NuFW adds user-based filtering to Netfilter, the state of the art IP filtering layer from the Linux kernel. Its exclusive algorithm allows authenticated filtering even on multiuser computers.
NuFW can be seen as an Identity access management solution, at the network level.
NuFW can :
Authenticate any connection that goes through your gateway or only from/to a chosen subset or a specific protocol.
Perform accounting, routing and quality of service based on users and not simply on IPs.
Filter packets with criterium such as application and OS used by distant users.
Log all traffic in SQL with username and application information
Be the key of a secure and simple Single Sign On system.
For a more precise presentation see NuFW Motivation.