Tom Eastep
546a48543d
Propagate LOG_VERBOSITY
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-28 17:30:11 -08:00
Tom Eastep
39883aa690
Eliminate LOG_VERBOSE
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-28 16:58:30 -08:00
Tom Eastep
fb55d63eaf
Allow verbosity to be separate from -V
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-28 16:42:50 -08:00
Tom Eastep
333ac21c2f
Prepare the footers for 4.6.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-28 15:25:25 -08:00
Tom Eastep
83ed0a401b
I'll eventually get it the way I like it
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-28 13:45:33 -08:00
Tom Eastep
585711caa8
Even simpler RE for detecting builtins
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-28 13:29:26 -08:00
Tom Eastep
693d0e5d4c
Make new test in add_jump() a bit safer.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-28 12:44:29 -08:00
Tom Eastep
d2992c21f4
Update version to Beta 2
2010-02-28 09:04:37 -08:00
Tom Eastep
061d850c16
Rename RESTOREPATH to g_restorepath
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-26 08:35:50 -08:00
Tom Eastep
7fe7ebc891
Fix Handling of NFQUEUE(queue-num) in policies
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-25 08:44:28 -08:00
Tom Eastep
70a246501e
Update version of Tc.pm
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-23 07:08:48 -08:00
Tom Eastep
3fc10cd94b
Prepend 'SW_' to constructed shell variable names.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-22 10:27:59 -08:00
Tom Eastep
2a965d42b9
Add a comment
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-21 07:57:34 -08:00
Tom Eastep
6307653a01
Pick up one fix from 4.4.7.4 regarding CONTINUE rules.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-20 09:42:58 -08:00
Tom Eastep
edaf541850
Don't apply rate limiting twice in ACCEPT+ rules
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-19 14:01:45 -08:00
Tom Eastep
ceff8adc78
Restore duplicate interface detection in tcinterfaces.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-18 16:11:30 -08:00
Tom Eastep
3a2173ddb4
Some code cleanup in Tc.pm.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-18 15:56:59 -08:00
Tom Eastep
ea8be87720
Use Hex representation of device numbers > 9 in simple TC.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-18 12:53:01 -08:00
Tom Eastep
00b0490cd7
Create a unique hashtable for each instance of a per-IP rate limit
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-17 15:39:21 -08:00
Tom Eastep
625963a4f0
Final (hopefully) fix for SFQ handle assignment
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-17 09:02:18 -08:00
Tom Eastep
41bb0782a3
Another tweak to SFQ handle assignment.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-17 08:06:27 -08:00
Tom Eastep
5649dbf9a8
Improve assignment of class ID for SFQ classses
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-17 07:41:30 -08:00
Tom Eastep
eaafeb8c2b
Add --hashlimit-htable-expire if the units are minutes or larger
2010-02-17 06:43:52 -08:00
Tom Eastep
375160d733
Avoid duplicate SFQ class numbers
2010-02-17 06:43:16 -08:00
Tom Eastep
167b29c2c5
Bump module version in Compiler.pm
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-15 14:24:52 -08:00
Tom Eastep
8aaf4aab3a
Don't create log chain for 'RETURN' rules
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-15 14:24:00 -08:00
Tom Eastep
4546394531
Cosmetic changes to Compiler.pm
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-15 14:07:35 -08:00
Tom Eastep
12d3420a5d
Detect FLOW_FILTER when LOAD_HELPERS_ONLY=No
2010-02-14 10:34:19 -08:00
Tom Eastep
5e9ecf1491
Update version of Config module
2010-02-13 11:00:34 -08:00
Tom Eastep
50d246c8be
A little cleanup of compiler.pl
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-13 10:03:32 -08:00
Tom Eastep
1258149e0e
Don't apply rate limiting twice in NAT rules
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-13 07:21:27 -08:00
Tom Eastep
ea5a6c79bc
Bump CAPVERSION
2010-02-11 16:22:47 -08:00
Tom Eastep
5a96771e07
Start 4.4.8 Beta 1
2010-02-11 15:46:57 -08:00
Tom Eastep
b35f20b403
Avoid CAPVERSION bump to implement FLOW_FILTER detection
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-11 07:29:41 -08:00
Tom Eastep
b8c195f570
Accurately detect 'flow' availability
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-10 14:50:26 -08:00
Tom Eastep
433fc385bc
'bridge' implies 'routeback'
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-09 14:04:36 -08:00
Tom Eastep
46e2afcf16
Ignore TYPE if old distro
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-08 07:13:20 -08:00
Tom Eastep
b45a70f98a
Make 'nosmurfs' work correctly on IPv6 with Address Type Match
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-08 07:12:58 -08:00
Tom Eastep
18d03a61f5
Make 'nosmurfs' work with Address Type Match on IPv6
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-07 08:43:31 -08:00
Tom Eastep
11a2ec9f7c
Update version to 4.4.7
2010-02-05 16:40:48 -08:00
Tom Eastep
e64af57cae
Give smurf logging chain a fixed name.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-03 16:04:59 -08:00
Tom Eastep
f4e175f149
Fix IPv6 'nosmurfs'. Make 'nosmurfs' logging more efficient.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-03 15:03:15 -08:00
Tom Eastep
52880a8822
Clean up generate_matrix() fix.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-03 06:57:51 -08:00
Tom Eastep
9d288241da
Fix issues in generate_matrix().
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-02 19:42:54 -08:00
Tom Eastep
1d8a7ad09f
Clear DEBUG and PURGE shell variables
...
Delete a blank line
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-02 13:55:29 -08:00
Tom Eastep
753eb97667
Update version to 4.4.7 RC2
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-02 10:30:53 -08:00
Tom Eastep
dd60f04a9f
Work around lack of MARK Target support
2010-02-01 16:22:57 -08:00
Tom Eastep
d354560863
Finish last change.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-01 14:25:51 -08:00
Tom Eastep
f0d101605b
Don't try to combine nat chains that include '-s'.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-02-01 14:24:07 -08:00
Tom Eastep
1981372c94
Make search for "-j ACCEPT" a little tighter
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-31 08:27:30 -08:00
Tom Eastep
3d39a47582
Set $have_ipsec after completing parse of the hosts file.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-30 07:26:35 -08:00
Tom Eastep
659f774451
Sort %detect_capability for easier verification.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-29 13:09:53 -08:00
Tom Eastep
9d2decd26d
Modify determine_capabilities to use detect_capability()
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-29 10:38:22 -08:00
Tom Eastep
b8ec2be516
Clean up handling of %detect_capability
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-28 16:39:45 -08:00
Tom Eastep
ecc7861115
Validate LOAD_HELPERS_ONLY before detecting capabilities.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-28 08:05:24 -08:00
Tom Eastep
ebd847ef70
Don't display capabilties if they have not been determined
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-28 08:04:54 -08:00
Tom Eastep
05f2bb4b3a
Correction to last patch.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-27 17:52:27 -08:00
Tom Eastep
9d25318d80
Fix detection of HASHLIMIT_MATCH on old kernels.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-27 12:53:31 -08:00
Tom Eastep
54456de888
Update module versions
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-27 09:01:00 -08:00
Tom Eastep
c05c1a6f50
Update version to 4.4.7 RC1
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-27 06:58:44 -08:00
Tom Eastep
1556002b54
A couple of tweaks to the LOAD_HELPERS_ONLY optimization change.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-25 15:59:31 -08:00
Tom Eastep
fb007bc1c7
Bump version to Beta 4
2010-01-25 12:25:01 -08:00
Tom Eastep
9408a114c6
Don't load unused modules when LOAD_HELPERS_ONLY=Yes
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-25 10:50:49 -08:00
Tom Eastep
d933aa602b
Eliminate 'ORIGINAL_POLICY_MATCH'
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-25 08:13:22 -08:00
Tom Eastep
90b68a05de
Don't export %capabilities
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-25 07:56:16 -08:00
Tom Eastep
bfdc6719c1
Fix DropBcasts()
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-24 12:16:15 -08:00
Tom Eastep
e14d48c2cf
Bump version to 4.4.7-Beta3
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-22 16:46:29 -08:00
Tom Eastep
0d63182ab4
Fix ambiguous syntax in Config.pm
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-22 16:44:45 -08:00
Tom Eastep
199a50e1c7
Update version to 4.4.7 Beta 2
...
Add problems corrected to the release notes.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-22 10:35:27 -08:00
Tom Eastep
8f85c75264
Implement LOAD_HELPERS_ONLY for IPv6
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-21 15:49:44 -08:00
Tom Eastep
efc43b1b24
Add implementation of LOAD_HELPERS_ONLY
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-21 15:49:35 -08:00
Tom Eastep
a248acb4d4
Add LOAD_HELPERS_ONLY Option
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-21 15:49:23 -08:00
Tom Eastep
e119037dea
Make 'is_isable()' work with 'lo'
2010-01-17 15:38:20 -08:00
Tom Eastep
f072c10b18
Set version to 4.4.7 Beta1
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-17 09:10:48 -08:00
Tom Eastep
f4102417ff
Shorewall::Config changes for TPROXY from 4.5
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-17 08:15:14 -08:00
Tom Eastep
07cdb8ca82
Backport TPROXY from 4.5
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-17 08:12:44 -08:00
Tom Eastep
47007c5dbd
Allow protocol to be expressed in octal or hex
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-16 14:20:47 -08:00
Tom Eastep
aad8ea837a
Allow port numbers to be specified in Hex
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-16 14:00:47 -08:00
Tom Eastep
5ec7759d81
Don't pass an undefined value to fatal_error when numeric conversion fails.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-16 12:35:18 -08:00
Tom Eastep
4bf0b8e1dd
Add new configuration options and optimization changes from 4.5
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-16 09:53:53 -08:00
Tom Eastep
d5cc302ad9
Start 4.4.7
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-16 08:11:13 -08:00
Tom Eastep
ebf1e55609
Version to 4.4.6
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-13 15:38:19 -08:00
Tom Eastep
880cd269c7
More mark geometry misses
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-13 12:16:40 -08:00
Tom Eastep
72de96760f
One more 0xFF -> $globals{TC_MASK} fix
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-13 12:11:00 -08:00
Tom Eastep
10c5630786
A few more instances of TC_MASK
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-13 10:50:14 -08:00
Tom Eastep
555133fa3c
Bump version to 4.4.6-Beta2
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-13 10:14:31 -08:00
Tom Eastep
b4b6dce7c8
Add some comments
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-13 08:12:00 -08:00
Tom Eastep
4821d5e8b7
Change quantum to 1875 for simple TC SFQ.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-13 08:11:49 -08:00
Tom Eastep
f69a741691
Port Simplified TC to 4.4.6
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-12 17:01:20 -08:00
Tom Eastep
7e183e8eb4
Change version to 4.4.6-Beta1
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-12 15:57:55 -08:00
Tom Eastep
57672d096c
Don't invoke 4.5 optimization under 4.4.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-12 15:47:14 -08:00
Tom Eastep
ae31a09e8b
Move code and add comments:
...
- Declare all of the 'preview' helpers together in Chains.pm
- Add some clarifying comments in the compiler.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-12 15:32:59 -08:00
Tom Eastep
4420eed8d7
Allow users to preview the generated ruleset.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-12 15:32:50 -08:00
Tom Eastep
6b085b7897
Update module versions
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-11 18:54:23 -08:00
Tom Eastep
5b4e9eb8e6
Revert change with migration issue
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-11 15:30:33 -08:00
Tom Eastep
0b549c7a15
Suppress mark geometry output
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-11 14:55:42 -08:00
Tom Eastep
1a74dbf93e
Add mark geometry changes to Shorewall::Chains and Shorewall::Compiler
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-11 14:39:22 -08:00
Tom Eastep
01293427f5
Add Mark Geometry changes to Shorewall::Tc
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-11 14:29:34 -08:00
Tom Eastep
4f5bb5e90b
Add new mark geometry changes to Shorewall::Providers
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-11 14:22:01 -08:00
Tom Eastep
d2d2912534
Add New mark geometry variables to Shorewall::Config
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-11 14:16:03 -08:00
Tom Eastep
4e50ea14ea
Back out EXMARK detection since it is unused in 4.4.
...
Long overdue change to LIBVERSION
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-09 09:30:25 -08:00
Tom Eastep
b0feeb805d
Fix typo in clear_firewall()
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-09 07:28:57 -08:00
Tom Eastep
e6c0c8f6b7
Allow both <...> and [...] for IPv6 Addresses
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-08 13:55:13 -08:00
Tom Eastep
83c2473d78
Correct typo in error message
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-06 08:26:13 -08:00
Tom Eastep
ca4eee3ae4
Correct handling of 'refresh' failures
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-06 08:01:46 -08:00
Tom Eastep
605da92eca
Don't try to restore ipsets when 'restore' is being used to recover
...
from a start/restart failure.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-06 07:44:34 -08:00
Tom Eastep
d362af9fb6
Set CAPSVERSION to 4.4.7 just to be safe.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-05 10:00:29 -08:00
Tom Eastep
ab1dc03986
Implement EXMARK capability
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-05 09:35:11 -08:00
Tom Eastep
d6123a8fbc
Improve IPSET_SAVE restore logic:
...
- Call startup_error() rather than fatal_error()
- Call startup_error when restore-ipsets file exists but Shorewall is running
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-04 14:23:33 -08:00
Tom Eastep
4e0f9b2ef3
Make save/restore work with SAVE_IPSETS=Yes
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-04 12:43:12 -08:00
Tom Eastep
1aa55779e2
Re-enable SAVE_IPSETS=Yes
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-04 11:14:45 -08:00
Tom Eastep
a1fd3aa7e3
Add a hack to work around a 'feature' of xtables-addons on Lenny
...
Be more careful about checking for the ipset utility before saving the ipsets
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-04 10:15:27 -08:00
Tom Eastep
55e874b23f
Update copyrights
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-01-01 12:58:27 -08:00
Tom Eastep
65c282af8b
Delete temporary nat chain used in capabilities detection.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2009-12-31 10:42:21 -08:00
Tom Eastep
ea2ab6e4b6
A better solution to Marcus Limosani's issue
2009-12-29 08:22:15 -08:00
Tom Eastep
f568f3df9e
Final fix for Marcus Limosani's problem
2009-12-28 15:05:54 -08:00
Tom Eastep
738a6de11b
Make use of interface chains deterministic
2009-12-28 07:36:15 -08:00
Tom Eastep
f933816735
Simplify handling of packet clearing
2009-12-26 15:04:41 -08:00
Tom Eastep
d62f3a4fed
Set version to 4.4.6
2009-12-24 08:00:59 -08:00
Tom Eastep
f233b86278
Fix 'forward' interface option in IPv6
2009-12-24 07:51:44 -08:00
Tom Eastep
e38df7efcb
Fix another bug in ROUTE_FILTER Handling
2009-12-23 15:13:43 -08:00
Tom Eastep
e37cf0a370
Fix other issues with rp_filter fix
2009-12-20 15:54:41 -08:00
Tom Eastep
61b2ed7b57
Fix bug that prevented routefilter=2
2009-12-19 16:57:16 -08:00
Tom Eastep
d5914addd1
Disallow port 00
2009-12-19 14:59:03 -08:00
Tom Eastep
19af1a081c
Handle kernel 2.6.31 and rp_filter
2009-12-19 13:47:12 -08:00
Tom Eastep
4f4d77be48
Add Kernel Version to the capabilities
2009-12-19 12:42:39 -08:00
Tom Eastep
24ddacb4a7
Adjust module versions
2009-12-19 07:35:30 -08:00
Tom Eastep
10ae98571b
Revert change that allowed out of order policies
2009-12-19 07:20:00 -08:00
Tom Eastep
182ed24b02
Add a comment to process_rule1()
2009-12-14 15:52:16 -08:00
Tom Eastep
576cd76842
Remove superfluous logic from process_rule1
2009-12-14 14:49:38 -08:00
Tom Eastep
e9d12cfc11
Remove superfluous line of code
2009-12-14 07:17:55 -08:00
Tom Eastep
9988cfb619
Remove silly logic in expand_rule()
2009-12-10 08:00:18 -08:00
Tom Eastep
3214b14197
Fix macro handling of SOURCE and DEST columns
2009-12-08 13:29:06 -08:00
Tom Eastep
5e1f550b69
Fix ENHANCED_REJECT and MODULE_SUFFIX
2009-12-07 13:51:54 -08:00
Tom Eastep
7a6ad80c8a
Make kernel version detection work with non-standard version naming such as found on OpenWRT
2009-12-06 10:42:28 -08:00
Tom Eastep
4bf55883ee
Auto-load cls_flow
2009-12-03 12:15:23 -08:00
Tom Eastep
4494272dcd
Improve error message
2009-11-29 09:55:32 -08:00
Tom Eastep
8c033de049
Fix limit check on TC mark values
2009-11-28 14:05:27 -08:00
Tom Eastep
e582f222ad
Backout another Patch from the Virtual Zone Sequence and re-apply a couple of small optimizations
2009-11-28 07:25:31 -08:00
Tom Eastep
e5106f10bc
Revert 8ff4d004c0
2009-11-28 07:23:23 -08:00
Tom Eastep
4e8d753682
Revert "Finish Virtual Zones"
...
This reverts commit 222c8cf88f
.
2009-11-28 07:20:52 -08:00
Tom Eastep
d1812b4174
Revert "Fix a couple of bugs in virtual zones"
...
This reverts commit 22991ac9dd
.
2009-11-28 07:20:28 -08:00
Tom Eastep
038b84e775
Revert "Small optimization in virtual zones"
...
This reverts commit 251d7116c8
.
2009-11-28 07:20:01 -08:00
Tom Eastep
f21c71d7a6
Revert "Match section rules to the number of mark rules"
...
This reverts commit 1699d8e941
.
2009-11-28 07:19:41 -08:00
Tom Eastep
0b1621027b
Revert "Make 'virtual' a zone type rather than an option"
...
This reverts commit 18eedf7e34
.
2009-11-28 07:19:10 -08:00
Tom Eastep
ea2c55a993
Revert "Fix off-by-one problem"
...
This reverts commit 543af8bccb
.
2009-11-28 07:18:07 -08:00
Tom Eastep
f5bf3c9b43
Fix merge conflicts
2009-11-28 07:16:03 -08:00
Tom Eastep
7352771c5d
Fix .spec history to omit false steps
2009-11-27 12:29:11 -08:00
Tom Eastep
543af8bccb
Fix off-by-one problem
2009-11-27 08:56:23 -08:00
Tom Eastep
7f16e96167
Set version to 4.4.5 Beta1
2009-11-27 08:52:37 -08:00
Tom Eastep
18eedf7e34
Make 'virtual' a zone type rather than an option
2009-11-27 08:17:18 -08:00
Tom Eastep
1699d8e941
Match section rules to the number of mark rules
2009-11-26 17:12:11 -08:00
Tom Eastep
251d7116c8
Small optimization in virtual zones
2009-11-26 14:48:46 -08:00
Tom Eastep
22991ac9dd
Fix a couple of bugs in virtual zones
2009-11-26 14:19:10 -08:00
Tom Eastep
222c8cf88f
Finish Virtual Zones
2009-11-26 12:14:58 -08:00
Tom Eastep
8ff4d004c0
Better virtual zone implementation
2009-11-25 18:14:14 -08:00
Tom Eastep
8263ea1312
Limit providers to 15
2009-11-25 12:18:08 -08:00
Tom Eastep
d189c08533
Revert "Add 'virtual' zone support"
...
This reverts commit a2cd4bd1f4
.
2009-11-25 11:51:13 -08:00
Tom Eastep
a2cd4bd1f4
Add 'virtual' zone support
2009-11-25 09:42:28 -08:00
Tom Eastep
4c40b205f8
Revert "Experimental explicit CONTINUE"
...
This reverts commit 10056a03d9
.
2009-11-24 13:14:24 -08:00
Tom Eastep
10056a03d9
Experimental explicit CONTINUE
2009-11-24 12:50:53 -08:00
Tom Eastep
cd84efea94
Yet one more change to IPv6 address validation
2009-11-24 08:29:12 -08:00
Tom Eastep
deb45c5a27
Yet another IPv6 Address Normalization fix
2009-11-23 15:57:12 -08:00
Tom Eastep
bdb673a642
More IPv6 fixes
2009-11-23 15:21:25 -08:00
Tom Eastep
1710f9ce7c
Several fixes to IPv6 Address Handling
2009-11-23 14:44:53 -08:00
Tom Eastep
9d85d0ff7a
Allow IPv6 DNS names in net contexts
2009-11-23 13:51:46 -08:00
Tom Eastep
5610f78a48
Update version of Shorewall::Policy; improve 'expanded' description in Shorewall::Chains
2009-11-23 11:31:38 -08:00
Tom Eastep
99a35c1bf0
Allow <zone>::<serverport> in the rules file DEST column
2009-11-23 09:33:16 -08:00
Tom Eastep
5b02ef68a5
Simplify port == 0 test
2009-11-22 09:00:03 -08:00
Tom Eastep
d4ff629fd8
Generate error on port == 0
2009-11-22 08:44:11 -08:00
Tom Eastep
6e9d9e239d
Apply 4.4.4.1 changes to master
2009-11-22 08:20:07 -08:00
Tom Eastep
4aeee6fd8b
Make 'expanded' apply to all wildcard policies
2009-11-21 14:18:01 -08:00
Tom Eastep
c7de19cf39
Allow specific policy to supersede an expanded one
2009-11-21 13:56:40 -08:00
Tom Eastep
cbe944c354
Open the 4.5.0 Thread
2009-11-21 11:41:10 -08:00
Tom Eastep
ecf6a0ec4a
Open 4.4.5
2009-11-21 11:08:50 -08:00
Tom Eastep
bce4d51a18
Allow wide MARK values in tcclasses when WIDE_TC_MARKS=Yes
2009-11-21 07:54:42 -08:00
Tom Eastep
c5bb493b29
Fix class number assignment when WIDE_TC_MARKS=Yes
2009-11-20 12:25:15 -08:00
Tom Eastep
0df84cf8b5
Remove superfluous line of code
2009-11-19 10:54:58 -08:00
Tom Eastep
a23632f45e
Mostly cosmetic cleanup of Shorewall::Chains
2009-11-19 10:35:25 -08:00
Tom Eastep
c39a9fb5eb
Fix typo in shorewall-rules(5)
2009-11-18 19:55:20 -08:00
Tom Eastep
4579a71574
More massaging of redundant test suppression
2009-11-17 11:14:02 -08:00
Tom Eastep
831611e792
Update version of Shorewall::Policy
2009-11-16 20:24:01 -08:00
Tom Eastep
5f70b261b6
Update version of Shorewall::Compiler
2009-11-16 20:21:59 -08:00
Tom Eastep
5ec4f8d82c
Unconditionally include route marking and sticky chains
2009-11-16 14:15:01 -08:00
Tom Eastep
2a910ebddf
Suppress redundant tests for provider availability in route rules processing
2009-11-16 12:43:44 -08:00
Tom Eastep
016537f631
Don't add route rules when interface is down
2009-11-16 10:58:38 -08:00
Tom Eastep
dd543a2934
Tweak policies display
2009-11-16 09:30:37 -08:00
Tom Eastep
f5a019becc
Implement 'show policies' command
2009-11-15 09:24:56 -08:00
Tom Eastep
b662718eec
Replace canonical_chain by rules_chain
2009-11-14 07:07:19 -08:00
Tom Eastep
10affb1cde
Set version to 4.4.4
2009-11-13 13:52:49 -08:00
Tom Eastep
fa3bdde214
Set version to Beta2
2009-11-13 12:39:41 -08:00
Tom Eastep
0e6c9abb5b
A fix for COPY handling
2009-11-12 16:45:39 -08:00
Tom Eastep
f904866336
More minor cleanup of chain name change
2009-11-12 12:30:08 -08:00
Tom Eastep
2d53f8cb0c
Delete unnecessary function
2009-11-11 16:35:46 -08:00
Tom Eastep
b943f09e37
Fix indentation
2009-11-11 12:34:15 -08:00
Tom Eastep
4e6b8f8f42
Set version to 4.4.4-Beta1
2009-11-11 10:58:22 -08:00
Tom Eastep
0f078e7440
Ignore empty port in INTERFACE column
2009-11-11 10:52:14 -08:00
Tom Eastep
a4eb581d44
Document full logical interface implementation
2009-11-11 10:45:01 -08:00
Tom Eastep
06d3b2c692
Allow wildcard logical names in COPY column
2009-11-11 10:17:53 -08:00
Tom Eastep
6987cd15c5
Avoid dereference of null variable
2009-11-11 10:10:45 -08:00
Tom Eastep
ba8ad6346a
More use of logical chain name
2009-11-11 10:06:06 -08:00
Tom Eastep
893a847c87
Suppress extra COMMENT warnings
2009-11-10 17:17:55 -08:00
Tom Eastep
bf8c38e054
Add ZONE2ZONE option to shorewall.conf
2009-11-10 14:12:55 -08:00
Tom Eastep
7120a73f0e
Minor efficiency improvement in move_rules()
2009-11-10 08:08:02 -08:00
Tom Eastep
c9e57c93a2
Insure uniqueness of physical names; use logical name when constructing the name of a chain
2009-11-10 07:24:14 -08:00
Tom Eastep
4e2f2923b6
Update ::Config::VERSION
2009-11-09 13:16:40 -08:00
Tom Eastep
79b5cb49df
Fix over-zealous use of physical name; Correct syntax errors
2009-11-09 12:38:00 -08:00
Tom Eastep
893a0c9d42
Remove order dependency in interface OPTIONS processing
2009-11-09 11:15:08 -08:00
Tom Eastep
9b127e6e06
