FireDog
A three-tier firewall system. The master is a Django + React web server where you author rules and monitor traffic — including an MCP server for AI agents; target tools enforce a default-DROP iptables policy on each managed Linux host (Debian/Ubuntu or openSUSE/SLES), with multi-NIC support and configurable SSH brute-force protection; dog-agent pairs each target with the master and streams heartbeat, statistics, and threats back over WebSocket.
Three tiers, one perimeter
Master (web server)
Django + React application. Hosts the policy editor, the live traffic dashboard, and an MCP server (POST /api/mcp) that lets authorized AI agents query rules, threats, traffic and network flows.
Target firewall tools
Installed on each managed host under /opt/sentinelsuite/firedog via a one-liner bootstrap (Debian/Ubuntu or openSUSE/SLES). Default-DROP iptables policy with SYN-flood, port-scan, and configurable SSH brute-force protection (temporary or permanent bans via a persistent ipset), plus a CLI rule manager.
Multi-NIC hosts
A target can expose more than one network interface. Rules can be scoped to a specific NIC (-i/-o), with per-interface rx/tx counters and a NIC selector in the target detail view. /etc/firewall/firedog.conf controls which interfaces are monitored and which ports stay open before the DROP policy kicks in.
Traffic capture & threat scoring
Blocked traffic is logged to PCAP via ulogd2 and analysed by the traffic analyzer, which assigns threat scores. Statistics and threats stream to the master dashboard in real time.
Dog-agent link
The shared suite agent (dog-agent) authenticates each target to the master with a 2-phase pairing, pushes heartbeat, stats, and threats over WebSocket, and applies rule commands sent from the master.
Requirements — Master
- OS
- Linux · Debian 12+ · Ubuntu 22.04+
- Runtime
- Python 3.11–3.13 · Node 20
- Services
- PostgreSQL · Redis · nginx
- Memory
- 2 GB RAM · 4 GB recommended
- Web port
- TCP :80 / :443 · via nginx
Requirements — Target (firewall tools)
- OS
- Linux · Debian / Ubuntu · openSUSE / SLES
- Firewall
- iptables + ulogd2 · default-DROP policy
- Install
- curl one-liner (self-installed on the target)
- Installs to
- /opt/sentinelsuite/firedog
- Pairing
- dog-agent · .deb/.rpm package, WebSocket
Manuale utente
Guida completa in italiano — architettura, installazione (master, target, dog-agent), ruoli e permessi, multi-NIC, regole firewall, protezione SSH e server MCP.
Master first, then pair your gateways
FireDog is distributed from GitHub — clone the latest release and follow INSTALL.md; systemd units are in deploy/. The target installer script is attached to the release.
Clone the repo and follow INSTALL.md. It covers PostgreSQL, Redis, virtualenv, Daphne, Celery, and nginx. Systemd units are ready in deploy/.
# clone the stabile branch and follow INSTALL.md git clone --branch stabile https://github.com/Dognet-Technologies/firedog.git cd firedog # prerequisites: Python 3.11–3.13, Node 20, PostgreSQL, Redis, nginx cat INSTALL.md
Run this on each target to install the firewall tools (iptables policy, PCAP logging, traffic analyzer) under /opt/sentinelsuite/firedog. Works on Debian/Ubuntu (apt) and openSUSE/SLES (zypper).
# download the installer, inspect it, then run it curl -fsSL https://raw.githubusercontent.com/Dognet-Technologies/firedog/stabile/firedog-package/get-firedog.sh -o get-firedog.sh less get-firedog.sh # installs tools + activates the firewall (default-DROP) on first run sudo bash get-firedog.sh # tools only — skip activation, pair from master UI later sudo bash get-firedog.sh --skip-init # one-liner alternative (same script, piped) curl -fsSL https://raw.githubusercontent.com/Dognet-Technologies/firedog/stabile/firedog-package/get-firedog.sh | sudo bash
Heads-up: activating the firewall applies a default-DROP policy on INPUT/OUTPUT — make sure you have console access, or use --skip-init and activate later. A specific branch or tag can be pinned with FIREDOG_REF=<ref>. Full instructions and pairing: INSTALL-TARGET.md.
Install dog-agent on every target (download the .deb), then add a [[targets]] block pointing at the FireDog master. See the Dog-Agent page for the full reference.
# install the suite agent (shared across all Dognet products) sudo dpkg -i dog-agent_1.1.1-1_amd64.deb # add a [[targets]] block for the FireDog master in agent.conf sudo nano /etc/dog-agent/agent.conf sudo systemctl enable --now dog-agent