o There are lots of changes in the firewall structure -- beware if you use /etc/shorewall/start to insert rules into the Shorewall-generated ruleset. o Sub-zones may now be excluded from DNAT and REDIRECT rules. o The names of the columns in a number of configuration files have been changed to be more consistent and self-explanatory. o The sample configuration files have been updated for 1.3. These are all of the functional changes that I plan for 1.3.0. Next version will be RC1. -Tom -- Tom Eastep \ Shorewall - iptables made easy AIM: tmeastep \ http://www.shorewall.net ICQ: #60745924 \ teastep@shorewall.net