Firewall Management Platform v1.0.1

FireDog

A three-tier firewall system. The master is a Django + React web server where you author rules and monitor traffic — including an MCP server for AI agents; target tools enforce a default-DROP iptables policy on each managed Linux host (Debian/Ubuntu or openSUSE/SLES), with multi-NIC support and configurable SSH brute-force protection; dog-agent pairs each target with the master and streams heartbeat, statistics, and threats back over WebSocket.

Architecture

Three tiers, one perimeter

Master (web server)

Django + React application. Hosts the policy editor, the live traffic dashboard, and an MCP server (POST /api/mcp) that lets authorized AI agents query rules, threats, traffic and network flows.

Target firewall tools

Installed on each managed host under /opt/sentinelsuite/firedog via a one-liner bootstrap (Debian/Ubuntu or openSUSE/SLES). Default-DROP iptables policy with SYN-flood, port-scan, and configurable SSH brute-force protection (temporary or permanent bans via a persistent ipset), plus a CLI rule manager.

Multi-NIC hosts

A target can expose more than one network interface. Rules can be scoped to a specific NIC (-i/-o), with per-interface rx/tx counters and a NIC selector in the target detail view. /etc/firewall/firedog.conf controls which interfaces are monitored and which ports stay open before the DROP policy kicks in.

Traffic capture & threat scoring

Blocked traffic is logged to PCAP via ulogd2 and analysed by the traffic analyzer, which assigns threat scores. Statistics and threats stream to the master dashboard in real time.

Dog-agent link

The shared suite agent (dog-agent) authenticates each target to the master with a 2-phase pairing, pushes heartbeat, stats, and threats over WebSocket, and applies rule commands sent from the master.

Requirements — Master

OS
Linux · Debian 12+ · Ubuntu 22.04+
Runtime
Python 3.11–3.13 · Node 20
Services
PostgreSQL · Redis · nginx
Memory
2 GB RAM · 4 GB recommended
Web port
TCP :80 / :443 · via nginx

Requirements — Target (firewall tools)

OS
Linux · Debian / Ubuntu · openSUSE / SLES
Firewall
iptables + ulogd2 · default-DROP policy
Install
curl one-liner (self-installed on the target)
Installs to
/opt/sentinelsuite/firedog
Pairing
dog-agent · .deb/.rpm package, WebSocket
Documentation

Manuale utente

Guida completa in italiano — architettura, installazione (master, target, dog-agent), ruoli e permessi, multi-NIC, regole firewall, protezione SSH e server MCP.

Quick install

Master first, then pair your gateways

FireDog is distributed from GitHub — clone the latest release and follow INSTALL.md; systemd units are in deploy/. The target installer script is attached to the release.

Clone the repo and follow INSTALL.md. It covers PostgreSQL, Redis, virtualenv, Daphne, Celery, and nginx. Systemd units are ready in deploy/.

bash — master server
# clone the stabile branch and follow INSTALL.md
git clone --branch stabile https://github.com/Dognet-Technologies/firedog.git
cd firedog
# prerequisites: Python 3.11–3.13, Node 20, PostgreSQL, Redis, nginx
cat INSTALL.md