Franco Fichtner
db43f38d1c
firmware: allow to upgrade to 18.1.r1
...
Packages are not yet in place, but we need it for testing.
2017-12-24 10:32:19 +01:00
Ad Schellevis
b79ff62b6d
Firewall/nat. implement new rule generation for the sections done sofar. for https://github.com/opnsense/core/issues/1326
...
Moves most rule generation features in our filter, filter_generate_address() is only used in vpn_openvpn_export.php now, so to keep clearity we're going to move this out of the way for now too.
2017-12-23 17:36:03 +01:00
Ad Schellevis
8747cc94b4
Firewall/Nat, add Nat and Npt rule registrations, next step is to ditch the old code in filter.inc for these topics and then we only have to refactor the outbound code and some additional testing.
...
all for https://github.com/opnsense/core/issues/1326
2017-12-23 17:28:34 +01:00
Ad Schellevis
b6f8d5d67a
Firewall/rule parsing, missed a spot in isIpV4() https://github.com/opnsense/core/issues/1326
2017-12-23 16:40:20 +01:00
Ad Schellevis
4aea87fb24
Firewall/forward, check protocol for autogenerated rules. https://github.com/opnsense/core/issues/1326
2017-12-23 16:17:50 +01:00
Ad Schellevis
9479df5c8e
Firewall/rule parsing, some for some autogenerated rules we need to know for which protocol a rule is targeted. for https://github.com/opnsense/core/issues/1326
2017-12-23 16:15:22 +01:00
Ad Schellevis
054d69cd01
Firewall/forward, typo in ForwardRule.php https://github.com/opnsense/core/issues/1326
2017-12-23 15:37:53 +01:00
Franco Fichtner
160820d2df
pkg: fix plist
2017-12-23 15:24:43 +01:00
Ad Schellevis
b291345848
Firewall, rule parsing. move suffix to parameters for parsePlainCurly() , also for https://github.com/opnsense/core/issues/1326
2017-12-23 15:11:49 +01:00
Ad Schellevis
a347623b41
Firewall/forward, missed a spot in last refactor https://github.com/opnsense/core/issues/1326
2017-12-23 14:53:43 +01:00
Ad Schellevis
c77718cb6b
Firewall, portforward. https://github.com/opnsense/core/issues/1326
...
Rename NatRule to ForwardRule, it seems better to split the logic for the different nat types and reuse the functionality in the base class. A portforward is actually a rdr entry combined with nat if relection is enabled, 1-on-1 nat is the exact opposite (nat, optionally combined with rdr). Which would make the parse logic to complicated to read if combined.
2017-12-23 14:13:23 +01:00
Ad Schellevis
bc235a3a69
Firewall/rules parsing, add support for reuse of fieldnames in ruleToText(). for https://github.com/opnsense/core/issues/1326
2017-12-23 13:57:22 +01:00
Ad Schellevis
6337818383
firewall, refactor text output so we can reuse the same logic in other classes as well. moved logic out of __toString() to ruleToText() in Rule class, only small downside is that conversion functions need to be accessible from the Rule() class for this to work, which requires them to be protected in stead of private.
...
related to https://github.com/opnsense/core/issues/1326
2017-12-23 13:45:46 +01:00
Ad Schellevis
fa0bb4a98c
firewall/rule parser, move standard rule parser logic to reader() in Rule class for reuse and rename fetchActualRules() to parseFilterRules() to better reflect it's function.
...
related to https://github.com/opnsense/core/issues/1326
2017-12-23 13:24:53 +01:00
Ad Schellevis
280781b582
firewall/rule parser, better to switch fetchActualRules() to a generator.
2017-12-23 12:45:17 +01:00
Ad Schellevis
6628d7f495
firewall/portforward, missing ipproto in reflection nat rule. for https://github.com/opnsense/core/issues/1326
...
pf can guess the ip protocol, but this doesn't appear to be flawless.
2017-12-23 11:34:59 +01:00
Fabian Franz
831bfc711e
lighttpd: add mime type for WPAD/PAC
2017-12-23 10:30:12 +01:00
Ad Schellevis
65d08b716c
firewall/nat, regression in previous. https://github.com/opnsense/core/issues/1326
...
Because we can't use :network when interfaces don't have any address configured on filter load, we need to make sure we know which addresses are configured, add relevant ifconfig
data to setInterfaceMapping() in filter.inc.
2017-12-22 21:52:46 +01:00
Ad Schellevis
3b53e1d089
firewall/nat, replace portforward code for https://github.com/opnsense/core/issues/1326
2017-12-22 21:01:24 +01:00
Ad Schellevis
687e71dc3d
firewall/nat, regression in forward. https://github.com/opnsense/core/issues/1326
2017-12-22 20:59:53 +01:00
Ad Schellevis
8ed255c696
firewall/nat, work in progress port forwards. Class names may change later on, but functionally this part should be able to render the portforward rules, which will be integrated first before moving the other redirect/nat portions.
2017-12-22 20:12:41 +01:00
Ad Schellevis
6d6ac731c9
firewall/parser add prefix and suffix to parseInterface, https://github.com/opnsense/core/issues/1326
2017-12-22 20:09:19 +01:00
Franco Fichtner
50e53ab4a0
interfaces: reload filter before reloading plugins for connectivity
...
PR: https://forum.opnsense.org/index.php?topic=4727.0
PR: https://github.com/opnsense/core/issues/1403
2017-12-22 18:18:31 +01:00
Franco Fichtner
4e1c7d4011
network time: ntp breaks the overly overlong lines, fix their parsing
...
PR: https://github.com/opnsense/core/issues/1764
2017-12-22 07:53:49 +00:00
Franco Fichtner
0ae4af9a7f
network time: third server offers IPv6 #1374
2017-12-22 08:31:48 +01:00
Franco Fichtner
97daba95d9
network time: we haz a pool! #1374
...
While here, time-update-interval does not exist and update the
xml lint pass to pick up the sample file, too.
2017-12-21 18:28:24 +01:00
Franco Fichtner
0284604dda
ntpd: fix for valid negative offset; closes #1968
2017-12-21 10:21:29 +01:00
Franco Fichtner
7c66c4f750
wizard: also disable dnsmasq on wizard to avoid clash
2017-12-21 09:44:10 +01:00
Franco Fichtner
85c1e0a82f
web proxy: tweak previous
...
We can't fix reconfigure, but at least we can split up restart
to be an explicit stop start to push 'squid -z -N' into the middle.
PR: https://github.com/opnsense/core/issues/2008
2017-12-21 07:18:45 +00:00
Franco Fichtner
25ca2ad23f
web proxy: run setup.sh more often to properly do squid -z
...
PR: https://github.com/opnsense/core/issues/2008
2017-12-21 07:30:16 +01:00
Ad Schellevis
6ab11f0636
firewall/aliases, template missing check for existence. https://github.com/opnsense/core/issues/1971
2017-12-20 18:26:12 +01:00
Franco Fichtner
5db9141a45
power: finally add that reboot wait dialog
...
And a few more tweaks in the other spots.
2017-12-20 08:14:16 +00:00
Franco Fichtner
0645d11653
webgui: reload stuff part 1 #1347
...
Reload the client side. If we can't connect back, the second
part of this rework will make sure that the system reverts to
its former state and this reload will be able to pick it up.
While here kill the questionable login autocomplete toggle.
2017-12-20 07:33:41 +00:00
Franco Fichtner
83670156ce
openvpn: start later alongside IPsec
...
Matches previous, no apparent reason not to do this.
2017-12-20 00:43:36 +01:00
Franco Fichtner
ed9005ada5
ipsec: move to plugin bootup hook
...
Eventually, OpenVPN should be loaded alongside IPsec like
we do in newwanip scripts, but that requires some research.
2017-12-20 00:33:49 +01:00
Franco Fichtner
db11170dbd
pkg: fix plist
2017-12-19 20:27:04 +01:00
Ad Schellevis
78686814a4
traffix shaper, some small style fixes for https://github.com/opnsense/core/issues/2004
2017-12-19 19:21:33 +01:00
Ad Schellevis
f2a263b74b
Merge pull request #2006 from fabianfrz/ts_show_not
...
traffic shaper: add a ! for negated fields
2017-12-19 19:12:59 +01:00
Fabian Franz
9e5ea69585
traffic shaper: add a ! for negated fields
2017-12-19 19:05:45 +01:00
Ad Schellevis
980915871c
firewall, nat. work in progress for https://github.com/opnsense/core/issues/1326
2017-12-19 18:23:16 +01:00
Ad Schellevis
d3f245b646
firewall, utils (new). add getPortAlias() to figure out the ports within an alias for new style code, needed for https://github.com/opnsense/core/issues/1326
2017-12-19 18:21:50 +01:00
Ad Schellevis
48465e49f0
firewall/rules, move some more parse functions to the base class
2017-12-19 16:52:06 +01:00
Ad Schellevis
f58c2ece05
fix formatting for diag_dump_states.php https://github.com/opnsense/core/issues/2005
2017-12-19 15:09:53 +01:00
Franco Fichtner
426cbba88b
pkg: add finterprint for 18.1
2017-12-19 01:33:45 +01:00
Franco Fichtner
3f649be7db
firewall: fix typo
2017-12-19 07:06:53 +01:00
Franco Fichtner
d7b3a6ab79
interfaces: fix previous
2017-12-19 06:52:37 +01:00
Franco Fichtner
58184df417
interfaces: adjust messages for new IP
2017-12-19 00:01:18 +01:00
Franco Fichtner
a48167c403
wizard: add unbound to wizard, remove dnssec from default #1962
2017-12-18 21:55:48 +00:00
Ad Schellevis
e8a4fc1b46
ditch filterdns, since we've refactored the aliases in https://github.com/opnsense/core/issues/1971 the only use for this is ipsec, but it's doubtful if it's required. see https://github.com/opnsense/core/issues/2003
2017-12-18 20:44:16 +01:00
Franco Fichtner
c2210a6988
pkg: fix plist
2017-12-18 19:31:55 +01:00