summaryrefslogtreecommitdiff
path: root/sbin
AgeCommit message (Collapse)Author
2002-03-28prototype pfctl_kill_states()Daniel Hartmeier
2002-03-28list out the ap's stationsMichael Shalayeff
2002-03-28chip id copies here; just for niels, all for niels, all in the name of nielsMichael Shalayeff
2002-03-28WI_RID_AUTH_CNTL was renamed to WI_RID_CNFAUTHMODETodd C. Miller
2002-03-27implement a "no-route" keyword.Michael Shalayeff
usage semantics are analogous w/ "any", meaning is "any ip address for which there is no route in the current routing table", could be used in both from and to. typical usage would be (assuming symmetrical routing): block in from no-route to any also doc "any" in the pf.conf.5, include in regress, etc. tested by me on i386 and sparc. dhartmei@ and frantzen@ ok
2002-03-27Calculate the maximum queue depth correctly.Grigoriy Orlov
PR2490 from Alexander Yurchenko <grange@rt.mipt.ru>
2002-03-26tidy up usage statement and sort headers. patch from dfa@solo.eeMike Frantzen
2002-03-26sort options and clean up the -k descrption. patch from dfa@solo.eeMike Frantzen
2002-03-26Don't message_dump_raw() bad length messages, i.e too short.Hakan Olsson
Should solve PR 2474 (unconfirmed). niklas@, me.
2002-03-25add -k option to shootdown all the state entries from the specified hostMike Frantzen
ok dhartmei@
2002-03-24Work around a compiler bug on sparc64; deraadt@ OKTodd C. Miller
2002-03-23examples of tcpdump filters on pf log fieldsMike Frantzen
2002-03-21o sync usage() to man pageTodd C. Miller
o -l does not require an argument o getopt() returns -1 not EOF From Brian Poole
2002-03-21Add r option to SYNOPSIS. From Brian Poole.Daniel Hartmeier
2002-03-21Change 'Airport' to 'Lucent (embedded)' to correspond to reality.Todd C. Miller
Otherwise, the embedded Lucent wavelan is called 'Airport' on Toshiba and Sony laptops.
2002-03-19Remove unnecessary prototype.Angelos D. Keromytis
2002-03-17Move SA_FILE definition to sa.h.Angelos D. Keromytis
2002-03-17Mention isakmpd_sa file.Angelos D. Keromytis
2002-03-17Add 'T' and 'S' commands (for tearing-down and reporting all Phase 2Angelos D. Keromytis
SAs), from bdallen@nps.navy.mil
2002-03-14fix a few overflows by using off_t, not 32bit longs; some parts are from ↵Michael Shalayeff
lucq.org; millert@ ok
2002-03-14kill more registers.Mike Pechkin
millert@ ok
2002-03-14Remove \n from err/errx/warn/warnx().Mike Pechkin
millert@ ok
2002-03-12Handle inet_ntop() returning NULL explicitly. Found by mpech@.Daniel Hartmeier
2002-03-11Add -r to reverse lookup addresses when displaying states.Daniel Hartmeier
From John Kerbawy.
2002-03-11no \n to warnx(3). From: Mike Pechkin <mpech@prosoft.org.lv>Jun-ichiro itojun Hagino
2002-03-08Fix arc4random() usage; add more randomness to intvl_random().Mike Pechkin
millert@ ok
2002-03-06Compile without warnings for older/newer OpenSSL.Hakan Olsson
2002-03-06Fix a couple of snprintf length bugs. Same problem <chris@stallion.oz.au>Hakan Olsson
found for policy passphrases.
2002-03-06Unbreak MD5 and SHA1 passphrases in policy check. FromHakan Olsson
<chris@stallion.oz.au>.
2002-03-05-Werror not possible, because of openssl constification. thanks guysTheo de Raadt
2002-03-05must pull -ldes here tooTheo de Raadt
2002-03-05must pull -ldes tooTheo de Raadt
2002-03-05handle constification from new opensslTheo de Raadt
2002-03-05need md5.h for prototypesTheo de Raadt
2002-03-02document tcp.ackonpushNiels Provos
2002-03-01Update to reflect recent changes in DH group handling. Remove BUGSHakan Olsson
section.
2002-03-01Change DH group handling in the pre-generated parts of theHakan Olsson
configuration. Add a -GRP{1,2,5} component to transform and suite names to directly specify which group to use. If no group is specified, use DH group 2 (MODP_1024). Earlier transforms and suites using the MD5 hash defaulted to DH group 1, this is no longer true. niklas@ ok.
2002-03-01document cryptodevallowsoftNiels Provos
2002-02-28Remove the ifconfig line again, it's in pflog(4), which is now linked,Daniel Hartmeier
and in pflogd context (started from rc), the interface is up already.
2002-02-28Document ethernet layer expressions.Daniel Hartmeier
2002-02-28Up the pflog0 interface. alphabetize xrefs and add pflog(4)Kjell Wooding
ok dhartmei@
2002-02-28Don't force /dev/pf to be opened read-write for pfctl -t/-m when valuesDaniel Hartmeier
are only queried but not set.
2002-02-27Instead of printing useless @0 rule numbers from pfctl -vR, increase aDaniel Hartmeier
counter. Helps debugging rule sets that are not loaded. Suggested by John Kerbawy.
2002-02-26Add optional pool memory hard limits, mainly as temporary solutionDaniel Hartmeier
until pool exhaustion causes problems no more.
2002-02-24Vax O1 workaround no longer needed.Hugh Graham
2002-02-23Add support for nwkey and powersave; from NetBSDTodd C. Miller
2002-02-23getc() returns an intTheo de Raadt
2002-02-23getc() returns an intTheo de Raadt
2002-02-23allowaperture is no longer i386 only. Noted by Dries Schellekens.Matthieu Herrb
2002-02-23sysctl kern.usercryptoTheo de Raadt