Re: Shorewall need clear to work after reboot
Rodrigo Araujo <[email protected]> Tue, 13 Jan 2026 16:23:15 +0000
| Newsgroups | gmane.comp.security.shorewall |
|---|---|
| Message-ID | <[email protected]> |
--===============0887283429805959219== Content-Type: multipart/alternative; boundary="=-RgVw6bDoC2j7Tuo93jAv" --=-RgVw6bDoC2j7Tuo93jAv Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Another suggestion: ensure firewalld (or other firewall system/service that may be present) is disabled/masked. It will clash with shorewall. On Tue, 2026-01-13 at 16:19 +0000, Rodrigo Araujo wrote: > rcortes, >=20 > can you confirm if you have "STARTUP_ENABLED=3DYes" in > /etc/shorewall/shorewall.conf ? >=20 > Best regards. >=20 >=20 > On Tue, 2026-01-13 at 11:11 -0500, Robert K Coffman Jr. -Info From > Data Corp. wrote: > > =20 > > Ok - what do the logs say after a reboot?=C2=A0 One potential issue tha= t > > might cause this is the status of any interfaces that are required > > but not ready when shorewall starts. > > =20 > > On 1/13/2026 9:52:47 AM, [email protected] wrote: > > =20 > > >=20 > > > Hi Robert, > > > =20 > > >=20 > > > =20 > > > =20 > > > I'm using systemcl=C2=A0 > > > =20 > > >=20 > > > =20 > > > =20 > > > systemctl enable shorewall after install package. > > > =20 > > >=20 > > > =20 > > > =20 > > > Thx. > > > =20 > > >=20 > > > =20 > > > =20 > > > El 2026-01-13 10:30, Robert K Coffman Jr. -Info From Data Corp. > > > escribi=C3=B3: > > > =20 > > > > =20 > > > > =20 > > > > How are you starting Shorewall after a reboot? > > > > =20 > > > >=20 > > > > =20 > > > > =20 > > > > On 1/13/2026 5:59:25 AM, rcortes--- via Shorewall-users wrote: > > > > =20 > > > > > Hi Simon,=20 > > > > >=20 > > > > > i use shorewall from shorewall site reference, in this case > > > > > 5.1.12 from > > > > > https://shorewall.org/pub/shorewall/5.1/shorewall-5.1.12/=20 > > > > > and 5.2.8 from > > > > > https://www.invoca.ch/pub/packages/shorewall/RPMS/ils-7/noarch/ > > > > >=20 > > > > >=20 > > > > > 5.1.12 or 5.1.10 start but dont work, need apply clear/start > > > > > to work.=20 > > > > > 5.2.8-12 start but dont work nat/dnat/proxyarp=20 > > > > >=20 > > > > > Thx=20 > > > > >=20 > > > > > El 2026-01-13 04:56, Simon Matter escribi=C3=B3:=20 > > > > >=20 > > > > > > Hi,=20 > > > > > >=20 > > > > > >=20 > > > > > > > Hello everyone!=20 > > > > > > >=20 > > > > > > > Somebody know why or how to fix shorewall for not need > > > > > > > clear and start=20 > > > > > > > after reboot?=C2=A0 i have EL7 and shorewall 5.1.12, > > > > > > > previously working with=20 > > > > > > > 5.1.10 and try with 5.2.8-12 but shorewall start but > > > > > > > nat/dnat/proxyarp=20 > > > > > > > dont work.=20 > > > > > >=20 > > > > > > Seems that your shorewall start is not working properly. > > > > > > Are you using a=20 > > > > > > shorewall package from epel? If so you could check the > > > > > > changelog to see=20 > > > > > > who has packaged it and ask directly?=20 > > > > > >=20 > > > > > > Regards,=20 > > > > > > Simon=20 > > > > >=20 > > > > >=20 > > > > > _______________________________________________=20 > > > > > Shorewall-users mailing list=20 > > > > > [email protected]=20 > > > > > https://lists.sourceforge.net/lists/listinfo/shorewall-users=20 > > > > =20 --=-RgVw6bDoC2j7Tuo93jAv Content-Type: text/html; charset="utf-8" Content-Transfer-Encoding: quoted-printable <html><head> =20 <style>pre,code,address { margin: 0px; } h1,h2,h3,h4,h5,h6 { margin-top: 0.2em; margin-bottom: 0.2em; } ol,ul { margin-top: 0em; margin-bottom: 0em; } blockquote { margin-top: 0em; margin-bottom: 0em; } </style><style>pre,code,address { margin: 0px; } h1,h2,h3,h4,h5,h6 { margin-top: 0.2em; margin-bottom: 0.2em; } ol,ul { margin-top: 0em; margin-bottom: 0em; } blockquote { margin-top: 0em; margin-bottom: 0em; } </style></head> <body><div>Another suggestion: ensure firewalld (or other firewall system= /service that may be present) is disabled/masked. It will clash with shorew= all.</div><div><br></div><div><br></div><div>On Tue, 2026-01-13 at 16:19 +0= 000, Rodrigo Araujo wrote:</div><blockquote type=3D"cite" style=3D"margin:0= 0 0 .8ex; border-left:2px #729fcf solid;padding-left:1ex"><div>rcortes,</d= iv><div><br></div><div>can you confirm if you have "STARTUP_ENABLED=3DYes" = in /etc/shorewall/shorewall.conf ?