Tom Eastep
|
b04b65cac8
|
Clear counters in all tables during 'reset'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-30 14:31:59 -08:00 |
|
Tom Eastep
|
5dcb684efc
|
Don't be specific when deleting IPv6 balanced/fallback default routes
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-28 15:26:17 -08:00 |
|
Tom Eastep
|
3e87e5004a
|
Merge branch 'master' of ssh://git.code.sf.net/p/shorewall/code
|
2017-11-27 09:36:13 -08:00 |
|
Roberto C. Sánchez
|
c89b113a61
|
Fix typos
|
2017-11-26 15:39:59 -05:00 |
|
Tom Eastep
|
7289175070
|
Chop first config dir if non-root or if compiling for export.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-23 09:57:12 -08:00 |
|
Tom Eastep
|
a9373d727b
|
Use logical interface names in the samples.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-22 09:40:15 -08:00 |
|
Tom Eastep
|
528b473f6b
|
Add some additional documentation to the Config module
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-22 08:41:37 -08:00 |
|
Tom Eastep
|
d22210c074
|
Set g_export before calling get_config()
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-14 13:46:41 -08:00 |
|
Tom Eastep
|
f411f7dd31
|
Remove redundant test
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-14 10:45:10 -08:00 |
|
Tom Eastep
|
502e98eb9f
|
Add Redfish console to the IPMI macro
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-14 10:44:54 -08:00 |
|
Tom Eastep
|
f73bad440d
|
Don't verify IP and SHOREWALL_SHELL when compiling/checking for test
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-14 10:02:15 -08:00 |
|
W. van den Akker
|
23bc019a82
|
Add OpenWRT options.
Signed-off-by: W. van den Akker <wvdakker@wilsoft.nl>
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-14 09:00:46 -08:00 |
|
Tom Eastep
|
9d299ef866
|
Don't verify IP and SHOREWALL_SHELL setting when compiling for export
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-14 08:50:05 -08:00 |
|
Tom Eastep
|
2a9272ccd1
|
Clean up RAs involving "|"
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-14 08:26:17 -08:00 |
|
Tom Eastep
|
130ddff9de
|
Correct a typo in an error message
- Includes cosmetic changes to Providers.pm
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-10 11:25:52 -08:00 |
|
Tom Eastep
|
9cf298482d
|
Merge branch '5.1.8'
|
2017-11-09 12:59:59 -08:00 |
|
Tom Eastep
|
c5a586aa37
|
Allow [...] around gateway address in the providers file
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-09 12:20:01 -08:00 |
|
Tom Eastep
|
832418585a
|
Don't make persistent routes and rules dependent on autosrc.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-08 09:46:25 -08:00 |
|
Tom Eastep
|
605f61fb3c
|
Don't make persistent routes and rules dependent on autosrc.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-08 09:45:59 -08:00 |
|
Tom Eastep
|
8dfa0be611
|
Add shorewall-logging(5)
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-02 15:26:14 -07:00 |
|
Tom Eastep
|
ef8b85fc3e
|
Implement support for logging in the SNAT file
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-02 12:44:42 -07:00 |
|
Tom Eastep
|
2b5613026a
|
Merge branch '5.1.8'
|
2017-10-25 09:14:20 -07:00 |
|
Tom Eastep
|
c7c318c0e7
|
Align columns in actions.std
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-25 09:13:37 -07:00 |
|
Tom Eastep
|
d1976189aa
|
Correct a couple of typos in the manpages
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-22 12:59:31 -07:00 |
|
Tom Eastep
|
6b4905c2c0
|
Replace 'tcp' with '6' in action.TCPFlags
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-20 12:33:36 -07:00 |
|
Tom Eastep
|
774b707352
|
Inline Multicast when Address Type Match is available
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-20 12:01:41 -07:00 |
|
Tom Eastep
|
c3bd58827f
|
Align columns in actions.std
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-20 11:44:10 -07:00 |
|
Tom Eastep
|
b35f1112f4
|
Allow 'noinline' in /etc/shorewall[6]/actions to override 'inline'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-20 09:19:50 -07:00 |
|
Tom Eastep
|
a0eb91cb90
|
Inline the Broadcast action when ADDRTYPE match is available
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-20 08:49:14 -07:00 |
|
Tom Eastep
|
77d9eeb915
|
Eliminate extra parameter editing of TPROXY parameter list.
