diff --git a/Shorewall-Website/download.htm b/Shorewall-Website/download.htm index 86d9616c8..843794efe 100644 --- a/Shorewall-Website/download.htm +++ b/Shorewall-Website/download.htm @@ -22,7 +22,7 @@ Texts. A copy of the license is included in the section entitled “GNU Free Documentation License”.

-

2005-01-26
+

2005-02-03


I strongly urge you to read and print a copy of the .

You will probably also want to download the HTML version of the documentation for easy reference.

-

Please check the -errata to see if there are updates that apply to the version -that you have downloaded.

+

Beginning with Shorewall 2.2.0, you will find a file named +known_problems.txt in the download directory. This file lists the known +problems with that version of Shorewall. If corrections are available, +they will be listed in the known problems and you can download them +from the 'errata' subdirectory.
+

+

Example:
+

+

ftp> +cd +pub/shorewall/2.2/shorewall-2.2.0
+250 OK. Current directory is +/pub/shorewall/2.2/shorewall-2.2.0
+ftp> ls
+227 Entering Passive Mode +(206,124,146,177,35,91)
+150 Accepted data connection
+drwxr-sr-x    3 +0        +0            +4096 Feb  1 09:52 .
+drwxr-sr-x    3 +0        +0            +4096 Jan 28 14:28 ..
+-rw-r--r--    1 +0        +0             +500 Jan 28 14:27 2.2.0.md5sums
+drwxr-sr-x    +2 0        +0            +4096 Feb  1 09:51 +errata             +<=== (1)
+-rw-r--r--    +1 0        +0             +156 Feb  1 09:52 known_problems.txt <=== (2)
+-rw-r--r--    1 +0        +0           16059 Jan +24 16:13 patch-2.2.0
+-rwxr-xr-x    1 +0        +0           22963 Jan +24 16:10 releasenotes.txt
+-rw-r--r--    1 +0        +0          100232 Jan 25 +15:58 shorewall-2.2.0-1.noarch.rpm
+-rw-r--r--    1 +0        +0          122161 Jan 25 +15:58 shorewall-2.2.0.tgz
+-rw-r--r--    1 +0        +0         2534077 Jan 28 13:29 +shorewall-docs-html-2.2.0.tgz
+-rw-r--r--    1 +0        +0         4481205 Jan 28 13:29 +shorewall-docs-xml-2.2.0.tgz
+-rw-r--r--    1 +0        +0           93905 Jan +25 15:58 shorewall-lrp-2.2.0.tgz
+226-Options: -a -l
+226 13 matches total
+ftp>
+

+

(1) Directory contraining updates.
+(2) List of known problems, +workarounds and updates.                            +

+

Download Sites:

diff --git a/Shorewall-Website/shorewall_index.htm b/Shorewall-Website/shorewall_index.htm index 9e48b2acd..2c571f83c 100644 --- a/Shorewall-Website/shorewall_index.htm +++ b/Shorewall-Website/shorewall_index.htm @@ -32,7 +32,8 @@ to 2.x releases of Shorewall. For older versions:

href="http://shorewall.net/pub/shorewall/2.2/shorewall-2.2.0/releasenotes.txt">release notes and here are the known -problems.
+problems and updates.

GNU Free Documentation License”.

-

2005-02-01

+

2005-02-05


Table of Contents

Introduction @@ -63,7 +64,9 @@ Shorewall on Mandrake® with a two-interface setup?
License

News

Shorewall + style="text-decoration: underline;">Shorewall +2.0.16
+Shorewall 2.2.0

@@ -158,6 +161,34 @@ of the license is included in the section entitled "GNU Free Documentation License".


News

+02/01/2005 +Shorewall 2.0.16
+

+This release back-ports the DROPINVALID shorewall.conf option from +2.2.0.
+
    +
  1. Recent 2.6 kernels include code that evaluates TCP packets based +on TCP Window analysis. This can cause packets that were previously +classified as NEW or ESTABLISHED to be classified as INVALID.
    +
    +The new kernel code can be disabled by including this command in your +/etc/shorewall/init file:
    +
    +echo 1 > /proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_be_liberal
    +
    +Additional kernel logging about INVALID TCP packets may be obtained by +adding this command to /etc/shorewall/init:
    +
    +echo 1 > /proc/sys/net/ipv4/netfilter/ip_conntrack_log_invalid
    +
    +Traditionally, Shorewall has dropped INVALID TCP packets early. The new +DROPINVALID option allows INVALID packets to be passed through the +normal rules chains by setting DROPINVALID=No.
    +
    +If not specified or if specified as empty (e.g., DROPINVALID="") then +DROPINVALID=Yes is assumed.
    +
  2. +
02/01/2005 Shorewall 2.2.0