aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
...
* add sample policy fileKaarle Ritvanen2012-05-011-0/+40
|
* cover ICMPv6 echo in ping service definitionKaarle Ritvanen2012-05-011-1/+4
|
* use local DNS resolverv0.1.0Kaarle Ritvanen2012-04-191-2/+1
|
* interrupted read triggers fallbackKaarle Ritvanen2012-04-191-1/+1
|
* Config object initialization from PolicySetKaarle Ritvanen2012-04-192-11/+12
|
* wrapped a long statement in policy.luaKaarle Ritvanen2012-04-191-1/+7
|
* corrected scope errorsKaarle Ritvanen2012-04-192-2/+2
|
* enable, disable, and list optional policy filesKaarle Ritvanen2012-04-122-8/+84
|
* configuration (policy) file handling moved to a dedicated moduleKaarle Ritvanen2012-04-122-57/+111
|
* convert empty strings to nil values in input configuration tableKaarle Ritvanen2012-04-121-2/+4
| | | | skip expansion in the variable fragment to avoid clearing variable declarations
* dnat option for filter rulesKaarle Ritvanen2012-04-122-1/+72
|
* module metadata processing moved to awall.loadmodulesKaarle Ritvanen2012-04-124-15/+29
| | | | | deterministic processing order within modules global classmap for dynamic module discovery
* module namespace-related style adjustmentsKaarle Ritvanen2012-04-123-9/+8
| | | | | drop awall prefix when accessing submodules from the main module remove module-level function/module shortcuts when used only once
* subfunctions prefixed with 'local'Kaarle Ritvanen2012-04-122-10/+10
|
* corrected fw zone exclusion in NATRule.initKaarle Ritvanen2012-04-091-2/+4
|
* optional, importable configuration filesKaarle Ritvanen2012-04-092-20/+55
|
* service definition added: bgpKaarle Ritvanen2012-04-051-0/+1
|
* string concatenation support in variable expansionKaarle Ritvanen2012-03-261-5/+14
|
* more service definitionsKaarle Ritvanen2012-03-261-0/+10
|
* safe activation mode (with automatic fallback)Kaarle Ritvanen2012-03-262-5/+66
|
* iptables module: backup and revert functionsKaarle Ritvanen2012-03-261-16/+30
| | | | private class for reading current configuration
* make verification using ip[6]tables-restore optionalKaarle Ritvanen2012-03-221-3/+5
| | | | verification requires root privileges
* control input and output directories from command lineKaarle Ritvanen2012-03-222-7/+26
|
* iptables module: use class model, new class for run-time backupsKaarle Ritvanen2012-03-222-19/+47
|
* use class model in ipset moduleKaarle Ritvanen2012-03-222-7/+5
|
* eliminate module-level configuration variablesKaarle Ritvanen2012-03-222-18/+7
|
* allow passing arguments to init when creating objects with class.newKaarle Ritvanen2012-03-222-7/+4
|
* class model utilized in init.luaKaarle Ritvanen2012-03-222-27/+26
| | | | context objects converted to explicit Config objects
* class model generalized and moved to a self-contained moduleKaarle Ritvanen2012-03-223-33/+51
|
* global variables eliminatedKaarle Ritvanen2012-03-224-41/+60
| | | | | (except for the DNS resolution cache) context, IPTables, and IPSet objects introduced
* dumping and testing functions separatedKaarle Ritvanen2012-03-165-21/+73
| | | | module for ipset tool-related functionality
* removed ununsed variableKaarle Ritvanen2012-03-161-1/+0
|
* test mode moved to awall-cli from init.luaKaarle Ritvanen2012-03-162-16/+32
|
* directory for default JSON filesKaarle Ritvanen2012-03-163-1/+2
|
* allow for non-existent ipset configuration fragmentKaarle Ritvanen2012-03-161-7/+9
|
* configuration file for masquerading ipsetKaarle Ritvanen2012-03-161-0/+8
|
* generate ipset definition fileKaarle Ritvanen2012-03-161-0/+9
|
* changed protocol strings to inet and inet6Kaarle Ritvanen2012-03-165-13/+13
|
* explicit declaration of ipsets (with protocol family information)Kaarle Ritvanen2012-03-161-1/+5
|
* multiple ipsets per ruleKaarle Ritvanen2012-03-161-11/+15
|
* process configuration files in deterministic orderKaarle Ritvanen2012-03-161-1/+5
|
* support for using externally controlled ipsets in rulesKaarle Ritvanen2012-03-161-2/+16
|
* enable ipset-based masqueradingKaarle Ritvanen2012-03-011-5/+5
|
* variable expansionKaarle Ritvanen2012-03-011-0/+30
|
* output verification using ip[6]tables-restoreKaarle Ritvanen2012-02-234-22/+40
| | | | | | output saved as rules[6]-save corrected a couple of syntax errors in output disabled the default rule in nat module
* descriptive chain namesKaarle Ritvanen2012-02-162-9/+13
|
* use lfs.dir for listing modulesKaarle Ritvanen2012-02-161-6/+11
|
* multiple configuration files, service definitionsKaarle Ritvanen2012-02-162-4/+41
|
* util.extend helper functionKaarle Ritvanen2012-02-162-10/+10
|
* initial versionKaarle Ritvanen2012-02-1610-0/+755