From 22180d58044cb0fbd0f76635efcf4b0f8cdb120b Mon Sep 17 00:00:00 2001 From: teastep Date: Wed, 28 Jan 2009 20:50:25 +0000 Subject: [PATCH] Tweak FAQ 80a git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9351 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb --- docs/FAQ.xml | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/docs/FAQ.xml b/docs/FAQ.xml index a69aed429..eb5f6b123 100644 --- a/docs/FAQ.xml +++ b/docs/FAQ.xml @@ -2203,11 +2203,12 @@ We have an error talking to the kernel Answer: Shorewall implements a stateful firewall which requires connection tracking be present in - ip6tables and in the kernel. Kernel's before 2.6.20 didn't have + ip6tables and in the kernel. Linux kernel's before 2.6.20 didn't have connection tracking for IPv6. So we could not even start to develop - IPv6 support until then. By the time that distributions began shipping - with kernels that supported IPv6 connection tracking, they were - shipping with 2.6.25. So that is what we developed IPv6 support on and + IPv6 support until 2.6.20. We understand that there were significant + problems with the facility until at least kernel 2.6.23. When + distributions began offering IPv6 connection tracking support, it was + with kernel 2.6.25. So that is what we developed IPv6 support on and that's all that it has been tested on. If you are running 2.6.20 or later, you can try to run Shorewall6 by hacking /usr/share/shorewall-perl/prog.footer6