Project

General

Profile

Activity

From 09/19/2012 to 10/18/2012

10/18/2012

09:04 AM Revision 2ed21904: Check if there is any configuration present before going through it.
Ermal LUÇI
09:03 AM Revision d96b96b9: Check if there is any configuration present before going through it.
Ermal LUÇI
08:53 AM Revision 95799b92: Switch to background launching
Seth Mos

10/16/2012

04:56 PM Revision 1d949f50: Add a few required things here to allow the script to work
Jim Pingle
02:58 PM Revision 399e4b3f: Fix spelling
Warren Baker
12:22 PM Revision 9e2822df: Fix syntax error
Jim Pingle

10/15/2012

09:51 PM Revision 6eb97c2e: Merge pull request #239 from phil-davis/master
Limiter addBwRowTo plus icon syntax Ermal LUÇI
12:41 PM Revision e7ccf2a5: Ooops fix removed line by accident
Ermal LUÇI

10/12/2012

10:47 AM Revision a1dd913e: Limiter addBwRowTo plus icon syntax
Fix the syntax so that the GUI Limiter, Creat new limiter, Bandwidth "+" icon as the correct title text, and the Mask... Phil Davis
10:20 AM Revision 65101877: Merge changes required for using the ISC dhclient in pfSense with prefix delegation. This should hopefully be a bit more reliable in the long run.
The dhclient6-script could be merged with dhclient-script in the future.
Still need to cleanup old adresses and prefi...
Seth Mos

10/11/2012

10:32 PM Revision b00dc866: Fix typo
Erik Fonnesbeck
03:24 PM Revision e8d517b4: Use only binat so both side can communicate properly. With nat only the side behind nat works
Ermal LUÇI
01:31 PM Revision 64846e1a: Merge pull request #238 from phil-davis/master
Handle case with no server or no client OpenVPN Jim Pingle
01:11 PM Revision b95f5460: Handle case with no server or no client OpenVPN
If there are OpenVPN servers but not clients, this warning is emitted:
Warning: Invalid argument supplied for foreach...
Phil Davis

10/10/2012

07:37 PM Revision d0da2c8c: Tune check so nat rules for single host ips get added
Ermal LUÇI

10/09/2012

07:17 PM Revision 3a343d73: Refine saving/applying on more pages - don't show apply or take an action unless the user is allowed to do that.
Jim Pingle
05:44 PM Revision c9ba2f8a: Make limiters have a schedule specified which applie bandwidth limits during that period
Ermal LUÇI
02:53 PM Revision 5ff00e73: Make sure admin can always write the config
Jim Pingle
02:44 PM Revision bec92ab9: Don't offer to apply changes if no changes actually happened.
Jim Pingle
02:40 PM Revision 170cb2bc: Add initial support for a privilege that denies write access to the config.
NOTE: This only prevents writing to config.xml - it does NOT prevent other changes/execution that do not involve writ... Jim Pingle

10/06/2012

09:36 PM Revision 6f3d3a07: Allow editing an imported CRL, and refresh OpenVPN CRLs when saving. Implements #2652
Jim Pingle

10/05/2012

08:39 PM Revision f9f6f7d4: Fix reference to gateway in pool config
Jim Pingle
07:41 PM Revision f3c338b3: This should fix ipsec status for natted tunnel(s).
Ermal LUÇI
07:08 PM Revision 909890c4: Correct the config generation
Ermal LUÇI
07:05 PM Revision a0c4a6ce: config.xml might have some elusive data so do not fail sainfo section for localside if there is an empty nat address. Just do not put the nat side in there
Ermal LUÇI
07:00 PM Revision 72dd4f07: Check against _address since that is the field inputed _type is always there.
Ermal LUÇI
06:17 PM Revision 9a5a078a: Properly set address type selection
Ermal LUÇI
06:15 PM Revision 6e97e102: Correct check since it might be an ip as well
Ermal LUÇI
06:12 PM Revision db535a1c: Correctly build the sainfo to avoid errors
Ermal LUÇI
06:07 PM Revision 67bcb765: Be more strict on validation during filter reload
Ermal LUÇI
06:04 PM Revision 261e72f0: Do not make natlocalid required
Ermal LUÇI
05:44 PM Revision 64eda26c: Fixup easyrule block for IPv6
Jim Pingle
04:58 PM Revision 023f744b: Use .= for strings rather than +=
Jim Pingle
04:30 PM Revision db277413: Don't write a rule out of the natlocal_subnet is blank.
Jim Pingle
04:21 PM Revision 2ecf5b34: This field isn't required, so only check it if there is a value
Jim Pingle
03:31 PM Revision 97f7a517: Safety belt
Jim Pingle
02:29 PM Revision 902052bc: show true/false in logged message instead of 1/<nothing>
Bill Marquette

10/04/2012

08:55 PM Revision 050fd8ad: Rather use the system constants as defined
Ermal LUÇI
08:51 PM Revision e4d7130d: Use integer rather than hex to put these values. AMD64 builds do rather awkward problems
Ermal LUÇI
06:37 PM Revision 3c107b76: Add a NAT entry for configuring NAT on ipsec phase2. It will add nat rules on enc interface
Ermal LUÇI
02:29 PM Revision 6f663992: Eliminate system calls here, use PHP instead.
Jim Pingle
02:28 PM Revision 80ff6bfe: Eliminate system calls here, use PHP instead.
Jim Pingle
01:24 PM Revision f5acd065: Sanitize some variables
Discovered-By: Yann CAM Jim Pingle
01:14 PM Revision 33ba4131: Sanitize some variables
Discovered-By: Yann CAM Jim Pingle
12:55 PM Revision fa9f5ff9: Verify posted kernel type against a defined list of good values.
Discovered-By: Yann CAM Jim Pingle
12:55 PM Revision 73b9d3c6: Verify posted kernel type against a defined list of good values.
Discovered-By: Yann CAM Jim Pingle
12:20 PM Revision d729dbeb: Fix reference to limitrules
Jim Pingle

10/03/2012

05:17 PM Revision 7b27db03: Add restrict lines to limit what local clients are allowed to do to the ntp server.
Jim Pingle
05:17 PM Revision 6162b068: Only attempt to unset this if it has been set.
Jim Pingle

10/02/2012

10:08 PM Revision 7f835f3c: Merge pull request #235 from PiBa-NL/master
openvpn-widget layout drawing fix Jim Pingle
07:20 PM Revision e18343fb: another openvpn-widget layout drawing fix, sorry.
Pi Ba
01:25 PM Revision a9f0df69: Make sure that the limits are included in the normal ruleset, otherwise pf will use the defaults.
Seth Mos
01:25 PM Revision fdcc1b82: Don't die silently if the time is too far off. Fix from: dhatz
Jim Pingle

10/01/2012

03:04 PM Revision 6646c0f9: Merge pull request #233 from bcyrill/rfc3168_flags
Add ECE and CWR TCP flags as defined in RFC 3168 Jim Pingle
02:59 PM Revision b4147482: Fixup processing of IPv6 IPs for EasyRule. Fixes #2649
Jim Pingle
02:20 PM Revision 51271f74: Merge pull request #234 from PiBa-NL/master
OpenVPN allow changing TUN/TAP, firewall-log filter on interface. carp show vip desciption in notification Jim Pingle
01:46 PM Revision f062f033: firewall log, show cell border when using 'column descriptions'
Pi Ba
12:48 PM Revision dcbafe17: Fix typo
Cyrill B
12:45 PM Revision da601f8e: Allow for changing OpenVPN TUN to TAP device mode without reboot.
Pi Ba
12:44 PM Revision 79cc9e6b: Add ECE and CWR TCP flags as defined in RFC 3168
Cyrill B
12:38 PM Revision d8cdfd3e: Merge branch 'master' of git://github.com/bsdperimeter/pfsense
Pi Ba
12:36 PM Revision 90763c7f: Firewall log, allow filtering by interface.
Pi Ba
06:40 AM Revision 19d61d27: Add UA support for BB PlayBook - patch by Pho Bia. Fixes #2648
Warren Baker

09/30/2012

03:11 PM Revision 193a8e1f: Revert "Allow for changing OpenVPN TUN to TAP device mode without reboot." -- Adds blank OpenVPN servers, see ticket #2643
This reverts commit c8bb7f1527a99c69784ab6c01d9050adcde6a8a0. Jim Pingle

09/29/2012

05:39 PM Revision e3449857: CARP notifications show vip description, 'Virtual IP Addresses' page shows interface.
Pi Ba

09/27/2012

04:55 PM Revision 680d543d: Add forgotten part of the IPsec split dns fix from yesterday
Jim Pingle
01:18 PM Revision 7a058f06: Add option to disable the dashboard auto-update check
Jim Pingle
04:43 AM Revision 96f7a687: Some more state killing refinements.
Jim Pingle

09/26/2012

07:41 PM Revision d7402222: Add option to separately specify the split dns domain list for IPsec mobile clients.
Jim Pingle
05:32 PM Revision 3b15c32c: Refine LB entry deletion to make sure blank entries can be removed.
Jim Pingle
05:20 PM Revision 6e9b046e: Due to the DHCP pool tag needing to be an array, rename the old LB "pool" variable to something else so it's not interpreted as an array.
Jim Pingle
01:43 PM Revision fd3515f2: Separate default gateway switching code to its own function, fix it to only operate on one address family at a time. Old method wouldn't re-set inet gateway if there was an inet6 default.
Jim Pingle
12:48 PM Revision 766cd450: Try a little harder to clear the states for the old PPP gateway
Jim Pingle
12:47 PM Revision 80c043fa: Remove states before removing the old address, or the file will be gone and the code to kill the states won't ever run.
Jim Pingle

09/25/2012

08:54 PM Revision 1be1a67a: while booting do not let carp wait for pfsync synchronization if pfsync is not enabled
Pi Ba
03:50 PM Revision 767cf960: Refine OpenVPN client/server deletion to allow for removing invalid empty entries. Fixes #2643
Jim Pingle
12:18 PM Revision f00278f1: Ticket #2635: during ipsec reload, do not generate spd for disabled ph1
Pierre POMES

09/24/2012

07:55 PM Revision 687dbc35: Merge pull request #232 from bcyrill/patch-2
Make tables sortable Jim Pingle
07:38 PM Revision 5b42a459: Make tables sortable
Cyrill B
06:50 PM Revision 4f98a4a0: Merge pull request #231 from bcyrill/patch-1
Update etc/inc/priv.defs.inc Jim Pingle
06:48 PM Revision 14551ae0: Update etc/inc/priv.defs.inc
Include privileges for Diagnostics Sockets page Cyrill B
04:51 PM Revision 4087a5f5: Merge pull request #230 from phil-davis/master
Separate backend keywords from GUI language display in captive portal Jim Pingle
04:11 PM Revision eafb21b3: Separate backend keywords from GUI language display in captive portal
When the GUI language was set to Portuguese, keywords like "default" and "unformatted" would be translated into Portu... Phil Davis
12:18 AM Revision 489a6e7f: Merge pull request #228 from PiBa-NL/master
fix few issues in virtual IP edit page Jim Pingle
12:05 AM Revision 26a5f8c8: fix warning message for CARP /32 /128 masks added /31 /127 as these are also not applicable for carp which needs at least 3 IP's to function.
Pi Ba

09/23/2012

11:21 PM Revision 362c9bb0: Don't die silently if the time is too far off. Fix from: dhatz
Jim Pingle
11:05 PM Revision 9e0f8e23: fix for breaking editing carp edit selection setting.
Pi Ba
08:55 PM Revision f665130d: Merge pull request #227 from PiBa-NL/master
Diagnose\Sockets page improvements. Jim Pingle
07:52 PM Revision c75fd3db: Diagnose\Sockets page renamed and now also has button to show all socket connections, explanation moved to bottom.
Pi Ba
01:46 AM Revision 5dc66dff: Merge pull request #225 from PiBa-NL/master
Virtual IP Edit consistent options, "Sockets listening" page, openVPN allow change mode Jim Pingle

09/22/2012

10:44 PM Revision d41bb447: Add a "Sockets listening" page to the Diagnostics menu.
This for easy viewing of what services are bound to which interface and port.
( based on the file diag_sockets.php fr...
Pi Ba
09:26 PM Revision b1aa3804: changed "Firewall: Virtual IP Address: Edit" page to always have the same options available (if applicable) for IPalias/CARP/ProxyArp/other
Pi Ba
09:23 PM Revision c8bb7f15: Allow for changing OpenVPN TUN to TAP device mode without reboot.
Pi Ba

09/19/2012

12:19 PM Revision ea68f6cc: We should also resync openvpn clients since they can use gateway groups too.
Jim Pingle
12:17 AM Revision 7e3891ff: don't log here, users can define their own logging rules if they want logging
Chris Buechler
 

Also available in: Atom