Re: Shorewall need clear to work after reboot
rcortes--- via Shorewall-users <[email protected]> Tue, 13 Jan 2026 13:31:44 -0300
| Newsgroups | gmane.comp.security.shorewall |
|---|---|
| Message-ID | <[email protected]> |
--===============0147133549395526574==
Content-Type: multipart/alternative;
boundary="=_370ca7aa941d3898d8515fec771a0332"
--=_370ca7aa941d3898d8515fec771a0332
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset=UTF-8;
format=flowed
is correct, startup is enable :)
shorewall show startup ok
[root@leviathan ~]# systemctl status shorewall
● shorewall.service - Shorewall IPv4 firewall
Loaded: loaded (/usr/lib/systemd/system/shorewall.service; enabled;
vendor preset: disabled)
Active: active (exited) since Tue 2026-01-13 09:48:45 EST; 1h 42min
ago
Process: 1042 ExecStart=/usr/sbin/shorewall $OPTIONS start
$STARTOPTIONS (code=exited, status=0/SUCCESS)
Main PID: 1042 (code=exited, status=0/SUCCESS)
CGroup: /system.slice/shorewall.service
Jan 13 09:48:44 leviathan.cypco.cl shorewall[1042]: Processing
/etc/shorewall/tcclear ...
Jan 13 09:48:44 leviathan.cypco.cl shorewall[1042]: Setting up Route
Filtering...
Jan 13 09:48:44 leviathan.cypco.cl shorewall[1042]: Setting up Martian
Logging...
Jan 13 09:48:44 leviathan.cypco.cl shorewall[1042]: Setting up Proxy
ARP...
Jan 13 09:48:45 leviathan.cypco.cl shorewall[1042]: Preparing
iptables-restore input...
Jan 13 09:48:45 leviathan.cypco.cl shorewall[1042]: Running
/sbin/iptables-restore --wait 60...
Jan 13 09:48:45 leviathan.cypco.cl shorewall[1042]: Processing
/etc/shorewall/start ...
Jan 13 09:48:45 leviathan.cypco.cl shorewall[1042]: Processing
/etc/shorewall/started ...
Jan 13 09:48:45 leviathan.cypco.cl shorewall[1042]: done.
Jan 13 09:48:45 leviathan.cypco.cl systemd[1]: Started Shorewall IPv4
firewall.
Thx.
El 2026-01-13 13:19, Rodrigo Araujo escribió:
> rcortes,
>
> can you confirm if you have "STARTUP_ENABLED=Yes" in
> /etc/shorewall/shorewall.conf ?
>
> Best regards.
>
> On Tue, 2026-01-13 at 11:11 -0500, Robert K Coffman Jr. -Info From Data
> Corp. wrote:
>
> Ok - what do the logs say after a reboot? One potential issue that
> might cause this is the status of any interfaces that are required but
> not ready when shorewall starts.
>
> On 1/13/2026 9:52:47 AM, [email protected] wrote:
>
> Hi Robert,
>
> I'm using systemcl
>
> systemctl enable shorewall after install package.
>
> Thx.
>
> El 2026-01-13 10:30, Robert K Coffman Jr. -Info From Data Corp.
> escribió:
>
> How are you starting Shorewall after a reboot?
>
> On 1/13/2026 5:59:25 AM, rcortes--- via Shorewall-users wrote:
>
> Hi Simon,
>
> i use shorewall from shorewall site reference, in this case 5.1.12 from
> https://shorewall.org/pub/shorewall/5.1/shorewall-5.1.12/
> and 5.2.8 from
> https://www.invoca.ch/pub/packages/shorewall/RPMS/ils-7/noarch/
>
> 5.1.12 or 5.1.10 start but dont work, need apply clear/start to work.
> 5.2.8-12 start but dont work nat/dnat/proxyarp
>
> Thx
>
> El 2026-01-13 04:56, Simon Matter escribió:
>
> Hi,
>
> Hello everyone!
>
> Somebody know why or how to fix shorewall for not need clear and start
> after reboot? i have EL7 and shorewall 5.1.12, previously working with
> 5.1.10 and try with 5.2.8-12 but shorewall start but nat/dnat/proxyarp
> dont work.
>
> Seems that your shorewall start is not working properly. Are you using
> a
> shorewall package from epel? If so you could check the changelog to see
> who has packaged it and ask directly?
>
> Regards,
> Simon
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users
--
Robert K Coffman Jr.
Info From Data Corp.
