Re: shorewall-nft 0.2.0 released
"Robert K Coffman Jr. -Info From Data Corp." <[email protected]> Wed, 22 Jul 2026 08:32:16 -0400
| Newsgroups | gmane.comp.security.shorewall |
|---|---|
| Organization | Info From Data Corporation |
| Message-ID | <[email protected]> |
--===============8734529082098481138==
Content-Language: en-US
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<p>Thank you Dave! I find this project intriguing, to say the
least. </p>
<p>- Robert</p>
<div class="moz-cite-prefix">On 7/21/2026 6:16:26 PM, Dave Kempe
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:CAEc_UVRXH5xLxTJPOqoCcxD6T5rqLS61oLDJxzgD7HLhATQMMg@mail.gmail.com">
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
<div dir="ltr">
<h2>shorewall-nft 0.2.0</h2>
<p>A feature release: run shorewall-nft on machines that cannot
run the compiler, and bootstrap a firewall on a clean box.</p>
<h3>Shorewall Lite</h3>
<p>Run a shorewall-nft firewall on a target with no compiler: a
small embedded system, an OpenWRT router, anything without
Python. A new runtime-only package, <strong>shorewall-nft-lite</strong>,
depends only on nftables and iproute2.</p>
<ul>
<li>Compile on a full system with <code>shorewall compile -e</code>,
deploy with <strong><code>shorewall load SYSTEM</code></strong>
over ssh, and run it on the target with <strong><code>shorewall-lite</code></strong>
(<code>start</code>, <code>stop</code>, <code>reload</code>,
<code>restart</code>, <code>status</code>, <code>check</code>).</li>
<li><strong><code>shorecap</code></strong> on the target
captures its capabilities so the admin can compile a ruleset
that matches that kernel with <code>--caps</code>.</li>
<li>Packages for Debian, Ubuntu, Fedora, RHEL, Arch and
OpenWRT.</li>
<li>See <a
href="https://github.com/sol1/shorewall-nft/blob/main/docs/lite.md"
moz-do-not-send="true">docs/lite.md</a> for running it and
<a
href="https://github.com/sol1/shorewall-nft/blob/main/docs/distros.md"
moz-do-not-send="true">docs/distros.md</a> for the
per-distro layout.</li>
</ul>
<h3>shorewall init</h3>
<p>Bootstrap a clean install, the counterpart to <code>migrate</code>.</p>
<ul>
<li><strong><code>shorewall init</code></strong> with no
arguments runs an interactive wizard: it detects your
interfaces, guesses the uplink from the default route, and
writes a working starting point (standalone, gateway or
three-zone).</li>
<li>Or non-interactively: <code>shorewall init --gateway
--net eth0 --loc eth1</code>.</li>
<li>It keeps SSH to the firewall open so you cannot lock
yourself out, never starts the firewall on its own, and
refuses to overwrite an existing configuration.</li>
</ul>
<br>
</div>
<br>
<fieldset class="moz-mime-attachment-header"></fieldset>
<br>
<fieldset class="moz-mime-attachment-header"></fieldset>
<pre wrap="" class="moz-quote-pre">_______________________________________________
Shorewall-users mailing list
<a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
<a class="moz-txt-link-freetext" href="https://lists.sourceforge.net/lists/listinfo/shorewall-users">https://lists.sourceforge.net/lists/listinfo/shorewall-users</a>
</pre>
</blockquote>
<pre class="moz-signature" cols="72">--
Robert K Coffman Jr.
Info From Data Corp.
3307249000
<a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a></pre>
</body>
</html>
--===============8734529082098481138==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--===============8734529082098481138==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline