Something simple and basic for Linux firewall configuration nobody else is 
willing to do. You don't build a firewall to keep the friendlies out, do you?

On July 19, 2026 8:56:49 PM AKDT, Winston Sorfleet <[email protected]> wrote:
>I echo this.  I got into Shorewall because I wanted an easy way to stay sane 
>with multi-ISP (where I live, the fast provider didn't give static IP nor 
>IPv6; DSL provided both but was hardly fast).  Shorewall[6] has been a 
>lifesaver and I'm eternally grateful to Tom, so if Dave is willing to take up 
>the banner and give back to Shorewall, thank you!
>
>On 2026-07-19 4:24 a.m., [email protected] wrote:
>> Well done David,
>> 
>> What a fantastic initiative to preserve the outstanding firewall abstraction 
>> provided by Shorewall, together with the years of development effort to 
>> support that abstraction.
>> 
>> Moving to Python is a great way forward.
>> 
>> I’ve been dreading migrating from Shorewall.  You’ve given me hope.
>> 
>> Cheers,
>> 
>> Bruce
>> 
>> 
>>> On 19 Jul 2026, at 14:56, Dave Kempe <[email protected]> wrote:
>>> 
>>> 
>>> Hi Shorewall people!
>>> 
>>> We (sol1.com.au <http://sol1.com.au>) have been avid Shorewall users and 
>>> supporters for around 20 years. Wow that is a long time. We have a fleet of 
>>> managed firewalls that use Shorewall, among other things, to keep many of 
>>> our customers online and secure. The decline of Shorewall has been "a 
>>> problem for another day" for a long time now, and I finally decided to do 
>>> something about it.
>>> 
>>> Shorewall-nft is a Python ground up rewrite, specifically to support 
>>> keeping your shorewall config the same, but it emits pure nftables.
>>> 
>>> https://github.com/sol1/shorewall-nft
>>> 
>>> We are running it on many of our systems already, in fact, these packets 
>>> are flowing to you over it right now. It was tested and developed against a 
>>> primary fleet of 45 different firewall configs, including all the standard 
>>> configurations and much of the weirder configurations represented.
>>> 
>>> Our aim is to replace Shorewall with shorewall-nft, and continue supporting 
>>> it. Our team has managed custom software and linux firewalls for years, and 
>>> would be honoured to become custodians of this project. Of course we 
>>> welcome all input, and this is a true Open Source project.
>>> 
>>> We would love some feedback on whether it works for you. You can simply 
>>> grab the deb or rpm, do  a shorewall check and shorewall migrate, and it 
>>> will flush your old rules and switch you to nftables.
>>> 
>>> As bonus features, we also built shorewall-lsm, a Link Status Monitor with 
>>> multi-ISP support that appears to be working well and geoip improvements 
>>> along they way. Any improvements maintain backwards config capability, and 
>>> simply add to the existing config base.
>>> See https://github.com/sol1/shorewall-nft/blob/main/docs/failover.md for 
>>> more info on shorewall-lsm
>>> 
>>> Happy to provide support or see FRs via github infrastructure. If the 
>>> project gets legs at all, we will consider a docs site or other further 
>>> improvements.
>>> 
>>> Thanks
>>> Dave Kempe
>>> 
>>> 
>>> _______________________________________________
>>> Shorewall-users mailing list
>>> [email protected]
>>> https://lists.sourceforge.net/lists/listinfo/shorewall-users
>> 
>> 
>> _______________________________________________
>> Shorewall-users mailing list
>> [email protected]
>> https://lists.sourceforge.net/lists/listinfo/shorewall-users
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to