Re: Introducing shorewall-nft

Phil Stracchino <[email protected]> Sun, 19 Jul 2026 13:34:47 -0400
Newsgroups gmane.comp.security.shorewall
Organization Fenian House Publishing
Message-ID <[email protected]>
On 7/19/26 00:55, Dave Kempe wrote:
> Hi Shorewall people!
> 
> We (sol1.com.au <http://sol1.com.au>) have been avid Shorewall users and 
> supporters for around 20 years. Wow that is a long time. We have a fleet 
> of managed firewalls that use Shorewall, among other things, to keep 
> many of our customers online and secure. The decline of Shorewall has 
> been "a problem for another day" for a long time now, and I finally 
> decided to do something about it.

I salute you!!!  Shorewall is a first-class tool that deserves to continue.

iptables, ipchains, nftables are all examples of utterly horrible 
software design:  An important tool whose syntax is not merely not 
user-friendly, but actively user-hostile.  It is the *operating 
system*'s job to understand that internal firewall syntax, not the 
user's.  The user should be able to just *describe what they want to 
happen* and then have that compiled into roles the OS understands, and 
that's what Shorewall does, and does it very well.

Before Shorewall, my firewall was an OpenBSD P4 box and pf, and as clear 
and easy as pf syntax is, I never once managed to get IRC DCC to work 
properly through NAT.  With Shorewall, I tell it DCC(enable) and it Just 
Freaking Works.



-- 
   Phil Stracchino
   Fenian House Publishing
   [email protected]
   [email protected]
   Landline: +1.603.293.8485
   Mobile:   +1.603.998.6958