Michael Tremer
41f3351320
Drop "OpenVPN" part from VPN N2N stats page
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
1e2b257789
Add routed IPsec connections to traffic graphs section
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
7ba652af8c
firewall: Write correct rules bound to interface for routes IPsec tunnels
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
f9dd134645
ipsec-interfaces: Resolve any remote hostnames
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
d985ce5ae9
ipsec-interfaces: Move conditional block into the loop
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
38f6bdb740
ipsec: Drop delayed restart setting
...
This is a very bad race-condition situation and is not solved by
an unintuitive setting.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
517683eeb1
ipsec: Drop VPN_IP setting
...
This is now a per-connection setting
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
26c2cc580b
ipsec: Add translation strings for recent changes
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
6826364580
ipsec-*: Name some more configuration variables
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
1ca2f88a74
ipsec-interfaces: Uses local IP address from connection first, then default
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
c32fc72e36
ipsec-policy: Correct open ports for connections on aliases
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
ae0d069827
ipsec: Allow to select local IP address used for peer on UI
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
455fdcb17a
ipsec: Re-arrange inputs for peer addresses, subnets, etc.
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
7e25093d42
ipsec: Don't allow to select VTI in transport mode
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
605c391aaf
vpnmain.cgi: Don't populate GREEN subnet when green doesn't exist
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
c94aa25475
ipsec-interfaces: Fix typo in variable name
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
327d1223f3
strongswan: No longer create any routes automatically
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
c821440ced
ipsec: Filter better for GRE/VTI interfaces
...
This tried to delete the GREEN interface before
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
6a45a1f101
ipsec: TTL only applies for GRE interfaces and not VTI
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
54bac01402
ipsec: Find correct RED IP address when using %defaultroute
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
3dc21d43bf
ipsec: Log a message when an interface could not be created
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
1a45f9a70a
ipsec-interfaces: Don't add any interfaces when IPsec is disabled
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
a56357b8be
Revert "ipsec-interfaces: Run when IPsec is disabled"
...
This reverts commit 3c3a1cfdb9b473fae9b792e8c211c9940fafc658.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
216bd9b389
vpnmain.cgi: Move advanced IPsec settings to connection page
...
This is required to make the initial setup easier for GRE/VTI connections
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
4cf038dcfe
ipsec-interfaces: Run when IPsec is disabled
...
This needs to run even when IPsec is disable to remove
and interfaces
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
05af70c2f3
ipsec-interfaces: Use correct righthost variable
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
f2d45a45ab
IPsec: Do not allow 0.0.0.0/0 as remote subnet
...
This renders the whole machine inaccessible
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
68e69b676f
network: Create IPsec interfaces when network is brought up
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
3446a17293
ipsecctrl: Call ipsec-interfaces script when turning up/shutting down connections
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
b8c153bca5
IPsec: Add (experimental) script that creates GRE/VTI interfaces
...
Signed-off-by: root <root@interim-edge-a.ec2.internal >
2019-02-04 18:20:36 +00:00
Michael Tremer
90aa4f1083
IPsec: Use left/rightprotoport in GRE mode
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
b89ae1a4e3
ipsecctrl: Don't wait when a connection is to be started
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
5a9c9ff312
ipsec-policy: Don't install any block rules for connections with an interface
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
b54cd874b9
ipsec-policy: Permit GRE traffic for GRE connections
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
2704dbbc28
ipsec-policy: Variables don't match those from the CGI
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
4cf4f8f623
ipsec-policy: Parse all configuration settings
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
6cf8bc9161
IPsec: Move opening ports from ipsecctrl into ipsec-policy script
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
6c920b19cd
IPsec: Rename ipsec-block script to ipsec-policy
...
This is a more general name for a script that will be extended
soon to do more than just add blocking rules.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
b01c17e9d0
IPsec: Update ipsec.conf for GRE/VTI changes
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
55842dda69
IPsec: Add UI for set interface MTU
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
7464131706
IPsec: Add option to configure IP address for tunnel interface
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
8ebe725416
IPsec: Set default inactivity timeout to half an hour
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
1e9457ac6f
IPsec: New connections should defatul to on-demand mode
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
cae1f4a7a8
IPsec: Add dropdown to select tunnel interface mode
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
5e6fa03e1e
vpnmain.cgi: Correctly carry over INACTIVITY_TIMEOUT
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
326728d53d
IPsec: Write tunnel/transport mode to strongSwan configuration
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
29f5e0e2b9
IPsec: Add selection for transport/tunnel mode
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Jonatan Schlag
08d91c0f7a
python3-msgpack: Fix build on i586
...
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 09:02:18 +00:00
Michael Tremer
e20b7de067
python3-dateutil: Update rootfiles
...
Changed because of new python3-setuptools
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 07:00:13 +00:00
Michael Tremer
1cca99e3a1
core128: Ship updated dhcpcd
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 00:40:02 +00:00