Age | Commit message (Collapse) | Author | |
---|---|---|---|
2003-05-18 | Forgot to remove a couple of debug messages | Hakan Olsson | |
2003-05-18 | struct sockaddr is not large enough in itself to contain the address | Hakan Olsson | |
value. Switching to sockaddr_storage makes interface rescanning work properly. niklas@ ok. | |||
2003-05-18 | More isakmpd privsep work. X509 private keys are now kept in the privileged | Hakan Olsson | |
process only. Various cleanup and bugfixes. markus@ ok | |||
2003-05-18 | Sysdep for native Linux IPSec, 2.5 and later. From Thomas Walpuski, with | Hakan Olsson | |
various tweaks by me. niklas@ ok. | |||
2003-05-17 | Better return codes from mm_send_fd and mm_receive_fd | Hakan Olsson | |
2003-05-17 | Use log_error(), not log_fatal(). | Hakan Olsson | |
Style. | |||
2003-05-17 | tweak; | Jason McIntyre | |
ok ho@ | |||
2003-05-17 | Fix proxy related output. | Daniel Hartmeier | |
2003-05-17 | A little bugfix. We want pfioc_states, not pfioc_state. | Ryan Thomas McBride | |
ok henning@ | |||
2003-05-17 | support inverse matching on tags like | Henning Brauer | |
block in ! tagged sometag ok dhartmei@ pb@ | |||
2003-05-16 | If the "Renegotiate-on-HUP" tag is defined in the [General] section, a | Hakan Olsson | |
HUP signal (or "R" to the FIFO) will also renegotiate all Phase 2 SAs, i.e all connections. ok niklas@, tested and ok kjell@. | |||
2003-05-16 | TCP SYN proxy. Instead of 'keep state' or 'modulate state', one can use | Daniel Hartmeier | |
'synproxy state' for TCP connections. pf will complete the TCP handshake with the active endpoint before passing any packets to the passive end- point, preventing spoofed SYN floods from reaching the passive endpoint. No additional memory requirements, no cookies needed, random initial sequence numbers, uses the existing sequence number modulators to translate packets after the handshakes. ok frantzen@ | |||
2003-05-15 | make getifaddrs(3) a default, as all BSD has it by now | Jun-ichiro itojun Hagino | |
2003-05-15 | properly complain about too long tags | Henning Brauer | |
2003-05-15 | Correct a two year old typo, which might actually make | Hakan Olsson | |
setsockopt(..., IP_IPSEC_LOCAL_AUTH, ...) start working. | |||
2003-05-15 | Cleanup. Do not store the private key in either the exchange or sa structs. | Hakan Olsson | |
2003-05-15 | Work around some OpenSSL BIO "features" to read the key correctly. | Hakan Olsson | |
2003-05-15 | Proper exit of the monitor process. | Hakan Olsson | |
2003-05-15 | wait() for the child process | Hakan Olsson | |
2003-05-15 | Start of privilege separation for isakmpd. | Hakan Olsson | |
There are some kinks left, so keep it default disabled for now. markus@ says ok to commit. | |||
2003-05-15 | (c) | Hakan Olsson | |
2003-05-14 | add scrub modifier "reassemble tcp" to turn on stateful TCP normalizations | Mike Frantzen | |
ok henning@ dhartmei@ | |||
2003-05-14 | properly terminate debug string (levels >=40) | Kjell Wooding | |
Use "%.*s" as suggested by Niklas. ok ho@. Lost by kjell. oked ho@. lost by kjell again. oked ho@ | |||
2003-05-14 | Remove the .if/.endif stuff that gmake does not understand. | Hakan Olsson | |
Replace with a comment about needing keynote for policy. | |||
2003-05-14 | tagging on binat | Henning Brauer | |
2003-05-14 | enabled tagging on rdr rules | Henning Brauer | |
2003-05-14 | Call the FreeS/WAN sysdep 'freeswan'. The 'linux' sysdep will be native ↵ | Hakan Olsson | |
Linux IPSec. | |||
2003-05-14 | Default public key directory definition sanity. | Hakan Olsson | |
2003-05-14 | Policy file default defined twice, kill the local copy. | Hakan Olsson | |
2003-05-14 | Fix a typo (in unused code). | Hakan Olsson | |
2003-05-14 | I did not test this enough. Unbreak. | Hakan Olsson | |
2003-05-14 | pflogd now uses the new pflog link type. Trying to append to an existing | Can Erkin Acar | |
old-style logfile will fail. Move away old log files. ok henning@ dhartmei@ frantzen@ | |||
2003-05-14 | Minor format string correctness. | Chad Loder | |
OK deraadt, ian darwin | |||
2003-05-14 | The ramdac's hater club is proud to present new yet another SBus frame | Miod Vallat | |
bufer driver, this time for the Southland Media Systems (now Quantum 3D) MGX and MGXPlus cards. Not complete, but a good start. | |||
2003-05-14 | with tag/tagged given, only whine about missing keep state on pass rules | Henning Brauer | |
2003-05-14 | allow SCRUB rules to specify protocol again. broken sometime in the past. | Mike Frantzen | |
okie dhartmei@, yay pb@ | |||
2003-05-14 | tags on nat rules: | Henning Brauer | |
nat on $ext_if all tag humppa -> $ext_if pass out tagged hummpa keep state | |||
2003-05-14 | gotta xref boot_hppa from here | Michael Shalayeff | |
2003-05-14 | move ETHERTYPE_xx declarations to <net/ethertypes.h>. meets netbsd practice. | Jun-ichiro itojun Hagino | |
deraadt ok | |||
2003-05-14 | Add the -q flag to suppress all output when setting a variable | Jean-Francois Brousseau | |
with -w ok jsyn@, millert@ | |||
2003-05-14 | print the redirection target for nat/rdr/binat slighly later. | Henning Brauer | |
no functional difference (yet) | |||
2003-05-13 | make sure tagging is only ever used with stateful filter rules | Henning Brauer | |
2003-05-13 | correct rule printing | Henning Brauer | |
2003-05-13 | userland part for tagging. | Henning Brauer | |
it's now possible to tag packets with an arbitary tag and filter based on that tag later on other interfaces: pass in quick on fxp0 keep state tag blah pass out quick on wi0 keep state with tag blah can be used to express trust between interfaces, to distinguish between NATed connections and connection originating from teh firewall itself and much more ok dhartmei@ frantzen@ pb@ mcbride@ | |||
2003-05-12 | update for mount args change | Ted Unangst | |
2003-05-12 | update for mount args changes | Ted Unangst | |
2003-05-12 | Update with some data for NAT-T specific payload types, IKEv2 | Hakan Olsson | |
notifications, ISAKMP EAP code and types, plus fix an old typo. | |||
2003-05-12 | AES -> AES_128_CBC | Hakan Olsson | |
2003-05-12 | Add two more encapsulation types (UDP encap, potential future NAT-T) | Hakan Olsson | |
Add BLOCK_SIZE attribute Rename IPSEC_ESP_AES -> IPSEC_ESP_AES_128_CBC. | |||
2003-05-12 | Adaptive timeout value scaling. Allows to reduce timeout values as the | Daniel Hartmeier | |
number of state table entries grows, so entries time out faster before the table fills up. Works both globally and per-rule. ok frantzen@ |