jim-p
|
127eb8e023
|
Add a toggle under System > Advanced on the misc tab to enable/disable debug mode for racoon.
|
2011-04-11 16:58:13 -04:00 |
|
jim-p
|
fbfd675a53
|
Add an IPsec xauth permission. Try to use the nologin shell first (just unlock the account). Ticket #1202
|
2011-04-08 08:59:50 -04:00 |
|
jim-p
|
02d9951153
|
Putting client-config-dir in the config is valid also for p2p_tls servers. Fixes #1417.
|
2011-04-08 08:28:31 -04:00 |
|
Ermal
|
9a36dc9d24
|
Resolves #1391. Bring back VPN auto rule disable advanced setting.
|
2011-04-06 18:22:27 +00:00 |
|
jim-p
|
ab75b4ee54
|
CRL is read in as an array now, so even in the imported config it will appear to be an array even though it can only have one value. Fixes #1358
|
2011-04-06 13:36:24 -04:00 |
|
jim-p
|
6177fd924c
|
Fixup text.
|
2011-04-06 13:14:50 -04:00 |
|
jim-p
|
557300a7eb
|
Actually re-parse the config if a valid config was not written. (Should help stop installs from blowing up on failed config upgrades). Save the bad config for inspection, and print a message to the console about what was done.
|
2011-04-06 12:55:32 -04:00 |
|
Ermal
|
4c613f8482
|
Correct error message for gateways to report down when the gateway is down and not high latency.
|
2011-04-06 14:59:30 +00:00 |
|
Ermal
|
19d9146637
|
Another sweep at keeping the default route always present when the default setup route is marked as down. This now adds checks for configuration where a defaultgw is not specified by the user but deduced automatically.
|
2011-04-06 14:58:27 +00:00 |
|
Ermal
|
262595f0d5
|
Unbreak inetd.conf generation to avoid entries containing Array entries. This gixes nat reflection and a spamming of the system with nc processes with wrong parameters.
|
2011-04-05 19:55:11 +00:00 |
|
jim-p
|
5b64e3369a
|
Fix variable name
|
2011-04-05 11:16:08 -04:00 |
|
Ermal
|
1d60ed9bb4
|
Try to always keep pfSense with a default gateway to avoid errors for service running from pfSense itself. Previously PBR should be configured for such services. While PBR is a better fix this at least keeps users from complaining in simple setups. Reported by many.
|
2011-04-04 11:09:06 +00:00 |
|
Ermal
|
f206afb57e
|
On interface ip change reload even igmpproxy. Reported-by: http://forum.pfsense.org/index.php/topic,34372.0.html
|
2011-04-04 10:32:55 +00:00 |
|
Ermal
|
056df2d9f0
|
Add -a to include all updaterrd.sh scripts running and also remove top killing since its not used anymore in stat gathering.
|
2011-04-04 10:24:57 +00:00 |
|
Ermal
|
d7f4030ad8
|
Fix indent.
|
2011-04-01 21:51:11 +00:00 |
|
jim-p
|
4936ff53df
|
Switch back to dev_mode so existing configs aren't broken by the other changes.
|
2011-04-01 14:11:33 -04:00 |
|
Ermal
|
bc78856172
|
Correct the conditional testing.
|
2011-03-31 17:52:01 +00:00 |
|
Ermal
|
57c448d034
|
Do not show the default queue selection for a queue that has child queues
|
2011-03-31 17:45:37 +00:00 |
|
Ermal
|
d1bd01fffb
|
Prevent non-numeric chars from being inputed on bandwidth field.
|
2011-03-31 17:39:01 +00:00 |
|
jim-p
|
857a4a7986
|
Use a different loop counter variable to avoid a name collision
|
2011-03-30 20:36:53 -04:00 |
|
Ermal
|
56a8bbf3af
|
Test for value present before using.
|
2011-03-30 22:21:13 +00:00 |
|
Ermal
|
d5b45febd6
|
Test for value present before using.
|
2011-03-30 22:13:55 +00:00 |
|
Ermal
|
ccf46756fd
|
Unset xmlrpcauth and not the first member of the array.
|
2011-03-30 21:49:51 +00:00 |
|
Ermal
|
cb0e3f8e7c
|
Check for function existence before calling it.
|
2011-03-30 20:58:02 +00:00 |
|
Ermal
|
47e5f74198
|
By default assume admin user and do not blindly copy the first user from the config.xml
|
2011-03-30 20:52:36 +00:00 |
|
jim-p
|
bfa992bc4e
|
Allow editing of CAs, so that imported CAs can have their private keys added later (mainly affected users upgrading from 1.2.3 and wanting to use the cert manager). Also, allow editing the CA's serial, since this shouldn't really be 0 for imported CAs, but the serial of the last cert that was made from this CA.
|
2011-03-30 16:37:45 -04:00 |
|
Ermal
|
b7d5a7bab8
|
Do not rely on first user being admin as this breaks in certain cases the XMLRPC authentication. TODO: pass username as argument too. This now can use the local system authentication settings as well.
|
2011-03-30 20:34:13 +00:00 |
|
Chris Buechler
|
176a282e33
|
clarify log
|
2011-03-30 15:56:27 -04:00 |
|
jim-p
|
a5187d4375
|
Check for "aes 256" as IPsec encryption type, not just rijndael.
|
2011-03-29 12:00:02 -04:00 |
|
jim-p
|
49bb5c074b
|
Add some upgrade code for IPsec mobile clients. Passes php -l but needs more testing.
|
2011-03-29 09:54:52 -04:00 |
|
Ermal
|
b0eaa10cda
|
Trim spaces out to avoid problems from explode.
|
2011-03-29 09:11:30 +00:00 |
|
Ermal
|
ad6df0b3ca
|
Add back gre allowing rules since they are needed.
|
2011-03-29 08:19:50 +00:00 |
|
jim-p
|
75c8044aa9
|
Allow TCP and UDP for DHCP failover traffic.
|
2011-03-28 13:51:35 -04:00 |
|
jim-p
|
c6dfd28923
|
In IPsec, s/mobileclients/client/, this was changed long ago in the config but not everywhere followed.
|
2011-03-28 12:17:41 -04:00 |
|
Warren Baker
|
8f587b1dbb
|
Correct PPTP Clients alias address. The PPTP server address was been utlized instead, which resulted in an incorrect firewall rule when 'PPTP Clients' was configured.
|
2011-03-28 16:46:57 +02:00 |
|
jim-p
|
17730d9d86
|
Only run conf_mount_rw here if there isn't another process going.
|
2011-03-26 17:33:15 -04:00 |
|
jim-p
|
974c5af729
|
Actually if /etc/sshd is already running, doing a conf_mount_ro() would be a bad thing, as the other process still expects rw.
|
2011-03-26 17:30:20 -04:00 |
|
jim-p
|
63e18082bb
|
Backing this out to see if it unbreaks NanoBSD upgrades with packages involved. Revert "Workaround for conf_mount_rw/ro during boot to only allow it to change at the start and end. Fixes #1279"
This reverts commit 548be1fd66.
|
2011-03-26 17:21:55 -04:00 |
|
Ermal
|
cd2c71fcf6
|
Make sure that there is a value before using it as a redirection.
|
2011-03-25 23:33:45 +00:00 |
|
Ermal
|
3b68081f5a
|
Make the return values on error consistent with the normal return value.
|
2011-03-25 22:44:13 +00:00 |
|
Ermal
|
2fe347eb72
|
Actually correctly report the timeleft in log messages. This is mostly cosmetic.
|
2011-03-25 22:33:52 +00:00 |
|
Ermal
|
3e404e0c6d
|
Make the two default page codes similar in regarding to redirurl in hope that when one voucher login succeeds it redirects to the url submmitted.
|
2011-03-25 22:04:26 +00:00 |
|
Ermal
|
351b699013
|
Correctly synchronize the db of vouchers from master. Also correctly write it to the files since before it is only allowed during bootup and not from xmlrpc.
|
2011-03-25 21:56:38 +00:00 |
|
Ermal
|
a34b8b3b77
|
Display the correct error page if vouchers are active or if normal CP is active when default provided forms are used.
|
2011-03-25 20:47:17 +00:00 |
|
Ermal
|
509e1202eb
|
Correct log messages to not display port twice.
|
2011-03-25 20:32:56 +00:00 |
|
Ermal
|
650b573bd8
|
Correctly handle aliases for the target on inetd rules. Otherwise bad parameters are passed to netcat(nc) and we DoS the host.
|
2011-03-25 18:45:25 +00:00 |
|
Warren Baker
|
d93ee937f2
|
Make sure to uses 'tables' in array.
|
2011-03-25 11:00:50 +02:00 |
|
Warren Baker
|
94aa3d215a
|
Remove legacy Bogons Privileges page and add Tables to Privileges.
|
2011-03-25 10:58:08 +02:00 |
|
Ermal
|
c8703797e5
|
Do not write ont rules anymore max-packets. This apparently was done by me in a previous commit, it helps with Ticket #636.
|
2011-03-24 17:34:26 +00:00 |
|
Ermal
|
2279a58782
|
Try to not stomp rule to each other. Reported-by: http://forum.pfsense.org/index.php/topic,34787.msg180186.html#msg180186
|
2011-03-24 15:27:52 +00:00 |
|