Re: Introducing shorewall-nft
justina colmena ~biz via Shorewall-users <[email protected]> Sun, 19 Jul 2026 21:26:26 -0800
| Newsgroups | gmane.comp.security.shorewall |
|---|---|
| Message-ID | <[email protected]> |
--===============8255387962883508449==
Content-Type: multipart/alternative;
boundary=----QGEU8UFDCRWVQ0D7VSFUW2V1FCWHKJ
Content-Transfer-Encoding: 7bit
------QGEU8UFDCRWVQ0D7VSFUW2V1FCWHKJ
Content-Type: text/plain;
charset=utf-8
Content-Transfer-Encoding: quoted-printable
Something simple and basic for Linux firewall configuration nobody else is =
willing to do=2E You don't build a firewall to keep the friendlies out, do =
you?
On July 19, 2026 8:56:49 PM AKDT, Winston Sorfleet <wls@romanus=2Eca> wrot=
e:
>I echo this=2E=C2=A0 I got into Shorewall because I wanted an easy way to=
stay sane with multi-ISP (where I live, the fast provider didn't give stat=
ic IP nor IPv6; DSL provided both but was hardly fast)=2E=C2=A0 Shorewall[6=
] has been a lifesaver and I'm eternally grateful to Tom, so if Dave is wil=
ling to take up the banner and give back to Shorewall, thank you!
>
>On 2026-07-19 4:24 a=2Em=2E, bruban262@gmail=2Ecom wrote:
>> Well done David,
>>=20
>> What a fantastic initiative to preserve the outstanding firewall abstra=
ction provided by Shorewall, together with the years of development effort =
to support that abstraction=2E
>>=20
>> Moving to Python is a great way forward=2E
>>=20
>> I=E2=80=99ve been dreading migrating from Shorewall=2E =C2=A0You=E2=80=
=99ve given me hope=2E
>>=20
>> Cheers,
>>=20
>> Bruce
>>=20
>>=20
>>> On 19 Jul 2026, at 14:56, Dave Kempe <davidkempe@gmail=2Ecom> wrote:
>>>=20
>>> =EF=BB=BF
>>> Hi Shorewall people!
>>>=20
>>> We (sol1=2Ecom=2Eau <http://sol1=2Ecom=2Eau>) have been avid Shorewall=
users and supporters for around 20 years=2E Wow that is a long time=2E We =
have a fleet of managed firewalls that use Shorewall, among other things, t=
o keep many of our customers online and secure=2E The decline of Shorewall =
has been "a problem for another day" for a long time now, and I finally dec=
ided to do something about it=2E
>>>=20
>>> Shorewall-nft is a Python ground up rewrite, specifically to support k=
eeping your shorewall config the same, but it emits pure nftables=2E
>>>=20
>>> https://github=2Ecom/sol1/shorewall-nft
>>>=20
>>> We are running it on many of our systems already,=C2=A0in fact, these =
packets are flowing to you over it right now=2E It was tested and developed=
against a primary fleet of 45 different firewall configs, including all th=
e standard=C2=A0configurations and much of the weirder configurations repre=
sented=2E
>>>=20
>>> Our aim is to replace Shorewall with shorewall-nft, and continue suppo=
rting it=2E Our team has managed custom software and linux firewalls for ye=
ars, and would be honoured to become custodians of this project=2E Of cours=
e we welcome all input, and this is a true Open Source project=2E
>>>=20
>>> We would love some feedback on whether it works for you=2E You can sim=
ply grab the deb or rpm, do=C2=A0 a shorewall check and shorewall migrate, =
and it will flush your old rules and switch you to nftables=2E
>>>=20
>>> As bonus features, we also built shorewall-lsm, a Link Status Monitor =
with multi-ISP support that appears to be working well and geoip improvemen=
ts along they way=2E Any improvements maintain backwards config capability,=
and simply add to the existing config base=2E
