]>
git.ipfire.org Git - people/ms/ipfire-2.x.git/log
Michael Tremer [Wed, 31 Jul 2013 13:47:25 +0000 (15:47 +0200)]
firewall: Language updates (English and German).
Michael Tremer [Wed, 31 Jul 2013 12:31:18 +0000 (14:31 +0200)]
firewall: Add TOR chains.
Michael Tremer [Wed, 31 Jul 2013 10:56:58 +0000 (12:56 +0200)]
core72: Add updated firewall script.
Michael Tremer [Wed, 31 Jul 2013 10:56:17 +0000 (12:56 +0200)]
torctrl: Add new binary to rootfiles.
Michael Tremer [Wed, 31 Jul 2013 10:55:08 +0000 (12:55 +0200)]
torctrl: Add stop action.
Michael Tremer [Wed, 31 Jul 2013 10:52:40 +0000 (12:52 +0200)]
tor: Add necessary firewall rules.
Michael Tremer [Wed, 31 Jul 2013 10:52:26 +0000 (12:52 +0200)]
tor: Add torctrl binary.
Alexander Marx [Wed, 31 Jul 2013 06:28:29 +0000 (08:28 +0200)]
Forward Firewall: Network addresses are now allowed as source and the ip addressfield has now size 18.
Michael Tremer [Tue, 30 Jul 2013 19:53:16 +0000 (21:53 +0200)]
tor: Import CGI script.
Michael Tremer [Tue, 30 Jul 2013 19:39:50 +0000 (21:39 +0200)]
tor: Configuration file updates.
Alexander Marx [Tue, 30 Jul 2013 10:32:25 +0000 (12:32 +0200)]
Forward Firewall: changed rule coloring. Now whole field is colored instead of just borders. Back Button in firewall groups /hostgroups showed a white site
Michael Tremer [Fri, 19 Jul 2013 12:34:14 +0000 (14:34 +0200)]
arm: New package.
Resource monitor for tor.
Michael Tremer [Fri, 19 Jul 2013 09:40:14 +0000 (11:40 +0200)]
tor: New package.
Michael Tremer [Thu, 25 Jul 2013 14:46:54 +0000 (16:46 +0200)]
vpnmain.cgi: Use MODP groups with smaller key lengths by default.
https://bugzilla.ipfire.org/show_bug.cgi?id=10396
Alexander Marx [Thu, 25 Jul 2013 08:36:36 +0000 (10:36 +0200)]
Forward Firewall: Bugfix: ICMP rules where applied double
Alexander Marx [Thu, 25 Jul 2013 05:33:20 +0000 (07:33 +0200)]
Forward FIrewall: Bugfix: When using predefined services in rulecreation, the rule was not applied. Bugfix: when in rulecreationpage and pressing "back" the site gets white.
Alexander Marx [Wed, 24 Jul 2013 06:06:24 +0000 (08:06 +0200)]
Forward FIrewall: BUGFIX: when setting outgoing to blocked and creating a rule, the last rule changes to "accept"
Michael Tremer [Sat, 20 Jul 2013 16:47:51 +0000 (18:47 +0200)]
Add IPsec ECP changes to core update 72.
Michael Tremer [Sat, 20 Jul 2013 15:35:53 +0000 (17:35 +0200)]
strongswan: Update to 5.1.0rc1.
Michael Tremer [Sat, 20 Jul 2013 10:49:46 +0000 (12:49 +0200)]
ipsec: Add ECP cryptography.
Allow selecting ECDH for IPsec VPN connections.
Stefan Schantl [Wed, 17 Jul 2013 20:30:29 +0000 (22:30 +0200)]
ovpnmain.cgi: Allow to keep the Remote field empty for N2N connections.
* It's now possible to keep the Remote Host/IP field empty.
* Cleaned up code.
Fixes #10392.
Arne Fitzenreiter [Fri, 19 Jul 2013 16:19:40 +0000 (18:19 +0200)]
transmission: update to 2.81.
