Commit Graph
1107 Commits
Author SHA1 Message Date
Vadim Kurland 74063d35c3 implemented support for mixed address lists for run-time address table objects with ipset module 2010-07-27 01:14:04 +00:00
Vadim Kurland 7efbcf6825 * code cleanup. Removed bunch of warnings and cleaned up some test
cases using small patches from Mike Slifcak  slif@bellsouth.net
2010-07-25 03:41:27 +00:00
Vadim Kurland e1bca13699 * Fixes #1635: included code generated by the configlet
run_time_address_tables into script for all linux-based host
OS
2010-07-24 06:41:46 +00:00
Vadim Kurland 1a8d8cd1ea fixed #1633 use ipset module in NATCompiler_ipt 2010-07-24 06:03:48 +00:00
Vadim Kurland 8c90295231 fixes 1625, #1627 See #137 added configlet for run time adress table objects with ipset module to check ipset tool and the module, check and load data from address table files 2010-07-24 03:09:02 +00:00
Vadim Kurland 11cb56d6c9 * PolicyCompiler_PrintRule.cpp (PrintRule::normalizeSetName):
fixed #1626 "convert space and other special characters found in
the run time address table object into underscores". The name of
the run-time Address Table object is used for the name of the
ipset module set. Making sure the name is sanitized of the
chanracters considered "special" by shell before it is used.
2010-07-24 00:02:53 +00:00
Vadim Kurland 15e8677943 * check_utilities: fixed #1625, #see 137: added ipset to the list
of command line utilities generated iptables script can
use. Script will check if the utility is present on the firewall
if user requested use of iptables module "set" for run-time
Address Table objects. Also added an input field for ipset in the
advanced settings host OS dialog for Linux to let the user specify
path to ipset if it is not standard.
2010-07-23 23:38:38 +00:00
Vadim Kurland e82f770956 * PolicyCompiler_PrintRule.cpp: added support for iptables module
"set" used to generate iptables command for rules with run-time
AddressTable objects. This module is only available in iptables
1.4.1.1 and later, however some embedded platforms do not have it
even though they ship later versions ofiptables (e.g. OpenWRT).
Use of this module is controlled by a checkbox in the iptables 
"advanced" settings dialog which is off by default. This checkbox
becomes disabled when iptables version is set to < 1.4.1.1.
2010-07-23 05:15:05 +00:00
Vadim Kurland 56ce332788 * newClusterDialog_create.cpp (newClusterDialog::createNewCluster):
fixed #1622 "Crash when configuring cluster". The GUI used to crash
if user created a cluster copying rules of one of the cluster members
while that rule set was opened in the rule set view.
2010-07-22 23:54:32 +00:00
Vadim Kurland df647bfab2 see #1615 better dialog layout but still too wide 2010-07-22 04:26:04 +00:00
Vadim Kurland 53a08e03c1 iptables "advanced" settings dialog redesign 2010-07-22 02:01:13 +00:00
Vadim Kurland 076cfdc8f1 fixed tab order in the interface editor widget See #1613 2010-07-22 01:11:42 +00:00
Vadim Kurland 7bd96d7042 rearranged elements in the interface editor widget to reduce its height. See #1613 2010-07-22 01:06:43 +00:00
Vadim Kurland 350fbfb45d * InterfaceEditorWidget.ui: set minimum height for the name, label
and few other input fields because they came out squished on Mac.
Fixes #1613.
2010-07-22 00:22:33 +00:00
Vadim Kurland 559d22e137 * FWWindow.cpp (fileNew): fixed #1611 "File/New should create new
project panel". Like #1612, open new data file in a new project
panel if current project panel has no data file associated with it
but has unsaved changes.
2010-07-21 23:45:22 +00:00
Vadim Kurland b48d84e6ab * FWWindow.cpp (loadFile): fixed #1612 "File/Open should create
new project panel". If user has some unsaved changes in the
default project panel (the one with no associated file) and then
uses File/Open menu to open another data file, the file should
open in a new project panel.
2010-07-21 23:40:35 +00:00
Vadim Kurland d870730db2 merge from v4_0 branch r3122-3124 2010-07-21 16:10:10 +00:00
Vadim Kurland fafcb2202c renamed release notes file; made main window wider by default 2010-07-21 05:06:19 +00:00
SVN User 4d398942cc moved install target definitions to res.pro 2010-07-21 04:42:00 +00:00
Vadim Kurland b8564b8f61 now really /4.1 in settings 2010-07-21 01:20:29 +00:00
Vadim Kurland 7247990781 added copy of routing_functions configlet for dd-wrt 2010-07-20 23:42:39 +00:00
Vadim Kurland c077f60e13 fixed #1603 Welcome dialog should show full version of the program 2010-07-20 22:19:08 +00:00
Vadim Kurland 565e888472 version 4.1.0 2010-07-20 18:02:45 +00:00
Vadim Kurland 53950163aa code clean-up 2010-07-20 16:54:37 +00:00
Vadim Kurland 671e772e1b fixed SF bug #3031930 "segfault starting discovery druid" 2010-07-20 06:29:22 +00:00
Vadim Kurland 468746142b fixing unit tests for the latest change 2010-07-20 03:52:42 +00:00
Vadim Kurland ebf137670c fixed SF bug 3031721 Standard bjects library was made read-write by mistake in one of the earlier builds 2010-07-19 22:33:45 +00:00
Vadim Kurland a70ef0272d fixed #1597 import method "import configuration of a firewall" is disabled on the first page of the discovery druid 2010-07-18 01:38:46 +00:00
Vadim Kurland cb020de62c Refs #1587 trying to eliminate unnecessary events when the same object is updated in the tree many times 2010-07-18 00:07:27 +00:00
Vadim Kurland f71349678e fixed #1582 tree is not refreshed when new network objects are created in the newFirewallDialog 2010-07-15 17:09:25 +00:00
Vadim Kurland 8a28fa0984 trying to fix unit test instDialogCompileTest.cpp 2010-07-15 02:01:38 +00:00
Vadim Kurland b6d53c7298 fixed #1571 "Installer does not work if firewall object name
contains spaces". Installer should use escaping to make sure
file name with a space is correctly interpreted by the script
it runs on the firewall.
2010-07-14 23:22:49 +00:00
Vadim Kurland 73e1ee1f0d fixed #1544 "fwbuilder crashes during import of file with rtf
formatting data". The fix should prevent crashes in other cases
when import was unsuccessful.
2010-07-14 19:26:11 +00:00
Vadim Kurland b6260cae89 fixed SF bug 3027284 added input field for ssh timeout in the Installer tab of global prefs dialog. Still needs testing on windows 2010-07-12 02:31:41 +00:00
Vadim Kurland 4c2b0d4f09 fixed SF bug 3027272 2010-07-10 19:36:10 +00:00
Vadim Kurland f8918cbb9a more checks for printing from command line, See #1533 2010-07-03 16:02:24 +00:00
Vadim Kurland d48283c45e see #1541 fixed warning dialog grammar 2010-06-29 00:27:23 +00:00
Vadim Kurland beb7952eca * utils.cpp (parseCommandLine): See #1542 since now user can enter
differet command line parameters together with the path to ssh and
scp clients in the global Preferences dialog, we need to parse
these properly. This is especially important if file paths or
arguments contain white space characters. Unit tests are in
src/gui/unit_tests/parseCommandLineTest
2010-06-28 23:14:56 +00:00
Vadim Kurland 8f695ec044 refs #1346 button "inspect" should be enabled only if some files were actually produced during compilation 2010-06-28 16:34:53 +00:00
Vadim Kurland cbd11fb9be see #1346 fixed navigation and cleaned up instDialog wizard 2010-06-27 19:22:37 +00:00
Vadim Kurland af71f2d80b automatically configuring putty session fwb_session_with_keepalive on windows 2010-06-27 04:54:47 +00:00
Vadim Kurland f0c8bfa2e8 all instllation commands should be
on the single line
2010-06-27 04:20:39 +00:00
Vadim Kurland fc517354c8 assembling ssh and scp path and all command line parameters in FirewallInstaller instead of ssh wrapper code 2010-06-27 01:39:41 +00:00
Vadim Kurland 1bbeb0f04f SF bug 3020381: Line failure should abort remote firewall install. Using ssh keepalives to make ssh client detect disconnect. Currently works only with unix ssh clients 2010-06-27 00:47:00 +00:00
Vadim Kurland fe684e16c1 release notes and changelog records 2010-06-25 21:49:26 +00:00
Vadim Kurland afdc06d9f6 using QStringList class methods available in QT 4.3 2010-06-25 19:48:28 +00:00
Vadim Kurland 1994f02f4d * OSConfigurator_linux24::printVirtualAddressesForNatCommands:
fixed bug 3001228 "v4.0.0 iptables: NAT not creating interface
addresses". Iptables script generated by fwbuilder used to include
commands to configure virtual ip addresses for NAT only if option
"configure interfaces" was turned on. Expected behavior is to
generate these commands when option "Add virtual addresses for
NAT" is turned on regardless of the setting of the option
"configure interfaces".
2010-06-25 03:38:24 +00:00
Vadim Kurland f4c5090383 changelog records 2010-06-25 00:41:14 +00:00
Vadim Kurland 1ee9ca248d * PolicyCompiler_ipt.cpp (specialCaseWithFWInDstAndOutbound::processNext):
fixed #1523 "outbound ipv6 rule matching multicast ipv6 destination
is not generated". The rule with network object fe80::/10 in source
and ipv6 muticast ff00::/8 in destination did not produce correspondign
ip6tables command. The change affects other cases with rules using
broadcast or multicast objects that should be considered matching
the firewall object.
2010-06-17 23:58:17 +00:00
Vadim Kurland dadfcfbc18 changelog entry 2010-06-17 17:59:46 +00:00