Michael Tremer
fa8229546b
firewall: Extend rate limiting for ICMP error messages.
...
Fixes #10489 .
2014-03-04 14:14:54 +01:00
Michael Tremer
fbd8ac3c8c
Merge remote-tracking branch 'amarx/beta3' into next
2014-03-04 14:14:45 +01:00
Michael Tremer
8225c4fc98
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
2014-03-04 14:14:36 +01:00
Alexander Marx
7429ee78b6
Firewall: Fix oversized Textfields
2014-03-04 14:07:04 +01:00
Michael Tremer
0bda23f5a1
firewall: Add chain name to logged rules.
...
This helps us to debug faster where a packet has been dropped.
2014-03-04 12:38:13 +01:00
Michael Tremer
3bb4bb3fa1
firewall: Add rate limiting for LOG messages.
...
Fixes #10488 .
2014-03-04 12:36:52 +01:00
Alexander Marx
f620fa34df
Firewall: Fix Bug 10490 and broken colorization of tables in firewall groups
2014-03-04 11:37:58 +01:00
Arne Fitzenreiter
36c92ab00d
kernel: arm-multi: add marvel and allwinner support.
2014-03-04 07:07:31 +01:00
Michael Tremer
c39413f2d5
vdr: Add eepg plugin.
2014-03-03 16:41:13 +01:00
Michael Tremer
d1dee6c1a1
vdr: Add DVBAPI plugin.
2014-03-03 16:31:59 +01:00
Michael Tremer
ece4c8cdc3
vdr: Update to 2.0.5.
...
Stupid outdated websites...
2014-03-03 16:28:51 +01:00
Michael Tremer
fa49910fa8
vdr: Update to 2.0.4.
2014-03-03 13:50:37 +01:00
Michael Tremer
fb5132aa57
strongswan: Update to 5.1.2.
...
http://www.strongswan.org/blog/2014/03/03/strongswan-5.1.2-released.html
2014-03-03 12:27:09 +01:00
Michael Tremer
824dc93601
firewall: Add a trailing space to all log prefixes for better readability.
2014-03-02 22:50:29 +01:00
Michael Tremer
9f80e81072
firewall: rules.pl: Remove unused variable $time_constraints.
2014-03-02 22:46:17 +01:00
Michael Tremer
d98aa95a55
firewall: rules.pl: Replace some hardcoded chain names.
2014-03-02 22:44:26 +01:00
Michael Tremer
7bb66417fa
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
2014-03-02 22:38:09 +01:00
Michael Tremer
1c3044d72c
firewall: Resurrect port forwardings with different external ports.
2014-03-02 22:35:27 +01:00
Michael Tremer
292cad90f7
firewall: Telnet uses TCP
2014-03-02 20:48:58 +01:00
Michael Tremer
0e53d8a991
firewall: Make OpenVPN access also possible when INPUT policy is REJECT.
2014-03-02 20:40:00 +01:00
Michael Tremer
6e87f0aa53
firewall: Allow accessing port forwardings from internal networks.
2014-03-02 20:37:44 +01:00
Arne Fitzenreiter
cbc492f516
apache2: update to 2.2.26.
2014-03-02 19:44:26 +01:00
Arne Fitzenreiter
239f8188e2
rootfile updates.
2014-03-02 19:39:42 +01:00
Michael Tremer
8f4f4634df
firewall: rules.pl: Refactored entire script.
2014-03-02 18:23:28 +01:00
Michael Tremer
b05ec50ac9
firewall: rules.pl: Cleanup time constraints generation.
2014-03-01 20:20:56 +01:00
Michael Tremer
6178953be5
firewall: rules.pl: Cleanup rule generation.
...
Various perl coding errors that have been suppressed by "no warnings uninitialized"
have been fixed and lots of helper variables have been introduced to make
it much more clearer what the code is actually doing.
2014-03-01 19:54:14 +01:00
Michael Tremer
a2b3eba9f5
general-functions.pl: Fix wrong perl syntax.
2014-03-01 18:23:52 +01:00
Michael Tremer
1f9e7b53b7
firewall: rules.pl: Remove $command and introduce $IPTABLES.
2014-03-01 18:19:09 +01:00
Michael Tremer
8531b94ae0
firewall: rules.pl: Remove command line args parsing and rest from old debugging mode.
2014-03-01 18:07:39 +01:00
Michael Tremer
68d1eb1017
firewall: rules.pl: Introduce a more slink debugging mode.
2014-03-01 18:04:40 +01:00
Michael Tremer
97ab0569bd
firewall: rules.pl: Fix some coding style.
2014-03-01 17:54:22 +01:00
Michael Tremer
b57edbd8ec
firewall: rules.pl: Remove totally bloated debug mode.
2014-03-01 17:49:22 +01:00
Michael Tremer
13585cc922
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
2014-03-01 16:59:32 +01:00
Michael Tremer
5c3de120aa
openvpnctrl: Allow ICMP error messages to pass the transfer net.
2014-03-01 16:51:03 +01:00
Michael Tremer
a0a5c14f85
firewall: Make sure that only packets that go through the tunnel are passing OVPNBLOCK.
2014-03-01 16:44:05 +01:00
Michael Tremer
2513ae737d
firewall: Allow access to the entire GREEN/BLUE/ORANGE subnets.
...
This includes the firewall itself as well.
2014-03-01 16:04:01 +01:00
Arne Fitzenreiter
d0ff84a675
red: change mac address of nas0 device.
...
Traverse Technology has reported that ppp over atm-bridge is not working
because there is a bogus mac address at the virtual nas0 device.
2014-03-01 16:01:11 +01:00
Michael Tremer
bb3834231e
firewall: Sort order in which chains are initialized.
...
This has been some real trouble because multiple rules could
not be properly inserted into the rule chains in the kernel
because the chains did not exist, yet.
2014-03-01 15:02:42 +01:00
Michael Tremer
60fb533157
firewall: rules.pl: Don't reload custom firewall rules here.
2014-03-01 15:01:58 +01:00
Michael Tremer
1db04adbef
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
2014-03-01 14:19:26 +01:00
Arne Fitzenreiter
c6f96750ba
ffmpeg: prevent executable stack.
2014-02-28 16:09:45 +01:00
Arne Fitzenreiter
26685b0742
libmad: prevent executable stack.
2014-02-28 16:09:04 +01:00
Arne Fitzenreiter
82a4a102f3
Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next
2014-02-28 07:04:45 +01:00
Arne Fitzenreiter
6887597c04
kernel: enable rts5139 driver.
2014-02-28 07:02:14 +01:00
Michael Tremer
3e5e8a4a88
firewall: Fix firewall policy table if only RED, GREEN + BLUE are present.
2014-02-27 20:53:25 +01:00
Alexander Marx
800077a689
Firewall: Skip rules on boot when red has no ip
2014-02-27 19:42:47 +01:00
Michael Tremer
5a7491ffd6
QoS: Actually accept subnets everywhere.
2014-02-27 19:39:18 +01:00
Alexander Marx
5eee5a607e
QOS: IP-Addresses can now be simple IP-Address or IP-Address and subnet
2014-02-27 19:12:06 +01:00
Michael Tremer
b18dba57de
Merge remote-tracking branch 'alfh/feature_graph_constant_color' into next
2014-02-27 13:37:53 +01:00
Michael Tremer
015e243b0d
Merge remote-tracking branch 'alfh/bugfix_openbox_center' into next
2014-02-27 13:36:38 +01:00