Ecosyste.ms: OpenCollective
An open API service for software projects hosted on Open Collective.
github.com/vyos/vyatta-cfg-vpn
Vyatta VPN configuration
https://github.com/vyos/vyatta-cfg-vpn
8353f0f8fc746c69d6006e5bba9baf45afe16385 authored almost 9 years ago by Kim Hagen <[email protected]>
fbddff7f2b6b485c93b5d3cf4d60a75f84c3a2b6 authored almost 9 years ago by Kim Hagen <[email protected]>
4b73a852d2fbc9ce60a31c10c7052ef5aef16fee authored almost 9 years ago by Kim Hagen <[email protected]>
bbd5b2a113cb64c872142b236b35c650804271eb authored almost 9 years ago by Kim Hagen <[email protected]>
5ee99ec9d5cca8c13804964eee23ce0b15578edf authored almost 9 years ago by Jeff Leung <[email protected]>
b558c886bf89e0fdf88ee991dc88d45f3b8dc95d authored almost 9 years ago by Daniil Baturin <[email protected]>
Update standards version and description.
28cb3d1d5b62595f3c033b85029132fec11b3c2d authored almost 9 years ago by Daniil Baturin <[email protected]>d6bb593aa88a8ffbd4eeb46e1e96b4a6dcb3fb16 authored almost 9 years ago by Kim Hagen <[email protected]>
cf093a78ecae246c52be0ad39ac894013aa2adfd authored about 9 years ago by Thomas Jepp <[email protected]>
Conflicts:
templates/vpn/ipsec/esp-group/node.tag/proposal/node.tag/encryption/node.def
templa...
Perltidy run on scripts/vyatta-vti-config.pl to have consistent
identation levels and style thro...
Remove old comments and other minor tidying up / rearranging of
scripts/vyatta-vti-config.pl
Validate the local address used for VTI based VPN connections to ensure
only either an IPv4 or I...
VTI interfaces can remain link down after IPSec SA expiry and renewal,
leaving the actual IPSec ...
Validate the peer address used for VTI based VPN connections to ensure
only either an IPv4 or IP...
fcab32f8c5cc416829dc054a41e578eae45951fa authored about 9 years ago by Daniil Baturin <[email protected]>
to the ipsec config
c9484a3906157a059b02c7619df4617ab8e2dee1 authored about 9 years ago by Kim Hagen <[email protected]>
Starting with strongSwan 5.3.3, chacha20poly1305 is a supported cipher for
IKE and ESP configura...
f179c69fcfd84d4889aec93bf87fdb265106f29e authored about 9 years ago by Jeff Leung <[email protected]>
This may be useful for scenarios where a user prefers to use an ECDSA key
or implement an xauth ...
8aa86bf3a045c51bae264a5716dd3d9c1063411e authored about 9 years ago by Jeff Leung <[email protected]>
5c1672341b33dc726da5d7845725bd74e3cc7cb6 authored over 9 years ago by Alex Harpin <[email protected]>
Validate the local address used for VTI based VPN connections to ensure
only either an IPv4 or I...
6237d4de2e8c64c1de42c42a070ef74907810dd7 authored over 9 years ago by Alex Harpin <[email protected]>
Validate the peer address used for VTI based VPN connections to ensure
only either an IPv4 or IP...
64fb9c14f25580ee6412643566c90879cd247ff1 authored over 9 years ago by Alex Harpin <[email protected]>
VTI interfaces can remain link down after IPSec SA expiry and renewal,
leaving the actual IPSec ...
Remove old comments and other minor tidying up / rearranging of
scripts/vyatta-vti-config.pl
Perltidy run on scripts/vyatta-vti-config.pl to have consistent
identation levels and style thro...
e0df1591e69b4228af9cb695853cb7c67fed6e2d authored over 9 years ago by Alex Harpin <[email protected]>
e4899aa23be30061fa94bd9c19b17431e299b709 authored over 9 years ago by Alex Harpin <[email protected]>
88aac84e3e49fd179ab2c75d8563c231aeda4926 authored over 9 years ago by Daniil Baturin <[email protected]>
5bfd6dcf50a76a9427141cc3d62f23f8be7f4543 authored over 9 years ago by Daniil Baturin <[email protected]>
Update support for RSA keys with strongSwan 5.2.x
070c754a733258a4b6900b01dd3ec141debcc9a8 authored over 9 years ago by Jeff Leung <[email protected]>321419cbd0cb81a8573316fb84a6bbbc20aa29f4 authored over 9 years ago by Daniil Baturin <[email protected]>
a914ffc44c888dc2591965c36363aa2a8de4a3bd authored over 9 years ago by Daniil Baturin <[email protected]>
158f7b865099010be751517d65c223c12c60dbdd authored almost 10 years ago by Alex Harpin <[email protected]>
6656e3ae1a2e9a1b4bb7d8eecf320f840b6837c2 authored almost 10 years ago by Ryan Riske <[email protected]>
57d284aded5003468dee946f906bf88f09a79d5a authored almost 10 years ago by Ryan Riske <[email protected]>
strongSwan 5.2.x no longer recognizes keys in RFC 3110 format inlined in
ipsec.conf and ipsec.se...
to the ipsec config
2e30fd044c830bddae7e4951b46b2346d7e3fbc0 authored almost 10 years ago by Kim Hagen <[email protected]>
Since charon's existence, generating them is redundant and as a matter of fact
causes issues wit...
This might help with strongSwan traversing through firewalls that
filter proto 51, but not UDP t...
6d36ea1fce45ec0cf4e085b5e8c441fd71659f54 authored almost 10 years ago by Alex Harpin <[email protected]>
As confirmed by Thermi in the strongSwan IRC channel inside freenode,
this parameter should not ...
If the user defines main mode, the config script will always enable
aggressive mode. Fix the log...
Originally we meant aggressive, not ikev2
832208422595261e1044890c18c16998a9aaf421 authored almost 10 years ago by Jeff Leung <[email protected]>
Since we're invoking the logger at runtime, there's really no point
on keeping this codeblock
Instead of configuring the ipsec logger at config time, configure
it at runtime. The codeblock t...
f0493b3e300c9553c9a2fbe813ef02de0af41e3f authored almost 10 years ago by Jeff Leung <[email protected]>
strongSwan's charon by design maintains all established connections
regardless, even if the conn...
This needs to be updated or VPN configurations won't be properly
handled on subsequent updates.
Setting this to a default value breaks ikev2 configurations since
aggressive mode is only applic...
For some odd reason doing an ipsec update does not make charon
pick up any newly created tunnels...
log-modes now expose charon's keywords instead of pluto's keywords.
Refer to the strongSwan's m...
cb76ae8fbdffa0c8dee28b95867776955806f025 authored almost 10 years ago by Jeff Leung <[email protected]>a64d08fe6cfbc6275c2682fbe92d4856334deec2 authored almost 10 years ago by Jeff Leung <[email protected]>
Although strongly not recommended by the developers of strongSwan,
sometimes remote VPN gateways...
1be0e699d43e2ea72b791c502749d78d9acc9e84 authored almost 10 years ago by Kim Hagen <[email protected]>
In strongSwan 5.0.0 and later series, pfs= and pfsgroup= parameters have
now been removed.
Since strongSwan 5.0.0, defining the PFS group settings has moved in the
esp= parameter.
If PFS...
d1618604bde40ae38ba3b587e655f16948212917 authored almost 10 years ago by Jeff Leung <[email protected]>
The IKE parameter parser now uses the new get_dh_cipher_result submodule
instead of the old if/e...
By adding this submodule we can reduce the amount of code we need to
maintain by having a single...
In preperation of moving towards the strongSwan 5.x series, we are
removing the legacy charonsta...
791097277d7ec62cc6c3f9b418d75b4a1a713759 authored almost 10 years ago by Daniil Baturin <[email protected]>
c17fd43333abc10cd0c9f644e2cb66b87064be00 authored almost 10 years ago by Daniil Baturin <[email protected]>
d7a394249c54dc951b8e78d2294b9e9c50612204 authored almost 10 years ago by Daniil Baturin <[email protected]>
a020c3ac4bb4bb22d909261d370811d35e9799b8 authored almost 10 years ago by Daniil Baturin <[email protected]>
5cf14ba5c537a4df57522e0b54a44b8912168be6 authored almost 10 years ago by Alex Harpin <[email protected]>
Updated the help for pre-shared secret key usage when special
characters are used. These need t...
90057becb0a3aac0636282b43aaf8b7ac4e7b967 authored about 10 years ago by Alex Harpin <[email protected]>
993f47c0d9eac439ae6d698a75d2e6e6b98a963d authored about 10 years ago by Alex Harpin <[email protected]>
831009e4c755e1e0ea16e5931b0416a21430d4a6 authored about 10 years ago by Daniil Baturin <[email protected]>
9ebf737b55b8974edac26d1275c77da15a6199a2 authored about 10 years ago by Daniil Baturin <[email protected]>
abd609b8947b8d731b0a1fa084c724b08dcbf3a6 authored about 10 years ago by Daniil Baturin <[email protected]>
Ikev2 reauth option
7b0e7ce1c46cec565952b18a5044f7bc7be82196 authored about 10 years ago by Daniil Baturin <[email protected]>478615bf9d92e79b66d89c37473b4bd457a76260 authored about 10 years ago by Alex Harpin <[email protected]>
The cfgvti helper program was originally added for configuring VTIs.
The functionality it provid...
a304c0754bdbf7cf70d30d12aac59c21f813dcf7 authored about 10 years ago by Alex Harpin <[email protected]>
Update lib/Vyatta/VPN/vtiIntf.pm to have consistent identation levels
and style throughout.
Reduce the vtiMarkBase value to prevent integer overflow on the created
ip xfrm states and polic...
Update the VTI creation process to go along with the changes added to
the vyatta-strongswan pack...
Update the parseVtiTun function to account for the new way of
configuring VTIs.
Bug #358 http:/...
09f1979c4bf0cfe1e1c60ca48b4d9be3cc5e0454 authored about 10 years ago by Alex Harpin <[email protected]>
Move vtiIntf.pm to a more logical place, in line with all the other
packages.
259abd0641a999e390d67cb424c9093e1c0f72bf authored about 10 years ago by Jason Hendry <[email protected]>
ae063db6eb21bb52ae5e995dfa4bef195de599be authored about 10 years ago by Jason Hendry <[email protected]>
dd17f6db97ad7e7f58e371e4b6f3ca5eceb4f3a0 authored about 10 years ago by Daniil Baturin <[email protected]>
d6bdf4f5edda42d0cef7b9146c0b9477e6a4f7a5 authored about 10 years ago by Daniil Baturin <[email protected]>
15caf2de5ee1f40568c30b3276f305a5708276ac authored about 10 years ago by Daniil Baturin <[email protected]>
d4221b8a5b38333e57b2fd5f8c42b7316fc8df59 authored about 10 years ago by Daniil Baturin <[email protected]>
8f276005e1e0fd61801b98e3e8e2bb90c15005c3 authored over 10 years ago by Daniil Baturin <[email protected]>
Commits for Bug #291 and Bug #332
be48755c2d00210f8c80696aea3b4be74bff0247 authored over 10 years ago by Daniil Baturin <[email protected]>
Prevent duplicate include statements, for the local rsa keys, being
added to the ipsec.secrets f...
Update scripts/vpn-config.pl to have consistent identation levels and
style throughout.
Rename vti-up-down.sh to vti-up-down to be consistent with others.
a45c529838e42e5584b9cb991c893d1675054b35 authored over 10 years ago by Alex Harpin <[email protected]>
Revert the fix put in place for Bug #183 as this causes multiple routes
to be installed when mor...
vyatta-cfg-vpn: add libnfnetlink-dev to build dependencies
62253b1ddf16631ec772cb8ff480d35bd989ffb6 authored over 10 years ago by Daniil Baturin <[email protected]>c72ae615426b77084e62672eaa62f6f40ba7e2c8 authored over 10 years ago by Alex Harpin <[email protected]>
Add libnfnetlink-dev to the list of build dependencies, required for
compiling src/cfgcti.
Bug ...
cf2c33b51d1799a70bb1b685edf1467f612c88d2 authored over 10 years ago by Alex Harpin <[email protected]>f1db9734ca1538f7bfc4829f53d56047fa921c32 authored over 10 years ago by Kim Hagen <[email protected]>
65a56dafd8acb7caa09a47a8e013472c6a03a016 authored over 10 years ago by Kim Hagen <[email protected]>