firewall
2013-02-10 Mark WoodingNew host `mango'.
2013-02-09 Mark Woodingclassify.m4: Hook the INPUT and FORWARD chains, not...
2013-02-09 Mark Woodingibanez.m4: Open an explicit hole for `udpkey'.
2013-02-09 Mark Woodinglocal.m4: Yet more explicit networks for asymmetric...
2013-01-26 Mark Woodinglocal.m4: New satellite network `binswood'.
2013-01-26 Mark Woodinglocal.m4: Make the net-class policies easier to read.
2013-01-26 Mark Woodinglocal.m4: Nothing should forward via `iodine'.
2013-01-26 Mark Woodingfunctions.m4, local.m4: Rename `forwards' to `via'.
2013-01-13 Mark WoodingNew host `orange'.
2013-01-13 Mark Woodingibanez.m4, vampire.m4: Provide NTP service to untrusted...
2013-01-08 Mark Woodingbookends.m4: Better check for bridging.
2012-12-29 Mark Woodingstratocaster.m4: Provide rsync service.
2012-12-28 Mark Wooding{roadstar,jem,telecaster,stratocaster}.m4: Move Git...
2012-12-28 Mark Woodingartist.m4: Moved the `rawk' server to artist.
2012-12-15 Mark Woodingjazz.m4, local.m4: Make jazz be a TrIPE endpoint.
2012-12-14 Mark Woodingnumbers.m4: Add port number for IRC.
2012-12-13 Mark WoodingMakefile: If the user overrides HOSTS, don't install...
2012-12-13 Mark Woodinglocal.m4: Add a prose commentary on address allocation.
2012-12-11 Mark Woodingfunctions.m4: Correctly clear `to' network field in...
2012-12-11 Mark Woodingclassify.m4: Dispatch on destination addresses to corre...
2012-12-11 Mark Woodingclassify.m4: Classify individual host routes correctly.
2012-12-11 Mark Woodingclassify.m4: Clean up interface map tracing.
2012-12-11 Mark Woodingfunctions.m4: Fix up commentary for `matchnets'.
2012-12-11 Mark Woodinglocal.m4, jazz.m4: Move iodine endpoint to jazz.
2012-12-11 Mark Woodingnumbers.m4, vampire.m4: Expose print server to local...
2012-10-14 Mark Woodingradius.m4: Allow external servers to contact the identd.
2012-10-14 Mark Woodinglocal.m4, radius.m4: radius is now the host gateway...
2012-09-12 Mark Woodinglocal.m4: artist should expect untrusted source addrs...
2012-09-12 Mark Woodinglocal.m4: Track VLAN renumbering in vampire's interface...
2012-06-08 Mark WoodingRate limiting for incoming DNS queries over UDP.
2012-06-08 Mark Woodingradius.m4: Handy ipset hook for ad-hoc safe/unstrusted...
2012-06-08 Mark Woodinglocal.m4: Refactor common SSH permission between safe...
2012-05-03 Mark Woodinglocal.m4: Packets can be routed over the safe network.
2012-04-25 Mark Woodinglocal.m4: Add the colocated servers to the VPN.
2012-04-23 Mark Woodinglocal.m4: Untrusted source addresses appear on the...
2012-04-23 Mark Woodingbookends.m4: Allow redirects to (non-routing) hosts.
2012-04-20 Mark WoodingConfiguration for new colocated virtual servers.
2012-04-20 Mark Woodinglocal.m4: More interfaces for artist.
2012-04-20 Mark Woodinglocal.m4: Default addresses reach the IPv6 tunnel inter...
2012-04-20 Mark Woodingjem.m4, artist.m4: Allow answers to DNS queries.
2012-04-20 Mark Woodingradius.m4: Load NAT helpers (from d119795).
2012-04-20 Mark Woodingbookends.m4: Configure IPv6 router advertisement stuff.
2012-04-20 Mark Woodingfunctions.m4, local.m4: Introduce more kinds of hosts.
2012-04-20 Mark Woodingfunctions.m4: Actually set the IPv6 options.
2012-03-30 Mark Woodingfender.m4: Define an address to be a guaranteed black...
2012-03-23 Mark Woodinglocal.m4: A new network for the SGO VPN.
2012-03-23 Mark Woodingfunctions.m4, classify.m4: Handle negative address...
2012-03-23 Mark WoodingMake FW_NOACT work properly.
2012-03-17 Mark Woodinglocal.m4: Declare network for anycast services.
2012-03-17 Mark Woodinglocal.m4: Reorder forwarding networks for `default'.
2012-03-17 Mark Woodinglocal.m4: Move `vpn' to the common networks section.
2012-03-12 Mark WoodingOverhaul address classification for link-local and...
2012-03-12 Mark Woodingfunctions.m4: Publish the per-class forwarding bitmasks.
2012-03-12 Mark Woodingfunctions.m4: The mark-{from,to}-* rules no longer...
2012-03-12 Mark Woodingclassify.m4: Use canonical forms for IPv6 addresses.
2012-03-12 Mark Woodinglocal.m4: Actually use the IPv6 fragmentation forbiddin...
2012-03-12 Mark WoodingExtend proper ICMP handling to IPv6.
2012-03-12 Mark Woodingbookends.m4: Optimize checking for forwarding IPv6...
2012-03-11 Mark Woodingvampire.m4: Extend services to untrusted hosts over...
2012-03-11 Mark WoodingIntroduce variable for expected input chains.
2012-03-11 Mark Woodinglocal.m4: Fix the `safe' network prefix length.
2012-03-11 Mark Woodinglocal.m4: Define the IPv6 network structure.
2012-03-11 Mark Woodinglocal.m4: Add routes to/from the `safe' network.
2012-03-11 Mark Woodinglocal.m4: The VPN will be available through the colo.
2012-03-11 Mark Woodingfunctions.m4: Correct defaulting of IPv6 host addresses.
2012-03-08 Mark Woodingclassify.m4: Reject the RFC5737 documentation-only...
2012-03-07 Mark WoodingMove per-host filtering to diversion 86 as promised.
2012-03-07 Mark Woodinglocal.m4: Add `unsafe' to ibanez `br-dmz' interface.
2012-03-07 Mark Woodingfunctions: Move NTP server list out of line.
2012-03-06 Mark Woodinglocal.m4: Allow dmz/jump packets on unsafe/colo network...
2012-03-06 Mark Woodingradius.m4: Forbid traffic directly to the NAT address.
2012-03-06 Mark Woodingradius.m4: Use the correct interface name for NAT.
2012-03-06 Mark Woodinglocal.m4: Fix IGMP acceptance (debris from old interfac...
2012-03-05 Mark Woodingfunctions.m4: Write the netclass ids to the trace output.
2012-03-05 Mark Woodingbookends.m4: If debugging, dump the final tables.
2012-03-05 Mark WoodingDetermine forwarding and reverse-path filtering from...
2012-03-05 Mark WoodingOverhaul address classification.
2012-03-05 Mark Woodinglocal.m4: Promote the NTP server configuration to a...
2012-03-05 Mark WoodingRenumber the diversions.
2012-03-05 Mark Woodingfixup! WIP on emergency: 7a108d1 Makefile: New target...
2012-03-05 Mark WoodingMakefile: New target for tracking diversions.
2012-03-05 Mark WoodingMakefile, base.m4: Inject the target hostname into...
2012-02-12 Mark Woodingnumbers.m4, gibson.m4: Allow gibson to receive IPMI...
2012-02-12 Mark Woodingbookends.m4: Open up tables we clobbered at exit.
2012-02-11 Mark Woodingfender: New host, with basic firewall.
2012-02-11 Mark Woodingnumbers.m4, vampire.m4: Serve TFTP to the untrusted...
2012-02-11 Mark Woodingnumbers.m4, gibson.m4: Allow gibson public SIP access.
2011-07-23 Mark Woodingjem.m4: Add a hook for SAUCE.
2011-07-23 Mark Woodingfunctions.m4: New function for arranging that an ipset...
2011-07-23 Mark Woodingfunctions.m4: Make clearchain tolerant of existing...
2011-07-23 Mark Woodingbookends.m4: Much more intelligent initialization.
2011-07-23 Mark Woodingjem.m4: Remove SMB for untrusted hosts.
2011-07-23 Mark Woodingfunctions.m4: Rate-limit rejections on error chains.
2011-07-17 Mark Woodingbookends.m4: Provide a hook chain for fail2ban.
2011-07-15 Mark Woodingradius.m4: Allow IPv6 tunnel from Hurricane Electric...
2011-07-15 Mark Woodingfunctions.m4, numbers.m4: Define protocol number for...
2011-07-15 Mark Woodingbookend.m4: Finish off the IPv6 chains.
2011-07-13 Mark Woodinghosts: Allow incoming ident requests.
2011-07-10 Mark Woodingradius.m4: Take over NAT duties.
2011-07-10 Mark WoodingMajor network restructuring.
next