Commit Graph

15815 Commits

Author SHA1 Message Date
Erik Fonnesbeck
3896d93ec5 Do this check earlier rather than later, instead of moving the interface_bring_down call. 2010-09-03 18:58:45 -06:00
Erik Fonnesbeck
0a28d38599 Revert "Rearrange function calls for wireless to prevent killing hostapd/wpa_supplicant at the wrong time."
This reverts commit e93385d06d.
2010-09-03 18:50:04 -06:00
Erik Fonnesbeck
fb2f0db170 Revert "Ticket #867. Do not destory interfaces other than preventing a loop for ppp interfaces during interface configuration."
This reverts commit 990fb7a9a9.
2010-09-03 18:49:32 -06:00
Erik Fonnesbeck
67e77adf47 Protect against wpa_supplicant dying when bringing down interfaces to change wireless regulatory configuration. 2010-09-03 17:42:39 -06:00
Ermal
b2a6623150 Ticket #873. Call write_config() before including file to avoid loosing already done modifications. While here do some code cleanup and formating to make it more readble. 2010-09-03 22:54:14 +00:00
Erik Fonnesbeck
e93385d06d Rearrange function calls for wireless to prevent killing hostapd/wpa_supplicant at the wrong time.
- Moved interface_wireless_configure call to after the new location of the interface_bring_down call to prevent it from killing hostapd and wpa_supplicant right after they start.
- Replaced the original interface_wireless_configure call with the call to the wireless cloning function so that the interface still exists soon enough in the function.
2010-09-03 16:50:40 -06:00
Ermal
e49a2031bd Ticket #843. Disable for now bringing down the interface unless we want to destroy it. While this is not all correct this seems to help alleviate problems when the parent is shared on cloned types. 2010-09-03 17:59:49 +00:00
Ermal
c12fb6cb54 Allow 1:1 rules to specify source and destination. This is almost the same as on Port Forward tab rules without protocol and ports. 2010-09-03 17:45:12 +00:00
Ermal
8fc0b2dcb8 Add missing break; 2010-09-03 17:28:11 +00:00
Ermal
90388e4812 Actually decode before writing to mpd.secret. Alos correct variable names. Discovered-by: Efonne(IRC) 2010-09-03 11:50:54 +00:00
Warren Baker
08d97c590f Added wiki help page for Tables and removed help link for Bogons (now included in Tables). 2010-09-03 11:47:16 +02:00
Ermal
2fc2902022 Base64 encode passowrd fields for safer operations. Suggested-by: Efonne(IRC) 2010-09-03 11:36:59 +00:00
Ermal
ce96805161 Upgrade user data too for new pppoe world. 2010-09-03 10:54:15 +00:00
Ermal
18de072801 Correct function name. Pointy-hat: jimp@ 2010-09-03 10:46:11 +00:00
jim-p
7e91b28a66 We no longer need system_usermanager_addcert.php, its redundant functionality has been merged with system_certmanager.php 2010-09-02 16:56:08 -04:00
jim-p
ad9b5c6783 Allow creating a user certificate, pre-fill some info, direct back to user edit screen if that is what led us here. If we are making a user certificate, give another choice to select a pre-existing certificate to associate with that user. 2010-09-02 16:50:15 -04:00
jim-p
b0884cde4a Adjust add link. 2010-09-02 16:50:14 -04:00
jim-p
c25f73ae85 Adjust the user manager to use cert references on the user instead of the actual certs. 2010-09-02 16:50:13 -04:00
jim-p
3554c9f05c When generating a user cert, put it in with the rest of the certificates and store a reference in the user. 2010-09-02 16:50:13 -04:00
jim-p
79e1ffedf1 Update sync code since CERT/CA have moved. 2010-09-02 16:50:12 -04:00
jim-p
0879599c4e Only allow a certificate to be deleted if it is not currently in use. 2010-09-02 16:50:11 -04:00
jim-p
dea989034a Remove two unused functions (now useless) and add a few more utility functions. 2010-09-02 16:50:11 -04:00
jim-p
d590fa20a9 Show was a certificate is used for, if anything. 2010-09-02 16:50:10 -04:00
jim-p
8fefb9dd22 Upgrade code to merge user certificates with normal certificates. 2010-09-02 16:50:08 -04:00
Warren Baker
395ba5d1af Remove obsolete Bogons files 2010-09-02 22:42:12 +02:00
Warren Baker
1c9ed80d24 Added missing Save message. 2010-09-02 22:24:44 +02:00
Warren Baker
6c474eb8d3 Remove redundant 'Show Bogons' link and added Bogons list to Diagnostics -> Tables while preserving the same download functionality. 2010-09-02 22:19:54 +02:00
Ermal
926677d428 These are obsolete now. 2010-09-02 17:33:26 +00:00
Vinicius Coque
f3ceee6eb9 Fix typo: s/write_confg/write_config/ 2010-09-02 14:11:28 -03:00
Ermal
6ae9f9b7f9 Upgrade code for pppoe. 2010-09-02 17:59:06 +00:00
Ermal
60b8b58091 Add my copyright. 2010-09-02 17:34:01 +00:00
Ermal
b1e2b044b2 Forgot to add the new file for pppoe. 2010-09-02 17:32:20 +00:00
Ermal
0e642c78b4 Make possible to run multiple instances of pppoe server. Not yet switched to mpd4. 2010-09-02 17:27:14 +00:00
Warren Baker
c73c126fda Bump 7.1 -> 8.1 2010-09-02 16:18:43 +02:00
Chris Buechler
00710912fc keep src-nodes the same as states, as it is by default. in some circumstances this can limit per-host connections 2010-09-02 03:09:43 -04:00
Scott Ullrich
4c4be113e0 Revert "Since IPFW is redirecting to the captive portal running on 127.0.0.1:"
This reverts commit d624c7902c.
2010-09-01 19:33:54 -04:00
Scott Ullrich
d624c7902c Since IPFW is redirecting to the captive portal running on 127.0.0.1:
65531 11375 1820680 fwd 127.0.0.1,8000 tcp from any to any in

