Re: shorewall-nft packages repo
Winston Sorfleet <[email protected]> Fri, 24 Jul 2026 13:27:42 -0400
| Newsgroups | gmane.comp.security.shorewall |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format.
--===============3364348626670993507==
Content-Type: multipart/alternative;
boundary="------------lLV7TXLyq1t7oY31ZMnDclxg"
Content-Language: en-CA
This is a multi-part message in MIME format.
--------------lLV7TXLyq1t7oY31ZMnDclxg
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
We are getting closer!
shorewall:
1. Macro forwardUPnP is not supported. (Legacy shorewall:
/usr/share/shorewall/action.forwardUPnP ). I would assume that its
relatives action.allowinUPnP and macro.DropUPnP & macro.A_DropUPnP would
do the same.
(Yeah, I know I shouldn't be using it. I have a bittorrent server behind).
2. tproxy doesn't work. I don't need it to; I just realized it was a
holdover from when squid was a thing.
3. ERROR: unsupported address or interface in an address column: cable
Offending lines:
/etc/shorewall/interfaces:
#ZONE INTERFACE BROADCAST OPTIONS
net cable detect
dhcp,tcpflags,rpfilter,logmartians=1,optional,wait=5,upnp
/etc/shorewall/providers:
#NAME NUMBER MARK DUPLICATE INTERFACE GATEWAY
OPTIONS COPY
rogers 3 3 - cable detect track,primary -
shorewall6:
1.. PYTHONPATH=src python3 -m shorewall_nft check /etc/shorewall6
/tmp/tmpmlobeofy.nft:105:18-54: Error: Could not resolve hostname:
Address family for hostname not supported
ip daddr 2607:fea8:be20:7fc:21c:23ff:fedd:1e22 tcp dport 80
accept comment "rules:40"
This is an expansion of the following rule:
Web(ACCEPT) net eloc:$FLAMEN_IP
("eloc" is the name of the internet zone)
and a params definition:
params:FLAMEN_IP=2607:fea8:be20:7fc:21c:23ff:fedd:1e22
On 2026-07-23 04:17, Dave Kempe wrote:
> Hi Winston,
> thanks for trying it out! Let me know if this release fixes your problems:
>
> https://github.com/sol1/shorewall-nft/releases/tag/v0.2.4
>
> Dave
>
> On Thu, 23 Jul 2026 at 12:05, Winston Sorfleet <[email protected]> wrote:
>
> Also, is this supposed to work in shorewall6?
>
>
>
>
> _______________________________________________
> Shorewall-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/shorewall-users
--------------lLV7TXLyq1t7oY31ZMnDclxg
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<p>We are getting closer!</p>
<p>shorewall:</p>
<p>1. Macro forwardUPnP is not supported. (Legacy shorewall:
/usr/share/shorewall/action.forwardUPnP ). I would assume that
its relatives action.allowinUPnP and macro.DropUPnP &
macro.A_DropUPnP would do the same.</p>
<p>(Yeah, I know I shouldn't be using it. I have a bittorrent
server behind).</p>
<p>2. tproxy doesn't work. I don't need it to; I just realized it
was a holdover from when squid was a thing.</p>
<p>3. ERROR: unsupported address or interface in an address
column: cable<br>
</p>
<p>Offending lines:</p>
<p>/etc/shorewall/interfaces:</p>
<p>#ZONE INTERFACE BROADCAST OPTIONS<br>
net cable detect
dhcp,tcpflags,rpfilter,logmartians=1,optional,wait=5,upnp</p>
<p>/etc/shorewall/providers:</p>
<p>#NAME NUMBER MARK DUPLICATE INTERFACE GATEWAY
OPTIONS COPY<br>
rogers 3 3 - cable detect
track,primary -<br>
<br>
</p>
<p>shorewall6:</p>
<p>1.. PYTHONPATH=src python3 -m shorewall_nft check /etc/shorewall6<br>
<br>
/tmp/tmpmlobeofy.nft:105:18-54: Error: Could not resolve hostname:
Address family for hostname not supported<br>
ip daddr 2607:fea8:be20:7fc:21c:23ff:fedd:1e22 tcp dport
80 accept comment "rules:40"</p>
<p>This is an expansion of the following rule:</p>
<p>Web(ACCEPT) net eloc:$FLAMEN_IP</p>
<p>("eloc" is the name of the internet zone)</p>
<p>and a params definition:
params:FLAMEN_IP=2607:fea8:be20:7fc:21c:23ff:fedd:1e22<br>
<br>
</p>
<p><br>
</p>
<div class="moz-cite-prefix">On 2026-07-23 04:17, Dave Kempe wrote:<br>
</div>
<blockquote type="cite"
cite="mid:CAEc_UVT2Og-C1u0iaEVWXSR5Yt+b+tCUCVetERjCarUEpk=x3Q@mail.gmail.com">
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
<div dir="ltr">
<div>Hi Winston,</div>
<div>thanks for trying it out! Let me know if this release fixes
your problems:</div>
<div><br>
</div>
<div><a
href="https://github.com/sol1/shorewall-nft/releases/tag/v0.2.4"
moz-do-not-send="true" class="moz-txt-link-freetext">https://github.com/sol1/shorewall-nft/releases/tag/v0.2.4</a></div>
<div><br>
</div>
<div>Dave</div>
<br>
<div class="gmail_quote gmail_quote_container">
<div dir="ltr" class="gmail_attr">On Thu, 23 Jul 2026 at
12:05, Winston Sorfleet <<a href="mailto:[email protected]"
moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a>>
wrote:<br>
</div>
<blockquote class="gmail_quote"
style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div>
<p>Also, is this supposed to work in shorewall6?</p>
<br>
</div>
</blockquote>
</div>
</div>
<br>
<fieldset class="moz-mime-attachment-header"></fieldset>
<br>
<fieldset class="moz-mime-attachment-header"></fieldset>
<pre wrap="" class="moz-quote-pre">_______________________________________________
Shorewall-users mailing list
<a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
<a class="moz-txt-link-freetext" href="https://lists.sourceforge.net/lists/listinfo/shorewall-users">https://lists.sourceforge.net/lists/listinfo/shorewall-users</a>
</pre>
</blockquote>
</body>
</html>
--------------lLV7TXLyq1t7oY31ZMnDclxg--
--===============3364348626670993507==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--===============3364348626670993507==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline