Re: Shorewall need clear to work after reboot

Rodrigo Araujo <[email protected]> Tue, 13 Jan 2026 16:23:15 +0000
Newsgroups gmane.comp.security.shorewall
Message-ID <[email protected]>
--===============0887283429805959219==
Content-Type: multipart/alternative; boundary="=-RgVw6bDoC2j7Tuo93jAv"

--=-RgVw6bDoC2j7Tuo93jAv
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Another suggestion: ensure firewalld (or other firewall system/service
that may be present) is disabled/masked. It will clash with shorewall.


On Tue, 2026-01-13 at 16:19 +0000, Rodrigo Araujo wrote:
> rcortes,
>=20
> can you confirm if you have "STARTUP_ENABLED=3DYes" in
> /etc/shorewall/shorewall.conf ?
>=20
> Best regards.
>=20
>=20
> On Tue, 2026-01-13 at 11:11 -0500, Robert K Coffman Jr. -Info From
> Data Corp. wrote:
> > =20
> > Ok - what do the logs say after a reboot?=C2=A0 One potential issue tha=
t
> > might cause this is the status of any interfaces that are required
> > but not ready when shorewall starts.
> > =20
> > On 1/13/2026 9:52:47 AM, [email protected] wrote:
> > =20
> > >=20
> > > Hi Robert,
> > > =20
> > >=20
> > > =20
> > > =20
> > > I'm using systemcl=C2=A0
> > > =20
> > >=20
> > > =20
> > > =20
> > > systemctl enable shorewall after install package.
> > > =20
> > >=20
> > > =20
> > > =20
> > > Thx.
> > > =20
> > >=20
> > > =20
> > > =20
> > > El 2026-01-13 10:30, Robert K Coffman Jr. -Info From Data Corp.
> > > escribi=C3=B3:
> > > =20
> > > > =20
> > > > =20
> > > > How are you starting Shorewall after a reboot?
> > > > =20
> > > >=20
> > > > =20
> > > > =20
> > > > On 1/13/2026 5:59:25 AM, rcortes--- via Shorewall-users wrote:
> > > > =20
> > > > > Hi Simon,=20
> > > > >=20
> > > > > i use shorewall from shorewall site reference, in this case
> > > > > 5.1.12 from
> > > > > https://shorewall.org/pub/shorewall/5.1/shorewall-5.1.12/=20
> > > > > and 5.2.8 from
> > > > > https://www.invoca.ch/pub/packages/shorewall/RPMS/ils-7/noarch/
> > > > >=20
> > > > >=20
> > > > > 5.1.12 or 5.1.10 start but dont work, need apply clear/start
> > > > > to work.=20
> > > > > 5.2.8-12 start but dont work nat/dnat/proxyarp=20
> > > > >=20
> > > > > Thx=20
> > > > >=20
> > > > > El 2026-01-13 04:56, Simon Matter escribi=C3=B3:=20
> > > > >=20
> > > > > > Hi,=20
> > > > > >=20
> > > > > >=20
> > > > > > > Hello everyone!=20
> > > > > > >=20
> > > > > > > Somebody know why or how to fix shorewall for not need
> > > > > > > clear and start=20
> > > > > > > after reboot?=C2=A0 i have EL7 and shorewall 5.1.12,
> > > > > > > previously working with=20
> > > > > > > 5.1.10 and try with 5.2.8-12 but shorewall start but
> > > > > > > nat/dnat/proxyarp=20
> > > > > > > dont work.=20
> > > > > >=20
> > > > > > Seems that your shorewall start is not working properly.
> > > > > > Are you using a=20
> > > > > > shorewall package from epel? If so you could check the
> > > > > > changelog to see=20
> > > > > > who has packaged it and ask directly?=20
> > > > > >=20
> > > > > > Regards,=20
> > > > > > Simon=20
> > > > >=20
> > > > >=20
> > > > > _______________________________________________=20
> > > > > Shorewall-users mailing list=20
> > > > > [email protected]=20
> > > > > https://lists.sourceforge.net/lists/listinfo/shorewall-users=20
> > > > =20

--=-RgVw6bDoC2j7Tuo93jAv
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

<html><head>
   =20
  <style>pre,code,address {
  margin: 0px;
}
h1,h2,h3,h4,h5,h6 {
  margin-top: 0.2em;
  margin-bottom: 0.2em;
}
ol,ul {
  margin-top: 0em;
  margin-bottom: 0em;
}
blockquote {
  margin-top: 0em;
  margin-bottom: 0em;
}
</style><style>pre,code,address {
  margin: 0px;
}
h1,h2,h3,h4,h5,h6 {
  margin-top: 0.2em;
  margin-bottom: 0.2em;
}
ol,ul {
  margin-top: 0em;
  margin-bottom: 0em;
}
blockquote {
  margin-top: 0em;
  margin-bottom: 0em;
}
</style></head>
  <body><div>Another suggestion: ensure firewalld (or other firewall system=
/service that may be present) is disabled/masked. It will clash with shorew=
all.</div><div><br></div><div><br></div><div>On Tue, 2026-01-13 at 16:19 +0=
000, Rodrigo Araujo wrote:</div><blockquote type=3D"cite" style=3D"margin:0=
 0 0 .8ex; border-left:2px #729fcf solid;padding-left:1ex"><div>rcortes,</d=
iv><div><br></div><div>can you confirm if you have "STARTUP_ENABLED=3DYes" =
in /etc/shorewall/shorewall.conf ?</div><div><br></div><div>Best regards.</=
div><div><br></div><div><br></div><div>On Tue, 2026-01-13 at 11:11 -0500, R=
obert K Coffman Jr. -Info From Data Corp. wrote:</div><blockquote type=3D"c=
ite" style=3D"margin:0 0 0 .8ex; border-left:2px #729fcf solid;padding-left=
:1ex"><div> </div><p>Ok - what do the logs say after a reboot?&nbsp; One po=
tential issue that might cause this is the status of any interfaces that ar=
e required but not ready when shorewall starts.</p><div> </div><div class=
=3D"moz-cite-prefix">On 1/13/2026 9:52:47 AM, <a class=3D"moz-txt-link-abbr=
eviated" href=3D"mailto:[email protected]">[email protected]</a> wrote:<br> </d=
iv><div> <br></div><blockquote type=3D"cite" cite=3D"mid:40c0ed91eb6a2a1400=
[email protected]" style=3D"margin:0 0 0 .8ex; border-left:2px #729fcf=
 solid;padding-left:1ex"><div> <meta http-equiv=3D"Content-Type" content=3D=
"text/html; charset=3DUTF-8"> </div><p>Hi Robert,</p><div> </div><p><br> </=
p><div> </div><p>I'm using systemcl&nbsp;</p><div> </div><p><br> </p><div> =
</div><p>systemctl enable shorewall after install package.</p><div> </div><=
p><br> </p><div> </div><p>Thx.</p><div> </div><p><br> </p><div> </div><p id=
=3D"reply-intro">El 2026-01-13 10:30, Robert K Coffman Jr. -Info From Data =
Corp. escribi=C3=B3:</p><div> <br></div><blockquote type=3D"cite" style=3D"=
margin:0 0 0 .8ex; border-left:2px #729fcf solid;padding-left:1ex"><div> </=
div><div id=3D"replybody1"> <p>How are you starting Shorewall after a reboo=
t?</p> <p><br> </p> <div class=3D"v1moz-cite-prefix">On 1/13/2026 5:59:25 A=
M, rcortes--- via Shorewall-users wrote:</div> <br><blockquote type=3D"cite=
" style=3D"margin:0 0 0 .8ex; border-left:2px #729fcf solid;padding-left:1e=
x"><div>Hi Simon, <br> <br> i use shorewall from shorewall site reference, =
in this case 5.1.12 from <a class=3D"v1moz-txt-link-freetext moz-txt-link-f=
reetext" href=3D"https://shorewall.org/pub/shorewall/5.1/shorewall-5.1.12/"=
 target=3D"_blank" rel=3D"noopener noreferrer" moz-do-not-send=3D"true">htt=
ps://shorewall.org/pub/shorewall/5.1/shorewall-5.1.12/</a> <br> and 5.2.8 f=
rom <a class=3D"v1moz-txt-link-freetext moz-txt-link-freetext" href=3D"http=
s://www.invoca.ch/pub/packages/shorewall/RPMS/ils-7/noarch/" target=3D"_bla=
nk" rel=3D"noopener noreferrer" moz-do-not-send=3D"true">https://www.invoca=
.ch/pub/packages/shorewall/RPMS/ils-7/noarch/</a> <br> <br> 5.1.12 or 5.1.1=
0 start but dont work, need apply clear/start to work. <br> 5.2.8-12 start =
but dont work nat/dnat/proxyarp <br> <br> Thx <br> <br> El 2026-01-13 04:56=
, Simon Matter escribi=C3=B3: <br> <br></div><blockquote type=3D"cite" styl=
e=3D"margin:0 0 0 .8ex; border-left:2px #729fcf solid;padding-left:1ex"><di=
v>Hi, <br> <br> <br></div><blockquote type=3D"cite" style=3D"margin:0 0 0 .=
8ex; border-left:2px #729fcf solid;padding-left:1ex"><div>Hello everyone! <=
br> <br> Somebody know why or how to fix shorewall for not need clear and s=
tart <br> after reboot?&nbsp; i have EL7 and shorewall 5.1.12, previously w=
orking with <br> 5.1.10 and try with 5.2.8-12 but shorewall start but nat/d=
nat/proxyarp <br> dont work. </div></blockquote><div> <br> Seems that your =
shorewall start is not working properly. Are you using a <br> shorewall pac=
kage from epel? If so you could check the changelog to see <br> who has pac=
kaged it and ask directly? <br> <br> Regards, <br> Simon </div></blockquote=
><div> <br> <br> _______________________________________________ <br> Shore=
wall-users mailing list <br> <a class=3D"v1moz-txt-link-abbreviated moz-txt=
-link-freetext" href=3D"mailto:[email protected]" rel=
=3D"noreferrer" moz-do-not-send=3D"true">[email protected].=
net</a> <br> <a class=3D"v1moz-txt-link-freetext moz-txt-link-freetext" hre=
f=3D"https://lists.sourceforge.net/lists/listinfo/shorewall-users" target=
=3D"_blank" rel=3D"noopener noreferrer" moz-do-not-send=3D"true">https://li=
sts.sourceforge.net/lists/listinfo/shorewall-users</a> </div></blockquote> =
<pre class=3D"v1moz-signature"></pre></div></blockquote></blockquote></bloc=
kquote></blockquote><div><br></div><div><span></span></div></body></html>

--=-RgVw6bDoC2j7Tuo93jAv--


--===============0887283429805959219==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============0887283429805959219==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline