2002-08-07 16:28:04 +02:00
|
|
|
|
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
|
|
|
|
|
<html>
|
|
|
|
|
<head>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
2002-09-16 19:02:45 +02:00
|
|
|
|
<meta http-equiv="Content-Type"
|
|
|
|
|
content="text/html; charset=windows-1252">
|
2002-08-07 16:28:04 +02:00
|
|
|
|
<title>Shoreline Firewall (Shorewall) 1.3</title>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
<base target="_self">
|
2002-08-07 16:28:04 +02:00
|
|
|
|
</head>
|
2002-09-16 19:02:45 +02:00
|
|
|
|
<body>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
2002-09-16 19:02:45 +02:00
|
|
|
|
<table border="0" cellpadding="0" cellspacing="4"
|
|
|
|
|
style="border-collapse: collapse;" width="100%" id="AutoNumber3"
|
|
|
|
|
bgcolor="#4b017c">
|
2002-10-09 17:47:48 +02:00
|
|
|
|
<tbody>
|
|
|
|
|
<tr>
|
|
|
|
|
<td width="100%" height="90">
|
|
|
|
|
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
2002-09-16 19:02:45 +02:00
|
|
|
|
<h1 align="center"> <font size="4"><i> <a
|
2002-09-30 20:11:25 +02:00
|
|
|
|
href="http://www.cityofshoreline.com"> <img vspace="4" hspace="4"
|
|
|
|
|
alt="Shorwall Logo" height="70" width="85" align="left"
|
|
|
|
|
src="images/washington.jpg" border="0">
|
2002-10-09 17:47:48 +02:00
|
|
|
|
</a></i></font><font color="#ffffff">Shorewall
|
|
|
|
|
1.3 - <font size="4">"<i>iptables made easy"</i></font></font></h1>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
2002-09-30 20:11:25 +02:00
|
|
|
|
<div align="center"><a href="1.2" target="_top"><font
|
|
|
|
|
color="#ffffff">Shorewall 1.2 Site here</font></a><br>
|
2002-10-09 17:47:48 +02:00
|
|
|
|
</div>
|
|
|
|
|
<br>
|
|
|
|
|
</td>
|
|
|
|
|
</tr>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
</tbody>
|
2002-09-16 19:02:45 +02:00
|
|
|
|
</table>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
<div align="center">
|
|
|
|
|
<center>
|
2002-09-16 19:02:45 +02:00
|
|
|
|
<table border="0" cellpadding="0" cellspacing="0"
|
|
|
|
|
style="border-collapse: collapse;" width="100%" id="AutoNumber4">
|
2002-10-09 17:47:48 +02:00
|
|
|
|
<tbody>
|
|
|
|
|
<tr>
|
|
|
|
|
<td width="90%">
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
2002-09-16 19:02:45 +02:00
|
|
|
|
<h2 align="left">What is it?</h2>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
<p>The Shoreline Firewall, more commonly known as "Shorewall", is a
|
|
|
|
|
<a href="http://www.netfilter.org">Netfilter</a> (iptables) based firewall
|
|
|
|
|
that can be used on a dedicated firewall system, a multi-function
|
|
|
|
|
gateway/router/server or on a standalone GNU/Linux system.</p>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
<p>This program is free software; you can redistribute it and/or modify
|
|
|
|
|
it under the terms of <a
|
|
|
|
|
href="http://www.gnu.org/licenses/gpl.html">Version 2 of the GNU General
|
|
|
|
|
Public License</a> as published by the Free Software Foundation.<br>
|
|
|
|
|
<br>
|
|
|
|
|
This program is distributed in the hope
|
|
|
|
|
that it will be useful, but WITHOUT ANY WARRANTY; without
|
|
|
|
|
even the implied warranty of MERCHANTABILITY or FITNESS FOR
|
|
|
|
|
A PARTICULAR PURPOSE. See the GNU General Public License for
|
|
|
|
|
more details.<br>
|
|
|
|
|
<br>
|
|
|
|
|
You should have received a copy of the
|
|
|
|
|
GNU General Public License along with this program; if
|
|
|
|
|
not, write to the Free Software Foundation, Inc., 675 Mass
|
|
|
|
|
Ave, Cambridge, MA 02139, USA</p>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2002-08-07 16:28:04 +02:00
|
|
|
|
<p><a href="copyright.htm">Copyright 2001, 2002 Thomas M. Eastep</a></p>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
|
2002-09-30 20:11:25 +02:00
|
|
|
|
<p> <a href="http://leaf.sourceforge.net" target="_top"><img
|
2002-09-16 19:02:45 +02:00
|
|
|
|
border="0" src="images/leaflogo.gif" width="49" height="36">
|
2002-10-09 17:47:48 +02:00
|
|
|
|
</a>Jacques Nilo and Eric Wolzak have
|
|
|
|
|
a LEAF distribution called <i>Bering</i> that features
|
|
|
|
|
Shorewall-1.3.3 and Kernel-2.4.18. You can find their work at:
|
|
|
|
|
<a href="http://leaf.sourceforge.net/devel/jnilo"> http://leaf.sourceforge.net/devel/jnilo</a></p>
|
|
|
|
|
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
2002-08-22 23:33:54 +02:00
|
|
|
|
<h2>News</h2>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<h2></h2>
|
|
|
|
|
|
|
|
|
|
<p><b>10/9/2002 - Shorewall 1.3.9b<EFBFBD></b><b><img border="0"
|
2002-09-30 20:11:25 +02:00
|
|
|
|
src="images/new10.gif" width="28" height="12" alt="(New)">
|
2002-10-09 17:47:48 +02:00
|
|
|
|
</b></p>
|
|
|
|
|
This release rolls up fixes to the installer and to the firewall script.<br>
|
|
|
|
|
<b><br>
|
|
|
|
|
10/6/2002 - Shorewall.net now running on RH8.0 </b><b><img border="0"
|
2002-09-30 20:11:25 +02:00
|
|
|
|
src="images/new10.gif" width="28" height="12" alt="(New)">
|
2002-10-09 17:47:48 +02:00
|
|
|
|
</b><br>
|
|
|
|
|
<br>
|
|
|
|
|
The firewall and server here at shorewall.net are now running RedHat release
|
|
|
|
|
8.0.<br>
|
|
|
|
|
|
|
|
|
|
<p><b>9/30/2002 - Shorewall 1.3.9a</b><b>
|
|
|
|
|
</b></p>
|
|
|
|
|
Roles up the fix for broken tunnels.<br>
|
|
|
|
|
|
|
|
|
|
<p><b>9/30/2002 - TUNNELS Broken in 1.3.9!!!</b><b>
|
|
|
|
|
</b></p>
|
|
|
|
|
<img src="images/j0233056.gif" alt="Brown Paper Bag"
|
|
|
|
|
width="50" height="86" align="left">
|
|
|
|
|
There is an updated firewall script at <a
|
|
|
|
|
href="ftp://www.shorewall.net/pub/shorewall/errata/1.3.9/firewall"
|
|
|
|
|
target="_top">ftp://www.shorewall.net/pub/shorewall/errata/1.3.9/firewall</a>
|
|
|
|
|
-- copy that file to /usr/lib/shorewall/firewall.<br>
|
|
|
|
|
|
|
|
|
|
<p><b><br>
|
|
|
|
|
</b></p>
|
|
|
|
|
|
|
|
|
|
<p><b><br>
|
|
|
|
|
</b></p>
|
|
|
|
|
|
|
|
|
|
<p><b><br>
|
|
|
|
|
9/28/2002 - Shorewall 1.3.9<EFBFBD></b><b> </b></p>
|
|
|
|
|
|
|
|
|
|
|
2002-09-16 19:02:45 +02:00
|
|
|
|
<p>In this version:<br>
|
2002-10-09 17:47:48 +02:00
|
|
|
|
</p>
|
|
|
|
|
|
|
|
|
|
|
2002-08-22 23:33:54 +02:00
|
|
|
|
<ul>
|
2002-10-09 17:47:48 +02:00
|
|
|
|
<li><a href="configuration_file_basics.htm#dnsnames">DNS
|
|
|
|
|
Names</a> are now allowed in Shorewall config files (although I recommend
|
|
|
|
|
against using them).</li>
|
|
|
|
|
<li>The connection SOURCE may now be qualified by both
|
|
|
|
|
interface and IP address in a <a href="Documentation.htm#Rules">Shorewall
|
|
|
|
|
rule</a>.</li>
|
|
|
|
|
<li>Shorewall startup is now disabled after initial installation
|
|
|
|
|
until the file /etc/shorewall/startup_disabled is removed. This avoids
|
|
|
|
|
nasty surprises at reboot for users who install Shorewall but don't
|
|
|
|
|
configure it.</li>
|
|
|
|
|
<li>The 'functions' and 'version' files and the 'firewall'
|
|
|
|
|
symbolic link have been moved from /var/lib/shorewall to /usr/lib/shorewall
|
|
|
|
|
to appease the LFS police at Debian.<br>
|
|
|
|
|
</li>
|
|
|
|
|
|
|
|
|
|
|
2002-08-22 23:33:54 +02:00
|
|
|
|
</ul>
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<p><b>9/23/2002 - Full Shorewall Site/Mailing List Archive Search Capability
|
|
|
|
|
Restored</b><b> </b><br>
|
|
|
|
|
</p>
|
|
|
|
|
<img src="images/j0233056.gif" alt="Brown Paper Bag"
|
2002-09-30 20:11:25 +02:00
|
|
|
|
width="50" height="86" align="left">
|
2002-10-09 17:47:48 +02:00
|
|
|
|
A couple of recent configuration changes at www.shorewall.net
|
|
|
|
|
broke the Search facility:<br>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<blockquote>
|
|
|
|
|
|
2002-09-30 20:11:25 +02:00
|
|
|
|
<ol>
|
2002-10-09 17:47:48 +02:00
|
|
|
|
<li>Mailing List Archive Search was not available.</li>
|
|
|
|
|
<li>The Site Search index was incomplete</li>
|
|
|
|
|
<li>Only one page of matches was presented.</li>
|
|
|
|
|
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
|
|
|
|
</ol>
|
2002-10-09 17:47:48 +02:00
|
|
|
|
</blockquote>
|
|
|
|
|
Hopefully these problems are now corrected.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<p><b>9/18/2002 - Debian 1.3.8 Packages Available<6C></b><b>
|
|
|
|
|
</b><br>
|
|
|
|
|
</p>
|
|
|
|
|
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
2002-09-30 20:11:25 +02:00
|
|
|
|
<p>Apt-get sources listed at <a
|
|
|
|
|
href="http://security.dsi.unimi.it/%7Elorenzo/debian.html">http://security.dsi.unimi.it/~lorenzo/debian.html</a></p>
|
2002-10-09 17:47:48 +02:00
|
|
|
|
<b> </b>
|
|
|
|
|
|
|
|
|
|
|
2002-09-30 20:11:25 +02:00
|
|
|
|
<p><b>9/16/2002 - Shorewall 1.3.8</b><b> </b></p>
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
|
2002-09-30 20:11:25 +02:00
|
|
|
|
<p>In this version:<br>
|
2002-10-09 17:47:48 +02:00
|
|
|
|
</p>
|
|
|
|
|
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
2002-09-16 19:02:45 +02:00
|
|
|
|
<ul>
|
2002-10-09 17:47:48 +02:00
|
|
|
|
<li>A NEWNOTSYN option has been added to
|
|
|
|
|
shorewall.conf. This option determines whether Shorewall accepts
|
|
|
|
|
TCP packets which are not part of an established connection and
|
|
|
|
|
that are not 'SYN' packets (SYN flag on and ACK flag off).</li>
|
|
|
|
|
<li>The need for the 'multi' option to communicate
|
|
|
|
|
between zones za and zb on the same interface is removed in the
|
|
|
|
|
case where the chain 'za2zb' and/or 'zb2za' exists. 'za2zb' will
|
|
|
|
|
exist if:
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
|
2002-09-30 20:11:25 +02:00
|
|
|
|
<ul>
|
2002-10-09 17:47:48 +02:00
|
|
|
|
<li>There is a policy for za to zb; or</li>
|
|
|
|
|
<li>There is at least one rule for za
|
|
|
|
|
to zb. </li>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
|
2002-09-30 20:11:25 +02:00
|
|
|
|
</ul>
|
2002-10-09 17:47:48 +02:00
|
|
|
|
</li>
|
|
|
|
|
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
2002-09-16 19:02:45 +02:00
|
|
|
|
</ul>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
|
2002-09-30 20:11:25 +02:00
|
|
|
|
<ul>
|
2002-10-09 17:47:48 +02:00
|
|
|
|
<li>The /etc/shorewall/blacklist file now
|
|
|
|
|
contains three columns. In addition to the SUBNET/ADDRESS column,
|
|
|
|
|
there are optional PROTOCOL and PORT columns to block only certain
|
|
|
|
|
applications from the blacklisted addresses.<br>
|
|
|
|
|
</li>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
|
2002-09-30 20:11:25 +02:00
|
|
|
|
</ul>
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
|
2002-09-16 19:02:45 +02:00
|
|
|
|
<p><b>9/11/2002 - Debian 1.3.7c Packages Available </b></p>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
|
2002-09-16 19:02:45 +02:00
|
|
|
|
<p>Apt-get sources listed at <a
|
|
|
|
|
href="http://security.dsi.unimi.it/%7Elorenzo/debian.html">http://security.dsi.unimi.it/~lorenzo/debian.html</a>.</p>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
|
2002-09-16 19:02:45 +02:00
|
|
|
|
<p><b>9/2/2002 - Shorewall 1.3.7c</b></p>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
<p>This is a role up of a fix for "DNAT" rules where the source zone
|
|
|
|
|
is $FW (fw).</p>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2002-09-16 19:02:45 +02:00
|
|
|
|
<p><b>8/26/2002 - Shorewall 1.3.7b</b></p>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
<p>This is a role up of the "shorewall refresh" bug fix and the change
|
|
|
|
|
which reverses the order of "dhcp" and "norfc1918" checking.</p>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2002-09-16 19:02:45 +02:00
|
|
|
|
<p><b>8/26/2002 - French FTP Mirror is Operational</b></p>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
|
2002-09-16 19:02:45 +02:00
|
|
|
|
<p><a target="_blank"
|
2002-10-09 17:47:48 +02:00
|
|
|
|
href="ftp://france.shorewall.net/pub/mirrors/shorewall">ftp://france.shorewall.net/pub/mirrors/shorewall</a>
|
|
|
|
|
is now available.</p>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
|
2002-09-16 19:02:45 +02:00
|
|
|
|
<p><b>8/25/2002 - Shorewall Mirror in France </b></p>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<p>Thanks to a Shorewall user in Paris, the Shorewall web site is now
|
|
|
|
|
mirrored at <a target="_top"
|
2002-09-30 20:11:25 +02:00
|
|
|
|
href="http://france.shorewall.net">http://france.shorewall.net</a>.</p>
|
|
|
|
|
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
|
2002-08-07 16:28:04 +02:00
|
|
|
|
<p><a href="News.htm">More News</a></p>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
|
2002-08-22 23:33:54 +02:00
|
|
|
|
<h2><a name="Donations"></a>Donations</h2>
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
</td>
|
|
|
|
|
<td width="88" bgcolor="#4b017c"
|
2002-09-30 20:11:25 +02:00
|
|
|
|
valign="top" align="center"> <a
|
|
|
|
|
href="http://sourceforge.net">M</a></td>
|
2002-10-09 17:47:48 +02:00
|
|
|
|
</tr>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
</tbody>
|
2002-09-16 19:02:45 +02:00
|
|
|
|
</table>
|
2002-10-09 17:47:48 +02:00
|
|
|
|
</center>
|
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
|
2002-09-16 19:02:45 +02:00
|
|
|
|
<table border="0" cellpadding="5" cellspacing="0"
|
|
|
|
|
style="border-collapse: collapse;" width="100%" id="AutoNumber2"
|
|
|
|
|
bgcolor="#4b017c">
|
2002-10-09 17:47:48 +02:00
|
|
|
|
<tbody>
|
|
|
|
|
<tr>
|
|
|
|
|
<td width="100%" style="margin-top: 1px;">
|
|
|
|
|
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
2002-09-16 19:02:45 +02:00
|
|
|
|
<p align="center"><a href="http://www.starlight.org"> <img
|
|
|
|
|
border="4" src="images/newlog.gif" width="57" height="100" align="left"
|
|
|
|
|
hspace="10">
|
2002-10-09 17:47:48 +02:00
|
|
|
|
<20> </a></p>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
<p align="center"><font size="4" color="#ffffff">Shorewall is free but
|
|
|
|
|
if you try it and find it useful, please consider making a donation
|
|
|
|
|
to <a href="http://www.starlight.org"><font
|
2002-09-30 20:11:25 +02:00
|
|
|
|
color="#ffffff">Starlight Children's Foundation.</font></a> Thanks!</font></p>
|
2002-10-09 17:47:48 +02:00
|
|
|
|
</td>
|
|
|
|
|
</tr>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
</tbody>
|
2002-09-16 19:02:45 +02:00
|
|
|
|
</table>
|
2002-10-09 17:47:48 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<p><font size="2">Updated 10/9/2002 - <a href="support.htm">Tom Eastep</a></font>
|
|
|
|
|
|
|
|
|
|
<br>
|
|
|
|
|
</p>
|
2002-09-30 20:11:25 +02:00
|
|
|
|
<br>
|
2002-09-16 19:02:45 +02:00
|
|
|
|
</body>
|
|
|
|
|
</html>
|