Summary: | net-firewall/shorewall-4.4.15.1: Multiple ICMP types are not permitted. | ||
---|---|---|---|
Product: | Gentoo Linux | Reporter: | Navid Zamani <navid.zamani> |
Component: | [OLD] Server | Assignee: | Gentoo Netmon project <netmon> |
Status: | VERIFIED INVALID | ||
Severity: | normal | CC: | rentorbuy |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Package list: | Runtime testing required: | --- |
Description
Navid Zamani
2011-02-25 16:19:18 UTC
Hi Navid, I looked at your problem. I think you misunderstood the documentation or the documentation is wrong. The functionality of multiple icmp-types is no longer present in shorewall. It was removed around version 3.9. I'm sorry if you had problems, but the old stable was really old and I was not able to add all changes to the emerge output. I just recently adopted this packages and was not aware, that the multi-icmp-functionality existed in 3.4 and was dropped. Ah, OK, thank you. :) Sounds like a really pointless change though. So could you point me to where I can find out the reasons it was changed. (I could not find some kind of changelog containing anything related to it. I also could not find an IRC channel to ask them.) Those have to be pretty good, to justify it. After all, you can do it for ports, so why not for ICMP types? The information I have is http://www.mail-archive.com/shorewall-users@lists.sourceforge.net/msg01734.html I looked at the code, the patched was integrated in the code-base. There is also an irc channel on freenode #shorewall :). Looks like they simply were lazy, and instead of implementing it properly (making one rules.conf ICMP rule into multiple iptables rules… or even better: fixing iptables!), they just disabled it. Oh well, I asked in their dead IRC channel, and on their mailing list, and will wait for an answer. Seems like this functionality will return in the 4.4.19 release of shorewall, see: http://www1.shorewall.net/pub/shorewall/development/4.4/shorewall-4.4.19-RC1/releasenotes.txt |