Re: Shorewall maintenance

Nate Bargmann <[email protected]> Sat, 8 Feb 2025 16:28:21 -0600
Newsgroups gmane.comp.security.shorewall
Organization Amateur Radio!
Message-ID <xdkcert2uvc5lyl3rqfm5tf6afdwodwo6aid7s22luhkua5rpe@qrgrbsmkfldw>
--===============0734453031274554226==
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="s32kybkhzaowepsc"
Content-Disposition: inline


--s32kybkhzaowepsc
Content-Type: text/plain; protected-headers=v1; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Subject: Re: [Shorewall-users] Shorewall maintenance
MIME-Version: 1.0

* On 2025 08 Feb 10:24 -0600, Wayne Shumaker wrote:
> I have now converted to foomuuri and find it was relatively painless,
> including ulogd2 logging. I also found adding blocklists fairly
> convenient with automatic daily updates.
>=20
> https://blog.frehi.be/2024/11/30/protecting-your-server-from-known-bad-ip=
s-with-foomuuri-iplists/
>=20
> and other things from https://blog.frehi.be/ - a former shorewall user.

I see that foomuuri is in Debian Bookworm backports and also includes a
replacement of firewalld for Network Manager.  I will have to check that
out for my laptop(s) where dynamic firewall rules are useful.

I've also used Shorewall and Shorewall6 for many years on my
workstations.  Even though my use case was quite simple as my OpenWrt
router handles most of the load.  Still I like the ease of knowing just
what ports are exposed to my LAN.  Thanks, Tom.

- Nate

--=20
"The optimist proclaims that we live in the best of all
possible worlds.  The pessimist fears this is true."
Web: https://www.n0nb.us
Projects: https://github.com/N0NB
GPG fingerprint: 82D6 4F6B 0E67 CD41 F689 BBA6 FB2C 5130 D55A 8819


--s32kybkhzaowepsc
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iF0EABECAB0WIQSC1k9rDmfNQfaJu6b7LFEw1VqIGQUCZ6fahAAKCRD7LFEw1VqI
GVNZAJ4kMCUWLUWlQXjvasmVjWDo9NFJ2gCdEpwk0Py75LFZUbNqmO/ygB0jOGo=
=wqSR
-----END PGP SIGNATURE-----

--s32kybkhzaowepsc--


--===============0734453031274554226==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============0734453031274554226==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline