http://shorewall.net/pub/shorewall/2.0/shorewall-2.0.6 ftp://shorewall.net/pub/shorewall/2.0/shorewall-2.0.6 Problems Corrected: 1) Some users have reported the packket type match option in iptables/ Netfilter failing to match certain broadcast packets. The result is that the firewall log shows a lot of broadcast packets. Other users have complained of the following message when starting Shorewall: modprobe: cant locate module ipt_pkttype Users experiencing either of these problems can use PKTTYPE=No in shorewall.conf to cause Shorewall to use IP address filtering of broadcasts rather than packet type. 2) The shorewall.conf and zones file are no longer given execute permission by the installer script. 3) ICMP packets that are in the INVALID state are now dropped by the Reject and Drop default actions. They do so using the new ''dropInvalid'' builtin action. -Tom -- Tom Eastep \ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ teastep@shorewall.net