More Persistent SNAT tweaks

This commit is contained in:
Tom Eastep 2009-08-15 08:56:05 -07:00
parent c908edab34
commit 201145eed9

View File

@ -173,7 +173,7 @@ None.
want a client to always receive the same source/destination IP
pair. It replaces SAME: which was removed in Shorewall 4.4.0.
To spacify persistence, follow the address range with
To specify persistence, follow the address range with
":persistent".
Example:
@ -185,7 +185,14 @@ None.
iptables.
If you use a capabilities file, you will need to create a new one
as a result of this feature.
as a result of this feature.
WARNING: Linux kernels beginning with 2.6.29 include persistent
SNAT support. If your iptables supports persistent SNAT but your
kernel does not, there is no way for Shorewall to determine that
persistent SNAT isn't going to work. The kernel SNAT code blindly
accepts all SNAT flags without verifying them and returns them to
iptables when asked.
----------------------------------------------------------------------------
N E W F E A T U R E S I N 4 . 4