Re: Introducing shorewall-nft

Boris via Shorewall-users <[email protected]> Sun, 19 Jul 2026 16:15:37 +0200
Newsgroups gmane.comp.security.shorewall
Message-ID <[email protected]>
Hello Dave

I read your announcement with great interest. Thank you very much for 
your dedication to this cause. It has long been an open question what 
the future holds for Shorewall since nftables came along. It would be a 
terrible loss if Shorewall were to wither away as a result.

Hello Erich,

in a different environment besides from LEAF I am using FirewallBuilder 
with good success and cooperation with guys that are not familiar with 
CLI-stuff.
It's a common practice to use management tools that don't run on the 
firewall itself. I'm familiar with this from commercial products 
(CheckPoint), and I do the same for LEAF boxes in a different context: I 
use XCA on my desktop to manage certificates for OpenVPN. It works 
wonderfully.

Regards,


Boris

Am 19.07.26 um 12:22 schrieb Erich Titl:
> Hi Dave
> 
> Am 19.07.2026 um 06:55 schrieb Dave Kempe:
>> Hi Shorewall people!
> ...
>>
>> Happy to provide support or see FRs via github infrastructure. If the 
>> project gets legs at all, we will consider a docs site or other 
>> further improvements.
> 
> It is a great achievement to continue the keep the shorewall interface 
> alive. We are using shorewall on a very small hardware footprint and I 
> am worrying about the hardware requirements for python and I would also 
> be worried to provide python on a firewall as it is a very powerful tool 
> if the user interface can be broken. So we might need to have a 
> shorewall-nft compiler on separate hardware.
> 
> regards
> 
> ET