Tom Eastep
|
282bf0a78c
|
Allow Events with Shorewall6
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-07-12 09:45:41 -07:00 |
|
Tom Eastep
|
71bcd11ab6
|
Make ?...shell/perl directives case insensitive
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-06-20 10:39:39 -07:00 |
|
Tom Eastep
|
4bd35a0b93
|
Allow 'routeback=0'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-06-16 08:37:53 -07:00 |
|
Tom Eastep
|
53f1cd40df
|
Add 'unmanaged' option
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-06-10 12:36:18 -07:00 |
|
Tom Eastep
|
a48a4b7a2e
|
Don't allow fowarding between local zones.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-05-28 06:14:44 -07:00 |
|
Tom Eastep
|
2de0fbf7d0
|
Change 'local' to 'loopback' and add 'local' zones that match non-loopback interfaces.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-05-26 14:06:51 -07:00 |
|
Tom Eastep
|
fd11eb7d82
|
Omit fw->fw jumps when there is a local zone.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-05-22 09:19:34 -07:00 |
|
Tom Eastep
|
ac02c484f5
|
Change 'local' interface option to a zone type.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-05-19 15:35:20 -07:00 |
|
Tom Eastep
|
b38f1416aa
|
Mention "all+' in the "Important" notes at the top
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-05-13 13:41:12 -07:00 |
|
Tom Eastep
|
c8133145e6
|
Add support for "all+" in the policy file.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-05-13 09:01:12 -07:00 |
|
Tom Eastep
|
e3d9b2762d
|
Add 'destonly' and 'local' to the interface manpages.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-05-12 12:48:58 -07:00 |
|
Tom Eastep
|
7215b61aa4
|
Document changes introduced by Mr-4.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-05-07 10:16:38 -07:00 |
|
Tom Eastep
|
577db69719
|
Support conditional compilation.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-05-07 09:36:02 -07:00 |
|
Roberto C. Sanchez
|
a0228e9d3b
|
Fix typos in manpages
|
2013-05-03 12:19:45 -04:00 |
|
Tom Eastep
|
8bb03a741d
|
Update blrules manpages
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-24 08:17:10 -07:00 |
|
Tom Eastep
|
f543c3bd1e
|
Finish Mr-4's NFACCT patch
- Correct indentation
- Remove '$type' argument to split_nfacct_list
- Update manpages.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-23 06:55:30 -07:00 |
|
Tom Eastep
|
5ad69aa650
|
Add CHAIN_SCRIPTS option
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-21 07:30:31 -07:00 |
|
Tom Eastep
|
a56dcc745d
|
Clarify <chain>:COUNT in the accounting files.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-20 17:11:46 -07:00 |
|
Tom Eastep
|
1b9fd642bb
|
Add INLINE to the accounting file.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-20 08:02:02 -07:00 |
|
Tom Eastep
|
1fd62e1612
|
Restore order in the NFACCT target.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-19 11:11:37 -07:00 |
|
Tom Eastep
|
6c2679ce75
|
Allow incrementing an nfacct object when an ipset matches.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-19 10:44:57 -07:00 |
|
Tom Eastep
|
91c4dd2e56
|
Document multiple nfacct objects in one rule.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-19 06:38:02 -07:00 |
|
Tom Eastep
|
8ef11a376b
|
Document 'HELPERS=none'.
- Also make 'check -u' work correctly regarding HELPERS=
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-18 11:30:47 -07:00 |
|
Tom Eastep
|
ef01748dc9
|
Update manpages for INLINE
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-17 07:34:00 -07:00 |
|
Tom Eastep
|
beec4a188f
|
Implement INLINE action (again).
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-11 09:15:59 -07:00 |
|
Tom Eastep
|
50494f667c
|
Implement INLINE action
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-08 17:30:00 -07:00 |
|
Tom Eastep
|
efebda76d2
|
Improve the description of 'accept_ra' in shorewall6-interfaces(5)
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-01 14:25:49 -07:00 |
|
Tom Eastep
|
d415de1883
|
Add the accept_ra Shorewall6 interface option.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-03-30 16:44:18 -07:00 |
|
Tom Eastep
|
b5ea4067e4
|
Implement USE_RT_NAMES
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-03-24 10:56:38 -07:00 |
|
Tom Eastep
|
1e866eac28
|
Implement the other forms of NULL routing.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-03-16 08:20:52 -07:00 |
|
Tom Eastep
|
fe6533943c
|
Correct 'routes' manpages.
- change 4.5.15 with 4.5.14 for the availability of blackhole routes
- Add 'main' to the legal providers.
|
2013-03-08 08:26:08 -08:00 |
|
Tom Eastep
|
06e7f297f7
|
Allow addition of blackhole routes.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-03-06 11:48:09 -08:00 |
|
Tom Eastep
|
631c1ac843
|
Mention the multiport match requirement for '='
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-03-04 12:53:00 -08:00 |
|
Tom Eastep
|
49918b654e
|
Support '=' in SOURCE PORT(S) columns
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-03-04 09:56:10 -08:00 |
|
Tom Eastep
|
8960f72532
|
Handle DNAT with no port correctly.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-03-01 07:58:58 -08:00 |
|
Tom Eastep
|
252dd9b676
|
Correct SUBSYSLOCK setting in shorewall6.conf
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-02-28 07:45:17 -08:00 |
|
Tom Eastep
|
418034579f
|
Support IPv6 Masquerade
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-02-27 09:25:26 -08:00 |
|
Tom Eastep
|
7006c62892
|
Correct port pair handling in the snat ADDRESS column.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-02-25 15:31:36 -08:00 |
|
Tom Eastep
|
0349a9a88c
|
Rename the IPv6 masq file 'snat'.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-02-19 13:05:24 -08:00 |
|
Tom Eastep
|
524d6242b0
|
More SNAT/DNAT manpage updates
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-02-19 12:42:09 -08:00 |
|
Tom Eastep
|
b562f7f311
|
Allow specification of destination addresses in Shorewall6 masq.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-02-19 08:34:03 -08:00 |
|
Tom Eastep
|
ce28c70c60
|
SNAT and DNAT support for IPv6.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-02-19 07:08:08 -08:00 |
|
Tom Eastep
|
010c44d07a
|
Correct description of the 'sourceroute' interface option.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-02-18 11:33:19 -08:00 |
|
Tom Eastep
|
e486c16513
|
Correct all configpath files.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-02-14 15:10:21 -08:00 |
|
Tom Eastep
|
f44becdee1
|
Rename BLACKLIST_LOGLEVEL to BLACKLIST_LOG_LEVEL for consistent naming.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-02-12 07:47:02 -08:00 |
|
Tom Eastep
|
aae6e001fe
|
Convert dropInvalid and allowInvalid to inline actions.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-02-07 11:21:13 -08:00 |
|
Tom Eastep
|
aa528dd075
|
Revert "Convert allowInvalid and dropInvalid into macros"
This reverts commit 272e1d330c .
|
2013-02-07 09:09:56 -08:00 |
|
Tom Eastep
|
272e1d330c
|
Convert allowInvalid and dropInvalid into macros
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-02-06 09:54:12 -08:00 |
|
Tom Eastep
|
61c219ed3a
|
Clarify the CHAIN column in the accounting manpage. Also mention ipset support.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-02-03 08:00:24 -08:00 |
|
Tom Eastep
|
0616dd9fcb
|
Add 'New' action for conntrack state NEW
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-02-02 09:33:24 -08:00 |
|