2008-12-16 17:54:06 +01:00
|
|
|
Shorewall 4.3.4
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2008-12-13 21:45:23 +01:00
|
|
|
Notice:
|
|
|
|
|
2008-12-16 17:54:06 +01:00
|
|
|
It was previously my intention to defer release of IPv6 support until
|
|
|
|
4.4. That plan was based on an architecture that supported a single
|
|
|
|
configuration for both IPv4 and IPv6.
|
2008-12-13 21:45:23 +01:00
|
|
|
|
2008-12-16 17:54:06 +01:00
|
|
|
Splitting IPv6 support out into separate products has made adding that
|
|
|
|
support an order of magnitude easier and less invasive. So it is my
|
|
|
|
current plan to release IPv6 support in a future 4.2.x release.
|
2008-12-13 21:45:23 +01:00
|
|
|
|
2008-12-16 17:54:06 +01:00
|
|
|
I am therefore opening the testing of the development branch to a wider
|
|
|
|
audience.
|
2008-12-13 21:45:23 +01:00
|
|
|
|
2008-12-07 19:17:26 +01:00
|
|
|
----------------------------------------------------------------------------
|
2008-12-11 00:24:55 +01:00
|
|
|
R E L E A S E 4 . 3 H I G H L I G H T S
|
2008-12-07 19:17:26 +01:00
|
|
|
----------------------------------------------------------------------------
|
2008-12-11 00:24:55 +01:00
|
|
|
1) Support is included for IPv6.
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2008-12-13 16:49:48 +01:00
|
|
|
Minimun system requirements:
|
|
|
|
|
2008-12-14 03:06:59 +01:00
|
|
|
- Kernel 2.6.25 or later.
|
2008-12-13 16:49:48 +01:00
|
|
|
- iptables 1.4.0 or later with 1.4.1 strongly recommended.
|
|
|
|
- Perl 5.10 if you wish to use DNS names in your IPv6 config files.
|
|
|
|
In that case you will also have to install Perl Socket6 support.
|
|
|
|
|
2008-12-16 17:54:06 +01:00
|
|
|
Problems Corrected in 4.3.4
|
2008-12-11 20:24:34 +01:00
|
|
|
|
2008-12-16 17:54:06 +01:00
|
|
|
1) Previously, an extra 'done' could be emitted in the generated shell
|
|
|
|
script resulting in a shell syntax error at run-time.
|
2008-12-13 16:49:48 +01:00
|
|
|
|
2008-12-16 17:54:06 +01:00
|
|
|
2) In IPv6, ipranges were previously not supported even when the
|
|
|
|
kernel and ip6tables included support for them.
|
2008-12-13 16:49:48 +01:00
|
|
|
|
2008-12-16 17:54:06 +01:00
|
|
|
3) An optimization in all Shorewall-perl 4.2 and 4.3 versions could
|
|
|
|
cause undesirable side effects. The optimization deleted the
|
|
|
|
<interface>_in and <interface>_fwd chains and moved their rules
|
|
|
|
to the appropriate rules chain (a <zone>2<xxx> chain).
|
2008-12-11 20:24:34 +01:00
|
|
|
|
2008-12-16 17:54:06 +01:00
|
|
|
This worked badly in cases where a zone was associated with more
|
|
|
|
than one interface. Rules could be duplicated or, worse, a rule
|
|
|
|
that was intended for only input from one of the zone's interfaces
|
|
|
|
would be applied to input from all of the zone's interfaces.
|
|
|
|
|
|
|
|
This problem has been corrected so that an interface-related
|
|
|
|
chains is only deleted if:
|
2008-12-11 20:24:34 +01:00
|
|
|
|
2008-12-16 17:54:06 +01:00
|
|
|
a) the chain has no rules in it; or
|
|
|
|
b) the interface is associated with only one zone and that zone is
|
|
|
|
associated with only that interface in which case it is safe to
|
|
|
|
move the rules.
|
2008-12-12 01:59:42 +01:00
|
|
|
|
2008-12-16 17:54:06 +01:00
|
|
|
Other Changes in 4.3.4
|
2008-12-13 00:20:47 +01:00
|
|
|
|
2008-12-16 17:54:06 +01:00
|
|
|
1) Shorewall and Shorewall Lite now show only IPv4 connections in the
|
|
|
|
output of 'shorewall show connections', 'shorewall-lite show
|
|
|
|
connections', 'shorewall dump' and 'shorewall-lite dump'.
|
2008-12-14 03:06:59 +01:00
|
|
|
|
2008-12-16 18:11:47 +01:00
|
|
|
2) The Shorewall and Shorewall lite commands that show log messages
|
|
|
|
('shorewall show log', ...) now show only IPv4 messages. The
|
|
|
|
corresponding commands in Shorewall6 and Shorewall6 Lite only show
|
|
|
|
IPv6 messages.
|
|
|
|
|
2008-12-07 19:17:26 +01:00
|
|
|
Migration Issues.
|
|
|
|
|
2008-12-11 20:24:34 +01:00
|
|
|
None.
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2008-12-11 00:24:55 +01:00
|
|
|
New Features in Shorewall 4.3
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2008-12-11 00:24:55 +01:00
|
|
|
1) Two new packages are included:
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2008-12-11 00:24:55 +01:00
|
|
|
a) Shorewall6 - analagous to Shorewall-common but handles IPv6
|
|
|
|
rather than IPv4.
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2008-12-11 00:24:55 +01:00
|
|
|
b) Shorewall6-lite - analagous to Shorewall-lite but handles IPv6
|
|
|
|
rather than IPv4.
