summaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
...
* | Don't enforce the use of only IPv4 or IPv6 when using IKEv2 since it works ↵jim-p2015-10-071-1/+1
| | | | | | | | fine with IKEv2
* | Where doing a dynamic DNS update on IPv4, force curl to resolve IPv4 IPs. ↵Chris Buechler2015-10-031-0/+4
| | | | | | | | Ticket #3858
* | Fix typoChris Buechler2015-10-021-1/+1
| |
* | Specify PSK for mobile configurations without the leading ID selectors. ↵Chris Buechler2015-10-021-0/+3
| | | | | | | | Fixes PSK mismatches from iOS clients.
* | When using eap-radius, if the virtual address pool is left blank, pull the ↵jim-p2015-10-011-2/+6
| | | | | | | | IP addresses from RADIUS instead. (Will need an IP address defined for each account.) Doesn't seem to be possible to pull from either RADIUS *or* a local pool that I can see from experimenting and looking at strongSwan's docs.
* | Specify %any where identifier is "any", so the note on these pagesChris Buechler2015-10-013-2/+5
|/ | | | actually works.
* Only need to check 'vip' here.Chris Buechler2015-09-301-1/+1
|
* Can't use continue here as it continues the foreach, which skips theChris Buechler2015-09-301-6/+5
| | | | | "ipfw zone" command, breaking CP for any system that doesn't have VIPs defined.
* Fix up IKE auto modeChris Buechler2015-09-292-3/+3
|
* Correctly show v1/v2/auto on vpn_ipsec.phpChris Buechler2015-09-291-2/+5
|
* Bring this back, I'll fix issues afterwards. Revert "Remove "auto", it's ↵Chris Buechler2015-09-292-4/+6
| | | | | | just a synonym for IKEv2. Ticket #4873" This reverts commit 47f802694a1e1dfbbd011d7ec431c0948358b5c3.
* Use the appropriate parent interface with gateway groups using CARP VIPs.Chris Buechler2015-09-291-2/+9
| | | | Ticket #4990
* Do a service reload of dyndns when changing gateways in case something hasChris Buechler2015-09-291-0/+2
| | | | changed. Ticket #5214
* Disable DHS as a dynamic DNS provider option. It's never worked, andChris Buechler2015-09-292-5/+6
| | | | | | | fixing is more complex than just fixing the variable screw up and disabling cert validation for their SSLLabs F-graded site. Updates made on their site even take quite some time to be reflected, seems to be a largely abandoned service.
* Use self rather than any in auto-added IPsec rules to preventChris Buechler2015-09-281-8/+8
| | | | over-matching. Ticket #5211
* Ensure this only contains a partial name, not a path, before attempting to ↵jim-p2015-09-281-0/+1
| | | | craft a full name and read the file. Fixes #5203.
* Merge pull request #1938 from phil-davis/patch-5Renato Botelho2015-09-281-2/+21
|\
| * Redmine #5200 be less aggressive about DHCP Pool Notice V2Phil Davis2015-09-261-2/+21
| | | | | | | | | | This one will log_error() the DHCP pool message when it detects the inconsistency at the end of the setup wizard during reload all. That way it can still be seen in the system log that this happened, and one day someone might chase down all the steps in the "reload all" process. Compare this with https://github.com/pfsense/pfsense/pull/1935 and choose which way you would like to go.
* | Merge pull request #1939 from doktornotor/patch-5Renato Botelho2015-09-281-3/+10
|\ \ | |/ |/|
| * Fix comment languagedoktornotor2015-09-281-1/+1
| |
| * Remove syslog.conf entries on package uninstall (Bug #5210) - RELENG_2_2doktornotor2015-09-271-3/+10
|/ | | The remove_text_from_file() is not needed at all. However, system_syslogd_start() must be run after the package entries are gone from config.xml, otherwise system_syslogd_start() just re-adds the (now almost removed) package logging configuration from there.
* Reset the value of a package field before this test in case it has no ↵jim-p2015-09-241-0/+1
| | | | default. Fixes #5199
* Merge pull request #1933 from phil-davis/patch-4Renato Botelho2015-09-241-10/+14
|\
| * Redmine #5196 Remove incorrect text about DNS servers - RELENG_2_2Phil Davis2015-09-241-10/+14
|/ | | | The correct text is already displayed under the DNS server boxes at line 892. This should also be done to master once the conversion of services_dhcp.php to bootstrap is stable.
* Use get_interface rather than find_interface here. It'll work for VIPs on ↵Chris Buechler2015-09-231-2/+2
| | | | gateway groups this way, and cache doesn't really matter here. Partial fix for Ticket #4990
* Do not pass vouchers shorter than 5 characters to voucher application, theyLuiz Otavio O Souza2015-09-221-2/+4
| | | | | | | are too short to be a valid voucher. Discussed with: Jim P Issue: #4985
* Merge pull request #1928 from phil-davis/patch-1Renato Botelho2015-09-221-14/+27
|\
| * Redmine #4568 Preserve MLPPP settings when saving interface settings ↵Phil Davis2015-09-221-14/+27
|/ | | | | | RELENG_2_2 Vagain with errors fixed. Supersedes https://github.com/pfsense/pfsense/pull/1781
* Merge pull request #1790 from phil-davis/pkg-install-4884-RELENG_2_2Renato Botelho2015-09-211-6/+12
|\
| * Pkg install error handling and connect timeout RELENG_2_2Phil Davis2015-07-271-6/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Fixes Redmine #4884 1) Line 778-780 - If the fetch of any of the package additional files fails then bail out. This prevents half-installed packages that look like they had a successful install. 2) Line 1458 - use the return boolean value from download_file_with_progress_bar() to determine success or failure here, like is done in the other places in this file. I had a case of installing a package with an error (timeout) and the download (I presume it was the download code) had left an empty file /usr/local/pkg/autoconfigbackup.xml - it passed the file_exists() check and the rest of the code went on to happily install the "nothing" in the package and then claim the package was successfully installed :( After the above 2 changes I could get reliable indication of success/failure of the package install and the code would abort nicely if a download went wrong. 3) Package installs happen either: i) On the end of a boot after upgrade or config restore, or; ii) Online while the main system is running (happily) Therefore there is no need to rush to abort if the download of a package file is taking some time to get started. It seems better to me to wait a decent amount of time rather than abort. Thus I have increased the connect timeout for this from the default (5) to 30 seconds. This makes my crap sites load packages much better :)
* | GratisDNS support for hosts without subdomainsmortencombat2015-09-211-2/+9
| | | | | | | | Resubmit of #1793
* | Add L2TP server's interface to mpd.confTarasSavchuk2015-09-211-0/+7
| | | | | | | | | | https://redmine.pfsense.org/issues/4830 https://forum.pfsense.org/index.php?topic=95908.0
* | Merge pull request #1907 from doktornotor/patch-5Renato Botelho2015-09-211-3/+6
|\ \
| * | pkg_edit.php - fix issue where default value was not being populated for ↵doktornotor2015-09-191-3/+6
| | | | | | | | | | | | | | | | | | | | | newly added fields Backport from PR #1906 / PR #1787 for RELENG_2_2. Check if the actual $fieldname element is present in the $a_pkg[$id] array before trying to assign its value. Do same with default_value. Fixes issue where default value was not being populated for newly added fields.
* | | Merge pull request #1916 from doktornotor/patch-15Renato Botelho2015-09-211-32/+50
|\ \ \
| * | | Fix Cloudflare support for Dynamic DNS Updatesdoktornotor2015-09-201-32/+50
| |/ / | | | | | | | | | | | | Backport of #1812 to RELENG_2_2 The current implementation isn't working due to API change. Credits: det0nat3 @ https://forum.pfsense.org/index.php?topic=87436.msg534817#msg534817
* | | Merge pull request #1807 from miken32/RELENG_2_2Renato Botelho2015-09-211-0/+9
|\ \ \
| * | | Fix missing DH group 22-24Michael Newton2015-08-041-0/+9
| | | |
* | | | Merge pull request #1836 from phil-davis/patch-4Renato Botelho2015-09-211-1/+9
|\ \ \ \
| * | | | Ignore DHCP pools that are out of range RELENG_2_2Phil Davis2015-08-281-1/+9
| | | | | | | | | | | | | | | Backport of https://github.com/pfsense/pfsense/pull/1824
* | | | | Merge pull request #1913 from doktornotor/patch-11Renato Botelho2015-09-211-1/+1
|\ \ \ \ \
| * | | | | pkg-utils.inc typo fix - RELENG_2_2doktornotor2015-09-201-1/+1
| | |_|/ / | |/| | |
* | | | | Merge pull request #1921 from doktornotor/patch-20Renato Botelho2015-09-211-4/+12
|\ \ \ \ \
| * | | | | show openvpn interfaces while reassigning the interfaces for a restored ↵doktornotor2015-09-201-4/+12
| |/ / / / | | | | | | | | | | | | | | | config backup - RELENG_2_2
* | | | | Merge pull request #1923 from phil-davis/patch-5Renato Botelho2015-09-211-6/+4
|\ \ \ \ \
| * | | | | Redmine #5162 do not allow alias rename to an existing name - RELENG_2_2Phil Davis2015-09-211-6/+4
| |/ / / /
* | | | | Merge pull request #1926 from doktornotor/patch-23Renato Botelho2015-09-212-10/+20
|\ \ \ \ \ | |/ / / / |/| | | |
| * | | | fix interface assignment menus running off VGA screendoktornotor2015-09-211-1/+1
| | | | | | | | | | | | | | | Remove leftover :
| * | | | fix interface assignment menus running off VGA screendoktornotor2015-09-211-5/+9
| | | | |
| * | | | fix interface assignment menus running off VGA screendoktornotor2015-09-211-4/+10
|/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When using VGA console, interface assignment can be a real pain in the ass because of the standard 80 columns width. Dmesg reports the many interface description names in very long strings that don't fit in a row, this breaks the nice appearance of the interface list in the assignment menu. The aestethics is one thing, but the real pain is that the interface list goes off screen by the time the menu asks for the WAN interface name, if there are many interfaces present. It's a real problem to choose from a list which is not visible anymore. One fix is to maximize the length of the interface description to 48 chars. The second fix (and also improvement for better overlooking when the list really goes off) is to print a small list of the interface names at each question. This is necessary because when somebody wants to assign the first interface to the last Optional port, the big list will be way off screen by then, and the name of it won't be visible. This also makes it nice clean and straightforward.
OpenPOWER on IntegriCloud