Re: Shorewall need clear to work after reboot

rcortes--- via Shorewall-users <[email protected]> Tue, 13 Jan 2026 13:32:31 -0300
Newsgroups gmane.comp.security.shorewall
Message-ID <[email protected]>
--===============7230203884326506171==
Content-Type: multipart/alternative;
 boundary="=_df98b6cf9e8c0fbbf079fa8062f07e79"

--=_df98b6cf9e8c0fbbf079fa8062f07e79
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset=UTF-8;
 format=flowed



Hi Rodrigo,

firewalld is disable :)

thx

El 2026-01-13 13:23, Rodrigo Araujo escribió:

> Another suggestion: ensure firewalld (or other firewall system/service 
> that may be present) is disabled/masked. It will clash with shorewall.
> 
> On Tue, 2026-01-13 at 16:19 +0000, Rodrigo Araujo wrote:
> rcortes,
> 
> can you confirm if you have "STARTUP_ENABLED=Yes" in 
> /etc/shorewall/shorewall.conf ?
> 
> Best regards.
> 
> On Tue, 2026-01-13 at 11:11 -0500, Robert K Coffman Jr. -Info From Data 
> Corp. wrote:
> 
> Ok - what do the logs say after a reboot?  One potential issue that 
> might cause this is the status of any interfaces that are required but 
> not ready when shorewall starts.
> 
> On 1/13/2026 9:52:47 AM, [email protected] wrote:
> 
> Hi Robert,
> 
> I'm using systemcl
> 
> systemctl enable shorewall after install package.
> 
> Thx.
> 
> El 2026-01-13 10:30, Robert K Coffman Jr. -Info From Data Corp. 
> escribió:
> 
> How are you starting Shorewall after a reboot?
> 
> On 1/13/2026 5:59:25 AM, rcortes--- via Shorewall-users wrote:
> 
> Hi Simon,
> 
> i use shorewall from shorewall site reference, in this case 5.1.12 from 
> https://shorewall.org/pub/shorewall/5.1/shorewall-5.1.12/
> and 5.2.8 from 
> https://www.invoca.ch/pub/packages/shorewall/RPMS/ils-7/noarch/
> 
> 5.1.12 or 5.1.10 start but dont work, need apply clear/start to work.
> 5.2.8-12 start but dont work nat/dnat/proxyarp
> 
> Thx
> 
> El 2026-01-13 04:56, Simon Matter escribió:
> 
> Hi,
> 
> Hello everyone!
> 
> Somebody know why or how to fix shorewall for not need clear and start
> after reboot?  i have EL7 and shorewall 5.1.12, previously working with
> 5.1.10 and try with 5.2.8-12 but shorewall start but nat/dnat/proxyarp
> dont work.
> 
> Seems that your shorewall start is not working properly. Are you using 
> a
> shorewall package from epel? If so you could check the changelog to see
> who has packaged it and ask directly?
> 
> Regards,
> Simon

