2007-03-18 03:53:58 +01:00
|
|
|
Changes in 3.4.2
|
|
|
|
|
|
|
|
1) Update modules file for 2.6.20 module madness.
|
|
|
|
|
2007-03-18 03:57:30 +01:00
|
|
|
2) Update /sbin/shorewall[-lite] to account for mindless renaming of
|
|
|
|
/proc/net/ip_conntrack to /proc/net/nf_conntrack.
|
|
|
|
|
2007-03-22 18:27:02 +01:00
|
|
|
3) Fix 'none[!]' and built-in actions.
|
|
|
|
|
2007-03-22 23:27:26 +01:00
|
|
|
4) Fix 'ipsecnat' tunnels.
|
|
|
|
|
2007-03-11 17:37:53 +01:00
|
|
|
Changes in 3.4.1
|
|
|
|
|
|
|
|
1) Add rest of proxy arp fix.
|
|
|
|
|
2007-03-14 20:33:31 +01:00
|
|
|
2) Fix two problems with log-prefix handling.
|
|
|
|
|
|
|
|
3) Nested Zones produced shell errors.
|
|
|
|
|
|
|
|
4) CONTINUE policies generated invalid iptables input.
|
|
|
|
|
2007-03-15 17:03:31 +01:00
|
|
|
6) Fix CRITICALHOSTS bug in 'stop_firewall()'
|
|
|
|
|
2007-02-26 17:48:24 +01:00
|
|
|
Changes in 3.4.0 Final
|
|
|
|
|
|
|
|
1) Add missing logic for "!" rules.
|
|
|
|
|
2007-03-02 17:26:04 +01:00
|
|
|
2) Restore missing function merge_macro_source_dest.
|
|
|
|
|
2007-03-06 04:51:14 +01:00
|
|
|
3) Fix obscure bug in rule activation logic.
|
|
|
|
|
2007-03-07 17:28:29 +01:00
|
|
|
4) Don't clear proxy arp unconditionally.
|
|
|
|
|
2007-02-25 17:09:36 +01:00
|
|
|
Changes in 3.4.0 RC 3
|
2007-02-11 18:30:09 +01:00
|
|
|
|
|
|
|
1) Add warning about 'loose' and 'balance'
|
|
|
|
|
2007-02-16 17:05:36 +01:00
|
|
|
2) Fix route_rules processing.
|
|
|
|
|
2007-02-20 17:43:45 +01:00
|
|
|
3) Fix restoration of ip range dynamic entries.
|
|
|
|
|
2007-02-20 18:52:29 +01:00
|
|
|
4) Fix exit status problem with 'restart'
|
|
|
|
|
2007-02-23 18:07:13 +01:00
|
|
|
5) Dump SPD and SAD in the dump command.
|
|
|
|
|
2007-02-03 02:28:29 +01:00
|
|
|
Changes in 3.4.0 RC 2
|
|
|
|
|
2007-02-04 18:25:26 +01:00
|
|
|
1) No longer include params file in compiled output.
|
2007-02-03 02:28:29 +01:00
|
|
|
|
2007-01-24 18:34:04 +01:00
|
|
|
Changes in 3.4.0 RC 1
|
|
|
|
|
|
|
|
1) LITEDIR option in shorewall.conf
|
|
|
|
|
2007-01-25 19:28:16 +01:00
|
|
|
2) Add some hacks for Shorewall Lite on OpenWRT
|
|
|
|
|
|
|
|
3) Add macro for SixXS.
|
|
|
|
|
2007-01-30 18:57:10 +01:00
|
|
|
4) Allow ranges and ipset names in the ADDRESSES column of maclist
|
|
|
|
file.
|
|
|
|
|
2007-02-09 17:15:08 +01:00
|
|
|
5) Add helpers for SIP to the modules file.
|
2007-01-26 17:44:17 +01:00
|
|
|
|
2007-02-09 17:15:08 +01:00
|
|
|
6) Only copy /etc/shorewall/params to output if non-export.
|
|
|
|
|
|
|
|
7) Add EXPORTPARAMS option
|
2007-02-06 22:29:30 +01:00
|
|
|
|
2007-01-09 16:55:47 +01:00
|
|
|
Changes in 3.4.0 Beta 3
|
|
|
|
|
|
|
|
1) Handle VLAN interface names like vlanX@ethY.
|
|
|
|
|
|
|
|
2) Fix ipp2p:udp handling in action body.
|
|
|
|
|
2007-01-15 20:27:15 +01:00
|
|
|
3) Be more careful about converting pre-3.2 maclist records.
|
|
|
|
|
2007-01-18 00:41:59 +01:00
|
|
|
4) 'noah' is implied by ipsecnat in /etc/shorewall/tunnels.
|
|
|
|
|
2007-01-22 17:04:11 +01:00
|
|
|
5) Reduce the number of rules in the 'blacklst' chain when
|
|
|
|
BLACKLIST_LOGLEVEL is specified.
|
|
|
|
|
2006-12-30 18:30:53 +01:00
|
|
|
Changes in 3.4.0 Beta 2
|
|
|
|
|
|
|
|
1) Fix for empty blacklist file.
|
|
|
|
|
2007-01-01 01:40:42 +01:00
|
|
|
2) Don't copy files from /usr/share/shorewall into the compiled
|
|
|
|
script.
|
|
|
|
|
|
|
|
3) Add wait4ifup.
|
2006-12-30 19:04:15 +01:00
|
|
|
|
2007-01-02 22:25:35 +01:00
|
|
|
4) Rename the shorewall.conf to shorewall-lite.conf.
|
2007-01-02 17:01:46 +01:00
|
|
|
|
2006-12-20 16:39:39 +01:00
|
|
|
Changes in 3.4.0 Beta 1
|
|
|
|
|
|
|
|
1) Correct handling of masq file.
|
|
|
|
|
2006-12-20 17:14:31 +01:00
|
|
|
2) Simplify log record processing and remove more noise from the
|
|
|
|
displayed record.
|
|
|
|
|
2006-11-20 16:42:20 +01:00
|
|
|
Changes in 3.3.6
|
|
|
|
|
2006-11-21 00:39:46 +01:00
|
|
|
1) Remove /etc/shorewall/Documentation.
|
2006-11-20 16:42:20 +01:00
|
|
|
|
2006-11-21 23:52:07 +01:00
|
|
|
2) Remove /usr/share/shorewall/help.
|
|
|
|
|
2006-11-24 03:28:08 +01:00
|
|
|
3) Use export directory's modules file with -e.
|
|
|
|
|
2006-11-28 01:05:52 +01:00
|
|
|
4) Use fwmark tc filter with unknown interfaces.
|
|
|
|
|
2006-11-29 01:38:10 +01:00
|
|
|
5) Use multiport match in tcrules.
|
|
|
|
|
2006-11-30 01:23:33 +01:00
|
|
|
6) Fix safe- commands.
|
|
|
|
|
2006-12-01 17:36:17 +01:00
|
|
|
7) Remove 'try' command.
|
|
|
|
|
2006-12-02 18:11:33 +01:00
|
|
|
8) Make colon after system optional in the 'export' command.
|
|
|
|
|
2006-12-03 19:18:21 +01:00
|
|
|
9) Restore 'try' command and improve 'safe-' commands.
|
|
|
|
|
2006-12-04 17:31:48 +01:00
|
|
|
10) Allow capabilities file to be used with Shorewall as well as
|
|
|
|
Shorewall Lite.
|
|
|
|
|
2006-12-05 22:24:49 +01:00
|
|
|
11) Allow in-memory circular buffer for system log.
|
|
|
|
|
2006-12-08 23:43:46 +01:00
|
|
|
12) Add ":T" qualifier in tcrules.
|
|
|
|
|
2006-12-10 21:40:25 +01:00
|
|
|
13) Log start/restart/restore failures.
|
|
|
|
|
2006-11-09 16:57:58 +01:00
|
|
|
Changes in 3.3.5
|
2006-10-20 19:41:13 +02:00
|
|
|
|
2006-10-30 19:22:46 +01:00
|
|
|
1) Restore default route when there are no 'balance' providers.
|
|
|
|
|
2006-10-30 20:25:39 +01:00
|
|
|
2) Fixes to change 1.
|
|
|
|
|
2006-11-01 18:15:23 +01:00
|
|
|
3) Many changed to improve the readability, appearance and effeciency
|
|
|
|
of the generated script.
|
|
|
|
|
|
|
|
4) Turn off POLICY_MATCH if no IPSEC.
|
|
|
|
|
2006-11-01 19:57:35 +01:00
|
|
|
5) Only compile traffic shaping once.
|
|
|
|
|
2006-11-06 19:20:48 +01:00
|
|
|
6) Move config file documentary comments to a separate file.
|
|
|
|
|
2006-11-08 01:16:30 +01:00
|
|
|
7) Fix whitespace in LOGFORMAT.
|
|
|
|
|
2006-11-09 05:18:49 +01:00
|
|
|
8) Move DNAT/REDIRECT code to lib.base.
|
|
|
|
|
2006-11-09 16:57:58 +01:00
|
|
|
9) Implement -c option to [re]load command.
|
|
|
|
|
2006-11-10 19:53:12 +01:00
|
|
|
10) Don't create ingress qdisc if IN-BANDWIDTH = 0.
|
|
|
|
|
2006-11-11 17:20:59 +01:00
|
|
|
11) Return success if start of running config.
|
|
|
|
|
2006-11-12 19:19:17 +01:00
|
|
|
12) Add Makefile especially for /usr/share/shorewall/configfiles/
|
|
|
|
|
2006-11-19 23:33:13 +01:00
|
|
|
13) Add man pages.
|
|
|
|
|
2006-10-30 19:22:46 +01:00
|
|
|
Changes in 3.3.4
|
|
|
|
|
2006-10-20 19:41:13 +02:00
|
|
|
1) Make exclusion work with "show zones"
|
|
|
|
|
2006-10-20 21:02:38 +02:00
|
|
|
2) Add 'show ip' and 'show routing' commands.
|
|
|
|
|
2006-10-23 23:18:37 +02:00
|
|
|
3) Add COMBINE_JUMPS option.
|
|
|
|
|
2006-10-24 17:07:18 +02:00
|
|
|
4) Add an output chain for each interface.
|
|
|
|
|
2006-10-25 17:13:49 +02:00
|
|
|
5) Rename COMBINE_JUMPS to OPTIMIZE and make its value numeric.
|
|
|
|
|
2006-10-26 23:47:58 +02:00
|
|
|
6) Suppress superfluous wildcard rules under OPTIMIZE > 0.
|
|
|
|
|
2006-10-28 00:00:48 +02:00
|
|
|
7) Support ip ranges in the drop, logdrop, reject, and allow commands.
|
|
|
|
|
2006-10-28 16:46:43 +02:00
|
|
|
8) Add lib.cli.
|
2006-10-28 00:42:05 +02:00
|
|
|
|
2006-10-29 18:19:11 +01:00
|
|
|
9) Attempt to undo routing changes.
|
|
|
|
|
2006-10-02 19:33:46 +02:00
|
|
|
Changes in 3.3.3
|
|
|
|
|
2006-10-04 20:04:24 +02:00
|
|
|
1) Fix excluding in SUBNET column.
|
2006-10-02 19:33:46 +02:00
|
|
|
|
|
|
|
2) Add logical AND and OR support for tcrules.
|
|
|
|
|
2006-10-05 00:40:34 +02:00
|
|
|
3) Make the maximum zone name length dependent on LOGFORMAT.
|
|
|
|
|
2006-10-08 19:06:52 +02:00
|
|
|
4) Clear provider marks in POSTROUTING when HIGH_ROUTE_MARKS=Yes.
|
|
|
|
|
2006-10-09 19:10:24 +02:00
|
|
|
5) Add COMMENT support.
|
|
|
|
|
2006-10-11 18:46:26 +02:00
|
|
|
6) Add macro.RDP.
|
|
|
|
|
2006-10-13 22:13:40 +02:00
|
|
|
7) Add maclog extension file.
|
2006-10-12 23:56:16 +02:00
|
|
|
|
2006-10-17 16:52:09 +02:00
|
|
|
8) Rename SUBNET column in the masq file.
|
|
|
|
|
2006-10-18 21:56:22 +02:00
|
|
|
9) Allow exclusion in /etc/shorewall/hosts.
|
|
|
|
|
2006-10-19 18:56:29 +02:00
|
|
|
10) Eliminate extra jumps to policy chains
|
|
|
|
|
2006-08-28 22:22:56 +02:00
|
|
|
Changes in 3.3.1
|
|
|
|
|
|
|
|
1) Load the proxyarp lib when 'proxyarp' option is specified.
|
|
|
|
|
2006-08-30 19:06:23 +02:00
|
|
|
2) Implement default action/macros at the individual policy level.
|
|
|
|
|
2006-09-06 19:12:00 +02:00
|
|
|
3) Add logfile name to output of "shorewall show log" and "shorewall
|
|
|
|
logwatch".
|
|
|
|
|
|
|
|
|
2006-08-30 19:06:23 +02:00
|
|
|
|
2006-07-04 19:15:33 +02:00
|
|
|
|