summaryrefslogtreecommitdiff
path: root/sbin
AgeCommit message (Collapse)Author
2002-06-10Move enum out of struct (gcc 3.1 wasn't happy), from David KrauseDaniel Hartmeier
2002-06-10save some entropy in random key generation. oked by angelos many moons agoKjell Wooding
2002-06-10some olde version piece crept into my diffski; pt out by dfa@Michael Shalayeff
2002-06-10split scrub rule processing into its own yacc target,Kjell Wooding
for imminent config file merge. ok frantzen@
2002-06-09Make pf_nat.saddr/daddr a pf_rule_addr instead of pf_addr_wrap, so itDaniel Hartmeier
includes ports and operator.
2002-06-09rm trailing whitespaceTodd T. Fries
2002-06-09spaced out developers...Theo de Raadt
2002-06-09spelling; moritz@jodeit.orgTheo de Raadt
2002-06-09Print message for kern.mbstat (to use netstat)Angelos D. Keromytis
2002-06-09Document kern.mbstatAngelos D. Keromytis
2002-06-09Mark attr payload as handled. Also make sure the correct payloadHakan Olsson
length is returned.
2002-06-09Add list parsing in RDR rules: e.g.Kjell Wooding
rdr on $IFLIST proto tcp from $SRC_LIST to $DST_LIST port 21 \ -> 127.0.0.1 port 8021 ok dhartmei@
2002-06-09use strchr() instead of index()Theo de Raadt
2002-06-09Bad me. Make sure it compiles before commit.Hakan Olsson
2002-06-09CFG_REQUESTHakan Olsson
2002-06-09Style.Hakan Olsson
2002-06-09Missed this.Hakan Olsson
2002-06-09Tighten the code to work for both SET/ACK and REQ/REPLY modes.Hakan Olsson
2002-06-08Document new sysctls.Angelos D. Keromytis
2002-06-08Factor out hash operations, some other cleanup.Hakan Olsson
2002-06-08add cfg_typeHakan Olsson
2002-06-08nuke unused parameter af to expand_label_portHenning Brauer
ok dhartmei@, pb@
2002-06-08Change remaining read-only lookup tables to const, suggestion drahn@Daniel Hartmeier
2002-06-08comment on IPv6 link-local twistsJun-ichiro itojun Hagino
2002-06-08support IPv4 in -prefixlen.Jun-ichiro itojun Hagino
2002-06-08a bit more for the responder casesHakan Olsson
2002-06-08pf_timeouts is shared between pfctl and authpf, put it in the shared file.Dale Rahn
unbreak build.
2002-06-08- extended SMART support.Grigoriy Orlov
- style, typos. - Big part of program redesigned and become more clean and simple. Work done by Alexander Yurchenko <grange@openbsd.ru>. Readattr command implementation and some cleanups by me. Costa@ ok.
2002-06-08Fix cut & paste error from last commit.Grigoriy Orlov
2002-06-08add list expansion to src/dest in NAT rules. i.e.Kjell Wooding
nat on fxp0 from { 10.0.0.0/24, 10.0.1.0/24 } to \ { 172.6.1.1, 172.14.1.2/32 } -> fxp0 ok theo, dhartmei@
2002-06-08remove macro concatenation via += per Theo's adviceHenning Brauer
2002-06-08allow macro concatenation likeHenning Brauer
webservers = "{ 10.0.0.1, 10.0.0.7, 10.0.0.8, " webservers += " 10.0.0.17, 10.0.0.25, 10.0.0.37 }" ok frantzen@, dhartmei@
2002-06-08Make state timeouts configurable per rule, likeDaniel Hartmeier
pass in from any to any port www keep state (tcp.established 60) ok frantzen@
2002-06-08expand $nr -> rule number in rule labelsHenning Brauer
okay dhartmei@, frantzen@
2002-06-08expand $proto in rule labelsHenning Brauer
okay frantzen@ dhartmei@
2002-06-07Handle realloc() failure gracefully. Terminates with err() anyway in thisDaniel Hartmeier
case, but we don't want to trigger "p = realloc(p," grepping causing false alarms here.
2002-06-07henning, read this to see what i mean by KNFTheo de Raadt
2002-06-07add the possibility to configure a TTL while return-rstPhilipp Buehler
ok dhartmei@, ipv6 part itojun@ ok
2002-06-07Avoid some gcc3 warnings. From David Krause <openbsd@davidkrause.com>Hakan Olsson
2002-06-07Add "(max <number>)" option for "keep/modulate state" to limit the numberDaniel Hartmeier
of concurrent connections a rule can create. ok frantzen@
2002-06-07Add wsconsctl recognition support for adb keyboard.Dale Rahn
2002-06-07Extend as per current IANA assignmentsHakan Olsson
2002-06-07Also allocate space for the attribute header.Hakan Olsson
2002-06-07Start for support of IKECFG in SET/ACK mode. Server side only so far.Hakan Olsson
2002-06-07allow using $srcaddr, $srcport, $dstaddr and $dstport in rule labels,Henning Brauer
evaluated at parse time. ok dhartmei@
2002-06-07minor KNF while I'm hereHenning Brauer
ok dhartmei@
2002-06-07make IPv6 scope identification work for dst (from any to fe80::1%lo0)Jun-ichiro itojun Hagino
2002-06-07support scoped IPv6 address in from/to portion.Jun-ichiro itojun Hagino
2002-06-07typoHakan Olsson
2002-06-07document net.inet6.ip6.v6onlyJun-ichiro itojun Hagino