Re: Errors testing migration from SW Iptables to SW Nft
Dave Kempe <[email protected]> Fri, 31 Jul 2026 11:30:35 +1000
| Newsgroups | gmane.comp.security.shorewall |
|---|---|
| Message-ID | <CAEc_UVTY_Jo1Rci_dbi_JTN42uHVwUPi25PTtdj-S8ECp6o1kg@mail.gmail.com> |
--===============4461185698694098373== Content-Type: multipart/alternative; boundary="0000000000006a6b5c0657de23c5" --0000000000006a6b5c0657de23c5 Content-Type: text/plain; charset="UTF-8" Matt, the latest release 0.2.8 should address your issues: https://github.com/sol1/shorewall-nft/releases/tag/v0.2.8 Dave On Thu, 30 Jul 2026 at 04:26, Matt Darfeuille <[email protected]> wrote: > Hi there, > > I'm "shorewall check"ing my Iptables configs and bumps into the following: > > - SW Iptables supports > https://shorewall.org/configuration_file_basics.htm#INCLUDE but not SW > NFT. > E.G: "?INCLUDE sw-dmz.macaddresses" > > - Sw Iptables supports using > https://shorewall.org/manpages/shorewall-params.html > but not fully SW Nft, more specifically: "file is always processed by > /bin/sh so the full range of shell capabilities may be used.". > E.G: "VM_NET=$(awk -F, '/domain=/ && /vm/{print $2}' $DNSMASQ_CONF)" > > - SW Iptables supports > https://shorewall.org/manpages/shorewall-maclist.html but SW Nft does > not work without a MAC address: > E.G: "ACCEPT $VM_IF - 10.17.240.100,10.17.240.120-10.17.240.124" > > > I'mtesting SW-nft in a VM, built from source. > > -- > Matt Darfeuille > > > _______________________________________________ > Shorewall-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/shorewall-users > --0000000000006a6b5c0657de23c5 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>Matt, the latest release 0.2.8 should=C2=A0address yo= ur issues:=C2=A0<a href=3D"https://github.com/sol1/shorewall-nft/releases/t= ag/v0.2.8">https://github.com/sol1/shorewall-nft/releases/tag/v0.2.8</a></d= iv><div><br></div><div>Dave</div></div><br><div class=3D"gmail_quote gmail_= quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Thu, 30 Jul 2026 = at 04:26, Matt Darfeuille <<a href=3D"mailto:[email protected]">matdarf@= gmail.com</a>> wrote:<br></div><blockquote class=3D"gmail_quote" style= =3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding= -left:1ex">Hi there,<br> <br> I'm "shorewall check"ing my Iptables configs and bumps into t= he following:<br> <br> - SW Iptables supports <br> <a href=3D"https://shorewall.org/configuration_file_basics.htm#INCLUDE" rel= =3D"noreferrer" target=3D"_blank">https://shorewall.org/configuration_file_= basics.htm#INCLUDE</a> but not SW NFT.<br> E.G: "?INCLUDE sw-dmz.macaddresses"<br> <br> - Sw Iptables supports using <br> <a href=3D"https://shorewall.org/manpages/shorewall-params.html" rel=3D"nor= eferrer" target=3D"_blank">https://shorewall.org/manpages/shorewall-params.= html</a><br> but not fully SW Nft, more specifically: "file is always processed by = <br> /bin/sh so the full range of shell capabilities may be used.".<br> E.G: "VM_NET=3D$(awk -F, '/domain=3D/ && /vm/{print $2}= 9; $DNSMASQ_CONF)"<br> <br> - SW Iptables supports <br> <a href=3D"https://shorewall.org/manpages/shorewall-maclist.html" rel=3D"no= referrer" target=3D"_blank">https://shorewall.org/manpages/shorewall-maclis= t.html</a> but SW Nft=C2=A0 does <br> not work without a MAC address:<br> E.G: "ACCEPT $VM_IF - 10.17.240.100,10.17.240.120-10.17.240.124"<= br> <br> <br> I'mtesting SW-nft in a VM, built from source.<br> <br> -- <br> Matt Darfeuille<br> <br> <br> _______________________________________________<br> Shorewall-users mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blank">= [email protected]</a><br> <a href=3D"https://lists.sourceforge.net/lists/listinfo/shorewall-users" re= l=3D"noreferrer" target=3D"_blank">https://lists.sourceforge.net/lists/list= info/shorewall-users</a><br> </blockquote></div> --0000000000006a6b5c0657de23c5-- --===============4461185698694098373== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============4461185698694098373== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline