Skip to content
BerryCade BETA
User manual

1. Introduction

BerryCade turns a Raspberry Pi into a complete firewall for the internet edge. It connects the internal network to the internet (including over PPPoE), splits the network into zones and VLANs, controls what can pass between them, and protects traffic with IDS/IPS, a category-based web filter and SSL inspection. It also provides IPsec and Tailscale VPN and monitors UniFi Wi-Fi access points.

Warning

Warning: BerryCade is in Beta: it is already available for everyone to try, but it is still being tested and receives frequent updates. There may be bugs and changes between versions — test it before using it at the edge of an important network, and keep a backup of the configuration.

All administration is done from the web panel. You don't need to edit files on the system: the panel validates each change, tests it before applying it and keeps a revision history.

Tip

Tip: to learn how to use the panel, turn on the tips in Sistema › Configurações › Aparência (System › Settings › Appearance): check Mostrar dicas (Show tips) and click Salvar tema (Save theme). With tips on, dialogs show explanatory boxes and each field gets a help text. The option applies to all administrators and can be turned off when you no longer need it.

1.1 Key concepts

ConceptWhat it is
InterfaceA network port (physical, VLAN or tunnel). Each interface belongs to a zone.
ZoneA group of interfaces with the same trust level, for example lan, wan, vpn. Rules are written between zones.
PolicyA firewall rule from a source zone to a destination zone: whatever matches is accepted, denied or rejected. Policies are evaluated from top to bottom; the first match decides.
Implicit denyAnything that doesn't match any policy is dropped and logged.
ObjectsReusable names for addresses (IP, network, range, FQDN, group) and services (ports and protocols), used in policies.
Security profilesIPS, web filter and SSL inspection. They are enabled in each policy.
NATAddress translation: lets the internal network browse using the WAN IP (source NAT) or publishes an internal service (Virtual IP).

1.2 How changes are applied

When you click OK or Aplicar (Apply), BerryCade:

  1. validates the data and the references between objects;
  2. generates the system configuration (nftables, network, DNS/DHCP, VPN, etc.) and tests each one before applying it;
  3. applies everything atomically — the rule set is swapped all at once, never halfway;
  4. confirms the change from the browser through the new rules;
  5. saves the revision to the history.
Tip

Important: if the confirmation doesn't arrive within 60 seconds — for example, because the change blocked your own access — the previous configuration rolls back automatically. So after you change the LAN IP or the panel port, open the new address and click Confirmar (Confirm) on the yellow bar.