<feed xmlns='http://www.w3.org/2005/Atom'>
<title>vyos-1x.git/interface-definitions/include/firewall/common-rule-inet.xml.i, branch circinus-public-unmaintained</title>
<subtitle>VyOS command definitions, scripts, and utilities (mirror of https://github.com/vyos/vyos-1x.git)
</subtitle>
<id>https://git.amelek.net/vyos/vyos-1x.git/atom?h=circinus-public-unmaintained</id>
<link rel='self' href='https://git.amelek.net/vyos/vyos-1x.git/atom?h=circinus-public-unmaintained'/>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/'/>
<updated>2024-05-15T17:09:16+00:00</updated>
<entry>
<title>T3900: add support for raw table in firewall.</title>
<updated>2024-05-15T17:09:16+00:00</updated>
<author>
<name>Nicolas Fort</name>
<email>nicolasfort1988@gmail.com</email>
</author>
<published>2024-05-15T17:09:16+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=6871c5541c1962e63d7a9b75d2bb43df2a8d372b'/>
<id>urn:sha1:6871c5541c1962e63d7a9b75d2bb43df2a8d372b</id>
<content type='text'>
</content>
</entry>
<entry>
<title>xml: T5738: use generic-disable-node building block for "disable" CLI nodes</title>
<updated>2024-03-05T19:20:27+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2024-03-05T19:20:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=21b0bf0168697fdbe514ae49a4a28b39a91ec777'/>
<id>urn:sha1:21b0bf0168697fdbe514ae49a4a28b39a91ec777</id>
<content type='text'>
Make the code more uniform and maintainable.
</content>
</entry>
<entry>
<title>T5977: firewall: remove ipsec options in output chain rule definitions, since it's not supported.</title>
<updated>2024-01-23T18:43:34+00:00</updated>
<author>
<name>Nicolas Fort</name>
<email>nicolasfort1988@gmail.com</email>
</author>
<published>2024-01-23T18:43:34+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=9d490ecf616eb9d019beee37a3802705c4109d9d'/>
<id>urn:sha1:9d490ecf616eb9d019beee37a3802705c4109d9d</id>
<content type='text'>
</content>
</entry>
<entry>
<title>firewall: T5834: Improve log message and simplify log-option include</title>
<updated>2023-12-27T03:49:51+00:00</updated>
<author>
<name>Indrajit Raychaudhuri</name>
<email>irc@indrajit.com</email>
</author>
<published>2023-12-22T23:22:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=53a48f499ae9bcc2f657136bb7779b38aad1c242'/>
<id>urn:sha1:53a48f499ae9bcc2f657136bb7779b38aad1c242</id>
<content type='text'>
`include/firewall/rule-log-options.xml.i` is now more aptly renamed to
`include/firewall/log-options.xml.i`.
</content>
</entry>
<entry>
<title>T5729: firewall: switch to valueless in order to remove unnecessary &lt;enable|disable&gt; commands; log and state moved to new syntax.</title>
<updated>2023-11-10T19:26:35+00:00</updated>
<author>
<name>Nicolas Fort</name>
<email>nicolasfort1988@gmail.com</email>
</author>
<published>2023-11-10T19:26:35+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=c4409d6a4e11bf2acc7b5b96888e2c471c4559e5'/>
<id>urn:sha1:c4409d6a4e11bf2acc7b5b96888e2c471c4559e5</id>
<content type='text'>
</content>
</entry>
<entry>
<title>T5616: firewall: add option to be able to match firewall marks in firewall filter and in policy route.</title>
<updated>2023-09-29T11:15:59+00:00</updated>
<author>
<name>Nicolas Fort</name>
<email>nicolasfort1988@gmail.com</email>
</author>
<published>2023-09-27T17:41:14+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=2ae3de0848dee0f3da28727fc30e2beeecd412e1'/>
<id>urn:sha1:2ae3de0848dee0f3da28727fc30e2beeecd412e1</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Merge pull request #2295 from sever-sever/T5217-synproxy</title>
<updated>2023-09-28T15:02:33+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2023-09-28T15:02:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=852e9c3328e61f5d0b92a9efca376aec94533f2b'/>
<id>urn:sha1:852e9c3328e61f5d0b92a9efca376aec94533f2b</id>
<content type='text'>
T5217: Add firewall synproxy</content>
</entry>
<entry>
<title>firewall: T5614: Add support for matching on conntrack helper</title>
<updated>2023-09-24T14:44:32+00:00</updated>
<author>
<name>sarthurdev</name>
<email>965089+sarthurdev@users.noreply.github.com</email>
</author>
<published>2023-09-24T12:38:12+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=81dee963a9ca3224ddbd54767a36efae5851a001'/>
<id>urn:sha1:81dee963a9ca3224ddbd54767a36efae5851a001</id>
<content type='text'>
</content>
</entry>
<entry>
<title>T5217: Add firewall synproxy</title>
<updated>2023-09-21T12:30:39+00:00</updated>
<author>
<name>Viacheslav Hletenko</name>
<email>v.gletenko@vyos.io</email>
</author>
<published>2023-09-20T11:46:42+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=bdad4e046872e054ec7783b2f04b73a8a690a045'/>
<id>urn:sha1:bdad4e046872e054ec7783b2f04b73a8a690a045</id>
<content type='text'>
Add ability to SYNPROXY connections
It is useful to protect against TCP SYN flood attacks and port-scanners

set firewall global-options syn-cookies 'enable'
set firewall ipv4 input filter rule 10 action 'synproxy'
set firewall ipv4 input filter rule 10 destination port '22'
set firewall ipv4 input filter rule 10 inbound-interface interface-name 'eth1'
set firewall ipv4 input filter rule 10 protocol 'tcp'
set firewall ipv4 input filter rule 10 synproxy tcp mss '1460'
set firewall ipv4 input filter rule 10 synproxy tcp window-scale '7'
</content>
</entry>
<entry>
<title>conntrack: T5217: Add tcp flag matching to `system conntrack ignore`</title>
<updated>2023-09-18T18:26:51+00:00</updated>
<author>
<name>sarthurdev</name>
<email>965089+sarthurdev@users.noreply.github.com</email>
</author>
<published>2023-09-18T18:24:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-1x.git/commit/?id=fb3ef9af5e394aa25692003fb3c185bfedefe3cb'/>
<id>urn:sha1:fb3ef9af5e394aa25692003fb3c185bfedefe3cb</id>
<content type='text'>
- Moves MSS node out of `tcp-flags.xml.i` and into `tcp-mss.xml.i`
- Update smoketest to verify TCP flag matching
</content>
</entry>
</feed>
