I agree with phish, fwbuilder is the way to go. It looks a lot like Checkpoint, and works great. For work my scripts are fairly simple usually only allowing one or two open ports to a range of ip...