firewall
2023-12-22 Mark Woodingclassify.m4: Explicitly class 255.255.255.255 as broadcast. master
2023-12-19 Mark Woodinglocal.m4: Add a correct VPN entry for `groove'.
2023-12-19 Mark Woodinglocal.m4: Delete incorrect host entry for `groove'.
2023-09-14 Mark Woodingroadstar.m4: Allow public access to the TLS web-cache...
2023-03-16 Mark Woodinglocal.m4: Fix the IPv4 version of the `inbound-untruste...
2023-02-25 Mark Woodinglocal.mk, roadstar.m4: Move lpr service to roadstar...
2022-05-30 Mark Wooding*.m4: Actually allow NFS to untrusted hosts.
2022-05-30 Mark Woodinglocal.m4, etc.: Establish `inbound-untrusted' chain...
2022-05-30 Mark Woodingfender.m4, ibanez.m4, vampire.m4: Invoke `footables...
2022-05-09 Mark WoodingMerge branch 'master' of git.distorted.org.uk:~mdw...
2022-05-09 Mark Woodingnumbers.m4, artist.m4: Add a second DisOrder port for...
2022-05-09 Mark Woodinglocal.m4: Add `mdwdev.upn'.
2021-11-01 Mark Woodingjazz.m4, numbers.m4: Allow Privoxy access to SGO VPN.
2021-02-03 Mark Woodinglocal.m4: Update external NTP servers.
2020-04-08 Mark Woodinglocal.m4: Add entry for new laptop `spirit'.
2018-12-26 Mark Woodinglocal.m4, precision.m4: Introduce `vpnnat' network...
2018-12-26 Mark Woodinglocal.mk: Reinstate mango.
2017-10-02 Mark Woodinglocal.m4: Filter out source routing in the firewall.
2017-10-02 Mark Woodinglocal.m4: Don't expect `forbidden' to return.
2017-10-01 Mark Woodinglocal.m4: Add the `hippotat' network.
2017-10-01 Mark Woodingclassify.m4: Note the older site-local IPv6 range.
2017-10-01 Mark Woodingclassify.m4: Fix typo in commentary.
2017-09-22 Mark Woodingtelecaster.m4: Open the old (implicit-TLS) `ftps' port.
2017-09-22 Mark Woodingroadstar.m4, telecaster.m4: No need to open the `ftp_da...
2017-07-02 Mark Woodingbase.m4: Improve LSB header to delay firewall shutdown.
2016-10-22 Mark Woodinglocal.m4: gibson uses untagged packets for the unsafe...
2016-07-01 Mark Woodinglocal.m4: Designate `vpn' as `trusted' rather than...
2016-07-01 Mark Woodingnational.m4: Configure as an authoritative DNS server.
2016-07-01 Mark WoodingFinish the switchover to Andrews & Arnold.
2016-07-01 Mark Woodingfender.m4: Fix silly typo in comment.
2016-06-27 Mark Woodinglocal.m4: Prepare for switchover to A&A.
2016-06-27 Mark Woodinglocal.m4: Fix whitespace oddity.
2016-06-15 Mark Woodingfender.m4: Provide NTP service to untrusted clients.
2016-02-07 Mark WoodingNew host universe.
2015-10-01 Mark Woodinglocal.m4, local.mk, national.m4: New virtual host ...
2015-10-01 Mark Woodinglocal.m4: New address range for untrusted VPN hosts.
2015-05-11 Mark Woodingfunctions.m4 (ntpclient): Handle NTP servers with IPv6...
2015-05-11 Mark Woodinglocal.m4: Allow IPv6 ping separately.
2015-04-01 Mark Woodingtelecaster.m4: External SMTP service for mailing lists.
2015-04-01 Mark Woodinglocal.mk: Remove orange and mango.
2015-04-01 Mark Woodingjem.m4, vampire.m4: Cull some external services.
2015-04-01 Mark Woodinglocal.m4: gibson now uses explicit VLAN tagging.
2015-03-26 Mark Woodingfunctions.m4: Only call `allow-non-init-frag' on fragments.
2015-03-26 Mark Woodingjaguar.m4, local.m4: Remove jaguar completely.
2015-03-19 Mark Woodingjem.m4: External rsync service.
2015-03-19 Mark Woodingradius.m4: Stop MSS clamping on egress now the external...
2015-02-28 Mark Woodinglocal.m4: Reinstate detailed filtering from scary networks.
2015-02-24 Mark Woodinglocal.m4: Inbound restriction on untrusted is no longer...
2015-02-16 Mark Woodinglocal.m4: Protect the `untrusted' network from incoming...
2015-02-16 Mark Woodingclassify.m4: Fix some typos in the commentary.
2015-02-09 Mark Woodingjazz.m4, numbers.m4: Expose the OpenPGP key server.
2015-02-07 Mark Woodinglocal.m4: Proper configuration for groove.
2015-02-07 Mark Woodinggroove.m4: New host.
2015-02-07 Mark Woodingartist.m4: Further Rygel hacking.
2014-09-05 Mark Woodingartist.m4: Punch a hole for Rygel service to local...
2014-07-15 Mark Woodinglocal.m4: Boundary network addresses can legitimately...
2014-07-15 Mark Woodingstratocaster.m4: Permit incoming finger.
2014-06-29 Mark Woodinglocal.m4: Load connection tracking modules as standard.
2014-04-27 Mark Woodingclassify.m4: Forbid the v4-mapped and v4-compatible...
2014-04-21 Mark Woodinglocal.m4: Move VPN hosts to ...:1.
2014-04-20 Mark Woodingtelecaster.m4: Allow external DNS service.
2014-04-19 Mark Woodinglocal.m4: Replacing IPv6 host routes with /112 networks.
2014-04-18 Mark Woodinglocal.m4: Mention that the IPv6 VPN net is logically...
2014-04-18 Mark Woodingicmp.m4: Actually track the correct ICMPv6 protocol.
2014-03-08 Mark WoodingMakefile: Explicit stdin from terminal, so `make -j...
2014-03-08 Mark Woodingfender.m4: BCP38 source-address filtering, at ebtables...
2014-03-08 Mark Woodingfender.m4: Reformat the ebtables hacking a bit.
2014-03-08 Mark Woodingfunctions.m4, radius.m4: BCP38 filtering for outbound...
2014-03-07 Mark Woodingbase.m4: Run firewall after local filesystems are mounted.
2014-02-12 Mark Woodingnumbers.m4, stratocaster.m4: Public-facing IMAP server.
2014-01-07 Mark Woodingnumbers.m4, telecaster.m4: TLS-enabled web cache.
2013-09-10 Mark Woodinglocal.mk: jaguar's firewall is maintained locally now.
2013-09-04 Mark Woodingfender.m4: Trap bad source IP addresses at the ethernet...
2013-09-02 Mark Woodingjazz.m4: Allow iodine hosts NATed internet access.
2013-09-02 Mark Woodingjaguar.m4, local.m4, local.mk: New host.
2013-05-06 Mark Woodingtelecaster.m4: Rate-limit incoming ICP.
2013-05-06 Mark Woodingfunctions.m4: Partially cope with ipset(8) command...
2013-04-19 Mark Woodingnumbers.m4, telecaster.m4: Expose the Squid ICP port.
2013-04-19 Mark Woodingmango.m4: Reverse NAT into the main network.
2013-04-19 Mark Woodingclassify.m4: Document the source of blacklisted address...
2013-03-26 Mark Woodingjazz.m4: No, jazz is not a nameserver.
2013-03-26 Mark Woodingmango.m4: Tighten up the SNAT rules.
2013-03-16 Mark Woodingconfig.m4: Extend the upper limit on open ports.
2013-02-10 Mark WoodingNew host `mango'.
2013-02-09 Mark Woodingclassify.m4: Hook the INPUT and FORWARD chains, not...
2013-02-09 Mark Woodingibanez.m4: Open an explicit hole for `udpkey'.
2013-02-09 Mark Woodinglocal.m4: Yet more explicit networks for asymmetric...
2013-01-26 Mark Woodinglocal.m4: New satellite network `binswood'.
2013-01-26 Mark Woodinglocal.m4: Make the net-class policies easier to read.
2013-01-26 Mark Woodinglocal.m4: Nothing should forward via `iodine'.
2013-01-26 Mark Woodingfunctions.m4, local.m4: Rename `forwards' to `via'.
2013-01-13 Mark WoodingNew host `orange'.
2013-01-13 Mark Woodingibanez.m4, vampire.m4: Provide NTP service to untrusted...
2013-01-08 Mark Woodingbookends.m4: Better check for bridging.
2012-12-29 Mark Woodingstratocaster.m4: Provide rsync service.
2012-12-28 Mark Wooding{roadstar,jem,telecaster,stratocaster}.m4: Move Git...
2012-12-28 Mark Woodingartist.m4: Moved the `rawk' server to artist.
2012-12-15 Mark Woodingjazz.m4, local.m4: Make jazz be a TrIPE endpoint.
2012-12-14 Mark Woodingnumbers.m4: Add port number for IRC.
2012-12-13 Mark WoodingMakefile: If the user overrides HOSTS, don't install...
next