I do this as well, but because I have a secondary ISP that goes up and down a lot, I put a

post-up shorewall enable ppp2; shorewall restart

in my /etc/network/interfaces (assuming you use one of those... if you are using e.g. netcfg I am sure there are places you can hook an explicit call in.  There is absolutely no harm in calling shorewall several times, as all it does is configure your iptables.

With systemd, make sure that shorewall.service contains

Wants=network-online.target
After=network-online.target

Hmmn... one thing you should make sure is that your network interface actually is *up* before you call shorewall.  It *can* be configured to figure this out itself, but that involves a more complex situation with optional in the /etc/shorewall[6]/interfaces file, and you would still want something to trigger shorewall enable.


On 2026-01-13 09:52, rcortes--- via Shorewall-users wrote:

Hi Robert,


I'm using systemcl


systemctl enable shorewall after install package.


Thx.


El 2026-01-13 10:30, Robert K Coffman Jr. -Info From Data Corp. escribió:

How are you starting Shorewall after a reboot?


On 1/13/2026 5:59:25 AM, rcortes--- via Shorewall-users wrote:
Hi Simon,

i use shorewall from shorewall site reference, in this case 5.1.12 from https://shorewall.org/pub/shorewall/5.1/shorewall-5.1.12/ <https://shorewall.org/pub/shorewall/5.1/shorewall-5.1.12/> and 5.2.8 from https://www.invoca.ch/pub/packages/shorewall/RPMS/ils-7/noarch/ <https://www.invoca.ch/pub/packages/shorewall/RPMS/ils-7/noarch/>

5.1.12 or 5.1.10 start but dont work, need apply clear/start to work.
5.2.8-12 start but dont work nat/dnat/proxyarp

Thx

El 2026-01-13 04:56, Simon Matter escribió:
Hi,

Hello everyone!

Somebody know why or how to fix shorewall for not need clear and start after reboot?  i have EL7 and shorewall 5.1.12, previously working with 5.1.10 and try with 5.2.8-12 but shorewall start but nat/dnat/proxyarp dont work.

Seems that your shorewall start is not working properly. Are you using a shorewall package from epel? If so you could check the changelog to see
who has packaged it and ask directly?

Regards,
Simon


_______________________________________________
Shorewall-users mailing list
[email protected] <mailto:[email protected]> https://lists.sourceforge.net/lists/listinfo/shorewall-users <https://lists.sourceforge.net/lists/listinfo/shorewall-users>
--
Robert K Coffman Jr.
Info From Data Corp.
3307249000
[email protected] <mailto:[email protected]>

_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users


_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to