Tom Eastep
|
eea9882953
|
Implement CPU Fanout for NFQUEUE.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-12-09 10:46:39 -08:00 |
|
Tom Eastep
|
cc937ffaba
|
NFQUEUE should be non-terminating
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-12-09 09:49:23 -08:00 |
|
Tom Eastep
|
5ea3334a66
|
Support a richer SOURCE and DEST syntax
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-12-09 09:43:10 -08:00 |
|
Tom Eastep
|
53adfbe863
|
Normalize parameters by removing trailing omitted args
- Avoids needless duplicate action chains
|
2016-12-03 11:34:02 -08:00 |
|
Tom Eastep
|
4a0a906510
|
Correct progress message in optimize_level4()
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-12-03 08:28:14 -08:00 |
|
Tom Eastep
|
7ceb0228e9
|
Merge branch 'master' into 5.1.0
|
2016-12-02 15:27:16 -08:00 |
|
Tom Eastep
|
f537e3e15c
|
Fix optimization bug in merge_rules()
- Reset the simple member if a unique option is merged
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-12-02 14:47:03 -08:00 |
|
Tom Eastep
|
5ae062317f
|
Merge branch 'master' into 5.1.0
|
2016-12-01 19:35:14 -08:00 |
|
Tom Eastep
|
a1981823f4
|
Correct typo (syntax error!)
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-12-01 15:21:25 -08:00 |
|
Tom Eastep
|
77e83f0afd
|
Eliminate the CHAIN_SCRIPTS option
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-29 16:33:23 -08:00 |
|
Tom Eastep
|
a45fe692cc
|
Add a SWITCH column to the mangle files
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-29 16:13:44 -08:00 |
|
Tom Eastep
|
799b17210c
|
Enhanced syntax for SOURCE and DEST columns in the rules file
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-25 15:10:14 -08:00 |
|
Tom Eastep
|
963dea54c5
|
Modify update defaults for LOGPREFIX and LOGLIMIT
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-23 14:30:07 -08:00 |
|
Tom Eastep
|
ccab75e69a
|
Avoid unnecessary change in the generated script
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-20 09:17:39 -08:00 |
|
Tom Eastep
|
36517cdb1e
|
Rename setup_environment to setup_product_environment
- Default to first detected product
- Verify that specified product is installed
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-20 08:48:18 -08:00 |
|
Tom Eastep
|
bb5c3a50f5
|
Avoid unnecessary change in the generated script
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-19 21:39:49 -08:00 |
|
Tom Eastep
|
8b99fe20b5
|
Pave the way for unifying the CLI
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-19 21:17:35 -08:00 |
|
Tom Eastep
|
88284ed568
|
Delete version from the heading of compiler.pl
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-16 13:03:00 -08:00 |
|
Tom Eastep
|
481afef2c3
|
Don't insist that route deletion succeeds
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-12 08:38:09 -08:00 |
|
Tom Eastep
|
6b38b3a515
|
Revert "More IPv6 routing cleanup"
This reverts commit 1e7f63834c .
|
2016-11-12 08:25:38 -08:00 |
|
Tom Eastep
|
80951d23c2
|
add/delete multi-nexthop IPv6 routes
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-12 08:24:46 -08:00 |
|
Tom Eastep
|
1e7f63834c
|
More IPv6 routing cleanup
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-09 10:34:19 -08:00 |
|
Tom Eastep
|
74b94f71f8
|
Always return $omitting from process_compiler_directive()
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-09 08:07:17 -08:00 |
|
Tom Eastep
|
ef4ab62dd3
|
Disable directive callbacks after file conversion.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-09 07:47:19 -08:00 |
|
Tom Eastep
|
42c1c2a205
|
Don't copy link-level address routes into provider tables.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-08 14:42:44 -08:00 |
|
Tom Eastep
|
d989241712
|
Retain shell variables during routestopped and blacklist conversions
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-07 11:26:17 -08:00 |
|
Tom Eastep
|
652bc75448
|
Omit Shorewall version from converted files.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-07 11:12:36 -08:00 |
|
Tom Eastep
|
d105da3964
|
Preserve shell variables when converting tos->mangle
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-06 17:25:35 -08:00 |
|
Tom Eastep
|
c5b393a074
|
Preserve shell variables when converting tcrules->mangle
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-06 17:25:01 -08:00 |
|
Tom Eastep
|
1b82dedb77
|
Preserve shell variables when converting masq -> snat
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-06 13:53:05 -08:00 |
|
Tom Eastep
|
6398756647
|
Add a routine to split the raw current line image
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-06 08:44:24 -08:00 |
|
Tom Eastep
|
daa2440d9a
|
Ensure that $directive_callback->() gets an unaltered image
- pass omitted lines to that function as well
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-06 08:03:31 -08:00 |
|
Tom Eastep
|
8441ac5c5f
|
Handle another issue with ADD_SNAT_ALIASES=Yes
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-03 15:06:38 -07:00 |
|
Tom Eastep
|
01a6881f4f
|
Catch total lack of address/port in SNAT argument
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-02 19:30:55 -07:00 |
|
Tom Eastep
|
f917670fbd
|
Tighten editing of SNAT/MASQ port ranges.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-02 19:30:18 -07:00 |
|
Tom Eastep
|
c376740329
|
Detect degenerate addr:port[-range] in SNAT rules.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-02 15:28:00 -07:00 |
|
Tom Eastep
|
4169520d63
|
Handle exceptionrule correctly with MASQUERADE.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-02 14:36:51 -07:00 |
|
Tom Eastep
|
53d97bbcc8
|
Correct handling of masquerade port range when ADD_SNAT_ALIASES=Yes
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-02 12:28:00 -07:00 |
|
Tom Eastep
|
9ae36e1989
|
Correct error message when multiple SNAT addresses are present.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-02 12:27:32 -07:00 |
|
Tom Eastep
|
60619fb3cb
|
Correct part of a recent patch to Nat.pm
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-02 09:00:19 -07:00 |
|
Tom Eastep
|
41ecee356b
|
Correct earlier faulty patch to Nat.pm.
- Similar Rules.pm patch was okay.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-01 19:39:52 -07:00 |
|
Tom Eastep
|
e188bde6c4
|
Fix additional masq/snat issues.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-01 18:42:16 -07:00 |
|
Tom Eastep
|
d37967f32f
|
Replace --to-ports <ports> with --to-source :<ports>
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-01 16:52:08 -07:00 |
|
Tom Eastep
|
10c1ad245a
|
Handle omitted port[-range] in SNAT correctly.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-01 12:59:44 -07:00 |
|
Tom Eastep
|
032a16eb43
|
Detect incorrect port-range separator in SNAT(...)
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-11-01 11:28:19 -07:00 |
|
Tom Eastep
|
3f68814a38
|
Disallow more than one address[-range] in SNAT rules
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-10-31 15:15:35 -07:00 |
|
Tom Eastep
|
95a1e65016
|
Clear target modifiers in interface loop
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-10-30 16:25:17 -07:00 |
|
Tom Eastep
|
282253022e
|
Correct handling of address variables out of the Providers module
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-10-29 14:59:34 -07:00 |
|
Tom Eastep
|
4d77d673e8
|
Be sure NAT is enabled before processing an snat file
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-10-28 09:30:17 -07:00 |
|
Tom Eastep
|
e4e424bbdc
|
Disallow '+' in inline SNAT action bodies
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2016-10-28 08:58:47 -07:00 |
|