mirror of
https://github.com/vincentmli/bpfire.git
synced 2026-04-27 03:07:43 +02:00
Merge remote-tracking branch 'amarx/firewall' into fifteen
This commit is contained in:
@@ -1,446 +0,0 @@
|
||||
#!/usr/bin/perl
|
||||
###############################################################################
|
||||
# #
|
||||
# IPFire.org - A linux based firewall #
|
||||
# Copyright (C) 2007 Michael Tremer & Christian Schmidt #
|
||||
# #
|
||||
# This program is free software: you can redistribute it and/or modify #
|
||||
# it under the terms of the GNU General Public License as published by #
|
||||
# the Free Software Foundation, either version 3 of the License, or #
|
||||
# (at your option) any later version. #
|
||||
# #
|
||||
# This program is distributed in the hope that it will be useful, #
|
||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of #
|
||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
|
||||
# GNU General Public License for more details. #
|
||||
# #
|
||||
# You should have received a copy of the GNU General Public License #
|
||||
# along with this program. If not, see <http://www.gnu.org/licenses/>. #
|
||||
# #
|
||||
###############################################################################
|
||||
|
||||
use strict;
|
||||
|
||||
# enable only the following on debugging purpose
|
||||
#use warnings;
|
||||
#use CGI::Carp 'fatalsToBrowser';
|
||||
|
||||
require '/var/ipfire/general-functions.pl';
|
||||
require "${General::swroot}/lang.pl";
|
||||
require "${General::swroot}/header.pl";
|
||||
|
||||
#workaround to suppress a warning when a variable is used only once
|
||||
my @dummy = ( ${Header::table2colour}, ${Header::colouryellow} );
|
||||
undef (@dummy);
|
||||
|
||||
my %cgiparams=();
|
||||
my %checked=();
|
||||
my %selected=();
|
||||
my %netsettings=();
|
||||
my $errormessage = '';
|
||||
my $filename = "${General::swroot}/dmzholes/config";
|
||||
|
||||
&General::readhash("${General::swroot}/ethernet/settings", \%netsettings);
|
||||
|
||||
&Header::showhttpheaders();
|
||||
|
||||
$cgiparams{'ENABLED'} = 'off';
|
||||
$cgiparams{'REMARK'} = '';
|
||||
$cgiparams{'ACTION'} = '';
|
||||
$cgiparams{'SRC_IP'} = '';
|
||||
$cgiparams{'DEST_IP'} ='';
|
||||
$cgiparams{'DEST_PORT'} = '';
|
||||
&Header::getcgihash(\%cgiparams);
|
||||
|
||||
open(FILE, $filename) or die 'Unable to open config file.';
|
||||
my @current = <FILE>;
|
||||
close(FILE);
|
||||
|
||||
if ($cgiparams{'ACTION'} eq $Lang::tr{'add'})
|
||||
{
|
||||
unless($cgiparams{'PROTOCOL'} =~ /^(tcp|udp)$/) { $errormessage = $Lang::tr{'invalid input'}; }
|
||||
unless(&General::validipormask($cgiparams{'SRC_IP'})) { $errormessage = $Lang::tr{'source ip bad'}; }
|
||||
unless($errormessage){$errormessage = &General::validportrange($cgiparams{'DEST_PORT'},'dst');}
|
||||
unless(&General::validipormask($cgiparams{'DEST_IP'})) { $errormessage = $Lang::tr{'destination ip bad'}; }
|
||||
unless ($errormessage) {
|
||||
$errormessage = &validNet($cgiparams{'SRC_NET'},$cgiparams{'DEST_NET'}); }
|
||||
# Darren Critchley - Remove commas from remarks
|
||||
$cgiparams{'REMARK'} = &Header::cleanhtml($cgiparams{'REMARK'});
|
||||
|
||||
unless ($errormessage)
|
||||
{
|
||||
if($cgiparams{'EDITING'} eq 'no') {
|
||||
open(FILE,">>$filename") or die 'Unable to open config file.';
|
||||
flock FILE, 2;
|
||||
print FILE "$cgiparams{'PROTOCOL'},"; # [0]
|
||||
print FILE "$cgiparams{'SRC_IP'},"; # [1]
|
||||
print FILE "$cgiparams{'DEST_IP'},"; # [2]
|
||||
print FILE "$cgiparams{'DEST_PORT'},"; # [3]
|
||||
print FILE "$cgiparams{'ENABLED'},"; # [4]
|
||||
print FILE "$cgiparams{'SRC_NET'},"; # [5]
|
||||
print FILE "$cgiparams{'DEST_NET'},"; # [6]
|
||||
print FILE "$cgiparams{'REMARK'}\n"; # [7]
|
||||
} else {
|
||||
open(FILE,">$filename") or die 'Unable to open config file.';
|
||||
flock FILE, 2;
|
||||
my $id = 0;
|
||||
foreach my $line (@current)
|
||||
{
|
||||
$id++;
|
||||
if ($cgiparams{'EDITING'} eq $id) {
|
||||
print FILE "$cgiparams{'PROTOCOL'},"; # [0]
|
||||
print FILE "$cgiparams{'SRC_IP'},"; # [1]
|
||||
print FILE "$cgiparams{'DEST_IP'},"; # [2]
|
||||
print FILE "$cgiparams{'DEST_PORT'},"; # [3]
|
||||
print FILE "$cgiparams{'ENABLED'},"; # [4]
|
||||
print FILE "$cgiparams{'SRC_NET'},"; # [5]
|
||||
print FILE "$cgiparams{'DEST_NET'},"; # [6]
|
||||
print FILE "$cgiparams{'REMARK'}\n"; # [7]
|
||||
} else { print FILE "$line"; }
|
||||
}
|
||||
}
|
||||
close(FILE);
|
||||
undef %cgiparams;
|
||||
&General::log($Lang::tr{'dmz pinhole rule added'});
|
||||
system('/usr/local/bin/setdmzholes');
|
||||
}
|
||||
}
|
||||
if ($cgiparams{'ACTION'} eq $Lang::tr{'remove'})
|
||||
{
|
||||
my $id = 0;
|
||||
open(FILE, ">$filename") or die 'Unable to open config file.';
|
||||
flock FILE, 2;
|
||||
foreach my $line (@current)
|
||||
{
|
||||
$id++;
|
||||
unless ($cgiparams{'ID'} eq $id) { print FILE "$line"; }
|
||||
}
|
||||
close(FILE);
|
||||
system('/usr/local/bin/setdmzholes');
|
||||
&General::log($Lang::tr{'dmz pinhole rule removed'});
|
||||
}
|
||||
if ($cgiparams{'ACTION'} eq $Lang::tr{'toggle enable disable'})
|
||||
{
|
||||
my $id = 0;
|
||||
open(FILE, ">$filename") or die 'Unable to open config file.';
|
||||
flock FILE, 2;
|
||||
foreach my $line (@current)
|
||||
{
|
||||
$id++;
|
||||
unless ($cgiparams{'ID'} eq $id) { print FILE "$line"; }
|
||||
else
|
||||
{
|
||||
chomp($line);
|
||||
my @temp = split(/\,/,$line);
|
||||
print FILE "$temp[0],$temp[1],$temp[2],$temp[3],$cgiparams{'ENABLE'},$temp[5],$temp[6],$temp[7]\n";
|
||||
}
|
||||
}
|
||||
close(FILE);
|
||||
system('/usr/local/bin/setdmzholes');
|
||||
}
|
||||
if ($cgiparams{'ACTION'} eq $Lang::tr{'edit'})
|
||||
{
|
||||
my $id = 0;
|
||||
foreach my $line (@current)
|
||||
{
|
||||
$id++;
|
||||
if ($cgiparams{'ID'} eq $id)
|
||||
{
|
||||
chomp($line);
|
||||
my @temp = split(/\,/,$line);
|
||||
$cgiparams{'PROTOCOL'} = $temp[0];
|
||||
$cgiparams{'SRC_IP'} = $temp[1];
|
||||
$cgiparams{'DEST_IP'} = $temp[2];
|
||||
$cgiparams{'DEST_PORT'} = $temp[3];
|
||||
$cgiparams{'ENABLED'} = $temp[4];
|
||||
$cgiparams{'SRC_NET'} = $temp[5];
|
||||
$cgiparams{'DEST_NET'} = $temp[6];
|
||||
$cgiparams{'REMARK'} = $temp[7];
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if ($cgiparams{'ACTION'} eq '')
|
||||
{
|
||||
$cgiparams{'PROTOCOL'} = 'tcp';
|
||||
$cgiparams{'ENABLED'} = 'on';
|
||||
$cgiparams{'SRC_NET'} = 'orange';
|
||||
$cgiparams{'DEST_NET'} = 'blue';
|
||||
}
|
||||
|
||||
$selected{'PROTOCOL'}{'udp'} = '';
|
||||
$selected{'PROTOCOL'}{'tcp'} = '';
|
||||
$selected{'PROTOCOL'}{$cgiparams{'PROTOCOL'}} = "selected='selected'";
|
||||
|
||||
$selected{'SRC_NET'}{'orange'} = '';
|
||||
$selected{'SRC_NET'}{'blue'} = '';
|
||||
$selected{'SRC_NET'}{$cgiparams{'SRC_NET'}} = "selected='selected'";
|
||||
|
||||
$selected{'DEST_NET'}{'blue'} = '';
|
||||
$selected{'DEST_NET'}{'green'} = '';
|
||||
$selected{'DEST_NET'}{$cgiparams{'DEST_NET'}} = "selected='selected'";
|
||||
|
||||
$checked{'ENABLED'}{'off'} = '';
|
||||
$checked{'ENABLED'}{'on'} = '';
|
||||
$checked{'ENABLED'}{$cgiparams{'ENABLED'}} = "checked='checked'";
|
||||
|
||||
&Header::openpage($Lang::tr{'dmz pinhole configuration'}, 1, '');
|
||||
|
||||
&Header::openbigbox('100%', 'left', '', $errormessage);
|
||||
|
||||
if ($errormessage) {
|
||||
&Header::openbox('100%', 'left', $Lang::tr{'error messages'});
|
||||
print "<class name='base'>$errormessage\n";
|
||||
print " </class>\n";
|
||||
&Header::closebox();
|
||||
}
|
||||
|
||||
print "<form method='post' action='$ENV{'SCRIPT_NAME'}'>\n";
|
||||
|
||||
my $buttonText = $Lang::tr{'add'};
|
||||
if ($cgiparams{'ACTION'} eq $Lang::tr{'edit'}) {
|
||||
&Header::openbox('100%', 'left', $Lang::tr{'edit a rule'});
|
||||
$buttonText = $Lang::tr{'update'};
|
||||
} else {
|
||||
&Header::openbox('100%', 'left', $Lang::tr{'add a new rule'});
|
||||
}
|
||||
print <<END
|
||||
<table width='100%'>
|
||||
<tr>
|
||||
<td>
|
||||
<select name='PROTOCOL'>
|
||||
<option value='udp' $selected{'PROTOCOL'}{'udp'}>UDP</option>
|
||||
<option value='tcp' $selected{'PROTOCOL'}{'tcp'}>TCP</option>
|
||||
</select>
|
||||
</td>
|
||||
<td>
|
||||
$Lang::tr{'source net'}:</td>
|
||||
<td>
|
||||
<select name='SRC_NET'>
|
||||
END
|
||||
;
|
||||
if (&haveOrangeNet()) {
|
||||
print "<option value='orange' $selected{'SRC_NET'}{'orange'}>$Lang::tr{'orange'}</option>";
|
||||
}
|
||||
if (&haveBlueNet()) {
|
||||
print "<option value='blue' $selected{'SRC_NET'}{'blue'}>$Lang::tr{'blue'}</option>";
|
||||
}
|
||||
print <<END
|
||||
</select>
|
||||
</td>
|
||||
<td class='base'>$Lang::tr{'source ip or net'}:</td>
|
||||
<td><input type='text' name='SRC_IP' value='$cgiparams{'SRC_IP'}' size='15' /></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>
|
||||
</td>
|
||||
<td>
|
||||
$Lang::tr{'destination net'}:</td>
|
||||
<td>
|
||||
<select name='DEST_NET'>
|
||||
END
|
||||
;
|
||||
if (&haveOrangeNet() && &haveBlueNet()) {
|
||||
print "<option value='blue' $selected{'DEST_NET'}{'blue'}>$Lang::tr{'blue'}</option>";
|
||||
}
|
||||
|
||||
print <<END
|
||||
<option value='green' $selected{'DEST_NET'}{'green'}>$Lang::tr{'green'}</option>
|
||||
</select>
|
||||
</td>
|
||||
<td class='base'>
|
||||
$Lang::tr{'destination ip or net'}:</td>
|
||||
<td>
|
||||
<input type='text' name='DEST_IP' value='$cgiparams{'DEST_IP'}' size='15' />
|
||||
</td>
|
||||
<td class='base'>
|
||||
$Lang::tr{'destination port'}:
|
||||
<input type='text' name='DEST_PORT' value='$cgiparams{'DEST_PORT'}' size='5' />
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
<table width='100%'>
|
||||
<tr>
|
||||
<td colspan='3' width='50%' class='base'>
|
||||
<font class='boldbase'>$Lang::tr{'remark title'} <img src='/blob.gif' alt='*' /></font>
|
||||
<input type='text' name='REMARK' value='$cgiparams{'REMARK'}' size='55' maxlength='50' />
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td class='base' width='50%'>
|
||||
<img src='/blob.gif' alt ='*' align='top' />
|
||||
<font class='base'>$Lang::tr{'this field may be blank'}</font>
|
||||
</td>
|
||||
<td class='base' width='25%' align='center'>$Lang::tr{'enabled'}<input type='checkbox' name='ENABLED' $checked{'ENABLED'}{'on'} /></td>
|
||||
<td width='25%' align='center'>
|
||||
<input type='hidden' name='ACTION' value='$Lang::tr{'add'}' />
|
||||
<input type='submit' name='SUBMIT' value='$buttonText' />
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
END
|
||||
;
|
||||
if ($cgiparams{'ACTION'} eq $Lang::tr{'edit'}) {
|
||||
print "<input type='hidden' name='EDITING' value='$cgiparams{'ID'}' />\n";
|
||||
} else {
|
||||
print "<input type='hidden' name='EDITING' value='no' />\n";
|
||||
}
|
||||
&Header::closebox();
|
||||
print "</form>\n";
|
||||
|
||||
&Header::openbox('100%', 'left', $Lang::tr{'current rules'});
|
||||
print <<END
|
||||
<table width='100%'>
|
||||
<tr>
|
||||
<td width='7%' class='boldbase' align='center'><b>$Lang::tr{'proto'}</b></td>
|
||||
<td width='3%' class='boldbase' align='center'><b>$Lang::tr{'net'}</b></td>
|
||||
<td width='25%' class='boldbase' align='center'><b>$Lang::tr{'source'}</b></td>
|
||||
<td width='2%' class='boldbase' align='center'> </td>
|
||||
<td width='3%' class='boldbase' align='center'><b>$Lang::tr{'net'}</b></td>
|
||||
<td width='25%' class='boldbase' align='center'><b>$Lang::tr{'destination'}</b></td>
|
||||
<td width='30%' class='boldbase' align='center'><b>$Lang::tr{'remark'}</b></td>
|
||||
<td width='1%' class='boldbase' align='center'> </td>
|
||||
<td width='4%' class='boldbase' colspan='3' align='center'><b>$Lang::tr{'action'}</b></td>
|
||||
END
|
||||
;
|
||||
|
||||
# Achim Weber: if i add a new rule, this rule is not displayed?!?
|
||||
# we re-read always config.
|
||||
# If something has happeened re-read config
|
||||
#if($cgiparams{'ACTION'} ne '')
|
||||
#{
|
||||
open(FILE, $filename) or die 'Unable to open config file.';
|
||||
@current = <FILE>;
|
||||
close(FILE);
|
||||
#}
|
||||
my $id = 0;
|
||||
foreach my $line (@current)
|
||||
{
|
||||
my $protocol='';
|
||||
my $gif='';
|
||||
my $toggle='';
|
||||
my $gdesc='';
|
||||
$id++;
|
||||
chomp($line);
|
||||
my @temp = split(/\,/,$line);
|
||||
if ($temp[0] eq 'udp') { $protocol = 'UDP'; } else { $protocol = 'TCP' }
|
||||
|
||||
my $srcnetcolor = ($temp[5] eq 'blue')? ${Header::colourblue} : ${Header::colourorange};
|
||||
my $destnetcolor = ($temp[6] eq 'blue')? ${Header::colourblue} : ${Header::colourgreen};
|
||||
|
||||
if ($cgiparams{'ACTION'} eq $Lang::tr{'edit'} && $cgiparams{'ID'} eq $id) {
|
||||
print "<tr bgcolor='${Header::colouryellow}'>\n"; }
|
||||
elsif ($id % 2) {
|
||||
print "<tr bgcolor='${Header::table1colour}'>\n"; }
|
||||
else {
|
||||
print "<tr bgcolor='${Header::table2colour}'>\n"; }
|
||||
if ($temp[4] eq 'on') { $gif='on.gif'; $toggle='off'; $gdesc=$Lang::tr{'click to disable'};}
|
||||
else { $gif = 'off.gif'; $toggle='on'; $gdesc=$Lang::tr{'click to enable'}; }
|
||||
|
||||
# Darren Critchley - Get Port Service Name if we can - code borrowed from firewalllog.dat
|
||||
my $dstprt =$temp[3];
|
||||
$_=$temp[3];
|
||||
if (/^\d+$/) {
|
||||
my $servi = uc(getservbyport($temp[3], lc($temp[0])));
|
||||
if ($servi ne '' && $temp[3] < 1024) {
|
||||
$dstprt = "$dstprt($servi)"; }
|
||||
}
|
||||
# Darren Critchley - If the line is too long, wrap the port numbers
|
||||
my $dstaddr = "$temp[2] : $dstprt";
|
||||
if (length($dstaddr) > 26) {
|
||||
$dstaddr = "$temp[2] :<br /> $dstprt";
|
||||
}
|
||||
print <<END
|
||||
<td align='center'>$protocol</td>
|
||||
<td bgcolor='$srcnetcolor'></td>
|
||||
<td align='center'>$temp[1]</td>
|
||||
<td align='center'><img src='/images/forward.gif' /></td>
|
||||
<td bgcolor='$destnetcolor'></td>
|
||||
<td align='center'>$dstaddr</td>
|
||||
<td align='center'>$temp[7]</td>
|
||||
|
||||
<td align='center'>
|
||||
<form method='post' name='frma$id' action='$ENV{'SCRIPT_NAME'}'>
|
||||
<input type='image' name='$Lang::tr{'toggle enable disable'}' src='/images/$gif' alt='$gdesc' />
|
||||
<input type='hidden' name='ID' value='$id' />
|
||||
<input type='hidden' name='ENABLE' value='$toggle' />
|
||||
<input type='hidden' name='ACTION' value='$Lang::tr{'toggle enable disable'}' />
|
||||
</form>
|
||||
</td>
|
||||
|
||||
<td align='center'>
|
||||
<form method='post' name='frmb$id' action='$ENV{'SCRIPT_NAME'}'>
|
||||
<input type='image' name='$Lang::tr{'edit'}' src='/images/edit.gif' alt='$Lang::tr{'edit'}' />
|
||||
<input type='hidden' name='ID' value='$id' />
|
||||
<input type='hidden' name='ACTION' value='$Lang::tr{'edit'}' />
|
||||
</form>
|
||||
</td>
|
||||
|
||||
<td align='center'>
|
||||
<form method='post' name='frmc$id' action='$ENV{'SCRIPT_NAME'}'>
|
||||
<input type='image' name='$Lang::tr{'remove'}' src='/images/delete.gif' alt='$Lang::tr{'remove'}' />
|
||||
<input type='hidden' name='ID' value='$id' />
|
||||
<input type='hidden' name='ACTION' value='$Lang::tr{'remove'}' />
|
||||
</form>
|
||||
</td>
|
||||
|
||||
</tr>
|
||||
END
|
||||
;
|
||||
}
|
||||
print "</table>\n";
|
||||
|
||||
# If the fixed lease file contains entries, print Key to action icons
|
||||
if ( ! -z "$filename") {
|
||||
print <<END
|
||||
<table>
|
||||
<tr>
|
||||
<td class='boldbase'> <b>$Lang::tr{'legend'}:</b></td>
|
||||
<td> <img src='/images/on.gif' alt='$Lang::tr{'click to disable'}' /></td>
|
||||
<td class='base'>$Lang::tr{'click to disable'}</td>
|
||||
<td> <img src='/images/off.gif' alt='$Lang::tr{'click to enable'}' /></td>
|
||||
<td class='base'>$Lang::tr{'click to enable'}</td>
|
||||
<td> <img src='/images/edit.gif' alt='$Lang::tr{'edit'}' /></td>
|
||||
<td class='base'>$Lang::tr{'edit'}</td>
|
||||
<td> <img src='/images/delete.gif' alt='$Lang::tr{'remove'}' /></td>
|
||||
<td class='base'>$Lang::tr{'remove'}</td>
|
||||
</tr>
|
||||
</table>
|
||||
END
|
||||
;
|
||||
}
|
||||
|
||||
&Header::closebox();
|
||||
|
||||
&Header::closebigbox();
|
||||
|
||||
&Header::closepage();
|
||||
|
||||
sub validNet
|
||||
{
|
||||
my $srcNet = $_[0];
|
||||
my $destNet = $_[1];
|
||||
|
||||
if ($srcNet eq $destNet) {
|
||||
return $Lang::tr{'dmzpinholes for same net not necessary'}; }
|
||||
unless ($srcNet =~ /^(blue|orange)$/) {
|
||||
return $Lang::tr{'select source net'}; }
|
||||
unless ($destNet =~ /^(blue|green)$/) {
|
||||
return $Lang::tr{'select dest net'}; }
|
||||
|
||||
return '';
|
||||
}
|
||||
|
||||
sub haveOrangeNet
|
||||
{
|
||||
if ($netsettings{'CONFIG_TYPE'} == 2) {return 1;}
|
||||
if ($netsettings{'CONFIG_TYPE'} == 4) {return 1;}
|
||||
return 0;
|
||||
}
|
||||
|
||||
sub haveBlueNet
|
||||
{
|
||||
if ($netsettings{'CONFIG_TYPE'} == 3) {return 1;}
|
||||
if ($netsettings{'CONFIG_TYPE'} == 4) {return 1;}
|
||||
return 0;
|
||||
}
|
||||
2463
html/cgi-bin/forwardfw.cgi
Executable file
2463
html/cgi-bin/forwardfw.cgi
Executable file
File diff suppressed because it is too large
Load Diff
2198
html/cgi-bin/fwhosts.cgi
Executable file
2198
html/cgi-bin/fwhosts.cgi
Executable file
File diff suppressed because it is too large
Load Diff
@@ -341,7 +341,7 @@ END
|
||||
} else { print $Lang::tr{'advproxy off'}; }
|
||||
}
|
||||
if ( $netsettings{'ORANGE_DEV'} ) { print <<END;
|
||||
<tr><td align='center' bgcolor='$Header::colourorange' width='25%'><a href="/cgi-bin/dmzholes.cgi"><font size='2' color='white'><b>$Lang::tr{'dmz'}</b></font></a><br>
|
||||
<tr><td align='center' bgcolor='$Header::colourorange' width='25%'><a href="/cgi-bin/forwardfw.cgi"><font size='2' color='white'><b>$Lang::tr{'dmz'}</b></font></a><br>
|
||||
<td width='30%' align='center'>$netsettings{'ORANGE_ADDRESS'}
|
||||
<td width='45%' align='center'><font color=$Header::colourgreen>Online</font>
|
||||
END
|
||||
|
||||
@@ -11,7 +11,6 @@
|
||||
# $Id: optionsfw.cgi,v 1.1.2.10 2005/10/03 00:34:10 gespinasse Exp $
|
||||
#
|
||||
#
|
||||
|
||||
# enable only the following on debugging purpose
|
||||
#use warnings;
|
||||
#use CGI::Carp 'fatalsToBrowser';
|
||||
@@ -22,38 +21,49 @@ require "${General::swroot}/header.pl";
|
||||
|
||||
|
||||
my %checked =(); # Checkbox manipulations
|
||||
|
||||
# File used
|
||||
my $filename = "${General::swroot}/optionsfw/settings";
|
||||
|
||||
our %settings=();
|
||||
$settings{'DISABLEPING'} = 'NO';
|
||||
$settings{'DROPNEWNOTSYN'} = 'on';
|
||||
$settings{'DROPINPUT'} = 'on';
|
||||
$settings{'DROPOUTPUT'} = 'on';
|
||||
$settings{'DROPPORTSCAN'} = 'on';
|
||||
$settings{'DROPWIRELESSINPUT'} = 'on';
|
||||
$settings{'DROPWIRELESSFORWARD'} = 'on';
|
||||
my %fwdfwsettings=();
|
||||
my %configfwdfw=();
|
||||
my %configoutgoingfw=();
|
||||
|
||||
my $configfwdfw = "${General::swroot}/forward/config";
|
||||
my $configoutgoing = "${General::swroot}/forward/outgoing";
|
||||
my $errormessage = '';
|
||||
my $warnmessage = '';
|
||||
my $filename = "${General::swroot}/optionsfw/settings";
|
||||
|
||||
&General::readhash("${General::swroot}/forward/settings", \%fwdfwsettings);
|
||||
&Header::showhttpheaders();
|
||||
|
||||
#Get GUI values
|
||||
&Header::getcgihash(\%settings);
|
||||
|
||||
if ($settings{'ACTION'} eq $Lang::tr{'save'}) {
|
||||
$errormessage = $Lang::tr{'new optionsfw later'};
|
||||
delete $settings{'__CGI__'};delete $settings{'x'};delete $settings{'y'};
|
||||
&General::writehash($filename, \%settings); # Save good settings
|
||||
} else {
|
||||
&General::readhash($filename, \%settings); # Get saved settings and reset to good if needed
|
||||
}
|
||||
if ($settings{'defpol'} ne '1'){
|
||||
$errormessage .= $Lang::tr{'new optionsfw later'};
|
||||
&General::writehash($filename, \%settings); # Save good settings
|
||||
system("/usr/local/bin/forwardfwctrl");
|
||||
}else{
|
||||
if ($settings{'POLICY'} ne ''){
|
||||
$fwdfwsettings{'POLICY'} = $settings{'POLICY'};
|
||||
}
|
||||
if ($settings{'POLICY1'} ne ''){
|
||||
$fwdfwsettings{'POLICY1'} = $settings{'POLICY1'};
|
||||
}
|
||||
my $MODE = $fwdfwsettings{'POLICY'};
|
||||
my $MODE1 = $fwdfwsettings{'POLICY1'};
|
||||
%fwdfwsettings = ();
|
||||
$fwdfwsettings{'POLICY'} = "$MODE";
|
||||
$fwdfwsettings{'POLICY1'} = "$MODE1";
|
||||
&General::writehash("${General::swroot}/forward/settings", \%fwdfwsettings);
|
||||
&General::readhash("${General::swroot}/forward/settings", \%fwdfwsettings);
|
||||
system("/usr/local/bin/forwardfwctrl");
|
||||
}
|
||||
&General::readhash($filename, \%settings); # Load good settings
|
||||
}
|
||||
|
||||
&Header::openpage($Lang::tr{'options fw'}, 1, '');
|
||||
&Header::openbigbox('100%', 'left', '', $errormessage);
|
||||
|
||||
&General::readhash($filename, \%settings);
|
||||
if ($errormessage) {
|
||||
&Header::openbox('100%', 'left', $Lang::tr{'warning messages'});
|
||||
print "<font color='red'>$errormessage </font>";
|
||||
@@ -66,9 +76,12 @@ $checked{'DROPNEWNOTSYN'}{$settings{'DROPNEWNOTSYN'}} = "checked='checked'";
|
||||
$checked{'DROPINPUT'}{'off'} = '';
|
||||
$checked{'DROPINPUT'}{'on'} = '';
|
||||
$checked{'DROPINPUT'}{$settings{'DROPINPUT'}} = "checked='checked'";
|
||||
$checked{'DROPOUTPUT'}{'off'} = '';
|
||||
$checked{'DROPOUTPUT'}{'on'} = '';
|
||||
$checked{'DROPOUTPUT'}{$settings{'DROPOUTPUT'}} = "checked='checked'";
|
||||
$checked{'DROPFORWARD'}{'off'} = '';
|
||||
$checked{'DROPFORWARD'}{'on'} = '';
|
||||
$checked{'DROPFORWARD'}{$settings{'DROPFORWARD'}} = "checked='checked'";
|
||||
$checked{'DROPOUTGOING'}{'off'} = '';
|
||||
$checked{'DROPOUTGOING'}{'on'} = '';
|
||||
$checked{'DROPOUTGOING'}{$settings{'DROPOUTGOING'}} = "checked='checked'";
|
||||
$checked{'DROPPORTSCAN'}{'off'} = '';
|
||||
$checked{'DROPPORTSCAN'}{'on'} = '';
|
||||
$checked{'DROPPORTSCAN'}{$settings{'DROPPORTSCAN'}} = "checked='checked'";
|
||||
@@ -84,6 +97,21 @@ $checked{'DROPPROXY'}{$settings{'DROPPROXY'}} = "checked='checked'";
|
||||
$checked{'DROPSAMBA'}{'off'} = '';
|
||||
$checked{'DROPSAMBA'}{'on'} = '';
|
||||
$checked{'DROPSAMBA'}{$settings{'DROPSAMBA'}} = "checked='checked'";
|
||||
$checked{'SHOWCOLORS'}{'off'} = '';
|
||||
$checked{'SHOWCOLORS'}{'on'} = '';
|
||||
$checked{'SHOWCOLORS'}{$settings{'SHOWCOLORS'}} = "checked='checked'";
|
||||
$checked{'SHOWREMARK'}{'off'} = '';
|
||||
$checked{'SHOWREMARK'}{'on'} = '';
|
||||
$checked{'SHOWREMARK'}{$settings{'SHOWREMARK'}} = "checked='checked'";
|
||||
$checked{'SHOWTABLES'}{'off'} = '';
|
||||
$checked{'SHOWTABLES'}{'on'} = '';
|
||||
$checked{'SHOWTABLES'}{$settings{'SHOWTABLES'}} = "checked='checked'";
|
||||
$checked{'SHOWDROPDOWN'}{'off'} = '';
|
||||
$checked{'SHOWDROPDOWN'}{'on'} = '';
|
||||
$checked{'SHOWDROPDOWN'}{$settings{'SHOWDROPDOWN'}} = "checked='checked'";
|
||||
$selected{'FWPOLICY'}{$settings{'FWPOLICY'}}= 'selected';
|
||||
$selected{'FWPOLICY1'}{$settings{'FWPOLICY1'}}= 'selected';
|
||||
$selected{'FWPOLICY2'}{$settings{'FWPOLICY2'}}= 'selected';
|
||||
|
||||
&Header::openbox('100%', 'center', $Lang::tr{'options fw'});
|
||||
print "<form method='post' action='$ENV{'SCRIPT_NAME'}'>";
|
||||
@@ -96,8 +124,10 @@ print <<END
|
||||
<input type='radio' name='DROPNEWNOTSYN' value='off' $checked{'DROPNEWNOTSYN'}{'off'} /> off</td></tr>
|
||||
<tr><td align='left' width='60%'>$Lang::tr{'drop input'}</td><td align='left'>on <input type='radio' name='DROPINPUT' value='on' $checked{'DROPINPUT'}{'on'} />/
|
||||
<input type='radio' name='DROPINPUT' value='off' $checked{'DROPINPUT'}{'off'} /> off</td></tr>
|
||||
<tr><td align='left' width='60%'>$Lang::tr{'drop output'}</td><td align='left'>on <input type='radio' name='DROPOUTPUT' value='on' $checked{'DROPOUTPUT'}{'on'} />/
|
||||
<input type='radio' name='DROPOUTPUT' value='off' $checked{'DROPOUTPUT'}{'off'} /> off</td></tr>
|
||||
<tr><td align='left' width='60%'>$Lang::tr{'drop forward'}</td><td align='left'>on <input type='radio' name='DROPFORWARD' value='on' $checked{'DROPFORWARD'}{'on'} />/
|
||||
<input type='radio' name='DROPFORWARD' value='off' $checked{'DROPFORWARD'}{'off'} /> off</td></tr>
|
||||
<tr><td align='left' width='60%'>$Lang::tr{'drop outgoing'}</td><td align='left'>on <input type='radio' name='DROPOUTGOING' value='on' $checked{'DROPOUTGOING'}{'on'} />/
|
||||
<input type='radio' name='DROPOUTGOING' value='off' $checked{'DROPOUTGOING'}{'off'} /> off</td></tr>
|
||||
<tr><td align='left' width='60%'>$Lang::tr{'drop portscan'}</td><td align='left'>on <input type='radio' name='DROPPORTSCAN' value='on' $checked{'DROPPORTSCAN'}{'on'} />/
|
||||
<input type='radio' name='DROPPORTSCAN' value='off' $checked{'DROPPORTSCAN'}{'off'} /> off</td></tr>
|
||||
<tr><td align='left' width='60%'>$Lang::tr{'drop wirelessinput'}</td><td align='left'>on <input type='radio' name='DROPWIRELESSINPUT' value='on' $checked{'DROPWIRELESSINPUT'}{'on'} />/
|
||||
@@ -105,7 +135,8 @@ print <<END
|
||||
<tr><td align='left' width='60%'>$Lang::tr{'drop wirelessforward'}</td><td align='left'>on <input type='radio' name='DROPWIRELESSFORWARD' value='on' $checked{'DROPWIRELESSFORWARD'}{'on'} />/
|
||||
<input type='radio' name='DROPWIRELESSFORWARD' value='off' $checked{'DROPWIRELESSFORWARD'}{'off'} /> off</td></tr>
|
||||
</table>
|
||||
<br />
|
||||
<br/>
|
||||
|
||||
<table width='95%' cellspacing='0'>
|
||||
<tr bgcolor='$color{'color20'}'><td colspan='2' align='left'><b>$Lang::tr{'fw blue'}</b></td></tr>
|
||||
<tr><td align='left' width='60%'>$Lang::tr{'drop proxy'}</td><td align='left'>on <input type='radio' name='DROPPROXY' value='on' $checked{'DROPPROXY'}{'on'} />/
|
||||
@@ -113,15 +144,77 @@ print <<END
|
||||
<tr><td align='left' width='60%'>$Lang::tr{'drop samba'}</td><td align='left'>on <input type='radio' name='DROPSAMBA' value='on' $checked{'DROPSAMBA'}{'on'} />/
|
||||
<input type='radio' name='DROPSAMBA' value='off' $checked{'DROPSAMBA'}{'off'} /> off</td></tr>
|
||||
</table>
|
||||
<br>
|
||||
<table width='95%' cellspacing='0'>
|
||||
<tr bgcolor='$color{'color20'}'><td colspan='2' align='left'><b>$Lang::tr{'fw settings'}</b></td></tr>
|
||||
<tr><td align='left' width='60%'>$Lang::tr{'fw settings color'}</td><td align='left'>on <input type='radio' name='SHOWCOLORS' value='on' $checked{'SHOWCOLORS'}{'on'} />/
|
||||
<input type='radio' name='SHOWCOLORS' value='off' $checked{'SHOWCOLORS'}{'off'} /> off</td></tr>
|
||||
<tr><td align='left' width='60%'>$Lang::tr{'fw settings remark'}</td><td align='left'>on <input type='radio' name='SHOWREMARK' value='on' $checked{'SHOWREMARK'}{'on'} />/
|
||||
<input type='radio' name='SHOWREMARK' value='off' $checked{'SHOWREMARK'}{'off'} /> off</td></tr>
|
||||
<tr><td align='left' width='60%'>$Lang::tr{'fw settings ruletable'}</td><td align='left'>on <input type='radio' name='SHOWTABLES' value='on' $checked{'SHOWTABLES'}{'on'} />/
|
||||
<input type='radio' name='SHOWTABLES' value='off' $checked{'SHOWTABLES'}{'off'} /> off</td></tr>
|
||||
<tr><td align='left' width='60%'>$Lang::tr{'fw settings dropdown'}</td><td align='left'>on <input type='radio' name='SHOWDROPDOWN' value='on' $checked{'SHOWDROPDOWN'}{'on'} />/
|
||||
<input type='radio' name='SHOWDROPDOWN' value='off' $checked{'SHOWDROPDOWN'}{'off'} /> off</td></tr>
|
||||
</table>
|
||||
<br />
|
||||
<table width='95%' cellspacing='0'>
|
||||
<tr bgcolor='$color{'color20'}'><td colspan='2' align='left'><b>$Lang::tr{'fw default drop'}</b></td></tr>
|
||||
<tr><td align='left' width='60%'>$Lang::tr{'drop action'}</td><td><select name='FWPOLICY'>
|
||||
<option value='DROP' $selected{'FWPOLICY'}{'DROP'}>DROP</option>
|
||||
<option value='REJECT' $selected{'FWPOLICY'}{'REJECT'}>REJECT</option></select>
|
||||
</td></tr>
|
||||
<tr><td align='left' width='60%'>$Lang::tr{'drop action1'}</td><td><select name='FWPOLICY1'>
|
||||
<option value='DROP' $selected{'FWPOLICY1'}{'DROP'}>DROP</option>
|
||||
<option value='REJECT' $selected{'FWPOLICY1'}{'REJECT'}>REJECT</option></select>
|
||||
</td></tr>
|
||||
<tr><td align='left' width='60%'>$Lang::tr{'drop action2'}</td><td><select name='FWPOLICY2'>
|
||||
<option value='DROP' $selected{'FWPOLICY2'}{'DROP'}>DROP</option>
|
||||
<option value='REJECT' $selected{'FWPOLICY2'}{'REJECT'}>REJECT</option></select>
|
||||
</td></tr>
|
||||
</table>
|
||||
|
||||
<br />
|
||||
<table width='10%' cellspacing='0'>
|
||||
<tr><td align='center'><form method='post' action='$ENV{'SCRIPT_NAME'}'>
|
||||
<input type='hidden' name='ACTION' value=$Lang::tr{'save'} />
|
||||
<input type='image' alt='$Lang::tr{'save'}' title='$Lang::tr{'save'}' src='/images/media-floppy.png' /></form></td></tr>
|
||||
<input type='submit' name='ACTION' value=$Lang::tr{'save'} />
|
||||
</form></td></tr>
|
||||
</table>
|
||||
</form>
|
||||
END
|
||||
;
|
||||
&Header::closebox();
|
||||
|
||||
&Header::openbox('100%', 'center', $Lang::tr{'fwdfw pol title'});
|
||||
if ($fwdfwsettings{'POLICY'} eq 'MODE1'){ $selected{'POLICY'}{'MODE1'} = 'selected'; } else { $selected{'POLICY'}{'MODE1'} = ''; }
|
||||
if ($fwdfwsettings{'POLICY'} eq 'MODE2'){ $selected{'POLICY'}{'MODE2'} = 'selected'; } else { $selected{'POLICY'}{'MODE2'} = ''; }
|
||||
if ($fwdfwsettings{'POLICY1'} eq 'MODE1'){ $selected{'POLICY1'}{'MODE1'} = 'selected'; } else { $selected{'POLICY1'}{'MODE1'} = ''; }
|
||||
if ($fwdfwsettings{'POLICY1'} eq 'MODE2'){ $selected{'POLICY1'}{'MODE2'} = 'selected'; } else { $selected{'POLICY1'}{'MODE2'} = ''; }
|
||||
print <<END;
|
||||
<form method='post' action='$ENV{'SCRIPT_NAME'}'>
|
||||
<table width='100%' border='0'>
|
||||
<tr><td colspan='3' style='font-weight:bold;color:red;' align='left'>FORWARD </td></tr>
|
||||
<tr><td colspan='3' align='left'>$Lang::tr{'fwdfw pol text'}</td></tr>
|
||||
<tr><td colspan='3'><hr /></td></tr>
|
||||
<tr><td width='15%' align='left'> <select name='POLICY' style="width: 100px">
|
||||
<option value='MODE1' $selected{'POLICY'}{'MODE1'}>$Lang::tr{'fwdfw pol block'}</option>
|
||||
<option value='MODE2' $selected{'POLICY'}{'MODE2'}>$Lang::tr{'fwdfw pol allow'}</option></select>
|
||||
<input type='submit' name='ACTION' value=$Lang::tr{'save'} /><input type='hidden' name='defpol' value='1'></td>
|
||||
END
|
||||
print "</tr></table></form>";
|
||||
print"<br><br>";
|
||||
print <<END;
|
||||
<form method='post' action='$ENV{'SCRIPT_NAME'}'>
|
||||
<table width='100%' border='0'>
|
||||
<tr><td colspan='3' style='font-weight:bold;color:red;' align='left'>OUTGOING </td></tr>
|
||||
<tr><td colspan='3' align='left'>$Lang::tr{'fwdfw pol text1'}</td></tr>
|
||||
<tr><td colspan='3'><hr /></td></tr>
|
||||
<tr><td width='15%' align='left'> <select name='POLICY1' style="width: 100px">
|
||||
<option value='MODE1' $selected{'POLICY1'}{'MODE1'}>$Lang::tr{'fwdfw pol block'}</option>
|
||||
<option value='MODE2' $selected{'POLICY1'}{'MODE2'}>$Lang::tr{'fwdfw pol allow'}</option></select>
|
||||
<input type='submit' name='ACTION' value='$Lang::tr{'save'}' /><input type='hidden' name='defpol' value='1'></td>
|
||||
END
|
||||
print "</tr></table></form>";
|
||||
&Header::closebox();
|
||||
|
||||
&Header::closebigbox();
|
||||
&Header::closepage();
|
||||
|
||||
@@ -1,849 +0,0 @@
|
||||
#!/usr/bin/perl
|
||||
###############################################################################
|
||||
# #
|
||||
# IPFire.org - A linux based firewall #
|
||||
# Copyright (C) 2005-2010 IPFire Team #
|
||||
# #
|
||||
# This program is free software: you can redistribute it and/or modify #
|
||||
# it under the terms of the GNU General Public License as published by #
|
||||
# the Free Software Foundation, either version 3 of the License, or #
|
||||
# (at your option) any later version. #
|
||||
# #
|
||||
# This program is distributed in the hope that it will be useful, #
|
||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of #
|
||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
|
||||
# GNU General Public License for more details. #
|
||||
# #
|
||||
# You should have received a copy of the GNU General Public License #
|
||||
# along with this program. If not, see <http://www.gnu.org/licenses/>. #
|
||||
# #
|
||||
###############################################################################
|
||||
|
||||
use strict;
|
||||
# enable only the following on debugging purpose
|
||||
#use warnings;
|
||||
#use CGI::Carp 'fatalsToBrowser';
|
||||
|
||||
require '/var/ipfire/general-functions.pl';
|
||||
require "${General::swroot}/lang.pl";
|
||||
require "${General::swroot}/header.pl";
|
||||
|
||||
my %outfwsettings = ();
|
||||
my %checked = ();
|
||||
my %selected= () ;
|
||||
my %netsettings = ();
|
||||
my $errormessage = "";
|
||||
my $configentry = "";
|
||||
my @configs = ();
|
||||
my @configline = ();
|
||||
my $p2pentry = "";
|
||||
my @p2ps = ();
|
||||
my @p2pline = ();
|
||||
|
||||
my $configfile = "/var/ipfire/outgoing/rules";
|
||||
my $configpath = "/var/ipfire/outgoing/groups/";
|
||||
my $p2pfile = "/var/ipfire/outgoing/p2protocols";
|
||||
my $servicefile = "/var/ipfire/outgoing/defaultservices";
|
||||
|
||||
my %color = ();
|
||||
my %mainsettings = ();
|
||||
&General::readhash("${General::swroot}/main/settings", \%mainsettings);
|
||||
&General::readhash("/srv/web/ipfire/html/themes/".$mainsettings{'THEME'}."/include/colors.txt", \%color);
|
||||
|
||||
&General::readhash("${General::swroot}/ethernet/settings", \%netsettings);
|
||||
|
||||
&Header::showhttpheaders();
|
||||
|
||||
### Values that have to be initialized
|
||||
$outfwsettings{'ACTION'} = '';
|
||||
$outfwsettings{'VALID'} = 'yes';
|
||||
$outfwsettings{'EDIT'} = 'no';
|
||||
$outfwsettings{'NAME'} = '';
|
||||
$outfwsettings{'SNET'} = '';
|
||||
$outfwsettings{'SIP'} = '';
|
||||
$outfwsettings{'SPORT'} = '';
|
||||
$outfwsettings{'SMAC'} = '';
|
||||
$outfwsettings{'DIP'} = '';
|
||||
$outfwsettings{'DPORT'} = '';
|
||||
$outfwsettings{'PROT'} = '';
|
||||
$outfwsettings{'STATE'} = '';
|
||||
$outfwsettings{'DISPLAY_DIP'} = '';
|
||||
$outfwsettings{'DISPLAY_DPORT'} = '';
|
||||
$outfwsettings{'DISPLAY_SMAC'} = '';
|
||||
$outfwsettings{'DISPLAY_SIP'} = '';
|
||||
$outfwsettings{'POLICY'} = 'MODE0';
|
||||
$outfwsettings{'MODE1LOG'} = 'off';
|
||||
|
||||
$outfwsettings{'TIME_FROM'} = '00:00';
|
||||
$outfwsettings{'TIME_TO'} = '00:00';
|
||||
|
||||
&General::readhash("${General::swroot}/outgoing/settings", \%outfwsettings);
|
||||
&Header::getcgihash(\%outfwsettings);
|
||||
|
||||
###############
|
||||
# DEBUG DEBUG
|
||||
#&Header::openbox('100%', 'left', 'DEBUG');
|
||||
#my $debugCount = 0;
|
||||
#foreach my $line (sort keys %outfwsettings) {
|
||||
#print "$line = $outfwsettings{$line}<br />\n";
|
||||
# $debugCount++;
|
||||
#}
|
||||
#print " Count: $debugCount\n";
|
||||
#&Header::closebox();
|
||||
# DEBUG DEBUG
|
||||
###############
|
||||
|
||||
$selected{'TIME_FROM'}{$outfwsettings{'TIME_FROM'}} = "selected='selected'";
|
||||
$selected{'TIME_TO'}{$outfwsettings{'TIME_TO'}} = "selected='selected'";
|
||||
|
||||
$checked{'MODE1LOG'}{'off'} = '';
|
||||
$checked{'MODE1LOG'}{'on'} = '';
|
||||
$checked{'MODE1LOG'}{$outfwsettings{'MODE1LOG'}} = "checked='checked'";
|
||||
$checked{'TIME_MON'}{'off'} = '';
|
||||
$checked{'TIME_MON'}{'on'} = '';
|
||||
$checked{'TIME_MON'}{$outfwsettings{'TIME_MON'}} = "checked='checked'";
|
||||
$checked{'TIME_TUE'}{'off'} = '';
|
||||
$checked{'TIME_TUE'}{'on'} = '';
|
||||
$checked{'TIME_TUE'}{$outfwsettings{'TIME_TUE'}} = "checked='checked'";
|
||||
$checked{'TIME_WED'}{'off'} = '';
|
||||
$checked{'TIME_WED'}{'on'} = '';
|
||||
$checked{'TIME_WED'}{$outfwsettings{'TIME_WED'}} = "checked='checked'";
|
||||
$checked{'TIME_THU'}{'off'} = '';
|
||||
$checked{'TIME_THU'}{'on'} = '';
|
||||
$checked{'TIME_THU'}{$outfwsettings{'TIME_THU'}} = "checked='checked'";
|
||||
$checked{'TIME_FRI'}{'off'} = '';
|
||||
$checked{'TIME_FRI'}{'on'} = '';
|
||||
$checked{'TIME_FRI'}{$outfwsettings{'TIME_FRI'}} = "checked='checked'";
|
||||
$checked{'TIME_SAT'}{'off'} = '';
|
||||
$checked{'TIME_SAT'}{'on'} = '';
|
||||
$checked{'TIME_SAT'}{$outfwsettings{'TIME_SAT'}} = "checked='checked'";
|
||||
$checked{'TIME_SUN'}{'off'} = '';
|
||||
$checked{'TIME_SUN'}{'on'} = '';
|
||||
$checked{'TIME_SUN'}{$outfwsettings{'TIME_SUN'}} = "checked='checked'";
|
||||
|
||||
if ($outfwsettings{'POLICY'} eq 'MODE0'){ $selected{'POLICY'}{'MODE0'} = 'selected'; } else { $selected{'POLICY'}{'MODE0'} = ''; }
|
||||
if ($outfwsettings{'POLICY'} eq 'MODE1'){ $selected{'POLICY'}{'MODE1'} = 'selected'; } else { $selected{'POLICY'}{'MODE1'} = ''; }
|
||||
if ($outfwsettings{'POLICY'} eq 'MODE2'){ $selected{'POLICY'}{'MODE2'} = 'selected'; } else { $selected{'POLICY'}{'MODE2'} = ''; }
|
||||
|
||||
# This is a little hack if poeple don<6F>t mark any date then all will be selected, because they might have forgotten to select
|
||||
# a valid day. A Rule without any matching day will never work, because the timeranges are new feature people might not notice
|
||||
# that they have to select a day for the rule.
|
||||
|
||||
if ( $outfwsettings{'TIME_MON'} eq "" &&
|
||||
$outfwsettings{'TIME_TUE'} eq "" &&
|
||||
$outfwsettings{'TIME_WED'} eq "" &&
|
||||
$outfwsettings{'TIME_THU'} eq "" &&
|
||||
$outfwsettings{'TIME_FRI'} eq "" &&
|
||||
$outfwsettings{'TIME_SAT'} eq "" &&
|
||||
$outfwsettings{'TIME_SUN'} eq "" )
|
||||
{
|
||||
$outfwsettings{'TIME_MON'} = "on";
|
||||
$outfwsettings{'TIME_TUE'} = "on";
|
||||
$outfwsettings{'TIME_WED'} = "on";
|
||||
$outfwsettings{'TIME_THU'} = "on";
|
||||
$outfwsettings{'TIME_FRI'} = "on";
|
||||
$outfwsettings{'TIME_SAT'} = "on";
|
||||
$outfwsettings{'TIME_SUN'} = "on";
|
||||
}
|
||||
|
||||
&Header::openpage($Lang::tr{'outgoing firewall'}, 1, '');
|
||||
&Header::openbigbox('100%', 'left', '', $errormessage);
|
||||
|
||||
############################################################################################################################
|
||||
############################################################################################################################
|
||||
|
||||
if ($outfwsettings{'ACTION'} eq $Lang::tr{'reset'})
|
||||
{
|
||||
$outfwsettings{'POLICY'}='MODE0';
|
||||
unlink $configfile;
|
||||
system("/usr/bin/touch $configfile");
|
||||
my $MODE = $outfwsettings{'POLICY'};
|
||||
%outfwsettings = ();
|
||||
$outfwsettings{'POLICY'} = "$MODE";
|
||||
&General::writehash("${General::swroot}/outgoing/settings", \%outfwsettings);
|
||||
}
|
||||
if ($outfwsettings{'ACTION'} eq $Lang::tr{'save'})
|
||||
{
|
||||
my $MODE = $outfwsettings{'POLICY'};
|
||||
my $MODE1LOG = $outfwsettings{'MODE1LOG'};
|
||||
%outfwsettings = ();
|
||||
$outfwsettings{'POLICY'} = "$MODE";
|
||||
$outfwsettings{'MODE1LOG'} = "$MODE1LOG";
|
||||
&General::writehash("${General::swroot}/outgoing/settings", \%outfwsettings);
|
||||
system("/usr/local/bin/outgoingfwctrl");
|
||||
}
|
||||
if ($outfwsettings{'ACTION'} eq 'enable')
|
||||
{
|
||||
open( FILE, "< $p2pfile" ) or die "Unable to read $p2pfile";
|
||||
@p2ps = <FILE>;
|
||||
close FILE;
|
||||
open( FILE, "> $p2pfile" ) or die "Unable to write $p2pfile";
|
||||
foreach $p2pentry (sort @p2ps)
|
||||
{
|
||||
@p2pline = split( /\;/, $p2pentry );
|
||||
if ($p2pline[1] eq $outfwsettings{'P2PROT'}) {
|
||||
print FILE "$p2pline[0];$p2pline[1];on;\n";
|
||||
} else {
|
||||
print FILE "$p2pline[0];$p2pline[1];$p2pline[2];\n";
|
||||
}
|
||||
}
|
||||
close FILE;
|
||||
system("/usr/local/bin/outgoingfwctrl");
|
||||
}
|
||||
if ($outfwsettings{'ACTION'} eq 'disable')
|
||||
{
|
||||
open( FILE, "< $p2pfile" ) or die "Unable to read $p2pfile";
|
||||
@p2ps = <FILE>;
|
||||
close FILE;
|
||||
open( FILE, "> $p2pfile" ) or die "Unable to write $p2pfile";
|
||||
foreach $p2pentry (sort @p2ps)
|
||||
{
|
||||
@p2pline = split( /\;/, $p2pentry );
|
||||
if ($p2pline[1] eq $outfwsettings{'P2PROT'}) {
|
||||
print FILE "$p2pline[0];$p2pline[1];off;\n";
|
||||
} else {
|
||||
print FILE "$p2pline[0];$p2pline[1];$p2pline[2];\n";
|
||||
}
|
||||
}
|
||||
close FILE;
|
||||
system("/usr/local/bin/outgoingfwctrl");
|
||||
}
|
||||
if ($outfwsettings{'ACTION'} eq $Lang::tr{'edit'})
|
||||
{
|
||||
open( FILE, "< $configfile" ) or die "Unable to read $configfile";
|
||||
@configs = <FILE>;
|
||||
close FILE;
|
||||
open( FILE, "> $configfile" ) or die "Unable to write $configfile";
|
||||
foreach $configentry (sort @configs)
|
||||
{
|
||||
@configline = split( /\;/, $configentry );
|
||||
|
||||
$configline[10] = "on" if not exists $configline[11];
|
||||
$configline[11] = "on" if not exists $configline[11];
|
||||
$configline[12] = "on" if not exists $configline[12];
|
||||
$configline[13] = "on" if not exists $configline[13];
|
||||
$configline[14] = "on" if not exists $configline[14];
|
||||
$configline[15] = "on" if not exists $configline[15];
|
||||
$configline[16] = "on" if not exists $configline[16];
|
||||
$configline[17] = "00:00" if not exists $configline[17];
|
||||
$configline[18] = "00:00" if not exists $configline[18];
|
||||
|
||||
unless (($configline[0] eq $outfwsettings{'STATE'}) &&
|
||||
($configline[1] eq $outfwsettings{'ENABLED'}) &&
|
||||
($configline[2] eq $outfwsettings{'SNET'}) &&
|
||||
($configline[3] eq $outfwsettings{'PROT'}) &&
|
||||
($configline[4] eq $outfwsettings{'NAME'}) &&
|
||||
($configline[5] eq $outfwsettings{'SIP'}) &&
|
||||
($configline[6] eq $outfwsettings{'SMAC'}) &&
|
||||
($configline[7] eq $outfwsettings{'DIP'}) &&
|
||||
($configline[9] eq $outfwsettings{'LOG'}) &&
|
||||
($configline[8] eq $outfwsettings{'DPORT'}) &&
|
||||
($configline[10] eq $outfwsettings{'TIME_MON'}) &&
|
||||
($configline[11] eq $outfwsettings{'TIME_TUE'}) &&
|
||||
($configline[12] eq $outfwsettings{'TIME_WED'}) &&
|
||||
($configline[13] eq $outfwsettings{'TIME_THU'}) &&
|
||||
($configline[14] eq $outfwsettings{'TIME_FRI'}) &&
|
||||
($configline[15] eq $outfwsettings{'TIME_SAT'}) &&
|
||||
($configline[16] eq $outfwsettings{'TIME_SUN'}) &&
|
||||
($configline[17] eq $outfwsettings{'TIME_FROM'}) &&
|
||||
($configline[18] eq $outfwsettings{'TIME_TO'}))
|
||||
{
|
||||
print FILE $configentry;
|
||||
}
|
||||
}
|
||||
close FILE;
|
||||
$selected{'SNET'}{"$outfwsettings{'SNET'}"} = 'selected';
|
||||
$selected{'PROT'}{"$outfwsettings{'PROT'}"} = 'selected';
|
||||
$selected{'LOG'}{"$outfwsettings{'LOG'}"} = 'selected';
|
||||
&addrule();
|
||||
&Header::closebigbox();
|
||||
&Header::closepage();
|
||||
exit
|
||||
system("/usr/local/bin/outgoingfwctrl");
|
||||
}
|
||||
if ($outfwsettings{'ACTION'} eq $Lang::tr{'delete'})
|
||||
{
|
||||
open( FILE, "< $configfile" ) or die "Unable to read $configfile";
|
||||
@configs = <FILE>;
|
||||
close FILE;
|
||||
open( FILE, "> $configfile" ) or die "Unable to write $configfile";
|
||||
foreach $configentry (sort @configs)
|
||||
{
|
||||
@configline = split( /\;/, $configentry );
|
||||
|
||||
$configline[10] = "on" if not exists $configline[11];
|
||||
$configline[11] = "on" if not exists $configline[11];
|
||||
$configline[12] = "on" if not exists $configline[12];
|
||||
$configline[13] = "on" if not exists $configline[13];
|
||||
$configline[14] = "on" if not exists $configline[14];
|
||||
$configline[15] = "on" if not exists $configline[15];
|
||||
$configline[16] = "on" if not exists $configline[16];
|
||||
$configline[17] = "00:00" if not exists $configline[17];
|
||||
$configline[18] = "00:00" if not exists $configline[18];
|
||||
|
||||
unless (($configline[0] eq $outfwsettings{'STATE'}) &&
|
||||
($configline[1] eq $outfwsettings{'ENABLED'}) &&
|
||||
($configline[2] eq $outfwsettings{'SNET'}) &&
|
||||
($configline[3] eq $outfwsettings{'PROT'}) &&
|
||||
($configline[4] eq $outfwsettings{'NAME'}) &&
|
||||
($configline[5] eq $outfwsettings{'SIP'}) &&
|
||||
($configline[6] eq $outfwsettings{'SMAC'}) &&
|
||||
($configline[7] eq $outfwsettings{'DIP'}) &&
|
||||
($configline[9] eq $outfwsettings{'LOG'}) &&
|
||||
($configline[8] eq $outfwsettings{'DPORT'}) &&
|
||||
($configline[10] eq $outfwsettings{'TIME_MON'}) &&
|
||||
($configline[11] eq $outfwsettings{'TIME_TUE'}) &&
|
||||
($configline[12] eq $outfwsettings{'TIME_WED'}) &&
|
||||
($configline[13] eq $outfwsettings{'TIME_THU'}) &&
|
||||
($configline[14] eq $outfwsettings{'TIME_FRI'}) &&
|
||||
($configline[15] eq $outfwsettings{'TIME_SAT'}) &&
|
||||
($configline[16] eq $outfwsettings{'TIME_SUN'}) &&
|
||||
($configline[17] eq $outfwsettings{'TIME_FROM'}) &&
|
||||
($configline[18] eq $outfwsettings{'TIME_TO'}))
|
||||
{
|
||||
print FILE $configentry;
|
||||
}
|
||||
}
|
||||
close FILE;
|
||||
system("/usr/local/bin/outgoingfwctrl");
|
||||
}
|
||||
if ($outfwsettings{'ACTION'} eq $Lang::tr{'add'})
|
||||
{
|
||||
if ( $outfwsettings{'VALID'} eq 'yes' ) {
|
||||
|
||||
if ( $outfwsettings{'SNET'} eq "all" ) {
|
||||
$outfwsettings{'SIP'} ="";
|
||||
$outfwsettings{'SMAC'}="";
|
||||
}
|
||||
open( FILE, ">> $configfile" ) or die "Unable to write $configfile";
|
||||
print FILE <<END
|
||||
$outfwsettings{'STATE'};$outfwsettings{'ENABLED'};$outfwsettings{'SNET'};$outfwsettings{'PROT'};$outfwsettings{'NAME'};$outfwsettings{'SIP'};$outfwsettings{'SMAC'};$outfwsettings{'DIP'};$outfwsettings{'DPORT'};$outfwsettings{'LOG'};$outfwsettings{'TIME_MON'};$outfwsettings{'TIME_TUE'};$outfwsettings{'TIME_WED'};$outfwsettings{'TIME_THU'};$outfwsettings{'TIME_FRI'};$outfwsettings{'TIME_SAT'};$outfwsettings{'TIME_SUN'};$outfwsettings{'TIME_FROM'};$outfwsettings{'TIME_TO'};
|
||||
END
|
||||
;
|
||||
close FILE;
|
||||
system("/usr/local/bin/outgoingfwctrl");
|
||||
} else {
|
||||
$outfwsettings{'ACTION'} = 'Add rule';
|
||||
}
|
||||
}
|
||||
if ($outfwsettings{'ACTION'} eq $Lang::tr{'Add Rule'})
|
||||
{
|
||||
&addrule();
|
||||
exit
|
||||
}
|
||||
|
||||
&General::readhash("${General::swroot}/outgoing/settings", \%outfwsettings);
|
||||
|
||||
if ($errormessage) {
|
||||
&Header::openbox('100%', 'left', $Lang::tr{'error messages'});
|
||||
print "<class name='base'>$errormessage\n";
|
||||
print " </class>\n";
|
||||
&Header::closebox();
|
||||
}
|
||||
|
||||
############################################################################################################################
|
||||
############################################################################################################################
|
||||
|
||||
if ($outfwsettings{'POLICY'} ne 'MODE0'){
|
||||
&Header::openbox('100%', 'center', 'Rules');
|
||||
print <<END
|
||||
<form method='post' action='$ENV{'SCRIPT_NAME'}'>
|
||||
<input type='submit' name='ACTION' value='$Lang::tr{'Add Rule'}' />
|
||||
</form>
|
||||
END
|
||||
;
|
||||
open( FILE, "< $configfile" ) or die "Unable to read $configfile";
|
||||
@configs = <FILE>;
|
||||
close FILE;
|
||||
if (@configs) {
|
||||
print <<END
|
||||
<hr />
|
||||
<table border='0' width='100%' cellspacing='0'>
|
||||
<tr bgcolor='$color{'color22'}'>
|
||||
<td width='14%' align='center'><b>$Lang::tr{'protocol'}</b></td>
|
||||
<td width='14%' align='center'><b>$Lang::tr{'network'}</b></td>
|
||||
<td width='14%' align='center'><b>$Lang::tr{'destination'}</b></td>
|
||||
<td width='14%' align='center'><b>$Lang::tr{'description'}</b></td>
|
||||
<td width='14%' align='center'><b>$Lang::tr{'policy'}</b></td>
|
||||
<td width='16%' align='center'><b>$Lang::tr{'logging'}</b></td>
|
||||
<td width='14%' align='center'><b>$Lang::tr{'action'}</b></td>
|
||||
END
|
||||
;
|
||||
foreach $configentry (sort @configs)
|
||||
{
|
||||
@configline = split( /\;/, $configentry );
|
||||
$outfwsettings{'STATE'} = $configline[0];
|
||||
$outfwsettings{'ENABLED'} = $configline[1];
|
||||
$outfwsettings{'SNET'} = $configline[2];
|
||||
$outfwsettings{'PROT'} = $configline[3];
|
||||
$outfwsettings{'NAME'} = $configline[4];
|
||||
$outfwsettings{'SIP'} = $configline[5];
|
||||
$outfwsettings{'SMAC'} = $configline[6];
|
||||
$outfwsettings{'DIP'} = $configline[7];
|
||||
$outfwsettings{'DPORT'} = $configline[8];
|
||||
$outfwsettings{'LOG'} = $configline[9];
|
||||
|
||||
$configline[10] = "on" if not exists $configline[11];
|
||||
$configline[11] = "on" if not exists $configline[11];
|
||||
$configline[12] = "on" if not exists $configline[12];
|
||||
$configline[13] = "on" if not exists $configline[13];
|
||||
$configline[14] = "on" if not exists $configline[14];
|
||||
$configline[15] = "on" if not exists $configline[15];
|
||||
$configline[16] = "on" if not exists $configline[16];
|
||||
$configline[17] = "00:00" if not exists $configline[17];
|
||||
$configline[18] = "00:00" if not exists $configline[18];
|
||||
|
||||
$outfwsettings{'TIME_MON'} = $configline[10];
|
||||
$outfwsettings{'TIME_TUE'} = $configline[11];
|
||||
$outfwsettings{'TIME_WED'} = $configline[12];
|
||||
$outfwsettings{'TIME_THU'} = $configline[13];
|
||||
$outfwsettings{'TIME_FRI'} = $configline[14];
|
||||
$outfwsettings{'TIME_SAT'} = $configline[15];
|
||||
$outfwsettings{'TIME_SUN'} = $configline[16];
|
||||
$outfwsettings{'TIME_FROM'} = $configline[17];
|
||||
$outfwsettings{'TIME_TO'} = $configline[18];
|
||||
|
||||
if ($outfwsettings{'DIP'} eq ''){ $outfwsettings{'DISPLAY_DIP'} = 'ALL'; } else { $outfwsettings{'DISPLAY_DIP'} = $outfwsettings{'DIP'}; }
|
||||
if ($outfwsettings{'DPORT'} eq ''){ $outfwsettings{'DISPLAY_DPORT'} = 'ALL'; } else { $outfwsettings{'DISPLAY_DPORT'} = $outfwsettings{'DPORT'}; }
|
||||
if ($outfwsettings{'STATE'} eq 'DENY'){ $outfwsettings{'DISPLAY_STATE'} = "<img src='/images/stock_stop.png' alt='DENY' />"; }
|
||||
if ($outfwsettings{'STATE'} eq 'ALLOW'){ $outfwsettings{'DISPLAY_STATE'} = "<img src='/images/stock_ok.png' alt='ALLOW' />"; }
|
||||
if ((($outfwsettings{'POLICY'} eq 'MODE1') && ($outfwsettings{'STATE'} eq 'ALLOW')) || (($outfwsettings{'POLICY'} eq 'MODE2') && ($outfwsettings{'STATE'} eq 'DENY'))){
|
||||
if ( $outfwsettings{'ENABLED'} eq "on" ){
|
||||
print "<tr bgcolor='$color{'color20'}'>";
|
||||
} else {
|
||||
print "<tr bgcolor='$color{'color18'}'>";
|
||||
}
|
||||
print <<END
|
||||
<td align='center'>$outfwsettings{'PROT'}
|
||||
<td align='center'>$outfwsettings{'SNET'}
|
||||
<td align='center'>$outfwsettings{'DISPLAY_DIP'}:$outfwsettings{'DISPLAY_DPORT'}
|
||||
<td align='center'>$outfwsettings{'NAME'}
|
||||
<td align='center'>$outfwsettings{'DISPLAY_STATE'}
|
||||
<td align='center'>$outfwsettings{'LOG'}
|
||||
<td align='center'>
|
||||
<table border='0' cellpadding='0' cellspacing='0'><tr>
|
||||
<td><form method='post' action='$ENV{'SCRIPT_NAME'}'>
|
||||
<input type='hidden' name='PROT' value='$outfwsettings{'PROT'}' />
|
||||
<input type='hidden' name='STATE' value='$outfwsettings{'STATE'}' />
|
||||
<input type='hidden' name='SNET' value='$outfwsettings{'SNET'}' />
|
||||
<input type='hidden' name='DPORT' value='$outfwsettings{'DPORT'}' />
|
||||
<input type='hidden' name='DIP' value='$outfwsettings{'DIP'}' />
|
||||
<input type='hidden' name='SIP' value='$outfwsettings{'SIP'}' />
|
||||
<input type='hidden' name='NAME' value='$outfwsettings{'NAME'}' />
|
||||
<input type='hidden' name='SMAC' value='$outfwsettings{'SMAC'}' />
|
||||
<input type='hidden' name='ENABLED' value='$outfwsettings{'ENABLED'}' />
|
||||
<input type='hidden' name='LOG' value='$outfwsettings{'LOG'}' />
|
||||
<input type='hidden' name='TIME_MON' value='$outfwsettings{'TIME_MON'}' />
|
||||
<input type='hidden' name='TIME_TUE' value='$outfwsettings{'TIME_TUE'}' />
|
||||
<input type='hidden' name='TIME_WED' value='$outfwsettings{'TIME_WED'}' />
|
||||
<input type='hidden' name='TIME_THU' value='$outfwsettings{'TIME_THU'}' />
|
||||
<input type='hidden' name='TIME_FRI' value='$outfwsettings{'TIME_FRI'}' />
|
||||
<input type='hidden' name='TIME_SAT' value='$outfwsettings{'TIME_SAT'}' />
|
||||
<input type='hidden' name='TIME_SUN' value='$outfwsettings{'TIME_SUN'}' />
|
||||
<input type='hidden' name='TIME_FROM' value='$outfwsettings{'TIME_FROM'}' />
|
||||
<input type='hidden' name='TIME_TO' value='$outfwsettings{'TIME_TO'}' />
|
||||
<input type='hidden' name='ACTION' value=$Lang::tr{'edit'} />
|
||||
<input type='image' src='/images/edit.gif' width="20" height="20" alt=$Lang::tr{'edit'} />
|
||||
</form>
|
||||
<td><form method='post' action='$ENV{'SCRIPT_NAME'}'>
|
||||
<input type='hidden' name='PROT' value='$outfwsettings{'PROT'}' />
|
||||
<input type='hidden' name='STATE' value='$outfwsettings{'STATE'}' />
|
||||
<input type='hidden' name='SNET' value='$outfwsettings{'SNET'}' />
|
||||
<input type='hidden' name='DPORT' value='$outfwsettings{'DPORT'}' />
|
||||
<input type='hidden' name='DIP' value='$outfwsettings{'DIP'}' />
|
||||
<input type='hidden' name='SIP' value='$outfwsettings{'SIP'}' />
|
||||
<input type='hidden' name='NAME' value='$outfwsettings{'NAME'}' />
|
||||
<input type='hidden' name='SMAC' value='$outfwsettings{'SMAC'}' />
|
||||
<input type='hidden' name='ENABLED' value='$outfwsettings{'ENABLED'}' />
|
||||
<input type='hidden' name='LOG' value='$outfwsettings{'LOG'}' />
|
||||
<input type='hidden' name='TIME_MON' value='$outfwsettings{'TIME_MON'}' />
|
||||
<input type='hidden' name='TIME_TUE' value='$outfwsettings{'TIME_TUE'}' />
|
||||
<input type='hidden' name='TIME_WED' value='$outfwsettings{'TIME_WED'}' />
|
||||
<input type='hidden' name='TIME_THU' value='$outfwsettings{'TIME_THU'}' />
|
||||
<input type='hidden' name='TIME_FRI' value='$outfwsettings{'TIME_FRI'}' />
|
||||
<input type='hidden' name='TIME_SAT' value='$outfwsettings{'TIME_SAT'}' />
|
||||
<input type='hidden' name='TIME_SUN' value='$outfwsettings{'TIME_SUN'}' />
|
||||
<input type='hidden' name='TIME_FROM' value='$outfwsettings{'TIME_FROM'}' />
|
||||
<input type='hidden' name='TIME_TO' value='$outfwsettings{'TIME_TO'}' />
|
||||
<input type='hidden' name='ACTION' value=$Lang::tr{'delete'} />
|
||||
<input type='image' src='/images/delete.gif' width="20" height="20" alt=$Lang::tr{'delete'} />
|
||||
</form></table>
|
||||
END
|
||||
;
|
||||
if (($outfwsettings{'SIP'}) || ($outfwsettings{'SMAC'})) {
|
||||
|
||||
unless ($outfwsettings{'SIP'}) {
|
||||
$outfwsettings{'DISPLAY_SIP'} = 'ALL';
|
||||
} else {
|
||||
$outfwsettings{'DISPLAY_SIP'} = $outfwsettings{'SIP'};
|
||||
}
|
||||
|
||||
unless ($outfwsettings{'SMAC'}) {
|
||||
$outfwsettings{'DISPLAY_SMAC'} = 'ALL';
|
||||
print "<tr><td /><td align='left'>$Lang::tr{'source ip or net'}: </td>";
|
||||
print "<td align='left' colspan='2'>$outfwsettings{'DISPLAY_SIP'}</td>";
|
||||
} else {
|
||||
$outfwsettings{'DISPLAY_SMAC'} = $outfwsettings{'SMAC'};
|
||||
print "<tr><td /><td align='left'>$Lang::tr{'source'} $Lang::tr{'mac address'}: </td>";
|
||||
print "<td align='left' colspan='2'>$outfwsettings{'DISPLAY_SMAC'}</td>";
|
||||
}
|
||||
}
|
||||
print <<END
|
||||
<tr><td width='14%' align='right'>$Lang::tr{'time'} - </td>
|
||||
<td width='14%' align='left'>
|
||||
END
|
||||
;
|
||||
if ($outfwsettings{'TIME_MON'} eq 'on') { print "<font color='$Header::colourgreen'>";}
|
||||
else { print "<font color='$Header::colourred'>";}
|
||||
print "$Lang::tr{'advproxy monday'}</font>,";
|
||||
if ($outfwsettings{'TIME_TUE'} eq 'on') { print "<font color='$Header::colourgreen'>";}
|
||||
else { print "<font color='$Header::colourred'>";}
|
||||
print "$Lang::tr{'advproxy tuesday'}</font>,";
|
||||
if ($outfwsettings{'TIME_WED'} eq 'on') { print "<font color='$Header::colourgreen'>";}
|
||||
else { print "<font color='$Header::colourred'>";}
|
||||
print "$Lang::tr{'advproxy wednesday'}</font>,";
|
||||
if ($outfwsettings{'TIME_THU'} eq 'on') { print "<font color='$Header::colourgreen'>";}
|
||||
else { print "<font color='$Header::colourred'>";}
|
||||
print "$Lang::tr{'advproxy thursday'}</font>,";
|
||||
if ($outfwsettings{'TIME_FRI'} eq 'on') { print "<font color='$Header::colourgreen'>";}
|
||||
else { print "<font color='$Header::colourred'>";}
|
||||
print "$Lang::tr{'advproxy friday'}</font>,";
|
||||
if ($outfwsettings{'TIME_SAT'} eq 'on') { print "<font color='$Header::colourgreen'>";}
|
||||
else { print "<font color='$Header::colourred'>";}
|
||||
print "$Lang::tr{'advproxy saturday'}</font>,";
|
||||
if ($outfwsettings{'TIME_SUN'} eq 'on') { print "<font color='$Header::colourgreen'>";}
|
||||
else { print "<font color='$Header::colourred'>";}
|
||||
print "$Lang::tr{'advproxy sunday'}</font>";
|
||||
print <<END
|
||||
</td>
|
||||
<td width='22%' align='center'>$Lang::tr{'advproxy from'} $outfwsettings{'TIME_FROM'}</td>
|
||||
<td width='22%' align='center'>$Lang::tr{'advproxy to'} $outfwsettings{'TIME_TO'}</td>
|
||||
</form>
|
||||
END
|
||||
;
|
||||
}
|
||||
}
|
||||
if ($outfwsettings{'POLICY'} eq 'MODE1'){
|
||||
print <<END
|
||||
<tr bgcolor='$color{'color20'}'><form method='post' action='$ENV{'SCRIPT_NAME'}'>
|
||||
<td align='center'>all
|
||||
<td align='center'>all
|
||||
<td align='center'>ALL
|
||||
<td align='center'>drop
|
||||
<td align='center'><img src='/images/stock_stop.png' alt='DENY' />
|
||||
<td align='center'>on <input type='radio' name='MODE1LOG' value='on' $checked{'MODE1LOG'}{'on'} /><input type='radio' name='MODE1LOG' value='off' $checked{'MODE1LOG'}{'off'} /> off
|
||||
<td align='center'><input type='hidden' name='ACTION' value=$Lang::tr{'save'} /><input type='image' src='/images/media-floppy.png' width="18" height="18" alt=$Lang::tr{'save'} /></form></tr>
|
||||
<table border='0' cellpadding='0' cellspacing='0'><tr>
|
||||
<td>
|
||||
<td></table>
|
||||
END
|
||||
;
|
||||
}
|
||||
print <<END
|
||||
</table>
|
||||
END
|
||||
;
|
||||
|
||||
}
|
||||
&Header::closebox();
|
||||
}
|
||||
|
||||
if ($outfwsettings{'POLICY'} ne 'MODE0'){
|
||||
open( FILE, "< $p2pfile" ) or die "Unable to read $p2pfile";
|
||||
@p2ps = <FILE>;
|
||||
close FILE;
|
||||
&Header::openbox('100%', 'center', 'P2P-Block');
|
||||
print <<END
|
||||
<table width='40%'>
|
||||
<tr bgcolor='$color{'color22'}'><td width='66%' align=center><b>$Lang::tr{'protocol'}</b>
|
||||
<td width='33%' align=center><b>$Lang::tr{'status'}</b>
|
||||
END
|
||||
;
|
||||
my $id = 1;
|
||||
foreach $p2pentry (sort @p2ps)
|
||||
{
|
||||
@p2pline = split( /\;/, $p2pentry );
|
||||
print <<END
|
||||
<form method='post' action='$ENV{'SCRIPT_NAME'}'>
|
||||
END
|
||||
;
|
||||
print "\t\t\t<tr bgcolor='$color{'color20'}'>\n";
|
||||
print <<END
|
||||
<td width='66%' align='center'>$p2pline[0]:
|
||||
<td width='33%' align='center'><input type='hidden' name='P2PROT' value='$p2pline[1]' />
|
||||
END
|
||||
;
|
||||
if ($p2pline[2] eq 'on') {
|
||||
print <<END
|
||||
<input type='hidden' name='ACTION' value='disable' />
|
||||
<input type='image' name='submit' src='/images/stock_ok.png' alt='$Lang::tr{'outgoing firewall p2p allow'}' title='$Lang::tr{'outgoing firewall p2p allow'}'/>
|
||||
END
|
||||
;
|
||||
} else {
|
||||
print <<END
|
||||
<input type='hidden' name='ACTION' value='enable' />
|
||||
<input type='image' name='submit' src='/images/stock_stop.png' alt='$Lang::tr{'outgoing firewall p2p deny'}' title='$Lang::tr{'outgoing firewall p2p deny'}' />
|
||||
END
|
||||
;
|
||||
}
|
||||
print <<END
|
||||
</form>
|
||||
END
|
||||
;
|
||||
}
|
||||
print <<END
|
||||
</table>
|
||||
<br />$Lang::tr{'outgoing firewall p2p description 1'} <img src='/images/stock_ok.png' align='absmiddle' alt='$Lang::tr{'outgoing firewall p2p deny'}'> $Lang::tr{'outgoing firewall p2p description 2'} <img src='/images/stock_stop.png' align='absmiddle' alt='$Lang::tr{'outgoing firewall p2p deny'}'> $Lang::tr{'outgoing firewall p2p description 3'}
|
||||
END
|
||||
;
|
||||
&Header::closebox();
|
||||
}
|
||||
|
||||
&Header::openbox('100%', 'center', 'Policy');
|
||||
print <<END
|
||||
<form method='post' action='$ENV{'SCRIPT_NAME'}'>
|
||||
<table width='100%'>
|
||||
<tr><td width='10%' align='left'><b>$Lang::tr{'mode'} 0:</b><td width='90%' align='left' colspan='2'>$Lang::tr{'outgoing firewall mode0'}</td></tr>
|
||||
<tr><td width='10%' align='left'><b>$Lang::tr{'mode'} 1:</b><td width='90%' align='left' colspan='2'>$Lang::tr{'outgoing firewall mode1'}</td></tr>
|
||||
<tr><td width='10%' align='left'><b>$Lang::tr{'mode'} 2:</b><td width='90%' align='left' colspan='2'>$Lang::tr{'outgoing firewall mode2'}</td></tr>
|
||||
<tr><td colspan='3'><hr /></td></tr>
|
||||
<tr><td width='10%' align='left'> <select name='POLICY' style="width: 85px"><option value='MODE0' $selected{'POLICY'}{'MODE0'}>$Lang::tr{'mode'} 0</option><option value='MODE1' $selected{'POLICY'}{'MODE1'}>$Lang::tr{'mode'} 1</option><option value='MODE2' $selected{'POLICY'}{'MODE2'}>$Lang::tr{'mode'} 2</option></select>
|
||||
<td width='45%' align='left'><input type='submit' name='ACTION' value=$Lang::tr{'save'} />
|
||||
<td width='45%' align='left'>
|
||||
END
|
||||
;
|
||||
if ($outfwsettings{'POLICY'} ne 'MODE0') {
|
||||
print <<END
|
||||
$Lang::tr{'outgoing firewall reset'}: <input type='submit' name='ACTION' value=$Lang::tr{'reset'} />
|
||||
END
|
||||
;
|
||||
}
|
||||
print <<END
|
||||
</table>
|
||||
</form>
|
||||
END
|
||||
;
|
||||
&Header::closebox();
|
||||
|
||||
############################################################################################################################
|
||||
############################################################################################################################
|
||||
|
||||
sub addrule
|
||||
{
|
||||
&Header::openbox('100%', 'center', $Lang::tr{'Add Rule'});
|
||||
if ($outfwsettings{'ENABLED'} eq 'on') { $selected{'ENABLED'} = 'checked'; }
|
||||
$selected{'TIME_FROM'}{$outfwsettings{'TIME_FROM'}} = "selected='selected'";
|
||||
$selected{'TIME_TO'}{$outfwsettings{'TIME_TO'}} = "selected='selected'";
|
||||
print <<END
|
||||
<form method='post' action='$ENV{'SCRIPT_NAME'}'>
|
||||
<table width='80%'>
|
||||
<tr>
|
||||
<td width='20%' align='right'>$Lang::tr{'description'}: <img src='/blob.gif' /></td>
|
||||
<td width='30%' align='left'><input type='text' name='NAME' maxlength='30' value='$outfwsettings{'NAME'}' /></td>
|
||||
<td width='20%' align='right' colspan='2'>$Lang::tr{'active'}:</td>
|
||||
<td width='30%' align='left' colspan='2'><input type='checkbox' name='ENABLED' $selected{'ENABLED'} /></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td width='20%' align='right'>$Lang::tr{'protocol'}</td>
|
||||
<td width='30%' align='left'>
|
||||
<select name='PROT'>
|
||||
<option value='all' $selected{'PROT'}{'all'}>All</option>
|
||||
<option value='tcp' $selected{'PROT'}{'tcp'}>TCP</option>
|
||||
<option value='udp' $selected{'PROT'}{'udp'}>UDP</option>
|
||||
<option value='gre' $selected{'PROT'}{'gre'}>GRE</option>
|
||||
<option value='esp' $selected{'PROT'}{'esp'}>ESP</option>
|
||||
</select>
|
||||
</td>
|
||||
<td width='20%' align='right' colspan='2'>$Lang::tr{'policy'}:</td>
|
||||
<td width='30%' align='left' colspan='2'>
|
||||
END
|
||||
;
|
||||
if ($outfwsettings{'POLICY'} eq 'MODE1'){
|
||||
print "\t\t\t\tALLOW<input type='hidden' name='STATE' value='ALLOW' />\n";
|
||||
} elsif ($outfwsettings{'POLICY'} eq 'MODE2'){
|
||||
