mirror of
https://github.com/pfsense/pfsense.git
synced 2025-10-26 11:38:35 +00:00
Merge pull request #2826 from NOYB/VPN_/_OpenVPN_-_Remove_Personalizations
(cherry picked from commit 28ca20bb51)
This commit is contained in:
parent
cbcea7e182
commit
a592bb2774
@ -217,9 +217,9 @@ if ($_POST) {
|
||||
|
||||
list($iv_iface, $iv_ip) = explode ("|", $pconfig['interface']);
|
||||
if (is_ipaddrv4($iv_ip) && (stristr($pconfig['protocol'], "6") !== false)) {
|
||||
$input_errors[] = gettext("Protocol and IP address families do not match. You cannot select an IPv6 protocol and an IPv4 IP address.");
|
||||
$input_errors[] = gettext("Protocol and IP address families do not match. An IPv6 protocol and an IPv4 IP address cannot be selected.");
|
||||
} elseif (is_ipaddrv6($iv_ip) && (stristr($pconfig['protocol'], "6") === false)) {
|
||||
$input_errors[] = gettext("Protocol and IP address families do not match. You cannot select an IPv4 protocol and an IPv6 IP address.");
|
||||
$input_errors[] = gettext("Protocol and IP address families do not match. An IPv4 protocol and an IPv6 IP address cannot be selected.");
|
||||
} elseif ((stristr($pconfig['protocol'], "6") === false) && !get_interface_ip($iv_iface) && ($pconfig['interface'] != "any")) {
|
||||
$input_errors[] = gettext("An IPv4 protocol was selected, but the selected interface has no IPv4 address.");
|
||||
} elseif ((stristr($pconfig['protocol'], "6") !== false) && !get_interface_ipv6($iv_iface) && ($pconfig['interface'] != "any")) {
|
||||
@ -498,7 +498,7 @@ if ($act=="new" || $act=="edit"):
|
||||
'number',
|
||||
$pconfig['local_port'],
|
||||
['min' => '0']
|
||||
))->setHelp('Set this option if you would like to bind to a specific port. Leave this blank or enter 0 for a random dynamic port.');
|
||||
))->setHelp('Set this option to bind to a specific port. Leave this blank or enter 0 for a random dynamic port.');
|
||||
|
||||
$section->addInput(new Form_Input(
|
||||
'server_addr',
|
||||
@ -555,7 +555,7 @@ if ($act=="new" || $act=="edit"):
|
||||
'Description',
|
||||
'text',
|
||||
$pconfig['description']
|
||||
))->setHelp('You may enter a description here for your reference (not parsed).');
|
||||
))->setHelp('A description may be entered here for administrative reference (not parsed).');
|
||||
|
||||
$form->add($section);
|
||||
$section = new Form_Section('User Authentication Settings');
|
||||
@ -599,7 +599,7 @@ if ($act=="new" || $act=="edit"):
|
||||
'tls',
|
||||
'Key',
|
||||
$pconfig['tls']
|
||||
))->setHelp('Paste your shared key here');
|
||||
))->setHelp('Paste the shared key here');
|
||||
|
||||
if (count($a_ca)) {
|
||||
$list = array();
|
||||
@ -616,7 +616,7 @@ if ($act=="new" || $act=="edit"):
|
||||
} else {
|
||||
$section->addInput(new Form_StaticText(
|
||||
'Peer Certificate Authority',
|
||||
sprintf('No Certificate Authorities defined. You may create one here: %s', '<a href="system_camanager.php">System > Cert. Manager</a>')
|
||||
sprintf('No Certificate Authorities defined. One may be created here: %s', '<a href="system_camanager.php">System > Cert. Manager</a>')
|
||||
));
|
||||
}
|
||||
|
||||
@ -630,7 +630,7 @@ if ($act=="new" || $act=="edit"):
|
||||
} else {
|
||||
$section->addInput(new Form_StaticText(
|
||||
'Peer Certificate Revocation list',
|
||||
sprintf('No Certificate Revocation Lists defined. You may create one here: %s', '<a href="system_crlmanager.php">System > Cert. Manager > Certificate Revocation</a>')
|
||||
sprintf('No Certificate Revocation Lists defined. One may be created here: %s', '<a href="system_crlmanager.php">System > Cert. Manager > Certificate Revocation</a>')
|
||||
));
|
||||
}
|
||||
|
||||
@ -645,7 +645,7 @@ if ($act=="new" || $act=="edit"):
|
||||
'shared_key',
|
||||
'Shared Key',
|
||||
$pconfig['shared_key']
|
||||
))->setHelp('Paste your shared key here');
|
||||
))->setHelp('Paste the shared key here');
|
||||
|
||||
$cl = openvpn_build_cert_list(true);
|
||||
|
||||
@ -706,7 +706,7 @@ if ($act=="new" || $act=="edit"):
|
||||
$pconfig['remote_network']
|
||||
))->setHelp('IPv4 networks that will be routed through the tunnel, so that a site-to-site VPN can be established without manually ' .
|
||||
'changing the routing tables. Expressed as a comma-separated list of one or more CIDR ranges. ' .
|
||||
'If this is a site-to-site VPN, enter the remote LAN/s here. You may leave this blank if you don\'t want a site-to-site VPN.');
|
||||
'If this is a site-to-site VPN, enter the remote LAN/s here. May be left blank for non site-to-site VPN.');
|
||||
|
||||
$section->addInput(new Form_Input(
|
||||
'remote_networkv6',
|
||||
@ -715,7 +715,7 @@ if ($act=="new" || $act=="edit"):
|
||||
$pconfig['remote_networkv6']
|
||||
))->setHelp('These are the IPv6 networks that will be routed through the tunnel, so that a site-to-site VPN can be established without manually ' .
|
||||
'changing the routing tables. Expressed as a comma-separated list of one or more IP/PREFIX. ' .
|
||||
'If this is a site-to-site VPN, enter the remote LAN/s here. You may leave this blank if you don\'t want a site-to-site VPN.');
|
||||
'If this is a site-to-site VPN, enter the remote LAN/s here. May be left blank for non site-to-site VPN.');
|
||||
|
||||
$section->addInput(new Form_Input(
|
||||
'use_shaper',
|
||||
@ -776,14 +776,14 @@ if ($act=="new" || $act=="edit"):
|
||||
'custom_options',
|
||||
'Custom options',
|
||||
$pconfig['custom_options']
|
||||
))->setHelp('Enter any additional options you would like to add to the OpenVPN client configuration here, separated by semicolon');
|
||||
))->setHelp('Enter any additional options to add to the OpenVPN client configuration here, separated by semicolon');
|
||||
|
||||
$section->addInput(new Form_Select(
|
||||
'verbosity_level',
|
||||
'Verbosity level',
|
||||
$pconfig['verbosity_level'],
|
||||
$openvpn_verbosity_level
|
||||
))->setHelp('Each level shows all info from the previous levels. Level 3 is recommended if you want a good summary of what\'s happening without being swamped by output' . '<br /><br />' .
|
||||
))->setHelp('Each level shows all info from the previous levels. Level 3 is recommended for a good summary of what\'s happening without being swamped by output' . '<br /><br />' .
|
||||
'None: Only fatal errors' . '<br />' .
|
||||
'Default through 4: Normal usage range' . '<br />' .
|
||||
'5: Output R and W characters to the console for each packet read and write, uppercase is used for TCP/UDP packets and lowercase is used for TUN/TAP packets' .'<br />' .
|
||||
|
||||
@ -372,7 +372,7 @@ if ($act == "new" || $act == "edit"):
|
||||
'Description',
|
||||
'text',
|
||||
$pconfig['description']
|
||||
))->setHelp('You may enter a description here for your reference (not parsed). ');
|
||||
))->setHelp('A description may be entered here for administrative reference (not parsed). ');
|
||||
|
||||
$section->addInput(new Form_Checkbox(
|
||||
'block',
|
||||
@ -399,7 +399,7 @@ if ($act == "new" || $act == "edit"):
|
||||
'text',
|
||||
$pconfig['local_network']
|
||||
))->setHelp('These are the IPv4 networks that will be accessible from this particular client. Expressed as a comma-separated list of one or more CIDR ranges. ' . '<br />' .
|
||||
'NOTE: You do not need to specify networks here if they have already been defined on the main server configuration.');
|
||||
'NOTE: Networks do not need to be specified here if they have already been defined on the main server configuration.');
|
||||
|
||||
$section->addInput(new Form_Input(
|
||||
'local_networkv6',
|
||||
@ -407,7 +407,7 @@ if ($act == "new" || $act == "edit"):
|
||||
'text',
|
||||
$pconfig['local_networkv6']
|
||||
))->setHelp('These are the IPv4 networks that will be accessible from this particular client. Expressed as a comma-separated list of one or more IP/PREFIX networks.' . '<br />' .
|
||||
'NOTE: You do not need to specify networks here if they have already been defined on the main server configuration.');
|
||||
'NOTE: Networks do not need to be specified here if they have already been defined on the main server configuration.');
|
||||
|
||||
$section->addInput(new Form_Input(
|
||||
'remote_network',
|
||||
@ -415,7 +415,7 @@ if ($act == "new" || $act == "edit"):
|
||||
'text',
|
||||
$pconfig['remote_network']
|
||||
))->setHelp('These are the IPv4 networks that will be routed to this client specifically using iroute, so that a site-to-site VPN can be established. ' .
|
||||
'Expressed as a comma-separated list of one or more CIDR ranges. You may leave this blank if there are no client-side networks to be routed.' . '<br />' .
|
||||
'Expressed as a comma-separated list of one or more CIDR ranges. May be left blank if there are no client-side networks to be routed.' . '<br />' .
|
||||
'NOTE: Remember to add these subnets to the IPv4 Remote Networks list on the corresponding OpenVPN server settings.');
|
||||
|
||||
$section->addInput(new Form_Input(
|
||||
@ -424,7 +424,7 @@ if ($act == "new" || $act == "edit"):
|
||||
'text',
|
||||
$pconfig['remote_networkv6']
|
||||
))->setHelp('These are the IPv4 networks that will be routed to this client specifically using iroute, so that a site-to-site VPN can be established. ' .
|
||||
'Expressed as a comma-separated list of one or more IP/PREFIX networks. You may leave this blank if there are no client-side networks to be routed.' . '<br />' .
|
||||
'Expressed as a comma-separated list of one or more IP/PREFIX networks. May be left blank if there are no client-side networks to be routed.' . '<br />' .
|
||||
'NOTE: Remember to add these subnets to the IPv6 Remote Networks list on the corresponding OpenVPN server settings.');
|
||||
|
||||
$section->addInput(new Form_Checkbox(
|
||||
@ -589,7 +589,7 @@ if ($act == "new" || $act == "edit"):
|
||||
'custom_options',
|
||||
'Advanced',
|
||||
$pconfig['custom_options']
|
||||
))->setHelp('Enter any additional options you would like to add for this client specific override, separated by a semicolon. ' . '<br />' .
|
||||
))->setHelp('Enter any additional options to add for this client specific override, separated by a semicolon. ' . '<br />' .
|
||||
'EXAMPLE: push "route 10.0.0.0 255.255.255.0"; ');
|
||||
|
||||
// The hidden fields
|
||||
|
||||
@ -286,9 +286,9 @@ if ($_POST) {
|
||||
|
||||
list($iv_iface, $iv_ip) = explode ("|", $pconfig['interface']);
|
||||
if (is_ipaddrv4($iv_ip) && (stristr($pconfig['protocol'], "6") !== false)) {
|
||||
$input_errors[] = gettext("Protocol and IP address families do not match. You cannot select an IPv6 protocol and an IPv4 IP address.");
|
||||
$input_errors[] = gettext("Protocol and IP address families do not match. An IPv6 protocol and an IPv4 IP address cannot be selected.");
|
||||
} elseif (is_ipaddrv6($iv_ip) && (stristr($pconfig['protocol'], "6") === false)) {
|
||||
$input_errors[] = gettext("Protocol and IP address families do not match. You cannot select an IPv4 protocol and an IPv6 IP address.");
|
||||
$input_errors[] = gettext("Protocol and IP address families do not match. An IPv4 protocol and an IPv6 IP address cannot be selected.");
|
||||
} elseif ((stristr($pconfig['protocol'], "6") === false) && !get_interface_ip($iv_iface) && ($pconfig['interface'] != "any")) {
|
||||
$input_errors[] = gettext("An IPv4 protocol was selected, but the selected interface has no IPv4 address.");
|
||||
} elseif ((stristr($pconfig['protocol'], "6") !== false) && !get_interface_ipv6($iv_iface) && ($pconfig['interface'] != "any")) {
|
||||
@ -302,7 +302,7 @@ if ($_POST) {
|
||||
}
|
||||
|
||||
if (empty($pconfig['authmode']) && (($pconfig['mode'] == "server_user") || ($pconfig['mode'] == "server_tls_user"))) {
|
||||
$input_errors[] = gettext("You must select a Backend for Authentication if the server mode requires User Auth.");
|
||||
$input_errors[] = gettext("A Backend for Authentication must be selected if the server mode requires User Auth.");
|
||||
}
|
||||
|
||||
/* input validation */
|
||||
@ -695,7 +695,7 @@ if ($act=="new" || $act=="edit"):
|
||||
'Description',
|
||||
'text',
|
||||
$pconfig['description']
|
||||
))->setHelp('You may enter a description here for your reference (not parsed).');
|
||||
))->setHelp('A description may be entered here for administrative reference (not parsed).');
|
||||
|
||||
$form->add($section);
|
||||
|
||||
@ -721,7 +721,7 @@ if ($act=="new" || $act=="edit"):
|
||||
'tls',
|
||||
'Key',
|
||||
$pconfig['tls']
|
||||
))->setHelp('Paste your shared key here');
|
||||
))->setHelp('Paste the shared key here');
|
||||
|
||||
if (count($a_ca)) {
|
||||
|
||||
@ -739,7 +739,7 @@ if ($act=="new" || $act=="edit"):
|
||||
} else {
|
||||
$section->addInput(new Form_StaticText(
|
||||
'Peer Certificate Authority',
|
||||
sprintf('No Certificate Authorities defined. You may create one here: %s', '<a href="system_camanager.php">System > Cert. Manager</a>')
|
||||
sprintf('No Certificate Authorities defined. One may be created here: %s', '<a href="system_camanager.php">System > Cert. Manager</a>')
|
||||
));
|
||||
}
|
||||
|
||||
@ -753,7 +753,7 @@ if ($act=="new" || $act=="edit"):
|
||||
} else {
|
||||
$section->addInput(new Form_StaticText(
|
||||
'Peer Certificate Revocation list',
|
||||
sprintf('No Certificate Revocation Lists defined. You may create one here: %s', '<a href="system_camanager.php">System > Cert. Manager</a>')
|
||||
sprintf('No Certificate Revocation Lists defined. One may be created here: %s', '<a href="system_camanager.php">System > Cert. Manager</a>')
|
||||
));
|
||||
}
|
||||
|
||||
@ -767,7 +767,7 @@ if ($act=="new" || $act=="edit"):
|
||||
}
|
||||
}
|
||||
} else {
|
||||
$certhelp = sprintf('%s%s%s$s', '<span id="certtype">', gettext('No Certificates defined. You may create one here: '), '<a href="system_camanager.php">' . gettext("System > Cert. Manager") . '</a>', '</span>');
|
||||
$certhelp = sprintf('%s%s%s$s', '<span id="certtype">', gettext('No Certificates defined. One may be created here: '), '<a href="system_camanager.php">' . gettext("System > Cert. Manager") . '</a>', '</span>');
|
||||
}
|
||||
|
||||
$cl = openvpn_build_cert_list(false, true);
|
||||
@ -787,7 +787,7 @@ if ($act=="new" || $act=="edit"):
|
||||
'DH Parameter length (bits)',
|
||||
$pconfig['dh_length'],
|
||||
array_combine($openvpn_dh_lengths, $openvpn_dh_lengths)
|
||||
))->setHelp(count($a_cert) ? '':sprintf('No Certificates defined. You may create one here: %s', '<a href="system_camanager.php">System > Cert. Manager</a>'));
|
||||
))->setHelp(count($a_cert) ? '':sprintf('No Certificates defined. One may be created here: %s', '<a href="system_camanager.php">System > Cert. Manager</a>'));
|
||||
|
||||
if (!$pconfig['shared_key']) {
|
||||
$section->addInput(new Form_Checkbox(
|
||||
@ -802,7 +802,7 @@ if ($act=="new" || $act=="edit"):
|
||||
'shared_key',
|
||||
'Shared Key',
|
||||
$pconfig['shared_key']
|
||||
))->setHelp('Paste your shared key here');
|
||||
))->setHelp('Paste the shared key here');
|
||||
|
||||
$section->addInput(new Form_Select(
|
||||
'crypto',
|
||||
@ -876,8 +876,8 @@ if ($act=="new" || $act=="edit"):
|
||||
'Bridge Interface',
|
||||
$pconfig['serverbridge_interface'],
|
||||
openvpn_build_bridge_list()
|
||||
))->setHelp('The interface to which this tap instance will be bridged. This is not done automatically. You must assign this ' .
|
||||
'interface and create the bridge separately. This setting controls which existing IP address and subnet ' .
|
||||
))->setHelp('The interface to which this tap instance will be bridged. This is not done automatically. This interface must be assigned ' .
|
||||
'and the bridge created separately. This setting controls which existing IP address and subnet ' .
|
||||
'mask are used by OpenVPN for the bridge. Setting this to "none" will cause the Server Bridge DHCP settings below to be ignored.');
|
||||
|
||||
$section->addInput(new Form_Input(
|
||||
@ -885,7 +885,7 @@ if ($act=="new" || $act=="edit"):
|
||||
'Server Bridge DHCP Start',
|
||||
'text',
|
||||
$pconfig['serverbridge_dhcp_start']
|
||||
))->setHelp('When using tap mode as a multi-point server, you may optionally supply a DHCP range to use on the ' .
|
||||
))->setHelp('When using tap mode as a multi-point server, a DHCP range may optionally be supplied to use on the ' .
|
||||
'interface to which this tap instance is bridged. If these settings are left blank, DHCP will be passed ' .
|
||||
'through to the LAN, and the interface setting above will be ignored.');
|
||||
|
||||
@ -910,8 +910,8 @@ if ($act=="new" || $act=="edit"):
|
||||
$pconfig['local_network']
|
||||
))->setHelp('IPv4 networks that will be accessible from the remote endpoint. ' .
|
||||
'Expressed as a comma-separated list of one or more CIDR ranges. ' .
|
||||
'You may leave this blank if you don\'t want to add a route to the local network through this tunnel on the remote machine. ' .
|
||||
'This is generally set to your LAN network.');
|
||||
'This may be left blank if not adding a route to the local network through this tunnel on the remote machine. ' .
|
||||
'This is generally set to the LAN network.');
|
||||
|
||||
$section->addInput(new Form_Input(
|
||||
'local_networkv6',
|
||||
@ -919,8 +919,8 @@ if ($act=="new" || $act=="edit"):
|
||||
'text',
|
||||
$pconfig['local_networkv6']
|
||||
))->setHelp('IPv6 networks that will be accessible from the remote endpoint. ' .
|
||||
'Expressed as a comma-separated list of one or more IP/PREFIX. You may leave this blank if you don\'t want to add a ' .
|
||||
'route to the local network through this tunnel on the remote machine. This is generally set to your LAN network.');
|
||||
'Expressed as a comma-separated list of one or more IP/PREFIX. This may be left blank if not adding a ' .
|
||||
'route to the local network through this tunnel on the remote machine. This is generally set to the LAN network.');
|
||||
|
||||
$section->addInput(new Form_Input(
|
||||
'remote_network',
|
||||
@ -929,7 +929,7 @@ if ($act=="new" || $act=="edit"):
|
||||
$pconfig['remote_network']
|
||||
))->setHelp('IPv4 networks that will be routed through the tunnel, so that a site-to-site VPN can be established without manually ' .
|
||||
'changing the routing tables. Expressed as a comma-separated list of one or more CIDR ranges. ' .
|
||||
'If this is a site-to-site VPN, enter the remote LAN/s here. You may leave this blank if you don\'t want a site-to-site VPN.');
|
||||
'If this is a site-to-site VPN, enter the remote LAN/s here. May be left blank for non site-to-site VPN.');
|
||||
|
||||
$section->addInput(new Form_Input(
|
||||
'remote_networkv6',
|
||||
@ -938,7 +938,7 @@ if ($act=="new" || $act=="edit"):
|
||||
$pconfig['remote_networkv6']
|
||||
))->setHelp('These are the IPv6 networks that will be routed through the tunnel, so that a site-to-site VPN can be established without manually ' .
|
||||
'changing the routing tables. Expressed as a comma-separated list of one or more IP/PREFIX. ' .
|
||||
'If this is a site-to-site VPN, enter the remote LAN/s here. You may leave this blank if you don\'t want a site-to-site VPN.');
|
||||
'If this is a site-to-site VPN, enter the remote LAN/s here. May be left blank for non site-to-site VPN.');
|
||||
|
||||
$section->addInput(new Form_Input(
|
||||
'maxclients',
|
||||
@ -1157,7 +1157,7 @@ if ($act=="new" || $act=="edit"):
|
||||
'custom_options',
|
||||
'Custom options',
|
||||
$pconfig['custom_options']
|
||||
))->setHelp('Enter any additional options you would like to add to the OpenVPN server configuration here, separated by semicolon' . '<br />' .
|
||||
))->setHelp('Enter any additional options to add to the OpenVPN server configuration here, separated by semicolon' . '<br />' .
|
||||
'EXAMPLE: push "route 10.0.0.0 255.255.255.0"');
|
||||
|
||||
$section->addInput(new Form_Select(
|
||||
@ -1165,7 +1165,7 @@ if ($act=="new" || $act=="edit"):
|
||||
'Verbosity level',
|
||||
$pconfig['verbosity_level'],
|
||||
$openvpn_verbosity_level
|
||||
))->setHelp('Each level shows all info from the previous levels. Level 3 is recommended if you want a good summary of what\'s happening without being swamped by output' . '<br /><br />' .
|
||||
))->setHelp('Each level shows all info from the previous levels. Level 3 is recommended for a good summary of what\'s happening without being swamped by output' . '<br /><br />' .
|
||||
'None: Only fatal errors' . '<br />' .
|
||||
'Default through 4: Normal usage range' . '<br />' .
|
||||
'5: Output R and W characters to the console for each packet read and write, uppercase is used for TCP/UDP packets and lowercase is used for TUN/TAP packets' .'<br />' .
|
||||
|
||||
Loading…
Reference in New Issue
Block a user