Skip to content

Releases: cloudarmour-io/neurowall-docs

Release list

Neurowall v0.1.0

Choose a tag to compare

@nishujangra nishujangra released this 21 Aug 14:56

NeuroWall (Community Edition) — v1.0.0

First public release. NeuroWall is a lightweight Next-Generation Firewall (NGFW) with a web-based admin UI.

  • neurowall-legacy — the backend firewall daemon. Enforces rules entirely via nftables (no eBPF/XDP dependency, no special kernel version required) — the easiest path to get NeuroWall running on any standard Linux box.
  • neurowall-fe — the web-based admin UI that manages it, so you rarely need to touch the CLI or edit config files by hand.

Features

Firewall Rules

  • Whitelist IP — explicitly allow specific source IPs/subnets, bypassing normal block rules — useful for trusted admin IPs, monitoring systems, or internal services that should never be filtered.
  • Blocklist IP (nftables) — block traffic from specific IPs or CIDR ranges at the nftables layer; add, edit, and remove blocked sources through the UI without writing nftables rules by hand.
  • Port Forwarding — forward incoming traffic on a given port/protocol to an internal host and port (DNAT), for exposing internal services (e.g. a web server or SSH box) through the firewall.

Networking

  • IP Configuration — view and manage IP addresses and default gateways per network interface, including live gateway reachability checks before committing a change.
  • Static Routes — add, edit, and remove static routes (destination, gateway, metric) so traffic to specific networks is routed the way you intend.
  • Masquerading — enable NAT/masquerading on an interface so internal/private hosts can reach the internet through the firewall's public IP.
  • DNS Local Records — define custom local DNS A/AAAA/CNAME-style overrides, so internal hostnames resolve to internal IPs instead of hitting the public internet.

DNS & Traffic Visibility

  • DNS Blocklist — block DNS resolution for specific domains (ad/tracker/malware-style blocklisting) at the resolver level, before a connection is even attempted.
  • Traffic — Darkstat — see per-host bandwidth usage and top talkers on your network, sourced from the bundled Darkstat traffic analyzer.
  • DNS — Unbound — visibility into the bundled Unbound resolver: queries, cache behavior, and resolution activity.

Monitoring & Diagnostics

  • System Overview — at-a-glance dashboard of CPU, memory, disk usage, and system load, plus core service health.
  • Connections Overview — see active network connections passing through the firewall in real time.
  • NIC Diagnostics — inspect network interface card stats and health (link state, errors, driver info) to help troubleshoot connectivity issues.
  • Diagnostics — run active network checks (ping, DNS lookups, connectivity tests) directly from the UI to troubleshoot issues without SSHing into the box.

Administration

  • Setup Wizard — guided first-run configuration: interface selection, admin credentials, and initial firewall setup, so you're not hand-editing YAML on day one.
  • Configuration — review and adjust core NeuroWall settings from a single settings page.
  • Preferences — personalize the admin UI (theme, display options) per logged-in user.
  • Passwords — change your own account password, or reset others' as an admin.
  • Audit Logs — a tamper-evident record of who changed what and when — every rule change, config edit, and admin action.
  • System Info — version, build, and environment details for support/troubleshooting.
  • Service Control — start, stop, or restart NeuroWall's underlying services directly from the UI.
  • Help — quick reference and links to setup guides, rule workflows, and documentation.