shorewall-nft 0.2.0 released
Dave Kempe <[email protected]> Wed, 22 Jul 2026 08:16:26 +1000
| Newsgroups | gmane.comp.security.shorewall |
|---|---|
| Message-ID | <CAEc_UVRXH5xLxTJPOqoCcxD6T5rqLS61oLDJxzgD7HLhATQMMg@mail.gmail.com> |
--===============4230566406219219811== Content-Type: multipart/alternative; boundary="00000000000074795a065726605e" --00000000000074795a065726605e Content-Type: text/plain; charset="UTF-8" shorewall-nft 0.2.0 A feature release: run shorewall-nft on machines that cannot run the compiler, and bootstrap a firewall on a clean box. Shorewall Lite Run a shorewall-nft firewall on a target with no compiler: a small embedded system, an OpenWRT router, anything without Python. A new runtime-only package, *shorewall-nft-lite*, depends only on nftables and iproute2. - Compile on a full system with shorewall compile -e, deploy with *shorewall load SYSTEM* over ssh, and run it on the target with *shorewall-lite* ( start, stop, reload, restart, status, check). - *shorecap* on the target captures its capabilities so the admin can compile a ruleset that matches that kernel with --caps. - Packages for Debian, Ubuntu, Fedora, RHEL, Arch and OpenWRT. - See docs/lite.md <https://github.com/sol1/shorewall-nft/blob/main/docs/lite.md> for running it and docs/distros.md <https://github.com/sol1/shorewall-nft/blob/main/docs/distros.md> for the per-distro layout. shorewall init Bootstrap a clean install, the counterpart to migrate. - *shorewall init* with no arguments runs an interactive wizard: it detects your interfaces, guesses the uplink from the default route, and writes a working starting point (standalone, gateway or three-zone). - Or non-interactively: shorewall init --gateway --net eth0 --loc eth1. - It keeps SSH to the firewall open so you cannot lock yourself out, never starts the firewall on its own, and refuses to overwrite an existing configuration. --00000000000074795a065726605e Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"> <h2>shorewall-nft 0.2.0</h2> <p>A feature release: run shorewall-nft on machines that cannot run the com= piler, and bootstrap a firewall on a clean box.</p> <h3>Shorewall Lite</h3> <p>Run a shorewall-nft firewall on a target with no compiler: a small=20 embedded system, an OpenWRT router, anything without Python. A new=20 runtime-only package, <strong>shorewall-nft-lite</strong>, depends only on = nftables and iproute2.</p> <ul><li>Compile on a full system with <code>shorewall compile -e</code>, de= ploy with <strong><code>shorewall load SYSTEM</code></strong> over ssh, and= run it on the target with <strong><code>shorewall-lite</code></strong> (<c= ode>start</code>, <code>stop</code>, <code>reload</code>, <code>restart</co= de>, <code>status</code>, <code>check</code>).</li><li><strong><code>shorec= ap</code></strong> on the target captures its capabilities so the admin can= compile a ruleset that matches that kernel with <code>--caps</code>.</li><= li>Packages for Debian, Ubuntu, Fedora, RHEL, Arch and OpenWRT.</li><li>See= <a href=3D"https://github.com/sol1/shorewall-nft/blob/main/docs/lite.md">d= ocs/lite.md</a> for running it and <a href=3D"https://github.com/sol1/shore= wall-nft/blob/main/docs/distros.md">docs/distros.md</a> for the per-distro = layout.</li></ul> <h3>shorewall init</h3> <p>Bootstrap a clean install, the counterpart to <code>migrate</code>.</p> <ul><li><strong><code>shorewall init</code></strong> with no arguments runs= =20 an interactive wizard: it detects your interfaces, guesses the uplink=20 from the default route, and writes a working starting point (standalone, gateway or three-zone).</li><li>Or non-interactively: <code>shorewall init= --gateway --net eth0 --loc eth1</code>.</li><li>It keeps SSH to the firewa= ll open so you cannot lock yourself out,=20 never starts the firewall on its own, and refuses to overwrite an=20 existing configuration.</li></ul> <br></div> --00000000000074795a065726605e-- --===============4230566406219219811== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============4230566406219219811== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline