Project

General

Profile

Statistics
| Branch: | Tag: | Revision:

# Date Author Comment
f41b7bdf 11/21/2010 09:21 PM Scott Ullrich

Remove bce item it is loader.conf only per jimp

2b8bdfe4 11/20/2010 07:42 PM Scott Ullrich

Add missing </item>

24352196 11/20/2010 07:40 PM Scott Ullrich

oops, typo

feae85bc 11/20/2010 07:40 PM Scott Ullrich

Increase vfs.read_max to 32. See http://ivoras.sharanet.org/blog/tree/2010-11-19.ufs-read-ahead.html .. This can help dramatically if using Squid or any other packae that does a lot of hard disk reads.

9ff73b79 10/19/2010 04:51 PM Jim Pingle

Convert fullname field on users to descr, so it gains CDATA protection.

e988813d 10/19/2010 04:39 PM Jim Pingle

desc to descr in Load Balancer config, so they gain CDATA protection and standardize field names. Ticket #320.

15864861 10/19/2010 04:00 PM Jim Pingle

Change the description field on sysctl tunables to be 'descr' and not 'desc' so they will gain CDATA protection. Ticket #320

6ae9f9b7 09/02/2010 05:59 PM Ermal LUÇI

Upgrade code for pppoe.

c7206520 08/04/2010 03:04 PM Jim Pingle

Disable TSO and LRO in the default config.

c8bf8b29 08/03/2010 08:33 PM Jim Pingle

Remove these from the default config. They moved into other sections and do not need to exist by default.

bb890d38 07/27/2010 01:19 PM Jim Pingle

Fix variable name for consistency.

24ed5c3b 04/13/2010 06:30 PM Ermal LUÇI

Remove associated rule-id from default config they confuse rule edit page.

676b4a39 04/12/2010 10:24 PM Ermal LUÇI

Remove bandwidth tags from default config they are not used.

10e41b74 04/06/2010 07:24 AM Marcus Brown

Don't use "local" as a domain. It breaks DNS resolution for hosts running mDNS.

The "local" search domain signifies to local hosts that are running
mDNS (bonjour or avahi) that mDNS is to be used to look up local hosts
instead of doing a normal DNS query to the server listed in...

9c4d33a1 03/27/2010 02:05 AM Erik Fonnesbeck

Fix whitespace.

0beab3f4 03/27/2010 02:00 AM Erik Fonnesbeck

Enable WAN and LAN in the default configuration.

6a688547 03/27/2010 12:28 AM Ermal LUÇI

Make lan/wan behave as all other interfaces.

f41c9fd5 02/03/2010 03:19 PM Ermal Luçi

ping_hosts.sh is no more in /etc. Remove some unneeded lines.

9b16b834 01/26/2010 11:59 PM Ermal Luçi

Ticket #136.

Fix associated nat rules.
Now both the filter rules and the nat ones contain a associated-rule-id tag which helps link the items together.
The API to use for this is in itemid.inc.

All the issues should be solved now.

473d0ff0 12/12/2009 08:57 PM Pierre POMES

Add patch from lietu (Janne Enberg). Ticket #136

1) Multiple NAT rules can be assigned the same filter rule
-> Fixed, added assigned-nat-rule-id to filter rules to keep track of the assignment

2) when removing the link (i.e. switching to "pass" or "none", the linked rule isn't deleted (should it be? probably yes)...

d0b461f5 12/06/2009 05:48 AM Scott Ullrich

Add lookup table for sysctl tunable (sysctl.inc). Make config.xml values default to value 'default' Ticket #71

ea7f7a84 12/03/2009 10:38 PM Scott Ullrich

Minor formatting change

effb9797 12/03/2009 10:38 PM Scott Ullrich

Set default protocol to HTTPS. Somehow this commit did not make it last time

326d2b8a 12/02/2009 09:45 PM Scott Ullrich

Make the default HTTPS. Ticket #63

880637d2 11/21/2009 10:05 PM Scott Ullrich

Default to only system information and interfaces widgets. This reduces load time on RSPRO from 9+ seconds to 2.5

08b17c6d 11/02/2009 09:27 PM Scott Ullrich

Add default load balancing monitor types for ICMP, TCP, HTTP, HTTPS and SMTP from BillM

51043cd1 09/09/2009 05:42 PM Scott Ullrich

Revert "add crontab entries for snort auto block and snort update"

This reverts commit b0d639a5e7880ee55c671cbabdb01cd0f1ae1b38.

b0d639a5 09/09/2009 04:30 PM robert zelaya

add crontab entries for snort auto block and snort update

b9e28d57 08/14/2009 08:53 PM unknown

Added support for automatically managing firewall rules with NAT rules.

5d88641f 07/13/2009 02:03 PM Scott Ullrich

Turn off flowtables by default

03509a7d 07/12/2009 05:38 AM Scott Ullrich

Enable flow table support by default for new installations

a1e3c4eb 07/12/2009 04:58 AM Scott Ullrich

Add enable/disable option for flow table support... Remove configuration option.

b220cc48 06/26/2009 12:57 AM Holger Bauer

Make pfSense_ng the new default theme

688d49ff 06/11/2009 08:36 PM Scott Ullrich

Nuke snort2c

Requested-by: rob iscool

4ebd7177 06/10/2009 02:38 AM Scott Ullrich

Add L2 L3 Cache lookup by default.

- Import infrastructure for caching flows as a means of accelerating L3 and L2 lookups
as well as providing stateful load balancing when used with RADIX_MPATH.
- Currently compiled in to i386 and amd64 but disabled by default, it can be enabled at...
4b38cdb7 05/14/2009 01:59 AM Chris Buechler

default to vr0/vr1 rather than sis, since the defaults should be for ALIX, not WRAP.

1512337f 05/08/2009 07:48 PM Ermal Luçi

Remove reset_slbd.sh from cron.

3fd1b895 05/07/2009 06:21 PM Ermal Luçi

Catch up with the latest additions.

049a688e 03/16/2009 05:50 PM Ermal Luçi

Remove ftp-proxy/pftpx/ftpsesame references we handle all of this in kernel now.(yay!)

4b96b367 03/15/2009 06:18 AM mgrooms

Modify IPsec code to allow for transport mode. All existing configurations are
marked as tunnel for backwards compatibility. There are problems with the spd
read code which Will likely choke on transport entries. We can fix this later.

0092b3bd 03/15/2009 12:39 AM mgrooms

Modify captive portal to use centralized user management. The user manager has
been modified to include an account expiration option to support this service.

0b7fd3e9 03/12/2009 09:51 PM mgrooms

Correct the configuration file IPsec certificate upgrade process.

d9acea75 03/12/2009 01:40 AM Scott Ullrich

Use nice -n20 for common launched items

451d439e 12/23/2008 10:26 AM Seth Mos

Update config.xml to 5.5 to prevent RRD database updates from triggering.
add rrd tag to default enabled

beb9061f 11/30/2008 12:01 AM Chris Buechler

change default to enable block bogons

e858896b 11/04/2008 04:33 AM Scott Ullrich

Add TCP TSO = 0 sysctl

138acd28 10/25/2008 09:02 PM Scott Ullrich

Change default icmplim to 750.

1a0cb96d 09/10/2008 11:29 PM Scott Ullrich

Revise default allow all to any rule text. Remove > and attempt to cleanup
text to make it more friendly to a new user.

bfea87ff 09/03/2008 05:52 PM Matthew Grooms

Remove the page locking privileges after discussion with Scott on IRC. The
feature was confusing and offered little utility that I could see. If we
really need to provide serialized access to sections of the webui, IMO it
should be a global lock option and enabled or disabled manually and not a...

e9e7d501 09/02/2008 04:46 PM Matthew Grooms

Modify all the default configuration files to ensure the versions match.
While in globals.inc, remove the easyrsa path and do some whitespace
cleanup.

3828b68a 09/01/2008 07:38 PM Scott Ullrich

Set net.inet.icmp.icmplim to 500. Apparently the low setting of 200
wrecked Seths firewall on upgrade due to overwhelming amounts of icmp
packets.

43ac3acf 08/30/2008 02:35 AM Scott Ullrich

Move WAN interface to appear first now that the interface code
programatically enumerates the interfaces. Not sure if we need
upgrade code to move the interface order.

b51eff52 08/11/2008 06:00 PM Scott Ullrich

Disable extended TCP debugging.

787295ea 08/05/2008 04:03 PM Ermal Luçi

Epose if_bridge(4) sysctl members.

6b07c15a 08/01/2008 06:30 AM Matthew Grooms

Rewrite the pfsense privilege system with the following goals in mind ...

1) Redefine page privileges to not use static urls
2) Accurate generation of privilege definitions from source
3) Merging the user and group privileges into a single set
4) Allow any privilege to be added to users or groups w/ inheritance...

a8b1097c 07/30/2008 11:31 PM Scott Ullrich
  • Switch XML tag from </pages> to <pages/>
  • Sync the all group which appears to be missing
a82db41d 07/28/2008 10:40 PM Scott Ullrich

latest config.xml version is 4.9

45ee90ed 07/25/2008 02:28 AM Matthew Grooms

Rewrite portions of the user manager to ensure data is properly synced to
the system password and group databases. This is to provide better support
for centralized user management when local account administration is
preferred.

I also took this opportunity to do some housekeeping. A lot of funtions...

ee7ff1f0 07/19/2008 02:16 AM Scott Ullrich

Add TCP Inflight

0da56ac7 06/14/2008 05:31 PM Chris Buechler

re-enable the sending of ICMP redirects by default

9deef53d 03/10/2008 01:27 AM Scott Ullrich

Remove unused tag.

e0ac2576 03/10/2008 12:52 AM Scott Ullrich

Unbreak package manager

8da7252b 02/20/2008 01:11 AM Scott Ullrich

Add missing bits from HEAD.

2821f8e6 02/18/2008 06:07 PM Scott Ullrich

Switch over to the newly provisioned 0.pfsense.pool.ntp.org which
ntp.org has graciously setup for pfSense.

d2f33646 02/02/2008 07:37 PM Scott Ullrich

Really disable CTRL+ALT+DELETE.

ae1ffb16 02/02/2008 07:36 PM Scott Ullrich

Disable CTRL+ALT+DELETE reboot sequence on keyboard.

Admnins commonly have to press this sequence to login to winderz boxen and
if you have a shared KVM you might accidently reboot your firewall.

2672d65d 11/28/2007 07:51 PM Scott Ullrich

Move update bogons script to 3am.

Discussed on pfSense-support@

d35fa17e 11/27/2007 08:22 PM Scott Ullrich
  • Download bogons entries from pfsense.com
  • Do not update on every minute on the 1st of the month
  • Sleep for a random period before updating to avoid killing the server
94f01c71 08/22/2007 06:01 PM Scott Ullrich

Increase net.inet.ip.intr_queue_maxlen to 1000 which is the IP input queue.

0ca9fb60 08/02/2007 02:14 AM Scott Ullrich

Reset slbd every 140 minutes as opposed to 300 minutes.

df23ccfe 07/05/2007 04:13 PM Scott Ullrich

Set the ephemeral port range starting port to 1024 instead of 49152.

On a busy firewall it is possible to run out of ephemeral ports and then the system will block new connections until a port is available.

53747d8e 06/27/2007 07:43 PM Scott Ullrich

s/bin/sbin/

b1d7bc01 06/27/2007 07:37 PM Scott Ullrich

Reset SLBD every 5 hours to avoid 100% cpu utilization

Ticket #1316

f3f5b5d6 06/02/2007 09:32 PM Scott Ullrich

We need to expire entries every hour, not every half hour. (snort)

9299ceaf 05/26/2007 10:34 PM Scott Ullrich

Add overlooked sysctl's.

6df9d7e3 05/26/2007 10:00 PM Scott Ullrich

Add system tunables area which allows the user to fine control sysctl's.

7995441e 05/15/2007 08:29 PM Scott Ullrich

Oops, we need /etc/ping_hosts.sh to run every 5 minutes.

ad171999 05/08/2007 02:47 PM Seth Mos

Add NTP server field to dhcp config.
From: Alexander Schaber

cff4feea 03/14/2007 10:06 PM Scott Ullrich

We actually have 2.9 has the default now.

fd416a10 02/09/2007 04:54 PM Scott Ullrich
  • Bump config version to 2.8
  • Automatically install a IPSEC pass rule for unsuspecting users
1071e028 01/29/2007 04:09 AM Scott Ullrich

Backport cron handling from HEAD.

Patches-submitted-by: DSH@

7c59d0c1 01/18/2007 11:45 PM Scott Ullrich

Change default theme to nervecenter.

No objections from any of the 13 other people in IRC. Make it so.

e15a4793 03/09/2006 08:44 PM Scott Ullrich

Disable NAT reflection by default.

f2ce60ad 02/26/2006 09:45 PM Scott Ullrich

Change back to sis0 and sis1 factory defaults

478743e1 01/01/2006 03:53 AM Scott Ullrich

Set theme back to metallic and avoid the lynching

7185e415 12/28/2005 12:55 AM Scott Ullrich

Change default theme back to pfsense.

Some people claim the fancy metallic theme is slower.

See http://forums.whirlpool.net.au/forum-replies-archive.cfm/436523.html

58543d68 11/16/2005 01:53 AM Scott Ullrich

Change default interfaces to vmware (lnc0 lnc1) for PC version

86309628 11/13/2005 07:39 PM Scott Ullrich

Do not enable SSHD by default.

Ticket #682

543dcec8 11/07/2005 12:04 AM Scott Ullrich

Disable FTP proxy helper on WAN by default

a48aec0a 09/28/2005 03:04 AM Bill Marquette

Remove ability to change schedulertype - we're only supporting HFSC for
now - priq may come back in future, the return of CBQ is unlikely

6823bfb6 08/21/2005 12:17 AM Scott Ullrich

1.10 -> 2.0

6394e649 08/06/2005 09:56 PM Scott Ullrich

Bump config version to 1.9

36aaefff 07/31/2005 01:15 AM Scott Ullrich

Allow SSH service to be disabled / enabled.

0e279b95 07/29/2005 10:36 PM Scott Ullrich

Turn off raw filter for new installs

e42cac89 07/18/2005 02:24 AM Scott Ullrich

3 out of 4 kids agree, metallic is a better theme!

c0ce312f 06/27/2005 04:22 PM Scott Ullrich

Enable ipsec passthrough by default

34caec13 05/26/2005 03:14 PM Scott Ullrich

Turn on prefer older sa's by default

82990721 02/20/2005 08:32 PM Scott Ullrich

Default to "raw" logging until the loging parsing items are updated.

adfaae0e 01/24/2005 10:37 PM Scott Ullrich

Switch default optimization method to normal. For some reason "default" does not work even though "Building firewalls with OpenBSD and PF" claims it does.

416ed28d 01/23/2005 12:52 AM Scott Ullrich

Allow for the user to customize the pf optimization options in the system -> advanced menu. the default is normal.