<feed xmlns='http://www.w3.org/2005/Atom'>
<title>svn-archive/archive/package/network/config/firewall, branch master</title>
<subtitle>OpenWrt SVN history</subtitle>
<id>https://git.openwrt.org/openwrt/svn-archive/archive/atom?h=master</id>
<link rel='self' href='https://git.openwrt.org/openwrt/svn-archive/archive/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/svn-archive/archive/'/>
<updated>2016-01-29T17:26:41Z</updated>
<entry>
<title>firewall: drop invalid by default, remove chain indirection, fix invert flags (#21738)</title>
<updated>2016-01-29T17:26:41Z</updated>
<author>
<name>Jo-Philipp Wich</name>
</author>
<published>2016-01-29T17:26:41Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/svn-archive/archive/commit/?id=d4721e8d8f00b569000c7f224831c1bec7406a0c'/>
<id>urn:sha1:d4721e8d8f00b569000c7f224831c1bec7406a0c</id>
<content type='text'>
* Enable drop_invalid by default to catch unnatted packets (#21738)
* Fix processing of inversions for -i, -o, -s, -d and -p flags
* Remove delegate_* chain indirection but rely on xt_id to identify own rules

Signed-off-by: Jo-Philipp Wich &lt;jow@openwrt.org&gt;

SVN-Revision: 48551
</content>
</entry>
<entry>
<title>firewall: add CONFIG_IPV6 to PKG_CONFIG_DEPENDS to fix a rebuild error</title>
<updated>2016-01-18T13:21:37Z</updated>
<author>
<name>Felix Fietkau</name>
</author>
<published>2016-01-18T13:21:37Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/svn-archive/archive/commit/?id=f531a5b7dd00009c8fb327a2405a75303229ba56'/>
<id>urn:sha1:f531a5b7dd00009c8fb327a2405a75303229ba56</id>
<content type='text'>
Signed-off-by: Felix Fietkau &lt;nbd@openwrt.org&gt;

SVN-Revision: 48315
</content>
</entry>
<entry>
<title>firewall: move to git.openwrt.org</title>
<updated>2016-01-04T15:13:10Z</updated>
<author>
<name>Felix Fietkau</name>
</author>
<published>2016-01-04T15:13:10Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/svn-archive/archive/commit/?id=56ba49df22a2eee30359e2fe39931b277b21593b'/>
<id>urn:sha1:56ba49df22a2eee30359e2fe39931b277b21593b</id>
<content type='text'>
Signed-off-by: Felix Fietkau &lt;nbd@openwrt.org&gt;

SVN-Revision: 48128
</content>
</entry>
<entry>
<title>firewall: allow DHCPv6 traffic to/from fc00::/6 instead of fe80::/10</title>
<updated>2015-09-25T08:41:12Z</updated>
<author>
<name>Jo-Philipp Wich</name>
</author>
<published>2015-09-25T08:41:12Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/svn-archive/archive/commit/?id=c71b2f0122e2be6aeff2d9235af699eed9405048'/>
<id>urn:sha1:c71b2f0122e2be6aeff2d9235af699eed9405048</id>
<content type='text'>
There is no RFC requirement that DHCPv6 servers must reply with a link local
address and some ISP servers in the wild appear to using addresses in the ULA
range to send DHCPv6 offers.

Signed-off-by: Jo-Philipp Wich &lt;jow@openwrt.org&gt;

SVN-Revision: 47048
</content>
</entry>
<entry>
<title>firewall: depend on kmod-ipt-conntrack (#20542)</title>
<updated>2015-09-17T15:31:45Z</updated>
<author>
<name>Jo-Philipp Wich</name>
</author>
<published>2015-09-17T15:31:45Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/svn-archive/archive/commit/?id=63142bae253ce42994c5d6ab41d54b9b3ab35eb9'/>
<id>urn:sha1:63142bae253ce42994c5d6ab41d54b9b3ab35eb9</id>
<content type='text'>
Our ruleset requires kernel support for conntrack state matching, therfore
depend on the require kmod. Fixes #20542.

Signed-off-by: Jo-Philipp Wich &lt;jow@openwrt.org&gt;

SVN-Revision: 46990
</content>
</entry>
<entry>
<title>firewall: Remove src_port from firewall.config to receive dhcpv6 replies</title>
<updated>2015-09-11T06:46:35Z</updated>
<author>
<name>Steven Barth</name>
</author>
<published>2015-09-11T06:46:35Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/svn-archive/archive/commit/?id=17a75f3f82185b7b798e51a0411d8a286a4ce1ca'/>
<id>urn:sha1:17a75f3f82185b7b798e51a0411d8a286a4ce1ca</id>
<content type='text'>
Seems like my second try was again whitespace broken. Sorry for the noise.

Remove src_port from firewall.config to receive dhcpv6 replies. Fixes #20295.

Signed-off-by: Anselm Eberhardt &lt;a.eberhardt@cygnusnetworks.de&gt;

SVN-Revision: 46842
</content>
</entry>
<entry>
<title>firewall: fix typo in ESP rule</title>
<updated>2015-07-27T11:47:20Z</updated>
<author>
<name>Steven Barth</name>
</author>
<published>2015-07-27T11:47:20Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/svn-archive/archive/commit/?id=78e616fb89176b5b7cd2aa867097460c1cd89490'/>
<id>urn:sha1:78e616fb89176b5b7cd2aa867097460c1cd89490</id>
<content type='text'>
Signed-off-by: Steven Barth &lt;steven@midlink.org&gt;

SVN-Revision: 46506
</content>
</entry>
<entry>
<title>firewall: comply with REC-22, REC-24 of RFC 6092</title>
<updated>2015-07-24T10:00:45Z</updated>
<author>
<name>Steven Barth</name>
</author>
<published>2015-07-24T10:00:45Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/svn-archive/archive/commit/?id=8f6686e98018894c8d62bb0642bebd3b9f82fd4a'/>
<id>urn:sha1:8f6686e98018894c8d62bb0642bebd3b9f82fd4a</id>
<content type='text'>
Signed-off-by: Steven Barth &lt;steven@midlink.org&gt;

SVN-Revision: 46478
</content>
</entry>
<entry>
<title>firewall: link iptables extensions dynamically</title>
<updated>2015-05-26T11:11:48Z</updated>
<author>
<name>Jo-Philipp Wich</name>
</author>
<published>2015-05-26T11:11:48Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/svn-archive/archive/commit/?id=4e1d79844649b3c2f5e6d4b27713f5e3d4eec1e1'/>
<id>urn:sha1:4e1d79844649b3c2f5e6d4b27713f5e3d4eec1e1</id>
<content type='text'>
Use shared libipt{,4,6}ext.so libraries instead of statically linking
the userspace matches into the fw3 executable.

As a side effect the match initialization is extremely simplified
compared to the weak function pointer juggling performed before.

This also fixes the initialization of the multiport match.

Signed-off-by: Jo-Philipp Wich &lt;jow@openwrt.org&gt;

SVN-Revision: 45764
</content>
</entry>
<entry>
<title>firewall: Allow IGMP and MLD input on WAN</title>
<updated>2015-05-05T13:22:41Z</updated>
<author>
<name>Steven Barth</name>
</author>
<published>2015-05-05T13:22:41Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/svn-archive/archive/commit/?id=7ac79479c12d40968a624cf2c29ba53143d1fb6c'/>
<id>urn:sha1:7ac79479c12d40968a624cf2c29ba53143d1fb6c</id>
<content type='text'>
The WAN port should at least respond to IGMP and MLD queries as
otherwise a snooping bridge/switch might drop traffic.

RFC4890 recommends to leave IGMP and MLD unfiltered as they are always
link-scoped anyways.

Signed-off-by: Linus Lüssing &lt;linus.luessing@c0d3.blue&gt;

SVN-Revision: 45613
</content>
</entry>
</feed>
