Project

General

Profile

Download (16.8 KB) Statistics
| Branch: | Tag: | Revision:

# Date Author Comment
102b0715 12/23/2008 10:28 AM Seth Mos

Update config.xml to 5.5 to prevent RRD database conversion from triggering.
add rrd tag to default enabled

beb9061f 11/30/2008 12:01 AM Chris Buechler

change default to enable block bogons

e858896b 11/04/2008 04:33 AM Scott Ullrich

Add TCP TSO = 0 sysctl

138acd28 10/25/2008 09:02 PM Scott Ullrich

Change default icmplim to 750.

1a0cb96d 09/10/2008 11:29 PM Scott Ullrich

Revise default allow all to any rule text. Remove > and attempt to cleanup
text to make it more friendly to a new user.

bfea87ff 09/03/2008 05:52 PM Matthew Grooms

Remove the page locking privileges after discussion with Scott on IRC. The
feature was confusing and offered little utility that I could see. If we
really need to provide serialized access to sections of the webui, IMO it
should be a global lock option and enabled or disabled manually and not a...

e9e7d501 09/02/2008 04:46 PM Matthew Grooms

Modify all the default configuration files to ensure the versions match.
While in globals.inc, remove the easyrsa path and do some whitespace
cleanup.

3828b68a 09/01/2008 07:38 PM Scott Ullrich

Set net.inet.icmp.icmplim to 500. Apparently the low setting of 200
wrecked Seths firewall on upgrade due to overwhelming amounts of icmp
packets.

43ac3acf 08/30/2008 02:35 AM Scott Ullrich

Move WAN interface to appear first now that the interface code
programatically enumerates the interfaces. Not sure if we need
upgrade code to move the interface order.

b51eff52 08/11/2008 06:00 PM Scott Ullrich

Disable extended TCP debugging.

6235e683 08/05/2008 04:11 PM Ermal Luçi

Sync to new config version number.

787295ea 08/05/2008 04:03 PM Ermal Luçi

Epose if_bridge(4) sysctl members.

6b07c15a 08/01/2008 06:30 AM Matthew Grooms

Rewrite the pfsense privilege system with the following goals in mind ...

1) Redefine page privileges to not use static urls
2) Accurate generation of privilege definitions from source
3) Merging the user and group privileges into a single set
4) Allow any privilege to be added to users or groups w/ inheritance...

a8b1097c 07/30/2008 11:31 PM Scott Ullrich
  • Switch XML tag from </pages> to <pages/>
  • Sync the all group which appears to be missing
a82db41d 07/28/2008 10:40 PM Scott Ullrich

latest config.xml version is 4.9

ee7ff1f0 07/19/2008 02:16 AM Scott Ullrich

Add TCP Inflight

9deef53d 03/10/2008 01:27 AM Scott Ullrich

Remove unused tag.

e0ac2576 03/10/2008 12:52 AM Scott Ullrich

Unbreak package manager

8da7252b 02/20/2008 01:11 AM Scott Ullrich

Add missing bits from HEAD.

2821f8e6 02/18/2008 06:07 PM Scott Ullrich

Switch over to the newly provisioned 0.pfsense.pool.ntp.org which
ntp.org has graciously setup for pfSense.

d2f33646 02/02/2008 07:37 PM Scott Ullrich

Really disable CTRL+ALT+DELETE.

ae1ffb16 02/02/2008 07:36 PM Scott Ullrich

Disable CTRL+ALT+DELETE reboot sequence on keyboard.

Admnins commonly have to press this sequence to login to winderz boxen and
if you have a shared KVM you might accidently reboot your firewall.

49ff6e40 02/01/2008 10:56 PM Ermal Luçi

Revert previous patch to retain compatibility in the GUI.

2a2f3167 02/01/2008 09:59 PM Ermal Luçi

Add defualt pass rule on lan interface and remove it from config.
It is a default policy so lets keep it with defaults and let the user override it when pleases.

Remove it from here since it is part of the default policy and allow that on a new installation,...

2672d65d 11/28/2007 07:51 PM Scott Ullrich

Move update bogons script to 3am.

Discussed on pfSense-support@

d35fa17e 11/27/2007 08:22 PM Scott Ullrich
  • Download bogons entries from pfsense.com
  • Do not update on every minute on the 1st of the month
  • Sleep for a random period before updating to avoid killing the server
94f01c71 08/22/2007 06:01 PM Scott Ullrich

Increase net.inet.ip.intr_queue_maxlen to 1000 which is the IP input queue.

0ca9fb60 08/02/2007 02:14 AM Scott Ullrich

Reset slbd every 140 minutes as opposed to 300 minutes.

df23ccfe 07/05/2007 04:13 PM Scott Ullrich

Set the ephemeral port range starting port to 1024 instead of 49152.

On a busy firewall it is possible to run out of ephemeral ports and then the system will block new connections until a port is available.

53747d8e 06/27/2007 07:43 PM Scott Ullrich

s/bin/sbin/

b1d7bc01 06/27/2007 07:37 PM Scott Ullrich

Reset SLBD every 5 hours to avoid 100% cpu utilization

Ticket #1316

f3f5b5d6 06/02/2007 09:32 PM Scott Ullrich

We need to expire entries every hour, not every half hour. (snort)

9299ceaf 05/26/2007 10:34 PM Scott Ullrich

Add overlooked sysctl's.

6df9d7e3 05/26/2007 10:00 PM Scott Ullrich

Add system tunables area which allows the user to fine control sysctl's.

7995441e 05/15/2007 08:29 PM Scott Ullrich

Oops, we need /etc/ping_hosts.sh to run every 5 minutes.

ad171999 05/08/2007 02:47 PM Seth Mos

Add NTP server field to dhcp config.
From: Alexander Schaber

cff4feea 03/14/2007 10:06 PM Scott Ullrich

We actually have 2.9 has the default now.

fd416a10 02/09/2007 04:54 PM Scott Ullrich
  • Bump config version to 2.8
  • Automatically install a IPSEC pass rule for unsuspecting users
1071e028 01/29/2007 04:09 AM Scott Ullrich

Backport cron handling from HEAD.

Patches-submitted-by: DSH@

7c59d0c1 01/18/2007 11:45 PM Scott Ullrich

Change default theme to nervecenter.

No objections from any of the 13 other people in IRC. Make it so.

e15a4793 03/09/2006 08:44 PM Scott Ullrich

Disable NAT reflection by default.

478743e1 01/01/2006 03:53 AM Scott Ullrich

Set theme back to metallic and avoid the lynching

7185e415 12/28/2005 12:55 AM Scott Ullrich

Change default theme back to pfsense.

Some people claim the fancy metallic theme is slower.

See http://forums.whirlpool.net.au/forum-replies-archive.cfm/436523.html

e265e49f 11/17/2005 09:52 PM Scott Ullrich

Change back to sis0 and sis1 for embedded. CDROM platform and other will pull in conf.defaults which is set for VMWARE if need be.

644d1f1c 11/16/2005 01:27 AM Scott Ullrich

Change the default interface setup in PC version to vmware.

86309628 11/13/2005 07:39 PM Scott Ullrich

Do not enable SSHD by default.

Ticket #682

543dcec8 11/07/2005 12:04 AM Scott Ullrich

Disable FTP proxy helper on WAN by default

6823bfb6 08/21/2005 12:17 AM Scott Ullrich

1.10 -> 2.0

6394e649 08/06/2005 09:56 PM Scott Ullrich

Bump config version to 1.9

36aaefff 07/31/2005 01:15 AM Scott Ullrich

Allow SSH service to be disabled / enabled.

0e279b95 07/29/2005 10:36 PM Scott Ullrich

Turn off raw filter for new installs

e42cac89 07/18/2005 02:24 AM Scott Ullrich

3 out of 4 kids agree, metallic is a better theme!

c0ce312f 06/27/2005 04:22 PM Scott Ullrich

Enable ipsec passthrough by default

34caec13 05/26/2005 03:14 PM Scott Ullrich

Turn on prefer older sa's by default

82990721 02/20/2005 08:32 PM Scott Ullrich

Default to "raw" logging until the loging parsing items are updated.

adfaae0e 01/24/2005 10:37 PM Scott Ullrich

Switch default optimization method to normal. For some reason "default" does not work even though "Building firewalls with OpenBSD and PF" claims it does.

416ed28d 01/23/2005 12:52 AM Scott Ullrich

Allow for the user to customize the pf optimization options in the system -> advanced menu. the default is normal.

12bcdc89 01/22/2005 02:57 AM Scott Ullrich

Commit what I have so far. Magic shaper now works 100% .. or atleast appears to!

44ce4df1 01/21/2005 11:31 PM Scott Ullrich

switch xml format over to pfsense header and footer. time to break away from m0n0walls configuration since ours is a little different now.

1220d12a 01/21/2005 10:13 PM Scott Ullrich

Move schedulertype configuration setting to system since we have switched to one scheduler per system.

1cd16057 01/12/2005 02:11 AM Scott Ullrich

Change default password to pfsense

41cefed7 01/05/2005 09:54 PM Scott Ullrich

Change ntp interval to 300 in alternate config file

b16a29f0 01/04/2005 08:47 PM Scott Ullrich

Change time update interval to 400.

Requested-by: B.Kharazmi

f213b40e 12/16/2004 06:57 PM Scott Ullrich

revert back to m0n0wall header and footer for xml config files. this will keep us partly compatible with m0n0wall -> pfSense upgraders

ee11cc6e 12/12/2004 01:44 AM Scott Ullrich

Say welcome to the pfSense package manager!

42d88fb2 11/21/2004 06:44 AM Scott Ullrich

change default scheduler type to hfsc

f56d2af1 11/07/2004 03:23 AM Scott Ullrich

change hostname to pfSense

5b237745 11/07/2004 03:06 AM Scott Ullrich

Initial revision