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2008-12-11 00:24:55 +01:00
|
|
|
The packages store their configurations in /etc/shorewall6/ and
|
|
|
|
/etc/shorewall6-lite/ respectively.
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2008-12-11 00:24:55 +01:00
|
|
|
The fact that the packages are separate from their IPv4 counterparts
|
|
|
|
means that you control IPv4 and IPv6 traffic separately (the same
|
|
|
|
way that Netfilter does). Starting/Stopping the firewall for one
|
|
|
|
address family has no effect on the other address family.
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2008-12-11 00:24:55 +01:00
|
|
|
Other features of Shorewall6 are:
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2008-12-11 00:24:55 +01:00
|
|
|
a) There is no NAT of any kind (most people see this as a giant step
|
|
|
|
forward). When an ISP assigns you a public IPv6 address, you are
|
|
|
|
actually assigned an IPv6 'prefix' which is like an IPv4
|
2008-12-12 01:08:03 +01:00
|
|
|
subnet. A 64-bit prefix allows 4 billion squared individual hosts
|
|
|
|
(the size of the current IPv4 address space squared).
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2008-12-11 00:24:55 +01:00
|
|
|
b) The default zone type is ipv6.
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2008-12-11 00:24:55 +01:00
|
|
|
c) The currently-supported interface options in Shorewall6 are:
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2008-12-11 00:24:55 +01:00
|
|
|
blacklist
|
|
|
|
bridge
|
2008-12-12 17:08:20 +01:00
|
|
|
dhcp
|
2008-12-14 03:06:59 +01:00
|
|
|
nosmurfs (traps multicast and Subnet-router anycast addresses
|
|
|
|
used as the packet source address).
|
2008-12-11 00:24:55 +01:00
|
|
|
optional
|
|
|
|
routeback
|
|
|
|
sourceroute
|
|
|
|
tcpflags
|
|
|
|
mss
|
2008-12-12 01:59:42 +01:00
|
|
|
forward (setting it to 0 makes the router behave like a host
|
|
|
|
on that interface rather than like a router).
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2008-12-11 00:24:55 +01:00
|
|
|
d) The currently-supported host options in Shorewall6 are:
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2008-12-11 00:24:55 +01:00
|
|
|
blacklist
|
|
|
|
routeback
|
|
|
|
tcpflags
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2008-12-13 18:00:11 +01:00
|
|
|
e) Traffic Shaping is disabled by default. The tcdevices and
|
|
|
|
tcclasses files are address-family independent so
|
|
|
|
to use the Shorewall builtin Traffic Shaper, TC_ENABLED=Internal
|
|
|
|
should be specified in Shorewall or in Shorewall6 but not in
|
|
|
|
both. In the configuration where the internal traffic shaper is
|
|
|
|
not enabled, CLEAR_TC=No should be specified.
|
|
|
|
|
|
|
|
tcfilters are not available in Shorewall6.
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2008-12-11 20:24:34 +01:00
|
|
|
f) When both an interface and an address or address list need to
|
2008-12-11 00:24:55 +01:00
|
|
|
be specified in a rule, the address or list must be enclosed in
|
2008-12-13 21:45:23 +01:00
|
|
|
angle brackets. Example:
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2008-12-13 00:20:47 +01:00
|
|
|
#ACTION SOURCE DEST
|
2008-12-13 21:45:23 +01:00
|
|
|
ACCEPT net:eth0:<2001:19f0:feee::dead:beef:cafe> dmz
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2008-12-11 20:24:34 +01:00
|
|
|
Note that this includes MAC addresses as well as IPv6 addresses.
|
|
|
|
|
|
|
|
The HOSTS column in /etc/shorewall6/hosts also uses this
|
|
|
|
convention:
|
|
|
|
|
2008-12-12 17:08:20 +01:00
|
|
|
#ZONE HOSTS OPTIONS
|
2008-12-13 21:45:23 +01:00
|
|
|
chat6 eth0:<2001:19f0:feee::dead:beef:cafe>
|
2008-12-12 17:08:20 +01:00
|
|
|
|
|
|
|
Even when an interface is not specified, it is permitted to
|
2008-12-13 21:45:23 +01:00
|
|
|
enclose addresses in <> to improve readability. Example:
|
2008-12-12 17:08:20 +01:00
|
|
|
|
|
|
|
#ACTION SOURCE DEST
|
2008-12-13 21:45:23 +01:00
|
|
|
ACCEPT net:<2001:1::1> $FW
|
2008-12-11 20:24:34 +01:00
|
|
|
|
2008-12-14 23:15:55 +01:00
|
|
|
g) The options available in shorewall6.conf are a subset of those
|
2008-12-11 00:24:55 +01:00
|
|
|
available in shorewall.conf.
|
2008-12-11 20:24:34 +01:00
|
|
|
|
2008-12-14 23:15:55 +01:00
|
|
|
h) The Socket6.pm Perl module is required if you include DNS names
|
2008-12-11 20:24:34 +01:00
|
|
|
in your Shorewall6 configuration. Note that it is loaded the
|
|
|
|
first time that a DNS name is encountered so if it is missing,
|
|
|
|
you get a message similar to this one:
|
|
|
|
|
|
|
|
...
|
|
|
|
Checking /etc/shorewall6/rules...
|
|
|
|
Can't locate Socket6.pm in @INC (@INC contains: /root ...
|
|
|
|
teastep@ursa:~/Configs/standalone6$
|