Age | Commit message (Collapse) | Author | |
---|---|---|---|
2011-02-08 | Initial x509 for site-to-site ipsec vpn | John Southworth | |
2011-02-07 | Bugfix 5802: add auto-update feature, for Dynamic DNS peers | John Southworth | |
2011-02-04 | Add the ability to define a default esp group for tunnels under a peer to use | John Southworth | |
2011-02-04 | Move protocol out of local and remote nodes as it has to be the same | John Southworth | |
2011-02-03 | Initial additions to support local and remote protoport in general instead ↵ | John Southworth | |
of just for GRE | |||
2011-01-31 | Make vpn errors and exiting consistent | John Southworth | |
2011-01-31 | Fix problem with multiple psk being generated per peer | John Southworth | |
2011-01-28 | Bugfix: 5684, added quotes around rsa keys in ipsec.conf so that strongswan ↵ | John Southworth | |
doesn't fail on == | |||
2011-01-26 | Bugfix: 5677 add protoport option for simpler GRE tunnels, for now this is ↵ | John Southworth | |
specifically for GRE more protocols can be added in the future if required. | |||
2011-01-26 | Make VPN config die after the first error occurs instead of continuing to ↵ | John Southworth | |
process the rest of the config | |||
2011-01-26 | Bug 2506: Moved the connection-type node to the peer level, as discussed ↵ | John Southworth | |
with support. | |||
2011-01-25 | Bugfix 6068. This fixes the given perl problem, however there may be more ↵ | John Southworth | |
that appear. We should die when an error is found and stop processing the file | |||
2011-01-25 | Bugfix 6229: don't allow local and remote subnets to be the same | John Southworth | |
2011-01-25 | bugfix: 2506 added option to define initiatior or responder mode | John Southworth | |
2011-01-20 | make adjustment so that op mode can deal with new secrets file format | John Southworth | |
(cherry picked from commit ef7acbaef8ccd9305644f22ddb6df1ca985fcf4a) | |||
2011-01-20 | fix conflict while merging | John Southworth | |
2011-01-17 | more location based error support. | Michael Larson | |
2011-01-17 | error location support changes to vpn (local-ip and auth missing only at ↵ | Michael Larson | |
this time). | |||
2010-07-22 | remove unused options | An-Cheng Huang | |
* high-level operations should not access CLI implementation details. | |||
2010-06-03 | Fix Bug 5652 set ike/ipsec keying tries to forever | Mohit Mehta | |
2010-05-26 | add passthrough connection if remote-subnet contains local-subnet | Mohit Mehta | |
2010-04-19 | Fix Bug 5542 | Mohit Mehta | |
* add commment for op-mode commands' dependency on config-mode check | |||
2010-03-31 | Fix Bug 5500 Unable to establish a VPN connection from a remote peer with a | Mohit Mehta | |
dynamic peer when using FQDN identifier for remote end * allow remote peer with dynamic IP to connect using Main Mode/PSK | |||
2010-03-18 | Fix Bug 5087 add support to specify PFS group when PFS is enabled | Mohit Mehta | |
2010-02-05 | 1. use correct notation to represent private,public networks | Mohit Mehta | |
i.e. use vhost:%priv,%no instead of %priv,%no. Previously used notation was never supposed to work. Corrected notation is what we use in l2tp/ipsec as well and is also recommended otherwise. 2. cannot use leftsourceip to add route when right-subnet is not specific is based on generalized private,public networks | |||
2010-01-30 | Fix Bug 1832 VPN copy-tos Disabling copy-tos field doesn't work | Mohit Mehta | |
* remove copy-tos field under 'vpn ipsec'. It's not supposed to work with NETKEY | |||
2010-01-28 | perltidy vpn-config.pl | Mohit Mehta | |
2010-01-28 | remove dead code. we use 'ipsec update' to update changes to connections now | Mohit Mehta | |
2010-01-25 | add back CLI node for disabling uniqreqid | Mohit Mehta | |
2010-01-12 | use leftsourceip to add route to remote subnet | Mohit Mehta | |
(cherry picked from commit eb6d27497bab9e82218d8999778f7b4959fd34ea) | |||
2010-01-12 | Do not start IKEv2 daemon for now | Mohit Mehta | |
(cherry picked from commit 7fab51307ecaf65a7da880f60a97a73bda87e5c7) | |||
2010-01-12 | * remove extraneous unused code | Mohit Mehta | |
* use @id for identification when it's specified. It can be used even if local-ip is not 0.0.0.0 * extend syntax check for id to allow specifying hostnames * fix ipsec.secrets generation - if specified always use ids for local and remote peer (cherry picked from commit 3e7a4e45af00c11e6009d38fd97c67c2de0fa145) | |||
2010-01-12 | add comment to identify end of connection description | Mohit Mehta | |
(cherry picked from commit cb9ed22ae45d03fa37148273d02cef4a9a179d1d) | |||
2010-01-12 | no need to maintain state of connections and take state-specific actions for | Mohit Mehta | |
each connection when config changes. `ipsec update` in strongswan determines any changes in ipsec.conf and updates the configuration on running daemon (cherry picked from commit 55b703e669e0f792c04d29541d8fe00d2a9d624b) | |||
2010-01-12 | First pass code changes to vyatta-cfg-vpn for migration to strongswan : | Mohit Mehta | |
Remove CLI support and back-end code for unsupported parameters * No aggressive mode support in strongswan * remove syslog facility.level CLI. strongswan uses authpriv facility by default, no syslog parameter support * remove Robert's disable-uniqreqids option for now. need to get strongswan to do the same thing first Remove Openswan specific parameters added to workaroung bugs * remove plutowait, this was added to workaround Openswan Bug 412 * remove nhelpers, this was added to workaround Openswan Bug 198 Other Changes * add '!' at the end of ike and esp proposal list to signify end of list * replace `ipsec start` commands with built-in commands for `ipsec starter` control utility * replace `ipsec auto` with `ipsec whack` commands. Still need to figure out if `ipsec auto --add|--up $connection` could be replaces by simply using `ipsec update` in stronswan * change pluto.ctl path | |||
2009-11-25 | pptp config check not needed when vpn ipsec is configured | Mohit Mehta | |
2009-11-02 | more formatting clean-up | Mohit Mehta | |
2009-11-02 | indent and reformat script using perltidy in hope of making it easier to read | Mohit Mehta | |
2009-10-27 | add support for same reqids to openswan cfg | Robert Bays | |
2009-10-06 | Fix Bug 3011 Remote VPN configuration issues site-to-site warning | Mohit Mehta | |
* issue warning when none of site-to-site peers, remote access l2tp/pptp set | |||
2009-09-04 | Fix 4902: setting ipsec site-to-site tunnel with authentication id <> and ↵ | Stig Thormodsrud | |
local-ip 0.0.0.0 got "no connection named <>" | |||
2009-08-20 | manage state of add|delete|restart on connections for vpn given disable node. | slioch | |
2009-08-20 | added support in configuration script to support tunnel disable node. | slioch | |
2009-07-10 | Fix 4623: Removing IPSEC VPN config without removing cluster ipsec config ↵ | Stig Thormodsrud | |
drops all interfaces. Add a check to prevent deleting ipsec if it's referenced by cluster. (cherry picked from commit b17d768af5845cb5b74e9ba8c6d8f8e2701bb0f6) | |||
2009-05-26 | Fix 3836: Allow VPN authentication ID to accept values of IP address, domain ↵ | Stig Thormodsrud | |
name and "" enclosed phrases | |||
2009-04-08 | Bugfix 3284: Allow commit to succeed if local-ip is not configured. | Bob Gilligan | |
Previously, the ipsec setup script would fail the commit if the IPv4 address given in the local-ip parameter was not configured on one of the ipsec-interfaces at the time that the commit took place. This causes problems for PPP interfaces that may be configured, but down for operational reasons. This change makes the setup script more liberal. It will allow the commit to complete, but issue a warning the address, they can restart ipsec. PPP has logic to restart ipsec when a link comes up. | |||
2009-04-06 | Bugfix 2387: Don't list interfaces in ipsec config file. | Bob Gilligan | |
The "interfaces=..." entry in the /etc/ipsec.conf file needs to list the actual interfaces we are using only if the underlying kernel IPsec support is provided by KLIPS. In our case, we are using NETKEY, so we don't need to list our interfaces there. Not listing them makes ipsec startup a bit more robust. | |||
2009-03-16 | Fix 4219: IPsec VPN does not launch on boot, error "The local-ip address ↵ | Stig Thormodsrud | |
X.X.X.X of peer "X.X.X.X" has not been configured in any of the local. | |||
2009-02-12 | Fix ambiguous use of $log | Stephen Hemminger | |
There were two definitions of $log | |||
2009-02-11 | Fix use of unitialized value | Stephen Hemminger | |
Bug 4021 Don't die if local ip not configured. |