Commit Graph

13270 Commits

Author SHA1 Message Date
Ermal LUÇI
face47a5e2 Revert "Disable this tunable for now. Ticket #4523"
This reverts commit 85a37985b1.
2015-05-27 16:14:19 +02:00
Ermal LUÇI
427d36b4a8 Ticket #4523 Major changes to how fsck is done.
Follow best practice of using fsck from FreeBSD rc.d/fsck script.
    This means run preen mode first and later on try forcefully to fix issues.

    Try to give as much information during boot on the status of the filesystem.

Follow best practice of using fsck from FreeBSD rc.d/fsck script.
This means run preen mode first and later on try forcefully to fix issues.

Try to give as much information during boot on the status of the filesystem.

Conflicts:
	etc/inc/services.inc
2015-05-27 10:51:38 +02:00
Ermal LUÇI
fc123231da Ticket #4523 Run fsck with -C flag and alway in foreground during bootup to prevent any issues that might schedule background mode. 2015-05-27 10:50:25 +02:00
Ermal LUÇI
85a37985b1 Disable this tunable for now. Ticket #4523 2015-05-25 14:25:26 +02:00
Chris Buechler
b96d67380f create /var/spool/lock on nano so tip works without hassles. Ticket #4532 2015-05-15 19:14:21 -05:00
Ermal LUÇI
b92af7ab20 Disable defering in pfsync which is used for active-active deployments not useble in FreeBSD. This should fix hangs reported on some machines wiht pfsync 2015-05-15 19:36:37 +02:00
Ermal LUÇI
380ae02017 Add some error checking to avoid warning during boot 2015-05-14 21:03:10 +02:00
Ermal LUÇI
3ce84694f9 Ticket #4652 actually return value as expected! 2015-05-01 22:36:44 +02:00
Ermal LUÇI
620c4df1bc Ticket #4235 put reply-to/route-to rules even for mobile-ipsec. 2015-05-01 21:55:56 +02:00
Ermal LUÇI
b514030704 Ticket #4651 Oops correct name of var 2015-05-01 21:09:32 +02:00
Ermal LUÇI
be8b480ed1 Fixes #4651 Assign a proper tracker for NEGATE rules 2015-05-01 21:07:46 +02:00
Ermal LUÇI
120acbae8c Fixes #4652 put workaround for bogus timestamp until real data are cosnumed. 2015-05-01 21:01:11 +02:00
Ermal LUÇI
afd0c1f2c9 Seems strongswan 5.3.0 has improved the situation on putting multiple phase2 on IKEv1 behaviour and it behaves even better with reqid not defined in config. 2015-04-30 22:53:00 +02:00
Ermal LUÇI
1e92a236f4 Revert "Use a dirty hack to make IKEv1 with multiple phase2 to work correctly with one IKE SA for each subnet"
This reverts commit 7d5add01e4.
2015-04-30 22:50:12 +02:00
Ermal LUÇI
6bc6a72766 Revert "Provide a description for the dirty hack to not come back scratching.... on it"
This reverts commit 6d7e7c0c5c.
2015-04-30 22:50:11 +02:00
Phil Davis
d7d6342c41 Fall back to getting local user pages and groups
if the groups could not be found from LDAP and there is a local user.
2015-04-27 09:09:40 -03:00
Ermal LUÇI
6d7e7c0c5c Provide a description for the dirty hack to not come back scratching.... on it 2015-04-24 17:33:18 +02:00
Ermal LUÇI
7d5add01e4 Use a dirty hack to make IKEv1 with multiple phase2 to work correctly with one IKE SA for each subnet 2015-04-24 17:30:50 +02:00
Ermal LUÇI
6ed34650a7 Is better to send the signal to starter rather than to charon directly. Starter manager charon properly. This should fix a lot of issues with configuration reloading that before sometimes did not work especially when changing phase2 entries 2015-04-24 16:54:51 +02:00
Ermal LUÇI
2334aff978 This was meant to remove duplicates here, even though charon will do by itself but better do it since it was meant to. 2015-04-23 20:16:37 +02:00
Ermal LUÇI
26b94b874f Merge manually pull request #1626 to this branch 2015-04-21 19:43:20 +02:00
Ermal LUÇI
e1bcb659be s/;/:/ 2015-04-21 19:40:11 +02:00
Ermal LUÇI
7b9d7eac04 Revert "Revert "Move to specifically specifying the ID type apart when an ip address to have strongswan do proper behaviour. Also for DynDNS names use the dns type id so strongswan does the resolving by its own.""
This reverts commit 4e8eacfd7c.

Conflicts:
	etc/inc/ipsec.inc
2015-04-21 19:39:11 +02:00
Jeremy Porter
3be781e759 Add new bios product id string 2015-04-20 18:26:34 -03:00
Ermal LUÇI
a75d1a5f01 Allow to configure new modes for phase1 according to RFC 5903 by manually merging pull request #1501 partially. While here preserve style. 2015-04-20 20:54:28 +02:00
Ermal LUÇI
905e115668 Fixes #4625, manual merge of pull request #1617 for RELENG_2_2 branch on fixing voucher disconnection. 2015-04-20 20:37:52 +02:00
Ermal LUÇI
1d839e6da6 Implement make bofre break feature avaliable on strongswan 5.3.0 useful for IKEv2. Fixes #4626 2015-04-18 10:35:51 +02:00
Ingo Bauersachs
0b884dd234 Make auth_get_authserver_list available to vpn.inc
This is a follow-up to PR #1613 and avoids a crash in this script at random times.
2015-04-17 10:16:09 +02:00
Ermal LUÇI
41ee551453 Fixes #4625 correct disconnection of users especially when called from xmlrpc code. 2015-04-16 20:17:18 +02:00
Ermal LUÇI
99d263f587 Merge pull request #1613 from ibauersachs/ipsec-mobile-eap-radius_2-2 2015-04-16 19:42:12 +02:00
Chris Buechler
ff3c14a510 Always do a filter reload in vpn_ipsec_configure to ensure the ruleset is
updated where necessary in every IPsec change scenario.
2015-04-16 12:34:46 -05:00
Renato Botelho
cc1f655f8e Remove boot_serial='yes' from loader.conf when serial is disabled, error introduced by me on commit 986e77a2ea 2015-04-16 12:15:05 -03:00
Phil Davis
98615a3156 Fix unbound warning when dnsallowoverride off and forwarding on
Reported in forum: https://forum.pfsense.org/index.php?topic=92437.0

The $ns array was being used further down, but if dnsallowoverride was off, the array never got created.
2015-04-16 07:32:18 -03:00
Renato Botelho
696b20ddaa Bump version to 2.2.3-DEVELOPMENT 2015-04-15 13:22:38 -03:00
Renato Botelho
a0990a91b1 Define var_path global key since it is being used in interfaces.inc, but it was not being declared anywhere 2015-04-15 10:07:14 -03:00
Ingo Bauersachs
d09155b684 Add support for EAP-RADIUS to IKEv2 Mobile Clients (Rel. 2.2) 2015-04-15 14:28:54 +02:00
Chris Buechler
4847615c9d Re-enable verification for selfhost since their chain issue is resolved. Ticket #4545 2015-04-14 22:50:32 -05:00
Chris Buechler
5d5fff6789 set forcesync to 1 by default for now, testing potential impact for Ticket #4523. 2015-04-14 21:55:50 -05:00
Chris Buechler
828f37aaaf Revert "Make forcesync default to the same behavior as freebsd rather than as intended for cf cards. People with issues on CF can enable the tunable"
This reverts commit 32e53d709f.
2015-04-14 21:52:05 -05:00
Ermal LUÇI
32e53d709f Make forcesync default to the same behavior as freebsd rather than as intended for cf cards. People with issues on CF can enable the tunable 2015-04-14 23:21:07 +02:00
Renato Botelho
1189757e91 Remove redundant/unused call to kldstat 2015-04-14 15:56:50 -03:00
Renato Botelho
8228109b6f Fix operator 2015-04-14 15:56:48 -03:00
Renato Botelho
3a644b618e Fix typo in variable name 2015-04-14 15:56:46 -03:00
Phil Davis
4b46e9b1bb Fix OpenVPN server listening on associated IPv6 address
As reported in forum https://forum.pfsense.org/index.php?topic=92174.0
If the ordinary interface is selected for an OpenVPN server and an IPV6 protocol is selected (e.g. UDP6) then al is good, the "local" line in the server1.conf is written with the primary IPv6 address of the interface.
If the interface has other associated VIPs (e.g. a CARP VIP) and the related IPv6 entry is selected as the OpenVPN server interface, then the "local" line was being omitted from server1.conf
Regardless of the IP address family, vpn_openvpn_server.php always writes the associated IP address into the settings key 'ipaddr' - which looks like a good and reasonable thing - we only want 1 IP address of some flavor to be remembered here.
This changes fixes openvpn.inc so it understands that $settings['ipaddr'] can be IPv4 or IPv6 as does the appropriate stuff with it.
2015-04-14 10:17:40 -03:00
Chris Buechler
31a810badf Don't remove all of /usr/local/libdata as obsolete files. User-installed
package contents may live there, factory default configs live there.
2015-04-13 19:51:24 -05:00
Robert Nelson
750695f54a Only initialize package's log if it doesn't exist 2015-04-13 11:01:49 -03:00
Robert Nelson
eb4a5192ae Remove obsolete logging code which is duplicated in system_syslogd_start() 2015-04-13 11:01:40 -03:00
Chris Buechler
9c6de8b8a0 bump to 2.2.2-RELEASE 2015-04-12 16:52:48 -05:00
Renato Botelho
c782b5867b Setup ADI boards to boot only using serial to avoid duplicated output when VGA redirection is enabled 2015-04-10 16:27:10 -03:00
Chris Buechler
eae4f953f6 Skip reflection rdrs where the interface doesn't have an IP. Ticket #4564 2015-04-09 00:34:59 -05:00