Felix Fietkau
|
10f627db5c
firewall: fix fallout from r18716 (fixes #6338)
|
16 anos atrás |
Felix Fietkau
|
74cbcc9ee5
firewall: get rid of recursive shell script inclusion to improve hush compatibility
|
16 anos atrás |
Jo-Philipp Wich
|
6cb040903b
firewall: initialize dest_port with src_dport if omitted in redirect sections to narrow down corresponding forward rules to the actual target ports - thanks Niels Boehm! (#6249)
|
16 anos atrás |
Felix Fietkau
|
70b6643034
firewall: fix zone defaults
|
16 anos atrás |
Felix Fietkau
|
2ecfe91b61
firewall: do not process rules in reverse
|
16 anos atrás |
Nicolas Thill
|
b3d3e5d752
firewall: fix MSS issue affection RELATED new connections (closes: #5173)
|
16 anos atrás |
Felix Fietkau
|
e9ec3a6e68
firewall: add sanity checks to zone default rules (patch from #5459)
|
16 anos atrás |
Felix Fietkau
|
590fdc946a
firewall: emit hotplug events for interface add/remove
|
16 anos atrás |
Jo-Philipp Wich
|
187e2ba9fc
firewall: add icmp_type option to specify the icmp type in rule sections, bump pkg revision (#5554)
|
16 anos atrás |
Florian Fainelli
|
7e2361d46a
fix typo in the uci firewall script
|
16 anos atrás |
Felix Fietkau
|
f81a781e1a
firewall: automatically set up NOTRACK rules to disable connection tracking for zones that have no masquerading, no conntrack and no forwarding from/to other zones with masq/conntrack
|
16 anos atrás |
Jo-Philipp Wich
|
cacb52e19f
firewall: process custom rules after forwardings and redirects, this actually allows blocking traffic to certain hosts and other rules
|
16 anos atrás |
Felix Fietkau
|
4fc8f4c5c8
firewall: don't clear the mangle table at startup or stop - it doesn't use it and clearing it breaks qos
|
16 anos atrás |
Jo-Philipp Wich
|
83c9ac173d
firewall: introduce drop_invalid option to allow disabling the invalid state match
|
17 anos atrás |
Felix Fietkau
|
5b58a8db1f
firewall: allow multiple interfaces to be part of one zone, fix the sanity checks for that
|
17 anos atrás |
Felix Fietkau
|
c7ff578b9f
firewall: clear the MSSFIX rules
|
17 anos atrás |
Steven Barth
|
d1049f535a
Unify portrange-support in firewall rule generator fixes #4404
|
17 anos atrás |
Felix Fietkau
|
359ce7f97e
disable the MSS fixup hack by default (most ISPs don't require this as a workaround for MTU problems, only some do). this should give a nice speedup for routing on standard-compliant ISPs
|
17 anos atrás |
John Crispin
|
3830b905e3
fixes firewall for trunk, custom chains were never reched, as policies apply beforehand
|
17 anos atrás |
John Crispin
|
221f4ad32d
fixes firewall rule generation. forwarding rules were inserted in input chains, fixes #4028
|
17 anos atrás |
John Crispin
|
b56d5cc36f
custom chains were never reached on DROP/REJECT policy, fixes #4004 #4029
|
17 anos atrás |
Felix Fietkau
|
13abdc0af1
firewall: fix default policies, add a check for duplicate defaults sections and make custom chains more generic
|
17 anos atrás |
Nicolas Thill
|
d7810ed63e
firewall changes: - implement a REJECT policy and enable it by default, reject packets with approriate response (closes: #3970) - cleanup syn_flood and remove logging
|
17 anos atrás |
Steven Barth
|
954c24c5ed
Fixed a typo in the firewall scripts
|
17 anos atrás |
Steven Barth
|
efb4cebbc6
Fixed a typo in firewall scripts, closes #4000
|
17 anos atrás |
John Crispin
|
7f6ee846b7
make uci firewall backwards compatible to the old firewall.user
|
17 anos atrás |
John Crispin
|
20216aa44d
add proto tcpudp to firewall
|
17 anos atrás |
John Crispin
|
9eaae4c61d
fix device duplication in firewall if the balancing of ifup and ifdown is broken
|
17 anos atrás |
John Crispin
|
924d10d611
make sure uci firewall reverts its states when stopped
|
17 anos atrás |
John Crispin
|
146b47b60a
fixes uci firewall init order, Signed-off-by: Roberto Riggio
|
17 anos atrás |