]> git.ipfire.org Git - people/ms/ipfire-2.x.git/log
people/ms/ipfire-2.x.git
11 years agoMerge remote-tracking branch 'amarx/firewall' into firewall-next firewall-next
Michael Tremer [Thu, 8 Aug 2013 13:01:36 +0000 (15:01 +0200)] 
Merge remote-tracking branch 'amarx/firewall' into firewall-next

11 years agoForward Firewall: delete double entries in config/backup/include
Alexander Marx [Thu, 8 Aug 2013 06:49:25 +0000 (08:49 +0200)] 
Forward Firewall: delete double entries in config/backup/include

11 years agoMerge branch 'firewall' of ssh://git.ipfire.org/pub/git/people/amarx/ipfire-2.x into...
Alexander Marx [Thu, 8 Aug 2013 06:38:54 +0000 (08:38 +0200)] 
Merge branch 'firewall' of ssh://git.ipfire.org/pub/git/people/amarx/ipfire-2.x into firewall

Conflicts:
config/forwardfw/rules.pl
config/rootfiles/common/apache2
langs/de/cgi-bin/de.pl
langs/en/cgi-bin/en.pl
lfs/configroot
lfs/strongswan

11 years agoForward Firewall: rebase to master branch
Alexander Marx [Thu, 8 Aug 2013 06:01:23 +0000 (08:01 +0200)] 
Forward Firewall: rebase to master branch

11 years agoForward Firewall: deleted double TOR chain
Alexander Marx [Mon, 5 Aug 2013 07:32:46 +0000 (09:32 +0200)] 
Forward Firewall: deleted double TOR chain

11 years agoForward Firewall: deleted outgoingfwmac from firewall script (not used in new firewall)
Alexander Marx [Mon, 5 Aug 2013 07:20:16 +0000 (09:20 +0200)] 
Forward Firewall: deleted outgoingfwmac from firewall script (not used in new firewall)

11 years agoDDNS: Use HTTPS for all-inkl.com.
Michael Tremer [Sat, 3 Aug 2013 11:36:19 +0000 (13:36 +0200)] 
DDNS: Use HTTPS for all-inkl.com.

11 years agotor.cgi: Always show all configuration options.
Michael Tremer [Fri, 2 Aug 2013 11:17:54 +0000 (13:17 +0200)] 
tor.cgi: Always show all configuration options.

Otherwise, if tor was disable, all settings like nickname, etc.
were reset to default.

11 years agotor.cgi: Check for valid accounting limit.
Michael Tremer [Fri, 2 Aug 2013 09:27:14 +0000 (11:27 +0200)] 
tor.cgi: Check for valid accounting limit.

11 years agotor.cgi: Check for valid relay address.
Michael Tremer [Fri, 2 Aug 2013 09:22:52 +0000 (11:22 +0200)] 
tor.cgi: Check for valid relay address.

11 years agotor.cgi: Check for valid port numbers.
Michael Tremer [Fri, 2 Aug 2013 09:20:53 +0000 (11:20 +0200)] 
tor.cgi: Check for valid port numbers.

11 years agotor.cgi: Catch invalid characters in relay name.
Michael Tremer [Fri, 2 Aug 2013 09:06:40 +0000 (11:06 +0200)] 
tor.cgi: Catch invalid characters in relay name.

11 years agotor.cgi: Burst bandwidth may never be less than rate.
Michael Tremer [Fri, 2 Aug 2013 08:57:01 +0000 (10:57 +0200)] 
tor.cgi: Burst bandwidth may never be less than rate.

11 years agotor: The slowest bandwidth rate for a relay is 20 kbyte/s.
Michael Tremer [Fri, 2 Aug 2013 08:42:41 +0000 (10:42 +0200)] 
tor: The slowest bandwidth rate for a relay is 20 kbyte/s.

11 years agotor: Fix path to readhash in initscript.
Michael Tremer [Fri, 2 Aug 2013 08:42:08 +0000 (10:42 +0200)] 
tor: Fix path to readhash in initscript.

11 years agoForward Firewall: deleted unused warning message regarding mac addresses
Alexander Marx [Fri, 2 Aug 2013 05:55:44 +0000 (07:55 +0200)] 
Forward Firewall: deleted unused warning message regarding mac addresses

11 years agotor: fix permissions.
Arne Fitzenreiter [Thu, 1 Aug 2013 20:27:37 +0000 (22:27 +0200)] 
tor: fix permissions.

