13 Commits

Author SHA1 Message Date
Natanael Copa
c2ad54cf99 main/shorewall-shell: fix redirect excludes
Fixes this error:

Setting up Rules...
Bad argument `10.12.96.1'
Try `iptables -h' or 'iptables --help' for more information.
   ERROR: Command "/sbin/iptables -t nat -A D_96_dnat -p tcp -d ! 10.12.96.1 --dport 80 -j REDIRECT --to-port 8080" Failed

on rule:
REDIRECT:info D_96      8080    tcp     80 -    !10.12.96.1
2012-07-11 08:34:39 +00:00
Natanael Copa
f87a4af445 main/shorewall-shell: remove unused post-install 2012-06-26 14:55:37 +00:00
Natanael Copa
2c42b21247 main/shorewall-shell: add option to disable saving/restoring default route
When starting, shorewall will save all default routes. When stop, it
will try to restore it. But does it badly. On multiisp setups with pingu
it will break things.

We (ab)use the RESTORE_DEFAULT_ROUTE to make it possible to avoid
restoring the default route.
2012-06-26 14:47:00 +00:00
Natanael Copa
3e9fded968 main/shorewall-shell: do not remove ip rule from addr when no gateway
We should not remove any ip rule that we have not created our selves
2012-01-03 14:35:10 +00:00
Natanael Copa
438e9609e2 main/shorewall-shell: set all/rp_filter based on ROUTE_FILTER
The kernel changed behavior around 2.6.31. We need a way to turn off
rp_filter.

details:
http://article.gmane.org/gmane.comp.security.shorewall/23329/match=rp_filter

This will disable routefilter if ROUTE_FILTER=no in
/etc/shorewall/shorewall.conf default. To enable you will need set the
routefilter option in /etc/shorewall/interfaces
2011-12-08 15:40:10 +00:00
Natanael Copa
a6ab887506 main/shorewall-shell: do not restore default gw that you never modified
Shorewall's restore default gw will intentinally break multi routes

When no 'balance' option is specified shorewall does not change the
default gw so there is no point in restoring (breaking) it either.
2011-10-14 09:09:16 +00:00
Natanael Copa
1e46ca9775 main/shorewall-shell: add support for "none" gateway in providers
This will make shorewall not add or delete any routes to the providers
route table
2011-10-13 07:36:41 +00:00
Natanael Copa
232a4772c2 main/shorewall-shell: upgrade to 4.2.11, add patch for ipset 2011-10-05 11:43:06 +00:00
Natanael Copa
4ff65ef299 main: mass-rebuild of packages missing arch in .PKGINFO
this is needed for apk-tools-2.1 migration
2011-03-31 13:43:08 +00:00
William Pitcock
ba2600dc6e Set all packages with arch="x86 x86_64" to arch="all". 2011-01-13 06:06:02 -06:00
Natanael Copa
da49ad32c4 main/*: add arch 2010-12-13 16:00:16 +00:00
Timo Teräs
758dce8058 main/shorewall-shell: add policy routing related patch
To allow creation of routing tables to be managed by an external
component (e.g. quagga or opennhrp).
2010-11-01 13:40:55 +02:00
Natanael Copa
b70981b68e moved extra/* to main/
and fixed misc build issues
2009-07-24 08:01:31 +00:00