summaryrefslogtreecommitdiffstats
AgeCommit message (Expand)Author
2025-03-17fw4: fix reading kernel versionmasterMieczyslaw Nalewaj
2025-03-17fw4: allow family `any` for ipsets not matching IP addressesJo-Philipp Wich
2025-03-17Revert "fw4: allow family `any` for ipsets not matching IP addresses"Jo-Philipp Wich
2025-03-17config: drop to-be-forwarded-nowhere packets on wansAndris PE
2025-03-17init: remove unnecessary stop logicAndris PE
2025-03-17fw4: allow family `any` for ipsets not matching IP addressesJo-Philipp Wich
2024-12-18init: use the reload data trigger to reload firewall on procd data changesFelix Fietkau
2024-06-03fw4: skip not existing netdev names in flowtable device listJo-Philipp Wich
2024-05-31fw4: do not add physical devices for soft offloadJo-Philipp Wich
2024-05-21fw4: substitute double quotes in stringsJo-Philipp Wich
2023-11-03ruleset: apply egress MSS fixup later to apply final MTU before wireAndris PE
2023-11-03ruleset: do not emit redundant drop invalid rulesAndris PE
2023-11-03tests: adjust zone log limit testcasesJo-Philipp Wich
2023-11-03ruleset: reduce ksoftirqd load by refering to looopback by numeric idAndris PE
2023-11-03ruleset: dispatch ct states using verdict mapAndris PE
2023-11-03Revert "ruleset: dispatch ct states using verdict map"Jo-Philipp Wich
2023-11-03ruleset: dispatch ct states using verdict mapUser User-User
2023-11-03fw4: add log_limit to rules and redirectsLuiz Angelo Daros de Luca
2023-11-03fw4: add support for zone log_limitLuiz Angelo Daros de Luca
2023-11-03fw4: pass zone to templates whenever possibleLuiz Angelo Daros de Luca
2023-10-12fw4: perform strict validation of zone and set namesJo-Philipp Wich
2023-09-01fw4: remove special cases around hw flow offloadingFelix Fietkau
2023-08-11fw4: fix another instance of invalid rule jump targetsJo-Philipp Wich
2023-08-04fw4: avoid emitting invalid rule jump targetsJo-Philipp Wich
2023-05-30tests: fix expected test outputJo-Philipp Wich
2023-03-23fw4: enable flowtable countersFelix Fietkau
2023-03-23fw4: remove accidentally committed .orig and .rej fileFelix Fietkau
2023-02-03fw4: fix syntax errors in ICMP type declarationsJo-Philipp Wich
2023-02-03tests: add testcase for automatic includesJo-Philipp Wich
2023-02-03fw4: add further symbolic ICMP type declarationsPaul D
2023-02-03fw4: fix handling the ipset "comment" optionJo-Philipp Wich
2022-11-29fw4: prevent null access when no ipsets are definedJo-Philipp Wich
2022-11-02config: drop input traffic by defaultBaptiste Jonglez
2022-10-26ruleset: drop ctstate invalid traffic for masq-enabled zonesJo-Philipp Wich
2022-10-18fw4: gracefully handle `null` return values from `fd.read("line")`Jo-Philipp Wich
2022-10-14ruleset.uc: log forwarded traffic not matched by zone policiesJo-Philipp Wich
2022-10-14main.uc: reintroduce set reload restrictionJo-Philipp Wich
2022-10-14ruleset: fix emitting set_mark/set_xmark rules with masksJo-Philipp Wich
2022-10-05ruleset: properly handle zone names starting with a digitJo-Philipp Wich
2022-10-05fw4: fix formatting of default log prefixJo-Philipp Wich
2022-10-05main.uc: remove uneeded/wrong set reload restrictionsJo-Philipp Wich
2022-10-03tests: fix testcasesJo-Philipp Wich
2022-09-08fw4: recognize `option log` and `option counter` in `config nat` sectionsJo-Philipp Wich
2022-09-08fw4: fall back to device if l3_device is not available in ifstatusJo-Philipp Wich
2022-09-01cli: introduce test mode and refuse firewall restart on errorsJo-Philipp Wich
2022-09-01fw4: fix cosmetic issue with per-ruleset and per-table include pathsJo-Philipp Wich
2022-09-01doc: fix swapped include positions in nftables.d READMEJo-Philipp Wich
2022-08-12fw4: support automatic includesJo-Philipp Wich
2022-08-08fw4: honour enabled option of include sectionsJo-Philipp Wich
2022-08-08tests: add missing fs.stat) mock data for `nf_conntrack_dummy`Jo-Philipp Wich