Skip to main content

Install the zLAN firewall

note

Installing in an offline environment? See Install zLAN offline for required packages and steps.

System requirements​

To run the NetFoundry zLAN firewall, your system must meet the following requirements:

  • Operating system: Linux (Ubuntu, Debian, or RedHat-based distributions)
    • Ubuntu: 22.04 LTS (Jammy Jellyfish) and above (with kernel 6.1+)
    • Ubuntu: 24.04 LTS (Noble Numbat) and above
    • Debian: 12 (Bookworm) and above (with kernel 6.1+)
    • Debian: 13 (Trixie) and above
    • RedHat/CentOS/Rocky/AlmaLinux: 9.4 and above
  • Kernel version: 6.1 or higher (required for eBPF access)
  • CPU: Minimum 2 vCPU
  • Memory: Minimum 4 GB RAM
  • Storage: Minimum 20 GB available

Access requirements​

  • Root privileges are required for installation and configuration.
  • Internet access is required to download packages and enroll the firewall. For offline installs, pre-download packages as described in Install zLAN offline.
  • Access to the NetFoundry zLAN console to obtain the installation command or JWT token for enrollment.

Manual installation​

You can install the NetFoundry zLAN firewall either by using the copy-paste command from the console UI or by manually setting up the repository and running the setup script.

1. Configure the repository (private option)​

Run the following command to configure the NetFoundry repository (replace <username> and <password> with your credentials):

curl -sSL https://get.netfoundry.io/install.bash | sudo bash -s --private --username <username> --password <password>

This will set up the repository for your distribution and update package metadata.

2. Install the NetFoundry zLAN firewall package​

Install the package using your distribution's package manager:

import Tabs from '@theme/Tabs'; import TabItem from '@theme/TabItem';

sudo apt-get install zlan-firewall
sudo dnf install zlan-firewall

3. Enroll and configure the firewall​

Obtain your JWT token from the NetFoundry Console, then run:

sudo /opt/openziti/zlan/scripts/zlan-firewall-setup.sh <JWT_TOKEN>

This script will:

  • Generate the configuration file
  • Enroll the router using the JWT
  • Start the required services

Upgrade the firewall​

To upgrade the zLAN firewall, use your package manager:

sudo apt-get update
sudo apt-get upgrade zlan-firewall zfw zlan-router
sudo dnf upgrade zlan-firewall zfw zlan-router

Downgrading to a previous version using your package manager is possible, but not recommended. If an upgrade causes issues, contact NetFoundry support before attempting a rollback.