3307249000
[email protected]
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users
--=_370ca7aa941d3898d8515fec771a0332
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset=UTF-8
<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; charset=
=3DUTF-8" /></head><body style=3D'font-size: 10pt; font-family: Verdana,Gen=
eva,sans-serif'>
<p>is correct, startup is enable :)</p>
<p><br /></p>
<p>shorewall show startup ok</p>
<div id=3D"signature"></div>
<p>[root@leviathan ~]# systemctl status shorewall<br />=E2=97=8F shorewall.=
service - Shorewall IPv4 firewall<br /> Loaded: loaded (/usr/li=
b/systemd/system/shorewall.service; enabled; vendor preset: disabled)<br />=
Active: active (exited) since Tue 2026-01-13 09:48:45 EST; 1h =
42min ago<br /> Process: 1042 ExecStart=3D/usr/sbin/shorewall $OPTION=
S start $STARTOPTIONS (code=3Dexited, status=3D0/SUCCESS)<br /> Main P=
ID: 1042 (code=3Dexited, status=3D0/SUCCESS)<br /> CGroup: /sys=
tem.slice/shorewall.service</p>
<p>Jan 13 09:48:44 leviathan.cypco.cl shorewall[1042]: Processing /etc/shor=
ewall/tcclear ...<br />Jan 13 09:48:44 leviathan.cypco.cl shorewall[1042]: =
Setting up Route Filtering...<br />Jan 13 09:48:44 leviathan.cypco.cl shore=
wall[1042]: Setting up Martian Logging...<br />Jan 13 09:48:44 leviathan.cy=
pco.cl shorewall[1042]: Setting up Proxy ARP...<br />Jan 13 09:48:45 leviat=
han.cypco.cl shorewall[1042]: Preparing iptables-restore input...<br />Jan =
13 09:48:45 leviathan.cypco.cl shorewall[1042]: Running /sbin/iptables-rest=
ore --wait 60...<br />Jan 13 09:48:45 leviathan.cypco.cl shorewall[1042]: P=
rocessing /etc/shorewall/start ...<br />Jan 13 09:48:45 leviathan.cypco.cl =
shorewall[1042]: Processing /etc/shorewall/started ...<br />Jan 13 09:48:45=
leviathan.cypco.cl shorewall[1042]: done.<br />Jan 13 09:48:45 leviathan.c=
ypco.cl systemd[1]: Started Shorewall IPv4 firewall.</p>
<p>Thx.</p>
<p id=3D"reply-intro">El 2026-01-13 13:19, Rodrigo Araujo escribió:<=
/p>
<blockquote type=3D"cite" style=3D"padding: 0 0.4em; border-left: #1010ff 2=
px solid; margin: 0">
<style type=3D"text/css">#replybody1 pre,#replybody1 code,#replybody1 addre=
ss { margin: 0px; }
#replybody1 h1,#replybody1 h2,#replybody1 h3,#replybody1 h4,#replybody1 h5,=
#replybody1 h6 { margin-top: 0.2em; margin-bottom: 0.2em; }
#replybody1 ol,#replybody1 ul { margin-top: 0em; margin-bottom: 0em; }
#replybody1 blockquote { margin-top: 0em; margin-bottom: 0em; }</style>
<div id=3D"replybody1">
<div>rcortes,</div>
<div> </div>
<div>can you confirm if you have "STARTUP_ENABLED=3DYes" in /etc/shorewall/=
shorewall.conf ?</div>
<div> </div>
<div>Best regards.</div>
<div> </div>
<div> </div>
<div>On Tue, 2026-01-13 at 11:11 -0500, Robert K Coffman Jr. -Info From Dat=
a Corp. wrote:</div>
<blockquote style=3D"margin: 0 0 0 .8ex; border-left: 2px #729fcf solid; pa=
dding-left: 1ex;">
<div> </div>
<p>Ok - what do the logs say after a reboot? One potential issue that=
might cause this is the status of any interfaces that are required but not=
ready when shorewall starts.</p>
<div> </div>
<div class=3D"v1moz-cite-prefix">On 1/13/2026 9:52:47 AM, <a class=3D"v1moz=
-txt-link-abbreviated" href=3D"mailto:[email protected]" rel=3D"noreferrer">r=
[email protected]</a> wrote:</div>
<div> </div>
<blockquote style=3D"margin: 0 0 0 .8ex; border-left: 2px #729fcf solid; pa=
dding-left: 1ex;">
<div> </div>
<p>Hi Robert,</p>
<div> </div>
<p><br /></p>
<div> </div>
<p>I'm using systemcl </p>
<div> </div>
<p><br /></p>
<div> </div>
<p>systemctl enable shorewall after install package.</p>
<div> </div>
<p><br /></p>
<div> </div>
<p>Thx.</p>
<div> </div>
<p><br /></p>
<div> </div>
<p id=3D"v1reply-intro">El 2026-01-13 10:30, Robert K Coffman Jr. -Info Fro=
m Data Corp. escribió:</p>
<div> </div>
<blockquote style=3D"margin: 0 0 0 .8ex; border-left: 2px #729fcf solid; pa=
dding-left: 1ex;">
<div> </div>
<div id=3D"v1replybody1">
<p>How are you starting Shorewall after a reboot?</p>
<p><br /></p>
<div class=3D"v1v1moz-cite-prefix">On 1/13/2026 5:59:25 AM, rcortes--- via =
Shorewall-users wrote:</div>
<br />
<blockquote style=3D"margin: 0 0 0 .8ex; border-left: 2px #729fcf solid; pa=
dding-left: 1ex;">
