Alexander Marx
debe3af564
Merge remote-tracking branch 'ms/firewall-new' into firewall
2013-08-12 13:30:45 +02:00
Arne Fitzenreiter
9d838dad03
core72: add ovpnmain.cgi to update.
2013-08-11 09:40:03 +02:00
Arne Fitzenreiter
f2665db1ad
snort: update to 2.9.5.3.
2013-08-10 20:10:00 +02:00
Michael Tremer
919a50208b
tor.cgi: Remove NoAdvertise option.
...
This does not make much sense with our setup.
2013-08-10 12:14:29 +02:00
Alexander Marx
9168da6fcc
Forward Firewall: deleted unused warning message regarding mac addresses
2013-08-09 14:50:09 +02:00
Alexander Marx
ab4fe66fc9
Forward Firewall: Network addresses are now allowed as source and the ip addressfield has now size 18.
2013-08-09 14:49:35 +02:00
Alexander Marx
43215686ce
Forward Firewall: changed rule coloring. Now whole field is colored instead of just borders. Back Button in firewall groups /hostgroups showed a white site
2013-08-09 14:49:35 +02:00
Alexander Marx
653a71b951
Forward FIrewall: Bugfix: When using predefined services in rulecreation, the rule was not applied. Bugfix: when in rulecreationpage and pressing "back" the site gets white.
2013-08-09 14:49:35 +02:00
Alexander Marx
6143bc300e
Forward FIrewall: BUGFIX: when setting outgoing to blocked and creating a rule, the last rule changes to "accept"
2013-08-09 14:49:35 +02:00
Alexander Marx
357b3fe80d
Forward Firewall: renamed IPFire to Firewall in SNAT area
2013-08-09 14:49:35 +02:00
Alexander Marx
4affc3e889
Forward Firewall: show default rule when input is empty
2013-08-09 14:16:42 +02:00
Alexander Marx
cb051c577c
Forward Firewall: language fixes on last rule in ruletable
2013-08-09 14:16:42 +02:00
Alexander Marx
34f30c5f92
Forward Firewall: set default options for optionsfw and minor change on optionsfw.cgi
2013-08-09 14:16:42 +02:00
Alexander Marx
2e99ab8bf8
Forward Firewall: added some javascript to automatically select radiobuttons when dropdowns are changed
2013-08-09 14:16:42 +02:00
Alexander Marx
b88c88291b
Forward Firewall: added some java Script to automatically select radiobuttons when dropdowns are changed. Some cleanup of the code
2013-08-09 14:16:40 +02:00
Alexander Marx
1ca546126e
Forward Firewall: deleted configfile "nat" in ovpnmain.cgi for portfw check. File "nat" no longer exists. Now the portfw rules are in file "config"
2013-08-09 14:15:33 +02:00
Alexander Marx
6584a984a0
Forward Firewall: just increased version number
2013-08-09 14:15:33 +02:00
Alexander Marx
595a90f003
Forward Firewall: The default rule table (at the end of Forward) shows only default values depending on the network configuration
2013-08-09 14:15:33 +02:00
Alexander Marx
f8bf364f0d
Forward Firewall: fixed check for already existing rules.
2013-08-09 14:15:33 +02:00
Alexander Marx
7326051edb
Forward Firewall: Updated outgoingfw-converter. redesign of the ruletable's defaultrules
2013-08-09 14:15:32 +02:00
Alexander Marx
4d2e7a35d9
Forward Firewall: some textalignment in last rule row
2013-08-09 14:15:32 +02:00
Alexander Marx
a648546338
Forward Firewall: added "default-rules-table" at the end of forward ruletable
2013-08-09 14:15:31 +02:00
Alexander Marx
b044bb0569
Forward Firewall: Bugfixes wrong interface in ruletable,when selecting alias firewall interface
2013-08-09 14:15:31 +02:00
Alexander Marx
fc83b09d43
Forward Firewall: some bugfixes
2013-08-09 14:15:31 +02:00
Alexander Marx
72586f0ff0
Forward Firewall: colorize ip addresses when possible in firewall groups. subnetmask now in cidr format
2013-08-09 14:15:31 +02:00
Alexander Marx
f1934a05ad
Forward Firewall: delted subnets from hosts in firewallgroups, colorized all ip-addresses from the firewall-groups if possible. Some minor changes in forwardfw.cgi
2013-08-09 14:15:31 +02:00
Alexander Marx
cb4439f394
Forward Firewall: Bugfix of last commit. Added "Interface" to source or target that uses "Firewall" interfaces
2013-08-09 14:15:31 +02:00
Alexander Marx
d4cb89d2d1
Forward Firewall: When using "Firewall" as source or target, the ruletable looks confusing. Theres "RED" in source and target. Now theres "INTERFACE RED".
2013-08-09 14:15:31 +02:00
root
43d8be093c
Forward Firewall: some language changes de.pl and en.pl as well as forwardfw.cgi and fwhost.cgi
2013-08-09 14:15:30 +02:00
Alexander Marx
1a8fde0e84
Forward Firewall: changed some names and added subnets to dropdowns
2013-08-09 14:15:30 +02:00
Alexander Marx
a0fb1099ef
Forward Firewall: Design changes
...
1) source has a new option "firewall" with dropdown for interfaces
2) source default networks->deleted IPFire, all ip's now in brackets
3) deleted warning message in Target that a mac is not usable
4) changes for "apply" button
5) in ruletable the protocol is now right beneath the ruletype column
6) changed target dropdown "INTERNET" to "RED"
7) renamed OpenVPN N-2N to OpenVPN Net-to-Net
8) set missing default firewall options
9) little changes on the en and de lang files
2013-08-09 14:15:30 +02:00
Alexander Marx
2af92cf5ac
Forward Firewall: added new line at bottom of all ruletables with the "final rule"
2013-08-09 14:15:30 +02:00
Alexander Marx
ac9e77e3ba
Forward Firewall: added missing fields to the converters (for dnat)
2013-08-09 14:15:30 +02:00
Alexander Marx
0ac6c61d37
UPNP: changed firewall chain from PORTFW to UPNPFW
2013-08-09 14:15:30 +02:00
Alexander Marx
c12392c0ef
Forward Firewall: removed NAT table and txt file.
2013-08-09 14:15:29 +02:00
Alexander Marx
4f3bd0ca20
Forward Firewall: changed layout of "apply-button" (after rules where changed. When using single hosts in rules, the prefix is no longer shown in the ruletable. Default settings for firewall-options changed
2013-08-09 14:15:29 +02:00
Alexander Marx
8442c93764
Forward Firewall: removed dmz from forwardfw.cgi
2013-08-09 14:15:29 +02:00
Alexander Marx
3b2ad4a1bd
Forward Firewall: moved "firewall default behaviour" from firewall page to firewall-options page. Some changes in languagefiles de and en.
2013-08-09 14:15:29 +02:00
Alexander Marx
533a2da388
Forward Firewall: reorganised ruletable layout
2013-08-09 14:15:29 +02:00
Alexander Marx
fb0ce57589
Forward Firewall: cleanup unused code
2013-08-09 14:15:28 +02:00
Alexander Marx
d9b691e18e
Forward Firewall: added checks if manual ip (src/tgt) is part of a OpenVPN to colour the rules accordingly
2013-08-09 14:15:28 +02:00
Alexander Marx
05d4f131e9
Forward Firewall: Implemented INPUT Firewall (extended external access)
...
Now you are able to define INPUT Rules on every interface ip
2013-08-09 14:15:27 +02:00
Alexander Marx
e1eef9d53e
Forward Firewall: BUGFIX: When creating DMZ Rules with MANUAL IP as source and afterwards editing the rule, the rule was copied and not just edited.
...
BUGFIX: When using SNAT (outbound) the rule does not seem to work. The NAT_SOURCE chain was on wron position in POSTROUTING
2013-08-09 14:13:12 +02:00
Alexander Marx
bac7013b21
Forward Firewall: BUGFIX - when using source Protocol and NO target protocol only the target protocol is shown in ruletable.(But rule is applied correctly)
2013-08-09 14:13:12 +02:00
Alexander Marx
04abd8d958
Forward Firewall: bugfix: counter failure when adding one host to more than 1 Group
2013-08-09 14:13:11 +02:00
Alexander Marx
eff2dbf833
Forward Firewall: changed sort-order to Sort::Naturally. This Perl Module will be available since core 68.
2013-08-09 14:13:11 +02:00
Alexander Marx
e3c589276a
Forward Firewall: if ipsec rw net is set to green subnet, the rules are colored green instead of purple
2013-08-09 14:13:11 +02:00
Alexander Marx
139a1ab947
Forward Firewall: removed devel-tags
2013-08-09 14:13:11 +02:00
Alexander Marx
6945e46310
Forward Firewall: rewrote portcheck routine in ovpnmain so that checks for portforwardingports are made against /var/ipfire/forward/nat instead of /var/ipfire/portfw/config
2013-08-09 14:13:11 +02:00
Alexander Marx
931e1fed53
Forward Firewall: added some plausi checks. Now it is checked if someone enters an manual ip address that is a openvpn client.
...
The colors are set correctly in ruletable when someone enters a manual ip which belongs to an IPsec Network, IPsec Roadwarrior (if iprange set) or openvpn n2n
2013-08-09 14:13:10 +02:00