Re: Errors testing migration from SW Iptables to SW Nft

Dave Kempe <[email protected]> Fri, 31 Jul 2026 07:22:40 +1000
Newsgroups gmane.comp.security.shorewall
Message-ID <CAEc_UVR+LB9yNyFOVTdHGGFJLwuxu5TRURQz8SxNnsO4uf0BKQ@mail.gmail.com>
--===============6253767397748180349==
Content-Type: multipart/alternative; boundary="000000000000cca9d70657daacd3"

--000000000000cca9d70657daacd3
Content-Type: text/plain; charset="UTF-8"

Hi Matt,
Happy to help out. Can you mention your shorewall-nft version? I will
investigate your report, - building parity with the vast array of shorewall
options is a bunch of work and testing.
Also feel free to lodge bugs on github:
https://github.com/sol1/shorewall-nft/issues

I'm also trying to keep this this authoritative:
https://github.com/sol1/shorewall-nft/blob/main/docs/coverage.md but it is
hard to cover all the combos available.

Dave

On Thu, 30 Jul 2026 at 04:26, Matt Darfeuille <[email protected]> wrote:

> Hi there,
>
> I'm "shorewall check"ing my Iptables configs and bumps into the following:
>
> - SW Iptables supports
> https://shorewall.org/configuration_file_basics.htm#INCLUDE but not SW
> NFT.
> E.G: "?INCLUDE sw-dmz.macaddresses"
>
> - Sw Iptables supports using
> https://shorewall.org/manpages/shorewall-params.html
> but not fully SW Nft, more specifically: "file is always processed by
> /bin/sh so the full range of shell capabilities may be used.".
> E.G: "VM_NET=$(awk -F, '/domain=/ && /vm/{print $2}' $DNSMASQ_CONF)"
>
> - SW Iptables supports
> https://shorewall.org/manpages/shorewall-maclist.html but SW Nft  does
> not work without a MAC address:
> E.G: "ACCEPT $VM_IF - 10.17.240.100,10.17.240.120-10.17.240.124"
>
>
> I'mtesting SW-nft in a VM, built from source.
>
> --
> Matt Darfeuille
>
>
> _______________________________________________
> Shorewall-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/shorewall-users
>

--000000000000cca9d70657daacd3
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Hi Matt,</div><div>Happy to help out. Can you mention=
 your shorewall-nft version? I will investigate your report, - building par=
ity with the vast array of shorewall options is a bunch of work and testing=
.</div><div>Also feel free to lodge bugs on github:=C2=A0<a href=3D"https:/=
/github.com/sol1/shorewall-nft/issues">https://github.com/sol1/shorewall-nf=
t/issues</a></div><div><br></div><div>I&#39;m also trying to keep this this=
 authoritative:=C2=A0<a href=3D"https://github.com/sol1/shorewall-nft/blob/=
main/docs/coverage.md">https://github.com/sol1/shorewall-nft/blob/main/docs=
/coverage.md</a> but it is hard to cover all the combos available.</div><di=
v><br></div><div>Dave</div></div><br><div class=3D"gmail_quote gmail_quote_=
container"><div dir=3D"ltr" class=3D"gmail_attr">On Thu, 30 Jul 2026 at 04:=
26, Matt Darfeuille &lt;<a href=3D"mailto:[email protected]">matdarf@gmail.=
com</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"marg=
in:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1e=
x">Hi there,<br>
<br>
I&#39;m &quot;shorewall check&quot;ing my Iptables configs and bumps into t=
he following:<br>
<br>
- SW Iptables supports <br>
<a href=3D"https://shorewall.org/configuration_file_basics.htm#INCLUDE" rel=
=3D"noreferrer" target=3D"_blank">https://shorewall.org/configuration_file_=
basics.htm#INCLUDE</a> but not SW NFT.<br>
E.G: &quot;?INCLUDE sw-dmz.macaddresses&quot;<br>
<br>
- Sw Iptables supports using <br>
<a href=3D"https://shorewall.org/manpages/shorewall-params.html" rel=3D"nor=
eferrer" target=3D"_blank">https://shorewall.org/manpages/shorewall-params.=
html</a><br>
but not fully SW Nft, more specifically: &quot;file is always processed by =
<br>
/bin/sh so the full range of shell capabilities may be used.&quot;.<br>
E.G: &quot;VM_NET=3D$(awk -F, &#39;/domain=3D/ &amp;&amp; /vm/{print $2}&#3=
9; $DNSMASQ_CONF)&quot;<br>
<br>
- SW Iptables supports <br>
<a href=3D"https://shorewall.org/manpages/shorewall-maclist.html" rel=3D"no=
referrer" target=3D"_blank">https://shorewall.org/manpages/shorewall-maclis=
t.html</a> but SW Nft=C2=A0 does <br>
not work without a MAC address:<br>
E.G: &quot;ACCEPT $VM_IF - 10.17.240.100,10.17.240.120-10.17.240.124&quot;<=
br>
<br>
<br>
I&#39;mtesting SW-nft in a VM, built from source.<br>
<br>
-- <br>
Matt Darfeuille<br>
<br>
<br>
_______________________________________________<br>
Shorewall-users mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank">=
[email protected]</a><br>
<a href=3D"https://lists.sourceforge.net/lists/listinfo/shorewall-users" re=
l=3D"noreferrer" target=3D"_blank">https://lists.sourceforge.net/lists/list=
info/shorewall-users</a><br>
</blockquote></div>

--000000000000cca9d70657daacd3--


--===============6253767397748180349==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============6253767397748180349==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline