2008-06-30 01:00:25 +02:00
|
|
|
Changes in 4.2.0-Beta3
|
|
|
|
|
|
|
|
1) Fix ip_forwarding vs the 'restore' command.
|
|
|
|
|
2008-06-30 16:38:29 +02:00
|
|
|
2) Don't assume -f in /etc/init.d/shorewall-lite
|
|
|
|
|
2008-07-06 17:54:20 +02:00
|
|
|
3) Implement USE_DEFAULT_RT
|
2008-07-03 22:06:47 +02:00
|
|
|
|
2008-07-11 18:53:50 +02:00
|
|
|
4) Add -f option to the restart command.
|
|
|
|
|
|
|
|
5) Fix COPY column.
|
2008-07-06 23:47:59 +02:00
|
|
|
|
2008-05-27 22:54:04 +02:00
|
|
|
Changes in 4.2.0-Beta2
|
|
|
|
|
|
|
|
1) Only issue a warning on RFC 1918 violation.
|
|
|
|
|
2008-06-02 21:39:35 +02:00
|
|
|
2) Implement 'save' user exit.
|
|
|
|
|
2008-06-05 22:39:05 +02:00
|
|
|
3) HELPER column in tcrules.
|
|
|
|
|
2008-06-13 04:56:51 +02:00
|
|
|
4) De-implement DYNAMIC_ZONES=Yes in Shorewall-perl.
|
|
|
|
|
2008-06-14 02:23:36 +02:00
|
|
|
5) Allow !+setname.
|
|
|
|
|
2008-06-19 18:45:44 +02:00
|
|
|
6) Add macro.Mail.
|
|
|
|
|
2008-05-12 18:47:57 +02:00
|
|
|
Changes in 4.2.0-Beta1
|
2008-05-04 02:18:47 +02:00
|
|
|
|
2008-05-12 18:47:57 +02:00
|
|
|
1) Fix handling of firewall marks.
|
2008-05-04 02:18:47 +02:00
|
|
|
|
2008-05-13 16:54:35 +02:00
|
|
|
2) Allow upper-case A-F in hex representation of MARK in tcclasses.
|
|
|
|
|
2008-06-19 00:06:56 +02:00
|
|
|
3) De-implement DYNAMIC_ZONES=Yes in Shorewall-perl and fix it in
|
|
|
|
Shorewall-shell.
|
|
|
|
|
2008-04-18 19:26:16 +02:00
|
|
|
Changes in 4.1.8
|
|
|
|
|
|
|
|
1) Fix some parsing issues with absurd configurations.
|
|
|
|
|
|
|
|
2) Undo routing changes applied by "NULL_ROUTE_RFC1918=Yes".
|
|
|
|
|
2008-04-20 03:11:55 +02:00
|
|
|
3) Improvements in parsing.
|
|
|
|
|
2008-04-28 19:32:31 +02:00
|
|
|
4) Add the -p option to start and stop
|
|
|
|
|
2008-04-30 17:11:26 +02:00
|
|
|
5) Allow installers to run under Cygwin without extra parameters.
|
|
|
|
|
2008-05-03 16:10:47 +02:00
|
|
|
6) Add -p option to 'start' and 'restart' commands.
|
|
|
|
|
2008-03-23 17:08:34 +01:00
|
|
|
Changes in 4.1.7
|
|
|
|
|
|
|
|
1) Fix port verification.
|
|
|
|
|
|
|
|
2) Fix number of columns calculation.
|
|
|
|
|
|
|
|
3) Allow user exits to detect gateway.
|
|
|
|
|
2008-03-23 23:23:12 +01:00
|
|
|
4) Add CONNBYTES column to tcrules.
|
|
|
|
|
2008-03-24 23:36:48 +01:00
|
|
|
5) Fix a couple of 4.1.6 bugs.
|
|
|
|
|
|
|
|
6) Add MANGLE_ENABLED option.
|
|
|
|
|
2008-03-25 16:45:26 +01:00
|
|
|
7) Fix priority mingling in tc filters.
|
|
|
|
|
2008-03-26 16:56:50 +01:00
|
|
|
8) Fix ":" parsing errors.
|
2008-03-26 16:36:23 +01:00
|
|
|
|
2008-03-28 01:05:25 +01:00
|
|
|
9) Add ORIGINAL DEST column to macros.
