Re: Introducing shorewall-nft

justina colmena ~biz via Shorewall-users <[email protected]> Sun, 19 Jul 2026 21:26:26 -0800
Newsgroups gmane.comp.security.shorewall
Message-ID <[email protected]>
--===============8255387962883508449==
Content-Type: multipart/alternative;
 boundary=----QGEU8UFDCRWVQ0D7VSFUW2V1FCWHKJ
Content-Transfer-Encoding: 7bit

------QGEU8UFDCRWVQ0D7VSFUW2V1FCWHKJ
Content-Type: text/plain;
 charset=utf-8
Content-Transfer-Encoding: quoted-printable

Something simple and basic for Linux firewall configuration nobody else is =
willing to do=2E You don't build a firewall to keep the friendlies out, do =
you?

On July 19, 2026 8:56:49 PM AKDT, Winston Sorfleet <wls@romanus=2Eca> wrot=
e:
>I echo this=2E=C2=A0 I got into Shorewall because I wanted an easy way to=
 stay sane with multi-ISP (where I live, the fast provider didn't give stat=
ic IP nor IPv6; DSL provided both but was hardly fast)=2E=C2=A0 Shorewall[6=
] has been a lifesaver and I'm eternally grateful to Tom, so if Dave is wil=
ling to take up the banner and give back to Shorewall, thank you!
>
>On 2026-07-19 4:24 a=2Em=2E, bruban262@gmail=2Ecom wrote:
>> Well done David,
>>=20
>> What a fantastic initiative to preserve the outstanding firewall abstra=
ction provided by Shorewall, together with the years of development effort =
to support that abstraction=2E
>>=20
>> Moving to Python is a great way forward=2E
>>=20
>> I=E2=80=99ve been dreading migrating from Shorewall=2E =C2=A0You=E2=80=
=99ve given me hope=2E
>>=20
>> Cheers,
>>=20
>> Bruce
>>=20
>>=20
>>> On 19 Jul 2026, at 14:56, Dave Kempe <davidkempe@gmail=2Ecom> wrote:
>>>=20
>>> =EF=BB=BF
>>> Hi Shorewall people!
>>>=20
>>> We (sol1=2Ecom=2Eau <http://sol1=2Ecom=2Eau>) have been avid Shorewall=
 users and supporters for around 20 years=2E Wow that is a long time=2E We =
have a fleet of managed firewalls that use Shorewall, among other things, t=
o keep many of our customers online and secure=2E The decline of Shorewall =
has been "a problem for another day" for a long time now, and I finally dec=
ided to do something about it=2E
>>>=20
>>> Shorewall-nft is a Python ground up rewrite, specifically to support k=
eeping your shorewall config the same, but it emits pure nftables=2E
>>>=20
>>> https://github=2Ecom/sol1/shorewall-nft
>>>=20
>>> We are running it on many of our systems already,=C2=A0in fact, these =
packets are flowing to you over it right now=2E It was tested and developed=
 against a primary fleet of 45 different firewall configs, including all th=
e standard=C2=A0configurations and much of the weirder configurations repre=
sented=2E
>>>=20
>>> Our aim is to replace Shorewall with shorewall-nft, and continue suppo=
rting it=2E Our team has managed custom software and linux firewalls for ye=
ars, and would be honoured to become custodians of this project=2E Of cours=
e we welcome all input, and this is a true Open Source project=2E
>>>=20
>>> We would love some feedback on whether it works for you=2E You can sim=
ply grab the deb or rpm, do=C2=A0 a shorewall check and shorewall migrate, =
and it will flush your old rules and switch you to nftables=2E
>>>=20
>>> As bonus features, we also built shorewall-lsm, a Link Status Monitor =
with multi-ISP support that appears to be working well and geoip improvemen=
ts along they way=2E Any improvements maintain backwards config capability,=
 and simply add to the existing config base=2E
>>> See https://github=2Ecom/sol1/shorewall-nft/blob/main/docs/failover=2E=
md for more info on shorewall-lsm
>>>=20
>>> Happy to provide support or see FRs via github infrastructure=2E If th=
e project gets legs at all, we will consider a docs site or other further i=
mprovements=2E
>>>=20
>>> Thanks
>>> Dave Kempe
>>>=20
>>>=20
>>> _______________________________________________
>>> Shorewall-users mailing list
>>> Shorewall-users@lists=2Esourceforge=2Enet
>>> https://lists=2Esourceforge=2Enet/lists/listinfo/shorewall-users
>>=20
>>=20
>> _______________________________________________
>> Shorewall-users mailing list
>> Shorewall-users@lists=2Esourceforge=2Enet
>> https://lists=2Esourceforge=2Enet/lists/listinfo/shorewall-users
------QGEU8UFDCRWVQ0D7VSFUW2V1FCWHKJ
Content-Type: text/html;
 charset=utf-8
Content-Transfer-Encoding: quoted-printable

