Re: shorewall-nft 0.2.0 released

"Robert K Coffman Jr. -Info From Data Corp." <[email protected]> Wed, 22 Jul 2026 08:32:16 -0400
Newsgroups gmane.comp.security.shorewall
Organization Info From Data Corporation
Message-ID <[email protected]>
--===============8734529082098481138==
Content-Language: en-US
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>Thank you Dave!  I find this project intriguing, to say the
      least.  </p>
    <p>- Robert</p>
    <div class="moz-cite-prefix">On 7/21/2026 6:16:26 PM, Dave Kempe
      wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:CAEc_UVRXH5xLxTJPOqoCcxD6T5rqLS61oLDJxzgD7HLhATQMMg@mail.gmail.com">
      <meta http-equiv="content-type" content="text/html; charset=UTF-8">
      <div dir="ltr">
        <h2>shorewall-nft 0.2.0</h2>
        <p>A feature release: run shorewall-nft on machines that cannot
          run the compiler, and bootstrap a firewall on a clean box.</p>
        <h3>Shorewall Lite</h3>
        <p>Run a shorewall-nft firewall on a target with no compiler: a
          small embedded system, an OpenWRT router, anything without
          Python. A new runtime-only package, <strong>shorewall-nft-lite</strong>,
          depends only on nftables and iproute2.</p>
        <ul>
          <li>Compile on a full system with <code>shorewall compile -e</code>,
            deploy with <strong><code>shorewall load SYSTEM</code></strong>
            over ssh, and run it on the target with <strong><code>shorewall-lite</code></strong>
            (<code>start</code>, <code>stop</code>, <code>reload</code>,
            <code>restart</code>, <code>status</code>, <code>check</code>).</li>
          <li><strong><code>shorecap</code></strong> on the target
            captures its capabilities so the admin can compile a ruleset
            that matches that kernel with <code>--caps</code>.</li>
          <li>Packages for Debian, Ubuntu, Fedora, RHEL, Arch and
            OpenWRT.</li>
          <li>See <a
href="https://github.com/sol1/shorewall-nft/blob/main/docs/lite.md"
              moz-do-not-send="true">docs/lite.md</a> for running it and
            <a
href="https://github.com/sol1/shorewall-nft/blob/main/docs/distros.md"
              moz-do-not-send="true">docs/distros.md</a> for the
            per-distro layout.</li>
        </ul>
        <h3>shorewall init</h3>
        <p>Bootstrap a clean install, the counterpart to <code>migrate</code>.</p>
        <ul>
          <li><strong><code>shorewall init</code></strong> with no
            arguments runs an interactive wizard: it detects your
            interfaces, guesses the uplink from the default route, and
            writes a working starting point (standalone, gateway or
            three-zone).</li>
          <li>Or non-interactively: <code>shorewall init --gateway
              --net eth0 --loc eth1</code>.</li>
          <li>It keeps SSH to the firewall open so you cannot lock
            yourself out, never starts the firewall on its own, and
            refuses to overwrite an existing configuration.</li>
        </ul>
        <br>
      </div>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
      <pre wrap="" class="moz-quote-pre">_______________________________________________
Shorewall-users mailing list
<a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
<a class="moz-txt-link-freetext" href="https://lists.sourceforge.net/lists/listinfo/shorewall-users">https://lists.sourceforge.net/lists/listinfo/shorewall-users</a>
</pre>
    </blockquote>
    <pre class="moz-signature" cols="72">-- 
Robert K Coffman Jr.
Info From Data Corp.
3307249000
<a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a></pre>
  </body>
</html>


--===============8734529082098481138==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============8734529082098481138==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline