On 7/18/26 11:55 PM, Dave Kempe wrote:
Hi Shorewall people!
We (sol1.com.au <http://sol1.com.au>) have been avid Shorewall users and
supporters for around 20 years. Wow that is a long time. We have a fleet
of managed firewalls that use Shorewall, among other things, to keep
many of our customers online and secure. The decline of Shorewall has
been "a problem for another day" for a long time now, and I finally
decided to do something about it.
Dave, perhaps you have noticed but I also started a shorewall-nf project:
https://github.com/smith153/ShorewallNF
With docs at:
https://smith153.github.io/ShorewallNF/
I had planned on announcing this to the list last month, but never got
around to it. As you can see, the code is all AI agent driven. I owe
most of my networking knowledge to the wonderful docs from the original
shorewall. That said, I quickly noticed I was in over my head in this
project. For one, outside of my simple home network setup, I don't
really have any other good or easy way to test more advanced set ups.
The current test suite I have for the project does run in a VM with full
root permissions and is free to create various network topologies at
will. The tests say everything is "working" but I have not tried running
the code outside of a VM. If you are truly running shorewall on customer
hardware, you are in a much better place to test the end product than I.
I am perfectly happy stopping development on my project and letting you
have the full lead as I haven't really put too much of my own time into
mine.
Where I did spend quite a bit of time though is the overall
architecture. So for your own consideration:
I too went with python. I did not want to move away from Perl as I know
10 years from now what ever I wrote in Perl would still be runnable.
Can't say the same with python but going with python would make it a
much more easy sell and ultimately that wins.
The next decision I faced was what to do about ipv4 and ipv6. Should we
treat the two as purely separate like shorewall? Since nftables handles
both protocols, it seemed the right way to go was with one config and
one rules file which could configure both stacks. Not sure if that is
the direction you went, might be worth community feedback.
Next up was where to handle TC and overall network topology config. I
decided to offload that to systemd, which worked best for my current
setups since I'd already been fighting conflicts between Shorewall and
systemd anyway. Not sure if that's the right call for a dedicated
firewall hardware appliance, though.
That's all I can think of at the moment. Will post more if they pop up.
Best of luck!
Regards,
Samuel Smith
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users