<div>Hi Simon, <br /><br />i use shorewall from shorewall site reference, i=
n this case 5.1.12 from <a class=3D"v1v1moz-txt-link-freetext v1moz-txt-lin=
k-freetext" href=3D"https://shorewall.org/pub/shorewall/5.1/shorewall-5.1.1=
2/" target=3D"_blank" rel=3D"noopener noreferrer">https://shorewall.org/pub=
/shorewall/5.1/shorewall-5.1.12/</a> <br />and 5.2.8 from <a class=3D"v1v1m=
oz-txt-link-freetext v1moz-txt-link-freetext" href=3D"https://www.invoca.ch=
/pub/packages/shorewall/RPMS/ils-7/noarch/" target=3D"_blank" rel=3D"noopen=
er noreferrer">https://www.invoca.ch/pub/packages/shorewall/RPMS/ils-7/noar=
ch/</a> <br /><br />5.1.12 or 5.1.10 start but dont work, need apply clear/=
start to work. <br />5.2.8-12 start but dont work nat/dnat/proxyarp <br /><=
br />Thx <br /><br />El 2026-01-13 04:56, Simon Matter escribió: <br=
/><br /></div>
<blockquote style=3D"margin: 0 0 0 .8ex; border-left: 2px #729fcf solid; pa=
dding-left: 1ex;">
<div>Hi, <br /><br /><br /></div>
<blockquote style=3D"margin: 0 0 0 .8ex; border-left: 2px #729fcf solid; pa=
dding-left: 1ex;">
<div>Hello everyone! <br /><br />Somebody know why or how to fix shorewall =
for not need clear and start <br />after reboot? i have EL7 and shore=
wall 5.1.12, previously working with <br />5.1.10 and try with 5.2.8-12 but=
shorewall start but nat/dnat/proxyarp <br />dont work.</div>
</blockquote>
<div><br />Seems that your shorewall start is not working properly. Are you=
using a <br />shorewall package from epel? If so you could check the chang=
elog to see <br />who has packaged it and ask directly? <br /><br />Regards=
, <br />Simon</div>
</blockquote>
<div><br /><br />_______________________________________________ <br />Shor=
ewall-users mailing list <br /><a class=3D"v1v1moz-txt-link-abbreviated v1m=
oz-txt-link-freetext" href=3D"mailto:[email protected]"=
rel=3D"noreferrer">[email protected]</a> <br /><a clas=
s=3D"v1v1moz-txt-link-freetext v1moz-txt-link-freetext" href=3D"https://lis=
ts.sourceforge.net/lists/listinfo/shorewall-users" target=3D"_blank" rel=3D=
"noopener noreferrer">https://lists.sourceforge.net/lists/listinfo/shorewal=
l-users</a></div>
</blockquote>
<pre class=3D"v1v1moz-signature">--=20
Robert K Coffman Jr.
Info From Data Corp.
3307249000
<a class=3D"v1v1moz-txt-link-abbreviated v1moz-txt-link-freetext" href=3D"m=
ailto:[email protected]" rel=3D"noreferrer">[email protected]=
</a></pre>
</div>
<div> </div>
<div class=3D"v1pre" style=3D"margin: 0; padding: 0; font-family: monospace=
;">_______________________________________________<br />Shorewall-users mai=
ling list<br /><a class=3D"v1moz-txt-link-freetext" href=3D"mailto:Shorewal=
[email protected]" rel=3D"noreferrer">[email protected]=
rceforge.net</a><br /><a class=3D"v1moz-txt-link-freetext" href=3D"https://=
lists.sourceforge.net/lists/listinfo/shorewall-users" target=3D"_blank" rel=
=3D"noopener noreferrer">https://lists.sourceforge.net/lists/listinfo/shore=
wall-users</a></div>
<div> </div>
</blockquote>
<div> </div>
</blockquote>
<div> </div>
<div>_______________________________________________</div>
<div>Shorewall-users mailing list</div>
<div><a href=3D"mailto:[email protected]" rel=3D"norefe=
rrer">[email protected]</a></div>
<div><a href=3D"https://lists.sourceforge.net/lists/listinfo/shorewall-user=
s" target=3D"_blank" rel=3D"noopener noreferrer">https://lists.sourceforge.=
net/lists/listinfo/shorewall-users</a></div>
<pre> </pre>
</blockquote>
<div> </div>
<div> </div>
</div>
<br />
<div class=3D"pre" style=3D"margin: 0; padding: 0; font-family: monospace">=
_______________________________________________<br />Shorewall-users mailin=
g list<br /><a href=3D"mailto:[email protected]">Shorew=
[email protected]</a><br /><a href=3D"https://lists.sourcefor=
ge.net/lists/listinfo/shorewall-users" target=3D"_blank" rel=3D"noopener no=
referrer">https://lists.sourceforge.net/lists/listinfo/shorewall-users</a><=
/div>
</blockquote>
</body></html>
--=_370ca7aa941d3898d8515fec771a0332--
--===============0147133549395526574==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--===============0147133549395526574==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline