I had good results with their tools, but they didn't support iptables when I needed them to, so I ended up going with Shorewall. My rules still need more tweaking -- I'm too permissive about outgoing connections -- but it all went together pretty easily.
no subject