>>> See https://github=2Ecom/sol1/shorewall-nft/blob/main/docs/failover=2E=
md for more info on shorewall-lsm
>>>=20
>>> Happy to provide support or see FRs via github infrastructure=2E If th=
e project gets legs at all, we will consider a docs site or other further i=
mprovements=2E
>>>=20
>>> Thanks
>>> Dave Kempe
>>>=20
>>>=20
>>> _______________________________________________
>>> Shorewall-users mailing list
>>> Shorewall-users@lists=2Esourceforge=2Enet
>>> https://lists=2Esourceforge=2Enet/lists/listinfo/shorewall-users
>>=20
>>=20
>> _______________________________________________
>> Shorewall-users mailing list
>> Shorewall-users@lists=2Esourceforge=2Enet
>> https://lists=2Esourceforge=2Enet/lists/listinfo/shorewall-users
------QGEU8UFDCRWVQ0D7VSFUW2V1FCWHKJ
Content-Type: text/html;
charset=utf-8
Content-Transfer-Encoding: quoted-printable
<!doctype html>
<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DUTF-=
8">
</head>
<body><div dir=3D"auto">Something simple and basic for Linux firewall co=
nfiguration nobody else is willing to do=2E You don't build a firewall to k=
eep the friendlies out, do you?</div><br><br><div class=3D"gmail_quote"><di=
v dir=3D"auto">On July 19, 2026 8:56:49 PM AKDT, Winston Sorfleet <wls@r=
omanus=2Eca> wrote:</div><blockquote class=3D"gmail_quote" style=3D"marg=
in: 0pt 0pt 0pt 0=2E8ex; border-left: 1px solid rgb(204, 204, 204); padding=
-left: 1ex;">
<p>I echo this=2E I got into Shorewall because I wanted an easy =
way
to stay sane with multi-ISP (where I live, the fast provider
didn't give static IP nor IPv6; DSL provided both but was hardly
fast)=2E Shorewall[6] has been a lifesaver and I'm eternally
grateful to Tom, so if Dave is willing to take up the banner and
give back to Shorewall, thank you!</p>
<div class=3D"moz-cite-prefix">On 2026-07-19 4:24 a=2Em=2E,
<a class=3D"moz-txt-link-abbreviated" href=3D"mailto:bruban262@gmail=
=2Ecom">bruban262@gmail=2Ecom</a> wrote:<br>
</div>
<blockquote type=3D"cite" cite=3D"mid:08654C71-A0C5-43F8-8F56-9934F9E5=
3E72@gmail=2Ecom">
<meta http-equiv=3D"content-type" content=3D"text/html; charset=3DUT=
F-8">
<div dir=3D"ltr">Well done David,</div>
<div dir=3D"ltr"><br>
</div>
<div dir=3D"ltr">What a fantastic initiative to preserve the
outstanding firewall abstraction provided by Shorewall, together
with the years of development effort to support that
abstraction=2E</div>
<div dir=3D"ltr"><br>
</div>
<div dir=3D"ltr">Moving to Python is a great way forward=2E</div>
<div dir=3D"ltr"><br>
</div>
<div dir=3D"ltr">I=E2=80=99ve been dreading migrating from Shorewall=
=2E
You=E2=80=99ve given me hope=2E</div>
<div dir=3D"ltr"><br>
</div>
<div dir=3D"ltr">Cheers,</div>
<div dir=3D"ltr"><br>
</div>
<div dir=3D"ltr">Bruce</div>
<div dir=3D"ltr"><br>
</div>
<div dir=3D"ltr"><br>
<blockquote type=3D"cite">On 19 Jul 2026, at 14:56, Dave Kempe
<a class=3D"moz-txt-link-rfc2396E" href=3D"mailto:davidkempe@gma=
il=2Ecom"><davidkempe@gmail=2Ecom></a> wrote:<br>
<br>
</blockquote>
</div>
<blockquote type=3D"cite">
<div dir=3D"ltr">=EF=BB=BF
<div dir=3D"ltr">
<div>Hi Shorewall people!</div>
<div><br>
</div>
<div>We (<a href=3D"http://sol1=2Ecom=2Eau" moz-do-not-send=3D=
"true">sol1=2Ecom=2Eau</a>)
have been avid Shorewall users and supporters for around
20 years=2E Wow that is a long time=2E We have a fleet of
managed firewalls that use Shorewall, among other things,
to keep many of our customers online and secure=2E The
decline of Shorewall has been "a problem for another day"