|
2008-03-27 20:45:23 +01:00
|
|
|
|
2008-03-29 01:35:00 +01:00
|
|
|
10) Add NULL_ROUTE_RFC1918 option.
|
|
|
|
|
2008-04-06 16:53:26 +02:00
|
|
|
11) Defer enabling of forwarding until rules are in place.
|
|
|
|
|
2008-04-09 17:26:05 +02:00
|
|
|
12) Merge Tuomo's SANE support patch.
|
|
|
|
|
2008-04-16 18:44:49 +02:00
|
|
|
13) Fix silly duplicate-rule error.
|
|
|
|
|
|
|
|
14) Fix IPSEC host entry with DYNAMIC_ZONES=Yes
|
|
|
|
|
2008-04-26 06:28:55 +02:00
|
|
|
15) Use the OPTIONS variable from /etc/default/shorewall[-lite] on Debian.
|
|
|
|
|
2008-02-24 17:33:46 +01:00
|
|
|
Changes in 4.1.6
|
|
|
|
|
|
|
|
1) Deprecate IMPLICIT_CONTINUE=Yes
|
|
|
|
|
2008-03-05 17:16:04 +01:00
|
|
|
2) Add REDIRECTED INTERFACES column to tcdevices.
|
|
|
|
|
2008-03-08 21:49:41 +01:00
|
|
|
3) Add L2TP tunnel support.
|
|
|
|
|
2008-03-14 20:26:09 +01:00
|
|
|
4) Add support for IFB devices -- phase I.
|
|
|
|
|
2008-03-16 21:31:50 +01:00
|
|
|
5) Add support for IFB devices -- phase II.
|
|
|
|
|
2008-02-13 20:11:02 +01:00
|
|
|
Changes in 4.1.5
|
|
|
|
|
|
|
|
1) More ruleset optimization.
|
|
|
|
|
2008-02-13 21:05:18 +01:00
|
|
|
2) Make LOG_MARTIANS=Yes the default.
|
|
|
|
|
2008-02-13 22:04:31 +01:00
|
|
|
3) Update modules file for 2.6.25.
|
|
|
|
|
2008-02-14 18:40:38 +01:00
|
|
|
4) Restore 3.4 code to work around busybox limination.
|
|
|
|
|
2008-02-15 19:29:11 +01:00
|
|
|
5) Add restriction handling in tcrules file.
|
|
|
|
|
|
|
|
6) Fix designator table in Tc.pm.
|
2008-02-14 18:40:38 +01:00
|
|
|
|
2008-02-18 18:38:25 +01:00
|
|
|
7) Generate an error when mac match is used in the POSTROUTING or
|
|
|
|
OUTPUT chains.
|
|
|
|
|
2008-02-22 20:58:54 +01:00
|
|
|
8) Add 'BROKEN_ROUTING' option.
|
|
|
|
|
2008-02-23 00:15:39 +01:00
|
|
|
9) Automatic macro comments.
|
|
|
|
|
2008-02-23 02:46:50 +01:00
|
|
|
10) But make automatic macro comments optional.
|
|
|
|
|
2007-12-29 17:31:49 +01:00
|
|
|
Changes in 4.1.4
|
|
|
|
|
|
|
|
1) Fix do_test() to accept 0 and to use the same mask as
|
|
|
|
Shorewall-shell
|
|
|
|
|
2008-01-05 00:20:09 +01:00
|
|
|
2) The compilation date recorded in the firewall.conf file produced by
|
|
|
|
Shorewall-perl was previously mangled.
|
|
|
|
|
2008-01-05 16:59:15 +01:00
|
|
|
3) Don't fully populate /etc/shorewall under Cygwin
|
|
|
|
|
2008-01-15 04:48:37 +01:00
|
|
|
4) Fix the DNAT/REDIRECT fiasco.
|
|
|
|
|
|
|
|
5) Allow interface lists in the masq and nat files.
|
2008-01-12 02:32:18 +01:00
|
|
|
|
2008-01-20 00:36:27 +01:00
|
|
|
6) Allow loose match of interface names used in masq, nat and netmap.
|
|
|
|
|
2008-01-23 00:48:03 +01:00
|
|
|
7) Allow loose match of interface names in match_source_dev().
|
|
|
|
|
|
|
|
8) Implement 'sourceonly' host entry option.
|
|
|
|
|
2008-01-25 00:45:24 +01:00
|
|
|
9) Make all non-firewall zones "complex".
