Tom Eastep
|
10d10b1c16
|
Remove a redundant capability test
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-15 12:52:06 -08:00 |
|
Tom Eastep
|
6194eceaa4
|
Restore text of 'Provider "..." compiled' message
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-15 12:51:39 -08:00 |
|
Tom Eastep
|
2142baca4f
|
Avoid inappropriate RELATED,ESTABLISHED rules
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-06 19:04:43 -08:00 |
|
Tom Eastep
|
004d0bcc38
|
Allow rules in the RELATED section when there are non-default settions of
the new RELATED_* options.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-06 13:38:11 -08:00 |
|
Tom Eastep
|
d4957696d1
|
Update man pages and sample files
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-05 17:45:09 -08:00 |
|
Tom Eastep
|
439af55312
|
Implement RELATED_DISPOSITION and RELATED_LOG_LEVEL
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-05 16:08:17 -08:00 |
|
Tom Eastep
|
febe9e5222
|
Apply Chris Boot's fix for TC_ENABLED=Shared
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-05 12:22:48 -08:00 |
|
Tom Eastep
|
2cffae738f
|
Initial implementation of CT target support in the 'notrack' file.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-04 17:15:58 -08:00 |
|
Tom Eastep
|
a794027f63
|
Implement CT capability
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-04 14:35:53 -08:00 |
|
Tom Eastep
|
e7d2b1d4ed
|
Consolidate the lib.common files.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-04 09:19:48 -08:00 |
|
Tom Eastep
|
6bb487bb68
|
Pass $CONFIG_PATH to compiler.pl
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-02 07:36:23 -08:00 |
|
Tom Eastep
|
8c6914d1a2
|
Don't deprecate 'optional' for shared providers
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-01 11:23:22 -08:00 |
|
Tom Eastep
|
a27f5655a7
|
Merge branch '4.4.26'
|
2011-12-01 10:41:22 -08:00 |
|
Tom Eastep
|
99bf7fb994
|
Don't do TC stuff during enable/disable of a shared provider
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-01 10:41:03 -08:00 |
|
Tom Eastep
|
568e3b2e5b
|
Allow a provider name in addition to an interface name in enable/disable
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-01 10:32:54 -08:00 |
|
Tom Eastep
|
8f14485d67
|
Allow a provider name in addition to an interface name in enable/disable
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-01 10:30:42 -08:00 |
|
Tom Eastep
|
3110f7c74a
|
Add enable/disable commands to the CLIs
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-12-01 10:25:51 -08:00 |
|
Tom Eastep
|
d8caa6498a
|
Add tracing to Optimize 16.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-30 07:57:19 -08:00 |
|
Tom Eastep
|
9e149ca038
|
Correct default values during update
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-27 14:12:51 -08:00 |
|
Tom Eastep
|
61d5c6d6da
|
Implement Shorewall::Chains::clone_rule()
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-26 09:36:02 -08:00 |
|
Tom Eastep
|
3498076a96
|
Accurately compare rule key values that are array references.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-26 08:03:02 -08:00 |
|
Tom Eastep
|
15d95b6977
|
Fix SAME target.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-26 07:48:03 -08:00 |
|
Tom Eastep
|
5cdb74168f
|
Correct port list capture with --multiport.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-25 16:22:23 -08:00 |
|
Tom Eastep
|
613e41c25a
|
Enable OPT 16 in check -r; Suppress duplicate rules
|
2011-11-25 16:05:07 -08:00 |
|
Tom Eastep
|
90e03e1833
|
Even more tweaks to optimize 16
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-25 14:46:37 -08:00 |
|
Tom Eastep
|
71bbd7963c
|
Some tweaks to optimize 16
|
2011-11-25 10:42:10 -08:00 |
|
Tom Eastep
|
f305da9d0d
|
Require extended multi-port match for OPTIMIZE 16.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-24 10:57:09 -08:00 |
|
Tom Eastep
|
8d8a681f40
|
Implement optimization level 16
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-24 10:22:04 -08:00 |
|
Tom Eastep
|
4559c8b5d0
|
Tweaks to convert_blacklist()
- Reword an error message to handle both missing file and zero-sized file.
- Don't rename file that doesn't exist.
|
2011-11-21 12:13:39 -08:00 |
|
Tom Eastep
|
dffb79e7bd
|
Handle empty blacklist file in 'update -b'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-20 17:02:01 -08:00 |
|
Tom Eastep
|
bd8ba435cd
|
Avoid uninitialized value in hash element.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-20 16:24:42 -08:00 |
|
Tom Eastep
|
4d30811794
|
Implement 'show marks'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-20 12:29:17 -08:00 |
|
Tom Eastep
|
e5a6387695
|
Eliminate use of WIDE_TC_MARKS in the Tc module
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-20 08:45:16 -08:00 |
|
Tom Eastep
|
382309bc53
|
Derive default values for the mark-layout options
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-20 07:03:33 -08:00 |
|
Tom Eastep
|
83d7cfa76a
|
Update documentation
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-19 15:18:43 -08:00 |
|
Tom Eastep
|
ae8aa3a45a
|
More fixes for ZONE_BITS
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-19 08:19:38 -08:00 |
|
Tom Eastep
|
ab1b65d6a8
|
Fixes for blacklist conversion
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-19 08:18:58 -08:00 |
|
Tom Eastep
|
4f9afc32ec
|
Allow zone names in the MARK column when ZONE_BITS != 0
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-18 07:23:24 -08:00 |
|
Tom Eastep
|
7c0cb69c29
|
Don't copy limited broadcast routes to provider tables
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-18 07:07:51 -08:00 |
|
Tom Eastep
|
364b30fd9b
|
Fix 'update -b' handling of missing files.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-18 06:26:37 -08:00 |
|
Tom Eastep
|
72f75c201c
|
Implement zone automark
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-17 16:07:45 -08:00 |
|
Tom Eastep
|
96f5aec71f
|
Add ZONE_BITS configuration option.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-17 10:40:47 -08:00 |
|
Tom Eastep
|
fe09646bed
|
Make zone types a power of 2.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-17 09:23:39 -08:00 |
|
Tom Eastep
|
348c6c8cf7
|
Correct handling of LOGMARK
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-17 07:22:07 -08:00 |
|
Tom Eastep
|
d096b9399a
|
Fix '\!' handling in validate_level()
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-15 16:41:32 -08:00 |
|
Tom Eastep
|
afaf0d9de8
|
Trivial optimiation in validate_level()
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-13 06:19:40 -08:00 |
|
Tom Eastep
|
28a1087cd4
|
Cleanup of rewritten validate_level()
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-13 05:58:59 -08:00 |
|
Tom Eastep
|
73ed66b9b9
|
Add ULOG and NFLOG capabilities plus LOGMARK for IPv6
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-12 14:10:48 -08:00 |
|
Tom Eastep
|
ffec7a4d95
|
More corrections to wildcard interfaces
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-11 07:29:44 -08:00 |
|
Tom Eastep
|
04dfe26549
|
Remove two unused variables.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2011-11-11 05:23:37 -08:00 |
|