Re: Shorewall need clear to work after reboot

Winston Sorfleet <[email protected]> Wed, 14 Jan 2026 02:07:38 -0500
Newsgroups gmane.comp.security.shorewall
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============2720300659769780072==
Content-Type: multipart/alternative;
 boundary="------------WBYiexBMZS8FnbmEKnyzefDX"
Content-Language: en-CA

This is a multi-part message in MIME format.
--------------WBYiexBMZS8FnbmEKnyzefDX
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

I do this as well, but because I have a secondary ISP that goes up and 
down a lot, I put a

post-up shorewall enable ppp2; shorewall restart

in my /etc/network/interfaces (assuming you use one of those... if you 
are using e.g. netcfg I am sure there are places you can hook an 
explicit call in.  There is absolutely no harm in calling shorewall 
several times, as all it does is configure your iptables.

With systemd, make sure that shorewall.service contains

Wants=network-online.target
After=network-online.target

Hmmn... one thing you should make sure is that your network interface 
actually is *up* before you call shorewall.  It *can* be configured to 
figure this out itself, but that involves a more complex situation with 
optional in the /etc/shorewall[6]/interfaces file, and you would still 
want something to trigger shorewall enable.


On 2026-01-13 09:52, rcortes--- via Shorewall-users wrote:
>
> Hi Robert,
>
>
> I'm using systemcl
>
>
> systemctl enable shorewall after install package.
>
>
> Thx.
>
>
> El 2026-01-13 10:30, Robert K Coffman Jr. -Info From Data Corp. escribió:
>
>> How are you starting Shorewall after a reboot?
>>
>>
>> On 1/13/2026 5:59:25 AM, rcortes--- via Shorewall-users wrote:
>>> Hi Simon,
>>>
>>> i use shorewall from shorewall site reference, in this case 5.1.12 
>>> from https://shorewall.org/pub/shorewall/5.1/shorewall-5.1.12/ 
>>> <https://shorewall.org/pub/shorewall/5.1/shorewall-5.1.12/>
>>> and 5.2.8 from 
>>> https://www.invoca.ch/pub/packages/shorewall/RPMS/ils-7/noarch/ 
>>> <https://www.invoca.ch/pub/packages/shorewall/RPMS/ils-7/noarch/>
>>>
>>> 5.1.12 or 5.1.10 start but dont work, need apply clear/start to work.
>>> 5.2.8-12 start but dont work nat/dnat/proxyarp
>>>
>>> Thx
>>>
>>> El 2026-01-13 04:56, Simon Matter escribió:
>>>> Hi,
>>>>
>>>>> Hello everyone!
>>>>>
>>>>> Somebody know why or how to fix shorewall for not need clear and 
>>>>> start
>>>>> after reboot?  i have EL7 and shorewall 5.1.12, previously working 
>>>>> with
>>>>> 5.1.10 and try with 5.2.8-12 but shorewall start but 
>>>>> nat/dnat/proxyarp
>>>>> dont work. 
>>>>
>>>> Seems that your shorewall start is not working properly. Are you 
>>>> using a
>>>> shorewall package from epel? If so you could check the changelog to 
>>>> see
>>>> who has packaged it and ask directly?
>>>>
>>>> Regards,
>>>> Simon 
>>>
>>>
>>> _______________________________________________
>>> Shorewall-users mailing list
>>> [email protected] 
>>> <mailto:[email protected]>
>>> https://lists.sourceforge.net/lists/listinfo/shorewall-users 
>>> <https://lists.sourceforge.net/lists/listinfo/shorewall-users> 
>> -- 
>> Robert K Coffman Jr.
>> Info From Data Corp.
>> 3307249000
>> [email protected] <mailto:[email protected]>
>>
>> _______________________________________________
>> Shorewall-users mailing list
>> [email protected]
>> https://lists.sourceforge.net/lists/listinfo/shorewall-users
>
>
> _______________________________________________
> Shorewall-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/shorewall-users
--------------WBYiexBMZS8FnbmEKnyzefDX
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>I do this as well, but because I have a secondary ISP that goes
      up and down a lot, I put a</p>
    <p>post-up shorewall enable ppp2; shorewall restart </p>
    <p>in my /etc/network/interfaces (assuming you use one of those...
      if you are using e.g. netcfg I am sure there are places you can
      hook an explicit call in.  There is absolutely no harm in calling
      shorewall several times, as all it does is configure your
      iptables.</p>
    <p>With systemd, make sure that shorewall.service contains</p>
    <p>Wants=network-online.target<br>
      After=network-online.target</p>
    <p>Hmmn... one thing you should make sure is that your network
      interface actually is *up* before you call shorewall.  It *can* be
      configured to figure this out itself, but that involves a more
      complex situation with optional in the
      /etc/shorewall[6]/interfaces file, and you would still want
      something to trigger shorewall enable.</p>
    <p><br>
    </p>
    <div class="moz-cite-prefix">On 2026-01-13 09:52, rcortes--- via
      Shorewall-users wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:[email protected]">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <p>Hi Robert,</p>
      <p><br>
      </p>
      <p>I'm using systemcl </p>
      <p><br>
      </p>
      <p>systemctl enable shorewall after install package.</p>
      <p><br>
      </p>
      <p>Thx.</p>
      <p><br>
      </p>
      <p id="reply-intro">El 2026-01-13 10:30, Robert K Coffman Jr.
        -Info From Data Corp. escribió:</p>
      <blockquote type="cite"
style="padding: 0 0.4em; border-left: #1010ff 2px solid; margin: 0">
        <div id="replybody1">
          <p>How are you starting Shorewall after a reboot?</p>
          <p><br>
          </p>
          <div class="v1moz-cite-prefix">On 1/13/2026 5:59:25 AM,
            rcortes--- via Shorewall-users wrote:</div>
          <blockquote type="cite"
style="padding: 0 0.4em; border-left: #1010ff 2px solid; margin: 0">Hi
            Simon, <br>
            <br>
            i use shorewall from shorewall site reference, in this case
            5.1.12 from <a
              class="v1moz-txt-link-freetext moz-txt-link-freetext"
href="https://shorewall.org/pub/shorewall/5.1/shorewall-5.1.12/"
              target="_blank" rel="noopener noreferrer"
              moz-do-not-send="true">https://shorewall.org/pub/shorewall/5.1/shorewall-5.1.12/</a>
            <br>
            and 5.2.8 from <a
              class="v1moz-txt-link-freetext moz-txt-link-freetext"
href="https://www.invoca.ch/pub/packages/shorewall/RPMS/ils-7/noarch/"
              target="_blank" rel="noopener noreferrer"
              moz-do-not-send="true">https://www.invoca.ch/pub/packages/shorewall/RPMS/ils-7/noarch/</a>
            <br>
            <br>
            5.1.12 or 5.1.10 start but dont work, need apply clear/start
            to work. <br>
            5.2.8-12 start but dont work nat/dnat/proxyarp <br>
            <br>
            Thx <br>
            <br>
            El 2026-01-13 04:56, Simon Matter escribió: <br>
            <blockquote type="cite"
style="padding: 0 0.4em; border-left: #1010ff 2px solid; margin: 0">Hi,
              <br>
              <br>
              <blockquote type="cite"
style="padding: 0 0.4em; border-left: #1010ff 2px solid; margin: 0">Hello
                everyone! <br>
                <br>
                Somebody know why or how to fix shorewall for not need
                clear and start <br>
                after reboot?  i have EL7 and shorewall 5.1.12,
                previously working with <br>
                5.1.10 and try with 5.2.8-12 but shorewall start but
                nat/dnat/proxyarp <br>
                dont work. </blockquote>
              <br>
              Seems that your shorewall start is not working properly.
              Are you using a <br>
              shorewall package from epel? If so you could check the
              changelog to see <br>
              who has packaged it and ask directly? <br>
              <br>
              Regards, <br>
              Simon </blockquote>
            <br>
            <br>
            _______________________________________________ <br>
            Shorewall-users mailing list <br>
            <a class="v1moz-txt-link-abbreviated moz-txt-link-freetext"
              href="mailto:[email protected]"
              rel="noreferrer" moz-do-not-send="true">[email protected]</a>
            <br>
            <a class="v1moz-txt-link-freetext moz-txt-link-freetext"
href="https://lists.sourceforge.net/lists/listinfo/shorewall-users"
              target="_blank" rel="noopener noreferrer"
              moz-do-not-send="true">https://lists.sourceforge.net/lists/listinfo/shorewall-users</a>
          </blockquote>
          <pre class="v1moz-signature">-- 
Robert K Coffman Jr.
Info From Data Corp.
3307249000
<a class="v1moz-txt-link-abbreviated moz-txt-link-freetext"
          href="mailto:[email protected]" rel="noreferrer"
          moz-do-not-send="true">[email protected]</a></pre>
        </div>
        <br>
        <div class="pre"
          style="margin: 0; padding: 0; font-family: monospace">_______________________________________________<br>
          Shorewall-users mailing list<br>
          <a href="mailto:[email protected]"
            moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a><br>
          <a
href="https://lists.sourceforge.net/lists/listinfo/shorewall-users"
            target="_blank" rel="noopener noreferrer"
            moz-do-not-send="true" class="moz-txt-link-freetext">https://lists.sourceforge.net/lists/listinfo/shorewall-users</a></div>
      </blockquote>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
      <pre wrap="" class="moz-quote-pre">_______________________________________________
Shorewall-users mailing list
<a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
<a class="moz-txt-link-freetext" href="https://lists.sourceforge.net/lists/listinfo/shorewall-users">https://lists.sourceforge.net/lists/listinfo/shorewall-users</a>
</pre>
    </blockquote>
  </body>
</html>

--------------WBYiexBMZS8FnbmEKnyzefDX--


--===============2720300659769780072==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============2720300659769780072==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline