Re: Introducing shorewall-nft

Simon Matter via Shorewall-users <[email protected]> Sun, 19 Jul 2026 11:52:43 +0200
Newsgroups gmane.comp.security.shorewall
Message-ID <[email protected]>
--===============1269224026869079912==
Content-Type: multipart/alternative;
 boundary="8999eea5-83dd-446c-83fa-c069a2f55015-1"

--8999eea5-83dd-446c-83fa-c069a2f55015-1
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

Hi Dave,

That's a wonderful idea, I almost can't believe it. Thanks for doing this=
, it's much appreciated and I'm sure a lot of shorewall users will be ver=
y happy!

Regards,Simon



Am 19. Juli 2026 um 06:55 schrieb "Dave Kempe" <[email protected] mail=
to:[email protected]?to=3D%22Dave%20Kempe%22%20%3Cdavidkempe%40gmail.c=
om%3E >:


>=20
>=20Hi Shorewall people!
>=20
>=20We (sol1.com.au http://sol1.com.au/ ) have been avid Shorewall users =
and supporters for around 20 years. Wow that is a long time. We have a fl=
eet of managed firewalls that use Shorewall, among other things, to keep =
many of our customers online and secure. The decline of Shorewall has bee=
n "a problem for another day" for a long time now, and I finally decided =
to do something about it.
>=20
>=20Shorewall-nft is a Python ground up rewrite, specifically to support =
keeping your shorewall config the same, but it emits pure nftables.
> https://github.com/sol1/shorewall-nft
>=20
>=20We are running it on many of our systems already,=C2=A0in fact, these=
 packets are flowing to you over it right now. It was tested and develope=
d against a primary fleet of 45 different firewall configs, including all=
 the standard=C2=A0configurations and much of the weirder configurations =
represented.
>=20
>=20Our aim is to replace Shorewall with shorewall-nft, and continue supp=
orting it. Our team has managed custom software and linux firewalls for y=
ears, and would be honoured to become custodians of this project. Of cour=
se we welcome all input, and this is a true Open Source project.
>=20
>=20We would love some feedback on whether it works for you. You can simp=
ly grab the deb or rpm, do=C2=A0 a shorewall check and shorewall migrate,=
 and it will flush your old rules and switch you to nftables.
>=20
>=20As bonus features, we also built shorewall-lsm, a Link Status Monitor=
 with multi-ISP support that appears to be working well and geoip improve=
ments along they way. Any improvements maintain backwards config capabili=
ty, and simply add to the existing config base.
> See=C2=A0https://github.com/sol1/shorewall-nft/blob/main/docs/failover.=
md for more info on shorewall-lsm
>=20
>=20Happy to provide support or see FRs via github infrastructure. If the=
 project gets legs at all, we will consider a docs site or other further =
improvements.
>=20
>=20Thanks
> Dave Kempe
>=20

--=20
Simon Matter Tel: +41 61 311 40 70
Glasiweg 8b
CH-6242 Wauwil
--8999eea5-83dd-446c-83fa-c069a2f55015-1
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE html><html><head><meta http-equiv=3D"Content-Type" content=3D"t=
ext/html; charset=3Dutf-8"></head><body>Hi Dave,<br><br>That's a wonderfu=
l idea, I almost can't believe it. Thanks for doing this, it's much appre=
ciated and I'm sure a lot of shorewall users will be very happy!<br><br>R=
egards,Simon<div><br><br></div><p>Am 19. Juli 2026 um 06:55 schrieb "Dave=
 Kempe" &lt;<a href=3D"mailto:[email protected]?to=3D%22Dave%20Kempe%2=
2%20%3Cdavidkempe%40gmail.com%3E" target=3D"_blank" tabindex=3D"-1">david=
[email protected]</a>&gt;:</p><blockquote><div dir=3D"ltr"><div>Hi Shorewal=
l people!</div><div><br></div><div>We (<a href=3D"http://sol1.com.au/" ta=
rget=3D"_blank" tabindex=3D"-1">sol1.com.au</a>) have been avid Shorewall=
 users and supporters for around 20 years. Wow that is a long time. We ha=
ve a fleet of managed firewalls that use Shorewall, among other things, t=
o keep many of our customers online and secure. The decline of Shorewall =
has been "a problem for another day" for a long time now, and I finally d=
ecided to do something about it.</div><div><br></div><div>Shorewall-nft i=
s a Python ground up rewrite, specifically to support keeping your shorew=
all config the same, but it emits pure nftables.</div><div><br><a href=3D=
"https://github.com/sol1/shorewall-nft" target=3D"_blank" tabindex=3D"-1"=
>https://github.com/sol1/shorewall-nft</a></div><div><br></div><div>We ar=
e running it on many of our systems already,=C2=A0in fact, these packets =
are flowing to you over it right now. It was tested and developed against=
 a primary fleet of 45 different firewall configs, including all the stan=
dard=C2=A0configurations and much of the weirder configurations represent=
ed.</div><div><br></div><div>Our aim is to replace Shorewall with shorewa=
ll-nft, and continue supporting it. Our team has managed custom software =
and linux firewalls for years, and would be honoured to become custodians=
 of this project. Of course we welcome all input, and this is a true Open=
 Source project.</div><div><br></div><div>We would love some feedback on =
whether it works for you. You can simply grab the deb or rpm, do=C2=A0 a =
shorewall check and shorewall migrate, and it will flush your old rules a=
nd switch you to nftables.</div><div><br></div><div>As bonus features, we=
 also built shorewall-lsm, a Link Status Monitor with multi-ISP support t=
hat appears to be working well and geoip improvements along they way. Any=
 improvements maintain backwards config capability, and simply add to the=
 existing config base.</div><div>See=C2=A0<a href=3D"https://github.com/s=
ol1/shorewall-nft/blob/main/docs/failover.md" target=3D"_blank" tabindex=
=3D"-1">https://github.com/sol1/shorewall-nft/blob/main/docs/failover.md<=
/a> for more info on shorewall-lsm</div><div><br></div><div>Happy to prov=
ide support or see FRs via github infrastructure. If the project gets leg=
s at all, we will consider a docs site or other further improvements.</di=
v><div><br></div><div>Thanks</div><div>Dave Kempe</div><div><br></div><di=
v><br></div></div></blockquote><br><br><div class=3D"rl-signature">-- <br=
>Simon Matter              Tel: +41 61 311 40 70<br>Glasiweg 8b<br>CH-624=
2 Wauwil</div></body></html>
--8999eea5-83dd-446c-83fa-c069a2f55015-1--


--===============1269224026869079912==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============1269224026869079912==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline