Alternatives to UFW

Linux Kernel, Network, and Services configuration.
Post Reply
Message
Author
DebianFox
Posts: 149
Joined: 2024-05-05 14:11
Has thanked: 20 times
Been thanked: 8 times

Alternatives to UFW

#1 Post by DebianFox »

Are there any good alternatives to ufw and its graphical counterpart, gufw? If so can you please give me the details? Have you used them? How good are they?

User avatar
Diesel330
Posts: 190
Joined: 2021-11-08 19:57
Location: Eastern Europe
Has thanked: 39 times
Been thanked: 24 times

Re: Alternatives to UFW

#2 Post by Diesel330 »

What's the problem with gufw? If you have any issues tell us because we using it

User avatar
Uptorn
Posts: 341
Joined: 2022-01-22 01:07
Has thanked: 280 times
Been thanked: 92 times

Re: Alternatives to UFW

#3 Post by Uptorn »

I will always recommend OpenSnitch. It is the kind of firewall that is more intuitive to the way that end-devices get used. Each application that initiates network traffic has to be approved on-access and per-application basis.

Newer versions implement inbound blocking like gufw, but that hasn't found its way into Debian yet.

DebianFox
Posts: 149
Joined: 2024-05-05 14:11
Has thanked: 20 times
Been thanked: 8 times

Re: Alternatives to UFW

#4 Post by DebianFox »

Diesel330 wrote: 2024-08-08 11:01 What's the problem with gufw? If you have any issues tell us because we using it
I do not have a problem with UFW and GUFW. For normal non-techie users they are decent enough. I wanted to evaluate whether there are some alternatives which are more powerful than UFW. Also UFW depends on IPTables. I wanted to know if there is an equivalent of UFW+GUFW which uses nftables instead of IPTables. I also would like to configure Firewall access on per application access. For example allow browser, DPKG/APT, rsyslogd to access the internet but not other applications and packages. I need to configure that as a rule.

Nothing against iptables or gufw or ufw.

DebianFox
Posts: 149
Joined: 2024-05-05 14:11
Has thanked: 20 times
Been thanked: 8 times

Re: Alternatives to UFW

#5 Post by DebianFox »

Uptorn wrote: 2024-08-09 03:22 I will always recommend OpenSnitch. It is the kind of firewall that is more intuitive to the way that end-devices get used. Each application that initiates network traffic has to be approved on-access and per-application basis.

Newer versions implement inbound blocking like gufw, but that hasn't found its way into Debian yet.
Thanks @Uptorn. OpenSnitch sounds promising. Does it use iptables of nftables? And to install it do we have to compile it from a source code? OR do we have to install it from its own repository, i.e. add its repository into the sources files of dpkg?

User avatar
Uptorn
Posts: 341
Joined: 2022-01-22 01:07
Has thanked: 280 times
Been thanked: 92 times

Re: Alternatives to UFW

#6 Post by Uptorn »

DebianFox wrote: 2024-08-09 08:29 Thanks @Uptorn. OpenSnitch sounds promising. Does it use iptables of nftables? And to install it do we have to compile it from a source code? OR do we have to install it from its own repository, i.e. add its repository into the sources files of dpkg?
It uses nftables and is already available in the Debian repository.

DebianFox
Posts: 149
Joined: 2024-05-05 14:11
Has thanked: 20 times
Been thanked: 8 times

Re: Alternatives to UFW

#7 Post by DebianFox »

Any suggestion? apart from OpenSnitch and firewalld?

Post Reply