1)  On systems running Upstart, shorewall-init cannot reliably secure
    the firewall before interfaces are brought up.

2)  Version 4.5.16 broke the handling of application helpers when the
    CT Target. Symptom is messages like the following:

    Use of uninitialized value $Shorewall::Config::sillyname in
    concatenation (.) or string at
    /usr/share/shorewall/Shorewall/Config.pm line 3907.

    Workaround: Use a capabilities file.

    Corrected in Shorewall 4.5.16.1.

3)  When INLINE is used in the tcrules file and no target ('-j' part)	
    is included in the free-form part of the rule, an invalid 
    iptables rule is generated.

    Workaround: Always specify '-j'.