_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users
--=_df98b6cf9e8c0fbbf079fa8062f07e79
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset=UTF-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; charset=
=3DUTF-8" /></head><body style=3D'font-size: 10pt; font-family: Verdana,Gen=
eva,sans-serif'>
<p>Hi Rodrigo,</p>
<p><br /></p>
<p>firewalld is disable :)</p>
<p><br /></p>
<p>thx</p>
<div id=3D"signature"></div>
<p><br /></p>
<p id=3D"reply-intro">El 2026-01-13 13:23, Rodrigo Araujo escribi&oacute;:<=
/p>
<blockquote type=3D"cite" style=3D"padding: 0 0.4em; border-left: #1010ff 2=
px solid; margin: 0">
<style type=3D"text/css">#replybody1 pre,#replybody1 code,#replybody1 addre=
ss { margin: 0px; }
#replybody1 h1,#replybody1 h2,#replybody1 h3,#replybody1 h4,#replybody1 h5,=
#replybody1 h6 { margin-top: 0.2em; margin-bottom: 0.2em; }
#replybody1 ol,#replybody1 ul { margin-top: 0em; margin-bottom: 0em; }
#replybody1 blockquote { margin-top: 0em; margin-bottom: 0em; }</style>
<style type=3D"text/css">#replybody1 pre,#replybody1 code,#replybody1 addre=
ss { margin: 0px; }
#replybody1 h1,#replybody1 h2,#replybody1 h3,#replybody1 h4,#replybody1 h5,=
#replybody1 h6 { margin-top: 0.2em; margin-bottom: 0.2em; }
#replybody1 ol,#replybody1 ul { margin-top: 0em; margin-bottom: 0em; }
#replybody1 blockquote { margin-top: 0em; margin-bottom: 0em; }</style>
<div id=3D"replybody1">
<div>Another suggestion: ensure firewalld (or other firewall system/service=
 that may be present) is disabled/masked. It will clash with shorewall.</di=
v>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div>On Tue, 2026-01-13 at 16:19 +0000, Rodrigo Araujo wrote:</div>
<blockquote style=3D"margin: 0 0 0 .8ex; border-left: 2px #729fcf solid; pa=
dding-left: 1ex;">
<div>rcortes,</div>
<div>&nbsp;</div>
<div>can you confirm if you have "STARTUP_ENABLED=3DYes" in /etc/shorewall/=
shorewall.conf ?</div>
<div>&nbsp;</div>
<div>Best regards.</div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div>On Tue, 2026-01-13 at 11:11 -0500, Robert K Coffman Jr. -Info From Dat=
a Corp. wrote:</div>
<blockquote style=3D"margin: 0 0 0 .8ex; border-left: 2px #729fcf solid; pa=
dding-left: 1ex;">
<div>&nbsp;</div>
<p>Ok - what do the logs say after a reboot?&nbsp; One potential issue that=
 might cause this is the status of any interfaces that are required but not=
 ready when shorewall starts.</p>
<div>&nbsp;</div>
<div class=3D"v1moz-cite-prefix">On 1/13/2026 9:52:47 AM, <a class=3D"v1moz=
-txt-link-abbreviated" href=3D"mailto:[email protected]" rel=3D"noreferrer">r=
[email protected]</a> wrote:</div>
<div>&nbsp;</div>
<blockquote style=3D"margin: 0 0 0 .8ex; border-left: 2px #729fcf solid; pa=
dding-left: 1ex;">
<div>&nbsp;</div>
<p>Hi Robert,</p>
<div>&nbsp;</div>
<p><br /></p>
<div>&nbsp;</div>
<p>I'm using systemcl&nbsp;</p>
<div>&nbsp;</div>
<p><br /></p>
<div>&nbsp;</div>
<p>systemctl enable shorewall after install package.</p>
<div>&nbsp;</div>
<p><br /></p>
<div>&nbsp;</div>
<p>Thx.</p>
<div>&nbsp;</div>
<p><br /></p>
<div>&nbsp;</div>
<p id=3D"v1reply-intro">El 2026-01-13 10:30, Robert K Coffman Jr. -Info Fro=
m Data Corp. escribi&oacute;:</p>
<div>&nbsp;</div>
<blockquote style=3D"margin: 0 0 0 .8ex; border-left: 2px #729fcf solid; pa=
dding-left: 1ex;">
<div>&nbsp;</div>
<div id=3D"v1replybody1">
<p>How are you starting Shorewall after a reboot?</p>
<p><br /></p>
<div class=3D"v1v1moz-cite-prefix">On 1/13/2026 5:59:25 AM, rcortes--- via =
Shorewall-users wrote:</div>
<br />
<blockquote style=3D"margin: 0 0 0 .8ex; border-left: 2px #729fcf solid; pa=
dding-left: 1ex;">
<div>Hi Simon, <br /><br />i use shorewall from shorewall site reference, i=
n this case 5.1.12 from <a class=3D"v1v1moz-txt-link-freetext v1moz-txt-lin=
k-freetext" href=3D"https://shorewall.org/pub/shorewall/5.1/shorewall-5.1.1=
2/" target=3D"_blank" rel=3D"noopener noreferrer">https://shorewall.org/pub=
/shorewall/5.1/shorewall-5.1.12/</a> <br />and 5.2.8 from <a class=3D"v1v1m=
oz-txt-link-freetext v1moz-txt-link-freetext" href=3D"https://www.invoca.ch=
/pub/packages/shorewall/RPMS/ils-7/noarch/" target=3D"_blank" rel=3D"noopen=
er noreferrer">https://www.invoca.ch/pub/packages/shorewall/RPMS/ils-7/noar=
ch/</a> <br /><br />5.1.12 or 5.1.10 start but dont work, need apply clear/=
start to work. <br />5.2.8-12 start but dont work nat/dnat/proxyarp <br /><=
br />Thx <br /><br />El 2026-01-13 04:56, Simon Matter escribi&oacute;: <br=
 /><br /></div>
<blockquote style=3D"margin: 0 0 0 .8ex; border-left: 2px #729fcf solid; pa=
dding-left: 1ex;">
<div>Hi, <br /><br /><br /></div>
<blockquote style=3D"margin: 0 0 0 .8ex; border-left: 2px #729fcf solid; pa=
dding-left: 1ex;">
<div>Hello everyone! <br /><br />Somebody know why or how to fix shorewall =
for not need clear and start <br />after reboot?&nbsp; i have EL7 and shore=
wall 5.1.12, previously working with <br />5.1.10 and try with 5.2.8-12 but=
 shorewall start but nat/dnat/proxyarp <br />dont work.</div>
</blockquote>
<div><br />Seems that your shorewall start is not working properly. Are you=
 using a <br />shorewall package from epel? If so you could check the chang=
elog to see <br />who has packaged it and ask directly? <br /><br />Regards=
, <br />Simon</div>
</blockquote>
<div><br /><br />_______________________________________________ <br />Shor=
ewall-users mailing list <br /><a class=3D"v1v1moz-txt-link-abbreviated v1m=
oz-txt-link-freetext" href=3D"mailto:[email protected]"=
 rel=3D"noreferrer">[email protected]</a> <br /><a clas=
s=3D"v1v1moz-txt-link-freetext v1moz-txt-link-freetext" href=3D"https://lis=
ts.sourceforge.net/lists/listinfo/shorewall-users" target=3D"_blank" rel=3D=
"noopener noreferrer">https://lists.sourceforge.net/lists/listinfo/shorewal=
l-users</a></div>
</blockquote>
<pre class=3D"v1v1moz-signature">&nbsp;</pre>
</div>
</blockquote>
</blockquote>
</blockquote>
</blockquote>
<div>&nbsp;</div>
<div>&nbsp;</div>
</div>
<br />
<div class=3D"pre" style=3D"margin: 0; padding: 0; font-family: monospace">=
_______________________________________________<br />Shorewall-users mailin=
g list<br /><a href=3D"mailto:[email protected]">Shorew=
[email protected]</a><br /><a href=3D"https://lists.sourcefor=
ge.net/lists/listinfo/shorewall-users" target=3D"_blank" rel=3D"noopener no=
referrer">https://lists.sourceforge.net/lists/listinfo/shorewall-users</a><=
/div>
</blockquote>
</body></html>

--=_df98b6cf9e8c0fbbf079fa8062f07e79--


--===============7230203884326506171==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============7230203884326506171==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline