2005-12-14 17:18:38 +01:00
|
|
|
Changes in 3.0.4
|
|
|
|
|
|
|
|
1) Console-friendly version of shorewall.conf.
|
|
|
|
|
2005-12-15 23:42:39 +01:00
|
|
|
2) Add 'Limit' as a standard action.
|
|
|
|
|
2005-12-17 02:55:02 +01:00
|
|
|
3) Enabled loopback traffic under the DISABLE_IPV6 option.
|
|
|
|
|
2005-12-20 00:37:40 +01:00
|
|
|
4) Close hole in bridged configurations.
|
|
|
|
|
|
|
|
5) Fix bug in NONE intra-zone policy handling.
|
|
|
|
|
2005-12-20 20:14:36 +01:00
|
|
|
6) Fix bug in RETAIN_ALIASES=Yes.
|
|
|
|
|
2005-12-21 05:20:16 +01:00
|
|
|
7) Wildcard port support.
|
|
|
|
|
2005-12-24 16:39:58 +01:00
|
|
|
8) Fix logging of old mapped standard actions.
|
|
|
|
|
2005-11-27 21:59:47 +01:00
|
|
|
Changes in 3.0.3
|
|
|
|
|
|
|
|
1) Implement "shorewall show macros"
|
|
|
|
|
2005-11-28 16:26:06 +01:00
|
|
|
2) Comments regarding bridge configuration were improved.
|
|
|
|
|
2005-11-29 17:51:53 +01:00
|
|
|
3) Applied Tuomo Soini's patch to pretty up the tc4shorewall files.
|
|
|
|
|
2005-11-29 20:39:43 +01:00
|
|
|
4) Fix 'safe-start' and 'safe'restart' -- add support for -q in the process.
|
|
|
|
|
2005-11-29 22:38:43 +01:00
|
|
|
5) Fix help text for restore. Add -q to help for safe-start and safe-restart.
|
|
|
|
|
2005-12-01 18:58:24 +01:00
|
|
|
6) Add more migration information to release notes.
|
|
|
|
|
2005-12-01 19:05:13 +01:00
|
|
|
7) Allow "-" in the ADDRESS/SUBNET column of the blacklist file.
|
|
|
|
|
2005-12-01 19:24:19 +01:00
|
|
|
8) Add traffic shaping information to "dump" output.
|
|
|
|
|
2005-12-03 00:58:57 +01:00
|
|
|
9) Allow 'none' in the COPY column of /etc/shorewall/providers.
|
|
|
|
|
|
|
|
10) Implement 'ipdecimal' command.
|
|
|
|
|
2005-12-07 23:03:44 +01:00
|
|
|
11) Implement 'reload' in the init script.
|
|
|
|
|
2005-12-09 00:26:25 +01:00
|
|
|
12) Correct README.txt
|
|
|
|
|
2005-12-10 00:11:46 +01:00
|
|
|
13) Add upgrade considerations for 2.0 users to release notes.
|
|
|
|
|
2005-12-10 21:11:07 +01:00
|
|
|
14) Change default for CLEAR_TC to "Yes".
|
|
|
|
|
2005-12-11 17:13:15 +01:00
|
|
|
15) Added warning to the zones file.
|
|
|
|
|
2005-12-12 19:52:40 +01:00
|
|
|
16) Fixed bug in tcrules processing (interface name in SOURCE column).
|
|
|
|
|
2005-12-13 20:42:23 +01:00
|
|
|
17) Create /var/log/shorewall-init.log when installing on Debian.
|
|
|
|
|
2005-11-22 03:27:00 +01:00
|
|
|
Changes in 3.0.2
|
|
|
|
|
|
|
|
1) Typos in the Samples corrected.
|
|
|
|
|
|
|
|
2) Incompatibility with old kernels worked around.
|
|
|
|
|
2005-11-22 23:48:18 +01:00
|
|
|
3) Added new Webmin macro
|
|
|
|
|
|
|
|
4) Arch Linux installation routines improved
|
|
|
|
|
2005-11-13 17:00:17 +01:00
|
|
|
Changes in 3.0.1
|
|
|
|
|
|
|
|
1) Set policies for chains in nat, mangle and raw tables.
|
|
|
|
|
2005-11-15 19:44:02 +01:00
|
|
|
2) Applied Tuomo's patch for Makefile.
