Project

General

Profile

Download (27 KB) Statistics
| Branch: | Tag: | Revision:

# Date Author Comment
637acd36 11/12/2005 06:35 PM Scott Ullrich
  • Turn of ACE. It doesn't work at all.
  • Killall racoon. IPSEC Tools racoon seems to work a bit diff
a636c6ba 11/05/2005 01:30 AM Scott Ullrich

Enable padlock support

a5a0c4c7 10/13/2005 09:31 PM Scott Ullrich

Move )

Pointy-hat-to: Me

89e910c6 10/13/2005 09:29 PM Scott Ullrich

Missing )

Pointy-hat-to: Me

cefde762 10/13/2005 08:50 PM Scott Ullrich

Forced commit to note that failover ipsec should be enabled as well (even if your not using failover, it simply sets the racoon listen ip address)

ab80b66f 10/13/2005 08:49 PM Scott Ullrich

Add NATT support. Currently this option is disabled. To enable simply set the <developer/> tag inside <system> in config.xml

816f2e58 09/23/2005 10:05 PM Scott Ullrich

Use correct mtu for pptp when wan is pppoe.

Have I mentioned how much I HATE pptp lately?

93f2d54e 08/31/2005 11:45 PM Scott Ullrich

Set /sbin/sysctl net.inet.ipsec.crypto_support=1 if Padlock

13beee7d 08/31/2005 11:34 PM Scott Ullrich

Detect ACE in CPU line

e6f48f2e 08/31/2005 11:13 PM Scott Ullrich

Do not set net.inet.ipsec.crypto_support

913b18e4 08/14/2005 09:22 PM Scott Ullrich

Only run padlock functions if <developer> bit is set

b7d4a627 08/14/2005 08:13 PM Scott Ullrich

Query Features line for ACE

c9c1bb3b 08/13/2005 10:10 PM Scott Ullrich

Echo out when enabling padlock

48f9d64f 08/13/2005 10:08 PM Scott Ullrich

Clear out setkey after enabling as instructions show.

65fdf7af 08/13/2005 07:14 PM Scott Ullrich

Only enable Padlock if we find ACE in the dmesg

2631018f 08/13/2005 04:39 PM Bill Marquette

Spello in comments

a15b7fdb 08/13/2005 12:32 PM Scott Ullrich

Enable hardware IPSEC

b454f16e 08/12/2005 07:35 PM Scott Ullrich

Padlock -> ACE

5b33809e 08/12/2005 06:23 PM Scott Ullrich

Minor style cleanups

1a5eeb97 08/12/2005 06:18 PM Scott Ullrich

Only setup via padlock on bootup.

b26cc217 08/12/2005 05:20 PM Scott Ullrich

Alert on bootup if we are enabling padlock

8c5096aa 08/12/2005 04:55 PM Scott Ullrich

Add via padlock support

8ee9b271 08/12/2005 03:09 PM Scott Ullrich

Check to see if item is dynamic dns a little better

5aad0d39 08/11/2005 06:53 PM Scott Ullrich

Detect DNS names and correctly set

0b03c149 08/06/2005 07:51 PM Scott Ullrich

dir_exist() -> dir_exists()

a429d105 08/06/2005 07:14 PM Scott Ullrich

Allow PPPoE server subnet to be defined by user.

Ticket #282

48918ed5 08/06/2005 06:53 PM Scott Ullrich

Make sure /var/etc/mpd-vpn exists

bc090ffc 08/01/2005 12:55 AM Scott Ullrich

Set pppoe interface

8b3500fe 07/31/2005 09:48 PM Scott Ullrich

Use unique variable name for interface

0ad64be0 07/31/2005 09:42 PM Scott Ullrich

Do not accept encryption

15fffebf 07/31/2005 09:40 PM Scott Ullrich

Kill sasyncd before restarting

2991a0d6 07/31/2005 09:37 PM Scott Ullrich

Assign a unique pppoe id

3775a3a4 07/31/2005 09:35 PM Scott Ullrich

Set mtu to 1492

0301deff 07/31/2005 09:34 PM Scott Ullrich

Translate interface

985db425 07/31/2005 09:20 PM Scott Ullrich

Do not set 10.* dns address

83773ab0 07/31/2005 09:20 PM Scott Ullrich

Add PPPoE server interface field

69a779d5 07/31/2005 03:27 PM Scott Ullrich

Load pppoe, not pt.

bb75cfdf 07/30/2005 10:11 PM Scott Ullrich

i -> $i

878f2719 07/30/2005 09:52 PM Scott Ullrich

vpn_pptp_configure() -> vpn_pptpd_configure()

06e69b03 07/30/2005 08:37 PM Scott Ullrich

Add PPPoE server hooks

fd5f1066 07/28/2005 08:48 PM Scott Ullrich

Do not spew sasyncd output to web browser.

b7e7d60e 07/28/2005 08:23 PM Scott Ullrich

Reload the filter even on bootup

10d470b9 07/25/2005 05:00 PM Scott Ullrich

WINS Server option

Ticket #255

41c649df 07/16/2005 06:31 PM Scott Ullrich

Add Dynamic DNS support to IPSEC.

fa40522b 07/14/2005 01:00 AM Scott Ullrich

Touch the /tmp/filter_dirty file and allow the filter to be reloaded on final bootup.

b5facc06 07/12/2005 11:26 PM Scott Ullrich

Ping 10 times to bring up tunnel

7616c107 07/12/2005 11:16 PM Scott Ullrich

Start sasyncd in the backgrounds

a63f7d55 07/12/2005 10:52 PM Scott Ullrich

Resync with prior working vpn.inc and add back in failover ipsec and cert support.

68c52178 07/11/2005 12:18 AM Scott Ullrich

Ping 10 times when bringing tunnel up

5dd24b70 07/10/2005 09:42 PM Scott Ullrich

Use logger to ensure we are getting sasyncd logs

42f2bcc9 07/10/2005 09:38 PM Scott Ullrich

Add more -v

1ac39951 07/10/2005 09:37 PM Scott Ullrich

Start sasyncd verbose

7dd31990 07/08/2005 01:10 AM Scott Ullrich

Reload filter configuration after vpn changes

5c119752 07/08/2005 12:59 AM Scott Ullrich

Setup sasyncd

8f67a8e1 07/08/2005 12:51 AM Scott Ullrich
  • Back out the M0n0wall certificate import. Somehow it broke ipsec.
  • Merge back in Failover VPN. It REALLY works now ;)
dcca036d 07/07/2005 07:17 PM Scott Ullrich

Do not assign variables if $config['installedpackages']['sasyncd']['config'] is not defined

669e1adb 07/04/2005 09:00 PM Bill Marquette

Various code cleanups and a few actual bugfixes courtesy of Zend

d8bde4c5 07/04/2005 04:22 PM Bill Marquette

Clean up foreach() warnings if you don't use sasyncd

649283ef 07/04/2005 03:20 AM Scott Ullrich

Correctly setup sasyncd and vpn failover

62aee443 07/04/2005 03:07 AM Scott Ullrich

Correctly set failover ip address

9824155a 07/04/2005 02:44 AM Scott Ullrich

only echo out when we're booting

b2db51ea 07/04/2005 12:03 AM Scott Ullrich

Use packages bindto area

e239df5a 07/03/2005 10:37 PM Scott Ullrich

Do not call filer_configure() if booting. set /tmp/filter_boot_dirty flag.

94fa3838 07/03/2005 10:37 PM Scott Ullrich

Do not call filer_configure() if booting. set /tmp/filter_boot_dirty flag.

9cbec820 07/03/2005 10:00 PM Scott Ullrich

Do not clear out previous string.

fa564d21 07/03/2005 09:26 PM Scott Ullrich

Remove extra white space

9816035f 07/03/2005 09:21 PM Scott Ullrich

Remove extra white space

e1a74484 07/03/2005 09:15 PM Scott Ullrich

Add mode, listen on and flush mode sync directives for sasyncd

600dd4e0 07/03/2005 09:12 PM Scott Ullrich

Add failover vpn backend support.

17da6c79 07/03/2005 07:13 PM Scott Ullrich Import back in pfSense modifications:
  • Failover IPSEC support ['ipsec']['ip']
  • creategfif support for multi subnet routing
bd9548e0 07/03/2005 07:08 PM Scott Ullrich

Import m0n0wall's backend vpn.inc which has certificate support.

4e2a17d0 06/14/2005 06:46 PM Scott Ullrich

Allow maximum PPTP clients to be overridden by:
pptp->n_pptp_units
pptp->n_pptp_units

5c6d0f65 05/18/2005 01:03 AM Colin Smith
  • Minor cleanup, almost entirely of bootup messages.
b146f6a2 04/26/2005 10:10 PM Scott Ullrich

Do not foreach through $ipseccfg['tunnel'] if its not defined

5ed67aad 03/31/2005 12:46 AM Scott Ullrich

Override correct wan ip address for vpn failover.

0f21fffd 03/31/2005 12:40 AM Scott Ullrich

extra }

3c105468 03/31/2005 12:27 AM Scott Ullrich

Allow ipsec->ip override for listen interface and spd.conf

307cd525 03/27/2005 10:43 PM Bill Marquette

Add $Id$ tag

a1049857 03/17/2005 05:48 AM Bill Marquette

use better mkdir function

b73cc056 03/03/2005 02:15 AM Scott Ullrich

Allow setting of racoon listening interface on the ipsec vpn screen. This allows failover vpn!

80f09203 01/25/2005 12:36 AM Scott Ullrich

Redirect sysctl output to /dev/null

3ea688d0 01/25/2005 12:35 AM Scott Ullrich

Supply full path to sysctl

0e535e84 01/11/2005 04:18 AM Scott Ullrich

sysctl -> system

4cbcdf91 01/11/2005 12:49 AM Scott Ullrich

fastforwarding is not compatible with ipsec tunnels -- turn it off if the user has ipsec tunnels.

cfc707f7 11/19/2004 11:12 PM Scott Ullrich

Add Copyright to each file that we have touched so far and re attribute the file to Manuel Kasper such as:

Copyright (C) 2004 Scott Ullrich
All rights reserved.
originally part of m0n0wall (http://m0n0.ch/wall)
Copyright (C) 2003-2004 Manuel Kasper &lt;&gt;....
1b2808f1 11/19/2004 11:05 PM Scott Ullrich

bug fix: Honour newer sa setting

dacc4f59 11/19/2004 09:24 PM Scott Ullrich

add support for net.key.preferred_oldsa and add a checkbox on IPSec screen

d41f17ce 11/19/2004 09:10 PM Scott Ullrich

add support for net.key.preferred_oldsa

dc3a01e4 11/14/2004 08:30 PM Scott Ullrich

take out the previous echo $ifface since that was a debugging item.

f6f1d6f7 11/11/2004 12:34 AM Scott Ullrich

allow user to set a hidden ipsec field called "creategif" which will create gif entries which are useful for routing.

5b237745 11/07/2004 03:06 AM Scott Ullrich

Initial revision