Tom Eastep
|
b55b6a913c
|
Insert the server address list into the error message in DNAT/REDIRECT
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-06-08 09:36:18 -07:00 |
|
Tom Eastep
|
9c9ae04c86
|
Raise an error when a server list is specified in a DNAT or REDIRECT rule
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-06-08 08:52:41 -07:00 |
|
Tom Eastep
|
c898129ad6
|
Correct pi-rho's patch to not deal with the loopback interface
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-06-06 13:12:02 -07:00 |
|
Tom Eastep
|
7adc16ace9
|
Merge branch 'master' of ssh://git.code.sf.net/p/shorewall/code
|
2014-06-06 12:45:36 -07:00 |
|
Tuomo Soini
|
7b38bc9558
|
remove optional SSH and WS-MAN from IPMI macro and only document
vendors which are tested to work
Signed-off-by: Tuomo Soini <tis@foobar.fi>
|
2014-06-06 22:15:37 +03:00 |
|
Tom Eastep
|
2cd5c41ec0
|
Clean up white space in pi-rho's patch
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-06-06 10:44:33 -07:00 |
|
Tom Eastep
|
bea5434de6
|
Merge branch '4.5.21'
|
2014-06-06 10:05:02 -07:00 |
|
Tom Eastep
|
8657dd97f7
|
Apply pi-rho's patch for rpfilter.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-06-06 10:04:42 -07:00 |
|
Tom Eastep
|
ef038d5eab
|
Merge branch 'master' of ssh://git.code.sf.net/p/shorewall/code
|
2014-06-04 15:21:05 -07:00 |
|
Tuomo Soini
|
b6ea20e7df
|
Added macro IPMI for Remote Console Protocl (RMCP)
Signed-off-by: Tuomo Soini <tis@foobar.fi>
|
2014-06-02 23:48:30 +03:00 |
|
Tom Eastep
|
6632afaf6a
|
Merge branch 'master' of ssh://git.code.sf.net/p/shorewall/code
|
2014-06-02 12:21:18 -07:00 |
|
Tuomo Soini
|
0f55863076
|
Add new macros for AMQP, MongoDB, Redis, and Sieve
Signed-off-by: Tuomo Soini <tis@foobar.fi>
|
2014-06-02 21:24:09 +03:00 |
|
Tom Eastep
|
954cddc37a
|
Enable 1:1 NAT in IPv6
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-05-25 12:50:00 -07:00 |
|
Tom Eastep
|
24721e01b6
|
Document nat vs. subzone restriction.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-05-25 10:07:07 -07:00 |
|
Tom Eastep
|
5a22b14947
|
Enable 1:1 NAT in IPv6
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-05-25 08:57:01 -07:00 |
|
Tom Eastep
|
89c5d5080b
|
A couple more tweaks to the masq manpages
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-05-22 11:14:46 -07:00 |
|
Tom Eastep
|
66b3d9aeb5
|
Correct the heading of the SOURCE masq column
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-05-22 09:07:00 -07:00 |
|
Tom Eastep
|
966926fac5
|
RHE7 support -- first cut
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-05-19 15:15:52 -07:00 |
|
Tom Eastep
|
dcc2fb27c5
|
Apply Tuomo Soini's whitespace patch
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-05-19 14:18:48 -07:00 |
|
Tom Eastep
|
6d3b1d80d4
|
Make 'update -A' convert the tcrules file
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-05-16 14:46:15 -07:00 |
|
Tom Eastep
|
d5e83a5295
|
Delete extra blank line from the IPv4 mangle file
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-05-16 12:11:11 -07:00 |
|
Tom Eastep
|
7835feb45e
|
Apply Simon Mater's cosmetic fix to the 'mangle' files.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-05-16 07:31:44 -07:00 |
|
Tom Eastep
|
c6565f051e
|
Clean up checking for chain designators with SOURCE $FW.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-05-16 07:18:35 -07:00 |
|
Tom Eastep
|
c9b6d4a670
|
Correct CHECKSUM handling
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-05-16 07:18:06 -07:00 |
|
Tom Eastep
|
00d3a94bfd
|
Make all actions FORMAT-2
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-05-09 09:01:29 -07:00 |
|
Tom Eastep
|
d15956feea
|
Deprecate FORMAT-1 actions and macros
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-05-08 14:30:33 -07:00 |
|
Tom Eastep
|
f717d097d7
|
Apply Tuomo Soini's Macro format patch
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-05-07 12:19:24 -07:00 |
|
Tom Eastep
|
670c33d20b
|
Update install files to secure the .service files as 644 rather than 600.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-05-01 11:43:59 -07:00 |
|
Tom Eastep
|
bcbb48d16e
|
Update install files to secure the .service files as 644 rather than 600.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-05-01 11:43:00 -07:00 |
|
Tom Eastep
|
2b43c28e98
|
Add tabs to mangle files
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-04-20 07:56:43 -07:00 |
|
Tom Eastep
|
ba3a7d0621
|
Do not deprecate USE_DEFAULT_RT
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-04-19 07:53:18 -07:00 |
|
Tom Eastep
|
15507aa265
|
Update sample rules files
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-04-19 07:48:42 -07:00 |
|
Tom Eastep
|
4d4e8b3df4
|
Do nothing when a rules file section is empty.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-04-18 14:13:34 -07:00 |
|
Tom Eastep
|
240d3d8cab
|
Improve interface option inheritence
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-04-18 13:36:06 -07:00 |
|
Tom Eastep
|
acda5482c4
|
If USE_DEFAULT_RT isn't specified, make it 'No'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-04-18 13:22:58 -07:00 |
|
Tom Eastep
|
e731ea1ca8
|
Revert "Always inherit interface options"
This reverts commit 65cde3475f .
|
2014-04-15 11:54:58 -07:00 |
|
Tom Eastep
|
65cde3475f
|
Always inherit interface options
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-04-15 11:37:51 -07:00 |
|
Tom Eastep
|
b3cd9ab15a
|
Default to LOAD_HELPERS_ONLY=Yes
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-04-12 11:05:28 -07:00 |
|
Tom Eastep
|
fdc391cf49
|
Change all *.conf files to reflect ZONE2ZONE=-
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-04-11 20:44:15 -07:00 |
|
Tom Eastep
|
58700b2301
|
Correct the behavior of rpfilter when FASTACCEPT=Yes
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-31 07:29:29 -07:00 |
|
Tom Eastep
|
a9ac9c274e
|
Correct the behavior of rpfilter when FASTACCEPT=Yes
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-31 07:28:30 -07:00 |
|
Tom Eastep
|
72869adcd6
|
Correct missing comment in trace entry.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-28 08:55:55 -07:00 |
|
Tom Eastep
|
0c8365001d
|
Avoid spurious comments on jumps to section chains.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-28 08:55:48 -07:00 |
|
Tom Eastep
|
6274f8444f
|
Correct missing comment in trace entry.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-28 08:55:23 -07:00 |
|
Tom Eastep
|
05816e94ee
|
Avoid spurious comments on jumps to section chains.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-28 08:55:00 -07:00 |
|
Tom Eastep
|
0561b10adb
|
Merge branch 'master' of ssh://server.shorewall.net/home/teastep/shorewall/code
|
2014-03-22 08:58:20 -07:00 |
|
Tom Eastep
|
db1b25b4d7
|
Restore small mark verification.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-22 08:38:57 -07:00 |
|
Tom Eastep
|
4de651ff55
|
Add a comment line
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-19 10:38:41 -07:00 |
|
Tom Eastep
|
5981ce59e3
|
Include -t <table> in debug_restore_input() error message
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-19 10:25:37 -07:00 |
|
Tom Eastep
|
54a5e4af52
|
A couple of minor tweaks to the Chains module.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-19 10:24:30 -07:00 |
|
Tom Eastep
|
4bd8d9791c
|
Include -t <table> in debug_restore_input() error message
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-18 07:28:14 -07:00 |
|
Tom Eastep
|
eb70234c52
|
Correct some typos in the .conf manpages
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-12 14:50:15 -07:00 |
|
Tom Eastep
|
39b7527cb6
|
Include rule priority in delete of generated address route rules.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-10 08:25:59 -07:00 |
|
Tom Eastep
|
08d29edf1a
|
Include rule priority in delete of generated address route rules.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-10 08:24:38 -07:00 |
|
Tom Eastep
|
20b10582b4
|
Moew deprecation of USE_DEFAULT_RT=No
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-10 08:24:12 -07:00 |
|
Tom Eastep
|
093ff580b5
|
Deprecate USE_DEFAULT_RT=No.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-09 07:48:05 -07:00 |
|
Tom Eastep
|
cea237620a
|
Change USE_DEFAULT_RT default to 'Yes'.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-09 07:42:22 -07:00 |
|
Tom Eastep
|
c9d7370fb4
|
Merge branch '4.5.21'
Conflicts:
Shorewall/manpages/shorewall.conf.xml
Shorewall6/manpages/shorewall6.conf.xml
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-05 09:00:34 -08:00 |
|
Tom Eastep
|
8b4d8bfa16
|
Finish ADMINISABSENDMINDED change
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-05 08:57:03 -08:00 |
|
Tom Eastep
|
caa72fb7d2
|
Correct routestopped files.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-03-02 10:39:12 -08:00 |
|
Tom Eastep
|
4eadec234a
|
Revert "Correct the behavior of ADMINISABSENTMINDED"
This reverts commit ded747a51a .
|
2014-03-02 08:25:05 -08:00 |
|
Tom Eastep
|
2b489993ca
|
Revert "Correct the behavior of ADMINISABSENTMINDED"
This reverts commit df09e0ccc5 .
|
2014-03-02 08:23:23 -08:00 |
|
Tom Eastep
|
ded747a51a
|
Correct the behavior of ADMINISABSENTMINDED
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-02-28 10:14:33 -08:00 |
|
Tom Eastep
|
df09e0ccc5
|
Correct the behavior of ADMINISABSENTMINDED
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-02-28 10:14:08 -08:00 |
|
Tom Eastep
|
454e53bcfa
|
Reformat preceding patch and correct syntax errors.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-02-25 13:21:23 -08:00 |
|
Tom Eastep
|
66fdc9f6a7
|
Call directive_callback for directives without '?'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-02-25 12:48:25 -08:00 |
|
Tom Eastep
|
c74235a200
|
Correct typos
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-02-17 14:17:49 -08:00 |
|
Tom Eastep
|
1759fc75b0
|
Correctly handle alternate specification with ';' in 'update -t'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-02-17 14:10:17 -08:00 |
|
Tom Eastep
|
3e87efc82b
|
Document -t option
- Also copy compiler directives to the mangle file.
|
2014-02-17 12:50:59 -08:00 |
|
Tom Eastep
|
a011ad8efe
|
Add raw matches to the converted mangle file.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-02-16 09:59:13 -08:00 |
|
Tom Eastep
|
0e40a42729
|
Allow SAVE and RESTORE in the postrouting chain
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-02-16 09:50:43 -08:00 |
|
Tom Eastep
|
69fe94ef08
|
Document the -t option
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-02-16 09:25:58 -08:00 |
|
Tom Eastep
|
669d15e2cf
|
Implement the -t update option.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-02-15 09:36:13 -08:00 |
|
Tom Eastep
|
708d58da21
|
Revert "Replace SECTION with ?SECTION in the rules file."
This reverts commit 34207fef1a .
|
2014-02-13 08:23:34 -08:00 |
|
Tom Eastep
|
34207fef1a
|
Replace SECTION with ?SECTION in the rules file.
|
2014-02-12 13:25:36 -08:00 |
|
Tom Eastep
|
2dbcd36a9c
|
Implement BASIC_FILTERS
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-02-04 16:34:03 -08:00 |
|
Tom Eastep
|
0383ca7de6
|
Correct semantics of ipset lists in tcfilters
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-02-04 12:27:46 -08:00 |
|
Tom Eastep
|
7ddc65133e
|
Support ipset lists in the tcfilters file.
- Also document the fact that ipset match options are not available in
the tcfilters file.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-02-04 12:16:35 -08:00 |
|
Tom Eastep
|
1d4a87a0d0
|
Excape an opening parehthesis.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-02-04 12:15:35 -08:00 |
|
Tom Eastep
|
3b3608ad65
|
Correct ICMP handling in basic filters.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-02-04 07:16:41 -08:00 |
|
Tom Eastep
|
081a387f1d
|
Fix some bugs in basic filter generation.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-02-03 14:59:27 -08:00 |
|
Tom Eastep
|
fbb03248c4
|
Correct 'dump' help text
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-02-02 13:01:42 -08:00 |
|
Tom Eastep
|
033a1a0367
|
Correct 'dump' help text
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-02-02 13:00:41 -08:00 |
|
Tom Eastep
|
c08655e0bc
|
Document ipset use in tcfilters
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-02-01 09:40:39 -08:00 |
|
Tom Eastep
|
50fb8e3f2f
|
Use HEX representation for matching IPv6 addresses in basic filters.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-01-31 12:49:47 -08:00 |
|
Tom Eastep
|
f029f5b483
|
Correct handling of logging of a non-terminating target
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-01-29 08:22:31 -08:00 |
|
Tom Eastep
|
86f667afd4
|
Correct handling of logging of a non-terminating target
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-01-29 08:19:53 -08:00 |
|
Tom Eastep
|
8a63053c13
|
Correct defects found in unit testing
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-01-21 20:19:56 -08:00 |
|
Tom Eastep
|
62557cb98e
|
Correct defects found during testing of ematch.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-01-21 12:53:33 -08:00 |
|
Tom Eastep
|
9c4089fc99
|
Initial basic filter implementation.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-01-20 18:40:40 -08:00 |
|
Tom Eastep
|
44e0d48fc5
|
Add <refmiscinfo>...</refmiscinfo> to remaining manpages
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-01-16 08:32:57 -08:00 |
|
Tom Eastep
|
5a649dc205
|
Add <refmiscinfo>...</refmiscinfo>
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-01-16 07:44:23 -08:00 |
|
Tom Eastep
|
89fd5ced15
|
Merge branch 'master' of ssh://git.code.sf.net/p/shorewall/code
|
2014-01-12 14:05:48 -08:00 |
|
Roberto C. Sanchez
|
b1a490b50a
|
Cleanup links in manpages so that hrefs in generated HTML don't take the user to a different server
|
2014-01-12 16:40:03 -05:00 |
|
Tom Eastep
|
a35b7821bf
|
Correct stoppedrules manpages re DROP
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-01-07 13:30:09 -08:00 |
|
Tom Eastep
|
fd28a12653
|
Allow DROP in the stoppedrules file
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-01-07 13:19:49 -08:00 |
|
Tom Eastep
|
7e6fc3229d
|
Correct handling of default chain when a mark range is specified.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-01-07 13:15:51 -08:00 |
|
Tom Eastep
|
42dd8dfee9
|
Change license to GPLv2+ and update copyrights
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-01-04 09:48:27 -08:00 |
|
Tom Eastep
|
5a7e458104
|
Backout ematch stuff for now
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-01-03 12:01:56 -08:00 |
|
Tom Eastep
|
7e1a310929
|
Implement ipset matches in tcfilters
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2014-01-03 09:35:34 -08:00 |
|