Tom Eastep
|
789854adce
|
Revert "Correct order of optional interface and address variable handling"
This reverts commit fbee4a91fd .
|
2018-01-28 14:54:06 -08:00 |
|
Tom Eastep
|
fbee4a91fd
|
Correct order of optional interface and address variable handling
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-28 10:53:20 -08:00 |
|
Tom Eastep
|
cb7071a213
|
Clarify BLACKLIST_DISPOSITION in shorewall.conf(5)
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-28 10:52:35 -08:00 |
|
Tom Eastep
|
cdf5ad45d5
|
Eliminate the MAPOLDACTIONS option
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-24 12:59:26 -08:00 |
|
Tom Eastep
|
070a67d665
|
Deimplement OPTIMIZE_USE_FIRST
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-24 11:56:20 -08:00 |
|
Tom Eastep
|
9796c58eb2
|
Add OPTIMIZE_MASK constant
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-23 13:15:44 -08:00 |
|
Tom Eastep
|
cabc20957f
|
Delete an unnecessary variable
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-23 09:45:50 -08:00 |
|
Tom Eastep
|
a9a379c5a5
|
Implement INPUT SNAT
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-22 16:37:38 -08:00 |
|
Tom Eastep
|
3bf5066f82
|
Document multiple DEST interfaces in the snat file
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-22 11:12:28 -08:00 |
|
Tom Eastep
|
64f704a964
|
Improve quoting in the route-balancing logic
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-21 14:46:51 -08:00 |
|
Tom Eastep
|
416224ee05
|
Correct typos and anachronisms in Chains.pm comments
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-21 11:53:58 -08:00 |
|
Tom Eastep
|
92ce1beddc
|
Move read_yesno_with_timeout() to lib.cli-std
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-20 14:26:13 -08:00 |
|
Tom Eastep
|
fb4b362724
|
Eliminate unnecessary local array
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-20 13:26:10 -08:00 |
|
Tom Eastep
|
97de2be778
|
Change a fatal_error() call with an assertion in add_policy_rules()
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-19 13:39:51 -08:00 |
|
Tom Eastep
|
85cae3c7f8
|
Add parens to improve readability
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-19 12:47:17 -08:00 |
|
Tom Eastep
|
acd425a3c2
|
Remove superfluous logic from validate_portpari1()
- Add comments
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-19 12:46:52 -08:00 |
|
Tom Eastep
|
4e6949f996
|
Document port masquerading
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-19 08:55:56 -08:00 |
|
Tom Eastep
|
5d7dcc3122
|
Unify variable style
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-18 13:42:13 -08:00 |
|
Tom Eastep
|
422d0b216a
|
Don't use the -quit option to Busybox find
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-18 13:39:44 -08:00 |
|
Tom Eastep
|
27a0f0f7a0
|
Make TRACK_PROVIDERS=Yes the default
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-10 08:46:01 -08:00 |
|
Tom Eastep
|
9ac075fd56
|
Clear the connection mark in tunneled packets from tracked providers
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-09 17:12:14 -08:00 |
|
Tom Eastep
|
b2604583af
|
Revert "Clear the connection mark in tunneled packets from tracked providers"
This reverts commit 62c6411cb0 .
|
2018-01-09 17:01:51 -08:00 |
|
Tom Eastep
|
62c6411cb0
|
Clear the connection mark in tunneled packets from tracked providers
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-09 14:51:57 -08:00 |
|
Tom Eastep
|
1bc90beb01
|
Update copyrights
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-07 15:01:46 -08:00 |
|
Tom Eastep
|
eaccf033c6
|
Update copyrights for 2018
- Update some header versions to 5.1
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-07 14:24:01 -08:00 |
|
Tom Eastep
|
056711d304
|
Remove anachronistic comment
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-06 13:58:20 -08:00 |
|
Tom Eastep
|
0aa0bebe07
|
Reword error message
- "Invalid action name ..." to "Reserved action name ..."
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-06 13:56:36 -08:00 |
|
Tom Eastep
|
1a68d87c94
|
Don't enable forwarding in 'clear'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-04 15:39:07 -08:00 |
|
Tom Eastep
|
c518cfaa4a
|
Allow address variables to work correctly with the 'clear' command
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-03 08:58:28 -08:00 |
|
Tom Eastep
|
2c3f121835
|
Don't call setup_dbl() unconditionally
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-02 13:11:31 -08:00 |
|
Tom Eastep
|
18ba5c7311
|
Don't verify 'conntrack' utility for 'remote-' commands
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2018-01-02 11:52:35 -08:00 |
|
Tom Eastep
|
09980cc75e
|
Use split() in uptodate()
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-12-31 15:59:28 -08:00 |
|
Tom Eastep
|
e0a757ea03
|
Quit find after finding the first newer file
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-12-31 14:15:45 -08:00 |
|
Tom Eastep
|
550003f0f4
|
Only look at regular files when running 'find'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-12-31 14:09:51 -08:00 |
|
Tom Eastep
|
4f50303318
|
Merge branch '5.1.10'
# Conflicts:
# Shorewall/lib.cli-std
|
2017-12-31 14:06:52 -08:00 |
|
Tom Eastep
|
5053999442
|
Don't run 'find' in the PWD
- Also remove -mindepth so as to catch deletions in the directories
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-12-31 13:33:16 -08:00 |
|
Tom Eastep
|
6b5889177b
|
Correct startup_error() inadvertent change
- Switch ensure_root() back to calling startup_error()
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-12-30 09:24:21 -08:00 |
|
Tom Eastep
|
377c9f5708
|
Only search files in each CONFIG_PATH directory - no recursion
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-12-30 08:44:05 -08:00 |
|
Tom Eastep
|
45a164733b
|
Fix breakage of ipp2p
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-12-30 08:38:14 -08:00 |
|
Tom Eastep
|
6f82bfe7d1
|
Handle PROTO '-' in conntrack file processing.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-12-29 15:54:15 -08:00 |
|
Tom Eastep
|
4e5b98d3d9
|
Only search files in each CONFIG_PATH directory - no recursion
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-12-29 15:42:09 -08:00 |
|
Tom Eastep
|
078c781dfa
|
Allow override of :syn assumption in CT rules
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-12-29 15:15:33 -08:00 |
|
Tom Eastep
|
46f68c6dcb
|
Move adjustment of the protocol in process_conntrack_rule()
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-12-29 13:51:33 -08:00 |
|
Tom Eastep
|
b42678269c
|
Revert "Add :syn to each TCP entry in the conntrack file"
This reverts commit f861f8da35 .
|
2017-12-29 13:08:27 -08:00 |
|
Tom Eastep
|
9bd10c0c00
|
Call fatal_error (not startup_error) when non-root does default compile
- Also reword the message
|
2017-12-29 12:49:43 -08:00 |
|
Tom Eastep
|
f861f8da35
|
Add :syn to each TCP entry in the conntrack file
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-12-29 12:38:58 -08:00 |
|
Tom Eastep
|
9e3cb27d0a
|
Use the synchain name in log messages rather than the base chain name
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-12-28 14:13:50 -08:00 |
|
Tom Eastep
|
d8a22d13dd
|
Allow non-root to run many 'show' commands
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-12-28 10:49:09 -08:00 |
|
Tom Eastep
|
9afe8daae0
|
Merge branch '5.1.10'
# Conflicts:
# Shorewall-core/install.sh
# Shorewall/install.sh
|
2017-12-26 15:45:20 -08:00 |
|
Tom Eastep
|
43adcd26a1
|
Make the /etc and the configfiles .conf files the same
Signed-off-by: Tom Eastep <teastep@shorewall.net>
# Conflicts:
# Shorewall/install.sh
|
2017-12-26 15:39:26 -08:00 |
|