Jo-Philipp Wich
|
756f1e21ed
ruleset: fix emitting set_mark/set_xmark rules with masks
|
2 years ago |
Jo-Philipp Wich
|
3db474135c
ruleset: properly handle zone names starting with a digit
|
2 years ago |
Jo-Philipp Wich
|
43d8ef5167
fw4: fix formatting of default log prefix
|
2 years ago |
Jo-Philipp Wich
|
592ba4577e
main.uc: remove uneeded/wrong set reload restrictions
|
2 years ago |
Jo-Philipp Wich
|
b0a6bff4ee
tests: fix testcases
|
2 years ago |
Jo-Philipp Wich
|
145e1591a3
fw4: recognize `option log` and `option counter` in `config nat` sections
|
2 years ago |
Jo-Philipp Wich
|
ce050a8778
fw4: fall back to device if l3_device is not available in ifstatus
|
2 years ago |
Jo-Philipp Wich
|
f5fcdcf2c5
cli: introduce test mode and refuse firewall restart on errors
|
2 years ago |
Jo-Philipp Wich
|
a540f6d537
fw4: fix cosmetic issue with per-ruleset and per-table include paths
|
2 years ago |
Jo-Philipp Wich
|
695e8211d1
doc: fix swapped include positions in nftables.d README
|
2 years ago |
Jo-Philipp Wich
|
a4484d4612
fw4: support automatic includes
|
2 years ago |
Jo-Philipp Wich
|
ca7e3a1ab6
fw4: honour enabled option of include sections
|
2 years ago |
Jo-Philipp Wich
|
5a02f74ec3
tests: add missing fs.stat) mock data for `nf_conntrack_dummy`
|
2 years ago |
Stijn Tintel
|
111a7f780a
fw4: don't inherit zone family from ct helpers
|
2 years ago |
Jo-Philipp Wich
|
15c38317ef
fw4: add support for `option log` in rule and redirect sections
|
2 years ago |
Jo-Philipp Wich
|
d79911c7ad
fw4: support sets with timeout capability but without default expiry
|
2 years ago |
Jo-Philipp Wich
|
3b5a0338b3
tests: add test coverage for firewall includes
|
2 years ago |
Jo-Philipp Wich
|
11256ff037
fw4: add support for configurable includes
|
2 years ago |
Jo-Philipp Wich
|
53886e559b
fw4: fix crash in parse_cthelper() if no helpers are present
|
2 years ago |
Jo-Philipp Wich
|
5994466353
fw4: simplify `is_loopback_dev()`
|
2 years ago |
Jo-Philipp Wich
|
880dd31353
fw4: fix skipping invalid IPv6 ipset entries
|
2 years ago |
Jo-Philipp Wich
|
11410b80eb
ruleset: reorder declarations & output tweaks
|
2 years ago |
Jo-Philipp Wich
|
e1cb763b65
ruleset: reuse zone-jump.uc template for notrack and helper chain jumps
|
2 years ago |
Stijn Tintel
|
a063317d96
ruleset: fix conntrack helpers
|
2 years ago |
Stijn Tintel
|
e35e26b965
tests: add test for zone helpers
|
2 years ago |
Stijn Tintel
|
b9d35ff6b4
fw4.uc: don't skip zone for unavailable helper
|
2 years ago |
Stijn Tintel
|
11f5c7bf88
fw4.uc: fix zone helper assignment
|
2 years ago |
Jo-Philipp Wich
|
210991df51
fw4: prefer /dev/stdin if available
|
2 years ago |
Jo-Philipp Wich
|
4e5e322626
fw4: make `fw4 restart` behavior more robust
|
2 years ago |
Jo-Philipp Wich
|
221040ee1c
ruleset: emit time ranges when both start and stop times are specified
|
2 years ago |