Project

General

Profile

Statistics
| Branch: | Tag: | Revision:

# Date Author Comment
855645a8 01/21/2008 06:57 AM Chris Buechler

Remove accidentally added debug code

b448e2cb 01/21/2008 06:54 AM Chris Buechler

Revert dhclient timeout to the default of 60 seconds. Setting it to 20 minutes
is a bit insane (if you haven't gotten a reply in 60 seconds, you aren't
getting one), and causes systems to hang 20 minutes during
"Configuring WAN" at boot when there is no DHCP server available...

02821543 01/15/2008 05:29 PM Seth Mos

attempt loading SPD entries 4 times

989f0b08 01/15/2008 11:36 AM Seth Mos

Somehow sending a SIGHUP before flushing and reloading works better then
after. Technically a SIGHUP to racoon should not do anything.

81cf1a89 01/15/2008 08:22 AM Seth Mos

Flush both SA and SPD entries

4311b114 01/15/2008 01:24 AM Scott Ullrich

Fix copy and pasto.

555db5b9 01/15/2008 01:19 AM Scott Ullrich
  • Use correct package name
  • Include filter rules
70c51c77 01/14/2008 11:17 PM Scott Ullrich

Add sipproxd hooks.

abd9c036 01/14/2008 09:37 PM Seth Mos

Make 3 passes at loading the SPD entries as this will fail on large configurations > 250 tunnels
Tested by smos@ 399 tunnels 239 active, ok by sullrich@

68ca6bf8 01/12/2008 07:21 PM Chris Buechler

remove DynDNS cache in services_dyndns_reset()

Ticket #1589

a43b9394 01/05/2008 07:43 AM Chris Buechler

add vr(4) VLAN support

Ticket #1561

2f381b82 01/05/2008 05:04 AM Scott Ullrich

Reapply patches from ticket #1532

bd997551 12/27/2007 01:48 AM Scott Ullrich

Correctly remove freebsd package upon package deletion.

ce094579 12/25/2007 11:23 PM Chris Buechler

text cleanup

434d8e7d 12/25/2007 09:15 AM Chris Buechler

Use list of VLAN long frame and native capable interfaces from globals.inc, and remove duplicate (and incomplete) list in interfaces.inc. Update list in globals.inc.

6556f547 12/24/2007 08:07 PM Scott Ullrich

Only iterate items if it is an array.

b73eda20 12/24/2007 07:44 AM Chris Buechler

Revert broken OPT interface removal commit. This breaks configurations entirely, worse than just improperly shifting configuration items.

Ticket #1532

d0d2c004 12/24/2007 06:57 AM Chris Buechler

change label to more accurately portray purpose of rule

0b1c5ff5 12/24/2007 12:40 AM Scott Ullrich

The original code did a mixed work: the part in interfaces_assign.php first renamed the interfaces, and then called cleanup_opt_interfaces_after_removal(). The latter didn't do anything at all: it never entered the loop, it didn't save the result of str_replace, it didn't save the resulting config after the processing. And if it had worked, it would have renamed the interfaces a second time as a side effect, completely messing-up the config....

ba308a09 12/16/2007 04:06 AM Scott Ullrich

globals.inc is required so that we use the correct lock file!

4882f3f0 12/13/2007 11:12 PM Scott Ullrich

If /etc/pwd.db.tmp exists when we are syncing the password database then remove the temporary file prior to attempting to sync.

2e7f11df 12/12/2007 10:20 PM Scott Ullrich

Don't forget line breaks!

f699a184 12/12/2007 05:45 PM Scott Ullrich

Correctly remove old clients correctly.

Submitted to m0n0wall list by R?nnblom Jan?ke /Teknous

8a1daf88 12/12/2007 05:42 PM Scott Ullrich

Define lanip

5a244130 12/10/2007 10:06 PM Scott Ullrich

Set server.max-request-size to 384 for captive portal.

4604d1e7 12/10/2007 10:00 PM Scott Ullrich

Set server.max-request-size to 384 for captive portal.

9db733ca 12/10/2007 09:53 PM Scott Ullrich

Limit captive portal uploads to /tmp/captiveportal which has no access to write files.

b4162528 12/10/2007 06:48 PM Scott Ullrich

Allow pfsync and carp traffic on captive portal.

9ce0c124 12/08/2007 11:48 PM Scott Ullrich

MFC from HEAD

Set dhclient timeout to 1200.
Set retry value to 1.
Set select-timeout to 0.
Set initial-interval to 1.

80e60d7c 12/07/2007 07:42 PM Scott Ullrich

Sometimes when the user enters the hostname of the HTTPs captive portal server it resolves the IP address to $LANIP. Allow access to $LANIP in addition to the $CPIP so that we can speedup captive portal by 10000* in these cases.

654d9c3a 11/28/2007 07:51 PM Scott Ullrich

Move update bogons script to 3am.

Discussed on pfSense-support@

c1aa7ba5 11/28/2007 02:26 AM Scott Ullrich

Log when we change the bogons frequency hour.

a984fffd 11/28/2007 02:20 AM Scott Ullrich

Move special case fixes before we return so that it can be processed.

adcda283 11/28/2007 02:02 AM Scott Ullrich

Change bogons update script frequency to 2am.

1df82ad5 11/28/2007 01:52 AM Scott Ullrich

Change bogons update script frequency to 2am.

7f37e7dc 11/06/2007 06:43 PM Scott Ullrich

Failover in 10 seconds as opposed to 60 seconds on DHCP Server failover mode.

f971bb63 11/05/2007 05:33 PM Scott Ullrich

IPSEC keep alive pinger using the wrong source IP address

Ticket #1482

73a80049 11/05/2007 01:33 AM Chris Buechler

fix setting of sysctls to remove error at bootup

37a7a75b 11/01/2007 06:14 PM Scott Ullrich

multiple vlans + spoofmac result in unexpected behaviour

Ticket #1514

Introduction
I have an acceptable workaround, so the problem is not urgent, but before i fiogured out the workaround, is was severely impacting performance (3 interfaces not operating). I am a network specialist and I am available to assist wherever possible. If the issue si considered seriousenough for a fix, I can assist in more detailed pinpointing using tcpdumps on test-platforms....

a7204435 11/01/2007 05:54 PM Scott Ullrich

Adding keep alive host to IPsec causes warning in webGUI

Ticket #1509

c1a304ac 10/24/2007 07:42 PM Scott Ullrich

MFC
Ticket 1709: fixed typo in OpenVPN cfg-page

9dcb92da 10/19/2007 08:52 PM Bill Marquette

Ticket #1482 - set the source to an interface that is inside the subnet definition

d8e4b5f5 10/13/2007 11:24 PM Scott Ullrich

Remove blank c/r

98b48086 10/13/2007 10:41 PM Scott Ullrich

Allow the interface assignment code to exit from its strict checking. This allows Netboot installation services to work correctly.

4205d512 10/05/2007 09:52 PM Bill Marquette

MFC of [19631] for Ticket #1456
drop one level of verbosity in tcpdump. Some protocols will still decode to multi-line message - not an easy fix. Doesn't appear to break non-raw log display

Add VRRP as a protocol type in the decode

c71dd217 09/18/2007 06:06 PM Scott Ullrich

Correctly set reflection timeout for all protocols.

5f05bdc4 09/17/2007 07:06 PM Seth Mos

MFC RELENG_1. Make it possible to disable RRD graphs. Bump config so it's on by default if it wasn't already.

fb0259fe 08/04/2007 08:27 PM Scott Ullrich

Sync NATT support from m0n0wall

1cb3a834 07/23/2007 04:57 PM Ryan Wagoner

-move upnp_action to services.inc
-make sure to clear rules when stopping miniupnpd
-fix status_upnp and status_services pages so they use upnp_action and not the rcfile

15c1fe85 07/15/2007 09:17 PM Seth Mos

Correct average times, otherwise the grap stops after 8 months.

ab325235 07/08/2007 09:04 PM Seth Mos

Oops, correct path to binaries

842a1aa3 07/07/2007 03:42 AM Scott Ullrich

CAPS kills. Literally. Do not set the description to upper case LAN when we are looking for lower case.

463cefdb 07/07/2007 03:20 AM Scott Ullrich

Kill off old pftpx processes correctly

11688040 07/06/2007 09:07 PM Seth Mos

MFC IPSEC fixes from seth, this should properly reload and handle large
configs > 300 tunnels.

44e4b117 07/05/2007 10:04 PM Scott Ullrich

Use $lanif for lan anti-lockout rule

60799565 07/05/2007 09:04 PM Scott Ullrich

Missed commmit

c9cd63b5 07/05/2007 08:40 PM Scott Ullrich

Escape $lan correctly

ad3e65b9 07/05/2007 08:39 PM Scott Ullrich

Do not use $iface as source or destination as it may be a member of a bridge without an ip address and pfctl will complain.

9cc9d7ed 07/05/2007 07:00 PM Scott Ullrich

Since we are matching traffic on incoming interface, do not link wan or lan to bridgeX

911760b0 07/05/2007 06:52 PM Scott Ullrich

Only pass anti-lockout traffic on $lan

165f9cb9 07/01/2007 07:59 PM Scott Ullrich

Cleanup IPSEC rules. We where blocking port = 500 UDP on CARP interfaces, for one.

a6bcda39 07/01/2007 07:24 PM Scott Ullrich

Be more verbose on logging so that we can correctly deterimine protocol, etc.

Ticket #1348

98e84487 06/30/2007 10:25 PM Scott Ullrich

$config needs to be global

0ec2b73d 06/30/2007 10:04 PM Scott Ullrich

unbreak policy routing rules network access to LAN IP

Ticket #1320

f7c2ef28 06/30/2007 09:49 PM Scott Ullrich

Correctly move upnp to base since LiveCD cannot write files to /usr/local/etc or /usr/local/etc/rc.d/

Ticket #1342

05b3900d 06/30/2007 09:19 PM Scott Ullrich

Remove openvpn csc file when option is disabled.

Ticket #1339

f877ef29 06/30/2007 08:38 PM Scott Ullrich

Do not antispoof on wan when it is bridged.

Ticket #1352

c95fcd0d 06/29/2007 04:22 PM Scott Ullrich

Move CARP and PFSYNC allow traffic before USER_RULES section. If a person has a restrictive ruleset then it is possible to disallow traffic.

620e7e13 06/19/2007 08:23 PM Scott Ullrich

Default to nat-reflection inactivity of 2000 which is roughtly 33 minutes.

72b906c9 06/18/2007 05:25 AM Scott Ullrich

Correct location of use_rrd_gateway.

64088d3f 06/09/2007 09:02 PM Scott Ullrich

Make sure we are writable for /etc/crontab

4b9b4ed1 06/09/2007 08:55 PM Scott Ullrich

Unbreak captive portal images.

0cc64c21 06/04/2007 10:47 PM Scott Ullrich

Restore previous PPTP changes.

2e54e8f7 06/03/2007 09:00 PM Scott Ullrich

With the tweaks that have occured today fastcgi can now run again on 64 megabyte machines.

119cd3af 06/02/2007 10:21 PM Scott Ullrich

Close STDIN ($fp) handle before returning back to shell. Major doh's.

3fcb53b6 06/02/2007 09:17 PM Scott Ullrich

use killall

d2d602ff 06/02/2007 09:10 PM Scott Ullrich
  • Flush SPD's on reload
  • Kilall -HUP racoon if its already running since racoonctl is brokie brokie
153e730b 06/02/2007 08:51 PM Scott Ullrich
  • Remove path from racoon grep
  • Remove [r] from racoon and simply grep for racoon
33b1881c 06/02/2007 08:49 PM Scott Ullrich

Correct ps location

d5be613c 06/02/2007 08:48 PM Scott Ullrich

Kill trailing space

c920cf13 05/31/2007 04:32 PM Scott Ullrich

Instead of skipping DHCP server on LAN in a bridged environment, simply log an error letting the operator know that DHCP Server is enabled on LAN in a bridging environment.

4bc3dc19 05/29/2007 11:14 PM Scott Ullrich

Use keep state instead of modulate state

3268867a 05/29/2007 10:21 PM Scott Ullrich

Really only allow adavanced tunables when some kind of state tracking is enabled.

7a22b7a1 05/29/2007 10:08 PM Scott Ullrich

Only allow adavanced tunables when some kind of state tracking is enabled.

676d63fc 05/29/2007 09:50 PM Scott Ullrich

Pass gre in any direction.

a88db555 05/27/2007 05:12 PM Scott Ullrich

Update static routes on filter reload

Ticket #1330

79b0d213 05/27/2007 04:59 PM Scott Ullrich

Unbreak local queries that where broken in Ticket #1190 until we hear back from author of the patch.

ab32f648 05/23/2007 10:35 PM Scott Ullrich
  • Add functions required for dashboard
  • Killing trailing space
6b21202e 05/21/2007 05:20 PM Scott Ullrich

Don't check carp settings, check if vip addresses exist.

bd410d49 05/21/2007 12:16 AM Scott Ullrich

usleep(1000); between down and delete. this appears to fix the carp issues.

865e64dd 05/20/2007 11:41 PM Scott Ullrich

Do not destroy carp interface which can lead to a panic. This has been tested and works just fine after deleting and adding new carp interfaces.

0fabced3 05/20/2007 04:52 PM Seth Mos

Commit forgotten vpn_ipsec_force_reload()

566c0e4d 05/20/2007 04:47 AM Scott Ullrich

Work around a FreeBSD where 2 carp interfaces exist and you delete 1. This ends up panicing the kernel. This is fixed in 7 so this will not be needed much longer.

ebfdf0cc 05/15/2007 01:24 AM Scott Dale

prepare for widget package

51a6bf4f 05/14/2007 11:56 PM Scott Ullrich

Use pfSync SYNCPEER directive if defined.

Ticket #1317

63d87073 05/11/2007 06:59 PM Scott Ullrich

Scrub the absolute minimum amount for PPPoE

cfc91d97 05/11/2007 05:23 PM Scott Ullrich

when pppoe aliases on pppoe server are made they make aliases for ng0 to whatever. but ng1 should be the start for pppoe-server ng0 should be reserved for pppoe client this problem could effect pptp server as well.

Ticket #1308

9a66dfe5 05/11/2007 07:14 AM Seth Mos

Do not flush SPA and SPD before starting. It upsets racoon.

f8aa7e0d 05/10/2007 05:16 PM Scott Ullrich

$config needs to be a global item

817c4729 05/10/2007 04:23 PM Scott Ullrich

Honor sticky-address setting from system->advanced for outgoing load balancing items if it is enabled.