Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | loaded policies included in PolicyConfig objects | Kaarle Ritvanen | 2012-06-28 | 1 | -3/+4 | |
| | ||||||
* | show original variable definitions in dump output | Kaarle Ritvanen | 2012-06-28 | 2 | -48/+40 | |
| | | | | | PolicyConfig.variables removed PolicyConfig.eval merged to PolicyConfig.expand | |||||
* | streamlined variable expansion | Kaarle Ritvanen | 2012-06-28 | 1 | -9/+2 | |
| | | | | side effects removed | |||||
* | corrected an error in raising an error (NAT rule interfaces) | Kaarle Ritvanen | 2012-06-28 | 1 | -1/+1 | |
| | ||||||
* | support for ACCEPT rules in NAT chains | Kaarle Ritvanen | 2012-06-28 | 1 | -1/+2 | |
| | ||||||
* | reset all built-in chains on activation/fallback regardless of translation ↵ | Kaarle Ritvanen | 2012-06-26 | 1 | -4/+22 | |
| | | | | results | |||||
* | support for empty zones | Kaarle Ritvanen | 2012-06-26 | 3 | -11/+13 | |
| | | | | (set either addr or iface attribute to an empty list) | |||||
* | apply ip[6]tables-restore only if protocol support loaded into kernel | Kaarle Ritvanen | 2012-06-26 | 1 | -10/+29 | |
| | ||||||
* | pretty output from awall list | Kaarle Ritvanen | 2012-06-26 | 3 | -15/+30 | |
| | ||||||
* | command for dumping variable and zone definitions | Kaarle Ritvanen | 2012-06-26 | 2 | -1/+34 | |
| | ||||||
* | new class for configuration loaded from policy files but not yet translated ↵ | Kaarle Ritvanen | 2012-06-26 | 3 | -46/+59 | |
| | | | | to iptables rules | |||||
* | masquerading set rule applied after other SNAT rulesv0.1.4 | Kaarle Ritvanen | 2012-06-21 | 1 | -4/+6 | |
| | ||||||
* | ipset-based masquerading moved to a module of its own | Kaarle Ritvanen | 2012-06-21 | 2 | -5/+17 | |
| | ||||||
* | set chain policy to ACCEPT in tables other than filter | Kaarle Ritvanen | 2012-06-21 | 1 | -3/+5 | |
| | ||||||
* | filter out ICMPv4/6 rules per protocol family even when message type not definedv0.1.3 | Kaarle Ritvanen | 2012-06-21 | 1 | -11/+11 | |
| | ||||||
* | by default, allow all ICMPv6 messages originating from or destined to local host | Kaarle Ritvanen | 2012-06-21 | 1 | -1/+10 | |
| | ||||||
* | multi-stage processing of default rules | Kaarle Ritvanen | 2012-06-21 | 3 | -21/+30 | |
| | ||||||
* | accept all loopback traffic | Kaarle Ritvanen | 2012-06-21 | 1 | -0/+9 | |
| | ||||||
* | add dhcp service | Jeremy Thomerson | 2012-06-13 | 1 | -1/+2 | |
| | ||||||
* | OUTPUT chain needs stateful tracking also | Timo Teräs | 2012-06-08 | 1 | -1/+1 | |
| | ||||||
* | report JSON file name on parse errorv0.1.2 | Kaarle Ritvanen | 2012-05-17 | 1 | -2/+10 | |
| | ||||||
* | adjust command line help text | Kaarle Ritvanen | 2012-05-03 | 1 | -4/+4 | |
| | ||||||
* | make the family attribute mandatory for ipset objects | Kaarle Ritvanen | 2012-05-03 | 1 | -3/+3 | |
| | | | | incidentally, this makes all IP set-referring rules specific to one protocol family | |||||
* | installer Makefile added | Kaarle Ritvanen | 2012-05-03 | 1 | -0/+47 | |
| | ||||||
* | policy file description attributev0.1.1 | Kaarle Ritvanen | 2012-05-01 | 3 | -10/+20 | |
| | ||||||
* | command line syntax help | Kaarle Ritvanen | 2012-05-01 | 1 | -5/+40 | |
| | ||||||
* | improved command line syntax | Kaarle Ritvanen | 2012-05-01 | 1 | -32/+47 | |
| | ||||||
* | add sample policy file | Kaarle Ritvanen | 2012-05-01 | 1 | -0/+40 | |
| | ||||||
* | cover ICMPv6 echo in ping service definition | Kaarle Ritvanen | 2012-05-01 | 1 | -1/+4 | |
| | ||||||
* | use local DNS resolverv0.1.0 | Kaarle Ritvanen | 2012-04-19 | 1 | -2/+1 | |
| | ||||||
* | interrupted read triggers fallback | Kaarle Ritvanen | 2012-04-19 | 1 | -1/+1 | |
| | ||||||
* | Config object initialization from PolicySet | Kaarle Ritvanen | 2012-04-19 | 2 | -11/+12 | |
| | ||||||
* | wrapped a long statement in policy.lua | Kaarle Ritvanen | 2012-04-19 | 1 | -1/+7 | |
| | ||||||
* | corrected scope errors | Kaarle Ritvanen | 2012-04-19 | 2 | -2/+2 | |
| | ||||||
* | enable, disable, and list optional policy files | Kaarle Ritvanen | 2012-04-12 | 2 | -8/+84 | |
| | ||||||
* | configuration (policy) file handling moved to a dedicated module | Kaarle Ritvanen | 2012-04-12 | 2 | -57/+111 | |
| | ||||||
* | convert empty strings to nil values in input configuration table | Kaarle Ritvanen | 2012-04-12 | 1 | -2/+4 | |
| | | | | skip expansion in the variable fragment to avoid clearing variable declarations | |||||
* | dnat option for filter rules | Kaarle Ritvanen | 2012-04-12 | 2 | -1/+72 | |
| | ||||||
* | module metadata processing moved to awall.loadmodules | Kaarle Ritvanen | 2012-04-12 | 4 | -15/+29 | |
| | | | | | deterministic processing order within modules global classmap for dynamic module discovery | |||||
* | module namespace-related style adjustments | Kaarle Ritvanen | 2012-04-12 | 3 | -9/+8 | |
| | | | | | drop awall prefix when accessing submodules from the main module remove module-level function/module shortcuts when used only once | |||||
* | subfunctions prefixed with 'local' | Kaarle Ritvanen | 2012-04-12 | 2 | -10/+10 | |
| | ||||||
* | corrected fw zone exclusion in NATRule.init | Kaarle Ritvanen | 2012-04-09 | 1 | -2/+4 | |
| | ||||||
* | optional, importable configuration files | Kaarle Ritvanen | 2012-04-09 | 2 | -20/+55 | |
| | ||||||
* | service definition added: bgp | Kaarle Ritvanen | 2012-04-05 | 1 | -0/+1 | |
| | ||||||
* | string concatenation support in variable expansion | Kaarle Ritvanen | 2012-03-26 | 1 | -5/+14 | |
| | ||||||
* | more service definitions | Kaarle Ritvanen | 2012-03-26 | 1 | -0/+10 | |
| | ||||||
* | safe activation mode (with automatic fallback) | Kaarle Ritvanen | 2012-03-26 | 2 | -5/+66 | |
| | ||||||
* | iptables module: backup and revert functions | Kaarle Ritvanen | 2012-03-26 | 1 | -16/+30 | |
| | | | | private class for reading current configuration | |||||
* | make verification using ip[6]tables-restore optional | Kaarle Ritvanen | 2012-03-22 | 1 | -3/+5 | |
| | | | | verification requires root privileges | |||||
* | control input and output directories from command line | Kaarle Ritvanen | 2012-03-22 | 2 | -7/+26 | |
| |