Tom Eastep
|
85430e459c
|
Restore trace output in move_rules()
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-17 14:35:25 -07:00 |
|
Tom Eastep
|
ad660d7fe5
|
Simplify move_rules()
|
2010-09-17 13:53:10 -07:00 |
|
Tom Eastep
|
7a6943fa54
|
Disallow mss and blacklist on firewall and vserver zones
|
2010-09-17 12:54:58 -07:00 |
|
Tom Eastep
|
b76ee408a5
|
Emit clearer error messages
|
2010-09-17 12:54:54 -07:00 |
|
Tom Eastep
|
2e3635ff50
|
Be sure that {frozen} is defined
|
2010-09-17 12:54:44 -07:00 |
|
Tom Eastep
|
28aa7b8267
|
Re-add OPTIONS column to blacklist templates
|
2010-09-17 12:54:38 -07:00 |
|
Tom Eastep
|
7175f8a63e
|
Revert versions on Rules and Zones modules
|
2010-09-17 11:08:45 -07:00 |
|
Tom Eastep
|
d898c87617
|
Eliminate a parameter to add_jump()
|
2010-09-17 11:08:12 -07:00 |
|
Tom Eastep
|
af24baaecd
|
Update version to RC1 (one more time)
|
2010-09-17 09:14:56 -07:00 |
|
Tom Eastep
|
e61230a3db
|
Update version to Beta 6
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-17 08:23:24 -07:00 |
|
Tom Eastep
|
8e2c8e5a8f
|
Document use of state match for NOTRACK
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-17 08:21:16 -07:00 |
|
Tom Eastep
|
882970a598
|
Use state match for UNTRACKED
|
2010-09-17 07:58:21 -07:00 |
|
Tom Eastep
|
2ce3c8aa88
|
Ensure that blacklist rules are before the other interface-oriented rules
|
2010-09-16 18:19:16 -07:00 |
|
Tom Eastep
|
27c445381e
|
Treat 'blacklist' uniformly in hosts and zones
|
2010-09-16 15:48:12 -07:00 |
|
Tom Eastep
|
67b9ae0d2c
|
Update release documents
|
2010-09-16 15:47:05 -07:00 |
|
Tom Eastep
|
1c870b532a
|
Preserve dynamic blacklist during stop/clear/restore
|
2010-09-16 12:17:04 -07:00 |
|
Tom Eastep
|
a8c9fc1859
|
Implement new Blacklisting Scheme
|
2010-09-16 09:40:28 -07:00 |
|
Tom Eastep
|
3c1cff0794
|
First steps toward zone-based blacklisting
|
2010-09-16 06:55:48 -07:00 |
|
Tom Eastep
|
1d650b41cd
|
Remove blacklisting by destination IP address support
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-15 15:24:58 -07:00 |
|
Tom Eastep
|
3ad3f0d9e0
|
Allow floating point numbers in tcinterfaces fields other than <rate>
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-15 14:07:21 -07:00 |
|
Tom Eastep
|
ba89ec39b5
|
Add :<burst> to /etc/shorewall/tcdevices
|
2010-09-15 11:56:14 -07:00 |
|
Tom Eastep
|
69a2fa1907
|
Replace to/from with dst/src
|
2010-09-15 11:25:46 -07:00 |
|
Tom Eastep
|
f925b335ef
|
Ignore the 'blacklist' host option
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-15 08:10:57 -07:00 |
|
Tom Eastep
|
373fc87165
|
More blacklisting wrapup
- Deprecate 'blacklist' in the hosts file
- Base blacklisting on interfaces alone
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-15 07:38:20 -07:00 |
|
Tom Eastep
|
4d0e8d129b
|
Add dup blacklist message
|
2010-09-14 18:04:27 -07:00 |
|
Tom Eastep
|
10a9ae496a
|
More manpage updates for 4.4.13
|
2010-09-14 16:47:45 -07:00 |
|
Tom Eastep
|
94cdc73ec2
|
Restore setpolicy() to prog.header*
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-14 13:50:22 -07:00 |
|
Tom Eastep
|
c4a40d8c7b
|
Set version to RC1 (again)
|
2010-09-14 13:09:50 -07:00 |
|
Tom Eastep
|
c6960f1ac2
|
Edit release notes
|
2010-09-14 07:36:29 -07:00 |
|
Tom Eastep
|
1f2691b052
|
Another fix for blacklisting; correct composition of $hosts1
|
2010-09-14 06:47:29 -07:00 |
|
Tom Eastep
|
0f913fca2f
|
Don't create blackout unnecessarily
|
2010-09-13 18:15:50 -07:00 |
|
Tom Eastep
|
82bccf16b5
|
Avoid internal error when there are no 'to' entries
|
2010-09-13 17:55:20 -07:00 |
|
Tom Eastep
|
bb38ed16b0
|
Document ipset creation fix
|
2010-09-13 15:54:44 -07:00 |
|
Tom Eastep
|
b1e9bff382
|
Create new ipsets on 'start'
|
2010-09-13 15:46:04 -07:00 |
|
Tom Eastep
|
a6194fabd2
|
Delete blank line
|
2010-09-13 14:15:47 -07:00 |
|
Tom Eastep
|
33adbe7a27
|
Update documentation for net TC features
|
2010-09-13 13:51:25 -07:00 |
|
Tom Eastep
|
1729da87f1
|
Allow both 'to' and 'from' in blacklist
|
2010-09-13 12:51:10 -07:00 |
|
Tom Eastep
|
9b4c3e22dd
|
Allow floating point numbers in TC rates
|
2010-09-13 12:50:50 -07:00 |
|
Tom Eastep
|
cb1f7adea3
|
Add :<burst> to IN-BANDWIDTH
|
2010-09-13 11:23:37 -07:00 |
|
Tom Eastep
|
283eda2fa5
|
Cosmetic change to OUT-BANDWIDTH code
|
2010-09-12 16:33:19 -07:00 |
|
Tom Eastep
|
bd9041306c
|
Add undocumented OUT-BANDWIDTH column to tcinterfaces
|
2010-09-12 16:25:45 -07:00 |
|
Tom Eastep
|
a3b7b9c11b
|
Delete unused functions from prog.header*
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-09-12 10:07:26 -07:00 |
|
Tom Eastep
|
931c5a8d0a
|
Add an assertion
|
2010-09-11 16:24:27 -07:00 |
|
Tom Eastep
|
50fc972d2a
|
Fix another SAME defect :-(
|
2010-09-11 16:15:09 -07:00 |
|
Tom Eastep
|
512cd7b08e
|
Bump version to 4.4.13 RC 1
|
2010-09-11 15:46:14 -07:00 |
|
Tom Eastep
|
aad7b70e18
|
Rename constant
|
2010-09-11 15:31:43 -07:00 |
|
Tom Eastep
|
c6c6503d83
|
Clean up a remaining issue with SAME
|
2010-09-11 15:24:01 -07:00 |
|
Tom Eastep
|
f004916055
|
Disallow a DEST interface in mangle OUTPUT rules
|
2010-09-11 14:10:05 -07:00 |
|
Tom Eastep
|
3ea7808b38
|
Disallow a DEST interface in mangle PREROUTING rules
|
2010-09-11 14:02:09 -07:00 |
|
Tom Eastep
|
37a5a01185
|
Correct INPUT marking documentation
|
2010-09-11 12:47:32 -07:00 |
|