A web-based network management platform for Linux that provides centralized management of firewall, routing, VPN, QoS, monitoring, and custom eBPF modules.
Download the latest preview ISO:
https://github.com/styx-firewall/styx-flf
Warning: This is a very early preview intended for testing only.
Configure physical and virtual interfaces
- Full nftables rule management across filter and NAT tables.
- Object-based configuration model.
- Static routes.
- Multipath routing.
- Routing tables.
Support for:
-
BGP
-
OSPF
-
RIP
-
BFD
-
IGMP proxy support
- IKEv1 and IKEv2.
- Tunnel and transport modes.
- Site-to-site and remote access (road warrior).
- Complete tunnel lifecycle management from the web interface.
Packet marking support for:
- Routing
- Firewall
- Traffic Control (TC)
- Support for the most commonly used qdiscs.
- Rate-limited classes.
- Traffic classification filters.
- Rules Interface
- Real-time monitoring charts and status.
- Real-time interface traffic statistics.
- Attach, detach, and manage kernel eBPF programs.
- Per-module statistics.
- Events and alerts integrated into the dashboard.
- ICMP *
- iperf3 bandwidth testing.
- Internal service watchdogs.
- Role-Based Access Control (RBAC).
- Fine-grained permissions.
- Multi-user support.
- AppArmor configuration and policy management.
- Internal auditing.
- auditd configuration and log management.
- Basic host event detection.
- Basic Network topology discovery.
- Anomalise/services detection in networks (planned)
- Suricata IDS/IPS support.
- REST API with token-based authentication.
- Complete configuration management through the API.
- Firewall, VPN, interfaces, routing, and QoS management.
- Every feature available in the web interface is also available through the API.
- Configuration backup and restore.
- Unified configuration model with distinct running and startup states.
- System event log with filtering and acknowledgement.
- Session-based and token-based authentication.
- Built on the latest Linux kernel technologies.
- Debian Based