aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
* masquerade: rename chainv1.7.0Kaarle Ritvanen2020-01-1719-57/+57
| | | | avoid double awall prefix
* support co-existence with other firewall management toolsKaarle Ritvanen2020-01-1718-29/+1649
|
* util: execute functionKaarle Ritvanen2020-01-172-6/+5
|
* util: startswithupper functionKaarle Ritvanen2020-01-172-3/+10
|
* iptables: isbuiltin functionKaarle Ritvanen2020-01-172-9/+8
|
* BaseIPTables: flush methodKaarle Ritvanen2020-01-171-1/+3
|
* BaseIPTables: restorecmd methodKaarle Ritvanen2020-01-171-3/+7
|
* iptables: stylistic adjustmentsKaarle Ritvanen2020-01-171-17/+25
|
* Config: methods for option fragment interpretationKaarle Ritvanen2020-01-173-17/+14
|
* init: use _ for unused index variableKaarle Ritvanen2020-01-172-8/+8
|
* README: align with command line helpKaarle Ritvanen2020-01-171-2/+5
|
* Config.init: remove redundant criterionv1.6.13Kaarle Ritvanen2019-12-241-7/+2
|
* test: customKaarle Ritvanen2019-12-2413-0/+1501
|
* IPSet.create: fix error checkKaarle Ritvanen2019-12-241-1/+2
|
* fallback: trigger no DNS queriesv1.6.12Kaarle Ritvanen2019-09-071-14/+16
| | | | | fixes race condition where an unnecessary DNS query fails after kernel rules have already been flushed
* filter: ignore IPv6 addresses of NAT destinationv1.6.11Kaarle Ritvanen2019-08-262-31/+37
|
* test: filter-dnatKaarle Ritvanen2019-08-265-0/+1441
|
* activate: initial setupv1.6.10Kaarle Ritvanen2019-02-021-13/+43
|
* iptables.flush: use actfamiliesKaarle Ritvanen2019-02-021-10/+7
|
* early detection of missing kernel supportKaarle Ritvanen2019-02-022-24/+33
|
* family: list of families enabled in kernelKaarle Ritvanen2019-02-021-1/+10
|
* optfrag: rename constant: FAMILYFRAGSKaarle Ritvanen2019-02-024-6/+6
|
* optfrag.FAMILIES: move to new moduleKaarle Ritvanen2019-02-024-9/+17
|
* util: run functionKaarle Ritvanen2019-02-023-11/+19
|
* host.resolve: properly handle CNAME recordsv1.6.9Kaarle Ritvanen2019-01-262-12/+15
|
* host.resolve: use drillv1.6.8Kaarle Ritvanen2018-12-131-10/+6
|
* services: openvpnv1.6.7Kaarle Ritvanen2018-12-067-0/+19
|
* host.resolve: avoid ANY queryKaarle Ritvanen2018-12-061-2/+2
|
* provide context for host.resolvelistv1.6.6Kaarle Ritvanen2018-10-312-3/+3
|
* fallback: suppress superfluous message on SIGINTKaarle Ritvanen2018-10-221-1/+1
|
* test: log: nflogv1.6.5Kaarle Ritvanen2018-09-0419-6/+80
|
* Log: deterministic option orderingKaarle Ritvanen2018-09-041-17/+19
|
* adp-ntp: allow DNSKaarle Ritvanen2018-09-041-1/+3
|
* adp: http serverv1.6.4Kaarle Ritvanen2018-08-151-0/+4
|
* deterministic dependency resolverv1.6.3Kaarle Ritvanen2018-08-131-4/+5
|
* adp: web-clientv1.6.2Kaarle Ritvanen2018-08-133-8/+12
|
* adp-router: configurable default actionKaarle Ritvanen2018-08-131-1/+9
|
* adp: zone naming conventionKaarle Ritvanen2018-08-136-9/+11
|
* adp: variable naming conventionKaarle Ritvanen2018-08-132-5/+11
|
* default policy naming conventionKaarle Ritvanen2018-08-137-1/+1
|
* router policy: fix masqueradingv1.6.1Kaarle Ritvanen2018-08-071-1/+1
|
* basic default policiesv1.6.0Kaarle Ritvanen2018-08-068-0/+49
|
* json: rename directoryKaarle Ritvanen2018-08-065-3/+3
|
* Log: use nflog-size instead of nflog-rangev1.5.1Kaarle Ritvanen2018-03-062-4/+4
|
* test: remove generated policiesv1.5.0Kaarle Ritvanen2017-11-031-1/+9
|
* host: resolvelist functionKaarle Ritvanen2017-11-034-21/+31
|
* test: filter-limit: service with no-trackKaarle Ritvanen2017-11-034-46542/+46542
|
* Log.optfrags: packet mirroringKaarle Ritvanen2017-11-0322-55096/+129605
|
* Log: simplify structureKaarle Ritvanen2017-11-032-25/+14
|
* LogRule: use mangleoptfrags instead of servoptfragsKaarle Ritvanen2017-11-031-4/+2
|