Re: shorewall-nft packages repo

Dave Kempe <[email protected]> Wed, 22 Jul 2026 16:51:40 +1000
Newsgroups gmane.comp.security.shorewall
Message-ID <CAEc_UVSaEXCRwBCugzsa+p5oWtuJ_cGKwSKW-3Dc0WzVTJRLkQ@mail.gmail.com>
--===============2059899478441948910==
Content-Type: multipart/alternative; boundary="0000000000000f572706572d9311"

--0000000000000f572706572d9311
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

The process below will take care of that for you - they conflict, so it
will uninstall the shorewall package and leave the config intact for you.
The two packages can't be installed at once - they both provide the
'shorewall' binary (script)

Dave

On Wed, 22 Jul 2026 at 15:45, Witold Tosta <[email protected]> wrote:

> Hi Dave,
>
> Do I need to uninstall the old shorewall and shorewall6 packages first,
> leaving only the directories with the configuration files? Can the old
> shorewall packages be installed? I'm using Debian Trixie.
>
> Best regards,
>
> Witold Tosta
>
> wt., 21 lip 2026, 08:45 u=C5=BCytkownik Dave Kempe <[email protected]>
> napisa=C5=82:
>
>> Hey everyone,
>> As a way to get started quickly, I have added shorewall-nft to the Sol1
>> packages repo.
>> You can set it up here: https://packages.sol1.net/
>> and then simply:
>> apt install shorewall-nft
>> shorewall check
>> shorewall migrate
>> And you are done.
>>
>> If encounter any problems with check or migrate, you can back out and go
>> back to shorewall, (apt install shorewall etc)
>> Note that shorewall-nft conflicts with shorewall and will uninstall it,
>> with the migrate command actually flushing iptables rules.
>>
>> I haven't got any packages repo for rpm based distros, as we are
>> debian/ubuntu from way back, but I'm sure a quick rpm command will work =
the
>> same sorta way.
>>
>> Dave
>>
>> _______________________________________________
>> Shorewall-users mailing list
>> [email protected]
>> https://lists.sourceforge.net/lists/listinfo/shorewall-users
>>
> _______________________________________________
> Shorewall-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/shorewall-users
>

--0000000000000f572706572d9311
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>The process below will take care of that for you - th=
ey conflict, so it will uninstall the shorewall package and leave the confi=
g intact for you.</div><div>The two packages can&#39;t be installed at once=
 - they both provide the &#39;shorewall&#39; binary (script)</div><div><br>=
</div><div>Dave</div><br><div class=3D"gmail_quote gmail_quote_container"><=
div dir=3D"ltr" class=3D"gmail_attr">On Wed, 22 Jul 2026 at 15:45, Witold T=
osta &lt;<a href=3D"mailto:[email protected]">[email protected]</=
a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0p=
x 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><d=
iv dir=3D"auto"><div>Hi Dave,</div><div dir=3D"auto"><br></div><div dir=3D"=
auto">Do I need to uninstall the old shorewall and shorewall6 packages firs=
t, leaving only the directories with the configuration files? Can the old s=
horewall packages be installed? I&#39;m using Debian Trixie.</div><div dir=
=3D"auto"><br></div><div dir=3D"auto">Best regards,</div><div><br></div><di=
v><div dir=3D"ltr"><div>Witold Tosta</div></div></div></div><br><div class=
=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">wt., 21 lip 2026, 08=
:45 u=C5=BCytkownik Dave Kempe &lt;<a href=3D"mailto:[email protected]" =
target=3D"_blank">[email protected]</a>&gt; napisa=C5=82:<br></div><bloc=
kquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:=
1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr"><div>Hey ever=
yone,</div><div>As a way to get started quickly, I have added shorewall-nft=
 to the Sol1 packages repo.</div><div>You can set it up here:=C2=A0<a href=
=3D"https://packages.sol1.net/" rel=3D"noreferrer" target=3D"_blank">https:=
//packages.sol1.net/</a></div><div>and then simply:</div><div>apt install s=
horewall-nft</div><div>shorewall check</div><div>shorewall migrate</div><di=
v>And you are done.</div><div><br></div><div>If encounter any problems with=
 check or migrate, you can back out and go back to shorewall, (apt install =
shorewall etc)</div><div>Note that shorewall-nft conflicts with shorewall a=
nd will uninstall it, with the migrate command actually=C2=A0flushing iptab=
les rules.</div><div><br></div><div>I haven&#39;t got any packages repo for=
 rpm based distros, as we are debian/ubuntu from way back, but I&#39;m sure=
 a quick rpm command will work the same sorta way.</div><div><br></div><div=
>Dave</div><div><br></div></div>
_______________________________________________<br>
Shorewall-users mailing list<br>
<a href=3D"mailto:[email protected]" rel=3D"noreferrer"=
 target=3D"_blank">[email protected]</a><br>
<a href=3D"https://lists.sourceforge.net/lists/listinfo/shorewall-users" re=
l=3D"noreferrer noreferrer" target=3D"_blank">https://lists.sourceforge.net=
/lists/listinfo/shorewall-users</a><br>
</blockquote></div>
_______________________________________________<br>
Shorewall-users mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank">=
[email protected]</a><br>
<a href=3D"https://lists.sourceforge.net/lists/listinfo/shorewall-users" re=
l=3D"noreferrer" target=3D"_blank">https://lists.sourceforge.net/lists/list=
info/shorewall-users</a><br>
</blockquote></div></div>

--0000000000000f572706572d9311--


--===============2059899478441948910==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============2059899478441948910==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline