Commit Graph

26 Commits (6ca53456456414a03b3f03535522804a2bd598ef)

Author SHA1 Message Date
Hauke Mehrtens 76409c643f [iptables] Update layer7 rules
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@15544 3c298f89-4303-0410-b956-a3cf2f4a3e73
2009-05-01 15:20:34 +00:00
John Crispin 275038cae7 adds a new uci firewall
- iptbales and netfilter packages need to be rewrapped when we switch to this firewall as default
- there are some examples in the file /etc/config/firewall
- iptables-save/restore are still missing
- hotplug takes care of adding/removing netdevs during runtime
- misisng features ? wishes ? let me know ...



git-svn-id: svn://svn.openwrt.org/openwrt/trunk@12089 3c298f89-4303-0410-b956-a3cf2f4a3e73
2008-08-04 11:51:58 +00:00
Felix Fietkau b8d0d61fdb move /etc/config/firewall to /etc/firewall.config to prevent it from interfering with uci - yes, this beast really needs a rewrite :)
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@10383 3c298f89-4303-0410-b956-a3cf2f4a3e73
2008-02-04 22:03:18 +00:00
Felix Fietkau 2f8b5f8c28 Here comes the new UCI. Enjoy :)
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@10367 3c298f89-4303-0410-b956-a3cf2f4a3e73
2008-02-03 06:48:15 +00:00
Tim Yardley b03c1401f6 update stripped subset of l7 patterns to 11-03-2007 patterns
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@9582 3c298f89-4303-0410-b956-a3cf2f4a3e73
2007-11-19 23:07:00 +00:00
Florian Fainelli d164fef8c5 Add a boolean to allow NAT from LAN or not, default to nat LAN (#2535)
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@9503 3c298f89-4303-0410-b956-a3cf2f4a3e73
2007-11-05 14:19:16 +00:00
Florian Fainelli 2166cc1ae8 Only masquerade LAN, other settings need manual tweaking
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@9461 3c298f89-4303-0410-b956-a3cf2f4a3e73
2007-10-29 11:00:33 +00:00
Florian Fainelli f57bf774e8 Only masquerade non routable addresses (#2535)
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@9460 3c298f89-4303-0410-b956-a3cf2f4a3e73
2007-10-29 10:31:16 +00:00
Felix Fietkau d6611faaef make the firewall script run after the network script again (required for working with dynamically assigned interfaces), include the network state
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@7806 3c298f89-4303-0410-b956-a3cf2f4a3e73
2007-06-30 19:30:38 +00:00
Florian Fainelli 6318a38a80 Initialise firewall before network (#1988)
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@7757 3c298f89-4303-0410-b956-a3cf2f4a3e73
2007-06-28 12:56:55 +00:00
Felix Fietkau fe34071314 fix a problem with the firewall script (multicast traffic could produce packet loss)
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@6726 3c298f89-4303-0410-b956-a3cf2f4a3e73
2007-03-27 16:45:10 +00:00
Felix Fietkau dc4d1dd12a port [6229] to kamikaze
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@6275 3c298f89-4303-0410-b956-a3cf2f4a3e73
2007-02-08 01:25:18 +00:00
Felix Fietkau 86709475a5 prepare for moving part of the firewall to hotplug. created new chains {input,forwarding,prerouting}_wan for wan port forwardings and updated the examples. syntax of /etc/config/firewall unchanged and old firewall.user files are still compatible
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@5878 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-12-20 05:58:41 +00:00
Felix Fietkau 437fe46ff7 replace br0 with $LAN
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@5492 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-11-09 23:13:15 +00:00
Florian Fainelli 390efb3b3c export WAN variable so that firewall works (#907)
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@5412 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-11-03 10:10:08 +00:00
Felix Fietkau 24591d8f63 add firewall protection for wan_device in addition to wan_ifname (fixes #852)
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@5136 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-10-15 23:04:23 +00:00
Felix Fietkau c731d42b1a init script cleanup, use /etc/rc.d/ for enabled scripts, /etc/init.d/<pkgname> (enable|disable) manages symlinks
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@5128 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-10-15 21:03:30 +00:00
Felix Fietkau 3aa127d7a5 add new rc.common for standardized init scripts, convert existing init scripts
git-svn-id: svn://svn.openwrt.org/openwrt/branches/buildroot-ng/openwrt@4915 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-10-04 20:05:48 +00:00
Felix Fietkau 652c662b7d fix missing update for include() api change (#815)
git-svn-id: svn://svn.openwrt.org/openwrt/branches/buildroot-ng/openwrt@4909 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-10-04 17:11:36 +00:00
Felix Fietkau cbfcdded83 sync firewall script with whiterussian changes
git-svn-id: svn://svn.openwrt.org/openwrt/branches/buildroot-ng/openwrt@4858 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-09-26 14:00:22 +00:00
Felix Fietkau d3a6fe9915 rewrite of the network scripts and configuration
git-svn-id: svn://svn.openwrt.org/openwrt/branches/buildroot-ng/openwrt@4323 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-07-30 03:09:09 +00:00
Felix Fietkau f02ffe6441 add missing copyright notices
git-svn-id: svn://svn.openwrt.org/openwrt/branches/buildroot-ng/openwrt@4097 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-06-27 23:53:48 +00:00
Felix Fietkau 340f1875ed resync with kamikaze
git-svn-id: svn://svn.openwrt.org/openwrt/branches/buildroot-ng/openwrt@3844 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-05-30 19:38:38 +00:00
Felix Fietkau e1b417ee76 large init script cleanup and merge of whiterussian changes, new dnsmasq config handling
git-svn-id: svn://svn.openwrt.org/openwrt/trunk/openwrt@3588 3c298f89-4303-0410-b956-a3cf2f4a3e73
2006-04-05 02:09:22 +00:00
OpenWrt Developers 3b0cd99905 Remove not working ssh pattern file
git-svn-id: svn://svn.openwrt.org/openwrt/trunk/openwrt@2611 3c298f89-4303-0410-b956-a3cf2f4a3e73
2005-12-11 15:34:01 +00:00
Felix Fietkau 4f330ac6d9 add layer7 patterns to iptables-mod-filter
git-svn-id: svn://svn.openwrt.org/openwrt/trunk/openwrt@2519 3c298f89-4303-0410-b956-a3cf2f4a3e73
2005-11-18 16:17:27 +00:00