Project

General

Profile

Statistics
| Branch: | Tag: | Revision:

# Date Author Comment
ae3c0a12 03/08/2011 07:18 PM Jim Pingle

Only run pfctl once per interface for stats, rather than four times.

3e5c0ab7 03/08/2011 05:47 PM Ermal LUÇI

Use foreach here to be sure we do not reference unexisting results.

13927322 03/08/2011 03:23 PM Ermal LUÇI

Do a proper test otherwise a override of the total_minutes var might happen.

c4ea3691 03/08/2011 03:16 PM Ermal LUÇI

Properly do testing of voucher existing or not rather than relying on an obscure feature of php. Also do exclusive locking rather than shared one when writing dbs.

6b5e978b 03/07/2011 10:45 PM Ermal LUÇI

Use racoonctl now that ipsec-0.8 is back to reload the config.

06d30ce7 03/07/2011 09:42 PM Ermal LUÇI

Handle the case on some special configs with a gateway of all 1's otherwise strange thing happens.

214bd062 03/07/2011 08:03 PM Jim Pingle

Fix typo

a5ccf623 03/07/2011 05:24 PM Jim Pingle

Add cas(4)

e8567e89 03/07/2011 03:07 PM Jim Pingle

When doing conf_mount_ro/rw on NanoBSD, pass sync,noatime to mount to preserve the options we have already set in fstab. Ticket #1279 and Ticket #444

fd4151a9 03/04/2011 10:05 PM Ermal LUÇI

Enforce session establishment.

bb7469ca 03/04/2011 10:02 PM Ermal LUÇI

Enforce session establishment.

de4333ba 03/04/2011 10:00 PM Ermal LUÇI

Enforce session establishment.

9fbb3599 03/04/2011 09:53 PM Ermal LUÇI

Add missing pages to the authentication system.

c53eb903 03/04/2011 08:50 PM Ermal LUÇI

Be smart and remove the needs package sync toggle since the begining otherwise not behaving packages might mess up the whole thing.

ce1942d6 03/04/2011 08:27 PM Ermal LUÇI

Oops more make code correct.

328c1def 03/04/2011 08:24 PM Ermal LUÇI

Oops make code correct.

006802ab 03/04/2011 08:15 PM Ermal LUÇI
  • Prevent concurrent logins on CP to not be recorded on the DB.
  • Make the locking more complex to avoid locking exclusively during pruning task which would hurt a lot CP performance.
  • Retire the disconnect_client and make all the disconnect functions use the sessionid as identifier....
9ccecb65 03/04/2011 05:37 PM Ermal LUÇI

If the interface triggering rc.newwanip is not assigned just reload packages and the filter and exit.

1b761f36 03/04/2011 01:09 PM Jim Pingle

Check if the protocol is empty, not just if it's set. Fixes #1323

1c1a74fa 03/04/2011 01:04 PM Jim Pingle

Only change protocol if it's set and not empty.

7ec0e6e2 03/03/2011 09:13 PM Jim Pingle

Add upgrade code to ensure rule protocols are all lower case.

06b3df52 03/03/2011 08:40 PM Jim Pingle

Make this lowercase before checking, or people who ended up with TCP or UDP in their config might end up with rules that have no port specified, leaving them a bit more open than expected.

4f4e85df 03/03/2011 04:30 PM Ermal LUÇI

Make sure we tell the code that the interface exists otherwise multiple laggs might get created.

ee487a68 03/03/2011 04:30 PM Ermal LUÇI

Not needed anymore.

6be90004 03/03/2011 02:24 PM Jim Pingle

Ensure the protocol on the firewall rule from the OpenVPN wizard ends up lower case, or it causes some GUI irregularities. Seen http://forum.pfsense.org/index.php/topic,33865.0.html and elsewhere.

67b0ed57 03/03/2011 05:42 AM Chris Buechler

lower limit to 101 MB

56f25370 03/02/2011 05:24 PM Erik Fonnesbeck

Simplify is_macaddr regex.

c5682801 03/02/2011 05:08 PM Jim Pingle

Slight regex fix on is_macaddr - the previous regex was letting through a mac without : separators, leading to improper validation and potentially invalid dhcp configs. Seen here http://forum.pfsense.org/index.php/topic,33830.0.html

199791f9 03/02/2011 02:09 PM Ermal LUÇI

Show friendly names of interface for root queues of ALTQ.

93c1127f 03/02/2011 01:57 PM Jim Pingle

Add GUI option to CARP settings for syncing certs. It was in the backend code but not the GUI. Fixes #1316

e77ecd8e 03/02/2011 11:52 AM Seth Mos

Attempt to mitigate fork bombs of rc.newipsecdns. Alternatively we should probably bail out with a exit(0);
instead.

d161b4d4 03/02/2011 09:14 AM Seth Mos

Always write out the filterdns-ipsec.hosts file, otherwise deleted tunnels will never get removed from the
filterdns-ipsec.hosts

bb3c6562 03/02/2011 08:08 AM Seth Mos

Add the toggle to disable successful login messages, show actual help text for redirect item

4fc3855f 03/02/2011 07:47 AM Seth Mos

Make it possible to turn off successful login messages, this should quiet the console, system logs

829fa12e 03/02/2011 07:21 AM Seth Mos

Add a check that should prevent configuration of racoon with duplicate phase 1 IP entries.

baca83aa 03/02/2011 04:51 AM Marcus Brown

Fix page title text. Replace "Firewall" with "Interfaces" in title.

539d5973 03/02/2011 12:25 AM Ermal LUÇI

Remove custom code for checking ip_addr and use the pfsense provided one.

cf46a14f 03/02/2011 12:23 AM Ermal LUÇI

Do not be so drastic on normal failure.

dcc897e5 03/02/2011 12:21 AM Ermal LUÇI

Since its only called during bootup there is no need to do conditionals here. Always sync config and start the miniupnpd process.

88cbd62a 03/02/2011 12:18 AM Ermal LUÇI

More fixes to comments and code for upnpd. Also bring up to speed the stop/start logic.

2816f43f 03/02/2011 12:05 AM Ermal LUÇI

Improve logging and some tests during miniupnpd config generation.

b469b7fe 03/01/2011 11:51 PM Ermal LUÇI

This is not true anymore as piece of code.

8df14984 03/01/2011 11:46 PM Ermal LUÇI

Correctly get only the interface mac address rather than any other found mac on this interface.

05c4bfa0 03/01/2011 11:40 PM Ermal LUÇI

Pass the -a parameters to pgrep to be certain we search ancestors as well. The side effects might be inoquos from the pfSense context.

c8487604 03/01/2011 06:18 PM Erik Fonnesbeck

Use the call to basename to remove the extension rather than trim, since trim takes a list of characters, not the exact string to remove. Suggested by http://forum.pfsense.org/index.php/topic,32967.0.html

8b19f4a7 03/01/2011 06:03 PM Erik Fonnesbeck

This is not NAT, so put it under the Firewall Advanced heading instead.

87ae1a2b 02/28/2011 07:02 PM Jim Pingle

Fix page title.

566193a5 02/28/2011 05:25 PM Jim Pingle

Only make gateway changes if we have been given a new gateway IP.

d7b4e38f 02/28/2011 05:21 PM Jim Pingle

Setup gateway monitoring since we just altered a gateway.

e121bebd 02/28/2011 05:16 PM Jim Pingle

Fix gateway handling in setup wizard.

2d539f40 02/28/2011 04:12 PM Erik Fonnesbeck

Only display gitsync settings on supported platforms.

cfaf6e69 02/27/2011 08:50 PM Scott Ullrich

Only show the you can monitor the filter reload process for filter related changes

58b4b246 02/27/2011 08:43 PM Scott Ullrich

Flush the buffer

4ed69f33 02/26/2011 07:20 PM Jim Pingle

Do a more strict check on the return value of the download function. Fixes #1309

153e3cb5 02/26/2011 04:40 PM Jim Pingle

Declare $g a global here.

73d885d7 02/26/2011 04:34 PM Jim Pingle

Ensure the pkg staging area exists on nanobsd before trying to use it.

17e7a243 02/25/2011 05:45 PM Scott Ullrich

missing $

da666ca8 02/25/2011 05:44 PM Scott Ullrich

missing $

a6f4ac66 02/25/2011 05:42 PM Scott Ullrich

misc whitespace cleanups

0c13af6c 02/25/2011 04:37 PM Scott Ullrich

Give this another shot

ebcdcaaa 02/25/2011 03:26 PM Jim Pingle

Fix admins group permission setting when upgrading from 1.2.3.

bc75a430 02/25/2011 09:27 AM Seth Mos

Correct IPsec carp interface upgrade code, off by one

a09d8bfc 02/24/2011 06:51 PM Jim Pingle

Use full path to pw

2aba8f77 02/24/2011 06:50 PM Jim Pingle

Add missing _relayd group, and when upgrading from 1.2.3, add _relayd group and user.

072bc34c 02/24/2011 06:20 PM Jim Pingle

Correct the test which displays an error if someone chose to save+test but doesn't have an ldap backend. Also, fix a typo.

bcc85621 02/24/2011 03:51 PM Jim Pingle

Fix find again... apparently -xdev is depreciated and tosses errors, replaced by -x

22beab88 02/24/2011 03:46 PM Jim Pingle

Move this code up a bit and also use /root/tmp to fetch packages instead of /tmp so it won't fill up.

9011a843 02/24/2011 03:37 PM Jim Pingle

If we're on nanobsd, pass -t to pkg_add to specify a different "staging area" path.

62958eae 02/24/2011 02:23 PM Seth Mos

Correct the vlan upgrade code to continue when we fixed up the interface

583f4913 02/24/2011 02:17 PM Seth Mos

Correct the find command, pipe into xargs

563b47bf 02/24/2011 01:10 PM Seth Mos

Make sure to resolve the gateway name before passing it off to the IPsec reload function

3acab378 02/24/2011 01:10 PM Seth Mos

Correct variable name. This could never have deleted the static route for IPsec vpns on multi wan

003d1b3d 02/23/2011 07:09 PM Jim Pingle

And one more place for PKG_TMPDIR... just in case.

633ef551 02/23/2011 07:07 PM Jim Pingle

Set PKG_TMPDIR here too, to help nanobsd pkg installs.

c99c1e4e 02/23/2011 05:49 PM Ermal LUÇI

Allow queues on top of bridge. Though more investigation is needed on its correct meaning.

6c67a28d 02/23/2011 05:36 PM Jim Pingle

Set PKG_TMPDIR for embedded/nano because it will fill up /var trying to download packages otherwise. (From sullrich)

0030036f 02/23/2011 05:14 PM Marcus Brown

Don't forget to clear username field so it doesn't show up on next edit.

And if for some reason user enters a username, store it for them.

ec465066 02/23/2011 05:06 PM Marcus Brown

Merge branch 'master' of rcs.pfsense.org:pfsense/mainline

d9cc4b24 02/23/2011 05:05 PM Marcus Brown

Try again, a little cleaner: Prevent GUI from giving error for freeDNS service since username and password

1f9d17ef 02/23/2011 04:54 PM Marcus Brown

Revert "Prevent GUI from giving error for freeDNS service since username and password"

This reverts commit 740f745922549283e29d3d964c7a60266d7dbf0a.

This is a little ugly. Let's do it a little differently.

62ce9874 02/23/2011 03:05 PM Marcus Brown

Update "Last Tested" date for freeDNS in comments

740f7459 02/23/2011 03:00 PM Marcus Brown

Prevent GUI from giving error for freeDNS service since username and password
aren't required.

Also add a note for freeDNS users to enter "Authentication Token"
in Hostname field. Zero out fake username and password before writing to config
so they don't show up in the GUI when you edit the record again.

4aa58d46 02/23/2011 02:45 PM Seth Mos

Correct the config path to the vip array

443f2e6e 02/23/2011 02:19 PM Seth Mos

Attempted fix that should convert the old carp[$i] naming to vip[$vhid]

3d039701 02/23/2011 02:07 PM Seth Mos

Make sure we iterate by the vlan number lest we end up with a empty variable? Hopefully fix new vlan name not being assigned to interfaces section

685a26fc 02/23/2011 02:01 PM Seth Mos

Correct the gateway group member name to the correct GW_". strtoupper($if) uppercase. This fixes outbound load balancer pools upgraded from 1.2.3
not working

219585da 02/23/2011 01:55 PM Seth Mos

Do not cross filesystem boundaries when removing files lest we empty Seth' USB stick

b8778031 02/23/2011 02:32 AM Luiz Gustavo S. Costa

Add a check if the configuration of dhcpd exists for wan before unset, resolves #1303

c54c9d15 02/22/2011 10:31 PM Ermal LUÇI

Remove direction from traffic shaper generated rules now that the match action is present to correctly put packets on proper queues. Before it was not possible since this would have also open firewall ports/holes.

2d1298ce 02/22/2011 07:29 PM Jim Pingle

Reset this var before this test, otherwise if the test is skipped, it will carry over the value from the previous run.

8364184a 02/22/2011 07:29 PM Jim Pingle

Don't consider a cert as in use by the GUI if it's in HTTP mode. Fixes #1171

ac631bba 02/22/2011 07:27 PM Luiz Gustavo S. Costa

Move all functions from index.php for captiveportal.inc

f1beeba5 02/22/2011 01:30 PM Luiz Gustavo S. Costa

Add Global reply-to disable checkbox, resolves the issue #1137

196440c8 02/22/2011 12:25 PM Luiz Gustavo S. Costa

reversal of accidentally deleted files
Revert "Add Global reply-to disable checkbox, resolves the issue #1137"

This reverts commit c646776871dacebcaa4225b083aa0789dc0bfba6.

c6467768 02/22/2011 02:43 AM Luiz Gustavo S. Costa

Add Global reply-to disable checkbox, resolves the issue #1137

95938fae 02/21/2011 09:45 PM Jim Pingle

Fix typo/spacing issue. Resolves #1300

4661598e 02/21/2011 06:23 PM Seth Mos

Add the diag_ipsec_xml.php page, this provides a XML interface to the
tunnel status built for a Coltex BV monitoring system

9e050072 02/21/2011 02:46 PM Seth Mos

Prevent empty remote endpoints from skewing the log output

a2a13c97 02/21/2011 02:19 PM Seth Mos

Trigger a VPN tunnel reload after configuring IPsec, it will handle all the hostname tunnels after boot finishes

df82fae1 02/21/2011 01:17 PM Seth Mos

Don't forget to include $g, otherwise the check will fail and still perform a DNS resolve