Improve performance of logical->physical mapping
2009-11-09 07:27:14 -08:00
Tom Eastep
92208251b7
Add undocumented LOGICAL_NAMES option
2009-11-09 07:01:25 -08:00
Tom Eastep
dda6f06883
Update module versions
2009-11-08 09:01:30 -08:00
Tom Eastep
4d977306f9
Make 'physical' work as a general logical name facility
2009-11-08 08:37:03 -08:00
Tom Eastep
83621ff416
Add logical->physical mapping to Shorewall::Chains
2009-11-08 07:11:38 -08:00
Tom Eastep
09f1b6501c
Add logical->physical mapping to Shorewall::Providers
2009-11-08 07:00:43 -08:00
Tom Eastep
ca1dd1416d
Add logical->physical mapping to Shorewall::Tc
2009-11-08 06:26:47 -08:00
Tom Eastep
1238b771a2
Apply logical->physical mapping to /proc settings
2009-11-07 18:59:10 -08:00
Tom Eastep
b1706e10e3
Correct typo
2009-11-07 07:58:15 -08:00
Tom Eastep
bcd4887d84
Correct capitalization in error message; remove unused variable
2009-11-07 07:39:28 -08:00
Tom Eastep
7f54a6fea9
Make non-wild physical work correctly
2009-11-07 07:19:52 -08:00
Tom Eastep
496cfc391e
Make parsing of zone options tighter
2009-11-06 15:51:53 -08:00
Tom Eastep
b491745f1c
More physical interface changes
2009-11-06 13:10:19 -08:00
Tom Eastep
4ef45ff665
Generate an error if a bridge port is configured as a provider interface
2009-11-06 09:22:16 -08:00
Tom Eastep
73eab1fa55
Report physical name in zone reports rather than logical name
2009-11-06 08:40:53 -08:00
Tom Eastep
d73ebb8a6a
Add comment explaining the purpose of dump_zone_contents()
2009-11-06 08:11:18 -08:00
Tom Eastep
7014bd3ea0
Add 'physical' interface option for bridge ports
2009-11-06 08:07:13 -08:00
Tom Eastep
89bdcf9a3d
Implement 'physical' option
2009-11-06 07:27:44 -08:00
Tom Eastep
a98195e156
Back out fix for multiple bridges with wildcard ports
2009-11-05 16:34:41 -08:00
Tom Eastep
fb3477b8b5
A couple of additional tweaks to the two-bridge fix
2009-11-05 13:40:03 -08:00
Tom Eastep
b4199fd068
Document ICMP codes
2009-11-05 11:44:40 -08:00
Tom Eastep
28b660c853
Avoid reporting bogus duplicate interface with two bridges and wildcard ports
2009-11-05 11:04:14 -08:00
Tom Eastep
4548db58da
Relax port list limitation in /etc/shorewall/routestopped
2009-11-03 11:36:32 -08:00
Tom Eastep
25549b176c
Update version to 4.4.4
2009-11-03 10:06:29 -08:00
Tom Eastep
5a525134ea
Be sure that startup log is secured 0600
2009-11-03 09:34:21 -08:00
Tom Eastep
f2f91ce7dd
Some optimizations
2009-11-03 09:28:34 -08:00
Tom Eastep
c893ba6ffa
Remove dependence of Shorewall::Rules on Scalar::Util
2009-11-03 07:40:06 -08:00
Tom Eastep
45653ffe79
A couple of more move_rules() tweaks
2009-11-02 15:35:00 -08:00
Tom Eastep
f97e0c5989
Flesh out fix for Perl run-time errors
2009-11-02 07:15:20 -08:00
Tom Eastep
11ddfa92e9
Eliminate Perl run-time errors out of move_rules()
2009-11-01 17:14:42 -08:00
Tom Eastep
59d01ccf97
A couple of tweaks to 'limit' class option
2009-10-27 12:33:14 -07:00
Tom Eastep
105754823a
Raise max limit to 128
2009-10-26 13:03:26 -07:00
Tom Eastep
f0b4b1f42e
Add limit option to tcclasses
2009-10-26 12:23:32 -07:00
Tom Eastep
cc0adc218f
Update comments and release documentation
2009-10-26 10:03:51 -07:00
Tom Eastep
8251948d2a
Add a comment
2009-10-24 15:55:56 -07:00
Tom Eastep
b3571261dd
Fix optional providers
2009-10-24 12:05:44 -07:00
Tom Eastep
3e2cf982a3
Correct messages issued when a provider is not added
2009-10-24 08:50:15 -07:00
Tom Eastep
86df82a29a
Fix IPv6 address validation error
2009-10-23 13:41:51 -07:00
Tom Eastep
46896e7dce
Fix for Ipv6
2009-10-23 11:34:13 -07:00
Tom Eastep
d0cda6b6ea
Add TRACK_PROVIDERS option
2009-10-20 13:24:17 -07:00
Tom Eastep
49f361124e
Make 'track' the default
2009-10-20 12:24:28 -07:00
Tom Eastep
7adb9b12bb
Move all function declarations from prog.footer6 to prog.header6
2009-10-19 07:37:49 -07:00
Tom Eastep
a0482132c6
Move all function declarations from prog.footer6 to prog.header6
2009-10-19 07:28:30 -07:00
Tom Eastep
abc9ab061a
Remove superfluous variables from generated script
2009-10-19 07:25:03 -07:00
Tom Eastep
65e4a5ff66
Move all functions from prog.footer to prog.header; minor tweaks elsewhere
2009-10-18 08:47:20 -07:00
Tom Eastep
0a74320bc2
Fix progress message
2009-10-17 14:23:11 -07:00
Tom Eastep
30dbfdc949
Fix intentation problem introduces with config-detection fix
2009-10-17 11:08:34 -07:00
Tom Eastep
e6755b7172
Merge nested zone fix into master
2009-10-17 10:59:41 -07:00
Tom Eastep
44c5ebcfa4
Fix initialization
2009-10-15 13:06:04 -07:00
Tom Eastep
19a90db09f
Back out last unnecessary change
2009-10-14 07:13:52 -07:00
Tom Eastep
990a9f0fdc
Fix RETAIN_ALIASES
2009-10-13 14:36:47 -07:00
Tom Eastep
80f41779f8
Replace keyword 'object' with 'script'
2009-10-12 08:24:47 -07:00
Tom Eastep
7064b8dd08
Update version of changed modules
2009-10-08 15:49:54 -07:00
Tom Eastep
3f7a1f9574
Rename a variable
2009-10-08 09:48:15 -07:00
Tom Eastep
83a9d8dd1b
Rename 'object' to 'script'
2009-10-05 15:43:29 -07:00
Tom Eastep
dc643c67e9
Move declaration to inner block where it is used
2009-10-05 14:23:43 -07:00
Tom Eastep
8089ef1599
Fix 'routeback' in routestopped file
2009-10-03 10:44:26 -07:00
Tom Eastep
964cba79a9
Initialize 4.4.3
2009-10-02 11:31:08 -07:00
Tom Eastep
a87cb7b95d
Generate list of builtins in initialize()
2009-10-01 15:02:14 -07:00
Tom Eastep
ddb46931a0
Update version
2009-10-01 08:44:05 -07:00
Tom Eastep
327e170be5
Fix range-in-masq patch
2009-10-01 08:16:22 -07:00
Tom Eastep
39ee3b2025
Tweak emitter
2009-09-29 14:28:50 -05:00
Tom Eastep
393673a884
Allow MARK in action body -- take 2
2009-09-25 16:15:56 -04:00
Tom Eastep
bfdc8db31a
Allow MARK in action body
2009-09-25 16:01:24 -04:00
Tom Eastep
d84458518e
Add capability to detect old hashlimit syntax
2009-09-23 16:56:31 -04:00
Tom Eastep
20250c9ce9
Hack to make new LIMIT stuff work on ancient iptables releases
2009-09-20 09:10:23 -04:00
Tom Eastep
96b19dd218
Fix accounting extension feature
2009-09-15 13:01:20 -07:00
Tom Eastep
120aade417
Allow Extension Scripts for Accounting Chains
2009-09-15 12:22:51 -07:00
Tom Eastep
4f4925002a
Revert "Allow Extension Scripts for Accounting Chains"
...
This reverts commit 728ad2fecf
.
2009-09-15 12:18:29 -07:00
Tom Eastep
728ad2fecf
Allow Extension Scripts for Accounting Chains
2009-09-15 11:16:37 -07:00
Tom Eastep
6afc43d200
Correct typo in comment
2009-09-13 09:20:32 -07:00
Tom Eastep
8fdbb6f252
Bump Nat.pm version; remove inadvertent paste
2009-09-13 09:13:50 -07:00
Tom Eastep
5793246d7c
Make processing of original dest in Format-1 macros more obvious
2009-09-13 09:01:34 -07:00
Tom Eastep
8fdebf0c38
Add new columns to macros
2009-09-13 08:09:40 -07:00
Tom Eastep
9b0a9e8ecd
Add -<family> to 'ip route del default' command
2009-09-12 08:48:52 -07:00
Tom Eastep
8c2a228a7d
Apply Jesse Shrieve's SNAT patch
2009-09-11 07:47:31 -07:00
Tom Eastep
f33e842f1b
Update module version
2009-09-10 14:56:23 -07:00
Tom Eastep
74aff4f4ef
Bump the version in a couple of modules modified for 4.4.2
2009-09-09 12:58:39 -07:00
Tom Eastep
212937a29d
Make 'map_old_actions' a little cleaner
2009-09-09 12:37:49 -07:00
Tom Eastep
0b03f52ad9
Don't look for extension script for built-in actions
2009-09-09 11:53:51 -07:00
Tom Eastep
5fc0137a2e
Update Compiler module version
2009-09-08 17:05:01 -07:00
Tom Eastep
128edd4bba
Slight optimization -- also makes code easier to read
2009-09-08 16:00:40 -07:00
Tom Eastep
b4712a93fa
Don't call compile_stop_firewall() during 'check'; call process_routestopped() instead - comments
2009-09-08 13:04:34 -07:00
Tom Eastep
5655dbb01b
Don't call compile_stop_firewall() during 'check'; call process_routestopped() instead
2009-09-08 12:54:23 -07:00
Tom Eastep
b03d502bbb
Allow comments on continued lines
2009-09-06 16:17:22 -07:00
Tom Eastep
70ebe17cb3
Reimplement MAPOLDACTIONS=Yes
2009-09-06 13:37:24 -07:00
Tom Eastep
7192b47289
Add a Lenny->Squeeze Howto
2009-09-06 09:51:32 -07:00
Tom Eastep
75eb186ea7
Split MASQ SOURCE warning into two separate warnings
2009-09-05 16:02:16 -07:00
Tom Eastep
ec94ed638e
Better modularization of Chains and Actions
2009-09-05 08:43:14 -07:00
Tom Eastep
bb8ad187f1
Update version to 4.4.2
2009-09-04 11:40:34 -07:00
Tom Eastep
03821dc22c
Process routestopped file during 'check'
2009-09-03 19:27:25 -07:00
Tom Eastep
76d9a80df3
A small optimization on the last restriction removal
2009-09-03 18:26:50 -07:00
Tom Eastep
84bff13e7f
Apply 4.4.1.2 fix to trunk
2009-09-03 18:25:32 -07:00
Tom Eastep
4a809e14ab
Documentation cleanup
2009-09-03 15:24:19 -07:00
Tom Eastep
df5291e119
Apply initialization fix to master branch
2009-09-03 14:54:47 -07:00
Tom Eastep
015d4f58ce
Allow moving rules with commands
2009-09-03 14:11:44 -07:00
Tom Eastep
4412a05a70
Fix detection of PERSISTENT_SNAT
2009-09-03 13:56:00 -07:00
Tom Eastep
62b1dbcd7f
Document portlist-splitting change
2009-09-02 15:30:26 -07:00
Tom Eastep
c9e9877f05
Combine port-list handling into a single function
2009-09-02 14:49:07 -07:00
Tom Eastep
9e09e61a1a
Delete blank line
2009-09-01 11:18:14 -07:00
Tom Eastep
b778f04b1a
Massage fix for multicast and nets=
2009-09-01 11:11:57 -07:00
Tom Eastep
b30da86cce
Fix automatic multicast with nets=
2009-09-01 08:56:54 -07:00
Tom Eastep
1544c0b2b1
Add some comments concerning "$|"
2009-08-31 10:41:08 -07:00
Tom Eastep
d368d80a12
More robust checking of zone definitions
2009-08-31 09:09:15 -07:00
Tom Eastep
5297bb8b8d
Fix undefined variable warning
2009-08-31 09:08:49 -07:00
Tom Eastep
2bb92a79f3
Fix silly hole in zones file parsing
2009-08-30 08:05:10 -07:00
Tom Eastep
b4f7b85b3b
Fix multicast network in Policy.pm
2009-08-29 09:26:46 -07:00
Tom Eastep
1ef00c547b
Disallow 'nets=' in a multi-zone interface definition
2009-08-29 07:41:27 -07:00
Tom Eastep
4809314fc1
Allow extending a zone defined with nets=
2009-08-29 07:20:16 -07:00
Tom Eastep
acfdc7e481
nets= allows multicast
2009-08-28 15:17:10 -07:00
Tom Eastep
383f3e8bcf
Fix nested IPSEC zones
2009-08-26 12:44:10 -07:00
Tom Eastep
52dfd5b259
Make cleanup after error explicit
2009-08-26 10:34:04 -07:00
Tom Eastep
db803807a7
Add comment regarding tcclass.guarantee
2009-08-26 10:32:57 -07:00
Tom Eastep
1b26c65cbc
Fix logging in rules at the end of INPUT and OUTPUT
2009-08-25 09:22:26 -07:00
Tom Eastep
088e164f18
Redefine 'full' when used in a sub-class definition
2009-08-24 11:56:16 -07:00
Tom Eastep
4eb9e5db3d
Correct example in the docs and ensure that future idiots don't place 'default' in the PRIO column of tcclasses
2009-08-24 06:25:26 -07:00
Tom Eastep
679cff2779
Correct example in the docs and ensure that future idiots don't place 'default' in the PRIO column of tcclasses
2009-08-23 20:45:05 -07:00
Tom Eastep
e24dbb9aea
Add 'clean' target to Makefiles
2009-08-23 10:43:01 -07:00
Tom Eastep
267bc808f5
Use 'set_command()' in the 'compile' case as well as the 'check' case
2009-08-22 09:39:15 -07:00
Tom Eastep
5ac331a5a0
Rename verbosity-oriented variables/functions
2009-08-22 07:57:55 -07:00
Tom Eastep
5dd41249c6
Remove trailing whitespace
2009-08-20 14:32:15 -07:00
Tom Eastep
8c16ac1d46
Update Module versions
2009-08-20 08:53:57 -07:00
Tom Eastep
ddf8bbe516
Remove some V4/V6 tests
2009-08-18 11:03:17 -07:00
Tom Eastep
1cf22ead7f
Correct allip() return value
2009-08-18 07:35:17 -07:00
Tom Eastep
90b0bedc43
More performance tweaks
2009-08-17 16:29:18 -07:00
Tom Eastep
787a1867a0
Another tiny performance enhancement
2009-08-17 12:58:50 -07:00
Tom Eastep
e756689d0c
Very minor performance tweak
2009-08-17 11:22:03 -07:00
Tom Eastep
89a6d7e5db
Tweak initialization comments
2009-08-17 10:45:46 -07:00
Tom Eastep
d8cc9c5c92
Fix capabilities test for PERSISTENT_SNAT
2009-08-17 08:07:58 -07:00
Tom Eastep
0557148bec
Avoid double globals initialization for IPv6
2009-08-16 09:24:51 -07:00
Tom Eastep
c908edab34
Add new capability for persistent SNAT
2009-08-15 08:35:54 -07:00
Tom Eastep
55f75604b3
Add support for 'persistent'
2009-08-15 08:15:38 -07:00
Tom Eastep
f042c641d6
Remove extraneous export
2009-08-15 07:01:06 -07:00
Tom Eastep
9b87812531
update version of Nat module
2009-08-14 15:03:59 -07:00
Tom Eastep
883f415e53
Start 4.4.1
2009-08-14 14:46:31 -07:00
Tom Eastep
2bac824207
Fix provider number in masq entry
2009-08-12 13:52:56 -07:00
Tom Eastep
5cb9ff0009
Fix 'upnpclient' on required interfaces
2009-08-11 08:31:58 -07:00
Tom Eastep
1a5027de9f
Restore ipset binding capability
2009-08-08 08:26:22 -07:00
Tom Eastep
70f46c02cc
Fix logging NAT rules
2009-08-05 12:48:14 -07:00
Tom Eastep
3efaef813f
Update version to 4.4.0
2009-08-03 10:16:37 -07:00
Tom Eastep
489e09a4d7
Propagate super option to parents
2009-07-29 15:33:47 -07:00
Tom Eastep
4af6c7650e
Correct handling of nested IPSEC zone
2009-07-29 14:35:27 -07:00
Tom Eastep
8d8920e7ad
Disallow ipsec zones nested within an ip zone
2009-07-29 07:49:06 -07:00
Tom Eastep
19736bcdbd
Update version to RC2
2009-07-28 13:45:26 -07:00
Tom Eastep
f2f8cab962
Make 'any' a reserved zone name
2009-07-26 12:29:37 -07:00
Tom Eastep
26cb2b1eeb
Allow Shorewall6 to recognize TC, IP and IPSET
2009-07-26 12:26:49 -07:00
Tom Eastep
c028fefa30
Fix 'disable_ipv6 -- take 2
2009-07-24 17:27:42 -07:00
Tom Eastep
fde24c16df
Fix 'disable_ipv6
2009-07-24 16:58:49 -07:00
Tom Eastep
c77f462d2d
Delete prog.functions and prog.functions6
2009-07-24 14:51:24 -07:00
Tom Eastep
45fffc7261
Replace 'edit' by 'validate' in compiler parameter handling logic
2009-07-22 10:43:53 -07:00
Tom Eastep
264126e9f5
Fix syntax error in last change
2009-07-22 10:43:15 -07:00
Tom Eastep
7f790e3aa2
Don't call generate_matrix() during 'check'
