| Commit message (Expand) | Author | Age | Files | Lines |
* | Keep firewall.user during sysupgrades | Travis Kemen | 2011-03-20 | 1 | -0/+1 |
* | firewall: move include sourcing into a subshell, this makes the firewall init... | Jo-Philipp Wich | 2011-03-02 | 1 | -2/+4 |
* | firewall: fix rule generation for v4 or v6 only zones (#8955) | Jo-Philipp Wich | 2011-03-01 | 1 | -0/+3 |
* | firewall: fix wrong rule order if multiple protocols are used | Jo-Philipp Wich | 2011-01-27 | 1 | -3/+3 |
* | firewall: insert SNAT and DNAT rules according to the order of the configurat... | Jo-Philipp Wich | 2010-10-08 | 2 | -2/+5 |
* | firewall: also establish forward rules when setting up nat reflection, back o... | Jo-Philipp Wich | 2010-10-03 | 1 | -6/+15 |
* | firewall: fix chain selection logic, option dest must be ignored for notrack ... | Jo-Philipp Wich | 2010-09-28 | 1 | -6/+5 |
* | firewall: don't setup nat reflection if negations are used | Jo-Philipp Wich | 2010-09-28 | 1 | -0/+3 |
* | fireall: - support negations for src_ip, dest_ip, src_dip options in rules an... | Jo-Philipp Wich | 2010-09-28 | 4 | -27/+41 |
* | firewall: protect iptables invocations with locks in interface ops, it might ... | Jo-Philipp Wich | 2010-09-19 | 1 | -0/+4 |
* | firewall: make invalid redirects and duplicate zones non-fatal, print a notic... | Jo-Philipp Wich | 2010-09-16 | 3 | -9/+11 |
* | firewall: run ifdown hotplug events synchronized, fixes a racecondition on "i... | Jo-Philipp Wich | 2010-09-15 | 2 | -9/+7 |
* | firewall: deliver remove hotplug events for all active zones/networks when re... | Jo-Philipp Wich | 2010-09-14 | 2 | -2/+41 |
* | firewall: - simplify masquerade rule setup - remove various subshell invocati... | Jo-Philipp Wich | 2010-09-11 | 6 | -93/+113 |
* | firewall: - fix possible endless loop when the family option is used for forw... | Jo-Philipp Wich | 2010-09-05 | 2 | -4/+6 |
* | firewall: introduce SNAT support for redirect sections | Jo-Philipp Wich | 2010-09-05 | 2 | -3/+18 |
* | firewall: add option to disable NAT reflection | Jo-Philipp Wich | 2010-09-04 | 1 | -0/+4 |
* | firewall: - handle NAT reflection in firewall hotplug, solves synchronizing i... | Jo-Philipp Wich | 2010-09-04 | 3 | -6/+30 |
* | firewall: - fix processing of rules with an ip family option - append interfa... | Jo-Philipp Wich | 2010-08-31 | 3 | -41/+62 |
* | firwall: fix nat reflection for zones covering multiple networks | Jo-Philipp Wich | 2010-07-31 | 1 | -34/+56 |
* | firewall: add basic NAT reflection/NAT loopback support | Jo-Philipp Wich | 2010-07-31 | 1 | -0/+79 |
* | firewall: allow redirecting only destination port (#7197) | Jo-Philipp Wich | 2010-07-16 | 1 | -2/+3 |
* | firewall: fix another notrack related bug | Jo-Philipp Wich | 2010-07-15 | 1 | -1/+1 |
* | firewall: - notrack support was broken in multiple ways, fix it - also consid... | Jo-Philipp Wich | 2010-07-15 | 4 | -8/+10 |
* | firewall: - support alias ifnames different from parent ifname - properly han... | Jo-Philipp Wich | 2010-06-02 | 1 | -10/+23 |
* | firewall: Initial alias interface support. This allows to define zones coveri... | Jo-Philipp Wich | 2010-06-01 | 2 | -28/+85 |
* | firewall: change the order of IPv4/IPv6 address detection, fixes mixed notati... | Jo-Philipp Wich | 2010-05-31 | 2 | -2/+2 |
* | firewall: fix support for netranges in redirect and rule sections | Jo-Philipp Wich | 2010-05-30 | 3 | -7/+7 |
* | firewall: count rules per chain and family, fix wrong order of ip6tables rule... | Jo-Philipp Wich | 2010-05-22 | 1 | -4/+4 |
* | firewall: don't apply default udp/68 rule to ip6tables | Jo-Philipp Wich | 2010-05-19 | 1 | -0/+1 |
* | firewall: - fix ip6tables rules when icmp_type option is set - add "family" o... | Jo-Philipp Wich | 2010-05-19 | 6 | -40/+104 |
* | firewall: add commented disable_ipv6 option to default config | Jo-Philipp Wich | 2010-05-19 | 1 | -0/+2 |
* | firewall: implement disable_ipv6 uci option | Jo-Philipp Wich | 2010-05-19 | 2 | -5/+11 |
* | firewall (#7355) - partially revert r21486, start firewall on init again - sk... | Jo-Philipp Wich | 2010-05-19 | 4 | -26/+11 |
* | firewall: fix a possible deadlock when the firewall config has syntax errors ... | Jo-Philipp Wich | 2010-05-18 | 1 | -2/+4 |
* | firewall: use uci_get_state() wrapper | Jo-Philipp Wich | 2010-05-17 | 1 | -1/+1 |
* | firewall: properly clear hooks in fw_stop() to prevent extensions from being ... | Jo-Philipp Wich | 2010-05-17 | 1 | -1/+8 |
* | firewall: - defer firewall start until the first interface is brought up by h... | Jo-Philipp Wich | 2010-05-17 | 3 | -6/+20 |
* | firewall: properly unset position for delete command, fixes rule removal in i... | Jo-Philipp Wich | 2010-05-05 | 1 | -2/+2 |
* | firewall: fix bug in iface hotplug handler | Jo-Philipp Wich | 2010-05-05 | 1 | -1/+1 |
* | firewall: - replace uci firewall with a modular dual stack implementation dev... | Jo-Philipp Wich | 2010-05-01 | 14 | -539/+1016 |
* | allow ping | Travis Kemen | 2010-03-18 | 1 | -0/+7 |
* | firewall: insert rules at the beginning of chains again while maintaining non... | Jo-Philipp Wich | 2010-03-02 | 1 | -1/+4 |
* | firewall: fix bad number error in fw_redirect() (#6704) | Jo-Philipp Wich | 2010-02-20 | 1 | -3/+3 |
* | Add destination ip of the wan adapter useful if you have multiple ip addresses. | Travis Kemen | 2010-02-11 | 1 | -0/+2 |
* | firewall: fix a race condition preventing interfaces from being added to the ... | Jo-Philipp Wich | 2010-01-19 | 1 | -2/+6 |
* | firewall: fix fallout from r18716 (fixes #6338) | Felix Fietkau | 2009-12-10 | 1 | -1/+3 |
* | firewall: get rid of recursive shell script inclusion to improve hush compati... | Felix Fietkau | 2009-12-09 | 2 | -37/+46 |
* | firewall: initialize dest_port with src_dport if omitted in redirect sections... | Jo-Philipp Wich | 2009-12-01 | 1 | -21/+21 |
* | firewall: fix zone defaults | Felix Fietkau | 2009-10-11 | 1 | -2/+19 |