Stefan Schantl
c1c754a121
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next-suricata
2019-02-08 09:59:31 +01:00
Peter Müller
e01e07ec8b
apply default firewall policy for ORANGE, too
...
If firewall default policy is set to DROP, this setting was not
applied to outgoing ORANGE traffic as well, which was misleading.
Fixes #11973
Signed-off-by: Peter Müller <peter.mueller@ipfire.org >
Cc: Michael Tremer <michael.tremer@ipfire.org >
Cc: Oliver Fuhrer <oliver.fuhrer@bluewin.ch >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-07 15:15:32 +00:00
Stefan Schantl
8117fff863
IDS: Call helper script when red interface gets up
...
The helper script will be automatically called when the red interface gets up
and will re-generate the HOME_NET file, to take care if the IP-address of this
interface has changed.
Fixes #11989
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-02-06 15:40:19 +01:00
Stefan Schantl
af0065691c
suricata: Do not display messages when starting up
...
Fixes #11979 .
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-02-05 13:57:40 +01:00
Stefan Schantl
c9b07d6a0c
initscripts/suricata: Generate firewall rules on start and reload
...
Fixes #11978
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-01-30 13:47:07 +01:00
Michael Tremer
17c2c09bcc
suricata: Scan outgoing traffic, too
...
Connections from the firewall and through the proxy must be filtered, too
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-01-29 14:08:51 +01:00
Stefan Schantl
c1a3401235
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next-suricata
2019-01-21 13:04:13 +01:00
Michael Tremer
f0092a6e3e
keepalived: Move change of conntrack sysctl option into package
...
The setting cannot be set on the default system because the ip_vs
module is not loaded by default and there is no reason to load it
just because we would be able to set the setting.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-13 12:50:26 +01:00
Michael Tremer
7d5caee6bd
Add initscript for conntrackd
...
The daemon will be started by default when a configuration
file exists.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-06 08:59:25 +00:00
Stefan Schantl
7b6f8596ed
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next-suricata
2018-12-28 07:36:59 +01:00
Michael Tremer
e978f0429f
keepalived: Fix incorrect path in initscript
...
This path to keepalived was just incorrect and therefore
the daemon could not easily be reloaded.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-19 23:38:48 +00:00
Michael Tremer
f33d28978d
unbound: Use correct parameter for IP addresses and hostnames
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-19 21:00:21 +01:00
Michael Tremer
c9ae511ecf
unbound: Allow forwarding to multiple servers at the same time
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-19 20:23:59 +01:00
Stefan Schantl
f5ad510e3c
suricata: Use "2" as repeat-mark and repeat-mask.
...
The previous used "1" was already used to mark source-natted
packets.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-12-17 15:04:48 +01:00
Michael Tremer
81e1e80e38
AWS: Prefer red* or eth* when importing configuration
...
This change is necessary to make sure that the script prefers
are link with internet access. That would usually be red (after
the second boot) or eth* (on the first boot).
That allows (and ensures) that we can install packages in
the user-data script.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-12 11:36:44 +00:00
Stefan Schantl
a13ddf04d9
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next-suricata
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-12-12 09:27:59 +01:00
Arne Fitzenreiter
23a3aec100
cpufrequtils: update initskript for xz compressed modules
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-12-07 21:05:50 +01:00
Arne Fitzenreiter
56726ed954
rngd: update initskript and add hwrngtty support
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-12-06 22:33:05 +01:00
Michael Tremer
93363446e4
AWS: Add a timestamp to user-data.log
...
This way, multiple (failed) runs of the script won't
overwrite the log file.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-05 14:42:54 +00:00
Michael Tremer
1022b203ad
AWS: Write user-data.log to /var/log
...
This should not be in /root at all.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-05 14:38:28 +00:00
Michael Tremer
a4e3a76af9
bird: Add initscript
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-01 16:13:25 +00:00
Michael Tremer
6dc7b04bea
shairport-sync: Add initscript
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-11-11 18:55:35 +00:00
Michael Tremer
95c60d31aa
udev: Do not try to change kernel hotplug handler any more
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-11-07 20:27:35 +00:00
Michael Tremer
e300a3d138
udev: Do no try to install any device nodes any more
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-11-07 20:26:34 +00:00
Michael Tremer
c19d29f701
Revert "haproxy: Make /dev/log available in chroot"
...
This reverts commit 699f0aa710 .
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-11-07 20:07:53 +00:00
Michael Tremer
9f60aa9679
syslog: Listen to network and block access from anywhere but localhost
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-11-07 20:07:53 +00:00
Michael Tremer
ed1349aa76
Merge remote-tracking branch 'ms/frr' into next
2018-10-31 09:31:38 +00:00
Michael Tremer
e1def10e29
frr: Set configuration file permissions correctly
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-10-30 17:32:48 +00:00
Michael Tremer
ebd6fe2b50
frr: Add initscript
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-10-30 17:27:28 +00:00
Michael Tremer
aeefbca730
clamav: Move database directory to /var partition
...
The clamav database is quite large and occupies valuable
space on the root partition that on older systems is only
2GB large. This change moves the virus definition database
to the /var partition which is larger and supposed to hold
data like this anyway.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-10-29 11:25:24 +00:00
Michael Tremer
699f0aa710
haproxy: Make /dev/log available in chroot
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-10-22 21:40:56 +02:00
Stefan Schantl
2d475a3c6c
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next-suricata
2018-09-26 14:49:34 +02:00
Michael Tremer
b8fdc7398c
static-routes: Make it clear that we are reloading routes
...
When RED is brought down, we will reload all static routes.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-09-13 15:03:59 +01:00
Michael Tremer
3da2a66193
aws: Don't update the system on first boot
...
This will violate AWS policy and therefore had to be removed.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-31 11:08:53 +01:00
Stefan Schantl
5f63067385
suricata: Fix initscript when using a single core machine
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-24 10:04:33 +02:00
Michael Tremer
95b87f39ac
localnet: Set FQDN without using domainname command
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-23 10:18:59 +01:00
Stefan Schantl
cb52183c6a
Fix merge conflicts during merge of next and the suricata branch
2018-08-23 10:34:17 +02:00
Michael Tremer
84cd9b9162
Drop the network-trigger script
...
This is done at boot time and doesn't normally need to be done again.
On AWS or in the setup, renaming any network interfaces is being
handled automatically.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-22 14:05:43 +01:00
Michael Tremer
f3d59d2c94
firstsetup: There is no need to restart udev here
...
All network interfaces are renamed accordingly in setup
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-22 14:02:43 +01:00
Michael Tremer
c5465a9453
aws: Let udev rename all network interfaces
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-22 14:00:39 +01:00
Stefan Schantl
55658ee381
suricata: Fix detection of enabled IDS on zone in initscript
...
I accidently commited the wrong file in the previous commit.
This is the fixed and working version.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-17 08:45:47 +02:00
Stefan Schantl
00a031145e
suricata: Give 644 permissions to the suricata pidfile
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-17 08:24:19 +02:00
Stefan Schantl
3c2c54831f
suricata: Add code to create iptables rules to the initscript
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-16 18:51:13 +02:00
Stefan Schantl
7c82ee6165
firewall: Add chains for IPS (suricata)
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-16 18:50:39 +02:00
Michael Tremer
046ef135e6
Merge remote-tracking branch 'origin/efi' into next
2018-08-16 12:49:13 +01:00
Michael Tremer
242cfc3395
localnet: Properly format and quote variables
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-16 12:42:25 +01:00
Michael Tremer
5b9f387d59
localnet: Correctly set domain name
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-16 12:41:52 +01:00
Michael Tremer
96422f85b6
aws: Hide pakfire update output
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-15 11:51:53 +01:00
Michael Tremer
40436fa149
aws: Write user-data log to file only
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-15 11:51:53 +01:00
Michael Tremer
281d75c945
aws: Execute reboot when an update requires one
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-15 11:51:53 +01:00