Anton Engelhardt
|
9d7f49df47
redurects: add support to define multiple zones for dnat reflection rules
|
6 lat temu |
Kristian Evensen
|
509e673dab
firewall3: Improve ipset support
|
5 lat temu |
Jo-Philipp Wich
|
12a7cf9db1
Add support for DSCP matches and target
|
6 lat temu |
Alin Nastac
|
d2bbeb7d42
firewall3: make reject types selectable by user
|
6 lat temu |
Pierre Lebleu
|
08b2c61b4d
helpers: make the proto field as a list rather than one option
|
6 lat temu |
Felix Fietkau
|
35b3e74a18
defaults: add support for setting --hw on the xt_FLOWOFFLOAD rule
|
6 lat temu |
Jo-Philipp Wich
|
c1a295a500
defaults: add support for xt_FLOWOFFLOAD rule
|
6 lat temu |
Jo-Philipp Wich
|
41c2ab5e5c
ipsets: add support for specifying entries
|
6 lat temu |
Stijn Tintel
|
a3ef503ed5
zones: allow per-table log control
|
6 lat temu |
Jo-Philipp Wich
|
f50a524847
helpers: implement explicit CT helper assignment support
|
6 lat temu |
Jo-Philipp Wich
|
e751cde895
zones: drop outgoing invalid traffic in masqueraded zones
|
7 lat temu |
Jo-Philipp Wich
|
13698aafb5
global: remove automatic notrack rules
|
8 lat temu |
Ralph Sennhauser
|
6015fc0761
musl-compat: avoid kernel header conflicts
|
8 lat temu |
Jo-Philipp Wich
|
be8ead27f6
treewide: replace jow@openwrt.org with jo@mein.io
|
8 lat temu |
Jo-Philipp Wich
|
1d0bd45db0
ubus: print rule name when reporting errors
|
9 lat temu |
Jo-Philipp Wich
|
2807cc26b8
Selectively flush conntrack
|
10 lat temu |
Jo-Philipp Wich
|
bba31cce05
Use netmasks instead of prefix lengths internally
|
10 lat temu |
Steven Barth
|
e678dcbf03
Add support for netifd-generated rules
|
10 lat temu |
Steven Barth
|
2f392a3b91
Add support for device and direction parameters
|
10 lat temu |
Steven Barth
|
1097a30f1d
snat: add support for connlimiting port-range SNAT
|
10 lat temu |
Jo-Philipp Wich
|
31456301f5
Initial support for "config nat" rules - this allows configuring zone-independant SNAT and MASQUERADE rules
|
10 lat temu |
Jo-Philipp Wich
|
c114b1e380
Treat option tcp_ecn as integer, not bool
|
11 lat temu |
Jo-Philipp Wich
|
3b4303ddcf
Change fw3_parse_options() to indicate whether all options where parsed successfully
|
11 lat temu |
Jo-Philipp Wich
|
9d900a9f86
Treat redirects as port redirections if the specified dest_ip belongs to the router itself, this is a compatibility fix to firewall2.
|
11 lat temu |
Jo-Philipp Wich
|
d4980027ea
Implement limit and limit_burst options for rules.
|
11 lat temu |
Jo-Philipp Wich
|
3a3d85b3c7
Extend ipset option syntax to support specifying directions inplace.
|
11 lat temu |
Jo-Philipp Wich
|
ea46bc485f
Mark fw3_address objects that got resolved by fw3_parse_network()
|
11 lat temu |
Jo-Philipp Wich
|
f12271d15d
Rename struct fw3_rule_spec to struct fw3_chain_spec and move the declaration to options.h
|
11 lat temu |
Jo-Philipp Wich
|
1fbc7b77f4
Remove now unused fw3_format_*() functions
|
11 lat temu |
Jo-Philipp Wich
|
6b27a6665c
Drop iptables-restore and create rules through libiptc and libxtables
|
11 lat temu |