FOOMUURI(8) User Manual FOOMUURI(8)

foomuuri - multizone bidirectional nftables firewall

foomuuri [OPTION] [COMMAND]

Foomuuri is a firewall generator for nftables based on the concept of zones. It is suitable for all systems from personal machines to corporate firewalls, and supports advanced features such as a rich rule language, IPv4/IPv6 rule splitting, dynamic DNS lookups, a D-Bus API and FirewallD emulation for NetworkManager’s zone support.

--help
display this help and exit
--verbose
verbose output
--version
output version information and exit
--set=option=value
set config option to value

load configuration files, generate new ruleset and load it to kernel
same as start but fallback to previous “good” ruleset if loading fails
remove ruleset from kernel
same as start, followed by resolve+iplist refresh
load configuration files and verify syntax
list active ruleset currently loaded to kernel
list active ruleset for zone-zone currently loaded to kernel
list all known macros
list all named counters
list entries in all configured iplists and resolves
list entries in named iplist/resolve
add or refresh IP address to iplist
delete IP address from iplist
refresh iplist @name entries now

Foomuuri reads configuration files from /etc/foomuuri/*.conf. See full documentation for configuration syntax.

Kim B. Heino, b@bbbs.net, Foobar Oy

Submit bug reports <https://github.com/FoobarOy/foomuuri/issues>

Full documentation <https://github.com/FoobarOy/foomuuri/wiki>

December 12, 2023 Foomuuri 0.22