Vadim Kurland
880cfb13fc
* PolicyCompiler_pf_writers.cpp (_printQueue): see #2390 Classify
...
does not generate "queue" string for rules created in V4.2.1.3538
This completes the fix for the bug #2385 .
2011-05-06 18:36:23 -07:00
Vadim Kurland
6fd2d6df2c
updated unit test files to the latest DTD version
2011-05-05 22:26:44 -07:00
Vadim Kurland
25c887595a
updated unit test files to the latest DTD version
2011-05-05 22:10:05 -07:00
Vadim Kurland
51774a5bf5
re-ran tests, checking in updated test files
2011-05-05 20:31:41 -07:00
Vadim Kurland
cb09818f44
build 3536
2011-05-03 11:35:06 -07:00
Vadim Kurland
350c40030e
* newFirewallDialog.cpp (finishClicked): see #2380 "Firewall
...
object is created in the middle of the "new firewall" wizard and
clicking Back creates two firewall objects". If user chose to
create new firewall object from a template and clicked Back after
choosing the template, the program actually created two firewall
objects but only one was visible in the tree.
2011-05-03 11:28:13 -07:00
Vadim Kurland
b9187f57ca
see #2376 need to recalculate the size of the column "Options"
2011-04-30 18:55:11 -07:00
Vadim Kurland
a1d70da445
build 3535
2011-04-30 12:57:12 -07:00
Vadim Kurland
32302739fd
see #2373 using different signal to call RuleSetView::updateAllColumnsSize() only once instead of doing it for each rule using object that changed
2011-04-30 12:48:47 -07:00
Vadim Kurland
7627a82cfe
see #2373 first fix for this problem
...
The change in UsageResolver
eliminates unnecessary scanning of all rule sets to check if the
affected rule set might be used as a branch. The program used to
scan the same objects many times.
.
2011-04-29 18:50:37 -07:00
Vadim Kurland
97ed9bf03a
fixes #2369 added release notes for 4.2.1
2011-04-29 13:13:44 -07:00
Vadim Kurland
2a00cea691
build 3534
2011-04-29 12:37:10 -07:00
Vadim Kurland
a62f914887
* iosaclAdvancedDialog.cpp (accept): fixes #2368 and SF bug
...
3294457 "External install script". External install script name
and arguments werent saved for IOS firewall objects.
2011-04-29 12:06:16 -07:00
Vadim Kurland
bb5abafe5b
* snmpNetworkDiscoveryWizard/ND_ProgressPage.h: fixes #2370 , #2371
...
"broken signals in network discovery wizard". Network discovery
wizard was not correctly initializased and did not work.
2011-04-29 11:49:06 -07:00
Vadim Kurland
1fe2f85c00
build 3533
2011-04-28 23:15:08 -07:00
Vadim Kurland
57a195538b
fixed SF bug 3169045 - problems with batch install; build 3532
2011-04-26 17:40:56 -07:00
Vadim Kurland
c63a347e80
more fixes for SF bug 3169045. Check if putty_session is not empty in addition to checking if maddr is not empty in instDialog::verifyManagementAddress(); added more debug print to help me trace it on windows
2011-04-26 16:38:37 -07:00
Vadim Kurland
103c06aec0
added changelog record for the latest fix
2011-04-20 10:48:53 -07:00
Vadim Kurland
15fca061ec
fixed bug (no #): "clear" commands were not added when option "generate only access-list, access-group, nat, static..." was in effect; also making sure "clear" commands for object-groups and ssh are not added when option "do not add clear commands" is on
2011-04-20 10:45:20 -07:00
Vadim Kurland
a46b7304d7
build 3529
2011-04-18 22:37:42 -07:00
Vadim Kurland
37b8f33260
need to remove .bak file before renaming data file in fwbedit, otherwise operation fails on windows
2011-04-18 22:31:30 -07:00
Vadim Kurland
3acb1c3787
minor fixes
2011-04-18 08:31:54 -07:00
Vadim Kurland
28072563fe
minor fixes
2011-04-18 08:30:49 -07:00
Vadim Kurland
3dbfe5508b
removed debug print
2011-04-17 17:42:05 -07:00
Vadim Kurland
019eba37ba
gui should find correct reelase notes file
2011-04-17 17:36:28 -07:00
Vadim Kurland
25633190e0
release notes for 4.2.0
2011-04-17 16:50:26 -07:00
Vadim Kurland
5e1e377c6a
* fwbedit.cpp (main): added command line switch "-d" to function
...
"import" in fwbedit. This switch activates object deduplication
on import.
2011-04-17 12:30:31 -07:00
Vadim Kurland
b3dbf7ce48
stripping binaries
2011-04-15 20:52:55 -07:00
Vadim Kurland
ff370be984
build fwbedit last because it depends on libgui at this time
2011-04-15 19:49:37 -07:00
Vadim Kurland
18256f52ef
see #2275 fixed parser to make it understand multiport matches with negation
2011-04-15 18:49:31 -07:00
Vadim Kurland
94379ed9b5
* fwbedit.cpp (main): see #2328 "Add ability to run firewall import
...
from the command line". This has been implemented as a new function
"import" in fwbedit. See man page fwbedit(1) and "fwbuilder -h" for
more details.
2011-04-15 18:34:53 -07:00
Vadim Kurland
fbf7f4e6da
see #2275 fixed parser to match a combination of any number of states separated by comma
2011-04-15 16:58:15 -07:00
Vadim Kurland
ef3485df4a
see #2354 fixed parser to recognize top level "ip" commands that we do not use but that should not cause parser error
2011-04-15 16:51:15 -07:00
Vadim Kurland
6d5d1a9079
see #2353 fixed parser to parse access list rules matching icmp and service object-group
2011-04-15 16:35:31 -07:00
Vadim Kurland
c51a8123c8
see #2352 test case
2011-04-15 16:17:13 -07:00
Vadim Kurland
7260649b16
see #2352 fixed parser to be able to handle empty access list declarations (where access list is declared but has no rules)
2011-04-15 16:13:49 -07:00
Vadim Kurland
dbdfb93905
refactoring in preparation for command line import in fwbedit
2011-04-15 14:28:03 -07:00
Vadim Kurland
db80629918
see #2264 added test case for the "short" script format
2011-04-15 12:49:07 -07:00
Vadim Kurland
26484829e2
see #2342 parser will now recognize command "management-only" but not act on it in any way; this removes parser error
2011-04-15 12:39:46 -07:00
Vadim Kurland
6185a88ceb
* iptables.g (multiport_tcp_udp_port_spec): see #2245 fixed bug in
...
parser for iptables that prevented correct import of iptables rules
using module "multiport" with port range matches.
2011-04-15 12:27:43 -07:00
Vadim Kurland
14258139ee
* CompilerDriver_pix_run.cpp (pixSecurityLevelChecks): see #2351
...
Security levels of ASA and FWSM interfaces do not have to be
unique. Removed check that enforced this.
2011-04-14 18:58:36 -07:00
Vadim Kurland
dbb1e8ab57
see #2295 test for fwsm import
2011-04-14 18:54:22 -07:00
Vadim Kurland
8693c09eb4
see #2295 correctly setting platform and host OS for imported FWSM configs
2011-04-14 18:49:59 -07:00
Vadim Kurland
1bbe7fcac8
* IPTImporterRun.cpp (run): see #2275 removed debug print
2011-04-14 18:28:36 -07:00
Vadim Kurland
838116ab50
* IPTImporterRun.cpp (run): see #2275 Importer for iptables now
...
correctly handles both "intrapositioned" ("-s ! address") and
"extrapositioned" ("! -s address") negation.
2011-04-14 18:19:54 -07:00
Vadim Kurland
17263fb3ff
see #2349
...
Import hostname is used for interface names even if the firewall name is changed
2011-04-14 16:51:47 -07:00
Vadim Kurland
0a50274c28
see #2295 added FWSM version 3.2
2011-04-14 16:34:38 -07:00
Vadim Kurland
9fd0a00218
see #2347 attach temporary acl to all interfaces
2011-04-14 16:06:21 -07:00
Vadim Kurland
1223e94ebf
* platform/pix.xml: see #2348 : "Accounting action is not valid for
...
FWSM platform". Actions "Accounting" and "Reject" should not
appear in the drop-down list of actions in the GUI if platform is
pix or fwsm.
2011-04-14 12:27:21 -07:00
Vadim Kurland
59f40e5d71
* PolicyCompiler_pix.cpp (printPreambleCommands): see #2347 "FWSM
...
move up the "access-list mode auto-commit" command". Command that
configures access list commit mode should be issued before any
commands that clear and configure access lists. Also in this
change moving commands that set up temporary access list to the
top of the script.
2011-04-14 12:11:15 -07:00
Vadim Kurland
3c0554c003
* PolicyCompiler_pix.cpp (printClearCommands): see #2322 If this
...
is FWSM and if manual commit mode is used, need to commit after
clearing ACLs before we clear object groups.
2011-04-14 11:47:05 -07:00
Vadim Kurland
41e1255101
fixes #2346 increase width of column "Comment" by 10 pixels
2011-04-13 20:45:08 -07:00
Vadim Kurland
1a9eda04a9
see #2338 updated unit test files
2011-04-13 20:36:18 -07:00
Vadim Kurland
d64b12221a
* PolicyCompiler_PrintRule.cpp (_printTarget): see #2235 "Modified
...
rule action for Continue". Rules with action "Continue" should
translate into iptables commands without "-j TARGET" parameter. If
such rule also has logging enabled, it should use target "-j LOG"
instead of generating additional chain.
2011-04-11 19:35:42 -07:00
Vadim Kurland
b49e76a052
* IPTImporter.cpp (pushPolicyRule): see #2206 Iptables commands with
...
no "-j TARGET" parameter should be imported using action "Continue".
2011-04-11 18:58:34 -07:00
Vadim Kurland
b2e9445cec
iptables parser w/o tracing
2011-04-11 18:53:52 -07:00
Vadim Kurland
e9ffe7b67b
* iptables.g (comment): see #2336 Importer for iptables recognizes
...
version stored in the top comment by iptables-save and sets
version in the firewall object it creates.
2011-04-11 18:17:48 -07:00
Vadim Kurland
aa4c661395
* utils.cpp (expand_interface_with_phys_address): see #2324 "NAT +
...
MAC-matching rules not generated properly". Iptables NAT rules
matching a group of host objects with both IP and MAC addresses each
in "Original Source" were not generated properly.
2011-04-10 18:58:29 -07:00
Vadim Kurland
f366e2dc66
* PolicyCompiler_PrintRule.cpp (_printOptionalGlobalRules): SF bug
...
3178186 "Add ND/NS allow rules for the FORWARD chain". Rules that are
added automatically to ipv6 Linux firewall to permit neighbor discovery
packets should be also added to the FORWARD chain if the firewall is
a bridge.
see #2323
2011-04-10 17:58:32 -07:00
Vadim Kurland
cac256054f
* ObjectManipulator_create_new.cpp (actuallyCreateObject): see #2229
...
"Multiple new objects with the same name". The GUI should automatically
choose unique object names for new objects.
2011-04-10 17:28:46 -07:00
Vadim Kurland
8b0febcb23
* platforms.cpp (setInterfaceTypes): see #2224 "FreeBSD - Bridge
...
interfaces with the name vlan<xx> dont show as Bridge Port
Interfaces". This actually applies to all OS where we support vlan
and bridge interfaces. Fwbuilder GUI should allow the user to set
subinterface type to both "ethernet" and "vlan" when its parent
interface has type "bridge". Setting subinterface type to
"ethernet" makes it bridge port, while setting the type to "vlan"
signals policy compiler that it should generate code to configure
real vlan interface. If the name of the subinterface does not
include the name of the parent, such as "vlan101", or when the
name does not match vlan ID, such as "vlan8101", global
preferences option "Verify interface names and autoconfigure their
parameters..." should turned off. The option is located in the
Preferences dialog, tab "Objects".
2011-04-10 17:12:05 -07:00
Vadim Kurland
3333ea173f
see #2288 Cisco ASA firewalls can be configured with invalid log interval set max allowed value of logging interval to 600
2011-04-08 19:08:46 -07:00
Vadim Kurland
0149bd0db5
* FWBSettings.cpp (init): fixed bug (no #): "Show text
...
description in rule columns" does not persist across sessions
fixes #2287
2011-04-08 19:06:14 -07:00
Vadim Kurland
7156094f89
* clusterMembersDialog.cpp (createMember): see SF bug 3211769
...
"Member interfaces not sorted". Sorting interfaces by name in the
dialog where user adds them to the cluster member group.
see #2325
2011-04-08 18:50:58 -07:00
Vadim Kurland
57b6dbdb00
see #2320 enable dialog to manage member interfaces
2011-04-08 18:44:50 -07:00
Vadim Kurland
eb141a88e2
see #2320 removing copies of cluster intrfaces
2011-04-08 18:40:52 -07:00
Vadim Kurland
578f7d771d
* os/ios.xml: see #2330 "Crash when creating a cluster of IOS
...
router firewalls". Added support for basic IOS router clusters.
No failover protocol support at this time, but the cluster can be
configured with protocol "None" and fwbuilder will do address
substitutions at compile time.
2011-04-08 18:31:41 -07:00
Vadim Kurland
e129b75f87
see #2331 fixed tab order in instOptions dialog
2011-04-08 18:19:34 -07:00
Vadim Kurland
126b561e32
* PolicyCompiler_cisco.cpp (processNext): see #2308 "ASA rules
...
with service set to "http" and destination set to asa firewall
object should generate different command syntax". Policy rules
that have firewall object in Destination and http object in
Service now generate "http" commands. This is similar to how
fwbuilder generates "ssh", "telnet" and "icmp" commands to permit
corresponding services to the firewall itself.
2011-04-08 18:08:56 -07:00
Vadim Kurland
7d7e5e7c47
mismatching protocols in src and dst should be treated as an error but not abort. See #2329
2011-04-08 16:53:57 -07:00
Vadim Kurland
59d3832166
* pix.g (static_starts_with_tcp_udp): more fixes for import of
...
PIX/ASA "static" command in different variations. See #2334
2011-04-08 16:45:24 -07:00
Vadim Kurland
1359e7bd2c
* ObjectEditor.cpp (changed): see #2335 "GUI switches between data
...
files upon closing editor panel". If user opened two data files in
the GUI and was in the process of editing objects in one of them,
the GUI would flip to the other file under certin circumstances.
2011-04-08 16:14:16 -07:00
Vadim Kurland
25f1ecb9e3
rolling back change in the installer, this is premature at this time and unnecessary
2011-04-08 12:54:54 -07:00
Vadim Kurland
7e5de74f39
added installation configlets for fwsm
2011-04-08 11:47:44 -07:00
Vadim Kurland
28b95bb3b3
register newly created anonymous objects for mirrored services
2011-04-07 21:12:12 -07:00
Vadim Kurland
390d56601a
* PIXImporterNat.cpp (buildDNATRule): resolved several problems
...
with import of "static" commands that use access list that matches
source or destination tcp/udp ports. See #2326 , #2327
2011-04-07 20:55:53 -07:00
Vadim Kurland
c3a922b4a3
see #2295 fixes for FWSM
2011-04-07 19:25:44 -07:00
Vadim Kurland
c1194cced1
simpler lexer configuration to make sure word "object" that appears as a substring in named object name or named address is not interpreted as token OBJECT
2011-04-07 18:21:22 -07:00
Vadim Kurland
4c89a6bc80
see #2167 parser should not be confused when "name" appears as a substring in object names or named addresses
2011-04-07 18:15:41 -07:00
Vadim Kurland
41a2ad2dcc
* PIXImporter.cpp (fixServiceObjectUsedForBothSrcAndDstPorts):
...
see #2265 "ASA 8.3 acl import: access-list commands using two
named objects or object-groups", see #2290 "Access lists that
include mix of service objects and inline service definitions are
not properly imported". To import access-list command that matches
both source and destination tcp/udp ports and uses object-group in
either match I should create a new service group with a collection
of TCP or UDP service objects matching all combinations of source
and destination port ranges defined by the rule. This should work
when one or both matches use object-group in combination with
inline port match.
2011-04-07 18:06:18 -07:00
Vadim Kurland
95c6c63818
see #2167 making sure names are replaced with addresses only as standalone words and not substrings
2011-04-07 16:03:52 -07:00
Vadim Kurland
bf753da2de
bugfix: setting configlet variable firewall_name right; also small patch to remove warnings that appear when uint128.h is compiled on 64 bit systems
2011-04-07 14:48:55 -07:00
Vadim Kurland
60ba676fcc
always include named objects and object groups in the generated PIX/FWSM config even when checkbox "generate only access-lists" (option "short_sctipt") is turned on
2011-04-07 14:42:42 -07:00
Vadim Kurland
10400f4737
* PIXImporter.cpp (pushPolicyRule): see #2297 Added warning when
...
importer enounters access-list command that matches tcp or udp
ports with "neq" port operators in both source and
destination. This configuration is not supported by import at this
time.
2011-04-07 14:05:02 -07:00
Vadim Kurland
30ee6d2f12
* PIXImporterNat.cpp (buildSNATRule): see #2319 "Imported nat
...
rules with multi-line access-lists have only the first entry"
2011-04-07 13:50:01 -07:00
Vadim Kurland
3af17b4404
* PIXImporterRun.cpp (run): see #2167 Implemented import of
...
"names" and "name" commands in PIX/ASA configs.
2011-04-07 12:53:31 -07:00
Vadim Kurland
3cb9ee856c
using path "disk:" on FWSM to place generated config
2011-04-07 12:09:09 -07:00
Vadim Kurland
4d6302a4cc
* CompilerDriver_pix_run.cpp (pixNetworkZoneChecks): see SF bug
...
3213019 "FWSM Network zone and IPv6". Currently we do not support
ipv6 with PIX/ASA and FWSM. If user creates a group to be used as
network zone object and places ipv6 address in it, this address
should be ignored while compiling the policy but this should not
be an error.
2011-04-07 11:05:46 -07:00
Vadim Kurland
c32da04d51
* FirewallInstaller.cpp (executeExternalInstallScript): see SF bug
...
3212988 "external script makes getopt difficult". User-defined
parameters for the external script moved to the end of the command
line.
2011-04-07 10:41:06 -07:00
Vadim Kurland
e541d4b1a1
updated activation path for FWSM; build 3519
2011-04-07 10:20:20 -07:00
Vadim Kurland
fdd5db5ded
fixes #2317 fixed linking of PIXImport unit test
2011-04-05 21:23:01 -07:00
Vadim Kurland
b1ad1cbec1
fixes #2299 improvements in the log format of iptables and iosacl importers
2011-04-05 21:11:37 -07:00
Vadim Kurland
6f79c1d644
* pix.g (static_command_common_last_parameters): see #2314 "Import
...
of static NAT statements drops netmask value and uses host
instead". "Netmask" parameter of a "static" command applies to
the real address.
2011-04-05 20:15:02 -07:00
Vadim Kurland
d5f95e0f2a
* PIXImporterNat.cpp (buildDNATRule): see #2313 "NAT with
...
access-list destination address and original service not set".
"Nat" and "static" commands that use access-list should import all
components of the access-list command (source, destination and
service/protocol).
2011-04-05 19:59:13 -07:00
Vadim Kurland
e3383349b0
see #2312 During nat import extraneous address objects are created
2011-04-05 19:35:45 -07:00
Vadim Kurland
55da233d22
* PIXImporterNat.cpp (buildSNATRule): see #2310 "Imported global /
...
nat rule has wrong interface defined". Importer mixed up inbound
and outbound interfaces in NAT commands created from combination
of "global" and "nat" PIX/ASA commands.
2011-04-05 19:06:35 -07:00
Vadim Kurland
6fdbb3ecce
using consistent warning announcement; updated unit test files see #2315
2011-04-05 18:59:56 -07:00
Vadim Kurland
e6e8455700
* pix.g (nat_new_top_level_command): since import of ASA8.3
...
"new" nat commands is not implemented yet, importer should issue
a warning when such command is encountered. See #2315
2011-04-05 18:55:53 -07:00
Vadim Kurland
327183c1f2
* FWObject.cpp (insert_before): see #2171 "Undoing delete of rule
...
ends up with rules being created with duplicate rule
numbers". Also see #2172 "Crash when deleting rule - related to
#2171 ". When user deleted the last rule in a rule set, then used
Undo to restore it, the program lost track of rules in the rule
set and became unstable.
2011-04-01 19:23:16 -07:00
Vadim Kurland
f6f28b983c
see #2225 the GUI should open first non-standard library when user cereates new file
2011-04-01 18:57:24 -07:00