2009-07-21 14:13:26 -07:00
Tom Eastep
0204ea46a6
Ensure that move_rules doesn't crash in NONAT case
2009-07-16 15:59:59 -07:00
Tom Eastep
55045ace4b
Optimize nonat rules in certain cases
2009-07-16 11:05:37 -07:00
Tom Eastep
f16b2300b6
Remove references to Shorewall-shell, Shorewall-perl and prior Shorewall versions from the manpages
2009-07-15 17:50:55 -07:00
Tom Eastep
9c2966448e
Fix NONAT of sub-zone
2009-07-15 15:59:53 -07:00
Tom Eastep
8e9bef0a61
Fix routing with no providers
2009-07-15 13:03:49 -07:00
Tom Eastep
3bd9d31c05
Correct NOROUTE logic when no providers
2009-07-15 12:32:26 -07:00
Tom Eastep
17f61ad1c6
Optimize creation of /etc/iproute2/rt_tables
2009-07-15 12:22:31 -07:00
Tom Eastep
8f57a5d7a2
Some minor tweaks to the Providers module
2009-07-14 16:12:59 -07:00
Tom Eastep
d64b526319
Come cleanup of the Chains module
2009-07-13 16:54:39 -07:00
Tom Eastep
887a643f9e
Initiate RC1
2009-07-12 10:06:57 -07:00
Tom Eastep
75861185e0
Minor typo/cosmetic corrections
2009-07-12 09:26:25 -07:00
Tom Eastep
5bd3d710b7
Push version to Beta 4
2009-07-09 16:41:10 -07:00
Tom Eastep
bdd124b504
Derive IP6TABLES from IPTABLES
2009-07-09 10:29:56 -07:00
Tom Eastep
2142e92f8a
Remove add_command and replace all calls with calls to add_commands
2009-07-06 18:38:39 -07:00
Tom Eastep
f88048ebe4
More revert conflicts
2009-07-06 18:23:23 -07:00
Tom Eastep
050375b211
Delete DISABLE_IPV6 option
2009-06-29 18:33:13 -07:00
Tom Eastep
9dbafc59d0
Fix 'findgw'
2009-06-29 08:14:53 -07:00
Tom Eastep
25c2403f48
Update version to Beta 3
2009-06-27 08:26:41 -07:00
Tom Eastep
b2b6633ced
More on port list split/validation
2009-06-26 15:05:35 -07:00
Tom Eastep
cb681ab5ca
Fix for source port counting
2009-06-26 10:31:43 -07:00
Tom Eastep
900cfa0def
1) Cosmetic change to compiler.pl
...
2) Make 'purge_jump' handle '-g <target>' correctly
3) Minor effeciency changes to Chains.pm
2009-06-26 09:46:15 -07:00
Tom Eastep
40bb8283d2
Verify the availability of the LOG target
2009-06-25 13:50:27 -07:00
Tom Eastep
6eb202666c
Fix for mis-configured interfaces
2009-06-24 08:58:37 -07:00
Tom Eastep
bd55a545b5
Rename lib.user to lib.private
2009-06-20 09:35:08 -07:00
Tom Eastep
01d046fac9
Add lib.user extension script
2009-06-19 14:39:45 -07:00
Tom Eastep
117116eb4e
Add USER/GROUP column to /etc/shorewall/masq
2009-06-19 08:00:26 -07:00
Tom Eastep
927aa5f0e8
Additional fix up of optional interface handling.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2009-06-17 09:39:35 -07:00
Tom Eastep
b99444ab8b
Make new optional interface code work with shared providers
2009-06-17 07:30:01 -07:00
Tom Eastep
3483e8052a
Small optimization in lookup_provider()
2009-06-16 15:52:38 -07:00
Tom Eastep
64fd1167d1
replace a couple of instances of 'which' with 'mywhich'; relocate some global variable code
2009-06-16 15:39:04 -07:00
Tom Eastep
c00195e62a
Replace '_IS_UP' with '_IS_USABLE'
2009-06-16 14:25:13 -07:00
Tom Eastep
2a7491ebf2
More work on optional interfaces
2009-06-16 14:03:15 -07:00
Tom Eastep
58b2488459
Clean up 'upnpclient' implementation
2009-06-16 09:43:22 -07:00
Tom Eastep
abe07c9fae
Add 'upnpclient' interface option
2009-06-15 13:34:35 -07:00
Tom Eastep
b6410902a0
Relocate code that sets provider variables
2009-06-15 12:25:20 -07:00
Tom Eastep
8eb6ab7cc9
Set optional interface variables when there are no providers
2009-06-15 12:07:18 -07:00
Tom Eastep
c96db9a01c
Set optional provider variables when NOROUTE is true
2009-06-15 11:35:46 -07:00
Tom Eastep
440cc08802
Fix ORIGINAL DEST issue
2009-06-15 08:45:34 -07:00
Tom Eastep
894d4e5aa5
Update version to Beta2
2009-06-15 06:50:21 -07:00
Tom Eastep
a6d2497653
Integerize r2q before using it in a 'qdisc add' command
2009-06-14 14:29:12 -07:00
Tom Eastep
7440cd7d21
Correct 'help' in compiler.pl
2009-06-14 13:39:42 -07:00
Tom Eastep
e2ae6453ac
Replace 'Shorewall-perl' with 'Shorewall'
2009-06-13 07:07:55 -07:00
Tom Eastep
265e4fa546
First cut at 4.4
2009-06-12 15:51:43 -07:00
Tom Eastep
1025ca6002
Refine ee0667c9da
slightly
2009-06-12 07:34:31 -07:00
Tom Eastep
ee0667c9da
Fix mnemonic handling in tcfilters
2009-06-12 07:27:08 -07:00
Tom Eastep
a1330cbfdf
Purely cosmetic change in the Actions module
2009-06-10 14:31:22 -07:00
Tom Eastep
91b0e5aaa1
Update version and release docs to start work on 4.3.13
2009-06-07 10:52:53 -07:00
Tom Eastep
cb77458070
Allow INITLOG to be set in /etc/default/shorewall[6]; fix syntax error in Zones module
2009-06-07 08:07:56 -07:00
Tom Eastep
be8b352ee7
Cleanup of STDERR redirection; Update module versions
2009-06-05 15:12:59 -07:00
Tom Eastep
69c78676ad
Redirect STDERR to log
2009-06-05 13:49:23 -07:00
Tom Eastep
9ee0d05507
Update version to 4.3.12
2009-06-05 11:53:01 -07:00
Tom Eastep
c370dc650c
Remove support for 'norfc1918' and it's associated settings in shorewall.conf
2009-06-05 10:51:30 -07:00
Tom Eastep
7621859e0f
Fix 'findgw'
2009-06-04 13:03:56 -07:00
Tom Eastep
93b2227ce6
Add FAQ 36 re: BANDWIDTH_IN
2009-06-03 17:11:14 -07:00
Tom Eastep
7ecd3f0437
Correct previous commit
2009-05-29 07:21:51 -07:00
Tom Eastep
f2cb2cca9e
Suppress duplicate progress messages
2009-05-29 07:03:24 -07:00
Tom Eastep
d33532d6cd
Add TOS field to tcfilters
2009-05-28 16:41:14 -07:00
Tom Eastep
97fa7a0513
Add LENGTH column to tcfilters file
2009-05-28 14:29:33 -07:00
Tom Eastep
d35274d7d9
Minor cosmetic change to the source
2009-05-28 14:04:42 -07:00
Tom Eastep
7418e27308
Deimplement ipset binding support
2009-05-28 07:22:48 -07:00
Tom Eastep
d0d999488b
Fix silly bug in capabilities detection
2009-05-28 06:42:47 -07:00
Tom Eastep
0bd3b0c0af
Clarify requirement for RT parameters
2009-05-24 16:58:41 -07:00
Tom Eastep
a0071a21e8
Tweak and document HFSC implementation
2009-05-24 10:06:36 -07:00
Tom Eastep
d97a96b350
First implementation of HFSC queuing discipline
2009-05-23 17:07:57 -07:00
Tom Eastep
787caa7f32
First implementation of HFSC queuing discipline
2009-05-23 17:04:39 -07:00
Tom Eastep
4cf2c1b59f
Avoid 'large quantum' warnings during start/restart
2009-05-23 09:04:06 -07:00
Tom Eastep
110b6a613d
More code structure cleanup -- Providers.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2009-05-22 13:55:39 -07:00
Tom Eastep
d6c8cd5d3e
Warn if 'proxyarp' specified on a non-loose provider
2009-05-21 09:39:43 -07:00
Tom Eastep
ad6b47d3bf
More code rationalization
2009-05-19 17:11:56 -07:00
Tom Eastep
f75f4158b3
Add 'findgw' user exit
2009-05-11 14:35:20 -07:00
Tom Eastep
3162eff925
Support version 3 of dhclient
2009-05-10 12:22:23 -07:00
Tom Eastep
e97f7a622c
Update version to 4.3.11
2009-05-10 07:08:47 -07:00
Tom Eastep
e1771ebead
Externalize the 'flow' classifier
2009-05-08 14:05:27 -07:00
Tom Eastep
8f1ea63711
Make traffic shaping work better with IPv6
2009-05-08 13:30:47 -07:00
Tom Eastep
0e94016462
Delete error message -- it's also occurring on 2.6.28
2009-05-08 13:19:48 -07:00
Tom Eastep
7766855e98
More comments about failing 'tc filter add' command
2009-05-08 08:12:54 -07:00
Tom Eastep
d66fc7a7e1
Add warning when successful tc command returns non-zero exit status
2009-05-07 07:19:25 -07:00
Tom Eastep
c9538bbdee
Minor code cleanup in Tc
2009-05-06 13:40:18 -07:00
Tom Eastep
71480f38e2
Complete prior commit.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2009-05-06 09:49:06 -07:00
Tom Eastep
202d5f800e
1) Avoid multiple pri 65535 fw filters
...
