Just my 2 cents.
There is a package on sourceforge called fwbuilder. Its a GTK based app that look like Checkpoint, much cooler, actually. It doesnt do VPN stuff, but it allows you to manage objects and eveything else. It creates the rules for the firewalls in xml, and then compiles the xml into either iptables rules, or ipfilter rules (BSD).
It make managing many firewalls very easy.
Maintained by the ILUG website team. The aim of Linux.ie is to
support and help commercial and private users of Linux in Ireland. You can
display ILUG news in your own webpages, read backend
information to find out how. Networking services kindly provided by HEAnet, server kindly donated by
Dell. Linux is a trademark of Linus Torvalds,
used with permission. No penguins were harmed in the production or maintenance
of this highly praised website. Looking for the
Indian Linux Users' Group? Try here. If you've read all this and aren't a lawyer: you should be!