| Commit message (Expand) | Author | Age | Files | Lines |
* | Only include a scheduled rule if it is strictly before the end timeRELENG_2_1_4 | Phil Davis | 2014-06-20 | 1 | -1/+1 |
* | Remove extra data after space and fix pf rule syntax. It should fix #3688 | Renato Botelho | 2014-06-20 | 1 | -1/+1 |
* | Do not garble the error logging message | Ermal | 2014-03-20 | 1 | -3/+4 |
* | Try to restore last working ruleset rather than staying without configuration... | Ermal | 2014-03-20 | 1 | -6/+11 |
* | Disable default allow incoming rules for 6to4 and 6rd interfaces. This rule u... | Ermal | 2014-03-17 | 1 | -2/+4 |
* | Only add dhcpv6 client allow rules if ipv6allow is set | Renato Botelho | 2014-02-18 | 1 | -1/+1 |
* | Move 'allow dhcpv6 client' rules above block bogonsv6 ones, it should fix #3395 | Renato Botelho | 2014-02-18 | 1 | -15/+18 |
* | captive portal, don't generate rules for disabled portal | PiBa-NL | 2014-02-18 | 1 | -0/+2 |
* | Move this global declaration to the proper file rather than backend code | Ermal | 2014-02-17 | 1 | -12/+0 |
* | Load only the options rather than clearing the whole ruleset. This solves a p... | Ermal | 2013-12-06 | 1 | -1/+1 |
* | Remove 0.0.0.0 from automatic outbound nat rules | Renato Botelho | 2013-11-28 | 1 | -1/+1 |
* | Fix 0.0.0.0 mask for automatic outbound NAT | Renato Botelho | 2013-11-28 | 1 | -1/+1 |
* | Fix #3331. Set interface subnet as destination when VIP is in the same subnet... | Renato Botelho | 2013-11-21 | 1 | -1/+4 |
* | Add subnet to 0.0.0.0 otherwise it's not added to table, ticket #2416 | Renato Botelho | 2013-11-18 | 1 | -1/+1 |
* | Remove unused variables and fix automatic nat to alias-address | Renato Botelho | 2013-11-13 | 1 | -5/+1 |
* | Add missing count increment | Renato Botelho | 2013-11-13 | 1 | -0/+1 |
* | Handle comma-separated list of remote networks when making vpn_networks table | Phil Davis | 2013-11-12 | 1 | -2/+5 |
* | Unset this variable used in the loop to avoid having wrong information | Ermal | 2013-11-07 | 1 | -0/+2 |
* | Do not forget the trace in the pf.conf that something went wrong during rules... | Ermal | 2013-11-07 | 1 | -1/+1 |
* | Make sure pf rule labels never have more than 63 chars. It should fix #3208 | Renato Botelho | 2013-10-23 | 1 | -25/+35 |
* | Fix #3268 - avoid pf table names conflict: | Renato Botelho | 2013-10-16 | 1 | -0/+12 |
* | use (self) instead of any for web lockout | Chris Buechler | 2013-10-04 | 1 | -1/+1 |
* | use (self) rather than any as the destination for the lockout rules | Chris Buechler | 2013-10-04 | 1 | -2/+2 |
* | Do not include disabled OpenVPN in vpn_networks and negate_networks | Phil Davis | 2013-09-10 | 1 | -4/+6 |
* | Correct typo that prevents dhcp rules from properly being generated. | Ermal | 2013-09-10 | 1 | -1/+1 |
* | Fix errant display of "0 table deleted" during filter reload on console. | jim-p | 2013-09-09 | 1 | -1/+1 |
* | Ticket #3181 do the state flushing only on down gateway detection rather than... | Ermal | 2013-09-05 | 1 | -11/+5 |
* | Revert "Revert back the behaviour to cleanup all states for 2.1 Fixes #3181 a... | Ermal | 2013-09-05 | 1 | -1/+27 |
* | Make the operation of saving old rule nearby the writing operation to be logi... | Ermal | 2013-09-04 | 1 | -4/+4 |
* | Sprinkle some unsets to reduce footprint and correct some whitespaces | Ermal | 2013-09-04 | 1 | -19/+17 |
* | filter_generate_port error log function name | Phil Davis | 2013-09-04 | 1 | -1/+1 |
* | Revert back the behaviour to cleanup all states for 2.1 Fixes #3181 and relat... | Ermal | 2013-09-03 | 1 | -27/+1 |
* | Fixes #3173 if any port information exists on the rule than put it on the NEG... | Ermal | 2013-09-03 | 1 | -27/+36 |
* | touch up text, s/nat/NAT/ | Chris Buechler | 2013-09-03 | 1 | -2/+2 |
* | Fix selection of IPv6 target IP for IPv6 Outbound NAT rules. | Chris Buechler | 2013-08-17 | 1 | -0/+6 |
* | Unbreak limitrules and probably pfblocker errors. Spotted-by: Jim | Ermal | 2013-08-15 | 1 | -3/+2 |
* | Add a parameter, off by default, to expand all alias items, including hostnames | Renato Botelho | 2013-08-14 | 1 | -7/+7 |
* | Try to do the loading operations as close as possible to avoid any issues com... | Ermal | 2013-08-06 | 1 | -4/+4 |
* | fix text - s/occured/occurred/ | Chris Buechler | 2013-08-01 | 1 | -1/+1 |
* | the state type is required/valid for all specifications of protocol, not | Chris Buechler | 2013-08-01 | 1 | -1/+1 |
* | Fix up filter_pflog_start - optimize some code, and fix $retval so that it wi... | jim-p | 2013-07-30 | 1 | -2/+5 |
* | Show the name of the unresolvable alias name as well as the rule description ... | jim-p | 2013-07-30 | 1 | -4/+6 |
* | Optimization has nothing to do with limits | Ermal | 2013-07-25 | 1 | -1/+1 |
* | Fix #3106, parse 'not' rules right on destination for port forward + reflecti... | Renato Botelho | 2013-07-25 | 1 | -4/+5 |
* | Allow advanced options state-related parameters to be used for TCP, UDP and ICMP | Phil Davis | 2013-07-24 | 1 | -16/+22 |
* | Minimize inclusion of bogonsv6 | Phil Davis | 2013-07-19 | 1 | -3/+18 |
* | Don't generate reflection rules if reflection is disabled for that rule. | jim-p | 2013-07-16 | 1 | -13/+14 |
* | Don't automatically add hidden rules to pass all IPv6 traffic to/from delegat... | jim-p | 2013-07-10 | 1 | -18/+0 |
* | Add independent logging choices to disable logging of bogon network rules and... | jim-p | 2013-07-09 | 1 | -8/+18 |
* | Fix typo in filter.inc. Fixes #3028. | Daniel Becker | 2013-07-07 | 1 | -1/+1 |