Age | Commit message (Collapse) | Author |
|
these are no longer needed.
|
|
|
|
updates to dscp node.def for better help text
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
* add code to set global policy for established, related, invalid states
|
|
* use Ipset.pm method rather than CLI path to validate group name
when using group as a match condition in a firewall ruleset
|
|
exists
* change commit check to only check if the interface being applied firewall ruleset
is in a zone if only the ruleset type is either name|ipv6-name. Thus, ignoring the
check when modify rule-set is being applied to an interface
(cherry picked from commit 8b2b85a129d3cf23565efe7b0ee15871ebff15c0)
|
|
|
|
|
|
|
|
|
|
deletes are contained within a single commit
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Shorten chain from VYATTA_PRE_CT_PREROUTING_HOOK to
VYATTA_CT_PREROUTING_HOOK
|
|
|
|
|
|
|
|
|
|
* added 'firewall conntrack-expect-table-size' to modify expect table's size
* added 'firewall conntrack-hash-size' to set hash size for conntrack table
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Handle the case where the IPv6 kernel module is not loaded more gracefully.
|
|
added tcp_udp as a valid protocol value to match both tcp and udp in 1 rule
|
|
(cherry picked from commit 4dadce6ebca29e6f6d7120a44541fd99034417f2)
|
|
(cherry picked from commit 90fb731c3a846e9a951c6fd1c5f73082e2bcf93a)
|
|
|
|
|