summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2009-05-12Fix Bug 4394 reject is an invalid action for rules in modify rulesetsMohit Mehta
* remove reject as an allowed value for action field in modify & ipv6-modify firewall rulesets
2009-05-110.13.7-42debian/0.13.7-42Mohit Mehta
2009-05-11Add 'reject' as a configurable value for default-policyMohit Mehta
under name and ipv6-name rulesets
2009-05-080.13.7-41debian/0.13.7-41Mohit Mehta
2009-05-08Fix Bug 4388 firewall name shouldn't have been set after commit failedMohit Mehta
* undo chain setup and refcnt work if chain rule failed during chain creation
2009-05-08Bugfix 4340: Enable net.netfilter.nf_conntrack_tcp_be_liberal by default.Bob Gilligan
The parameter in question loosens the "acceptability" check on TCP sequence and ACK numbers in the TCP conntrack module. This allows connection tracking to survive certain cases where packet loss would cause it to loose sync with the TCP endpoints.
2009-05-050.13.7-40debian/0.13.7-40Mohit Mehta
2009-05-05* don't allow user to create a chain that exists in the system. This may beMohit Mehta
either vyatta/user defined chains or system chains such as INPUT, OUTPUT etc. * don't allow user to create chains with name starting from 'VZONE'. This is reserved for zone chains created by us.
2009-05-010.13.7-39debian/0.13.7-39Mohit Mehta
2009-05-01* setup table only for specific tree, not both filter and mangleMohit Mehta
as we teardown table only for the tree that was in the CLI * remove 'next' statement for removed for loop * fix Bug 4244 - Committing firewall changes breaks WAN Load-balancing (WLB) we only delete chains that are configured under firewall and don't touch chains that might be owned by other features such as zone based firewall, WLB * remove unused code, code cleanup
2009-04-290.13.7-38debian/0.13.7-38Bob Gilligan
2009-04-29Handle files moved from other packages to this package.Bob Gilligan
Add "Replace:" clause for each package from which files were moved.
2009-04-290.13.7-37debian/0.13.7-37Stephen Hemminger
2009-04-29Rename virtual-ethernet to pseudo-ethernetStephen Hemminger
2009-04-270.13.7-36debian/0.13.7-36Mohit Mehta
2009-04-27outlaw applying firewall to an interface that is defined under a zoneMohit Mehta
2009-04-270.13.7-35debian/0.13.7-35Stig Thormodsrud
2009-04-27Disable firewall debuging by default.Stig Thormodsrud
2009-04-240.13.7-34debian/0.13.7-34Stig Thormodsrud
2009-04-24enable/disable conntrack separately for ipv4/ipv6Stig Thormodsrud
2009-04-240.13.7-33debian/0.13.7-33Stig Thormodsrud
2009-04-24Move setup/teardown out from top-level firewall node.Stig Thormodsrud
Add refcnts to know when to teardown.
2009-04-240.13.7-32debian/0.13.7-32Bob Gilligan
2009-04-24bugfix 4297: Don't allow modify rulesets on local traffic.Bob Gilligan
2009-04-24Add support for virtual-ethernetStephen Hemminger
2009-04-220.13.7-31debian/0.13.7-31Mohit Mehta
2009-04-22Fix Bug 4261 - Features missing in various firewall sub-treesMohit Mehta
add 'disable', 'fragment', 'ipsec', and 'recent' under 'firewall modify' tree
2009-04-130.13.7-30debian/0.13.7-30Bob Gilligan
2009-04-13Add conntrack and post firewall hooks for IPv6.Bob Gilligan
2009-04-130.13.7-29debian/0.13.7-29Stig Thormodsrud
2009-04-13Fix bug where an empty firewall rule deletes the default drop policy.Stig Thormodsrud
2009-04-13Move firewall "end" processing down to each table.Stig Thormodsrud
Fix bug for global enable/disable of conntrack.
2009-04-090.13.7-28debian/0.13.7-28Stig Thormodsrud
2009-04-09Add ability for firename to select default policy.Stig Thormodsrud
2009-04-08Fix faulty search loop.Stig Thormodsrud
2009-04-070.13.7-27debian/0.13.7-27Stig Thormodsrud
2009-04-07Apply interface firewalls to separate VYATTA_(IN|OUT)_HOOK.Stig Thormodsrud
This enforces in firewall to be processed before out firewall.
2009-04-030.13.7-26debian/0.13.7-26Bob Gilligan
2009-04-03Bugfix 4261: Add support to configure "limit" for IPv6 modify rulesets.Bob Gilligan
2009-04-030.13.7-25debian/0.13.7-25Bob Gilligan
2009-04-03Bugfix 4261: Add support to configure "limit" in IPv6.Bob Gilligan
2009-03-310.13.7-24debian/0.13.7-24Stig Thormodsrud
2009-03-31Remove extra carriage return that was breaking the generated firewallStig Thormodsrud
template.
2009-03-30Cleanup perl code that generates templatesStephen Hemminger
1. Check for errors in open/mkdir 2. Use mkdir_p in perl rather than calling system 3. Use Perl Best Practices style 3 arg open 4. Put less blank lines in templates 5. reindent with perltidy 6. turn on warnings
2009-03-27Revert "Allow user configurable default-policy on firewall."Stig Thormodsrud
Further test identified a problem. The patch is broken if a packet must do both an in & out filter. This reverts commit 754d0f4d855a59020afa20ad8867218708b5c978.
2009-03-27Allow user configurable default-policy on firewall.Stig Thormodsrud
2009-03-260.13.7-23debian/0.13.7-23Mohit Mehta
2009-03-26* add 'redirect' to Valid ICMPv6 TypesMohit Mehta
* add comp_help for ICMPv4 type-name
2009-03-130.13.7-22debian/0.13.7-22Stephen Hemminger
2009-03-13Merge branch 'jenner' of suva.vyatta.com:/git/vyatta-cfg-firewall into jennerStephen Hemminger