Rule Engine & Firewall

Use readable firewall intent with dry-run, preview, aliases, backup/restore and direct native rule access when required.

One-Click documentation · Step-by-step guide

Rule Engine converts readable operator intent into validated firewall actions while keeping the native firewall visible. It is intended to reduce syntax mistakes, not hide Linux networking.

Examples

one-click engine "allow ssh"
one-click engine "close 3306"
one-click engine --dry-run "open https"
one-click rule-engine "enable icmp"
one-click firewall "delete line 3"

Capabilities

  • TCP, UDP, ICMP and multiport rules.
  • Source/destination filtering with CIDR notation.
  • Service-name mapping such as ssh to port 22.
  • Dry-run preview and interactive confirmation.
  • Rule backup and restore.
  • Aliases for groups of IP addresses.
  • Raw native input for advanced cases.

Raw Mode

Raw mode is for operators who already know the native firewall command they want. Because it bypasses the natural-language parser, use it only when the readable workflow cannot represent the required rule.