Commit Graph

25080 Commits

Author SHA1 Message Date
Chris Buechler
05b7eef94f Only restore rrd.tgz where platform is appropriate, or RAM disk being
used, otherwise you're restoring a probably old backup file. Ticket #4531
2015-04-08 18:45:37 -05:00
Renato Botelho
fe29fe04d3 Add Super Micro C2758 to the list of known platforms 2015-04-06 15:21:25 -03:00
dneuhaeuser
946877fa28 small correction of relative paths to icons 2015-04-06 09:44:24 -03:00
Phil Davis
ed005b2000 Few minor text typos
Note that advertise is spelt with an "s" in other places in the GUI, so
making it consistent in services_ntpd - but maybe Americans do spell it
"advertize" these days?
2015-04-06 09:41:59 -03:00
PiBa-NL
5d7a0701d1 diag_sockets show sockets listening on localhost
this helps pick a free port for services using sockets bound to localhost, and helps determine if the service has at least started and bound the port without needing to go through all 'connected' sockets as well
2015-04-06 09:38:52 -03:00
Chris Buechler
38253ce6e5 Include additional subnets for RAs in radvd.conf. Ticket #4468 2015-04-04 20:36:13 -05:00
Chris Buechler
c5292060a4 Fix up Ticket #4504 implementation. Match config style with other areas. Use a config setting to disable, rather than enable, this functionality since it's enabled by default so the tag isn't necessary in the default config. Remove now unnecessary config upgrade code. 2015-04-04 19:52:10 -05:00
Chris Buechler
600b4c3bb8 fix type. Ticket #4504 2015-04-04 19:35:59 -05:00
Chris Buechler
bc395b180b Remove array_intersect_key here too, definitely not needed. add to obsoletedfiles 2015-04-04 00:23:09 -05:00
Chris Buechler
a8c07dc8e0 uploadbar dir no longer needed 2015-04-04 00:12:33 -05:00
Chris Buechler
7dff06c41d There is no longer any need to restrict protocols for IPv4+IPv6 rules, the appropriate ruleset is generated and problem scenarios that would otherwise break here are prevented by other input validation. 2015-04-04 00:06:02 -05:00
Chris Buechler
6986b70344 remove dead code, clean up excess white space a bit. 2015-04-03 23:57:48 -05:00
Ermal LUÇI
b9115c26dd Prevent empty addresses for being put in the ruleset. Ticket #4564 2015-04-03 20:32:49 +02:00
Ermal LUÇI
3d48d3c54b Ticket #4504 actually make it correct 2015-04-03 20:12:07 +02:00
Ermal LUÇI
5a2ebbb1e5 Upgraded configurations should keep the default configuration of bypassing lan from ipsec. Ticket #4504 2015-04-03 20:10:34 +02:00
Ermal LUÇI
491c76c802 Fixes #4504 Provide a newline to generate proper config 2015-04-03 20:08:55 +02:00
Ermal LUÇI
9b7ca37d12 Fixes #4504 use correct key index 2015-04-03 20:03:49 +02:00
Ermal LUÇI
534753890c Fixes #4504 Allow the bypass policy for LAN to be enabled and prevent traffic sent to lan ip to go to the ipsec tunnel 2015-04-03 19:59:23 +02:00
Ermal LUÇI
9bbc482102 Fixes #4259 Use proper variable to do calculations 2015-04-03 17:16:15 +02:00
Chris Buechler
490b6c4f53 Only use mobile clients PFS config with mobile ph2ent. Ticket #4538 2015-04-03 03:07:12 -05:00
Chris Buechler
8841c0fd98 disable SSL validation for selfhost since it fails. Ticket #4545 2015-04-03 02:35:25 -05:00
Chris Buechler
963621f294 enable ike_name for daemon facility as well, to add connection identifiers to logs. 2015-04-02 22:57:30 -05:00
Chris Buechler
83ccc8649b Use real interface here for dhcrelay v6. Ticket #4572 2015-04-02 19:46:10 -05:00
Chris Buechler
35ff72fa04 0 could be valid for hostname aliases too. Ticket #4573 2015-04-02 19:11:42 -05:00
Chris Buechler
052e4ee829 Don't omit hosts specified as "0". Ticket #4573 2015-04-02 19:07:15 -05:00
Phil Davis
a46212734a Bug #4566 Only route-to a gateway if it is not force_down
When generating policy-routing rules there was no check if a gateway had force-down set, so gateway with force_down set would still get policy-routing rules written for it, even if skip_rules_gw_down was enabled.
2015-04-02 13:40:18 -03:00
Chris Buechler
d985cfa679 call this RCC-VE rather than C2358 2015-03-31 20:32:41 -05:00
Chris Buechler
68e322065d Add a check for whether IPsec is enabled, so it doesn't spit out "IPsec
daemon not running or has a problem!" when IPsec isn't enabled.
2015-03-31 15:18:26 -05:00
jim-p
d6710783a2 Add SCTP to protocol list for filtering. 2015-03-31 15:05:09 -04:00
Ermal LUÇI
887f2517a3 Merge manually pull request #1593 2015-03-31 18:18:21 +02:00
jim-p
08c1db2dbf Fix encoding issues in Configuration History list. 2015-03-31 09:26:55 -04:00
jim-p
05a463843a Fix a few misc encoding issues in load balancer code. 2015-03-31 09:26:04 -04:00
Philip Hansen
807cdae39e Fixed minor spelling error 2015-03-30 11:50:05 -03:00
Chris Buechler
4f00900cdf Remove wireless cards from ALTQ-capable interfaces, since ALTQ is broken on wlandev in FreeBSD 10.x at the moment. Ticket #4406 2015-03-28 00:09:21 -05:00
Chris Buechler
e593bac7e0 add missing ) 2015-03-26 18:51:04 -05:00
Chris Buechler
72371a3d77 Include net.key.preferred_oldsa in the sysctl list, set to 0 (disable) so
it doesn't fall through to the default (1).
2015-03-26 16:56:01 -05:00
Gertjan
96e8a99926 Voucher messages using wrong config field name
https://forum.pfsense.org/index.php?topic=91168.msg505273#msg505273
$config['voucher'][$cpzone]['msgnoaccess']
and
$config['voucher'][$cpzone]['msgexpired']
do not exist.
These should be
$config['voucher'][$cpzone]['descrmsgnoaccess']
and
$config['voucher'][$cpzone]['descrmsgexpired']
2015-03-26 14:51:32 -03:00
Phil Davis
8e2a5adf50 RRD Graph Custom Tab display friendly description
The other tabs of Status:RRD Graphs put the friendly description of each interface into the drop-down list for selection.
This change makes the Custom tab do that also.
2015-03-26 13:28:08 -03:00
Phil Davis
383dd72d61 Always include general setup DNS servers in unbound.conf
when forwarding mode is on.
The General Setup setting "Allow DNS server list to be overridden by DHCP/PPP on WAN" has always been used in dnsmasq to ADD DHCP/PPP provided DNS servers to the list, while also keeping the DNS servers specified in General Setup. That behavior is needed if:
1) WAN1 static IP with upstream DNS server/s specified in General Setup and selecting the WAN1 gateway. WAN2 uses DHCP, DNS server received by DHCP from upstream. The user needs to tick "Allow DNS server list to be overridden by DHCP/PPP on WAN" to get the WAN2 DNS server to be used, but also wants the DNS server from General Setup to also be used.
2) WAN1 static IP, DNS server/s specified in General Setup. For whatever reason the user has also ticked "Allow DNS server list to be overridden by DHCP/PPP on WAN". In actual fact there are no WAN-style interfaces set to DHCP, so "allowing to be overridden" should not come into effect anyway - the DNS servers in General Setup should be used.
3) WAN1 DHCP, but the upstream DHCP does not give out any DNS server/s. "Allow DNS server list to be overridden by DHCP/PPP on WAN" is ticked. Again there are no DNS servers received via DHCP, so any "override" should not be invoked.

In all cases, it turns out that actually we want any General Setup DNS servers to be included in the DNS forwarder/resolver conf in addition to whatever (if any) DNS servers happen to be provided from a DHPC-WAN.

This change makes unbound behave that way - the same as dnsmasq already does.
2015-03-26 13:00:12 -03:00
Phil Davis
11fd072b11 Only list nameservers once in resolv.conf
I was on a test system and had an upstream DNS server IP specified in System-General Setup. WAN was setup with a static IP and a gateway to that upstream device. All good.
Then I also checked "Allow DNS server list to be overridden by DHCP/PPP on WAN" and changed WAN to be DHCP. It received by DHCP the same DNS server IP that already happened to be in General Setup (and the same gateway IP - not the issue here).
/var/etc/resolv.conf had the name server line twice with the same IP address - once from the DHCP acquired data, and once from the General Setup data.
I don't think it broke anything, but it does look odd.
This change makes sure that DNS servers from General Setup are only added to resolv.conf when they are not already there.
2015-03-26 11:23:38 -03:00
Phil Davis
6eb5191b7c Status DHCP Leases handle expire never
Note: We can let the code pass "never" (or any other unexpected stuff)
to adjust_gmt()
adjust_gmt() should anyway handle the case when strtotime() cannot
understand the input string and thus returns false. In that case we
return the input string as-is so it will be displayed as the time. That
way the user will see it and can report easily whatever other unexpected
char data was in the leases file.
It also prevents "false" (zero) being converted to the date-time string
and thus becoming the Unix epoch 1 Jan 1970 on the display.
Latest forum report of this kind of thing:
https://forum.pfsense.org/index.php?topic=90083.0
2015-03-26 11:08:45 -03:00
jim-p
3c3a3bf9c5 Eliminate the "this_device" test from the resync check in rc.openvpn.
It is not necessary to check, as the only times a gateway event should trigger the VPN to restart are when the current and new devices differ.
This also allows us to simplify the code a bit and eliminate some single-use variables.
See the discussion at 4aefcf9151
2015-03-25 10:40:50 -04:00
jim-p
d4d24d6a08 The logic of this test seems to be incorrect.
If the interface is the same, this test will fail, and that's the one case that should not need a resync.
The logic in this test has been flipped and reversed a few times over the years and without comments it's difficult to discern its true purpose.
2015-03-24 14:08:53 -04:00
Phil Davis
e0f5f6f487 Be consistent about Unbound service descriptive name
Forum: https://forum.pfsense.org/index.php?topic=91075.0

For DNS Forwarder (dnsmasq)
1) dnsmasq is the name of the service
2) DNS Forwarder is the text description

Make Unbound consistent with that, so that menu names and services status display and... work in the same way:
1) unbound is the name of the service
2) DNS Resolver is the text description
2015-03-23 11:50:43 -03:00
k-paulius
78317c2562 Use is_numericint() instead of empty() to check if value has been entered because empty() does not allow 0, which is a valid value. 2015-03-23 10:36:14 -03:00
k-paulius
0f7f6aa91f Make sure 'DHCPv6 Prefix Delegation size' is provided if 'Send IPv6 prefix hint' flag is checked to avoid generating invalid dhcp6c configuration file. 2015-03-23 10:36:08 -03:00
Phil Davis
4e34cdf3bf Handle release number in installer
This code just looked wrong. It was considering 10.1-RELEASE-p6 to be release number "1" and comparing it to "9".
These changes to do what it seems to intend. This will make that UFS+J stuff appear, if that is of any consequence.
2015-03-23 08:15:57 -03:00
Jose Luis Duran
c2b0382055 Use none instead of a whitespace in sshd_config
Use the `none` keyword instead of a whitespace to disable the FreeBSD version in sshd_config.
2015-03-20 16:04:11 -03:00
Chris Buechler
c1ef7cfb41 Add option for wireless standard "auto", to omit "mode" entirely from ifconfig. This shouldn't be necessary, but specifying mode has proven to trigger driver problems that don't exist if it's left unspecified (such as FreeBSD PR 198680). Chosing "auto" fixes ath(4) BSS mode issues otherwise preventing it from connecting. 2015-03-18 23:52:46 -05:00
Jared Dillard
57413f7fd1 change the location of jquery-ui images in each theme's css file 2015-03-18 14:07:43 -05:00