Document TC fixes

This commit is contained in:
Tom Eastep 2011-05-01 06:39:17 -07:00
parent f8c433c2b3
commit 44bd1708f1
2 changed files with 21 additions and 1 deletions

View File

@ -3,6 +3,8 @@ Changes in Shorewall 4.4.19.2
1) Restore the ability to have IPSET names in the ORIGINAL DEST column 1) Restore the ability to have IPSET names in the ORIGINAL DEST column
of a DNAT or REDIRECT rule. of a DNAT or REDIRECT rule.
2) Correct several complex TC issues reported by Mr Dash4.
Changes in Shorewall 4.4.19.1 Changes in Shorewall 4.4.19.1
1) Eliminate silly duplicate rule when stopped. 1) Eliminate silly duplicate rule when stopped.

View File

@ -28,7 +28,25 @@ VI. PROBLEMS CORRECTED AND NEW FEATURES IN PRIOR RELEASES
will implicitly add this rule will implicitly add this rule
ACCEPT net dmz:10.1.1.2 tcp 80 ACCEPT net dmz:10.1.1.2 tcp 80
2) Two problems with complex TC have been corrected:
a) The following entry in /etc/shorewall/tcclasses
A:1 - 10*full/100:50ms 20*full/100 1 tcp-ack
produced this error:
ERROR: Unknown INTERFACE (A) : /etc/shorewall/tcclasses
This has been corrected by requiring that class numbers
containing a-f or A-F must be prefaced by '0x'.
b) Shorewall reserves class number 1 for the root class of the
queuing discipline. Definining class 1 in
/etc/shorewall/tcclasses was previoulsly escaping detection by
the compiler, resulting in a run-time error.
4.4.19.1 4.4.19.1