- Clarify syntax for actions with multiple parameters
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-19 13:08:12 -07:00 |
|
Tom Eastep
|
17838c1443
|
Add TCPMSS to the allowed mangle actions.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-19 12:58:38 -07:00 |
|
Tom Eastep
|
5867ce6c3b
|
CLAMPMSS now done in the mangle table.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-18 15:55:07 -07:00 |
|
Tom Eastep
|
8ea96098bf
|
Warning when 'persistent' used with RESTORE_DEFAULT_ROUTE=Yes
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-11 15:22:07 -07:00 |
|
Tom Eastep
|
02ed36332a
|
Revert "Warn when RESTORE_DEFAULT_ROUTE=Yes and a persistent provider is defined"
This reverts commit 39a3c72057 .
|
2017-10-11 11:24:54 -07:00 |
|
Tom Eastep
|
15a3b29a32
|
Revert "Document warning when RESTORE_DEFAULT_ROUTE=Yes and 'persistent'"
This reverts commit bfab002dda .
|
2017-10-11 11:24:39 -07:00 |
|
Tom Eastep
|
cb4f9e7261
|
Don't restore default routes when there is an enabled fallback provider
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-11 11:24:13 -07:00 |
|
Tom Eastep
|
bfab002dda
|
Document warning when RESTORE_DEFAULT_ROUTE=Yes and 'persistent'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-11 11:01:09 -07:00 |
|
Tom Eastep
|
ddb12fcad9
|
Add/correct comments
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-11 11:00:46 -07:00 |
|
Tom Eastep
|
42ce754961
|
Don't restore default routes when a fallback= provider is enabled
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-11 11:00:05 -07:00 |
|
Tom Eastep
|
5cd4d63bc5
|
Delete main default routes when a fallback provider is enabled
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-11 10:59:31 -07:00 |
|
Tom Eastep
|
5b567f2d8b
|
Correct delete_default_routes() in tables other than main
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-11 10:58:48 -07:00 |
|
Tom Eastep
|
39a3c72057
|
Warn when RESTORE_DEFAULT_ROUTE=Yes and a persistent provider is defined
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-11 10:58:09 -07:00 |
|
Tom Eastep
|
b47e633c38
|
Use 'route replace' rather than 'route add' to avoid persistence issues
Previous failure case was:
- disable interface
- reload
- enable interface
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-09 08:58:10 -07:00 |
|
Tom Eastep
|
1b55a37a28
|
Ensure that 'rule add' commands don't fail with persistent interfaces
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-08 08:53:53 -07:00 |
|
Tom Eastep
|
a97dcd23d0
|
Allow merging of rules that specify an IPSEC policy
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-07 13:17:43 -07:00 |
|
Tom Eastep
|
108b169d8d
|
Treat LOG_TARGET like all other capabilities
- Previous implementation could generate unworkable script when
LOAD_HELPERS_ONLY=Yes
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-06 08:01:52 -07:00 |
|
Tom Eastep
|
8469f983d8
|
Merge branch '5.1.7'
# Conflicts:
# Shorewall/Perl/prog.footer
|
2017-09-29 15:25:37 -07:00 |
|
Tom Eastep
|
f54acb665a
|
Correct handling of mark range in MARK target.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-09-29 14:44:33 -07:00 |
|
Tom Eastep
|
3d2e9eb93e
|
Improve the fix for SELinux "getattr" denials
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-09-28 15:16:50 -07:00 |
|
Tom Eastep
|
c6a939301f
|
Improve the fix for SELinux "getattr" denials
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-09-28 15:16:00 -07:00 |
|