Skip to content
BerryCade BETA
Edge firewall · Raspberry Pi 3, 4 and 5

A real firewall, on a Raspberry Pi.

Zone-to-zone policies with NAT, VLANs, PPPoE, IDS/IPS, web filter and VPN, configured from the browser, like commercial firewalls. Every change is tested before it takes effect, and rolls back on its own if you lose access.

Image for Raspberry Pi 3, 4 and 5 (.img.xz)

  • Plain nftables
  • Debian 13 "trixie"
  • Suricata
  • strongSwan
  • Tailscale
BerryCade berrycade · Firewall Policy
Firewall Policyby sequence
IDNameSourceDestinationServiceActionSecurity
1LAN-InternetLAN out to the internet with NAT lanwanALL ✓ ACCEPT—
2LAN-VPNLAN to the VPN tunnels lanvpntailscaleALL ✓ ACCEPT—
3VPN-LANVPN tunnels to the LAN vpnlanALL ✓ ACCEPT—
Configuration in sync with the kernel3 policies

Red while the change is applied, green once it is in operation.

Why BerryCade

Built to sit at the edge of the network

  • A complete firewall

    Plain nftables, zone-to-zone policies evaluated top to bottom, NAT on the rule itself, VLANs and PPPoE.

  • Security per policy

    IPS (Suricata), category web filter and SSL inspection, turned on in each rule that needs them.

  • You can't lock yourself out

    Every change must be confirmed through the new rules. Without confirmation within 60 s, the previous configuration comes back on its own.

  • Panel and kernel always match

    The ruleset is swapped in one go, never halfway, and a checker fixes any drift.

  • Safe updates

    Signed firmware (Ed25519), a self-test before activation, automatic rollback on failure and up to three installed versions.

  • Installs in minutes

    A ready image to write to the card and a setup wizard on first access.

Screens

Everything from the browser

No editing files on the system: the panel validates, tests and applies every change, and keeps the history of all of them. The panel is in Brazilian Portuguese.

Dashboard: CPU, temperature, memory, disk, WAN and LAN usage, ports and services.
Features

What comes with BerryCade

Organized like the panel menu.

Network

  • Ports: onboard or any USB-Ethernet adapter, pinned by MAC address.
  • WAN over PPPoE, DHCP or static IP.
  • 802.1Q VLANs with their own IP range and zone.
  • DHCP per interface, with reservations, revocation and banning.
  • DNS with a local domain, and static routes.

Policy & objects

  • Zone-to-zone policies with a logged implicit deny.
  • NAT on the rule itself or in a central table.
  • Addresses, services, virtual IPs (port forwarding) and pools.
  • Per-rule counters; reorder by dragging the row.

Security profiles

  • IDS/IPS with Suricata and ET Open rules updated every day.
  • Web filter by category (UT1, Block List Project, HaGeZi), with a block page.
  • SSL inspection by certificate or deep, with exemptions for banks.
  • Anti-bypass: blocks DNS over TLS and over HTTPS.

VPN

  • IPsec (strongSwan) with a wizard and an advanced mode.
  • Pre-shared key or certificates with a local CA.
  • Tailscale as subnet router and exit node.

Wi-Fi

  • UniFi access points monitored over SSH, read-only.
  • Wi-Fi networks (SSIDs) and AP settings stay on the UniFi controller.
  • Clients with signal, channel, traffic and device name.
  • The AP password is used once and is not stored.

System

  • Revisions of every change, with rollback to any of them.
  • Full backup, optionally encrypted.
  • Administrators restricted by IP.
  • Light and dark themes and custom colors.
How a change is applied

Nothing counts until it's tested

The configuration file is the source of truth, versioned on every change. From clicking OK to the rule in operation:

  1. Validate

    Data and references between objects are checked before anything else.

  2. Generate and test

    Firewall, network, DNS, proxy and VPN are generated and tested: nft -c, dnsmasq --test, squid -k parse.

  3. Apply in one go

    The whole ruleset is swapped atomically, with no open window in between.

  4. Confirm

    The browser confirms through the new rules. The change becomes a revision.

  5. Or roll back on its own

    Without confirmation within 60 s, the previous configuration is restored.

Command line

Also from the console, with Tab

Everything you configure in the panel can also be configured from the console or over SSH. The Tab key completes commands, existing names, fields and values.

  • The same validation and the same history as the panel.
  • If a change cuts SSH off, the confirmation never arrives and everything rolls back.
  • Recovery commands work even with the panel stopped.
Hardware and installation

From SD card to firewall

  1. Write the image

    Download berrycade-<version>.img.xz from the published releases and write it to the card with Raspberry Pi Imager ("Use custom") or balenaEtcher.

  2. Adjust before powering on (optional)

    Edit berrycade.txt on the boot partition: name, LAN IP, gateway and DNS.

  3. Power on with the LAN connected

    On first boot the partition is expanded and the wizard asks for the LAN and WAN ports, the LAN IP, the internet connection and the device name.

You will need

  • Raspberry Pi 3, 4 or 5 (64-bit). For IDS/IPS, a Pi 4 or 5 with 4 GB or more.
  • A microSD card of 8 GB or more.
  • A second network port: any USB-Ethernet adapter.

First access

Address
https://10.0.0.99/
User
admin
Password
admin (must be changed at first login)
Beta

In testing, with frequent updates

BerryCade is in beta: there may be bugs and behavior changes between versions. Test it before putting it at the edge of an important network, and keep a backup of the configuration (Sistema › Backup e Restauração).

The panel and the command line are in Brazilian Portuguese for now; this site and the user manual are also available in English. Found a problem or have a suggestion? Feedback from testers guides the next versions.

Go to support