Re: Introducing shorewall-nft
Simon Matter via Shorewall-users <[email protected]> Sun, 19 Jul 2026 11:52:43 +0200
| Newsgroups | gmane.comp.security.shorewall |
|---|---|
| Message-ID | <[email protected]> |
--===============1269224026869079912== Content-Type: multipart/alternative; boundary="8999eea5-83dd-446c-83fa-c069a2f55015-1" --8999eea5-83dd-446c-83fa-c069a2f55015-1 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Hi Dave, That's a wonderful idea, I almost can't believe it. Thanks for doing this= , it's much appreciated and I'm sure a lot of shorewall users will be ver= y happy! Regards,Simon Am 19. Juli 2026 um 06:55 schrieb "Dave Kempe" <[email protected] mail= to:[email protected]?to=3D%22Dave%20Kempe%22%20%3Cdavidkempe%40gmail.c= om%3E >: >=20 >=20Hi Shorewall people! >=20 >=20We (sol1.com.au http://sol1.com.au/ ) have been avid Shorewall users = and supporters for around 20 years. Wow that is a long time. We have a fl= eet of managed firewalls that use Shorewall, among other things, to keep = many of our customers online and secure. The decline of Shorewall has bee= n "a problem for another day" for a long time now, and I finally decided = to do something about it. >=20 >=20Shorewall-nft is a Python ground up rewrite, specifically to support = keeping your shorewall config the same, but it emits pure nftables. > https://github.com/sol1/shorewall-nft >=20 >=20We are running it on many of our systems already,=C2=A0in fact, these= packets are flowing to you over it right now. It was tested and develope= d against a primary fleet of 45 different firewall configs, including all= the standard=C2=A0configurations and much of the weirder configurations = represented. >=20 >=20Our aim is to replace Shorewall with shorewall-nft, and continue supp= orting it. Our team has managed custom software and linux firewalls for y= ears, and would be honoured to become custodians of this project. Of cour= se we welcome all input, and this is a true Open Source project. >=20 >=20We would love some feedback on whether it works for you. You can simp= ly grab the deb or rpm, do=C2=A0 a shorewall check and shorewall migrate,= and it will flush your old rules and switch you to nftables. >=20 >=20As bonus features, we also built shorewall-lsm, a Link Status Monitor= with multi-ISP support that appears to be working well and geoip improve= ments along they way. Any improvements maintain backwards config capabili= ty, and simply add to the existing config base. > See=C2=A0https://github.com/sol1/shorewall-nft/blob/main/docs/failover.= md for more info on shorewall-lsm >=20 >=20Happy to provide support or see FRs via github infrastructure. If the= project gets legs at all, we will consider a docs site or other further = improvements. >=20 >=20Thanks > Dave Kempe >=20 --=20 Simon Matter Tel: +41 61 311 40 70 Glasiweg 8b CH-6242 Wauwil --8999eea5-83dd-446c-83fa-c069a2f55015-1 Content-Type: text/html; charset="utf-8" Content-Transfer-Encoding: quoted-printable <!DOCTYPE html><html><head><meta http-equiv=3D"Content-Type" content=3D"t= ext/html; charset=3Dutf-8"></head><body>Hi Dave,<br><br>That's a wonderfu= l idea, I almost can't believe it. Thanks for doing this, it's much appre= ciated and I'm sure a lot of shorewall users will be very happy!<br><br>R= egards,Simon<div><br><br></div><p>Am 19. Juli 2026 um 06:55 schrieb "Dave= Kempe" <<a href=3D"mailto:[email protected]?to=3D%22Dave%20Kempe%2= 2%20%3Cdavidkempe%40gmail.com%3E" target=3D"_blank" tabindex=3D"-1">david= [email protected]</a>>:</p><blockquote><div dir=3D"ltr"><div>Hi Shorewal= l people!</div><div><br></div><div>We (<a href=3D"http://sol1.com.au/" ta= rget=3D"_blank" tabindex=3D"-1">sol1.com.au</a>) have been avid Shorewall= users and supporters for around 20 years. Wow that is a long time. We ha= ve a fleet of managed firewalls that use Shorewall, among other things, t= o keep many of our customers online and secure. The decline of Shorewall = has been "a problem for another day" for a long time now, and I finally d= ecided to do something about it.</div><div><br></div><div>Shorewall-nft i= s a Python ground up rewrite, specifically to support keeping your shorew= all config the same, but it emits pure nftables.</div><div><br><a href=3D= "https://github.com/sol1/shorewall-nft" target=3D"_blank" tabindex=3D"-1"= >https://github.com/sol1/shorewall-nft</a></div><div><br></div><div>We ar= e running it on many of our systems already,=C2=A0in fact, these packets = are flowing to you over it right now. It was tested and developed against= a primary fleet of 45 different firewall configs, including all the stan= dard=C2=A0configurations and much of the weirder configurations represent= ed.</div><div><br></div><div>Our aim is to replace Shorewall with shorewa= ll-nft, and continue supporting it. Our team has managed custom software = and linux firewalls for years, and would be honoured to become custodians= of this project. Of course we welcome all input, and this is a true Open= Source project.</div><div><br></div><div>We would love some feedback on = whether it works for you. You can simply grab the deb or rpm, do=C2=A0 a = shorewall check and shorewall migrate, and it will flush your old rules a= nd switch you to nftables.</div><div><br></div><div>As bonus features, we= also built shorewall-lsm, a Link Status Monitor with multi-ISP support t= hat appears to be working well and geoip improvements along they way. Any= improvements maintain backwards config capability, and simply add to the= existing config base.</div><div>See=C2=A0<a href=3D"https://github.com/s= ol1/shorewall-nft/blob/main/docs/failover.md" target=3D"_blank" tabindex= =3D"-1">https://github.com/sol1/shorewall-nft/blob/main/docs/failover.md<= /a> for more info on shorewall-lsm</div><div><br></div><div>Happy to prov= ide support or see FRs via github infrastructure. If the project gets leg= s at all, we will consider a docs site or other further improvements.</di= v><div><br></div><div>Thanks</div><div>Dave Kempe</div><div><br></div><di= v><br></div></div></blockquote><br><br><div class=3D"rl-signature">-- <br= >Simon Matter Tel: +41 61 311 40 70<br>Glasiweg 8b<br>CH-624= 2 Wauwil</div></body></html> --8999eea5-83dd-446c-83fa-c069a2f55015-1-- --===============1269224026869079912== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============1269224026869079912== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline