Hi Dave,

That's a wonderful idea, I almost can't believe it. Thanks for doing this, it's 
much appreciated and I'm sure a lot of shorewall users will be very happy!

Regards,Simon



Am 19. Juli 2026 um 06:55 schrieb "Dave Kempe" <[email protected] 
mailto:[email protected]?to=%22Dave%20Kempe%22%20%3Cdavidkempe%40gmail.com%3E
 >:


> 
> Hi Shorewall people!
> 
> We (sol1.com.au http://sol1.com.au/ ) have been avid Shorewall users and 
> supporters for around 20 years. Wow that is a long time. We have a fleet of 
> managed firewalls that use Shorewall, among other things, to keep many of our 
> customers online and secure. The decline of Shorewall has been "a problem for 
> another day" for a long time now, and I finally decided to do something about 
> it.
> 
> Shorewall-nft is a Python ground up rewrite, specifically to support keeping 
> your shorewall config the same, but it emits pure nftables.
> https://github.com/sol1/shorewall-nft
> 
> We are running it on many of our systems already, in fact, these packets are 
> flowing to you over it right now. It was tested and developed against a 
> primary fleet of 45 different firewall configs, including all the standard 
> configurations and much of the weirder configurations represented.
> 
> Our aim is to replace Shorewall with shorewall-nft, and continue supporting 
> it. Our team has managed custom software and linux firewalls for years, and 
> would be honoured to become custodians of this project. Of course we welcome 
> all input, and this is a true Open Source project.
> 
> We would love some feedback on whether it works for you. You can simply grab 
> the deb or rpm, do  a shorewall check and shorewall migrate, and it will 
> flush your old rules and switch you to nftables.
> 
> As bonus features, we also built shorewall-lsm, a Link Status Monitor with 
> multi-ISP support that appears to be working well and geoip improvements 
> along they way. Any improvements maintain backwards config capability, and 
> simply add to the existing config base.
> See https://github.com/sol1/shorewall-nft/blob/main/docs/failover.md for more 
> info on shorewall-lsm
> 
> Happy to provide support or see FRs via github infrastructure. If the project 
> gets legs at all, we will consider a docs site or other further improvements.
> 
> Thanks
> Dave Kempe
> 

-- 
Simon Matter Tel: +41 61 311 40 70
Glasiweg 8b
CH-6242 Wauwil
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to