Back to updates
New releaseAug 19, 2026

easywall v2.7.0

Web interface for the nftables firewall on Linux, written in Go. The apply undoes itself after 120 seconds unless you confirm it — you cannot lock yourself out. Debian & Docker install.

Share

easywall

Your firewall. Your rules. No surprises.

Tests Build Security Coverage

Latest release Go version GPL-3.0 Discord Support on Ko-fi

Live demo · Documentation · Changelog

nftables through a web interface that cannot lock you out: every apply reverts itself unless you confirm it.

The easywall dashboard: firewall status with acceptance state, pending changes and last apply; tiles counting TCP ports, UDP ports, blacklist, whitelist, custom rules and forwarding; and a recent-activity list.

The idea

Editing a rule changes nothing. Applying it changes everything — for 120 seconds. If the new rules cut your connection you cannot click Confirm, and not confirming is what brings the old rules back.

State machine: editing leads to Staged, applying leads to Live, confirming within the window leads to Confirmed, and letting the window expire leads to Rolled back, from where the staged edits are still available.

Architecture

Two processes. The one exposed to the network holds no privilege worth stealing.

Browser talks HTTPS to easywall-web, which runs unprivileged; easywall-web talks typed JSON over a Unix socket to easywall-core, which runs as root and speaks netlink to the nftables table inet easywall.

A complete rewrite of the original easywall — Python, Flask, iptables via subprocess — which was archived in 2022 after a CVE. Both root causes are gone: the privileges live in a different process, and the apply path builds Go structs instead of a command line. How it works →

Install

Decision tree: just looking leads to demo mode; Debian or Ubuntu leads to the .deb package; already running containers leads to Docker; otherwise build from source.
# Debian / Ubuntu — amd64 and arm64
ARCH=$(dpkg --print-architecture)
wget https://github.com/jp1337/easywall/releases/latest/download/easywall_$ARCH.deb
sudo dpkg -i easywall_$ARCH.deb && sudo apt-get install -f

# Docker
git clone https://github.com/jp1337/easywall.git && cd easywall && docker compose up -d

# From source — Go 1.26+, nftables
git clone https://github.com/jp1337/easywall.git && cd easywall
make build && sudo make install
sudo systemctl enable --now easywall-core easywall-web

Then open https://localhost:12227. The first visit sets up the account and stages the first rules.

What you get

PortsTCP and UDP, single or range, with per-rule SSH brute-force routing
Blacklist & whitelistIPv4, IPv6 and CIDR, evaluated before any port rule
Protection modulesTwelve, five on by default — floods, scans, bogons, fragments, broadcast/multicast/anycast
Port forwardingNAT redirects with protocol selection
Custom rulesRaw nftables, syntax-checked before it is applied
Export / importThe whole rule set as JSON
Audit logWhat changed and when, one JSON object per line
Docker coexistenceOwns table inet easywall, touches nothing else
English & GermanSwitchable in the interface, including before sign-in
Light & darkFollows the OS, with a manual toggle; both contrast-checked

Built with

Go 1.26, single binarygo-chi/chi · html/template
nftables via google/nftablesdirect netlink, no nft subprocess
Argon2idgolang.org/x/crypto, 16-byte salt per password
CSRFnet/http.CrossOriginProtection, Go 1.25 native
Design systemDESIGN.md + Tailwind v4 — no third-party UI library
FontsInter + JetBrains Mono, self-hosted, ~145 KB — works air-gapped
CIgovulncheck, gosec, CodeQL, -race, and an integration suite against a real kernel

Roadmap

Correctness first: a firewall that quietly does less than it says is worse than one that does less and says so.

2.6Integration tests that assert meaning, not rule counts
2.7Identity — a user in the socket protocol, then login events, then multiple accounts, then 2FA
2.8A REST API with token auth, ACME as an option, opt-in trusted reverse proxy
2.9An opt-in count of installations

Why each comes when it does, and what the count would send: Roadmap →

Getting help

A question, or something not behavingDiscord
A bug, or a feature you wantGitHub issues
A security vulnerabilitySecurity advisorynot Discord, and not a public issue

Contributing

Setup, commit conventions and the review checklist: CONTRIBUTING.md. Anything visual goes through DESIGN.md first.

Security issues: not as a public issue — use GitHub Security Advisories.

License

GPL-3.0 — see LICENSE.

Categories