- Feb 21, 2024
-
-
Jo-Philipp Wich authored
Ref: https://forum.openwrt.org/t/question-about-firewall-rules/188656 Signed-off-by: Jo-Philipp Wich <jo@mein.io>
-
- Dec 30, 2023
-
-
Jonas Dreßler authored
Apparently the "Forward" entry of the individual firewall zones controls forwarding within the zone (between the individual interfaces) only, and not the forwarding of packets from the zone to other zones. This is quite confusing, as the meaning is different from the global "Forward" option above, which does control forwarding between zones. Quote from user jow on the forum: > The per-zone forward controls forwarding traffic among the ifaces of this > zone. Traffic from/to other zones is handled by the global forward policy, > or individual forwardings or rules. See https://forum.openwrt.org/t/likely-bug-in-openwrt-firewall-rule-generation/18152 Let's try to be a bit more concise with the naming here and rename this entry to "Intra zone forward", which hopefully makes the difference clear. Signed-off-by: Jonas Dreßler <verdre@v0yd.nl>
-
- Nov 28, 2023
-
-
Vladislav Grigoryev authored
Allow creating redirects using IP family `any`. This helps redirect both IPv4 and IPv6 traffic. It is used to intercept traffic on the router. Signed-off-by: Vladislav Grigoryev <vg.aetera@gmail.com>
-
- Oct 12, 2023
-
-
Jo-Philipp Wich authored
Ensure that user supplied set name values conform to the nftables identifier syntax constraints. Fixes: #6633 Fixes: 04843439 ("luci-app-firewall: implement IPsets GUI") Signed-off-by: Jo-Philipp Wich <jo@mein.io>
-
- Jul 31, 2023
-
-
清靈語 authored
-
- Jul 12, 2023
-
-
Julien Cassette authored
This allows to to define multiple zones for NAT reflection rules. Fixes: #1560 Signed-off-by: Julien Cassette <julien.cassette@gmail.com>
-
- Jun 10, 2023
-
-
Sergey Ponomarev authored
Signed-off-by: Sergey Ponomarev <stokito@gmail.com>
-
- May 16, 2023
-
-
Jonathan G. Underwood authored
This adds entries for ICMPv6 MLD types. This fixes the ICMPv6 MLD types to be consistent with fw4. These types were added to fw4 in this commit: - https://github.com/openwrt/firewall4/commit/e6e82a55206cf7017f26b92f7097f779161b5cac But were omitted from the corresponding luci-app-firewall commit: - https://github.com/openwrt/luci/commit/88a016cb Signed-off-by: Jonathan G. Underwood <jonathan.underwood@gmail.com>
-
- Apr 05, 2023
-
-
Dirk Brenken authored
* corrects the view as IPv4 and IPv6 for rules where the family is 'any' and the IP not set (this fixes #9c55500f ), e.g. a forward rule like that: config redirect 'adblock_lan53' option name 'Adblock DNS (lan, 53)' option src 'lan' option proto 'tcp udp' option src_dport '53' option dest_port '53' option target 'DNAT' option family 'any' Signed-off-by: Dirk Brenken <dev@brenken.org>
-
- Mar 30, 2023
-
-
Jo-Philipp Wich authored
Fixes: 48086e1c ("luci-app-firewall: Add ipset field to snats") Fixes: d0d891c2 ("luci-app-firewall: Add ipset field to forwards (redirects)") Fixes: f407a013 ("luci-app-firewall: Add ipset field to rules") Signed-off-by: Jo-Philipp Wich <jo@mein.io>
-
Tianling Shen authored
Allow configure Masquerading6 via LuCI interface. Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
-
- Mar 29, 2023
-
-
Paul Dee authored
Signed-off-by: Paul Dee <itsascambutmailmeanyway@gmail.com>
-
Paul Dee authored
Signed-off-by: Paul Dee <itsascambutmailmeanyway@gmail.com>
-
Paul Dee authored
Signed-off-by: Paul Dee <itsascambutmailmeanyway@gmail.com>
-
Paul Dee authored
Enable it and place it between snats and custom tabs Tested on 22.03.2, 22.03.3 Signed-off-by: Paul Dee <itsascambutmailmeanyway@gmail.com>
-
- Mar 15, 2023
-
-
Chen Minqiang authored
Allow setup ipv6 for Port Forwards and NAT Rules if firewall4 is used. Add 'Restrict to address family' option for NAT Rules, if family is any/empty , assume it is ipv4. this allow setup NAT6 rules in web ui Signed-off-by: Chen Minqiang <ptpt52@gmail.com>
-
Jo-Philipp Wich authored
Ensure that the description of the masquerade option does not end up in the grid section overview as it messes up the table layout. Fixes: c54efde7 ("luci-app-firewall: Add clarification to masquerading option") Signed-off-by: Jo-Philipp Wich <jo@mein.io>
-
- Feb 17, 2023
-
-
Paul Dee authored
luci complement to https://github.com/openwrt/firewall4/commit/e6e82a55206cf7017f26b92f7097f779161b5cac Tested on 22.03.3 Signed-off-by: Paul Dee <itsascambutmailmeanyway@gmail.com>
-
Paul Dee authored
This prevents its inconsistent checked/unchecked behaviour when exiting and re-entering the dialogue. Tested on 22.03.3 Signed-off-by: Paul Dee <itsascambutmailmeanyway@gmail.com>
-
- Feb 04, 2023
-
-
Martijn Staal authored
Signed-off-by: Martijn Staal <27222398+mastaal@users.noreply.github.com>
-
- Mar 30, 2022
-
-
Jo-Philipp Wich authored
Fixes: #5749 Signed-off-by: Jo-Philipp Wich <jo@mein.io>
-
- Feb 16, 2022
-
-
Jo-Philipp Wich authored
Fixes: #5685 Signed-off-by: Jo-Philipp Wich <jo@mein.io>
-
- Jan 06, 2022
-
-
Stijn Tintel authored
Initial changes required for firewall4 compatibility: * depend on uc-firewall instead of firewall * detect installed version of firewall and hide incompatible features Signed-off-by: Stijn Tintel <stijn@linux-ipv6.be> Reviewed-by: Jo-Philipp Wich <jo@mein.io>
-
- Dec 09, 2021
-
-
Jo-Philipp Wich authored
Prevent incorrectly replacing unrecognized protocol numbers with -1. Fixes: #5587 Signed-off-by: Jo-Philipp Wich <jo@mein.io>
-
- Nov 11, 2021
-
-
Jo-Philipp Wich authored
Use the new `firewall.getZoneColorStyle()` helper to apply background color styles. Signed-off-by: Jo-Philipp Wich <jo@mein.io>
-
- Nov 10, 2021
-
-
Jo-Philipp Wich authored
No functional changes but required for styling rules. Signed-off-by: Jo-Philipp Wich <jo@mein.io>
-
- Aug 31, 2021
-
-
Paul Dee authored
to firewall 'Match ICMP type' field. See issue #5213 Signed-off-by: Paul Dee <systemcrash@users.noreply.github.com>
-
- Aug 11, 2021
-
-
Fritz D. Ansel authored
10 lines are very few and there is much unused space Signed-off-by: Fritz D. Ansel <fdansel@yandex.ru>
-
- Aug 04, 2021
-
-
Stan Grishin authored
Signed-off-by: Stan Grishin <stangri@melmac.net>
-
- Jun 03, 2021
-
-
Jo-Philipp Wich authored
Rework some further code instances to fall back to the legacy ipv4/ipv6 properties if needed. Fixes: c7b7b42c ("treewide: Update JS using luci-rpc getHostHints") Signed-off-by: Jo-Philipp Wich <jo@mein.io>
-
Niels Widger authored
Update frontend JS code which uses luci-rpc getHostHints to support the new response format which removes the `ipv4` and `ipv6` host hint string fields and replaces them with `ipaddrs` and `ip6addrs` weighted string list fields. Signed-off-by: Niels Widger <niels@qacafe.com> [rework code to be forwards/backwards compatible, fix some Network.Hosts methods, fix IP choice ordering, change commit subject, rewrap commit message] Signed-off-by: Jo-Philipp Wich <jo@mein.io>
-
- Mar 15, 2021
-
-
Jo-Philipp Wich authored
Signed-off-by: Jo-Philipp Wich <jo@mein.io>
-
- Mar 01, 2021
-
-
Jo-Philipp Wich authored
Fixes: #4812 Signed-off-by: Jo-Philipp Wich <jo@mein.io>
-
Jo-Philipp Wich authored
Fixes: #4845 Signed-off-by: Jo-Philipp Wich <jo@mein.io>
-
Jo-Philipp Wich authored
Signed-off-by: Jo-Philipp Wich <jo@mein.io>
-
- Feb 19, 2021
-
-
Jo-Philipp Wich authored
Store multiple space separated custom address values as separate uci list items in the configuration. Fixes: #4822 Signed-off-by: Jo-Philipp Wich <jo@mein.io>
-
- Jan 13, 2021
-
-
Florian Eckert authored
Signed-off-by: Florian Eckert <fe@dev.tdt.de>
-
Florian Eckert authored
Signed-off-by: Florian Eckert <fe@dev.tdt.de>
-
- Dec 16, 2020
-
-
Florian Eckert authored
Before the change, the options '*' and 'any' in the drop down were not recognized as valid options, when loaded from the uci. With this change, the options '*' and 'any' are mapped to 'all' and saved as such. This change is especially important if the proto option is changed manually to '*' or 'any' in shell and then further configured via LuCI. Signed-off-by: Florian Eckert <fe@dev.tdt.de>
-
- Nov 20, 2020
-
-
Jo-Philipp Wich authored
Fixes: #4608 Signed-off-by: Jo-Philipp Wich <jo@mein.io>
-