1
iptables v1.2.10 Changelog
2
======================================================================
3
This version requires kernel >= 2.4.4
4
This version recommends kernel >= 2.4.18
8
- physdev match: fix new structure layout for kernel > 2.6.0-test8
11
- Better 64bit / 32bit split architecture detection
12
- IPv6 LOG target: Fix compiler warnings on 64bit
13
- LOG target: Fix compiler warnings on 64bit
14
- IPv6 MARK target: Use full 64bit mark on 64bit archs
15
- MARK target: Use full 64bit mark on 64bit archs
16
- SAME target: Fix 64bit/32bit splitarch problems
17
- ULOG target: Fix 64bit/32bit splitarch problems
18
- conntrack match: Fix 64bit/32bit splitarch problem
19
- IPv6 limit match: Fix 64bit/32bit splitarch problem
20
- limit match: Fix 64bit/32bit splitarch problem
21
- IPv6 mark match: Use full 64bit mark on 64bit archs
22
- mark match: Use full 64bit mark on 64bit archs
23
- owner match: Fix compiler warnings on 64bit
26
- connbytes match: Fix signedness / unsigned issue
29
- connlimit match: Fix '/0' netmask
32
- ipv6 owner match: fix possibly not zero terminated string
33
- helper match: fix possibly not zero terminated string
34
- recent match: fix possibly not zero terminated string
37
- ICMP match: fix '--icmp-type any' case
40
- CONNMARK target: major update (add mark/mask matching)
43
- DSCP target: Fix cosmetic help message problem
46
- string match: Fix iptables-save/restore for ascii strings with spaces
49
- ip(6)tables-restore: Make sure matches are used in the same order
52
- ip(6)tables-restore: Fix '--verbose' option
53
- ip(6)tables-restore: Add '--test' option
54
- ip(6)tables-restore: Complain about missing 'COMMIT'
57
- ip(6)tables-restore: Allow embedding of quote character in quoted strings
60
- libipq: Protect against spoofed queue messages (check if sender is kernel)
66
- time match: add 'datestart' and 'datestop' parameters
69
- modular manpage build, depending on actually compiled-in features
72
- additional documentation in manpage snippets formerly missing
75
- support new CLUSTERIP Target
78
- support new account match
81
- support new connrate match
84
- support new dstlimit match
87
- support new 'set' match / 'SET' target
90
- osf match: add support for netlink reporting
93
- new SCTP protocol match
97
Please note: Since version 1.2.7a, patch-o-matic is now no longer part of
98
iptables but rather distributed as a seperate package
99
(ftp://ftp.netfilter.org/pub/patch-o-matic/)
101
Please also note: Since Kernel 2.6.x is out, we now use patch-o-matic-ng, distributed as seperate package:
102
(ftp://ftp.netfilter.org/pub/patch-o-matic-ng)