<!doctype html>
<html>
  <head>
    <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DUTF-=
8">
  </head>
  <body><div dir=3D"auto">Something simple and basic for Linux firewall co=
nfiguration nobody else is willing to do=2E You don't build a firewall to k=
eep the friendlies out, do you?</div><br><br><div class=3D"gmail_quote"><di=
v dir=3D"auto">On July 19, 2026 8:56:49 PM AKDT, Winston Sorfleet &lt;wls@r=
omanus=2Eca&gt; wrote:</div><blockquote class=3D"gmail_quote" style=3D"marg=
in: 0pt 0pt 0pt 0=2E8ex; border-left: 1px solid rgb(204, 204, 204); padding=
-left: 1ex;">

    <p>I echo this=2E&nbsp; I got into Shorewall because I wanted an easy =
way
      to stay sane with multi-ISP (where I live, the fast provider
      didn't give static IP nor IPv6; DSL provided both but was hardly
      fast)=2E&nbsp; Shorewall[6] has been a lifesaver and I'm eternally
      grateful to Tom, so if Dave is willing to take up the banner and
      give back to Shorewall, thank you!</p>
    <div class=3D"moz-cite-prefix">On 2026-07-19 4:24 a=2Em=2E,
      <a class=3D"moz-txt-link-abbreviated" href=3D"mailto:bruban262@gmail=
=2Ecom">bruban262@gmail=2Ecom</a> wrote:<br>
    </div>
    <blockquote type=3D"cite" cite=3D"mid:08654C71-A0C5-43F8-8F56-9934F9E5=
3E72@gmail=2Ecom">
      <meta http-equiv=3D"content-type" content=3D"text/html; charset=3DUT=
F-8">
      <div dir=3D"ltr">Well done David,</div>
      <div dir=3D"ltr"><br>
      </div>
      <div dir=3D"ltr">What a fantastic initiative to preserve the
        outstanding firewall abstraction provided by Shorewall, together
        with the years of development effort to support that
        abstraction=2E</div>
      <div dir=3D"ltr"><br>
      </div>
      <div dir=3D"ltr">Moving to Python is a great way forward=2E</div>
      <div dir=3D"ltr"><br>
      </div>
      <div dir=3D"ltr">I=E2=80=99ve been dreading migrating from Shorewall=
=2E
        &nbsp;You=E2=80=99ve given me hope=2E</div>
      <div dir=3D"ltr"><br>
      </div>
      <div dir=3D"ltr">Cheers,</div>
      <div dir=3D"ltr"><br>
      </div>
      <div dir=3D"ltr">Bruce</div>
      <div dir=3D"ltr"><br>
      </div>
      <div dir=3D"ltr"><br>
        <blockquote type=3D"cite">On 19 Jul 2026, at 14:56, Dave Kempe
          <a class=3D"moz-txt-link-rfc2396E" href=3D"mailto:davidkempe@gma=
il=2Ecom">&lt;davidkempe@gmail=2Ecom&gt;</a> wrote:<br>
          <br>
        </blockquote>
      </div>
      <blockquote type=3D"cite">
        <div dir=3D"ltr">=EF=BB=BF
          <div dir=3D"ltr">
            <div>Hi Shorewall people!</div>
            <div><br>
            </div>
            <div>We (<a href=3D"http://sol1=2Ecom=2Eau" moz-do-not-send=3D=
"true">sol1=2Ecom=2Eau</a>)
              have been avid Shorewall users and supporters for around
              20 years=2E Wow that is a long time=2E We have a fleet of
              managed firewalls that use Shorewall, among other things,
              to keep many of our customers online and secure=2E The
              decline of Shorewall has been "a problem for another day"
              for a long time now, and I finally decided to do something
              about it=2E</div>
            <div><br>
            </div>
            <div>Shorewall-nft is a Python ground up rewrite,
              specifically to support keeping your shorewall config the
              same, but it emits pure nftables=2E</div>
            <div><br>
              <a href=3D"https://github=2Ecom/sol1/shorewall-nft" moz-do-n=
ot-send=3D"true" class=3D"moz-txt-link-freetext">https://github=2Ecom/sol1/=
shorewall-nft</a></div>
            <div><br>
            </div>
