Re: Introducing shorewall-nft
Mark Dixon <[email protected]> Wed, 22 Jul 2026 16:57:57 +0100 (BST)
| Newsgroups | gmane.comp.security.shorewall |
|---|---|
| Message-ID | <[email protected]> |
All I can say is: Thank you Dave Thank you Sam And mostly, thank you Tom. I'm very happy to learn of the effort to keep Shorewall alive - looking forward to giving shorewall-nft a try! Best wishes, Mark On Tue, 21 Jul 2026, Sam via Shorewall-users wrote: > [EXTERNAL EMAIL] > > On 7/18/26 11:55 PM, Dave Kempe wrote: >> Hi Shorewall people! >> >> We (sol1.com.au >> <http://sol1.com.au/>) >> have been avid Shorewall users and >> supporters for around 20 years. Wow that is a long time. We have a fleet >> of managed firewalls that use Shorewall, among other things, to keep >> many of our customers online and secure. The decline of Shorewall has >> been "a problem for another day" for a long time now, and I finally >> decided to do something about it. >> > > > Dave, perhaps you have noticed but I also started a shorewall-nf project: > https://github.com/smith153/ShorewallNF > With docs at: > https://smith153.github.io/ShorewallNF/ > > I had planned on announcing this to the list last month, but never got > around to it. As you can see, the code is all AI agent driven. I owe > most of my networking knowledge to the wonderful docs from the original > shorewall. That said, I quickly noticed I was in over my head in this > project. For one, outside of my simple home network setup, I don't > really have any other good or easy way to test more advanced set ups. > The current test suite I have for the project does run in a VM with full > root permissions and is free to create various network topologies at > will. The tests say everything is "working" but I have not tried running > the code outside of a VM. If you are truly running shorewall on customer > hardware, you are in a much better place to test the end product than I. > I am perfectly happy stopping development on my project and letting you > have the full lead as I haven't really put too much of my own time into > mine. > Where I did spend quite a bit of time though is the overall > architecture. So for your own consideration: > > I too went with python. I did not want to move away from Perl as I know > 10 years from now what ever I wrote in Perl would still be runnable. > Can't say the same with python but going with python would make it a > much more easy sell and ultimately that wins. > > The next decision I faced was what to do about ipv4 and ipv6. Should we > treat the two as purely separate like shorewall? Since nftables handles > both protocols, it seemed the right way to go was with one config and > one rules file which could configure both stacks. Not sure if that is > the direction you went, might be worth community feedback. > > Next up was where to handle TC and overall network topology config. I > decided to offload that to systemd, which worked best for my current > setups since I'd already been fighting conflicts between Shorewall and > systemd anyway. Not sure if that's the right call for a dedicated > firewall hardware appliance, though. > > That's all I can think of at the moment. Will post more if they pop up. > Best of luck! > > Regards, > Samuel Smith > > > > _______________________________________________ > Shorewall-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/shorewall-users >