{"repo":"rfxn/advanced-policy-firewall","free":true,"listed":false,"github":"https://github.com/rfxn/advanced-policy-firewall","clone":"git clone https://github.com/rfxn/advanced-policy-firewall.git","description":"iptables/netfilter firewall for Linux servers with stateful filtering, trust system, ipset block lists, SYN flood protection, VNET per-IP policies, and Docker support","language":"Shell","stars":112,"topics":["bash","firewall","ipset","iptables","linux-security","netfilter","network-security","server-hardening"],"license":"GPL-2.0","category":"cli-tools","readme_excerpt":"Advanced Policy Firewall (APF) iptables/netfilter-based firewall management for Linux servers — stateful packet filtering, trust-based host management, reactive address blocking, and per-IP virtual network policies. (C) 2002-2026, R-fx Networks &lt;proj@rfxn.com&gt; (C) 2026, Ryan MacDonald &lt;ryan@rfxn.com&gt; Licensed under GNU GPL v2 --- What's New in 2.0.2 - GeoIP country blocking — ipset-based country filtering with ISO 3166-1 codes, continent shorthand ( @EU , @AS ), dual-stack IPv4/IPv6, advanced per-port/protocol syntax, audit mode, and tiered data sources with local caching - Connection tracking limit — global per-IP connection limit via periodic conntrack scanning with configurable thresholds, port/state filters, CIDR exemptions, and PERMBLOCK escalation - Temporary trust with TTL — apf -ta / -td with per-entry time-to-live (5m, 1h, 7d), automatic cron expiry, and block escalation for repeat offenders - Structured event logging — dual log model via elog lib.sh with JSONL audit trail at /var/log/apf/audit.log covering trust mutations, config events, and service state - SYN flood protection — iptables-level rate limiting with configurable rate/burst, complementing kernel sysctl protection See CHANGELOG for the complete release notes. --- Contents - Quick Start - 1. Introduction - 1.1 Supported Systems - 2. Installation - 2.1 Boot Loading - 2.2 Upgrading - 2.3 Key Files - 2.4 Uninstallation - 3. Configuration - 3.1 Basic Options - 3.2 Outbound Filtering - 3.3 Advanced","default_branch":null,"files":null,"tree":[],"storefront":"/r/rfxn","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/rfxn/advanced-policy-firewall/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}