Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
easywall — Web interface for the nftables firewall on Linux, written in Go. The apply undoes itself after 120 seconds unless you confirm it — you cannot lock yourself out. Debian & Docker install. | Kitploit
Tools/GitHubGitHub/jp1337/easywall
Defensive ToolsConfiguration AuditingNetwork Access ControlNetwork SecurityMisconfiguration
GitHubjp1337/easywall

easywall

Web interface for the nftables firewall on Linux, written in Go. The apply undoes itself after 120 seconds unless you confirm it — you cannot lock yourself out. Debian & Docker install.

View Repository
6473 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website
<p align="center">
  <img src="https://raw.githubusercontent.com/jp1337/easywall/HEAD/web/static/icon.svg" alt="" width="88" height="88">
</p>

<h1 align="center">easywall</h1>

<p align="center"><em>Your firewall. Your rules. No surprises.</em></p>

<!-- One badge service, so the set shares a shape, a typeface and a logo
     treatment. The three status badges read from the workflows by name; the
     version, licence and Go badges read from the repository and go.mod, so
     none of them can drift the way a hand-written version number could. -->
<p align="center">
  <a href="https://github.com/jp1337/easywall/actions/workflows/test.yml"><img src="https://img.shields.io/github/actions/workflow/status/jp1337/easywall/test.yml?branch=main&amp;label=tests&amp;logo=github&amp;logoColor=white" alt="Tests"></a>
  <a href="https://github.com/jp1337/easywall/actions/workflows/build.yml"><img src="https://img.shields.io/github/actions/workflow/status/jp1337/easywall/build.yml?branch=main&amp;label=build&amp;logo=github&amp;logoColor=white" alt="Build"></a>
  <a href="https://github.com/jp1337/easywall/actions/workflows/security.yml"><img src="https://img.shields.io/github/actions/workflow/status/jp1337/easywall/security.yml?branch=main&amp;label=security&amp;logo=github&amp;logoColor=white" alt="Security"></a>
  <a href="https://codecov.io/gh/jp1337/easywall"><img src="https://img.shields.io/codecov/c/github/jp1337/easywall?logo=codecov&amp;logoColor=white&amp;label=coverage" alt="Coverage"></a>
</p>

<p align="center">
  <a href="https://github.com/jp1337/easywall/releases/latest"><img src="https://img.shields.io/github/v/release/jp1337/easywall?logo=github&amp;logoColor=white&amp;label=release" alt="Latest release"></a>
  <a href="https://go.dev"><img src="https://img.shields.io/github/go-mod/go-version/jp1337/easywall?logo=go&amp;logoColor=white&amp;label=go" alt="Go version"></a>
  <a href="https://www.gnu.org/licenses/gpl-3.0"><img src="https://img.shields.io/github/license/jp1337/easywall?logo=opensourceinitiative&amp;logoColor=white&amp;label=license&amp;color=blue" alt="GPL-3.0"></a>
  <a href="https://discord.gg/3zJMvChvUA"><img src="https://img.shields.io/badge/discord-join-5865F2?logo=discord&amp;logoColor=white" alt="Discord"></a>
  <a href="https://ko-fi.com/jp1337"><img src="https://img.shields.io/badge/ko--fi-support-13C3FF?logo=kofi&amp;logoColor=white" alt="Support on Ko-fi"></a>
</p>

<p align="center">
  <a href="https://demo.easywall-project.org"><strong>Live demo</strong></a> ·
  <a href="https://easywall-project.org"><strong>Documentation</strong></a> ·
  <a href="https://github.com/jp1337/easywall/blob/main/CHANGELOG.md">Changelog</a>
</p>

nftables through a web interface that cannot lock you out: **every apply reverts
itself unless you confirm it.**

<picture>
  <source media="(prefers-color-scheme: dark)" srcset="docs/assets/img/screens/dashboard-dark.png">
  <img src="https://assets.kitploit.com/production/public/readmes/43596/614cbeca6ebf752bf79ddc8d910eb14f46b45390f1cb5b8f53032578aed5fb40.png" alt="The easywall dashboard: firewall status with acceptance state, pending changes and last apply; tiles counting TCP ports, UDP ports, blocklist, allowlist, custom rules and forwarding; and a recent-activity list.">
</picture>

## The idea

Editing a rule changes nothing. Applying it changes everything — for 120 seconds.
If the new rules cut your connection you cannot click Confirm, and *not* confirming
is what brings the old rules back.

<picture>
  <source media="(prefers-color-scheme: dark)" srcset="docs/assets/diagrams/apply-flow-dark.svg">
  <img src="https://raw.githubusercontent.com/jp1337/easywall/HEAD/docs/assets/diagrams/apply-flow-light.svg" alt="State machine: editing leads to Staged, applying leads to Live, confirming within the window leads to Confirmed, and letting the window expire leads to Rolled back, from where the staged edits are still available.">
</picture>

## Architecture

Two processes. The one exposed to the network holds no privilege worth stealing.

<picture>
  <source media="(prefers-color-scheme: dark)" srcset="docs/assets/diagrams/architecture-dark.svg">
  <img src="https://raw.githubusercontent.com/jp1337/easywall/HEAD/docs/assets/diagrams/architecture-light.svg" alt="Browser talks HTTPS to easywall-web, which runs unprivileged; easywall-web talks typed JSON over a Unix socket to easywall-core, which runs as root and speaks netlink to the nftables table inet easywall.">
</picture>

A complete rewrite of the original easywall — Python, Flask, `iptables` via
subprocess — which was archived in 2022 after a CVE. Both root causes are gone:
the privileges live in a different process, and the apply path builds Go structs
instead of a command line. [How it works →](https://easywall-project.org/architecture/)

## Install

<picture>
  <source media="(prefers-color-scheme: dark)" srcset="docs/assets/diagrams/install-choice-dark.svg">
  <img src="https://raw.githubusercontent.com/jp1337/easywall/HEAD/docs/assets/diagrams/install-choice-light.svg" alt="Decision tree: just looking leads to demo mode; Debian or Ubuntu leads to the .deb package; already running containers leads to Docker; otherwise build from source.">
</picture>

```bash
# Debian / Ubuntu — amd64 and arm64
ARCH=$(dpkg --print-architecture)
wget https://github.com/jp1337/easywall/releases/latest/download/easywall_$ARCH.deb
sudo dpkg -i easywall_$ARCH.deb && sudo apt-get install -f

# Docker
git clone https://github.com/jp1337/easywall.git && cd easywall && docker compose up -d

# From source — Go 1.27+, nftables
git clone https://github.com/jp1337/easywall.git && cd easywall
make build && sudo make install
sudo systemctl enable --now easywall-core easywall-web
```

Then open `https://localhost:12227`. The first visit
[sets up the account and stages the first rules](https://easywall-project.org/installation/first-run/).

## What you get

| | |
|---|---|
| **Ports** | TCP and UDP, single or range, with per-rule SSH brute-force routing |
| **Blocklist & allowlist** | IPv4, IPv6 and CIDR, evaluated before any port rule |
| **Protection modules** | Twelve, five on by default — floods, scans, bogons, fragments, broadcast/multicast/anycast |
| **Port forwarding** | NAT redirects with protocol selection |
| **Custom rules** | Raw nftables, syntax-checked before it is applied |
| **Export / import** | The whole rule set as JSON |
| **Audit log** | What changed and when, one JSON object per line |
| **Docker coexistence** | Owns `table inet easywall`, touches nothing else |
| **English, Deutsch, Français** | Switchable in the interface, including before sign-in. A language may be partial: what it is missing renders English, and the gap is reported rather than hidden |
| **Light & dark** | Follows the OS, with a manual toggle; both contrast-checked |

## Built with

| | |
|---|---|
| Go 1.27, single binary | `go-chi/chi` · `html/template` |
| nftables via `google/nftables` | direct netlink, no `nft` subprocess |
| Argon2id | `golang.org/x/crypto`, 16-byte salt per password |
| CSRF | `net/http.CrossOriginProtection`, Go 1.25 native |
| Design system | [`DESIGN.md`](https://github.com/jp1337/easywall/blob/main/DESIGN.md) + Tailwind v4 — no third-party UI library |
| Fonts | Inter + JetBrains Mono, self-hosted, ~145 KB — works air-gapped |
| CI | `govulncheck`, `gosec`, CodeQL, `-race`, and an integration suite against a real kernel |

## Getting help

| | |
|---|---|
| A question, or something not behaving | [Discord](https://discord.gg/3zJMvChvUA) |
| A bug, or a feature you want | [GitHub issues](https://github.com/jp1337/easywall/issues) |
| A security vulnerability | [Security advisory](https://github.com/jp1337/easywall/security/advisories/new) — **not** Discord, and not a public issue |

## Contributing

Setup, commit conventions and the review checklist: [CONTRIBUTING.md](https://github.com/jp1337/easywall/blob/main/CONTRIBUTING.md).
Anything visual goes through [`DESIGN.md`](https://github.com/jp1337/easywall/blob/main/DESIGN.md) first.

Security issues: **not** as a public issue — use
[GitHub Security Advisories](https://github.com/jp1337/easywall/security/advisories/new).

## License

GPL-3.0 — see [LICENSE](https://github.com/jp1337/easywall/blob/main/LICENSE).
Download Tool