Releases: cloudarmour-io/neurowall-docs
Releases · cloudarmour-io/neurowall-docs
Release list
Neurowall v0.1.0
NeuroWall (Community Edition) — v1.0.0
First public release. NeuroWall is a lightweight Next-Generation Firewall (NGFW) with a web-based admin UI.
neurowall-legacy— the backend firewall daemon. Enforces rules entirely via nftables (no eBPF/XDP dependency, no special kernel version required) — the easiest path to get NeuroWall running on any standard Linux box.neurowall-fe— the web-based admin UI that manages it, so you rarely need to touch the CLI or edit config files by hand.
Features
Firewall Rules
- Whitelist IP — explicitly allow specific source IPs/subnets, bypassing normal block rules — useful for trusted admin IPs, monitoring systems, or internal services that should never be filtered.
- Blocklist IP (nftables) — block traffic from specific IPs or CIDR ranges at the nftables layer; add, edit, and remove blocked sources through the UI without writing nftables rules by hand.
- Port Forwarding — forward incoming traffic on a given port/protocol to an internal host and port (DNAT), for exposing internal services (e.g. a web server or SSH box) through the firewall.
Networking
- IP Configuration — view and manage IP addresses and default gateways per network interface, including live gateway reachability checks before committing a change.
- Static Routes — add, edit, and remove static routes (destination, gateway, metric) so traffic to specific networks is routed the way you intend.
- Masquerading — enable NAT/masquerading on an interface so internal/private hosts can reach the internet through the firewall's public IP.
- DNS Local Records — define custom local DNS A/AAAA/CNAME-style overrides, so internal hostnames resolve to internal IPs instead of hitting the public internet.
DNS & Traffic Visibility
- DNS Blocklist — block DNS resolution for specific domains (ad/tracker/malware-style blocklisting) at the resolver level, before a connection is even attempted.
- Traffic — Darkstat — see per-host bandwidth usage and top talkers on your network, sourced from the bundled Darkstat traffic analyzer.
- DNS — Unbound — visibility into the bundled Unbound resolver: queries, cache behavior, and resolution activity.
Monitoring & Diagnostics
- System Overview — at-a-glance dashboard of CPU, memory, disk usage, and system load, plus core service health.
- Connections Overview — see active network connections passing through the firewall in real time.
- NIC Diagnostics — inspect network interface card stats and health (link state, errors, driver info) to help troubleshoot connectivity issues.
- Diagnostics — run active network checks (ping, DNS lookups, connectivity tests) directly from the UI to troubleshoot issues without SSHing into the box.
Administration
- Setup Wizard — guided first-run configuration: interface selection, admin credentials, and initial firewall setup, so you're not hand-editing YAML on day one.
- Configuration — review and adjust core NeuroWall settings from a single settings page.
- Preferences — personalize the admin UI (theme, display options) per logged-in user.
- Passwords — change your own account password, or reset others' as an admin.
- Audit Logs — a tamper-evident record of who changed what and when — every rule change, config edit, and admin action.
- System Info — version, build, and environment details for support/troubleshooting.
- Service Control — start, stop, or restart NeuroWall's underlying services directly from the UI.
- Help — quick reference and links to setup guides, rule workflows, and documentation.