Introducing shorewall-nft

Dave Kempe <[email protected]> Sun, 19 Jul 2026 14:55:10 +1000
Newsgroups gmane.comp.security.shorewall
Message-ID <CAEc_UVQmbjKNYonimiiQi14mvaegry8xAPd-1AoMo5A8JDseZw@mail.gmail.com>
--===============3081892283959616745==
Content-Type: multipart/alternative; boundary="000000000000fa08b70656ef986b"

--000000000000fa08b70656ef986b
Content-Type: text/plain; charset="UTF-8"

Hi Shorewall people!

We (sol1.com.au) have been avid Shorewall users and supporters for around
20 years. Wow that is a long time. We have a fleet of managed firewalls
that use Shorewall, among other things, to keep many of our customers
online and secure. The decline of Shorewall has been "a problem for another
day" for a long time now, and I finally decided to do something about it.

Shorewall-nft is a Python ground up rewrite, specifically to support
keeping your shorewall config the same, but it emits pure nftables.

https://github.com/sol1/shorewall-nft

We are running it on many of our systems already, in fact, these packets
are flowing to you over it right now. It was tested and developed against a
primary fleet of 45 different firewall configs, including all the
standard configurations and much of the weirder configurations represented.

Our aim is to replace Shorewall with shorewall-nft, and continue supporting
it. Our team has managed custom software and linux firewalls for years, and
would be honoured to become custodians of this project. Of course we
welcome all input, and this is a true Open Source project.

We would love some feedback on whether it works for you. You can simply
grab the deb or rpm, do  a shorewall check and shorewall migrate, and it
will flush your old rules and switch you to nftables.

As bonus features, we also built shorewall-lsm, a Link Status Monitor with
multi-ISP support that appears to be working well and geoip improvements
along they way. Any improvements maintain backwards config capability, and
simply add to the existing config base.
See https://github.com/sol1/shorewall-nft/blob/main/docs/failover.md for
more info on shorewall-lsm

Happy to provide support or see FRs via github infrastructure. If the
project gets legs at all, we will consider a docs site or other further
improvements.

Thanks
Dave Kempe

--000000000000fa08b70656ef986b
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Hi Shorewall people!</div><div><br></div><div>We (<a =
href=3D"http://sol1.com.au">sol1.com.au</a>) have been avid Shorewall users=
 and supporters for around 20 years. Wow that is a long time. We have a fle=
et of managed firewalls that use Shorewall, among other things, to keep man=
y of our customers online and secure. The decline of Shorewall has been &qu=
ot;a problem for another day&quot; for a long time now, and I finally decid=
ed to do something about it.</div><div><br></div><div>Shorewall-nft is a Py=
thon ground up rewrite, specifically to support keeping your shorewall conf=
ig the same, but it emits pure nftables.</div><div><br><a href=3D"https://g=
ithub.com/sol1/shorewall-nft">https://github.com/sol1/shorewall-nft</a></di=
v><div><br></div><div>We are running it on many of our systems already,=C2=
=A0in fact, these packets are flowing to you over it right now. It was test=
ed and developed against a primary fleet of 45 different firewall configs, =
including all the standard=C2=A0configurations and much of the weirder conf=
igurations represented.</div><div><br></div><div>Our aim is to replace Shor=
ewall with shorewall-nft, and continue supporting it. Our team has managed =
custom software and linux firewalls for years, and would be honoured to bec=
ome custodians of this project. Of course we welcome all input, and this is=
 a true Open Source project.</div><div><br></div><div>We would love some fe=
edback on whether it works for you. You can simply grab the deb or rpm, do=
=C2=A0 a shorewall check and shorewall migrate, and it will flush your old =
rules and switch you to nftables.</div><div><br></div><div>As bonus feature=
s, we also built shorewall-lsm, a Link Status Monitor with multi-ISP suppor=
t that appears to be working well and geoip improvements along they way. An=
y improvements maintain backwards config capability, and simply add to the =
existing config base.<br></div><div>See=C2=A0<a href=3D"https://github.com/=
sol1/shorewall-nft/blob/main/docs/failover.md">https://github.com/sol1/shor=
ewall-nft/blob/main/docs/failover.md</a> for more info on shorewall-lsm</di=
v><div><br></div><div>Happy to provide support or see FRs via github infras=
tructure. If the project gets legs at all, we will consider a docs site or =
other further improvements.</div><div><br></div><div>Thanks</div><div>Dave =
Kempe</div><div><br></div><div><br></div></div>

--000000000000fa08b70656ef986b--


--===============3081892283959616745==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============3081892283959616745==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline