The distribution for creating firewalls NethSecurity 8.3 has been published, based on the NethServer platform and designed for rapid deployment of a firewall. In addition to packet filtering, it provides capabilities for intrusion detection and prevention, antivirus scanning, ad blocking, prioritization of different types of traffic, deep packet inspection (DPI), and content filtering. Deployed in a corporate network, NethSecurity can also selectively block Netflix, YouTube, TikTok, Instagram, Facebook, and other services that may distract employees from work. The size of the bootable image in compressed form is 52 MB.
The platform is built as an integrated solution that can be used for installation on physical servers and virtual machines, as well as for creating bootable USB drives that turn any computer into a firewall. It supports the creation of tunnels via IPsec and OpenVPN, deployment of wireless access points, and operation through multiple external internet connection channels (MultiWAN).
Management and administration are carried out through a web interface, which offers, among other things, options for creating/restoring configuration backups, resetting to factory settings, managing the installation of updates, and connecting via SSH (web interface for SSH client). When used in an infrastructure servers based on the NethServer distribution, centralized remote management of all hosts with NethSecurity through the NethServer interface is possible, as well as connection to a shared monitoring and logging system.
Among the changes in the new version:
- The package base is synchronized with the OpenWrt 23.05.5 distribution.
- Tools have been implemented for centralized management of software updates (from the NethSecurity Controller node, updates of individual packages and the entire system image can be installed on other nodes).

- A summary page (dashboard) for real-time monitoring has been added to the web interface.

- The NethSecurity Controller node has implemented the ability to view the history of monitoring events.

- Threat Shield settings have been enhanced with tools for managing the local blacklist, block log, and brute force protection settings.

- A page has been added with address translation settings.

- The network port forwarding settings now include a field to restrict access for certain types of objects.

- Utility packages for KVM and VMware virtualization systems have been added.
- Anonymous telemetry collection for system usage has been implemented.
- Work has been done to improve the web interface's convenience and navigation.
Source: opennet.ru