print "\t\t\t\tDENY<input type='hidden' name='STATE' value='DENY' />\n";
|
||||
}
|
||||
print <<END
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td width='20%' align='right'>$Lang::tr{'source'}:</td>
|
||||
<td width='30%' align='left'>
|
||||
<select name='SNET'>
|
||||
<optgroup label='---'>
|
||||
<option value='all' $selected{'SNET'}{'ALL'}>$Lang::tr{'all'}</option>
|
||||
<optgroup label='$Lang::tr{'mac address'}'>
|
||||
<option value='mac' $selected{'SNET'}{'mac'}>$Lang::tr{'source'} $Lang::tr{'mac address'}</option>
|
||||
</optgroup>
|
||||
<optgroup label='$Lang::tr{'ip address'}'>
|
||||
<option value='ip' $selected{'SNET'}{'ip'}>$Lang::tr{'source ip or net'}</option>
|
||||
<option value='red' $selected{'SNET'}{'red'}>$Lang::tr{'red'} IP</option>
|
||||
</optgroup>
|
||||
<optgroup label='$Lang::tr{'alt vpn'}'>
|
||||
<option value='ovpn' $selected{'SNET'}{'ovpn'}>OpenVPN $Lang::tr{'interface'}</option>
|
||||
</optgroup>
|
||||
<optgroup label='$Lang::tr{'network'}'>
|
||||
<option value='green' $selected{'SNET'}{'green'}>$Lang::tr{'green'}</option>
|
||||
END
|
||||
;
|
||||
if (&Header::blue_used()){
|
||||
print "\t\t\t\t\t<option value='blue' $selected{'SNET'}{'blue'}>$Lang::tr{'wireless'}</option>\n";
|
||||
}
|
||||
if (&Header::orange_used()){
|
||||
print "\t\t\t\t\t<option value='orange' $selected{'SNET'}{'orange'}>$Lang::tr{'dmz'}</option>\n";
|
||||
}
|
||||
print <<END
|
||||
</optgroup>
|
||||
<optgroup label='IP $Lang::tr{'advproxy NCSA group'}'>
|
||||
END
|
||||
;
|
||||
my @ipgroups = qx(ls $configpath/ipgroups/);
|
||||
foreach (sort @ipgroups){
|
||||
chomp($_);
|
||||
print "\t\t\t\t\t<option value='$_' $selected{'SNET'}{$_}>$_</option>\n";
|
||||
}
|
||||
print <<END
|
||||
</optgroup>
|
||||
<optgroup label='MAC $Lang::tr{'advproxy NCSA group'}'>
|
||||
END
|
||||
;
|
||||
my @macgroups = qx(ls $configpath/macgroups/);
|
||||
foreach (sort @macgroups){
|
||||
chomp($_);
|
||||
print "\t\t\t\t\t<option value='$_' $selected{'SNET'}{$_}>$_</option>\n";
|
||||
}
|
||||
print <<END
|
||||
</optgroup>
|
||||
</select>
|
||||
</td>
|
||||
<td align='right' colspan='4'><font color='red'>$Lang::tr{'outgoing firewall warning'}</font></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td align='right' colspan='4' >$Lang::tr{'source ip or net'}<img src='/blob.gif' /></td>
|
||||
<td align='left' colspan='4' ><input type='text' name='SIP' value='$outfwsettings{'SIP'}' /></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td align='right' colspan='4' >$Lang::tr{'source'} $Lang::tr{'mac address'}: <img src='/blob.gif' />
|
||||
<td align='left' colspan='4' ><input type='text' name='SMAC' maxlength='23' value='$outfwsettings{'SMAC'}' />
|
||||
</tr>
|
||||
<tr>
|
||||
<td width='20%' align='right'>$Lang::tr{'logging'}:</td>
|
||||
<td width='30%' align='left'>
|
||||
<select name='LOG'>
|
||||
<option value='$Lang::tr{'active'}' $selected{'LOG'}{$Lang::tr{'active'}}>$Lang::tr{'active'}</option>
|
||||
<option value='$Lang::tr{'inactive'}' $selected{'LOG'}{$Lang::tr{'inactive'}}>$Lang::tr{'inactive'}</option>
|
||||
</select>
|
||||
</td>
|
||||
<td width='20%' align='right' colspan='2' />
|
||||
<td width='30%' align='left' colspan='2' />
|
||||
<tr>
|
||||
<td width='20%' align='right'>$Lang::tr{'destination ip or net'}: <img src='/blob.gif' /></td>
|
||||
<td width='30%' align='left'><input type='text' name='DIP' value='$outfwsettings{'DIP'}' /></td>
|
||||
<td width='20%' align='right' colspan='2'>$Lang::tr{'destination port'}(s) <img src='/blob.gif' /></td>
|
||||
<td width='30%' align='left' colspan='2'><input type='text' name='DPORT' value='$outfwsettings{'DPORT'}' /></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td width='20%' align='right'>$Lang::tr{'time'}:</td>
|
||||
<td width='30%' align='left'>$Lang::tr{'advproxy monday'} $Lang::tr{'advproxy tuesday'} $Lang::tr{'advproxy wednesday'} $Lang::tr{'advproxy thursday'} $Lang::tr{'advproxy friday'} $Lang::tr{'advproxy saturday'} $Lang::tr{'advproxy sunday'}</td>
|
||||
<td width='20%' align='right' colspan='2' />
|
||||
<td width='15%' align='left'>$Lang::tr{'advproxy from'}</td>
|
||||
<td width='15%' align='left'>$Lang::tr{'advproxy to'}</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td width='20%' align='right'></td>
|
||||
<td width='30%' align='left'>
|
||||
<input type='checkbox' name='TIME_MON' $checked{'TIME_MON'}{'on'} />
|
||||
<input type='checkbox' name='TIME_TUE' $checked{'TIME_TUE'}{'on'} />
|
||||
<input type='checkbox' name='TIME_WED' $checked{'TIME_WED'}{'on'} />
|
||||
<input type='checkbox' name='TIME_THU' $checked{'TIME_THU'}{'on'} />
|
||||
<input type='checkbox' name='TIME_FRI' $checked{'TIME_FRI'}{'on'} />
|
||||
<input type='checkbox' name='TIME_SAT' $checked{'TIME_SAT'}{'on'} />
|
||||
<input type='checkbox' name='TIME_SUN' $checked{'TIME_SUN'}{'on'} />
|
||||
</td>
|
||||
<td width='20%' align='right' colspan='2' />
|
||||
<td width='15%' align='left'>
|
||||
<select name='TIME_FROM'>
|
||||
END
|
||||
;
|
||||
for (my $i=0;$i<=23;$i++) {
|
||||
$i = sprintf("%02s",$i);
|
||||
for (my $j=0;$j<=45;$j+=15) {
|
||||
$j = sprintf("%02s",$j);
|
||||
my $time = $i.":".$j;
|
||||
print "\t\t\t\t\t<option $selected{'TIME_FROM'}{$time}>$i:$j</option>\n";
|
||||
}
|
||||
}
|
||||
print <<END
|
||||
</select>
|
||||
</td>
|
||||
<td width='15%' align='left'><select name='TIME_TO'>
|
||||
END
|
||||
;
|
||||
for (my $i=0;$i<=23;$i++) {
|
||||
$i = sprintf("%02s",$i);
|
||||
for (my $j=0;$j<=45;$j+=15) {
|
||||
$j = sprintf("%02s",$j);
|
||||
my $time = $i.":".$j;
|
||||
print "\t\t\t\t\t<option $selected{'TIME_TO'}{$time}>$i:$j</option>\n";
|
||||
}
|
||||
}
|
||||
print <<END
|
||||
</select>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td colspan='6' />
|
||||
<tr>
|
||||
<tr>
|
||||
<td width='40%' align='right' colspan='2'><img src='/blob.gif' />$Lang::tr{'this field may be blank'}</td>
|
||||
<td width='60%' align='left' colspan='4'><input type='submit' name='ACTION' value=$Lang::tr{'add'} /></td>
|
||||
</table></form>
|
||||
END
|
||||
;
|
||||
&Header::closebox();
|
||||
|
||||
if ($outfwsettings{'POLICY'} eq 'MODE1' || $outfwsettings{'POLICY'} eq 'MODE2')
|
||||
{
|
||||
&Header::openbox('100%', 'center', 'Quick Add');
|
||||
|
||||
open( FILE, "< /var/ipfire/outgoing/defaultservices" ) or die "Unable to read default services";
|
||||
my @defservices = <FILE>;
|
||||
close FILE;
|
||||
|
||||
print "<table width='100%'><tr bgcolor='$color{'color20'}'><td><b>$Lang::tr{'service'}</b></td><td><b>$Lang::tr{'description'}</b></td><td><b>$Lang::tr{'port'}</b></td><td><b>$Lang::tr{'protocol'}</b></td><td><b>$Lang::tr{'source net'}</b></td><td><b>$Lang::tr{'logging'}</b></td><td><b>$Lang::tr{'action'}</b></td></tr>";
|
||||
foreach my $serviceline(@defservices)
|
||||
{
|
||||
my @service = split(/,/,$serviceline);
|
||||
print <<END
|
||||
<tr><form method='post' action='$ENV{'SCRIPT_NAME'}'>
|
||||
<td>$service[0]<input type='hidden' name='NAME' value='@service[0]' /></td>
|
||||
<td>$service[3]</td>
|
||||
<td><a href='http://isc.sans.org/port_details.php?port=$service[1]' target='top'>$service[1]</a><input type='hidden' name='DPORT' value='@service[1]' /></td>
|
||||
<td>$service[2]<input type='hidden' name='PROT' value='@service[2]' /></td>
|
||||
<td><select name='SNET'><option value='all' $selected{'SNET'}{'ALL'}>$Lang::tr{'all'}</option><option value='green' $selected{'SNET'}{'green'}>$Lang::tr{'green'}</option>
|
||||
END
|
||||
;
|
||||
if (&Header::blue_used()){
|
||||
print "<option value='blue' $selected{'SNET'}{'blue'}>$Lang::tr{'wireless'}</option>";
|
||||
}
|
||||
if (&Header::orange_used()){
|
||||
print "<option value='orange' $selected{'SNET'}{'orange'}>$Lang::tr{'dmz'}</option>";
|
||||
}
|
||||
print <<END
|
||||
</select></td>
|
||||
<td><select name='LOG'><option value='$Lang::tr{'active'}'>$Lang::tr{'active'}</option><option value='$Lang::tr{'inactive'}' 'selected'>$Lang::tr{'inactive'}</option></select></td><td>
|
||||
<input type='hidden' name='ACTION' value=$Lang::tr{'add'} />
|
||||
<input type='image' alt='$Lang::tr{'add'}' src='/images/add.gif' />
|
||||
<input type='hidden' name='ENABLED' value='on' />
|
||||
END
|
||||
;
|
||||
if ($outfwsettings{'POLICY'} eq 'MODE1'){ print "<input type='hidden' name='STATE' value='ALLOW' /></form></td></tr>";}
|
||||
elsif ($outfwsettings{'POLICY'} eq 'MODE2'){print "<input type='hidden' name='STATE' value='DENY' /></form></td></tr>";}
|
||||
}
|
||||
print "</table>";
|
||||
&Header::closebox();
|
||||
}
|
||||
}
|
||||
|
||||
&Header::closebigbox();
|
||||
&Header::closepage();
|
||||
@@ -30,6 +30,7 @@ use File::Copy;
|
||||
use File::Temp qw/ tempfile tempdir /;
|
||||
use strict;
|
||||
use Archive::Zip qw(:ERROR_CODES :CONSTANTS);
|
||||
use Sort::Naturally;
|
||||
require '/var/ipfire/general-functions.pl';
|
||||
require "${General::swroot}/lang.pl";
|
||||
require "${General::swroot}/header.pl";
|
||||
@@ -165,49 +166,29 @@ sub deletebackupcert
|
||||
unlink ("${General::swroot}/ovpn/certs/$hexvalue.pem");
|
||||
}
|
||||
}
|
||||
|
||||
sub checkportfw {
|
||||
my $KEY2 = $_[0]; # key2
|
||||
my $SRC_PORT = $_[1]; # src_port
|
||||
my $PROTOCOL = $_[2]; # protocol
|
||||
my $SRC_IP = $_[3]; # sourceip
|
||||
|
||||
my $pfwfilename = "${General::swroot}/portfw/config";
|
||||
open(FILE, $pfwfilename) or die 'Unable to open config file.';
|
||||
my @pfwcurrent = <FILE>;
|
||||
close(FILE);
|
||||
my $pfwkey1 = 0; # used for finding last sequence number used
|
||||
foreach my $pfwline (@pfwcurrent)
|
||||
{
|
||||
my @pfwtemp = split(/\,/,$pfwline);
|
||||
|
||||
chomp ($pfwtemp[8]);
|
||||
if ($KEY2 eq "0"){ # if key2 is 0 then it is a portfw addition
|
||||
if ( $SRC_PORT eq $pfwtemp[3] &&
|
||||
$PROTOCOL eq $pfwtemp[2] &&
|
||||
$SRC_IP eq $pfwtemp[7])
|
||||
{
|
||||
$errormessage = "$Lang::tr{'source port in use'} $SRC_PORT";
|
||||
}
|
||||
# Check if key2 = 0, if it is then it is a port forward entry and we want the sequence number
|
||||
if ( $pfwtemp[1] eq "0") {
|
||||
$pfwkey1=$pfwtemp[0];
|
||||
}
|
||||
# Darren Critchley - Duplicate or overlapping Port range check
|
||||
if ($pfwtemp[1] eq "0" &&
|
||||
$PROTOCOL eq $pfwtemp[2] &&
|
||||
$SRC_IP eq $pfwtemp[7] &&
|
||||
$errormessage eq '')
|
||||
{
|
||||
&portchecks($SRC_PORT, $pfwtemp[5]);
|
||||
# &portchecks($pfwtemp[3], $pfwtemp[5]);
|
||||
# &portchecks($pfwtemp[3], $SRC_IP);
|
||||
my $DPORT = shift;
|
||||
my $DPROT = shift;
|
||||
my %natconfig =();
|
||||
my $confignat = "${General::swroot}/forward/config";
|
||||
$DPROT= uc ($DPROT);
|
||||
&General::readhasharray($confignat, \%natconfig);
|
||||
foreach my $key (sort keys %natconfig){
|
||||
my @portarray = split (/\|/,$natconfig{$key}[30]);
|
||||
foreach my $value (@portarray){
|
||||
if ($value =~ /:/i){
|
||||
my ($a,$b) = split (":",$value);
|
||||
if ($DPROT eq $natconfig{$key}[12] && $DPORT gt $a && $DPORT lt $b){
|
||||
$errormessage= "$Lang::tr{'source port in use'} $DPORT";
|
||||
}
|
||||
}else{
|
||||
if ($DPROT eq $natconfig{$key}[12] && $DPORT eq $value){
|
||||
$errormessage= "$Lang::tr{'source port in use'} $DPORT";
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
# $errormessage="$KEY2 $SRC_PORT $PROTOCOL $SRC_IP";
|
||||
|
||||
return;
|
||||
return;
|
||||
}
|
||||
|
||||
sub checkportoverlap
|
||||
@@ -239,32 +220,6 @@ sub checkportinc
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
# Darren Critchley - Duplicate or overlapping Port range check
|
||||
sub portchecks
|
||||
{
|
||||
my $p1 = $_[0]; # New port range
|
||||
my $p2 = $_[1]; # existing port range
|
||||
# $_ = $_[0];
|
||||
our ($prtrange1, $prtrange2);
|
||||
$prtrange1 = 0;
|
||||
# if (m/:/ && $prtrange1 == 1) { # comparing two port ranges
|
||||
# unless (&checkportoverlap($p1,$p2)) {
|
||||
# $errormessage = "$Lang::tr{'source port overlaps'} $p1";
|
||||
# }
|
||||
# }
|
||||
if (m/:/ && $prtrange1 == 0 && $errormessage eq '') { # compare one port to a range
|
||||
unless (&checkportinc($p2,$p1)) {
|
||||
$errormessage = "$Lang::tr{'srcprt within existing'} $p1";
|
||||
}
|
||||
}
|
||||
$prtrange1 = 1;
|
||||
if (! m/:/ && $prtrange1 == 1 && $errormessage eq '') { # compare one port to a range
|
||||
unless (&checkportinc($p1,$p2)) {
|
||||
$errormessage = "$Lang::tr{'srcprt range overlaps'} $p2";
|
||||
}
|
||||
}
|
||||
return;
|
||||
}
|
||||
|
||||
# Darren Critchley - certain ports are reserved for IPFire
|
||||
# TCP 67,68,81,222,445
|
||||
@@ -1144,7 +1099,7 @@ if ($cgiparams{'ACTION'} eq $Lang::tr{'save'} && $cgiparams{'TYPE'} eq '' && $cg
|
||||
|
||||
|
||||
if ($cgiparams{'ENABLED'} eq 'on'){
|
||||
&checkportfw(0,$cgiparams{'DDEST_PORT'},$cgiparams{'DPROTOCOL'},'0.0.0.0');
|
||||
&checkportfw($cgiparams{'DDEST_PORT'},$cgiparams{'DPROTOCOL'});
|
||||
}
|
||||
|
||||
if ($errormessage) { goto SETTINGS_ERROR; }
|
||||
@@ -4895,11 +4850,10 @@ END
|
||||
</tr>
|
||||
END
|
||||
;
|
||||
my $id = 0;
|
||||
my $gif;
|
||||
foreach my $key (sort { uc($confighash{$a}[1]) cmp uc($confighash{$b}[1]) } keys %confighash) {
|
||||
if ($confighash{$key}[0] eq 'on') { $gif = 'on.gif'; } else { $gif = 'off.gif'; }
|
||||
|
||||
my $id = 0;
|
||||
my $gif;
|
||||
foreach my $key (sort { ncmp ($confighash{$a}[1],$confighash{$b}[1]) } keys %confighash) {
|
||||
if ($confighash{$key}[0] eq 'on') { $gif = 'on.gif'; } else { $gif = 'off.gif'; }
|
||||
if ($id % 2) {
|
||||
print "<tr bgcolor='$color{'color20'}'>\n";
|
||||
} else {
|
||||
|
||||
134
html/cgi-bin/p2p-block.cgi
Executable file
134
html/cgi-bin/p2p-block.cgi
Executable file
@@ -0,0 +1,134 @@
|
||||
#!/usr/bin/perl
|
||||
###############################################################################
|
||||
# #
|
||||
# IPFire.org - A linux based firewall #
|
||||
# Copyright (C) 2013 #
|
||||
# #
|
||||
# This program is free software: you can redistribute it and/or modify #
|
||||
# it under the terms of the GNU General Public License as published by #
|
||||
# the Free Software Foundation, either version 3 of the License, or #
|
||||
# (at your option) any later version. #
|
||||
# #
|
||||
# This program is distributed in the hope that it will be useful, #
|
||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of #
|
||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
|
||||
# GNU General Public License for more details. #
|
||||
# #
|
||||
# You should have received a copy of the GNU General Public License #
|
||||
# along with this program. If not, see <http://www.gnu.org/licenses/>. #
|
||||
# #
|
||||
###############################################################################
|
||||
# Author: Alexander Marx (Amarx@ipfire.org) #
|
||||
###############################################################################
|
||||
|
||||
use strict;
|
||||
no warnings 'uninitialized';
|
||||
# enable only the following on debugging purpose
|
||||
#use warnings;
|
||||
#use CGI::Carp 'fatalsToBrowser';
|
||||
|
||||
require '/var/ipfire/general-functions.pl';
|
||||
require "${General::swroot}/lang.pl";
|
||||
require "${General::swroot}/header.pl";
|
||||
|
||||
my $errormessage='';
|
||||
my $p2pfile = "${General::swroot}/forward/p2protocols";
|
||||
|
||||
my @p2ps = ();
|
||||
my %fwdfwsettings=();
|
||||
my %color=();
|
||||
my %mainsettings=();
|
||||
|
||||
&General::readhash("${General::swroot}/forward/settings", \%fwdfwsettings);
|
||||
&General::readhash("${General::swroot}/main/settings", \%mainsettings);
|
||||
&General::readhash("/srv/web/ipfire/html/themes/".$mainsettings{'THEME'}."/include/colors.txt", \%color);
|
||||
|
||||
|
||||
|
||||
&Header::showhttpheaders();
|
||||
&Header::getcgihash(\%fwdfwsettings);
|
||||
&Header::openpage($Lang::tr{'fwdfw menu'}, 1, '');
|
||||
&Header::openbigbox('100%', 'center',$errormessage);
|
||||
|
||||
if ($fwdfwsettings{'ACTION'} eq ''){
|
||||
&p2pblock;
|
||||
}
|
||||
if ($fwdfwsettings{'ACTION'} eq 'togglep2p')
|
||||
{
|
||||
open( FILE, "< $p2pfile" ) or die "Unable to read $p2pfile";
|
||||
@p2ps = <FILE>;
|
||||
close FILE;
|
||||
open( FILE, "> $p2pfile" ) or die "Unable to write $p2pfile";
|
||||
foreach my $p2pentry (sort @p2ps)
|
||||
{
|
||||
my @p2pline = split( /\;/, $p2pentry );
|
||||
if ($p2pline[1] eq $fwdfwsettings{'P2PROT'}) {
|
||||
if($p2pline[2] eq 'on'){
|
||||
$p2pline[2]='off';
|
||||
}else{
|
||||
$p2pline[2]='on';
|
||||
}
|
||||
}
|
||||
print FILE "$p2pline[0];$p2pline[1];$p2pline[2];\n";
|
||||
}
|
||||
close FILE;
|
||||
&rules;
|
||||
&p2pblock;
|
||||
}
|
||||
if ($fwdfwsettings{'ACTION'} eq $Lang::tr{'fwdfw reread'})
|
||||
{
|
||||
&reread_rules;
|
||||
&p2pblock;
|
||||
}
|
||||
|
||||
|
||||
sub p2pblock
|
||||
{
|
||||
if (-f "${General::swroot}/forward/reread"){
|
||||
print "<table border='1' rules='groups' bgcolor='lightgreen' width='100%'><form method='post'><td><div style='font-size:11pt; font-weight: bold;vertical-align: middle; '><input type='submit' name='ACTION' value='$Lang::tr{'fwdfw reread'}' style='font-face: Comic Sans MS; color: green; font-weight: bold; font-size: 14pt;'>    $Lang::tr{'fwhost reread'}</div></td></tr></table></form><br>";
|
||||
}
|
||||
my $gif;
|
||||
open( FILE, "< $p2pfile" ) or die "Unable to read $p2pfile";
|
||||
@p2ps = <FILE>;
|
||||
close FILE;
|
||||
&Header::openbox('100%', 'center', 'P2P-Block');
|
||||
print <<END;
|
||||
<table width='35%' border='0'>
|
||||
<tr bgcolor='$color{'color22'}'><td align=center colspan='2' ><b>$Lang::tr{'protocol'}</b></td><td align='center'><b>$Lang::tr{'status'}</b></td></tr>
|
||||
END
|
||||
foreach my $p2pentry (sort @p2ps)
|
||||
{
|
||||
my @p2pline = split( /\;/, $p2pentry );
|
||||
if($p2pline[2] eq 'on'){
|
||||
$gif="/images/on.gif"
|
||||
}else{
|
||||
$gif="/images/off.gif"
|
||||
}
|
||||
print <<END;
|
||||
<form method='post' action='$ENV{'SCRIPT_NAME'}'>
|
||||
<tr bgcolor='$color{'color20'}'>
|
||||
<td align='center' colspan='2' >$p2pline[0]:</td><td align='center'><input type='hidden' name='P2PROT' value='$p2pline[1]' /><input type='image' img src='$gif' alt='$Lang::tr{'click to disable'}' title='$Lang::tr{'fwdfw toggle'}' style='padding-top: 0px; padding-left: 0px; padding-bottom: 0px ;padding-right: 0px ;display: block;' ><input type='hidden' name='ACTION' value='togglep2p'></td></tr></form>
|
||||
END
|
||||
}
|
||||
print"<tr><td><img src='/images/on.gif'></td><td align='left'>$Lang::tr{'outgoing firewall p2p allow'}</td></tr>";
|
||||
print"<tr><td><img src='/images/off.gif'></td><td align='left'>$Lang::tr{'outgoing firewall p2p deny'}</td></tr></table>";
|
||||
print"<br><br><br><table width='100%'><tr><td align='left'>$Lang::tr{'fwdfw p2p txt'}</td></tr></table>";
|
||||
&Header::closebox();
|
||||
}
|
||||
sub rules
|
||||
{
|
||||
if (!-f "${General::swroot}/forward/reread"){
|
||||
system("touch ${General::swroot}/forward/reread");
|
||||
system("touch ${General::swroot}/fwhosts/reread");
|
||||
}
|
||||
}
|
||||
sub reread_rules
|
||||
{
|
||||
system("/usr/local/bin/forwardfwctrl");
|
||||
if ( -f "${General::swroot}/forward/reread"){
|
||||
system("rm ${General::swroot}/forward/reread");
|
||||
system("rm ${General::swroot}/fwhosts/reread");
|
||||
}
|
||||
}
|
||||
&Header::closebigbox();
|
||||
&Header::closepage();
|
||||
File diff suppressed because it is too large
Load Diff
@@ -82,7 +82,7 @@ if ($upnpsettings{'ACTION'} eq $Lang::tr{'save'})
|
||||
debug_mode = $upnpsettings{'DEBUGMODE'}
|
||||
insert_forward_rules = $upnpsettings{'FORWARDRULES'}
|
||||
forward_chain_name = FORWARD
|
||||
prerouting_chain_name = PORTFW
|
||||
prerouting_chain_name = UPNPFW
|
||||
upstream_bitrate = $upnpsettings{'DOWNSTREAM'}
|
||||
downstream_bitrate = $upnpsettings{'UPSTREAM'}
|
||||
description_document_name = $upnpsettings{'DESCRIPTION'}
|
||||
|
||||
@@ -23,7 +23,7 @@ use Net::DNS;
|
||||
use File::Copy;
|
||||
use File::Temp qw/ tempfile tempdir /;
|
||||
use strict;
|
||||
|
||||
use Sort::Naturally;
|
||||
# enable only the following on debugging purpose
|
||||
#use warnings;
|
||||
#use CGI::Carp 'fatalsToBrowser';
|
||||
@@ -2491,7 +2491,7 @@ END
|
||||
;
|
||||
my $id = 0;
|
||||
my $gif;
|
||||
foreach my $key (keys %confighash) {
|
||||
foreach my $key (sort { ncmp ($confighash{$a}[1],$confighash{$b}[1]) } keys %confighash) {
|
||||
if ($confighash{$key}[0] eq 'on') { $gif = 'on.gif'; } else { $gif = 'off.gif'; }
|
||||
|
||||
if ($id % 2) {
|
||||
|
||||
Reference in New Issue
Block a user