Ermal
620a0292bd
Optimization has nothing to do with limits
2013-07-25 13:13:10 +00:00
Renato Botelho
ef561db1f5
Fix #3106 , parse 'not' rules right on destination for port forward + reflection proxy rules
2013-07-25 09:29:26 -03:00
Phil Davis
06d6a54384
Allow advanced options state-related parameters to be used for TCP, UDP and ICMP
...
Allows the state-related parameters to be specified for UDP and ICMP as well as TCP. Discussed in forum http://forum.pfsense.org/index.php/topic,64653.0.html
2013-07-24 01:35:58 -07:00
N0YB
06ff126ebb
Update rrd.inc
...
Fix this error
php: rc.bootup: The command '/usr/bin/nice -n20 /usr/local/bin/rrdtool update /var/db/rrd/system-mbuf.rrd N:U:U:U:U:U' returned exit code '1', the output was 'ERROR: expected 4 data source readings (got 5) from N:U:U:U:U:U'
2013-07-23 22:15:01 -03:00
Ermal
dbb4e08918
Implement an option to allow using the IPv4 connectivity interface for sending the dhcpv6 information. Usually useful for ppp[oe] type links and some ISP
2013-07-23 09:49:24 +00:00
Warren Baker
33e2fb05ff
Add missing backup of gettytab
2013-07-22 09:25:15 +02:00
Renato Botelho
4fbe5be02b
Merge pull request #718 from N0YB/Advanced_DHCP_Client_Options
...
Fix required options syntax typo
2013-07-21 15:26:01 -07:00
N0YB
f669800cac
Fix required options syntax typo
2013-07-21 13:28:57 -07:00
N0YB
3e2ecafe4d
3652 days worth is a too much. Scale it back to more reasonable 1.25 x maximum used data (2284 days).
2013-07-19 22:32:56 -03:00
jim-p
d30232e230
Handle IPv6 in ip_in_interface_alias_subnet()
2013-07-19 09:39:29 -04:00
Renato Botelho
04498edb46
Merge pull request #714 from phil-davis/master
...
Minimize inclusion of bogonsv6
2013-07-19 05:58:55 -07:00
jim-p
dce51b017a
Disable the BEAST protection by default because the GUI *will* break if you use this and have a Hifn card installed. Others may break similarly. Change it into a checkbox option, off by default, and automatically disable it if a conflicting card has been detected.
2013-07-18 09:35:21 -04:00
Phil Davis
7f76f2df35
Minimize inclusion of bogonsv6
...
If "Allow IPv6" is on, but actually there is no enabled interface with "Block bogon networks" enabled, then we also do not need to include the bogonsv6 table into pf.
This allows some more flexibility for users to leave "Allow IPv6" checked, but still not use up memory for bogonsv6.
2013-07-18 05:10:46 -07:00
jim-p
845adb3549
Sync p0f database for OS detection w/current file from FreeBSD
2013-07-17 13:48:45 -04:00
jim-p
bcf4b8ccf6
Don't blow up the config if someone enters int'l chars in an LDAP attribute/DN field. Ticket #2227
2013-07-17 10:52:25 -04:00
jim-p
a5cd1c5a42
Add LDAP server options to control UTF8-encoding of parameters. Fixes #2227 . While I'm here, add a checkbox to prevent the stripping of @ from the LDAP username if the user wants the full name transmitted.
2013-07-17 10:13:08 -04:00
Renato Botelho
de8f007563
Call interface_ipalias_cleanup() after $interface is initialized, and get current IP after it
2013-07-16 16:31:34 -03:00
jim-p
3ed917c724
Add an RRD graph for MBUFs under system. Tweaks welcome.
2013-07-16 14:14:39 -04:00
jim-p
241eed1ab7
Don't generate reflection rules if reflection is disabled for that rule.
2013-07-16 09:53:31 -04:00
Ermal
4cc3bb6ce9
Do not break ppp type interfaces on v6
2013-07-16 12:52:24 +00:00
Ermal
15a73ba86d
For ppp interfaces the real interface is not present anymore in the xml config section of the interface. Due to this do some more work on extracting the real interface when ipv4 is pppoe/ppp/... and ipv6 configuration files will use the wrong interface to request information from provider. Reported-by: http://forum.pfsense.org/index.php/topic,64483.0.html
2013-07-16 07:47:28 +00:00
Ermal
2657f21f9e
Enable filtering on ipfw sysctl not dependent on ipfw module otherwise issue reported here http://forum.pfsense.org/index.php/topic,64412.0.html happens
2013-07-15 20:05:32 +00:00
Ermal
23c652cd21
Ignore errors/warnings from these calls
2013-07-15 14:02:17 +00:00
dhatz
ab17ed4e70
support mitigating BEAST attack
...
According to http://redmine.lighttpd.net/projects/lighttpd/wiki/Release-1_4_30
"...by setting
ssl.cipher-list = "ECDHE-RSA-AES256-SHA384:AES256-SHA256:RC4-SHA:RC4:HIGH:!MD5:!aNULL:!EDH:!AESGCM"
you can mitigate BEAST attacks."
2013-07-14 16:15:49 -04:00
Jim P
da60727cea
Merge pull request #712 from phil-davis/master
...
Correctly decide if dhcrelay (v4) is enabled
2013-07-14 11:23:22 -07:00
Phil Davis
4701c8de28
Correctly decide if dhcrelay is enabled
2013-07-14 09:15:05 -07:00
Jim P
6a4e4405e1
Merge pull request #711 from phil-davis/master
...
Teach services code about start stop restart of dhcrelay6
2013-07-13 11:50:29 -07:00
Phil Davis
9590e0de97
Teach service start stop restart about dhcrelay6
2013-07-13 09:18:36 -07:00
Phil Davis
54a9d71ddf
Consistent dhcrelay6 pid file location
2013-07-13 09:16:49 -07:00
Ermal Luçi
68bbaf061e
Merge pull request #710 from phil-davis/master
...
Start DHCrelay6 on boot
2013-07-13 08:01:59 -07:00
Renato Botelho
45eb8aeb58
Fix #3091 , fix bad var assignment
2013-07-13 11:41:58 -03:00
Phil Davis
06433d7524
Start DHCrelay6 on boot
2013-07-13 06:15:34 -07:00
Phil Davis
874f099a35
services_dhcrelay6_configure developerspew debug text fix
2013-07-13 05:49:03 -07:00
jim-p
e09b941d28
Move variable declaration to the top, declare it global before defining. Fixes #3090
2013-07-11 15:17:55 -04:00
jim-p
a5a2fc68d7
Remove irrelevant comment.
2013-07-11 15:17:54 -04:00
Ermal Luçi
5b0f719197
Fix copy/pasto introduced in previous commit.
2013-07-11 15:59:52 +02:00
jim-p
ac2035130d
Don't automatically add hidden rules to pass all IPv6 traffic to/from delegated prefixes. Default IPv6 from LAN -> any rule covers outbound properly as-is, and WAN rules shouldn't pass in that permissively. Also the prefix length calculation was off and the LAN rule(s) would be too permissive anyhow.
2013-07-10 15:49:02 -04:00
Ermal
7fb233997d
Implement proper releasing of pipes allocated based on CPzone. Keep track of which zone a pipe is and release those pipes during disabling/deleting of zone. Ticket #3062 , Pull request #698
2013-07-10 15:26:26 +00:00
Ermal
0f50d70d30
Use empty to cover all needed cases as suggested on #3062 . Suggested from pull request #698
2013-07-10 15:20:31 +00:00
Ermal Luçi
4624f50fce
Merge pull request #703 from razzfazz/dyndns_custom_v6
...
Add support for HE.net AAAA record updates. Fixes #1825 .
2013-07-10 08:01:59 -07:00
jim-p
1cf24f0aed
Add independent logging choices to disable logging of bogon network rules and private network rules. Add upgrade code to obey the existing behavior for users (if default block logging was disabled, so is bogon/private rule blocking). Also add a checkbox to disable the lighttpd log for people who don't want their system log spammed by lighty.
2013-07-09 12:02:19 -04:00
Renato Botelho
dd042c5159
Implement URL Table aliases for ports instead of IP addresses
2013-07-08 12:38:37 -03:00
Daniel Becker
da40615d09
Add support for custom IPv6 DDNS.
2013-07-07 15:40:16 -07:00
Daniel Becker
b4319c50f7
Change separator as per JimP's request.
2013-07-07 15:28:35 -07:00
Daniel Becker
66185fc79a
Merge branch 'master' into dyndns_custom_v6
2013-07-07 14:45:22 -07:00
Daniel Becker
d7e6f57368
Clean up HE.net AAAA backend support.
2013-07-07 14:44:05 -07:00
Daniel Becker
b4025ccd10
Add backend support for HE.net AAAA record updates.
...
Defines a new DynDNS provider 'he-net-v6' for updating AAAA entries on
dns.he.net.
2013-07-07 12:39:13 -07:00
Daniel Becker
14e9b0526f
Fix typo in filter.inc. Fixes #3028 .
...
Due to the typo, FilterIfList never got a 'track6-interface' entry,
which in turn prevented the DHCP6-related pass rules from being
generated for the LAN interface.
2013-07-07 11:22:18 -07:00
Evan Susarret
2740f12c50
Typo in configuration option
...
Should be 'leases', not 'mappings'.
2013-07-06 23:39:06 -04:00
Evan Susarret
64b299d87d
DHCP also update Dynamic DNS for static leases
...
Previously, Dynamic DNS is only updated for clients that get addresses from the DHCP address pool. Static mappings are ignored.
Adding this line updates Dynamic DNS for both static-mapped and dynamic DHCP clients.
2013-07-06 23:02:42 -04:00