2
<head><title>The Netfilter HomePage: iptables 1.2.2</title></head>
3
<body bgcolor="#ffffff" text="#101010">
4
<center><h1>The Netfilter HomePage: iptables 1.2.2</h1></center>
6
This version requires kernel 2.4.1 or above.
7
This version recommends kernel 2.4.4 or above.
10
<strong>Bugs Fixed from 1.2.1a:</strong>
12
<li> fixes for SAME Target<br>
14
<li> fixes for iplimit match in combination with iptables-save/-restore<br>
16
<li> fix for TCP match in combination with iptables-save/-restore<br>
18
<li> iptables-restore now deals correclty with spaces in --log-prefix<br>
20
<li> fix in 'isapplied' script. It used to give false negatives<br>
22
<li> fix in BALANCE target, target now uses full ip address range<br>
24
<li> fix for NETLINK target, was sending wrong interface name<br>
26
<li> fix for collision of ftp and irc NAT helpers<br>
28
<li> ip6tables brought in sync with iptables<br>
31
<li> Kernel bugfixes in patch-o-matic:
33
<li> Fix possible security vulnerability in ip_conntrack_ftp<br>
34
[ Cristiano Lincoln Mattos, James Morris and Rusty ]
38
<strong>Changes from 1.2.1a:</strong>
40
<li> libiptc should now be usable from C++ applications<br>
42
<li> seqoffset-,ftp-security, ... patches are combined in 2.4.4.patch<br>
44
<li> lots of old pre-2.4.1 patches now combined in 2.4.1.patch<br>
46
<li> IRC conntrack + nat cleanup<br>
48
<li> string match cleanup<br>
50
<li> ULOG cleanup, new version. Fixes 'unable to send nflink' bug<br>
53
<li> New patch-o-matic patches:
55
<li> New NETMAP Target for mapping whole networks 1:1 to other addresses<br>
56
[ Svenning Soerensen ]
57
<li> New length Target for matching packet length<br>
59
<li> New ipv4options match for matching IPv4 header options<br>
61
<li> New IPv6 agr match for matching IPv6 global aggregatable unicast adresses<br>
63
<li> New pkttype match for matching link-layer multicast / broadcast packets<br>
65
<li> New time match for matching the packet's receive time<br>
67
<li> New talk conntack + NAT helper module<br>