Vadim Kurland
5c25bfb711
* IPTImporter.cpp (pushPolicyRule): see #2189 Policy importer
...
warnings and errors now include line numbers to help find relevant
lines in the original configuration file.
2011-03-06 13:16:11 -08:00
Vadim Kurland
cac6101e0f
fixes #2188 protocol "gre" could not be resolved to ip protocol number on Winbdows; implemented wrappers for getprotobyname() and getservbyname(), including protocol and tcp/udp service name resolution for cisco IOS and PIX; fixed unit tests for the importer
2011-03-06 12:47:20 -08:00
Vadim Kurland
9dbb444a51
fixes #2187 iptables parser error formatting problem
2011-03-05 23:49:47 -08:00
Vadim Kurland
bc0b69ae71
fixes #2148 ASA Import - name of created firewall is hostname
2011-03-05 23:41:25 -08:00
Vadim Kurland
6a331a7642
bugfix: an error in regex list that should match pf.conf made it match all kinds of configs
2011-03-05 22:40:02 -08:00
Vadim Kurland
a7dfe07409
see #2185 rearranged #include to make sure I include snmp.h only where it is really needed and always after all Qt headers
2011-03-05 21:33:53 -08:00
Vadim Kurland
9bf118bc12
trying to resolve build problem on windows "/usr/include/net-snmp/*"
2011-03-05 18:52:19 -08:00
Vadim Kurland
1100f1842a
still trying to fix windows build
2011-03-05 16:04:09 -08:00
Vadim Kurland
7d962bb1ce
see #2176 autodetect pf.conf format in importer
2011-03-05 15:55:46 -08:00
Vadim Kurland
d82b81682e
fixes #2183 count errors and warnings generated by the importer and show the numbers in the progress page of the wizard
2011-03-05 15:48:02 -08:00
Vadim Kurland
633b65f9d7
see #2174 warning for IOS, see #2175 warning for iptables
2011-03-05 15:38:20 -08:00
Vadim Kurland
538732c4ce
fixes #2178 set platform and host os for FWSM; fixes #2156 After import the firewall should be opened in object tree
2011-03-05 15:32:53 -08:00
Vadim Kurland
4596a6cd53
fixes #2158 iptables import log is poorly formatted
2011-03-05 15:10:36 -08:00
Vadim Kurland
4b4febd253
fixes #2180 hitting Cancel while importer is working should not wait for it to complete
2011-03-05 14:54:07 -08:00
Vadim Kurland
85afa6dc8e
see #2162 renamed menu item File / Import Firewall; see #2179 button Finish should be disabled while importer is still running
2011-03-05 11:06:22 -08:00
Vadim Kurland
834dd22e25
trying to fix windows build that got broken when I refactored snmp discovery into a separate wixard
2011-03-04 23:47:10 -08:00
Vadim Kurland
08265c5f0f
minor clean up, removed unused function in Tools; trying to get rid of warnings about C4290 on windows; trying to fix windows build that got broken when I refactored snmp discovery into a separate wixard
2011-03-04 23:13:47 -08:00
Vadim Kurland
2e65d946da
see #2161 import wizard finished
2011-03-04 18:06:54 -08:00
Vadim Kurland
0ed86de82a
new policy import wizard; see #2161 - automatic detection of firewall platform and host name works
2011-03-04 13:34:45 -08:00
Vadim Kurland
0516ac43e5
build 3493
2011-03-03 21:59:55 -08:00
Vadim Kurland
56ad849d50
see #2163 creting objects discovered via snmp; snmp network discovery wizard is now functional
2011-03-03 21:55:10 -08:00
Vadim Kurland
c21214c6a2
see #2163 passing data from the progress page to pages where user chooses networks and objects
2011-03-03 19:43:23 -08:00
Vadim Kurland
4b88c05cd6
see #2163 making sure crawler object is properly destroyed and recreated when user navigates back and forth within the wizard; also properly destroying the object after it is finished when user closes the wizard
2011-03-03 18:08:30 -08:00
Vadim Kurland
68a5bc7ef8
see #2163 pages that set up snmp crawler and crawler background process with progress log now work. Using QThread to run background process.
2011-03-03 14:05:28 -08:00
Vadim Kurland
2eed260387
see #2163 first page of snmp discovery wizard works (page "setup")
2011-03-02 21:29:45 -08:00
Vadim Kurland
3b2307b21c
fixing build problems on windows, still messing around with -I
2011-03-01 21:47:50 -08:00
Vadim Kurland
a164655216
fixing build problems on windows: added "-I .." to make #include work inside wizard subdirectories
2011-03-01 21:11:58 -08:00
Vadim Kurland
485a681bb0
fixing build problems on windows
2011-03-01 19:21:15 -08:00
Vadim Kurland
21fe9b7117
fixing build problems on windows
2011-03-01 18:56:12 -08:00
Vadim Kurland
fd307f2320
added #include "ObjectDescriptor.h"
2011-03-01 18:01:46 -08:00
Vadim Kurland
bea625d3b4
see #2163 remove #include "discoveryDruid.h" since it is not used anymore
2011-03-01 17:46:20 -08:00
Vadim Kurland
a0eb7989ef
build 3491
2011-03-01 17:20:44 -08:00
Vadim Kurland
bebfd9fbff
see #2163 code that imports addresses from a file in /etc/hosts format moved to its own wizard; using QWizard and QWizardPage classes with correct implementation of page sequencing and validation; old discovery druid has been disabled
2011-03-01 17:14:26 -08:00
Vadim Kurland
7e312722dc
added test case for a group of hosts with mac addresses in a nat rule (SF bug should be opened later); re-ran tests
2011-02-27 22:37:16 -08:00
Vadim Kurland
19ce284f21
see #2156 select new firewall in tree, expand subtree and open firewall object in the editor after successful import
2011-02-27 13:30:22 -08:00
Vadim Kurland
30db079476
fixes #2159 ; also using macros for discovery druid page numbers
2011-02-27 12:54:08 -08:00
Vadim Kurland
689e54005d
see #2160 "Installer reports error "Generated script file
...
<firewall>.fw not found."". The problem was intorduced earlier
while fixing #2047
2011-02-27 12:39:22 -08:00
Vadim Kurland
73500e15c5
see #2153 Wizard shows
...
additional page when user imports PIX/ASA config. This page
explains concept of network zones and offers UI to let them choose
network objects or groups as a network zone of each interface.
2011-02-26 20:45:57 -08:00
Vadim Kurland
849482d15d
see #2153 added page with network zones explanation and widget; not functional yet but wizard navigates to it
2011-02-26 20:26:51 -08:00
Vadim Kurland
ff53d6bd07
see #2145 Vlan interfaces discovered in the process of PIX configuration
...
import should be created as subinterfaces of the corresponding
parent with correct interface type and vlan id.
2011-02-26 12:17:23 -08:00
Vadim Kurland
1714e27233
see #2146 Issue a warning when
...
parser encounters "standby" parameter in an interface
configuration. We do not support import of PIX failover
configuration at this time.
2011-02-26 11:09:38 -08:00
Vadim Kurland
1258c4580e
new build 3488; see #2147 "ASA Import - some versions are not detected correctly". SEtting version in the created firewall object to the best match of the version found in imported config
2011-02-26 10:45:40 -08:00
Vadim Kurland
59562d852c
see #87 tested parser on pix6, pix7 and asa8 configs, making sure it parses different interface configurations correctly
2011-02-25 20:40:04 -08:00
Vadim Kurland
dfb9983a7c
see #87 fixed unit tests
2011-02-25 17:52:32 -08:00
Vadim Kurland
3f3a9030b9
see #87 changing explanation text in discovery druid page when user selects PIX; using #define to refer to import platform choices; better fix for the crash on open of discover druid (see #2144 )
2011-02-25 17:34:15 -08:00
Vadim Kurland
ef575257f1
Merge branch 'development' into pix_import
2011-02-25 17:15:11 -08:00
Vadim Kurland
e0ac139d78
fixes #2144 GUI crash when user clicks "Import firewall configuration" shortcut button; new build 3487
2011-02-25 17:14:53 -08:00
Vadim Kurland
db4d501ece
see #87 import of interfaces for pix6,7 and 8 works. PArsing inetrface name, label, security level, address
2011-02-25 16:43:25 -08:00
Vadim Kurland
e799b24496
see #87 minimal grammar, importer classes
2011-02-25 14:02:32 -08:00
Vadim Kurland
c1eff2c7f9
renamed class AddressTableEditor to TextFileEditor
2011-02-24 11:16:54 -08:00
Vadim Kurland
d841231a28
* AddressTableDialog.cpp (browse): see #2140 "Attempting to create
...
new Address Table file results in read-only error". Implemented
support for the workflow when user wants to create the file used
to feed addresses to the AddressTable object.
2011-02-24 11:10:52 -08:00
Vadim Kurland
da776105be
see #2139 show warning dialog and offer choice: open file for veiwing read-only or cancel
2011-02-24 10:19:46 -08:00
Vadim Kurland
25fa09d626
see #2135 Editing table objects
2011-02-23 19:28:22 -08:00
Vadim Kurland
222ff26e14
fixed unit test
2011-02-22 16:49:09 -08:00
Vadim Kurland
1aa38dc375
fixed unit test
2011-02-22 16:32:27 -08:00
Vadim Kurland
e84751e95c
see #2008 compiler avoids INPUT/OUTPUT chain if interface in the rule column "Interface" is a bridge port and firewall is bridging firewall (which means we are going to use --physdev-in or --physdev-out option for this rule)
2011-02-21 17:06:43 -08:00
Vadim Kurland
8ee59ebbf8
* newFirewallDialog.cpp (monitor): see #2126 Using snmp sysDescr
...
OID to guess version of the new firewall when it is created using
snmp polling.
2011-02-21 16:34:29 -08:00
Vadim Kurland
cdbd1e35c3
see #1990 newly created PIX/ASA firewalls now have "generate outbound acl" option turned on by default
2011-02-21 15:11:47 -08:00
Vadim Kurland
b42fe3e802
see #1678 When creating a firewall from template it appears that a default template is selected
2011-02-21 13:52:09 -08:00
Vadim Kurland
cc509571f3
upgraded templartes.xml
2011-02-21 13:42:44 -08:00
Vadim Kurland
264d6bc3ee
see #1971 dialog does not let user enter range end address lower than range start address
2011-02-21 13:35:13 -08:00
Vadim Kurland
0c1031aebf
see #2085 modify platform name for Cisco IOS ACL
2011-02-21 13:21:41 -08:00
Vadim Kurland
886cfbea86
see #2113 removed unused function guessSecurityLevel (the second form that takes list of InterfaceData)
2011-02-21 13:21:17 -08:00
Vadim Kurland
49e79663a8
see #2113 looks like I need to support at least three patterns to cver different versions of PIX and ASA software. Moving routines that guess label and security level to platforms.cpp so I can use QString
2011-02-21 13:04:11 -08:00
Vadim Kurland
f909d073eb
see #2113 added pattern for ASA interface descriptions which is different from PIX interface descirptions
2011-02-21 12:20:21 -08:00
Vadim Kurland
966533a672
see #2113 added pattern for ASA interface descriptions which is different from PIX interface descirptions
2011-02-21 11:33:25 -08:00
Vadim Kurland
56f81407f1
fixes #2124 some error messages get multiplied when compiler splits rules
2011-02-20 21:32:58 -08:00
Vadim Kurland
2b342aa67d
see #2057 detection of loops in branching rules ; see #2124 some error messages appeared multiple times in generated script
2011-02-20 20:12:18 -08:00
Vadim Kurland
344010c873
see #1920 Setting host interface to unnumbered after it has been assigned IP address doesnt have desired effect
2011-02-20 18:11:16 -08:00
Vadim Kurland
e9e7f89cf2
see #1920 Setting host interface to unnumbered after it has been assigned IP address doesnt have desired effect
2011-02-20 18:03:21 -08:00
Vadim Kurland
37ab989922
see #1877 added test case for this
2011-02-20 17:45:46 -08:00
Vadim Kurland
f817ddfe24
see #133 test case for SF feature request 1954286
2011-02-20 17:34:36 -08:00
Vadim Kurland
6f5f1ac075
fixes #153 Deprecate Rule::getInterfaceStr() fixes #2123 deprecate rule processor convertInterfaceIdToStr
2011-02-20 17:27:24 -08:00
Vadim Kurland
926db9b942
see #153 deprecating getInterfaceStr: eliminated use of this function in policy compiler for PIX and IOS ACL
2011-02-20 16:11:29 -08:00
Vadim Kurland
c272997b6b
see #2098 support for interfaces in PIX/ASA NAT rules; see #153 deprecating Rule::getInterfaceStr()
2011-02-19 19:15:54 -08:00
Vadim Kurland
4136d63957
see #2098 support for interfaces in PIX/ASA NAT rules; see #153 deprecating Rule::getInterfaceStr()
2011-02-19 19:13:01 -08:00
Vadim Kurland
ccbe413c22
upgraded regression tests data fles
2011-02-19 16:29:43 -08:00
