Project

General

Profile

Download (51.4 KB) Statistics
| Branch: | Tag: | Revision:

# Date Author Comment
b1e4005f 07/18/2011 06:33 PM Vinicius Coque

removes variables concatenation on gettext strings

8b6313a4 07/12/2011 11:57 PM Jim Pingle

Merge remote-tracking branch 'upstream/master'

Conflicts:
etc/inc/easyrule.inc
etc/inc/filter.inc
etc/inc/interfaces.inc
etc/inc/services.inc
etc/inc/xmlrpc_client.inc
usr/local/www/fbegin.inc
usr/local/www/services_dhcp.php

156bf9b1 06/08/2011 06:13 PM Jim Pingle

Merge remote branch 'upstream/master'

d8012adb 06/07/2011 01:47 PM Vinicius Coque

Merge remote-tracking branch 'mainline/master' into inc

Conflicts:
etc/inc/voucher.inc
usr/local/www/fbegin.inc

4e192846 06/06/2011 06:12 PM Ermal LUÇI

Correct event calling during bootup for rc.newipsecdns and also convert the command executed during an ipsec even to go through check_reload_status which will prevent races on calling rc.newipsecdns. Which might lead to many filterdns processes.

534375b6 06/03/2011 07:34 PM Jim Pingle

Merge remote branch 'upstream/master'

Conflicts:
etc/inc/openvpn.inc

5cd9e96a 06/03/2011 01:50 PM Jim Pingle

Add a GUI selection for racoon's generate_policy directive since it may be useful in certain configurations, especially for mobile clients.

58005e52 06/01/2011 01:00 PM Jim Pingle

Merge remote branch 'upstream/master'

Conflicts:
conf.default/config.xml
etc/inc/filter.inc
etc/inc/globals.inc
etc/inc/pfsense-utils.inc
etc/inc/upgrade_config.inc
usr/local/www/interfaces.php

224ddbad 05/27/2011 08:24 AM Ermal LUÇI

Silence the route changing since it fills the logs with not needed info.

45d4b71e 05/23/2011 06:57 PM Vinicius Coque

Merge remote-tracking branch 'mainline/master' into inc

d21d6e20 05/23/2011 06:41 PM Vinicius Coque

Merge remote-tracking branch 'mainline/master' into inc

Conflicts:
etc/inc/interfaces.inc
etc/inc/upgrade_config.inc
etc/inc/vpn.inc

27d0722d 05/19/2011 12:50 PM Jim Pingle

Merge remote branch 'upstream/master'

a7af5ddc 05/17/2011 06:04 PM Jim Pingle

Don't put an empty PSK into the file, and try to avoid extra whitespace to be safe.

69be9601 05/13/2011 11:43 AM Seth Mos

Merge remote branch 'upstream/master'

Conflicts:
etc/inc/vslb.inc
etc/version

9c04a8c0 05/07/2011 02:51 AM Chris Buechler

passive should always be on for mobile clients per racoon man page

131f3a50 05/04/2011 05:58 PM Jim Pingle

Disable this log message, as it can be extremely spammy in the logs.

cfd2ca3c 05/04/2011 10:07 AM Seth Mos

Remove stray debugging lines in VPN

dcb846e3 05/03/2011 08:09 AM Seth Mos

Merge remote branch 'upstream/master'

Conflicts:
usr/local/www/status_rrd_graph_img.php

8c218e1d 05/02/2011 10:26 PM Ermal LUÇI

Give time to filterdns to exit gracefully and after that start a new process.

a51493d1 04/15/2011 04:38 PM Vinicius Coque

Merge remote-tracking branch 'mainline/master' into inc

Conflicts:
etc/inc/gwlb.inc

b1c305e7 04/15/2011 08:42 AM Seth Mos

Merge remote branch 'upstream/master'

c8cc0c1c 04/13/2011 07:52 AM Seth Mos

Add missing fields for l2tp to define dns and wins servers

af8f910e 04/12/2011 08:40 AM Seth Mos

Merge remote branch 'upstream/master'

127eb8e0 04/11/2011 08:58 PM Jim Pingle

Add a toggle under System > Advanced on the misc tab to enable/disable debug mode for racoon.