for a long time now, and I finally decided to do something
about it=2E</div>
<div><br>
</div>
<div>Shorewall-nft is a Python ground up rewrite,
specifically to support keeping your shorewall config the
same, but it emits pure nftables=2E</div>
<div><br>
<a href=3D"https://github=2Ecom/sol1/shorewall-nft" moz-do-n=
ot-send=3D"true" class=3D"moz-txt-link-freetext">https://github=2Ecom/sol1/=
shorewall-nft</a></div>
<div><br>
</div>
<div>We are running it on many of our systems already, in
fact, these packets are flowing to you over it right now=2E
It was tested and developed against a primary fleet of 45
different firewall configs, including all the
standard configurations and much of the weirder
configurations represented=2E</div>
<div><br>
</div>
<div>Our aim is to replace Shorewall with shorewall-nft, and
continue supporting it=2E Our team has managed custom
software and linux firewalls for years, and would be
honoured to become custodians of this project=2E Of course
we welcome all input, and this is a true Open Source
project=2E</div>
<div><br>
</div>
<div>We would love some feedback on whether it works for
you=2E You can simply grab the deb or rpm, do a shorew=
all
check and shorewall migrate, and it will flush your old
rules and switch you to nftables=2E</div>
<div><br>
</div>
<div>As bonus features, we also built shorewall-lsm, a Link
Status Monitor with multi-ISP support that appears to be
working well and geoip improvements along they way=2E Any
improvements maintain backwards config capability, and
simply add to the existing config base=2E<br>
</div>
<div>See <a href=3D"https://github=2Ecom/sol1/shorewall-n=
ft/blob/main/docs/failover=2Emd" moz-do-not-send=3D"true" class=3D"moz-txt-=
link-freetext">https://github=2Ecom/sol1/shorewall-nft/blob/main/docs/failo=
ver=2Emd</a>
for more info on shorewall-lsm</div>
<div><br>
</div>
<div>Happy to provide support or see FRs via github
infrastructure=2E If the project gets legs at all, we will
consider a docs site or other further improvements=2E</div>
<div><br>
</div>
<div>Thanks</div>
<div>Dave Kempe</div>
<div><br>
</div>
<div><br>
</div>
</div>
<span>_______________________________________________</span><br>
<span>Shorewall-users mailing list</span><br>
<span><a class=3D"moz-txt-link-abbreviated" href=3D"mailto:Shore=
wall-users@lists=2Esourceforge=2Enet">Shorewall-users@lists=2Esourceforge=
=2Enet</a></span><br>
<span><a class=3D"moz-txt-link-freetext" href=3D"https://lists=
=2Esourceforge=2Enet/lists/listinfo/shorewall-users">https://lists=2Esource=
forge=2Enet/lists/listinfo/shorewall-users</a></span><br>
</div>
</blockquote>
<br>
<fieldset class=3D"moz-mime-attachment-header"></fieldset>
<br>
<fieldset class=3D"moz-mime-attachment-header"></fieldset>
<pre wrap=3D"" class=3D"moz-quote-pre">_____________________________=
__________________
Shorewall-users mailing list
<a class=3D"moz-txt-link-abbreviated" href=3D"mailto:Shorewall-users@lists=
=2Esourceforge=2Enet">Shorewall-users@lists=2Esourceforge=2Enet</a>
<a class=3D"moz-txt-link-freetext" href=3D"https://lists=2Esourceforge=2En=
et/lists/listinfo/shorewall-users">https://lists=2Esourceforge=2Enet/lists/=
listinfo/shorewall-users</a>
</pre>
</blockquote>
</blockquote></div></body>
</html>
------QGEU8UFDCRWVQ0D7VSFUW2V1FCWHKJ--
--===============8255387962883508449==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--===============8255387962883508449==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline