Maximilian Wilhelm
|
5fc21b1d9d
icinga2: Ignore ifupdown2 check on nodes running ifupdown-ng
|
3 years ago |
Maximilian Wilhelm
|
1c6d5423bd
systemd: Work around new systemd persistent MAC "feature"
|
3 years ago |
Maximilian Wilhelm
|
6f0f5b35ff
nftables: Disable uRPF for non-routers entirely.
|
3 years ago |
Maximilian Wilhelm
|
1b948c057a
Allow forcing uRPF (de)activation via Netbox tags
|
3 years ago |
Maximilian Wilhelm
|
5850353c41
nftables: Fix service rule source annotation.
|
3 years ago |
Maximilian Wilhelm
|
3407aa7492
nftables: Fix AF issue
|
3 years ago |
Maximilian Wilhelm
|
876ef52736
nftables: Allow OSPF only on interfaces which should form an adjacency
|
3 years ago |
Maximilian Wilhelm
|
1fa7f5166b
SDN/bird: Move bool->string translation into template
|
3 years ago |
Maximilian Wilhelm
|
b18f7eaec9
nftables: Annotate rules with their origin
|
3 years ago |
Maximilian Wilhelm
|
97ed0e5bd8
nftables: Clean up
|
3 years ago |
Maximilian Wilhelm
|
efda5a5c04
nftables: Clean up generator code + template
|
3 years ago |
Maximilian Wilhelm
|
4acb9f1940
nftables: Allow mld-listener-reduction, too
|
3 years ago |
Maximilian Wilhelm
|
e1724dda70
nftables: Only generate VXLAN roles when required
|
3 years ago |
Maximilian Wilhelm
|
ea5aef8de8
nftables: Unify counters
|
3 years ago |
Philipp Fromme
|
ef8c13534b
Merge pull request #9 from BarbarossaTM/feature/nftables-forward
|
3 years ago |
Maximilian Wilhelm
|
e2a4779460
nftables: Allow link-local IPv6 in uRPF check
|
3 years ago |
Maximilian Wilhelm
|
6e67dd76be
nftables: Allow IPv6 MLD
|
3 years ago |
Maximilian Wilhelm
|
ada909efa6
nftables: Fix bug in NAT rule generation, D'oh.
|
3 years ago |
Maximilian Wilhelm
|
c3e585fafd
nftables: Update uRPF interface classification code
|
3 years ago |
Maximilian Wilhelm
|
e73f0b9e7f
nftables: Do proper uRPF checks in input chain, too.
|
3 years ago |
Maximilian Wilhelm
|
996e84a89c
nftables: Move uRPF checks into seperate chain
|
3 years ago |
Maximilian Wilhelm
|
a4dcdec312
nftables: Allow respondd requests to B.A.T.M.A.N. adv. gateways
|
3 years ago |
Maximilian Wilhelm
|
e7bf3f3bbc
nftables: Drop all broadcast packets before logging
|
3 years ago |
Maximilian Wilhelm
|
9f302065c1
nftables: Allow DHCP requests according to firewall policy
|
3 years ago |
Maximilian Wilhelm
|
c558c2fa6f
nftables: Allow VXLAN on interfaces requiring it.
|
3 years ago |
Maximilian Wilhelm
|
a88732a11d
nftables: Do not sort ports as they are pre-arranged by NACL
|
3 years ago |
Maximilian Wilhelm
|
c17fadd54f
nftabes: Generate rules for uRPF
|
3 years ago |
Maximilian Wilhelm
|
ea33ab41c8
nftables: Ignore packets for UDP port 0
|
3 years ago |
Maximilian Wilhelm
|
585642a35f
nftables: First shot at NAT support
|
3 years ago |
Maximilian Wilhelm
|
a6db6d7f8f
nftables: First shot at generating forwarding rules.
|
3 years ago |