Re: Errors testing migration from SW Iptables to SW Nft
Dave Kempe <[email protected]> Fri, 31 Jul 2026 07:22:40 +1000
| Newsgroups | gmane.comp.security.shorewall |
|---|---|
| Message-ID | <CAEc_UVR+LB9yNyFOVTdHGGFJLwuxu5TRURQz8SxNnsO4uf0BKQ@mail.gmail.com> |
--===============6253767397748180349== Content-Type: multipart/alternative; boundary="000000000000cca9d70657daacd3" --000000000000cca9d70657daacd3 Content-Type: text/plain; charset="UTF-8" Hi Matt, Happy to help out. Can you mention your shorewall-nft version? I will investigate your report, - building parity with the vast array of shorewall options is a bunch of work and testing. Also feel free to lodge bugs on github: https://github.com/sol1/shorewall-nft/issues I'm also trying to keep this this authoritative: https://github.com/sol1/shorewall-nft/blob/main/docs/coverage.md but it is hard to cover all the combos available. Dave On Thu, 30 Jul 2026 at 04:26, Matt Darfeuille <[email protected]> wrote: > Hi there, > > I'm "shorewall check"ing my Iptables configs and bumps into the following: > > - SW Iptables supports > https://shorewall.org/configuration_file_basics.htm#INCLUDE but not SW > NFT. > E.G: "?INCLUDE sw-dmz.macaddresses" > > - Sw Iptables supports using > https://shorewall.org/manpages/shorewall-params.html > but not fully SW Nft, more specifically: "file is always processed by > /bin/sh so the full range of shell capabilities may be used.". > E.G: "VM_NET=$(awk -F, '/domain=/ && /vm/{print $2}' $DNSMASQ_CONF)" > > - SW Iptables supports > https://shorewall.org/manpages/shorewall-maclist.html but SW Nft does > not work without a MAC address: > E.G: "ACCEPT $VM_IF - 10.17.240.100,10.17.240.120-10.17.240.124" > > > I'mtesting SW-nft in a VM, built from source. > > -- > Matt Darfeuille > > > _______________________________________________ > Shorewall-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/shorewall-users > --000000000000cca9d70657daacd3 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>Hi Matt,</div><div>Happy to help out. Can you mention= your shorewall-nft version? I will investigate your report, - building par= ity with the vast array of shorewall options is a bunch of work and testing= .</div><div>Also feel free to lodge bugs on github:=C2=A0<a href=3D"https:/= /github.com/sol1/shorewall-nft/issues">https://github.com/sol1/shorewall-nf= t/issues</a></div><div><br></div><div>I'm also trying to keep this this= authoritative:=C2=A0<a href=3D"https://github.com/sol1/shorewall-nft/blob/= main/docs/coverage.md">https://github.com/sol1/shorewall-nft/blob/main/docs= /coverage.md</a> but it is hard to cover all the combos available.</div><di= v><br></div><div>Dave</div></div><br><div class=3D"gmail_quote gmail_quote_= container"><div dir=3D"ltr" class=3D"gmail_attr">On Thu, 30 Jul 2026 at 04:= 26, Matt Darfeuille <<a href=3D"mailto:[email protected]">matdarf@gmail.= com</a>> wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"marg= in:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1e= x">Hi there,<br> <br> I'm "shorewall check"ing my Iptables configs and bumps into t= he following:<br> <br> - SW Iptables supports <br> <a href=3D"https://shorewall.org/configuration_file_basics.htm#INCLUDE" rel= =3D"noreferrer" target=3D"_blank">https://shorewall.org/configuration_file_= basics.htm#INCLUDE</a> but not SW NFT.<br> E.G: "?INCLUDE sw-dmz.macaddresses"<br> <br> - Sw Iptables supports using <br> <a href=3D"https://shorewall.org/manpages/shorewall-params.html" rel=3D"nor= eferrer" target=3D"_blank">https://shorewall.org/manpages/shorewall-params.= html</a><br> but not fully SW Nft, more specifically: "file is always processed by = <br> /bin/sh so the full range of shell capabilities may be used.".<br> E.G: "VM_NET=3D$(awk -F, '/domain=3D/ && /vm/{print $2}= 9; $DNSMASQ_CONF)"<br> <br> - SW Iptables supports <br> <a href=3D"https://shorewall.org/manpages/shorewall-maclist.html" rel=3D"no= referrer" target=3D"_blank">https://shorewall.org/manpages/shorewall-maclis= t.html</a> but SW Nft=C2=A0 does <br> not work without a MAC address:<br> E.G: "ACCEPT $VM_IF - 10.17.240.100,10.17.240.120-10.17.240.124"<= br> <br> <br> I'mtesting SW-nft in a VM, built from source.<br> <br> -- <br> Matt Darfeuille<br> <br> <br> _______________________________________________<br> Shorewall-users mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blank">= [email protected]</a><br> <a href=3D"https://lists.sourceforge.net/lists/listinfo/shorewall-users" re= l=3D"noreferrer" target=3D"_blank">https://lists.sourceforge.net/lists/list= info/shorewall-users</a><br> </blockquote></div> --000000000000cca9d70657daacd3-- --===============6253767397748180349== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============6253767397748180349== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline