From mboxrd@z Thu Jan 1 00:00:00 1970 From: git@ipfire.org To: ipfire-scm@lists.ipfire.org Subject: [git.ipfire.org] IPFire 2.x development tree branch, fifteen, updated. f5e106c42ab1fcb54f2d4c2605dfbe213b5b792a Date: Tue, 07 Jan 2014 17:56:17 +0100 Message-ID: <20140107165618.0C50F205A3@argus.ipfire.org> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============0206138565869275462==" List-Id: --===============0206138565869275462== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable This is an automated email from the git hooks/post-receive script. It was generated because a ref change was pushed to the repository containing the project "IPFire 2.x development tree". The branch, fifteen has been updated via f5e106c42ab1fcb54f2d4c2605dfbe213b5b792a (commit) via af8750fdc2c974899c35114a7340f51a09516bd9 (commit) via d2d87f2ca06349f63d025e12dafda1b910956e40 (commit) via 4ad0b5b680e7d72f391434a9bad0a2dfc61fee92 (commit) via afd5d8f76e725ac910c238e94f2282f78bce5da7 (commit) via cbb3a8f91e2e7aa220b5bc9e9773fa4547f0ce85 (commit) via 4e156911cc45c2788bfa7e04561e2a7e550c68b8 (commit) from 277060a472c826541885b40392e0d5a96ba1cf97 (commit) Those revisions listed above that are new to this repository have not appeared on any other notification email; so we list those revisions in full, below. - Log ----------------------------------------------------------------- commit f5e106c42ab1fcb54f2d4c2605dfbe213b5b792a Merge: 277060a af8750f Author: Michael Tremer Date: Tue Jan 7 17:55:57 2014 +0100 Merge remote-tracking branch 'ms/ipsec-dpd' into fifteen commit af8750fdc2c974899c35114a7340f51a09516bd9 Author: Michael Tremer Date: Tue Jan 7 17:54:10 2014 +0100 Update translations. commit d2d87f2ca06349f63d025e12dafda1b910956e40 Author: Michael Tremer Date: Tue Jan 7 17:50:44 2014 +0100 IPsec: Make connection configuration more pleasant for the eye. commit 4ad0b5b680e7d72f391434a9bad0a2dfc61fee92 Author: Michael Tremer Date: Tue Jan 7 17:08:35 2014 +0100 IPsec: Move IKE protocol option to advanced settings page. commit afd5d8f76e725ac910c238e94f2282f78bce5da7 Author: Michael Tremer Date: Tue Jan 7 17:00:30 2014 +0100 IPsec: Allow to disable DPD. commit cbb3a8f91e2e7aa220b5bc9e9773fa4547f0ce85 Author: Michael Tremer Date: Tue Jan 7 01:37:00 2014 +0100 IPsec: Fix and enhance DPD configuration. =20 Also the action option has now moved to the advanced settings page and the design has been improved. commit 4e156911cc45c2788bfa7e04561e2a7e550c68b8 Author: Alexander Marx Date: Tue Jan 7 00:38:36 2014 +0100 IPsec: Add DPD configuration options to advanced settings. ----------------------------------------------------------------------- Summary of changes: doc/language_issues.de | 3 +- doc/language_issues.en | 2 +- doc/language_issues.es | 7 ++ doc/language_issues.fr | 7 ++ doc/language_issues.nl | 7 ++ doc/language_issues.pl | 7 ++ doc/language_issues.ru | 7 ++ doc/language_issues.tr | 7 ++ doc/language_missings | 16 ++++ html/cgi-bin/vpnmain.cgi | 231 +++++++++++++++++++++++++++++++++++----------= -- langs/de/cgi-bin/de.pl | 4 + langs/en/cgi-bin/en.pl | 7 +- 12 files changed, 242 insertions(+), 63 deletions(-) Difference in files: diff --git a/doc/language_issues.de b/doc/language_issues.de index bcc0214..02c9990 100644 --- a/doc/language_issues.de +++ b/doc/language_issues.de @@ -150,6 +150,7 @@ WARNING: translation string unused: eciadsl upload WARNING: translation string unused: edit network WARNING: translation string unused: edit service WARNING: translation string unused: editor +WARNING: translation string unused: eg WARNING: translation string unused: email server can not be empty WARNING: translation string unused: enable javascript WARNING: translation string unused: enabled on @@ -198,7 +199,6 @@ WARNING: translation string unused: from warn email bad WARNING: translation string unused: fwdfw MODE1 WARNING: translation string unused: fwdfw MODE2 WARNING: translation string unused: fwdfw err prot_port1 -WARNING: translation string