every address. It follows jumps between chains, so the rules ufw keeps in
ufw-user-inputcount when you look at iptables. The port is the one sshd listens on, or the one set in Settings. - Confirm by typing to turn a firewall off or delete an nftables table.
- Command preview. The rule dialog shows the exact commands Ervisio will run.
- Tables and chains written by other tools (ufw, firewalld, Docker, fail2ban, Kubernetes) are marked, folded away and left out of the rule dialog.
Everything goes through the 47 commands declared in plugin/manifest.json, generated by
scripts/gen-manifest.mjs. The daemon checks every argument against a regular expression
that matches the whole value: actions, addresses, ports, zones, chain names, file paths. No user input reaches a shell:
the few sh -c scripts are fixed text and read only positional parameters from an enumerated list (ufw, iptables,
/etc/nftables.conf...). Commands that change the firewall are admin: Ervisio asks for administrator rights when you
need them. Log commands are adminUnlessGroup: "adm", so members of adm read logs as themselves.
| Area | Commands |
|---|---|
| Detection | detect (versions, systemd units, ufw.conf, time zone; no admin), listening (ss -tulnp), state |
| ufw | ufw-status, ufw-enable, ufw-disable, ufw-reload, ufw-default, ufw-logging, ufw-delete, ufw-apps, 8 rule forms (port, port for TCP and UDP, addresses, profile, with interface, before the others) |
| firewalld | fwd-info, fwd-change, fwd-rich, fwd-forward (each runtime or --permanent), fwd-default-zone, fwd-reload, fwd-persist, fwd-log-denied |
| nftables | nft-list, nft-rule, nft-delete-rule, nft-table, nft-chain, nft-base-chain, nft-policy, nft-save |
| iptables | ipt-list, ipt-port, ipt-host, ipt-delete, ipt-policy, ipt-save (one command for iptables and ip6tables) |
| fail2ban | f2b-status, f2b-set |
| Logs | log-journal, log-journal-follow, log-file, log-file-follow |
Settings live in ~/.config/ervisio/plugins/firewall/settings.json. The background check is a job (watchdog) that
runs state and sends a notification when the result changes; it reads the firewall as root, so an administrator
approves it once in Settings › Plugin jobs.
npm install
npm test # parsers, translations, SSH guard, strings
npm run build # manifest check, typecheck, bundle to dist/firewall/, copy plugin/*
npm run pack # dist/firewall-<version>.tar.gz and .sha256Load dist/firewall from Ervisio › Plugins › Developer (developer mode on). After changing a command, run
npm run manifest and commit the new plugin/manifest.json.
test/integration.test.ts runs the translated commands against real firewalls in Docker containers, through the
manifest argv as the daemon would:
docker run -d --privileged --name fwtest ubuntu:24.04 sleep infinity
docker exec fwtest bash -c 'apt-get update && apt-get install -y ufw nftables iptables fail2ban iproute2'
FW_UBUNTU=fwtest npm testFor firewalld, a Fedora container with dbus-daemon and firewalld --nofork (set IPv6_rpfilter=no and
NftablesTableOwner=no in /etc/firewalld/firewalld.conf inside Docker Desktop), then FW_FEDORA=<name>.
node scripts/try.mjs <container> <command> [args...] runs a single manifest command the same way.
MIT, see LICENSE.