Shorewall 2.0.15

git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@1897 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
This commit is contained in:
teastep 2005-01-12 21:02:14 +00:00
parent 3f706c77e7
commit 5d8c550d88
10 changed files with 20 additions and 9 deletions

View File

@ -1,11 +1,11 @@
# #
# Shorewall 2.0 /etc/shorewall/action.AllowTrcrt # Shorewall 2.0 /etc/shorewall/action.AllowTrcrt
# #
# This action accepts Traceroute (for up to 20 hops): # This action accepts Traceroute (for up to 30 hops):
# #
###################################################################################### ######################################################################################
#TARGET SOURCE DEST PROTO DEST SOURCE RATE USER/ #TARGET SOURCE DEST PROTO DEST SOURCE RATE USER/
# PORT PORT(S) LIMIT GROUP # PORT PORT(S) LIMIT GROUP
ACCEPT - - udp 33434:33454 #UDP Traceroute ACCEPT - - udp 33434:33524 #UDP Traceroute
ACCEPT - - icmp 8 #ICMP Traceroute ACCEPT - - icmp 8 #ICMP Traceroute
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE

View File

@ -1860,7 +1860,7 @@ setup_syn_flood_chain ()
run_iptables -N $chain run_iptables -N $chain
run_iptables -A $chain -m limit --limit $limit $limit_burst -j RETURN run_iptables -A $chain -m limit --limit $limit $limit_burst -j RETURN
[ -n "$3" ] && \ [ -n "$3" ] && \
log_rule_limit $3 $chain $chain DROP "-m limit --limit 5/min --limit-burst 5" "" "" log_rule_limit $3 $chain DROP "-m limit --limit 5/min --limit-burst 5" ""
run_iptables -A $chain -j DROP run_iptables -A $chain -j DROP
} }

View File

@ -1 +1 @@
2.0.14 2.0.15

View File

@ -113,3 +113,5 @@ Changes in 2.0.14
Changes in 2.0.15 Changes in 2.0.15
1) Increased port range for Traceroute. 1) Increased port range for Traceroute.
2) Corrected port of rate-limit logging change.

View File

@ -28,7 +28,7 @@
# shown below. Simply run this script to revert to your prior version of # shown below. Simply run this script to revert to your prior version of
# Shoreline Firewall. # Shoreline Firewall.
VERSION=2.0.14 VERSION=2.0.15
usage() # $1 = exit status usage() # $1 = exit status
{ {

View File

@ -1860,7 +1860,7 @@ setup_syn_flood_chain ()
run_iptables -N $chain run_iptables -N $chain
run_iptables -A $chain -m limit --limit $limit $limit_burst -j RETURN run_iptables -A $chain -m limit --limit $limit $limit_burst -j RETURN
[ -n "$3" ] && \ [ -n "$3" ] && \
log_rule_limit $3 $chain $chain DROP "-m limit --limit 5/min --limit-burst 5" "" "" log_rule_limit $3 $chain DROP "-m limit --limit 5/min --limit-burst 5" ""
run_iptables -A $chain -j DROP run_iptables -A $chain -j DROP
} }

View File

@ -22,7 +22,7 @@
# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA # Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA
# #
VERSION=2.0.14 VERSION=2.0.15
usage() # $1 = exit status usage() # $1 = exit status
{ {

View File

@ -269,3 +269,10 @@ Problems corrected in 2.0.15
1) The range of ports opened by the AllowTrcrt action has been 1) The range of ports opened by the AllowTrcrt action has been
expanded to 33434:33524. expanded to 33434:33524.
2) Code mis-ported from 2.2.0 caused the following error during
"shorewall start" where SYN rate-limiting is present in
/etc/shorewall/policy:
Bad argument `DROP'
Try `iptables -h' or 'iptables --help' for more information.

View File

@ -1,5 +1,5 @@
%define name shorewall %define name shorewall
%define version 2.0.14 %define version 2.0.15
%define release 1 %define release 1
%define prefix /usr %define prefix /usr
@ -141,6 +141,8 @@ fi
%doc COPYING INSTALL changelog.txt releasenotes.txt tunnel %doc COPYING INSTALL changelog.txt releasenotes.txt tunnel
%changelog %changelog
* Wed Jan 12 2005 Tom Eastep tom@shorewall.net
- Updated to 2.0.15-1
* Mon Jan 03 2005 Tom Eastep tom@shorewall.net * Mon Jan 03 2005 Tom Eastep tom@shorewall.net
- Updated to 2.0.14-1 - Updated to 2.0.14-1
* Thu Dec 02 2004 Tom Eastep tom@shorewall.net * Thu Dec 02 2004 Tom Eastep tom@shorewall.net

View File

@ -26,7 +26,7 @@
# You may only use this script to uninstall the version # You may only use this script to uninstall the version
# shown below. Simply run this script to remove Seattle Firewall # shown below. Simply run this script to remove Seattle Firewall
VERSION=2.0.14 VERSION=2.0.15
usage() # $1 = exit status usage() # $1 = exit status
{ {