2) Fix tcdevices > 9
3) Add some decimal/binary comments
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2009-05-06 09:47:13 -07:00
Tom Eastep
56016ca1bb
Improve interface number assignment
2009-05-06 07:07:38 -07:00
Tom Eastep
83bef182b1
Update some module versions
2009-05-05 18:11:49 -07:00
Tom Eastep
2125f3140f
Allow upper case A-F in Hex numbers
2009-05-05 16:23:37 -07:00
Tom Eastep
df42a82b01
Minor cosmetic improvements
2009-05-05 16:00:12 -07:00
Tom Eastep
404a7250b0
Some early code cleanup
2009-05-05 15:43:38 -07:00
Tom Eastep
5758ba3f69
Fix SCTP source port filtering
2009-05-05 14:13:05 -07:00
Tom Eastep
94a7df0cd5
Pass many fewer arguments while processing providers file and route_rules file
2009-05-05 11:38:45 -07:00
Tom Eastep
1b380fbbab
Pass many fewer arguments while processing masq rules
2009-05-05 11:31:47 -07:00
Tom Eastep
e68b571abe
Pass many fewer arguments while processing accounting rules
2009-05-05 11:25:56 -07:00
Tom Eastep
293987a383
Pass many fewer arguments while processing traffic shaping files
2009-05-05 11:23:01 -07:00
Tom Eastep
a23fc3c46c
Pass many fewer arguments while processing a record in /etc/shorewall/rules
2009-05-05 11:14:53 -07:00
Tom Eastep
c05071afc4
Another class number decimal/hex fix
2009-05-05 08:24:02 -07:00
Tom Eastep
624c24f2c0
Sequentially assign class numbers when WIDE_TC_MARKS=Yes
2009-05-05 07:50:46 -07:00
Tom Eastep
8f6130cca4
Update to nested classes; document nested classes in the release docs
2009-05-04 16:03:14 -07:00
Tom Eastep
03cd8350dc
Initial implementation of nested classes
2009-05-04 14:19:09 -07:00
Tom Eastep
d3cd3ea26c
Remove obsolete test
2009-05-04 13:25:21 -07:00
Tom Eastep
2db6130c26
Disallow 'occurs' with 'classify'; allow '<devname>:<classnum>' in tcclasses
2009-05-04 09:48:22 -07:00
Tom Eastep
13d3f86e23
Correct clearing of marks in POSTROUTING so that IPMARK works in the FORWARD table
2009-05-04 08:54:20 -07:00
Tom Eastep
b02dc1692f
Clean up latest occurs effort
2009-05-03 17:05:02 -07:00
Tom Eastep
f533468da0
Resolve merge conflicts
2009-05-03 09:56:13 -07:00
Tom Eastep
79adcb964f
Cosmetic improvements in tcclasses processing
2009-05-03 09:03:00 -07:00
Tom Eastep
90b07d849d
Fix compile for export
2009-05-03 09:01:33 -07:00
Tom Eastep
16826aeb31
Remove IPMARK support
2009-05-03 08:38:27 -07:00
Tom Eastep
626b60ff0e
Add error check
2009-05-02 17:28:50 -07:00
Tom Eastep
5e4196dafb
Fix occurs suffix handling
2009-05-02 16:19:50 -07:00
Tom Eastep
4a9a8534e3
Finish fast per-IP classifier
2009-05-02 16:01:48 -07:00
Tom Eastep
3e0a55f072
Fix 'all' in the SOURCE of DNAT- rules
2009-05-02 13:23:29 -07:00
Tom Eastep
2aecb9ac12
More tcfilter readability improvements
2009-05-02 10:47:23 -07:00
Tom Eastep
8216a4e721
Simplify tcfilter generation -- take 2
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2009-05-02 09:46:54 -07:00
Tom Eastep
ababc533f1
Revert "Vastly simplify generation of tc filters"
...
This reverts commit 22da513b3a
.
2009-05-02 09:33:21 -07:00
Tom Eastep
22da513b3a
Vastly simplify generation of tc filters
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2009-05-02 09:25:27 -07:00
Tom Eastep
c1cf1695c0
Deprecate interface names in the SOURCE column of /etc/shorewall/masq
2009-04-29 15:13:22 -07:00
Tom Eastep
7cf5c32358
Treat Class IDs as hex rather than as decimal numbers
2009-04-23 12:43:57 -07:00
Tom Eastep
7cd9a2a983
Replace 'pref' by 'prio' in 'tc xxx add' commands
2009-04-21 16:44:41 -07:00
Tom Eastep
b6090948dd
Allow compile to STDOUT
2009-04-21 09:41:23 -07:00
Tom Eastep
e465fea86a
Better fix for '-0x...' handling
2009-04-21 07:08:47 -07:00
Tom Eastep
846af27ebf
Fix Steven's other nit regarding -0x...
2009-04-20 20:39:38 -07:00
Tom Eastep
82bf6eb3f5
Revise WIDE_TC_MARKS classid generation
2009-04-20 17:54:33 -07:00
Tom Eastep
dcee6562a2
Fix another bug reported by Steven Springl
2009-04-20 16:35:48 -07:00
Tom Eastep
34791612b5
Implement WIDE_TC_MARKS. Fix problems reported by Steven Springl.
2009-04-20 13:26:47 -07:00
Tom Eastep
58fa0fe114
Clean up of shared optional provider fix
2009-04-20 10:28:18 -07:00
Tom Eastep
ec04636c86
Correct handling of optional shared providers
2009-04-20 08:30:15 -07:00
Tom Eastep
aa4afa6b66
Prepare 4.3.10
2009-04-19 17:37:36 -07:00
teastep
8d450e673c
Change classid generation algorithm
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9939 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-19 19:56:04 +00:00
teastep
0bb8fffcd9
Add support for IPMARK -- Phase II
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9937 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-19 16:47:40 +00:00
teastep
32a1ac87f5
Add IPMARK target support -- first phase
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9936 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-19 15:46:57 +00:00
teastep
3cb7186e90
Modify regression test to ensure that modification timestamp of the output file changes
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9935 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-19 14:19:40 +00:00
teastep
322a5de871
Recommit lost commit
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9934 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-18 18:48:28 +00:00
teastep
834064f3af
Cosmetic improvement to generated script
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9933 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-18 16:32:45 +00:00
teastep
985c551d26
Add IP, TC and IPSET configuration options
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9932 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-18 16:28:25 +00:00
teastep
b8988a2171
Handle empty setup_common()
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9930 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-18 16:20:06 +00:00
teastep
0cc60ea021
Avoid 'Invalid BROADCAST address' errors
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9919 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-17 22:57:59 +00:00
teastep
fd7108784f
Allow Shorewall6 on kernel 4.2.24
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9908 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-17 16:04:54 +00:00
teastep
ade958dd51
Add undocumented LOGMARK log level
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9851 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-12 15:22:19 +00:00
teastep
347090da6e
Correct netmask generation in tcfilters
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9850 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-12 15:22:00 +00:00
teastep
97e61965c0
Fix another inversion case
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9846 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-11 21:48:34 +00:00
teastep
de037034a5
Bump version to 4.3.9
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9845 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-11 15:31:25 +00:00
teastep
9bfc7b6d99
Tiny optimization.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9844 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-11 15:28:50 +00:00
teastep
c39fcc4db7
Optimization of log rule code
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9843 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-10 20:36:22 +00:00
teastep
b734d3af31
Fix subtle bug introduced in last commit
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9842 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-10 20:36:09 +00:00
teastep
20cfd0033c
Fix a 4.3 bug in expand_rule().
...
Don't repeat matches on target rule when log chain is used.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9841 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-10 19:47:39 +00:00
teastep
28e84a6aba
Break up long port lists in jump to logging chain
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9840 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-10 16:31:04 +00:00
teastep
e0040f4011
Small optimizations in expand_rule()
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9837 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-10 16:16:25 +00:00
teastep
ff014f328b
Correct usage text
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9836 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-10 16:15:36 +00:00
teastep
8278203e03
Remove one argument from expand_rule()
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9835 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-09 22:21:48 +00:00
teastep
f20013898e
Don't use -g when the target might not be terminating
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9834 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-09 20:18:11 +00:00
teastep
ae169f00a7
Implement rules that also log as a separate chain. Preserve original target in logging rules
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9833 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-09 18:45:21 +00:00
teastep
7d2b410904
Correct rule generation when an interface is specified as the destination of a PREROUTING rule.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9831 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-08 03:37:15 +00:00
teastep
28b6fd8033
Simplify hashlimit match code
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9830 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-07 18:15:51 +00:00
teastep
36e0c85f5f
Require the Hashlimit Match capability for per-IP rate limiting
...
Use the current key words in the generated hashlimit match
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9828 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-07 17:36:23 +00:00
teastep
c545e65cea
First part of 'hashlimit' implemenation
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9826 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-07 03:23:01 +00:00
teastep
b1e9453c62
The other half of the re-implementation of 'enable/disable_object'
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9825 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-07 03:22:49 +00:00
teastep
0744df13d6
Reimplement object_enable/disable
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9824 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-07 03:22:30 +00:00
teastep
b6053d8577
Fix second bug regarding ADD_IP_ALIASES=Yes
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9823 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-07 03:22:16 +00:00
teastep
844bb448c7
Fix inversion rules (omitted hunk)
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9797 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-04 15:09:17 +00:00
teastep
e2c5ad441a
Generate inversion that satisfies iptables 1.4.3.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9796 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-04 15:09:04 +00:00
teastep
77bbd88ab4
Cosmetic improvement in generated code for arp and route filtering.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9787 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-03 14:36:16 +00:00
teastep
54620a962e
Small optimization in "logmartians" fix. Update manpage to reflect new implementation
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9786 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-03 14:31:21 +00:00
teastep
8a9af0acf5
Fix LOG_MARTIANS=Yes
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9784 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-02 16:33:56 +00:00
teastep
29c8098d37
Cosmetic improvement in generated script.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9780 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-01 19:53:38 +00:00
teastep
ef50c0be25
More removal of SAME target
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9775 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-01 01:31:16 +00:00
teastep
dbf23f64e2
Removal of SAME support
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9774 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-01 01:31:04 +00:00
teastep
35790476a3
Fix bug in Shorewall::Rules::process_rule1()
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9773 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-01 00:04:04 +00:00
teastep
d3a54e626c
De-implement $Shorewall::Config::object_enabled and associated methods
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9772 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-04-01 00:03:51 +00:00
teastep
d00f52f933
Fix run-time error in Shorewall::process_rules1()
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9771 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-31 22:42:49 +00:00
teastep
39131f3809
Some optimizations in Shorewall::Rules::compile_stop_firewall()
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9770 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-31 22:42:37 +00:00
teastep
6c205d922a
Add AUTOMAKE option
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9767 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-31 17:31:23 +00:00
teastep
22526979db
Make generation of 'stop' ruleset activation more foolproof.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9764 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-30 19:58:26 +00:00
teastep
b215f91d4a
Pass input directly to iptables[6]-restore during stop
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9763 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-30 18:33:30 +00:00
teastep
715554e579
Cleanup of iptables-restore/stop code. Don't purge ipsets on stop.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9762 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-30 18:00:23 +00:00
teastep
cddd1b1ae9
Use iptables[6]-restore to instantiate the 'stopped' ruleset
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9761 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-30 00:49:00 +00:00
teastep
7210e8c15e
Move generation of stop_firewall() to the end of the compilation sequence
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9760 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-29 17:52:24 +00:00
teastep
adb9830e9e
Move 'compile_stop_firewall' to Shorewall::Rules
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9743 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-28 19:22:15 +00:00
teastep
d9622dabfe
Centralize iptables knowledge in the Chains module -- first phase
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9742 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-28 19:21:36 +00:00
teastep
b663644d0d
Ignore leading white space on certain continuation lines
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9740 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-27 16:55:51 +00:00
teastep
d67c94de9c
Move extension script handling to generate_script_1()
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9739 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-26 18:18:09 +00:00
teastep
9328f0fc4c
Detect dhclient dynamic gateway
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9734 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-24 20:58:04 +00:00
teastep
6013e8b53d
Improve error message for startup errors. Document in release documents.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9730 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-23 22:51:05 +00:00
teastep
1545d62ba9
Update version by hand
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9729 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-23 22:50:04 +00:00
teastep
1ff093b1c0
Minor tweak to Shorewall::Zones
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9724 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-21 22:46:16 +00:00
teastep
bb8e562d18
Detect IP configuration early in start/restart so that stopping the fireawall isn't necessary in the case of failure.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9722 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-21 16:45:27 +00:00
teastep
6dac69554f
Apply Tuomo Soini's patch for USE_DEFAULT_RT
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9704 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-19 14:04:57 +00:00
teastep
2734d2b8cb
Change 'flow' filter rule (which still doesn't work :-()
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9702 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-18 21:33:28 +00:00
teastep
08cd0684ec
Use new syntax in standard actions. Add additional comments in Shorewall::Config
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9695 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-16 16:37:21 +00:00
teastep
fc3a2fc386
Add explanation of maximum zone length
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9690 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-15 15:54:29 +00:00
teastep
229e573c3c
Make zone type numeric for faster comparison
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9684 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-13 22:59:49 +00:00
teastep
e75789d894
A few minor changes in Shorewall::Chains.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9682 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-11 01:16:45 +00:00
teastep
77444634e1
Correct fatal error message generated by assert()
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9675 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-09 21:45:30 +00:00
teastep
ce5efc5dfa
Add a comment
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9674 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-09 21:45:18 +00:00
teastep
5a6d66f263
Replace discrete tests with calls to fatal_error() with calls to assert();
...
second batch
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9673 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-09 20:57:18 +00:00
teastep
b987ea4940
Replace discrete tests with fatal_error() calls with assert() calls.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9672 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-09 20:56:53 +00:00
teastep
70570c4a18
Change policy->{is_optional} to policy->{provisional}
...
Signed-off-by: Tom Eastep <teastep@ursa.(none)>
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9668 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-09 16:28:29 +00:00
teastep
faa8a9ec2d
Cosmetic changes to four Perl Modules
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9626 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-08 16:51:22 +00:00
teastep
dcee4a3d08
Commit updates from Git
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9625 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-08 01:40:35 +00:00
teastep
94bd270bcd
Delete 'routefilter' from valid hosts file options
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9623 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-07 23:30:19 +00:00
teastep
ec52331dfc
More port OPTIONS changes
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9622 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-07 20:22:20 +00:00
teastep
3d92f7a016
More tweaks to ipset management
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9615 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-07 00:39:04 +00:00
teastep
a7126b6b4c
First working dynamic zone implementation
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9612 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-06 17:00:38 +00:00
teastep
f788e4ecb3
Reincarnation of Dynamic Zones -- Phase II
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9611 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-06 04:08:07 +00:00
teastep
3795f02f70
Reincarnation of Dynamic Zones -- Phase I
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9610 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-06 00:14:42 +00:00
teastep
be8e9990bd
Back out silly part of last change
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9608 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-05 20:27:22 +00:00
teastep
410e551a69
Re-enable list-valued return from validate_4address()
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9606 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-05 19:56:24 +00:00
teastep
062c7ec822
Change 'Provides' for Shorewall6-lite
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9605 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-05 16:18:58 +00:00
teastep
14673e4ab5
Detect bogus DNAT- rule
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9600 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-05 04:03:05 +00:00
teastep
661029a38e
Cosmetic Change
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9599 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-05 04:02:03 +00:00
teastep
36b87dff49
Put all Perl components in a common directory -- Phase I
...
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@9595 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
2009-03-04 22:41:56 +00:00