Vadim Kurland
ad5a140932
see #2087 disabling "reboot" checkbox when "test run" is unchecked
2011-02-19 16:21:04 -08:00
Vadim Kurland
73c31a589f
see #2117 CARP interfaces in cluster that use VLAN interaces have no interface set to MASTER
2011-02-19 16:17:25 -08:00
Vadim Kurland
aea53d35eb
see #2116 "When CARP interface IP address cant be assigned error or warning should appear". Script should abort if command trying to add an ip address to an interface fails
2011-02-19 15:33:30 -08:00
Vadim Kurland
3a871d5f06
getting rid of sprintf where I can
2011-02-18 22:25:52 -08:00
Vadim Kurland
a8b65e6506
getting rid of sprintf where I can
2011-02-18 22:09:50 -08:00
Vadim Kurland
66681b9695
see #153 #133 got rid of getInterfaceStr and getInterfaceId in policy and nat compilers for PF
2011-02-18 18:54:21 -08:00
Vadim Kurland
2542b082f3
see #153 #2097 got rid of getInterfaceStr and getInterfaceId in policy and nat compilers for iptables
2011-02-18 18:48:16 -08:00
Vadim Kurland
df39b1d0fd
new build 3481
2011-02-17 19:38:26 -08:00
Vadim Kurland
8c78deb9b9
fixes #2114 invalid XML is created when interface object is duplicated
2011-02-17 18:50:33 -08:00
Vadim Kurland
faece9e40c
see #2097 more test cases with negation and vlan interfaces
2011-02-17 18:39:17 -08:00
Vadim Kurland
698286100a
see #133 #2097 skip bridge ports while doing negation in interface column, unless firewall is a bridge
2011-02-17 18:33:44 -08:00
Vadim Kurland
581ccdc68e
see #2097 #133 additional test cases
2011-02-17 18:01:45 -08:00
Vadim Kurland
6f30bc3446
* NATCompiler_ipt.cpp (processNext): see #2097 #133 "support for
...
inbound and outbound interface columns in iptables NAT
rules". This also addresses SF feature requests 1954286 "DNAT with
interface as condition not possible" and 621023 "manipulating
interface in NAT rule".
2011-02-17 17:48:04 -08:00
Vadim Kurland
d0ae7bac01
* NATCompiler_ipt.cpp (processNext): see #2097 #133 "support for
...
inbound and outbound interface columns in iptables NAT
rules". This also addresses SF feature requests 1954286 "DNAT with
interface as condition not possible" and 621023 "manipulating
interface in NAT rule".
2011-02-17 17:47:42 -08:00
Vadim Kurland
5162212073
see #2097 #133 : no need to replace cluster interfaces with member interfaces in NATCompiler_pf::AssignInterface::processNext() since it was already done in replaceClusterInterfaceInItfOutb
2011-02-17 15:36:28 -08:00
Vadim Kurland
cf17bb995c
see #2097 showing "interface" columns in iptables NAT ruels
2011-02-17 15:27:37 -08:00
Vadim Kurland
f8b668e691
see #2101 setting master advskew to 10 and default advskew to 20
2011-02-17 15:02:45 -08:00
Vadim Kurland
b116a2ac23
see #2110 VLAN interfaces are disabled in new cluster configuration
2011-02-17 14:54:56 -08:00
Vadim Kurland
91f16fb85a
documenting decision to stop making builds on Hardy. See #2107
2011-02-17 14:36:17 -08:00
Vadim Kurland
fdb899bdd2
* NATCompiler_ipf.cpp (processNext): see #133 , fixes #2108 making
...
nat compiler for ipfilter work with interface column, however the
column is not exposed to the user. Compiler behavior should be
backwards compatible with older versions of fwbuilder.
2011-02-17 12:06:50 -08:00
Vadim Kurland
100dca74bb
* NATCompiler_pf.cpp (processNext): see #133 . MErged code from the
...
branch, running tests. Making sure rules that have firewall
object in ODst and interface columnblank end up with rdr command
without "on interface" clause as before.
2011-02-17 11:50:14 -08:00
Vadim Kurland
ee2204086e
new build 3479a
2011-02-16 20:03:44 -08:00
Vadim Kurland
c042430cb2
merged from branch development; see #2095 "Support for interface groups in "nat" and "rdr" rules", see #2096 "support for negation in "Interface" column of PF NAT rules"
2011-02-16 19:55:07 -08:00