|
|
|
|
|
2007-12-07 22:17:14 +01:00
|
|
|
Changes in 4.1.3
|
|
|
|
|
|
|
|
1) Fix NFLOG/ULOG upcasing problem.
|
|
|
|
|
|
|
|
2) Fix STARTUP_LOG without LOG_VERBOSITY.
|
|
|
|
|
|
|
|
3) Fix LOG_VERBOSITY without STARTUP_LOG.
|
|
|
|
|
2007-12-15 00:13:36 +01:00
|
|
|
4) Fall back to /bin/sh if SHOREWALL_SHELL isn't viable.
|
|
|
|
|
2007-12-15 19:49:05 +01:00
|
|
|
5) Fix mis-handling of <interface>:<mac>
|
|
|
|
|
2007-12-17 23:36:08 +01:00
|
|
|
6) Add better diagnostic when not running as root.
|
|
|
|
|
2007-12-19 00:55:20 +01:00
|
|
|
7) Detect lack of interfaces and IPv4 zones.
|
|
|
|
|
2007-12-21 23:56:36 +01:00
|
|
|
8) Classify marked traffic using tc filter rules.
|
|
|
|
|
2007-12-26 17:35:02 +01:00
|
|
|
9) Allow installation on Cygwin.
|
|
|
|
|
2007-11-23 22:33:36 +01:00
|
|
|
Changes in 4.1.2
|
|
|
|
|
|
|
|
1) Enhanced Operational Logging
|
|
|
|
|
2007-11-26 23:34:36 +01:00
|
|
|
2) Fix undefined value when config file missing.
|
|
|
|
|
|
|
|
3) Handle exit status 4 from iptables.
|
|
|
|
|
2007-12-01 18:09:38 +01:00
|
|
|
4) Fix formatting of macro headings (again).
|
|
|
|
|
|
|
|
5) Update sample shorewall.conf files with new options.
|
|
|
|
|
2007-12-04 01:02:35 +01:00
|
|
|
6) Correct Jabber macro names.
|
|
|
|
|
|
|
|
7) Tighten up HIGH_ROUTE_MARKS in the OUTPUT chain.
|
2007-12-01 18:09:38 +01:00
|
|
|
|
2007-12-06 18:26:37 +01:00
|
|
|
8) Add 'nomarks' OPTION to tcdevices.
|
2007-12-05 19:52:38 +01:00
|
|
|
|
2007-12-07 00:49:21 +01:00
|
|
|
9) Add COMMENTs to macros.
|
|
|
|
|
2007-11-20 17:01:27 +01:00
|
|
|
Changes in 4.1.1
|
|
|
|
|
|
|
|
1) Fix ULOG/NFLOG output.
|
|
|
|
|
|
|
|
2) Fix NFQUEUE(<queue-num>) in Policy file.
|
|
|
|
|
2007-11-21 17:28:36 +01:00
|
|
|
3) Allow specifying an address in the Providers file.
|
|
|
|
|
2007-11-19 22:15:36 +01:00
|
|
|
Changes in 4.1.0.
|
2007-11-16 02:21:33 +01:00
|
|
|
|
2007-11-19 22:15:36 +01:00
|
|
|
1) Add 'shared' provider option.
|
2007-11-16 02:21:33 +01:00
|
|
|
|
2007-11-19 22:15:36 +01:00
|
|
|
2) Allow refresh of entire table and refresh mangle by default.
|
2007-11-16 00:24:54 +01:00
|
|
|
|
2007-11-19 22:15:36 +01:00
|
|
|
3) Add NFLOG support.
|
2007-11-16 00:24:54 +01:00
|
|
|
|
2007-11-19 22:15:36 +01:00
|
|
|
4) Implement alternative syntax for params.
|
2007-11-16 00:24:54 +01:00
|
|
|
|
|
|
|
5) Add support for embedded shell and Perl scripts.
|
|
|
|
|
|
|
|
6) Add support for manual chains.
|
|
|
|
|
|
|
|
7) Don't require GATEWAY in tunnels file.
|
|
|
|
|
|
|
|
8) Fix HIGH_ROUTE_MARKS fsck-up.
|
|
|
|
|
|
|
|
9) Fix Makefiles for VARDIR
|
|
|
|
|
|
|
|
10) Add -t option to hits command.
|
|
|
|
|
|
|
|
11) Add DONT_LOAD option
|
|
|
|
|
|
|
|
12) Add support for --random.
|