awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

9 个仓库

Awesome GitHub RepositoriesFirewall Management

Tools for configuring network-level access restrictions and traffic filtering.

Distinguishing note: Focuses on IP-based traffic blocking for server protection.

Explore 9 awesome GitHub repositories matching security & cryptography · Firewall Management. Refine with filters or upvote what's useful.

Awesome Firewall Management GitHub Repositories

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • mastodon/mastodonmastodon 的头像

    mastodon/mastodon

    50,053在 GitHub 上查看↗

    Mastodon is a self-hosted, decentralized social networking platform that functions as a microblogging application. It enables independent server instances to communicate and exchange social data through the standardized ActivityPub protocol, allowing users to participate in a global, interoperable network. The platform distinguishes itself through its federated architecture, which grants administrators full control over their community instances. This includes comprehensive tools for user moderation, account management, and the enforcement of community guidelines. The system is designed to ha

    Configures system-level firewall rules to drop incoming traffic from specific IP addresses.

    Rubyactivity-streamactivitypubdocker
    在 GitHub 上查看↗50,053
  • fail2ban/fail2banfail2ban 的头像

    fail2ban/fail2ban

    17,993在 GitHub 上查看↗

    Fail2ban is an intrusion prevention system that monitors system log files to detect malicious activity and automatically enforce security policies. By parsing log data in real time, the tool identifies patterns of unauthorized access or repeated authentication failures and responds by dynamically updating network access control lists to restrict offending sources. The software functions as a firewall automation tool that maintains stateful tracking of suspicious behavior across various network services. It utilizes a regex-driven pattern matching engine to identify specific attack signatures,

    Automates firewall management by dynamically banning hosts that exceed defined thresholds for suspicious behavior.

    Pythonanti-botattack-preventionban-hosts
    在 GitHub 上查看↗17,993
  • stamparm/maltrailstamparm 的头像

    stamparm/maltrail

    8,498在 GitHub 上查看↗

    Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o

    Exports filtered lists of attacker source IPs for integration with external blocking tools and firewalls.

    Pythonattack-detectionintrusion-detectionmalware
    在 GitHub 上查看↗8,498
  • henrypp/simplewallhenrypp 的头像

    henrypp/simplewall

    8,044在 GitHub 上查看↗

    Simplewall is an application firewall manager and network traffic filter that provides a graphical interface for the Windows Filtering Platform. It controls inbound and outbound network access for individual programs and services by intercepting and filtering traffic at the kernel level. The project identifies specific binaries using file hashes to prevent spoofing and allows users to define custom firewall rules based on IP addresses, CIDR ranges, and port numbers. It includes a system for blocking operating system telemetry and managing blocklists of known malicious IP addresses. The tool

    Controls inbound and outbound network access for individual programs based on file paths and hashes.

    Carm64firewallfoss
    在 GitHub 上查看↗8,044
  • celzero/rethink-appcelzero 的头像

    celzero/rethink-app

    4,580在 GitHub 上查看↗

    This project is a network security tool providing an application network firewall, a DNS blocklist manager, and a VPN client with multi-hop capabilities. It functions as a traffic controller that allows or blocks internet access for specific applications on a device. The system distinguishes itself through a DNS-over-HTTPS firewall and traffic obfuscation tools that inject random packets to mask communication patterns and bypass regional internet censorship. It utilizes multi-hop routing to hide the origin of network traffic by chaining connections through multiple remote servers. The softwa

    Provides an application network firewall to block or allow internet access for specific apps.

    Kotlinandroidandroid-appandroid-application
    在 GitHub 上查看↗4,580
  • opnsense/coreopnsense 的头像

    opnsense/core

    4,493在 GitHub 上查看↗

    该项目是安全设备的核心管理框架,为防火墙管理、网络入侵防御和高可用性网络提供主要基础设施。它作为控制网络安全策略、过滤流量和管理安全设备仪表板的集中式系统。 该系统以其高可用性功能而著称,包括在冗余节点之间同步配置和连接状态表,以实现自动硬件故障转移。它还具有用于扩展后端逻辑和用户界面的模块化插件架构,以及用于防火墙规则和系统设置程序化管理的基于 JSON 的 API。 该平台涵盖了广泛的功能领域,包括 IPv4 和 IPv6 的网络配置、安全 VPN 隧道、强制门户 (captive portal) 管理以及全面的监控和可观测性工具。它进一步集成了具有多因素身份验证的身份管理,并提供了用于配置备份、版本跟踪和跨 x86-64 硬件部署的工具。

    Provides a centralized system for configuring network-level access restrictions, traffic filtering, and firewall rule management.

    PHPapibsdcaptive-portal
    在 GitHub 上查看↗4,493
  • firehol/blocklist-ipsetsfirehol 的头像

    firehol/blocklist-ipsets

    3,850在 GitHub 上查看↗

    This project is a security utility for aggregating threat intelligence and automating the deployment of high-performance firewall rules. It functions as an aggregator that fetches and normalizes malicious IP address lists from multiple external security feeds and a management tool that deploys these lists into the Linux kernel using ipset for packet filtering. The system maintains network perimeter defense by using atomic kernel updates to swap IP sets, which allows firewall rules to be updated without interrupting active connections. It includes a range optimizer that simplifies network addr

    Automates the deployment of curated IP blocklists into the Linux kernel using ipset for high-performance filtering.

    Shellabusesattacksblocklists
    在 GitHub 上查看↗3,850
  • openziti/zitiopenziti 的头像

    openziti/ziti

    3,883在 GitHub 上查看↗

    Ziti is a zero-trust network overlay and identity-based mesh network. It provides a software-defined perimeter that replaces traditional IP-based routing and VPNs by mapping network services to cryptographically verified identities, effectively cloaking applications from the public internet. The project distinguishes itself through an outbound-only connection model that eliminates open listening ports and a Zero Trust SDK that allows developers to embed encryption and identity-based access control directly into application source code. It also provides transparent tunneling proxies to extend

    Provides an SDK-based approach for encrypted traffic and identity integration without requiring host-level agents.

    Goappsecgolangmesh
    在 GitHub 上查看↗3,883
  • serverless-dns/serverless-dnsserverless-dns 的头像

    serverless-dns/serverless-dns

    3,704在 GitHub 上查看↗

    This project is a serverless DNS resolver and DNS over HTTPS gateway that translates domain names into IP addresses. It functions as an edge computing DNS filter designed to encrypt queries, prevent tampering, and improve user privacy on browsers and mobile devices. The system distinguishes itself by operating as an edge DNS traffic monitor that logs and analyzes request patterns in real time. It utilizes curated blocklists at the network edge to block malicious domains and trackers. The software provides capabilities for private DNS filtering, network traffic monitoring, and the management

    Provides firewall-like control to block or allow internet access on a per-application basis.

    JavaScriptadblockcloudflarecloudflare-workers
    在 GitHub 上查看↗3,704
  1. Home
  2. Security & Cryptography
  3. Firewall Management

探索子标签

  • Application-Level Access Controls1 个子标签Firewall rules that restrict internet access based on the originating application process. **Distinct from Firewall Management:** Distinct from Firewall Management: focuses on per-app process identity rather than IP-based server protection.
  • IPSet ManagersTools for downloading and normalizing threat intelligence to update kernel-level IP sets for real-time filtering. **Distinct from Firewall Management:** Distinct from Firewall Management: focuses specifically on IPSet-based blocklist management.