{"id":2866,"date":"2022-05-17T20:34:58","date_gmt":"2022-05-17T20:34:58","guid":{"rendered":"https:\/\/dft.wiki\/?p=2866"},"modified":"2026-06-08T21:49:55","modified_gmt":"2026-06-09T01:49:55","slug":"setting-up-the-linux-firewall-ipfire","status":"publish","type":"post","link":"https:\/\/dft.wiki\/?p=2866","title":{"rendered":"Setting Up the Linux Firewall IPFire"},"content":{"rendered":"<p><strong>IPFire<\/strong> is a hardened open-source Linux firewall and router distribution for physical or virtual networks. Available for download at [<a href=\"https:\/\/www.ipfire.org\/\">Link<\/a>] in x86 (64-bit) and ARM (64-bit) formats.<\/p>\n<p>It uses its own package manager called Pakfire (not Debian or RHEL based), focused on simplicity and security.<\/p>\n<p>Configuration is handled through a WebUI (e.g. https:\/\/10.10.10.1:444\/), with SSH available for advanced management.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-2867 aligncenter\" src=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2022\/05\/Screenshot-2022-05-17-154304-300x225.png\" alt=\"\" width=\"395\" height=\"296\" srcset=\"https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2022\/05\/Screenshot-2022-05-17-154304-300x225.png 300w, https:\/\/dft.wiki\/wp-content\/uploads\/sites\/15\/2022\/05\/Screenshot-2022-05-17-154304.png 635w\" sizes=\"auto, (max-width: 395px) 100vw, 395px\" \/><\/p>\n<p>IPFire uses color-coded zones to classify network segments:<\/p>\n<ul>\n<li>RED\n<ul>\n<li>WAN side.<\/li>\n<li>Public Internet.<\/li>\n<li>Interface name: red0.<\/li>\n<\/ul>\n<\/li>\n<li>GREEN\n<ul>\n<li>LAN side.<\/li>\n<li>Private internal network.<\/li>\n<li>Interface name: green0.<\/li>\n<\/ul>\n<\/li>\n<li>BLUE (optional)\n<ul>\n<li>DMZ (Demilitarized Zone).<\/li>\n<li>Limited protection network.<\/li>\n<li>Exposes specific ports (or all) to the Internet (e.g. port forwarding).<\/li>\n<\/ul>\n<\/li>\n<li>ORANGE (optional)\n<ul>\n<li>WLAN (wireless network).<\/li>\n<li>Segregated network for wireless devices.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Each zone requires a dedicated network adapter.<\/p>\n<p>Key features include:<\/p>\n<ul>\n<li>Rate limiting and traffic logging.<\/li>\n<li>Quality of Service (QoS) for latency-sensitive applications like VoIP.<\/li>\n<li>Intrusion Prevention System (IPS) via Snort.<\/li>\n<li>Web proxy with content caching and URL filtering.<\/li>\n<li>Site-to-site VPN support via IPsec or OpenVPN.<\/li>\n<li>DNS proxy with DNSSEC and DNS-over-TLS (DoT).<\/li>\n<li>Captive Portal.<\/li>\n<\/ul>\n<p>Common Pakfire commands:<\/p>\n<ul>\n<li>pakfire help\n<ul>\n<li>Lists available commands and descriptions.<\/li>\n<\/ul>\n<\/li>\n<li>pakfire install htop\n<ul>\n<li>Installs a single package.<\/li>\n<\/ul>\n<\/li>\n<li>pakfire install -y samba nano\n<ul>\n<li>Installs multiple packages without a confirmation prompt.<\/li>\n<\/ul>\n<\/li>\n<li>pakfire update\n<ul>\n<li>Updates the package list.<\/li>\n<\/ul>\n<\/li>\n<li>pakfire update &#8211;force\n<ul>\n<li>Forces a package list update.<\/li>\n<\/ul>\n<\/li>\n<li>pakfire upgrade\n<ul>\n<li>Upgrades all installed packages to the latest version.<\/li>\n<\/ul>\n<\/li>\n<li>pakfire upgrade &#8211;force\n<ul>\n<li>Repairs a broken upgrade.<\/li>\n<\/ul>\n<\/li>\n<li>pakfire list\n<ul>\n<li>Lists all available packages.<\/li>\n<\/ul>\n<\/li>\n<li>pakfire status\n<ul>\n<li>Shows the current core update level and status summary.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>To change the Pakfire repository, edit <strong>\/opt\/pakfire\/etc\/pakfire.conf<\/strong> and set your preferred mirror from the list at [<a href=\"https:\/\/mirrors.ipfire.org\/\">Link<\/a>].<\/p>\n<p>Standard Linux commands also available:<\/p>\n<ul>\n<li>ip address<\/li>\n<li>ip route<\/li>\n<li>service ntp {status|stop|start|restart}<\/li>\n<\/ul>\n<p>Note: keep your system updated. Like any internet-connected system, IPFire can be exploited if left unpatched. As an example, there is a known Metasploit module that exploits version 156 to obtain a reverse Meterpreter shell as <strong>admin<\/strong> [<a href=\"https:\/\/www.infosecmatter.com\/metasploit-module-library\/?mm=exploit\/linux\/http\/ipfire_pakfire_exec\">Link<\/a>].<\/p>\n","protected":false},"excerpt":{"rendered":"<p>IPFire is a hardened open-source Linux firewall and router distribution for physical or virtual networks. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,1],"tags":[],"class_list":["post-2866","post","type-post","status-publish","format-standard","hentry","category-linux","category-ccna"],"_links":{"self":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/2866","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2866"}],"version-history":[{"count":4,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/2866\/revisions"}],"predecessor-version":[{"id":5681,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/2866\/revisions\/5681"}],"wp:attachment":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2866"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2866"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2866"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}