The Shorewall Team is pleased to announce the availability of Shorewall
4.6.9.

Problems Corrected:

1)  This release contains defect repair from Shorewall 4.6.8.1 and
    earlier releases.

2)  The means for preventing loading of helper modules has been
    clarified in the documentation.

3)  The SetEvent and ResetEvent actions previously set/reset the event
    even if the packet did not match the other specified columns. This
    has been corrected.

4)  Previously, the 'show capabilities' command was ignoring the
    HELPERS setting. This resulted in unwanted modules being autoloaded
    and, when the -f option was given, an incorrect capabilities file
    was generated.

5)  Previously, when 'wait' was specified for an interface, the
    generated script erroneously checked for required interfaces on all
    commands rather than just start, restart and restore.

New Features:

1)  There is now a TCPMSS Target (TCPMSS_TARGET) capability. Your
    iptables and kernel must support this capability in order to use
    the CLAMPMSS option in shorewall.conf and the 'mss=' option in the
    zones, interfaces and hosts files. This capability was added when
    it was learned that Debian on ARM doesn't provide the feature.

    When using a capabilities file from at earlier release, the
    compiler assumes that this capability is available, since most
    distributions have traditionally provided the capability.

2)  The CLI manpages now state explicitly that 'list' and 'ls' are
    synonyms for 'show' and refer the reader to the description of
    'show'.

3)  The complete syntax of each CLI command is now repeated in the
    detailed description of the command in the man pages.

4)  Tuomo Soini has contributed a QUIC macro.

5)  The JabberSecure macro is now deprecated. Configure Jabber to use
    TLS and use the Jabber macro instead. (Tuomo Soini).

6)  The enable and disable commands now execute more quickly on slow
    hardware.

7)  The CLI programs now support a 'reenable' command. This command is
    logically equivalent to a 'disable' command followed by an 'enable'
    command, with the exception that no error is generated if the
    specified interface or provider is disabled at the time the
    command is given.

Thank you for using Shorewall
-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
One dashboard for servers and applications across Physical-Virtual-Cloud 
Widest out-of-the-box monitoring support with 50+ applications
Performance metrics, stats and reports that give you Actionable Insights
Deep dive visibility with transaction tracing using APM Insight.
http://ad.doubleclick.net/ddm/clk/290420510;117567292;y
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to