Update blacklist-helper to not emit messages from pf during operation.Use 'pfctl -k' when blocking a site to kill active tcp connectionsfrom the blocked address.Fix 'purge' operation for pf, whi
Update blacklist-helper to not emit messages from pf during operation.Use 'pfctl -k' when blocking a site to kill active tcp connectionsfrom the blocked address.Fix 'purge' operation for pf, which must dynamically determine whichfilters have been created, so the filters can be flushed by name.MFC after: 2 weeks
show more ...
Merge latest version of blacklist sources from NetBSD (@ 20170503)MFC after: 3 daysSponsored by: The FreeBSD Foundation
Improve ipfw rule creation for blacklist-helper scriptWhen blocking an address, the blacklist-helper scriptneeds to do the following things for the ipfw packetfilter: - create a table to hold t
Improve ipfw rule creation for blacklist-helper scriptWhen blocking an address, the blacklist-helper scriptneeds to do the following things for the ipfw packetfilter: - create a table to hold the addresses to be blocked, so lookups can be done quickly, and place the address to be blocked in that table - create rule that does the lookup in the table and blocks the packetThe ipfw system allows multiple rules to be inserted fora given rule number. There only needs to be one ruleto do the lookup per port. Modify the script to probefor the existence of the rule before attempting to createit, so only one rule is inserted, rather than one rule perblocked address.PR: 214980Reported by: azhegalov (at) gmail.comReviewed by: emasteMFC after: 3 daysSponsored by: The FreeBSD FoundationDifferential Revision: https://reviews.freebsd.org/D9681
Make blacklist-helper commands emit a message when successfulThe blacklistd daemon expects to see a message on stdout, insteadof just relying on the exit value from any invoked programs.Change t
Make blacklist-helper commands emit a message when successfulThe blacklistd daemon expects to see a message on stdout, insteadof just relying on the exit value from any invoked programs.Change the pf filtering to create multiple filters, attached undera the "blacklist/*" anchor point. This prevents the filtering foreach port's filtering rule from overwriting the previously installedfiltering rule. Check for an existing filtering rule for each port,so the installation of a given filtering rule only happens once.Reinstalling the same rule resets the counters for the pf rule, andwe don't want that.Reported by: David Horn (dhorn2000 at gmail.com)Reviewed by: emasteMFC after: 1 weekSponsored by: The FreeBSD FoundationDifferential Revision: https://reviews.freebsd.org/D8081
Add ipfilter support to blacklistd-helperIn addition to adding initial support for the ipfilterpacket filtering system, wrap a few long lines, performwhitespace cleanup and sync with upstream cha
Add ipfilter support to blacklistd-helperIn addition to adding initial support for the ipfilterpacket filtering system, wrap a few long lines, performwhitespace cleanup and sync with upstream changes madein NetBSD.Submitted by: cyReviewed by: cyApproved by: re (hrs)Relnotes: YESSponsored by: The FreeBSD FoundationDifferential Revision: https://reviews.freebsd.org/D6823
Add IPFW support to blacklistd-helperRelnotes: YESSponsored by: The FreeBSD FoundationDifferential Revision: https://reviews.freebsd.org/D6753
Import NetBSD's blacklist source from vendor treeThis import includes The basic blacklist library and utility programs,to add a system-wide packet filtering notification mechanism toFreeBSD.The
Import NetBSD's blacklist source from vendor treeThis import includes The basic blacklist library and utility programs,to add a system-wide packet filtering notification mechanism toFreeBSD.The rational behind the daemon was given by Christos Zoulas in apresentation at vBSDcon 2015: https://youtu.be/fuuf8G28mjsReviewed by: rpauloApproved by: rpauloObtained from: NetBSDRelnotes: YESSponsored by: The FreeBSD FoundationDifferential Revision: https://reviews.freebsd.org/D5912