            <div>We are running it on many of our systems already,&nbsp;in
              fact, these packets are flowing to you over it right now=2E
              It was tested and developed against a primary fleet of 45
              different firewall configs, including all the
              standard&nbsp;configurations and much of the weirder
              configurations represented=2E</div>
            <div><br>
            </div>
            <div>Our aim is to replace Shorewall with shorewall-nft, and
              continue supporting it=2E Our team has managed custom
              software and linux firewalls for years, and would be
              honoured to become custodians of this project=2E Of course
              we welcome all input, and this is a true Open Source
              project=2E</div>
            <div><br>
            </div>
            <div>We would love some feedback on whether it works for
              you=2E You can simply grab the deb or rpm, do&nbsp; a shorew=
all
              check and shorewall migrate, and it will flush your old
              rules and switch you to nftables=2E</div>
            <div><br>
            </div>
            <div>As bonus features, we also built shorewall-lsm, a Link
              Status Monitor with multi-ISP support that appears to be
              working well and geoip improvements along they way=2E Any
              improvements maintain backwards config capability, and
              simply add to the existing config base=2E<br>
            </div>
            <div>See&nbsp;<a href=3D"https://github=2Ecom/sol1/shorewall-n=
ft/blob/main/docs/failover=2Emd" moz-do-not-send=3D"true" class=3D"moz-txt-=
link-freetext">https://github=2Ecom/sol1/shorewall-nft/blob/main/docs/failo=
ver=2Emd</a>
              for more info on shorewall-lsm</div>
            <div><br>
            </div>
            <div>Happy to provide support or see FRs via github
              infrastructure=2E If the project gets legs at all, we will
              consider a docs site or other further improvements=2E</div>
            <div><br>
            </div>
            <div>Thanks</div>
            <div>Dave Kempe</div>
            <div><br>
            </div>
            <div><br>
            </div>
          </div>
          <span>_______________________________________________</span><br>
          <span>Shorewall-users mailing list</span><br>
          <span><a class=3D"moz-txt-link-abbreviated" href=3D"mailto:Shore=
wall-users@lists=2Esourceforge=2Enet">Shorewall-users@lists=2Esourceforge=
=2Enet</a></span><br>
          <span><a class=3D"moz-txt-link-freetext" href=3D"https://lists=
=2Esourceforge=2Enet/lists/listinfo/shorewall-users">https://lists=2Esource=
forge=2Enet/lists/listinfo/shorewall-users</a></span><br>
        </div>
      </blockquote>
      <br>
      <fieldset class=3D"moz-mime-attachment-header"></fieldset>
      <br>
      <fieldset class=3D"moz-mime-attachment-header"></fieldset>
      <pre wrap=3D"" class=3D"moz-quote-pre">_____________________________=
__________________
Shorewall-users mailing list
<a class=3D"moz-txt-link-abbreviated" href=3D"mailto:Shorewall-users@lists=
=2Esourceforge=2Enet">Shorewall-users@lists=2Esourceforge=2Enet</a>
<a class=3D"moz-txt-link-freetext" href=3D"https://lists=2Esourceforge=2En=
et/lists/listinfo/shorewall-users">https://lists=2Esourceforge=2Enet/lists/=
listinfo/shorewall-users</a>
</pre>
    </blockquote>
  </blockquote></div></body>
</html>

------QGEU8UFDCRWVQ0D7VSFUW2V1FCWHKJ--


--===============8255387962883508449==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============8255387962883508449==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline