On 7/19/26 00:55, Dave Kempe wrote:
Hi Shorewall people!
We (sol1.com.au <http://sol1.com.au>) have been avid Shorewall users and
supporters for around 20 years. Wow that is a long time. We have a fleet
of managed firewalls that use Shorewall, among other things, to keep
many of our customers online and secure. The decline of Shorewall has
been "a problem for another day" for a long time now, and I finally
decided to do something about it.
I salute you!!! Shorewall is a first-class tool that deserves to continue.
iptables, ipchains, nftables are all examples of utterly horrible
software design: An important tool whose syntax is not merely not
user-friendly, but actively user-hostile. It is the *operating
system*'s job to understand that internal firewall syntax, not the
user's. The user should be able to just *describe what they want to
happen* and then have that compiled into roles the OS understands, and
that's what Shorewall does, and does it very well.
Before Shorewall, my firewall was an OpenBSD P4 box and pf, and as clear
and easy as pf syntax is, I never once managed to get IRC DCC to work
properly through NAT. With Shorewall, I tell it DCC(enable) and it Just
Freaking Works.
--
Phil Stracchino
Fenian House Publishing
[email protected]
[email protected]
Landline: +1.603.293.8485
Mobile: +1.603.998.6958
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users