|
|
|
|
|
|
|
|
3) Add Farkas ordering to generated SOURCE and DEST column when expanding
|
|
|
|
macros.
|
|
|
|
|
2005-11-16 18:08:09 +01:00
|
|
|
4) Clarify PORTS column in blacklist file.
|
|
|
|
|
2005-11-17 19:49:25 +01:00
|
|
|
5) Correct CLAMPMSS/FASTACCEPT interaction.
|
2005-11-17 19:23:19 +01:00
|
|
|
|
2005-11-04 18:07:58 +01:00
|
|
|
Changes in 3.0.0 Final
|
|
|
|
|
|
|
|
None.
|
|
|
|
|
2005-10-24 21:43:53 +02:00
|
|
|
Changes in 3.0.0 RC 3.
|
|
|
|
|
2005-10-25 00:35:05 +02:00
|
|
|
1) ROUTE target and Extended Mark removed from capabilities.
|
2005-10-24 21:43:53 +02:00
|
|
|
|
2005-10-28 05:18:49 +02:00
|
|
|
2) Suppress 'ambiguous redirect' error messages.
|
|
|
|
|
2005-10-31 22:06:01 +01:00
|
|
|
3) Correct stupid typo in release notes ([rej|drop]NewNot vs. [rej|drop]NewNon).
|
|
|
|
|
|
|
|
4) Stop whining about ipt_owner messages under kernel 2.6.14.
|
2005-10-27 04:00:23 +02:00
|
|
|
|
2005-10-31 22:23:16 +01:00
|
|
|
5) Update config files with cmd-owner info.
|
|
|
|
|
2005-11-02 16:32:33 +01:00
|
|
|
6) Fix DHCP with MACLIST_TABLE=mangle.
|
|
|
|
|
2005-11-02 22:40:04 +01:00
|
|
|
7) Remove Slackware special case from INSTALL instructions.
|
|
|
|
|
2005-10-18 17:20:12 +02:00
|
|
|
Changes in 3.0.0 RC 2.
|
|
|
|
|
|
|
|
1) Fix support for OpenVPN and tcp.
|
|
|
|
|
2005-10-19 16:30:13 +02:00
|
|
|
2) Correct cut-and-paste error in 'arp_ignore' processing.
|
|
|
|
|
2005-10-21 00:10:10 +02:00
|
|
|
3) Add 'src' to gateway routes. Make 'find_first_interface_address' look for
|
|
|
|
global addresses only.
|
|
|
|
|
2005-10-21 23:12:28 +02:00
|
|
|
4) Update /etc/shorewall/interfaces to describe multiple interfaces to a zone.
|
|
|
|
|
2005-10-17 16:09:50 +02:00
|
|
|
Changes in 3.0.0 RC 1.
|
2005-10-10 23:35:37 +02:00
|
|
|
|
|
|
|
1) Correct spelling of MACLIST_TABLE in shorewall.conf.
|
|
|
|
|
2005-10-09 22:26:37 +02:00
|
|
|
Changes in 3.0.0 Beta 1.
|
2005-10-08 00:16:03 +02:00
|
|
|
|
2005-10-09 17:47:47 +02:00
|
|
|
1) Add TC_ENABLED=Internal
|
2005-10-08 00:16:03 +02:00
|
|
|
|
2005-10-08 16:57:10 +02:00
|
|
|
2) Fix default tc class bug.
|
|
|
|
|
2005-10-06 22:30:27 +02:00
|
|
|
Changes in 2.5.8
|
|
|
|
|
|
|
|
1) Fix 'shorewall refresh' with long tcrules entries.
|
|
|
|
|
|
|
|
2) Implement MACLIST_TABLE.
|
|
|
|
|
2005-10-07 00:46:17 +02:00
|
|
|
3) Make tc class ids unique between devices.
|
|
|
|
|
2005-09-19 16:17:09 +02:00
|
|
|
Changes in 2.5.7
|
|
|
|
|
|
|
|
1) Fix ADMINISABSENTMINDED=Yes vs. entries in /etc/shorewall/routestopped.
|
|
|
|
|
2005-09-30 18:54:24 +02:00
|
|
|
2) Fix traffic shaping and "shorewall refresh"
|
|
|
|
|
|
|
|
3) Add capabilities report to "shorewall dump".
|
|
|
|
|
2005-09-30 19:16:22 +02:00
|
|
|
4) Rename 'plain' to 'ipv4'
|
|
|
|
|
2005-10-01 17:55:41 +02:00
|
|
|
5) Deimplement NEWNOTSYN
|
|
|
|
|
2005-10-02 18:28:24 +02:00
|
|
|
6) Fix logging IPP2P rules.
|
|
|
|
|
2005-10-04 16:54:56 +02:00
|
|
|
7) Add zone type to /var/lib/shorewall/zones.
|
|
|
|
|
2005-10-04 18:20:30 +02:00
|
|
|
8) Give better diagnostics when IPP2P match isn't available.
|
|
|
|
|
2005-10-04 19:04:19 +02:00
|
|
|
9) Do not touch mangle chain during "refresh".
|
|
|
|
|
2005-10-04 20:46:35 +02:00
|
|
|
10) Implement support for UDP IPP2P Matching.
|
|
|
|
|
2005-09-13 19:13:35 +02:00
|
|
|
Changes in 2.5.6
|
|
|
|
|
|
|
|
1) Finish install/fallback cleanup.
|
|
|
|
|
2005-09-15 01:01:13 +02:00
|
|
|
2) Fix startup failure.
|
|
|
|
|
|
|
|
3) Add "-n" option.
|
|
|
|
|
2005-09-05 22:07:00 +02:00
|
|
|
Changes in 2.5.5
|
|
|
|
|
|
|
|
1) Zone file alchemy attempted.
|
|
|
|
|
|
|
|
2) Fix install.sh re: Makefile
|
|
|
|
|
2005-09-08 22:57:29 +02:00
|
|
|
3) Fix error handling.
|
|
|
|
|
2005-09-09 00:30:32 +02:00
|
|
|
4) Add SHOREWALL_LIBRARY function.
|
|
|
|
|
2005-08-30 00:51:49 +02:00
|
|
|
Changes in 2.5.4
|
|
|
|
|
|
|
|
1) Allow TAG to be used as a general parameter mechanism [hack].
|
|
|
|
|
|
|
|
2) Fix some ghastly bugs in macros.
|
2005-08-16 20:54:11 +02:00
|
|
|
|
2005-08-30 17:54:29 +02:00
|
|
|
3) "shorewall check" now checks the masq file.
|
|
|
|
|
2005-08-30 19:42:21 +02:00
|
|
|
4) "shorewall check" now checks the proxyarp file.
|
|
|
|
|
2005-08-30 22:29:42 +02:00
|
|
|
5) "shorewall check" now checks the nat file.
|
|
|
|
|
|
|
|
6) "shorewall check" now checks the providers file.
|
|
|
|
|
2005-08-31 22:48:22 +02:00
|
|
|
7) Merge 'tc4shorewall'
|
|
|
|
|
2005-09-01 17:16:11 +02:00
|
|
|
8) Modify tc4shorewall so that it plays well with Shorewall
|
|
|
|
save/restore.
|
|
|
|
|
2005-08-16 20:54:11 +02:00
|
|
|
Changes in 2.5.3
|
|
|
|
|
|
|
|
1) Allow exclusion lists in /etc/shorewall/tcrules.
|
|
|
|
|
2005-08-16 23:57:43 +02:00
|
|
|
2) Added 'openvpnserver' and 'openvpnclient' tunnel types.
|
|
|
|
|
2005-08-17 19:52:32 +02:00
|
|
|
3) Set COMMAND=restore in restore-base.
|
|
|
|
|
2005-08-18 22:18:08 +02:00
|
|
|
4) Allow exclusion lists in actions.
|
2005-08-17 23:00:33 +02:00
|
|
|
|
2005-08-18 23:39:30 +02:00
|
|
|
5) Make intra-zone policies more rational.
|
|
|
|
|
2005-08-25 00:39:19 +02:00
|
|
|
6) Clear the raw table on stop and [re]start
|
|
|
|
|
2005-08-26 21:55:05 +02:00
|
|
|
7) Section the rules file.
|
|
|
|
|
2005-08-27 16:50:33 +02:00
|
|
|
8) Fixed tunnels/rules interaction problems.
|
|
|
|
|
2005-08-29 22:32:16 +02:00
|
|
|
9) Provide hack for passing arguments to action extension scripts.
