summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2016-01-240.12.105+vyos2+current1debian/0.12.105+vyos2+current1Kim Hagen
2015-12-16Fix build depends.Thomas Jepp
2015-06-280.12.105+vyos2+lithium17debian/0.12.105+vyos2+lithium17Alex Harpin
2015-06-26vyatta-cfg-vpn: validate local address for vti based vpn connectionsAlex Harpin
Validate the local address used for VTI based VPN connections to ensure only either an IPv4 or IPv6 address is used. Currently VTIs can only accept these for local addresses, other values will fail with extraneous error messages, trap these earlier in the configuation commit process for now. Bug #213 http://bugzilla.vyos.net/show_bug.cgi?id=213
2015-06-260.12.105+vyos2+lithium16debian/0.12.105+vyos2+lithium16Alex Harpin
2015-06-22vyatta-cfg-vpn: validate peer address for vti based vpn connectionsAlex Harpin
Validate the peer address used for VTI based VPN connections to ensure only either an IPv4 or IPv6 address is used. Currently VTIs can only accept these for peer addresses, other values will fail with extraneous error messages, trap these earlier in the configuation commit process for now. Bug #359 http://bugzilla.vyos.net/show_bug.cgi?id=359
2015-06-180.12.105+vyos2+lithium15debian/0.12.105+vyos2+lithium15Alex Harpin
2015-06-18vyatta-cfg-vpn: vti interfaces remain link down after ipsec sa renewalAlex Harpin
VTI interfaces can remain link down after IPSec SA expiry and renewal, leaving the actual IPSec tunnel up and active but the route relating to this VTI interface absent from the routing table; with the end result of no traffic passing through it without manual intervention. Earlier fixes for this issue in both bug #183 and bug #291 fixed one issue but introduced another, this commit fixes both scenarios. Bug #568 http://bugzilla.vyos.net/show_bug.cgi?id=568
2015-06-17vyatta-cfg-vpn: further tidy up of vyatta-vti-config.plAlex Harpin
Remove old comments and other minor tidying up / rearranging of scripts/vyatta-vti-config.pl
2015-06-17vyatta-cfg-vpn: formatting changes for style consistencyAlex Harpin
Perltidy run on scripts/vyatta-vti-config.pl to have consistent identation levels and style throughout.
2015-06-160.12.105+vyos2+lithium14debian/0.12.105+vyos2+lithium14Alex Harpin
2015-06-16vyatta-cfg-vpn: update dh_gencontrol with new development build flagAlex Harpin
2015-06-140.12.105+vyos2+lithium13debian/0.12.105+vyos2+lithium13Daniil Baturin
2015-06-14Bug #504: add an option for pulling IPsec local id from the cert.Daniil Baturin
2015-05-040.12.105+vyos2+lithium12debian/0.12.105+vyos2+lithium12Daniil Baturin
2015-05-04Bug #469: add options for AES-128/256-GCM mode.Daniil Baturin
2015-04-020.12.105+vyos2+lithium11debian/0.12.105+vyos2+lithium11Alex Harpin
2015-02-16Move execution of nhrp script to "end" of ipsec config so it executes on all ↵Kim Hagen
changes made to the ipsec config
2015-02-090.12.105+vyos2+lithium10debian/0.12.105+vyos2+lithium10Alex Harpin
2015-02-02Bug #367 - DMVPN Testing, but I do not see ESP traffic.Kim Hagen
2015-01-190.12.105+vyos2+lithium9debian/0.12.105+vyos2+lithium9Daniil Baturin
2015-01-19Remove @ from the id/remote-id help string. It was never required.Daniil Baturin
2015-01-190.12.105+vyos2+lithium8debian/0.12.105+vyos2+lithium8Daniil Baturin
2015-01-19Bug #348: remove unnecessary restrictions on the PSK format.Daniil Baturin
2015-01-170.12.105+vyos2+lithium7debian/0.12.105+vyos2+lithium7Alex Harpin
2015-01-17vyatta-cfg-vpn: update pre-shared secret key help for single quotesAlex Harpin
Updated the help for pre-shared secret key usage when special characters are used. These need to be enclosed in single quotes to stop them being expanded by the bash shell. Bug #451 http://bugzilla.vyos.net/show_bug.cgi?id=451
2014-12-260.12.105+vyos2+lithium6debian/0.12.105+vyos2+lithium6Alex Harpin
2014-12-26Update maintainer addressAlex Harpin
2014-12-190.12.105+vyos2+lithium5debian/0.12.105+vyos2+lithium5Daniil Baturin
2014-12-19Bug #415: use remote-id for peer ID unconditionally if it's set.Daniil Baturin
2014-12-19Bug #414: quote the leftid value to avoid problems with non-alphanumeric ↵Daniil Baturin
characters.
2014-12-18Merge pull request #11 from jhendryUK/ikev2_reauth_optionDaniil Baturin
Ikev2 reauth option
2014-12-050.12.105+vyos2+lithium4debian/0.12.105+vyos2+lithium4Alex Harpin
2014-12-05vyatta-cfg-vpn: remove the cfgvti helper programAlex Harpin
The cfgvti helper program was originally added for configuring VTIs. The functionality it provided is now included upstream in iproute, so it is no longer required following the previous commits for Bug #358. Bug #358 http://bugzilla.vyos.net/show_bug.cgi?id=358
2014-12-050.12.105+vyos2+lithium3debian/0.12.105+vyos2+lithium3Alex Harpin
2014-12-04vyatta-cfg-vpn: formatting changes for style consistencyAlex Harpin
Update lib/Vyatta/VPN/vtiIntf.pm to have consistent identation levels and style throughout.
2014-12-04vyatta-cfg-vpn: reduce the vti mark base to prevent integer overflowAlex Harpin
Reduce the vtiMarkBase value to prevent integer overflow on the created ip xfrm states and policies.
2014-12-04vyatta-cfg-vpn: update vti creation in line with changes to strongswanAlex Harpin
Update the VTI creation process to go along with the changes added to the vyatta-strongswan package, due to changes in the kernel vti module. This also removes the need for additional netfilter rules to ensure that packets are directed to the corresponding VTI. Bug #358 http://bugzilla.vyos.net/show_bug.cgi?id=358
2014-12-04vyatta-cfg-vpn: update parseVtiTun to account for vti changesAlex Harpin
Update the parseVtiTun function to account for the new way of configuring VTIs. Bug #358 http://bugzilla.vyos.net/show_bug.cgi?id=358
2014-12-04vyatta-cfg-vpn: move scripts/vtiIntf.pm to lib/Vyatta/VPN/vtiIntf.pmAlex Harpin
Move vtiIntf.pm to a more logical place, in line with all the other packages.
2014-12-01Fixing syntax error in vpn-config.pl, fixing allowed parameters in the ↵Jason Hendry
per-tunnel ikev2-reauth node
2014-12-01Exposing ikev2 reauth option in CLI, defaulting to 'no'Jason Hendry
2014-10-290.12.105+vyos2+lithium2debian/0.12.105+vyos2+lithium2Daniil Baturin
2014-10-29Update changelog for the new branch.Daniil Baturin
2014-10-190.12.105+vyos1+helium4debian/0.12.105+vyos1+helium4Daniil Baturin
2014-10-19Remove the VTI script after use.Daniil Baturin
2014-10-080.12.105+vyos1+helium3debian/0.12.105+vyos1+helium3Daniil Baturin
2014-10-06Merge pull request #10 from cyclops8456/heliumDaniil Baturin
Commits for Bug #291 and Bug #332
2014-10-05vyatta-cfg-vpn: prevent duplicate local rsa key includesAlex Harpin
Prevent duplicate include statements, for the local rsa keys, being added to the ipsec.secrets file when more than one VPN connection is configured. Bug #332 http://bugzilla.vyos.net/show_bug.cgi?id=332
2014-10-05vyatta-cfg-vpn: formatting changes for style consistencyAlex Harpin
Update scripts/vpn-config.pl to have consistent identation levels and style throughout.