Re: Shorewall maintenance

Wayne Shumaker <[email protected]> Sat, 08 Feb 2025 08:56:02 -0700
Newsgroups gmane.comp.security.shorewall
Message-ID <[email protected]>
--===============4506155873469799468==
Content-Type: multipart/alternative;
	boundary="=====================_6414171==.ALT"

--=====================_6414171==.ALT
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

At 2/6/2025 02:25 PM, Winston wrote:

>Shorewall (and Shorewall6) has been fantastic to me, as a multi-ISP user.=
=C2  I'm deeply indebted to Tom for this fantastic tool, and all the work he=
 put into the documentation especially. Nothing else seems to come close to=
 ease-of-configuration and maintenance.=C2  I'm dreading the day when Debian=
 (or the kernel itself) moves iptables from deprecated to discarded, and I=
 know that nftables is the future, but I'm still yet waiting for something=
 that even comes close before I risk destablizing everything my home system=
 relies upon.=C2  Tom, if you're reading this, can I ask - are you still=
 running your own systems, and what you expect to be shifting to yourself?

I have used shorewall since I can't remember. I struggled quite a while (4=
 years) trying to find an alternative to shorewall. Nothing was right for me=
 and nothing compared to shorewall, until foomuuri came along. Yes, systemd=
 is likely needed. foomuuri is still young but I see it as my path forward=
 with nftables.

As for iptables going obsolete, on my previous debian (bookworm) router=
 using shorewall, typing:

nft list ruleset

I see that the shorewall iptables was converted to nftables anyway via=
 iptables-nft. So as long as iptables-nft exists, shorewall should be=
 converting to nftables.

I have now converted to foomuuri and find it was relatively painless,=
 including ulogd2 logging. I also found adding blocklists fairly convenient=
 with automatic daily updates.

https://blog.frehi.be/2024/11/30/protecting-your-server-from-known-bad-ips-w=
ith-foomuuri-iplists/

and other things from https://blog.frehi.be/ - a former shorewall user.

Wayne








--=====================_6414171==.ALT
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html>
<body>
<font size=3D3>At 2/6/2025 02:25 PM, Winston wrote:<br><br>
<blockquote type=3Dcite class=3Dcite cite=3D"">Shorewall (and Shorewall6) ha=
s
been fantastic to me, as a multi-ISP user.=C2&nbsp; I'm deeply indebted to
Tom for this fantastic tool, and all the work he put into the
documentation especially. Nothing else seems to come close to
ease-of-configuration and maintenance.=C2&nbsp; I'm dreading the day when
Debian (or the kernel itself) moves iptables from deprecated to
discarded, and I know that nftables is the future, but I'm still yet
waiting for something that even comes close before I risk destablizing
everything my home system relies upon.=C2&nbsp; Tom, if you're reading
this, can I ask - are you still running your own systems, and what you
expect to be shifting to yourself?</blockquote><br>
</font>I have used shorewall since I can't remember. I struggled quite a
while (4 years) trying to find an alternative to shorewall. Nothing was
right for me and nothing compared to shorewall, until foomuuri came
along. Yes, systemd is likely needed. foomuuri is still young but I see
it as my path forward with nftables.<br><br>
As for iptables going obsolete, on my previous debian (bookworm) router
using shorewall, typing:<br><br>
nft list ruleset<br><br>
I see that the shorewall iptables was converted to nftables anyway via
iptables-nft. So as long as iptables-nft exists, shorewall should be
converting to nftables.<br><br>
I have now converted to foomuuri and find it was relatively painless,
including ulogd2 logging. I also found adding blocklists fairly
convenient with automatic daily updates.<br><br>
<a=
 href=3D"https://blog.frehi.be/2024/11/30/protecting-your-server-from-known-=
bad-ips-with-foomuuri-iplists/" eudora=3D"autourl">
https://blog.frehi.be/2024/11/30/protecting-your-server-from-known-bad-ips-w=
ith-foomuuri-iplists/</a>
<br><br>
and other things from
<a href=3D"https://blog.frehi.be/" eudora=3D"autourl">
https://blog.frehi.be/</a> - a former shorewall user.<br><br>
Wayne<br><br>
<br><br>
<br><br>
<br><br>
</body>
</html>

--=====================_6414171==.ALT--



--===============4506155873469799468==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============4506155873469799468==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline