Arne Fitzenreiter
c955ae653a
Merge remote-tracking branch 'ms/dfs' into next
2019-03-30 16:55:35 +01:00
Michael Tremer
b6c60092db
openvpn: Remove subnet check for static pools
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-22 15:24:03 +00:00
Michael Tremer
ceaf0ef008
dnsforward.cgi: Add DNSSEC option to legend
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-18 17:26:16 +00:00
Michael Tremer
08ded6035f
dnsforward.cgi: Check DISABLE_DNSSEC checkbox when editing
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-18 15:36:04 +00:00
Michael Tremer
c31c8078cf
hostapd: Always enable 80 MHz channel width for 802.11ac
...
This is mandatory to support by all hardware and works well.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:36:03 +00:00
Michael Tremer
70a7c454af
hostapd: Automatically disassociate any clients with high error rates
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:36:03 +00:00
Peter Müller
5b4464a944
hostapd: make client isolation configurable via WebUI
...
hostapd supports client-isolation, but this feature could
not be configured via the WebUI so far. Since it might be
desired in public wireless networks, or even private ones,
it makes sense to provide a radio button to let the user
decide on.
Fixes #11974 .
Signed-off-by: Peter Müller <peter.mueller@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:34:06 +00:00
Stefan Schantl
7bf5b0f221
logs.cgi/ids.dat: Fixup processing dates from logfiles which contains a year
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:27:55 +00:00
Michael Tremer
3bc001dbf9
Update contributors
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-14 13:20:56 +00:00
Michael Tremer
01604708c3
Merge remote-tracking branch 'stevee/next-suricata' into next
2019-03-14 13:19:35 +00:00
Michael Tremer
beac548962
Update list of contributors
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-11 15:58:45 +00:00
Michael Tremer
56947acb12
Merge remote-tracking branch 'ms/dns-forwarding' into next
2019-03-11 15:57:15 +00:00
Michael Tremer
8288c0394b
Merge remote-tracking branch 'ms/dhcp' into next
2019-03-11 09:53:56 +00:00
Peter Müller
04f9321955
Tor WebUI: drop relay bandwith options < 1 MBit/s
...
Tor requires at least 1 MBit/s in order to participate.
Fixes #12001
Signed-off-by: Peter Müller <peter.mueller@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-11 09:52:54 +00:00
Michael Tremer
025d8e6318
DNS Forwarding: Add UI to Allow to disable DNSSEC for a zone
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-05 16:10:17 +00:00
Michael Tremer
71a355c3a2
Merge branch 'ipsec-on-demand' into next
2019-03-05 15:25:36 +00:00
Michael Tremer
b15b70bc6b
vpnmain.cgi: Make on-demand mode default for IPsec VPNs
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-05 15:24:19 +00:00
Michael Tremer
eb09c90ef4
vpnmain.cgi: Carry over START_ACTION attribute correctly
...
This setting was not carried correctly and therefore the default was ignored.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-05 15:23:33 +00:00
Matthias Fischer
d50a78220d
Bug 12008 - Typo in 'proxy.cgi' leads to wrong path for 'basic_ldap_auth'
...
Hi,
This should fix https://bugzilla.ipfire.org/show_bug.cgi?id=12008
Best,
Matthias
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-02 14:13:17 +00:00
Michael Tremer
31672dc8bd
DHCP: Fix error when editing a newly added fixed lease
...
They key was remembered but then the array was sorted which resulted
the key showing a wrong line.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-26 16:33:46 +00:00
Michael Tremer
4eb23a9198
DHCP: Restart server in background
...
This allows for the CGI to return quicker.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-26 10:18:33 +00:00
Michael Tremer
820ab96c69
DHCP: Escape slashes in filename
...
Fixes : #12006
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-26 10:16:21 +00:00
Michael Tremer
f6a1d9e929
Update list of contributors
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-25 02:30:56 +00:00
Peter Müller
0675a66d83
update metrics links in Tor WebUI
...
https://atlas.torproject.org/ is deprecated in favour of
https://metrics.torproject.org/ by now.
Fixes #11781 .
Signed-off-by: Peter Müller <peter.mueller@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-25 01:02:59 +00:00
Stefan Schantl
d0f9526beb
ids.cgi: Add language string for ignored hosts section.
...
Fixes #12002 .
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-02-18 13:29:47 +01:00
Stefan Schantl
0d8cc90f4d
services.cgi: Show status of suricata instead of snort
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-02-15 12:18:45 +01:00
Stefan Schantl
5fbd7b2982
ids.cgi: Format and show date of the current ruleset again
...
Fixes #11992
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-02-07 10:33:29 +01:00
Stefan Schantl
ee7fe87ea6
ids.cgi: Change name of the button to apply the ruleset changes
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-02-07 09:46:01 +01:00
Stefan Schantl
dd8d6f5ee8
logs.cgi/ids.dat: Do not call the IDS snort again
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-02-07 09:00:35 +01:00
Stefan Schantl
5bd8940d68
ids.cgi: Improve showed messages while the IDS is working
...
Reference #11993
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-02-07 08:51:31 +01:00
Stefan Schantl
9074e3d74c
ids.cgi: Lock page while autoupdate script is running
...
Fixes #11991
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-02-07 08:24:15 +01:00
Stefan Schantl
5f2145eb59
ids.cgi: Show "Update Ruleset"-Button only if automatic updates are disabled
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-02-07 07:44:11 +01:00
Stefan Schantl
f6eb1a40a0
aliases.cgi: Handle suricata related actions when dealing with aliases
...
When working with aliases (adding/modifying/removing), the file which
contains the HOME_NET declarations needs to be re-generated and suricata
requires a restart afterwards.
Fixes #11990
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-02-06 15:59:02 +01:00
Stefan Schantl
613f58fbfa
ids.cgi: Check if the selected ruleset requires an oinkcode
...
Fixes #11983
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-02-06 12:49:01 +01:00
Stefan Schantl
f644a167ab
ids.cgi: Only perform actions when saving ruleset settings, if there are no error messages
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-02-06 12:48:08 +01:00
Stefan Schantl
422dc4caf9
ids.cgi: Fix HTML formated spaces.
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-02-05 14:34:44 +01:00
Stefan Schantl
9e9b477d7c
ids.cgi: Rework "Enable IPS" section
...
Just use one language string for a maximum of flexiblity for the
transloators.
Fixes #11986
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-02-05 14:17:19 +01:00
Stefan Schantl
cc9057c014
ids.cgi: Change lang string from "Activate IPS" to "Enable IPS"
...
Reference #11986
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-02-05 13:51:08 +01:00
Stefan Schantl
97870bf29c
ids.cgi: Stop suricata when the rulest source has been changed
...
If the ruleset source has been changed, it has to be configured again.
This happens because of different rule categories, filenames rule ID's etc.
In case suricata currently is running it has to be stopped and after the configuration
has been done by the user, it can be launched again.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-02-05 12:43:49 +01:00
Stefan Schantl
5709768b0b
ids.cgi: Fix downloading rules if source changed
...
Fix the if statement to detect wheater the ruleset has been
changed and automatically download the new one.
Fixes #11984 .
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-02-05 12:36:30 +01:00
Stefan Schantl
b7a9b4edc2
ids.cgi: Update automatic download texts
...
Update the showed texts in the dropdown box as mentioned in the
bug report.
Fixes #11985
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2019-02-05 12:13:28 +01:00
Michael Tremer
1e2b257789
Add routed IPsec connections to traffic graphs section
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
38f6bdb740
ipsec: Drop delayed restart setting
...
This is a very bad race-condition situation and is not solved by
an unintuitive setting.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
517683eeb1
ipsec: Drop VPN_IP setting
...
This is now a per-connection setting
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
ae0d069827
ipsec: Allow to select local IP address used for peer on UI
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
455fdcb17a
ipsec: Re-arrange inputs for peer addresses, subnets, etc.
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
7e25093d42
ipsec: Don't allow to select VTI in transport mode
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
605c391aaf
vpnmain.cgi: Don't populate GREEN subnet when green doesn't exist
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
216bd9b389
vpnmain.cgi: Move advanced IPsec settings to connection page
...
This is required to make the initial setup easier for GRE/VTI connections
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
f2d45a45ab
IPsec: Do not allow 0.0.0.0/0 as remote subnet
...
This renders the whole machine inaccessible
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00