summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2009-04-29Handle files moved from other packages to this package.Bob Gilligan
Add "Replace:" clause for each package from which files were moved.
2009-04-290.13.7-37debian/0.13.7-37Stephen Hemminger
2009-04-29Rename virtual-ethernet to pseudo-ethernetStephen Hemminger
2009-04-270.13.7-36debian/0.13.7-36Mohit Mehta
2009-04-27outlaw applying firewall to an interface that is defined under a zoneMohit Mehta
2009-04-270.13.7-35debian/0.13.7-35Stig Thormodsrud
2009-04-27Disable firewall debuging by default.Stig Thormodsrud
2009-04-240.13.7-34debian/0.13.7-34Stig Thormodsrud
2009-04-24enable/disable conntrack separately for ipv4/ipv6Stig Thormodsrud
2009-04-240.13.7-33debian/0.13.7-33Stig Thormodsrud
2009-04-24Move setup/teardown out from top-level firewall node.Stig Thormodsrud
Add refcnts to know when to teardown.
2009-04-240.13.7-32debian/0.13.7-32Bob Gilligan
2009-04-24bugfix 4297: Don't allow modify rulesets on local traffic.Bob Gilligan
2009-04-24Add support for virtual-ethernetStephen Hemminger
2009-04-220.13.7-31debian/0.13.7-31Mohit Mehta
2009-04-22Fix Bug 4261 - Features missing in various firewall sub-treesMohit Mehta
add 'disable', 'fragment', 'ipsec', and 'recent' under 'firewall modify' tree
2009-04-130.13.7-30debian/0.13.7-30Bob Gilligan
2009-04-13Add conntrack and post firewall hooks for IPv6.Bob Gilligan
2009-04-130.13.7-29debian/0.13.7-29Stig Thormodsrud
2009-04-13Fix bug where an empty firewall rule deletes the default drop policy.Stig Thormodsrud
2009-04-13Move firewall "end" processing down to each table.Stig Thormodsrud
Fix bug for global enable/disable of conntrack.
2009-04-090.13.7-28debian/0.13.7-28Stig Thormodsrud
2009-04-09Add ability for firename to select default policy.Stig Thormodsrud
2009-04-08Fix faulty search loop.Stig Thormodsrud
2009-04-070.13.7-27debian/0.13.7-27Stig Thormodsrud
2009-04-07Apply interface firewalls to separate VYATTA_(IN|OUT)_HOOK.Stig Thormodsrud
This enforces in firewall to be processed before out firewall.
2009-04-030.13.7-26debian/0.13.7-26Bob Gilligan
2009-04-03Bugfix 4261: Add support to configure "limit" for IPv6 modify rulesets.Bob Gilligan
2009-04-030.13.7-25debian/0.13.7-25Bob Gilligan
2009-04-03Bugfix 4261: Add support to configure "limit" in IPv6.Bob Gilligan
2009-03-310.13.7-24debian/0.13.7-24Stig Thormodsrud
2009-03-31Remove extra carriage return that was breaking the generated firewallStig Thormodsrud
template.
2009-03-30Cleanup perl code that generates templatesStephen Hemminger
1. Check for errors in open/mkdir 2. Use mkdir_p in perl rather than calling system 3. Use Perl Best Practices style 3 arg open 4. Put less blank lines in templates 5. reindent with perltidy 6. turn on warnings
2009-03-27Revert "Allow user configurable default-policy on firewall."Stig Thormodsrud
Further test identified a problem. The patch is broken if a packet must do both an in & out filter. This reverts commit 754d0f4d855a59020afa20ad8867218708b5c978.
2009-03-27Allow user configurable default-policy on firewall.Stig Thormodsrud
2009-03-260.13.7-23debian/0.13.7-23Mohit Mehta
2009-03-26* add 'redirect' to Valid ICMPv6 TypesMohit Mehta
* add comp_help for ICMPv4 type-name
2009-03-130.13.7-22debian/0.13.7-22Stephen Hemminger
2009-03-13Merge branch 'jenner' of suva.vyatta.com:/git/vyatta-cfg-firewall into jennerStephen Hemminger
2009-03-12Doing strict ES won't work for routerStephen Hemminger
Need a different kind of filter to fix 4061. (Not sure if it is even possible as firewall rule since it depends on quagga config rules).
2009-03-120.13.7-21debian/0.13.7-21Stephen Hemminger
2009-03-12Don't use -PStephen Hemminger
Changing default property of rules screws up other things
2009-03-12Enable strict host matchingStephen Hemminger
Bug 4061 Host (INPUT) chain will only accept packets where destination address matches address on incoming interface.
2009-03-100.13.7-20debian/0.13.7-20Bob Gilligan
2009-03-10Bugfix 4203: Name of template should be classical-ipoa, not classical_ipoaBob Gilligan
2009-03-090.13.7-19debian/0.13.7-19Bob Gilligan
2009-03-09Automatically generate more per-interface firewall templates.Bob Gilligan
Added code to generate at build time the templates for: bridge, openvpn, multilink, serial, and wirelessmodem interfaces.
2009-03-060.13.7-18debian/0.13.7-18Bob Gilligan
2009-03-06Remove per-interface firewall templates; They are now generated.Bob Gilligan
2009-03-040.13.7-17debian/0.13.7-17Bob Gilligan