awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoServidor MCPAcerca deCómo clasificamosPrensa
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

9 repositorios

Awesome GitHub RepositoriesFirewall Management

Tools for configuring network-level access restrictions and traffic filtering.

Distinguishing note: Focuses on IP-based traffic blocking for server protection.

Explore 9 awesome GitHub repositories matching security & cryptography · Firewall Management. Refine with filters or upvote what's useful.

Awesome Firewall Management GitHub Repositories

Encuentra los mejores repositorios con IA.Buscaremos los repositorios que mejor coincidan usando IA.
  • mastodon/mastodonAvatar de mastodon

    mastodon/mastodon

    50,053Ver en GitHub↗

    Mastodon is a self-hosted, decentralized social networking platform that functions as a microblogging application. It enables independent server instances to communicate and exchange social data through the standardized ActivityPub protocol, allowing users to participate in a global, interoperable network. The platform distinguishes itself through its federated architecture, which grants administrators full control over their community instances. This includes comprehensive tools for user moderation, account management, and the enforcement of community guidelines. The system is designed to ha

    Configures system-level firewall rules to drop incoming traffic from specific IP addresses.

    Rubyactivity-streamactivitypubdocker
    Ver en GitHub↗50,053
  • fail2ban/fail2banAvatar de fail2ban

    fail2ban/fail2ban

    17,993Ver en GitHub↗

    Fail2ban is an intrusion prevention system that monitors system log files to detect malicious activity and automatically enforce security policies. By parsing log data in real time, the tool identifies patterns of unauthorized access or repeated authentication failures and responds by dynamically updating network access control lists to restrict offending sources. The software functions as a firewall automation tool that maintains stateful tracking of suspicious behavior across various network services. It utilizes a regex-driven pattern matching engine to identify specific attack signatures,

    Automates firewall management by dynamically banning hosts that exceed defined thresholds for suspicious behavior.

    Pythonanti-botattack-preventionban-hosts
    Ver en GitHub↗17,993
  • stamparm/maltrailAvatar de stamparm

    stamparm/maltrail

    8,498Ver en GitHub↗

    Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o

    Exports filtered lists of attacker source IPs for integration with external blocking tools and firewalls.

    Pythonattack-detectionintrusion-detectionmalware
    Ver en GitHub↗8,498
  • henrypp/simplewallAvatar de henrypp

    henrypp/simplewall

    8,044Ver en GitHub↗

    Simplewall is an application firewall manager and network traffic filter that provides a graphical interface for the Windows Filtering Platform. It controls inbound and outbound network access for individual programs and services by intercepting and filtering traffic at the kernel level. The project identifies specific binaries using file hashes to prevent spoofing and allows users to define custom firewall rules based on IP addresses, CIDR ranges, and port numbers. It includes a system for blocking operating system telemetry and managing blocklists of known malicious IP addresses. The tool

    Controls inbound and outbound network access for individual programs based on file paths and hashes.

    Carm64firewallfoss
    Ver en GitHub↗8,044
  • celzero/rethink-appAvatar de celzero

    celzero/rethink-app

    4,580Ver en GitHub↗

    This project is a network security tool providing an application network firewall, a DNS blocklist manager, and a VPN client with multi-hop capabilities. It functions as a traffic controller that allows or blocks internet access for specific applications on a device. The system distinguishes itself through a DNS-over-HTTPS firewall and traffic obfuscation tools that inject random packets to mask communication patterns and bypass regional internet censorship. It utilizes multi-hop routing to hide the origin of network traffic by chaining connections through multiple remote servers. The softwa

    Provides an application network firewall to block or allow internet access for specific apps.

    Kotlinandroidandroid-appandroid-application
    Ver en GitHub↗4,580
  • opnsense/coreAvatar de opnsense

    opnsense/core

    4,493Ver en GitHub↗

    This project is the core management framework for a security appliance, providing the primary infrastructure for firewall management, network intrusion prevention, and high-availability networking. It serves as the centralized system for controlling network security policies, filtering traffic, and administering a security appliance dashboard. The system is distinguished by its high-availability capabilities, which include synchronizing configurations and connection state tables across redundant nodes to enable automatic hardware failover. It also features a modular plugin architecture for ex

    Provides a centralized system for configuring network-level access restrictions, traffic filtering, and firewall rule management.

    PHPapibsdcaptive-portal
    Ver en GitHub↗4,493
  • firehol/blocklist-ipsetsAvatar de firehol

    firehol/blocklist-ipsets

    3,850Ver en GitHub↗

    This project is a security utility for aggregating threat intelligence and automating the deployment of high-performance firewall rules. It functions as an aggregator that fetches and normalizes malicious IP address lists from multiple external security feeds and a management tool that deploys these lists into the Linux kernel using ipset for packet filtering. The system maintains network perimeter defense by using atomic kernel updates to swap IP sets, which allows firewall rules to be updated without interrupting active connections. It includes a range optimizer that simplifies network addr

    Automates the deployment of curated IP blocklists into the Linux kernel using ipset for high-performance filtering.

    Shellabusesattacksblocklists
    Ver en GitHub↗3,850
  • openziti/zitiAvatar de openziti

    openziti/ziti

    3,883Ver en GitHub↗

    Ziti is a zero-trust network overlay and identity-based mesh network. It provides a software-defined perimeter that replaces traditional IP-based routing and VPNs by mapping network services to cryptographically verified identities, effectively cloaking applications from the public internet. The project distinguishes itself through an outbound-only connection model that eliminates open listening ports and a Zero Trust SDK that allows developers to embed encryption and identity-based access control directly into application source code. It also provides transparent tunneling proxies to extend

    Provides an SDK-based approach for encrypted traffic and identity integration without requiring host-level agents.

    Goappsecgolangmesh
    Ver en GitHub↗3,883
  • serverless-dns/serverless-dnsAvatar de serverless-dns

    serverless-dns/serverless-dns

    3,704Ver en GitHub↗

    This project is a serverless DNS resolver and DNS over HTTPS gateway that translates domain names into IP addresses. It functions as an edge computing DNS filter designed to encrypt queries, prevent tampering, and improve user privacy on browsers and mobile devices. The system distinguishes itself by operating as an edge DNS traffic monitor that logs and analyzes request patterns in real time. It utilizes curated blocklists at the network edge to block malicious domains and trackers. The software provides capabilities for private DNS filtering, network traffic monitoring, and the management

    Provides firewall-like control to block or allow internet access on a per-application basis.

    JavaScriptadblockcloudflarecloudflare-workers
    Ver en GitHub↗3,704
  1. Home
  2. Security & Cryptography
  3. Firewall Management

Explorar subetiquetas

  • Application-Level Access Controls1 sub-etiquetaFirewall rules that restrict internet access based on the originating application process. **Distinct from Firewall Management:** Distinct from Firewall Management: focuses on per-app process identity rather than IP-based server protection.
  • IPSet ManagersTools for downloading and normalizing threat intelligence to update kernel-level IP sets for real-time filtering. **Distinct from Firewall Management:** Distinct from Firewall Management: focuses specifically on IPSet-based blocklist management.