6606 Commits

Author SHA1 Message Date
Ad Schellevis
4dbc24ef82 (filter) move bogons, without breaking application logic, for https://github.com/opnsense/core/issues/1331 2017-01-16 09:29:39 +01:00
Franco Fichtner
c5b1ddef72 ddb: /etc/ddb.conf is perfectly fine, always use it 2017-01-15 12:07:39 +01:00
Franco Fichtner
9079f06dd9 mvc: contained fix for apply button spinner on 17.1 2017-01-13 12:43:57 +01:00
Ad Schellevis
a0e9f738aa fix Content-Disposition for chrome in captive portal and network insight 2017-01-11 22:31:23 +01:00
Franco Fichtner
6b39cd2e45 ntp: fix a typo spotted by pavelb 2017-01-11 18:36:39 +01:00
Franco Fichtner
bd188bd895 system: correctly apply /dev/pf flags if loader.conf was missing 2017-01-10 17:15:45 +01:00
Franco Fichtner
cf48dbb970 web proxy: disable caching more carefully; /var MFS caching is ok
PR: https://forum.opnsense.org/index.php?topic=4227.0
2017-01-10 09:11:09 +01:00
Franco Fichtner
d3e27cface web proxy: lock down caching completely if set to off
PR: https://forum.opnsense.org/index.php?topic=4152.0
2017-01-09 09:08:38 +01:00
Franco Fichtner
397c95f89c interfaces: better safe than sorry 2017-01-09 08:59:09 +01:00
Franco Fichtner
e97c4f1d11 interfaces: fix a crash report 2017-01-09 08:45:31 +01:00
Franco Fichtner
6c6b8f1d29 interfaces: fix a crash report
There could be another error in here with the reported IPv6 issues...
2017-01-09 08:13:08 +01:00
Franco Fichtner
e1733a01bf ntp: fix a crash report 2017-01-09 08:02:31 +01:00
Franco Fichtner
3bbe389533 interfaces: fix validation of hex in PHP 7
PR: https://github.com/opnsense/core/issues/1331
2017-01-08 09:38:56 +01:00
Franco Fichtner
6801b20c06 src: use the opportunity to scrub supurious ";;" spots 2017-01-07 10:46:06 +01:00
Ad Schellevis
15aaebc87e (mvc) still delivering twice, funny thing is nobody probably noticed because delivered zip files (from CP) are unpacked normally 2017-01-06 18:55:38 +01:00
Franco Fichtner
92ed1a7b63 mvc: remove unused mutable table work in progress for stable/17.1 2017-01-06 18:35:35 +01:00
Ad Schellevis
0c000739f3 (mvc) bugfix afterExecuteRoute, on some occasions content could be delivered twice... 2017-01-06 17:21:53 +01:00
Franco Fichtner
fe5eb31a37 firmware: update these numbers
i386 is less storage-intense, but a reasonable amount of
free storage space is recommended in any case.
2017-01-05 15:10:06 +01:00
Alexander Shursha
e818a80539 Fix setting locale 2017-01-05 10:00:56 +01:00
Franco Fichtner
fadc0ab5ad load balancer (relayd): remove from core 2017-01-03 23:40:46 +01:00
Franco Fichtner
44e4ae85c0 upnp: remove from core 2017-01-03 23:29:13 +01:00
Franco Fichtner
130d52da8f wol: remove from core 2017-01-03 23:21:10 +01:00
Franco Fichtner
c91841afd6 igmp proxy: remove from core 2017-01-03 23:09:19 +01:00
Franco Fichtner
52184b09d3 snmp: remove from core 2017-01-03 22:58:42 +01:00
Franco Fichtner
80eefebf42 pkg: also rc.shutdown hook, better for ACPI shutdown 2017-01-03 17:54:51 +01:00
Franco Fichtner
a25633f1f9 intrusion detection: two more 2017-01-03 09:41:51 +01:00
Franco Fichtner
5cd40f0422 intrusion detection: fix spacing for apply button spinner 2017-01-03 09:31:31 +01:00
Franco Fichtner
d14bfe618f bump copyright; happy new year! 2017-01-01 14:39:47 +01:00
Ad Schellevis
151e633d09 (dhcpd/unbound) don't try to handle empty section, closes https://github.com/opnsense/core/issues/1320 2016-12-31 16:25:50 +01:00
Franco Fichtner
54e63dc41f system: options for IDS and Web Proxy XMLRPC sync; closes #1319 2016-12-31 15:12:32 +01:00
Franco Fichtner
3773faf7bf wol: fixed plist, but did not add file :D 2016-12-31 15:07:06 +01:00
Franco Fichtner
9fb7a30568 system: more migration of xmlrcp sync settings #1319 2016-12-31 15:04:19 +01:00
Franco Fichtner
2e44a885ca plugins: xml sync refactor for ipfw features #1319 2016-12-31 14:11:51 +01:00
Ad Schellevis
6e54b6c00b Merge pull request #1318 from sxnxl/master
Optimized dhcp_clean_leases()
2016-12-31 10:40:24 +01:00
Ad Schellevis
5f3936ab36 (netflow) fix missing check for egress_only 2016-12-30 17:42:53 +01:00
Senol Korkmaz
5d93e8d77d removed some whitespace characters from pattern for more optimization 2016-12-29 14:56:59 +03:00
Senol Korkmaz
9f883fd722 use regular expressions to optimize dhcp_clean_leases() 2016-12-29 14:25:54 +03:00
Franco Fichtner
5b4acfac2a firmware: mark auf-feindgebiet.de as Cloudflare CDN
This is a pretty good option for anybody with a lack of a viable
local mirror, sparked by talks of a South-East Asia region mirror.
2016-12-28 16:09:20 +01:00
Andrew Berry
16ffbff991 Note that src and dst ports only apply to TCP and UDP 2016-12-28 15:59:08 +01:00
Franco Fichtner
c687c9bb36 system: fix crash report in previous 2016-12-28 13:39:16 +01:00
Franco Fichtner
deda19dc61 system: tweak wording on previous 2016-12-28 13:32:09 +01:00
Franco Fichtner
0caeb312c0 pkg: fix plist 2016-12-28 13:22:22 +01:00
Franco Fichtner
1d694b2f29 pkg: for the moment "openvpn23" is the right package
FreeBSD added OpenVPN 2.4, but we're not ready yet.
2016-12-28 13:20:41 +01:00
Franco Fichtner
384b751515 scripts: fix line breaks in csv 2016-12-28 10:26:32 +01:00
Ad Schellevis
c726dc39cf (proxy) fix subnet computation using netaddr.IPNetwork, closes https://github.com/opnsense/core/issues/1309 2016-12-27 18:13:19 +01:00
Ad Schellevis
15657d8749 (configd) add netaddr.IPNetwork to template helpers, for https://github.com/opnsense/core/issues/1309 2016-12-27 18:10:57 +01:00
Ad Schellevis
99dac4ab7e (webconfigurator) optionally limit ciphers. closes https://github.com/opnsense/core/issues/1301 2016-12-27 17:23:01 +01:00
Ad Schellevis
5f7fa5900d (IDS) fix previous 2016-12-27 12:21:50 +01:00
Ad Schellevis
565fd72bba (ids) add support for inline configuration settings (subscription based url's for example), add basic auth support.
Example supported format:

<?xml version="1.0"?>
<ruleset>
    <location url="https://www.snort.org/rules/snortrules-snapshot-2990.tar.gz?oinkcode=%%snort.oinkcode%%" prefix="Snort"/>
    <files>
        <file description="blacklist" url="inline::rules/blacklist.rules">snort.blacklist.rules</file>
    </files>
    <properties>
        <property name="snort.oinkcode" default=""/>
    </properties>
</ruleset>

---
Registers the setting "snort.oinkcode" which is used to construct the download url.
This commit doesn't include definitions for new content, in case someone wants to create a definition file, it should be easy now :)
2016-12-27 12:08:54 +01:00
Franco Fichtner
cb051070a1 pkg: add release switch formerly handled by tools.git 2016-12-24 14:56:34 +01:00