Firewall, Audit and IDS
Manage firewall rules, inspect attacks, handle IP reputation and configure host integrity monitoring.
Source: supplied One-Click help · Confirm options on your installed release
The firewall engine supports readable rules with a confirmation and rollback workflow. Preview sensitive changes and keep access to a remote console before editing networking rules.
General OperationsTraffic RulesProtocols, Ports and AliasesSecurity Audit and IP ReputationHost IDS Scanner
General Operations
one-click engine --dry-runPreview changes without applying rules.one-click engine open [table|all]List active firewall rules.one-click engine flush <table>Remove rules from one table.one-click engine flush allFlush all firewall tables; destructive.one-click engine backupBack up firewall configuration.one-click engine restoreRestore firewall rules from a saved backup.one-click engine raw <iptables command>Pass an advanced native iptables command.one-click engine chain create <chain>Create a custom firewall chain.Traffic Rules
one-click engine allow <arg>Accept matching inbound traffic.one-click engine deny <arg>Drop traffic silently (also: drop).one-click engine reject <arg>Reject matching traffic (also: decline).one-click engine delete <arg>Remove a rule, alias or backup (also: remove).one-click engine maskEnable NAT masquerading (also: hide).one-click engine "allow ssh from office"Use a named source alias.one-click engine "allow 443 to 10.0.0.5"Apply a destination condition.one-click engine "allow udp port 100"Explicit UDP traffic rule.one-click engine "allow ssh from office and deny ssh from blacklist"Combine human-readable rules.Protocols, Ports and Aliases
one-click engine enable icmpAllow ICMP echo requests (also: echo).one-click engine disable icmpDisable ICMP echo requests.one-click engine "allow udp port 100"UDP rule; TCP is default.one-click engine "allow https multiport 50 556 4000"Apply a rule to multiple ports.one-click engine "range 1000-2000"Apply a port-range constraint.one-click engine alias-create <name> <ips...>Create named IP address groups.one-click engine alias-append <name> <ips...>Add IPs to an existing group.one-click engine alias-prune <name> <ips...>Remove IPs from a group.one-click engine sensitive <ports...>Mark ports that require confirmation.one-click engine sensitive-listList sensitive ports.one-click engine sensitive-remove <ports...>Remove a port from sensitive list.Security Audit and IP Reputation
one-click engine auditInspect firewall rules, drops and activity.one-click engine audit sshInspect SSH brute-force detections.one-click engine audit block <ID> dur=NTemporarily block an identified source; N in minutes.one-click engine audit block <ID> permPermanently block an identified source.one-click engine audit unblock <ID>Remove an applied block.one-click engine audit historyReview past audit actions.one-click engine audit banlistView Rule Engine and Fail2Ban bans.one-click engine "audit jail <name> port <port> retry <count>"Configure a Fail2Ban jail.one-click engine audit key <APIKEY>Configure AbuseIPDB; avoid exposing keys in shared shell history.one-click engine audit lookup <IP>Request an AbuseIPDB IP reputation lookup.Host IDS Scanner
one-click engine "audit scan --init"Initialise a trusted filesystem baseline.one-click engine "audit scan"Run the standard integrity scan.one-click engine "audit scan --deep"Run deeper filesystem inspection.one-click engine "audit scan --verify"Verify the baseline (help-wrapper option; version-dependent).one-click engine "audit scan --rebase"Rebuild the baseline after reviewing changes (version-dependent).one-click engine "audit scan --stats"Show IDS statistics (version-dependent).one-click engine "audit scan --json"Machine-readable statistics (version-dependent).one-click engine "audit scan --status"Show IDS status (version-dependent).one-click engine "audit scan --cron"Schedule scan-only monitoring (version-dependent).one-click engine "audit scan --disable-cron"Disable scheduled scans (version-dependent).one-click engine "audit scan --cleanup"Remove expired retained evidence (version-dependent).one-click engine "audit scan --events-limit <count>"Show recent events (version-dependent).one-click engine "audit scan --disable"Disable scan automation (version-dependent).one-click engine "audit scan --help"Show scanner help where supported.IDS Version Compatibility
The attached One-Click help lists scanner flags such as --rebase, --cron and --verify, while the separate IDS v1.6 module uses names such as --rebaseline, --schedule and --verify-baseline. Check the wrapper installed on your system before using these newer controls. Older scheduled scanner versions may allow unattended remediation; review them before enabling automation.