Re: Introducing shorewall-nft
Phil Stracchino <[email protected]> Sun, 19 Jul 2026 13:34:47 -0400
| Newsgroups | gmane.comp.security.shorewall |
|---|---|
| Organization | Fenian House Publishing |
| Message-ID | <[email protected]> |
On 7/19/26 00:55, Dave Kempe wrote: > Hi Shorewall people! > > We (sol1.com.au <http://sol1.com.au>) have been avid Shorewall users and > supporters for around 20 years. Wow that is a long time. We have a fleet > of managed firewalls that use Shorewall, among other things, to keep > many of our customers online and secure. The decline of Shorewall has > been "a problem for another day" for a long time now, and I finally > decided to do something about it. I salute you!!! Shorewall is a first-class tool that deserves to continue. iptables, ipchains, nftables are all examples of utterly horrible software design: An important tool whose syntax is not merely not user-friendly, but actively user-hostile. It is the *operating system*'s job to understand that internal firewall syntax, not the user's. The user should be able to just *describe what they want to happen* and then have that compiled into roles the OS understands, and that's what Shorewall does, and does it very well. Before Shorewall, my firewall was an OpenBSD P4 box and pf, and as clear and easy as pf syntax is, I never once managed to get IRC DCC to work properly through NAT. With Shorewall, I tell it DCC(enable) and it Just Freaking Works. -- Phil Stracchino Fenian House Publishing [email protected] [email protected] Landline: +1.603.293.8485 Mobile: +1.603.998.6958