Tom Eastep
|
380443f26d
|
Eliminate %defaults
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-18 15:44:07 -07:00 |
|
Tom Eastep
|
faeb2da2ba
|
Corrections to Defaults
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-18 15:38:08 -07:00 |
|
Tom Eastep
|
f93ac02bfc
|
Provide default values for added entries
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-18 14:50:07 -07:00 |
|
Tom Eastep
|
96f6dc3558
|
More defined => supplied changes
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-18 13:08:26 -07:00 |
|
Tom Eastep
|
6f2cc31dde
|
Implement .conf file upgrade
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-18 13:03:55 -07:00 |
|
Tom Eastep
|
d23f932ebe
|
Don't generate INPUT hairpin rules
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-18 06:21:36 -07:00 |
|
Tom Eastep
|
f9ee8c494d
|
Exempt wildcard interfaces from sfilter
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-14 06:45:22 -07:00 |
|
Tom Eastep
|
9aedd407cc
|
Quell compiler warnings from Perl 5.14.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-13 06:40:03 -07:00 |
|
Tom Eastep
|
9ab901927f
|
Use supplied() where appropriate
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-11 16:14:31 -07:00 |
|
Tom Eastep
|
774aac1228
|
Add a supplied() function
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-11 15:40:55 -07:00 |
|
Tom Eastep
|
a60fe6e665
|
Allow parameters to be specified to Default Actions in the policy file
and in shorewall.conf.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-11 14:58:54 -07:00 |
|
Tom Eastep
|
3dd363677c
|
Implement set_action_param
Export both set_action_params and read_action_param by default
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-11 08:33:21 -07:00 |
|
Tom Eastep
|
8b6a7a7053
|
Implement read_action_param()
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-11 07:49:57 -07:00 |
|
Tom Eastep
|
f278d05637
|
Rename action param functions
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-11 07:46:54 -07:00 |
|
Tom Eastep
|
2549982528
|
Fix DEFAULTS
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-11 07:23:41 -07:00 |
|
Tom Eastep
|
6e6be468a9
|
Support for DEFAULT statements in actions
|
2011-06-10 17:05:09 -07:00 |
|
Tom Eastep
|
32c7d36cd0
|
Make zones with multiple interfaces complex
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-10 15:37:26 -07:00 |
|
Tom Eastep
|
dbd30f981c
|
Set the interface routeback option if there are any IP host groups with 'routeback'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-10 15:37:09 -07:00 |
|
Tom Eastep
|
8a7ad569e4
|
Don't leave unused sfilter chains in the config
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-09 17:22:48 -07:00 |
|
Tom Eastep
|
3e9a54d404
|
Couple of tweaks
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-09 17:22:34 -07:00 |
|
Tom Eastep
|
a0b0c5bdac
|
Jump (don't go) to sfilter1
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-09 14:24:44 -07:00 |
|
Tom Eastep
|
1399a8ffde
|
Don't move rules from a chain with references
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-09 14:24:38 -07:00 |
|
Tom Eastep
|
9555a552c2
|
Fix FORWARD with ipsec dest
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-09 14:24:08 -07:00 |
|
Tom Eastep
|
71177c3ca3
|
Exempt ipsec from sfilter
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-09 07:27:06 -07:00 |
|
Tom Eastep
|
fa2746d469
|
Apply sfilter to INPUT as well as FORWARD
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-08 09:40:28 -07:00 |
|
Tom Eastep
|
35d1586672
|
Correct sfq handle assignment
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-07 13:58:45 -07:00 |
|
Tom Eastep
|
a3968beb7e
|
Add fix inadvertently dropped from 4.4.19.4
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-07 13:57:52 -07:00 |
|
Tom Eastep
|
0e839f3d7b
|
Initiate 4.4.21
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-07 09:54:35 -07:00 |
|
Tom Eastep
|
9c2c562bf5
|
Correct autorepeat wart
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-07 06:45:50 -07:00 |
|
Tom Eastep
|
cf0275a049
|
Make FAKE_AUDIT work again
|
2011-06-06 16:08:29 -07:00 |
|
Tom Eastep
|
642319d706
|
Change annotated documentation default
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-06 15:40:21 -07:00 |
|
Tom Eastep
|
cfb3d6a801
|
Merge branch '4.4.20'
|
2011-06-06 14:09:26 -07:00 |
|
Tom Eastep
|
6136e986cf
|
Update version to 4.4.20.1
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-06 14:08:25 -07:00 |
|
Tom Eastep
|
aabefe91f1
|
Merge branch '4.4.20'
|
2011-06-04 08:46:40 -07:00 |
|
Tom Eastep
|
f1cbfab7ac
|
More blacklist/audit fixes
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-04 08:45:23 -07:00 |
|
Tom Eastep
|
653a61a04a
|
Merge branch '4.4.20'
|
2011-06-04 07:44:24 -07:00 |
|
Tom Eastep
|
a9c0824a30
|
Correct BLACKLIST_DISPOSITION=A_xxx with BLACKLIST_LOG_LEVEL
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-04 07:44:07 -07:00 |
|
Tom Eastep
|
aa86b65ec3
|
Merge branch '4.4.20'
|
2011-06-02 11:44:15 -07:00 |
|
Tom Eastep
|
254e1ed784
|
Add 'I' STATE to secmarks
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-02 11:43:55 -07:00 |
|
Tom Eastep
|
c3b56c1e73
|
Merge branch '4.4.20'
|
2011-06-02 10:07:03 -07:00 |
|
Tom Eastep
|
561d461a25
|
Add 'NI' STATE setting in secmarks.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-02 10:06:27 -07:00 |
|
Tom Eastep
|
1e883c2fdf
|
Merge branch '4.4.20'
|
2011-06-02 06:47:09 -07:00 |
|
Tom Eastep
|
f9c5b8b0d5
|
Improve some comments
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-02 06:23:37 -07:00 |
|
Tom Eastep
|
36aee407ef
|
Merge branch '4.4.20'
|
2011-06-01 13:01:27 -07:00 |
|
Tom Eastep
|
5f08605adc
|
Delete some cruft
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-06-01 12:26:05 -07:00 |
|
Tom Eastep
|
243a09783c
|
Merge branch '4.4.20'
|
2011-05-31 15:45:09 -07:00 |
|
Tom Eastep
|
7bf74bb8c9
|
Add new builtin targets to %builtin_target
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-05-31 15:43:42 -07:00 |
|
Tom Eastep
|
468ff6efab
|
First cut at IPSET/Dynamic-zone support in Shorewall6
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-05-31 11:23:43 -07:00 |
|
Tom Eastep
|
8df470b5f5
|
Version to 4.4.20
|
2011-05-31 09:30:18 -07:00 |
|
Tom Eastep
|
2f6c5fd260
|
Set 'bridge-nf-call-ip6?tables' if bridges are configured.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-05-31 06:59:43 -07:00 |
|