julian
dfe0135978
Max's changes got left out of the MRT commit.
2008-05-09 23:53:01 +00:00
mlaier
5cb64aae63
Make ALTQ cope with disappearing interfaces (particularly common with mpd
...
and netgraph in gernal). This also allows to add queues for an interface
that is not yet existing (you have to provide the bandwidth for the
interface, however).
PR: kern/106400, kern/117827
MFC after: 2 weeks
2008-03-29 00:24:36 +00:00
remko
dfed0500c5
MFOpenBSD rev 1.393 pf.conf.5
...
do not describe `/' as solidus; from Allen (freebsd pr120484);
PR: 120484
Submitted by: Allen <alandsidel at 1001islington dot com>
MFC After: 3 days
2008-02-11 21:09:34 +00:00
mlaier
8ad5ea95ae
Update for libpcap 0.9.8
2007-10-16 02:12:06 +00:00
mlaier
73f16a7800
Lost these during the import. Hand me the pointy hat.
...
Approved by: re (implicit)
2007-07-03 14:08:49 +00:00
mlaier
edb0b64179
Commit resolved import of OpenBSD 4.1 pf userland from perforce.
...
Approved by: re (kensmith)
2007-07-03 12:30:03 +00:00
mlaier
d1f1f8d084
This commit was generated by cvs2svn to compensate for changes in r171169,
...
which included commits to RCS files with non-trunk default branches.
2007-07-03 12:22:02 +00:00
mlaier
9501569295
Import pf userland from OpenBSD 4.1 and (for ftp-proxy) libevent 1.3b as
...
a local lib.
2007-07-03 12:22:02 +00:00
remko
48e05cbb50
Revert my previous change, add an MLINK from securelevel.7 to security.7
...
Discussed with: brueffer
2007-06-01 21:33:21 +00:00
remko
02d75b0108
Change securelevel(7) to security(7). Yes i am aware
...
that this is within the contrib directory.
PR: docs/104402
Submitted by: Dr. Markus Waldeck <waldeck at gmx dot de>
Discussed with: mlaier
2007-06-01 21:09:11 +00:00
dhartmei
b84c57b21a
From OpenBSD, rev. 1.379
...
Document how 'allow-opts' applies to routing headers in IPv6.
MFC after: 1 week
Discussed with: mlaier
2007-05-21 20:12:35 +00:00
mlaier
7a56ec02c0
From OpenBSD, rev. 1.91:
...
fix servicecurve check; no point in checking the same sc three times, it
was obviously intended to check all three. has been wrong since the
beginning, 4 years... noticed by Earl Lapus <earl.lapus@gmail.com>, Vasil
Dimov <vd@FreeBSD.org> mailed me then, ok mcbride
MFC after: 3 days
2006-11-30 18:55:36 +00:00
mlaier
3c9a14bd36
Mention that we do not support route labels in the BUGS section.
...
PR: docs/93590
Reported by: Niki Denev
2006-10-30 15:15:37 +00:00
glebius
cd66f71303
- Note that the synchronisation interface needs to be up and have
...
an IP address assigned.
- Add "quick" keyword to pf.conf example.
PR: docs/85209
2006-06-06 12:35:53 +00:00
mlaier
332f3f5a7b
Document authpf's requirement for a mounted fdescfs(5).
...
PR: docs/89635
MFC after: 1 day
2006-03-28 15:26:16 +00:00
mlaier
26d969a376
Constfy errstr as it is in OpenBSD to unbreak the build.
...
Pointed out by: Suken Woo, Martin Wilke, Wesley Morgan
2006-03-15 16:28:12 +00:00
mlaier
8e7c134331
Use strtonum now that we have it in libc as well.
2006-03-15 00:30:19 +00:00
mlaier
74c57f2ec0
Fix build after timeval.tv_sec changed from long to time_t.
2005-12-25 22:57:08 +00:00
yar
327895a26d
Add an rc.d script to start pfsync at the right moment of the
...
system boot, and hook it up in the system.
The separate script is needed because in the presence of various
interface lists in rc.conf ($network_interfaces, $cloned_interfaces,
$sppp_interfaces, $gif_interfaces, more to come) it is hard to start
them orderly, so that pfsync is brought up after its syncdev, which
is required for the proper startup of pfsync.
Discussed with: mlaier on -pf
MFC after: 5 days
2005-10-02 18:59:02 +00:00
mlaier
f86976eb12
Redirect bridge(4) to if_bridge(4). These should have pointed to if_bridge
...
from the begining.
Reminded by: ru
2005-09-28 08:11:15 +00:00
csjp
f267b4783c
FreeBSD now supports BIOCLOCK. So we can use it now.
...
Reviewed by: mlaier
2005-08-23 00:03:58 +00:00
brueffer
ec4f7f03b1
More tcpdump 8->1 cleanup.
...
Approved by: mlaier
MFC after: 3 days
2005-08-06 13:03:03 +00:00
brueffer
2a75eb6afb
- Remove MLINKS to nonexistant manpages
...
- Change some section numbers to match reality
- For MLINKS to manpages from ports, mention which port installs them
MFC after: 3 days
2005-07-14 20:29:08 +00:00
mlaier
b28479dfe2
Resolve conflicts created during the import of pf 3.7 Some features are
...
missing and will be implemented in a second step. This is functional as is.
Tested by: freebsd-pf, pfsense.org
Obtained from: OpenBSD
2005-05-03 16:55:20 +00:00
mlaier
511d1c13c3
Import pf userland from OpenBSD 3.7 (OPENBSD_3_7 as of today)
2005-05-03 16:47:37 +00:00
mlaier
f9e60af500
This commit was generated by cvs2svn to compensate for changes in r145837,
...
which included commits to RCS files with non-trunk default branches.
2005-05-03 16:47:37 +00:00
glebius
d94b19b89c
- remove OpenBSDisms, add FreeBSDisms
...
- comment out feature, we do not have yet: tcpdumping on pfsync,
add a BUGS section
- reference carp.4
- dereference bpf(4), tcpdump(7), hostname.if(5)
- sort references
- tell when pfsync appeared in FreeBSD
Reviewed by: mlaier
MFC after: 1 week
2005-02-23 17:37:39 +00:00
mlaier
ccaba02daa
Fix sloppy use of "manpage", bump .Dd where applicable and rename RED to
...
Random Early Detection (not ... Drop) in order to be consistent with other
documentation on ALTQ
Pointed out by: simon, ru, Brad Davis
2005-02-07 23:20:12 +00:00
mlaier
8b6d2b4fe7
Be more verbose about altq SYNOPSIS and add more linkage in the relating pf
...
documents.
Inspired by: scottl
Reviewed by: Brad Davis <so14kNOso14kSPAMcom>
MFC after: 3 days
2005-02-07 11:46:36 +00:00
mlaier
89e05e38ca
Fix a reference from pool(9) -> zone(9), but keep on talking about "memory
...
pools" as that is what UMA provides.
Submitted by: Jay <jay NO meangrape SPAM com>
2004-11-14 17:05:54 +00:00
mlaier
d848661392
Rename the QUEUEING section to QUEUEING/ALTQ to make it easier to find the
...
appropiate section when redirected from ALTQ(4).
MFC after: 2 days
2004-10-07 15:39:02 +00:00
mlaier
c5e647a2a2
Make pflogd cope with module unload (and the sudden disappearing of pflog0).
...
Instead of eating all the available CPU we now shutdown gracefully.
Submitted by: yongari
MFC after: 3 days
2004-10-05 08:26:34 +00:00
mlaier
283a694fdb
Document a problem with user/group filtering. With debug.mpsafenet=1 this
...
might result in a deadlock. The fix involves critical changes in the PF
locking strategy (which will happen after 5.3R). For now advise users to set
debug.mpsafenet=0 if they use this kind of filtering.
The same problem exists for IPFW.
mdoc help from: simon
MFC after: 2 days
2004-10-03 10:42:42 +00:00
mlaier
f00a812528
PFIL_HOOKS is no longer an optional item.
...
Submitted by: Anders Hanssen
MFC after: 1 day
2004-09-26 16:10:40 +00:00
mlaier
61e73d53e0
Bring in some examples (and create space for future work here):
...
- Add OpenBSD example rulesets as advertised in etc/pf.conf and pf.conf(5)
- Tweak the pointer to fit the FreeBSD default location share/examples/pf
- Account for the new directory in BSD.usr.dist (no hier(7) change required
as share/examples is an opaque item there).
Obtained from: OpenBSD
Reminded by: Thomas T. Veldhouse
PR: docs/71691
MFC after: 2 days
2004-09-14 01:07:19 +00:00
mlaier
8fda63d007
Make pflogd(8) store pcap_sf_pkthdr instead of MD timeval contaminated
...
pcap_pkthdr. This makes /var/log/pflog standart compliant on 64bit archs.
OpenBSD has fixed this by changing the bpf timeval to 32bit in the kernel,
so no need to report this over (again).
PR: bin/71096 (w/ changes)
Submitted by: Ville-Pertti Keinonen
Tested by: amd64(submitter), sparc64(yongari), i386(myself)
MFC after: 3 days
2004-08-31 18:04:34 +00:00
mlaier
7dfba5d635
Loopback a fix from Cedric Berger:
...
Fix table add/replace commands with securelevel=2.
Reported by James J. Lippard.
Discussed with: yongari
MFC after: 5 days
2004-08-22 16:58:06 +00:00
mlaier
51d3d6ad22
Import pfctl_table.c#1.61 from OpenBSD into vendor branch.
2004-08-22 16:53:39 +00:00
mlaier
58f0a68784
Fix printing of u_int64_t with a cast to unsigned long long.
...
Found-by: tinderbox(amd64)
2004-06-17 15:23:51 +00:00
mlaier
f60cf9b58b
Commit userland part of pf version 3.5 from OpenBSD (OPENBSD_3_5_BASE).
2004-06-16 23:39:33 +00:00
mlaier
6a32f6ec2e
Import userland of pf 3.5 from OpenBSD (OPENBSD_3_5_BASE).
2004-06-16 23:26:00 +00:00
mlaier
a5725614a7
This commit was generated by cvs2svn to compensate for changes in r130614,
...
which included commits to RCS files with non-trunk default branches.
2004-06-16 23:26:00 +00:00
mlaier
3442b26030
FreeBSD-ify the manpage. Our inetd does not support bind-address:port syntax
...
Christian will follow up with some additional words about how to protect
this from the outside world.
Submitted-by: brueffer
Approved-by: bms(mentor)
2004-05-27 23:51:05 +00:00
mlaier
903381680b
FreeBSD-if .4 manpages for pf/pflog/pfsync.
...
PR: docs/65687
Submitted by: Sergey Matveychuk
Approved by: bms(mentor)
2004-04-18 13:59:12 +00:00
obrien
c0b1fcdc1f
Fix $FreeBSD$ ids.
2004-03-16 17:24:06 +00:00
mlaier
4c91a73d42
Fix some style(9) related issues after discussion with/education from bde:
...
- Add <sys/param.h> and <limits.h> where required (do not depend on other
headers pulling it in).
- __dead -> __dead2
- #if defined() -> #ifdef
- Remove ugly PRIu64 macros and use %llu w/ (unsigned long long) cast.
All changes looped back to OpenBSD (where applicable) for easier sync in the
future.
Requested by: bde
Approved by: bms(mentor)
2004-03-15 13:41:17 +00:00
mlaier
b62869e4ee
Fix two instances of improper NULL/0 use idetified by the changes lately.
...
Submitted by: Patrick Marie
Approved by: bms(mentor)
2004-03-08 15:19:55 +00:00
mlaier
b5cdc99a73
Add local define of HTONL() as it was decided to protect this by _KERNEL
...
in <net/pfvar.h>
2004-02-28 18:41:43 +00:00
mlaier
c9eda2a3d0
Missed those two during the original import. Taken from OpenBSD's util.h
...
Approved by: bms(mentor)
2004-02-28 18:35:40 +00:00
mlaier
9b90066201
This commit was generated by cvs2svn to compensate for changes in r126357,
...
which included commits to RCS files with non-trunk default branches.
2004-02-28 18:35:40 +00:00