John Crispin
275038cae7
adds a new uci firewall
...
- iptbales and netfilter packages need to be rewrapped when we switch to this firewall as default
- there are some examples in the file /etc/config/firewall
- iptables-save/restore are still missing
- hotplug takes care of adding/removing netdevs during runtime
- misisng features ? wishes ? let me know ...
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@12089 3c298f89-4303-0410-b956-a3cf2f4a3e73
2008-08-04 11:51:58 +00:00
Felix Fietkau
b8d0d61fdb
move /etc/config/firewall to /etc/firewall.config to prevent it from interfering with uci - yes, this beast really needs a rewrite :)
...
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@10383 3c298f89-4303-0410-b956-a3cf2f4a3e73
2008-02-04 22:03:18 +00:00
Felix Fietkau
2f8b5f8c28
Here comes the new UCI. Enjoy :)
...
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@10367 3c298f89-4303-0410-b956-a3cf2f4a3e73
2008-02-03 06:48:15 +00:00
Tim Yardley
b03c1401f6
update stripped subset of l7 patterns to 11-03-2007 patterns
...
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@9582 3c298f89-4303-0410-b956-a3cf2f4a3e73
2007-11-19 23:07:00 +00:00
Florian Fainelli
d164fef8c5
Add a boolean to allow NAT from LAN or not, default to nat LAN ( #2535 )
...
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@9503 3c298f89-4303-0410-b956-a3cf2f4a3e73
2007-11-05 14:19:16 +00:00
Florian Fainelli
2166cc1ae8
Only masquerade LAN, other settings need manual tweaking
...
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@9461 3c298f89-4303-0410-b956-a3cf2f4a3e73
2007-10-29 11:00:33 +00:00
Florian Fainelli
f57bf774e8
Only masquerade non routable addresses ( #2535 )
...
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@9460 3c298f89-4303-0410-b956-a3cf2f4a3e73
2007-10-29 10:31:16 +00:00
Felix Fietkau
d6611faaef
make the firewall script run after the network script again (required for working with dynamically assigned interfaces), include the network state
...
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@7806 3c298f89-4303-0410-b956-a3cf2f4a3e73
2007-06-30 19:30:38 +00:00
Florian Fainelli
6318a38a80
Initialise firewall before network ( #1988 )
...
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@7757 3c298f89-4303-0410-b956-a3cf2f4a3e73
2007-06-28 12:56:55 +00:00
Felix Fietkau
fe34071314
fix a problem with the firewall script (multicast traffic could produce packet loss)
...
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@6726 3c298f89-4303-0410-b956-a3cf2f4a3e73
2007-03-27 16:45:10 +00:00
Felix Fietkau
dc4d1dd12a
port [6229] to kamikaze
...
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@6275 3c298f89-4303-0410-b956-a3cf2f4a3e73
2007-02-08 01:25:18 +00:00
Felix Fietkau
86709475a5
prepare for moving part of the firewall to hotplug. created new chains {input,forwarding,prerouting}_wan for wan port forwardings and updated the examples. syntax of /etc/config/firewall unchanged and old firewall.user files are still compatible
...
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@5878 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-12-20 05:58:41 +00:00
Felix Fietkau
437fe46ff7
replace br0 with $LAN
...
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@5492 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-11-09 23:13:15 +00:00
Florian Fainelli
390efb3b3c
export WAN variable so that firewall works ( #907 )
...
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@5412 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-11-03 10:10:08 +00:00
Felix Fietkau
24591d8f63
add firewall protection for wan_device in addition to wan_ifname ( fixes #852 )
...
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@5136 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-10-15 23:04:23 +00:00
Felix Fietkau
c731d42b1a
init script cleanup, use /etc/rc.d/ for enabled scripts, /etc/init.d/<pkgname> (enable|disable) manages symlinks
...
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@5128 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-10-15 21:03:30 +00:00
Felix Fietkau
3aa127d7a5
add new rc.common for standardized init scripts, convert existing init scripts
...
git-svn-id: svn://svn.openwrt.org/openwrt/branches/buildroot-ng/openwrt@4915 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-10-04 20:05:48 +00:00
Felix Fietkau
652c662b7d
fix missing update for include() api change ( #815 )
...
git-svn-id: svn://svn.openwrt.org/openwrt/branches/buildroot-ng/openwrt@4909 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-10-04 17:11:36 +00:00
Felix Fietkau
cbfcdded83
sync firewall script with whiterussian changes
...
git-svn-id: svn://svn.openwrt.org/openwrt/branches/buildroot-ng/openwrt@4858 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-09-26 14:00:22 +00:00
Felix Fietkau
d3a6fe9915
rewrite of the network scripts and configuration
...
git-svn-id: svn://svn.openwrt.org/openwrt/branches/buildroot-ng/openwrt@4323 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-07-30 03:09:09 +00:00
Felix Fietkau
f02ffe6441
add missing copyright notices
...
git-svn-id: svn://svn.openwrt.org/openwrt/branches/buildroot-ng/openwrt@4097 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-06-27 23:53:48 +00:00
Felix Fietkau
340f1875ed
resync with kamikaze
...
git-svn-id: svn://svn.openwrt.org/openwrt/branches/buildroot-ng/openwrt@3844 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-05-30 19:38:38 +00:00
Felix Fietkau
e1b417ee76
large init script cleanup and merge of whiterussian changes, new dnsmasq config handling
...
git-svn-id: svn://svn.openwrt.org/openwrt/trunk/openwrt@3588 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-04-05 02:09:22 +00:00
OpenWrt Developers
3b0cd99905
Remove not working ssh pattern file
...
git-svn-id: svn://svn.openwrt.org/openwrt/trunk/openwrt@2611 3c298f89-4303-0410-b956-a3cf2f4a3e73
2005-12-11 15:34:01 +00:00
Felix Fietkau
4f330ac6d9
add layer7 patterns to iptables-mod-filter
...
git-svn-id: svn://svn.openwrt.org/openwrt/trunk/openwrt@2519 3c298f89-4303-0410-b956-a3cf2f4a3e73
2005-11-18 16:17:27 +00:00