firewall
2018-12-26 Mark Woodinglocal.mk: Reinstate mango.
2017-10-02 Mark Woodinglocal.m4: Filter out source routing in the firewall.
2017-10-02 Mark Woodinglocal.m4: Don't expect `forbidden' to return.
2017-10-01 Mark Woodinglocal.m4: Add the `hippotat' network.
2017-10-01 Mark Woodingclassify.m4: Note the older site-local IPv6 range.
2017-10-01 Mark Woodingclassify.m4: Fix typo in commentary.
2017-09-22 Mark Woodingtelecaster.m4: Open the old (implicit-TLS) `ftps' port.
2017-09-22 Mark Woodingroadstar.m4, telecaster.m4: No need to open the `ftp_da...
2017-07-02 Mark Woodingbase.m4: Improve LSB header to delay firewall shutdown.
2016-10-22 Mark Woodinglocal.m4: gibson uses untagged packets for the unsafe...
2016-07-01 Mark Woodinglocal.m4: Designate `vpn' as `trusted' rather than...
2016-07-01 Mark Woodingnational.m4: Configure as an authoritative DNS server.
2016-07-01 Mark WoodingFinish the switchover to Andrews & Arnold.
2016-07-01 Mark Woodingfender.m4: Fix silly typo in comment.
2016-06-27 Mark Woodinglocal.m4: Prepare for switchover to A&A.
2016-06-27 Mark Woodinglocal.m4: Fix whitespace oddity.
2016-06-15 Mark Woodingfender.m4: Provide NTP service to untrusted clients.
2016-02-07 Mark WoodingNew host universe.
2015-10-01 Mark Woodinglocal.m4, local.mk, national.m4: New virtual host ...
2015-10-01 Mark Woodinglocal.m4: New address range for untrusted VPN hosts.
2015-05-11 Mark Woodingfunctions.m4 (ntpclient): Handle NTP servers with IPv6...
2015-05-11 Mark Woodinglocal.m4: Allow IPv6 ping separately.
2015-04-01 Mark Woodingtelecaster.m4: External SMTP service for mailing lists.
2015-04-01 Mark Woodinglocal.mk: Remove orange and mango.
2015-04-01 Mark Woodingjem.m4, vampire.m4: Cull some external services.
2015-04-01 Mark Woodinglocal.m4: gibson now uses explicit VLAN tagging.
2015-03-26 Mark Woodingfunctions.m4: Only call `allow-non-init-frag' on fragments.
2015-03-26 Mark Woodingjaguar.m4, local.m4: Remove jaguar completely.
2015-03-19 Mark Woodingjem.m4: External rsync service.
2015-03-19 Mark Woodingradius.m4: Stop MSS clamping on egress now the external...
2015-02-28 Mark Woodinglocal.m4: Reinstate detailed filtering from scary networks.
2015-02-24 Mark Woodinglocal.m4: Inbound restriction on untrusted is no longer...
2015-02-16 Mark Woodinglocal.m4: Protect the `untrusted' network from incoming...
2015-02-16 Mark Woodingclassify.m4: Fix some typos in the commentary.
2015-02-09 Mark Woodingjazz.m4, numbers.m4: Expose the OpenPGP key server.
2015-02-07 Mark Woodinglocal.m4: Proper configuration for groove.
2015-02-07 Mark Woodinggroove.m4: New host.
2015-02-07 Mark Woodingartist.m4: Further Rygel hacking.
2014-09-05 Mark Woodingartist.m4: Punch a hole for Rygel service to local...
2014-07-15 Mark Woodinglocal.m4: Boundary network addresses can legitimately...
2014-07-15 Mark Woodingstratocaster.m4: Permit incoming finger.
2014-06-29 Mark Woodinglocal.m4: Load connection tracking modules as standard.
2014-04-27 Mark Woodingclassify.m4: Forbid the v4-mapped and v4-compatible...
2014-04-21 Mark Woodinglocal.m4: Move VPN hosts to ...:1.
2014-04-20 Mark Woodingtelecaster.m4: Allow external DNS service.
2014-04-19 Mark Woodinglocal.m4: Replacing IPv6 host routes with /112 networks.
2014-04-18 Mark Woodinglocal.m4: Mention that the IPv6 VPN net is logically...
2014-04-18 Mark Woodingicmp.m4: Actually track the correct ICMPv6 protocol.
2014-03-08 Mark WoodingMakefile: Explicit stdin from terminal, so `make -j...
2014-03-08 Mark Woodingfender.m4: BCP38 source-address filtering, at ebtables...
2014-03-08 Mark Woodingfender.m4: Reformat the ebtables hacking a bit.
2014-03-08 Mark Woodingfunctions.m4, radius.m4: BCP38 filtering for outbound...
2014-03-07 Mark Woodingbase.m4: Run firewall after local filesystems are mounted.
2014-02-12 Mark Woodingnumbers.m4, stratocaster.m4: Public-facing IMAP server.
2014-01-07 Mark Woodingnumbers.m4, telecaster.m4: TLS-enabled web cache.
2013-09-10 Mark Woodinglocal.mk: jaguar's firewall is maintained locally now.
2013-09-04 Mark Woodingfender.m4: Trap bad source IP addresses at the ethernet...
2013-09-02 Mark Woodingjazz.m4: Allow iodine hosts NATed internet access.
2013-09-02 Mark Woodingjaguar.m4, local.m4, local.mk: New host.
2013-05-06 Mark Woodingtelecaster.m4: Rate-limit incoming ICP.
2013-05-06 Mark Woodingfunctions.m4: Partially cope with ipset(8) command...
2013-04-19 Mark Woodingnumbers.m4, telecaster.m4: Expose the Squid ICP port.
2013-04-19 Mark Woodingmango.m4: Reverse NAT into the main network.
2013-04-19 Mark Woodingclassify.m4: Document the source of blacklisted address...
2013-03-26 Mark Woodingjazz.m4: No, jazz is not a nameserver.
2013-03-26 Mark Woodingmango.m4: Tighten up the SNAT rules.
2013-03-16 Mark Woodingconfig.m4: Extend the upper limit on open ports.
2013-02-10 Mark WoodingNew host `mango'.
2013-02-09 Mark Woodingclassify.m4: Hook the INPUT and FORWARD chains, not...
2013-02-09 Mark Woodingibanez.m4: Open an explicit hole for `udpkey'.
2013-02-09 Mark Woodinglocal.m4: Yet more explicit networks for asymmetric...
2013-01-26 Mark Woodinglocal.m4: New satellite network `binswood'.
2013-01-26 Mark Woodinglocal.m4: Make the net-class policies easier to read.
2013-01-26 Mark Woodinglocal.m4: Nothing should forward via `iodine'.
2013-01-26 Mark Woodingfunctions.m4, local.m4: Rename `forwards' to `via'.
2013-01-13 Mark WoodingNew host `orange'.
2013-01-13 Mark Woodingibanez.m4, vampire.m4: Provide NTP service to untrusted...
2013-01-08 Mark Woodingbookends.m4: Better check for bridging.
2012-12-29 Mark Woodingstratocaster.m4: Provide rsync service.
2012-12-28 Mark Wooding{roadstar,jem,telecaster,stratocaster}.m4: Move Git...
2012-12-28 Mark Woodingartist.m4: Moved the `rawk' server to artist.
2012-12-15 Mark Woodingjazz.m4, local.m4: Make jazz be a TrIPE endpoint.
2012-12-14 Mark Woodingnumbers.m4: Add port number for IRC.
2012-12-13 Mark WoodingMakefile: If the user overrides HOSTS, don't install...
2012-12-13 Mark Woodinglocal.m4: Add a prose commentary on address allocation.
2012-12-11 Mark Woodingfunctions.m4: Correctly clear `to' network field in...
2012-12-11 Mark Woodingclassify.m4: Dispatch on destination addresses to corre...
2012-12-11 Mark Woodingclassify.m4: Classify individual host routes correctly.
2012-12-11 Mark Woodingclassify.m4: Clean up interface map tracing.
2012-12-11 Mark Woodingfunctions.m4: Fix up commentary for `matchnets'.
2012-12-11 Mark Woodinglocal.m4, jazz.m4: Move iodine endpoint to jazz.
2012-12-11 Mark Woodingnumbers.m4, vampire.m4: Expose print server to local...
2012-10-14 Mark Woodingradius.m4: Allow external servers to contact the identd.
2012-10-14 Mark Woodinglocal.m4, radius.m4: radius is now the host gateway...
2012-09-12 Mark Woodinglocal.m4: artist should expect untrusted source addrs...
2012-09-12 Mark Woodinglocal.m4: Track VLAN renumbering in vampire's interface...
2012-06-08 Mark WoodingRate limiting for incoming DNS queries over UDP.
2012-06-08 Mark Woodingradius.m4: Handy ipset hook for ad-hoc safe/unstrusted...
2012-06-08 Mark Woodinglocal.m4: Refactor common SSH permission between safe...
2012-05-03 Mark Woodinglocal.m4: Packets can be routed over the safe network.
next