Re: Shorewall need clear to work after reboot
Winston Sorfleet <[email protected]> Wed, 14 Jan 2026 02:07:38 -0500
| Newsgroups | gmane.comp.security.shorewall |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --===============2720300659769780072== Content-Type: multipart/alternative; boundary="------------WBYiexBMZS8FnbmEKnyzefDX" Content-Language: en-CA This is a multi-part message in MIME format. --------------WBYiexBMZS8FnbmEKnyzefDX Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit I do this as well, but because I have a secondary ISP that goes up and down a lot, I put a post-up shorewall enable ppp2; shorewall restart in my /etc/network/interfaces (assuming you use one of those... if you are using e.g. netcfg I am sure there are places you can hook an explicit call in. There is absolutely no harm in calling shorewall several times, as all it does is configure your iptables. With systemd, make sure that shorewall.service contains Wants=network-online.target After=network-online.target Hmmn... one thing you should make sure is that your network interface actually is *up* before you call shorewall. It *can* be configured to figure this out itself, but that involves a more complex situation with optional in the /etc/shorewall[6]/interfaces file, and you would still want something to trigger shorewall enable. On 2026-01-13 09:52, rcortes--- via Shorewall-users wrote: > > Hi Robert, > > > I'm using systemcl > > > systemctl enable shorewall after install package. > > > Thx. > > > El 2026-01-13 10:30, Robert K Coffman Jr. -Info From Data Corp. escribió: > >> How are you starting Shorewall after a reboot? >> >> >> On 1/13/2026 5:59:25 AM, rcortes--- via Shorewall-users wrote: >>> Hi Simon, >>> >>> i use shorewall from shorewall site reference, in this case 5.1.12 >>> from https://shorewall.org/pub/shorewall/5.1/shorewall-5.1.12/ >>> <https://shorewall.org/pub/shorewall/5.1/shorewall-5.1.12/> >>> and 5.2.8 from >>> https://www.invoca.ch/pub/packages/shorewall/RPMS/ils-7/noarch/ >>> <https://www.invoca.ch/pub/packages/shorewall/RPMS/ils-7/noarch/> >>> >>> 5.1.12 or 5.1.10 start but dont work, need apply clear/start to work. >>> 5.2.8-12 start but dont work nat/dnat/proxyarp >>> >>> Thx >>> >>> El 2026-01-13 04:56, Simon Matter escribió: >>>> Hi, >>>> >>>>> Hello everyone! >>>>> >>>>> Somebody know why or how to fix shorewall for not need clear and >>>>> start >>>>> after reboot? i have EL7 and shorewall 5.1.12, previously working >>>>> with >>>>> 5.1.10 and try with 5.2.8-12 but shorewall start but >>>>> nat/dnat/proxyarp >>>>> dont work. >>>> >>>> Seems that your shorewall start is not working properly. Are you >>>> using a >>>> shorewall package from epel? If so you could check the changelog to >>>> see >>>> who has packaged it and ask directly? >>>> >>>> Regards, >>>> Simon >>> >>> >>> _______________________________________________ >>> Shorewall-users mailing list >>> [email protected] >>> <mailto:[email protected]> >>> https://lists.sourceforge.net/lists/listinfo/shorewall-users >>> <https://lists.sourceforge.net/lists/listinfo/shorewall-users> >> -- >> Robert K Coffman Jr. >> Info From Data Corp. >> 3307249000 >> [email protected] <mailto:[email protected]> >> >> _______________________________________________ >> Shorewall-users mailing list >> [email protected] >> https://lists.sourceforge.net/lists/listinfo/shorewall-users > > > _______________________________________________ > Shorewall-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/shorewall-users --------------WBYiexBMZS8FnbmEKnyzefDX Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 8bit <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> </head> <body> <p>I do this as well, but because I have a secondary ISP that goes up and down a lot, I put a</p> <p>post-up shorewall enable ppp2; shorewall restart </p> <p>in my /etc/network/interfaces (assuming you use one of those... if you are using e.g. netcfg I am sure there are places you can hook an explicit call in. There is absolutely no harm in calling shorewall several times, as all it does is configure your iptables.</p> <p>With systemd, make sure that shorewall.service contains</p> <p>Wants=network-online.target<br> After=network-online.target</p> <p>Hmmn... one thing you should make sure is that your network interface actually is *up* before you call shorewall. It *can* be configured to figure this out itself, but that involves a more complex situation with optional in the /etc/shorewall[6]/interfaces file, and you would still want something to trigger shorewall enable.</p> <p><br> </p> <div class="moz-cite-prefix">On 2026-01-13 09:52, rcortes--- via Shorewall-users wrote:<br> </div> <blockquote type="cite" cite="mid:[email protected]"> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <p>Hi Robert,</p> <p><br> </p> <p>I'm using systemcl </p> <p><br> </p> <p>systemctl enable shorewall after install package.</p> <p><br> </p> <p>Thx.</p> <p><br> </p> <p id="reply-intro">El 2026-01-13 10:30, Robert K Coffman Jr. -Info From Data Corp. escribió:</p> <blockquote type="cite" style="padding: 0 0.4em; border-left: #1010ff 2px solid; margin: 0"> <div id="replybody1"> <p>How are you starting Shorewall after a reboot?</p> <p><br> </p> <div class="v1moz-cite-prefix">On 1/13/2026 5:59:25 AM, rcortes--- via Shorewall-users wrote:</div> <blockquote type="cite" style="padding: 0 0.4em; border-left: #1010ff 2px solid; margin: 0">Hi Simon, <br> <br> i use shorewall from shorewall site reference, in this case 5.1.12 from <a class="v1moz-txt-link-freetext moz-txt-link-freetext" href="https://shorewall.org/pub/shorewall/5.1/shorewall-5.1.12/" target="_blank" rel="noopener noreferrer" moz-do-not-send="true">https://shorewall.org/pub/shorewall/5.1/shorewall-5.1.12/</a> <br> and 5.2.8 from <a class="v1moz-txt-link-freetext moz-txt-link-freetext" href="https://www.invoca.ch/pub/packages/shorewall/RPMS/ils-7/noarch/" target="_blank" rel="noopener noreferrer" moz-do-not-send="true">https://www.invoca.ch/pub/packages/shorewall/RPMS/ils-7/noarch/</a> <br> <br> 5.1.12 or 5.1.10 start but dont work, need apply clear/start to work. <br> 5.2.8-12 start but dont work nat/dnat/proxyarp <br> <br> Thx <br> <br> El 2026-01-13 04:56, Simon Matter escribió: <br> <blockquote type="cite" style="padding: 0 0.4em; border-left: #1010ff 2px solid; margin: 0">Hi, <br> <br> <blockquote type="cite" style="padding: 0 0.4em; border-left: #1010ff 2px solid; margin: 0">Hello everyone! <br> <br> Somebody know why or how to fix shorewall for not need clear and start <br> after reboot? i have EL7 and shorewall 5.1.12, previously working with <br> 5.1.10 and try with 5.2.8-12 but shorewall start but nat/dnat/proxyarp <br> dont work. </blockquote> <br> Seems that your shorewall start is not working properly. Are you using a <br> shorewall package from epel? If so you could check the changelog to see <br> who has packaged it and ask directly? <br> <br> Regards, <br> Simon </blockquote> <br> <br> _______________________________________________ <br> Shorewall-users mailing list <br> <a class="v1moz-txt-link-abbreviated moz-txt-link-freetext" href="mailto:[email protected]" rel="noreferrer" moz-do-not-send="true">[email protected]</a> <br> <a class="v1moz-txt-link-freetext moz-txt-link-freetext" href="https://lists.sourceforge.net/lists/listinfo/shorewall-users" target="_blank" rel="noopener noreferrer" moz-do-not-send="true">https://lists.sourceforge.net/lists/listinfo/shorewall-users</a> </blockquote> <pre class="v1moz-signature">-- Robert K Coffman Jr. Info From Data Corp. 3307249000 <a class="v1moz-txt-link-abbreviated moz-txt-link-freetext" href="mailto:[email protected]" rel="noreferrer" moz-do-not-send="true">[email protected]</a></pre> </div> <br> <div class="pre" style="margin: 0; padding: 0; font-family: monospace">_______________________________________________<br> Shorewall-users mailing list<br> <a href="mailto:[email protected]" moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a><br> <a href="https://lists.sourceforge.net/lists/listinfo/shorewall-users" target="_blank" rel="noopener noreferrer" moz-do-not-send="true" class="moz-txt-link-freetext">https://lists.sourceforge.net/lists/listinfo/shorewall-users</a></div> </blockquote> <br> <fieldset class="moz-mime-attachment-header"></fieldset> <br> <fieldset class="moz-mime-attachment-header"></fieldset> <pre wrap="" class="moz-quote-pre">_______________________________________________ Shorewall-users mailing list <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a> <a class="moz-txt-link-freetext" href="https://lists.sourceforge.net/lists/listinfo/shorewall-users">https://lists.sourceforge.net/lists/listinfo/shorewall-users</a> </pre> </blockquote> </body> </html> --------------WBYiexBMZS8FnbmEKnyzefDX-- --===============2720300659769780072== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============2720300659769780072== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline