Re: shorewall-nft packages repo

Winston Sorfleet <[email protected]> Fri, 24 Jul 2026 13:27:42 -0400
Newsgroups gmane.comp.security.shorewall
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============3364348626670993507==
Content-Type: multipart/alternative;
 boundary="------------lLV7TXLyq1t7oY31ZMnDclxg"
Content-Language: en-CA

This is a multi-part message in MIME format.
--------------lLV7TXLyq1t7oY31ZMnDclxg
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

We are getting closer!

shorewall:

1. Macro forwardUPnP is not supported.  (Legacy shorewall: 
/usr/share/shorewall/action.forwardUPnP ).  I would assume that its 
relatives action.allowinUPnP and macro.DropUPnP & macro.A_DropUPnP would 
do the same.

(Yeah, I know I shouldn't be using it.  I have a bittorrent server behind).

2. tproxy doesn't work.  I don't need it to; I just realized it was a 
holdover from when squid was a thing.

3.    ERROR: unsupported address or interface in an address column: cable

Offending lines:

/etc/shorewall/interfaces:

#ZONE   INTERFACE       BROADCAST       OPTIONS
net    cable        detect 
dhcp,tcpflags,rpfilter,logmartians=1,optional,wait=5,upnp

/etc/shorewall/providers:

#NAME   NUMBER  MARK    DUPLICATE       INTERFACE       GATEWAY       
  OPTIONS         COPY
rogers    3    3    -        cable        detect track,primary      -

shorewall6:

1.. PYTHONPATH=src python3 -m shorewall_nft check /etc/shorewall6

/tmp/tmpmlobeofy.nft:105:18-54: Error: Could not resolve hostname: 
Address family for hostname not supported
         ip daddr 2607:fea8:be20:7fc:21c:23ff:fedd:1e22 tcp dport 80 
accept comment "rules:40"

This is an expansion of the following rule:

Web(ACCEPT)     net             eloc:$FLAMEN_IP

("eloc" is the name of the internet zone)

and a params definition: 
params:FLAMEN_IP=2607:fea8:be20:7fc:21c:23ff:fedd:1e22


On 2026-07-23 04:17, Dave Kempe wrote:
> Hi Winston,
> thanks for trying it out! Let me know if this release fixes your problems:
>
> https://github.com/sol1/shorewall-nft/releases/tag/v0.2.4
>
> Dave
>
> On Thu, 23 Jul 2026 at 12:05, Winston Sorfleet <[email protected]> wrote:
>
>     Also, is this supposed to work in shorewall6?
>
>
>
>
> _______________________________________________
> Shorewall-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/shorewall-users
--------------lLV7TXLyq1t7oY31ZMnDclxg
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>We are getting closer!</p>
    <p>shorewall:</p>
    <p>1. Macro forwardUPnP is not supported.  (Legacy shorewall:
      /usr/share/shorewall/action.forwardUPnP ).  I would assume that
      its relatives action.allowinUPnP and macro.DropUPnP &amp;
      macro.A_DropUPnP would do the same.</p>
    <p>(Yeah, I know I shouldn't be using it.  I have a bittorrent
      server behind).</p>
    <p>2. tproxy doesn't work.  I don't need it to; I just realized it
      was a holdover from when squid was a thing.</p>
    <p>3.    ERROR: unsupported address or interface in an address
      column: cable<br>
    </p>
    <p>Offending lines:</p>
    <p>/etc/shorewall/interfaces:</p>
    <p>#ZONE   INTERFACE       BROADCAST       OPTIONS<br>
      net    cable        detect       
      dhcp,tcpflags,rpfilter,logmartians=1,optional,wait=5,upnp</p>
    <p>/etc/shorewall/providers:</p>
    <p>#NAME   NUMBER  MARK    DUPLICATE       INTERFACE       GATEWAY 
             OPTIONS         COPY<br>
      rogers    3    3    -        cable        detect       
      track,primary      -<br>
      <br>
    </p>
    <p>shorewall6:</p>
    <p>1.. PYTHONPATH=src python3 -m shorewall_nft check /etc/shorewall6<br>
      <br>
      /tmp/tmpmlobeofy.nft:105:18-54: Error: Could not resolve hostname:
      Address family for hostname not supported<br>
              ip daddr 2607:fea8:be20:7fc:21c:23ff:fedd:1e22 tcp dport
      80 accept comment "rules:40"</p>
    <p>This is an expansion of the following rule:</p>
    <p>Web(ACCEPT)     net             eloc:$FLAMEN_IP</p>
    <p>("eloc" is the name of the internet zone)</p>
    <p>and a params definition:
      params:FLAMEN_IP=2607:fea8:be20:7fc:21c:23ff:fedd:1e22<br>
      <br>
    </p>
    <p><br>
    </p>
    <div class="moz-cite-prefix">On 2026-07-23 04:17, Dave Kempe wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:CAEc_UVT2Og-C1u0iaEVWXSR5Yt+b+tCUCVetERjCarUEpk=x3Q@mail.gmail.com">
      <meta http-equiv="content-type" content="text/html; charset=UTF-8">
      <div dir="ltr">
        <div>Hi Winston,</div>
        <div>thanks for trying it out! Let me know if this release fixes
          your problems:</div>
        <div><br>
        </div>
        <div><a
href="https://github.com/sol1/shorewall-nft/releases/tag/v0.2.4"
            moz-do-not-send="true" class="moz-txt-link-freetext">https://github.com/sol1/shorewall-nft/releases/tag/v0.2.4</a></div>
        <div><br>
        </div>
        <div>Dave</div>
        <br>
        <div class="gmail_quote gmail_quote_container">
          <div dir="ltr" class="gmail_attr">On Thu, 23 Jul 2026 at
            12:05, Winston Sorfleet &lt;<a href="mailto:[email protected]"
              moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a>&gt;
            wrote:<br>
          </div>
          <blockquote class="gmail_quote"
style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
            <div>
              <p>Also, is this supposed to work in shorewall6?</p>
              <br>
            </div>
          </blockquote>
        </div>
      </div>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
      <pre wrap="" class="moz-quote-pre">_______________________________________________
Shorewall-users mailing list
<a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
<a class="moz-txt-link-freetext" href="https://lists.sourceforge.net/lists/listinfo/shorewall-users">https://lists.sourceforge.net/lists/listinfo/shorewall-users</a>
</pre>
    </blockquote>
  </body>
</html>

--------------lLV7TXLyq1t7oY31ZMnDclxg--


--===============3364348626670993507==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============3364348626670993507==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline