Projet

Général

Profil

Statistiques
| Branche: | Tag: | Révision:

univnautes / etc / inc @ 0b857543

# Date Auteur Commentaire
0b857543 16 septembre 2014 18:13 Phil Davis

Fix #3866 Firewall Log Filtering

on master

7e7f07ae 12 septembre 2014 21:17 Ermal

This really does not need the =

e9a9e1a7 12 septembre 2014 21:17 Ermal

Remove wrongly used type

3d77ec5d 12 septembre 2014 19:49 Ermal

Ooops restore this

3b9ef0ef 12 septembre 2014 19:40 Ermal

Inverse the sense of the toggles to avoid configuration upgrades

16c02722 12 septembre 2014 19:34 Ermal

Actually use the new toggles

ac19d32a 12 septembre 2014 19:23 Ermal

Only for movile users

fa4e059e 12 septembre 2014 19:22 Ermal

Provide a first implementation of EAP-TLS authentication with IKEv2. It is a start and might not work on all cases

e373e4cd 12 septembre 2014 17:13 Ermal

Make this work properly and not throw out errors.

111bea0d 11 septembre 2014 23:22 Renato Botelho

Add a function to redirect to a page passing parameters through POST

415b71f1 11 septembre 2014 21:57 Ermal

Fixes #3666. Set the sysctl net.inet.icmp.reply_from_interface to 1 to use the incoming interface to send the icmp reply from. It uses another part of patch to pf to undo NAT if it was already performed before

77bf9d5e 11 septembre 2014 20:31 Ermal

Add security priviledge for new page

7a668bd8 11 septembre 2014 19:28 Ermal

Fix path to xml and make sure the parser will see the custom tags

8a2f80b2 11 septembre 2014 19:23 jim-p

Add pages missing from the Status > Traffic Graph privilege that are required for the full page to load

4889b4c0 11 septembre 2014 13:38 Renato Botelho

Merge pull request #1260 from DasTestament/master

7ab6ad70 10 septembre 2014 22:39 Ermal

Make use of the xml output from stroke leases command

9060f420 10 septembre 2014 22:02 Renato Botelho

Change is_port() to only validate a single port, we have is_portrange() for specific cases. Make necessary adjustments after check all is_port() calls. It fixes #3857

ed5fc757 10 septembre 2014 19:34 Ermal

Return something meaningful until the widget is made to work correctly

4881e5a9 10 septembre 2014 19:33 Ermal

Remove racoon references

e952906e 10 septembre 2014 19:23 Ermal

Remove traces of older implementation still present

3b977eff 10 septembre 2014 18:38 Ermal

Put some tuning on number of half open connection possible in one time.

816672f1 10 septembre 2014 18:36 Ermal

Provide some parallellizm on the IKESA lookups for heavy loaded boxes.

c966c7ec 10 septembre 2014 00:43 Ermal

Actually roll this back since it was a testing glitch

eadda967 10 septembre 2014 00:08 Ermal

Also here be more strict on checking to return proper result. (some missed from previous commit)

fe06990e 10 septembre 2014 00:04 Ermal

Also here be more strict on checking to return proper result

76e656ba 09 septembre 2014 22:55 Renato Botelho

Merge pull request #1273 from fsSnowboard/master

60ef0911 09 septembre 2014 22:53 Renato Botelho

Make sure dhclient is not running before start it, it fixes console interface setup when interface is using dhcpv4. It should also help #3482

d9d1bd20 09 septembre 2014 22:52 Renato Botelho

Implement a function to kill dhclient process, sometimes it takes a little time to die, so use a sleep(1) there

397e40d5 09 septembre 2014 22:50 Renato Botelho

find_dhclient_process() returns an int, not string

9e74f980 09 septembre 2014 22:30 Ermal

Be more explicit

9eb4257f 09 septembre 2014 22:26 Ermal

Correct log prepending value

f049d544 09 septembre 2014 22:12 Renato Botelho

Some device names are bigger now (eg vtnet, ixgbe, cxgbe)

38f5ac9b 09 septembre 2014 21:38 Ermal

Correct generating loglevels for startup through ipsec.conf

aa352bb3 09 septembre 2014 21:34 Tyler Turner

Fix minor typo to name and port range

Typo on the name of the FaceTime shape rule, and missing 1 from Google
Talk port range.

572f6ccc 09 septembre 2014 19:07 jim-p

Fix guess_interface_from_ip() to account for differences in netstat output. Fixes #3853

76fa9adb 09 septembre 2014 17:28 Ermal

Blah unconditionally set rightsourceip per https://forum.pfsense.org/index.php?topic=80300.0 Until pools can be supported properly.

b22ef160 09 septembre 2014 14:14 Renato Botelho

As pointed out by Ermal, VIPs should go first in the list since NAT is first match. Ticket #983

d629f1ca 08 septembre 2014 23:35 Renato Botelho

igmpproxy param -d doesn't like the space before optarg. Fixes #3852

a1b5f07b 08 septembre 2014 22:44 Ermal

Fixes #3664, actually make sense of this function to work properly

fa9667d2 08 septembre 2014 22:28 Ermal

Fixes #3823 Properly parse auth tags as variables

b5bef5dc 05 septembre 2014 01:27 Tyler Turner

Add more services and reorder

Add following shaping rules:
ARMA 3
WII
EA Origin
Games For Windows Live
Crysis 3
DeadSpace 2
DeadSpace 3
DragonAge2
MassEffect3
Facetime
Google Hangouts
TeamSpeak 3
Ventrilo
iTunes Rado
IMAP/S
POP3/S
SMTP/S
Apple Mobile Sync...

060c3ac0 02 septembre 2014 19:58 Renato Botelho

Fix subnet display for IPsec status. Ticket #3826

985ed11c 29 août 2014 15:09 Renato Botelho

Merge pull request #1258 from yarick123/master

56d23722 28 août 2014 13:32 Renato Botelho

Fix match for help pages privileges, it fixes #3777

2b7fb769 28 août 2014 00:42 Renato Botelho

Do not use regex to check filetype to avoid being wrong since . is a regex metachar. It fixes #3817

ae14317d 26 août 2014 22:42 Renato Botelho

Merge pull request #1255 from leleobhz/master

2cff71c4 22 août 2014 17:12 Renato Botelho

Take virtual IPs into consideration for automatic outbound NAT rules, it should now fix #983

b075c1e2 22 août 2014 14:28 Chris Buechler

delete the dhcpd.pid file before starting dhcpd. Fixes bug where on rare occasions a stale PID file could prevent dhcpd from starting until it's manually deleted.

c38764dc 20 août 2014 14:50 Dmitriy K.

fix #3515

bfe9c9e7 19 août 2014 20:32 jim-p

Move the fetching of a package's config file and additional files to separate functions, and then have the "xml" package button perform these so that it is not only a redundant copy of the "pkg" reinstall button. This can help ensure a package files are in a known-good state before other actions are performed, in case the deinstall would fail or behave erratically due to other files being missing.

17402c63 18 août 2014 22:33 Ermal

Correct the ipsec status pages to show proper information as needed.

5bce82b4 18 août 2014 22:13 Ermal

Correct processing and assignment on ikeid variable so it does the right thing

30c591d6 18 août 2014 21:53 Ermal

Use proper path to setkey now that ipsec-tools are not used anymore

fe12d7ea 18 août 2014 21:51 Ermal

Correct the functions for returning tunnel status to use strongswan status reports

c650b2f7 18 août 2014 21:18 Ermal

Allow HASH algorithms to be empty for phase2 in case the encryption one is AES-GCM

ae170e96 18 août 2014 12:25 Ermal

Do not allow duplicate subnet entries on left|rightsubnet specification since it will blackhole all traffic to that subnet when connection is setup as route

5d37d515 18 août 2014 12:18 Ermal

Do not accept proposal out of that configured even for IKEv2 even though there is no possibility in the GUI to set more than one proposal for Phase1 so far.

3b68ec45 18 août 2014 08:52 Ermal

Restore behaviour as with racoon to trigger tunnel startup from traffic that needs to go into the tunnel. Even related to Ticket #3806.

8bb47a46 15 août 2014 15:41 Ermal

Do not show errors from trying to delete a socket or similar

154298f1 14 août 2014 07:14 Chris Buechler

rightsourceip must be used with PSK+Xauth.

7f1b720f 14 août 2014 06:59 Chris Buechler

This is required for PSK+Xauth. I'll commit that clarification in a bit.
Revert "Revert "Fix assignment of tunnel IPs to mobile clients.""

This reverts commit 23ba08fc940b711f3b44551199890dc8e28a63b6.

3cb773da 14 août 2014 02:18 yarick123

cherry pic from 'hotfix/3347-Certificate_Authority_SAN_names_not_working':

bugfix #3347: Certificate Authority SAN names not working in 2.1

subjectAltName can be set only via configuration file - created three extra sections in openssl.cnf to use in case of existing subjectAltName....

23ba08fc 13 août 2014 11:52 Ermal

Revert "Fix assignment of tunnel IPs to mobile clients."
This normally is not needed since the attr plugin deals with all this.

This reverts commit 00311d6a841c0f6fc162ea11da06569f10220f5e.

1c70bdff 12 août 2014 23:11 Ermal

Actually disable this plugin for now. It was not really needed for solving the issues with IKEv1

b8137fc2 12 août 2014 20:03 Leonardo Amaral
  • Fix a typo mismatch in /etc/inc/dyndns.class for CloudFlare URL entry.
b462fc5e 11 août 2014 16:47 Renato Botelho

Move dhcp6c log to dhcpd.log, it fixes #3799

687d11a6 11 août 2014 14:44 Renato Botelho

Remove double defined 'localhost' on the list of networks to create outbound NAT rules. It should fix #3800

565908d2 11 août 2014 14:40 Renato Botelho

Do not create automatic outbound NAT rule for disabled openvpn servers and clients

00311d6a 11 août 2014 12:19 Chris Buechler

Fix assignment of tunnel IPs to mobile clients.

dc63467f 09 août 2014 00:09 Matt Smith

Fix #3798 - 'IPsec phase 2 pinghost is not used if the source IP should be a virtual IP address'

762e8cf9 08 août 2014 18:24 jim-p

Avoid a "Cannot use string offset as an array" error if the packages section of the config is missing.

bf8aab82 08 août 2014 15:40 Ermal

Correct this so the dpdaction is created properly as restart

9f6a5b50 07 août 2014 22:53 Ermal

Do a reload on the cofniguration which is better than update. Also let the keyingtries to 3 rather than forever to avoid problems on recovery.

0b5fc1d1 07 août 2014 20:53 Ermal

Change the logic of the vpn config generation to make connectivity more stable especially ipsec. Also for IKEv1 just generate the policies and only on traffic start them.

b31a2c76 07 août 2014 17:52 Ermal

Move the rekey to yes always to avoid issues.

959dc96b 07 août 2014 04:38 Chris Buechler

Per the dhcpd.conf man page and other documentation from ISC, mclt must not be defined on the secondary.

071f6059 06 août 2014 21:27 jim-p

Escape the individual dnsmasq advanced/custom options

f088b8cd 01 août 2014 22:52 Ermal

Do not try to rekey for IKEv1.

9b915686 01 août 2014 22:39 Ermal

Use a uniqid() to track phase2 entries to avoid confustion and various mistakes when modifying and editing them.

fa0a1411 30 juillet 2014 17:57 Matt Smith

Fix for #3785 - 'strongswan config being generated with ike SA lifetime set to value of ipsec SA lifetime'

63dd9f08 30 juillet 2014 00:28 Ermal

Remove even the config.cache from /tmp to avoid issues while here

9280a998 29 juillet 2014 17:59 Matt Smith

Fix #3781 - 'strongswan dpdtimeout value not generated correctly'

1f2acda1 23 juillet 2014 18:19 Matt Smith

Fix for bug 3769

1b37ae46 22 juillet 2014 18:13 Renato Botelho

Fix #983 - Add IP aliases subnets to interface subnet macro on GUI, since I'm here also fix not rules for PPTP clients macro.

ef74c9e4 21 juillet 2014 23:57 Renato Botelho

Concat var before call escapeshellarg

604623a1 21 juillet 2014 23:56 Renato Botelho

Make dhcpleases use unbound pid when it's configured

9d83d01f 21 juillet 2014 23:54 Renato Botelho

Fix shell script syntax, it should fix #3361

dd030de9 18 juillet 2014 19:18 Renato Botelho

Detect when protocol changes and invalidate session to get a new cookie with secure flag set according. It fixes #3714

639567b8 18 juillet 2014 18:21 Renato Botelho

Merge pull request #1247 from DasTestament/master

dca795b7 15 juillet 2014 16:34 Renato Botelho

Use cron.pid to get pid number and avoid kill minicron processes. It fixes #3757

375fce94 10 juillet 2014 04:56 Chris Buechler

use HTTPS for files.pfsense.org for update_bogons and priv_url in pkg-utils

a061ddb9 09 juillet 2014 07:07 Chris Buechler

no () around qlength here

c9a88bbd 08 juillet 2014 13:47 Chris Buechler

qlimit must be included here

971de1f9 08 juillet 2014 01:06 Renato Botelho

Convert almost all /sbin/sysctl calls to php functions

79cd8239 07 juillet 2014 17:52 Renato Botelho

Fix sysctl name

82f75815 07 juillet 2014 16:05 Renato Botelho

Add set_single_sysctl(), a wrapper to set_sysctl() to make it simple to set value of a single sysctl

ff23363d 07 juillet 2014 15:57 Renato Botelho

Add get_single_sysctl(), a wrapper to get_sysctl() to make it simple to get value of a single sysctl

42bb1bee 07 juillet 2014 13:42 Renato Botelho

Remove extra spaces and tabs

e7f65689 06 juillet 2014 21:25 Renato Botelho

Remove extra quote and fix syntax

64746cf6 05 juillet 2014 23:00 Chris Buechler

use HTTPS for dyndns providers that support it