|
|
|
|
|
2005-08-16 20:54:11 +02:00
|
|
|
Changes in 2.5.2
|
|
|
|
|
2005-08-30 00:51:49 +02:00
|
|
|
1) Allow port lists in /etc/shorewall/accounting.
|
2005-08-16 20:54:11 +02:00
|
|
|
|
|
|
|
2) Fix PKTTYPE=No and packet type match capability reporting.
|
|
|
|
|
|
|
|
3) Add FASTACCEPT option.
|
|
|
|
|
|
|
|
4) Generate error if norfc1918 is specified on an interface with an RFC
|
|
|
|
1918 IP address.
|
|
|
|
|
|
|
|
5) Implement exclusion lists in /etc/shorewall/rules.
|
|
|
|
|
2005-07-27 22:30:16 +02:00
|
|
|
Changes in 2.5.1
|
|
|
|
|
|
|
|
1) Make "shorewall add" work with 'ipsec' in hosts file.
|
|
|
|
|
|
|
|
2) Remove dependence on 'which'
|
|
|
|
|
2005-07-28 16:37:56 +02:00
|
|
|
3) Rename "status" to "dump" and add real status command.
|
|
|
|
|
|
|
|
4) Fix Makefile (compare to restore-base rather than restarted).
|
|
|
|
|
2005-08-05 16:13:45 +02:00
|
|
|
5) Add "all+"
|
|
|
|
|
|
|
|
6) Don't generate redundant ACCEPT rules for DNAT/REDIRECT/SAME
|
|
|
|
|
2005-08-11 21:53:07 +02:00
|
|
|
7) Add FASTACCEPT option in shorewall.conf.
|
|
|
|
|
2005-08-14 18:45:48 +02:00
|
|
|
8) Generate error for 'norfc1918' on an interface with an RFC 1918 IP
|
|
|
|
address.
|
|
|
|
|
2005-08-15 19:35:45 +02:00
|
|
|
9) Finally implement exclude lists in rules.
|
|
|
|
|
2005-07-27 22:30:16 +02:00
|
|
|
Changes in 2.5.1ex/2.5.0
|
2003-05-22 22:37:24 +02:00
|
|
|
|
2005-07-26 01:08:09 +02:00
|
|
|
1) Clean up handling of zones
|
2003-06-18 20:37:37 +02:00
|
|
|
|
2005-07-26 01:08:09 +02:00
|
|
|
2) Make the removal of the ipsec file upward compatible.
|
2004-01-24 00:48:30 +01:00
|
|
|
|
2005-07-26 01:08:09 +02:00
|
|
|
3) Improve CONTINUE policy handling.
|
2004-01-24 00:48:30 +01:00
|
|
|
|
2005-07-26 01:08:09 +02:00
|
|
|
4) Implement arp_ignore support.
|
2004-01-24 00:48:30 +01:00
|
|
|
|
2005-07-26 01:08:09 +02:00
|
|
|
Changes in 2.5.0ex
|
2004-01-27 23:33:32 +01:00
|
|
|
|
2005-07-26 01:08:09 +02:00
|
|
|
1) Make warning and error messages easier to find by using
|
|
|
|
capitalization.
|
2004-01-27 23:33:32 +01:00
|
|
|
|
2005-07-26 01:08:09 +02:00
|
|
|
2) Remove /etc/shorewall/ipsec and merge it's function with
|
|
|
|
/etc/shorewall/zones.
|
2004-01-28 01:52:03 +01:00
|
|
|
|
2005-07-26 01:08:09 +02:00
|
|
|
3) Apply small fix to the above patch.
|
2004-01-28 01:52:03 +01:00
|
|
|
|
2005-07-26 01:08:09 +02:00
|
|
|
4) Remove dynamic zone support.
|
2004-01-29 20:11:51 +01:00
|
|
|
|
2005-07-26 01:08:09 +02:00
|
|
|
5) Add "established policy" support.
|
2004-02-05 21:13:24 +01:00
|
|
|
|
2005-07-26 01:08:09 +02:00
|
|
|
6) Add CRITICALHOSTS support.
|
2005-07-09 06:45:32 +02:00
|
|
|
|
2005-07-26 01:08:09 +02:00
|
|
|
7) Remove 'bogon' stuff.
|
2005-07-09 06:45:32 +02:00
|
|
|
|
2005-07-26 01:08:09 +02:00
|
|
|
8) Implement Macros.
|