11 years agocore72: Add strongswan update.
Michael Tremer [Thu, 1 Aug 2013 17:41:21 +0000 (19:41 +0200)] 
core72: Add strongswan update.

11 years agostrongswan: Update to 5.1.0.
Michael Tremer [Thu, 1 Aug 2013 17:38:50 +0000 (19:38 +0200)] 
strongswan: Update to 5.1.0.

11 years agoDDNS: Support for all-inkl.com.
Michael Tremer [Thu, 1 Aug 2013 15:38:12 +0000 (17:38 +0200)] 
DDNS: Support for all-inkl.com.

Requested by Daniel Kovacs <daniel.kovacs@pleasuredome.org>.

11 years agotor.cgi: Show number of connected relays.
Michael Tremer [Wed, 31 Jul 2013 17:26:37 +0000 (19:26 +0200)] 
tor.cgi: Show number of connected relays.

11 years agotor: Don't ship torify.
Michael Tremer [Wed, 31 Jul 2013 17:22:00 +0000 (19:22 +0200)] 
tor: Don't ship torify.

This will need tsocks, which is not present on IPFire.

11 years agoWUI: Add Tor menu entry.
Michael Tremer [Wed, 31 Jul 2013 17:20:42 +0000 (19:20 +0200)] 
WUI: Add Tor menu entry.

11 years agotor.cgi: Minor functionality fixes and layout improvements.
Michael Tremer [Wed, 31 Jul 2013 17:11:59 +0000 (19:11 +0200)] 
tor.cgi: Minor functionality fixes and layout improvements.

11 years agoarm: Don't require distutils.
Michael Tremer [Wed, 31 Jul 2013 16:06:05 +0000 (18:06 +0200)] 
arm: Don't require distutils.

We don't have that module shipped and we don't really
need it for arm either.

11 years agofirewall: Language updates (English and German).
Michael Tremer [Wed, 31 Jul 2013 13:47:25 +0000 (15:47 +0200)] 
firewall: Language updates (English and German).

11 years agofirewall: Add TOR chains.
Michael Tremer [Wed, 31 Jul 2013 12:31:18 +0000 (14:31 +0200)] 
firewall: Add TOR chains.

11 years agocore72: Add updated firewall script.
Michael Tremer [Wed, 31 Jul 2013 10:56:58 +0000 (12:56 +0200)] 
core72: Add updated firewall script.

11 years agotorctrl: Add new binary to rootfiles.
Michael Tremer [Wed, 31 Jul 2013 10:56:17 +0000 (12:56 +0200)] 
torctrl: Add new binary to rootfiles.

11 years agotorctrl: Add stop action.
Michael Tremer [Wed, 31 Jul 2013 10:55:08 +0000 (12:55 +0200)] 
torctrl: Add stop action.

11 years agotor: Add necessary firewall rules.
Michael Tremer [Wed, 31 Jul 2013 10:52:40 +0000 (12:52 +0200)] 
tor: Add necessary firewall rules.

11 years agotor: Add torctrl binary.
Michael Tremer [Wed, 31 Jul 2013 10:52:26 +0000 (12:52 +0200)] 
tor: Add torctrl binary.

11 years agoForward Firewall: Network addresses are now allowed as source and the ip addressfield...
Alexander Marx [Wed, 31 Jul 2013 06:28:29 +0000 (08:28 +0200)] 
Forward Firewall: Network addresses are now allowed as source and the ip addressfield has now size 18.

11 years agotor: Import CGI script.
Michael Tremer [Tue, 30 Jul 2013 19:53:16 +0000 (21:53 +0200)] 
tor: Import CGI script.

11 years agotor: Configuration file updates.
Michael Tremer [Tue, 30 Jul 2013 19:39:50 +0000 (21:39 +0200)] 
tor: Configuration file updates.

11 years agoForward Firewall: changed rule coloring. Now whole field is colored instead of just...
Alexander Marx [Tue, 30 Jul 2013 10:32:25 +0000 (12:32 +0200)] 
Forward Firewall: changed rule coloring. Now whole field is colored instead of just borders. Back Button in firewall groups /hostgroups showed a white site

11 years agoarm: New package.
Michael Tremer [Fri, 19 Jul 2013 12:34:14 +0000 (14:34 +0200)] 
arm: New package.

