mirror of
https://gitlab.com/shorewall/code.git
synced 2024-12-22 22:30:58 +01:00
b6e0759a4e
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@8980 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
72 lines
2.2 KiB
Plaintext
72 lines
2.2 KiB
Plaintext
Shorewall 4.3.0
|
|
|
|
----------------------------------------------------------------------------
|
|
R E L E A S E 4 . 3 H I G H L I G H T S
|
|
----------------------------------------------------------------------------
|
|
1) Support is included for IPv6.
|
|
|
|
Migration Issues.
|
|
|
|
None.
|
|
|
|
New Features in Shorewall 4.3
|
|
|
|
1) Two new packages are included:
|
|
|
|
a) Shorewall6 - analagous to Shorewall-common but handles IPv6
|
|
rather than IPv4.
|
|
|
|
b) Shorewall6-lite - analagous to Shorewall-lite but handles IPv6
|
|
rather than IPv4.
|
|
|
|
The packages store their configurations in /etc/shorewall6/ and
|
|
/etc/shorewall6-lite/ respectively.
|
|
|
|
The fact that the packages are separate from their IPv4 counterparts
|
|
means that you control IPv4 and IPv6 traffic separately (the same
|
|
way that Netfilter does). Starting/Stopping the firewall for one
|
|
address family has no effect on the other address family.
|
|
|
|
Other features of Shorewall6 are:
|
|
|
|
a) There is no NAT of any kind (most people see this as a giant step
|
|
forward). When an ISP assigns you a public IPv6 address, you are
|
|
actually assigned an IPv6 'prefix' which is like an IPv4
|
|
subnet. A 96-bit prefix allows 4 billion individual hosts (the
|
|
size of the current IPv4 address space).
|
|
|
|
b) The default zone type is ipv6.
|
|
|
|
c) The currently-supported interface options in Shorewall6 are:
|
|
|
|
blacklist
|
|
bridge
|
|
optional
|
|
routeback
|
|
sourceroute
|
|
tcpflags
|
|
mss
|
|
forward (replaces the IP_FORWARDING .conf option -- forwarding
|
|
is enabled on a per-interface basis in IPv6).
|
|
|
|
d) The currently-supported host options in Shorewall6 are:
|
|
|
|
blacklist
|
|
routeback
|
|
tcpflags
|
|
|
|
e) Traffic Shaping and Multi-ISP support are currently disabled. Packet
|
|
marking and connection marking are available to feed your current
|
|
traffic shaping defined in Shorewall.
|
|
|
|
f) When both an interface and an IPv6 address or address list need to
|
|
be specified in a rule, the address or list must be enclosed in
|
|
square brackets. Example:
|
|
|
|
ACCEPT net:eth0:[2001:19f0:feee::dead:beef:cafe] dmz
|
|
|
|
g) There are currently no Shorewall6 or Shorewall6-lite manpages.
|
|
|
|
h) The options available in shorewall6.conf are a subset of those
|
|
available in shorewall.conf.
|