Мне описание понравилось

. Да и возможности действительно неплохие.
Administration
* no iptables knowledge required
* humanly readable rules syntax
* traffic shaping
* Ncurses GUI, no X required.
* portforwarding is made very simple
* easy to setup in with NAT
* secure default policy
* entirely manageble through ssh and from the console (including from windows using PuTTY)
* scriptable for integration with other tools
* can produce a bash firewall script
* anti-spoofing features
* killing of unwanted connections
* supports working with Snort_inline using QUEUE or NFQUEUE
Monitoring
* realtime logviewing
* realtime connection viewing
* filtering in logviewing and connection viewing
* basic traffic volume accounting
* searching through old logfiles
Accounting
* audit logging: all changes are logged
* logging of new connections and bad packets
* traffic volume accounting