Project

General

Profile

Statistics
| Branch: | Tag: | Revision:

# Date Author Comment
265ccfc3 09/22/2006 11:31 PM Scott Ullrich

Ensure space after vpns list

c52719a8 09/22/2006 11:22 PM Scott Ullrich

Do not destroy previous items, whiping out the listen directive.

70a6aeb0 09/22/2006 09:49 PM Scott Ullrich

do not unlink sh commands.txt, simply unlink commands.txt

Pointy-hat-to: ME

76252260 09/22/2006 08:27 PM Scott Ullrich
  • Fix MFC error where nat rules are blown out
  • Fix optional interface + carp
3f6fd1f3 09/22/2006 07:48 PM Scott Ullrich

Correct filenames in (C) header

fb2a6c76 09/22/2006 07:45 PM Scott Ullrich

Correctly associate carp interfaces with optional interfaces as well. This should hopefully fix CARP failover on optional interfaces

2f0a7613 09/22/2006 06:41 PM Scott Ullrich

MFC openvpn fixes by Fernando

c4b76267 09/22/2006 06:29 PM Scott Ullrich

Introduce rc.filter_configure and rc.filter_configure_sync.

45d7fb39 09/22/2006 05:51 PM Scott Ullrich

Use /etc/rc.filter_figure instead of 2 command touch /tmp/filter_dirty which does the absolute same thing but prevents openvpn from being tricked due to quoting.

3582e210 09/22/2006 04:20 PM Scott Ullrich

Inctroduce another snapshot before RC3

4b31e652 09/22/2006 04:01 PM Scott Ullrich

nve will support altq in just a moment.

Reminded-numerous-times-by: Christos Dionissopoulos <>

920cafaf 09/22/2006 02:39 PM Scott Ullrich

Move helper function to correct area

e7933a2b 09/22/2006 03:06 AM Scott Ullrich

-HEAD wasn't working. Unify both tree's.

e88adead 09/22/2006 02:53 AM Scott Ullrich

--ipchange silently didnt allow openvpn to run

c1fdf93b 09/22/2006 02:47 AM Scott Ullrich

--up only needs one argument

763ce2e6 09/21/2006 09:16 PM Scott Ullrich

RC3 time. Party on, excellent.

18ea86eb 09/21/2006 08:45 PM Scott Ullrich

MFC 14433
Move miniupnpd anchor to the end of the NAT rules so they have precedence.

e8ad9d31 09/21/2006 08:23 PM Scott Ullrich

Do not allow openvpn and ipsec entries to run together.

ed3ccdc7 09/21/2006 07:34 PM Scott Ullrich

Set net.link.tap.user_open to 1 by default.

d42d2184 09/21/2006 03:16 AM Scott Ullrich

512K is enough for 1000 rows. Back out previous commit.

66f8efe7 09/21/2006 03:08 AM Scott Ullrich

Version bump

4fa1ffbb 09/21/2006 02:29 AM Scott Ullrich

Increase filter log space to 784K so that it can accept 999 entries

d87e27e0 09/21/2006 02:11 AM Scott Ullrich

When a failover ipsec ip address is defined, use it as the ip address endpoint for ipsec.

b1ad443d 09/21/2006 12:57 AM Scott Ullrich

Include Id and copyright headers. Not sure how this slipped past.

df477d2b 09/21/2006 12:22 AM Scott Ullrich

The interface le absolutely supports ALTQ. Make it so.

0526354f 09/20/2006 11:02 PM Scott Ullrich

When running with verbose mode, tcpdump deocdes sip traffic. Bad boy.

24012690 09/20/2006 05:49 PM Scott Ullrich

Ensure filter reloads after openvpn state changes

2bccfcdb 09/19/2006 10:28 PM Scott Ullrich

Allow CTRL-C, CTRL-Z on console, etc.

6d17a9b9 09/18/2006 08:53 PM Scott Ullrich

Version bump

6a14ed37 09/17/2006 08:01 PM Scott Ullrich

Version bump from outter space

0a33f73e 09/17/2006 04:45 PM Scott Ullrich

Dont allow items to run together

Ticket #1105

45e38645 09/17/2006 06:47 AM Scott Ullrich

Add (y/n) hint

2c05cc10 09/17/2006 06:45 AM Scott Ullrich

Explain to the user that the developer bootstrap process populates /usr/src, etc.

012472a4 09/15/2006 06:10 PM Scott Ullrich
  • Only run the commands.txt file if it exists.
  • Unlink afterwards
a78b7955 09/14/2006 08:14 PM Scott Ullrich

Execute after commands via sh &

0a6d4110 09/14/2006 04:45 PM Scott Ullrich

Version bump

411d8c36 09/13/2006 04:56 PM Scott Ullrich

Kill correct process

5963133d 09/12/2006 09:13 PM Scott Ullrich

Woops, only change the first occurance of 19999

2ef857b2 09/12/2006 09:00 PM Scott Ullrich

Start at 19000 since we are ++'ing at the end of the loop.

8d896506 09/12/2006 08:37 PM Scott Ullrich

Version bump from outter space!

fe4d7d52 09/12/2006 08:05 PM Scott Ullrich

Match on the beginning of the string so that the 110 network is included

Submitted-by: XAI via IRC

0a5f89fa 09/12/2006 07:06 PM Scott Ullrich

We + the starting port at the end of the for loop. Do not + it at the beginning leading to power of 2 redirect entries.

0363c100 09/12/2006 05:31 PM Scott Ullrich

Correctly deterimine the previous ip address when running under pppoe, as well. Log an error if we cannot deterimine the ip address for any reason.

bd572fb6 09/12/2006 05:26 PM Scott Ullrich

Clear the filter cache before reloading. Now that Bill has worked his caching magic, this hit is almost nill.

b1b1bace 09/12/2006 01:30 AM Scott Ullrich

Expand special character descrption search and replace for xmlrpc to all description areas that are sync'd via XMLRPC. Note: this only replaces the special characters on the backup nodes

0ee99516 09/11/2006 09:45 PM Scott Ullrich

$starting_localhost_port++ for tcp/udp rules

1916ddad 09/11/2006 08:21 PM Scott Ullrich

Install both tcp and udp reflection helper entries

f29908ad 09/10/2006 10:38 PM Scott Ullrich
  • Cleanup -u whitespace
  • Actually install the correct protocol in the rule
383d15cc 09/10/2006 08:26 PM Scott Ullrich

We already check for $g['booting'] at the beginning of the function. Do not do it twice.

2ebd3617 09/10/2006 06:53 PM Scott Ullrich

Version bump

3afe16db 09/10/2006 05:49 PM Scott Ullrich

Do not install vpn helper entries on Optional interfaces that are disabled

0e9671ef 09/10/2006 05:42 PM Scott Ullrich

Do not install vpn helper entries on Optional interfaces that are disabled

b7ba117b 09/10/2006 01:07 AM Scott Ullrich

Version bump

0e871eb9 09/10/2006 01:00 AM Scott Ullrich

Convert interface to friendly name, actually use it.

785e986a 09/10/2006 12:51 AM Scott Ullrich

Actually redirect traffic when no vpn's are defined, too.

Pointy-hat-to: ME

e244be50 09/10/2006 12:01 AM Scott Ullrich

Backout last commit

842beb79 09/09/2006 11:35 PM Scott Ullrich

Cover the tcp case since Alan swears up and down it is not being invoked correctly.

See http://forum.pfsense.org/index.php/topic,2043.0.html

279006d9 09/09/2006 10:53 PM Scott Ullrich
  • Setup pass connections for correct protocols when reflection is in use.
  • Netcat needs a -u switch for udp type connections

Submitted-by: alan walters <>

d748e0b8 09/09/2006 09:31 PM Scott Ullrich

Back out last commit

1ddc3074 09/09/2006 09:24 PM Scott Ullrich

Fix reflection typo.

a6d1eaf8 09/08/2006 09:27 PM Scott Ullrich

Missed commits

50797647 09/08/2006 09:05 PM Scott Ullrich

Our compatibility code raelly needs to go into functions.inc so it can get installed before other php files are sourced.

022a0f9a 09/08/2006 08:54 PM Scott Ullrich

Correctly write out ttyd0 entry

0efc887f 09/08/2006 08:45 PM Scott Ullrich

Actually enable the serial port correctly and present the menu when needed.

819ccd08 09/06/2006 10:06 PM Scott Ullrich

Set export VARMFS_COPYDBPKG=yes during varmfs mounting so that we can see the entire /var/db/pkg/$PACKAGENAME/$CONTENTS structure

2b0a8a19 09/06/2006 09:44 PM Scott Ullrich

Version bump

80b638eb 09/06/2006 08:55 PM Scott Ullrich

We only need to match connections coming in on the interface

Noticed-by: BillM

e90481ff 09/06/2006 08:35 PM Scott Ullrich

Only define $vpns if there are vpns defined.

fb47169a 09/06/2006 08:31 PM Scott Ullrich

Correctly negate IPSEC FTP Helper connections and OpenVPN FTP Helper connections.

