Re: shorewall-nft packages repo
Winston Sorfleet <[email protected]> Wed, 22 Jul 2026 18:49:44 -0400
| Newsgroups | gmane.comp.security.shorewall |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --===============3416859295511808426== Content-Type: multipart/alternative; boundary="------------pmSzftaecZ1bo7SWnuy84Hqm" Content-Language: en-US This is a multi-part message in MIME format. --------------pmSzftaecZ1bo7SWnuy84Hqm Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit Doing a |PYTHONPATH=src python3 -m shorewall_nft check /etc/shorewall shorewall-nft: warning: interfaces:12: interface option 'rpfilter' is accepted but not yet enforced; anti-spoofing is NOT applied to this interface. shorewall-nft: warning: interfaces:15: interface option 'rpfilter' is accepted but not yet enforced; anti-spoofing is NOT applied to this interface. shorewall-nft: warning: interfaces:16: interface option 'rpfilter' is accepted but not yet enforced; anti-spoofing is NOT applied to this interface. ERROR: /etc/shorewall/rules:17: unknown zone all Suggests that it does not recognize the old shorewall macro "all"? | On 2026-07-22 2:51 a.m., Dave Kempe wrote: > The process below will take care of that for you - they conflict, so > it will uninstall the shorewall package and leave the config intact > for you. > The two packages can't be installed at once - they both provide the > 'shorewall' binary (script) > > Dave > > On Wed, 22 Jul 2026 at 15:45, Witold Tosta <[email protected]> wrote: > > Hi Dave, > > Do I need to uninstall the old shorewall and shorewall6 packages > first, leaving only the directories with the configuration files? > Can the old shorewall packages be installed? I'm using Debian Trixie. > > Best regards, > > Witold Tosta > > wt., 21 lip 2026, 08:45 użytkownik Dave Kempe > <[email protected]> napisał: > > Hey everyone, > As a way to get started quickly, I have added shorewall-nft to > the Sol1 packages repo. > You can set it up here: https://packages.sol1.net/ > and then simply: > apt install shorewall-nft > shorewall check > shorewall migrate > And you are done. > > If encounter any problems with check or migrate, you can back > out and go back to shorewall, (apt install shorewall etc) > Note that shorewall-nft conflicts with shorewall and will > uninstall it, with the migrate command actually flushing > iptables rules. > > I haven't got any packages repo for rpm based distros, as we > are debian/ubuntu from way back, but I'm sure a quick rpm > command will work the same sorta way. > > Dave > > _______________________________________________ > Shorewall-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/shorewall-users > > _______________________________________________ > Shorewall-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/shorewall-users > > > > _______________________________________________ > Shorewall-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/shorewall-users --------------pmSzftaecZ1bo7SWnuy84Hqm Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 8bit <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> </head> <body> <p>Doing a </p> <pre class="notranslate"><code>PYTHONPATH=src python3 -m shorewall_nft check /etc/shorewall shorewall-nft: warning: interfaces:12: interface option 'rpfilter' is accepted but not yet enforced; anti-spoofing is NOT applied to this interface. shorewall-nft: warning: interfaces:15: interface option 'rpfilter' is accepted but not yet enforced; anti-spoofing is NOT applied to this interface. shorewall-nft: warning: interfaces:16: interface option 'rpfilter' is accepted but not yet enforced; anti-spoofing is NOT applied to this interface. ERROR: /etc/shorewall/rules:17: unknown zone all Suggests that it does not recognize the old shorewall macro "all"? </code></pre> <div class="moz-cite-prefix">On 2026-07-22 2:51 a.m., Dave Kempe wrote:<br> </div> <blockquote type="cite" cite="mid:CAEc_UVSaEXCRwBCugzsa+p5oWtuJ_cGKwSKW-3Dc0WzVTJRLkQ@mail.gmail.com"> <meta http-equiv="content-type" content="text/html; charset=UTF-8"> <div dir="ltr"> <div>The process below will take care of that for you - they conflict, so it will uninstall the shorewall package and leave the config intact for you.</div> <div>The two packages can't be installed at once - they both provide the 'shorewall' binary (script)</div> <div><br> </div> <div>Dave</div> <br> <div class="gmail_quote gmail_quote_container"> <div dir="ltr" class="gmail_attr">On Wed, 22 Jul 2026 at 15:45, Witold Tosta <<a href="mailto:[email protected]" moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a>> wrote:<br> </div> <blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"> <div dir="auto"> <div>Hi Dave,</div> <div dir="auto"><br> </div> <div dir="auto">Do I need to uninstall the old shorewall and shorewall6 packages first, leaving only the directories with the configuration files? Can the old shorewall packages be installed? I'm using Debian Trixie.</div> <div dir="auto"><br> </div> <div dir="auto">Best regards,</div> <div><br> </div> <div> <div dir="ltr"> <div>Witold Tosta</div> </div> </div> </div> <br> <div class="gmail_quote"> <div dir="ltr" class="gmail_attr">wt., 21 lip 2026, 08:45 użytkownik Dave Kempe <<a href="mailto:[email protected]" target="_blank" moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a>> napisał:<br> </div> <blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"> <div dir="ltr"> <div>Hey everyone,</div> <div>As a way to get started quickly, I have added shorewall-nft to the Sol1 packages repo.</div> <div>You can set it up here: <a href="https://packages.sol1.net/" rel="noreferrer" target="_blank" moz-do-not-send="true" class="moz-txt-link-freetext">https://packages.sol1.net/</a></div> <div>and then simply:</div> <div>apt install shorewall-nft</div> <div>shorewall check</div> <div>shorewall migrate</div> <div>And you are done.</div> <div><br> </div> <div>If encounter any problems with check or migrate, you can back out and go back to shorewall, (apt install shorewall etc)</div> <div>Note that shorewall-nft conflicts with shorewall and will uninstall it, with the migrate command actually flushing iptables rules.</div> <div><br> </div> <div>I haven't got any packages repo for rpm based distros, as we are debian/ubuntu from way back, but I'm sure a quick rpm command will work the same sorta way.</div> <div><br> </div> <div>Dave</div> <div><br> </div> </div> _______________________________________________<br> Shorewall-users mailing list<br> <a href="mailto:[email protected]" rel="noreferrer" target="_blank" moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a><br> <a href="https://lists.sourceforge.net/lists/listinfo/shorewall-users" rel="noreferrer noreferrer" target="_blank" moz-do-not-send="true" class="moz-txt-link-freetext">https://lists.sourceforge.net/lists/listinfo/shorewall-users</a><br> </blockquote> </div> _______________________________________________<br> Shorewall-users mailing list<br> <a href="mailto:[email protected]" target="_blank" moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a><br> <a href="https://lists.sourceforge.net/lists/listinfo/shorewall-users" rel="noreferrer" target="_blank" moz-do-not-send="true" class="moz-txt-link-freetext">https://lists.sourceforge.net/lists/listinfo/shorewall-users</a><br> </blockquote> </div> </div> <br> <fieldset class="moz-mime-attachment-header"></fieldset> <br> <fieldset class="moz-mime-attachment-header"></fieldset> <pre wrap="" class="moz-quote-pre">_______________________________________________ Shorewall-users mailing list <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a> <a class="moz-txt-link-freetext" href="https://lists.sourceforge.net/lists/listinfo/shorewall-users">https://lists.sourceforge.net/lists/listinfo/shorewall-users</a> </pre> </blockquote> </body> </html> --------------pmSzftaecZ1bo7SWnuy84Hqm-- --===============3416859295511808426== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============3416859295511808426== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline