1) On systems running Upstart, shorewall-init cannot reliably secure the firewall before interfaces are brought up. 2) The 'enable', 'reenable' and 'disable' commands do not work correctly in configurations with USE_DEFAULT_RT=No. 3) Start/restart/reload fails under the following conditions: - DOCKER=Yes - The firewall has been started previously with Docker running. - The start, restart or reload command is executed with Docker not running. Workaround: rm /var/lib/shorewall/.nat_OUTPUT Corrected in Shorewall 5.0.6.1 4) In Shorewall 5.0.6, the 'check -r' command dies with an assertion failure.