</div><div><br></div><div>Best regards.</= div><div><br></div><div><br></div><div>On Tue, 2026-01-13 at 11:11 -0500, R= obert K Coffman Jr. -Info From Data Corp. wrote:</div><blockquote type=3D"c= ite" style=3D"margin:0 0 0 .8ex; border-left:2px #729fcf solid;padding-left= :1ex"><div> </div><p>Ok - what do the logs say after a reboot? One po= tential issue that might cause this is the status of any interfaces that ar= e required but not ready when shorewall starts.</p><div> </div><div class= =3D"moz-cite-prefix">On 1/13/2026 9:52:47 AM, <a class=3D"moz-txt-link-abbr= eviated" href=3D"mailto:[email protected]">[email protected]</a> wrote:<br> </d= iv><div> <br></div><blockquote type=3D"cite" cite=3D"mid:40c0ed91eb6a2a1400= [email protected]" style=3D"margin:0 0 0 .8ex; border-left:2px #729fcf= solid;padding-left:1ex"><div> <meta http-equiv=3D"Content-Type" content=3D= "text/html; charset=3DUTF-8"> </div><p>Hi Robert,</p><div> </div><p><br> </= p><div> </div><p>I'm using systemcl </p><div> </div><p><br> </p><div> = </div><p>systemctl enable shorewall after install package.</p><div> </div><= p><br> </p><div> </div><p>Thx.</p><div> </div><p><br> </p><div> </div><p id= =3D"reply-intro">El 2026-01-13 10:30, Robert K Coffman Jr. -Info From Data = Corp. escribi=C3=B3:</p><div> <br></div><blockquote type=3D"cite" style=3D"= margin:0 0 0 .8ex; border-left:2px #729fcf solid;padding-left:1ex"><div> </= div><div id=3D"replybody1"> <p>How are you starting Shorewall after a reboo= t?</p> <p><br> </p> <div class=3D"v1moz-cite-prefix">On 1/13/2026 5:59:25 A= M, rcortes--- via Shorewall-users wrote:</div> <br><blockquote type=3D"cite= " style=3D"margin:0 0 0 .8ex; border-left:2px #729fcf solid;padding-left:1e= x"><div>Hi Simon, <br> <br> i use shorewall from shorewall site reference, = in this case 5.1.12 from <a class=3D"v1moz-txt-link-freetext moz-txt-link-f= reetext" href=3D"https://shorewall.org/pub/shorewall/5.1/shorewall-5.1.12/"= target=3D"_blank" rel=3D"noopener noreferrer" moz-do-not-send=3D"true">htt= ps://shorewall.org/pub/shorewall/5.1/shorewall-5.1.12/</a> <br> and 5.2.8 f= rom <a class=3D"v1moz-txt-link-freetext moz-txt-link-freetext" href=3D"http= s://www.invoca.ch/pub/packages/shorewall/RPMS/ils-7/noarch/" target=3D"_bla= nk" rel=3D"noopener noreferrer" moz-do-not-send=3D"true">https://www.invoca= .ch/pub/packages/shorewall/RPMS/ils-7/noarch/</a> <br> <br> 5.1.12 or 5.1.1= 0 start but dont work, need apply clear/start to work. <br> 5.2.8-12 start = but dont work nat/dnat/proxyarp <br> <br> Thx <br> <br> El 2026-01-13 04:56= , Simon Matter escribi=C3=B3: <br> <br></div><blockquote type=3D"cite" styl= e=3D"margin:0 0 0 .8ex; border-left:2px #729fcf solid;padding-left:1ex"><di= v>Hi, <br> <br> <br></div><blockquote type=3D"cite" style=3D"margin:0 0 0 .= 8ex; border-left:2px #729fcf solid;padding-left:1ex"><div>Hello everyone! <= br> <br> Somebody know why or how to fix shorewall for not need clear and s= tart <br> after reboot? i have EL7 and shorewall 5.1.12, previously w= orking with <br> 5.1.10 and try with 5.2.8-12 but shorewall start but nat/d= nat/proxyarp <br> dont work. </div></blockquote><div> <br> Seems that your = shorewall start is not working properly. Are you using a <br> shorewall pac= kage from epel? If so you could check the changelog to see <br> who has pac= kaged it and ask directly? <br> <br> Regards, <br> Simon </div></blockquote= ><div> <br> <br> _______________________________________________ <br> Shore= wall-users mailing list <br> <a class=3D"v1moz-txt-link-abbreviated moz-txt= -link-freetext" href=3D"mailto:[email protected]" rel= =3D"noreferrer" moz-do-not-send=3D"true">[email protected].= net</a> <br> <a class=3D"v1moz-txt-link-freetext moz-txt-link-freetext" hre= f=3D"https://lists.sourceforge.net/lists/listinfo/shorewall-users" target= =3D"_blank" rel=3D"noopener noreferrer" moz-do-not-send=3D"true">https://li= sts.sourceforge.net/lists/listinfo/shorewall-users</a> </div></blockquote> = <pre class=3D"v1moz-signature"></pre></div></blockquote></blockquote></bloc= kquote></blockquote><div><br></div><div><span></span></div></body></html> --=-RgVw6bDoC2j7Tuo93jAv-- --===============0887283429805959219== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============0887283429805959219== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline