Jo-Philipp Wich
|
fe2d387a8c
|
firewall: bail out if uci is used in firewall include files
SVN-Revision: 30694
|
2012-02-23 18:50:47 +00:00 |
|
Jo-Philipp Wich
|
50a22f4f9e
|
firewall: relocate TCPMSS rules into mangle table, add code to selectively clear them out again
SVN-Revision: 28669
|
2011-10-29 18:02:45 +00:00 |
|
Jo-Philipp Wich
|
c7ac1b5b0c
|
firewall: do not produce 0.0.0.0/0 if a symbolic masq_src or masq_dest is given but does not resolve to an ip
SVN-Revision: 28628
|
2011-10-27 18:14:55 +00:00 |
|
Jo-Philipp Wich
|
995face56d
|
firewall: make ESTABLISHED,RELATED rules match before INVALID, use conntrack instead of state match (#10038)
SVN-Revision: 28148
|
2011-09-01 20:37:22 +00:00 |
|
Jo-Philipp Wich
|
c014101d73
|
firewall: allow symbolic names of interfaces and aliases in masq_src and masq_dest
SVN-Revision: 27196
|
2011-06-16 21:54:59 +00:00 |
|
Jo-Philipp Wich
|
13333a6742
|
firewall: move include sourcing into a subshell, this makes the firewall init immune against exit in the include scripts
SVN-Revision: 25835
|
2011-03-02 19:20:29 +00:00 |
|
Jo-Philipp Wich
|
6a335579b8
|
fireall: - support negations for src_ip, dest_ip, src_dip options in rules and redirects - add NOTRACK target to rule sections, allows to define fine grained notrack rules
SVN-Revision: 23141
|
2010-09-28 10:42:56 +00:00 |
|
Jo-Philipp Wich
|
f90328f26e
|
firewall: make invalid redirects and duplicate zones non-fatal, print a notice and discard them
SVN-Revision: 23080
|
2010-09-16 11:47:35 +00:00 |
|
Jo-Philipp Wich
|
f3dd8278bb
|
firewall: - simplify masquerade rule setup - remove various subshell invocations - speedup fw() by not relying on xargs and pipes - rework SNAT support - attach to dest zone, use src_dip/src_dport as snat source
SVN-Revision: 23024
|
2010-09-11 20:04:34 +00:00 |
|
Jo-Philipp Wich
|
ca5bf9e291
|
firewall: - handle NAT reflection in firewall hotplug, solves synchronizing issues on boot - introduce masq_src and masq_dest options to limit zone masq to specific ip ranges, supports multiple subnets and negation
SVN-Revision: 22888
|
2010-09-04 15:49:13 +00:00 |
|
Jo-Philipp Wich
|
ee4dd61b10
|
firewall: - fix processing of rules with an ip family option - append interface rules at the end of internal zone chains, simplifies injecting user or addon rules - support simple file logging (option log + option log_limit per zone)
SVN-Revision: 22847
|
2010-08-31 01:54:08 +00:00 |
|
Jo-Philipp Wich
|
d6d1dd47d3
|
firewall: fix another notrack related bug
SVN-Revision: 22218
|
2010-07-15 23:24:01 +00:00 |
|
Jo-Philipp Wich
|
f8fa598bf4
|
firewall: - notrack support was broken in multiple ways, fix it - also consider a zone conntracked if any redirect references it (#7196)
SVN-Revision: 22215
|
2010-07-15 22:01:48 +00:00 |
|
Jo-Philipp Wich
|
40ad9defcc
|
firewall: - fix ip6tables rules when icmp_type option is set - add "family" option to zones, forwardings, redirects and rules to selectively apply rules to iptables and/or ip6tables
SVN-Revision: 21508
|
2010-05-19 21:35:23 +00:00 |
|
Jo-Philipp Wich
|
3ffd27f905
|
firewall: implement disable_ipv6 uci option
SVN-Revision: 21503
|
2010-05-19 01:55:46 +00:00 |
|
Jo-Philipp Wich
|
c284cb51c0
|
firewall: - replace uci firewall with a modular dual stack implementation developed by Malte S. Stretz - bump version to 2
SVN-Revision: 21286
|
2010-05-01 18:22:01 +00:00 |
|