From d9d0687bfa4872dbd0a3601108187809404fc3b7 Mon Sep 17 00:00:00 2001 From: Vadim Kurland Date: Thu, 3 Jan 2008 17:16:18 +0000 Subject: [PATCH] removed old release notes --- doc/ReleaseNotes_2.0.1.html | 103 -------- doc/ReleaseNotes_2.0.1.txt | 55 ---- doc/ReleaseNotes_2.0.2.html | 171 ------------ doc/ReleaseNotes_2.0.2.txt | 100 ------- doc/ReleaseNotes_2.0.3.html | 306 ---------------------- doc/ReleaseNotes_2.0.3.txt | 204 --------------- doc/ReleaseNotes_2.0.4.html | 381 --------------------------- doc/ReleaseNotes_2.0.4.txt | 254 ------------------ doc/ReleaseNotes_2.0.5.html | 212 --------------- doc/ReleaseNotes_2.0.5.txt | 140 ---------- doc/ReleaseNotes_2.0.6.html | 259 ------------------- doc/ReleaseNotes_2.0.6.txt | 166 ------------ doc/ReleaseNotes_2.0.7.html | 271 ------------------- doc/ReleaseNotes_2.0.7.txt | 181 ------------- doc/ReleaseNotes_2.0.8.html | 203 --------------- doc/ReleaseNotes_2.0.8.txt | 124 --------- doc/ReleaseNotes_2.0.9.html | 100 ------- doc/ReleaseNotes_2.0.9.txt | 56 ---- doc/ReleaseNotes_2.1.10.html | 59 ----- doc/ReleaseNotes_2.1.10.txt | 33 --- doc/ReleaseNotes_2.1.11.html | 109 -------- doc/ReleaseNotes_2.1.11.txt | 65 ----- doc/ReleaseNotes_2.1.12.html | 436 ------------------------------- doc/ReleaseNotes_2.1.12.txt | 311 ---------------------- doc/ReleaseNotes_2.1.13.html | 106 -------- doc/ReleaseNotes_2.1.13.txt | 67 ----- doc/ReleaseNotes_2.1.14.html | 106 -------- doc/ReleaseNotes_2.1.14.txt | 64 ----- doc/ReleaseNotes_2.1.15.html | 88 ------- doc/ReleaseNotes_2.1.15.txt | 55 ---- doc/ReleaseNotes_2.1.7.html | 487 ----------------------------------- doc/ReleaseNotes_2.1.7.txt | 325 ----------------------- doc/ReleaseNotes_2.1.8.html | 97 ------- doc/ReleaseNotes_2.1.8.txt | 56 ---- doc/ReleaseNotes_2.1.9.html | 187 -------------- doc/ReleaseNotes_2.1.9.txt | 118 --------- doc/ReleaseNotes_2_0.html | 335 ------------------------ doc/ReleaseNotes_2_0.txt | 227 ---------------- 38 files changed, 6617 deletions(-) delete mode 100644 doc/ReleaseNotes_2.0.1.html delete mode 100644 doc/ReleaseNotes_2.0.1.txt delete mode 100644 doc/ReleaseNotes_2.0.2.html delete mode 100644 doc/ReleaseNotes_2.0.2.txt delete mode 100644 doc/ReleaseNotes_2.0.3.html delete mode 100644 doc/ReleaseNotes_2.0.3.txt delete mode 100644 doc/ReleaseNotes_2.0.4.html delete mode 100644 doc/ReleaseNotes_2.0.4.txt delete mode 100644 doc/ReleaseNotes_2.0.5.html delete mode 100644 doc/ReleaseNotes_2.0.5.txt delete mode 100644 doc/ReleaseNotes_2.0.6.html delete mode 100644 doc/ReleaseNotes_2.0.6.txt delete mode 100644 doc/ReleaseNotes_2.0.7.html delete mode 100644 doc/ReleaseNotes_2.0.7.txt delete mode 100644 doc/ReleaseNotes_2.0.8.html delete mode 100644 doc/ReleaseNotes_2.0.8.txt delete mode 100644 doc/ReleaseNotes_2.0.9.html delete mode 100644 doc/ReleaseNotes_2.0.9.txt delete mode 100644 doc/ReleaseNotes_2.1.10.html delete mode 100644 doc/ReleaseNotes_2.1.10.txt delete mode 100644 doc/ReleaseNotes_2.1.11.html delete mode 100644 doc/ReleaseNotes_2.1.11.txt delete mode 100644 doc/ReleaseNotes_2.1.12.html delete mode 100644 doc/ReleaseNotes_2.1.12.txt delete mode 100644 doc/ReleaseNotes_2.1.13.html delete mode 100644 doc/ReleaseNotes_2.1.13.txt delete mode 100644 doc/ReleaseNotes_2.1.14.html delete mode 100644 doc/ReleaseNotes_2.1.14.txt delete mode 100644 doc/ReleaseNotes_2.1.15.html delete mode 100644 doc/ReleaseNotes_2.1.15.txt delete mode 100644 doc/ReleaseNotes_2.1.7.html delete mode 100644 doc/ReleaseNotes_2.1.7.txt delete mode 100644 doc/ReleaseNotes_2.1.8.html delete mode 100644 doc/ReleaseNotes_2.1.8.txt delete mode 100644 doc/ReleaseNotes_2.1.9.html delete mode 100644 doc/ReleaseNotes_2.1.9.txt delete mode 100644 doc/ReleaseNotes_2_0.html delete mode 100644 doc/ReleaseNotes_2_0.txt diff --git a/doc/ReleaseNotes_2.0.1.html b/doc/ReleaseNotes_2.0.1.html deleted file mode 100644 index a26a08736..000000000 --- a/doc/ReleaseNotes_2.0.1.html +++ /dev/null @@ -1,103 +0,0 @@ - - - - - - Release Notes 2.0.1 - - - -

Firewall Builder Release Notes

-
-

Version 2.0.1

-
-

-Released 08/11/04 -
-GUI and compilers v2.0.1 require API library libfwbuilder version 2.0.1 -
-

Summary

-

-Firewall Builder GUI v2.0.1 is a maintenance release that includes -fixes for bugs discovered since 2.0 has been released. -

-For those who wish to build from source, instructions are outlined -in "Install -and Build instructions" - - -

Bugs fixed in libfwbuilder API:

- - - -
-
-

Bugs fixed in GUI:

- - -
-
-

Bugs fixed in iptables policy compiler fwb_ipt:

- - - -
- - -Last modified: Wed Aug 11 20:54:38 PDT 2004 - - - diff --git a/doc/ReleaseNotes_2.0.1.txt b/doc/ReleaseNotes_2.0.1.txt deleted file mode 100644 index 108711613..000000000 --- a/doc/ReleaseNotes_2.0.1.txt +++ /dev/null @@ -1,55 +0,0 @@ - Firewall Builder Release Notes - -Version 2.0.1 - - Released 08/11/04 - GUI and compilers v2.0.1 require API library libfwbuilder version 2.0.1 - -Summary - - Firewall Builder GUI v2.0.1 is a maintenance release that includes fixes for bugs discovered - since 2.0 has been released. - - For those who wish to build from source, instructions are outlined in "Install and Build - instructions" - -Bugs fixed in libfwbuilder API: - - * bug #1001725: "object with empty name can not be deleted". the problem was caused by the - algorithm used in FWObject::getPath. If object had had a blank name, the path returned by - this method would end with the name of its parent without slash. - -Bugs fixed in GUI: - - * bug #1001521: "Cant create ICMP service". ICMP Service dialog did not save icmp code and - type numbers in the object. - * bug #1001275: "object duplication fails w/ no action". GUI used to not allow user to - duplicate IP address object. Now any object can be duplicated so that the copy is placed - under the same parent, including IP address. - * bug #1000862: "Creating groups in Deleted Objects". Library "Deleted objects" should not - be offered as a choice for "group objects" operation. - * bug #1000485: "Firewalls in the drop-down box not ordered". List of firewalls in the - pull-down that controls policy views is now alphabetically sorted on program startup. - * there were two TCP Service objects "linuxconf" in the Standard objects library. Object - with ID id3AED0D6D has been removed. It seems this object has been duplicated long time - ago (at least it was like this in 1.1.2) - * bug #1002388: "Clamp MSS to MTU" option was missing in 2.0 - * bug #1001833: fixed memory leak that appeared when autosave option was used - * bug #1003068: "object copy/paste not always working". IP address object could not be - placed under interface using copy/paste operation. Now ip address object can be pasted to - interface as well as to Objects/Addresses folder. - * Operation File/discard could not be used if the file was upgraded. Changed the way - operation File/Discard works: it now closes the file, discards all the changes that have - been made to it and replaces it with a fresh copy of the head revision from RCS. This - works if user wants to abort file upgrade when they switch to the new version of - fwbuilder. - -Bugs fixed in iptables policy compiler fwb_ipt: - - * bug #1004153 "limit-burst = 0 is not valid". Iptables does not accept the rule using - "limit-burst" option if it is set to zero. - - ------------------------------------------------------------------------------------------ - - Last modified: Wed Aug 11 20:54:38 PDT 2004 -6 PDT 2004 diff --git a/doc/ReleaseNotes_2.0.2.html b/doc/ReleaseNotes_2.0.2.html deleted file mode 100644 index 125e138c8..000000000 --- a/doc/ReleaseNotes_2.0.2.html +++ /dev/null @@ -1,171 +0,0 @@ - - - - - - Release Notes 2.0.2 - - - -

Firewall Builder Release Notes

-
-

Version 2.0.2

-
-

-Released 08/31/04 -
-GUI and compilers v2.0.2 require API library libfwbuilder version 2.0.2 -
-

Summary

-

-Firewall Builder GUI v2.0.2 is a maintenance release that includes -fixes for bugs discovered since 2.0.1 has been released. -

-For those who wish to build from source, instructions are outlined -in "Install -and Build instructions" - - -

General

- -

- - -
-
-

New standard objects

- -

- - -
-
-

New template objects

- -

- -
-
-

New features in policy compiler for PF

- -

- - -
-
-

Bugs fixed in libfwbuilder API:

- -

- -
-
-

Bugs fixed in GUI:

- - -
-
-

Bugs fixed in iptables policy compiler fwb_ipt:

- - - -
- - -Last modified: Tue Aug 31 20:38:55 PDT 2004 - - - diff --git a/doc/ReleaseNotes_2.0.2.txt b/doc/ReleaseNotes_2.0.2.txt deleted file mode 100644 index 84263f728..000000000 --- a/doc/ReleaseNotes_2.0.2.txt +++ /dev/null @@ -1,100 +0,0 @@ - Firewall Builder Release Notes - -Version 2.0.2 - - Released 08/31/04 - GUI and compilers v2.0.2 require API library libfwbuilder version 2.0.2 - -Summary - - Firewall Builder GUI v2.0.2 is a maintenance release that includes fixes - for bugs discovered since 2.0.1 has been released. - - For those who wish to build from source, instructions are outlined in - "Install and Build instructions" - -General - - * Updated FreeBSD ports, tested on 5.3-BETA - -New standard objects - - * added new service objects to the Standard objects library: "xmas scan" - (old object renamed "xmas scan - full"), rsync, distcc, cvspserver, - cvsup, afp, whois, bgp, radius and radius acct, SSDP and UPnP. - -New template objects - - * added template firewall objects for Linksys firewall and a web server. - -New features in policy compiler for PF - - * Implemented support for all timeout settings in pf: - tcp.first,tcp.opening,tcp.established, - tcp.closing,tcp.finwait,tcp.closed,udp.first,udp.single,udp.multiple, - icmp.first,icmp.error,other.first,other.single,other.multiple, - including adaptive timeout scaling options adaptive.start and - adaptive.end - * Added support for options "max", "max-src-nodes" and "max-src-states" - in pf. These allow to limit number of concurrent state table entries - ("max"), number of source addresses that can simultaneously have state - table entries ("max-src-nodes") and number of simultaneous state - entries per source address ("max-src-states") per rule. - -Bugs fixed in libfwbuilder API: - - * : added element physAddress to list of child elements of Library (bug - #1011617) - * bug #1012733: "configure --libdir=DIR will be ignored at - installation". Needed to use macro _libdir to specify target directory - for libraries. Used it in configure, qmake.in, libfwbuilder-config-2 - and a .spec file. Code should compile and install in correct place on - 64-bit systems. - -Bugs fixed in GUI: - - * bug #1019691: "040829 nightly build doesn't add paths for linksys" - * bug #1013177: "deleting multiple hosts causes crash" - * bug #1009345: "Can only move one host object at a time between - libraries" - * bug #1013018: "host OS settings" dialog is missing for linksys. Added - host OS settings dialog for linksys/Sveasoft. Dialog provides entry - fields for paths to iptables, lsmod, modprobe, logger tools and two - shell prompt string patterns, this should help to work around changes - in the shell prompt on Linksys. - * bug #1013022: "can not install policy script on linksts Alchemy - pre-5.2". Built-in installer uses shell prompt string patterns - configured in the host OS settings dialog for linksys. - * bug #1008956: "Existing .fwb file gets overwritten if has wrong - extension". If the GUI needs to rename a data file with old extension - .xml to .fwb, it checks if a file with new extension exists and offers - user a chance to choose a different name. It also treats symlinks in a - special way: if user creates a symlink with extension .xml pointing at - a file with extension .fwb, the GUI simply follows the link and works - with .fwb file. This should work with Windows shortcuts, too. - * bug #1013485: "File/Import should allow to import .fwb file". Function - File/Import offers a choice of .fwl, .fwb and "all files" in the open - file dialog. - * bug #1011248: "need two xmas scan service objects". - * bug #1013957: "incorrect NAT rule in firewall created from template - #3". The problem was caused by incorrect ip address of interface "dmz" - in the template object #3. - * bug #1014725: "adding new ICMP types". If user created service group - with the name "ICMP", the GUI would place new ICMP objects under this - group instead of the standard folder "ICMP". There was the same - problem with other object types, too. - * bug #1015884: "Export more than one library fails with 0 references". - Export library operation failed if user exported two libraries with - groups or rules in one library referencing objects in the other. - -Bugs fixed in iptables policy compiler fwb_ipt: - - * bug #1005148: "MAC matching - space missing". Space was missing - between MAC address and custom service code. - * avoiding grep in the script generated for Linksys/Sveasoft firewall - - Sveasoft Alchemy pre-5.2.3 does not have grep - * bug #1019943: "Missing ip addresses in the rule using interfaces" - - ---------------------------------------------------------------------- - - Last modified: Tue Aug 31 20:38:55 PDT 2004 diff --git a/doc/ReleaseNotes_2.0.3.html b/doc/ReleaseNotes_2.0.3.html deleted file mode 100644 index 769ad81df..000000000 --- a/doc/ReleaseNotes_2.0.3.html +++ /dev/null @@ -1,306 +0,0 @@ - - - - - - Release Notes 2.0.3 - - - -

Firewall Builder Release Notes

-
-

Version 2.0.3

-
-

-Released 09/30/04 -
-GUI and compilers v2.0.3 require API library libfwbuilder version 2.0.3 -
-

Summary

-

-Firewall Builder GUI v2.0.3 is a maintenance release that includes -fixes for bugs discovered since 2.0.2 has been released. -

-For those who wish to build from source, instructions are outlined -in "Install -and Build instructions" - -

-

- - -

Caveats

- -

New version (as of build 421) completely changes the way it - loads and activates firewall script on linksys. Old version put - the whole script in variable rc_firewall. New one puts script in - variable fwb and puts a one-line command in rc_firewall to read - the script from fwb and execute it. This was done because of the - need to uncompress it when linksys executes command stored in - rc_firewall, in other words, rc_firewall needs to be a little - script that uncompresses and runs the main firewall script. This - is why scripts were separated and rc_firewall has changed compared - to the previous versions of fwbuilder. - -

Reverting from v2.0.3 (build 421 and later) to v2.0.2 requires - you to erase nvram variable "fwb" which holds the whole script in - the new builds. - -

- - - -
-

New features in the built in policy installer

- -

- - -
-
-

New features in policy compiler for iptables

- - - -
-
-

New features in policy compiler for PF

- -

- - -
-
-

Bugs fixed in libfwbuilder API:

- -

- -
-
-

Bugs fixed in GUI:

- - -
-
-

Bugs fixed in iptables policy compiler fwb_ipt:

- - - - -
-
-

Bugs fixed in iptables policy compiler fwb_pf:

- - -
- - -Last modified: Thu Sep 30 20:16:23 PDT 2004 - - - diff --git a/doc/ReleaseNotes_2.0.3.txt b/doc/ReleaseNotes_2.0.3.txt deleted file mode 100644 index f673b2884..000000000 --- a/doc/ReleaseNotes_2.0.3.txt +++ /dev/null @@ -1,204 +0,0 @@ - Firewall Builder Release Notes - -Version 2.0.3 - - Released 09/30/04 - GUI and compilers v2.0.3 require API library libfwbuilder version 2.0.3 - -Summary - - Firewall Builder GUI v2.0.3 is a maintenance release that includes fixes - for bugs discovered since 2.0.2 has been released. - - For those who wish to build from source, instructions are outlined in - "Install and Build instructions" - - * This release improves support for the PF firewall by always using - tables in policy rules; it also uses syntax " ! " for negation, - assignes "rdr" rules to interfaces and adds "flags S/SA" to policy - rules that keep state. - * This release significantly improves optimizer for iptables and adds an - automatically generated rule to block packets that correspond to an - INVALID state - * Built-in policy installer can compress firewall policy script before - it is installed in flash memory on Linksys/Sveasoft firewall; this - allows for much larger policy to be used on Linksys. Script - compression is optional. - * Built-in policy installer can be used to test new policy rules with - automatic roll-back to the previous version of the policy after - specified interval of time. This feature helps to work around errors - in the policy that block access to the firewall from the management - workstation. - -Caveats - - New version (as of build 421) completely changes the way it loads and - activates firewall script on linksys. Old version put the whole script in - variable rc_firewall. New one puts script in variable fwb and puts a - one-line command in rc_firewall to read the script from fwb and execute - it. This was done because of the need to uncompress it when linksys - executes command stored in rc_firewall, in other words, rc_firewall needs - to be a little script that uncompresses and runs the main firewall script. - This is why scripts were separated and rc_firewall has changed compared to - the previous versions of fwbuilder. - - Reverting from v2.0.3 (build 421 and later) to v2.0.2 requires you to - erase nvram variable "fwb" which holds the whole script in the new builds. - -New features in the built in policy installer - - * added an option for test run. When this option is activated, policy - script is pushed to the firewall and is executed but is not stored - there permanently. Firewall reverts to the last working configuration - after reboot. - * implemented compression of the firewall script for Linksys/Sveasoft - combo. Using gzip and uuencode/uudecode to compress the script and - store it in flash variable 'fwb'. Installer prints flash memory stats - after commiting changes. Installer uses scp to copy firewall script to - the firewall and autogenerated prompt to detect when it logged in; it - does not depend on Linksys shell prompt anymore. - * added an option to schedule automatic firewall reboot in specified - time (in minutes) after policy activation. This option is available - for all firewall platforms but PIX. This option only works if user - requested policy activation in a test mode, in which case policy is - copied and activated on the firewall but not stored in the permanent - location. After reboot the firewall reverts to the previous version of - the policy. To cancel scheduled reboot, run installer again with "test - run" option turned off. Installer stores the policy in the permanent - location, activates it and cancels scheduled reboot. The commands used - to schedule reboot and cancel it depend on the host os of the - firewall. On Linux, it will use "shutdown -r +NN" and "shutdown -c". - On *BSD systems it uses "shutdown -r +NN" and a combination of ps and - awk to find and kill shutdown when reboot is canceled. Installer uses - "reboot" and kills it with "killall" on linksys. - * All manipulations that installer does on the firewall are programmed - in little one-line scripts stored in resource file for each supported - OS the firewall is running. These are in /usr/share/fwbuilder/os on - Linux/*BSD or in C:\FWBuilder\resources\os on Windows. Users can hack - commands in these files to make installer work with host OS that is - not supported by default. Currently, the GUI only looks for the - OS-specific resource files in the system-wide directory. Future - versions will also look in a predefined directory in users' home. - Directory path to be defined later. - * Added option "output file name" to firewall settings dialogs for all - platforms. User can specify the name for the output file; this name is - then used by built in installer in place of a macro %FWSCRIPT%. - -New features in policy compiler for iptables - - * implemented feature request #1023430: "add checkbox for INVALID - support in fw settings". Added two checkboxes to the firewall settings - dialog: one adds a rule to drop INVALID packets and another adds - logging to the rule. - * rules that permit packets associated with ESTABLISHED,RELATED states - moved to the beginning of the script before NAT rules. - * bug #1022216: "negated time produces incorrect iptables rule". - Implemented negation for the "Time" rule element for iptables - * using abbreviated versions of "--dport", "--sport", "--dports", - "--sports" options to make generated iptables script smaller. Also - changed the name of the variables used to hold IP address of dynamic - interface from "interface_" to "i_". All this should - help to fit larger policies into small flash on linksys. These changes - shrunk my test script from 7964 bytes to 7430 bytes - * Generated iptables script flushes only secondary ip addresses on - interfaces during initialization phase if option "configure - interfaces" is on. This should fix a bug that caused linksys/sveasoft - unit to lose default route upon reboot if external interface has - static IP address. - * Generated script checks if /usr/sbin/ip exists on the firewall before - it tries to use it to verify interfaces and configure IP addresses. - This check is only performed if user activated options that use this - tool. An error message "Interface eth0 does not exist" was generated - if package iproute2 was not installed on the firewall, which was - confusing. - -New features in policy compiler for PF - - * A NAT rule of type DNAT (rdr rule) is assigned to an interface of the - firewall if interface object or its address object is used in ODst. To - get rdr rule without interface assignment, use an Address or a Host - object that has the same IP address as that of firewall's interface - but that is not a child of an interface. This is the same approach - that is used in iptables. - * Compiler for pf always uses tables; this breaks compatibility with - older OpenBSD systems (3.2 and 3.3) - * Compiler for pf puts interface name in a table for rules that use - multiple objects in src or dst and one of these objects is dynamic - interface of the firewall that is being processed. Using dynamic - interface of another object in a rule is still considered an error. - Compiler puts the name of dynamic interface in a table verbatim, - without brackets '(' ')' since pf does not replace dynamic interface - with its address dynamically if it is used in a table (pfctl issues an - error if interface is put in brackets) - * added an option to permit tcp sessions opened prior to firewall - restart. This is needed now since compiler generates "flags S/SA" for - the "keep state" and "modulate state" rules which means firewall won't - permit TCP sessions unless it saw opening SYN packet. - * bug #1028973: fwb_pf: missing "flags S/SA" in front of "modulate - state". Compiler adds "flags S/SA" to policy rules that use either - "keep state" or "modulate state" options. - * bug #1028980: "need an option to turn logging on on fallback rule". - Option has been added. - -Bugs fixed in libfwbuilder API: - - * bug #1022788: "GUI corrupts XML file after creating a second - firewall". Global object ID counter was getting reset every time new - FWObjectDatabase object was created. This lead to the ID collision if - user quickly created and deleted complex objects (such as Firewall) - and used database merge. This should also fix bug #1022785: "GUI - corrupts XML file after creating a host entry" - * fixed bug (no number): all references to the interfaces, as well as - their IP and MAC addresses, in policy and NAT rules should be replaced - when Firewall object is duplicated. Until now only references to the - firewall object itself and to its interfaces were replaced with - references to the newly created copies of object. References to IP and - MAC addresses still pointed at the old objects. - -Bugs fixed in GUI: - - * bug (no number): after deleting a library firewall objects that belong - to it were not removed from the pull-down list - * bug #1026945: '"Save As" does not work if current file is in RCS' - * bug #1028078: "options.png is not displayed for "Assume firewall is - part..." - * bug #1035132: "compile errors with default Linksys firewall object". - This bug has been introduced in build 435. When user created a new - firewall object using one of the template objects, the GUI would add - bunch of garbage to the firewall options. This garbage violated XML - DTD, so compilers and the GUI would not accept the data file anymore. - * bug #1035130: 'Persistent "Save" dialog box'. Certain combination of - actions on user's part used to lead to an indefinite loop of "do you - want to save the data" dialogs. The problem was triggered if user - skipped choosing a name for the new file in startup dialog. - -Bugs fixed in iptables policy compiler fwb_ipt: - - * bug #1024861: "optimizer is broken in fwb_ipt". Used idea and a patch - by Mark Vevers . Fixed compiler fwb_ipt generates - more efficient iptables script for rules with multiple objects in all - rule elements. The script is smaller and eliminates unnecessary - comparisons for packet attributes. Every attribute (i.e. source - address, destination address, protocol and port numbers) is checked by - the script only once. This should help reduce load on firewalls with - lots of complex rules. - * bug #1026509: "incorrect rules generated for dual negation with time". - Compiler generated incorrect iptables commands for rules that had - negation in two or more rule elements, one of which was Time. - * bug #1026794: multiple SRC ntwks --> "iptables: invalid argument". - Recent changes in optimizer introduced this bug. Rules with multiple - objects in src or dst, TCP service, action Reject and option "reject - with TCP RST" would generate iptables command that used option - "--reject-with tcp-reset" without "-p tcp" - -Bugs fixed in iptables policy compiler fwb_pf: - - * bug #1006906: "Negated network causes pass on network". Compiler for - pf uses native negation syntax that is now available in pf - * bug (no num): "firewall settings" dialog for OpenBSD pf did not save - option "Use tables". Since compiler is always using tables, this - option was removed from the dialog. - - ---------------------------------------------------------------------- - - Last modified: Thu Sep 30 20:16:23 PDT 2004 diff --git a/doc/ReleaseNotes_2.0.4.html b/doc/ReleaseNotes_2.0.4.html deleted file mode 100644 index 9ee827a91..000000000 --- a/doc/ReleaseNotes_2.0.4.html +++ /dev/null @@ -1,381 +0,0 @@ - - - - - - - -

Firewall Builder Release Notes

-
-

Version 2.0.4

-
-

-Released 12/02/04 -
-GUI and compilers v2.0.4 require API library libfwbuilder version 2.0.4 -
-

Summary

-

- -

-For those who wish to build from source, instructions are outlined -in the document "Install and Build instructions" on our web site here - -

What's new

-
    - -
  • Improvements in the GUI -

    -

      -
    • improved error handling: if the GUI is started with a - file on the command line or is configured to open a file - automatically on startup and RCS can not check the file out, - the GUI will come up empty (with only standard objects - loaded). Previously in a situation when the GUI was - configured to open a file automatically, but the file could - not be checked out, there was no way to cancel this - automatic file open operation since the GUI would never come - up.
    • - -
    • Added Japanese translation by Tadashi Jokagi - <elf@elf.no-ip.org>
    • - -
    • Added Russian translation by RusBusinessSecurity Co. Ltd., - Russia. This translation is fairly complete but is still - considered preliminary. Bug reports and suggestions are very - welcome. -
    • - -
    - - -
  • Improvements in the built-in policy installer -

    -

      -
    • Built-in installer checks exit status of the script it - runs on the firewall and aborts installation sequence if it - detects an error. OS resource files have been updated - accordingly so they return exit status '1' in case of error - and '0' when they succeed.
    • - -
    • Added an option to push PIX configuration to a standby - firewall at the end of install.
    • - -
    • Added support in installer for new configuration script - formats for PIX: -

      -

        -
      1. basic or old format when access lists are cleared - and added from scratch
      2. - -
      3. Access lists have unique names each time policy is - recompiled, lists are added without clearing.
      4. - -
      5. Access lists are added with temporary names and - assigned to interfaces, then the same lists are added - with permanent names, lists are swapped and temporary - lists cleared
      6. -
      - -

      Last two methods provide for instantaneous access list - swap so that the firewall never runs with empty - lists. This helps maintain access to the firewall if - configuration is installed remotely. -

    • - -
    -
  • - -
  • Improvements in policy compiler for iptables: -

    -

      -
    • implemented Feature Request #1021201: "output - iptables-restore compatible config from fwb_ipt". Policy - compiler for iptables can use iptables-restore to activate - firewall policy. Iptables-restore provides for atomic policy - load and allows to load large policy much faster. Atomic - load means the whole filter or nat table is activated at - once, and if there is an error, nothing is changed. Compiler - generates script in three possible formats: -

      -

        -
      1. the ususal shell script that adds rules one at a - time by executing iptables command with an "-A" flag to - add a rule;
      2. - -
      3. commands are fed to iptables-restore, this format is - used when all interfaces of the firewall have static IP - addresses and script does not need to determine - addresses at run time;
      4. - -
      5. script determines IP addresses of interfaces and - discovers dynamic interfaces that were defined as a - "wildcard" interface in fwbuilder (e.g. 'ppp*'); code - that is sent to iptables-restore is generated - dynamically by the script at run time.
      6. -
      - -

      Using iptables-restore is optional and is controlled by - the checkbutton in the "Script options" tab of firewall - settings dialog. Path to iptables-restore utility can be - set in the "Paths" tab of the host settings dialog. -

      -
    • - -
    • policy installation via iptables-restore has been tested - with old versions of iptables (1.2.6a). Script need to - include "-m tcp", "-m udp" or "-m icmp", otherwise - iptables-restore does not understand options "--dport", - "--tcp-flags" and some others. Also had to use "--tcp-flags - SYN,RST,ACK SYN" instea dof "--syn" for better backwards - compatibility.
    • - -
    • A change in the script generated by fwb_ipt: if - iptables-restore is not used to load policy, generated shell - script purges existing firewall policy (all tables and - chains) and sets default chain policies after it configures - interfaces of the firewall. Previously, it would flush - tables and set default policy before it configured - interfaces.
    • - - -
    • removed code that added iptables command to the "drop" - table to drop and log all dropped packets. This rule used - obsoleted patch-o-matic patch "drop" which is not available - anymore.
    • - -
    • moved rule permitting backup ssh access from the - management station to the firewall to the top of the - script. This helps maintain ssh session, otherwise it may - stall or break because stdout buffer is filled with - diagnostic or progress output from the script that is - printed after all chains are flushed but before rule - permitting ssh to the firewall is added. If stdout buffer is - full, ssh stops and tries to send the text to the management - station but times out because firewall blocks it.
    • - - -
    -

    -
  • - -
  • Improvements in policy compiler for pf: -

    -

      -
    • Activation script for PF flushes only information about - rules, nat, source and tables (it used to flush "all"). This - preserves queue entries and states.
    • - -
    -

    -

  • - -
  • Improvements in policy compilers for all platforms: -

    -

      -
    • added support for prolog and epilog scripts for all - firewall platforms. This was available for PIX for some - time, now it has been added for all - platforms. "Prolog/Epilog" tab of the firewall settings - dialog allows for editing of two blocks of commands that - will be added to the generated firewall script - verbatim. Prolog block is added on top, while epilog block - is added at the bottom. Both prolog and epilog are expected - to be shell scripts and are added to the generated shell - script that activates firewall. For iptables and ipfw all - compiler generates is this shell script and prolog and - epilog commands are inserted into it. These commands may - execute some actions, as well as add any policy or nat - commands. For ipf and pf prolog and epilog commands are - added to the activation shell script ( .fw file); prolog is - added immediately after the command that flushes all - rules. This way user may either execute shell commands or - add policy and/or nat rules by loading them from external - file.
    • - -
    • all policy compilers properly detect an error when the - output file can not be created or overwritten and print - error message to warn the user.
    • - - -
    • Added element "Target/family" to all OS resource XML - files. Compilers use "family" resource element to determine - if host OS is supported. User may want to copy host OS - resource file to modify installer scriptlets; as long as the - family element is kept the same, compiler will accept new - resource file.
    • -
    -

    -

  • - -
    -
- -
-
-
- - -
-
-

Bugs fixed in GUI:

-
    -
  • bug #1077072: "CrossPlatform Firewall Builder Crash" - - pressing arrow down key on the keyboard right after the GUI - started with no firewall objects defined caused crash.
  • - -
  • bug (no num): if a library was assigned a name with - non-ascii characters, it would appear distorted in the pull-down - list in object dialogs.
  • - -
  • bug (no number) introduced in 2.0.3 when GUI crashed if user - tried to choose pull-down menu item in the firewall list after - the very first firewall object has been created.
  • - -
  • bug (no number): group object dialog corrupted object names - if they contained non-ascii characters.
  • - -
  • bug #1046345: "ipfw - no option to specify ipfw - executable". Added GUI control to let user specify alternative - path to "ipfw" on FreeBSD. Control like that was previously - available only for Mac OS X
  • - -
  • bug #1028866: "incorrect order when several rules copied - using copy/paste". Pasting multiple rules into an empty policy - caused rules to be inserted in the wrong order.
  • - -
  • bug (no number): Policy installer failed if the following - conditions were met: - it was running on Linux, FreeBSD or Mac - OS X - working directory configured in the "General" tab of the - Preferences dialog did not exist and could not be created or its - permissions did not allow user that runs the GUI to access - it
  • - -
  • Added #include to make code compile with gcc 3.4.2 - and glibc 2.3.3
  • - -
  • bug (no number): GUI could not find names of the object - libraries in external library files that user added for - automatic load in the Preferences dialog on Windows. It would - find the name of the library in the first file, but failed to - find library names in subsequent files and used the name from - the first file. Since this library was only present in the first - file, object tree was getting corrupted when the program - attempted to load this library from every file configured for - automatic pre-load. This only happened on Windows.
  • -
- -
-
-

Bugs fixed in API:

-
    -
  • bug #1077496 ] Error compiling libfwbuilder in FreeBSD: - The problem was caused by changed major version number of libnetsnmp library - in the latest net-snmp port (v5.2)
  • - -
  • bug #1055937: "Any->all_multicasts not in INPUT Chain". Need - to check if network objects are multicasts; assume that - multicast always matches firewall object (e.g fwb_ipt will put - rule with such network object in destination in INPUT - chain)
  • - -
  • bug #1040773: need to match network address as well as - broadcast. Packets sent to the network address (192.168.1.0 for - net 192.168.1.0/24) go in the broadcast frame and behave just - like IP broadcast packets (sent to 192.168.1.1255 for the same - net)
  • - -
  • bug (no number): rule shadowing algorithm now assumes that - IPService object with protocol number '0' shades any other - service just like 'any' does.
  • - -
  • bug (no num): rule shadowing algorithm checks for IP flags - in IP service object. IP service object with protocol 0 shades - anything only if its flags are cleared. Two IP services shade - each other only if they are completely equal (protocols and all - flags settings are the same). However, IP service with protocol - 0 shades other IP service with protocol !=0 if all flags - settings are the same.
  • - -
  • change in the object database merge algorithm: when an - object database we are trying to merge has non-empty "Deleted - objects" library, deleted objects from this library should be - ignored (they used to be deleted from the current - tree). Likewise, when current tree has non-empty "Deleted - objects" library and objects in it match objects being merged - in, objects should be removed from "Deleted objects" library to - avoid creating duplicate IDs with objects being merged in.
  • - -
  • bug (no number): program crashed on FreeBSD 5.3 when using - SNMP to obtain parameters for hosts and interfaces. Crash - occurred because of use of uninitialized mutex variables in - module dns.cpp
  • - -
  • bug (no number): The API used to corrupt CustomService - object while saving data to the XML file if service code - included special characters such as '&'
  • - -
- -
-
-

Bugs fixed in policy compiler for iptables fwb_ipt:

-
    -
  • bug #1073491: incorrect code for rules using two interfaces - with negation. If a rule had two (or more) interfaces of the - firewall in the destination, with negation, the code generated - by compiler would check one interface's address in INPUT chain - and another in FORWARD chain. It should check addresses of all - interfaces from the corresponding rule element in the INPUT - chain and also check addresses and possibly services from other - rule elements in the FORWARD chain. This bug affected rules with - two or more interfaces both in source and destination.
  • - -
  • bug #1040788: fwb_ipt and user name. Compiler used to read - environment variable "USER" to find out user's name. Sometimes - this variable is not set, which caused compiler to abort. Using - env variable LOGNAME in addition to USER.
  • - -
  • bug #1040599: "unnecessary FORWARD rules". If ip forwarding - is turned off in the host settings dialog of the linux-based - firewall, compiler should not generate rules in FORWARD - chain.
  • - -
  • bug (no number): compiler placed extra quote '"' at the end - of each NAT command in the script using iptables-restore; this - happened only if all interfaces of the firewall had static - addresses.
  • - -
  • bug (no number) in fwb_ipt that caused no-nat rules with - firewall in OSrc to be placed only in OUTPUT chain. Packets - originating on the firewall go into OUTPUT and POSTROUTING - chains, so no-nat rules must be placed in both. Other minor - improvements for NAT of the locally originated connections have - been done as well.
  • - -
  • bug (no number) where compiler for iptables used option - "--destination-port" with module "multiport" for versions of - iptables that do not understand it (1.2.6 and later, as well as - default version setting 'any'). The option should be - "--destination-ports" or "--dports".
  • - -
  • bug #1063953: "Wrong accept/multiport rule - generated". Compiler generated wrong code for rules using - multiple service objects of different types (TCP and UDP, or TCP - and ICMP etc), multiple addresses in src or dst with option that - requires using TCP RST for action REJECT. This bug was - introduced in build 453
  • - -
  • bug (no number): policy compiler for iptables used "tail -1" - in the shell script that read actual IP addresses of interfaces - of the firewall. This shell code failed to determine correct - address of an interface that was configured with a secondary - address. Reverted to using grep (I switched to tail when ran - into limitations of one of the beta builds of Sveasoft Linksys - firmware that did not have grep)
  • -
- - - - diff --git a/doc/ReleaseNotes_2.0.4.txt b/doc/ReleaseNotes_2.0.4.txt deleted file mode 100644 index e9901f58d..000000000 --- a/doc/ReleaseNotes_2.0.4.txt +++ /dev/null @@ -1,254 +0,0 @@ - Firewall Builder Release Notes - -Version 2.0.4 - - Released 12/02/04 - GUI and compilers v2.0.4 require API library libfwbuilder version 2.0.4 - -Summary - - For those who wish to build from source, instructions are outlined in the - document "Install and Build instructions" on our web site here - -What's new - - * Improvements in the GUI - - * improved error handling: if the GUI is started with a file on the - command line or is configured to open a file automatically on - startup and RCS can not check the file out, the GUI will come up - empty (with only standard objects loaded). Previously in a - situation when the GUI was configured to open a file - automatically, but the file could not be checked out, there was - no way to cancel this automatic file open operation since the GUI - would never come up. - * Added Japanese translation by Tadashi Jokagi - * Added Russian translation by RusBusinessSecurity Co. Ltd., - Russia. This translation is fairly complete but is still - considered preliminary. Bug reports and suggestions are very - welcome. - - * Improvements in the built-in policy installer - - * Built-in installer checks exit status of the script it runs on - the firewall and aborts installation sequence if it detects an - error. OS resource files have been updated accordingly so they - return exit status '1' in case of error and '0' when they - succeed. - * Added an option to push PIX configuration to a standby firewall - at the end of install. - * Added support in installer for new configuration script formats - for PIX: - - 1. basic or old format when access lists are cleared and added - from scratch - 2. Access lists have unique names each time policy is - recompiled, lists are added without clearing. - 3. Access lists are added with temporary names and assigned to - interfaces, then the same lists are added with permanent - names, lists are swapped and temporary lists cleared - - Last two methods provide for instantaneous access list swap so - that the firewall never runs with empty lists. This helps - maintain access to the firewall if configuration is installed - remotely. - - * Improvements in policy compiler for iptables: - - * implemented Feature Request #1021201: "output iptables-restore - compatible config from fwb_ipt". Policy compiler for iptables can - use iptables-restore to activate firewall policy. - Iptables-restore provides for atomic policy load and allows to - load large policy much faster. Atomic load means the whole filter - or nat table is activated at once, and if there is an error, - nothing is changed. Compiler generates script in three possible - formats: - - 1. the ususal shell script that adds rules one at a time by - executing iptables command with an "-A" flag to add a rule; - 2. commands are fed to iptables-restore, this format is used - when all interfaces of the firewall have static IP addresses - and script does not need to determine addresses at run time; - 3. script determines IP addresses of interfaces and discovers - dynamic interfaces that were defined as a "wildcard" - interface in fwbuilder (e.g. 'ppp*'); code that is sent to - iptables-restore is generated dynamically by the script at - run time. - - Using iptables-restore is optional and is controlled by the - checkbutton in the "Script options" tab of firewall settings - dialog. Path to iptables-restore utility can be set in the - "Paths" tab of the host settings dialog. - - * policy installation via iptables-restore has been tested with old - versions of iptables (1.2.6a). Script need to include "-m tcp", - "-m udp" or "-m icmp", otherwise iptables-restore does not - understand options "--dport", "--tcp-flags" and some others. Also - had to use "--tcp-flags SYN,RST,ACK SYN" instea dof "--syn" for - better backwards compatibility. - * A change in the script generated by fwb_ipt: if iptables-restore - is not used to load policy, generated shell script purges - existing firewall policy (all tables and chains) and sets default - chain policies after it configures interfaces of the firewall. - Previously, it would flush tables and set default policy before - it configured interfaces. - * removed code that added iptables command to the "drop" table to - drop and log all dropped packets. This rule used obsoleted - patch-o-matic patch "drop" which is not available anymore. - * moved rule permitting backup ssh access from the management - station to the firewall to the top of the script. This helps - maintain ssh session, otherwise it may stall or break because - stdout buffer is filled with diagnostic or progress output from - the script that is printed after all chains are flushed but - before rule permitting ssh to the firewall is added. If stdout - buffer is full, ssh stops and tries to send the text to the - management station but times out because firewall blocks it. - - * Improvements in policy compiler for pf: - - * Activation script for PF flushes only information about rules, - nat, source and tables (it used to flush "all"). This preserves - queue entries and states. - - * Improvements in policy compilers for all platforms: - - * added support for prolog and epilog scripts for all firewall - platforms. This was available for PIX for some time, now it has - been added for all platforms. "Prolog/Epilog" tab of the firewall - settings dialog allows for editing of two blocks of commands that - will be added to the generated firewall script verbatim. Prolog - block is added on top, while epilog block is added at the bottom. - Both prolog and epilog are expected to be shell scripts and are - added to the generated shell script that activates firewall. For - iptables and ipfw all compiler generates is this shell script and - prolog and epilog commands are inserted into it. These commands - may execute some actions, as well as add any policy or nat - commands. For ipf and pf prolog and epilog commands are added to - the activation shell script ( .fw file); prolog is added - immediately after the command that flushes all rules. This way - user may either execute shell commands or add policy and/or nat - rules by loading them from external file. - * all policy compilers properly detect an error when the output - file can not be created or overwritten and print error message to - warn the user. - * Added element "Target/family" to all OS resource XML files. - Compilers use "family" resource element to determine if host OS - is supported. User may want to copy host OS resource file to - modify installer scriptlets; as long as the family element is - kept the same, compiler will accept new resource file. - - ---------------------------------------------------------------------- - -Bugs fixed in GUI: - - * bug #1077072: "CrossPlatform Firewall Builder Crash" - pressing arrow - down key on the keyboard right after the GUI started with no firewall - objects defined caused crash. - * bug (no num): if a library was assigned a name with non-ascii - characters, it would appear distorted in the pull-down list in object - dialogs. - * bug (no number) introduced in 2.0.3 when GUI crashed if user tried to - choose pull-down menu item in the firewall list after the very first - firewall object has been created. - * bug (no number): group object dialog corrupted object names if they - contained non-ascii characters. - * bug #1046345: "ipfw - no option to specify ipfw executable". Added GUI - control to let user specify alternative path to "ipfw" on FreeBSD. - Control like that was previously available only for Mac OS X - * bug #1028866: "incorrect order when several rules copied using - copy/paste". Pasting multiple rules into an empty policy caused rules - to be inserted in the wrong order. - * bug (no number): Policy installer failed if the following conditions - were met: - it was running on Linux, FreeBSD or Mac OS X - working - directory configured in the "General" tab of the Preferences dialog - did not exist and could not be created or its permissions did not - allow user that runs the GUI to access it - * Added #include to make code compile with gcc 3.4.2 and glibc - 2.3.3 - * bug (no number): GUI could not find names of the object libraries in - external library files that user added for automatic load in the - Preferences dialog on Windows. It would find the name of the library - in the first file, but failed to find library names in subsequent - files and used the name from the first file. Since this library was - only present in the first file, object tree was getting corrupted when - the program attempted to load this library from every file configured - for automatic pre-load. This only happened on Windows. - -Bugs fixed in API: - - * bug #1077496 ] Error compiling libfwbuilder in FreeBSD: The problem - was caused by changed major version number of libnetsnmp library in - the latest net-snmp port (v5.2) - * bug #1055937: "Any->all_multicasts not in INPUT Chain". Need to check - if network objects are multicasts; assume that multicast always - matches firewall object (e.g fwb_ipt will put rule with such network - object in destination in INPUT chain) - * bug #1040773: need to match network address as well as broadcast. - Packets sent to the network address (192.168.1.0 for net - 192.168.1.0/24) go in the broadcast frame and behave just like IP - broadcast packets (sent to 192.168.1.1255 for the same net) - * bug (no number): rule shadowing algorithm now assumes that IPService - object with protocol number '0' shades any other service just like - 'any' does. - * bug (no num): rule shadowing algorithm checks for IP flags in IP - service object. IP service object with protocol 0 shades anything only - if its flags are cleared. Two IP services shade each other only if - they are completely equal (protocols and all flags settings are the - same). However, IP service with protocol 0 shades other IP service - with protocol !=0 if all flags settings are the same. - * change in the object database merge algorithm: when an object database - we are trying to merge has non-empty "Deleted objects" library, - deleted objects from this library should be ignored (they used to be - deleted from the current tree). Likewise, when current tree has - non-empty "Deleted objects" library and objects in it match objects - being merged in, objects should be removed from "Deleted objects" - library to avoid creating duplicate IDs with objects being merged in. - * bug (no number): program crashed on FreeBSD 5.3 when using SNMP to - obtain parameters for hosts and interfaces. Crash occurred because of - use of uninitialized mutex variables in module dns.cpp - * bug (no number): The API used to corrupt CustomService object while - saving data to the XML file if service code included special - characters such as '&' - -Bugs fixed in policy compiler for iptables fwb_ipt: - - * bug #1073491: incorrect code for rules using two interfaces with - negation. If a rule had two (or more) interfaces of the firewall in - the destination, with negation, the code generated by compiler would - check one interface's address in INPUT chain and another in FORWARD - chain. It should check addresses of all interfaces from the - corresponding rule element in the INPUT chain and also check addresses - and possibly services from other rule elements in the FORWARD chain. - This bug affected rules with two or more interfaces both in source and - destination. - * bug #1040788: fwb_ipt and user name. Compiler used to read environment - variable "USER" to find out user's name. Sometimes this variable is - not set, which caused compiler to abort. Using env variable LOGNAME in - addition to USER. - * bug #1040599: "unnecessary FORWARD rules". If ip forwarding is turned - off in the host settings dialog of the linux-based firewall, compiler - should not generate rules in FORWARD chain. - * bug (no number): compiler placed extra quote '"' at the end of each - NAT command in the script using iptables-restore; this happened only - if all interfaces of the firewall had static addresses. - * bug (no number) in fwb_ipt that caused no-nat rules with firewall in - OSrc to be placed only in OUTPUT chain. Packets originating on the - firewall go into OUTPUT and POSTROUTING chains, so no-nat rules must - be placed in both. Other minor improvements for NAT of the locally - originated connections have been done as well. - * bug (no number) where compiler for iptables used option - "--destination-port" with module "multiport" for versions of iptables - that do not understand it (1.2.6 and later, as well as default version - setting 'any'). The option should be "--destination-ports" or - "--dports". - * bug #1063953: "Wrong accept/multiport rule generated". Compiler - generated wrong code for rules using multiple service objects of - different types (TCP and UDP, or TCP and ICMP etc), multiple addresses - in src or dst with option that requires using TCP RST for action - REJECT. This bug was introduced in build 453 - * bug (no number): policy compiler for iptables used "tail -1" in the - shell script that read actual IP addresses of interfaces of the - firewall. This shell code failed to determine correct address of an - interface that was configured with a secondary address. Reverted to - using grep (I switched to tail when ran into limitations of one of the - beta builds of Sveasoft Linksys firmware that did not have grep) diff --git a/doc/ReleaseNotes_2.0.5.html b/doc/ReleaseNotes_2.0.5.html deleted file mode 100644 index 61585335e..000000000 --- a/doc/ReleaseNotes_2.0.5.html +++ /dev/null @@ -1,212 +0,0 @@ - - - - - - - -

Firewall Builder Release Notes

-
-

Version 2.0.5

-
-

-Released 01/07/05 -
-GUI and compilers v2.0.5 require API library libfwbuilder version 2.0.5 -
-

Summary

-

-This is a bugfix release; its main focus is on internationalization and usability -

-For those who wish to build from source, instructions are outlined -in the document "Install and Build instructions" on our web site here - -

What's new

-
    - -
  • Improvements in the GUI -

    -

      -
    • Fixed lots of places were strings were not properly - marked for localization, this lead to GUI showing '????' - instead of a text in some menu items and dialogs in - non-english locales
    • - -
    • properly synchronizing state of the items main menu with - state of corresponding items in the pop-up menu that appears - when user right-mouse-clicks on an object in the tree
    • - -
    • fixes for non-localized text strings in dialogs (mostly - "Continue", "Yes"/"No" etc. in many places)
    • - -
    • proper localization of the human-readable version number - text for iptables; also made info window print readable text - instead of "lt_1.2.6"
    • - -
    • cosmetic changes in some dialogs layout to make the look - better when localized text makes strings much longer
    • - -
    • firewall object dialog tab "Templates" has been hidden. It - is unlikely that this feature will be implemented in 2.0.X - series.
    • - -
    • Streamlined logic in the object editor dialog. This improves - handling of the situation when user closes dialog by clicking on - [x] while 1) there are unsaved data and/or 2) some of the - object's parameters have illegal values. The dialog behavior - also depends on the setting of the global flag "Autosave" that - causes dialog to automatically save data when user switches - between objects.
    • - -
    • when user opens data file in the old format (fwbuilder - v1.1.x, extension .xml) and after autoupgrade the program - discovers that the same file with extension .fwb already - exists, it offers the user a chance to choose different - name. If user clicks "Cancel" at this point, the program - cancel operation and reverts upgraded data file back to its - original name and version.
    • - -
    • improved behavior of the main menu "Edit" as well as - pop-up menu that appears when user right mouse clicks on an - object in the tree. Menu item "Paste" should only be enabled - if the clipboard is not empty and objects that are stored in - it can be pasted into selected object in the tree.
    • - -
    • when user clicks menu item "File/Open" to open a new - file, the GUI should save and close currently opened file - only after the user chooses new file. If user clicks Cancel - in the File/Open dialog, operation should be cancelled so - the user can continue working with currently opened - file. The same applies to operation File/New.
    • - -
    • implemented feature request: colors that are used to - color rules can be changed in Preferences dialog.
    • - -
    • main menu item "Object/New Object/Address" and - corresponding toolbar button always creates an Address - object under Objects/Addresses folder in the tree. Address - of an interface can be created using pop-up menu item "Add - IP Address"
    • - -
    • Pull-down menu "On startup" in the "General" tab of the - preferences dialog now has three items: "Load standard - objects", "Load last edited file" and "Ask user what to - do". The last item is default.
    • - -
    • Updated Japanese and Russian translations
    • -
    -
  • -
- -
-
-
- - -
-
-

Bugs fixed in GUI:

-
    -
  • bug (no num): the GUI crashed when user tried to add a - library file for auto-load in Preferences/Libraries and the - first library object in that file had a name using non-ascii - characters
  • - -
  • bug (internal #34) the program should issue a warning when - user tries to add a library file (.fwl) that contains object - library that already exists in the opened data file.
  • - -
  • bugfixes for the behavior of the object editor - dialogs. Dialog should ask if user wants to save data and then - validate it when user clicks on [x] to close editor dialog. It - used to validate the data first, then ask if they want to close - dialog.
  • - -
  • bug (localization): RCS log entries made using non-ascii - characters used to appear as '???' in Open File and - File/Properties dialogs.
  • - -
  • localization was broken on win32 and mac os x because - translation files were not installed properly. Now fixed.
  • - -
  • bug #1092810: "Multiline RCS comments are shown as a single - line on windows". As it turned out, this bug affected all - platforms.
  • - -
  • bug (no num) that caused GUI crash when user created new - firewall object using template with three interfaces.
  • -
- -
-
-

Bugs fixed in API:

-
    -
  • bug #1068119: "additional whitespace for Rule comments in - .fw file". Added extra space between rule number and interface - spec in rule comments.
  • -
- -
-
-

Bugs fixed in policy compiler for iptables fwb_ipt:

-
    -
  • bug #1089586: "default --icmp-type value is 0 in iptables < - 1.2.9". The problem concerns policy rules using service object - "any ICMP". A rule like this is supposed to match any ICMP - packet. Few versions ago I had to add option "-m icmp" (and "-m - udp", "-m tcp") because I've discovered that iptables-restore on - some systems (linksys sveasoft firmware, iptables v1.2.11) - refused to load rules without it. Now it turns out that iptables - v < 1.2.9 (tested on 1.2.6a and 1.2.7a) implicitly adds - equivalent of "--icmp-type 0" to rules with "-p icmp -m icmp" - and without "--icmp-type" option. Since type 0 is actually icmp - echo reply, a rule like this does not match "any ICMP" as it was - supposed to do. Iptables 1.2.9 implicitly adds "--icmp-type 255" - which matches any icmp type. Using "--icmp-type 255" on iptables - 1.2.6 and 1.2.7 does not work (a rule does not match icmp - packets with type different from 255). The fix generates "-p - icmp -m icmp --icmp-type any" for iptables 1.2.9 and later, as - well as when iptables version is not specified in the firewall - object settings. It generates just "-p icmp" for versions < - 1.2.9.
  • - -
  • bug #1092141: "irritating FORWARD rule for established - connections". Need rule in FORWARD chain only if ip forwarding - is on or set to "no change"
  • - -
  • bug #1059393: "function getaddr failed for - eth1.0020". Generated script can now work with interfaces that - have a dot in their name (such as "eth1.0020" - vlan interface)
  • - -
- - - -
-
-

Bugs fixed in policy compiler for ipfw fwb_ipfw:

-
    -
  • bug #1089866: "multiple services in one rule confuses ipfw - compiler". If several UDP or TCP objects were used in the same - policy rule and these service objects had source port ranges - defined, the compiler would produce incorrect code by combining - source port range specifications together in the same ipfw - command.
  • - -
  • bug #1093461: "problem with 'established' in ipfw". Ipfw - requires protocol to be set to 'tcp' if option 'established' is - used in a rule.
  • - -
  • bug #1093472: "ipfw port range(s) errors". There can only be - one port range in a single ipfw rule.
  • - -
  • bug #1093620: "path (to ipfw) with spaces fails". Generated - script failed if path to ipfw contained space. I only worked - around this problem for ipfw; paths to sysctl and logger must be - standard and never contain spaces.
  • - -
- - - diff --git a/doc/ReleaseNotes_2.0.5.txt b/doc/ReleaseNotes_2.0.5.txt deleted file mode 100644 index fdc46f4ad..000000000 --- a/doc/ReleaseNotes_2.0.5.txt +++ /dev/null @@ -1,140 +0,0 @@ - Firewall Builder Release Notes - -Version 2.0.5 - - Released 01/07/05 - GUI and compilers v2.0.5 require API library libfwbuilder version 2.0.5 - -Summary - - This is a bugfix release; its main focus is on internationalization and - usability - - For those who wish to build from source, instructions are outlined in the - document "Install and Build instructions" on our web site here - -What's new - - * Improvements in the GUI - - * Fixed lots of places were strings were not properly marked for - localization, this lead to GUI showing '????' instead of a text - in some menu items and dialogs in non-english locales - * properly synchronizing state of the items main menu with state of - corresponding items in the pop-up menu that appears when user - right-mouse-clicks on an object in the tree - * fixes for non-localized text strings in dialogs (mostly - "Continue", "Yes"/"No" etc. in many places) - * proper localization of the human-readable version number text for - iptables; also made info window print readable text instead of - "lt_1.2.6" - * cosmetic changes in some dialogs layout to make the look better - when localized text makes strings much longer - * firewall object dialog tab "Templates" has been hidden. It is - unlikely that this feature will be implemented in 2.0.X series. - * Streamlined logic in the object editor dialog. This improves - handling of the situation when user closes dialog by clicking on - [x] while 1) there are unsaved data and/or 2) some of the - object's parameters have illegal values. The dialog behavior also - depends on the setting of the global flag "Autosave" that causes - dialog to automatically save data when user switches between - objects. - * when user opens data file in the old format (fwbuilder v1.1.x, - extension .xml) and after autoupgrade the program discovers that - the same file with extension .fwb already exists, it offers the - user a chance to choose different name. If user clicks "Cancel" - at this point, the program cancel operation and reverts upgraded - data file back to its original name and version. - * improved behavior of the main menu "Edit" as well as pop-up menu - that appears when user right mouse clicks on an object in the - tree. Menu item "Paste" should only be enabled if the clipboard - is not empty and objects that are stored in it can be pasted into - selected object in the tree. - * when user clicks menu item "File/Open" to open a new file, the - GUI should save and close currently opened file only after the - user chooses new file. If user clicks Cancel in the File/Open - dialog, operation should be cancelled so the user can continue - working with currently opened file. The same applies to operation - File/New. - * implemented feature request: colors that are used to color rules - can be changed in Preferences dialog. - * main menu item "Object/New Object/Address" and corresponding - toolbar button always creates an Address object under - Objects/Addresses folder in the tree. Address of an interface can - be created using pop-up menu item "Add IP Address" - * Pull-down menu "On startup" in the "General" tab of the - preferences dialog now has three items: "Load standard objects", - "Load last edited file" and "Ask user what to do". The last item - is default. - * Updated Japanese and Russian translations - - ---------------------------------------------------------------------- - -Bugs fixed in GUI: - - * bug (no num): the GUI crashed when user tried to add a library file - for auto-load in Preferences/Libraries and the first library object in - that file had a name using non-ascii characters - * bug (internal #34) the program should issue a warning when user tries - to add a library file (.fwl) that contains object library that already - exists in the opened data file. - * bugfixes for the behavior of the object editor dialogs. Dialog should - ask if user wants to save data and then validate it when user clicks - on [x] to close editor dialog. It used to validate the data first, - then ask if they want to close dialog. - * bug (localization): RCS log entries made using non-ascii characters - used to appear as '???' in Open File and File/Properties dialogs. - * localization was broken on win32 and mac os x because translation - files were not installed properly. Now fixed. - * bug #1092810: "Multiline RCS comments are shown as a single line on - windows". As it turned out, this bug affected all platforms. - * bug (no num) that caused GUI crash when user created new firewall - object using template with three interfaces. - -Bugs fixed in API: - - * bug #1068119: "additional whitespace for Rule comments in .fw file". - Added extra space between rule number and interface spec in rule - comments. - -Bugs fixed in policy compiler for iptables fwb_ipt: - - * bug #1089586: "default --icmp-type value is 0 in iptables < 1.2.9". - The problem concerns policy rules using service object "any ICMP". A - rule like this is supposed to match any ICMP packet. Few versions ago - I had to add option "-m icmp" (and "-m udp", "-m tcp") because I've - discovered that iptables-restore on some systems (linksys sveasoft - firmware, iptables v1.2.11) refused to load rules without it. Now it - turns out that iptables v < 1.2.9 (tested on 1.2.6a and 1.2.7a) - implicitly adds equivalent of "--icmp-type 0" to rules with "-p icmp - -m icmp" and without "--icmp-type" option. Since type 0 is actually - icmp echo reply, a rule like this does not match "any ICMP" as it was - supposed to do. Iptables 1.2.9 implicitly adds "--icmp-type 255" which - matches any icmp type. Using "--icmp-type 255" on iptables 1.2.6 and - 1.2.7 does not work (a rule does not match icmp packets with type - different from 255). The fix generates "-p icmp -m icmp --icmp-type - any" for iptables 1.2.9 and later, as well as when iptables version is - not specified in the firewall object settings. It generates just "-p - icmp" for versions < 1.2.9. - * bug #1092141: "irritating FORWARD rule for established connections". - Need rule in FORWARD chain only if ip forwarding is on or set to "no - change" - * bug #1059393: "function getaddr failed for eth1.0020". Generated - script can now work with interfaces that have a dot in their name - (such as "eth1.0020" - vlan interface) - -Bugs fixed in policy compiler for ipfw fwb_ipfw: - - * bug #1089866: "multiple services in one rule confuses ipfw compiler". - If several UDP or TCP objects were used in the same policy rule and - these service objects had source port ranges defined, the compiler - would produce incorrect code by combining source port range - specifications together in the same ipfw command. - * bug #1093461: "problem with 'established' in ipfw". Ipfw requires - protocol to be set to 'tcp' if option 'established' is used in a rule. - * bug #1093472: "ipfw port range(s) errors". There can only be one port - range in a single ipfw rule. - * bug #1093620: "path (to ipfw) with spaces fails". Generated script - failed if path to ipfw contained space. I only worked around this - problem for ipfw; paths to sysctl and logger must be standard and - never contain spaces. diff --git a/doc/ReleaseNotes_2.0.6.html b/doc/ReleaseNotes_2.0.6.html deleted file mode 100644 index e794b3740..000000000 --- a/doc/ReleaseNotes_2.0.6.html +++ /dev/null @@ -1,259 +0,0 @@ - - - - - - - -

Firewall Builder Release Notes

-
-

Version 2.0.6

-
-

- Released 02/17/05 -
- GUI and compilers v2.0.6 require API library libfwbuilder version 2.0.6 -
-

Summary

-

- This release adds ability to print firewall rulesets -

- For those who wish to build from source, instructions are outlined - in the document "Install and Build instructions" on our web site here - -

What's new

-
    - -
  • Improvements in the GUI -

    -

      -
    • Support for printing of firewall rulesets: -

      -

        -
      • prints policies and NAT rules for the currently - opened firewall object
      • - -
      • can print a header on each page, header includes - file name, RCS revision number and page number. Header - can be turned off
      • - -
      • can print a legend at the end of the - printout. Legend shows each icon and what object type it - corresponds to. Printing of the legend can be turned - off.
      • - -
      • can print a list of objects used in all rules of the - firewall. Each object is accompanied with a brief - summary of its parameters. This can be turned off as - well.
      • - -
      • While printing rule sets, the program will break the - table on the boundary of a rule when it reaches end of - the page
      • - -
      • Rule sets are printed as screenshots of the same - table widget used in the GUI. The user can change - scaling factor for the tables to make them fit on the - page
      • - -
      • Printing has been tested on Linux, Windows and Mac - OS X
      • -
      -
    • - -
    • slightly changed logic with user warnings in the object - removal code. The program asks the user for confirmation if - they remove an ordinary object from a regular - library. Confirmation is not asked if object is removed from - "Deleted objects" library or when a library is being deleted - (in this case we ask a different quastion later - anyway). This helps avoid double warning when a library is - deleted. -

      -

    • - -
    • New service objects: -
        -
      • TCP service objects for regular VNC viewer (displays - 0 and 1) and Java VNC viewer (displays 0 and 1)
      • -
      • UDP service object for OpenVPN
      • -
      -
    • -
    -
  • - -
  • Improvements in compiler for iptables fwb_ipt -

    -

      -
    • implemented feature req. #1112980: "Need unique names - for accounting rules". User can now specify a unique name - for rules with action 'Accounting'; this name will be - converted to a chain name. This simplifies accounting since - chain name for such rule won't change if the user adds or - removes rules above or below.
    • -
    -
  • -
- -
-
-
- - -
-
-

Bugs fixed in GUI:

-
    -
  • bug #1107838: "bug in configure script in fwbuilder - 2.0.6". Need to specify path "./" when calling runqmake.sh
  • - -
  • bug #1109631: "can not copy firewall script to /etc on - Linksys". Added an option ot all OS resource files that - determines whether user is allowed to change installation - directory on the firewall. Currently it is allowed on all - supported OS except Linksys/Sveasoft because there /etc/ resides - on read-only filesystem
  • - -
  • bug #1109174: "Cannot print rule base" - implemented - printing
  • - -
  • bug #1111244 "GUI allows to add more than one MAC address to - an interface". There can only be one MAC address for each - interface.
  • - -
  • bug #1112264: "Load last edited file" setting doesn't - work. This was broken only on Mac OS X.
  • - -
  • bug #1112764: "some Objects are partially obscured in - printout". Parts of the "Objects" table were clipped.
  • - -
  • bug #1112776: "some items touching seperator lines on - printouts". Rule elements "Action", "Direction", "Options" and - "Comment" were placed right at the top of the table cell which - led to their clipping when rule set was printed on Mac OS - X. Need more testing.
  • - -
  • bug #1115412: "Problem installer FWbuilder 2.0.5 for - Windows". Switched to command line option "-l" to specify user - name for external ssh in installer. This was necessary because - Van Dyke SecureCRT on Windows does not support user@host syntax.
  • - -
  • bug #1030538: "incorrect highlighting when selecting - multiple rules". This bug seems to be specific to Mac OS X
  • - -
  • support request #1118039: "Error when Windows client calls - plink -ssh". The problem is that putty ignores protocol and port - specified in the session file if command line option -ssh is - given. On the other hand, the sign of session usage is an empty - user name, so we can check for that. If user name is empty, then - putty will use current Windows account name to log in to the - firewall and this is unlikely to work anyway. This seems to be a - decent workaround.
  • - -
  • bug #1118717: "fwbuilder 206 on Windows XP SP2: error - checking out". Env variable USERNAME was not set in user's - profile, which triggered this bug. Now using getuid to get user - name on Unix and GetUserName on Windows. This should make the - program more resilient for situations when environment variable - LOGNAME or USERNAME is not set
  • - -
  • bug #1120904: "GUI hangs when accessing RCS file". Improved - parsing of rlog output.
  • -
- -
-
-

Bugs fixed in API:

-
    -
  • bug #1108861: "two rules using MAC address matching shadow - each other". Need to check for MAC addresses while processing - rules for shadowing.
  • - -
  • bug #1105167: "Crash when importing a library that has been - deleted".
  • - - -
- -
-
-

Bugs fixed in policy compiler for iptables fwb_ipt:

-
    -
  • bug #1106701: 'backup ssh access' and statefulness - interation. Need to add rules matching states ESTABLISHED and - RELATED for the backup ssh access to make sure it works even if - global rule matching these states is disabled.
  • - -
  • bug #1101910: "Samba problem with Bridged Firewall". Need to - split rule to take care of broadcasts forwarded by the bridge - and broadcasts that are accepted by the firewall itself. Need to - do this only if the rule is not associated with any bridging - interface.
  • - -
  • bug #1102629: "lost chain in accounting rules". Rules with - multiple objects in one of the rule elements and action - 'Accounting' generated code that ignored objects in that rule - element
  • - -
  • bug #1112976: "Accounting rule with logging produces looped - iptables command"
  • - -
  • bug #1112470: "Problem with FW part of ANY in Bridged mode". - If fw is considered part of any, we should place rule in - INPUT/OUTPUT chains even if it is a bridging fw since fw itself - may send or receive packets.
  • - -
  • bug #1123748 "busybox grep -E". Busybox does not support - option "-E" with grep, however it has "egrep".
  • - -
  • bug #1123933 "iptables add_addr() expr binary not found". As - it turns out, /usr/bin/ is not in PATH during boot time on - Slackware. I added /usr/bin/ to PATH variable in generated - iptables script.
  • -
- - -
-
-

Bugs fixed in policy compiler for pf fwb_pf:

-
    -
  • bug #1105755 "Custom Service objects not working for PF - compiler".User tried to generate a nat rule like this using - CustomService object: -

    -

    - nat on eth1 proto {tcp udp icmp gre} from 192.168.1.0/24 to any -> 22.22.22.22 -
    -

    - Taken from the bug report: -

    - as it turned out, I can not fix this. You are trying to use - Custom Service object to insert protocol list into a "nat" - rule. Normally, a service object such as TCP or UDP service - generates two components for any rule where it is used: a - protocol specification and port specification (type/ code spec - for ICMP). PF is sensitive to the order of parameters in the - rule, in particular, protocol must be defined after interface - but before src/dst addresses in the rule, while port numbers - go after addresses. Compiler easily retrieves this - information from IP, TCP, UDP and ICMP services and places it - in a proper slots in the rule it generates. CustomService - does not have a notion of protocol and parameters for it, so - compiler puts a string that is configured in the CustomService - in the place reserved for port numbers. This means you can not - use CustomService to specify protocols. -

    - There still was a bug in fwb_pf where it would print - "custom_service" in place of protocol. This is fixed in 2.0.6 - build 542. Protocols can not be inserted with Custom Service - though. -

    - Feature request #1111267 "CustomService should specify protocol - and parameters for it" has been opened -

  • -
- - - - diff --git a/doc/ReleaseNotes_2.0.6.txt b/doc/ReleaseNotes_2.0.6.txt deleted file mode 100644 index 5a76f75bd..000000000 --- a/doc/ReleaseNotes_2.0.6.txt +++ /dev/null @@ -1,166 +0,0 @@ - Firewall Builder Release Notes - -Version 2.0.6 - - Released 02/17/05 - GUI and compilers v2.0.6 require API library libfwbuilder version 2.0.6 - -Summary - - This release adds ability to print firewall rulesets - - For those who wish to build from source, instructions are outlined in the - document "Install and Build instructions" on our web site here - -What's new - - * Improvements in the GUI - - * Support for printing of firewall rulesets: - - * prints policies and NAT rules for the currently opened - firewall object - * can print a header on each page, header includes file name, - RCS revision number and page number. Header can be turned - off - * can print a legend at the end of the printout. Legend shows - each icon and what object type it corresponds to. Printing - of the legend can be turned off. - * can print a list of objects used in all rules of the - firewall. Each object is accompanied with a brief summary of - its parameters. This can be turned off as well. - * While printing rule sets, the program will break the table - on the boundary of a rule when it reaches end of the page - * Rule sets are printed as screenshots of the same table - widget used in the GUI. The user can change scaling factor - for the tables to make them fit on the page - * Printing has been tested on Linux, Windows and Mac OS X - - * slightly changed logic with user warnings in the object removal - code. The program asks the user for confirmation if they remove - an ordinary object from a regular library. Confirmation is not - asked if object is removed from "Deleted objects" library or when - a library is being deleted (in this case we ask a different - quastion later anyway). This helps avoid double warning when a - library is deleted. - - * New service objects: - - * TCP service objects for regular VNC viewer (displays 0 and - 1) and Java VNC viewer (displays 0 and 1) - * UDP service object for OpenVPN - - * Improvements in compiler for iptables fwb_ipt - - * implemented feature req. #1112980: "Need unique names for - accounting rules". User can now specify a unique name for rules - with action 'Accounting'; this name will be converted to a chain - name. This simplifies accounting since chain name for such rule - won't change if the user adds or removes rules above or below. - - ---------------------------------------------------------------------- - -Bugs fixed in GUI: - - * bug #1107838: "bug in configure script in fwbuilder 2.0.6". Need to - specify path "./" when calling runqmake.sh - * bug #1109631: "can not copy firewall script to /etc on Linksys". Added - an option ot all OS resource files that determines whether user is - allowed to change installation directory on the firewall. Currently it - is allowed on all supported OS except Linksys/Sveasoft because there - /etc/ resides on read-only filesystem - * bug #1109174: "Cannot print rule base" - implemented printing - * bug #1111244 "GUI allows to add more than one MAC address to an - interface". There can only be one MAC address for each interface. - * bug #1112264: "Load last edited file" setting doesn't work. This was - broken only on Mac OS X. - * bug #1112764: "some Objects are partially obscured in printout". Parts - of the "Objects" table were clipped. - * bug #1112776: "some items touching seperator lines on printouts". Rule - elements "Action", "Direction", "Options" and "Comment" were placed - right at the top of the table cell which led to their clipping when - rule set was printed on Mac OS X. Need more testing. - * bug #1115412: "Problem installer FWbuilder 2.0.5 for Windows". - Switched to command line option "-l" to specify user name for external - ssh in installer. This was necessary because Van Dyke SecureCRT on - Windows does not support user@host syntax. - * bug #1030538: "incorrect highlighting when selecting multiple rules". - This bug seems to be specific to Mac OS X - * support request #1118039: "Error when Windows client calls plink - -ssh". The problem is that putty ignores protocol and port specified - in the session file if command line option -ssh is given. On the other - hand, the sign of session usage is an empty user name, so we can check - for that. If user name is empty, then putty will use current Windows - account name to log in to the firewall and this is unlikely to work - anyway. This seems to be a decent workaround. - * bug #1118717: "fwbuilder 206 on Windows XP SP2: error checking out". - Env variable USERNAME was not set in user's profile, which triggered - this bug. Now using getuid to get user name on Unix and GetUserName on - Windows. This should make the program more resilient for situations - when environment variable LOGNAME or USERNAME is not set - * bug #1120904: "GUI hangs when accessing RCS file". Improved parsing of - rlog output. - -Bugs fixed in API: - - * bug #1108861: "two rules using MAC address matching shadow each - other". Need to check for MAC addresses while processing rules for - shadowing. - * bug #1105167: "Crash when importing a library that has been deleted". - -Bugs fixed in policy compiler for iptables fwb_ipt: - - * bug #1106701: 'backup ssh access' and statefulness interation. Need to - add rules matching states ESTABLISHED and RELATED for the backup ssh - access to make sure it works even if global rule matching these states - is disabled. - * bug #1101910: "Samba problem with Bridged Firewall". Need to split - rule to take care of broadcasts forwarded by the bridge and broadcasts - that are accepted by the firewall itself. Need to do this only if the - rule is not associated with any bridging interface. - * bug #1102629: "lost chain in accounting rules". Rules with multiple - objects in one of the rule elements and action 'Accounting' generated - code that ignored objects in that rule element - * bug #1112976: "Accounting rule with logging produces looped iptables - command" - * bug #1112470: "Problem with FW part of ANY in Bridged mode". If fw is - considered part of any, we should place rule in INPUT/OUTPUT chains - even if it is a bridging fw since fw itself may send or receive - packets. - * bug #1123748 "busybox grep -E". Busybox does not support option "-E" - with grep, however it has "egrep". - * bug #1123933 "iptables add_addr() expr binary not found". As it turns - out, /usr/bin/ is not in PATH during boot time on Slackware. I added - /usr/bin/ to PATH variable in generated iptables script. - -Bugs fixed in policy compiler for pf fwb_pf: - - * bug #1105755 "Custom Service objects not working for PF compiler".User - tried to generate a nat rule like this using CustomService object: - - nat on eth1 proto {tcp udp icmp gre} from 192.168.1.0/24 to any -> - 22.22.22.22 - - Taken from the bug report: - - as it turned out, I can not fix this. You are trying to use Custom - Service object to insert protocol list into a "nat" rule. Normally, a - service object such as TCP or UDP service generates two components for - any rule where it is used: a protocol specification and port - specification (type/ code spec for ICMP). PF is sensitive to the order - of parameters in the rule, in particular, protocol must be defined - after interface but before src/dst addresses in the rule, while port - numbers go after addresses. Compiler easily retrieves this information - from IP, TCP, UDP and ICMP services and places it in a proper slots in - the rule it generates. CustomService does not have a notion of - protocol and parameters for it, so compiler puts a string that is - configured in the CustomService in the place reserved for port - numbers. This means you can not use CustomService to specify - protocols. - - There still was a bug in fwb_pf where it would print "custom_service" - in place of protocol. This is fixed in 2.0.6 build 542. Protocols can - not be inserted with Custom Service though. - - Feature request #1111267 "CustomService should specify protocol and - parameters for it" has been opened diff --git a/doc/ReleaseNotes_2.0.7.html b/doc/ReleaseNotes_2.0.7.html deleted file mode 100644 index 42a8ece3e..000000000 --- a/doc/ReleaseNotes_2.0.7.html +++ /dev/null @@ -1,271 +0,0 @@ - - - - - - - -

Firewall Builder Release Notes

-
-

Version 2.0.7

-
-

- Released 05/08/2005 -
- GUI and compilers v2.0.7 require API library libfwbuilder version 2.0.7 -
-

Summary

-

- This is a bug fix release -

- For those who wish to build from source, instructions are outlined - in the document "Install and Build instructions" on our web site here - -

What's new

-
    -
  • Improvements in the GUI -

    -

      -
    • implemented feature req. #1151220: "Close" button should - change is caption/title to "Install". When user clicks - "Install" toolbar button or main menu item, the "Close" - button in the pop-up window that displays compiler progress - changes its text caption to "Install"
    • - -
    • implemented feature request #1151206: "Search for IP - Addresses". "Find" dialog searches for objects by a - combination of name and one of the following attributes: - address, tcp/udp port, ip protocol number or icmp message - type. Regular expressions can be used for both name and - attribute.
    • - -
    • Support for SNMP operations has been added in Windows - packages of Firewall Builder
    • -
    -
  • - -
  • Improvements in built-in installer: -

    - User can specify additional command line parameters for ssh - that built-in installer runs to access firewall. This allows - for alternative ssh port or alternative ssh identity to be - used when accessing firewall. Parameters can be added in the - "Installer" tab of firewall settings dialog for all - platforms. -

    -
  • - -
  • Improvements in compiler for ipfilter fwb_ipf -

    - Added support for dynamic addresses in ipfilter. Actual - address of dynamic interface is now determined at run-time - in the policy activation script <firewall_name>.fw - generated by fwbuilder. If dynamic interface is used - somewhere in the policy or nat rules, it will be replaced - with its actual address by activation script before - configuration is sent to ipf or ipnat for activation. This - run-time substitution is done only if a checkbox is checked - in the "Script options" tab of firewall settings - dialog. Default behavior is to use "any". This is because - ipfilter configuration files <firewall>-ipf.conf and - <firewall>-nat.conf that rely on run-time substitution - of dynamic interface address can not be loaded using - standard activation scripts that come with FreeBSD. -

    -

    - Generated script uses function getaddr() to determine - address of dynamic interface. This function falls back to - 0.0.0.0/32 if dynamic interface has not been assigned an - address yet or is down. Ipfilter policy using run-time - substitution of dynamic interface addresses will be - functional even if these interfaces are down or do not have - IP address. -

    -
  • - -
  • Improvements in compiler for iptables fwb_ipt -

    - Generated iptables script sets default policies to DROP in - all ipv6 filter chains. More detailed control can be - implemented using prolog or epilog scripts. -

    - Note that this changes behavior of the generated iptables - script with respect to IPv6. Until now, the script just - ignored IPv6 but some people felt this leaves a hole in the - firewall and asked me to make the script close it. Generated - shell code will check if ip6tables is installed on the - system and if it actually works before setting default - policies to DROP. This means it won't try to do it if - ip6tables is not installed or if it is present, but IPv6 is - not compiled into the kernel (so ip6tables does not work and - generates errors). -

    -
  • -
- -
-
-
- - -
-
-

Bugs fixed in GUI:

-
    -
  • bug #1151052: "Not external interfaces marked as - external". Dialog for an interface object that belongs to a host - should not show checkbox "external (insecure) interface"
  • - -
  • bug #1151212: "Collapsed sub-objects shouldn't be added if - they are hidden". When user selects multiple objects in the tree - some of which have child objects, those child objects used to be - also selected and added to groups in addition to their parent - objects via drag-and-drop operation.
  • - -
  • bug #1151243: "Maintain format of description text". The GUI - ignored text formatting in object comment when displayed it in - the info panel (lower left corner of the main windows)
  • - -
  • bug #1155163: "print does not print group contents". The - program printed only number of objects contaned in object or - service groups. Now it prints lists of member objects for all - groups used in rules. If groups contain other groups, they are - printed recursively.
  • - -
  • bug #1172620: "Add tcp service object for icslap". Added - this object to the objects library "Standard".
  • - -
  • bug #1184791: "can not copy/paste multiple objects into a - group"
  • - -
- -
-
-

Bugs fixed in API:

-
    -
  • - bug #1158870: "mutexes are not properly created on - FreeBSD". Mutexes gethostbyname_mutex and gethostbyaddr_mutex - were never created but used on OS where thread-safe resolver - is not available. -
  • - -
  • bug #1151219: "New Host creation window is not well - dimensioned". Fixed wrong dialog page layout in the new host - wizard.
  • - -
  • bug #1157976: "patches to make fwbuilder compile under - NetBSD 1.6". Applied patches.
  • - -
  • bug #1173801: '"&" character in prolog/epilog'. Needed to - call xmlEncodeSpecialChars to encode special characters in - firewall options
  • -
- -
-
-

Bugs fixed in policy compiler for iptables fwb_ipt:

-
    -
  • - bug #1123748: "busybox grep -E". Busybox in floppyfw is - compiled without support for egrep (or grep -E). Switched to - using "plain" grep.
  • - -
  • bug #1160186: 'IPTables Compiler - Multiport Issue'. When 16 - or 31 ports were used in a single rule, compiler generated - command with conflicting options "-m multiport --dport"
  • - -
  • - bug #1176890: "block IPv6". Generated iptables script sets - default policies to DROP in all ipv6 filter chains. More - detailed control can be implemented using prolog or epilog - scripts. -

    - Note that this changes behavior of the generated iptables - script with respect to IPv6. Until now, the script just - ignored IPv6 but some people felt this leaves a hole in the - firewall and asked me to make the script close it. Generated - shell code will check if ip6tables is installed on the - system and if it actually works before setting default - policies to DROP. This means it won't try to do it if - ip6tables is not installed or if it is present, but IPv6 is - not compiled into the kernel (so ip6tables does not work and - generates errors). -

  • - -
  • bug #1176890: "block IPv6". Generated iptables script sets - default policies to DROP in all ipv6 filter chains. More - detailed control can be implemented using prolog or epilog - scripts.
  • - -
  • bug #1179103: 'compiled rules can not be - installed'. Generated iptables script could not be used on - systems with non-English locale where timezone name used local - characters because these characters were printed as hex ( - "&#21488;" ) and '&' caused problems with shell. Now using - single quotes to make shell ignore any characters in the - string. Will deal with proper printing of localazed timezone - later.
  • - -
  • bug #1181359: "Missing traling space in "INVALID state" - syslog message"
  • - -
  • bug #1195201: "getaddr function return error ip address". Yet - another change in the way we use grep to find IP addresses of an - interface on Linux. We can't use regex (bug #1123748) and need - to filter out secondary addresses from the "ip addr show" - output. It looks like "grep -v :" neatly solves the problem - without using regex.
  • - -
- - -
-
-

Bugs fixed in policy compiler for pf fwb_ipf:

-
    -
  • bug #1173067: "support for port ranges in NAT rules - (ipfilter)" - policy compiler for ipfilter should split DNAT - rules (rdr) that use TCP or UDP objects with port ranges. A - warning is issued if more than 20 rules are created. -
  • - -
  • bug - #1173064: "support for dynamic interfaces in ipfilter". Actual - address of dynamic interface is now determined at run-time in the - policy activation script <firewall_name>.fw generated by - fwbuilder. If dynamic interface is used somewhere in the policy or - nat rules, it will be replaced with its actual address by - activation script before configuration is sent to ipf or ipnat for - activation. This run-time substitution is done only if a checkbox - is checked in the "Script options" tab of firewall settings - dialog. Default behavior is to use "any". This is because ipfilter - configuration files <firewall>-ipf.conf and <firewall>-nat.conf - that rely on run-time substitution of dynamic interface address - can not be loaded using standard activation scripts that come with - FreeBSD. -

    - This also fixes another problem in fwb_ipf where it generated rdr - and nat commands with address 0.0.0.0/32 if dynamic interface was - used in a NAT rule.

  • - -
- - - -
-
-

Bugs fixed in policy compiler for pf fwb_pf:

-
    -
  • bug #1176051: "incorrect rule generated for TCP service - ftp-data". If a rule used several TCP or UDP service objects and - one of them has source port range configured, generated PF - filter rule incorrectly matched on a combiantion of that source - port range _and_ destination port ranges from all other service - objects. This bug affected compilers for OpenBSD PF and ipfilter
  • -
- - - diff --git a/doc/ReleaseNotes_2.0.7.txt b/doc/ReleaseNotes_2.0.7.txt deleted file mode 100644 index ed200dff2..000000000 --- a/doc/ReleaseNotes_2.0.7.txt +++ /dev/null @@ -1,181 +0,0 @@ - Firewall Builder Release Notes - -Version 2.0.7 - - Released 05/08/2005 - GUI and compilers v2.0.7 require API library libfwbuilder version 2.0.7 - -Summary - - This is a bug fix release - - For those who wish to build from source, instructions are outlined in the - document "Install and Build instructions" on our web site here - -What's new - - * Improvements in the GUI - - * implemented feature req. #1151220: "Close" button should change - is caption/title to "Install". When user clicks "Install" toolbar - button or main menu item, the "Close" button in the pop-up window - that displays compiler progress changes its text caption to - "Install" - * implemented feature request #1151206: "Search for IP Addresses". - "Find" dialog searches for objects by a combination of name and - one of the following attributes: address, tcp/udp port, ip - protocol number or icmp message type. Regular expressions can be - used for both name and attribute. - * Support for SNMP operations has been added in Windows packages of - Firewall Builder - - * Improvements in built-in installer: - - User can specify additional command line parameters for ssh that - built-in installer runs to access firewall. This allows for - alternative ssh port or alternative ssh identity to be used when - accessing firewall. Parameters can be added in the "Installer" tab of - firewall settings dialog for all platforms. - - * Improvements in compiler for ipfilter fwb_ipf - - Added support for dynamic addresses in ipfilter. Actual address of - dynamic interface is now determined at run-time in the policy - activation script .fw generated by fwbuilder. If - dynamic interface is used somewhere in the policy or nat rules, it - will be replaced with its actual address by activation script before - configuration is sent to ipf or ipnat for activation. This run-time - substitution is done only if a checkbox is checked in the "Script - options" tab of firewall settings dialog. Default behavior is to use - "any". This is because ipfilter configuration files - -ipf.conf and -nat.conf that rely on run-time - substitution of dynamic interface address can not be loaded using - standard activation scripts that come with FreeBSD. - - Generated script uses function getaddr() to determine address of - dynamic interface. This function falls back to 0.0.0.0/32 if dynamic - interface has not been assigned an address yet or is down. Ipfilter - policy using run-time substitution of dynamic interface addresses will - be functional even if these interfaces are down or do not have IP - address. - - * Improvements in compiler for iptables fwb_ipt - - Generated iptables script sets default policies to DROP in all ipv6 - filter chains. More detailed control can be implemented using prolog - or epilog scripts. - - Note that this changes behavior of the generated iptables script with - respect to IPv6. Until now, the script just ignored IPv6 but some - people felt this leaves a hole in the firewall and asked me to make - the script close it. Generated shell code will check if ip6tables is - installed on the system and if it actually works before setting - default policies to DROP. This means it won't try to do it if - ip6tables is not installed or if it is present, but IPv6 is not - compiled into the kernel (so ip6tables does not work and generates - errors). - - ---------------------------------------------------------------------- - -Bugs fixed in GUI: - - * bug #1151052: "Not external interfaces marked as external". Dialog for - an interface object that belongs to a host should not show checkbox - "external (insecure) interface" - * bug #1151212: "Collapsed sub-objects shouldn't be added if they are - hidden". When user selects multiple objects in the tree some of which - have child objects, those child objects used to be also selected and - added to groups in addition to their parent objects via drag-and-drop - operation. - * bug #1151243: "Maintain format of description text". The GUI ignored - text formatting in object comment when displayed it in the info panel - (lower left corner of the main windows) - * bug #1155163: "print does not print group contents". The program - printed only number of objects contaned in object or service groups. - Now it prints lists of member objects for all groups used in rules. If - groups contain other groups, they are printed recursively. - * bug #1172620: "Add tcp service object for icslap". Added this object - to the objects library "Standard". - * bug #1184791: "can not copy/paste multiple objects into a group" - -Bugs fixed in API: - - * bug #1158870: "mutexes are not properly created on FreeBSD". Mutexes - gethostbyname_mutex and gethostbyaddr_mutex were never created but - used on OS where thread-safe resolver is not available. - * bug #1151219: "New Host creation window is not well dimensioned". - Fixed wrong dialog page layout in the new host wizard. - * bug #1157976: "patches to make fwbuilder compile under NetBSD 1.6". - Applied patches. - * bug #1173801: '"&" character in prolog/epilog'. Needed to call - xmlEncodeSpecialChars to encode special characters in firewall options - -Bugs fixed in policy compiler for iptables fwb_ipt: - - * bug #1123748: "busybox grep -E". Busybox in floppyfw is compiled - without support for egrep (or grep -E). Switched to using "plain" - grep. - * bug #1160186: 'IPTables Compiler - Multiport Issue'. When 16 or 31 - ports were used in a single rule, compiler generated command with - conflicting options "-m multiport --dport" - * bug #1176890: "block IPv6". Generated iptables script sets default - policies to DROP in all ipv6 filter chains. More detailed control can - be implemented using prolog or epilog scripts. - - Note that this changes behavior of the generated iptables script with - respect to IPv6. Until now, the script just ignored IPv6 but some - people felt this leaves a hole in the firewall and asked me to make - the script close it. Generated shell code will check if ip6tables is - installed on the system and if it actually works before setting - default policies to DROP. This means it won't try to do it if - ip6tables is not installed or if it is present, but IPv6 is not - compiled into the kernel (so ip6tables does not work and generates - errors). - * bug #1176890: "block IPv6". Generated iptables script sets default - policies to DROP in all ipv6 filter chains. More detailed control can - be implemented using prolog or epilog scripts. - * bug #1179103: 'compiled rules can not be installed'. Generated - iptables script could not be used on systems with non-English locale - where timezone name used local characters because these characters - were printed as hex ( "台" ) and '&' caused problems with shell. - Now using single quotes to make shell ignore any characters in the - string. Will deal with proper printing of localazed timezone later. - * bug #1181359: "Missing traling space in "INVALID state" syslog - message" - * bug #1195201: "getaddr function return error ip address". Yet another - change in the way we use grep to find IP addresses of an interface on - Linux. We can't use regex (bug #1123748) and need to filter out - secondary addresses from the "ip addr show" output. It looks like - "grep -v :" neatly solves the problem without using regex. - -Bugs fixed in policy compiler for pf fwb_ipf: - - * bug #1173067: "support for port ranges in NAT rules (ipfilter)" - - policy compiler for ipfilter should split DNAT rules (rdr) that use - TCP or UDP objects with port ranges. A warning is issued if more than - 20 rules are created. - * bug #1173064: "support for dynamic interfaces in ipfilter". Actual - address of dynamic interface is now determined at run-time in the - policy activation script .fw generated by fwbuilder. If - dynamic interface is used somewhere in the policy or nat rules, it - will be replaced with its actual address by activation script before - configuration is sent to ipf or ipnat for activation. This run-time - substitution is done only if a checkbox is checked in the "Script - options" tab of firewall settings dialog. Default behavior is to use - "any". This is because ipfilter configuration files - -ipf.conf and -nat.conf that rely on run-time - substitution of dynamic interface address can not be loaded using - standard activation scripts that come with FreeBSD. - - This also fixes another problem in fwb_ipf where it generated rdr and - nat commands with address 0.0.0.0/32 if dynamic interface was used in - a NAT rule. - -Bugs fixed in policy compiler for pf fwb_pf: - - * bug #1176051: "incorrect rule generated for TCP service ftp-data". If - a rule used several TCP or UDP service objects and one of them has - source port range configured, generated PF filter rule incorrectly - matched on a combiantion of that source port range _and_ destination - port ranges from all other service objects. This bug affected - compilers for OpenBSD PF and ipfilter diff --git a/doc/ReleaseNotes_2.0.8.html b/doc/ReleaseNotes_2.0.8.html deleted file mode 100644 index 875b1872c..000000000 --- a/doc/ReleaseNotes_2.0.8.html +++ /dev/null @@ -1,203 +0,0 @@ - - - - - - - -

Firewall Builder Release Notes

-
-

Version 2.0.8

-
-

- Released 07/08/2005 -
- GUI and compilers v2.0.8 require API library libfwbuilder version 2.0.8 -
-

Summary

-

- This is a bug fix release -

- For those who wish to build from source, instructions are outlined - in the document "Install and Build instructions" on our web site here - -

What's new

-
    -
  • Improvements in the GUI -

    -

      -
    • Included updated German translation by Hans Peter - Dittler <hpdittler at braintec-consult.de> -
    • - -
    • implemented Feature Request #1145666: "Print RCS - Log". File/Properties dialog can now print RCS log. Thanks - to "Ilya V. Yalovoy" <yalovoy@pilot.aip.mk.ua> for the - patch.
    • - -
    • Some code changes were made to make the code comiple and - work on Solaris. In particular, tests and emulation for - forkpty and cfmakeraw functions were added. Currently this - still remains largely untested.
    • - -
    -
  • - -
  • Improvements in policy compilers for pf, ipf, ipfw -

    -

      -
    • implemented support for subnets for backup ssh access for - pf,ipf,ipfw. Subnet can be defined using either full netmask or - bitlength: both "192.168.1.0/255.255.255.0" and "192.168.1.0/24" - are acceptable. Single host address works too, both as - "192.168.1.10" and as "192.168.1.10/255.255.255.255" or - "192.168.1.10/32". Incorrect address or netmask cause compiler - to abort processing.
    • -
    -
  • - -
  • Improvements in compiler for ipfw -

    -

      -
    • using rule sets to atomically swap old and new - rules. New rules are loaded in the set 1 and then swapped - into set 0. If there is an error in a new rule set, it is - caught while loading rules into inactive set 1, at which - point script stops without changing old firewall rules.
    • - -
    • added "established" rule on top of the regular backup - ssh access rule; this allows to maintain management ssh - session after the policy is reloaded. both "ipfw -f" and - swapping sets flushes all states, so the ssh session used to - upload and activate new policy breaks. A rule with - "established" keyword maintains this session.
    • -
    -
  • - - -
- -
-
-
- - -
-
-

Bugs fixed in the Standard Objects library:

-
    -
  • bug #210518: 'Incorrect ending day in the standard object - "weekends"'. This object defined time interval ending at 23:59 - on Monday instead of Sunday
  • - -
- - -
-
-

Bugs fixed in scripts and tools:

-
    -
  • bug #1200902: "fwb_compile_all does not work in 2.0". Script - fwb_compile_all broke because of changes in data file - format
  • - -
- - -
-
-

Bugs fixed in GUI:

-
    -
  • bug #1072842: "fwbuilder: Solaris and forkpty". We need - forkpty fr built-in installer but this function is not awailable - on Solaris. I am adding re-implementation, but it hasn't been - tested since I do not have Solaris machine.
  • - -
  • bug #1201406: "shutdown messages should be - suppressed". Installation scriptlet tries to kill shutdown - process, if there is one, to cancel pending shutdown that might - have been left over from test install. If there is none, the - script prints an error message "shutdown process not found" or - similar, which confuses user. Needed to suppress these error - messages.
  • - -
  • bug #1204067: "incorrect timezone handling in RCS". Windows - version of RCS incorrectly converts check-in time when time zone - is east of GMT. This caused the GUI to incorrectly show checkin - time of files in the "Open File" dialog if the program was - running in locale East of GMT, for instance in Japan.
  • - -
  • bug #1207983: "incorrect size of "I" and "L" buttons in the - group view dialog". Tested with large font and cleaned up layout - in many dialogs.
  • - -
  • bug #1212121: "sudo shutdown doesn't work".
  • - -
  • bug #1212123: "executing file below /tmp as root". Avoiding - world-writable directory /tmp/ while activating policy in the - test mode. This change makes installer use subdirectory "tmp" - under directory specified in the "intaller" tab of firewall - settings dialog. That directory is expected to have proper - permissions; subdirectory "tmp" can be created manually, - otherwise installer creates it. Either way, it is not - world-writable, therefore unauthorized users can not create - scripts in it.
  • - -
  • bug #1212179: "tool tips for TCP services cuts off some - services". The gui would show very long tooltip for large - groups; if the group was too large, the tooltip did not fit on - the screen.
  • - -
  • bug #1213361: "PF on FreeBSD-5.4R". Bug description is - misleading, the probem was caused by built-in installer rather - than by compiler for PF. Installer would not copy generated - script over ssh if the script was longer than some threshold and - the gui was running on FreeBSD.
  • - -
- -
-
-

Bugs fixed in policy compiler for iptables:

-
    -
  • bug #191423: "Weekend Time restriction not created - correctly". Rules with time restriction spanning from Saturday - to Sunday were generated with incorrect "--day" option -
  • - -
  • bug #1205665: "Error with summer time when compiling - script". Sometimes timezone name has "'" in it which confuses - shell and causes an error when generated script prints - "Activating firewall policy..." log message
  • - -
  • bug #1215279: "rate limiting rule logs everything". Rule - utlilizing "limit" module to rate limit packets with logging - logged every packet and dropped those that exceeded the - limit. The fix makes it apply the limit first and then log only - packets that were dropped.
  • -
- - -
-
-

Bugs fixed in policy compiler for iptw:

-
    -
  • bug #1155351: "Remote install of FW rulset fails due to race - condition". Generated ipfw firewall script could not be ran - reliably over ssh session because "ipfw -f" flushes all rules - and all state, which breaks ssh session. As soon as the script - needed to print anything, it got I/O error from the system - because TCP session for ssh was blocked; this stopped the script - and did not let it activate new firewall policy. Using rule sets - and "established" rule for the backup ssh access solved the - problem. -
  • - -
- - - - - - diff --git a/doc/ReleaseNotes_2.0.8.txt b/doc/ReleaseNotes_2.0.8.txt deleted file mode 100644 index 5d28df63f..000000000 --- a/doc/ReleaseNotes_2.0.8.txt +++ /dev/null @@ -1,124 +0,0 @@ - Firewall Builder Release Notes - -Version 2.0.8 - - Released 07/08/2005 - GUI and compilers v2.0.8 require API library libfwbuilder version 2.0.8 - -Summary - - This is a bug fix release - - For those who wish to build from source, instructions are outlined in the - document "Install and Build instructions" on our web site here - -What's new - - * Improvements in the GUI - - * Included updated German translation by Hans Peter Dittler - - * implemented Feature Request #1145666: "Print RCS Log". - File/Properties dialog can now print RCS log. Thanks to "Ilya V. - Yalovoy" for the patch. - * Some code changes were made to make the code comiple and work on - Solaris. In particular, tests and emulation for forkpty and - cfmakeraw functions were added. Currently this still remains - largely untested. - - * Improvements in policy compilers for pf, ipf, ipfw - - * implemented support for subnets for backup ssh access for - pf,ipf,ipfw. Subnet can be defined using either full netmask or - bitlength: both "192.168.1.0/255.255.255.0" and "192.168.1.0/24" - are acceptable. Single host address works too, both as - "192.168.1.10" and as "192.168.1.10/255.255.255.255" or - "192.168.1.10/32". Incorrect address or netmask cause compiler to - abort processing. - - * Improvements in compiler for ipfw - - * using rule sets to atomically swap old and new rules. New rules - are loaded in the set 1 and then swapped into set 0. If there is - an error in a new rule set, it is caught while loading rules into - inactive set 1, at which point script stops without changing old - firewall rules. - * added "established" rule on top of the regular backup ssh access - rule; this allows to maintain management ssh session after the - policy is reloaded. both "ipfw -f" and swapping sets flushes all - states, so the ssh session used to upload and activate new policy - breaks. A rule with "established" keyword maintains this session. - - ---------------------------------------------------------------------- - -Bugs fixed in the Standard Objects library: - - * bug #210518: 'Incorrect ending day in the standard object "weekends"'. - This object defined time interval ending at 23:59 on Monday instead of - Sunday - -Bugs fixed in scripts and tools: - - * bug #1200902: "fwb_compile_all does not work in 2.0". Script - fwb_compile_all broke because of changes in data file format - -Bugs fixed in GUI: - - * bug #1072842: "fwbuilder: Solaris and forkpty". We need forkpty fr - built-in installer but this function is not awailable on Solaris. I am - adding re-implementation, but it hasn't been tested since I do not - have Solaris machine. - * bug #1201406: "shutdown messages should be suppressed". Installation - scriptlet tries to kill shutdown process, if there is one, to cancel - pending shutdown that might have been left over from test install. If - there is none, the script prints an error message "shutdown process - not found" or similar, which confuses user. Needed to suppress these - error messages. - * bug #1204067: "incorrect timezone handling in RCS". Windows version of - RCS incorrectly converts check-in time when time zone is east of GMT. - This caused the GUI to incorrectly show checkin time of files in the - "Open File" dialog if the program was running in locale East of GMT, - for instance in Japan. - * bug #1207983: "incorrect size of "I" and "L" buttons in the group view - dialog". Tested with large font and cleaned up layout in many dialogs. - * bug #1212121: "sudo shutdown doesn't work". - * bug #1212123: "executing file below /tmp as root". Avoiding - world-writable directory /tmp/ while activating policy in the test - mode. This change makes installer use subdirectory "tmp" under - directory specified in the "intaller" tab of firewall settings dialog. - That directory is expected to have proper permissions; subdirectory - "tmp" can be created manually, otherwise installer creates it. Either - way, it is not world-writable, therefore unauthorized users can not - create scripts in it. - * bug #1212179: "tool tips for TCP services cuts off some services". The - gui would show very long tooltip for large groups; if the group was - too large, the tooltip did not fit on the screen. - * bug #1213361: "PF on FreeBSD-5.4R". Bug description is misleading, the - probem was caused by built-in installer rather than by compiler for - PF. Installer would not copy generated script over ssh if the script - was longer than some threshold and the gui was running on FreeBSD. - -Bugs fixed in policy compiler for iptables: - - * bug #191423: "Weekend Time restriction not created correctly". Rules - with time restriction spanning from Saturday to Sunday were generated - with incorrect "--day" option - * bug #1205665: "Error with summer time when compiling script". - Sometimes timezone name has "'" in it which confuses shell and causes - an error when generated script prints "Activating firewall policy..." - log message - * bug #1215279: "rate limiting rule logs everything". Rule utlilizing - "limit" module to rate limit packets with logging logged every packet - and dropped those that exceeded the limit. The fix makes it apply the - limit first and then log only packets that were dropped. - -Bugs fixed in policy compiler for iptw: - - * bug #1155351: "Remote install of FW rulset fails due to race - condition". Generated ipfw firewall script could not be ran reliably - over ssh session because "ipfw -f" flushes all rules and all state, - which breaks ssh session. As soon as the script needed to print - anything, it got I/O error from the system because TCP session for ssh - was blocked; this stopped the script and did not let it activate new - firewall policy. Using rule sets and "established" rule for the backup - ssh access solved the problem. diff --git a/doc/ReleaseNotes_2.0.9.html b/doc/ReleaseNotes_2.0.9.html deleted file mode 100644 index a7176ff2c..000000000 --- a/doc/ReleaseNotes_2.0.9.html +++ /dev/null @@ -1,100 +0,0 @@ - - - - - - -

Firewall Builder Release Notes

-
-

Version 2.0.9

-
-

- Released 09/17/2005 -
- GUI and compilers v2.0.9 require API library libfwbuilder version 2.0.9 -
-

Summary

-

- This is a bug fix release -

- For those who wish to build from source, instructions are outlined - in the document "Install and Build instructions" on our web site here - -

What's new

-
    -
  • Added support for Cisco FWSM. This includes recognition - of platform-specific options and parameters for FWSM v2.3 - (based on PIX 6.3), as well as interaction with FWSM in - built-in policy installer. Firewall Builder for PIX v1.1.10 - is required to generate configuration compatible with FWSM. -
  • - -
  • Improvements in the GUI -

    -

      -
    • Feature Request #1225393 "Print comments on objects" -
    • - -
    • Feature Request #1187461 "Add "commit" menu item". This - menu item commits opened data file to RCS but keeps it - opened so the user can continue editing.
    • - -
    • Spanish translation has been added, thanks to Carlos - Lozano <clozano@andago.com>
    • - -
    -
  • -
- -
-
-

Bugs fixed in the GUI:

-
    -
  • bug #1254775: "RCS checkin fails on Windows when data file - is too big". RCS tools failed to check the file in if it - consisted of one huge line of text. This fix makes th GUI save - data file (.fwb) in formatted form on Windows, just like on - Linux. This means each XML element is saved on separate line - instead of all of them being on the same line.
  • - -
  • bug #1226069: "Segfault: Drag&Drop between two - instances". If user started two instances of the GUI and tried - to drag and drop objects between them, the instance receiving an - object crashed.
  • - -
  • bugs #1233165: "Illegal Logging-Limit string" and #1287755: - "i18n is breaking iptables script". The GUI stored options of the - "limit" module as translated strings instead of standard - attributes.
  • - -
  • bug #1240205: "Iilegal --log-level Information". The GUI - stored log levels as translated strings instead of standard - attributes. -
  • - -
  • bug #1277129: "script is truncated when installed by the GUI - running on Mac". Built-in installer truncated firewall script - while copying it to the firewall if GUI was running on Mac OS X - and the script was relatively large. This bug triggered only on - Mac OS X.
  • - -
- -
-
-

Bugs fixed in policy compiler for PF:

-
    -
  • bug #1276083: "Destination NAT rules". Old restriction on - "rdr" rules that required service in OSrv is not valid anymore, - pf supports rdr rules with no protocol specification.
  • - -
- - - - - - - - diff --git a/doc/ReleaseNotes_2.0.9.txt b/doc/ReleaseNotes_2.0.9.txt deleted file mode 100644 index 37e9dd474..000000000 --- a/doc/ReleaseNotes_2.0.9.txt +++ /dev/null @@ -1,56 +0,0 @@ - Firewall Builder Release Notes - -Version 2.0.9 - - Released 09/17/2005 - GUI and compilers v2.0.9 require API library libfwbuilder version 2.0.9 - -Summary - - This is a bug fix release - - For those who wish to build from source, instructions are outlined in the - document "Install and Build instructions" on our web site here - -What's new - - * Added support for Cisco FWSM. This includes recognition of - platform-specific options and parameters for FWSM v2.3 (based on PIX - 6.3), as well as interaction with FWSM in built-in policy installer. - Firewall Builder for PIX v1.1.10 is required to generate configuration - compatible with FWSM. - * Improvements in the GUI - - * Feature Request #1225393 "Print comments on objects" - * Feature Request #1187461 "Add "commit" menu item". This menu item - commits opened data file to RCS but keeps it opened so the user - can continue editing. - * Spanish translation has been added, thanks to Carlos Lozano - - -Bugs fixed in the GUI: - - * bug #1254775: "RCS checkin fails on Windows when data file is too - big". RCS tools failed to check the file in if it consisted of one - huge line of text. This fix makes th GUI save data file (.fwb) in - formatted form on Windows, just like on Linux. This means each XML - element is saved on separate line instead of all of them being on the - same line. - * bug #1226069: "Segfault: Drag&Drop between two instances". If user - started two instances of the GUI and tried to drag and drop objects - between them, the instance receiving an object crashed. - * bugs #1233165: "Illegal Logging-Limit string" and #1287755: "i18n is - breaking iptables script". The GUI stored options of the "limit" - module as translated strings instead of standard attributes. - * bug #1240205: "Iilegal --log-level Information". The GUI stored log - levels as translated strings instead of standard attributes. - * bug #1277129: "script is truncated when installed by the GUI running - on Mac". Built-in installer truncated firewall script while copying it - to the firewall if GUI was running on Mac OS X and the script was - relatively large. This bug triggered only on Mac OS X. - -Bugs fixed in policy compiler for PF: - - * bug #1276083: "Destination NAT rules". Old restriction on "rdr" rules - that required service in OSrv is not valid anymore, pf supports rdr - rules with no protocol specification. diff --git a/doc/ReleaseNotes_2.1.10.html b/doc/ReleaseNotes_2.1.10.html deleted file mode 100644 index 1bb890f02..000000000 --- a/doc/ReleaseNotes_2.1.10.html +++ /dev/null @@ -1,59 +0,0 @@ - - - - - - - -

Firewall Builder Release Notes

-
-

Version 2.1.10

-
-

-Released 02/17/2007 -
-GUI and compilers v2.1.10 require API library libfwbuilder version 2.1.10 -
-

Summary

-

-This is bugfix release. - -

-For those who wish to build from source, instructions are outlined -in the document "Install and Build instructions" on our web site here - - - -

Improvements and bug fixes in the GUI

-
    - -
  • fixed bug #1661140: "built-in installer broken in 2.1.9 for - PF". Installer incorrectly set name for files it copied to the - firewall if generated configuration consisted of several - files. Affected platforms are PF and ipfilter because normally for - these platforms compiler generates two files. -
  • - -
  • fixed bug #1659832: "No compile with QT without STL - support"
  • - -
  • a workaround for the bug 1629461: "Policy tabs do not scroll @ - window extent on OSX". The tab widget used to show policy, nat, - routing and policy branch rulesets does not switch to a "folded" - mode on Mac OS X when it needs to show more tabs that fit in the - window. Since I can't figure out a way to force it to do that, I - am dropping "Policy/" from the tab titles for branches to make - them shorter. This will help users with policies with many - branches, however it does not solve the problem because as they - keep adding branches, at some point they won't fit in the window - again.
  • - -
  • added an item "Where used" to the context menu associated with - objects in rules
  • -
- - - - - diff --git a/doc/ReleaseNotes_2.1.10.txt b/doc/ReleaseNotes_2.1.10.txt deleted file mode 100644 index 50236975b..000000000 --- a/doc/ReleaseNotes_2.1.10.txt +++ /dev/null @@ -1,33 +0,0 @@ - Firewall Builder Release Notes - -Version 2.1.10 - - Released 02/17/2007 - GUI and compilers v2.1.10 require API library libfwbuilder version 2.1.10 - -Summary - - This is bugfix release. - - For those who wish to build from source, instructions are outlined in the - document "Install and Build instructions" on our web site here - -Improvements and bug fixes in the GUI - - * fixed bug #1661140: "built-in installer broken in 2.1.9 for PF". - Installer incorrectly set name for files it copied to the firewall if - generated configuration consisted of several files. Affected platforms - are PF and ipfilter because normally for these platforms compiler - generates two files. - * fixed bug #1659832: "No compile with QT without STL support" - * a workaround for the bug 1629461: "Policy tabs do not scroll @ window - extent on OSX". The tab widget used to show policy, nat, routing and - policy branch rulesets does not switch to a "folded" mode on Mac OS X - when it needs to show more tabs that fit in the window. Since I can't - figure out a way to force it to do that, I am dropping "Policy/" from - the tab titles for branches to make them shorter. This will help users - with policies with many branches, however it does not solve the - problem because as they keep adding branches, at some point they won't - fit in the window again. - * added an item "Where used" to the context menu associated with objects - in rules diff --git a/doc/ReleaseNotes_2.1.11.html b/doc/ReleaseNotes_2.1.11.html deleted file mode 100644 index 4003a085d..000000000 --- a/doc/ReleaseNotes_2.1.11.html +++ /dev/null @@ -1,109 +0,0 @@ - - - - - - - -

Firewall Builder Release Notes

-
-

Version 2.1.11

-
-

-Released 04/29/2007 -
-GUI and compilers v2.1.11 require API library libfwbuilder version 2.1.11 -
-

Summary

-

-This is bugfix release. - -

-For those who wish to build from source, instructions are outlined -in the document "Install and Build instructions" on our web site here - - - -

Improvements and bug fixes in the GUI

-
    - -
  • redesigned TimeService object dialog
  • - -
  • minor redesign of the interface object dialog to make network - zone more prominent and easier to set when network and group - objects have long names.
  • - -
  • fixed bug #1685741: "GUI crash: click on an empty part of obj - tree, then desktop"
  • - -
  • fixed bug #1692411: "can't set accouting rule name (fwbuilder - 2.1.11)"
  • - -
  • fixed bug #1684334: "RCS should use $LOGNAME when commit"
  • - -
  • fixed bug #1701971: "Enabeling test mode doent activate the - reboot interval". Checking "Test mode" checkbox in the - installer options dialog should enable widgets that configure - automatic reboot timeout.
  • - -
  • fixed bug #1702830: "fwbuilder does not detect errors during - policy install". Built-in installer detects error messages - printed by iptables and iptables-restore and aborts - installation process. Summary page shown in the end reflects - this as failed install.
  • - -
- -

Improvements and bug fixes in policy compiler for iptables

-
    -
  • Added support for --datestart and --datestop options for module - 'time' in compiler for iptables
  • - -
  • fixed bug #1672191: "Time limit generates unexpected iptables - command"
  • - -
  • fixed bug #1695481: "compliation error with lower end - port". Before, user could enter start port range number - greater than the end port range number. Neither the GUI nor - compiler noticed this, which resulted in the incorrect - firewall configuration. This fix adds check in the GUI to not - let the user enter port ranges like that.
  • - -
  • fixed bug 1699483: "hashlimit-htable-expire not set". Added GUI - controls and compiler support for hashlimit module options - "--hashlimit-name", "--hashlimit-htable-size", - "--hashlimit-htable-max", "--hashlimit-htable-expire" and - "--hashlimit-htable-gcinterval"
  • - -
  • fixed bug #1703954: "Mark target in postrouting chain". Packets - that originate on the firewall should be marked in the OUTPUT - chain. According to the netfilter packet flow diagram at - http://www.shorewall.net/NetfilterOverview.html , rerouting - happens after OUTPUT hook but before POSTROUTING hook. So in - order to be able to reroute packet originated on the firewall, - they should be marked in OUTPUT
  • - -
- - -

Improvements and bug fixes in policy compiler for PF

-
    -
  • fixed bug #1674940: "if max-src-conn == 0: syntax - error". Options max-src-conn and max-src-states can not have - value '0'
  • - -
- -

Improvements and bug fixes in policy compiler for ipfilter

-
    -
  • fixed bug #1678410: "Ipfilter compiler uses wrong keyword for - "fragment""
  • - -
  • fixed bug #1676845: "lsrr option not compiling"
  • - -
- - - - diff --git a/doc/ReleaseNotes_2.1.11.txt b/doc/ReleaseNotes_2.1.11.txt deleted file mode 100644 index bf302789f..000000000 --- a/doc/ReleaseNotes_2.1.11.txt +++ /dev/null @@ -1,65 +0,0 @@ - Firewall Builder Release Notes - -Version 2.1.11 - - Released 04/29/2007 - GUI and compilers v2.1.11 require API library libfwbuilder version 2.1.11 - -Summary - - This is bugfix release. - - For those who wish to build from source, instructions are outlined in the - document "Install and Build instructions" on our web site here - -Improvements and bug fixes in the GUI - - * redesigned TimeService object dialog - * minor redesign of the interface object dialog to make network zone - more prominent and easier to set when network and group objects have - long names. - * fixed bug #1685741: "GUI crash: click on an empty part of obj tree, - then desktop" - * fixed bug #1692411: "can't set accouting rule name (fwbuilder 2.1.11)" - * fixed bug #1684334: "RCS should use $LOGNAME when commit" - * fixed bug #1701971: "Enabeling test mode doent activate the reboot - interval". Checking "Test mode" checkbox in the installer options - dialog should enable widgets that configure automatic reboot timeout. - * fixed bug #1702830: "fwbuilder does not detect errors during policy - install". Built-in installer detects error messages printed by - iptables and iptables-restore and aborts installation process. Summary - page shown in the end reflects this as failed install. - -Improvements and bug fixes in policy compiler for iptables - - * Added support for --datestart and --datestop options for module 'time' - in compiler for iptables - * fixed bug #1672191: "Time limit generates unexpected iptables command" - * fixed bug #1695481: "compliation error with lower end port". Before, - user could enter start port range number greater than the end port - range number. Neither the GUI nor compiler noticed this, which - resulted in the incorrect firewall configuration. This fix adds check - in the GUI to not let the user enter port ranges like that. - * fixed bug 1699483: "hashlimit-htable-expire not set". Added GUI - controls and compiler support for hashlimit module options - "--hashlimit-name", "--hashlimit-htable-size", - "--hashlimit-htable-max", "--hashlimit-htable-expire" and - "--hashlimit-htable-gcinterval" - * fixed bug #1703954: "Mark target in postrouting chain". Packets that - originate on the firewall should be marked in the OUTPUT chain. - According to the netfilter packet flow diagram at - http://www.shorewall.net/NetfilterOverview.html , rerouting happens - after OUTPUT hook but before POSTROUTING hook. So in order to be able - to reroute packet originated on the firewall, they should be marked in - OUTPUT - -Improvements and bug fixes in policy compiler for PF - - * fixed bug #1674940: "if max-src-conn == 0: syntax error". Options - max-src-conn and max-src-states can not have value '0' - -Improvements and bug fixes in policy compiler for ipfilter - - * fixed bug #1678410: "Ipfilter compiler uses wrong keyword for - "fragment"" - * fixed bug #1676845: "lsrr option not compiling" diff --git a/doc/ReleaseNotes_2.1.12.html b/doc/ReleaseNotes_2.1.12.html deleted file mode 100644 index 90194b251..000000000 --- a/doc/ReleaseNotes_2.1.12.html +++ /dev/null @@ -1,436 +0,0 @@ - - - - - - - -

Firewall Builder Release Notes

-
-

Version 2.1.12

-
-

-Released 06/24/2007 -
-GUI and compilers v2.1.12 require API library libfwbuilder version 2.1.12 -
-

Summary

-

-This release comes with support for Cisco IOS access lists and ability -to import existing iptables and IOS access lists -configurations. Multiple bug fixes are included as well. - -

-For those who wish to build from source, instructions are outlined -in the document "Install and Build instructions" on our web site here - -

Support for Cisco IOS access lists

- -Policy compiler for Cisco IOS Access lists has been implemented as -part of the Firewall Builder GUI as of version 2.1.12. The first -functional build were importer worked on all supported OS was build -270 (May 22, 2007) -

- - Features implemented in this version: -

-

    - -
  • The compiler generates extended ACLs using "ip access-list - extended" command. ACL names are automatically generated using - abbreviated interface names and direction symbols to make it easy - to figure out which ACL is which. Compiler uses rather minimal set - of options of the "ip access-list" command and should generate code - that will work for IOS 12.x. I did not test with 11.x but I am - pretty sure it will work, at least with the latest versions of - 11.x. - -
  • Compiler can also add commands to configure logging. - -
  • The GUI includes built-in installer for routers which works just - like installer for PIX. Both installers were updated however to - improve support for the automatic roll-back feature in case you - lose connect with the firewall or the router because of an error in - the policy. Now you can make installer schedule reboot in a few - minutes, then upload new policy or ACLs and then cancel reboot if - upload was successful. While before auto-rollback option was only - available if you installed in the test mode, now you can always use - it. Test mode means that installer does not save configuration in - the permanent memory, as before. - -
  • All three installation methods that were available for PIX are now - available for routers: you can make it clear all access lists and - then load new ones or just update access lists without - clearing. The last method (the "safety net" method) creates - temporary acl to permit communication with the management station, - assigns it to the interface marked as management interface, then - clears all access lists and loads new ones and in the end swaps - proper list on the management interface. This helps prevent - locking yourself out of the router in the middle of the - installation process in case of an error in the ACL and at the same - time does not leave the router with no acls for the time it takes - to install new policy. In combination with automatic roll-back, - installation process is pretty reliable. - -
  • New option has been added to the interface object, called - "unprotected". This allows you to mark some interfaces to be - skipped by the compiler when it picks interfaces for ACL - rules. This should be useful when you have routers with many - interfaces and only want to add ACLs to some of them. Also, you can - explicitly put interface objects into policy rules and specify - direction if you want to do this manually. - -
  • Since router ACLs have no state, all rules should be created in the - policy pretty much like you do it on the router, including rules - that permit reply packets. New option has been added to the TCP - Service object, called "established". This makes compiler use - option "established" in rules it generates if it is supported by - the firewall platform. Compilers for iptables, ipfilter, pf and PIX - can not use objects with this option and treat it as an error - because corresponding platforms do not support it. IPFW, on the - other hand, supports it so compiler fwb_ipfw can use it. - -
-

- - Shortcomings of this version: -

-

    -
  • "tos", "precedence" and "time-range" options are not supported -
  • "igmp" access lists can no be generated -
-

- - -

Policy import iptables configurations (v2.1.12, build 281 and later)

-

-Policy importer has been implemented as part of the Firewall Builder -GUI as of version 2.1.12. The first functional build were importer -worked on all supported OS was build 270 (May 22, 2007) -

-Policy importer uses ANTLR lexer and parser ( http://www.antlr.org/ ) -Version 2.7.7 is used in Firewall Builder v2.1.12 ( http://www.antlr2.org/ ) -

-Firewall Builder needs ANTLR C++ runtime header files and library and -include these in the source tree under src/antlr. Unless you want to -change the grammar (*.g files) you don't need to install ANTLR -separately. All relevant ANTLR files are included in the package. For -more information on ANTRL see: http://www.antlr2.org -

- Features implemented in this version : - -

    -
  • Importer can parse iptables config saved using iptables-save - utility. Because of the huge variety of iptables modules, Importer - can only interpret basic iptables configuration and a subset of - modules. Currently the following modules are supported: -

    -

      -
    • state -
    • multiport -
    • limit -
    • mark -
    -

    -
  • Importer creates firewall object with all interfaces. It can not - assign object name for the firewall object nor add IP and MAC - addresses to interfaces because this information is not present in - iptables-save file. - -
  • option "Assume firewall is part of 'any'" is off in the created - firewall object. Import is done this way in order to preserve logic - of chains INPUT, OUTPUT and FORWARD in the recreated fwbuilder - rules. Rules that had chain INPUT in the imported script will have - firewall object in "destination" in the corresponding fwbuilder - rules. Firewall object is placed in "Source" for rules with chain - OUTPUT. For rules with chain FORWARD rule elements "Source" and - "Destination" are populated with objects created using options "-s" - and "-d" of the original rules or left empty ("any"). - -
  • all recognized iptables rules are imported and interface and - direction are set in all rules appropriately. Interface objects are - created as parser finds them in the script. - -
  • targets ACCEPT, DROP, REJECT, MARK and others are converted to the - corresponding fwbuilder policy rule actions. Unrecognized targets - and converted to branching rules, where the name of the target - becomes the name of the branch. - -
  • SNAT, DNAT, MASQUERADING, REDIRECT and NETMAP targets and their - parameters are recognized in the NAT rules. - -
  • Address and service objects are created in the process for all - addresses and ports used in all rules. - -
  • iptables rules can refer to tcp/udp ports both by name or by - number. Importer can properly interpret both formats using system - function getservbyname() to convert service name to the port - number. Since the result of this function depends on the OS, some - port names may not convert on some systems. For example, Windows - can convert more limited set of service names compared to Linux or - BSD. - -
  • targets LOG and ULOG are converted to the "logging" option in - fwbuilder rules with action "Continue". This is an empty action - that does not affect packet flow through the firewall but can be - used in combination with "logging" option to log the packet. If - such empty (logging-only) rule is undesired, it must be manually - merged with some other rule in the policy. - -
  • "--log-prefix", and "--log-level" options of the LOG target are - recognized - -
  • "--ulog-prefix" option of the ULOG target is recognized. Other - options of the ULOG target are not. - -
  • Address and service objects are reused in the process of import. - -
  • in case when importer fails to parse some part of the iptables-save - file, corresponding policy rule is colored red and appropriate - diagnostic message added to its comment. The problem must be - corrected manually. - -
  • comments ("#") found inside access lists are ignored. -
- -Shortcomings of this version: - -
    -
  • user-defined chains in table "nat" are not supported -
  • no import of time intervals -
  • no MAC address matching import -
- -

- - -

Policy import of Cisco IOS access lists (v2.1.12, build 270)

-

- - Features implemented in this version : - -

    -
  • Importer can parse router config saved using "show run" - command. Although importer can only interpret a subset of IOS - configuration commands, other commands that it does not understand - will be ignored and should not affect operation. No manual editing - of the config is required prior to import. - -
  • Importer creates firewall object with all interfaces - -
  • firewall object name is assigned if "hostname" command is found in - the configuration. If this command is not present, the name remains - generic "New Firewall" - -
  • interface addresses are assigned if command "ip address" is found - (multiple addresses per interface are supported). Interfaces - without "ip address" in the configuration are marked as - "unnumbered" in the firewall builder object tree. - -
  • all access lists are imported and interface and direction are set - in all rules appropriately - -
  • Address and service objects are created in the process for all - addresses and ports used in access lists - -
  • IOS access lists can define ip protocol, icmp code and type, and - tcp/udp ports both by name or by number. Importer can properly - interpret both formats. - -
  • "log", "log-input", "fragments", "established" keywords are - supported and translated into rule or object options as - appropriate. - -
  • Address and service objects are reused in the process of import. - -
  • in case when importer fails to parse some part of the access-list - command, corresponding policy rule is colored in red and - appropriate diagnostic message added to its comment. The problem - must be corrected manually. - -
  • "remark" commands found inside access lists are translated into - rule comments - -
  • comments ("!") found inside access lists are ignored. -
-

- - Shortcomings of this version: - -

    -
  • importer does not use address and service objects that existed in - the tree before the operation has started, it creates new - ones. Deduplication only works for objects created in the process - of import. - -
  • the following keywords available in extended access lists are not - supported at this time: tos, precedence, time-range. - -
  • igmp access lists are not parsed. -
- -

-


-

- -

New object types and improvements in the base API

- -
    - -
  • TCPService object now has flag "established". Policy comilers - for platforms that have special keyword for this flag can recognize - this flag in TCPService object.
  • - -
  • TCPService object "All TCP established" has been added to the - Standard objects library.
  • - -
  • Interface of the firewall has new flag "unprotected", currently - only used in compiler for Cisco IOS access lists. Compiler skips - interfaces marked as "unprotected" when it decides which interface a - policy rule should be assigned to. -
- - -

Improvements and bug fixes in the GUI

-
    - -
  • dialogs and resource files for Cisco IOS access lists.
  • - -
  • Policy installer for Cisco routers
  • - -
  • fixed long-standing problem with size of the built-in installer - options dialog. The dialog was too big and did not properly resize - itself when some options were hidden.
  • - -
  • PIX and Cisco routers (IOS) : built-in installer can schedule - reboot of the firewall before activating new policy, then cancel - it if the policy has been activated successfully.
  • - -
  • note about built-in installer on windows. Installer seems to - have broke with upgrade of QT to 3.3.8. Specifically, in - SSHSession::readFromStdout(), proc->readStdout() returns a byte - array that contains actual output from the device, with some - garbage appeneded to it. The garbage is included in the size() - count of QByteArray returned by readStdout so it gets included - into the QString which we append to stdoutBuffer. This happens - only on win32; reverting to QT 3.3.7 fixes the problem.
  • - -
  • the GUI is compiled with ANTLR C++ run-time, used for policy - importer
  • - -
  • Policy importer: can read and import iptables rules from the - iptables-save file and Cisco IOS access lists from the router - configuration saved using "show run" command. See - README.policy_import file for more details.
  • - -
  • allow for object group in "Interface" rule element
  • - -
  • Added support for action "Continue" (an empty action) in the GUI - and compiler for iptables. This action creates a rule that does - nothing, however it generates iptables command with target "-j - LOG" if logging is turned on. This can be useful if one wants only - to log packets that match certain pattern but not make any policy - decision in the same rule.
  • - -
  • After changes made in the compiler to simplify algorithm used to - decide which chain a rule with action Tag should go to, rule - action option "Mark connections in PREROUTING chain" ( - "ipt_mark_prerouting" ) has been deprecated.
  • - -
  • fixed bug (no number) where installer failed to properly copy - .fwb file over to the firewall if file name contained - whitespace
  • - -
  • fixed bug #1739373: "FWB2111, register Routing not printed". Tab - "Routing" was not included in the printed copy of firewall - policies
  • -
- -

Improvements and bug fixes in policy compiler for iptables

-
    - -
  • fixed bug 1737733: "install script doesn't detect BROADCAST if - eth is NO-CARRIER". If firewall script runs before network - interface comes up (i.e. is still in NO-CARRIER state), script - failed to add virtual addresses for NAT.
  • - -
  • fixed bug #1711595: "ip6tables DROPs". Compiler adds rules to - permit any-to-any on loopback interface for ipv6 in addition to - rules that set default policy to DROP for all chains in ipv6
  • - -
  • streamlined algorithm that assigns chain to a rule with action - Tag. The goal is to always use chain PREROUTING for rules with - direction Inbound or Both and a combination of OUTPUT and - POSTROUTING for rules with direction Outbound and Both.
  • - -
  • Added support for action "Continue" (an empty action) in the GUI - and compiler for iptables. This action creates a rule that does - nothing, however it generates iptables command with target "-j - LOG" if logging is turned on. This can be useful if one wants only - to log packets that match certain pattern but not make any policy - decision in the same rule.
  • - -
  • fixed bug #1718791: "Bug with more than one router". This bug - affected routing rules.
  • - -
  • fixed bug #1720022: "Fail to load modules .ko.gz".
  • - -
  • fixed bug #1720480: '"-A POSTROUTING -i interface" in branching - rules'. Compiler should not generate iptables commands in - POSTROUTING chain with "-i interface" clause.
  • - -
  • bug (no number): compiler used to not set unique internal id for - rules in branches, which lead to chain names like 'C.0' in - generated script.
  • - -
  • bug (no number): when a rule number is inserted into a log - record in place of macro %N, it should be formatted as "N/M" for - rules in a branch.
  • - -
  • bug (no number): setting chain for Classify action only if it - has not been set before. Setting chain to POSTROUTING always broke - things if a rule with action 'Classify' was used in a branch (so - the chain has been set to that of the branch)
  • - -
  • bugs #1676635: "no way to match on state if the action is drop" - and #1671910: "2.1.8 In 'Branch' acton compiler doesn't insert NEW - stanza". Rely only on rule option 'stateless' to decide whether - the rule should have "-m state --state NEW". Rule option - 'stateless' is automatically set when user changes rule action so - it becomes anything except 'Accept', 'Tag' or 'Route'. This option - is also automatically cleared when action is switched to any of - these three actions. The user can override these default settings - by checking or unchecking the option in the rule options dialog. - -
  • - -
- - -

Improvements and bug fixes in policy compiler for PF

-
    -
  • fixed bug #1727715: "Policy Installer failed but indicates - succes". Activation script for PF exits with non-zero return code - if script activation fails.
  • - -
  • fixed bug #1740545: "AddressTable in NAT section". Policy - compiler for PF crashed if AddressTable object was used in TDst - element of a NAT rule.
  • - -
- - -

Improvements and bug fixes in policy compiler for ipfw

-
    -
  • new TCPService object flag "established" in compiler for - ipfw.
  • - -
  • - -
- - - - - diff --git a/doc/ReleaseNotes_2.1.12.txt b/doc/ReleaseNotes_2.1.12.txt deleted file mode 100644 index ffb8dad33..000000000 --- a/doc/ReleaseNotes_2.1.12.txt +++ /dev/null @@ -1,311 +0,0 @@ - Firewall Builder Release Notes - -Version 2.1.12 - - Released 06/24/2007 - GUI and compilers v2.1.12 require API library libfwbuilder version 2.1.12 - -Summary - - This release comes with support for Cisco IOS access lists and ability to - import existing iptables and IOS access lists configurations. Multiple bug - fixes are included as well. - - For those who wish to build from source, instructions are outlined in the - document "Install and Build instructions" on our web site here - -Support for Cisco IOS access lists - - Policy compiler for Cisco IOS Access lists has been implemented as part of - the Firewall Builder GUI as of version 2.1.12. The first functional build - were importer worked on all supported OS was build 270 (May 22, 2007) - - Features implemented in this version: - - * The compiler generates extended ACLs using "ip access-list extended" - command. ACL names are automatically generated using abbreviated - interface names and direction symbols to make it easy to figure out - which ACL is which. Compiler uses rather minimal set of options of the - "ip access-list" command and should generate code that will work for - IOS 12.x. I did not test with 11.x but I am pretty sure it will work, - at least with the latest versions of 11.x. - * Compiler can also add commands to configure logging. - * The GUI includes built-in installer for routers which works just like - installer for PIX. Both installers were updated however to improve - support for the automatic roll-back feature in case you lose connect - with the firewall or the router because of an error in the policy. Now - you can make installer schedule reboot in a few minutes, then upload - new policy or ACLs and then cancel reboot if upload was successful. - While before auto-rollback option was only available if you installed - in the test mode, now you can always use it. Test mode means that - installer does not save configuration in the permanent memory, as - before. - * All three installation methods that were available for PIX are now - available for routers: you can make it clear all access lists and then - load new ones or just update access lists without clearing. The last - method (the "safety net" method) creates temporary acl to permit - communication with the management station, assigns it to the interface - marked as management interface, then clears all access lists and loads - new ones and in the end swaps proper list on the management interface. - This helps prevent locking yourself out of the router in the middle of - the installation process in case of an error in the ACL and at the - same time does not leave the router with no acls for the time it takes - to install new policy. In combination with automatic roll-back, - installation process is pretty reliable. - * New option has been added to the interface object, called - "unprotected". This allows you to mark some interfaces to be skipped - by the compiler when it picks interfaces for ACL rules. This should be - useful when you have routers with many interfaces and only want to add - ACLs to some of them. Also, you can explicitly put interface objects - into policy rules and specify direction if you want to do this - manually. - * Since router ACLs have no state, all rules should be created in the - policy pretty much like you do it on the router, including rules that - permit reply packets. New option has been added to the TCP Service - object, called "established". This makes compiler use option - "established" in rules it generates if it is supported by the firewall - platform. Compilers for iptables, ipfilter, pf and PIX can not use - objects with this option and treat it as an error because - corresponding platforms do not support it. IPFW, on the other hand, - supports it so compiler fwb_ipfw can use it. - - Shortcomings of this version: - - * "tos", "precedence" and "time-range" options are not supported - * "igmp" access lists can no be generated - -Policy import iptables configurations (v2.1.12, build 281 and later) - - Policy importer has been implemented as part of the Firewall Builder GUI - as of version 2.1.12. The first functional build were importer worked on - all supported OS was build 270 (May 22, 2007) - - Policy importer uses ANTLR lexer and parser ( http://www.antlr.org/ ) - Version 2.7.7 is used in Firewall Builder v2.1.12 ( http://www.antlr2.org/ - ) - - Firewall Builder needs ANTLR C++ runtime header files and library and - include these in the source tree under src/antlr. Unless you want to - change the grammar (*.g files) you don't need to install ANTLR separately. - All relevant ANTLR files are included in the package. For more information - on ANTRL see: http://www.antlr2.org - - Features implemented in this version : - - * Importer can parse iptables config saved using iptables-save utility. - Because of the huge variety of iptables modules, Importer can only - interpret basic iptables configuration and a subset of modules. - Currently the following modules are supported: - - * state - * multiport - * limit - * mark - - * Importer creates firewall object with all interfaces. It can not - assign object name for the firewall object nor add IP and MAC - addresses to interfaces because this information is not present in - iptables-save file. - * option "Assume firewall is part of 'any'" is off in the created - firewall object. Import is done this way in order to preserve logic of - chains INPUT, OUTPUT and FORWARD in the recreated fwbuilder rules. - Rules that had chain INPUT in the imported script will have firewall - object in "destination" in the corresponding fwbuilder rules. Firewall - object is placed in "Source" for rules with chain OUTPUT. For rules - with chain FORWARD rule elements "Source" and "Destination" are - populated with objects created using options "-s" and "-d" of the - original rules or left empty ("any"). - * all recognized iptables rules are imported and interface and direction - are set in all rules appropriately. Interface objects are created as - parser finds them in the script. - * targets ACCEPT, DROP, REJECT, MARK and others are converted to the - corresponding fwbuilder policy rule actions. Unrecognized targets and - converted to branching rules, where the name of the target becomes the - name of the branch. - * SNAT, DNAT, MASQUERADING, REDIRECT and NETMAP targets and their - parameters are recognized in the NAT rules. - * Address and service objects are created in the process for all - addresses and ports used in all rules. - * iptables rules can refer to tcp/udp ports both by name or by number. - Importer can properly interpret both formats using system function - getservbyname() to convert service name to the port number. Since the - result of this function depends on the OS, some port names may not - convert on some systems. For example, Windows can convert more limited - set of service names compared to Linux or BSD. - * targets LOG and ULOG are converted to the "logging" option in - fwbuilder rules with action "Continue". This is an empty action that - does not affect packet flow through the firewall but can be used in - combination with "logging" option to log the packet. If such empty - (logging-only) rule is undesired, it must be manually merged with some - other rule in the policy. - * "--log-prefix", and "--log-level" options of the LOG target are - recognized - * "--ulog-prefix" option of the ULOG target is recognized. Other options - of the ULOG target are not. - * Address and service objects are reused in the process of import. - * in case when importer fails to parse some part of the iptables-save - file, corresponding policy rule is colored red and appropriate - diagnostic message added to its comment. The problem must be corrected - manually. - * comments ("#") found inside access lists are ignored. - - Shortcomings of this version: - - * user-defined chains in table "nat" are not supported - * no import of time intervals - * no MAC address matching import - -Policy import of Cisco IOS access lists (v2.1.12, build 270) - - Features implemented in this version : - - * Importer can parse router config saved using "show run" command. - Although importer can only interpret a subset of IOS configuration - commands, other commands that it does not understand will be ignored - and should not affect operation. No manual editing of the config is - required prior to import. - * Importer creates firewall object with all interfaces - * firewall object name is assigned if "hostname" command is found in the - configuration. If this command is not present, the name remains - generic "New Firewall" - * interface addresses are assigned if command "ip address" is found - (multiple addresses per interface are supported). Interfaces without - "ip address" in the configuration are marked as "unnumbered" in the - firewall builder object tree. - * all access lists are imported and interface and direction are set in - all rules appropriately - * Address and service objects are created in the process for all - addresses and ports used in access lists - * IOS access lists can define ip protocol, icmp code and type, and - tcp/udp ports both by name or by number. Importer can properly - interpret both formats. - * "log", "log-input", "fragments", "established" keywords are supported - and translated into rule or object options as appropriate. - * Address and service objects are reused in the process of import. - * in case when importer fails to parse some part of the access-list - command, corresponding policy rule is colored in red and appropriate - diagnostic message added to its comment. The problem must be corrected - manually. - * "remark" commands found inside access lists are translated into rule - comments - * comments ("!") found inside access lists are ignored. - - Shortcomings of this version: - - * importer does not use address and service objects that existed in the - tree before the operation has started, it creates new ones. - Deduplication only works for objects created in the process of import. - * the following keywords available in extended access lists are not - supported at this time: tos, precedence, time-range. - * igmp access lists are not parsed. - - ---------------------------------------------------------------------- - -New object types and improvements in the base API - - * TCPService object now has flag "established". Policy comilers for - platforms that have special keyword for this flag can recognize this - flag in TCPService object. - * TCPService object "All TCP established" has been added to the Standard - objects library. - * Interface of the firewall has new flag "unprotected", currently only - used in compiler for Cisco IOS access lists. Compiler skips interfaces - marked as "unprotected" when it decides which interface a policy rule - should be assigned to. - -Improvements and bug fixes in the GUI - - * dialogs and resource files for Cisco IOS access lists. - * Policy installer for Cisco routers - * fixed long-standing problem with size of the built-in installer - options dialog. The dialog was too big and did not properly resize - itself when some options were hidden. - * PIX and Cisco routers (IOS) : built-in installer can schedule reboot - of the firewall before activating new policy, then cancel it if the - policy has been activated successfully. - * note about built-in installer on windows. Installer seems to have - broke with upgrade of QT to 3.3.8. Specifically, in - SSHSession::readFromStdout(), proc->readStdout() returns a byte array - that contains actual output from the device, with some garbage - appeneded to it. The garbage is included in the size() count of - QByteArray returned by readStdout so it gets included into the QString - which we append to stdoutBuffer. This happens only on win32; reverting - to QT 3.3.7 fixes the problem. - * the GUI is compiled with ANTLR C++ run-time, used for policy importer - * Policy importer: can read and import iptables rules from the - iptables-save file and Cisco IOS access lists from the router - configuration saved using "show run" command. See README.policy_import - file for more details. - * allow for object group in "Interface" rule element - * Added support for action "Continue" (an empty action) in the GUI and - compiler for iptables. This action creates a rule that does nothing, - however it generates iptables command with target "-j LOG" if logging - is turned on. This can be useful if one wants only to log packets that - match certain pattern but not make any policy decision in the same - rule. - * After changes made in the compiler to simplify algorithm used to - decide which chain a rule with action Tag should go to, rule action - option "Mark connections in PREROUTING chain" ( "ipt_mark_prerouting" - ) has been deprecated. - * fixed bug (no number) where installer failed to properly copy .fwb - file over to the firewall if file name contained whitespace - * fixed bug #1739373: "FWB2111, register Routing not printed". Tab - "Routing" was not included in the printed copy of firewall policies - -Improvements and bug fixes in policy compiler for iptables - - * fixed bug 1737733: "install script doesn't detect BROADCAST if eth is - NO-CARRIER". If firewall script runs before network interface comes up - (i.e. is still in NO-CARRIER state), script failed to add virtual - addresses for NAT. - * fixed bug #1711595: "ip6tables DROPs". Compiler adds rules to permit - any-to-any on loopback interface for ipv6 in addition to rules that - set default policy to DROP for all chains in ipv6 - * streamlined algorithm that assigns chain to a rule with action Tag. - The goal is to always use chain PREROUTING for rules with direction - Inbound or Both and a combination of OUTPUT and POSTROUTING for rules - with direction Outbound and Both. - * Added support for action "Continue" (an empty action) in the GUI and - compiler for iptables. This action creates a rule that does nothing, - however it generates iptables command with target "-j LOG" if logging - is turned on. This can be useful if one wants only to log packets that - match certain pattern but not make any policy decision in the same - rule. - * fixed bug #1718791: "Bug with more than one router". This bug affected - routing rules. - * fixed bug #1720022: "Fail to load modules .ko.gz". - * fixed bug #1720480: '"-A POSTROUTING -i interface" in branching - rules'. Compiler should not generate iptables commands in POSTROUTING - chain with "-i interface" clause. - * bug (no number): compiler used to not set unique internal id for rules - in branches, which lead to chain names like 'C.0' in generated script. - * bug (no number): when a rule number is inserted into a log record in - place of macro %N, it should be formatted as "N/M" for rules in a - branch. - * bug (no number): setting chain for Classify action only if it has not - been set before. Setting chain to POSTROUTING always broke things if a - rule with action 'Classify' was used in a branch (so the chain has - been set to that of the branch) - * bugs #1676635: "no way to match on state if the action is drop" and - #1671910: "2.1.8 In 'Branch' acton compiler doesn't insert NEW - stanza". Rely only on rule option 'stateless' to decide whether the - rule should have "-m state --state NEW". Rule option 'stateless' is - automatically set when user changes rule action so it becomes anything - except 'Accept', 'Tag' or 'Route'. This option is also automatically - cleared when action is switched to any of these three actions. The - user can override these default settings by checking or unchecking the - option in the rule options dialog. - -Improvements and bug fixes in policy compiler for PF - - * fixed bug #1727715: "Policy Installer failed but indicates succes". - Activation script for PF exits with non-zero return code if script - activation fails. - * fixed bug #1740545: "AddressTable in NAT section". Policy compiler for - PF crashed if AddressTable object was used in TDst element of a NAT - rule. - -Improvements and bug fixes in policy compiler for ipfw - - * new TCPService object flag "established" in compiler for ipfw. - * diff --git a/doc/ReleaseNotes_2.1.13.html b/doc/ReleaseNotes_2.1.13.html deleted file mode 100644 index f51f681c9..000000000 --- a/doc/ReleaseNotes_2.1.13.html +++ /dev/null @@ -1,106 +0,0 @@ - - - - - - - -

Firewall Builder Release Notes

-
-

Version 2.1.13

-
-

-Released 07/22/2007 -
-GUI and compilers v2.1.13 require API library libfwbuilder version 2.1.13 -
-

Summary

-

-This is bugfix release; its main focus is better support for new -features available in PF in OpenBSD 4.1. - -

-For those who wish to build from source, instructions are outlined -in the document "Install and Build instructions" on our web site here - - - -

Improvements and bug fixes in the GUI

-
    - -
  • fixed bug #1740766: "lock not saved". This method now copies the - value of "ro" attribute (read-only). Clear it in the caller if - neccessary. Method duplicate() clears it after calling - shallowDuplicate in order to be able to modify the object, then - restores this attribute to its original value.
  • - -
  • fixed bug #1743117: "crash while editing any". Added check, user - should not be able to unlock Standard objects library
  • - -
  • fixed bug #1753188: "policy activation fails on PIX and - IOS". Installer failed if account used to authenticate to the - router or PIX went straight to 'enable' mode after login.
  • - -
  • added simple template object for Cisco router 36xx
  • -
- -

Improvements and bug fixes in policy compiler for iptables

-
    - -
  • fixed bug #1746257: "fwbuilder breaks IPv6". Added an option to - the firewall settings dialog for iptables that controls whether - compiler should skip generation of the code to set default policy - of all ipv6 chains to DROP. This option is off by default, that is - compiler puts the code in. This helps maintain backwards - compatibility with old data files that do not have this option, - which is equivalent to this option being "off".
  • - -
  • fixed bug #1747332: "missing CONNMARK/ restore mark in Output - Chain"
  • - -
  • compiler permits setting direction in the rule while interface - field is "All". This generates iptables command in chain INPUT or - OUTPUT with "-i +" or "-o +" interface specification to match all - interfaces.
  • - -
- - -

Improvements and bug fixes in policy compiler for PF

-
    -
  • fixed bug #1747828: "anchors generation - "log" not - supported". "Log" keyword is not allowed in "anchor" rules; - compiler should not generate it even if user turned logging on in - a rule with action 'Branch'
  • - -
  • implemented support for PF limit options "src-nodes", "tables" - and "table-entries". Feature Req. #1674919: "Support "set limit - table-entries""
  • - -
  • better compliance with PF 4.x. Feature Req. #1679793: "add 'no - state' and 'flags any'". If version is set to 4.x, compiler skips - "flags S/SA keep state" for rules mathcing tcp services. However, - according to the section "1.2. Operational changes" in PF FAQ at - http://www.openbsd.org/faq/upgrade41.html , there should be a way - to add "keep state" explicitly for rules on interface enc0. Added - this option to the rule options dialog.
  • - -
  • Added support for "set skip on " command for PF. If an - interface is marked as "unprotected" in the GUI, compiler - generates this command for it. This is useful for loopback or - other virtual interfaces. - - -
- -

Improvements and bug fixes in policy compilers for Cisco IOS ACL

-
    -
  • Fixed bug that caused compiler to exit abnormally while - compiling a rule with interface field "all". Compiler should - generate ACL lines for all interfaces of the router (except those - marked "unprotected")
  • -
- - - diff --git a/doc/ReleaseNotes_2.1.13.txt b/doc/ReleaseNotes_2.1.13.txt deleted file mode 100644 index 021c8d8c3..000000000 --- a/doc/ReleaseNotes_2.1.13.txt +++ /dev/null @@ -1,67 +0,0 @@ - Firewall Builder Release Notes - -Version 2.1.13 - - Released 07/22/2007 - GUI and compilers v2.1.13 require API library libfwbuilder version 2.1.13 - -Summary - - This is bugfix release; its main focus is better support for new features - available in PF in OpenBSD 4.1 - - For those who wish to build from source, instructions are outlined in the - document "Install and Build instructions" on our web site here - -Improvements and bug fixes in the GUI - - * fixed bug #1740766: "lock not saved". This method now copies the value - of "ro" attribute (read-only). Clear it in the caller if neccessary. - Method duplicate() clears it after calling shallowDuplicate in order - to be able to modify the object, then restores this attribute to its - original value. - * fixed bug #1743117: "crash while editing any". Added check, user - should not be able to unlock Standard objects library - * fixed bug #1753188: "policy activation fails on PIX and IOS". - Installer failed if account used to authenticate to the router or PIX - went straight to 'enable' mode after login. - * added simple template object for Cisco router 36xx - -Improvements and bug fixes in policy compiler for iptables - - * fixed bug #1746257: "fwbuilder breaks IPv6". Added an option to the - firewall settings dialog for iptables that controls whether compiler - should skip generation of the code to set default policy of all ipv6 - chains to DROP. This option is off by default, that is compiler puts - the code in. This helps maintain backwards compatibility with old data - files that do not have this option, which is equivalent to this option - being "off". - * fixed bug #1747332: "missing CONNMARK/ restore mark in Output Chain" - * compiler permits setting direction in the rule while interface field - is "All". This generates iptables command in chain INPUT or OUTPUT - with "-i +" or "-o +" interface specification to match all interfaces. - -Improvements and bug fixes in policy compiler for PF - - * fixed bug #1747828: "anchors generation - "log" not supported". "Log" - keyword is not allowed in "anchor" rules; compiler should not generate - it even if user turned logging on in a rule with action 'Branch' - * implemented support for PF limit options "src-nodes", "tables" and - "table-entries". Feature Req. #1674919: "Support "set limit - table-entries"" - * better compliance with PF 4.x. Feature Req. #1679793: "add 'no state' - and 'flags any'". If version is set to 4.x, compiler skips "flags S/SA - keep state" for rules mathcing tcp services. However, according to the - section "1.2. Operational changes" in PF FAQ at - http://www.openbsd.org/faq/upgrade41.html , there should be a way to - add "keep state" explicitly for rules on interface enc0. Added this - option to the rule options dialog. - * Added support for "set skip on " command for PF. If an interface is - marked as "unprotected" in the GUI, compiler generates this command - for it. This is useful for loopback or other virtual interfaces. - -Improvements and bug fixes in policy compilers for Cisco IOS ACL - - * Fixed bug that caused compiler to exit abnormally while compiling a - rule with interface field "all". Compiler should generate ACL lines - for all interfaces of the router (except those marked "unprotected") diff --git a/doc/ReleaseNotes_2.1.14.html b/doc/ReleaseNotes_2.1.14.html deleted file mode 100644 index 59766969b..000000000 --- a/doc/ReleaseNotes_2.1.14.html +++ /dev/null @@ -1,106 +0,0 @@ - - - - - - - -

Firewall Builder Release Notes

-
-

Version 2.1.14

-
-

-Released 09/10/2007 -
-GUI and compilers v2.1.14 require API library libfwbuilder version 2.1.14 -
-

Summary

-

-This is another bugfix release, it comes with numerous improvements in -the iptables policy importer and fixes for gcc 4.2 and 4.3 - -

-For those who wish to build from source, instructions are outlined -in the document "Install and Build instructions" on our web site here - - - -

Improvements and bug fixes in libfwbuilder library

-
    - -
  • fixed bug #1761373: "libfwbuilder doesn't build on Mandriva - cooker". Applied fixes to make the code compile with gcc 4.2
  • - -
- -

Improvements and bug fixes in the policy importer for iptables

-
    -
  • fixed bug #1764988: "iptables import -> GUI crash": -

    -

      - -
    • iptables policy importer recognizes and parses target - RETURN
    • - -
    • iptables policy importer recognizes and parses TCP flag - parameters ALL and NONE
    • - -
    • syntax for TCP flag matching in iptables-save should allow - for more than 2 flags in 'comp' part
    • - -
    -

    -

  • - -
  • fixed bug (no num): iptables policy importer should properly - parse numeric protocol specification (e.g. "-p 47").
  • - -
  • added missing supprot for "--log-tcp-sequence", -"--log-tcp-options" and "--log-ip-options" options for target LOG to - iptables policy importer
  • - -
  • added a workaround for a situation when several iptables - commands pass control to the same user-define chain in the - iptables-save file. As of fwbuilder v2.1, branch ruleset is a - child object of PolicyRule. This means two different rules can not - point at the same branch ruleset. This is unfortunate but it is - hard to fix in the current version because it requires changes XML - DTD and API. Will do this in 3.0. Meanwhile, checking if branch - ruleset with requested name already exists and change the name by - adding suffix '1', '2' etc to make it different. Imported rule is - marked as 'bad' (red background) and gets a comment explaining - this.
  • - -
  • fixed bug (no num): importer for iptables should properly assign - rule options when it finds "-m limit" and "--limit" options in the - input file.
  • - -
- -

Improvements and bug fixes in the GUI

-
    -
  • configure.in: another patch by Carlos Silva - <r3pek@r3pek.org> to add third parameter to - AC_DEFINE_UNQUOTED - -
  • fixed bug reported in Debian Bug report #417685 - added missing - #include to make code compile with gcc 4.3
  • - -
  • applied patch by Carlos Silva <r3pek@r3pek.org> to make - configure.in use ANTLR C++ run-time installed on the system if - it can find one; otherwise it uses copy in src/antlr
  • - -
  • fixed bug #1772722: "installer should recognize when it uses - plink 0.60". We detect when installer uses plink on Windows by - checking the name of the configured ssh client. The check should - be case-insensitive.
  • - -
  • fixed bug #1764971: "allowed value range for burst - limit". Iptables "--limit-burst" option should not be limited in - the GUI.
  • - -
- - - diff --git a/doc/ReleaseNotes_2.1.14.txt b/doc/ReleaseNotes_2.1.14.txt deleted file mode 100644 index 81c3a9218..000000000 --- a/doc/ReleaseNotes_2.1.14.txt +++ /dev/null @@ -1,64 +0,0 @@ - Firewall Builder Release Notes - -Version 2.1.14 - - Released 09/10/2007 - GUI and compilers v2.1.14 require API library libfwbuilder version 2.1.14 - -Summary - - This is another bugfix release, it comes with numerous improvements in the - iptables policy importer and fixes for gcc 4.2 and 4.3 - - For those who wish to build from source, instructions are outlined in the - document "Install and Build instructions" on our web site here - -Improvements and bug fixes in libfwbuilder library - - * fixed bug #1761373: "libfwbuilder doesn't build on Mandriva cooker". - Applied fixes to make the code compile with gcc 4.2 - -Improvements and bug fixes in the policy importer for iptables - - * fixed bug #1764988: "iptables import -> GUI crash": - - * iptables policy importer recognizes and parses target RETURN - * iptables policy importer recognizes and parses TCP flag - parameters ALL and NONE - * syntax for TCP flag matching in iptables-save should allow for - more than 2 flags in 'comp' part - - * fixed bug (no num): iptables policy importer should properly parse - numeric protocol specification (e.g. "-p 47"). - * added missing supprot for "--log-tcp-sequence", "--log-tcp-options" - and "--log-ip-options" options for target LOG to iptables policy - importer - * added a workaround for a situation when several iptables commands pass - control to the same user-define chain in the iptables-save file. As of - fwbuilder v2.1, branch ruleset is a child object of PolicyRule. This - means two different rules can not point at the same branch ruleset. - This is unfortunate but it is hard to fix in the current version - because it requires changes XML DTD and API. Will do this in 3.0. - Meanwhile, checking if branch ruleset with requested name already - exists and change the name by adding suffix '1', '2' etc to make it - different. Imported rule is marked as 'bad' (red background) and gets - a comment explaining this. - * fixed bug (no num): importer for iptables should properly assign rule - options when it finds "-m limit" and "--limit" options in the input - file. - -Improvements and bug fixes in the GUI - - * configure.in: another patch by Carlos Silva to add - third parameter to AC_DEFINE_UNQUOTED - * fixed bug reported in Debian Bug report #417685 - added missing - #include to make code compile with gcc 4.3 - * applied patch by Carlos Silva to make configure.in - use ANTLR C++ run-time installed on the system if it can find one; - otherwise it uses copy in src/antlr - * fixed bug #1772722: "installer should recognize when it uses plink - 0.60". We detect when installer uses plink on Windows by checking the - name of the configured ssh client. The check should be - case-insensitive. - * fixed bug #1764971: "allowed value range for burst limit". Iptables - "--limit-burst" option should not be limited in the GUI. diff --git a/doc/ReleaseNotes_2.1.15.html b/doc/ReleaseNotes_2.1.15.html deleted file mode 100644 index 278dfc13e..000000000 --- a/doc/ReleaseNotes_2.1.15.html +++ /dev/null @@ -1,88 +0,0 @@ - - - - - - - -

Firewall Builder Release Notes

-
-

Version 2.1.15

-
-

-Released 12/10/2007 -
-GUI and compilers v2.1.15 require API library libfwbuilder version 2.1.15 -
-

Summary

-

-This is another bugfix release. Several problems with policy installer -running in batch mode have been fixed, also this release resolves -compatibility issues with Windows Vista and Mac OS X Leopard. - -

-For those who wish to build from source, instructions are outlined -in the document "Install and Build instructions" on our web site here - -

-The GUI code is in the freeze for QT4 conversion. I will fix bugs in -policy compilers but will try to avoid changes in the GUI. New GUI -based on QT4 will be released next spring when KDE4 is included in all -major Linux distributions and FreeBSD. There will be one more bugfix -release for v2.1 if necessary. - - -

Improvements and bug fixes in the GUI

-
    -
  • fixed bug #1811781: "Batch Install". Built-in installer used - address of the first firewall of the batch to communicate with - all firewalls in the "batch install" mode. -
  • - -
  • fixed bug #1826558: "OSX 10.5 font problem". This problem - appeared only in Mac OS X Leoprard (10.5) build, other platforms - were unaffected.
  • - -
  • Starting with build 320 Windows packages install on Vista
  • - -
  • Added Brazilian Portuguese translation by Jose Carlos Medeiros - <jose@psabs.com.br>
  • - -
  • fixed bug #1821576: "Rule option tracking gives inavlid config - with default value". Compiler should skip max-src-nodes when it is - set to default '0' in the GUI.
  • -
- -

Improvements and bug fixes in the policy importer for iptables

-
    -
  • fixed bug #1812295: "Can't use runtime address tables AND - iptabels-restore". Script generated by fwb_ipt used "here - document" if the option "use iptables-restore to activate - policy" was turned on. This did not work in case policy used - any tun-time address table objects. Now generated script - always uses "echo" to generate iptables commands that it sends - to th standard input of iptables-restore. -
  • - -
- -

Improvements and bug fixes in the policy importer for ipfilter

-
    -
  • applied patch by to add support for - Kerberos rcmd and Kerberos ekshell proxies in ipfilter NAT rules. -
  • - -
- -

Improvements and bug fixes in the policy importer for pf

-
    -
  • fixed bug #1800875 "'keep state' missing from pass out going - traffic rule". Compilers for pf, ipf and ipfw were affected. -
  • - -
- - - - diff --git a/doc/ReleaseNotes_2.1.15.txt b/doc/ReleaseNotes_2.1.15.txt deleted file mode 100644 index 40c1a7c47..000000000 --- a/doc/ReleaseNotes_2.1.15.txt +++ /dev/null @@ -1,55 +0,0 @@ - Firewall Builder Release Notes - -Version 2.1.15 - - Released 12/10/2007 - GUI and compilers v2.1.15 require API library libfwbuilder version 2.1.15 - -Summary - - This is another bugfix release. Several problems with policy installer - running in batch mode have been fixed, also this release resolves - compatibility issues with Windows Vista and Mac OS X Leopard. - - For those who wish to build from source, instructions are outlined in the - document "Install and Build instructions" on our web site here - - The GUI code is in the freeze for QT4 conversion. I will fix bugs in - policy compilers but will try to avoid changes in the GUI. New GUI based - on QT4 will be released next spring when KDE4 is included in all major - Linux distributions and FreeBSD. There will be one more bugfix release for - v2.1 if necessary. - -Improvements and bug fixes in the GUI - - * fixed bug #1811781: "Batch Install". Built-in installer used address - of the first firewall of the batch to communicate with all firewalls - in the "batch install" mode. - * fixed bug #1826558: "OSX 10.5 font problem". This problem appeared - only in Mac OS X Leoprard (10.5) build, other platforms were - unaffected. - * Starting with build 320 Windows packages install on Vista - * Added Brazilian Portuguese translation by Jose Carlos Medeiros - - * fixed bug #1821576: "Rule option tracking gives inavlid config with - default value". Compiler should skip max-src-nodes when it is set to - default '0' in the GUI. - -Improvements and bug fixes in the policy importer for iptables - - * fixed bug #1812295: "Can't use runtime address tables AND - iptabels-restore". Script generated by fwb_ipt used "here document" if - the option "use iptables-restore to activate policy" was turned on. - This did not work in case policy used any tun-time address table - objects. Now generated script always uses "echo" to generate iptables - commands that it sends to th standard input of iptables-restore. - -Improvements and bug fixes in the policy importer for ipfilter - - * applied patch by to add support for - Kerberos rcmd and Kerberos ekshell proxies in ipfilter NAT rules. - -Improvements and bug fixes in the policy importer for pf - - * fixed bug #1800875 "'keep state' missing from pass out going traffic - rule". Compilers for pf, ipf and ipfw were affected. diff --git a/doc/ReleaseNotes_2.1.7.html b/doc/ReleaseNotes_2.1.7.html deleted file mode 100644 index 0f7dbe5cf..000000000 --- a/doc/ReleaseNotes_2.1.7.html +++ /dev/null @@ -1,487 +0,0 @@ - - - - - - - -

Firewall Builder Release Notes

-
-

Version 2.1.7

-
-

-Released 10/31/2006 -
-GUI and compilers v2.1.7 require API library libfwbuilder version 2.1.7 -
-

Summary

-

- -

-For those who wish to build from source, instructions are outlined -in the document "Install and Build instructions" on our web site here - - -

Installation

- -

- Packages of Firewall Builder 2.1 are built in a such way that you - should be able to install them on the same machine with Firewall - Builder 2.0.X. All binaries have names that end with "21", - e.g. "fwbuilder21" or "fwb_ipt21". On Windows the - binary name is the same but the package installs in - directory c:\FWBuilder21 which is different from the default - directory for Firewall Builder 2.0; all registry entries are also - located in different subtrees. All this is done to ensure the user - can run Firewall Builder 2.1 while still using stable version 2.0.12 - on the same machine. -

- -

Improvements and changes in the GUI

-
    - -
  • The GUI works much faster with very large object trees. Tested - using a data file with over 3000 objects) -

    -

    -
  • - -
  • "Where used" menu item has been added to quickly find and show - all groups and firewall rules that reference given - object. Confirmation dialog that is shown when user tries to - delete an object also shows all groups and rules that use it. -

    -

    -
  • - -
  • By popular request, built-in installer can now save a copy of - .fwb file to the firewall. -

    -

    -
  • - -
  • Compile/install dialog is now an independent window instead of a - modal dialog, this means the user can look at the policy and - objects while compilation and/or installation is going on. This is - especially convenient as it allows one to inspect the rules after - failed compilation while still having compiler error on screen. -

    -

    -
  • - - -
  • Network discovery driud is back, ported from fwbuilder - 1.0. As before, it supports reading object definitions from a - file in /etc/hosts format, can read DNS zone and also can - crawl the network using SNMP queries. -

    -

    -
  • - -
  • Startup wizard ("Welcome to Firewall Builder") has been - removed. The GUI now starts either into an empty database or - opens data file specified on the command line. -

    -

  • - -
  • Keeping track of dependencies between objects. This is - useful when many firewalls in the tree use the same set of - objects. Each firewall object keeps track of objects it - depends on, so if any object is modified, all firewalls that - use it in their rules are marked with bold font to indicate - that they need to be recompiled. Object dependencies are - tracked not only when objects are directly used in rules, - but also when they apepar there indirectly, as members of - groups -

    -

  • - -
  • Added bulk compile and install operations. This is useful - when there are many firewalls in the tree that need to be - compiled and installed in one go. Bulk install operation is - only possible if all firewalls use the same user name and - password for authentication. If this is not the case, - built-in installer can be instructed to ask for the - authentication information before it touches each firewall. -

    -

  • - -
  • All object dialogs have been converted into built-in - panels that appear in the right hand part of the main - window. This simplifies navigation ( pop-up dialogs used to - obscure parts of the main window). Objects open in the - editor on a single mouse click in the tree and rules. -

    -

  • - -
  • Improvements in "Find" function: administrator can now - drag an object into a well in the find dialog panel to make - it search for this particular object. This is useful if the - name of the obejct is not unique. Search by object's name or - a value of its attribute is also possible. -

    - -

    -

  • - -
  • In addition to the "Find" function, the "Find and replace" - operation has been implemented. Objects can be found and - replaced in groups and firewall rules -

    - -

    -

  • - -
- - -

New object types, new rule types and rule elements, new - actions and other new features

-
    -
  • AddressTable  This object resolves to a set of - IP addresses defined in an external file. The object can be - configured to read the file at compile time or at run time. For - each compile-time AddressTable object defined in the object tree - compiler tries to find and read the file specified in the object - configuration. Compiler aborts processing if the file can not be - found or can not be read. If the file is in place and can be - read, such AddressTable object behaves as if it was a group of - IP address objects, that is, all addresses are explicitly copied - into generated configuration, although compiler may use target - firewall syntax that helps to group such sets of addresses into - tables. Compilers for iptables, ipfw, ipf and PIX generate bunch - of rules matching each address read from the file. Compiler for - PF creates a table and also lists all IP addresses it reads from - the file; it uses the name of the AddressTable object for the - name of the table it creates.

    - - - Run-time AddressTable objects are only supported by - compilers for iptables and PF. Compiler for iptables - generates shell code to read the contents of the file when - firewall configuration is activated. Compiler for PF uses - native "table <name> persist file <file_name>" - syntax. Here also the name of the table is the same as the - name of the AddressTable object it was created for. -

    -

  • - -
  • DNSName:  This object resolves a host name to - the IP address using DNS. Object can be confgiured to do so at - compile time or run time. Resolution is done using system call - gethostbyaddr() to read DNS A records for the name. System - resolver should take care of recursion and CNAME records, if - any. If the name resolves to several IP addresses, all addresses - are used in the generated firewall configuration. Run-time - DNSName objects rely on the target firewall software to be able - to convert symbolic names used in rules into actual IP addresses - at a time when policy is activated. Not all platforms provide - means to support run-time DNSName objects. -

    -

  • - - -
  • TagService:  This object matches tags set by - action Tag. It is translated into --mark - <mark_code> for iptables and tag option for - PF. This service object is only supported by compilers for - iptables and PF. -

    -

  • - -
  • Interface objects can now have an attribute to mark - them as bridge ports, used for bridging firewalls. -

    -

  • - - -
  • Support for routing rules has been implemented using patch - provided by Tidei Maurizio <fwbuilder-routing at - compal.de> Support for routing rules is only implemented in - compiler for iptables. See file README.routing included in - fwbuilder2 package. -

    -

    - NOTE: I can only provide very limited support for this feature, please direct your questions and bugreports to the author -
    -

    -

  • - -
  • Global policy and interface policies have been merged. Each - policy rule now has rule element "Interface". Administrator - can drag and drop interface object of the firewall into this - rule element field. Policy compilers support multiple - interfaces and negation in "Interface" rule element. Rule - element "direction" that previously was only part of the - interface policy rules is now part of all policy rules. -

    -

  • - -
  • Policy rules can have the following new actions:

    -

      -
    • Queue:  This action passes the packet to - user space process for inspection, it is translated - into QUEUE for iptables and divert for - ipfw. This action is only supported by compilers for - iptables and ipfw.. -

      -

    • - -
    • Custom:  This action allows administrator - to define arbitrary piece of code to be used in place of - an action. Supported by compilers for iptables, ipf and - ipfw -

      -

    • - -
    • Branch:  This action is used to create a - branch in the rule set. It works on target platforms that - provide suitable syntax and allow control to return to the - higher level rule set if the branch can not make final - decision about the packet. For iptables this action is - translated into user-defined chain. The name of the chain - is the name of the branch choosen by administrator. For PF - this action is translated into an anchor with the name the - same as the name of the branch defined by the - administrator. This action is only supported by compilers - for iptables and PF. -

      -
      - Fig.1 Rule #0 of the global policy creates a branch with the name rule0_branch -

      -

      -

    • - -
    • Tag:  This action associates internal tag - with the packet. Tag can later be inspected using - service object TagService. This action is - translated into MARK target with - corresponding --set-mark parameter and optionally - additional rule with CONNMARK --save-mark target - for iptables. If option that activates CONNMARK - target is used, compiler also adds a rule at the very - top of the policy to restore the mark. Rules are placed - in INPUT,OUTPUT and FORWARD chain - of the "mangle" table, this ensures - that DNAT happens before rules placed in the - mangle table see the packet. PREROUTING chain in - mangle table is executed before PREROUTING chain - in the nat table, so placing tagging rules in the - PREROUTING chain would make them fire before - DNAT. POSTROUTING chain of the mangle - table, as well as its FORWARD and OUTPUT - chains, work before corresponding chains of the nat - table. In all cases the goal is to make sure DNAT - rules process the packet before, and SNAT rules process - it after filtering and tagging rules.

      - - For PF this action is translated into tag. - Supported only by compilers for iptables and PF. -

      -
      - Fig.2 Example of a rule utilizing action Tag. To illustrate policy branches, this rule belongs to the branch with the name rule0_branch -

      -

      -

    • - -
    • Classify:  This action allows the firewall - to define QoS class for the packet that matches the - rule. It is translated into CLASSIFY for - iptables, with parameter --set-class. For PF it - is translated into queue; compiler for ipfw can - use pipe, queue or divert depending - on how the action is configured by the administrator in - the GUI. This action is only supported by compilers for - iptables, PF and ipfw. -

      -

    • - -
    • Route:  This action makes the firewall to - route the packet that matches the rule through an - interface or a gateway specified in the parameters of the - action. This action is translated into ROUTE target - for iptables and route option for PF and - ipfilter. Compilers for PF and ipfilter - support fastroute, route-to, - reply-to and dup-to options. -

      -
      - Fig.3 Rules #0 and #1 tag packets entering the firewall through interfaces eth0 and eth2; rules #3 and #4 help route reply packets back through the same interfaces -

      -

      - -

    • -
    -

    - The GUI uses different names for the new actions depending - on the target firewall platform to simplify adoption. For - example, new action that created branch in rule set is - called Chain for iptables firewalls and Anchor - for PF fierwalls. -

    -
  • - -
  • Firewall object now has an attribute "inactive". Firewall - marked as inactive will not be picked by the GUI for the bulk - compile and install operations even if the timestamps indicate - that this firewall object needs to be recompiled -

    -

  • - -
- - -

Compiler for iptables

-
    -
  • Support for address tables loaded from external files at - compile or run time -

    -

  • - -
  • Support user defined chains with predefined names (using - special action ) -

    -

  • - -
  • Support - for CLASSIFY, MARK, CONNMARK, QUEUE, ROUTE - targets -

    -

  • - -
  • Support for physdev module for bridging firewalls -

    -

  • - -
  • additional optimization of rules i INPUT and OUTPUT chain: - now removing firewall object from src or dst to simplify rule - if it uses OUTPUT or INPUT chain. Doing this only if original - rule did not have negation and we do not add any virtual - addresses for NAT. After removal the rule collapses to a - simple command like this: -

    -

    -	iptables -A INPUT -p tcp --dport 22 -m state --state NEW -j ACCEPT
    -      
    -

    - this works fine except if we have added virtual addresses for - NAT. It is assumed that firewall object in rules represents - combination of addresses configured in its interfaces in the - GUI. Virtual addresses added for NAT are considered to be a - side effect and connections should not be implicitly permitted - to them by a rule with fw object in destination. The same - applies to fw object in source. See bug #685947 for - discussion. To avoid inadvertently opening holes in the - firewall by a rule like that, we remove fw object only when it - is safe to do so. -

    -

  • - -
  • support for modules connlimit - and hashlimit. There is an option to generate commands - for the latter module using name dstlimit because older - versions of iptables included this module under this (now - obsolete) name. -

    -

  • - -
- - -

Compiler for PF

-
    - -
  • Support for load balancing rules
  • - -
  • Support for tag and route options
  • - -
  • Support for address ranges and networ objects in TSrc in NAT - rules
  • - -
  • Support for pool types in NAT rules ('bitmask', 'random', - 'source-hash', 'round-robin'), as well as 'static-port' - option.
  • - -
  • Supprot for anchors (by way of a special action)
  • - -
  • Support for tables with predefined names (using AddressTable object)
  • - -
  • Support for packet 'tagging' (by way of a special action and service object TagService)
  • - -
- - -

Compiler for ipfilter

-
    -
  • Support for PPTP and IRC proxies
  • - -
  • Support for route option
  • - -
- -

API

-
    -
  • internal object ID is augumented with process ID of the - program that creates an object. This allows fwbedit to quickly - create objects and still ensure their IDs are unique -
  • - -
  • -
- -

fwbedit

- -

- Fwbedit can now create objects and repair broken object - database. This tool can now be used to populate object database - using shell scripts or other automation. For example, to create an - address object in object library 'Test' one could run it like - this: -

-

- -

- fwbedit -f filename.fwb -t IPv4 -n newAddress -L Test -o 192.0.2.1 -
- -
-       Firewall Builder:  general purpose object tree editing tool
-       Version 2.1.5-b
-       Usage: fwbedit21 -f filename.fwb -u [-a obj,grp] [-r obj,grp] [-d obj] [-s] [-l path] [(-p parent|-L library) -t objtype -n objname [-o object attributes]] 
-
-       -t objtype : create an object of this type
-       -L library : specify library when creating a new object
-       -p obj     : specify parent object when creating a new object
-       -n name    : specify a name of the new object
-       -o attribute1[,attribute2...]  :  specify attributes when creating a new object
-       -a obj,grp :  create reference to object 'obj' in the group 'grp'
-       -r obj,grp :  remove reference to object 'obj' from the group 'grp'
-       -d obj     :  delete object 'obj' and remove references to it from
-       all rules and groups
-       -l path    :  print list of objects for 'path'
-       -s         :  test and repair object tree structure
-       -u         : autoupgrade of file
-
-       An object and a group can be defined by their ID or 
-       by the full path and name in the XML tree
-
-       Object creation syntax:
-
-       -t Firewall -n obj_name -L User -o platform, host OS
-       -t IPv4 -n obj_name -L User -o IP address
-       -t DNSName -n obj_name -L User -o DNS record,run time
-       -t AddressRange -n obj_name -L User -o start address, end address
-       -t ObjectGroup
-       -t Network -n obj_name -L User -o address,netmask
-       -t Interval -n obj_name -L User -o start time,start date,start day,end time, end date, end day
-       -t Interface -n obj_name -L User -o security level,address type (dynamic or unnumbered),management
-       -t Host
-       -t TCPService -n obj_name -L User -o source port range start,end,Destination port range start,end,UAPRSF,UAPRSF
-       -t UDPService -n obj_name -L User -o source port range start,end,Destination port range start,end
-       -t ICMPService -n obj_name -L User -o ICMP type,ICMP code
-       -t IPService -n obj_name -L User -o protocol number,lsrr/ssrr/rr/ts/fragm/short_fragm 
-  
- - - diff --git a/doc/ReleaseNotes_2.1.7.txt b/doc/ReleaseNotes_2.1.7.txt deleted file mode 100644 index 4e4645218..000000000 --- a/doc/ReleaseNotes_2.1.7.txt +++ /dev/null @@ -1,325 +0,0 @@ - Firewall Builder Release Notes - -Version 2.1.7 - - Released 10/31/2006 - GUI and compilers v2.1.7 require API library libfwbuilder version 2.1.7 - -Summary - - For those who wish to build from source, instructions are outlined in the - document "Install and Build instructions" on our web site here - -Installation - - Packages of Firewall Builder 2.1 are built in a such way that you should - be able to install them on the same machine with Firewall Builder 2.0.X. - All binaries have names that end with "21", e.g. "fwbuilder21" or - "fwb_ipt21". On Windows the binary name is the same but the package - installs in directory c:\FWBuilder21 which is different from the default - directory for Firewall Builder 2.0; all registry entries are also located - in different subtrees. All this is done to ensure the user can run - Firewall Builder 2.1 while still using stable version 2.0.12 on the same - machine. - -Improvements and changes in the GUI - - * The GUI works much faster with very large object trees. Tested using a - data file with over 3000 objects) - - * "Where used" menu item has been added to quickly find and show all - groups and firewall rules that reference given object. Confirmation - dialog that is shown when user tries to delete an object also shows - all groups and rules that use it. - - * By popular request, built-in installer can now save a copy of .fwb - file to the firewall. - - * Compile/install dialog is now an independent window instead of a modal - dialog, this means the user can look at the policy and objects while - compilation and/or installation is going on. This is especially - convenient as it allows one to inspect the rules after failed - compilation while still having compiler error on screen. - - * Network discovery driud is back, ported from fwbuilder 1.0. As before, - it supports reading object definitions from a file in /etc/hosts - format, can read DNS zone and also can crawl the network using SNMP - queries. - - * Startup wizard ("Welcome to Firewall Builder") has been removed. The - GUI now starts either into an empty database or opens data file - specified on the command line. - - * Keeping track of dependencies between objects. This is useful when - many firewalls in the tree use the same set of objects. Each firewall - object keeps track of objects it depends on, so if any object is - modified, all firewalls that use it in their rules are marked with - bold font to indicate that they need to be recompiled. Object - dependencies are tracked not only when objects are directly used in - rules, but also when they apepar there indirectly, as members of - groups - - * Added bulk compile and install operations. This is useful when there - are many firewalls in the tree that need to be compiled and installed - in one go. Bulk install operation is only possible if all firewalls - use the same user name and password for authentication. If this is not - the case, built-in installer can be instructed to ask for the - authentication information before it touches each firewall. - - * All object dialogs have been converted into built-in panels that - appear in the right hand part of the main window. This simplifies - navigation ( pop-up dialogs used to obscure parts of the main window). - Objects open in the editor on a single mouse click in the tree and - rules. - - * Improvements in "Find" function: administrator can now drag an object - into a well in the find dialog panel to make it search for this - particular object. This is useful if the name of the obejct is not - unique. Search by object's name or a value of its attribute is also - possible. - - * In addition to the "Find" function, the "Find and replace" operation - has been implemented. Objects can be found and replaced in groups and - firewall rules - -New object types, new rule types and rule elements, new actions and other new -features - - * AddressTable This object resolves to a set of IP addresses defined in - an external file. The object can be configured to read the file at - compile time or at run time. For each compile-time AddressTable object - defined in the object tree compiler tries to find and read the file - specified in the object configuration. Compiler aborts processing if - the file can not be found or can not be read. If the file is in place - and can be read, such AddressTable object behaves as if it was a group - of IP address objects, that is, all addresses are explicitly copied - into generated configuration, although compiler may use target - firewall syntax that helps to group such sets of addresses into - tables. Compilers for iptables, ipfw, ipf and PIX generate bunch of - rules matching each address read from the file. Compiler for PF - creates a table and also lists all IP addresses it reads from the - file; it uses the name of the AddressTable object for the name of the - table it creates. - - Run-time AddressTable objects are only supported by compilers for - iptables and PF. Compiler for iptables generates shell code to read - the contents of the file when firewall configuration is activated. - Compiler for PF uses native "table persist file " - syntax. Here also the name of the table is the same as the name of the - AddressTable object it was created for. - - * DNSName: This object resolves a host name to the IP address using - DNS. Object can be confgiured to do so at compile time or run time. - Resolution is done using system call gethostbyaddr() to read DNS A - records for the name. System resolver should take care of recursion - and CNAME records, if any. If the name resolves to several IP - addresses, all addresses are used in the generated firewall - configuration. Run-time DNSName objects rely on the target firewall - software to be able to convert symbolic names used in rules into - actual IP addresses at a time when policy is activated. Not all - platforms provide means to support run-time DNSName objects. - - * TagService: This object matches tags set by action Tag. It is - translated into --mark for iptables and tag option for PF. - This service object is only supported by compilers for iptables and - PF. - - * Interface objects can now have an attribute to mark them as bridge - ports, used for bridging firewalls. - - * Support for routing rules has been implemented using patch provided by - Tidei Maurizio Support for routing - rules is only implemented in compiler for iptables. See file - README.routing included in fwbuilder2 package. - - NOTE: I can only provide very limited support for this feature, - please direct your questions and bugreports to the author - - * Global policy and interface policies have been merged. Each policy - rule now has rule element "Interface". Administrator can drag and drop - interface object of the firewall into this rule element field. Policy - compilers support multiple interfaces and negation in "Interface" rule - element. Rule element "direction" that previously was only part of the - interface policy rules is now part of all policy rules. - - * Policy rules can have the following new actions: - - * Queue: This action passes the packet to user space process for - inspection, it is translated into QUEUE for iptables and divert - for ipfw. This action is only supported by compilers for iptables - and ipfw.. - - * Custom: This action allows administrator to define arbitrary - piece of code to be used in place of an action. Supported by - compilers for iptables, ipf and ipfw - - * Branch: This action is used to create a branch in the rule set. - It works on target platforms that provide suitable syntax and - allow control to return to the higher level rule set if the - branch can not make final decision about the packet. For iptables - this action is translated into user-defined chain. The name of - the chain is the name of the branch choosen by administrator. For - PF this action is translated into an anchor with the name the - same as the name of the branch defined by the administrator. This - action is only supported by compilers for iptables and PF. - - Fig.1 Rule #0 of the global policy creates a branch with the name - rule0_branch - - * Tag: This action associates internal tag with the packet. Tag - can later be inspected using service object TagService. This - action is translated into MARK target with corresponding - --set-mark parameter and optionally additional rule with CONNMARK - --save-mark target for iptables. If option that activates - CONNMARK target is used, compiler also adds a rule at the very - top of the policy to restore the mark. Rules are placed in - INPUT,OUTPUT and FORWARD chain of the "mangle" table, this - ensures that DNAT happens before rules placed in the mangle table - see the packet. PREROUTING chain in mangle table is executed - before PREROUTING chain in the nat table, so placing tagging - rules in the PREROUTING chain would make them fire before DNAT. - POSTROUTING chain of the mangle table, as well as its FORWARD and - OUTPUT chains, work before corresponding chains of the nat table. - In all cases the goal is to make sure DNAT rules process the - packet before, and SNAT rules process it after filtering and - tagging rules. - - For PF this action is translated into tag. Supported only by - compilers for iptables and PF. - - Fig.2 Example of a rule utilizing action Tag. To illustrate - policy branches, this rule belongs to the branch with the name - rule0_branch - - * Classify: This action allows the firewall to define QoS class - for the packet that matches the rule. It is translated into - CLASSIFY for iptables, with parameter --set-class. For PF it is - translated into queue; compiler for ipfw can use pipe, queue or - divert depending on how the action is configured by the - administrator in the GUI. This action is only supported by - compilers for iptables, PF and ipfw. - - * Route: This action makes the firewall to route the packet that - matches the rule through an interface or a gateway specified in - the parameters of the action. This action is translated into - ROUTE target for iptables and route option for PF and ipfilter. - Compilers for PF and ipfilter support fastroute, route-to, - reply-to and dup-to options. - - Fig.3 Rules #0 and #1 tag packets entering the firewall through - interfaces eth0 and eth2; rules #3 and #4 help route reply - packets back through the same interfaces - - The GUI uses different names for the new actions depending on the - target firewall platform to simplify adoption. For example, new action - that created branch in rule set is called Chain for iptables firewalls - and Anchor for PF fierwalls. - - * Firewall object now has an attribute "inactive". Firewall marked as - inactive will not be picked by the GUI for the bulk compile and - install operations even if the timestamps indicate that this firewall - object needs to be recompiled - -Compiler for iptables - - * Support for address tables loaded from external files at compile or - run time - - * Support user defined chains with predefined names (using special - action ) - - * Support for CLASSIFY, MARK, CONNMARK, QUEUE, ROUTE targets - - * Support for physdev module for bridging firewalls - - * additional optimization of rules i INPUT and OUTPUT chain: now - removing firewall object from src or dst to simplify rule if it uses - OUTPUT or INPUT chain. Doing this only if original rule did not have - negation and we do not add any virtual addresses for NAT. After - removal the rule collapses to a simple command like this: - - iptables -A INPUT -p tcp --dport 22 -m state --state NEW -j ACCEPT - - - this works fine except if we have added virtual addresses for NAT. It - is assumed that firewall object in rules represents combination of - addresses configured in its interfaces in the GUI. Virtual addresses - added for NAT are considered to be a side effect and connections - should not be implicitly permitted to them by a rule with fw object in - destination. The same applies to fw object in source. See bug #685947 - for discussion. To avoid inadvertently opening holes in the firewall - by a rule like that, we remove fw object only when it is safe to do - so. - - * support for modules connlimit and hashlimit. There is an option to - generate commands for the latter module using name dstlimit because - older versions of iptables included this module under this (now - obsolete) name. - -Compiler for PF - - * Support for load balancing rules - * Support for tag and route options - * Support for address ranges and networ objects in TSrc in NAT rules - * Support for pool types in NAT rules ('bitmask', 'random', - 'source-hash', 'round-robin'), as well as 'static-port' option. - * Supprot for anchors (by way of a special action) - * Support for tables with predefined names (using AddressTable object) - * Support for packet 'tagging' (by way of a special action and service - object TagService) - -Compiler for ipfilter - - * Support for PPTP and IRC proxies - * Support for route option - -API - - * internal object ID is augumented with process ID of the program that - creates an object. This allows fwbedit to quickly create objects and - still ensure their IDs are unique - * fwbedit - - Fwbedit can now create objects and repair broken object database. This - tool can now be used to populate object database using shell scripts or - other automation. For example, to create an address object in object - library 'Test' one could run it like this: - - fwbedit -f filename.fwb -t IPv4 -n newAddress -L Test -o 192.0.2.1 - - Firewall Builder: general purpose object tree editing tool - Version 2.1.5-b - Usage: fwbedit21 -f filename.fwb -u [-a obj,grp] [-r obj,grp] [-d obj] [-s] [-l path] [(-p parent|-L library) -t objtype -n objname [-o object attributes]] - - -t objtype : create an object of this type - -L library : specify library when creating a new object - -p obj : specify parent object when creating a new object - -n name : specify a name of the new object - -o attribute1[,attribute2...] : specify attributes when creating a new object - -a obj,grp : create reference to object 'obj' in the group 'grp' - -r obj,grp : remove reference to object 'obj' from the group 'grp' - -d obj : delete object 'obj' and remove references to it from - all rules and groups - -l path : print list of objects for 'path' - -s : test and repair object tree structure - -u : autoupgrade of file - - An object and a group can be defined by their ID or - by the full path and name in the XML tree - - Object creation syntax: - - -t Firewall -n obj_name -L User -o platform, host OS - -t IPv4 -n obj_name -L User -o IP address - -t DNSName -n obj_name -L User -o DNS record,run time - -t AddressRange -n obj_name -L User -o start address, end address - -t ObjectGroup - -t Network -n obj_name -L User -o address,netmask - -t Interval -n obj_name -L User -o start time,start date,start day,end time, end date, end day - -t Interface -n obj_name -L User -o security level,address type (dynamic or unnumbered),management - -t Host - -t TCPService -n obj_name -L User -o source port range start,end,Destination port range start,end,UAPRSF,UAPRSF - -t UDPService -n obj_name -L User -o source port range start,end,Destination port range start,end - -t ICMPService -n obj_name -L User -o ICMP type,ICMP code - -t IPService -n obj_name -L User -o protocol number,lsrr/ssrr/rr/ts/fragm/short_fragm - diff --git a/doc/ReleaseNotes_2.1.8.html b/doc/ReleaseNotes_2.1.8.html deleted file mode 100644 index 8a866713a..000000000 --- a/doc/ReleaseNotes_2.1.8.html +++ /dev/null @@ -1,97 +0,0 @@ - - - - - - - -

Firewall Builder Release Notes

-
-

Version 2.1.8

-
-

-Released 12/02/2006 -
-GUI and compilers v2.1.8 require API library libfwbuilder version 2.1.8 -
-

Summary

-

- -

-For those who wish to build from source, instructions are outlined -in the document "Install and Build instructions" on our web site here - - -

Installation

- -

- - Optinon poll ran on the fwbuilder-discussion mailing list showed - that majority of users are not interested in ability to install and - run both fwbuilder 2.0 and 2.1 on the same machine at the same - time. Hence we are reverting to the old naming schema without suffix - '21' for the binaries and man pages in this release. - -

- -

Improvements and bug fixes in the GUI

-
    - -
  • The user can search for objects using regular expressions - matching their names or attributes. -

    -

    -
  • - -
  • Fixed bug #1592130: "Policy Chaining Issues". The GUI should - properly display nested branch rulesets. The user can create - policy branches within other branches. -
  • - - -
- - -

All compilers

- -
    -
  • Fixed bug #1590746 "problem with using "DNS Names" objects on MS - Windows". Compiler failed to convert DNSName objects set to resolve - at compile time into IP addresses. -
  • -
- - -

Compiler for iptables

-
    -
  • fixed bug #1593221: "iptables filtering bridge problem - PHYSDEV: - no physdev opti..." Some times rules were generated with "-m - physdev" but witout "--physdev-in" or "--physdev-out" options. -
  • -
- -

Compiler for Cisco PIX

-
    - -
  • fixed a bug (no num, support req. #1604103: "fwb_pix policy - compiler dies when SNMP or NTP hosts defined". Compiler did not - print error message when it could not find an interface with - network zone matching IP address of NTP or SNMP server (it just - printed the address without explanation of what went wrong) -
  • - -
  • Experimental utility fwb_pix_diff has been added to the - package. This utility takes two PIX configurations on the command - line and produces the 'diff' that consists of a set of commands - that should bring the firewall from the state defined by the first - config to the state defined by the second. Only PIX 7.0 is - supported. This utility will be incorporated into policy installer - in the future to make policy updates simpler and faster, - especially when small changes are made to the large set of access - lists and nat rules. -
  • -
- - - diff --git a/doc/ReleaseNotes_2.1.8.txt b/doc/ReleaseNotes_2.1.8.txt deleted file mode 100644 index 6ef1417e8..000000000 --- a/doc/ReleaseNotes_2.1.8.txt +++ /dev/null @@ -1,56 +0,0 @@ - Firewall Builder Release Notes - -Version 2.1.8 - - Released 12/02/2006 - GUI and compilers v2.1.8 require API library libfwbuilder version 2.1.8 - -Summary - - For those who wish to build from source, instructions are outlined in the - document "Install and Build instructions" on our web site here - -Installation - - Optinon poll ran on the fwbuilder-discussion mailing list showed that - majority of users are not interested in ability to install and run both - fwbuilder 2.0 and 2.1 on the same machine at the same time. Hence we are - reverting to the old naming schema without suffix '21' for the binaries - and man pages in this release. - -Improvements and bug fixes in the GUI - - * The user can search for objects using regular expressions matching - their names or attributes. - - * Fixed bug #1592130: "Policy Chaining Issues". The GUI should properly - display nested branch rulesets. The user can create policy branches - within other branches. - -All compilers - - * Fixed bug #1590746 "problem with using "DNS Names" objects on MS - Windows". Compiler failed to convert DNSName objects set to resolve at - compile time into IP addresses. - -Compiler for iptables - - * fixed bug #1593221: "iptables filtering bridge problem - PHYSDEV: no - physdev opti..." Some times rules were generated with "-m physdev" but - witout "--physdev-in" or "--physdev-out" options. - -Compiler for Cisco PIX - - * fixed a bug (no num, support req. #1604103: "fwb_pix policy compiler - dies when SNMP or NTP hosts defined". Compiler did not print error - message when it could not find an interface with network zone matching - IP address of NTP or SNMP server (it just printed the address without - explanation of what went wrong) - * Experimental utility fwb_pix_diff has been added to the package. This - utility takes two PIX configurations on the command line and produces - the 'diff' that consists of a set of commands that should bring the - firewall from the state defined by the first config to the state - defined by the second. Only PIX 7.0 is supported. This utility will be - incorporated into policy installer in the future to make policy - updates simpler and faster, especially when small changes are made to - the large set of access lists and nat rules. diff --git a/doc/ReleaseNotes_2.1.9.html b/doc/ReleaseNotes_2.1.9.html deleted file mode 100644 index 55056ecaf..000000000 --- a/doc/ReleaseNotes_2.1.9.html +++ /dev/null @@ -1,187 +0,0 @@ - - - - - - - -

Firewall Builder Release Notes

-
-

Version 2.1.9

-
-

-Released 02/10/2007 -
-GUI and compilers v2.1.9 require API library libfwbuilder version 2.1.9 -
-

Summary

-

-This is bugfix release. - -

-For those who wish to build from source, instructions are outlined -in the document "Install and Build instructions" on our web site here - - - -

Improvements and bug fixes in the GUI

-
    - -
  • New feature: new operation "Tools/Find Conflicting Objects in - Two Data Files". This operation inspects two data files (either - .fwb or .fwl) and finds conflicting objects. Conflicting objects - have the same internal ID but different attributes. Two data files - can not be merged, or one imported into another, if they contain - such objects. This operation also helps identify changes made to - objects in two copies of the same data file. This operation does - not find objects present in one file but not in the other, such - objects present no problem for merge or import operations. This - operation works with two external files, neither of which needs to - be opened in the program. Currently opened data file is not - affected by this operation and objects in the tree do not - change. In the process of this operation user is presented with - series of dialogs showing conflicting objects side by side. In the - end the program can generate report and write it to a text - file.
  • - - -
  • installOptionsDialog was too large and did not fit on some - laptop screens. Doing tricks to make sure the dialog properly - resized after unused GUI elements are hidden. -
  • - -
  • bug #1629521: "can't delete empty chain/policy tab"
  • - -
  • bug #1619842: "prolog "script editor" opens behind other - windows"
  • - -
  • bug #1620206: "RuleOptions' "Apply" button greyed-out until menu - selection"
  • - -
  • bug 1619930: "Prolog tab's ScriptEditor's import fails to - overwrite"
  • - -
  • bug #1617501:"Install fails after compile". The GUI got confused - when user enter full path to the policy file in the "Output file - name" input field in the "Compiler" tab of firewall object - dialog. Making sure we always strip directory path from the file - name if user specified full path for the policy file in the - "Output file name" input field in the "Compiler" tab of firewall - object dialog. Need to strip path when macro "%FWSCRIPT%" is - substituted in installation scriptlets and in some other - places.
  • - -
  • "Apply" and "Close" buttons in the objct editor panel should be - of fixed size horizontally
  • - -
  • bug #1624577: "group window doesn't stay open on - multiple-adds". Using special flag to tell ObjectTreeView that it - should ignore MouseReleaseEvent it gets after d&d operation, so it - wont switch object in the editor panel. Note the bug triggered - only on Mac OS X.
  • - -
  • bug (no num.): GUI used show fanthom 'Policy', 'NAT' and - 'Routing' tabs when user deleted objects from the Deleted Objects - library, provided some of these objects were previously deleted - firewalls.
  • - -
  • bug #1620284: "conflict when adding library to - Preferences/Libraries". When the user tried to add a library to - the list in Preferemces/Libraries when a data file with the same - object library was loaded, the GUI detected the conflict and - showed error dialog.
  • - -
  • bug #1650369: "[patch] please add support for - GNU/kFreeBSD". Applied patch to make code compile on kFreeBSD.
  • - -
- - - - -

Compiler for iptables

-
    -
  • bug #1623338: "Can not disable rules in a branch". Compiler for - iptables ignored flag 'disabled' on rules in a branch. -
  • - -
  • bug #1623113: 'connlimit fails in compiled "address table" - rules' Module connlimit can only be used in iptables rules - matching TCP services. Such iptables commands have "-p tcp" - and/or "-m tcp" options. If a rule in fwbuilder uses TCP Service - and connlimit option and has multiple objects in src and dst, - optimizer used to split it to minimize matches. It however - preserved connlimit option in all subrules, even though some of - them did not have TCP service after the split. This lead to - generation of incorrect iptables commands.
  • - -
  • bug #1620925: "compile-time AddressTable object with empty - file". Compile-time AddressTable object that uses file with no - addresses should be treated as an empty group according to the - "Ignore empty groups" option.
  • - -
  • bug #1618381: "CLASSIFY/MARK are non-terminating". This bug - report in fact reported several problems. -

    -

      -
    • For action Branch with option to add branching rule to the - mangle table: we now generate rules in PREROUTING, - POSTROUTING, INPUT, OUTPUT and FORWARD chains. This is - because some targets can only work in PREROUTING or - POSTROUTING chains but we do not know what rules will user - put in the branch. So we need to branch in all chains -
    • - -
    • For rules in mangle table with direction set to Inbound or - Outbound force chain to PREROUTING or POSTROUTING - respectively early. This eliminates duplicates such as the - same rule in PREROUTING and INPUT chains. Also since most - (all?) targets that require mangle table go into either - PREROUTING or POSTROUTING chains, it should be enough to use - these two chains. -
    • - -
    • Non-terminating rules shadow each other "backwards", that - is more general rule shadows other rules _above_ it. Added - flag 'reverse' to the method find_more_general_rule and - added new rule processor - DetectShadowingForNonTerminatingRules that finds such cases - of 'reverse' shadowing. Using it for rules in the mangle - table for iptables. -
    • - -
    • Adding iptables rule with target ACCEPT to emulate - terminating behavior for Tag and Classify actions. Emulation - is controlled by a global option in the "Compiler" tab of - the firewall properties dialog (default is "off"). This - means emulation can be turned on and off for all rules that - might require it at once. It is impossible to mix such rules - with terminating and non-termninating behavior. The reason - for this is that shadowing detection algorithm can only work - with either terminating or non-terminating rules, not with - the mix.
    • - -
    -

    -
  • - -
  • bug #1628989: "run-time-loaded rules don't accept ";" as line - comment"
  • - -
  • bug #1632054: "Runtime AddressObjects FAIL to load if "Name:" - contains "."". Compiler checks if the name of the run-time - AddressTable object contains characters that have special meaning - in sheel and relaces them with '_' when it generates the name of - the temporary shell variable.
  • - -
  • bug (no num.): data files used for run-time AddressTable objects - can have empty lines, the script should skip them.
  • - - - -
- - - - diff --git a/doc/ReleaseNotes_2.1.9.txt b/doc/ReleaseNotes_2.1.9.txt deleted file mode 100644 index c1a771ec8..000000000 --- a/doc/ReleaseNotes_2.1.9.txt +++ /dev/null @@ -1,118 +0,0 @@ - Firewall Builder Release Notes - -Version 2.1.9 - - Released 02/10/2007 - GUI and compilers v2.1.9 require API library libfwbuilder version 2.1.9 - -Summary - - This is bugfix release. - - For those who wish to build from source, instructions are outlined in the - document "Install and Build instructions" on our web site here - -Improvements and bug fixes in the GUI - - * New feature: new operation "Tools/Find Conflicting Objects in Two Data - Files". This operation inspects two data files (either .fwb or .fwl) - and finds conflicting objects. Conflicting objects have the same - internal ID but different attributes. Two data files can not be - merged, or one imported into another, if they contain such objects. - This operation also helps identify changes made to objects in two - copies of the same data file. This operation does not find objects - present in one file but not in the other, such objects present no - problem for merge or import operations. This operation works with two - external files, neither of which needs to be opened in the program. - Currently opened data file is not affected by this operation and - objects in the tree do not change. In the process of this operation - user is presented with series of dialogs showing conflicting objects - side by side. In the end the program can generate report and write it - to a text file. - * installOptionsDialog was too large and did not fit on some laptop - screens. Doing tricks to make sure the dialog properly resized after - unused GUI elements are hidden. - * bug #1629521: "can't delete empty chain/policy tab" - * bug #1619842: "prolog "script editor" opens behind other windows" - * bug #1620206: "RuleOptions' "Apply" button greyed-out until menu - selection" - * bug 1619930: "Prolog tab's ScriptEditor's import fails to overwrite" - * bug #1617501:"Install fails after compile". The GUI got confused when - user enter full path to the policy file in the "Output file name" - input field in the "Compiler" tab of firewall object dialog. Making - sure we always strip directory path from the file name if user - specified full path for the policy file in the "Output file name" - input field in the "Compiler" tab of firewall object dialog. Need to - strip path when macro "%FWSCRIPT%" is substituted in installation - scriptlets and in some other places. - * "Apply" and "Close" buttons in the objct editor panel should be of - fixed size horizontally - * bug #1624577: "group window doesn't stay open on multiple-adds". Using - special flag to tell ObjectTreeView that it should ignore - MouseReleaseEvent it gets after d&d operation, so it wont switch - object in the editor panel. Note the bug triggered only on Mac OS X. - * bug (no num.): GUI used show fanthom 'Policy', 'NAT' and 'Routing' - tabs when user deleted objects from the Deleted Objects library, - provided some of these objects were previously deleted firewalls. - * bug #1620284: "conflict when adding library to Preferences/Libraries". - When the user tried to add a library to the list in - Preferemces/Libraries when a data file with the same object library - was loaded, the GUI detected the conflict and showed error dialog. - * bug #1650369: "[patch] please add support for GNU/kFreeBSD". Applied - patch to make code compile on kFreeBSD. - -Compiler for iptables - - * bug #1623338: "Can not disable rules in a branch". Compiler for - iptables ignored flag 'disabled' on rules in a branch. - * bug #1623113: 'connlimit fails in compiled "address table" rules' - Module connlimit can only be used in iptables rules matching TCP - services. Such iptables commands have "-p tcp" and/or "-m tcp" - options. If a rule in fwbuilder uses TCP Service and connlimit option - and has multiple objects in src and dst, optimizer used to split it to - minimize matches. It however preserved connlimit option in all - subrules, even though some of them did not have TCP service after the - split. This lead to generation of incorrect iptables commands. - * bug #1620925: "compile-time AddressTable object with empty file". - Compile-time AddressTable object that uses file with no addresses - should be treated as an empty group according to the "Ignore empty - groups" option. - * bug #1618381: "CLASSIFY/MARK are non-terminating". This bug report in - fact reported several problems. - - * For action Branch with option to add branching rule to the mangle - table: we now generate rules in PREROUTING, POSTROUTING, INPUT, - OUTPUT and FORWARD chains. This is because some targets can only - work in PREROUTING or POSTROUTING chains but we do not know what - rules will user put in the branch. So we need to branch in all - chains - * For rules in mangle table with direction set to Inbound or - Outbound force chain to PREROUTING or POSTROUTING respectively - early. This eliminates duplicates such as the same rule in - PREROUTING and INPUT chains. Also since most (all?) targets that - require mangle table go into either PREROUTING or POSTROUTING - chains, it should be enough to use these two chains. - * Non-terminating rules shadow each other "backwards", that is more - general rule shadows other rules _above_ it. Added flag 'reverse' - to the method find_more_general_rule and added new rule processor - DetectShadowingForNonTerminatingRules that finds such cases of - 'reverse' shadowing. Using it for rules in the mangle table for - iptables. - * Adding iptables rule with target ACCEPT to emulate terminating - behavior for Tag and Classify actions. Emulation is controlled by - a global option in the "Compiler" tab of the firewall properties - dialog (default is "off"). This means emulation can be turned on - and off for all rules that might require it at once. It is - impossible to mix such rules with terminating and - non-termninating behavior. The reason for this is that shadowing - detection algorithm can only work with either terminating or - non-terminating rules, not with the mix. - - * bug #1628989: "run-time-loaded rules don't accept ";" as line comment" - * bug #1632054: "Runtime AddressObjects FAIL to load if "Name:" contains - "."". Compiler checks if the name of the run-time AddressTable object - contains characters that have special meaning in sheel and relaces - them with '_' when it generates the name of the temporary shell - variable. - * bug (no num.): data files used for run-time AddressTable objects can - have empty lines, the script should skip them. diff --git a/doc/ReleaseNotes_2_0.html b/doc/ReleaseNotes_2_0.html deleted file mode 100644 index fc9264e6f..000000000 --- a/doc/ReleaseNotes_2_0.html +++ /dev/null @@ -1,335 +0,0 @@ - - - - - - - -

Firewall Builder Release Notes

-
-

Version 2.0

-
-

-Released 07/28/04 -
-GUI and compilers v2.0 require API library libfwbuilder version 2.0 -
-

Summary

-

- -Firewall Builder GUI v2.0 has been completely rewritten using QT -

-For those who wish to build from source, instructions are outlined -in "Install -and Build instructions" - -

What's new

-

- The GUI has been rewritten from scratch. The new GUI is based on - QT 3.x. It has been tested with Qt v3.1.1, 3.2.3 and 3.3.1. We - build on RedHat 9.0, Mandrake 10, SuSE 9.1, FreeBSD 5.2 using QT - packages that come with these systems. - -

The GUI has been redesigned to addresses problems known to - exist in fwbuilder 1.1.x user interface: - -

    -
  • Speed imporevements in the GUI. Firewall policy that consist - of 1000 rules renders just as fast as policy that has only 10 - rules. The GUI has actually been tested with 1000 rules - policies.
  • - -
  • Object tree is not synchronized with firewall policy - view. Selecting an object in the tree does not immediately open - it in the right hand panel in the main window. Right hand side - panel is dedicated for the policy view and always shows policy - or NAT rules of the firewall selected in the pull-down menu - above it. Editing of all objects is done in a separate floating - editor window that can be kept open at all times. -
  • - -
  • Properties of an object selected in the tree or in any rule - are shown in the information panel under the tree. The size of - the panel can be changed; the panel has three modes of - operation: a) hidden, b) showing only comment associated with - selected object, c) showing its parameters and comment. User can - choose the mode by clilcking on the toolbar button under the - information panel.
  • - -
  • "Find object" function finds obejcts by their name in the - tree, in groups and in rules. Regular expressions are - recognized.
  • - -
  • Built-in version control based on RCS provides for a simple - way to track changes.
  • - -
  • Data file can be opened read-only for inspection. If the - file is checked out and locked by a different user, it can only - be opened read-only.
  • - -
  • Data file can be given on the command line without "-f" - switch. The "-f" is also supported for backwards - compatibility.
  • - -
  • The program does not make copies of standard objects in user - data file anymore (per Feature Request #810504 "'Standard' - definitions should not be saved" )
  • - -
  • Users can create and distribute their own libraries of - objects. The GUI allows for objects to be exported to external - library file with extension .fwl and imported from such - file.
  • - -
  • Objects in the 'Standard' objects library, as well as - objects in libraries imported from external files, are - read-only
  • - -
  • Added an option for autosave - if this option is turned on, - the gui periodically saves data to the file. The autosave - interval can be set between 1 minute and 2 hours.
  • - -
  • The GUI detects collisions between objects when external - library is imported. Collision is detected when any attribute of - an objects in the tree is different from that attribute in the - object with the same unique ID in the file being imported. Some - old data files may trigger collisions because of subtle - differences in comments
  • - -
  • Whenever user changes the name of a firewall, host or an - interface object, the GUI asks whether they want to also rename - all IP and MAC addresses that belong to that firewall or - host. If user agrees to rename them, the program generates names - automatically using scheme 'host_name:interface_name:ip' and - 'host_name:interface_name:mac'
  • - -
  • Deleted objects are moved to a special library and can be - recovered with "Undelete" operation
  • - -
  • Rules can be color-labeled in all policies.
  • - -
  • Window size and position is remembered across multiple - sessions for all dialogs.
  • - -
  • Two modes of drag-and-drop of objects in policy and NAT - rules: dragging of an object moves it; dragging of an object - with Ctrl key pressed copies it
  • - -
  • Multiple objects can be selected in the tree. Operations - such as duplication, moving between libraries, copy/paste can be - performed on multiple selected objects
  • - -
  • Multiple rules can also be selected for operations such as - moving, deleting, copy/paste, setting colors
  • - -
  • A collection of firewall template objects comes in a - separate XML file with the package. You can create a new - firewall object using one for these templates. This replaced - "help me build firewall" wizard.
  • - -
  • The "Help me build firewall policy" wizard was phased out - and replaced with firewall templates. The template library will - be extended in the future releases.
  • - -
  • GUI has a built-in installer that uses external ssh client - to communicate with firewall. Installer has simple GUI interface - and works on both Linux and Windows (uses putty or SecureCRT on - Windows). There is no need in external install script - fwb_install anymore.
  • - -
  • An option has been added to firewall platforms iptables, - ipfilter, pf and ipfw that sets up a policy rule to permit ssh - access from one specified IP address to the firewall regardless - of other rules. This is for a backup ssh access from the - management workstation in case of an error in the policy that - locks user out of the firewall. The option (a checkbox and entry - field for the management station address) is located in the - "Compiler" tab of the firewall settings dialog. A command that - permits ssh to the firewall from the given address is added on - top of all other rules.
  • - -
  • Packages for Windows 2000, Windows XP and Mac OS X will be - distributed under a different license.
  • - -
  • The build process is based on qmake and uses autoconf - sparingly. Libtool is not used at all.
  • - -
  • Internationalization is done using gettext 0.14.1 which - supports QT .qm files
  • - -
  • Reasonably complete French translation is provided.
  • - -
  • Object names and comments are stored in the object file in - UTF-8 format. This allows for names and comments to be entered - and displayed in local languages. Although object names can be - localized, it is recommended to keep firewall names in plain - ASCII because compilers do not support UTF-8 yet. This fixes - very old bug #657156: "Special characters problem".
  • - -
  • Code compiles with gcc 3.4
  • -
-
- - -
-
-

New firewall platforms and new features that apply to all - platforms:

-
    -
  • - Added support for Linksys devices running Sveasoft - firmware. Firewall object should be configured as platform - "iptables", host OS "linksys". Policy installer works both - using password and public key authentication.
  • - -
  • Added an option to firewall platforms iptables, ipfilter, pf - and ipfw that sets up a policy rule to permit ssh access from - one specified IP address to the firewall regardless of other - rules. This is for a backup ssh access from the management - workstation in case of an error in the policy that locks user - out of the firewall. The option (a checkbox and entry field for - the management station address) is located in the "Compiler" tab - of the firewall settings dialog. A command that permits ssh to - the firewall from the given address is added on top of all other - rules.
  • - -
  • added attribute 'lastModified' to element FWBObjectDatabase - in DTD. this attribute holds time of last modification done to - any object in the database (GMT). Added support for this - attribute in class FWObjectDatabase. This attribute is - implied.
  • -
- -
-
-
- -

Bugs fixed in libfwbuilder API:

-
    -
  • fixed bug that appeared only when used with libxml2 2.6.6 - and libxslt 1.0.33 - '*Group' elements were not converted - properly (losing all child elements). It worked on RH 9 with - libxml2 2.5.4 and libxslt 1.0.27. Fix tested with libxml2 2.6.6 - and libxslt 1.0.33 on Fedora C1
  • - -
  • Method Firewall::duplicate replaces references to the - firewall, its interfaces as well as IPv4 and physical addresses - of the interfaces in all rule sets with references to the copies - of corresponding objects. Now firewall created from another one - using 'duplicate' does not reference interfaces or addresses - that belong to the original firewall object.
  • - -
  • bug #950857: "Incorrect conversion of address range" - - address range that consisted of two IP addresses was converted - to a set of networks incorrectly.
  • - -
  • bug that occured on big endian architecture (e.g. Macintosh) - because of incorrect usage of preprocessor directives to check - BYTE_ORDER. This bug caused incorrect address arithmetics.
  • - -
  • bug #906709: "A dynamic interface". Dynamic interface used - to "shadow" old broadcast object (0.0.0.0)
  • -
- - -
-
-

New features in iptables policy compiler fwb_ipt:

-
    -
  • Feature Request #913273: make "assume fw is part of any" a - per-rule option
  • - -
  • Processing of policy rules where firewall object is used in - src or dst with negation (possibly in combination with other - objects) has been optimized. Before, generated script would - match firewall's addresses in INPUT/OUTPUT and FORWARD chains - which added redundant checks in the FORWARD chain.
  • -
- - -
-
-

Bugs fixed in iptables policy compiler fwb_ipt:

-
    -
  • - bug #956544: "Error into load modules script generation", - where generated script would not load kernel modules with - names "module.ko.gz". Regular expression should match on - ".ko.*$" to find these modules properly. Thanks to Andrey - Kaminsky who pointed this out. -
  • - -
  • bug #934949: "duplicate rules". fwb_ipt created duplicate - rules for a bridging firewall if fw object or its interfaces or - their addresses were not in the source or desintaion
  • - -
  • bug #912849: "Reorder activation of network interfaces in - IPT" - script generated by the compiler for iptables sets - default policy to DROP, flushes all rules and then reconfigures - interfaces of the firewall (it used to reconfigure intefaces and - then flush the rules).
  • - -
  • bug #906709: "A dynamic interface". Dynamic interface used - to "shadow" old broadcast object (0.0.0.0)
  • - -
  • bug #979484: "improper command for rule with service any and - action reject." For rules like that, and if rule options dialog - does not specify particular way to handle this combination, the - compiler splits the rule; the first iptables command rejects any - tcp packet with TCP RST, while the second rejects everything - else with ICMP message.
  • - -
  • bug #917422: "compiler misinterprets interface with addr - 0.0.0.0". If an interface has IP address "0.0.0.0", it is - considered an error.
  • - -
  • bug #978854: "false rule generated for fw object in - interface rule". Policy compiler for iptables generated - incorrect code for rules using negated firewall object in source - or destination when global option "assume firewall is part of - any" was turned off.
  • - -
  • bug #925199: "compiles wrongly a double negation". Policy - compiler for iptables generated incorrect code for rules where - two rule elements used negation (i.e. both src and dst, or dst - and srv, etc.)
  • - -
  • bug #988860: "Logging missing when firewall start is - aborted". When iptables script generated by fwb_ipt finds - missing interfaces, it prints error message both on stdout and - sends it to the log.
  • - -
  • bug #965558: "False ruleset generated for iptables (negate - w/ nat)". There were problems with double negations in NAT rules - (OSrc and ODst, or ODst and OSrv, etc).
  • - -
  • bugs #935794: "dual translation and negation in fwb_ipt" and - #986376: "Wrong result for negated source in NAT rules". Dual - translation rule with negation in OSrc did not process negation - in the second half (POSTROUTING rule, the one that translates - the source).
  • - -
  • bug #990037: "Wrong rule generated: fw interface included in - negated group". Rules with negation should not generate code in - INPUT/OUTPUT chains if option "assume firewall is part of any" - is off.
  • -
- - -
-
-

Bugs fixed in iptables policy compiler fwb_pf:

-
    -
  • bug (no number) where fwb_pf would not include code defined by - custom service object in the .conf file
  • - -
  • bug #985527: pf NAT rules miss destination port - specification. NAT rules that translate to "map" missed - destination port specification.
  • - -
  • bug #986518: "PF redirection always point to loopback - address"
  • -
- - - diff --git a/doc/ReleaseNotes_2_0.txt b/doc/ReleaseNotes_2_0.txt deleted file mode 100644 index 2cbec50aa..000000000 --- a/doc/ReleaseNotes_2_0.txt +++ /dev/null @@ -1,227 +0,0 @@ - Firewall Builder Release Notes - -Version 2.0 - - Released 07/28/04 - GUI and compilers v2.0 require API library libfwbuilder version 2.0 - -Summary - - Firewall Builder GUI v2.0 has been completely rewritten using QT - - For those who wish to build from source, instructions are outlined in - "Install and Build instructions" - -What's new - - The GUI has been rewritten from scratch. The new GUI is based on QT 3.x. - It has been tested with Qt v3.1.1, 3.2.3 and 3.3.1. We build on RedHat - 9.0, Mandrake 10, SuSE 9.1, FreeBSD 5.2 using QT packages that come with - these systems. - - The GUI has been redesigned to addresses problems known to exist in - fwbuilder 1.1.x user interface: - - * Speed imporevements in the GUI. Firewall policy that consist of 1000 - rules renders just as fast as policy that has only 10 rules. The GUI - has actually been tested with 1000 rules policies. - * Object tree is not synchronized with firewall policy view. Selecting - an object in the tree does not immediately open it in the right hand - panel in the main window. Right hand side panel is dedicated for the - policy view and always shows policy or NAT rules of the firewall - selected in the pull-down menu above it. Editing of all objects is - done in a separate floating editor window that can be kept open at - all times. - * Properties of an object selected in the tree or in any rule are - shown in the information panel under the tree. The size of the panel - can be changed; the panel has three modes of operation: a) hidden, - b) showing only comment associated with selected object, c) showing - its parameters and comment. User can choose the mode by clilcking on - the toolbar button under the information panel. - * "Find object" function finds obejcts by their name in the tree, in - groups and in rules. Regular expressions are recognized. - * Built-in version control based on RCS provides for a simple way to - track changes. - * Data file can be opened read-only for inspection. If the file is - checked out and locked by a different user, it can only be opened - read-only. - * Data file can be given on the command line without "-f" switch. The - "-f" is also supported for backwards compatibility. - * The program does not make copies of standard objects in user data - file anymore (per Feature Request #810504 "'Standard' definitions - should not be saved" ) - * Users can create and distribute their own libraries of objects. The - GUI allows for objects to be exported to external library file with - extension .fwl and imported from such file. - * Objects in the 'Standard' objects library, as well as objects in - libraries imported from external files, are read-only - * Added an option for autosave - if this option is turned on, the gui - periodically saves data to the file. The autosave interval can be - set between 1 minute and 2 hours. - * The GUI detects collisions between objects when external library is - imported. Collision is detected when any attribute of an objects in - the tree is different from that attribute in the object with the - same unique ID in the file being imported. Some old data files may - trigger collisions because of subtle differences in comments - * Whenever user changes the name of a firewall, host or an interface - object, the GUI asks whether they want to also rename all IP and MAC - addresses that belong to that firewall or host. If user agrees to - rename them, the program generates names automatically using scheme - 'host_name:interface_name:ip' and 'host_name:interface_name:mac' - * Deleted objects are moved to a special library and can be recovered - with "Undelete" operation - * Rules can be color-labeled in all policies. - * Window size and position is remembered across multiple sessions for - all dialogs. - * Two modes of drag-and-drop of objects in policy and NAT rules: - dragging of an object moves it; dragging of an object with Ctrl key - pressed copies it - * Multiple objects can be selected in the tree. Operations such as - duplication, moving between libraries, copy/paste can be performed - on multiple selected objects - * Multiple rules can also be selected for operations such as moving, - deleting, copy/paste, setting colors - * A collection of firewall template objects comes in a separate XML - file with the package. You can create a new firewall object using - one for these templates. This replaced "help me build firewall" - wizard. - * The "Help me build firewall policy" wizard was phased out and - replaced with firewall templates. The template library will be - extended in the future releases. - * GUI has a built-in installer that uses external ssh client to - communicate with firewall. Installer has simple GUI interface and - works on both Linux and Windows (uses putty or SecureCRT on - Windows). There is no need in external install script fwb_install - anymore. - * An option has been added to firewall platforms iptables, ipfilter, - pf and ipfw that sets up a policy rule to permit ssh access from one - specified IP address to the firewall regardless of other rules. This - is for a backup ssh access from the management workstation in case - of an error in the policy that locks user out of the firewall. The - option (a checkbox and entry field for the management station - address) is located in the "Compiler" tab of the firewall settings - dialog. A command that permits ssh to the firewall from the given - address is added on top of all other rules. - * Packages for Windows 2000, Windows XP and Mac OS X will be - distributed under a different license. - * The build process is based on qmake and uses autoconf sparingly. - Libtool is not used at all. - * Internationalization is done using gettext 0.14.1 which supports QT - .qm files - * Reasonably complete French translation is provided. - * Object names and comments are stored in the object file in UTF-8 - format. This allows for names and comments to be entered and - displayed in local languages. Although object names can be - localized, it is recommended to keep firewall names in plain ASCII - because compilers do not support UTF-8 yet. This fixes very old bug - #657156: "Special characters problem". - * Code compiles with gcc 3.4 - -New firewall platforms and new features that apply to all platforms: - - * Added support for Linksys devices running Sveasoft firmware. - Firewall object should be configured as platform "iptables", host OS - "linksys". Policy installer works both using password and public key - authentication. - * Added an option to firewall platforms iptables, ipfilter, pf and - ipfw that sets up a policy rule to permit ssh access from one - specified IP address to the firewall regardless of other rules. This - is for a backup ssh access from the management workstation in case - of an error in the policy that locks user out of the firewall. The - option (a checkbox and entry field for the management station - address) is located in the "Compiler" tab of the firewall settings - dialog. A command that permits ssh to the firewall from the given - address is added on top of all other rules. - * added attribute 'lastModified' to element FWBObjectDatabase in DTD. - this attribute holds time of last modification done to any object in - the database (GMT). Added support for this attribute in class - FWObjectDatabase. This attribute is implied. - - -------------------------------------------------------------------- - -Bugs fixed in libfwbuilder API: - - * fixed bug that appeared only when used with libxml2 2.6.6 and - libxslt 1.0.33 - '*Group' elements were not converted properly - (losing all child elements). It worked on RH 9 with libxml2 2.5.4 - and libxslt 1.0.27. Fix tested with libxml2 2.6.6 and libxslt 1.0.33 - on Fedora C1 - * Method Firewall::duplicate replaces references to the firewall, its - interfaces as well as IPv4 and physical addresses of the interfaces - in all rule sets with references to the copies of corresponding - objects. Now firewall created from another one using 'duplicate' - does not reference interfaces or addresses that belong to the - original firewall object. - * bug #950857: "Incorrect conversion of address range" - address range - that consisted of two IP addresses was converted to a set of - networks incorrectly. - * bug that occured on big endian architecture (e.g. Macintosh) because - of incorrect usage of preprocessor directives to check BYTE_ORDER. - This bug caused incorrect address arithmetics. - * bug #906709: "A dynamic interface". Dynamic interface used to - "shadow" old broadcast object (0.0.0.0) - -New features in iptables policy compiler fwb_ipt: - - * Feature Request #913273: make "assume fw is part of any" a per-rule - option - * Processing of policy rules where firewall object is used in src or - dst with negation (possibly in combination with other objects) has - been optimized. Before, generated script would match firewall's - addresses in INPUT/OUTPUT and FORWARD chains which added redundant - checks in the FORWARD chain. - -Bugs fixed in iptables policy compiler fwb_ipt: - - * bug #956544: "Error into load modules script generation", where - generated script would not load kernel modules with names - "module.ko.gz". Regular expression should match on ".ko.*$" to find - these modules properly. Thanks to Andrey Kaminsky who - pointed this out. - * bug #934949: "duplicate rules". fwb_ipt created duplicate rules for - a bridging firewall if fw object or its interfaces or their - addresses were not in the source or desintaion - * bug #912849: "Reorder activation of network interfaces in IPT" - - script generated by the compiler for iptables sets default policy to - DROP, flushes all rules and then reconfigures interfaces of the - firewall (it used to reconfigure intefaces and then flush the - rules). - * bug #906709: "A dynamic interface". Dynamic interface used to - "shadow" old broadcast object (0.0.0.0) - * bug #979484: "improper command for rule with service any and action - reject." For rules like that, and if rule options dialog does not - specify particular way to handle this combination, the compiler - splits the rule; the first iptables command rejects any tcp packet - with TCP RST, while the second rejects everything else with ICMP - message. - * bug #917422: "compiler misinterprets interface with addr 0.0.0.0". - If an interface has IP address "0.0.0.0", it is considered an error. - * bug #978854: "false rule generated for fw object in interface rule". - Policy compiler for iptables generated incorrect code for rules - using negated firewall object in source or destination when global - option "assume firewall is part of any" was turned off. - * bug #925199: "compiles wrongly a double negation". Policy compiler - for iptables generated incorrect code for rules where two rule - elements used negation (i.e. both src and dst, or dst and srv, etc.) - * bug #988860: "Logging missing when firewall start is aborted". When - iptables script generated by fwb_ipt finds missing interfaces, it - prints error message both on stdout and sends it to the log. - * bug #965558: "False ruleset generated for iptables (negate w/ nat)". - There were problems with double negations in NAT rules (OSrc and - ODst, or ODst and OSrv, etc). - * bugs #935794: "dual translation and negation in fwb_ipt" and - #986376: "Wrong result for negated source in NAT rules". Dual - translation rule with negation in OSrc did not process negation in - the second half (POSTROUTING rule, the one that translates the - source). - * bug #990037: "Wrong rule generated: fw interface included in negated - group". Rules with negation should not generate code in INPUT/OUTPUT - chains if option "assume firewall is part of any" is off. - -Bugs fixed in iptables policy compiler fwb_pf: - - * bug (no number) where fwb_pf would not include code defined by - custom service object in the .conf file - * bug #985527: pf NAT rules miss destination port specification. NAT - rules that translate to "map" missed destination port specification. - * bug #986518: "PF redirection always point to loopback address"