We need to permit traffic from the Captive Portal interface to 127.0.0.1.  Otherwise the portal will not come up without a seperate rule allowing it or a allow all rule.

How to reproduce: Set your captive portal interface rule to allow traffic from its subnet to it's subnet.   IE: * OPT1 net * OPT1 net * * none

Try using the captive portal.   Now add in this commit and the portal should work without a dedicated user rule permitting traffic to 127.0.0.1.

The other solution is to change the IPFW fwd to redirect to the Captive Portal interface IP address in question but this is much easier and just as clean.
2010-09-01 18:52:24 -04:00
Ermal
00621aeefe Add even carp ips to the sloppy state filter rules of CP. 2010-09-01 21:52:53 +00:00
Erik Fonnesbeck
56c100ab34 Fix line endings on remaining files that did not have the same line endings as everything else. 2010-09-01 14:53:30 -06:00
jim-p
b4e6524c16 CA/CERT Move 2010-09-01 15:26:50 -04:00
jim-p
4e990e1e20 CA/CERT Move 2010-09-01 15:18:44 -04:00
jim-p
1e332e981c CA/CERT Move 2010-09-01 15:15:08 -04:00
jim-p
b9d959b9ed Bump version of config so upgrade code will run. 2010-09-01 15:06:44 -04:00
jim-p
9ad72e5e30 Moving certs and ca out from under system. Provide upgrade code to move existing certs. 2010-09-01 15:06:43 -04:00
Ermal
064e18072d And some safe belts to prevent wrong lines in inetd.conf 2010-09-01 16:42:47 +00:00
Ermal
680714775f Just take action when there is a file otherwise just call filter_reload. 2010-09-01 16:09:03 +00:00
Ermal
e847108459 Ticket #866 #632. Save old settings or actions to be taken for reconfiguring a route/vip on a tmp file and make use that information when apply settings buttons is clicked. This makes the gui behave as expected. 2010-09-01 15:51:38 +00:00
Ermal
8e0c376055 Ticket #568. Do not show the save/cancel buttons on the edit page of firewall rules if that are advanced options set. 2010-09-01 12:32:29 +00:00
Ermal
990fb7a9a9 Ticket #867. Do not destory interfaces other than preventing a loop for ppp interfaces during interface configuration. 2010-09-01 12:13:46 +00:00
Chris Buechler
5281b3e8e7 also include split_dns, as Cisco VPN clients won't query across the VPN without it. 2010-09-01 00:33:15 -04:00