Public bug reported:

Binary package hint: shorewall

Shorewall 3.4.5 is available with the following release highlights, bug
fixes, and other changes:

Release Highlights

1)  Shorewall can now be tailored to reduce its footprint on embedded
    systems. As part of this change, actions are now completely
    optional.

    See http://www.shorewall.net/Modularization.html for details.

2)  Exclusion is now possible in /etc/shorewall/hosts. This is required
    for bridge/firewalls under kernel 2.6.20 and later.

    See http://www.shorewall.net/NewBridge.html.

3)  Shorewall and Shorewall Lite now include man pages. There is a 
    man page for shorewall(8), one for shorewall-lite(8) and one for
    each configuration file. As part of this change, all documentation
    has been removed from Shorewall configuration files. This should
    make it easier from users to upgrade from one release to the next
    since the configuration files will only change when column is added
    or renamed.

    See http://www.shorewall.net/manpages/Manpages.html

4)  Shorewall now remembers the changes that it has made to routing as
    a result of entries in /etc/shorewall/providers and
    /etc/shorewall/route_rules and reverses those changes when
    appropriate.

Problems Corrected in 3.4.5.

1)  DYNAMIC_ZONES=Yes can now coexist with Shorewall-perl's 'bport'
    zones. Those zones themselves may not be dynamically modified but
    the presence of bport zones no longer causes the 'shorewall add'
    command to fail.

2)  Shorewall's internal traffic shaper once again works when the 'sed'
    utility is provided by the Busybox package.

3)  Version 3.4.4 erroneously accepted the values On, Off, on, off, ON
    and OFF for the IP_FORWARDING option. These values were treated
    like 'Keep'. The listed values are now once again flagged as an
    error.

4)  If 'routeback' and 'detectnets' were specified on an interface,
    limited broadcasts (to 255.255.255.255) and multicasts were dropped
    when forwarded through the interface. This could cause
    broadcast-based and multicast applications to fail when running
    through a bridge with 'detectnets'.

5)  The 'hits' command works once again.

6)  IPSECFILE=ipsec (either explicitly or defaulted) works
    now. Previously, processing of the ipsec file was bypassed; often
    with a confusing "missing file" message.

7)  If DETECT_DNAT_IPADDRS=Yes in shorewall.conf but you did't have conntrack
    match support, then the generated script was missing 'done's.

Other changes in 3.4.5.

1)  When a Shorewall release includes detection of an additional
    capability, existing capabilities files become out of
    date. Previously, this condition was not detected.

    Beginning with this release, each generated capabilities file
    contains a CAPVERSION specification which defines the capabilities
    version of the file. If the CAPVERSION in a capabilities file is
    less than the current CAPVERSION, then Shorewall will issue the
    following message:

    WARNING: <file> is out of date -- it does not contain all of
    the capabilities defined by Shorewall version <version>

    where

        <file>    is the name of the capabilities file.
        <version> is the current Shorewall version.

    Existing capabilities files contain no CAPVERSION. When such a file
    is read, Shorewall will issue this message:

    WARNING: <file> may be not contain all of the capabilities defined
    by Shorewall version <version>

2)  When a directory is specified in a command such as 'start' or
    'compile', Shorewall now reads the shorewall.conf file (if any) in
    that directory before deciding which compiler to use. So if
    SHOREWALL_COMPILER is not specified in
    /etc/shorewall/shorewall.conf and the -C option was not specified
    on the run-line, then if Shorewall-perl is installed, the additional
    shorewall.conf file is read to see if it specifies a
    SHOREWALL_COMPILER.

3)  The 'save' command now uses iptables-save from the same directory
    containing iptables. Previously, iptables-save was located via the
    PATH setting.

** Affects: shorewall (Ubuntu)
     Importance: Undecided
         Status: New

-- 
Shorewall 3.4.5 fixes 7 bugs in 3.4.4, plus allows exclusions, makes actions 
optional, has man pages, etc.
https://bugs.launchpad.net/bugs/127231
You received this bug notification because you are a member of Ubuntu
Bugs, which is the bug contact for Ubuntu.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to