Tom Eastep
|
2ce3c8aa88
|
Ensure that blacklist rules are before the other interface-oriented rules
|
2010-09-16 18:19:16 -07:00 |
|
Tom Eastep
|
27c445381e
|
Treat 'blacklist' uniformly in hosts and zones
|
2010-09-16 15:48:12 -07:00 |
|
Tom Eastep
|
1c870b532a
|
Preserve dynamic blacklist during stop/clear/restore
|
2010-09-16 12:17:04 -07:00 |
|
Tom Eastep
|
a8c9fc1859
|
Implement new Blacklisting Scheme
|
2010-09-16 09:40:28 -07:00 |
|
Tom Eastep
|
3c1cff0794
|
First steps toward zone-based blacklisting
|
2010-09-16 06:55:48 -07:00 |
|
Tom Eastep
|
1d650b41cd
|
Remove blacklisting by destination IP address support
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-15 15:24:58 -07:00 |
|
Tom Eastep
|
3ad3f0d9e0
|
Allow floating point numbers in tcinterfaces fields other than <rate>
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-15 14:07:21 -07:00 |
|
Tom Eastep
|
ba89ec39b5
|
Add :<burst> to /etc/shorewall/tcdevices
|
2010-09-15 11:56:14 -07:00 |
|
Tom Eastep
|
69a2fa1907
|
Replace to/from with dst/src
|
2010-09-15 11:25:46 -07:00 |
|
Tom Eastep
|
f925b335ef
|
Ignore the 'blacklist' host option
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-15 08:10:57 -07:00 |
|
Tom Eastep
|
373fc87165
|
More blacklisting wrapup
- Deprecate 'blacklist' in the hosts file
- Base blacklisting on interfaces alone
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-15 07:38:20 -07:00 |
|
Tom Eastep
|
4d0e8d129b
|
Add dup blacklist message
|
2010-09-14 18:04:27 -07:00 |
|
Tom Eastep
|
10a9ae496a
|
More manpage updates for 4.4.13
|
2010-09-14 16:47:45 -07:00 |
|
Tom Eastep
|
94cdc73ec2
|
Restore setpolicy() to prog.header*
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-14 13:50:22 -07:00 |
|
Tom Eastep
|
c4a40d8c7b
|
Set version to RC1 (again)
|
2010-09-14 13:09:50 -07:00 |
|
Tom Eastep
|
1f2691b052
|
Another fix for blacklisting; correct composition of $hosts1
|
2010-09-14 06:47:29 -07:00 |
|
Tom Eastep
|
0f913fca2f
|
Don't create blackout unnecessarily
|
2010-09-13 18:15:50 -07:00 |
|
Tom Eastep
|
82bccf16b5
|
Avoid internal error when there are no 'to' entries
|
2010-09-13 17:55:20 -07:00 |
|
Tom Eastep
|
b1e9bff382
|
Create new ipsets on 'start'
|
2010-09-13 15:46:04 -07:00 |
|
Tom Eastep
|
a6194fabd2
|
Delete blank line
|
2010-09-13 14:15:47 -07:00 |
|
Tom Eastep
|
33adbe7a27
|
Update documentation for net TC features
|
2010-09-13 13:51:25 -07:00 |
|
Tom Eastep
|
1729da87f1
|
Allow both 'to' and 'from' in blacklist
|
2010-09-13 12:51:10 -07:00 |
|
Tom Eastep
|
9b4c3e22dd
|
Allow floating point numbers in TC rates
|
2010-09-13 12:50:50 -07:00 |
|
Tom Eastep
|
cb1f7adea3
|
Add :<burst> to IN-BANDWIDTH
|
2010-09-13 11:23:37 -07:00 |
|
Tom Eastep
|
283eda2fa5
|
Cosmetic change to OUT-BANDWIDTH code
|
2010-09-12 16:33:19 -07:00 |
|
Tom Eastep
|
bd9041306c
|
Add undocumented OUT-BANDWIDTH column to tcinterfaces
|
2010-09-12 16:25:45 -07:00 |
|
Tom Eastep
|
a3b7b9c11b
|
Delete unused functions from prog.header*
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-12 10:07:26 -07:00 |
|
Tom Eastep
|
931c5a8d0a
|
Add an assertion
|
2010-09-11 16:24:27 -07:00 |
|
Tom Eastep
|
50fc972d2a
|
Fix another SAME defect :-(
|
2010-09-11 16:15:09 -07:00 |
|
Tom Eastep
|
512cd7b08e
|
Bump version to 4.4.13 RC 1
|
2010-09-11 15:46:14 -07:00 |
|
Tom Eastep
|
aad7b70e18
|
Rename constant
|
2010-09-11 15:31:43 -07:00 |
|
Tom Eastep
|
c6c6503d83
|
Clean up a remaining issue with SAME
|
2010-09-11 15:24:01 -07:00 |
|
Tom Eastep
|
f004916055
|
Disallow a DEST interface in mangle OUTPUT rules
|
2010-09-11 14:10:05 -07:00 |
|
Tom Eastep
|
3ea7808b38
|
Disallow a DEST interface in mangle PREROUTING rules
|
2010-09-11 14:02:09 -07:00 |
|
Tom Eastep
|
e93a7fe9df
|
Avoid recent problems by not padding $target in process_tc_rule()
|
2010-09-11 11:03:28 -07:00 |
|
Tom Eastep
|
d9ced1051a
|
One more fix for SAME
|
2010-09-11 10:35:45 -07:00 |
|
Tom Eastep
|
367fc041b8
|
Correct handling of SAME -- Take 2
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-11 09:36:19 -07:00 |
|
Tom Eastep
|
dbc9f6ac8f
|
Correct handling of SAME
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-11 08:56:22 -07:00 |
|
Tom Eastep
|
8dd42c9e19
|
Correct handling of dst/src list in ipset invocation
|
2010-09-11 07:41:01 -07:00 |
|
Tom Eastep
|
99f8f84024
|
Fix name of F chain in secmarks
|
2010-09-10 16:45:22 -07:00 |
|
Tom Eastep
|
69817007bf
|
Some more fixes for blacklisting
|
2010-09-09 14:53:12 -07:00 |
|
Tom Eastep
|
50300a60b7
|
A number of corrections to split blacklisting.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-09 11:20:49 -07:00 |
|
Tom Eastep
|
64544f4ab5
|
Correct comparison in 'blacklist' handling
|
2010-09-09 10:22:48 -07:00 |
|
Tom Eastep
|
cd4b5d80ed
|
Reduce patch footprint by two lines
|
2010-09-09 09:00:28 -07:00 |
|
Tom Eastep
|
df1e17eaa8
|
Re-enable 'blacklist' on bridge ports
|
2010-09-09 07:09:08 -07:00 |
|
Tom Eastep
|
50b4bd8dfe
|
More Blacklist and Secmark documentation updates
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-06 17:26:49 -07:00 |
|
Tom Eastep
|
f3255cd83a
|
Rework blacklisting
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-06 15:29:20 -07:00 |
|
Tom Eastep
|
c6f58ba924
|
Enhance SELinux support:
- Add state match
- Add user/group match
- Add examples to the man pages
|
2010-09-06 09:06:40 -07:00 |
|
Tom Eastep
|
33dc8de8fb
|
Allow dash's in ipset names
|
2010-09-05 11:41:35 -07:00 |
|
Tom Eastep
|
23e94e136c
|
Allow COMMENT, SAVE and RESTORE to work correctly in secmarks
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-05 08:17:58 -07:00 |
|