152ab4d0 03/25/2011 11:59 AM Vinicius Coque

Merge remote-tracking branch 'mainline/master' into inc

Conflicts:
etc/inc/interfaces.inc
etc/inc/priv.defs.inc
etc/inc/shaper.inc
etc/inc/system.inc

54bdff75 03/25/2011 11:49 AM Vinicius Coque

Merge remote-tracking branch 'mainline/master' into inc

Conflicts:
etc/inc/auth.inc
etc/inc/config.lib.inc
etc/inc/filter.inc
etc/inc/pfsense-utils.inc
etc/inc/pkg-utils.inc
etc/inc/priv.defs.inc
etc/inc/services.inc...

6f979763 03/16/2011 09:05 PM Scott Ullrich

Fix merge conflict

aff70640 03/16/2011 12:28 PM Seth Mos

Swap if statement, add fields into ipsecpinghosts file

80c1e99f 03/16/2011 12:18 PM Seth Mos

Correct ping hosts functionality for > 1 tunnel. Add v6 functionality

ac463c00 03/16/2011 11:16 AM Seth Mos

Fix the IPsec ping hosts file generation. This only worked for the last
tunnel

98790f61 03/15/2011 03:29 PM Seth Mos

Try to make IPv6 feature complete for IPv6 support. Looks like ipsec-tools was built without v6 support, make sure you have a newer build

fb17f629 03/14/2011 09:03 PM Seth Mos

Commit the backend function that writes out the racoon.conf

6c4f3b54 03/14/2011 08:40 PM Seth Mos

Make sure to note the limitations to gethostbyname, it does not work for Quad A records. Fix resolve_retry in the process, use that.

6b5e978b 03/07/2011 10:45 PM Ermal LUÇI

Use racoonctl now that ipsec-0.8 is back to reload the config.

d161b4d4 03/02/2011 09:14 AM Seth Mos

Always write out the filterdns-ipsec.hosts file, otherwise deleted tunnels will never get removed from the
filterdns-ipsec.hosts

829fa12e 03/02/2011 07:21 AM Seth Mos

Add a check that should prevent configuration of racoon with duplicate phase 1 IP entries.

71e91e50 02/21/2011 12:29 PM Seth Mos

Add more safeguards and IP address checks

621a459a 02/21/2011 11:47 AM Seth Mos

Do not resolve the hostname during boot, also make really sure we have a IP address here.

41393f1e 02/21/2011 11:30 AM Seth Mos

Prevent a empty remote gateway IP from ending up in the config

603b4346 02/21/2011 11:21 AM Seth Mos

Make sure to initialize the remote gateway IP variable so that it does not end up with a broken config

d0399410 02/11/2011 07:25 AM Seth Mos

Do not resolve the dyndns hostnames during boot. With many tunnels that have a hostname this can
cause huge boot issues if the DNS server is slow or not responding at all. By skipping those but
adding them to the DNS watchlist it should reload these later. This should allow the box to start...

5cda0e03 01/31/2011 07:11 PM Jim Pingle

Fix typo (swapped parameters)

01d473df 01/31/2011 06:20 PM Jim Pingle

Fix typo

44ab93a4 01/29/2011 12:40 AM Ermal LUÇI

Correct configuration file name.

9d3d8d00 01/28/2011 07:32 PM Vinicius Coque

Merge branch 'master' into inc

Conflicts:
etc/inc/captiveportal.inc
etc/inc/config.console.inc
etc/inc/config.lib.inc
etc/inc/easyrule.inc
etc/inc/filter.inc
etc/inc/ipsec.inc
etc/inc/pkg-utils.inc
etc/inc/shaper.inc...

f8c10a18 01/26/2011 09:12 PM Ermal LUÇI

Use filterdns instead of dnswatch which will be retired.

6ae19856 01/05/2011 08:43 PM Ermal LUÇI

Actually use sigkillbypid.

e7af9a80 01/05/2011 08:41 PM Ermal LUÇI

Send a HUP to racoon which is equivalent to the reload-config racoonctl command which seems to not work in 0.7.3 of ipsec-tools.

c3583058 12/28/2010 10:10 PM Ermal LUÇI

Add radius port and radius accounting port to config if supplied.

8f5c3d8d 12/28/2010 09:23 PM Pierre POMES

Ticket #1116: anonymous sainfo may be used only for single phase2 ipsec VPN's

c513c309 12/22/2010 10:32 PM Ermal LUÇI

Prevent other types of interface for being added to ng_ether(4). It might be the cause of panics reported here http://forum.pfsense.org/index.php/topic,31404.0.html

673e8095 12/22/2010 03:39 PM Scott Ullrich

nuke trailing carriage returns

67b057a9 12/17/2010 10:55 PM Ermal LUÇI

Do not attach ng_etther(4) to every system interface. Instead do a search if netgraph is needed on single/every interface during interface configuration. Also enable netgraph support for interface as needed when enabling pptp/l2tp/pppoe/... . This should prevent the netgraph queue to slow down network performance on fast links.

c92ccac7 12/14/2010 11:56 AM Vinicius Coque

Merge remote branch 'mainline/master' into inc

Conflicts:
etc/inc/auth.inc
etc/inc/config.lib.inc
etc/inc/filter.inc
etc/inc/gwlb.inc
etc/inc/interfaces.inc
etc/inc/pfsense-utils.inc
etc/inc/pkg-utils.inc...

20699f3f 12/10/2010 09:38 PM Jim Pingle

Some IPsec mobile changes to inch a little closer to working L2TP+IPsec. Ticket #475

8ab82dec 12/08/2010 06:04 PM Jim Pingle

Only print "sainfo anonymous" also for xauth-psk setups. See http://forum.pfsense.org/index.php/topic,29164.msg157864.html#msg157864

6706a83a 12/06/2010 06:16 PM Ermal LUÇI

Do the setting earlier to not miss any code and make ipsec not work.

39a8090a 11/16/2010 11:31 AM Renato Botelho

Merge remote branch 'mainline/master' into inc

Conflicts:
etc/inc/PEAR.inc
etc/inc/filter.inc

9734b054 11/10/2010 05:00 PM Scott Ullrich

Remove trailing carriage return

12984150 11/09/2010 11:58 AM Renato Botelho

Merge remote branch 'mainline/master' into inc

Conflicts:
etc/inc/pkg-utils.inc
etc/inc/system.inc

79eea0c1 11/03/2010 08:08 PM Ermal LUÇI

Activate code to allow ipsec to work normally.

4816e5ca 11/03/2010 02:53 PM Renato Botelho

Merge remote branch 'mainline/master' into inc

Conflicts:
etc/inc/auth.inc
etc/inc/config.lib.inc
etc/inc/priv.defs.inc
etc/inc/system.inc
etc/inc/upgrade_config.inc
etc/inc/vpn.inc

a6607b5f 11/02/2010 07:14 PM Jim Pingle

More VPN log fixes, for consistency. Ticket #912

f856e762 11/02/2010 06:29 PM Jim Pingle

Fix typo (standart -> standard)

e9a95ac8 11/02/2010 03:43 PM Jim Pingle

Switch to a unified vpn-linkup and vpn-linkdown.

2c7feef7 11/02/2010 02:07 PM Jim Pingle

Fix l2tp interface naming. Fixes #985

917b0a56 11/01/2010 08:22 PM Jim Pingle

Use individual linkdown scripts.

f2a86ca9 10/19/2010 06:19 PM Jim Pingle

Rename 'name' to 'descr' for CA, Certificates, and CRLs, to gain CDATA protection and standardize field names. Ticket #320.

10f0a57a 10/11/2010 03:53 PM Renato Botelho

Merge remote branch 'mainline/master' into inc

Conflicts:
etc/inc/authgui.inc

aab78bd9 10/06/2010 01:19 AM Pierre POMES

Fix racoon.conf generation for localid_type=address. Ticket #936

4178a1dd 10/05/2010 12:34 PM Jim Pingle

Add contributed patch to allow certain IPsec mobile clients to save Xauth passwords. Fixes #933.

addc0439 10/01/2010 01:17 PM Renato Botelho

Fix quotes to use %N$X on gettext calls

43652f2f 09/28/2010 01:19 PM Renato Botelho

Merge remote branch 'mainline/master' into inc

db3791e9 09/23/2010 09:56 AM Warren Baker

DNSWatch core dumps when it encounters white spaces.

7b2fdac4 09/22/2010 02:07 PM Jim Pingle

Properly check and set "Prefer older IPsec SAs" setting in the config and its associated sysctl. Move setting the sysctl to its own function to avoid code duplication.

8c04b1ae 09/08/2010 01:20 PM Renato Botelho

Merge remote branch 'mainline/master' into inc

Conflicts:
etc/inc/filter.inc
etc/inc/pkg-utils.inc
etc/inc/service-utils.inc
etc/inc/system.inc
etc/inc/vpn.inc

90388e48 09/03/2010 11:50 AM Ermal LUÇI

Actually decode before writing to mpd.secret. Alos correct variable names. Discovered-by: Efonne(IRC)

0e642c78 09/02/2010 05:27 PM Ermal LUÇI

Make possible to run multiple instances of pppoe server. Not yet switched to mpd4.

1e332e98 09/01/2010 07:15 PM Jim Pingle

CA/CERT Move

5281b3e8 09/01/2010 04:33 AM Chris Buechler

also include split_dns, as Cisco VPN clients won't query across the VPN without it.

e91e23b9 08/31/2010 04:21 PM Ermal LUÇI

Fix spelling error. Thanks-to: wagnoza (IRC)

bf34296a 08/31/2010 04:00 PM Ermal LUÇI

Do proper checking on the interval used for dnswatch. Otherwise might pass wrong parameters to dnswatch.

47f12397 08/30/2010 11:36 PM Renato Botelho

Fix gettext calls with printf to permit change strings order

487caee6 08/30/2010 11:26 AM Renato Botelho

Merge remote branch 'mainline/master' into inc

Conflicts:
etc/inc/interfaces.inc

37d7de2d 08/27/2010 12:13 PM Jim Pingle

Fix some PPPoE server radius variable references. Fixes #853.

561130e4 08/19/2010 07:23 PM Carlos Eduardo Ramos

Fix gettext on vpn.inc

89ceb4ba 08/18/2010 06:49 PM Renato Botelho

Implement gettext() calls on vpn.inc

a22d475f 08/13/2010 06:15 PM Jim Pingle

Let the user choose the IPsec CA instead of assuming.

dc291feb 08/13/2010 06:03 PM Jim Pingle

Only write out the CA if one exists.

4ccea790 08/13/2010 05:57 PM Jim Pingle

Flip this check

96ef83a7 08/13/2010 05:57 PM Jim Pingle

When using a certificate for IPsec, also write out and reference the certificate's CA.

29a3ac40 08/13/2010 05:57 PM Jim Pingle

Honor a phase 1 proposal_check if one is set, otherwise use the default.

6c74ac23 08/10/2010 02:40 PM Ermal LUÇI

Resolves #815. Do not add protection rules if lan interface has no ip.

72b7647f 07/27/2010 01:18 PM Jim Pingle

Fix test of preferoldsa to check the proper variable name.

98c02cac 07/22/2010 03:34 PM Ermal LUÇI

Ticket #655. Another try at this.

fb86a74b 07/21/2010 08:35 PM Ermal LUÇI

Fixes #755. Workaround bug on dnswatch and properties_read by actually creating a correct file for properties_read API.

3bb6bfd2 06/15/2010 07:27 PM Ermal LUÇI

Remove gif creation/deletion in ipsec code it seems unlikely and unused for a long time. This also removes the risk of doing damages on gifs configured through the GUI.

09f2bf85 06/07/2010 03:54 PM Jim Pingle

Honor GUI configured DNS settings for PPTP/PPPoE/L2TP if present.

4ed2dde7 05/28/2010 08:13 PM Jim Pingle

Add per-user PSKs to racoon.

96033063 05/20/2010 04:55 PM Erik Fonnesbeck

Various fixes to usage of ip2long, long2ip, and negated subnet masks, mostly affecting 64-bit. Ticket #459