Age | Commit message (Collapse) | Author | |
---|---|---|---|
2002-10-08 | remove <0 checks on unsigned numbers. | Vincent Labrecque | |
ok henning@ | |||
2002-10-07 | -Wsign-compare clean | Daniel Hartmeier | |
2002-10-07 | Two cases of const-correctness and make one global local. | Daniel Hartmeier | |
2002-10-07 | set block-policy [drop|return] | Henning Brauer | |
drop is default, same behaviour as before support block drop to override a return policy | |||
2002-10-07 | support a generic return | Henning Brauer | |
block return in|out ... acts like return-rst on tcp, like return-icmp on udp and like an ordinary block on anything else ok dhartmei@ | |||
2002-10-07 | make return-icmp work for rules covering both v4 and v6 | Henning Brauer | |
-new field "return_icmp6" in pf_rule -parser accepts block return-icmp(ipv4-icmpcode, ipv6-icmpcode) ok and some input dhartmei@ | |||
2002-10-07 | use a new rule_flag PFRULE_RETURNICMP to decide wether to return-icmp or not | Henning Brauer | |
instead of just testing return_icmp > 0 ok dhartmei@ | |||
2002-10-07 | Add 'reply-to' to filter rules, similar to route-to, but applying to | Daniel Hartmeier | |
replies (packets that flow in the opposite direction of the packet that created state), used for symmetric routing enforcement. Document how route-to and reply-to work in context of stateful filtering. | |||
2002-10-06 | Move CHECK_ROOT into LOOP_THROUGH, gets rid of one macro and saves | Daniel Hartmeier | |
several lines, no functional difference. From Camiel Dobbelaar. | |||
2002-10-05 | Expand {} lists from left to right, so 'pass in from { a, b } to any' | Daniel Hartmeier | |
becomes '@0 pass in from a to any @1 pass in from b to any' instead of the other way around. Patch from Camiel Dobbelaar. | |||
2002-10-05 | Allow filtering based on IP header's tos field. | Daniel Hartmeier | |
2002-09-29 | much prettier; wgriffin@jtan.com | Theo de Raadt | |
2002-09-22 | little KNF: return(something) -> return (something) | Henning Brauer | |
2002-09-22 | fix linenumber counting in findeol, and simplify by ignoring the \ case, | Henning Brauer | |
that's already handled earlier. fast-forward on errnous lines partitially from camield@, parts result of a discussion with Mike ok frantzen@ dhartmei@ | |||
2002-09-22 | antispoof, take 2. | Henning Brauer | |
also block incoming packets with our own IP as src. discussion & help frantzen ok ho@ dhartmei@ frantzen@ | |||
2002-09-18 | fix Xr refs; frisco@blackant.net | Theo de Raadt | |
2002-09-17 | easier "self" implementation. | Henning Brauer | |
no functional changes ok pb@ | |||
2002-09-15 | set a netmask in the dynaddr case | Henning Brauer | |
noticed by <han@mijncomputer.nl> ok pb@ | |||
2002-09-14 | oooooooopsie | Henning Brauer | |
2002-09-14 | bit more clue in rdr/nat rules wrt address family examination | Henning Brauer | |
don't take the af from host_node structs based on interface lookups, most interfaces will have both IPv4 and IPv6 addresses. Most rdr/nat rules will at least have one IP address specified from whoch we take the af for the whole rule. The rare exceptional cases require the user to specify the af. ok frantzen@ | |||
2002-09-14 | Document -R default (10000); ok deraadt | Peter Valchev | |
2002-09-12 | check for calloc() failure; ho@ | Henning Brauer | |
2002-09-12 | antispoof [log] [quick] for [interface|interface_list] [af] | Henning Brauer | |
e. g. antispoof log quick for { dc0, dc1 } inet docs & regress coming ok pb@, frantzen@, deraadt@ also looked over kjell@, markus@, itojun@, dhartmei@ IPv6 help itojun@ finally, a long story finds its happy end here. | |||
2002-09-12 | rework netmask handling: | Henning Brauer | |
-don't set netmask in host token handler -clear netmask in ipmask() proper before setting it -in ifa_load(), also store interface's netmask and broadcast address -allow ifa_lookup() to return either the interface's IP address(es), network(s) or broadcast address(es) - not used anywhere yet. This implies that ifa_lookup() also returns the netmask now. -host() returns netmasks, too ok pb@, frantzen@, deraadt@ also looked over kjell@, markus@, itojun@, dhartmei@ | |||
2002-09-11 | signed vs unsigned from -pedantic. | Hakan Olsson | |
2002-09-11 | signed vs unsigned, some void * arithmetic, from -pedantic. niklas@ ok. | Hakan Olsson | |
2002-09-10 | socklen_t; cloder | Theo de Raadt | |
2002-09-08 | ansi pedantic. sync w/kame | Jun-ichiro itojun Hagino | |
2002-09-08 | be more clueful wrt address family in nat/rdr rules. | Henning Brauer | |
behaviour noticed by Paul de Weerd, thanks! ok dhartmei@ | |||
2002-09-08 | Fix -pedantic errors. | Hakan Olsson | |
2002-09-06 | remove Xr to photuris | Theo de Raadt | |
2002-09-06 | socklen_t and various other minor tweaks | Theo de Raadt | |
2002-09-06 | socklen_t | Theo de Raadt | |
2002-09-06 | support long names; henning ok | Theo de Raadt | |
2002-09-06 | assume that noone uses photurisd anymore. | Theo de Raadt | |
2002-09-06 | socklen_t | Theo de Raadt | |
2002-09-06 | bogus ; outside of function | Theo de Raadt | |
2002-09-06 | missing arg in a msglog(); silvio@big.net.au | Theo de Raadt | |
2002-09-05 | Without IDs wait until next step/retry to handle CERTREQs. This should | Hakan Olsson | |
make certificate auth work better with some clients, such as SSH Sentinel. | |||
2002-09-05 | Do not require the presence of subjectAltName in certificates used for | Hakan Olsson | |
IKE auth. Should make interoperating with for example FreeS/WAN easier (Pluto). | |||
2002-09-05 | Do not create SAs for transaction exchanges either. By niklas@ | Hakan Olsson | |
2002-09-03 | add strlcpy/cat for BSD/OS | Markus Friedl | |
2002-09-03 | CPI_RESERVED_MIN is not defined on KAME+BSD/OS; ok ho@ | Markus Friedl | |
2002-09-03 | use sig_atomic_t; cloder | Theo de Raadt | |
2002-09-02 | Fix parsing of port ranges in translation rules (port a:b -> port c:d). | Daniel Hartmeier | |
ok henning@ | |||
2002-09-02 | Make sure the interface specified with route-to/dup-to/fastroute exists | Daniel Hartmeier | |
and null-terminate the interface name. Found by Michael Wallis. ok henning@ | |||
2002-08-29 | need CPI_xx decls | Jun-ichiro itojun Hagino | |
2002-08-29 | size_t has to be casted to u_long on printing. | Jun-ichiro itojun Hagino | |
From: Martti Kuparinen <martti.kuparinen@iki.fi> | |||
2002-08-29 | Work around arguably correct OpenSSL behaviour and only ask for CRL | Hakan Olsson | |
checks when we actually have CRLs to check against. Problem pointed out by <sturm@sec.informatik.tu-darmstadt.de>. | |||
2002-08-23 | Initial support for MacOS X (v10.2 and later). | Hakan Olsson | |