Stefan Schantl
1ed8aedfdb
fwhosts.cgi: Fix fw-reload detection when adding new entries to a geoip group.
...
Read-in firewall config files for detection if the current group is used
by at least one firewall rule and mark the firewall to need a reload if
neccessary.
Fixes #10771 .
2015-03-15 11:41:50 +01:00
Stefan Schantl
93bfe63d55
Merge branch 'seventeen-geoip' into next-geoip
2015-03-15 11:38:45 +01:00
Dominik Hassler
e60cd3a404
use colour of destination network for DNAT
2015-03-13 14:33:47 +01:00
Michael Tremer
dfea4f86c2
strongswan: Allow using AES-GCM in various configurations
2015-03-11 18:13:25 +01:00
Bernhard Bitsch
ea40188f66
BUG10502: Fix wrong interfaces in firewall.log
...
Fix from BeBiMa
2015-03-11 13:53:36 +01:00
Michael Tremer
274ebe1d9d
Merge remote-tracking branch 'origin/master' into next
...
Conflicts:
config/rootfiles/packages/clamav
lfs/clamav
2015-03-04 23:58:47 +01:00
Michael Tremer
ea92da89c6
Merge remote-tracking branch 'amarx/BUG10756' into next
2015-03-03 21:13:46 +01:00
Christoph Anderegg
165b25b2dc
vpnmain.cgi: Added inclusion of ipsec.user-post.conf to the end of ipsec.conf in order to allow connection parameters to be overwritten in ipsec.user.conf.
2015-03-03 11:16:47 +01:00
Alexander Marx
5ca4ae11ae
BUG10756: fixes possibillity to enable logging when editing a rule. Also remark can be deleted
2015-03-02 15:33:44 +01:00
Alexander Marx
84a0531148
BUG10756: consolidate rulecheck
2015-03-02 15:20:32 +01:00
Alexander Marx
85abeb1376
BUG10753: Fix servicegroups to have only max. 15 services per protocol
2015-02-25 08:09:05 +01:00
Stefan Schantl
bc9446c65f
Merge branch 'master' of ssh://git.ipfire.org/pub/git/ipfire-2.x into seventeen-geoip
...
Conflicts:
make.sh
2015-02-14 12:34:31 +01:00
Stefan Schantl
c0a97a0f4a
firewall.cgi: Add support for GeoIP locations / GeoIP groups.
2015-02-08 18:41:44 +01:00
Stefan Schantl
e472a10de9
geoip-block.cgi: Use geoip-functions.pl.
2015-02-08 18:24:51 +01:00
Stefan Schantl
4313aa18e9
fwhosts.cgi: Add support for GeoIP groups.
2015-02-08 13:37:06 +01:00
Michael Tremer
de0ccf8f8c
Merge branch 'master' into next
...
Conflicts:
make.sh
2015-02-04 13:24:05 +01:00
Michael Tremer
fe53fa8dac
Merge remote-tracking branch 'ummeegge/lynis' into next
...
Conflicts:
make.sh
2015-01-28 22:49:36 +01:00
Arne Fitzenreiter
12f74b8f91
wlanap.cgi: remove trailing 0 from channellist.
2015-01-21 14:20:54 +01:00
Michael Tremer
f57a228c4b
ipsec: Allow IKE lifetime of up to 24 hours
...
Requested in #10722
The recommended time has not been changed, but it is often
stated that 24 hours is a common lifetime for IKE.
2015-01-19 17:04:37 +01:00
Michael Tremer
3906cf7e85
Merge remote-tracking branch 'amarx/vpn-statistic1' into next
2015-01-13 17:37:18 +01:00
Stefan Schantl
82bd80b387
ddns.cgi: Add support for token based auth for spdns.de.
2015-01-09 19:43:37 +01:00
Arne Fitzenreiter
8e23b35195
wlanap.cgi: add country code 00;
...
regdump not display this anymore.
2015-01-04 22:11:44 +01:00
Arne Fitzenreiter
2bb836df11
hostapd: change default channel to 6.
2015-01-04 20:17:26 +01:00
Stefan Schantl
192a8266e2
geoip-block.cgi: Requires firewall-lib.pl.
2015-01-04 14:07:06 +01:00
Stefan Schantl
593c32275a
Move "sub get_geoip_locations" to firewall-lib.
2015-01-04 01:03:21 +01:00
Stefan Schantl
91634dbe88
geoip-block.cgi: New CGI for managing geoip blocking.
2015-01-03 20:20:10 +01:00
Alexander Marx
87fe47e9d9
vpn-statistic: Move logfiles to /var/run because of flash writes
2014-12-23 12:43:49 +01:00
Michael Tremer
18f2b3d171
Merge remote-tracking branch 'ummeegge/OpenVPN_additional_configs' into next
2014-12-08 19:12:48 +01:00
Michael Tremer
1450cfebde
Merge remote-tracking branch 'ummeegge/OpenVPN_validating_N2N' into next
2014-12-08 19:12:39 +01:00
Erik Kapfer
badd8c1c63
OpenVPN_rand: Deleted pseudo-random generator option.
...
Deleted the -rand /proc/interrupts:/proc/net/rt_cache option in ovpnmain.cgi
Fix #10682
2014-12-06 13:03:59 +01:00
Erik Kapfer
f4fbb93510
OpenVPN: Added 'valid til (days)' field for N2N.
...
Fixes #10680
2014-11-13 10:40:42 +01:00
Erik Kapfer
ffbe77c8bc
OpenVPN: Added additional configuration for server and clients
...
* Added a possibility to manualy extend OpenVPNs server and client configuration.
* Added also a checkbox (on/off) in the WUI under 'Advanced server options' .
* Changed the order in 'Miscellaneous options' section for better overview.
* Optimized code in particular sections a little.
Added a filehandle instead of system(touch...) for ccd* file generation.
Unified the html code tags in processed section.
Fixes #10577
2014-11-13 03:09:51 +01:00
Matthias Fischer
8d29504c4d
snort: Update urls for rules download (2.9.7.0) in 'ids.cgi'
2014-11-05 19:20:59 +01:00
Alexander Marx
c9ac8b8052
vpn-statistics: change graphs and datatypes of rrd
2014-10-21 07:29:06 +02:00
Michael Tremer
478d8bb5da
Merge remote-tracking branch 'teissler/bug_10535' into next
2014-09-27 23:00:05 +02:00
Timo Eissler
1c4308c1f2
urlfilter.cgi: enhance file extension blocking
...
Fixes #10535
Add flv, mkv and mp4 as audio/video file exentions.
Add 7z as archive file extension.
2014-09-27 22:24:26 +02:00
Michael Tremer
0e6e5d46c1
Merge remote-tracking branch 'teissler/Bug_10415' into next
2014-09-27 20:43:23 +02:00
Timo Eissler
6ae884e5f9
urlfilter.cgi: safe search enhancements
...
Fixes : #10415
Activate bing safe search.
Add nwshp to google url patterns.
2014-09-26 22:15:13 +02:00
Michael Tremer
60bce6ba6a
Merge remote-tracking branch 'amarx/BUG10615' into next
2014-09-26 13:02:28 +02:00
Michael Tremer
b14e0f7d0e
Merge remote-tracking branch 'amarx/fw-checksubnet' into next
2014-09-26 12:59:26 +02:00
Michael Tremer
df6649b0fe
Merge remote-tracking branch 'amarx/firewall-dnat' into next
...
Conflicts:
config/firewall/rules.pl
2014-09-26 12:55:55 +02:00
Alexander Marx
0d0ee70f3b
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into vpn-statistic1
2014-09-26 12:53:05 +02:00
Stefan Schantl
34ebab463b
urlfilter.cgi: Fix path to squidGuard binary when converting custom blacklists.
...
Fixes #10626 .
2014-09-20 11:49:39 +02:00
Alexander Marx
d8cc443938
fw-groups: fix language strings
2014-09-19 13:44:20 +02:00
Alexander Marx
59c2888bae
BUG10617: Allow rules from local networks to firewall itself
2014-09-19 08:11:24 +02:00
Alexander Marx
5795fc1b55
vpn-statistic: added new statistic page for OpenVPN Roadwarrior
2014-09-18 16:29:10 +02:00
Stefan Schantl
9cc46b56ad
logs.cgi/ids.dat: Change url for snort sid details.
...
Fixes #10578 .
2014-09-16 20:37:16 +02:00
Alexander Marx
5751876534
BUG10615: fix wrong values in firewall.cgi
2014-09-11 15:10:48 +02:00
Alexander Marx
d8deec0b4f
BUG10615 part2: Add ratelimit to firewallgui
2014-09-11 13:59:54 +02:00
Alexander Marx
79ad6f7e53
BUG10615 part1: Add connectionlimit to firewallgui
2014-09-11 10:59:25 +02:00