# \[Finished\] OpenWrt: updating crowdsec-firewall-bouncer package

**URL:** <https://discourse.crowdsec.net/t/finished-openwrt-updating-crowdsec-firewall-bouncer-package/1119>\
**Category:** crowdsec\
**Created:** [January 26, 2023, 7:08pm UTC](https://discourse.crowdsec.net/t/finished-openwrt-updating-crowdsec-firewall-bouncer-package/1119 "2023-01-26T19:08:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ne20002](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/ne20002/32/1012_2.png) [@ne20002](https://discourse.crowdsec.net/u/ne20002)\
**Post date:** [January 26, 2023, 7:08pm UTC](https://discourse.crowdsec.net/t/finished-openwrt-updating-crowdsec-firewall-bouncer-package/1119/1 "2023-01-26T19:08:41Z")

</div>

I’m currently working on an updated and more OpenWrt style package for the Crowdsec firewall bouncer on OpenWrt.

Already achieved is:

- having a uci config file with configuration
- creating nftables rules for input and forward chain
- start/stop with luci including creation/removal of process and nftables rules
- no dependencies / interferrences with OpenWrt firewall 4

This is done based on the package from OpenWrt 21.

Next steps:

- eleminating bouncer config file template and create it on the fly from the uci config
- updating the Crowdsec bouncer executable (currently v0.0.21)
- update packaging script / make file
- submitting pull request to OpenWrt project

I used the documentation for the bouncer [configuration](https://docs.crowdsec.net/docs/bouncers/firewall/) but it is unclear in terms of what options are optional and have a default and what of the configuration is needed for the different modes. In my case: what is needed in the configuration file for a nftables set-only setup.

Perhaps someone can clarify on this?

---

<div class="post-metadata">

**Author:** ![ne20002](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/ne20002/32/1012_2.png) [@ne20002](https://discourse.crowdsec.net/u/ne20002)\
**Post date:** [January 30, 2023, 8:24am UTC](https://discourse.crowdsec.net/t/finished-openwrt-updating-crowdsec-firewall-bouncer-package/1119/2 "2023-01-30T08:24:48Z")

</div>

I have finished my work so far and will start next step by updating the Makefile and create a pull request for OpenWrt. Luci-App is also ready.

I still need to figure a few things about the Makefile and OpenWrt build/packaging process.

---

<div class="post-metadata">

**Author:** ![ne20002](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/ne20002/32/1012_2.png) [@ne20002](https://discourse.crowdsec.net/u/ne20002)\
**Post date:** [January 31, 2023, 7:11am UTC](https://discourse.crowdsec.net/t/finished-openwrt-updating-crowdsec-firewall-bouncer-package/1119/3 "2023-01-31T07:11:38Z")

</div>

Pull request to OpenWrt has been opened.

---

<div class="post-metadata">

**Author:** ![ne20002](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/ne20002/32/1012_2.png) [@ne20002](https://discourse.crowdsec.net/u/ne20002)\
**Post date:** [February 4, 2023, 9:42am UTC](https://discourse.crowdsec.net/t/finished-openwrt-updating-crowdsec-firewall-bouncer-package/1119/4 "2023-02-04T09:42:37Z")

</div>

My pull request for the bouncer has been merged. The LuCi app pull request is still open.

---

<div class="post-metadata">

**Author:** ![ne20002](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/ne20002/32/1012_2.png) [@ne20002](https://discourse.crowdsec.net/u/ne20002)\
**Post date:** [February 6, 2023, 4:29pm UTC](https://discourse.crowdsec.net/t/finished-openwrt-updating-crowdsec-firewall-bouncer-package/1119/5 "2023-02-06T16:29:08Z")

</div>

The package (crowdsec-firewall-bouncer 0.0.25-1) is now available in OpenWrt snapshot.
