summaryrefslogtreecommitdiff
path: root/sbin
AgeCommit message (Collapse)Author
2003-08-18catch max-mss values > 65535, report by Gregory SteuckDaniel Hartmeier
2003-08-18typos; ho@Markus Friedl
note that ping is still not working on -current; however, SA/SPD/flow setup works for testing isakmpd/ipsec on a signle machine.
2003-08-16more errx/warnx style \n errors; tom.cosgrove@arches-consulting.comTheo de Raadt
2003-08-11Dynamic select(2) support; deraadt@ OKTodd C. Miller
2003-08-09This patch remove the restriction that tables cannot be used in routing orCedric Berger
redirection rules... The advantage of using tables in redirection/routing rules is not efficiency, in fact it will run slower than straight address pools. However, this brings a lot of flexibility to PF, allowing simple scripts/daemons to add/remove addresses from redirection/routing pools easily. This implementation support all table features, including cidr blocks and negated addresses. So specifying { 10.0.0.0/29 !10.0.0.0 !10.0.0.7 } will correctly round-robin between the six addresses: .1, .2, .3, .4, .5, .6. Tables can also be combined with simple addresses, so the following rule will work as expected: "nat on foo0 -> { 1.1.1.1 <bar> }" ok henning@ mcbride@
2003-08-09new sentence, new line + small cleanup;Jason McIntyre
ok ho@
2003-08-08refer to RFCs consistently (RFC XXXX);Jason McIntyre
2003-08-08Be more careful when using constant_lookup() in messages. Pointed out byHakan Olsson
Jean-Francois Dive, although I opted for a slightly different patch.
2003-08-08Fine grained selectors for Linux native IPsec. From Jean-Francois Dive.Hakan Olsson
2003-08-07add missing tags and make this compile with debug.Federico G. Schwindt
2003-08-06Remove some double semicolons (hmm, do two semis equal a maxi?).Todd C. Miller
I've skipped the GNU stuff for now. From Patrick Latifi.
2003-08-06Remove an unused variable and plug a memory leak; Patrick LatifiTodd C. Miller
2003-08-06support ESP with cast/blowfish in KAME plattformsMarkus Friedl
2003-08-06support ESP with cast/blowfish on KAME platformsMarkus Friedl
2003-08-06ufs -> ffs as requested in pr3391. also rework part talking aboutTed Unangst
slices/partitions to have more openbsd flavor. ok jmc@
2003-08-05print info about procfs now that it's there to look atTed Unangst
2003-08-05better wording for the -y option;Jason McIntyre
ok fgsch@ tedu@
2003-08-04Not every suggested patch is perfect :)Daniel Hartmeier
ERRX() has two effects: the message printing and goto _error; which causes exit(1). While we don't want the message if pfctl was invoked with -n, we DO want to abort. Otherwise subsequent 'load anchor' statements will get executed, for instance, and the return value is handy for scripts.
2003-08-04nuke paragraph about snapshots. we don't support them.Federico G. Schwindt
henning millert ok.
2003-08-04don't whine about "cannot load ruleset" when ruleset load wasn't desiredHenning Brauer
(with pfctl -n) Jared Yanovich <phirerunner@comcast.net>
2003-08-04spelling, freebsd pr50979 via khalek on ircTed Unangst
2003-07-31Make table tickets per-ruleset instead of global.Cedric Berger
Make table tickets u_int32_t for consistency with other parts of PF. Ok dhartmei@ henning@
2003-07-31remove the old tree when we find a new ticket.Kenjiro Cho
this fixes printing obsolete (non-existent) queues. ok henning@
2003-07-30Remove my email address from my entry in the AUTHORS sectionTodd C. Miller
2003-07-30NULL -> (char *)NULL in execle; ok millert@Anil Madhavapeddy
2003-07-30change SIOCDIFADDR/SIOCAIFADDR warnings into errors (now this has correctPeter Valchev
return code in certain cases); ok henning itojun
2003-07-29more prettyTed Unangst
2003-07-29If euid == 0 make datasize unlimited instead of cranking to the maxTodd C. Miller
value returned by getrlimit(). Avoid resource limit issues when fscking very large filesystems.
2003-07-29Remove space at end of line.Cedric Berger
Ok dhartmei@ henning@
2003-07-29indentTheo de Raadt
2003-07-29spacesTheo de Raadt
2003-07-29off-by-one in a printf %sAnil Madhavapeddy
markus@ ok a while back
2003-07-28tweak;Jason McIntyre
ok tedu@
2003-07-28growfsTed Unangst
2003-07-28introducing growfs, compliments of freebsd. cleaned up slightly to obey knf.Ted Unangst
requests/oks from many.
2003-07-28rcsid should say openbsd. make 'em const while here.Ted Unangst
2003-07-25add sha2Markus Friedl
2003-07-25add sha2 support; ok ho@Markus Friedl
2003-07-25packet loss count in floating point (double). Wouter ClarieJun-ichiro itojun Hagino
2003-07-24conform to RFC2367 on SADB_xx naming (local name must be prefixed withJun-ichiro itojun Hagino
SADB_X_xx)
2003-07-24hmac-sha2-{256,384,512} support in AH/ESP auth. markus okJun-ichiro itojun Hagino
2003-07-24make packet loss double and print using %.1lf; based on diff from jeffi@rcn.comTheo de Raadt
2003-07-24pull header from hereTheo de Raadt
2003-07-23move junk (bad code, terrible APIs) to the only program that uses it;Theo de Raadt
millert ok
2003-07-21KNFHenning Brauer
2003-07-21ld needs -Z flag since W^X. from marius erikson in pr3360. ok drahn@Ted Unangst
2003-07-19Simplify struct pf_pooladdr to include struct pf_addr_wrap directlyCedric Berger
instead of indirectly trough struct pf_rule_addr. Ryan McBride says: If I'm not mistaken, the code _used_ to use the ports in pf_rule_addr as well. The code was changed to fix some of the bugs with port ranges, but it was too late in the release cycle to make kernel API changes, so the structure was left as is. Needless to say: KERNEL/USERLAND SYNC REQUIRED. ok henning@ mcbride@
2003-07-18Simplify handling of flags (-R, -N...). Remove PFCTL_FLAG_ALL.Cedric Berger
ok dhartmei@
2003-07-16new default frag/block sizes.Ted Unangst
reminded by millert@
2003-07-16remove default limit of 16 cylinders per group. it's now set toTed Unangst
as many as fit with the other parameters given. change default frag size to 2048, bumping block size to 16k. from freebsd. ok deraadt@ and co.