Re: Monitoring utility

Winston Sorfleet <[email protected]> Fri, 10 Oct 2025 17:30:28 -0400
Newsgroups gmane.comp.security.shorewall
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============0577571837467180496==
Content-Type: multipart/alternative;
 boundary="------------00TKJg1DBSpnDoTKjps6J04Z"
Content-Language: en-CA

This is a multi-part message in MIME format.
--------------00TKJg1DBSpnDoTKjps6J04Z
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

I'm not sure what you want by "as it operates".  Shorewall(6) only 
creates rules, and AFAIK, the rules aren't dynamic (barring some things 
like failover setups).  You can see the various rules after shorewall 
starts (e.g. all the chains with shorewall show). Of course, the rules 
can include logging, so you can see what happens *as a result* of those 
rules, at the packet level, in the kernel log.  Other than tail -f 
/var/log/kern.log, I am not sure what else can be done to monitor what 
shorewall is doing, tools like tcpdump.

On 2025-10-10 04:43, Luca Saccarola wrote:
> Hi there,
>
> Wikipedia (https://en.wikipedia.org/wiki/Shorewall) states that "A 
> monitoring utility packaged with Shorewall can be used to watch the 
> status of the system as it operates and to assist in testing.". Can 
> you tell me which utility they are referring to ?
>
> Best,
> Luca
>
>
> _______________________________________________
> Shorewall-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/shorewall-users
--------------00TKJg1DBSpnDoTKjps6J04Z
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>I'm not sure what you want by "as it operates".  Shorewall(6)
      only creates rules, and AFAIK, the rules aren't dynamic (barring
      some things like failover setups).  You can see the various rules
      after shorewall starts (e.g. all the chains with shorewall show). 
      Of course, the rules can include logging, so you can see what
      happens *as a result* of those rules, at the packet level, in the
      kernel log.  Other than tail -f /var/log/kern.log, I am not sure
      what else can be done to monitor what shorewall is doing, tools
      like tcpdump.<br>
    </p>
    <div class="moz-cite-prefix">On 2025-10-10 04:43, Luca Saccarola
      wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:CAND9tcOVrTt=4bgOYmx8Antz8pCtAWH7kn-utACdsFr01+o+Nw@mail.gmail.com">
      <meta http-equiv="content-type" content="text/html; charset=UTF-8">
      <div dir="ltr">
        <div>
          <div style="font-family:verdana,sans-serif"
            class="gmail_default"><font size="2">Hi there,</font></div>
          <div class="gmail_default"><font size="2"><span
                style="font-family:verdana,sans-serif"><br>
              </span></font></div>
          <div style="font-family:verdana,sans-serif"
            class="gmail_default"><font size="2">Wikipedia (</font><a
              href="https://en.wikipedia.org/wiki/Shorewall"
              moz-do-not-send="true" class="moz-txt-link-freetext">https://en.wikipedia.org/wiki/Shorewall</a>) <font
              size="2">states that "<span
style="color:rgb(32,33,34);font-style:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-decoration:none;display:inline;float:none">A
                monitoring utility packaged with Shorewall can be used
                to watch the status of the system as it operates and to
                assist in testing.". C</span></font>an you tell me which
            utility they are referring to ?</div>
          <br>
        </div>
        <div>
          <div style="font-family:verdana,sans-serif;font-size:small"
            class="gmail_default">Best,</div>
        </div>
        <div>
          <div dir="ltr" class="gmail_signature"
            data-smartmail="gmail_signature">
            <div dir="ltr">
              <div>Luca</div>
            </div>
          </div>
        </div>
      </div>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
      <pre wrap="" class="moz-quote-pre">_______________________________________________
Shorewall-users mailing list
<a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
<a class="moz-txt-link-freetext" href="https://lists.sourceforge.net/lists/listinfo/shorewall-users">https://lists.sourceforge.net/lists/listinfo/shorewall-users</a>
</pre>
    </blockquote>
  </body>
</html>

--------------00TKJg1DBSpnDoTKjps6J04Z--


--===============0577571837467180496==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============0577571837467180496==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline