Commit Graph

124 Commits

Author SHA1 Message Date
Daniel Ding
4b9a53a54e fix: load acls from json 2024-03-27 15:46:48 +08:00
Daniel Ding
34c452c41d fea: support add or del acl rule 2024-03-27 13:17:41 +08:00
Daniel Ding
e4c6b4376e fea: support metrics via prometheus 2024-03-12 15:00:53 +00:00
Daniel Ding
3619f393b5 fix: dhcp without host interface 2024-01-27 20:21:26 +08:00
Daniel Ding
335d273f70 fix: set gre mtu to 1450 2024-01-24 16:40:35 +08:00
Daniel Ding
d285594f33 fea: support dstport for vxlan 2024-01-24 15:37:29 +08:00
Daniel Ding
430cf1c5d8 fix: format output parameters 2024-01-23 10:42:20 +08:00
Daniel Ding
4d76ae91af fix: update hi-xx mtu when has outputs 2024-01-17 22:25:31 +08:00
Daniel Ding
44dee5de3c fix: dont request address for link 2024-01-16 22:43:56 +08:00
Daniel Ding
6226cc0b15 fix: unload routes firstlly 2024-01-14 17:51:00 +08:00
Daniel Ding
c8a6fd68f9 fix: replace input as vrf 2024-01-11 21:53:27 +08:00
Daniel Ding
6283f49713 fix: output from vrf dont goto zone 2024-01-11 20:17:32 +08:00
Daniel Ding
64866cb4da fea: support ct zone #24 2024-01-11 18:47:32 +08:00
Daniel Ding
1fc23f3db8 fea: support vrf for a network 2024-01-10 22:37:09 +08:00
Daniel Ding
c542a184cc fea: add statics for output 2024-01-08 20:56:21 +08:00
Daniel Ding
53dcac37f9 fea: switch: support key options for gretap 2024-01-08 17:35:36 +08:00
Daniel Ding
044c529532 fix: vxlan name prefixas vxn 2024-01-08 15:08:32 +08:00
Daniel Ding
4854546db8 fix: update docs 2024-01-07 21:51:33 +08:00
Daniel Ding
8c30f6122f fix: switch: set mtu to 1450 for vxlan 2024-01-06 22:38:54 +08:00
Daniel Ding
403cdbfd27 fix: openvpn: default route not add to ipset 2024-01-06 15:56:23 +08:00
Daniel Ding
8159e73256 fix: vxlan support openvpn 2024-01-06 00:21:52 +08:00
Daniel Ding
11f032c358 fix: update ztrust.md 2024-01-03 10:54:19 +08:00
Daniel Ding
d8f2a2193a fix: not clear rules after deleting guest 2024-01-02 16:51:20 +08:00
Daniel Ding
77fa149380 fea: support age timer for knock 2024-01-02 15:53:19 +08:00
Daniel Ding
1af91f2f65 fix: support list guest and knock 2024-01-02 11:14:54 +08:00
Daniel Ding
9a039a6d3c fea: add commands for zero trust 2024-01-01 22:38:07 +08:00
Daniel Ding
e856c6dfe0 fea: support zero trust 2023-12-31 20:48:16 +08:00
Daniel Ding
6efbb74f0f fea: support import profile from openvpn client 2023-12-29 17:04:13 +08:00
Daniel Ding
d5bf8a9064 fix: move acl from raw to mangle 2023-12-27 23:00:44 +08:00
Daniel Ding
9909380092 fea: support get openvpn file from user 2023-12-27 21:24:02 +08:00
Daniel Ding
04092ee0c5 support: cmd: set log level 2023-11-14 13:18:50 +08:00
Daniel Ding
c9f96beba8 fix: confd: ignore virtual link not change 2023-11-13 17:49:54 +08:00
Daniel Ding
e1898579d3 review: ipsec esp code. 2023-11-13 17:47:17 +08:00
Daniel Ding
0488e5c2fd fea: updating info for virtual link 2023-11-08 17:09:32 +08:00
Daniel Ding
668788dc0d fix: cert not update 2023-09-26 20:50:55 +08:00
Daniel Ding
b093aefd8c fea: switch: router support openvpn
Signed-off-by: Daniel Ding <danieldin186@gmail.com>
2023-09-26 19:51:14 +08:00
Daniel Ding
6f976111f3 fea: set ct state for openlan network. 2023-09-26 16:16:04 +08:00
Daniel Ding
a15a737e2c fea: switch: support router network 2023-09-26 15:32:34 +08:00
Daniel Ding
29a74c42b4 fix: switch: print LoadRoute info using save var rt
Signed-off-by: Daniel Ding <danieldin186@gmail.com>
2023-09-23 14:41:46 +08:00
Daniel Ding
6711d43b39 switch: fix del iptable rule failed when stopping
Signed-off-by: Daniel Ding <danieldin186@gmail.com>
2023-09-16 12:47:23 +08:00
zhihui.ding
593908f1fc fix: switch: 0.0.0.0/0 as invalid CIDR for ipset
Signed-off-by: zhihui.ding <danieldin186@gmail.com>
2023-09-10 21:30:58 +08:00
zhihui.ding
21ab345adc fix: network: ipset in sbin 2023-09-09 23:17:19 +08:00
zhihui.ding
c4f7b9cdc5 fea: switch: support ipset
Signed-off-by: zhihui.ding <danieldin186@gmail.com>
2023-09-09 18:39:46 +08:00
zhihui.ding
c080fafed0 openlan: route to vpn subnet
Signed-off-by: zhihui.ding <danieldin186@gmail.com>
2023-09-07 18:40:29 +08:00
zhihui.ding
e271313307 fix: cache: let ldap promise to backend 2023-09-07 10:30:42 +08:00
zhihui.ding
b2ee3d9b2e fix: firewall: add comments for iptable rules
Signed-off-by: zhihui.ding <danieldin186@gmail.com>
2023-08-24 22:11:56 +08:00
zhihui.ding
d118d36039 fix: openlan: set hostname as default for client server.
Signed-off-by: zhihui.ding <danieldin186@gmail.com>
2023-08-20 15:57:14 +08:00
zhihui.ding
123b1c7112 fix: openlan: update routes of openvpn.
Signed-off-by: zhihui.ding <danieldin186@gmail.com>
2023-08-19 22:10:28 +08:00
zhihui.ding
b20c501762 switch: let iptables to network from switch.
Signed-off-by: zhihui.ding <danieldin186@gmail.com>
2023-08-19 16:00:48 +08:00
zhihui.ding
771537c1dc firewall: introduce iptables per network.
Signed-off-by: zhihui.ding <danieldin186@gmail.com>
2023-08-19 13:43:44 +08:00