unused: fwdfw err tgt_port WARNING: translation string unused: fwdfw final_rule WARNING: translation string unused: fwdfw from WARNING: translation string unused: fwdfw ipsec network @@ -572,6 +572,7 @@ WARNING: untranslated string: Scan for Songs WARNING: untranslated string: advproxy cache-digest WARNING: untranslated string: bytes WARNING: untranslated string: community rules +WARNING: untranslated string: dead peer detection WARNING: untranslated string: emerging rules WARNING: untranslated string: fwhost err hostip WARNING: untranslated string: new diff --git a/doc/language_issues.en b/doc/language_issues.en index 1eccc80..b6b506f 100644 --- a/doc/language_issues.en +++ b/doc/language_issues.en @@ -173,6 +173,7 @@ WARNING: translation string unused: eciadsl upload WARNING: translation string unused: edit network WARNING: translation string unused: edit service WARNING: translation string unused: editor +WARNING: translation string unused: eg WARNING: translation string unused: email server can not be empty WARNING: translation string unused: enable javascript WARNING: translation string unused: enabled on @@ -221,7 +222,6 @@ WARNING: translation string unused: from warn email bad WARNING: translation string unused: fwdfw MODE1 WARNING: translation string unused: fwdfw MODE2 WARNING: translation string unused: fwdfw err prot_port1 -WARNING: translation string unused: fwdfw err tgt_port WARNING: translation string unused: fwdfw final_rule WARNING: translation string unused: fwdfw from WARNING: translation string unused: fwdfw ipsec network diff --git a/doc/language_issues.es b/doc/language_issues.es index 6b6424a..d32c90a 100644 --- a/doc/language_issues.es +++ b/doc/language_issues.es @@ -167,6 +167,7 @@ WARNING: translation string unused: eciadsl upload WARNING: translation string unused: edit network WARNING: translation string unused: edit service WARNING: translation string unused: editor +WARNING: translation string unused: eg WARNING: translation string unused: email server can not be empty WARNING: translation string unused: enable javascript WARNING: translation string unused: enabled on @@ -595,6 +596,7 @@ WARNING: untranslated string: ccd none WARNING: untranslated string: ccd routes WARNING: untranslated string: ccd subnet WARNING: untranslated string: ccd used +WARNING: untranslated string: dead peer detection WARNING: untranslated string: default ip WARNING: untranslated string: deprecated fs warn WARNING: untranslated string: dnat address @@ -605,6 +607,8 @@ WARNING: untranslated string: dnsforward edit an entry WARNING: untranslated string: dnsforward entries WARNING: untranslated string: dnsforward forward_server WARNING: untranslated string: dnsforward zone +WARNING: untranslated string: dpd delay +WARNING: untranslated string: dpd timeout WARNING: untranslated string: drop action WARNING: untranslated string: drop action1 WARNING: untranslated string: drop action2 @@ -664,6 +668,7 @@ WARNING: untranslated string: fwdfw err src_addr WARNING: untranslated string: fwdfw err tgt_addr WARNING: untranslated string: fwdfw err tgt_grp WARNING: untranslated string: fwdfw err tgt_mac +WARNING: untranslated string: fwdfw err tgt_port WARNING: untranslated string: fwdfw err time WARNING: untranslated string: fwdfw external port nat WARNING: untranslated string: fwdfw hint ip1 @@ -774,6 +779,8 @@ WARNING: untranslated string: fwhost used WARNING: untranslated string: fwhost welcome WARNING: untranslated string: grouptype WARNING: untranslated string: integrity +WARNING: untranslated string: invalid input for dpd delay +WARNING: untranslated string: invalid input for dpd timeout WARNING: untranslated string: least preferred WARNING: untranslated string: lifetime WARNING: untranslated string: minute diff --git a/doc/language_issues.fr b/doc/language_issues.fr index 2f7f60d..344c234 100644 --- a/doc/language_issues.fr +++ b/doc/language_issues.fr @@ -167,6 +167,7 @@ WARNING: translation string unused: eciadsl upload WARNING: translation string unused: edit network WARNING: translation string unused: edit service WARNING: translation string unused: editor +WARNING: translation string unused: eg WARNING: translation string unused: email server can not be empty WARNING: translation string unused: enable javascript WARNING: translation string unused: enabled on @@ -597,6 +598,7 @@ WARNING: untranslated string: ccd none WARNING: untranslated string: ccd routes WARNING: untranslated string: ccd subnet WARNING: untranslated string: ccd used +WARNING: untranslated string: dead peer detection WARNING: untranslated string: default ip WARNING: untranslated string: deprecated fs warn WARNING: untranslated string: dnat address @@ -608,6 +610,8 @@ WARNING: untranslated string: dnsforward edit an entry WARNING: untranslated string: dnsforward entries WARNING: untranslated string: dnsforward forward_server WARNING: untranslated string: dnsforward zone +WARNING: untranslated string: dpd delay +WARNING: untranslated string: dpd timeout WARNING: untranslated string: drop action WARNING: untranslated string: drop action1 WARNING: untranslated string: drop action2 @@ -667,6 +671,7 @@ WARNING: untranslated string: fwdfw err src_addr WARNING: untranslated string: fwdfw err tgt_addr WARNING: untranslated string: fwdfw err tgt_grp WARNING: untranslated string: fwdfw err tgt_mac +WARNING: untranslated string: fwdfw err tgt_port WARNING: untranslated string: fwdfw err time WARNING: untranslated string: fwdfw external port nat WARNING: untranslated string: fwdfw hint ip1 @@ -777,6 +782,8 @@ WARNING: untranslated string: fwhost used WARNING: untranslated string: fwhost welcome WARNING: untranslated string: grouptype WARNING: untranslated string: integrity +WARNING: untranslated string: invalid input for dpd delay +WARNING: untranslated string: invalid input for dpd timeout WARNING: untranslated string: least preferred WARNING: untranslated string: lifetime WARNING: untranslated string: minute diff --git a/doc/language_issues.nl b/doc/language_issues.nl index d543069..44d92e5 100644 --- a/doc/language_issues.nl +++ b/doc/language_issues.nl @@ -169,6 +169,7 @@ WARNING: translation string unused: eciadsl upload WARNING: translation string unused: edit network WARNING: translation string unused: edit service WARNING: translation string unused: editor +WARNING: translation string unused: eg WARNING: translation string unused: email server can not be empty WARNING: translation string unused: enable javascript WARNING: translation string unused: enabled on @@ -563,6 +564,7 @@ WARNING: untranslated string: advproxy errmsg proxy ports= equal WARNING: untranslated string: advproxy proxy port transparent WARNING: untranslated string: bytes WARNING: untranslated string: ccd iroute2 +WARNING: untranslated string: dead peer detection WARNING: untranslated string: default ip WARNING: untranslated string: dnat address WARNING: untranslated string: dnsforward @@ -572,6 +574,8 @@ WARNING: untranslated string: dnsforward edit an entry WARNING: untranslated string: dnsforward entries WARNING: untranslated string: dnsforward forward_server WARNING: untranslated string: dnsforward zone +WARNING: untranslated string: dpd delay +WARNING: untranslated string: dpd timeout WARNING: untranslated string: drop action WARNING: untranslated string: drop action1 WARNING: untranslated string: drop action2 @@ -613,6 +617,7 @@ WARNING: untranslated string: fwdfw err src_addr WARNING: untranslated string: fwdfw err tgt_addr WARNING: untranslated string: fwdfw err tgt_grp WARNING: untranslated string: fwdfw err tgt_mac +WARNING: untranslated string: fwdfw err tgt_port WARNING: untranslated string: fwdfw err time WARNING: untranslated string: fwdfw external port nat WARNING: untranslated string: fwdfw hint ip1 @@ -723,6 +728,8 @@ WARNING: untranslated string: fwhost used WARNING: untranslated string: fwhost welcome WARNING: untranslated string: grouptype WARNING: untranslated string: integrity +WARNING: untranslated string: invalid input for dpd delay +WARNING: untranslated string: invalid input for dpd timeout WARNING: untranslated string: least preferred WARNING: untranslated string: lifetime WARNING: untranslated string: most preferred diff --git a/doc/language_issues.pl b/doc/language_issues.pl index 6b6424a..d32c90a 100644 --- a/doc/language_issues.pl +++ b/doc/language_issues.pl @@ -167,6 +167,7 @@ WARNING: translation string unused: eciadsl upload WARNING: translation string unused: edit network WARNING: translation string unused: edit service WARNING: translation string unused: editor +WARNING: translation string unused: eg WARNING: translation string unused: email server can not be empty WARNING: translation string unused: enable javascript WARNING: translation string unused: enabled on @@ -595,6 +596,7 @@ WARNING: untranslated string: ccd none WARNING: untranslated string: ccd routes WARNING: untranslated string: ccd subnet WARNING: untranslated string: ccd used +WARNING: untranslated string: dead peer detection WARNING: untranslated string: default ip WARNING: untranslated string: deprecated fs warn WARNING: untranslated string: dnat address @@ -605,6 +607,8 @@ WARNING: untranslated string: dnsforward edit an entry WARNING: untranslated string: dnsforward entries WARNING: untranslated string: dnsforward forward_server WARNING: untranslated string: dnsforward zone +WARNING: untranslated string: dpd delay +WARNING: untranslated string: dpd timeout WARNING: untranslated string: drop action WARNING: untranslated string: drop action1 WARNING: untranslated string: drop action2 @@ -664,6 +668,7 @@ WARNING: untranslated string: fwdfw err src_addr WARNING: untranslated string: fwdfw err tgt_addr WARNING: untranslated string: fwdfw err tgt_grp WARNING: untranslated string: fwdfw err tgt_mac +WARNING: untranslated string: fwdfw err tgt_port WARNING: untranslated string: fwdfw err time WARNING: untranslated string: fwdfw external port nat WARNING: untranslated string: fwdfw hint ip1 @@ -774,6 +779,8 @@ WARNING: untranslated string: fwhost used WARNING: untranslated string: fwhost welcome WARNING: untranslated string: grouptype WARNING: untranslated string: integrity +WARNING: untranslated string: invalid input for dpd delay +WARNING: untranslated string: invalid input for dpd timeout WARNING: untranslated string: least preferred WARNING: untranslated string: lifetime WARNING: untranslated string: minute diff --git a/doc/language_issues.ru b/doc/language_issues.ru index 5a1296b..09c6930 100644 --- a/doc/language_issues.ru +++ b/doc/language_issues.ru @@ -166,6 +166,7 @@ WARNING: translation string unused: eciadsl upload WARNING: translation string unused: edit network WARNING: translation string unused: edit service WARNING: translation string unused: editor +WARNING: translation string unused: eg WARNING: translation string unused: email server can not be empty WARNING: translation string unused: enable javascript WARNING: translation string unused: enabled on @@ -590,6 +591,7 @@ WARNING: untranslated string: ccd routes WARNING: untranslated string: ccd subnet WARNING: untranslated string: ccd used WARNING: untranslated string: community rules +WARNING: untranslated string: dead peer detection WARNING: untranslated string: default ip WARNING: untranslated string: deprecated fs warn WARNING: untranslated string: disk access per @@ -601,6 +603,8 @@ WARNING: untranslated string: dnsforward edit an entry WARNING: untranslated string: dnsforward entries WARNING: untranslated string: dnsforward forward_server WARNING: untranslated string: dnsforward zone +WARNING: untranslated string: dpd delay +WARNING: untranslated string: dpd timeout WARNING: untranslated string: drop action WARNING: untranslated string: drop action1 WARNING: untranslated string: drop action2 @@ -650,6 +654,7 @@ WARNING: untranslated string: fwdfw err src_addr WARNING: untranslated string: fwdfw err tgt_addr WARNING: untranslated string: fwdfw err tgt_grp WARNING: untranslated string: fwdfw err tgt_mac +WARNING: untranslated string: fwdfw err tgt_port WARNING: untranslated string: fwdfw err time WARNING: untranslated string: fwdfw external port nat WARNING: untranslated string: fwdfw hint ip1 @@ -761,6 +766,8 @@ WARNING: untranslated string: fwhost welcome WARNING: untranslated string: grouptype WARNING: untranslated string: incoming traffic in bytes per second WARNING: untranslated string: integrity +WARNING: untranslated string: invalid input for dpd delay +WARNING: untranslated string: invalid input for dpd timeout WARNING: untranslated string: least preferred WARNING: untranslated string: lifetime WARNING: untranslated string: minute diff --git a/doc/language_issues.tr b/doc/language_issues.tr index 299c74d..07ee128 100644 --- a/doc/language_issues.tr +++ b/doc/language_issues.tr @@ -174,6 +174,7 @@ WARNING: translation string unused: eciadsl upload WARNING: translation string unused: edit network WARNING: translation string unused: edit service WARNING: translation string unused: editor +WARNING: translation string unused: eg WARNING: translation string unused: email server can not be empty WARNING: translation string unused: enable javascript WARNING: translation string unused: enabled on @@ -576,8 +577,11 @@ WARNING: untranslated string: Scan for Songs WARNING: untranslated string: advproxy errmsg proxy ports equal WARNING: untranslated string: advproxy proxy port transparent WARNING: untranslated string: bytes +WARNING: untranslated string: dead peer detection WARNING: untranslated string: default ip WARNING: untranslated string: dnat address +WARNING: untranslated string: dpd delay +WARNING: untranslated string: dpd timeout WARNING: untranslated string: drop action WARNING: untranslated string: drop action1 WARNING: untranslated string: drop action2 @@ -619,6 +623,7 @@ WARNING: untranslated string: fwdfw err src_addr WARNING: untranslated string: fwdfw err tgt_addr WARNING: untranslated string: fwdfw err tgt_grp WARNING: untranslated string: fwdfw err tgt_mac +WARNING: untranslated string: fwdfw err tgt_port WARNING: untranslated string: fwdfw err time WARNING: untranslated string: fwdfw external port nat WARNING: untranslated string: fwdfw hint ip1 @@ -729,6 +734,8 @@ WARNING: untranslated string: fwhost used WARNING: untranslated string: fwhost welcome WARNING: untranslated string: grouptype WARNING: untranslated string: integrity +WARNING: untranslated string: invalid input for dpd delay +WARNING: untranslated string: invalid input for dpd timeout WARNING: untranslated string: least preferred WARNING: untranslated string: lifetime WARNING: untranslated string: most preferred diff --git a/doc/language_missings b/doc/language_missings index 86f45b0..952e1e5 100644 --- a/doc/language_missings +++ b/doc/language_missings @@ -70,6 +70,8 @@ < dnsforward entries < dnsforward forward_server < dnsforward zone +< dpd delay +< dpd timeout < drop action < drop action1 < drop action2 @@ -268,6 +270,8 @@ < fw settings ruletable < grouptype < integrity +< invalid input for dpd delay +< invalid input for dpd timeout < least preferred < lifetime < minute @@ -488,6 +492,8 @@ < dnsforward entries < dnsforward forward_server < dnsforward zone +< dpd delay +< dpd timeout < drop action < drop action1 < drop action2 @@ -686,6 +692,8 @@ < fw settings ruletable < grouptype < integrity +< invalid input for dpd delay +< invalid input for dpd timeout < least preferred < lifetime < minute @@ -898,6 +906,8 @@ < dnsforward entries < dnsforward forward_server < dnsforward zone +< dpd delay +< dpd timeout < drop action < drop action1 < drop action2 @@ -1088,6 +1098,8 @@ < fw settings ruletable < grouptype < integrity +< invalid input for dpd delay +< invalid input for dpd timeout < least preferred < lifetime < minute @@ -1287,6 +1299,8 @@ < dnsforward entries < dnsforward forward_server < dnsforward zone +< dpd delay +< dpd timeout < drop action < drop action1 < drop action2 @@ -1481,6 +1495,8 @@ < hour-graph < incoming traffic in bytes per second < integrity +< invalid input for dpd delay +< invalid input for dpd timeout < least preferred < lifetime < minute diff --git a/html/cgi-bin/vpnmain.cgi b/html/cgi-bin/vpnmain.cgi index 64bf17e..af68d50 100644 --- a/html/cgi-bin/vpnmain.cgi +++ b/html/cgi-bin/vpnmain.cgi @@ -104,7 +104,8 @@ $cgiparams{'ROOTCERT_OU'} =3D ''; $cgiparams{'ROOTCERT_CITY'} =3D ''; $cgiparams{'ROOTCERT_STATE'} =3D ''; $cgiparams{'RW_NET'} =3D ''; - +$cgiparams{'DPD_DELAY'} =3D '30'; +$cgiparams{'DPD_TIMEOUT'} =3D '120'; &Header::getcgihash(\%cgiparams, {'wantfile' =3D> 1, 'filevar' =3D> 'FH'}); =20 ### @@ -384,9 +385,27 @@ sub writeipsecfiles { print CONF "\tcompress=3Dyes\n" if ($lconfighash{$key}[13] eq 'on'); =20 # Dead Peer Detection - print CONF "\tdpddelay=3D30\n"; - print CONF "\tdpdtimeout=3D120\n"; - print CONF "\tdpdaction=3D$lconfighash{$key}[27]\n"; + my $dpdaction =3D $lconfighash{$key}[27]; + print CONF "\tdpdaction=3D$dpdaction\n"; + + # If the dead peer detection is disabled and IKEv2 is used, + # dpddelay must be set to zero, too. + if ($dpdaction eq "none") { + if ($lconfighash{$key}[29] eq "ikev2") { + print CONF "\tdpddelay=3D0\n"; + } + } else { + my $dpddelay =3D $lconfighash{$key}[30]; + if (!$dpddelay) { + $dpddelay =3D 30; + } + print CONF "\tdpddelay=3D$dpddelay\n"; + my $dpdtimeout =3D $lconfighash{$key}[31]; + if (!$dpdtimeout) { + $dpdtimeout =3D 120; + } + print CONF "\tdpdtimeout=3D$dpdtimeout\n"; + } =20 # Build Authentication details: LEFTid RIGHTid : PSK psk my $psk_line; @@ -1274,6 +1293,16 @@ END $cgiparams{'ONLY_PROPOSED'} =3D $confighash{$cgiparams{'KEY'}}[24]; $cgiparams{'PFS'} =3D $confighash{$cgiparams{'KEY'}}[28]; $cgiparams{'VHOST'} =3D $confighash{$cgiparams{'KEY'}}[14]; + $cgiparams{'DPD_TIMEOUT'} =3D $confighash{$cgiparams{'KEY'}}[30]; + $cgiparams{'DPD_DELAY'} =3D $confighash{$cgiparams{'KEY'}}[31]; + + if (!$cgiparams{'DPD_DELAY'}) { + $cgiparams{'DPD_DELAY'} =3D 30; + } + + if (!$cgiparams{'DPD_TIMEOUT'}) { + $cgiparams{'DPD_TIMEOUT'} =3D 120; + } =20 } elsif ($cgiparams{'ACTION'} eq $Lang::tr{'save'}) { $cgiparams{'REMARK'} =3D &Header::cleanhtml($cgiparams{'REMARK'}); @@ -1748,7 +1777,7 @@ END my $key =3D $cgiparams{'KEY'}; if (! $key) { $key =3D &General::findhasharraykey (\%confighash); - foreach my $i (0 .. 28) { $confighash{$key}[$i] =3D "";} + foreach my $i (0 .. 31) { $confighash{$key}[$i] =3D "";} } $confighash{$key}[0] =3D $cgiparams{'ENABLED'}; $confighash{$key}[1] =3D $cgiparams{'NAME'}; @@ -1788,6 +1817,8 @@ END $confighash{$key}[24] =3D $cgiparams{'ONLY_PROPOSED'}; $confighash{$key}[28] =3D $cgiparams{'PFS'}; $confighash{$key}[14] =3D $cgiparams{'VHOST'}; + $confighash{$key}[30] =3D $cgiparams{'DPD_TIMEOUT'}; + $confighash{$key}[31] =3D $cgiparams{'DPD_DELAY'}; =20 #free unused fields! $confighash{$key}[6] =3D 'off'; @@ -1823,9 +1854,17 @@ END =20 # choose appropriate dpd action=09 if ($cgiparams{'TYPE'} eq 'host') { - $cgiparams{'DPD_ACTION'} =3D 'clear'; + $cgiparams{'DPD_ACTION'} =3D 'clear'; } else { - $cgiparams{'DPD_ACTION'} =3D 'restart'; + $cgiparams{'DPD_ACTION'} =3D 'restart'; + } + + if (!$cgiparams{'DPD_DELAY'}) { + $cgiparams{'DPD_DELAY'} =3D 30; + } + + if (!$cgiparams{'DPD_TIMEOUT'}) { + $cgiparams{'DPD_TIMEOUT'} =3D 120; } =20 # Default IKE Version to v2 @@ -1869,15 +1908,6 @@ END $checked{'AUTH'}{'auth-dn'} =3D ''; $checked{'AUTH'}{$cgiparams{'AUTH'}} =3D "checked=3D'checked'"; =20 - $selected{'DPD_ACTION'}{'clear'} =3D ''; - $selected{'DPD_ACTION'}{'hold'} =3D ''; - $selected{'DPD_ACTION'}{'restart'} =3D ''; - $selected{'DPD_ACTION'}{$cgiparams{'DPD_ACTION'}} =3D "selected=3D'selec= ted'"; - - $selected{'IKE_VERSION'}{'ikev1'} =3D ''; - $selected{'IKE_VERSION'}{'ikev2'} =3D ''; - $selected{'IKE_VERSION'}{$cgiparams{'IKE_VERSION'}} =3D "selected=3D'sel= ected'"; - &Header::showhttpheaders(); &Header::openpage($Lang::tr{'vpn configuration main'}, 1, ''); &Header::openbigbox('100%', 'left', '', $errormessage); @@ -1898,6 +1928,7 @@ END print "
"; print< + @@ -1910,23 +1941,30 @@ END + + + END ; if ($cgiparams{'KEY'}) { print ""; + print "= "; print "= "; } =20 - &Header::openbox('100%', 'left', "$Lang::tr{'connection'}:"); + &Header::openbox('100%', 'left', "$Lang::tr{'connection'}: $cgiparams{'N= AME'}"); print ""; - print ""; - if ($cgiparams{'KEY'}) { - print ""; - } else { - print ""; + if (!$cgiparams{'KEY'}) { + print < + + + + +EOF } - print ""; - print ''; =20 my $disabled; my $blob; @@ -1937,44 +1975,41 @@ END =20 print < - - - - + + + - - + + + - - - - - - - - + - - + + + + + + - - - END ; @@ -2184,6 +2219,17 @@ if(($cgiparams{'ACTION'} eq $Lang::tr{'advanced'}) || goto ADVANCED_ERROR; } =20 + if ($cgiparams{'DPD_DELAY'} !~ /^\d+$/) { + $errormessage =3D $Lang::tr{'invalid input for dpd delay'}; + goto ADVANCED_ERROR; + } + + if ($cgiparams{'DPD_TIMEOUT'} !~ /^\d+$/) { + $errormessage =3D $Lang::tr{'invalid input for dpd timeout'}; + goto ADVANCED_ERROR; + } + + $confighash{$cgiparams{'KEY'}}[29] =3D $cgiparams{'IKE_VERSION'}; $confighash{$cgiparams{'KEY'}}[18] =3D $cgiparams{'IKE_ENCRYPTION'}; $confighash{$cgiparams{'KEY'}}[19] =3D $cgiparams{'IKE_INTEGRITY'}; $confighash{$cgiparams{'KEY'}}[20] =3D $cgiparams{'IKE_GROUPTYPE'}; @@ -2197,6 +2243,9 @@ if(($cgiparams{'ACTION'} eq $Lang::tr{'advanced'}) || $confighash{$cgiparams{'KEY'}}[24] =3D $cgiparams{'ONLY_PROPOSED'}; $confighash{$cgiparams{'KEY'}}[28] =3D $cgiparams{'PFS'}; $confighash{$cgiparams{'KEY'}}[14] =3D $cgiparams{'VHOST'}; + $confighash{$cgiparams{'KEY'}}[27] =3D $cgiparams{'DPD_ACTION'}; + $confighash{$cgiparams{'KEY'}}[30] =3D $cgiparams{'DPD_TIMEOUT'}; + $confighash{$cgiparams{'KEY'}}[31] =3D $cgiparams{'DPD_DELAY'}; &General::writehasharray("${General::swroot}/vpn/config", \%confighash); &writeipsecfiles(); if (&vpnenabled) { @@ -2205,6 +2254,7 @@ if(($cgiparams{'ACTION'} eq $Lang::tr{'advanced'}) || } goto ADVANCED_END; } else { + $cgiparams{'IKE_VERSION'} =3D $confighash{$cgiparams{'KEY'}}[29]; $cgiparams{'IKE_ENCRYPTION'} =3D $confighash{$cgiparams{'KEY'}}[18]; $cgiparams{'IKE_INTEGRITY'} =3D $confighash{$cgiparams{'KEY'}}[19]; $cgiparams{'IKE_GROUPTYPE'} =3D $confighash{$cgiparams{'KEY'}}[20]; @@ -2217,6 +2267,17 @@ if(($cgiparams{'ACTION'} eq $Lang::tr{'advanced'}) || $cgiparams{'ONLY_PROPOSED'} =3D $confighash{$cgiparams{'KEY'}}[24]; $cgiparams{'PFS'} =3D $confighash{$cgiparams{'KEY'}}[28]; $cgiparams{'VHOST'} =3D $confighash{$cgiparams{'KEY'}}[14]; + $cgiparams{'DPD_ACTION'} =3D $confighash{$cgiparams{'KEY'}}[27]; + $cgiparams{'DPD_TIMEOUT'} =3D $confighash{$cgiparams{'KEY'}}[30]; + $cgiparams{'DPD_DELAY'} =3D $confighash{$cgiparams{'KEY'}}[31]; + + if (!$cgiparams{'DPD_DELAY'}) { + $cgiparams{'DPD_DELAY'} =3D 30; + } + + if (!$cgiparams{'DPD_TIMEOUT'}) { + $cgiparams{'DPD_TIMEOUT'} =3D 120; + } =20 if ($confighash{$cgiparams{'KEY'}}[3] eq 'net' || $confighash{$cgiparams{'K= EY'}}[10]) { $cgiparams{'VHOST'} =3D 'off'; @@ -2279,6 +2340,16 @@ if(($cgiparams{'ACTION'} eq $Lang::tr{'advanced'}) || $checked{'PFS'} =3D $cgiparams{'PFS'} eq 'on' ? "checked=3D'checked'" : = '' ; $checked{'VHOST'} =3D $cgiparams{'VHOST'} eq 'on' ? "checked=3D'checked'= " : '' ; =20 + $selected{'IKE_VERSION'}{'ikev1'} =3D ''; + $selected{'IKE_VERSION'}{'ikev2'} =3D ''; + $selected{'IKE_VERSION'}{$cgiparams{'IKE_VERSION'}} =3D "selected=3D'sel= ected'"; + + $selected{'DPD_ACTION'}{'clear'} =3D ''; + $selected{'DPD_ACTION'}{'hold'} =3D ''; + $selected{'DPD_ACTION'}{'restart'} =3D ''; + $selected{'DPD_ACTION'}{'none'} =3D ''; + $selected{'DPD_ACTION'}{$cgiparams{'DPD_ACTION'}} =3D "selected=3D'selec= ted'"; + &Header::showhttpheaders(); &Header::openpage($Lang::tr{'vpn configuration main'}, 1, ''); &Header::openbigbox('100%', 'left', '', $errormessage); @@ -2306,14 +2377,24 @@ if(($cgiparams{'ACTION'} eq $Lang::tr{'advanced'}) ||
$Lang::tr{'name'}:$cgiparams{'NAME'}$Lang::tr{'name'}: + +
$Lang::tr{'enabled'}

$Lang::tr{'remote host/ip'}: $blob - - $Lang::tr{'remote subnet'} - + $Lang::tr{'enabled'} + + $Lang::tr{'local= subnet'} +
$Lang::tr{'local subnet'} - + $Lang::tr{'remote host/ip'}: = $blob + + $Lang::tr{'remot= e subnet'} +
$Lang::tr{'vpn local id'}:
($Lang::tr{'eg'}= @xy.example.com)
$Lang::tr{'vpn remote id'}:

$Lang::tr{'vpn keyexchange'}: + $Lang::tr{'vpn local id'}: + $Lang::tr{'dpd action'}: + $Lang::tr{'vpn remote id'}: + +

$Lang::tr{'remark title'}  +
$Lang::tr{'remark title'} 3D'*'
- + - + + + + + + =20 - + - + @@ -2371,7 +2452,7 @@ if(($cgiparams{'ACTION'} eq $Lang::tr{'advanced'}) || - +
IKE ESP
$Lang::tr{'encryption'}$Lang::tr{'vpn keyexchange'}: + +
$Lang::tr{'encryption'}
$Lang::tr{'integrity'}$Lang::tr{'integrity'}
$Lang::tr{'lifetime'}$Lang::tr{'lifetime'} $Lang::tr{'hours'}
$Lang::tr{'grouptype'}$Lang::tr{'grouptype'}
=20 +

+ +

$Lang::tr{'dead peer detection'}

+ + + + + + + + + + + + + + +
$Lang::tr{'dpd action'}: + +
$Lang::tr{'dpd timeout'}: + +
$Lang::tr{'dpd delay'}: + +
+
=20 @@ -2441,7 +2552,7 @@ EOF =20 print < - diff --git a/langs/de/cgi-bin/de.pl b/langs/de/cgi-bin/de.pl index 01cd3f6..568f057 100644 --- a/langs/de/cgi-bin/de.pl +++ b/langs/de/cgi-bin/de.pl @@ -749,6 +749,8 @@ 'download pkcs12 file' =3D> 'PKCS12-Datei herunterladen', 'download root certificate' =3D> 'Root-Zertifikat herunterladen', 'dpd action' =3D> 'Aktion f=C3=BCr Dead Peer Detection', +'dpd delay' =3D> 'Verz=C3=B6gerung', +'dpd timeout' =3D> 'Zeit=C3=BCberschreitung', 'driver' =3D> 'Treiber', 'drop action' =3D> 'Standardverhalten der (Forward) Firewall in Modus "Block= ed"', 'drop action1' =3D> 'Standardverhalten der (Outgoing) Firewall in Modus "Blo= cked"', @@ -1209,6 +1211,8 @@ 'invalid input for dhcp dns' =3D> 'Ung=C3=BCltige Eingabe f=C3=BCr DHCP DNS', 'invalid input for dhcp domain' =3D> 'Ung=C3=BCltige Eingabe f=C3=BCr DHCP D= omain', 'invalid input for dhcp wins' =3D> 'Ung=C3=BCltige Eingabe f=C3=BCr DHCP WIN= S', +'invalid input for dpd delay' =3D> 'Ung=C3=BCltige Eingabe f=C3=BCr DPD-Verz= =C3=B6gerung', +'invalid input for dpd timeout' =3D> 'Ung=C3=BCltige Eingabe f=C3=BCr DPD-Ze= it=C3=BCberschreitung', 'invalid input for e-mail address' =3D> 'Ung=C3=BCltige Eingabe f=C3=BCr die= E-mail Adresse', 'invalid input for esp keylife' =3D> 'Ung=C3=BCltige Eingabe f=C3=BCr ESP Sc= hl=C3=BCssel-Lebensdauer', 'invalid input for hostname' =3D> 'Ung=C3=BCltige Eingabe f=C3=BCr Hostname', diff --git a/langs/en/cgi-bin/en.pl b/langs/en/cgi-bin/en.pl index dc38129..451ea79 100644 --- a/langs/en/cgi-bin/en.pl +++ b/langs/en/cgi-bin/en.pl @@ -634,6 +634,7 @@ 'ddns noip prefix' =3D> 'To use no-ip in group mode, prefix hostname with %', 'deactivate' =3D> 'deactivate', 'deactivate user' =3D> 'deactivate user', +'dead peer detection' =3D> 'Dead Peer Detection', 'debugme' =3D> 'Not yet implemented', 'december' =3D> 'December', 'deep scan directories' =3D> 'Scan recursive', @@ -772,7 +773,9 @@ 'download new ruleset' =3D> 'Download new ruleset', 'download pkcs12 file' =3D> 'Download PKCS12 file', 'download root certificate' =3D> 'Download root certificate', -'dpd action' =3D> 'Dead Peer Detection action', +'dpd action' =3D> 'Action', +'dpd delay' =3D> 'Delay', +'dpd timeout' =3D> 'Timeout', 'driver' =3D> 'Driver', 'drop action' =3D> 'Default behaviour of (forward) firewall in mode "Blocked= "', 'drop action1' =3D> 'Default behaviour of (outgoing) firewall in mode "Block= ed"', @@ -1237,6 +1240,8 @@ 'invalid input for dhcp dns' =3D> 'Invalid input for DHCP DNS', 'invalid input for dhcp domain' =3D> 'Invalid input for DHCP domain', 'invalid input for dhcp wins' =3D> 'Invalid input for DHCP WINS', +'invalid input for dpd delay' =3D> 'Invalid input for DPD delay', +'invalid input for dpd timeout' =3D> 'Invalid input for DPD timeout', 'invalid input for e-mail address' =3D> 'Invalid input for e-mail address.', 'invalid input for esp keylife' =3D> 'Invalid input for ESP Keylife', 'invalid input for hostname' =3D> 'Invalid input for hostname.', hooks/post-receive -- IPFire 2.x development tree --===============0206138565869275462==--
+