Project

General

Profile

Statistics
| Branch: | Tag: | Revision:

# Date Author Comment
d25b4a55 12/22/2006 09:02 PM Scott Ullrich

Only use freebsd-sendfile network handler on Full Installations. Tests have shown that it actually slows down the metallic theme on embedded by Holger.

fda8dc28 12/22/2006 04:55 PM Seth Mos

Fix DHCP status on status_interfaces.php. Use find_dhclient_process() for test.

bd18ec7c 12/21/2006 11:16 PM Scott Ullrich

version bump

bb7d60f9 12/21/2006 10:15 PM Seth Mos MFC find_dhclient_process() fixes.
  • Fix pgrep regexp for new dhclient version
  • Kill process by number instead of (non-existant) pid file.
  • Return PID number instead of executing the file $pid
770b4b9c 12/21/2006 09:08 PM Scott Ullrich

Use correct directive.

a56e787d 12/21/2006 09:05 PM Scott Ullrich

MFC use freebsd-sendfile

7c069592 12/21/2006 08:55 PM Scott Ullrich

Remove bad sysctl

Pointed-out-by: rsw686 via irc

e789a625 12/21/2006 12:28 AM Scott Ullrich

Output dhclient.conf in the same format as current m0n0.ch beta (freebsd 6 + isc dhclient)

bdc3c489 12/21/2006 12:21 AM Scott Ullrich
  • Set dhclient-script using option
  • Use -nw

Obtained from latest m0n0 beta 1.3

751cf8be 12/20/2006 10:31 PM Scott Ullrich

Version bump

8a7553ab 12/20/2006 10:06 PM Scott Ullrich

Switch to ISC-Dhclient. OpenBSD's dhclient is driving me bonkers.

1cbc2a1c 12/17/2006 06:04 PM Scott Ullrich

Use correct interface when restarting dhclient

f86e2cf9 12/17/2006 05:58 PM Scott Ullrich

"Always sent Session-Time in accounting packets. This makes most prepaid systems to work again."

Obtained from m0n0wall

b1f7e75e 12/16/2006 01:37 AM Scott Ullrich

Revert previous dhclient crontab mojo. When running rc.newwanip if the ip == 0.0.0.0 then fire off dhclient again.

As seen on the forums ( http://forum.pfsense.org/index.php/topic,2645.0/topicseen.html )

716d68e3 12/15/2006 01:22 AM Scott Ullrich

Version bump.

Captive portal optional interface users should consider upgrading to this version.

a32edd35 12/14/2006 09:35 PM Seth Mos

Create valid pf Syntax!

76212648 12/13/2006 01:22 AM Scott Ullrich

Only pass in on Captive Portal interface

Ticket #1188

8b80a848 12/13/2006 12:46 AM Scott Ullrich

For interfaces using the Captive Portal, ensure that traffic can reach port 8000 and 8001 which is the Captive Portal auth interfaces.

Ticket #1188

be6c03cb 12/12/2006 06:22 PM Scott Ullrich

Version bump

29edaa0b 12/12/2006 06:18 PM Scott Ullrich

Check DHCP interfaces every 6 hours for dhclient issues. Launch dhclient if it is not bound to an interface correctly.

317e8e1a 12/11/2006 07:44 PM Seth Mos

- livecd/embedded: do not create a md on /var/db/rrd, /var already is one
-7 lines, +6MB ram. Tested on WRAP + LiveCD

b6bf759b 12/11/2006 05:48 PM Scott Ullrich

Version bump

84e5047d 12/11/2006 05:10 PM Scott Ullrich

Silence eclipse warnings

161a01bd 12/11/2006 04:56 PM Scott Ullrich

Ticket #1185
Check $hostname, not $domain

37f91468 12/09/2006 08:00 PM Scott Ullrich

Work around a dynamic rule problem that is known in FreeBSD for IPFW2:

">Strange, why only me(?) get this problem.. Isn't

net.inet.ip.fw.dyn_keepalive=1 by default ?

This is a workaround. I am aware about this problem from several people.
Here is needed more testing to determine the cause of the bug."

0395fc39 12/08/2006 08:18 PM Scott Ullrich

Version bump

bee6ca26 12/06/2006 11:10 PM Scott Ullrich

Version bump

42756417 12/05/2006 05:59 PM Scott Ullrich

Version bump

4e5205b1 12/05/2006 05:52 PM Scott Ullrich

MFC 15495
fix: root key files are not in /etc/ssh/root ...

8777488b 12/05/2006 05:45 PM Scott Ullrich

MFC 15411
is_domain(): MS breaks all laws, so unserscores are allowed...

856887a3 12/05/2006 05:42 PM Scott Ullrich

MFC 15402
is_domain(): domains must not contain underscores; empty strings are not valid

c4b966b7 12/05/2006 01:39 AM Scott Ullrich

Back out changes to try and fix OpenVPN. We really need to fix check_reload_status

d9978237 12/04/2006 08:04 PM Scott Ullrich

Version bump.

687092ae 12/03/2006 11:04 PM Scott Ullrich

Misc spelling mistakes. Remove old commented out code.

ae87302c 12/03/2006 10:22 PM Scott Ullrich

Work around the fact that check_reload_status is inheriting socket descriptors from other programs. Kill check_reload_status on wan ip change and restart it. That way openvpn can be killed and restarted, etc.

In addition while I am here, we really should restart openvpn after WAN ip changes as well.

7d5b8f4a 12/02/2006 12:53 PM Seth Mos

Do no install default pass in rules for openvpn interfaces with a
gateway.

86c2b561 11/30/2006 09:49 PM Scott Ullrich

Install frickin pptp proxy rules

60906d7c 11/30/2006 07:05 PM Scott Ullrich

Version bump

490ebea1 11/30/2006 06:39 PM Scott Ullrich

Add frickin pptp proxy hooks.

6de03121 11/29/2006 05:43 PM Scott Ullrich

Version bump

4c02f57a 11/28/2006 07:15 PM Scott Ullrich

Version bump

481fda7f 11/28/2006 07:14 PM Scott Ullrich

Start OpenVPN with nohup

85d70ed4 11/25/2006 11:53 PM Scott Ullrich

Version bump. Includes check_reload_status fixes which should help some DHCLIENT users.

f2f4d281 11/24/2006 07:07 PM Scott Ullrich

Version bump

66cc9614 11/24/2006 06:32 AM Seth Mos

Uhm, previous was almost right. Limit dropped to a 115MB available ram
so people can use computers with up to 8MB of shared graphics memory.

41ca428b 11/24/2006 03:53 AM Scott Ullrich

Do not forget rule anchor for imspector.

Pointed-out-by: dberlin

193877d3 11/24/2006 03:38 AM Scott Ullrich

MFC 15441
added imspector anchor

da3cb207 11/22/2006 10:36 PM Seth Mos

If the available memory is between 97 and 128 MB do not prompt. This is
the same approach as system.inc does. This fixes boot for people with
onboard graphic cards and you miss a few MB.

6ab7ae50 11/22/2006 05:47 PM Seth Mos

Merge newer rrd graphing code, drop down now only lists valid rrd
targets. Added CPU and States graphs. More logging in case of graph
generation. Minor bugfixes and cleanup.

09da8bfa 11/22/2006 05:06 PM Scott Ullrich

Version bump

f1d634bb 11/22/2006 05:04 PM Scott Ullrich

Move $config = parse_config() statement to end of file to attempt to prevent the error:

Fatal error: Unknown function: parse_config() in /etc/inc/config.inc on line 198

581daddc 11/20/2006 07:06 PM Scott Ullrich

Run fsck -fy instead of fsck -y

3e0896d5 11/19/2006 07:13 PM Scott Ullrich

MFC 15106
Ticket #1146: binat rules MUST be before NAT else they don't work as
expected.

f80f3194 11/19/2006 06:55 PM Scott Ullrich

MFC 15382
fix: is_process_running() does inaccurate matches

e65bc7e2 11/19/2006 06:21 PM Scott Ullrich

Version bump to SNAPSHOT.

43511be8 11/17/2006 03:46 PM Scott Ullrich
  • Move stop package code out to it's own file rc.stop_packages
579946e2 11/12/2006 06:57 PM Scott Ullrich

MFC
pclose -> fclose

3c61530f 11/11/2006 09:54 PM Scott Ullrich

Do not complain unless user has less than 126 megs of ram. Some motherboards share ram with video cards.

6a01ea44 11/11/2006 05:52 PM Bill Marquette

MFC [15285]
add dhcpd static mappings to dns forwarder

0dbac999 11/10/2006 07:58 PM Scott Ullrich

Only enumerate the variable if it is an array to avoid:

Warning: fclose(): supplied argument is not a valid stream resource in /etc/inc/system.inc on line 147

c5a2bfdb 11/10/2006 06:27 PM Scott Ullrich

Allow priv to appear multiple times so that a person can downgrade from the pile of SHIT we call -HEAD.

029d1a71 11/10/2006 04:06 PM Scott Ullrich MFC 15253
  • suppress the annoying 'missing default locale' warning if calling the tar binary
95385647 11/06/2006 09:59 PM Scott Ullrich

Apparently my big fat warning about needing two interfaces is not a big enough warning. Make the language a bit more precise and stern to thwart bogus support requests.

634d6ab3 11/05/2006 11:40 PM Bill Marquette

MFC [15201]
unset $extport before assigning to it as not all elements of the array are
assigned each time through the loop, but all elements are checked and used
if already assigned. Oops.

c64f4049 10/29/2006 12:28 AM Bill Marquette

apparently 5m cache slows stuff WAAAYYYYYYY down, 7m has a negligable
performance diff from 30m and works better than 5m, so let's use it

16403b3a 10/28/2006 01:43 AM Bill Marquette

Only check for check_reload_status process if machine is booted
rc scripts launch this process at the end of boot

d2834563 10/27/2006 04:29 PM Scott Ullrich

Ticket #1154: Bad format for generated syslog.conf

Submitted-by: Angelo Turetta aturetta+pfsense at bestunion.it

36f83392 10/26/2006 02:52 PM Scott Ullrich

Be a little more agressive when blocking snort2c traffic

df0d836b 10/24/2006 05:09 PM Scott Ullrich

Version bump to 1.0.1

69122db2 10/23/2006 02:14 AM Scott Ullrich

Woops, somehow I forgot to add this files content.

96e85395 10/23/2006 12:09 AM Bill Marquette

Ticket #1136: Make sure check_reload_status is running so we can regen
rules

ec6adc21 10/22/2006 10:09 PM Bill Marquette

PF doesn't know what "congestion" TOS flag is

1387e454 10/22/2006 05:21 AM Bill Marquette

MFC [15086]
Ticket #1137: find_interface_ip() doesn't do what it says. Really return only the first found IP. This fixes issues with people configuring FreeBSD IP aliases on interfaces

0a972a1a 10/22/2006 04:47 AM Bill Marquette

MFC [15083]
Ticket #1145: Don't background the stop process, we really do need to stop the daemon before it tries to start again

7a7abeba 10/20/2006 05:00 PM Scott Ullrich

Remove pf states for client ip when disconnecting from captive portal.

0d67f297 10/17/2006 09:50 PM Scott Ullrich

Create rc.linkup.sh to simplify check_reload_status

3696f576 10/17/2006 09:28 PM Scott Ullrich

Woops, we need the ftp anchor BEFORE the user rules, and the inital PASS rules AFTER.

This controls the initial port 21 connetion and once that is allowed through the ftp rules installed by pftpx should bypass USER_RULES.

33082c49 10/17/2006 08:52 PM Scott Ullrich

Change APC caching size to 5 megabytes. php.ini is generated from system.inc on bootup now.

9d0b14e0 10/17/2006 05:12 PM Scott Ullrich

Set ClientAliveCountMax to 5.

89a75ca9 10/15/2006 05:20 AM Bill Marquette

ZoneEdit now works, tested by myself and korozion
MFC checkin [15047]

91dc2ecf 10/14/2006 05:34 PM Scott Ullrich

file_notice() requires notices.inc

11d30033 10/14/2006 05:28 PM Scott Ullrich

file_notice() requires notices.inc

477135b9 10/14/2006 02:23 PM Bill Marquette

Ticket #1124 - fix wording
MFC of commit [15039]

7ce92c10 10/12/2006 09:44 PM Scott Ullrich

Do not unlink filter_drity, allow check_reload_status to handle this.

e4d75494 10/12/2006 05:28 PM Scott Ullrich

1.0-RELEASE time. I never thought we would make it! w00h0000!

4184c024 10/10/2006 01:28 AM Scott Ullrich

Do not write out php.ini on cdrom platform.

a164b0ca 10/10/2006 01:21 AM Scott Ullrich

Call the php.ini creation function after the other functions have been loaded into memory.

3a551579 10/10/2006 01:00 AM Scott Ullrich

Call the php.ini creation function after the other functions have been loaded into memory.

adf4b768 10/10/2006 12:38 AM Scott Ullrich
  • Dynamically create php.ini on bootup
  • Do not use APC for embedded machines. Advice from #lighttpd
632e8d54 10/10/2006 12:12 AM Scott Ullrich

If user has defined the maxprocperip to 0 then do not install mod_evasive directions to limit the connection count per ip address.

b0bdc06e 10/09/2006 11:54 PM Scott Ullrich

Use mod_evasive to limit connections per ip

61f1e2ec 10/09/2006 08:51 PM Scott Ullrich

Ensure nameserver information is removed at bootup before its discovered again.

087ce411 10/08/2006 09:53 PM Scott Ullrich

Add missing \n

232374b7 10/08/2006 09:43 PM Scott Ullrich

Add missing "

c108ec01 10/08/2006 08:45 PM Scott Ullrich

Show a big fat warning on every bootup via the notices system if the minimum ram requirements are not met.

65929949 10/08/2006 08:40 PM Scott Ullrich

Show a BIG FAT WARNING that under 128 megaytes does not work during initial setup if <128 megs of ram detected.

c1f46b20 10/06/2006 11:30 PM Scott Ullrich

Stop packages before restarting.

bb42c780 10/06/2006 07:55 PM Scott Ullrich

Check for TAP interfaces as well as TUN. Some people fancy bridging openvpn to TAP which allows for stuff like Bonjour to work across the tunnel.

8b7fb7ec 10/05/2006 10:10 PM Scott Ullrich

Do not log NTPD messages to OpenVPN tab

5c424e3d 10/05/2006 10:04 PM Scott Ullrich

Add OpenNTPD logging tab