shorewall-nft 0.2.0 released

Dave Kempe <[email protected]> Wed, 22 Jul 2026 08:16:26 +1000
Newsgroups gmane.comp.security.shorewall
Message-ID <CAEc_UVRXH5xLxTJPOqoCcxD6T5rqLS61oLDJxzgD7HLhATQMMg@mail.gmail.com>
--===============4230566406219219811==
Content-Type: multipart/alternative; boundary="00000000000074795a065726605e"

--00000000000074795a065726605e
Content-Type: text/plain; charset="UTF-8"

 shorewall-nft 0.2.0

A feature release: run shorewall-nft on machines that cannot run the
compiler, and bootstrap a firewall on a clean box.
Shorewall Lite

Run a shorewall-nft firewall on a target with no compiler: a small embedded
system, an OpenWRT router, anything without Python. A new runtime-only
package, *shorewall-nft-lite*, depends only on nftables and iproute2.

   - Compile on a full system with shorewall compile -e, deploy with *shorewall
   load SYSTEM* over ssh, and run it on the target with *shorewall-lite* (
   start, stop, reload, restart, status, check).
   - *shorecap* on the target captures its capabilities so the admin can
   compile a ruleset that matches that kernel with --caps.
   - Packages for Debian, Ubuntu, Fedora, RHEL, Arch and OpenWRT.
   - See docs/lite.md
   <https://github.com/sol1/shorewall-nft/blob/main/docs/lite.md> for
   running it and docs/distros.md
   <https://github.com/sol1/shorewall-nft/blob/main/docs/distros.md> for
   the per-distro layout.

shorewall init

Bootstrap a clean install, the counterpart to migrate.

   - *shorewall init* with no arguments runs an interactive wizard: it
   detects your interfaces, guesses the uplink from the default route, and
   writes a working starting point (standalone, gateway or three-zone).
   - Or non-interactively: shorewall init --gateway --net eth0 --loc eth1.
   - It keeps SSH to the firewall open so you cannot lock yourself out,
   never starts the firewall on its own, and refuses to overwrite an existing
   configuration.

--00000000000074795a065726605e
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">
<h2>shorewall-nft 0.2.0</h2>
<p>A feature release: run shorewall-nft on machines that cannot run the com=
piler, and bootstrap a firewall on a clean box.</p>
<h3>Shorewall Lite</h3>
<p>Run a shorewall-nft firewall on a target with no compiler: a small=20
embedded system, an OpenWRT router, anything without Python. A new=20
runtime-only package, <strong>shorewall-nft-lite</strong>, depends only on =
nftables and iproute2.</p>
<ul><li>Compile on a full system with <code>shorewall compile -e</code>, de=
ploy with <strong><code>shorewall load SYSTEM</code></strong> over ssh, and=
 run it on the target with <strong><code>shorewall-lite</code></strong> (<c=
ode>start</code>, <code>stop</code>, <code>reload</code>, <code>restart</co=
de>, <code>status</code>, <code>check</code>).</li><li><strong><code>shorec=
ap</code></strong> on the target captures its capabilities so the admin can=
 compile a ruleset that matches that kernel with <code>--caps</code>.</li><=
li>Packages for Debian, Ubuntu, Fedora, RHEL, Arch and OpenWRT.</li><li>See=
 <a href=3D"https://github.com/sol1/shorewall-nft/blob/main/docs/lite.md">d=
ocs/lite.md</a> for running it and <a href=3D"https://github.com/sol1/shore=
wall-nft/blob/main/docs/distros.md">docs/distros.md</a> for the per-distro =
layout.</li></ul>
<h3>shorewall init</h3>
<p>Bootstrap a clean install, the counterpart to <code>migrate</code>.</p>
<ul><li><strong><code>shorewall init</code></strong> with no arguments runs=
=20
an interactive wizard: it detects your interfaces, guesses the uplink=20
from the default route, and writes a working starting point (standalone,
 gateway or three-zone).</li><li>Or non-interactively: <code>shorewall init=
 --gateway --net eth0 --loc eth1</code>.</li><li>It keeps SSH to the firewa=
ll open so you cannot lock yourself out,=20
never starts the firewall on its own, and refuses to overwrite an=20
existing configuration.</li></ul>

<br></div>

--00000000000074795a065726605e--


--===============4230566406219219811==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============4230566406219219811==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline