Tom Eastep
|
e0a222938a
|
Merge branch '4.5.19'
|
2013-07-27 08:14:35 -07:00 |
|
Tom Eastep
|
bf15b859bc
|
Clarify the relationship between ROUTE_FILTER and routefilter.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-07-27 08:09:23 -07:00 |
|
Tom Eastep
|
aabb22a50f
|
Add the TRACK_RULES option
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-07-24 07:22:51 -07:00 |
|
Tom Eastep
|
765b748283
|
Documentation updates
- Add meaningful IDs to some sections in Events.xml
- Correct typos in the accounting manpages
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-07-22 07:54:45 -07:00 |
|
Tom Eastep
|
d6d0cad2f9
|
Add 'show event[s]' to manpages.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-07-12 10:37:27 -07:00 |
|
Tom Eastep
|
4bd35a0b93
|
Allow 'routeback=0'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-06-16 08:37:53 -07:00 |
|
Tom Eastep
|
53f1cd40df
|
Add 'unmanaged' option
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-06-10 12:36:18 -07:00 |
|
Tom Eastep
|
a48a4b7a2e
|
Don't allow fowarding between local zones.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-05-28 06:14:44 -07:00 |
|
Tom Eastep
|
2de0fbf7d0
|
Change 'local' to 'loopback' and add 'local' zones that match non-loopback interfaces.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-05-26 14:06:51 -07:00 |
|
Tom Eastep
|
fd11eb7d82
|
Omit fw->fw jumps when there is a local zone.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-05-22 09:19:34 -07:00 |
|
Tom Eastep
|
ac02c484f5
|
Change 'local' interface option to a zone type.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-05-19 15:35:20 -07:00 |
|
Tom Eastep
|
b38f1416aa
|
Mention "all+' in the "Important" notes at the top
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-05-13 13:41:12 -07:00 |
|
Tom Eastep
|
c8133145e6
|
Add support for "all+" in the policy file.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-05-13 09:01:12 -07:00 |
|
Tom Eastep
|
e3d9b2762d
|
Add 'destonly' and 'local' to the interface manpages.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-05-12 12:48:58 -07:00 |
|
Tom Eastep
|
7215b61aa4
|
Document changes introduced by Mr-4.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-05-07 10:16:38 -07:00 |
|
Tom Eastep
|
577db69719
|
Support conditional compilation.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-05-07 09:36:02 -07:00 |
|
Roberto C. Sanchez
|
a0228e9d3b
|
Fix typos in manpages
|
2013-05-03 12:19:45 -04:00 |
|
Tom Eastep
|
8bb03a741d
|
Update blrules manpages
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-24 08:17:10 -07:00 |
|
Tom Eastep
|
f543c3bd1e
|
Finish Mr-4's NFACCT patch
- Correct indentation
- Remove '$type' argument to split_nfacct_list
- Update manpages.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-23 06:55:30 -07:00 |
|
Tom Eastep
|
5ad69aa650
|
Add CHAIN_SCRIPTS option
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-21 07:30:31 -07:00 |
|
Tom Eastep
|
a56dcc745d
|
Clarify <chain>:COUNT in the accounting files.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-20 17:11:46 -07:00 |
|
Tom Eastep
|
1b9fd642bb
|
Add INLINE to the accounting file.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-20 08:02:02 -07:00 |
|
Tom Eastep
|
1fd62e1612
|
Restore order in the NFACCT target.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-19 11:11:37 -07:00 |
|
Tom Eastep
|
6c2679ce75
|
Allow incrementing an nfacct object when an ipset matches.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-19 10:44:57 -07:00 |
|
Tom Eastep
|
91c4dd2e56
|
Document multiple nfacct objects in one rule.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-19 06:38:02 -07:00 |
|
Tom Eastep
|
8ef11a376b
|
Document 'HELPERS=none'.
- Also make 'check -u' work correctly regarding HELPERS=
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-18 11:30:47 -07:00 |
|
Tom Eastep
|
ef01748dc9
|
Update manpages for INLINE
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-04-17 07:34:00 -07:00 |
|
Tom Eastep
|
b5ea4067e4
|
Implement USE_RT_NAMES
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-03-24 10:56:38 -07:00 |
|
Tom Eastep
|
1e866eac28
|
Implement the other forms of NULL routing.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-03-16 08:20:52 -07:00 |
|
Tom Eastep
|
6e9fc77f73
|
Remove nonsensical comment from the stoppedrules manpage
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-03-09 08:15:13 -08:00 |
|
Tom Eastep
|
fe6533943c
|
Correct 'routes' manpages.
- change 4.5.15 with 4.5.14 for the availability of blackhole routes
- Add 'main' to the legal providers.
|
2013-03-08 08:26:08 -08:00 |
|
Tom Eastep
|
06e7f297f7
|
Allow addition of blackhole routes.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-03-06 11:48:09 -08:00 |
|
Tom Eastep
|
6ffedae4fb
|
Document '=' in the SOURCE PORT(S) column of shorewall-tcrules(5)
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-03-05 08:39:14 -08:00 |
|
Tom Eastep
|
631c1ac843
|
Mention the multiport match requirement for '='
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-03-04 12:53:00 -08:00 |
|
Tom Eastep
|
49918b654e
|
Support '=' in SOURCE PORT(S) columns
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-03-04 09:56:10 -08:00 |
|
Tom Eastep
|
524d6242b0
|
More SNAT/DNAT manpage updates
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-02-19 12:42:09 -08:00 |
|
Tom Eastep
|
010c44d07a
|
Correct description of the 'sourceroute' interface option.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-02-18 11:33:19 -08:00 |
|
Tom Eastep
|
f44becdee1
|
Rename BLACKLIST_LOGLEVEL to BLACKLIST_LOG_LEVEL for consistent naming.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-02-12 07:47:02 -08:00 |
|
Tom Eastep
|
61c219ed3a
|
Clarify the CHAIN column in the accounting manpage. Also mention ipset support.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-02-03 08:00:24 -08:00 |
|
Tom Eastep
|
f407068d20
|
Update shorewall[6]-actions(5) regarding inline for some standard actions
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-01-30 08:27:30 -08:00 |
|
Tom Eastep
|
fc73c3934b
|
Replace BLACKLISTNEWONLY with BLACKLIST
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-01-30 08:00:47 -08:00 |
|
Tom Eastep
|
519861d7b2
|
Add CONTINUE as a possible setting for RELATED_DISPOSITION.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-01-28 07:58:03 -08:00 |
|
Tom Eastep
|
c958329d14
|
More manpage updates for RELATED and UNTRACKED rules sections.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-01-24 19:24:01 -08:00 |
|
Tom Eastep
|
575673a8f5
|
Correct broken links in the .conf manpages.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-01-24 15:42:20 -08:00 |
|
Tom Eastep
|
6403f4959d
|
Implement UNTRACKED SECTION
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-01-24 15:42:01 -08:00 |
|
Tom Eastep
|
c2bc74cdfe
|
Add INVALID section to the rules file.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-01-24 08:33:59 -08:00 |
|
Tom Eastep
|
17eae4adee
|
Update the description of BLACKLISTNEWONLY to match the implementation.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-01-22 09:11:15 -08:00 |
|
Tom Eastep
|
ea0325a1f5
|
Clarify IPv6 again.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-01-17 11:29:36 -08:00 |
|
Tom Eastep
|
066c159b4d
|
Provide instructions for changing DISABLE_IPV6 from Yes to No
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-01-17 10:21:08 -08:00 |
|
Tom Eastep
|
89a09f0256
|
Implement DEFER_DNS_RESOLUTION
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2013-01-13 17:00:14 -08:00 |
|