Resource monitor for tor.

11 years agotor: New package.
Michael Tremer [Fri, 19 Jul 2013 09:40:14 +0000 (11:40 +0200)] 
tor: New package.

11 years agovpnmain.cgi: Use MODP groups with smaller key lengths by default.
Michael Tremer [Thu, 25 Jul 2013 14:46:54 +0000 (16:46 +0200)] 
vpnmain.cgi: Use MODP groups with smaller key lengths by default.

https://bugzilla.ipfire.org/show_bug.cgi?id=10396

11 years agoForward Firewall: Bugfix: ICMP rules where applied double
Alexander Marx [Thu, 25 Jul 2013 08:36:36 +0000 (10:36 +0200)] 
Forward Firewall: Bugfix: ICMP rules where applied double

11 years agoForward FIrewall: Bugfix: When using predefined services in rulecreation, the rule...
Alexander Marx [Thu, 25 Jul 2013 05:33:20 +0000 (07:33 +0200)] 
Forward FIrewall: Bugfix: When using predefined services in rulecreation, the rule was not applied. Bugfix: when in rulecreationpage and pressing "back" the site gets white.

11 years agoForward FIrewall: BUGFIX: when setting outgoing to blocked and creating a rule, the...
Alexander Marx [Wed, 24 Jul 2013 06:06:24 +0000 (08:06 +0200)] 
Forward FIrewall: BUGFIX: when setting outgoing to blocked and creating a rule, the last rule changes to "accept"

11 years agoAdd IPsec ECP changes to core update 72.
Michael Tremer [Sat, 20 Jul 2013 16:47:51 +0000 (18:47 +0200)] 
Add IPsec ECP changes to core update 72.

11 years agostrongswan: Update to 5.1.0rc1.
Michael Tremer [Sat, 20 Jul 2013 15:35:53 +0000 (17:35 +0200)] 
strongswan: Update to 5.1.0rc1.

11 years agoipsec: Add ECP cryptography.
Michael Tremer [Sat, 20 Jul 2013 10:49:46 +0000 (12:49 +0200)] 
ipsec: Add ECP cryptography.

Allow selecting ECDH for IPsec VPN connections.

11 years agoovpnmain.cgi: Allow to keep the Remote field empty for N2N connections.
Stefan Schantl [Wed, 17 Jul 2013 20:30:29 +0000 (22:30 +0200)] 
ovpnmain.cgi: Allow to keep the Remote field empty for N2N connections.

* It's now possible to keep the Remote Host/IP field empty.
* Cleaned up code.

Fixes #10392.

11 years agotransmission: update to 2.81.
Arne Fitzenreiter [Fri, 19 Jul 2013 16:19:40 +0000 (18:19 +0200)] 
transmission: update to 2.81.

11 years agostart core72.
Arne Fitzenreiter [Fri, 19 Jul 2013 08:03:22 +0000 (10:03 +0200)] 
start core72.

11 years agostrongswan: Update rootfile.
Michael Tremer [Thu, 18 Jul 2013 19:22:10 +0000 (21:22 +0200)] 
strongswan: Update rootfile.

11 years agoForward Firewall: renamed IPFire to Firewall in SNAT area
Alexander Marx [Thu, 18 Jul 2013 11:15:10 +0000 (13:15 +0200)] 
Forward Firewall: renamed IPFire to Firewall in SNAT area

11 years agovdr: Add /etc/sysconfig/vdr to backup.
Michael Tremer [Thu, 18 Jul 2013 11:10:22 +0000 (13:10 +0200)] 
vdr: Add /etc/sysconfig/vdr to backup.

11 years agovdr: Disable debugging logging.
Michael Tremer [Thu, 18 Jul 2013 11:06:42 +0000 (13:06 +0200)] 
vdr: Disable debugging logging.

3 is default and includes a lot of debugging output which
leads to really heavy IO with installations with a lot of
channels (satellite mainly).

http://www.vdr-wiki.de/wiki/index.php/VDR_Optionen

11 years agoForward Firewall: SOme language changes and missing translations for firewall-options
Alexander Marx [Thu, 18 Jul 2013 09:53:08 +0000 (11:53 +0200)] 
Forward Firewall: SOme language changes and missing translations for firewall-options

11 years agoovpnmain.cgi: Set mtu-disc to off if not configured.
Stefan Schantl [Wed, 17 Jul 2013 19:01:14 +0000 (21:01 +0200)] 
ovpnmain.cgi: Set mtu-disc to off if not configured.

Fixes #10391.

11 years agoovpnmain.cgi: Add check for a valid N2N network.
Stefan Schantl [Wed, 17 Jul 2013 17:58:20 +0000 (19:58 +0200)] 
ovpnmain.cgi: Add check for a valid N2N network.

Fixes #10390.

11 years agoopenvpnctrl: Save the binary from crashing with wrong input.
Michael Tremer [Wed, 17 Jul 2013 16:53:13 +0000 (18:53 +0200)] 
openvpnctrl: Save the binary from crashing with wrong input.

See #10390.

11 years agoipsecctrl: Re-read everything when configuration is reloaded.
Michael Tremer [Tue, 16 Jul 2013 10:04:29 +0000 (12:04 +0200)] 
ipsecctrl: Re-read everything when configuration is reloaded.

11 years agostrongswan: Enable EAP authentication algorithms.
Michael Tremer [Tue, 16 Jul 2013 18:54:28 +0000 (20:54 +0200)] 
strongswan: Enable EAP authentication algorithms.

11 years agostrongswan: Update to 5.1.0dr2.
Michael Tremer [Sun, 14 Jul 2013 10:58:38 +0000 (12:58 +0200)] 
strongswan: Update to 5.1.0dr2.

11 years agoForward Firewall: show default rule when input is empty
Alexander Marx [Fri, 12 Jul 2013 11:30:14 +0000 (13:30 +0200)] 
Forward Firewall: show default rule when input is empty

11 years agoForward Firewall: language fixes on last rule in ruletable
Alexander Marx [Fri, 12 Jul 2013 09:40:04 +0000 (11:40 +0200)] 
Forward Firewall: language fixes on last rule in ruletable

11 years agoForward Firewall: set default options for optionsfw and minor change on optionsfw.cgi
Alexander Marx [Fri, 12 Jul 2013 09:05:57 +0000 (11:05 +0200)] 
Forward Firewall: set default options for optionsfw and minor change on optionsfw.cgi

11 years agoForward Firewall: added some javascript to automatically select radiobuttons when...
Alexander Marx [Fri, 12 Jul 2013 06:01:01 +0000 (08:01 +0200)] 
Forward Firewall: added some javascript to automatically select radiobuttons when dropdowns are changed

11 years agoForward Firewall: added some java Script to automatically select radiobuttons when...
Alexander Marx [Thu, 11 Jul 2013 15:15:15 +0000 (17:15 +0200)] 
Forward Firewall: added some java Script to automatically select radiobuttons when dropdowns are changed. Some cleanup of the code

11 years agoForward Firewall: deleted configfile "nat" in ovpnmain.cgi for portfw check. File...
Alexander Marx [Thu, 11 Jul 2013 05:43:42 +0000 (07:43 +0200)] 
Forward Firewall: deleted configfile "nat" in ovpnmain.cgi for portfw check. File "nat" no longer exists. Now the portfw rules are in file "config"

11 years agoForward Firewall: just increased version number
Alexander Marx [Wed, 10 Jul 2013 11:51:46 +0000 (13:51 +0200)] 
Forward Firewall: just increased version number

11 years agoForward Firewall: The default rule table (at the end of Forward) shows only default...
Alexander Marx [Wed, 10 Jul 2013 11:49:52 +0000 (13:49 +0200)] 
Forward Firewall: The default rule table (at the end of Forward) shows only default values depending on the network configuration

11 years agoForward Firewall: fixed check for already existing rules.
Alexander Marx [Tue, 9 Jul 2013 12:59:55 +0000 (14:59 +0200)] 
Forward Firewall: fixed check for already existing rules.

11 years agoForward Firewall: deleted postrouting block in firewall (not used anywhere)
Alexander Marx [Tue, 9 Jul 2013 12:58:30 +0000 (14:58 +0200)] 
Forward Firewall: deleted postrouting block in firewall (not used anywhere)

11 years agoiptables: Cleanup creating SNAT/DNAT chains.
Michael Tremer [Mon, 8 Jul 2013 13:53:30 +0000 (15:53 +0200)] 
iptables: Cleanup creating SNAT/DNAT chains.

11 years agoiptables: Remove OPENSSL{PHYSICAL,VIRTUAL} chains which are unused.
Michael Tremer [Mon, 8 Jul 2013 13:50:02 +0000 (15:50 +0200)] 
iptables: Remove OPENSSL{PHYSICAL,VIRTUAL} chains which are unused.

11 years agoiptables: Jump into the firewall rulesets after everything else has been done.
Michael Tremer [Mon, 8 Jul 2013 13:47:57 +0000 (15:47 +0200)] 
iptables: Jump into the firewall rulesets after everything else has been done.

11 years agoiptables: Create OVPNNAT chain after CUSTOM* chains.
Michael Tremer [Mon, 8 Jul 2013 13:41:15 +0000 (15:41 +0200)] 
iptables: Create OVPNNAT chain after CUSTOM* chains.

11 years agoiptables: Create guardian's chains after the CUSTOM* chains.
Michael Tremer [Mon, 8 Jul 2013 13:38:39 +0000 (15:38 +0200)] 
iptables: Create guardian's chains after the CUSTOM* chains.

11 years agoiptables: Cleanup creating the OVPNBLOCK chain.
Michael Tremer [Mon, 8 Jul 2013 13:36:45 +0000 (15:36 +0200)] 
iptables: Cleanup creating the OVPNBLOCK chain.

This should happen after the CUSTOM* chains.

11 years agoiptables: Block all loopback packets on non-loopback interfaces.
Michael Tremer [Mon, 8 Jul 2013 13:25:48 +0000 (15:25 +0200)] 
iptables: Block all loopback packets on non-loopback interfaces.

11 years agoiptables: Create LOOPBACK chain.
Michael Tremer [Mon, 8 Jul 2013 13:21:04 +0000 (15:21 +0200)] 
iptables: Create LOOPBACK chain.

This chain accepts all communication on the loopback
interface without running it through the entire connection
tracking first.

Packets on lo can never be blocked and must always be
accepted. The firewall has to trust itself anyway.

11 years agoiptables: Only jump into BADTCP for TCP packets.
Michael Tremer [Mon, 8 Jul 2013 13:17:56 +0000 (15:17 +0200)] 
iptables: Only jump into BADTCP for TCP packets.

This saves us from evaluating lots of rules for non-TCP
packets.

11 years agoiptables: Replace state module by conntrack module.
Michael Tremer [Mon, 8 Jul 2013 13:14:15 +0000 (15:14 +0200)] 
iptables: Replace state module by conntrack module.

The state module is deprecated in recent releases of iptables
and should not be used any more.

Additionally, this patch adds an extra chain for all
connection tracking rules, so we can keep the entire ruleset
more small and clean.

11 years agoForward Firewall: Updated outgoingfw-converter. redesign of the ruletable's defaultrules
Alexander Marx [Fri, 5 Jul 2013 10:15:05 +0000 (12:15 +0200)] 
Forward Firewall: Updated outgoingfw-converter. redesign of the ruletable's defaultrules

11 years agostrongswan: Update to 5.1.0dr1.
Michael Tremer [Thu, 4 Jul 2013 10:41:25 +0000 (12:41 +0200)] 
strongswan: Update to 5.1.0dr1.

11 years agoForward Firewall: some textalignment in last rule row
Alexander Marx [Thu, 4 Jul 2013 10:37:34 +0000 (12:37 +0200)] 
Forward Firewall: some textalignment in last rule row

11 years agoForward Firewall: added "default-rules-table" at the end of forward ruletable
Alexander Marx [Thu, 4 Jul 2013 10:19:50 +0000 (12:19 +0200)] 
Forward Firewall: added "default-rules-table" at the end of forward ruletable

11 years agogperf: New package.
Michael Tremer [Wed, 3 Jul 2013 19:38:17 +0000 (21:38 +0200)] 
gperf: New package.

11 years agoForward Firewall: moved default rules from FORWARDFW to POLICYFWD
Alexander Marx [Wed, 3 Jul 2013 12:38:40 +0000 (14:38 +0200)] 
Forward Firewall: moved default rules from FORWARDFW to POLICYFWD

11 years agoForward Firewall: removed nat part from rules.pl (file nat not existent anymore)
Alexander Marx [Wed, 3 Jul 2013 09:26:44 +0000 (11:26 +0200)] 
Forward Firewall: removed nat part from rules.pl (file nat not existent anymore)

11 years agoForward Firewall: Bugfixes wrong interface in ruletable,when selecting alias firewall...
Alexander Marx [Wed, 3 Jul 2013 08:13:06 +0000 (10:13 +0200)] 
Forward Firewall: Bugfixes wrong interface in ruletable,when selecting alias firewall interface

11 years agoForward Firewall: some bugfixes
Alexander Marx [Wed, 3 Jul 2013 07:26:39 +0000 (09:26 +0200)] 
Forward Firewall: some bugfixes

11 years agoForward Firewall: colorize ip addresses when possible in firewall groups. subnetmask...
Alexander Marx [Tue, 2 Jul 2013 13:43:44 +0000 (15:43 +0200)] 
Forward Firewall: colorize ip addresses when possible in firewall groups. subnetmask now in cidr format

11 years agoForward Firewall: delted subnets from hosts in firewallgroups, colorized all ip-addre...
Alexander Marx [Tue, 2 Jul 2013 12:55:46 +0000 (14:55 +0200)] 
Forward Firewall: delted subnets from hosts in firewallgroups, colorized all ip-addresses from the firewall-groups if possible. Some minor changes in forwardfw.cgi

11 years agoForward Firewall: Bugfix of last commit. Added "Interface" to source or target that...
Alexander Marx [Tue, 2 Jul 2013 06:21:38 +0000 (08:21 +0200)] 
Forward Firewall: Bugfix of last commit. Added "Interface" to source or target that uses "Firewall" interfaces

11 years agoForward Firewall: When using "Firewall" as source or target, the ruletable looks...
Alexander Marx [Tue, 2 Jul 2013 06:03:25 +0000 (08:03 +0200)] 
Forward Firewall: When using "Firewall" as source or target, the ruletable looks confusing. Theres "RED" in source and target. Now theres "INTERFACE RED".

11 years agoForward Firewall: some language changes de.pl and en.pl as well as forwardfw.cgi...
root [Tue, 2 Jul 2013 02:16:52 +0000 (04:16 +0200)] 
Forward Firewall: some language changes de.pl and en.pl as well as forwardfw.cgi and fwhost.cgi

11 years agoForward Firewall: changed some names and added subnets to dropdowns
Alexander Marx [Mon, 1 Jul 2013 14:38:14 +0000 (16:38 +0200)] 
Forward Firewall: changed some names and added subnets to dropdowns

11 years agoForward Firewall: Design changes
Alexander Marx [Fri, 28 Jun 2013 07:36:31 +0000 (09:36 +0200)] 
Forward Firewall: Design changes
1) source has a new option "firewall" with dropdown for interfaces
2) source default networks->deleted IPFire, all ip's now in brackets
3) deleted warning message in Target that a mac is not usable
4) changes for "apply" button
5) in ruletable the protocol is now right beneath the ruletype column
6) changed target dropdown "INTERNET" to "RED"
7) renamed OpenVPN N-2N to OpenVPN Net-to-Net
8) set missing default firewall options
9) little changes on the en and de lang files

11 years agoForward Firewall: added new line at bottom of all ruletables with the "final rule"
Alexander Marx [Thu, 27 Jun 2013 05:28:06 +0000 (07:28 +0200)] 
Forward Firewall: added new line at bottom of all ruletables with the "final rule"

11 years agoForward Firewall: added missing fields to the converters (for dnat)
Alexander Marx [Wed, 26 Jun 2013 13:25:50 +0000 (15:25 +0200)] 
Forward Firewall: added missing fields to the converters (for dnat)

11 years agoUPNP: changed firewall chain from PORTFW to UPNPFW
Alexander Marx [Wed, 26 Jun 2013 11:54:18 +0000 (13:54 +0200)] 
UPNP: changed firewall chain from PORTFW to UPNPFW

11 years agoForward Firewall: removed PORTFWACCESS flushing from rules.pl
Alexander Marx [Wed, 26 Jun 2013 11:43:53 +0000 (13:43 +0200)] 
Forward Firewall: removed PORTFWACCESS flushing from rules.pl

11 years agoForward Firewall: removed NAT table and txt file.
Alexander Marx [Wed, 26 Jun 2013 11:30:30 +0000 (13:30 +0200)] 
Forward Firewall: removed NAT table and txt file.