Project

General

Profile

Statistics
| Branch: | Tag: | Revision:

# Date Author Comment
86fa7e0e 08/25/2009 12:54 AM Scott Ullrich

Use array_splice() to unset items that should not be sync'd (nosync) Resolves #38

5fba3c6e 08/21/2009 07:21 AM Seth

Make altq driver list up to date with 7.2

6d6746da 08/21/2009 07:06 AM Seth

Add vge interface to AltQ capable list

06e48ccd 08/21/2009 05:20 AM Scott Ullrich

Sync run_plugins() with head

3b659222 08/21/2009 05:00 AM Scott Ullrich

Unbreak parse_config plugins and fix autoconfigbackup

9aca6e5b 08/20/2009 08:56 AM Chris Buechler

Disable sshlockout. It's locking out after one failed login now that it's reading the logs correctly. It also isn't configurable, doesn't have a status page. Since 1.2.3 is close, let's ditch this from RELENG_1_2 and fix it properly for 2.0.

ddd61833 08/17/2009 09:05 AM Chris Buechler

Merge branch 'RELENG_1_2' of http://gitweb.pfsense.org/pfsense/mainline into RELENG_1_2

defe97dd 08/17/2009 08:55 AM Chris Buechler

Fix typo

2f90ab8c 08/16/2009 05:36 PM Scott Ullrich

When a UDP reflection line was added for inetd, it was added as stream

37ca89c5 08/12/2009 07:09 PM Scott Ullrich

Cleanup NanoBSD firmware upgrade

482e9e22 08/10/2009 08:42 PM Scott Ullrich

Make sure config.inc is sourced

4fc46699 08/09/2009 10:12 PM Chris Buechler

Allow logging everything to syslog (allows syslog of snort, amongst other things)

ace6d864 08/08/2009 10:59 PM Chris Buechler

Allow tcpdump by default on enc. There is no measurable performance impact, and it's annoying to flip the sysctls to allow when needed.

efefb2a1 08/04/2009 12:19 AM Chris Buechler

add "Disable reply-to" box. Work around for bug #14

e4079496 07/29/2009 03:35 PM Scott Ullrich

Tell syslogd to not compress information to the following line is repeated N times. This unbreaks sshlockout_pf.

3f6975ee 07/24/2009 04:54 PM Chris Buechler

Don't log an error unless there really is one.

e5b9dc32 07/23/2009 05:26 PM Chris Buechler

Fix rdr on PPPoE and PPTP servers

10bfe265 07/19/2009 10:39 PM Scott Ullrich

Revert the flowtable addition that should have never been accidently commited. Skip pfsync0 similar to how we do in master/HEAD

c553931b 07/19/2009 06:09 AM Chris Buechler

Load glxsb by default, unless disabled. Add option to disable to System -> Advanced.

bb655a67 07/16/2009 09:31 AM Seth

Fix variable name so that the prefer old SA knob actually does what one expects it to do.

645bdcb4 07/16/2009 01:46 AM Scott Ullrich

needs to be a global now

461fcf07 07/16/2009 01:44 AM Scott Ullrich

Do not allow muting of serial + full install

1286004b 07/16/2009 01:41 AM Scott Ullrich

Do not allow muting of a serial console. The kernel gets very cranky and dishes cannot control tty errors

2b7dc757 07/14/2009 08:23 AM Seth

Switch over the dns list from arguments to dnswatch to a file which holds them which dnswatch will use

865af177 07/12/2009 01:01 AM Scott Ullrich

Allow auto firmware upgrade to work on NanoBSD

c62c873c 07/12/2009 01:01 AM Scott Ullrich

Allow auto firmware upgrade to work on NanoBSD

963f93f2 07/12/2009 01:01 AM Scott Ullrich

For now set the number of flows to the same as allowable states.

d1073bf6 07/11/2009 09:10 PM Seth

Do not add hostname to watch in the refresh ipsec policy section, there may be other tunnels using the same
endpoint which need refreshing as well.
This is also done in the part where the racoon configuration is written so it's safe to skip it here.

Silence the logging in the dnscache code and the ipsec route add code into a debug check...

02e9c21b 07/10/2009 10:10 PM Seth

Make the dnswatch list array unique before processing

83c195f2 07/09/2009 07:01 PM Seth

Increase the PHP running memory limit to 128MB from 32MB, on 1.5MB large
config XML files we run out of memory.

2add0a66 07/09/2009 06:38 PM Scott Ullrich

This routine was not meant to foreach() even though it is inside a foreach(). It's slightly confusing but the foreach obtains the correct namespace and then processes. Add the needed break; statemenet because on subequent foreach() loops, the carp password will be WRONG/BLANK.

89a55272 07/09/2009 06:08 AM Chris Buechler

MFC fix from Ermal

Fixes #26

102b2d8a 07/07/2009 07:38 PM Scott Ullrich

Do not call mute_kernel_msgs() it causes havoc.

d2692076 07/03/2009 07:30 PM Scott Ullrich

Match 4.X polling behavior. See thread "Polling and kern.polling.idle_poll"

47ef844d 07/01/2009 04:06 AM Scott Ullrich

Remove trailing /

78de2481 07/01/2009 04:04 AM Scott Ullrich

Add missing /

4b4dcdea 07/01/2009 03:48 AM Scott Ullrich

Correct the name its parse_config

5666fb4d 07/01/2009 03:48 AM Scott Ullrich

Correct the name its parse_config

6fabe487 06/27/2009 11:13 PM Scott Ullrich

If the key is 0 then return, it is not a valid key.

f05d33ce 06/27/2009 11:03 PM Scott Ullrich

Surpress sem_ errors

ed88d0a8 06/27/2009 08:46 PM Scott Ullrich

Teach config about nanobsd

e9fc058c 06/25/2009 06:31 PM Scott Ullrich

Check to see if dir exists before blindly mounting rw

ca8e7d45 06/25/2009 06:29 PM Scott Ullrich

Add missing conf_mount_ro();

e18e4ed4 06/25/2009 06:16 PM Scott Ullrich

No need to call conf_mount_rw() when generating config.cache, it is on /tmp

991ad577 06/25/2009 06:36 AM Chris Buechler

Patch from Aarno Aukia for cvstrac ticket #1932

c8c4c1d0 06/22/2009 09:11 PM Chris Buechler

remove watchdog

854a64d1 06/22/2009 04:29 PM Scott Ullrich

Disable watchdogd until we can find a workaround. When IPSEC is thumping (or any other network intensive opeartion) for long period of times can trigger the watchdog. Really watchdogd needs to check to see if network packets are flowing because if network packets are flowing the box is up from our standpoint.

840549ca 06/18/2009 07:19 PM Chris Buechler

patch from jim-p to fix remote VPN logging now that we have apinger

7f7a359b 06/17/2009 09:03 PM Scott Ullrich

Adding base_package feature to restore menu items for base packages after configuration
restore.

1a7d4821 06/17/2009 08:58 PM Scott Ullrich

Handle packages on embedded the same. Ssshhhh, don't tell anyone.

45e974c9 06/15/2009 02:49 PM Chris Buechler

Fix ruleset for > 100 OpenVPN connections

clean up the old unused bridge code while here.

0edee281 06/06/2009 09:01 PM Scott Ullrich

Exclude ppp from interface mismatch check

3142c883 06/05/2009 06:32 AM Seth Mos

Remove RRD options from the apinger configuration.
They do not make any sense to generate since they are not used anywhere in 1.2

372d28b0 06/03/2009 05:58 AM Seth Mos

Eventhough you can set the racoon admin socket to a different path in the configuration it will be ignored by ipsec-tools 0.8+
Align all the sockets into the new path /var/db/racoon so that we can find it.
Remove the old killall -HUP racoon as this prevents the newer racoon from properly loading it's initial configuration. This might actually also have been a possible problem on the old ipsec-tools...

3283437d 06/02/2009 10:36 PM Scott Ullrich

Oops, make that /bin/mkdir

adf44688 06/01/2009 09:55 PM Scott Ullrich

Exclude plip from get_interface_list

24afa018 05/31/2009 08:36 PM Chris Buechler

Merge branch 'RELENG_1_2' of http://gitweb.pfsense.org/pfsense/mainline into RELENG_1_2

47c13f03 05/31/2009 08:36 PM Chris Buechler

fix static route deletion

a0793ae4 05/31/2009 06:51 PM Scott Ullrich

Add NAT-T ports.

Submitted-by: JimP@

30934c59 05/31/2009 06:31 AM Scott Ullrich

Set hostname then call hostid

08d591b5 05/30/2009 08:51 PM Scott Ullrich

Ensure /var/db/racoon exists

20afbdfe 05/29/2009 10:36 PM Seth Mos

Oh dear, looks like I had the values for loss and latency reversed.
That is not very useful.

0f2bd8e7 05/29/2009 10:36 PM Seth Mos

Make the apinger rrd files end up in /tmp so they are not seen by the
web ui.

991eb938 05/28/2009 11:04 PM Scott Ullrich

Adding --all-servers flag for DNSMasq which can help when a DNS server is unreachable and in some cases speedup queries since it will ask each known dns server all at once and use the first response that it finds.

6f255c8b 05/28/2009 07:50 AM Seth Mos

Change the warning threshold for the apinger delay warning from 100 to 200 ms.

e1c6b3d6 05/28/2009 07:45 AM Seth Mos

Backport apinger from 2.0 to 1.2
This removes the gateway support from the slbd load balancer. It will now create a apinger configuration instead.
Change syslog configuration so apinger logs to the slbd.log
Correct status page so that it shows the gateway status....

1bc43e42 05/28/2009 07:22 AM Scott Ullrich

Hide errors.

41f4fada 05/23/2009 08:30 PM Scott Ullrich

Hide errors on sem_get() too

c77050d5 05/23/2009 08:26 PM Scott Ullrich

Surpress semaphore errors

032d2dc1 05/22/2009 01:44 AM Chris Buechler

use real if name for get MTU function

8751763c 05/20/2009 12:24 AM Chris Buechler

merge Ermal's CP locking changes

6785fbfe 05/18/2009 05:17 AM Chris Buechler

Merge branch 'RELENG_1_2' of :pfsense/mainline into RELENG_1_2

eccd3813 05/18/2009 05:16 AM Chris Buechler

Kill rrdtool before killing updaterrd, possibly prevent multiple updaterrd from running.

82cab169 05/15/2009 12:49 AM Scott Ullrich

Move firmware update text format to globals.inc

82f4ffb5 05/11/2009 04:54 PM Chris Buechler

add missing \n's caught by jim-p

42cf9c5c 05/09/2009 08:40 PM Chris Buechler

point to correct path for nsupdate

cc4a5388 05/08/2009 09:22 PM Chris Buechler

colons are valid in usernames, such as for no-ip subaccounts.

9b590c5e 05/07/2009 05:30 PM Chris Buechler

add msk(4)m

fb534738 05/03/2009 07:40 PM Chris Buechler

remove debug logging

e6d0e46a 04/26/2009 12:56 AM Scott Ullrich

Add /var/run directory in dhcpd chroot

a4d71dc1 04/24/2009 12:03 AM Chris Buechler

Fix "disable checksum offloading", and some other bugs with certain combinations of options while here.

23df7095 04/18/2009 07:18 AM Chris Buechler

Clean up polling fix a bit.

7c964ff0 04/18/2009 07:10 AM Chris Buechler

Fix polling, update supported interfaces list.

f031a007 04/16/2009 05:30 AM Chris Buechler

Allow disabling of auto-added VPN rules

0529f24a 04/06/2009 05:26 PM Chris Buechler

Set ipfw's state limit the same as pf's

9ffede93 04/06/2009 03:41 PM Scott Ullrich

Trigger drop down menus on 83 chars

4bc0961e 04/06/2009 02:00 AM Chris Buechler

Block all IPv6 traffic by default, since IPv6 isn't supported, there isn't any way to add such rules in the GUI, and nearly all users won't want IPv6 to traverse their firewall at this point. Add "Allow IPv6" checkbox to disable this behavior.

0958770c 04/06/2009 12:35 AM Chris Buechler

Since they're listed by name, order alphabetically.

d38805bc 04/05/2009 01:01 AM Chris Buechler

Honor monitor type for server load balancing

aebbbb63 04/02/2009 06:57 PM Scott Ullrich

Use 80 chars

f56097a3 04/02/2009 06:55 PM Scott Ullrich

Woops, use 80 chars not 70

3a42330e 04/02/2009 06:54 PM Scott Ullrich

Switch to a dropdown menu when there are more than 80 characters combined
in the display_top_tabs() function.

fd03e4f3 04/01/2009 10:01 AM Seth Mos

Add Broadcom BCM5708 bce driver to the list
Add Intel 82598 10 Gigabit ixgbe driver to the list

8e9c0681 03/31/2009 08:21 PM Scott Ullrich

Improve the matching of carp ints to IPs.
Previously this stristr substring match would return incorrect/unexpected results. 10.0.0.1 would also match 10.0.0.16, 10.0.0.135. Adding a space to the IP to check will only match the specific IP given, since it is followed by spaces in the ifconfig output.

fa1fafb6 03/30/2009 04:43 AM Chris Buechler

When optimization is "conservative", also increase UDP timeouts. Helps prevent disconnects and drops with some VoIP services.

c1285ca6 03/26/2009 05:27 AM Chris Buechler

Change log message. This doesn't necessarily mean the IP has changed, so it was misleading.

12df13d4 03/26/2009 05:15 AM Chris Buechler

Log actual interface rather than CARP interface

1cb58b79 03/24/2009 07:33 PM Scott Ullrich

Add hideplatform item which is useful for rebranding

e28d3bb3 03/23/2009 09:36 PM Scott Ullrich

Ensure dpddelay is a value, not that its simply set leading to racoon.conf errors:

my /var/etc/racoon.conf file has: "dpd_delay ;"

Reported in ##pfSense on FreeNODE by Overrand

45faf3da 03/18/2009 04:19 AM Scott Ullrich

Revert "Sync from HEAD to avoid complete meltdowns when downgrading from 2.0"

This reverts commit 1987293b2cf80d15677860f9c5d6ff52b9ff03db.