Arne Fitzenreiter [Fri, 19 Jul 2013 08:03:22 +0000 (10:03 +0200)]
start core72.
Michael Tremer [Thu, 18 Jul 2013 19:22:10 +0000 (21:22 +0200)]
strongswan: Update rootfile.
Alexander Marx [Thu, 18 Jul 2013 11:15:10 +0000 (13:15 +0200)]
Forward Firewall: renamed IPFire to Firewall in SNAT area
Michael Tremer [Thu, 18 Jul 2013 11:10:22 +0000 (13:10 +0200)]
vdr: Add /etc/sysconfig/vdr to backup.
Michael Tremer [Thu, 18 Jul 2013 11:06:42 +0000 (13:06 +0200)]
vdr: Disable debugging logging.
3 is default and includes a lot of debugging output which
leads to really heavy IO with installations with a lot of
channels (satellite mainly).
http://www.vdr-wiki.de/wiki/index.php/VDR_Optionen
Alexander Marx [Thu, 18 Jul 2013 09:53:08 +0000 (11:53 +0200)]
Forward Firewall: SOme language changes and missing translations for firewall-options
Stefan Schantl [Wed, 17 Jul 2013 19:01:14 +0000 (21:01 +0200)]
ovpnmain.cgi: Set mtu-disc to off if not configured.
Fixes #10391.
Stefan Schantl [Wed, 17 Jul 2013 17:58:20 +0000 (19:58 +0200)]
ovpnmain.cgi: Add check for a valid N2N network.
Fixes #10390.
Michael Tremer [Wed, 17 Jul 2013 16:53:13 +0000 (18:53 +0200)]
openvpnctrl: Save the binary from crashing with wrong input.
See #10390.
Michael Tremer [Tue, 16 Jul 2013 10:04:29 +0000 (12:04 +0200)]
ipsecctrl: Re-read everything when configuration is reloaded.
Michael Tremer [Tue, 16 Jul 2013 18:54:28 +0000 (20:54 +0200)]
strongswan: Enable EAP authentication algorithms.
Michael Tremer [Sun, 14 Jul 2013 10:58:38 +0000 (12:58 +0200)]
strongswan: Update to 5.1.0dr2.
Alexander Marx [Fri, 12 Jul 2013 11:30:14 +0000 (13:30 +0200)]
Forward Firewall: show default rule when input is empty
Alexander Marx [Fri, 12 Jul 2013 09:40:04 +0000 (11:40 +0200)]
Forward Firewall: language fixes on last rule in ruletable
Alexander Marx [Fri, 12 Jul 2013 09:05:57 +0000 (11:05 +0200)]
Forward Firewall: set default options for optionsfw and minor change on optionsfw.cgi
Alexander Marx [Fri, 12 Jul 2013 06:01:01 +0000 (08:01 +0200)]
Forward Firewall: added some javascript to automatically select radiobuttons when dropdowns are changed
Alexander Marx [Thu, 11 Jul 2013 15:15:15 +0000 (17:15 +0200)]
Forward Firewall: added some java Script to automatically select radiobuttons when dropdowns are changed. Some cleanup of the code
Alexander Marx [Thu, 11 Jul 2013 05:43:42 +0000 (07:43 +0200)]
Forward Firewall: deleted configfile "nat" in ovpnmain.cgi for portfw check. File "nat" no longer exists. Now the portfw rules are in file "config"
Alexander Marx [Wed, 10 Jul 2013 11:51:46 +0000 (13:51 +0200)]
Forward Firewall: just increased version number
Alexander Marx [Wed, 10 Jul 2013 11:49:52 +0000 (13:49 +0200)]
Forward Firewall: The default rule table (at the end of Forward) shows only default values depending on the network configuration
Alexander Marx [Tue, 9 Jul 2013 12:59:55 +0000 (14:59 +0200)]
Forward Firewall: fixed check for already existing rules.
Alexander Marx [Tue, 9 Jul 2013 12:58:30 +0000 (14:58 +0200)]
Forward Firewall: deleted postrouting block in firewall (not used anywhere)
Michael Tremer [Mon, 8 Jul 2013 13:53:30 +0000 (15:53 +0200)]
iptables: Cleanup creating SNAT/DNAT chains.
Michael Tremer [Mon, 8 Jul 2013 13:50:02 +0000 (15:50 +0200)]
iptables: Remove OPENSSL{PHYSICAL,VIRTUAL} chains which are unused.
Michael Tremer [Mon, 8 Jul 2013 13:47:57 +0000 (15:47 +0200)]
iptables: Jump into the firewall rulesets after everything else has been done.
Michael Tremer [Mon, 8 Jul 2013 13:41:15 +0000 (15:41 +0200)]
iptables: Create OVPNNAT chain after CUSTOM* chains.
Michael Tremer [Mon, 8 Jul 2013 13:38:39 +0000 (15:38 +0200)]
iptables: Create guardian's chains after the CUSTOM* chains.
Michael Tremer [Mon, 8 Jul 2013 13:36:45 +0000 (15:36 +0200)]
iptables: Cleanup creating the OVPNBLOCK chain.
This should happen after the CUSTOM* chains.
Michael Tremer [Mon, 8 Jul 2013 13:25:48 +0000 (15:25 +0200)]
iptables: Block all loopback packets on non-loopback interfaces.
Michael Tremer [Mon, 8 Jul 2013 13:21:04 +0000 (15:21 +0200)]
iptables: Create LOOPBACK chain.
This chain accepts all communication on the loopback
interface without running it through the entire connection
tracking first.
Packets on lo can never be blocked and must always be
accepted. The firewall has to trust itself anyway.
Michael Tremer [Mon, 8 Jul 2013 13:17:56 +0000 (15:17 +0200)]
iptables: Only jump into BADTCP for TCP packets.
This saves us from evaluating lots of rules for non-TCP
packets.
Michael Tremer [Mon, 8 Jul 2013 13:14:15 +0000 (15:14 +0200)]
iptables: Replace state module by conntrack module.
The state module is deprecated in recent releases of iptables
and should not be used any more.
Additionally, this patch adds an extra chain for all
connection tracking rules, so we can keep the entire ruleset
more small and clean.
Alexander Marx [Fri, 5 Jul 2013 10:15:05 +0000 (12:15 +0200)]
Forward Firewall: Updated outgoingfw-converter. redesign of the ruletable's defaultrules
Michael Tremer [Thu, 4 Jul 2013 10:41:25 +0000 (12:41 +0200)]
strongswan: Update to 5.1.0dr1.
Alexander Marx [Thu, 4 Jul 2013 10:37:34 +0000 (12:37 +0200)]
Forward Firewall: some textalignment in last rule row
Alexander Marx [Thu, 4 Jul 2013 10:19:50 +0000 (12:19 +0200)]
Forward Firewall: added "default-rules-table" at the end of forward ruletable
Michael Tremer [Wed, 3 Jul 2013 19:38:17 +0000 (21:38 +0200)]
gperf: New package.
Alexander Marx [Wed, 3 Jul 2013 12:38:40 +0000 (14:38 +0200)]
Forward Firewall: moved default rules from FORWARDFW to POLICYFWD
Alexander Marx [Wed, 3 Jul 2013 09:26:44 +0000 (11:26 +0200)]
Forward Firewall: removed nat part from rules.pl (file nat not existent anymore)
Alexander Marx [Wed, 3 Jul 2013 08:13:06 +0000 (10:13 +0200)]
Forward Firewall: Bugfixes wrong interface in ruletable,when selecting alias firewall interface
Alexander Marx [Wed, 3 Jul 2013 07:26:39 +0000 (09:26 +0200)]
Forward Firewall: some bugfixes
Alexander Marx [Tue, 2 Jul 2013 13:43:44 +0000 (15:43 +0200)]
Forward Firewall: colorize ip addresses when possible in firewall groups. subnetmask now in cidr format
Alexander Marx [Tue, 2 Jul 2013 12:55:46 +0000 (14:55 +0200)]
Forward Firewall: delted subnets from hosts in firewallgroups, colorized all ip-addresses from the firewall-groups if possible. Some minor changes in forwardfw.cgi
Alexander Marx [Tue, 2 Jul 2013 06:21:38 +0000 (08:21 +0200)]
Forward Firewall: Bugfix of last commit. Added "Interface" to source or target that uses "Firewall" interfaces
Alexander Marx [Tue, 2 Jul 2013 06:03:25 +0000 (08:03 +0200)]
Forward Firewall: When using "Firewall" as source or target, the ruletable looks confusing. Theres "RED" in source and target. Now theres "INTERFACE RED".
root [Tue, 2 Jul 2013 02:16:52 +0000 (04:16 +0200)]
Forward Firewall: some language changes de.pl and en.pl as well as forwardfw.cgi and fwhost.cgi
Alexander Marx [Mon, 1 Jul 2013 14:38:14 +0000 (16:38 +0200)]
Forward Firewall: changed some names and added subnets to dropdowns
Alexander Marx [Fri, 28 Jun 2013 07:36:31 +0000 (09:36 +0200)]
Forward Firewall: Design changes
1) source has a new option "firewall" with dropdown for interfaces
2) source default networks->deleted IPFire, all ip's now in brackets
3) deleted warning message in Target that a mac is not usable
4) changes for "apply" button
5) in ruletable the protocol is now right beneath the ruletype column
6) changed target dropdown "INTERNET" to "RED"
7) renamed OpenVPN N-2N to OpenVPN Net-to-Net
8) set missing default firewall options
9) little changes on the en and de lang files
Alexander Marx [Thu, 27 Jun 2013 05:28:06 +0000 (07:28 +0200)]
Forward Firewall: added new line at bottom of all ruletables with the "final rule"
Alexander Marx [Wed, 26 Jun 2013 13:25:50 +0000 (15:25 +0200)]
Forward Firewall: added missing fields to the converters (for dnat)
Alexander Marx [Wed, 26 Jun 2013 11:54:18 +0000 (13:54 +0200)]
UPNP: changed firewall chain from PORTFW to UPNPFW
Alexander Marx [Wed, 26 Jun 2013 11:43:53 +0000 (13:43 +0200)]
Forward Firewall: removed PORTFWACCESS flushing from rules.pl
Alexander Marx [Wed, 26 Jun 2013 11:30:30 +0000 (13:30 +0200)]
Forward Firewall: removed NAT table and txt file.
Alexander Marx [Wed, 26 Jun 2013 08:29:02 +0000 (10:29 +0200)]
Forward Firewall: changed layout of "apply-button" (after rules where changed. When using single hosts in rules, the prefix is no longer shown in the ruletable. Default settings for firewall-options changed
Alexander Marx [Wed, 26 Jun 2013 07:42:38 +0000 (09:42 +0200)]
Forward Firewall: removed dmz from forwardfw.cgi
Alexander Marx [Wed, 26 Jun 2013 07:07:05 +0000 (09:07 +0200)]
Forward Firewall: removed DMZ from rules.pl (does no longer exist, is forward now
Alexander Marx [Wed, 26 Jun 2013 05:56:35 +0000 (07:56 +0200)]
Forward Firewall: convert-dmz now puts converted files into /var/ipfire/forward/config instead of /var/ipfire/forward/dmz
Alexander Marx [Wed, 26 Jun 2013 05:38:15 +0000 (07:38 +0200)]
Forward Firewall: moved "firewall default behaviour" from firewall page to firewall-options page. Some changes in languagefiles de and en.
Alexander Marx [Tue, 25 Jun 2013 10:35:01 +0000 (12:35 +0200)]
Forward Firewall: reorganised ruletable layout
Alexander Marx [Thu, 20 Jun 2013 09:23:43 +0000 (11:23 +0200)]
Forward Firewall: on every reload of the new firewall-rules the firewall.local is also reloaded
Alexander Marx [Wed, 19 Jun 2013 11:31:40 +0000 (13:31 +0200)]
Forward Firewall: changed /etc/init.d/firewall. deleted stop routine and rearranged iptables_init and restart routine
Now it should be possible to use /etc/init.d/firewall restart without errors
Alexander Marx [Mon, 17 Jun 2013 10:45:57 +0000 (12:45 +0200)]
Forward Firewall: cleanup unused code
Alexander Marx [Mon, 17 Jun 2013 08:21:24 +0000 (10:21 +0200)]
Forward Firewall: changed order of LOG and DROP rules for INPUT Chain
Alexander Marx [Fri, 14 Jun 2013 06:22:56 +0000 (08:22 +0200)]
Forward Firewall: redesign of "add timeframe" table in rule creation
Alexander Marx [Thu, 13 Jun 2013 08:17:18 +0000 (10:17 +0200)]
Forward Firewall: added checks if manual ip (src/tgt) is part of a OpenVPN to colour the rules accordingly
Alexander Marx [Wed, 12 Jun 2013 13:17:12 +0000 (15:17 +0200)]
Forward Firewall: INPUT Firewall added "ALL" with ip 0.0.0.0
Alexander Marx [Wed, 12 Jun 2013 13:05:31 +0000 (15:05 +0200)]
Forward Firewall 0.9.9.7: reordered INPUT POLICY.
Michael Tremer [Wed, 12 Jun 2013 12:14:53 +0000 (14:14 +0200)]
openvpnctrl: Cleanup flushChain functions.
Alexander Marx [Wed, 12 Jun 2013 11:00:20 +0000 (13:00 +0200)]
Forward Firewall: added OVPNBLOCK and fixed rules.pl to correctly get ip address of red iface
Michael Tremer [Wed, 12 Jun 2013 10:50:33 +0000 (12:50 +0200)]
openvpnctl: Flush BLOCK and SNAT chain when needed.
Alexander Marx [Tue, 11 Jun 2013 13:53:31 +0000 (15:53 +0200)]
Forward Firewall: Implemented INPUT Firewall (extended external access)
Now you are able to define INPUT Rules on every interface ip
Michael Tremer [Fri, 31 May 2013 11:31:48 +0000 (13:31 +0200)]
openvpnctrl: Block all transfer subnets.
Michael Tremer [Thu, 30 May 2013 19:55:26 +0000 (21:55 +0200)]
openvpnctrl: Remove unneeded code.
Michael Tremer [Thu, 30 May 2013 19:49:32 +0000 (21:49 +0200)]
openvpnctrl: Fixes and improvements.
Handle invalid data and make the code more robust.
Michael Tremer [Wed, 29 May 2013 15:16:37 +0000 (17:16 +0200)]
openvpnctrl: SNAT transfer networks.
Alexander Marx [Mon, 27 May 2013 08:33:50 +0000 (10:33 +0200)]
Forward Firewall: BUGFIX: When creating DMZ Rules with MANUAL IP as source and afterwards editing the rule, the rule was copied and not just edited.
BUGFIX: When using SNAT (outbound) the rule does not seem to work. The NAT_SOURCE chain was on wron position in POSTROUTING
Alexander Marx [Wed, 22 May 2013 05:43:46 +0000 (07:43 +0200)]
Forward Firewall: extended the customservices list
Alexander Marx [Wed, 8 May 2013 06:19:03 +0000 (08:19 +0200)]
Forward Firewall: BUGFIX - when using source Protocol and NO target protocol only the target protocol is shown in ruletable.(But rule is applied correctly)