Skip to content

Panel Firewall

Host-level firewall & DDoS mitigation for the Pterodactyl Panel host itself — panel pages, API, websocket, and SFTP traffic terminating on the panel machine — driven by an admin-only panel UI that talks to a privileged, HMAC-authenticated Node.js daemon.

Panel Firewall protects the machine your panel runs on, not the game servers. It programs kernel iptables/ipset rules through atomic iptables-restore transactions with checkpoints, a 60-second confirm/auto-rollback window, and an emergency safe mode — so a bad apply can never lock you out. On top of the static L3/L4 ruleset, a SMART engine watches traffic with EWMA anomaly detection and escalates through L1→L3 mitigations automatically, while an L7 sensor tails the web server's access log and temporarily bans HTTP-flood sources — with no nginx/apache config changes required.

Built for PingLess Studios by AnAverageBeingGitHub Repo · Studio

Panel host vs. per-server protection

Panel Firewall guards the panel host only. For per-game-server container firewalling, see the sibling project Firewall-Plus.


Architecture

The panel never calls iptables or ipset. Every mutation is an HMAC-signed JSON request to the daemon, a Fastify + better-sqlite3 service on 127.0.0.1:8475 running as root under a sandboxed systemd unit (CAP_NET_ADMIN/CAP_NET_RAW only). The daemon is the single privileged component and refuses to touch any chain, rule, or ipset outside its reserved PTDL_* / ptdl-* ownership prefixes.


Key Features

  • L3/L4 packet hygiene & rate limiting — invalid/fragment/null-scan/XMAS/NEW-non-SYN drops, per-IP NEW-connection and SYN hashlimits, whitelist-first rule order with a final RETURN safety rail. See Protection Layers.
  • 5 traffic presetslow, medium, high, veryHigh, underAttack, tuning PPS/CPS/SYN/burst/concurrency ceilings per deployment.
  • Whitelist & blacklist ipsetshash:net sets with strict CIDR validation, O(1) kernel lookup, and temp-ban automation with expiry.
  • SMART adaptive mitigation — EWMA + variance anomaly detection (default 4σ) driving L1→L3 mitigation levels with cooldowns and repeat-offender scoring.
  • L7 HTTP-flood detection — tails nginx/apache/caddy access logs (autodetected), counts per-IP request rates in a sliding window, and feeds offenders into the temp-ban ipset with a per-minute ban budget. Private/reserved IPs and whitelist entries are never banned.
  • Transactional, crash-safe applies — plan → validate → fsync'd checkpoint → atomic iptables-restore --noflush → verify → 60s confirm window with automatic rollback, plus startup recovery of expired pending applies.
  • One-command install — Blueprint .blueprint or standalone install.sh; the installer auto-installs the daemon and auto-generates the shared bearer token. No manual token step.
  • Analytics & audit — traffic, mitigation and ban timeseries with Chart.js graphs, dual panel+daemon audit logs, Discord-compatible webhooks with HMAC secrets.

Quick Install

bash
cd /var/www/pterodactyl
blueprint -install pterodactylpanelfirewall-v0.3.0.blueprint
bash
cd panel-firewall-standalone
sudo bash install.sh

Both paths end the same way: files merged, migrations run, daemon installed to /opt/panel-firewall, 64-hex token generated and synced into the panel DB, systemd service running. See Installation for the full guide and troubleshooting.


Blueprint vs Standalone

BlueprintStandalone
RequirementBlueprint framework installedStock Pterodactyl panel, root shell
Install commandblueprint -install <file>.blueprintsudo bash install.sh
Daemon auto-install + auto tokenYesYes
Provider registrationdata/install.sh (hard fail)data/patch.sh (hard fail)
Laravel 11 bootstrap/providers.phpSupportedSupported
Uninstallblueprint -remove / data/remove.shsudo bash uninstall.sh
Data kept on removeYes (unless --purge-data)Yes (unless --purge-data)

Documentation Map