1. Introduction
BerryCade turns a Raspberry Pi into a complete firewall for the internet edge. It connects the internal network to the internet (including over PPPoE), splits the network into zones and VLANs, controls what can pass between them, and protects traffic with IDS/IPS, a category-based web filter and SSL inspection. It also provides IPsec and Tailscale VPN and monitors UniFi Wi-Fi access points.
Warning: BerryCade is in Beta: it is already available for everyone to try, but it is still being tested and receives frequent updates. There may be bugs and changes between versions — test it before using it at the edge of an important network, and keep a backup of the configuration.
All administration is done from the web panel. You don't need to edit files on the system: the panel validates each change, tests it before applying it and keeps a revision history.
Tip: to learn how to use the panel, turn on the tips in Sistema › Configurações › Aparência (System › Settings › Appearance): check Mostrar dicas (Show tips) and click Salvar tema (Save theme). With tips on, dialogs show explanatory boxes and each field gets a help text. The option applies to all administrators and can be turned off when you no longer need it.
1.1 Key concepts
| Concept | What it is |
|---|---|
| Interface | A network port (physical, VLAN or tunnel). Each interface belongs to a zone. |
| Zone | A group of interfaces with the same trust level, for example lan, wan, vpn. Rules are written between zones. |
| Policy | A firewall rule from a source zone to a destination zone: whatever matches is accepted, denied or rejected. Policies are evaluated from top to bottom; the first match decides. |
| Implicit deny | Anything that doesn't match any policy is dropped and logged. |
| Objects | Reusable names for addresses (IP, network, range, FQDN, group) and services (ports and protocols), used in policies. |
| Security profiles | IPS, web filter and SSL inspection. They are enabled in each policy. |
| NAT | Address translation: lets the internal network browse using the WAN IP (source NAT) or publishes an internal service (Virtual IP). |
1.2 How changes are applied
When you click OK or Aplicar (Apply), BerryCade:
- validates the data and the references between objects;
- generates the system configuration (nftables, network, DNS/DHCP, VPN, etc.) and tests each one before applying it;
- applies everything atomically — the rule set is swapped all at once, never halfway;
- confirms the change from the browser through the new rules;
- saves the revision to the history.
Important: if the confirmation doesn't arrive within 60 seconds — for example, because the change blocked your own access — the previous configuration rolls back automatically. So after you change the LAN IP or the panel port, open the new address and click Confirmar (Confirm) on the yellow bar.