Shorewall 3.2.7 is now available.

Problems Corrected in 3.2.7

1)  Handling of saved ipsets in /etc/shorewall/ipsets is broken when
    used on a system running Shorewall Lite. If there is a file named
    'ipsets' on the CONFIG_PATH when the firewall script is compiled,
    then the compiled script attempts to restore the ipsets from that
    file (which may not exist on the firewall system).

2)  The 'try' command failed on systems whose /bin/sh is Busybox ash:

        /sbin/shorewall: export: 2158: Illegal option -n

3)  Previously, Shorewall has assumed that the root user is named
    'root'. Beginning with this release, the root user may have a
    different name. This required the addition of an '-r' option for
    the 'shorewall load' and 'shorewall reload' commands.

        [re]load [ -e ] [ -c ] [ -r <root user> ] [ <dir> ] system

    Example: shorewall reload -r foobar firewall

4)  On systems with a light-weight shell such as ash or dash for /bin/sh,
    the output of "shorewall show macros" was garbled.

Other Changes in 3.2.7

1)  Prior to this release, on firewall systems with Shorewall Lite
    installed, the local modules file is used to determine which kernel
    modules to load. Beginning with this release, if there is a
    'modules' file in the export directory when the firewall script is
    compiled, then that file will be copied into the compiled script
    and used on the firewall system.

2)  When syslogd is run with the -C option (which in some
    implementations causes syslogd to log to an in-memory circular
    buffer), /sbin/shorewall will now use the 'logread' command to read
    the log from that buffer. This is for combatibility with OpenWRT.

3)  Failures of the start, restart and restore commands are now logged
    using 'logger'. These failures are logged with the 'kern' facility
    and 'err' priority. As part of this change, normal state changes
    are now logged with the 'kern' facility and 'info' priority.

-Tom
-- 
Tom Eastep    \ Nothing is foolproof to a sufficiently talented fool
Shoreline,     \ http://shorewall.net
Washington USA  \ [EMAIL PROTECTED]
PGP Public Key   \ https://lists.shorewall.net/teastep.pgp.key

Attachment: signature.asc
Description: OpenPGP digital signature

-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys - and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to