Tom Eastep
|
6bed5e5e55
|
Merge branch '4.4.27'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-30 07:28:14 -08:00 |
|
Tom Eastep
|
5b2f960db3
|
Disallow :P in CLASSIFY rules and complain if :F is used when the SOURCE or DEST is $FW.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-30 07:22:14 -08:00 |
|
Tom Eastep
|
1da7f52ed5
|
Copy output interface options rather than jump
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-29 18:49:47 -08:00 |
|
Tom Eastep
|
39f214208a
|
Fix silly bug in the new option chain implementation
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-29 17:57:39 -08:00 |
|
Tom Eastep
|
6926bcdbb9
|
More refinements of the option chain stuff.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-29 14:52:07 -08:00 |
|
Tom Eastep
|
f9960a0c94
|
Restore blacklst and blackout chains
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-29 13:45:35 -08:00 |
|
Tom Eastep
|
2c441b5393
|
Copy option rules into interface chains if no blacklist
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-29 09:32:16 -08:00 |
|
Tom Eastep
|
bddfb4f41c
|
Add output option chains
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-29 08:22:00 -08:00 |
|
Tom Eastep
|
03610181fd
|
Disallow :P in CLASSIFY rules and complain if :F is used when the SOURCE or DEST is $FW.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-29 07:49:53 -08:00 |
|
Tom Eastep
|
b367fb46af
|
Add a caution to the Getting Started Doc
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-29 07:49:40 -08:00 |
|
Tom Eastep
|
2ca7984f60
|
Add a caution to the Getting Started Doc
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-29 07:46:37 -08:00 |
|
Tom Eastep
|
3ca9577f04
|
Cruft removal
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-28 16:22:11 -08:00 |
|
Tom Eastep
|
8cdc83638e
|
Don't allow PREROUTING CLASSIFY rules.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-28 14:07:12 -08:00 |
|
Tom Eastep
|
a98c85cbc4
|
Make 'audit' work on a converted blacklist file.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-28 10:30:24 -08:00 |
|
Tom Eastep
|
eda918215d
|
Option chain phase II implementation
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-28 10:29:15 -08:00 |
|
Tom Eastep
|
0518def9cf
|
Merge branch '4.4.27'
|
2011-12-28 09:58:19 -08:00 |
|
Tom Eastep
|
09f58512be
|
Make 'audit' work on a converted blacklist file.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-28 09:34:34 -08:00 |
|
Tom Eastep
|
eff447ac11
|
Phase one option chain implementation.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-27 18:12:58 -08:00 |
|
Tom Eastep
|
53451bdaa6
|
Remove BLACKLIST section from rules files.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-27 15:32:49 -08:00 |
|
Tom Eastep
|
d827b6ae5d
|
Remove BLACKLIST section from the rules file manpages
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-27 15:29:37 -08:00 |
|
Tom Eastep
|
ea9c59a297
|
Add an interface filter chain for each interface.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-27 13:52:44 -08:00 |
|
Tom Eastep
|
49eb84b9e2
|
Remove more helper/proto silliness
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-27 13:06:37 -08:00 |
|
Tom Eastep
|
8a8214704e
|
Centralize checking for required proto with helper
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-27 13:04:19 -08:00 |
|
Tom Eastep
|
aa743f2886
|
Merge branch '4.4.27'
|
2011-12-27 13:02:08 -08:00 |
|
Tom Eastep
|
c5868ef6e4
|
Revert "Remove redundant check."
This reverts commit 53dd13cf15 .
|
2011-12-27 13:01:27 -08:00 |
|
Tom Eastep
|
7721644209
|
Merge branch '4.4.27' of ssh://shorewall.git.sourceforge.net/gitroot/shorewall/shorewall into 4.4.27
Conflicts:
Shorewall/Perl/Shorewall/Chains.pm
Shorewall/Perl/Shorewall/Raw.pm
|
2011-12-27 12:32:13 -08:00 |
|
Tom Eastep
|
1c2ab238a5
|
Merge branch '4.4.27' of ssh://shorewall.git.sourceforge.net/gitroot/shorewall/shorewall into 4.4.27
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-26 13:22:30 -08:00 |
|
Tom Eastep
|
3541767881
|
Don't croak when adding gateway route fails for IPv6.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-26 11:58:06 -08:00 |
|
Tom Eastep
|
53dd13cf15
|
Remove redundant check.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-26 11:57:34 -08:00 |
|
Tom Eastep
|
6db8748ee8
|
Don't show IPv6 cached routes unless asked.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-26 11:57:18 -08:00 |
|
Tom Eastep
|
5520a6d31d
|
Validate helper<->protocol
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-24 09:24:01 -08:00 |
|
Tom Eastep
|
be4cb9d26a
|
Validate helper<->protocol
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-23 17:55:13 -08:00 |
|
Tom Eastep
|
97354c8ce8
|
Detect CT_TARGET when LOAD_HELPERS_ONLY=No
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-23 11:59:51 -08:00 |
|
Tom Eastep
|
e8c7ec38dc
|
Allow netstat output to appear in dumps on Fedora
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-23 11:59:19 -08:00 |
|
Tom Eastep
|
b58ad8e758
|
Be sure to delete fooX chain on errors in determine_capabilities()
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-23 10:55:08 -08:00 |
|
Tom Eastep
|
0e3ad6ff91
|
Omit the chain designator from an error message
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-23 07:51:12 -08:00 |
|
Tom Eastep
|
1c535ee0f9
|
Correct handling of a chain designator in CLASSIFY rules.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-23 07:44:16 -08:00 |
|
Tom Eastep
|
3081ab1da1
|
Correct RELATED_DISPOSITION error message
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-22 15:51:50 -08:00 |
|
Tom Eastep
|
ce735e9415
|
Allow a chain designator in CLASSIFY rules
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-22 15:41:16 -08:00 |
|
Tom Eastep
|
e93dbdcb99
|
Stop generation of superfluous routing rules.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-21 08:01:25 -08:00 |
|
Tom Eastep
|
ea8efd1c44
|
Correct 'show ipa'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-21 07:25:20 -08:00 |
|
Tom Eastep
|
c03fe0a076
|
Implement USE_LOGICAL_NAMES.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-20 16:03:56 -08:00 |
|
Tom Eastep
|
3e72442954
|
Convert sample notrack files to FORMAT 2
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-20 14:38:44 -08:00 |
|
Tom Eastep
|
0d4a6c1c28
|
Replace SHOREWALL_DIR with g_shorewalldir
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-20 08:19:57 -08:00 |
|
Tom Eastep
|
74cee48bc0
|
Change /sbin/shorewall6 back into a file
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-19 15:52:42 -08:00 |
|
Tom Eastep
|
075d7ca68b
|
Rename $nolock to $g_nolock
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-19 06:29:05 -08:00 |
|
Tom Eastep
|
6b90c09c04
|
Correct 'show raw'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-18 15:11:56 -08:00 |
|
Tom Eastep
|
1c8f6d3856
|
Eliminate a variable
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-18 15:05:03 -08:00 |
|
Tom Eastep
|
c00068e08d
|
Another correction to the 'CT' target
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-18 07:21:32 -08:00 |
|
Tom Eastep
|
a80b46be81
|
Allow a port number to be appended to a helper name
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-17 17:08:24 -08:00 |
|