Age | Commit message (Collapse) | Author | |
---|---|---|---|
2012-03-29 | Add a script for validating single IPv4 or IPv6 address with no prefix | Daniil Baturin | |
length. | |||
2012-02-29 | Fix uninitilized bug | John Southworth | |
2012-02-28 | Bugfix 6839: Warn that pre-shared key changes aren't loaded until a rekey ↵ | John Southworth | |
interval | |||
2011-06-15 | Bugfix 6767: Move /tmp/ipsec.log to /var/log/vyatta and rotate it. | Bob Gilligan | |
2011-06-08 | Bugfix 7145: same changes were needed for site-to-site as well | John Southworth | |
2011-04-01 | Bugfix 6972: Suppress messages from the ipsec dhcp script | John Southworth | |
2011-02-23 | Much cleaner way to do the check to see if something has changed in the ↵ | John Southworth | |
ipsec or rsa-key config tree. | |||
2011-02-23 | Don't make vpn-config.pl run if there were no relevant changes, before it ↵ | John Southworth | |
ran everytime there was a change in pptp or l2tp configs as well. | |||
2011-02-22 | Fix some dhcp config problems | John Southworth | |
2011-02-22 | Make sure only interfaces with dhcp enabled are allowed as a dhcp-interface | John Southworth | |
2011-02-22 | Fix minor x509 configuration error message problem | John Southworth | |
2011-02-17 | Fix the no old ip given from dhclient problem | John Southworth | |
2011-02-17 | Log the change when this script is run | John Southworth | |
2011-02-17 | Reread secrets before an update | John Southworth | |
2011-02-17 | Fix initial boot problems for dhcp interfaces | John Southworth | |
2011-02-17 | Added Placeholder for ipsec dhclient hook | John Southworth | |
2011-02-16 | Initial support for configuring dhcp-interfaces for IPSEC, needs testing | John Southworth | |
2011-02-08 | Initial x509 for site-to-site ipsec vpn | John Southworth | |
2011-02-07 | Bugfix 5802: add auto-update feature, for Dynamic DNS peers | John Southworth | |
2011-02-04 | Add the ability to define a default esp group for tunnels under a peer to use | John Southworth | |
2011-02-04 | Move protocol out of local and remote nodes as it has to be the same | John Southworth | |
2011-02-03 | Initial additions to support local and remote protoport in general instead ↵ | John Southworth | |
of just for GRE | |||
2011-01-31 | Make vpn errors and exiting consistent | John Southworth | |
2011-01-31 | Fix problem with multiple psk being generated per peer | John Southworth | |
2011-01-28 | Bugfix: 5684, added quotes around rsa keys in ipsec.conf so that strongswan ↵ | John Southworth | |
doesn't fail on == | |||
2011-01-26 | Bugfix: 5677 add protoport option for simpler GRE tunnels, for now this is ↵ | John Southworth | |
specifically for GRE more protocols can be added in the future if required. | |||
2011-01-26 | Make VPN config die after the first error occurs instead of continuing to ↵ | John Southworth | |
process the rest of the config | |||
2011-01-26 | Bug 2506: Moved the connection-type node to the peer level, as discussed ↵ | John Southworth | |
with support. | |||
2011-01-25 | Bugfix 6068. This fixes the given perl problem, however there may be more ↵ | John Southworth | |
that appear. We should die when an error is found and stop processing the file | |||
2011-01-25 | Bugfix 6229: don't allow local and remote subnets to be the same | John Southworth | |
2011-01-25 | bugfix: 2506 added option to define initiatior or responder mode | John Southworth | |
2011-01-20 | make adjustment so that op mode can deal with new secrets file format | John Southworth | |
(cherry picked from commit ef7acbaef8ccd9305644f22ddb6df1ca985fcf4a) | |||
2011-01-20 | fix conflict while merging | John Southworth | |
2011-01-17 | more location based error support. | Michael Larson | |
2011-01-17 | error location support changes to vpn (local-ip and auth missing only at ↵ | Michael Larson | |
this time). | |||
2010-07-22 | remove unused options | An-Cheng Huang | |
* high-level operations should not access CLI implementation details. | |||
2010-06-03 | Fix Bug 5652 set ike/ipsec keying tries to forever | Mohit Mehta | |
2010-05-26 | add passthrough connection if remote-subnet contains local-subnet | Mohit Mehta | |
2010-04-19 | Fix Bug 5542 | Mohit Mehta | |
* add commment for op-mode commands' dependency on config-mode check | |||
2010-03-31 | Fix Bug 5500 Unable to establish a VPN connection from a remote peer with a | Mohit Mehta | |
dynamic peer when using FQDN identifier for remote end * allow remote peer with dynamic IP to connect using Main Mode/PSK | |||
2010-03-18 | Fix Bug 5087 add support to specify PFS group when PFS is enabled | Mohit Mehta | |
2010-02-05 | 1. use correct notation to represent private,public networks | Mohit Mehta | |
i.e. use vhost:%priv,%no instead of %priv,%no. Previously used notation was never supposed to work. Corrected notation is what we use in l2tp/ipsec as well and is also recommended otherwise. 2. cannot use leftsourceip to add route when right-subnet is not specific is based on generalized private,public networks | |||
2010-01-30 | Fix Bug 1832 VPN copy-tos Disabling copy-tos field doesn't work | Mohit Mehta | |
* remove copy-tos field under 'vpn ipsec'. It's not supposed to work with NETKEY | |||
2010-01-28 | perltidy vpn-config.pl | Mohit Mehta | |
2010-01-28 | remove dead code. we use 'ipsec update' to update changes to connections now | Mohit Mehta | |
2010-01-25 | add back CLI node for disabling uniqreqid | Mohit Mehta | |
2010-01-12 | use leftsourceip to add route to remote subnet | Mohit Mehta | |
(cherry picked from commit eb6d27497bab9e82218d8999778f7b4959fd34ea) | |||
2010-01-12 | Do not start IKEv2 daemon for now | Mohit Mehta | |
(cherry picked from commit 7fab51307ecaf65a7da880f60a97a73bda87e5c7) | |||
2010-01-12 | * remove extraneous unused code | Mohit Mehta | |
* use @id for identification when it's specified. It can be used even if local-ip is not 0.0.0.0 * extend syntax check for id to allow specifying hostnames * fix ipsec.secrets generation - if specified always use ids for local and remote peer (cherry picked from commit 3e7a4e45af00c11e6009d38fd97c67c2de0fa145) | |||
2010-01-12 | add comment to identify end of connection description | Mohit Mehta | |
(cherry picked from commit cb9ed22ae45d03fa37148273d02cef4a9a179d1d) |