2010-05-01 21:22:01 +03:00
|
|
|
# Copyright (C) 2009-2010 OpenWrt.org
|
|
|
|
|
|
|
|
FW_LIBDIR=${FW_LIBDIR:-/lib/firewall}
|
|
|
|
|
|
|
|
. $FW_LIBDIR/fw.sh
|
|
|
|
include /lib/network
|
|
|
|
|
|
|
|
fw_start() {
|
|
|
|
fw_init
|
|
|
|
|
|
|
|
FW_DEFAULTS_APPLIED=
|
|
|
|
|
|
|
|
fw_is_loaded && {
|
|
|
|
echo "firewall already loaded" >&2
|
|
|
|
exit 1
|
|
|
|
}
|
2010-05-18 23:15:47 +03:00
|
|
|
|
2010-05-01 21:22:01 +03:00
|
|
|
uci_set_state firewall core "" firewall_state
|
|
|
|
|
|
|
|
fw_clear DROP
|
|
|
|
|
|
|
|
fw_callback pre core
|
|
|
|
|
|
|
|
echo "Loading defaults"
|
|
|
|
fw_config_once fw_load_defaults defaults
|
|
|
|
|
|
|
|
echo "Loading zones"
|
|
|
|
config_foreach fw_load_zone zone
|
|
|
|
|
|
|
|
echo "Loading forwardings"
|
|
|
|
config_foreach fw_load_forwarding forwarding
|
|
|
|
|
|
|
|
echo "Loading redirects"
|
|
|
|
config_foreach fw_load_redirect redirect
|
|
|
|
|
|
|
|
echo "Loading rules"
|
|
|
|
config_foreach fw_load_rule rule
|
|
|
|
|
|
|
|
echo "Loading includes"
|
|
|
|
config_foreach fw_load_include include
|
|
|
|
|
2010-07-16 01:01:48 +03:00
|
|
|
[ -z "$FW_NOTRACK_DISABLED" ] && {
|
2010-05-01 21:22:01 +03:00
|
|
|
echo "Optimizing conntrack"
|
|
|
|
config_foreach fw_load_notrack_zone zone
|
|
|
|
}
|
|
|
|
|
|
|
|
echo "Loading interfaces"
|
|
|
|
config_foreach fw_configure_interface interface add
|
|
|
|
|
|
|
|
fw_callback post core
|
|
|
|
|
2010-09-15 02:11:12 +03:00
|
|
|
uci_set_state firewall core zones "$FW_ZONES"
|
2010-05-01 21:22:01 +03:00
|
|
|
uci_set_state firewall core loaded 1
|
|
|
|
}
|
|
|
|
|
|
|
|
fw_stop() {
|
|
|
|
fw_init
|
|
|
|
|
|
|
|
fw_callback pre stop
|
|
|
|
|
2010-09-15 04:53:36 +03:00
|
|
|
local z n i
|
|
|
|
config_get z core zones
|
|
|
|
for z in $z; do
|
|
|
|
config_get n core "${z}_networks"
|
|
|
|
for n in $n; do
|
2010-09-15 02:11:12 +03:00
|
|
|
config_get i core "${n}_ifname"
|
|
|
|
[ -n "$i" ] && env -i ACTION=remove ZONE="$z" \
|
2010-09-15 04:53:36 +03:00
|
|
|
INTERFACE="$n" DEVICE="$i" /sbin/hotplug-call firewall
|
2010-09-15 02:11:12 +03:00
|
|
|
done
|
|
|
|
done
|
|
|
|
|
2010-05-01 21:22:01 +03:00
|
|
|
fw_clear ACCEPT
|
|
|
|
|
|
|
|
fw_callback post stop
|
|
|
|
|
|
|
|
uci_revert_state firewall
|
|
|
|
config_clear
|
2010-05-17 20:20:37 +03:00
|
|
|
|
|
|
|
local h
|
|
|
|
for h in $FW_HOOKS; do unset $h; done
|
|
|
|
|
|
|
|
unset FW_HOOKS
|
2010-05-01 21:22:01 +03:00
|
|
|
unset FW_INITIALIZED
|
|
|
|
}
|
|
|
|
|
|
|
|
fw_restart() {
|
|
|
|
fw_stop
|
|
|
|
fw_start
|
|
|
|
}
|
|
|
|
|
|
|
|
fw_reload() {
|
|
|
|
fw_restart
|
|
|
|
}
|
|
|
|
|
|
|
|
fw_is_loaded() {
|
2010-05-17 22:38:13 +03:00
|
|
|
local bool=$(uci_get_state firewall.core.loaded)
|
2010-05-17 15:47:14 +03:00
|
|
|
return $((! ${bool:-0}))
|
2010-05-01 21:22:01 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
fw_die() {
|
|
|
|
echo "Error:" "$@" >&2
|
|
|
|
fw_log error "$@"
|
|
|
|
fw_stop
|
|
|
|
exit 1
|
|
|
|
}
|
|
|
|
|
|
|
|
fw_log() {
|
|
|
|
local level="$1"
|
2010-09-16 14:47:35 +03:00
|
|
|
[ -n "$2" ] && shift || level=notice
|
|
|
|
[ "$level" != error ] || echo "Error: $@" >&2
|
2010-05-01 21:22:01 +03:00
|
|
|
logger -t firewall -p user.$level "$@"
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
fw_init() {
|
|
|
|
[ -z "$FW_INITIALIZED" ] || return 0
|
|
|
|
|
|
|
|
. $FW_LIBDIR/config.sh
|
|
|
|
|
|
|
|
scan_interfaces
|
|
|
|
fw_config_append firewall
|
|
|
|
|
|
|
|
local hooks="core stop defaults zone notrack synflood"
|
|
|
|
local file lib hk pp
|
|
|
|
for file in $FW_LIBDIR/core_*.sh; do
|
|
|
|
. $file
|
|
|
|
hk=$(basename $file .sh)
|
|
|
|
hk=${hk#core_}
|
|
|
|
append hooks $hk
|
|
|
|
done
|
|
|
|
for file in $FW_LIBDIR/*.sh; do
|
|
|
|
lib=$(basename $file .sh)
|
|
|
|
lib=${lib##[0-9][0-9]_}
|
|
|
|
case $lib in
|
|
|
|
core*|fw|config|uci_firewall) continue ;;
|
|
|
|
esac
|
|
|
|
. $file
|
|
|
|
for hk in $hooks; do
|
|
|
|
for pp in pre post; do
|
2010-05-17 20:20:37 +03:00
|
|
|
type ${lib}_${pp}_${hk}_cb >/dev/null && {
|
2010-05-01 21:22:01 +03:00
|
|
|
append FW_CB_${pp}_${hk} ${lib}
|
2010-05-17 20:20:37 +03:00
|
|
|
append FW_HOOKS FW_CB_${pp}_${hk}
|
|
|
|
}
|
2010-05-01 21:22:01 +03:00
|
|
|
done
|
|
|
|
done
|
|
|
|
done
|
|
|
|
|
|
|
|
fw_callback post init
|
|
|
|
|
|
|
|
FW_INITIALIZED=1
|
|
|
|
return 0
|
|
|
|
}
|