Tom Eastep
|
f73bad440d
|
Don't verify IP and SHOREWALL_SHELL when compiling/checking for test
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-14 10:02:15 -08:00 |
|
W. van den Akker
|
23bc019a82
|
Add OpenWRT options.
Signed-off-by: W. van den Akker <wvdakker@wilsoft.nl>
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-14 09:00:46 -08:00 |
|
Tom Eastep
|
9d299ef866
|
Don't verify IP and SHOREWALL_SHELL setting when compiling for export
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-14 08:50:05 -08:00 |
|
Tom Eastep
|
2a9272ccd1
|
Clean up RAs involving "|"
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-14 08:26:17 -08:00 |
|
Tom Eastep
|
130ddff9de
|
Correct a typo in an error message
- Includes cosmetic changes to Providers.pm
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-10 11:25:52 -08:00 |
|
Tom Eastep
|
9cf298482d
|
Merge branch '5.1.8'
|
2017-11-09 12:59:59 -08:00 |
|
Tom Eastep
|
c5a586aa37
|
Allow [...] around gateway address in the providers file
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-09 12:20:01 -08:00 |
|
Tom Eastep
|
832418585a
|
Don't make persistent routes and rules dependent on autosrc.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-08 09:46:25 -08:00 |
|
Tom Eastep
|
605f61fb3c
|
Don't make persistent routes and rules dependent on autosrc.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-08 09:45:59 -08:00 |
|
Tom Eastep
|
8dfa0be611
|
Add shorewall-logging(5)
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-02 15:26:14 -07:00 |
|
Tom Eastep
|
ef8b85fc3e
|
Implement support for logging in the SNAT file
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-11-02 12:44:42 -07:00 |
|
Tom Eastep
|
2b5613026a
|
Merge branch '5.1.8'
|
2017-10-25 09:14:20 -07:00 |
|
Tom Eastep
|
c7c318c0e7
|
Align columns in actions.std
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-25 09:13:37 -07:00 |
|
Tom Eastep
|
d1976189aa
|
Correct a couple of typos in the manpages
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-22 12:59:31 -07:00 |
|
Tom Eastep
|
6b4905c2c0
|
Replace 'tcp' with '6' in action.TCPFlags
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-20 12:33:36 -07:00 |
|
Tom Eastep
|
774b707352
|
Inline Multicast when Address Type Match is available
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-20 12:01:41 -07:00 |
|
Tom Eastep
|
c3bd58827f
|
Align columns in actions.std
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-20 11:44:10 -07:00 |
|
Tom Eastep
|
b35f1112f4
|
Allow 'noinline' in /etc/shorewall[6]/actions to override 'inline'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-20 09:19:50 -07:00 |
|
Tom Eastep
|
a0eb91cb90
|
Inline the Broadcast action when ADDRTYPE match is available
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-20 08:49:14 -07:00 |
|
Tom Eastep
|
77d9eeb915
|
Eliminate extra parameter editing of TPROXY parameter list.
- Clarify syntax for actions with multiple parameters
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-19 13:08:12 -07:00 |
|
Tom Eastep
|
17838c1443
|
Add TCPMSS to the allowed mangle actions.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-19 12:58:38 -07:00 |
|
Tom Eastep
|
5867ce6c3b
|
CLAMPMSS now done in the mangle table.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-18 15:55:07 -07:00 |
|
Tom Eastep
|
8ea96098bf
|
Warning when 'persistent' used with RESTORE_DEFAULT_ROUTE=Yes
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-11 15:22:07 -07:00 |
|
Tom Eastep
|
02ed36332a
|
Revert "Warn when RESTORE_DEFAULT_ROUTE=Yes and a persistent provider is defined"
This reverts commit 39a3c72057 .
|
2017-10-11 11:24:54 -07:00 |
|
Tom Eastep
|
15a3b29a32
|
Revert "Document warning when RESTORE_DEFAULT_ROUTE=Yes and 'persistent'"
This reverts commit bfab002dda .
|
2017-10-11 11:24:39 -07:00 |
|
Tom Eastep
|
cb4f9e7261
|
Don't restore default routes when there is an enabled fallback provider
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-11 11:24:13 -07:00 |
|
Tom Eastep
|
bfab002dda
|
Document warning when RESTORE_DEFAULT_ROUTE=Yes and 'persistent'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-11 11:01:09 -07:00 |
|
Tom Eastep
|
ddb12fcad9
|
Add/correct comments
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-11 11:00:46 -07:00 |
|
Tom Eastep
|
42ce754961
|
Don't restore default routes when a fallback= provider is enabled
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-11 11:00:05 -07:00 |
|
Tom Eastep
|
5cd4d63bc5
|
Delete main default routes when a fallback provider is enabled
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-11 10:59:31 -07:00 |
|
Tom Eastep
|
5b567f2d8b
|
Correct delete_default_routes() in tables other than main
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-11 10:58:48 -07:00 |
|
Tom Eastep
|
39a3c72057
|
Warn when RESTORE_DEFAULT_ROUTE=Yes and a persistent provider is defined
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-11 10:58:09 -07:00 |
|
Tom Eastep
|
b47e633c38
|
Use 'route replace' rather than 'route add' to avoid persistence issues
Previous failure case was:
- disable interface
- reload
- enable interface
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-09 08:58:10 -07:00 |
|
Tom Eastep
|
1b55a37a28
|
Ensure that 'rule add' commands don't fail with persistent interfaces
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-08 08:53:53 -07:00 |
|
Tom Eastep
|
a97dcd23d0
|
Allow merging of rules that specify an IPSEC policy
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-07 13:17:43 -07:00 |
|
Tom Eastep
|
108b169d8d
|
Treat LOG_TARGET like all other capabilities
- Previous implementation could generate unworkable script when
LOAD_HELPERS_ONLY=Yes
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-10-06 08:01:52 -07:00 |
|
Tom Eastep
|
8469f983d8
|
Merge branch '5.1.7'
# Conflicts:
# Shorewall/Perl/prog.footer
|
2017-09-29 15:25:37 -07:00 |
|
Tom Eastep
|
f54acb665a
|
Correct handling of mark range in MARK target.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-09-29 14:44:33 -07:00 |
|
Tom Eastep
|
3d2e9eb93e
|
Improve the fix for SELinux "getattr" denials
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-09-28 15:16:50 -07:00 |
|
Tom Eastep
|
c6a939301f
|
Improve the fix for SELinux "getattr" denials
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-09-28 15:16:00 -07:00 |
|
Tom Eastep
|
1cb98254cc
|
Handle SELinux getattr denials in open() processing
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-09-26 16:42:54 -07:00 |
|
Tom Eastep
|
baa791a1e3
|
Handle SELinux getattr denials in open() processing
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-09-26 16:41:50 -07:00 |
|
Tom Eastep
|
8b4b965f63
|
Remove unnecessary disable/enable of script generation
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-09-21 14:36:30 -07:00 |
|
Tom Eastep
|
8ee2d6246c
|
Update a comment in the compiler
- get_configuration() also processes the shorewallrc file(s)
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-09-21 12:32:34 -07:00 |
|
Tom Eastep
|
a7be3dfece
|
Align progress messages produced by 'reenable'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-09-19 13:29:13 -07:00 |
|
Tom Eastep
|
846e8c4ece
|
Correct reenable logic
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-09-19 13:29:08 -07:00 |
|
Tom Eastep
|
e2bf7e6584
|
Align progress messages produced by 'reenable'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-09-19 13:28:09 -07:00 |
|
Tom Eastep
|
ff3994f6a1
|
Correct reenable logic
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-09-19 13:17:50 -07:00 |
|
Tom Eastep
|
494ec9c59c
|
Avoid extra comparison in reload_command()
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-09-19 10:49:11 -07:00 |
|
Tom Eastep
|
1cde92e8f3
|
Initialize g_dockeringress
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2017-09-19 10:43:44 -07:00 |
|