Commit Graph

2668 Commits

Author SHA1 Message Date
Michael Tremer
3027c6bb96 initscripts: Reset links that reload the firewall after RED connected. 2013-08-12 14:45:07 +02:00
Alexander Marx
debe3af564 Merge remote-tracking branch 'ms/firewall-new' into firewall 2013-08-12 13:30:45 +02:00
Arne Fitzenreiter
9e78ce6142 Merge remote-tracking branch 'origin/next' 2013-08-11 11:51:40 +02:00
Arne Fitzenreiter
0251dca9e8 core72: start ipsec only if enabled after update. 2013-08-11 09:46:16 +02:00
Arne Fitzenreiter
bdc9033f08 core72: allow to update "ovpn verify script".
Don't forget to readd this exclude to next core updater to prevent overwrite
the user ca at a openvpn update.
2013-08-11 09:40:54 +02:00
Arne Fitzenreiter
9d838dad03 core72: add ovpnmain.cgi to update. 2013-08-11 09:40:03 +02:00
Arne Fitzenreiter
93443c472f core72: stop/start squid while update. 2013-08-11 09:34:52 +02:00
Arne Fitzenreiter
b9c6c0ecd3 core72: add language files to update. 2013-08-11 09:33:25 +02:00
Arne Fitzenreiter
f2665db1ad snort: update to 2.9.5.3. 2013-08-10 20:10:00 +02:00
Arne Fitzenreiter
7bcfd0dd83 daq: update to 2.0.1. 2013-08-10 20:09:03 +02:00
Arne Fitzenreiter
ba47633494 snort: enable non-ether-decoder for ppp support. 2013-08-10 18:48:16 +02:00
Michael Tremer
bfcb3212dc OpenVPN verify: Fix login for RW clients with >= 2 spaces in name.
http://forum.ipfire.org/index.php?topic=8702.0
2013-08-10 11:10:39 +02:00
Alexander Marx
be9be7cb5b Forward Firewall: enabled /var/ipfire/optionsfw/settings in configroot 2013-08-09 14:13:10 +02:00
Alexander Marx
bc912c6e0c Forward Firewall: Version 0.9.9.2
1) Some changes in en.pl
2) DNAT now supports REJECT/DROP rules
3) Bugfix: comma in remark customservicegroup
4) improved installer
2013-08-09 14:12:39 +02:00
Alexander Marx
a60dbb4b6a Forward Firewall: added dmz-converter.
Also extended backup.pl script to support old backups. Now it is possible to restore old backups into new firewall. On restore, all config files of new firewall will be destroyed and the 4 converters will recreate them.
2013-08-09 14:12:37 +02:00
Alexander Marx
6397b6e789 Forward Firewall: deleted portfw from buildsystem 2013-08-09 14:11:56 +02:00
Alexander Marx
9efd8d1c7e Forward Firewall: delete old portforwarding from system and fix for wlan-firewall part 1 (loop) 2013-08-09 14:11:56 +02:00
Alexander Marx
5aa8edf6f7 Forward Firewall: some changes for ISO 2013-08-09 14:09:12 +02:00
Alexander Marx
30d80ed42a Forward Firewall: added p2p-block.cgi to apache2 2013-08-09 14:08:25 +02:00
Alexander Marx
5d7faa4518 Forward Firewall: First part of adding OUTGOING to th efirewall 2013-08-09 14:08:20 +02:00
Alexander Marx
45cfd81131 Forward Firewall: deleted 22-outgoingfwctrl 2013-08-09 14:08:14 +02:00
Alexander Marx
27f4a6b159 Forward Firewall: added converters for old exaccess rules and old rules from outgoingfw and old firewallgroups.
Also fixed a Bug: Day SUN was not checked when in rule-edit mode
2013-08-09 14:08:11 +02:00
Alexander Marx
7f9d1c3969 Forward Firewall: added p2protocols to /var/ipfire/forward/ for p2pblocking options 2013-08-09 14:08:10 +02:00
Alexander Marx
485aac6395 Forward Firewall: Deleted /var/ipfire/outgoing from /config/rootfiles/common/configroot 2013-08-09 14:08:08 +02:00
Alexander Marx
62fc851166 Forward Firewall: fixed 12 Bugs from forum.
1) Added more possible chars in remark: : / .
2) Added "Internet" to std networks to be able to define internetaccess
3) When renaming a custom address, the firewallrules get updated
4) Ports are now ignored when using GRE as Protocol
5) When saving a customservice, the cursor is now in first textfield
6) Added a customservices file to installation with predefined services
7) Added ESP as protocol
8) Fixed counterproblem
9) Dropdownboxes for customservices and groups now sorted
10) Firewallrules now sorted in right order
11) fixed a Bug when defining manual address in source and target, the hint message is no longer displayed
12) When defining an external access rule, the last forwardrule was deleted
2013-08-09 14:08:04 +02:00
Alexander Marx
9bdb6b5045 Forward Firewall: Deleted outgoingfw.cgi,outgoinggroups.cgi and xtaccess.cgi from /config/rootfils7common/apache2 2013-08-09 14:05:20 +02:00
Alexander Marx
adf41e6f37 Forward Firewall: removed outgoingfw.cgi from /config/rootfiles/core/66/filelists/files 2013-08-09 14:04:42 +02:00
Alexander Marx
c04f132d49 Forward Firewall: removed outgoingfwctrl from /config/rootfiles/misc-progs 2013-08-09 14:04:42 +02:00
Alexander Marx
231499fcc8 Forward Firewall: build iso with new firewall 2013-08-09 14:04:38 +02:00
Michael Tremer
111c99ddfa Forward Firewall: applied all changes as diff and added new files. Also deleted c files from xtaccess and setdmzholes.
Signed-off-by: Alexander Marx <amarx@ipfire.org>

Conflicts:
	config/backup/include
	lfs/configroot
	lfs/usb-stick
2013-08-09 14:02:02 +02:00
Michael Tremer
7323724196 squid: Fix two security issues.
* CVE-2013-4115
* CVE-2013-4123

http://www.squid-cache.org/Versions/v3/3.1/changesets/
2013-08-07 22:15:31 +02:00
Michael Tremer
52a2f02f41 Merge branch 'ddns-all-inkl' into next
Conflicts:
	config/rootfiles/core/72/filelists/files
2013-08-02 10:41:27 +02:00
Michael Tremer
592efb85b8 core72: Add strongswan update. 2013-08-01 19:42:03 +02:00
Michael Tremer
ae99d423b9 Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into strongswan-next 2013-08-01 18:24:03 +02:00
Michael Tremer
80002fe433 DDNS: Support for all-inkl.com.
Requested by Daniel Kovacs <daniel.kovacs@pleasuredome.org>.
2013-08-01 18:12:01 +02:00
Michael Tremer
cee75a0d96 tor: Don't ship torify.
This will need tsocks, which is not present on IPFire.
2013-07-31 19:22:00 +02:00
Michael Tremer
0830129a3c WUI: Add Tor menu entry. 2013-07-31 19:20:42 +02:00
Michael Tremer
ae4bf64b6a core72: Add updated firewall script. 2013-07-31 12:56:58 +02:00
Michael Tremer
d3f2ac3f5d torctrl: Add new binary to rootfiles. 2013-07-31 12:56:17 +02:00
Michael Tremer
13b5ce6e40 tor: Import CGI script. 2013-07-30 21:53:16 +02:00
Michael Tremer
295649ff27 tor: Configuration file updates. 2013-07-30 21:39:50 +02:00
Michael Tremer
ce33eb3e3b arm: New package.
Resource monitor for tor.
2013-07-29 21:29:34 +02:00
Michael Tremer
b312967ce3 tor: New package. 2013-07-29 21:29:34 +02:00
Michael Tremer
72417e2f7b Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into strongswan-next 2013-07-20 18:48:29 +02:00
Michael Tremer
6ab7955c31 Add IPsec ECP changes to core update 72. 2013-07-20 18:47:51 +02:00
Michael Tremer
6cdde6c0bb Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next 2013-07-20 18:47:36 +02:00
Michael Tremer
6b0a04c0f8 strongswan: Update to 5.1.0rc1. 2013-07-20 17:36:53 +02:00
Michael Tremer
4f64e2090f Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into strongswan-next 2013-07-20 12:51:26 +02:00
Arne Fitzenreiter
c92602f161 start core72. 2013-07-19 10:03:22 +02:00
Michael Tremer
0d33245b56 strongswan: Update rootfile. 2013-07-18 21:22:10 +02:00