Beta 5 is now ready for testing. Changes since Beta 4: 1) A new BASIC_FILTERS option is now supported. When set to 'Yes', this option causes the compiler to generate basic TC filters from tcfilters entries rather than u32 filters. Basic filters are more straight-forward than u32 filters and, in later iptables/kernel versions, basic filters support ipset matches. Please note that Shorewall cannot reliably detect whether your iptables/kernel support ipset matches, so an error-free compilation does not guarantee that the firewall will start successfully when ipset names are specified in tcfilters entries. 2) The update command now supports an -A option. This is intended to perform all available updates to the configuration and is currently equivalent to '-b -D -t'. Thank you for testing, -Tom -- Tom Eastep \ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington, USA \ all of the passengers in his car http://shorewall.net \________________________________________________ ------------------------------------------------------------------------------ Flow-based real-time traffic analytics software. Cisco certified tool. Monitor traffic, SLAs, QoS, Medianet, WAAS etc. with NetFlow Analyzer Customize your own dashboards, set traffic alerts and generate reports. Network behavioral analysis & security monitoring. All-in-one tool. http://pubads.g.doubleclick.net/gampad/clk?id=126839071&iu=/4140/ostg.clktrk