the ideas for the firewall are:
- make it as easy as possible
- no manual changes needed
- ports are opened/closed "automatic"
- NAT works by default
- there are contribs for port-opening, port-closing, port-forwarding, and so on
- its no need for editing the iptables-rules
cheers klaus