RC 1 is now available for testing. Problems Corrected in RC 1:
1) The CT target in /etc/shorewall[6]/notrack now works with exclusion.
2) /sbin/shorewall6 is once again a file rather than a symbolic
link. The latter proved difficult for rpm to cope with.
3) The 'show ipa' command now works; it was broken in one of the betas.
4) When providers were used in an IPv6 configuration, each time that
Shorewall6 was started or restarted, entries as follows would be
added to the IPv4 (!) routing rules:
32767: from all lookup default
One such entry would be added for each provider.
Now, one such an entry is added to the IPv6 routing rules, only if
that entry does not already exist.
New Features in RC 1:
1) A new option, USE_PHYSICAL_NAMES, has been added to shorewall.conf
and shorewall6.conf. Normally, when the rules compiler creates a
Netfilter chain that relates to an interface, the logical name of
the interface is used as the base for the chain name. For example,
if an interface has logical name OAKLAND and physical name eth0,
then the primary chain for input arriving on that interface is
normally 'OAKLAND_in'. When USE_PHYSICAL_NAMES=Yes, the name would
be 'eth0_in'.
Thank you for testing,
-Tom
--
Tom Eastep \ When I die, I want to go like my Grandfather who
Shoreline, \ died peacefully in his sleep. Not screaming like
Washington, USA \ all of the passengers in his car
http://shorewall.net \________________________________________________
signature.asc
Description: This is a digitally signed message part
------------------------------------------------------------------------------ Write once. Port to many. Get the SDK and tools to simplify cross-platform app development. Create new or port existing apps to sell to consumers worldwide. Explore the Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join http://p.sf.net/sfu/intel-appdev
_______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
