0.2.6 20060312 rules.pl: SNAT now makes use of NOIF: any ip and any interface possible 20060219 rules.pl: prolog now contains NEW-INP, NEW-OUT, NEW-FWD and corresponding $sitename for statistical anaylse of logfiles, thx to Lexi Pimenidis, misc mag. 1/2006 p.26 20060127 ipsec.generator: Thanks to fd0 ipsec.secrets no longer derived from $RANDOM in bash, /dev/random seems too hard, /dev/urandom should be sufficient 0.2.5 20050216 Install-hints written, sspe.pdf now included minor corrections, mainly for debugging. Reason: moved the sources to my home-office 20040904 public released at sf.net 0.2.4 20040827 mangling-[start|end] included foreach machine may be used for any purpose, even sysctl or tc might be the most important step forward, lets see! production and public now only differ in DEMO=[0|1] in .config 0.2.3 20040727 logging for tcp myself=2 added NONAT added 0.2.2 20040219 A lot was done: 1:rules.pl:SYSL-option<=> SPT=DPT=514,NOSTATE=1 should not be SYSLOG which logs additionally 2:Default-RULE changed to $sitename-dropped for joining of multiple machines syslogs 3:new file desc/xxx/apply-options: may contain wait-for or sleep-for, recognized by dist-rules-linux 4:new file desc/xxx/never-apply: dist-rules checks if it exists, apply never does anything for this machine 5:apply now shows state of every machine 0.2.1 20040205 NOIF introduced in udp,tcp for pluto due to faults using ipsec0 interface 0.2.0 20040127 NOSTATE introduced in udp,tcp for pluto ip-proto logging added, actions corrected (was accept only! as never needed else) Reason: Provider changed RFC1918 to official addresses on transfernet 0.1.9 20040115 new Option: FORCED overrides routing-decison Reason: dropping broadcast and network-addr. 0.1.8 20040107 ip-proto added due to crazy foolish BNE corrupted tcp-packets, works fine! 20031[0|1] Linux-Magazine: Brave GNU World mentioned sspe. Thank you very much. 0.1.7 20030329 first published 0.1.6 20030202 Minor correcions in rules.pl, corrections in menues 0.1.5 ?? Can't remember. 0.1.4 20020508 Locking to prevent multiple simultaneous usage Berlin/ISDN/Cologne, to France and Germany OK: added ipsec.conf.const, appended to ipsec.conf 0.1.3 20020430 New Name: DFCT got SSPE 0.1.2 20020322 first online try in real life before development without any connection to the net.