Google
 
 
Home arrow Shorewall Developement Release 2.1.8 Available

Main Menu
 Home
 Linux Articles
 FreeBSD Articles
 Apache Articles
 Perl Articles
 Other Articles
 Program Downloads
 Free Books
 News
 The Web Links
 Contact Us

Most Read
Automating SFTP using expect
FreeBSD PPTP VPN
SnortShorwall - Using Snort And Shorewall Together
Shorewall Router on Linux
Shorewall Stand Alone Firewall

Polls
Favorite Linux/BSD
Fedora
Mandrake
Debian
Slackware
Gentoo
Suse
FreeBSD
Other
  

Syndicate
Latest news direct to your desktop
RSS

Login Form
Username

Password

Remember me
Forgotten your password?
No account yet? Create one

Members Online
 Linux-BSD-Central Has a Total of 14201 Members   Members (14201) # Online
 We have 10 Guests Online. Guests 10
 We have 0 Users Online. Users 0

Online Users
No Users Online

Statistics
OS: Linux w
PHP: 5.2.17
MySQL: 5.1.56
Time: 18:02
Members: 14201
Hits: 1793704
News: 281
WebLinks: 15





Shorewall Developement Release 2.1.8 Available   PDF  Print  E-mail 
Contributed by Chad Brandt  
Wednesday, 08 September 2004
A new 2.1 development release is available. This release fixes some minor bugs and adds a few more new features.

Problems corrected since 2.1.7

1)  Fix parsing of ACTION with ":" but no log level (Richard Musil).

2)  Fix parsing of PROTO column in /etc/shorewall/tcrules.

3)  Packets that will be encrypted or that have been decrypted by IPSEC
    are now exempted from the rules established by one-to-one NAT. This
    allows tunnel mode IPSEC to work for local networks where some of
    the systems use one-to-one NAT.

4)  The shorewall.spec file now directs rpm to cause Shorewall to start
    automatically at boot. This feature was inadvertently removed in
    Shorewall 2.1.3.

New features since 2.1.7

1) Shorewall now verifies that your kernel and iptables have physdev
    match support if BRIDGING=Yes in shorewall.conf.

2) Beginning with this release, if your kernel and iptables have
    iprange match support (see the output from "shorewall check"), then
    with the exception of the /etc/shorewall/netmap file, anywhere that
    a network address may appear an IP address range of the form <low
    address>-<high address> may also appear.

3) Support has been added for the iptables CLASSIFY target. That
    target allows you to classify packets for traffic shaping directly
    rather than indirectly through fwmark. Simply entry the
    <major>:<minor> classification in the first column of
    /etc/shorewall/tcrules:

    Example:

#MARK/      SOURCE       DEST      PROTO     PORT(S)
#CLASSIFY
1:30     - -    tcp      25

    Marking using the CLASSIFY target always occurs in the POSTROUTING
    chain of the mangle table and is not affected by the setting of
    MARK_IN_FORWARD_CHAIN in shorewall.conf.

Visit Shorewalls Web Site

Comments

Only registered users can write comments.
Please login or register.

Powered by AkoComment 1.0 beta 2!



Read More News



 


 

Check out TwistByte - The best mobile apps available For awesome Android and IPhone applications!!