Document application of sfilters to INPUT traffic.

Signed-off-by: Tom Eastep <teastep@shorewall.net>
This commit is contained in:
Tom Eastep
2011-06-08 11:02:39 -07:00
parent 6f3f49e45a
commit b0c47d4f47
2 changed files with 8 additions and 2 deletions

View File

@ -4,6 +4,8 @@ Changes in Shorewall 4.4.20.2
2) Correct tc defect. 2) Correct tc defect.
3) Apply sfilters to INPUT traffic.
Changes in Shorewall 4.4.20.1 Changes in Shorewall 4.4.20.1
1) Corrected FSF address. 1) Corrected FSF address.

View File

@ -15,8 +15,8 @@ VI. PROBLEMS CORRECTED AND NEW FEATURES IN PRIOR RELEASES
4.4.20.2 4.4.20.2
1) Fixed item 1 from 4.4.19.4 was inadvertently omitted from 4.4.20. It 1) Corrected item #1 from 4.4.19.4 was inadvertently omitted from
is now included. 4.4.20. It is now included.
2) A defect introduced in 4.4.20 could cause the following failure at 2) A defect introduced in 4.4.20 could cause the following failure at
start/restart: start/restart:
@ -24,6 +24,10 @@ VI. PROBLEMS CORRECTED AND NEW FEATURES IN PRIOR RELEASES
ERROR: Command "tc qdisc add dev eth0 parent 1:11 handle 1: ERROR: Command "tc qdisc add dev eth0 parent 1:11 handle 1:
sfq quantum 12498 limit 127 perturb 10" failed sfq quantum 12498 limit 127 perturb 10" failed
3) The 'sfilter' interface option introduced in 4.4.20 was only
applied to forwarded traffic. Now it is also applied to traffic
addressed to the firewall itself.
4.4.20.1 4.4.20.1
1) The address of the Free Software Foundation has been corrected in 1) The address of the Free Software Foundation has been corrected in