Commit Graph

152 Commits

Author SHA1 Message Date
Jo-Philipp Wich
e0fa9a4881 iptables: update to v1.4.6, relocate patches - patch by Edgar Soldin
SVN-Revision: 19302
2010-01-23 22:28:32 +00:00
Nicolas Thill
94dbd93ea4 iptables: add an iptables-mod-ipset package (closes: #6327)
SVN-Revision: 18832
2009-12-18 17:17:49 +00:00
Felix Fietkau
1ab62895f7 iptables: move to 'Network' in menuconfig
SVN-Revision: 18713
2009-12-09 13:36:35 +00:00
Jo-Philipp Wich
cc7827d993 iptables: bump pkg revision
SVN-Revision: 18707
2009-12-08 20:53:27 +00:00
Jo-Philipp Wich
e830181f47 iptables: add comment match to the core package
SVN-Revision: 18706
2009-12-08 20:52:58 +00:00
Florian Fainelli
2d463950c3 fix breakage introduced with r18315
SVN-Revision: 18316
2009-11-05 14:35:36 +00:00
Florian Fainelli
dbdfbb4b5d remove the patch dir hack in iptables when building with an external tree, this did not work at all.
SVN-Revision: 18315
2009-11-05 14:21:05 +00:00
Felix Fietkau
f97b87b6e7 remove $(FPIC) from iptables, it is handled internally correctly. saves 2k on mips
SVN-Revision: 18098
2009-10-20 11:44:16 +00:00
Nicolas Thill
0e43e71159 remove ipset support from core, it is now provided by xtables-addons from the packages feed
SVN-Revision: 17844
2009-10-03 23:51:10 +00:00
Felix Fietkau
1b35350431 iptables: fix build error with linux 2.6.31
SVN-Revision: 17721
2009-09-25 14:10:42 +00:00
Florian Fainelli
34e22309ef libiptc and libxtables should install their libraries as symbolic links (#5313, #5639)
SVN-Revision: 17162
2009-08-07 09:36:55 +00:00
Florian Fainelli
034933808a install libiptc/libipulog from iptables (#5549)
SVN-Revision: 17089
2009-08-01 23:16:06 +00:00
Florian Fainelli
0c27222ac4 force iptables to be configured with ipv6 enabled (#5586)
SVN-Revision: 17076
2009-08-01 12:10:59 +00:00
Florian Fainelli
cd64d4ce6e make patches against iptables apply again after update to 1.4.4 (#5540)
SVN-Revision: 16878
2009-07-17 12:37:10 +00:00
Markus Wigge
fa7f32c962 upgrade to new upstream version 1.4.4
SVN-Revision: 16853
2009-07-15 16:33:01 +00:00
Florian Fainelli
67a444c462 fix typo in iptables makefile resulting in patches not being applied (#5311)
SVN-Revision: 16392
2009-06-09 07:54:46 +00:00
Florian Fainelli
d861885cbf do not apply iptables patches when building with CONFIG_EXTERNAL_KERNEL_TREE
SVN-Revision: 16336
2009-06-04 13:14:00 +00:00
Felix Fietkau
01392262c1 iptables: export libipq
SVN-Revision: 16164
2009-05-29 00:51:33 +00:00
Jo-Philipp Wich
addb4fe33f iptables: update imq userspace part
SVN-Revision: 15653
2009-05-07 03:06:56 +00:00
Jo-Philipp Wich
b7569a3a34 iptables: install essential headers into staging dir
SVN-Revision: 15621
2009-05-05 11:51:51 +00:00
Jo-Philipp Wich
1b890c945c iptables: fix segfault in xtables_parse_protocol() if an unknown protocol is specified for -p
SVN-Revision: 15573
2009-05-03 14:31:36 +00:00
Nicolas Thill
8c7602a3f4 iptables: - add libtool fixups - fix libiptc & libxtables packages, containing only symlinks but missing the actual library files - enable static versions of libiptc & libxtables - install pkgconfig .pc files as well - cleanup & reorg
SVN-Revision: 15572
2009-05-03 06:54:49 +00:00
Jo-Philipp Wich
26f40c4bd4 iptables: install libxtables.so and libiptc.so into staging dir
SVN-Revision: 15550
2009-05-02 00:53:41 +00:00
Jo-Philipp Wich
8738678fbf iptables: replace exot_error() with xtables_error() in layer7 patch
SVN-Revision: 15547
2009-05-01 21:30:43 +00:00
Hauke Mehrtens
e50d6f12f7 Update layer7 rules
SVN-Revision: 15544
2009-05-01 15:20:34 +00:00
Hauke Mehrtens
a93f9f0eee In r15501 the libxt_layer7.c was placed in a wrong location.
SVN-Revision: 15541
2009-05-01 15:15:56 +00:00
Jo-Philipp Wich
2515392870 drop iptables 1.3.8 and switch to to 1.4.3.2, refresh layer7 kernel patches and add packages for libiptc + libxtables
SVN-Revision: 15501
2009-04-29 23:31:23 +00:00
Imre Kaloz
6032279e79 we don't need the libiptc library
SVN-Revision: 15487
2009-04-29 13:55:49 +00:00
Imre Kaloz
3671591480 upgrade iptables to 1.4.3.2
SVN-Revision: 15478
2009-04-29 11:31:20 +00:00
Felix Fietkau
34939cad39 get rid of $Id$ - it has never helped us and it has broken too many patches ;)
SVN-Revision: 15242
2009-04-17 14:09:46 +00:00
Felix Fietkau
b72191aa74 fix a description which still mentioned ipp2p
SVN-Revision: 14603
2009-02-21 19:33:10 +00:00
Felix Fietkau
68d73be80c remove support for ipp2p - it's unmaintained, broken, overmatching and undermatching => not that useful for QoS
SVN-Revision: 14596
2009-02-21 16:30:44 +00:00
Gabor Juhos
e5c9f00637 netfilter: remove CHAOS, TARPIT and DELUDE references
SVN-Revision: 14461
2009-02-09 13:27:39 +00:00
Gabor Juhos
2b2541ebad iptables: remove CHAOS and TARPIT patches
SVN-Revision: 14447
2009-02-08 17:25:26 +00:00
Claudio Mignanti
7c2c6da09a fix table alignment for cris (#4104)
SVN-Revision: 14407
2009-02-04 14:40:37 +00:00
Nicolas Thill
28a92fe717 fix userland netfilter headers installed by iptables
SVN-Revision: 14083
2009-01-18 06:35:54 +00:00
Nicolas Thill
704402ab56 temp fix for iptables build failure after [13931]
SVN-Revision: 13932
2009-01-08 02:18:45 +00:00
Felix Fietkau
98677bd970 fix iptables compile with 2.6.26
SVN-Revision: 13747
2008-12-27 01:55:48 +00:00
Imre Kaloz
9d93e2a4e0 upgrade iptables to 1.4.1.1, needed for proper 2.6.27 support
SVN-Revision: 13458
2008-12-01 20:27:46 +00:00
Florian Fainelli
61863b4bed Finally fix iptables -m conntrack (#988), bump release numnber
SVN-Revision: 13235
2008-11-16 17:40:49 +00:00
Gabor Juhos
7613c343b5 netfilter/iptables: disable IMQ on 2.6.27
SVN-Revision: 12984
2008-10-15 10:56:13 +00:00
Nicolas Thill
2c8010b2dc make the whole iptables/netfiter modular (closes: #3871, #3527)
SVN-Revision: 12649
2008-09-22 15:19:59 +00:00
Felix Fietkau
e9ea28b0af use $(FPIC) in a few places where it matters
SVN-Revision: 12225
2008-08-06 22:10:29 +00:00
John Crispin
21bbdc24c3 adds a new uci firewall - iptbales and netfilter packages need to be rewrapped when we switch to this firewall as default - there are some examples in the file /etc/config/firewall - iptables-save/restore are still missing - hotplug takes care of adding/removing netdevs during runtime - misisng features ? wishes ? let me know ...
SVN-Revision: 12089
2008-08-04 11:51:58 +00:00
Gabor Juhos
f9518d9a74 netfilter/iptables: enable IMQ on 2.6.25
SVN-Revision: 11335
2008-06-02 19:46:47 +00:00
Florian Fainelli
82247228ea We do not need to make the experimental/install-experimental targets starting with 1.4.x version
SVN-Revision: 11325
2008-06-02 11:54:05 +00:00
Gabor Juhos
1b90498e69 IMQ is not yet available on 2.6.25
SVN-Revision: 11007
2008-05-02 11:29:53 +00:00
Gabor Juhos
d80f43d15f update iptables to 1.4.0 (2.6 kernels only), refresh kernel patches
SVN-Revision: 10843
2008-04-15 06:11:23 +00:00
Florian Fainelli
52315c5150 Fix layer7 user-space iptables compilation (#3307)
SVN-Revision: 10745
2008-04-06 18:01:53 +00:00
Gabor Juhos
4e45a1d1ac iptables: remove obsolete patch
SVN-Revision: 10464
2008-02-15 09:31:07 +00:00
Felix Fietkau
c89de79512 move /etc/config/firewall to /etc/firewall.config to prevent it from interfering with uci - yes, this beast really needs a rewrite :)
SVN-Revision: 10383
2008-02-04 22:03:18 +00:00
Felix Fietkau
0cf1a58282 Here comes the new UCI. Enjoy :)
SVN-Revision: 10367
2008-02-03 06:48:15 +00:00
Felix Fietkau
2a45adfcda remove uninstalldev templates (no longer necessary)
SVN-Revision: 9906
2007-12-25 01:40:47 +00:00
Felix Fietkau
93575b53a7 Use $(CP) instead of $(INSTALL_BIN) for binaries.
Signed-off-by: Andy Boyett <agb-openwrt@padded-cell.net>

SVN-Revision: 9694
2007-12-09 18:53:06 +00:00
Tim Yardley
85b17a4e9e update stripped subset of l7 patterns to 11-03-2007 patterns
SVN-Revision: 9582
2007-11-19 23:07:00 +00:00
Florian Fainelli
9d7192e5fa Add a boolean to allow NAT from LAN or not, default to nat LAN (#2535)
SVN-Revision: 9503
2007-11-05 14:19:16 +00:00
Gabor Juhos
79712043cc iptables: update description of the iptables-mod-ipopt
SVN-Revision: 9468
2007-10-31 20:21:58 +00:00
Florian Fainelli
ada8e5dd95 Only masquerade LAN, other settings need manual tweaking
SVN-Revision: 9461
2007-10-29 11:00:33 +00:00
Florian Fainelli
304d5c8845 Only masquerade non routable addresses (#2535)
SVN-Revision: 9460
2007-10-29 10:31:16 +00:00
Florian Fainelli
109d5fbca4 Update description, iptables-mod-ipsec includes libipt_policy.so
SVN-Revision: 9336
2007-10-16 14:04:59 +00:00
Gabor Juhos
8309e3dff2 add TARPIT support to netfilter/iptables * netfilter: add the xt_TARPIT target module required by xt_CHAOS * include/netfilter.mk: reorder, xt_CHAOS depends on xt_TARPIT and xt_DELUDE * iptables: add libipt_TARPIT to the kmod-ipt-extra package, bump release number * original patchset can be found [http://tinyurl.com/2mjk2kx here]
SVN-Revision: 9178
2007-10-07 17:17:04 +00:00
Felix Fietkau
969ac7459e add $(STAGING_DIR) as argument to the InstallDev template and update packages accordingly - this way we can reuse InstallDev to automatically generate UninstallDev or create -dev packages
SVN-Revision: 9052
2007-09-28 01:45:11 +00:00
Nicolas Thill
3a713ff202 move exec permissions fix at Build/Prepare stage
SVN-Revision: 8802
2007-09-16 16:25:53 +00:00
Nicolas Thill
34bb4638e7 move package description to a separate definition, remove it when DESCRIPTION=TITLE
SVN-Revision: 8659
2007-09-07 08:34:51 +00:00
Florian Fainelli
22282193a9 Package ip6tables-utils as well (#2318)
SVN-Revision: 8636
2007-09-05 21:40:11 +00:00
Tim Yardley
782d02ed1b iptables: refresh patches to 1.3.8
SVN-Revision: 8286
2007-07-31 20:28:55 +00:00
Florian Fainelli
2e4f6093c6 Fix the ip6tables dependency (#2079)
SVN-Revision: 7978
2007-07-15 18:53:33 +00:00
Tim Yardley
5f6dfc231a move to iptables 1.3.8
SVN-Revision: 7946
2007-07-12 16:05:28 +00:00
Felix Fietkau
2cc2d7707b make the firewall script run after the network script again (required for working with dynamically assigned interfaces), include the network state
SVN-Revision: 7806
2007-06-30 19:30:38 +00:00
Florian Fainelli
01b4fd853a Initialise firewall before network (#1988)
SVN-Revision: 7757
2007-06-28 12:56:55 +00:00
Tim Yardley
35d1063a75 package ipset for use
SVN-Revision: 7517
2007-06-07 15:30:59 +00:00
Felix Fietkau
04324c48cf upgrade a few packages to newer versions (includes patch by kaloz) - preparation for 2.6.22
SVN-Revision: 7507
2007-06-05 22:46:02 +00:00
Felix Fietkau
9114220553 refresh all package patches in the buildroot using quilt
SVN-Revision: 7490
2007-06-04 11:25:53 +00:00
Florian Fainelli
908b616d8e Add iprange (#1799)
SVN-Revision: 7462
2007-06-02 22:57:33 +00:00
Imre Kaloz
615e8af841 break trunk temporary - upgrade to 2.6.21.1 and iptables 1.3.7
SVN-Revision: 7315
2007-05-23 19:48:34 +00:00
Florian Fainelli
cd65230eea Add raw and NOTRACK targets (#1583)
SVN-Revision: 6945
2007-04-13 11:28:45 +00:00
Felix Fietkau
235692a7d6 fix iptables extension issue with mac os x builds
SVN-Revision: 6786
2007-04-01 12:28:56 +00:00
Felix Fietkau
c05a061e4e fix a problem with the firewall script (multicast traffic could produce packet loss)
SVN-Revision: 6726
2007-03-27 16:45:10 +00:00
Felix Fietkau
8e85262a8b improve autorebuild for iptables when the kernel config changes
SVN-Revision: 6652
2007-03-23 19:19:23 +00:00
Felix Fietkau
24faf55360 add file type autodetection for the unpack command and nuke PKG_CAT:= in lots of places
SVN-Revision: 6582
2007-03-16 20:21:39 +00:00
Felix Fietkau
1d307eea87 add a default for PKG_BUILD_DIR and PKG_INSTALL_DIR (will use KERNEL_BUILD_DIR if kernel.mk is included, BUILD_DIR otherwise)
SVN-Revision: 6580
2007-03-16 19:18:55 +00:00
Tim Yardley
ccfa4a7af6 trunk.. same deal as changeset:6526
SVN-Revision: 6527
2007-03-05 01:38:44 +00:00
Felix Fietkau
30ef579f48 make the iptables package robust to kernel config changes
SVN-Revision: 6447
2007-03-01 11:59:42 +00:00
Florian Fainelli
780712e30e Add ipt_CLASSIFY target for 2.4 kernels (#1338)
SVN-Revision: 6424
2007-02-28 12:04:58 +00:00
Felix Fietkau
8e88bb54ba port [6229] to kamikaze
SVN-Revision: 6275
2007-02-08 01:25:18 +00:00
Nicolas Thill
574c87a244 fix chaostables patch (closes: #1246)
SVN-Revision: 6184
2007-01-23 16:08:24 +00:00
Florian Fainelli
acf6ec373e Add chaostable from #1187, also enable netfilter modules for ixp4xx.
SVN-Revision: 6182
2007-01-22 23:55:22 +00:00
Nicolas Thill
bed47be36c more use of the INSTALL_DIR variable
SVN-Revision: 6023
2007-01-08 00:53:24 +00:00
Felix Fietkau
34272dbc04 fix iptables warning about 'wierd' interface names (#1082)
SVN-Revision: 5962
2007-01-01 23:31:36 +00:00
Florian Fainelli
343b935afa Forgot kmod-ipt-imq dependency (#1076)
SVN-Revision: 5901
2006-12-25 17:43:06 +00:00
Felix Fietkau
4323774d59 prepare for moving part of the firewall to hotplug. created new chains {input,forwarding,prerouting}_wan for wan port forwardings and updated the examples. syntax of /etc/config/firewall unchanged and old firewall.user files are still compatible
SVN-Revision: 5878
2006-12-20 05:58:41 +00:00
Felix Fietkau
63d865e7a1 prepare packages for kernel upgrade to 2.6.19
SVN-Revision: 5786
2006-12-14 08:00:20 +00:00
Tim Yardley
c962551b3a install-devel puts this here, kill it too
SVN-Revision: 5652
2006-11-26 23:15:20 +00:00
Tim Yardley
7de8690fc7 cleanup some of the custom work for devel libs
SVN-Revision: 5651
2006-11-26 23:13:49 +00:00
Felix Fietkau
680009ecd0 install iptables devel headers into the staging dir
SVN-Revision: 5650
2006-11-26 22:34:15 +00:00
Felix Fietkau
c2211dc51e replace lots of manual install commands with INSTALL_* variables
SVN-Revision: 5624
2006-11-23 00:29:07 +00:00
Felix Fietkau
105a602ecf implement target profiles in menuconfig
SVN-Revision: 5512
2006-11-12 05:06:56 +00:00
Felix Fietkau
223fdb0443 replace br0 with $LAN
SVN-Revision: 5492
2006-11-09 23:13:15 +00:00
Florian Fainelli
a72fd20a82 export WAN variable so that firewall works (#907)
SVN-Revision: 5412
2006-11-03 10:10:08 +00:00
Felix Fietkau
afd6539a65 add firewall protection for wan_device in addition to wan_ifname (fixes #852)
SVN-Revision: 5136
2006-10-15 23:04:23 +00:00