]> git.ipfire.org Git - people/teissler/ipfire-2.x.git/log
people/teissler/ipfire-2.x.git
9 years agoFirewall: BUG 10526 (missing RED iface in SNAT Dropdown)
Alexander Marx [Tue, 22 Apr 2014 08:03:50 +0000 (10:03 +0200)] 
Firewall: BUG 10526 (missing RED iface in SNAT Dropdown)

9 years agofirewall: Fix accessing port forwardings from internal networks.
Michael Tremer [Sun, 20 Apr 2014 16:13:35 +0000 (18:13 +0200)] 
firewall: Fix accessing port forwardings from internal networks.

When a different "external port" was used, false rules have
been created in the mangle table.

10 years agoUpdate layer7 patch.
Michael Tremer [Fri, 18 Apr 2014 21:11:39 +0000 (23:11 +0200)] 
Update layer7 patch.

This should fix some issues with concurrent access to skbuf.

10 years agoMerge branch 'master' of ssh://git.ipfire.org/pub/git/ipfire-2.x
Michael Tremer [Fri, 18 Apr 2014 20:24:24 +0000 (22:24 +0200)] 
Merge branch 'master' of ssh://git.ipfire.org/pub/git/ipfire-2.x

10 years agoFix spelling of "IPsec".
Michael Tremer [Thu, 17 Apr 2014 10:44:18 +0000 (12:44 +0200)] 
Fix spelling of "IPsec".

10 years agoUpdate translations.
Michael Tremer [Thu, 17 Apr 2014 10:40:04 +0000 (12:40 +0200)] 
Update translations.

10 years agoFirewall: Bug10513
Alexander Marx [Thu, 17 Apr 2014 09:14:25 +0000 (11:14 +0200)] 
Firewall: Bug10513

10 years agofirewall: Explicitely allow DHCP messages.
Michael Tremer [Thu, 17 Apr 2014 10:31:27 +0000 (12:31 +0200)] 
firewall: Explicitely allow DHCP messages.

10 years agostrongswan: rootfile update.
Arne Fitzenreiter [Wed, 16 Apr 2014 04:52:01 +0000 (06:52 +0200)] 
strongswan: rootfile update.

10 years agomove core75 files to oldcore.
Arne Fitzenreiter [Tue, 15 Apr 2014 23:54:14 +0000 (01:54 +0200)] 
move core75 files to oldcore.

10 years agoRename IPFire 2.15 Core Update 76 -> 77.
Michael Tremer [Tue, 15 Apr 2014 19:38:24 +0000 (21:38 +0200)] 
Rename IPFire 2.15 Core Update 76 -> 77.

10 years agostrongswan: Update to 5.1.3.
Michael Tremer [Tue, 15 Apr 2014 19:16:14 +0000 (21:16 +0200)] 
strongswan: Update to 5.1.3.

Fixes CVE-2014-2338.

10 years agoFirewall: Bug 10514 fixed
Alexander Marx [Mon, 14 Apr 2014 06:02:16 +0000 (08:02 +0200)] 
Firewall: Bug 10514 fixed

10 years agokernel: update to 3.10.37.
Arne Fitzenreiter [Mon, 14 Apr 2014 18:13:14 +0000 (20:13 +0200)] 
kernel: update to 3.10.37.

10 years agofirewall: Fix outgoing OpenVPN N2N tunnel packets.
Michael Tremer [Sat, 12 Apr 2014 14:17:20 +0000 (16:17 +0200)] 
firewall: Fix outgoing OpenVPN N2N tunnel packets.

Don't throw away packets from the firewall that pass through
an OpenVPN N2N tunnel.

10 years agofirewall: Fix spelling and seperate spelling issues.
Michael Tremer [Sat, 12 Apr 2014 14:01:11 +0000 (16:01 +0200)] 
firewall: Fix spelling and seperate spelling issues.

10 years agofirewall: Change headlines for rule sections.
Michael Tremer [Sat, 12 Apr 2014 13:55:44 +0000 (15:55 +0200)] 
firewall: Change headlines for rule sections.

10 years agorules.pl: Rewrite P2P protocol filter.
Michael Tremer [Sat, 12 Apr 2014 13:39:08 +0000 (15:39 +0200)] 
rules.pl: Rewrite P2P protocol filter.

10 years agofirewall.cgi: Sort protocols alphabetically.
Michael Tremer [Sat, 12 Apr 2014 13:23:45 +0000 (15:23 +0200)] 
firewall.cgi: Sort protocols alphabetically.

10 years agofirewall: Fix creation of automatic rules for the firewall.
Michael Tremer [Sat, 12 Apr 2014 13:16:08 +0000 (15:16 +0200)] 
firewall: Fix creation of automatic rules for the firewall.

If the firewall is part of a local network (e.g. GREEN),
we automatically add rules that grant/forbid access for the firewall,
too.

This has been broken for various default policies other than ALLOWED.

10 years agomedia.cgi: Add missing 'tr'.
Michael Tremer [Sat, 12 Apr 2014 10:18:57 +0000 (12:18 +0200)] 
media.cgi: Add missing 'tr'.

10 years agoUpdate translations.
Michael Tremer [Fri, 11 Apr 2014 13:17:21 +0000 (15:17 +0200)] 
Update translations.

10 years agoMerge remote-tracking branch 'amarx/RC2-master'
Michael Tremer [Fri, 11 Apr 2014 13:17:08 +0000 (15:17 +0200)] 
Merge remote-tracking branch 'amarx/RC2-master'

10 years agoFirewall: When having rules with more than 3 protocols, show "many" and tooltip
Alexander Marx [Fri, 11 Apr 2014 10:06:52 +0000 (12:06 +0200)] 
Firewall: When having rules with more than 3 protocols, show "many" and tooltip

10 years agokernel: disable intel mei.
Arne Fitzenreiter [Wed, 9 Apr 2014 16:20:46 +0000 (18:20 +0200)] 
kernel: disable intel mei.

Intel Management Engine Interface is still crashing the kernel.

10 years agoFirewall: Fix 10510 - Show all protocols from servicegroups (GRE,IPIP,IPV6,...)
Alexander Marx [Wed, 9 Apr 2014 14:23:55 +0000 (16:23 +0200)] 
Firewall: Fix 10510 - Show all protocols from servicegroups (GRE,IPIP,IPV6,...)

10 years agokernel: disable intel mei.
Arne Fitzenreiter [Wed, 9 Apr 2014 16:20:46 +0000 (18:20 +0200)] 
kernel: disable intel mei.

Intel Management Engine Interface is still crashing the kernel.

10 years agofirewall-policy: Remove empty line.
Michael Tremer [Wed, 9 Apr 2014 13:14:25 +0000 (15:14 +0200)] 
firewall-policy: Remove empty line.

10 years agoFix missing Connection Scheduler strings.
Michael Tremer [Wed, 9 Apr 2014 13:11:41 +0000 (15:11 +0200)] 
Fix missing Connection Scheduler strings.

10 years agoaliases.cgi: Mark name field as mandatory.
Michael Tremer [Wed, 9 Apr 2014 12:19:16 +0000 (14:19 +0200)] 
aliases.cgi: Mark name field as mandatory.

10 years agofirewall: Apply destination NAT rules for the firewall itself, too.
Michael Tremer [Wed, 9 Apr 2014 12:16:32 +0000 (14:16 +0200)] 
firewall: Apply destination NAT rules for the firewall itself, too.

10 years agofirewall: Fix rule generation for protocols without ports.
Michael Tremer [Wed, 9 Apr 2014 12:06:32 +0000 (14:06 +0200)] 
firewall: Fix rule generation for protocols without ports.

10 years agoopenssl: update to 1.0.1g.
Arne Fitzenreiter [Mon, 7 Apr 2014 19:33:34 +0000 (21:33 +0200)] 
openssl: update to 1.0.1g.

Fix for CVE-2014-0160
Add TLS padding extension workaround for broken servers.
Fix for CVE-2014-0076

10 years agoFirewall: fix coloring of internet hosts
Alexander Marx [Mon, 7 Apr 2014 14:14:20 +0000 (16:14 +0200)] 
Firewall: fix coloring of internet hosts

10 years agoFirewall: Fix source preselection of alias when Firewall is selected
Alexander Marx [Mon, 7 Apr 2014 10:09:16 +0000 (12:09 +0200)] 
Firewall: Fix source preselection of alias when Firewall is selected

10 years agoFirewall: BUGFIX 10505
Alexander Marx [Mon, 7 Apr 2014 10:04:50 +0000 (12:04 +0200)] 
Firewall: BUGFIX 10505

10 years agoFirewall: BUGFIX 10507
Alexander Marx [Mon, 7 Apr 2014 06:24:54 +0000 (08:24 +0200)] 
Firewall: BUGFIX 10507

10 years agoMerge branch 'master' of ssh://git.ipfire.org/pub/git/ipfire-2.x
Michael Tremer [Mon, 7 Apr 2014 14:49:33 +0000 (16:49 +0200)] 
Merge branch 'master' of ssh://git.ipfire.org/pub/git/ipfire-2.x

10 years agoglibc: rootfile update (arm).
Arne Fitzenreiter [Sun, 6 Apr 2014 22:35:31 +0000 (00:35 +0200)] 
glibc: rootfile update (arm).

10 years agokernel-header: rootfile update.
Arne Fitzenreiter [Sun, 6 Apr 2014 21:33:51 +0000 (23:33 +0200)] 
kernel-header: rootfile update.

10 years agomedia.cgi: Fix typo once again.
Michael Tremer [Sun, 6 Apr 2014 15:24:13 +0000 (17:24 +0200)] 
media.cgi: Fix typo once again.

10 years agoUpdate Turkish translation.
Ersan Yildirim [Sun, 6 Apr 2014 15:22:31 +0000 (17:22 +0200)] 
Update Turkish translation.

10 years agocore76: Include changed /etc/sysctl.conf in update.
Michael Tremer [Sun, 6 Apr 2014 10:53:30 +0000 (12:53 +0200)] 
core76: Include changed /etc/sysctl.conf in update.

10 years agoglibc: fix image, updater and filecount in installer.
Arne Fitzenreiter [Sun, 6 Apr 2014 08:29:27 +0000 (10:29 +0200)] 
glibc: fix image, updater and filecount in installer.

switch from locale-archive to normale locales add est. 5000 files.
todo: arm-rootfile.

10 years agofirewall: Fix using aliases.
Michael Tremer [Sat, 5 Apr 2014 15:09:56 +0000 (17:09 +0200)] 
firewall: Fix using aliases.

Fix coding errors, actually read aliases configuration
and fall back to default RED IP address if no suitable
alias was found.

10 years agoconvert-portfw: Fix converting aliases.
Michael Tremer [Sat, 5 Apr 2014 15:08:17 +0000 (17:08 +0200)] 
convert-portfw: Fix converting aliases.

ALL is not suitable as it is not a valid configuration value.

10 years agoMerge branch 'master' of ssh://git.ipfire.org/pub/git/ipfire-2.x
Michael Tremer [Sat, 5 Apr 2014 15:02:33 +0000 (17:02 +0200)] 
Merge branch 'master' of ssh://git.ipfire.org/pub/git/ipfire-2.x

10 years agofirewall: fix green only mode.
Arne Fitzenreiter [Sat, 5 Apr 2014 09:04:25 +0000 (11:04 +0200)] 
firewall: fix green only mode.

disable masquerade and green IP/NET check if internet is
connected via green.

10 years agoapache2: update to 2.2.27.
Arne Fitzenreiter [Fri, 4 Apr 2014 19:17:08 +0000 (21:17 +0200)] 
apache2: update to 2.2.27.

10 years agokernel: update to 3.10.36.
Arne Fitzenreiter [Fri, 4 Apr 2014 11:53:41 +0000 (13:53 +0200)] 
kernel: update to 3.10.36.

10 years agokernel: update to 3.10.35.
Arne Fitzenreiter [Thu, 3 Apr 2014 08:06:47 +0000 (10:06 +0200)] 
kernel: update to 3.10.35.

10 years agoglibc: Install all known locales.
Michael Tremer [Tue, 1 Apr 2014 14:24:50 +0000 (16:24 +0200)] 
glibc: Install all known locales.

10 years agofirewall: Fix perl coding error.
Michael Tremer [Mon, 31 Mar 2014 11:16:26 +0000 (13:16 +0200)] 
firewall: Fix perl coding error.

Example:
my @as = (1, 2, 3);
foreach my $a (@as) {
$a += 1;
print "$a\n";
}

$a will be a reference to the number in the array and not
copied. Therefore $a += 1 will change the numbers in the
array as well, so that after the loop the content of @as
would be (2, 3, 4).
To avoid that, the number needs to be copied into a new
variable like: my $b = $a; and we are fine.

This caused that the content of the @sources and @destinations
array has been altered for the second run of the loop and
incorrect (i.e. no) rules were created.

10 years agoMerge branch 'kernel-layer7-oom'
Michael Tremer [Sun, 30 Mar 2014 21:28:35 +0000 (23:28 +0200)] 
Merge branch 'kernel-layer7-oom'

10 years agokernel: Update layer7 patch.
Michael Tremer [Sun, 30 Mar 2014 21:26:29 +0000 (23:26 +0200)] 
kernel: Update layer7 patch.

Brings back the /proc interface and is supposed to
fix a memory leak.

10 years agofirewall-policy: Clarify policy rules.
Michael Tremer [Sun, 30 Mar 2014 20:33:58 +0000 (22:33 +0200)] 
firewall-policy: Clarify policy rules.

There are no functional changes here. Everything that
is not explicitely allowed is now forbidden when the
forward policy is "ALLOWED".

10 years agofirewall-policy: fix drop and logging on red0;
Arne Fitzenreiter [Sat, 29 Mar 2014 14:06:35 +0000 (15:06 +0100)] 
firewall-policy: fix drop and logging on red0;

10 years agoset version to IPFire 2.15 rc1.
Arne Fitzenreiter [Fri, 28 Mar 2014 17:16:31 +0000 (18:16 +0100)] 
set version to IPFire 2.15 rc1.

10 years agofirewall: Create mangle chain NAT_DESTINATION to silence error messages when updating.
Michael Tremer [Thu, 27 Mar 2014 14:08:17 +0000 (15:08 +0100)] 
firewall: Create mangle chain NAT_DESTINATION to silence error messages when updating.

10 years agoFirewall: fix Update from core 75 to 76
Alexander Marx [Thu, 27 Mar 2014 10:58:48 +0000 (11:58 +0100)] 
Firewall: fix Update from core 75 to 76

10 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Michael Tremer [Thu, 27 Mar 2014 14:07:26 +0000 (15:07 +0100)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next

10 years agocups: Fix rootfile.
Michael Tremer [Thu, 27 Mar 2014 10:36:12 +0000 (11:36 +0100)] 
cups: Fix rootfile.

Basically, include just everything.

10 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Arne Fitzenreiter [Thu, 27 Mar 2014 06:30:56 +0000 (07:30 +0100)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next

10 years agorpi-firmware: update to 18a7921.
Arne Fitzenreiter [Thu, 27 Mar 2014 06:29:19 +0000 (07:29 +0100)] 
rpi-firmware: update to 18a7921.

10 years agokernel: update RPi patchset to dea8280.
Arne Fitzenreiter [Thu, 27 Mar 2014 06:25:24 +0000 (07:25 +0100)] 
kernel: update RPi patchset to dea8280.

10 years agoipsecctrl: Fix compiler warning.
Michael Tremer [Wed, 26 Mar 2014 22:47:14 +0000 (23:47 +0100)] 
ipsecctrl: Fix compiler warning.

10 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Michael Tremer [Wed, 26 Mar 2014 22:35:18 +0000 (23:35 +0100)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next

10 years agomedia.cgi: Fix typo 'writen'.
Michael Tremer [Wed, 26 Mar 2014 22:34:58 +0000 (23:34 +0100)] 
media.cgi: Fix typo 'writen'.

10 years agowlanap.cgi: fix missing line from wlan info.
Arne Fitzenreiter [Wed, 26 Mar 2014 07:35:00 +0000 (08:35 +0100)] 
wlanap.cgi: fix missing line from wlan info.

10 years agohostapd: change setting of the regdomain.
Arne Fitzenreiter [Tue, 25 Mar 2014 18:11:03 +0000 (19:11 +0100)] 
hostapd: change setting of the regdomain.

the regdomain is only updated if it was really changed but after boot
the system believe it is "00" World but it is not correctly set at
some cards. So we set a region and set it back to "00" before the
real region was set.

10 years agowlanap: fix typo.
Arne Fitzenreiter [Tue, 25 Mar 2014 12:15:43 +0000 (13:15 +0100)] 
wlanap: fix typo.

10 years agowlanap.cgi: fix detection of not useable channels.
Arne Fitzenreiter [Tue, 25 Mar 2014 12:03:56 +0000 (13:03 +0100)] 
wlanap.cgi: fix detection of not useable channels.

10 years agoiwlwifi: use noibss flags only on radar detection channels.
Arne Fitzenreiter [Tue, 25 Mar 2014 11:59:37 +0000 (12:59 +0100)] 
iwlwifi: use noibss flags only on radar detection channels.

10 years agokernel: update to 3.10.34.
Arne Fitzenreiter [Mon, 24 Mar 2014 12:28:29 +0000 (13:28 +0100)] 
kernel: update to 3.10.34.

10 years agographs.pl: fix links position in chrome for android.
Arne Fitzenreiter [Sun, 23 Mar 2014 16:39:47 +0000 (17:39 +0100)] 
graphs.pl: fix links position in chrome for android.

10 years agofirewall: rules.pl: Honour time constraints for NAT rules as well.
Michael Tremer [Fri, 21 Mar 2014 12:39:03 +0000 (13:39 +0100)] 
firewall: rules.pl: Honour time constraints for NAT rules as well.

10 years agofirewall: rules.pl: Catch invalid configurations.
Michael Tremer [Fri, 21 Mar 2014 12:33:08 +0000 (13:33 +0100)] 
firewall: rules.pl: Catch invalid configurations.

10 years agofirewall: rules.pl: Allow REDIRECT rules.
Michael Tremer [Fri, 21 Mar 2014 12:28:00 +0000 (13:28 +0100)] 
firewall: rules.pl: Allow REDIRECT rules.

10 years agoFirewall: Allow DNAT with target firewall
Alexander Marx [Fri, 21 Mar 2014 11:54:12 +0000 (12:54 +0100)] 
Firewall: Allow DNAT with target firewall

10 years agoFirewall: Rename defaultNetworks to netsettings
Alexander Marx [Fri, 21 Mar 2014 11:20:50 +0000 (12:20 +0100)] 
Firewall: Rename defaultNetworks to netsettings

10 years agoFirewall: DNAT - Show right DNAT interface in ruletable
Alexander Marx [Fri, 21 Mar 2014 07:28:24 +0000 (08:28 +0100)] 
Firewall: DNAT - Show right DNAT interface in ruletable

Now:
When using a hostgroup as source there are all corresponding DNAT
interfaces shown in ruletable depending on the entries in the group.

When in DNAT area "-automatic" is selected, the DNAT interfaces are
shown as IP-Addresses, else they are shown as "ORANGE","GREEN","BLUE"...

BUGFIX: When there is a MAC address used in a sourcegroup, the rules could not be set. Now MAC addresses get allways the public interface as DNAT

10 years agoFirewall: Move some functions from rules.pl to firewall-lib.pl
Alexander Marx [Thu, 20 Mar 2014 16:27:53 +0000 (17:27 +0100)] 
Firewall: Move some functions from rules.pl to firewall-lib.pl

10 years agofirewall: rules.pl: Fix rules with other NAT port.
Michael Tremer [Fri, 21 Mar 2014 11:40:55 +0000 (12:40 +0100)] 
firewall: rules.pl: Fix rules with other NAT port.

10 years agoUpdate translations.
Michael Tremer [Thu, 20 Mar 2014 22:07:26 +0000 (23:07 +0100)] 
Update translations.

10 years agoFirewall: DNAT - always show right red address in dropdown.
Alexander Marx [Thu, 20 Mar 2014 15:23:47 +0000 (16:23 +0100)] 
Firewall: DNAT - always show right red address in dropdown.

Edited language String in DNAT area: external ip address is now Firewall
Interface

10 years agoMerge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next
Arne Fitzenreiter [Wed, 19 Mar 2014 18:07:27 +0000 (19:07 +0100)] 
Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next

10 years agohostapd: enable CONFIG_ACS for dfs channels.
Arne Fitzenreiter [Wed, 19 Mar 2014 18:03:22 +0000 (19:03 +0100)] 
hostapd: enable CONFIG_ACS for dfs channels.

10 years agohostapd: change channellist and status for dfs channels.
Arne Fitzenreiter [Wed, 19 Mar 2014 18:00:47 +0000 (19:00 +0100)] 
hostapd: change channellist and status for dfs channels.

10 years agocore76: add wpa_supplicant to update.
Arne Fitzenreiter [Wed, 19 Mar 2014 08:05:37 +0000 (09:05 +0100)] 
core76: add wpa_supplicant to update.

10 years agoMerge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next
Arne Fitzenreiter [Wed, 19 Mar 2014 06:23:40 +0000 (07:23 +0100)] 
Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next

10 years agohostapd: update to 2.1.
Arne Fitzenreiter [Wed, 19 Mar 2014 06:22:49 +0000 (07:22 +0100)] 
hostapd: update to 2.1.

10 years agofirewall: rules.pl: Add support for auto selection of NAT addresses.
Michael Tremer [Tue, 18 Mar 2014 22:49:23 +0000 (23:49 +0100)] 
firewall: rules.pl: Add support for auto selection of NAT addresses.

10 years agoFirewall: select right value in DNAT Dropdown
Alexander Marx [Tue, 18 Mar 2014 14:13:02 +0000 (15:13 +0100)] 
Firewall: select right value in DNAT Dropdown

10 years agoFirewall: extend DNAT dropdown with auto,BLUE,ORANGE,GREEN
Alexander Marx [Tue, 18 Mar 2014 14:02:55 +0000 (15:02 +0100)] 
Firewall: extend DNAT dropdown with auto,BLUE,ORANGE,GREEN

10 years agoopenssh: Update to 6.6p1.
Michael Tremer [Tue, 18 Mar 2014 17:03:14 +0000 (18:03 +0100)] 
openssh: Update to 6.6p1.

10 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Michael Tremer [Tue, 18 Mar 2014 17:00:42 +0000 (18:00 +0100)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next

10 years agocore76: add tzdata to update.
Arne Fitzenreiter [Tue, 18 Mar 2014 06:28:13 +0000 (07:28 +0100)] 
core76: add tzdata to update.

10 years agotzdata: fix rootfile.
Arne Fitzenreiter [Tue, 18 Mar 2014 06:20:41 +0000 (07:20 +0100)] 
tzdata: fix rootfile.

10 years agoinitskripts: add pcengines apu support to leds.
Arne Fitzenreiter [Mon, 17 Mar 2014 23:25:08 +0000 (00:25 +0100)] 
initskripts: add pcengines apu support to leds.

10 years agoMerge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next
Arne Fitzenreiter [Mon, 17 Mar 2014 23:22:24 +0000 (00:22 +0100)] 
Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next