Re: Comments needed!
I implemented IP filters for one gateway and two servers in a DMZ network with ferm, and it it VERY easy to setup. Way better then other filter setup scripts, because you don't lose the flexibility of the iptables system.
The only thing missing is an init script to load a pre-defined ferm script (say, /etc/ip-filter.ferm). But this might be a job for packagers.