summaryrefslogtreecommitdiff
path: root/sbin
AgeCommit message (Collapse)Author
2002-06-11Add -N, -RKjell Wooding
2002-06-11Add -N and -R options. When used in conjunction withKjell Wooding
pfctl -f <rulefile> they allow just the nat or filter rules to be reloaded, respectively. The default (no flags) is to load everything. If -N is specified, any existing filter rules are retained, similarly for -R. ok deraadt@, dhartmei@
2002-06-11sync with realityHenning Brauer
ok dhartmei@
2002-06-11KNF, remove function parameter namesDaniel Hartmeier
2002-06-11Remove parse_nat() prototype, it's gone. Yes, authpf is broken at theDaniel Hartmeier
moment.
2002-06-11Add $OpenBSD, license, include guards and remove one superfluousDaniel Hartmeier
prototype. From Chris Kuethe
2002-06-11print a string for UDP and OTHER state level instead of a numeric levelMike Frantzen
ok dhartmei@, henning@
2002-06-11SCRUB(fragcache) to do gap tracking and overlap pruning of IPv4 fragmentsMike Frantzen
without the memory overhead of the conventional defrag in SCRUB ok dhartmei@, idea by deraadt@
2002-06-11sync usage() with realityHenning Brauer
2002-06-11Make NAT proxy port range configurable per rule, for instance privilegedDaniel Hartmeier
source ports can mapped to privileged proxy ports, or source port 500 to proxy port 500. ok frantzen@
2002-06-11rework pfctl statistics displayHenning Brauer
move FCNT_NAMES from pfvar.h to pfctl_parser.h, only used by pfctl some input by nick@ ok frantzen@, dhartmei@
2002-06-10Merge the NAT and rules files into a single rulefile. Rules must beKjell Wooding
in this order, to remove any ambiguity about what order things happen in: scrub rules nat rules filter rules The -N and -R modifiers go away. Rulefiles are now loaded with the more POSIXly-correct '-f' ok frantzen@
2002-06-10print ethernet address; ok provos@, itojun@Markus Friedl
2002-06-10permit DNS name (they are considered RTF_HOST if specified as destination).Jun-ichiro itojun Hagino
PR 2152
2002-06-10CPIs cannot be selected from the same range as SPIs.Hakan Olsson
2002-06-10Zap a few remaining libkeynote refs.Hakan Olsson
2002-06-10kill __FUNCTION__Marc Espie
add __attribute__((format...) Fix one bad call. okay provos@
2002-06-10Allow ports to be specified in nat rules, useful later on for individualDaniel Hartmeier
proxy port ranges.
2002-06-10Remove mention of dynamic loadingHakan Olsson
2002-06-10The dlopen() stuff goes away.Hakan Olsson
2002-06-10Move enum out of struct (gcc 3.1 wasn't happy), from David KrauseDaniel Hartmeier
2002-06-10save some entropy in random key generation. oked by angelos many moons agoKjell Wooding
2002-06-10some olde version piece crept into my diffski; pt out by dfa@Michael Shalayeff
2002-06-10split scrub rule processing into its own yacc target,Kjell Wooding
for imminent config file merge. ok frantzen@
2002-06-09Make pf_nat.saddr/daddr a pf_rule_addr instead of pf_addr_wrap, so itDaniel Hartmeier
includes ports and operator.
2002-06-09rm trailing whitespaceTodd T. Fries
2002-06-09spaced out developers...Theo de Raadt
2002-06-09spelling; moritz@jodeit.orgTheo de Raadt
2002-06-09Print message for kern.mbstat (to use netstat)Angelos D. Keromytis
2002-06-09Document kern.mbstatAngelos D. Keromytis
2002-06-09Mark attr payload as handled. Also make sure the correct payloadHakan Olsson
length is returned.
2002-06-09Add list parsing in RDR rules: e.g.Kjell Wooding
rdr on $IFLIST proto tcp from $SRC_LIST to $DST_LIST port 21 \ -> 127.0.0.1 port 8021 ok dhartmei@
2002-06-09use strchr() instead of index()Theo de Raadt
2002-06-09Bad me. Make sure it compiles before commit.Hakan Olsson
2002-06-09CFG_REQUESTHakan Olsson
2002-06-09Style.Hakan Olsson
2002-06-09Missed this.Hakan Olsson
2002-06-09Tighten the code to work for both SET/ACK and REQ/REPLY modes.Hakan Olsson
2002-06-08Document new sysctls.Angelos D. Keromytis
2002-06-08Factor out hash operations, some other cleanup.Hakan Olsson
2002-06-08add cfg_typeHakan Olsson
2002-06-08nuke unused parameter af to expand_label_portHenning Brauer
ok dhartmei@, pb@
2002-06-08Change remaining read-only lookup tables to const, suggestion drahn@Daniel Hartmeier
2002-06-08comment on IPv6 link-local twistsJun-ichiro itojun Hagino
2002-06-08support IPv4 in -prefixlen.Jun-ichiro itojun Hagino
2002-06-08a bit more for the responder casesHakan Olsson
2002-06-08pf_timeouts is shared between pfctl and authpf, put it in the shared file.Dale Rahn
unbreak build.
2002-06-08- extended SMART support.Grigoriy Orlov
- style, typos. - Big part of program redesigned and become more clean and simple. Work done by Alexander Yurchenko <grange@openbsd.ru>. Readattr command implementation and some cleanups by me. Costa@ ok.
2002-06-08Fix cut & paste error from last commit.Grigoriy Orlov
2002-06-08add list expansion to src/dest in NAT rules. i.e.Kjell Wooding
nat on fxp0 from { 10.0.0.0/24, 10.0.1.0/24 } to \ { 172.6.1.1, 172.14.1.2/32 } -> fxp0 ok theo, dhartmei@