a2ad637a388d2485eaf57783a93f06d332e4884c
- Updated the `evofw-firewall.sh` script to refine the port ACL logic, ensuring the correct order of operations for deny and allow rules. - Introduced a new structure for port ACL rows in the UI, allowing for better management of system and EvoFW rules. - Enhanced the documentation to clarify the new port ACL behavior, including implicit drops for open ports and the distinction between EvoFW and system rules. - Improved the handling of port ranges and source addresses in the UI, ensuring accurate representation of firewall rules. These changes improve the functionality and clarity of port ACL management, enhancing user experience and system reliability.
EvoFirewall
Централизованный firewall controller: Linux / MikroTik agents, IP lists, allow/deny политики, статистика.
Интеграции: auth-portal (SSO, app id fw), EvoBGP (источник префиксов).
Стек
- Monorepo: pnpm workspaces + turbo
apps/web— Vite + React + TanStack + shadcn/ui + ReUI Frameapps/api— Fastify 5 + Drizzle + SQLite- Packages:
@evofw/ui,@evofw/shared,@evofw/db
Быстрый старт
pnpm install
cp .env.example .env
pnpm --filter @evofw/db build
pnpm --filter @evofw/shared build
pnpm --filter @evofw/api dev # :8080
pnpm --filter @evofw/web dev # :5177
Linux agent (short link из UI /agents → Добавить агента):
curl -fsSL http://localhost:8080/agent-install/<id> | bash
# или:
curl -fsSL http://localhost:8080/<slug> | bash
Legacy one-liner:
curl -fsSL http://localhost:8080/v1/agent/install.sh | \
EVOFW_CP_URL=http://localhost:8080 \
EVOFW_SEED=dev-enroll-seed-change-me \
EVOFW_CLIENT_NAME="web-01" \
bash
Затем Approve в UI /agents.
Docs
См. docs/README.md.
Git
origin https://git.shts.su/denozord/EvoFirewall.git