A real firewall, on a Raspberry Pi.
Zone-to-zone policies with NAT, VLANs, PPPoE, IDS/IPS, web filter and VPN, configured from the browser, like commercial firewalls. Every change is tested before it takes effect, and rolls back on its own if you lose access.
Image for Raspberry Pi 3, 4 and 5 (.img.xz)
- Plain nftables
- Debian 13 "trixie"
- Suricata
- strongSwan
- Tailscale
| ID | Name | Source | Destination | Service | Action | Security |
|---|---|---|---|---|---|---|
| 1 | LAN-InternetLAN out to the internet with NAT | lan | wan | ALL | ✓ ACCEPT | — |
| 2 | LAN-VPNLAN to the VPN tunnels | lan | vpntailscale | ALL | ✓ ACCEPT | — |
| 3 | VPN-LANVPN tunnels to the LAN | vpn | lan | ALL | ✓ ACCEPT | — |
Red while the change is applied, green once it is in operation.
Built to sit at the edge of the network
A complete firewall
Plain nftables, zone-to-zone policies evaluated top to bottom, NAT on the rule itself, VLANs and PPPoE.
Security per policy
IPS (Suricata), category web filter and SSL inspection, turned on in each rule that needs them.
You can't lock yourself out
Every change must be confirmed through the new rules. Without confirmation within 60 s, the previous configuration comes back on its own.
Panel and kernel always match
The ruleset is swapped in one go, never halfway, and a checker fixes any drift.
Safe updates
Signed firmware (Ed25519), a self-test before activation, automatic rollback on failure and up to three installed versions.
Installs in minutes
A ready image to write to the card and a setup wizard on first access.
Everything from the browser
No editing files on the system: the panel validates, tests and applies every change, and keeps the history of all of them. The panel is in Brazilian Portuguese.
What comes with BerryCade
Organized like the panel menu.
Network
- Ports: onboard or any USB-Ethernet adapter, pinned by MAC address.
- WAN over PPPoE, DHCP or static IP.
- 802.1Q VLANs with their own IP range and zone.
- DHCP per interface, with reservations, revocation and banning.
- DNS with a local domain, and static routes.
Policy & objects
- Zone-to-zone policies with a logged implicit deny.
- NAT on the rule itself or in a central table.
- Addresses, services, virtual IPs (port forwarding) and pools.
- Per-rule counters; reorder by dragging the row.
Security profiles
- IDS/IPS with Suricata and ET Open rules updated every day.
- Web filter by category (UT1, Block List Project, HaGeZi), with a block page.
- SSL inspection by certificate or deep, with exemptions for banks.
- Anti-bypass: blocks DNS over TLS and over HTTPS.
VPN
- IPsec (strongSwan) with a wizard and an advanced mode.
- Pre-shared key or certificates with a local CA.
- Tailscale as subnet router and exit node.
Wi-Fi
- UniFi access points monitored over SSH, read-only.
- Wi-Fi networks (SSIDs) and AP settings stay on the UniFi controller.
- Clients with signal, channel, traffic and device name.
- The AP password is used once and is not stored.
System
- Revisions of every change, with rollback to any of them.
- Full backup, optionally encrypted.
- Administrators restricted by IP.
- Light and dark themes and custom colors.
Nothing counts until it's tested
The configuration file is the source of truth, versioned on every change. From clicking OK to the rule in operation:
Validate
Data and references between objects are checked before anything else.
Generate and test
Firewall, network, DNS, proxy and VPN are generated and tested: nft -c, dnsmasq --test, squid -k parse.
Apply in one go
The whole ruleset is swapped atomically, with no open window in between.
Confirm
The browser confirms through the new rules. The change becomes a revision.
Or roll back on its own
Without confirmation within 60 s, the previous configuration is restored.
Also from the console, with Tab
Everything you configure in the panel can also be configured from the console or over SSH. The Tab key completes commands, existing names, fields and values.
- The same validation and the same history as the panel.
- If a change cuts SSH off, the confirmation never arrives and everything rolls back.
- Recovery commands work even with the panel stopped.
# a new object, allowed in policy 1 $ berrycade add addresses name=server value=10.0.0.10/32 $ berrycade set policies 1 dst_addr+=server · nftables aplicado Alteração aplicada. Confirmar? [s/N] s confirmado (revisão 66f7b6d) # errors say what to fix $ berrycade set addresses server coment=x erro: campo desconhecido: coment - você quis dizer: comment?
From SD card to firewall
Write the image
Download berrycade-<version>.img.xz from the published releases and write it to the card with Raspberry Pi Imager ("Use custom") or balenaEtcher.
Adjust before powering on (optional)
Edit berrycade.txt on the boot partition: name, LAN IP, gateway and DNS.
Power on with the LAN connected
On first boot the partition is expanded and the wizard asks for the LAN and WAN ports, the LAN IP, the internet connection and the device name.
You will need
- Raspberry Pi 3, 4 or 5 (64-bit). For IDS/IPS, a Pi 4 or 5 with 4 GB or more.
- A microSD card of 8 GB or more.
- A second network port: any USB-Ethernet adapter.
First access
- Address
- https://10.0.0.99/
- User
- admin
- Password
- admin (must be changed at first login)
In testing, with frequent updates
BerryCade is in beta: there may be bugs and behavior changes between versions. Test it before putting it at the edge of an important network, and keep a backup of the configuration (Sistema › Backup e Restauração).
The panel and the command line are in Brazilian Portuguese for now; this site and the user manual are also available in English. Found a problem or have a suggestion? Feedback from testers guides the next versions.
Go to support