6f57956c 09/06/2006 06:42 PM Scott Ullrich

Correctly define remote OpenVPN subnets thanks to Fernando.

b5defbd4 09/06/2006 06:10 PM Scott Ullrich
  • Use tables to negate IPSEC vpns from FTP Helper
  • Add OpenVPN entries to negate from FTP Helper as well

Ticket #1099

NOTE: Not tested as of yet. Will test when I arrive at home.

189ea1b5 09/06/2006 03:47 AM Scott Ullrich

Reflection + FTP don't play well together, mmmkay?

cf83f490 09/05/2006 02:35 AM Bill Marquette

Fix usage of multi-host aliases in rdr

9b00dc26 09/05/2006 02:33 AM Bill Marquette

MFC commit [14178]
Correctly handle multi-host aliases

1d05769d 09/05/2006 01:01 AM Scott Ullrich

Increase default clog log file sizes

a8c5b0a8 09/04/2006 11:15 PM Scott Ullrich

Bump snapshot date

b7edc0e7 09/04/2006 11:14 PM Scott Ullrich

When the local port and external ports are the same, do not install a target port = foo entry

cedeafc0 09/04/2006 03:54 AM Scott Ullrich

Do not start ftpsesame on disabled interfaces (optionals)

7ce318d6 09/03/2006 09:32 PM Scott Ullrich

Set net.link.bridge.pfil_onlyip=0

2382762b 09/03/2006 09:02 PM Scott Ullrich

Build a snapshot set and test latest build changes

2e44fb05 09/02/2006 12:11 AM Scott Ullrich

Check that watchdogd is running before trying to kill it

f15b7e03 09/01/2006 11:23 PM Scott Ullrich

Provide other writable upload and post temporary folders for lighty

a3046c54 09/01/2006 11:18 PM Scott Ullrich

Check to see if dhcpd is running before blindly issuing killall

17bdf526 09/01/2006 11:16 PM Scott Ullrich

Don't echo . on bootup in rw and ro functions

2e269da2 09/01/2006 11:07 PM Scott Ullrich

Make bootup text consistent with others

f05740c1 09/01/2006 10:37 PM Scott Ullrich

Do not space after ...

cb74ffd5 09/01/2006 10:23 PM Scott Ullrich

Now that we are optimized switch the loading firewall output on bootup to a "." method.

87294955 09/01/2006 10:16 PM Scott Ullrich
  • Do not read-only mount if a firmware upgrade is in progress
  • Spew more .'s and pretend we boot faster
d03f2faa 09/01/2006 10:08 PM Scott Ullrich

Don't duplicate upload-dirs lighttpd directive

ee959dc4 09/01/2006 09:53 PM Scott Ullrich

Set upload path to /root/

e9f2dd08 09/01/2006 09:40 PM Scott Ullrich

Use a much larger growable ram disk (128 megs) vs the default low one.

It is now possible to upgrade firmware on embedded images, ladies and gentleman.

6d2b109d 09/01/2006 09:38 PM Scott Ullrich

When a firmware update is in progress, it is very important that we do not go RO.

1ef7b568 09/01/2006 06:08 PM Scott Ullrich
  • Move lighty upload to a definable globals.inc value upload_path
  • Use new upload_path for firmware updates

This in combination with 128 megabyte embedded images should fix the dreaded upgrade problem for the embedded platform.

9503c25e 09/01/2006 05:49 PM Scott Ullrich

MFC 13859
Move the upnp rules to the end of the list so a user rule can block access!

97fd5cb8 09/01/2006 04:56 PM Scott Ullrich

Restart OLSR correctly.

Ticket #1071

81d12935 09/01/2006 04:50 PM Scott Ullrich

Don't spike RRD stats after reboot.

Ticket #1089

Submitted-by:

5e5f5fac 09/01/2006 12:03 AM Bill Marquette

MFC of [14076]
fix typo and don't output the package config file

e5098817 08/29/2006 09:36 PM Scott Ullrich

NAT reflection is created for the int. instead for the ext. port

Ticket #1088

d99f7864 08/27/2006 10:55 PM Scott Ullrich

Back out last commit

7e1f7ce5 08/26/2006 07:51 PM Scott Ullrich

Send dhcp client name.

Ticket #1087