- a258ad7 Multiple matches of the same type can be specified on the commandline. by Joszef Kadlecsik · 19 years ago
- cbe1ec7 Make '-p all' a special case that is handled before calling getprotoent() (Closes: #446) by Harald Welte · 19 years ago
- d6bc608 fix double-free if a single match is used multiple times within a signle rule by Harald Welte · 19 years ago
- 0fbc862 don't install libiptc.a by Harald Welte · 19 years ago
- 6f38a30 fix segfault or loading of invalid counters in ip[6]tables-restore (Olaf Rempel) (Closes: #437) by Harald Welte · 19 years ago
- d3476b2 make policy match compile independant of kernel headers by Harald Welte · 19 years ago
- 54c603a Some !%$!*##$@ has modified the kernel include/linux/netfilter_ipv4/ipt_sctp.h by Harald Welte · 19 years ago
- 11e4718 fix ipt_conntrack compilation against very early (2.4.0) kernel releases by Harald Welte · 19 years ago
- 38315b1 remove other bits of old ip pool code, people should use ipset (ipset.netfilter.org) these days by Harald Welte · 19 years ago
- 26441e7 remove ippool by Harald Welte · 19 years ago
- 02e88f2 Prepare policy match for x_tables unification by making sure both by Patrick McHardy · 19 years ago
- 0829a2b fix 'save' (Michael Rash) by Michael Rash · 19 years ago
- 28e5b79 major manpage update (Yasuyuki Kozakai) by Yasuyuki KOZAKAI · 19 years ago
- 469d18f Add 'copy+paste' support for 'state' and 'connmark' match, as well as by Harald Welte · 19 years ago
- 4b1be69 add note about deprecated state by Harald Welte · 19 years ago
- 599d2a1 fix spelling 'adress' -> 'address' (Closes: #431) (MJ Anthony) by Harald Welte · 19 years ago
- 3f34756 Fix "empty policy element" complaining in non-strict mode. by Noticed by Tom Eastep · 19 years ago
- 37b7c9b Clarify --tunnel-src/--tunnel-dst options by Patrick McHardy · 19 years ago
- a46d88d Move empty policy element check to also catch last element by Patrick McHardy · 19 years ago
- 1d0f57c Don't allow using --next option without specifying a policy element by Patrick McHardy · 19 years ago
- cddae3d Fix invalid assignment of tunnel-src to dest address (Patrick McHardy) by Patrick McHardy · 19 years ago
- 014a48f Add documentation for string match (Pablo Neira) by Pablo Neira · 19 years ago
- f5b86e6 Fix probing for supported revisions (Jones Desougi <jones@ingate.com>) by Jones Desougi · 19 years ago
- 402c311 fix iptables-save of 'goto' target (Closes: #410) by Harald Welte · 19 years ago
- dbbcf27 Add note that TCPMSS is only valid in the mangle table (not true today, but maybe someday) by Patrick McHardy · 19 years ago
- 72bd87e fix compilation of iptables on [old] systems that don't have IPT_F_GOTO by Harald Welte · 19 years ago
- 3a02693 note that we can only delete chains that are empty by Harald Welte · 19 years ago
- 11b8591 tcp-rst is the alias, not tcp-reset (Torsten Hilbrich) by Harald Welte · 19 years ago
- 524bb80 Add policy match extensions from patch-o-matic by Patrick McHardy · 19 years ago
- 2739cb8 Fix some gcc-4 warnings by Patrick McHardy · 19 years ago
- 6656e13 Don't eat numeric arguments for other extensions by Patrick McHardy · 19 years ago
- 5a4892b The conntrack match does not print any info for --ctproto, thus by Phil Oester · 19 years ago
- 0b90564 only set revisions on real targets, not on jumps. (Pablo Neira) by Pablo Neira · 19 years ago
- d6ba6f5 - Fix memory leak in TC_COMMIT() (Markus Sundberg) by Harald Welte · 19 years ago
- 17fc163 add 'goto' support (Henrik Nordstrom <hno@marasystems.com>) by Henrik Nordstrom · 19 years ago
- 361bac2 fix connmark, it's now only 32bits (Deti Fliegl <deti@fliegl.de) by Deti Fliegl · 19 years ago
- 8502747 about to release 1.3.4 by Harald Welte · 19 years ago
- 55548fd The conntrack match extension doesn't handle address inversion correctly. (Tom Eastep) by Tom Eastep · 19 years ago
- 8cf6591 Kernels higher than 2.6.10 don't support multiple --to arguments in by Phil Oester · 19 years ago
- 3643aca * specifying random seed for the Jenkins hash works as documented by KOVACS Krisztian · 19 years ago
- 3ef4c8f Add the aligned_u64 typedef, it's defined in linux/types.h in the kernel. by Martin Josefsson · 19 years ago
- ae65b52 Make libipt_connbytes.c compile with the ipt_connbytes version that has been merged into the 2.6 kernel by Martin Josefsson · 19 years ago
- a4749bc Update manpage to reflect missing ability to SNAT to multiple ranges in 2.6.11-rc1 and later by Harald Welte · 19 years ago
- d2baafe Update manpage to reflect missing NAT to multiple ranges support in 2.6.11-rc1 and later. by Harald Welte · 19 years ago
- c6fbf41 update string match to reflect new kernel implementation (Pablo Neira) by Pablo Neira · 19 years ago
- 9cfc9b9 Note which kernel versions are affected by REJECT change (Maciej Soltysiak) by Maciej Soltysiak · 19 years ago
- e40b11d add support for new 'dccp' protocol match by Harald Welte · 19 years ago
- ae87b8a port Eric Leblond's NFQUEUE missing-break fix to ip6tables by Harald Welte · 19 years ago
- 6fdefcf Add missing 'break' to make parsing of NFQUEUE numbers work (Eric Leblond) by Eric Leblond · 19 years ago
- feca057 _really_ sort only user defined chains (Robert de Barth <list-netfilter@debarth.co.uk> by Robert de Barth · 19 years ago
- 2ed4f1b 1.3.3 release by Harald Welte · 19 years ago
- d91ed75 The call to free_opts() in merge_options() is invalid C. The oldopts by Marcus Sundberg · 19 years ago
- 7bdfca4 update manpage to reflect QUEUE / nfnetlink_queue / NFQUEUE changes by Harald Welte · 19 years ago
- 36d870c Fix NAT of ICMP ID ranges (Patrick McHardy) by Patrick McHardy · 19 years ago
- efa8fc2 get rid of numerous gcc-4 warnings by Harald Welte · 19 years ago
- daa1ef3 add NFQUEUE support for ipv4 and ipv6 by Harald Welte · 19 years ago
- 893b688 fix various missing header file / #define issues on old kernels. I've now tested compilation with kernels starting 2.4.17 by Harald Welte · 19 years ago
- 63d68bf we need to have this header file included, since old kernels don't define IP6T_LOG_UID. by Harald Welte · 19 years ago
- 20900e1 bump version number to 1.3.2 by Harald Welte · 19 years ago
- e2efcfc add note to https://bugzilla.netfilter.org/bugzilla/show_bug.cgi?id=334 by Harald Welte · 19 years ago
- 195ae91 attempt to fix save/restore of '! --uid-owner squid' problem as reported by Costa Tsaousis (backport from ipv4 owner) by Harald Welte · 19 years ago
- 64d900f add pointer to bugzilla by Harald Welte · 19 years ago
- ffd403f we don't have any counter issues in sparc64 by Harald Welte · 19 years ago
- 0c4c91c Add --log-uid support to libip6t_LOG (Patrick McHardy <kaber@trash.net>) by Patrick McHardy · 19 years ago
- 5ee8862 fix deletion of targets where kernel size != userspace size (Pablo Neira) by Pablo Neira · 19 years ago
- 9867e81 reduce code replication of parse_interface() (Yasuyuki Kozakai) by Yasuyuki KOZAKAI · 19 years ago
- a3a9c0d This patch prevents user to set negative port value of SNAT/DNAT. by Yasuyuki KOZAKAI · 19 years ago
- 8d8c8ea Chain name should not start with '!' (Yasuyuki Kozakai <yasuyuki.kozakai@toshiba.co.jp>) by Yasuyuki KOZAKAI · 19 years ago
- 595e493 Flush chain with noflush when it is redefined (Charlie Brady <charlieb-netfilter-devel@budge.apana.org.au>) by Charlie Brady · 19 years ago
- 38eb730 OSF: lib_ipt.c changes to support connector notifications (Evgeniy Polyakov <johnpol@2ka.mipt.ru>) by Evgeniy Polyakov · 19 years ago
- 86c8513 update multiport manpage (Phil Oester <kernel@linuxace.com>) by Phil Oester · 19 years ago
- f3aa491 Fix CONNMARK save/restore (Tom Eastep <teastep@shorewall.net>, Pawel Sikora <pluto@agmk.net>) by Tom Eastep · 19 years ago
- dfdcd64 Release previously merged options from merge_opts(), reduces memory-usage of iptables-restore dramatically (Pablo Neira) by Pablo Neira · 19 years ago
- 56506a1 While adding testing for inversion of multiport, noticed that documentation about --ports is *wrong*. Ports do not have to be equal: either dest or src being in list is enough for match. by Rusty Russell · 19 years ago
- 38ed421 include FIN bit in mask of "--syn" bits by Harald Welte · 20 years ago
- e556800 Ignore unknown arguments in libipt_ULOG (Patrick McHardy <kaber@trash.net>) by Patrick McHardy · 20 years ago
- 1c0f236 Fix connbytes command line parsing bug (Piotrek Kaczmarek <kaczorek@daleka.net>) by Piotrek Kaczmarek · 20 years ago
- 7d77451 pull out pmtu changes to fix compilation issues by Harald Welte · 20 years ago
- e267792 poll goto specific changes out of trunk by Harald WeltePablo Neira · 20 years ago
- 1a39d1e fix iptables-save/restore of goto (Jonas Berlin) by Jonas Berlin · 20 years ago
- 6b5effc omeone forgot to update ipt_conntrack.h header in user space. So, update it to use ip_conntrack_old_tuple. (Pablo Neira) by Harald WeltePablo Neira · 20 years ago
- 7a8bdfd add REJECT with icmp-frag-needed (Florian Lohoff) by Florian Lohoff · 20 years ago
- 182f3f6 don't allow newlines in LOG prefix (Phil Oester) (Closes: #312) by Phil Oester · 20 years ago
- 1b91e59 re-sync ip6tables with iptables (check for init functions) (Jonas Berlin) by Jonas Berlin · 20 years ago
- f33c461 add lots of man pages (Jonas Berlin) by Jonas Berlin · 20 years ago
- 4a06cf0 the optflags array contains a '3' for the OPT_LINENUMBERS entry while everywhere else '0' is used (Jonas Berlin) by Jonas Berlin · 20 years ago
- b9e814c SET target bugfix by Michal Pokrywka applied by Michal Pokrywka · 20 years ago
- 1afcffd Fix TCPLAG version (Torsten Lüttgert <t.luettgert@pressestimmen.de>) by Torsten Lüttgert · 20 years ago
- 8b7cc8a improve REDIRECT manpage (Jonas Berlin <xkr47@outerspace.dyndns.org>) by Jonas Berlin · 20 years ago
- fc4b10c bump version to 1.3.1 by Harald Welte · 20 years ago
- 800938f This fixes rule deletion in CLUSTERIP in iptables (Pablo Neira) by Pablo Neira · 20 years ago
- 9d3ed77 Restore chain order (Olaf Rempel <razzor@kopf-tisch.de>) by Olaf Rempel · 20 years ago
- 8115e54 Kill NFC_* stuff in iptables (Pablo Neira <pablo@eurodev.net>) by Pablo Neira · 20 years ago
- 69558bf Allow "--realm ! foo" and "! --realm foo" (Closes: #297) by Harald Welte · 20 years ago
- 8430fb9 fix missing comma at end of line by Harald Welte · 20 years ago
- 02964b8 Fix CONNMARK/connmark issues with 64bit kernel and 32bit userspace. by Martin Josefsson · 20 years ago
- c10f251 time to release 1.3.0 final by Harald Welte · 20 years ago
- 21ccef2 remove way outdated files by Harald Welte · 20 years ago
- c271df7 update notes to reflect subversion usage by Harald Welte · 20 years ago
- 61d274f try to fix realm save/restore issue (Adresses: #297) by Harald Welte · 20 years ago