2008-12-07 19:17:26 +01:00
|
|
|
#!/bin/sh
|
|
|
|
#
|
2009-02-22 17:54:19 +01:00
|
|
|
# Shorewall Packet Filtering Firewall Control Program - V4.4
|
2008-12-07 19:17:26 +01:00
|
|
|
#
|
|
|
|
# This program is under GPL [http://www.gnu.org/licenses/old-licenses/gpl-2.0.txt]
|
|
|
|
#
|
2011-05-23 18:51:51 +02:00
|
|
|
# (c) 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010,2011 -
|
|
|
|
# Tom Eastep (teastep@shorewall.net)
|
2008-12-07 19:17:26 +01:00
|
|
|
#
|
|
|
|
# This file should be placed in /sbin/shorewall.
|
|
|
|
#
|
|
|
|
# Shorewall documentation is available at http://www.shorewall.net
|
|
|
|
#
|
|
|
|
# This program is free software; you can redistribute it and/or modify
|
|
|
|
# it under the terms of Version 2 of the GNU General Public License
|
|
|
|
# as published by the Free Software Foundation.
|
|
|
|
#
|
|
|
|
# This program is distributed in the hope that it will be useful,
|
|
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
# GNU General Public License for more details.
|
|
|
|
#
|
|
|
|
# You should have received a copy of the GNU General Public License
|
|
|
|
# along with this program; if not, write to the Free Software
|
|
|
|
# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
|
|
|
#
|
2011-12-03 19:59:01 +01:00
|
|
|
# For a list of supported commands, type 'shorewall help' or 'shorewall6 help'
|
2008-12-07 19:17:26 +01:00
|
|
|
#
|
2011-05-23 23:36:21 +02:00
|
|
|
################################################################################################
|
2008-12-07 19:17:26 +01:00
|
|
|
#
|
2011-12-03 19:59:01 +01:00
|
|
|
# Set the configuration variables from the .conf file
|
2008-12-07 19:17:26 +01:00
|
|
|
#
|
|
|
|
# $1 = Yes: read the params file
|
|
|
|
# $2 = Yes: check for STARTUP_ENABLED
|
|
|
|
# $3 = Yes: Check for LOGFILE
|
2010-06-07 18:16:56 +02:00
|
|
|
#
|
2008-12-07 19:17:26 +01:00
|
|
|
|
|
|
|
#
|
|
|
|
# Execution begins here
|
|
|
|
#
|
2010-02-23 01:43:38 +01:00
|
|
|
g_debugging=
|
2008-12-07 19:17:26 +01:00
|
|
|
|
|
|
|
if [ $# -gt 0 ] && [ "x$1" = "xdebug" -o "x$1" = "xtrace" ]; then
|
2010-02-23 01:43:38 +01:00
|
|
|
g_debugging=$1
|
2008-12-07 19:17:26 +01:00
|
|
|
shift
|
|
|
|
fi
|
|
|
|
|
|
|
|
nolock=
|
|
|
|
|
|
|
|
if [ $# -gt 0 ] && [ "$1" = "nolock" ]; then
|
|
|
|
nolock=nolock
|
|
|
|
shift
|
|
|
|
fi
|
|
|
|
|
|
|
|
SHOREWALL_DIR=
|
2010-03-03 18:50:07 +01:00
|
|
|
g_noroutes=
|
|
|
|
g_purge=
|
2010-02-22 17:05:23 +01:00
|
|
|
|
|
|
|
g_ipt_options="-nv"
|
|
|
|
g_fast=
|
|
|
|
g_verbose_offset=0
|
|
|
|
g_use_verbosity=
|
|
|
|
g_debug=
|
|
|
|
g_export=
|
2011-05-16 22:08:32 +02:00
|
|
|
g_refreshchains=:none:
|
2011-05-24 19:21:49 +02:00
|
|
|
g_confess=
|
2011-06-19 16:14:27 +02:00
|
|
|
g_update=
|
2011-11-08 21:59:40 +01:00
|
|
|
g_convert=
|
2011-06-18 22:03:55 +02:00
|
|
|
g_annotate=
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2010-10-29 00:17:37 +02:00
|
|
|
#
|
|
|
|
# Make sure that these variables are cleared
|
|
|
|
#
|
|
|
|
VERBOSE=
|
|
|
|
VERBOSITY=
|
|
|
|
|
2011-12-03 22:13:25 +01:00
|
|
|
g_program=$(basename $0)
|
|
|
|
|
|
|
|
if [ $g_program = shorewall6 ]; then
|
|
|
|
SHAREDIR=/usr/share/shorewall6
|
|
|
|
CONFDIR=/etc/shorewall6
|
|
|
|
g_product="Shorewall6"
|
|
|
|
g_family=6
|
|
|
|
g_tool=
|
2011-12-04 18:19:48 +01:00
|
|
|
g_basedir=/usr/share/shorewall
|
2011-12-06 21:54:51 +01:00
|
|
|
g_lite=
|
|
|
|
elif [ $g_program = shorewall6-lite ]; then
|
|
|
|
SHAREDIR=/usr/share/shorewall6-lite
|
|
|
|
CONFDIR=/etc/shorewall6-lite
|
|
|
|
g_product="Shorewall6 Lite"
|
|
|
|
g_family=6
|
|
|
|
g_base=shorewall6
|
|
|
|
g_tool=ip6tables
|
|
|
|
g_basedir=/usr/share/shorewall6-lite
|
|
|
|
g_lite=Yes
|
|
|
|
elif [ $g_program = shorewall-lite ]; then
|
|
|
|
SHAREDIR=/usr/share/shorewall-lite
|
|
|
|
CONFDIR=/etc/shorewall-lite
|
|
|
|
g_product="Shorewall Lite"
|
|
|
|
g_family=4
|
|
|
|
g_base=shorewall
|
|
|
|
g_tool=iptables
|
|
|
|
g_basedir=/usr/share/shorewall-lite
|
|
|
|
g_lite=Yes
|
2011-12-03 22:13:25 +01:00
|
|
|
else
|
|
|
|
g_program=shorewall
|
|
|
|
SHAREDIR=/usr/share/shorewall
|
|
|
|
CONFDIR=/etc/shorewall
|
|
|
|
g_product="Shorewall"
|
|
|
|
g_family=4
|
2011-12-04 18:19:48 +01:00
|
|
|
g_tool=
|
|
|
|
g_basedir=/usr/share/shorewall
|
2011-12-06 21:54:51 +01:00
|
|
|
g_lite=
|
2011-12-03 22:13:25 +01:00
|
|
|
fi
|
|
|
|
|
2008-12-07 19:17:26 +01:00
|
|
|
finished=0
|
|
|
|
|
|
|
|
while [ $finished -eq 0 ]; do
|
|
|
|
[ $# -eq 0 ] && usage 1
|
|
|
|
option=$1
|
|
|
|
case $option in
|
|
|
|
-)
|
|
|
|
finished=1
|
|
|
|
;;
|
|
|
|
-*)
|
|
|
|
option=${option#-}
|
|
|
|
|
|
|
|
while [ -n "$option" ]; do
|
|
|
|
case $option in
|
|
|
|
c)
|
2011-12-06 21:54:51 +01:00
|
|
|
[ $# -eq 1 -o -n "$g_lite" ] && usage 1
|
2008-12-07 19:17:26 +01:00
|
|
|
|
|
|
|
if [ ! -d $2 ]; then
|
|
|
|
if [ -e $2 ]; then
|
|
|
|
echo "$2 is not a directory" >&2 && exit 2
|
|
|
|
else
|
|
|
|
echo "Directory $2 does not exist" >&2 && exit 2
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
|
|
|
|
SHOREWALL_DIR=$(resolve_file $2)
|
|
|
|
option=
|
|
|
|
shift
|
|
|
|
;;
|
|
|
|
e*)
|
2011-12-06 21:54:51 +01:00
|
|
|
[ -n "$g_lite" ] && usage 1
|
2010-02-22 17:05:23 +01:00
|
|
|
g_export=Yes
|
2008-12-07 19:17:26 +01:00
|
|
|
option=${option#e}
|
|
|
|
;;
|
|
|
|
x*)
|
2010-02-22 17:05:23 +01:00
|
|
|
g_ipt_options="-xnv"
|
2008-12-07 19:17:26 +01:00
|
|
|
option=${option#x}
|
|
|
|
;;
|
|
|
|
q*)
|
2010-02-22 17:05:23 +01:00
|
|
|
g_verbose_offset=$(($g_verbose_offset - 1 ))
|
2008-12-07 19:17:26 +01:00
|
|
|
option=${option#q}
|
|
|
|
;;
|
|
|
|
f*)
|
2010-02-22 17:05:23 +01:00
|
|
|
g_fast=Yes
|
2008-12-07 19:17:26 +01:00
|
|
|
option=${option#f}
|
|
|
|
;;
|
|
|
|
v*)
|
|
|
|
option=${option#v}
|
2010-06-07 18:16:56 +02:00
|
|
|
case $option in
|
2008-12-07 19:17:26 +01:00
|
|
|
-1*)
|
2010-02-22 17:05:23 +01:00
|
|
|
g_use_verbosity=-1
|
2008-12-07 19:17:26 +01:00
|
|
|
option=${option#-1}
|
|
|
|
;;
|
|
|
|
0*)
|
2010-02-22 17:05:23 +01:00
|
|
|
g_use_verbosity=0
|
2008-12-07 19:17:26 +01:00
|
|
|
option=${option#0}
|
|
|
|
;;
|
|
|
|
1*)
|
2010-02-22 17:05:23 +01:00
|
|
|
g_use_verbosity=1
|
2008-12-07 19:17:26 +01:00
|
|
|
option=${option#1}
|
|
|
|
;;
|
|
|
|
2*)
|
2010-02-22 17:05:23 +01:00
|
|
|
g_use_verbosity=2
|
2008-12-07 19:17:26 +01:00
|
|
|
option=${option#2}
|
|
|
|
;;
|
|
|
|
*)
|
2010-02-22 17:05:23 +01:00
|
|
|
g_verbose_offset=$(($g_verbose_offset + 1 ))
|
|
|
|
g_use_verbosity=
|
2008-12-07 19:17:26 +01:00
|
|
|
;;
|
|
|
|
esac
|
|
|
|
;;
|
|
|
|
n*)
|
2010-03-03 18:50:07 +01:00
|
|
|
g_noroutes=Yes
|
2008-12-07 19:17:26 +01:00
|
|
|
option=${option#n}
|
|
|
|
;;
|
|
|
|
t*)
|
2010-03-03 18:50:07 +01:00
|
|
|
g_timestamp=Yes
|
2008-12-07 19:17:26 +01:00
|
|
|
option=${option#t}
|
|
|
|
;;
|
|
|
|
-)
|
|
|
|
finished=1
|
|
|
|
option=
|
|
|
|
;;
|
|
|
|
*)
|
|
|
|
usage 1
|
|
|
|
;;
|
|
|
|
esac
|
|
|
|
done
|
|
|
|
shift
|
|
|
|
;;
|
|
|
|
*)
|
|
|
|
finished=1
|
|
|
|
;;
|
|
|
|
esac
|
|
|
|
done
|
|
|
|
|
|
|
|
if [ $# -eq 0 ]; then
|
|
|
|
usage 1
|
|
|
|
fi
|
|
|
|
|
|
|
|
PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/bin:/usr/local/sbin
|
|
|
|
MUTEX_TIMEOUT=
|
|
|
|
|
2010-03-03 18:50:07 +01:00
|
|
|
g_recovering=
|
|
|
|
g_timestamp=
|
2011-05-12 16:42:09 +02:00
|
|
|
g_libexec=/usr/share
|
|
|
|
g_perllib=/usr/share/shorewall
|
2008-12-07 19:17:26 +01:00
|
|
|
|
|
|
|
[ -f ${CONFDIR}/vardir ] && . ${CONFDIR}/vardir
|
|
|
|
|
2011-12-03 19:59:01 +01:00
|
|
|
[ -n "${VARDIR:=/var/lib/$g_program}" ]
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2009-03-01 20:46:30 +01:00
|
|
|
if [ ! -f ${VARDIR}/firewall ]; then
|
2011-12-06 21:54:51 +01:00
|
|
|
[ -f ${VARDIR}/.restore ] && cp -f ${VARDIR}/.rstore ${VARDIR}/firewall
|
2009-03-01 20:46:30 +01:00
|
|
|
fi
|
|
|
|
|
2010-02-23 16:52:35 +01:00
|
|
|
g_firewall=${VARDIR}/firewall
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2011-12-06 21:54:51 +01:00
|
|
|
if [ -z "$g_lite" ]; then
|
|
|
|
for library in base cli cli-std; do
|
|
|
|
. /usr/share/shorewall/lib.$library
|
|
|
|
done
|
|
|
|
else
|
|
|
|
for library in base cli cli-lite; do
|
|
|
|
. ${SHAREDIR}/lib.$library
|
|
|
|
done
|
|
|
|
fi
|
2008-12-07 19:17:26 +01:00
|
|
|
|
2010-02-23 16:52:35 +01:00
|
|
|
version_file=$SHAREDIR/version
|
|
|
|
if [ -f $version_file ]; then
|
2010-03-02 17:02:10 +01:00
|
|
|
SHOREWALL_VERSION=$(cat $version_file)
|
2008-12-07 19:17:26 +01:00
|
|
|
else
|
2011-12-03 19:59:01 +01:00
|
|
|
echo " ERROR: $g_product is not properly installed" >&2
|
2010-02-23 16:52:35 +01:00
|
|
|
echo " The file $version_file does not exist" >&2
|
2008-12-07 19:17:26 +01:00
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
|
2011-12-03 19:59:01 +01:00
|
|
|
banner="${g_product}-${SHOREWALL_VERSION} Status at $g_hostname -"
|
2008-12-07 19:17:26 +01:00
|
|
|
|
|
|
|
case $(echo -e) in
|
|
|
|
-e*)
|
2010-02-23 16:52:35 +01:00
|
|
|
g_ring_bell="echo \a"
|
|
|
|
g_echo_e="echo"
|
2008-12-07 19:17:26 +01:00
|
|
|
;;
|
|
|
|
*)
|
2010-02-23 16:52:35 +01:00
|
|
|
g_ring_bell="echo -e \a"
|
|
|
|
g_echo_e="echo -e"
|
2008-12-07 19:17:26 +01:00
|
|
|
;;
|
|
|
|
esac
|
|
|
|
|
|
|
|
case $(echo -n "Testing") in
|
|
|
|
-n*)
|
2010-02-23 16:52:35 +01:00
|
|
|
g_echo_n=
|
2008-12-07 19:17:26 +01:00
|
|
|
;;
|
|
|
|
*)
|
2010-02-23 16:52:35 +01:00
|
|
|
g_echo_n=-n
|
2008-12-07 19:17:26 +01:00
|
|
|
;;
|
|
|
|
esac
|
|
|
|
|
|
|
|
COMMAND=$1
|
|
|
|
|
|
|
|
case "$COMMAND" in
|
|
|
|
start)
|
|
|
|
get_config Yes Yes
|
|
|
|
shift
|
|
|
|
start_command $@
|
|
|
|
;;
|
2010-05-20 23:09:40 +02:00
|
|
|
stop|clear)
|
2008-12-07 19:17:26 +01:00
|
|
|
[ $# -ne 1 ] && usage 1
|
2011-05-24 01:41:51 +02:00
|
|
|
get_config
|
2011-12-03 19:59:01 +01:00
|
|
|
[ -x $g_firewall ] || fatal_error "$g_product has never been started"
|
2010-07-23 18:26:47 +02:00
|
|
|
[ -n "$nolock" ] || mutex_on
|
|
|
|
run_it $g_firewall $g_debugging $COMMAND
|
|
|
|
[ -n "$nolock" ] || mutex_off
|
2008-12-07 19:17:26 +01:00
|
|
|
;;
|
|
|
|
reset)
|
|
|
|
get_config
|
|
|
|
shift
|
2010-07-23 18:26:47 +02:00
|
|
|
[ -n "$nolock" ] || mutex_on
|
2011-12-03 19:59:01 +01:00
|
|
|
[ -x $g_firewall ] || fatal_error "$g_product has never been started"
|
2010-07-23 18:26:47 +02:00
|
|
|
run_it $g_firewall $g_debugging reset $@
|
|
|
|
[ -n "$nolock" ] || mutex_off
|
2008-12-07 19:17:26 +01:00
|
|
|
;;
|
|
|
|
restart)
|
|
|
|
get_config Yes Yes
|
|
|
|
shift
|
|
|
|
restart_command $@
|
|
|
|
;;
|
2011-12-01 19:25:51 +01:00
|
|
|
disable|enable)
|
|
|
|
get_config Yes
|
2011-12-03 19:59:01 +01:00
|
|
|
if product_is_started; then
|
2011-12-01 19:25:51 +01:00
|
|
|
run_it ${VARDIR}/firewall $g_debugging $@
|
|
|
|
else
|
|
|
|
fatal_error "Shorewall is not running"
|
|
|
|
fi
|
|
|
|
;;
|
2009-03-06 21:43:46 +01:00
|
|
|
show|list)
|
2008-12-07 19:17:26 +01:00
|
|
|
get_config Yes No Yes
|
|
|
|
shift
|
|
|
|
show_command $@
|
|
|
|
;;
|
|
|
|
status)
|
|
|
|
[ $# -eq 1 ] || usage 1
|
2011-12-01 19:25:51 +01:00
|
|
|
[ "$(id -u)" != 0 ] && fatal_error "The status command may only be run by root"
|
2008-12-07 19:17:26 +01:00
|
|
|
get_config
|
2011-12-06 16:47:34 +01:00
|
|
|
status_command
|
2008-12-07 19:17:26 +01:00
|
|
|
;;
|
|
|
|
dump)
|
|
|
|
get_config Yes No Yes
|
|
|
|
shift
|
|
|
|
dump_command $@
|
|
|
|
;;
|
|
|
|
hits)
|
2011-12-03 19:59:01 +01:00
|
|
|
[ $g_family -eq 6 ] && usage 1
|
2008-12-07 19:17:26 +01:00
|
|
|
get_config Yes No Yes
|
2010-02-23 01:43:38 +01:00
|
|
|
[ -n "$g_debugging" ] && set -x
|
2008-12-07 19:17:26 +01:00
|
|
|
shift
|
|
|
|
hits_command $@
|
|
|
|
;;
|
|
|
|
version)
|
|
|
|
shift
|
|
|
|
version_command $@
|
|
|
|
;;
|
|
|
|
logwatch)
|
|
|
|
get_config Yes Yes Yes
|
2011-12-03 19:59:01 +01:00
|
|
|
banner="${g_product}-$SHOREWALL_VERSION Logwatch at $g_hostname -"
|
2008-12-07 19:17:26 +01:00
|
|
|
logwatch_command $@
|
|
|
|
;;
|
|
|
|
drop)
|
|
|
|
get_config
|
2010-02-23 01:43:38 +01:00
|
|
|
[ -n "$g_debugging" ] && set -x
|
2008-12-07 19:17:26 +01:00
|
|
|
[ $# -eq 1 ] && usage 1
|
2011-12-06 16:47:34 +01:00
|
|
|
drop_command $@
|
2008-12-07 19:17:26 +01:00
|
|
|
;;
|
|
|
|
logdrop)
|
|
|
|
get_config
|
2010-02-23 01:43:38 +01:00
|
|
|
[ -n "$g_debugging" ] && set -x
|
2008-12-07 19:17:26 +01:00
|
|
|
[ $# -eq 1 ] && usage 1
|
2011-12-06 16:47:34 +01:00
|
|
|
logdrop_command $@
|
2008-12-07 19:17:26 +01:00
|
|
|
;;
|
|
|
|
reject|logreject)
|
|
|
|
get_config
|
2010-02-23 01:43:38 +01:00
|
|
|
[ -n "$g_debugging" ] && set -x
|
2008-12-07 19:17:26 +01:00
|
|
|
[ $# -eq 1 ] && usage 1
|
2011-12-06 16:47:34 +01:00
|
|
|
reject_command $@
|
2008-12-07 19:17:26 +01:00
|
|
|
;;
|
|
|
|
allow)
|
|
|
|
get_config
|
|
|
|
allow_command $@
|
|
|
|
;;
|
2009-03-06 18:00:38 +01:00
|
|
|
add)
|
|
|
|
get_config
|
|
|
|
shift
|
|
|
|
add_command $@
|
|
|
|
;;
|
|
|
|
delete)
|
|
|
|
get_config
|
|
|
|
shift
|
2009-04-18 20:48:28 +02:00
|
|
|
delete_command $@
|
2009-03-06 21:25:59 +01:00
|
|
|
;;
|
2008-12-07 19:17:26 +01:00
|
|
|
save)
|
|
|
|
get_config
|
2010-02-23 01:43:38 +01:00
|
|
|
[ -n "$g_debugging" ] && set -x
|
2011-12-06 16:47:34 +01:00
|
|
|
save_command $@
|
2008-12-07 19:17:26 +01:00
|
|
|
;;
|
|
|
|
forget)
|
|
|
|
get_config
|
2011-12-06 16:47:34 +01:00
|
|
|
forget_command $@
|
2008-12-07 19:17:26 +01:00
|
|
|
;;
|
|
|
|
ipcalc)
|
2010-02-23 01:43:38 +01:00
|
|
|
[ -n "$g_debugging" ] && set -x
|
2011-12-06 16:47:34 +01:00
|
|
|
ipcalc_command $@
|
2008-12-07 19:17:26 +01:00
|
|
|
;;
|
|
|
|
|
|
|
|
iprange)
|
2010-02-23 01:43:38 +01:00
|
|
|
[ -n "$g_debugging" ] && set -x
|
2011-12-06 16:47:34 +01:00
|
|
|
iprange_command $@
|
2008-12-07 19:17:26 +01:00
|
|
|
;;
|
|
|
|
ipdecimal)
|
2010-02-23 01:43:38 +01:00
|
|
|
[ -n "$g_debugging" ] && set -x
|
2011-12-06 16:47:34 +01:00
|
|
|
ipdecimal_command $@
|
2008-12-07 19:17:26 +01:00
|
|
|
;;
|
|
|
|
restore)
|
|
|
|
get_config
|
|
|
|
shift
|
|
|
|
restore_command $@
|
|
|
|
;;
|
|
|
|
call)
|
|
|
|
get_config
|
2010-02-23 01:43:38 +01:00
|
|
|
[ -n "$g_debugging" ] && set -x
|
2008-12-07 19:17:26 +01:00
|
|
|
#
|
|
|
|
# Undocumented way to call functions in ${SHAREDIR}/functions directly
|
|
|
|
#
|
|
|
|
shift
|
|
|
|
$@
|
|
|
|
;;
|
|
|
|
help)
|
|
|
|
shift
|
|
|
|
usage
|
|
|
|
;;
|
2009-06-17 21:03:05 +02:00
|
|
|
iptrace)
|
|
|
|
get_config
|
|
|
|
shift
|
2011-12-06 16:47:34 +01:00
|
|
|
iptrace_command $@
|
2010-06-07 18:16:56 +02:00
|
|
|
;;
|
2009-06-17 21:03:05 +02:00
|
|
|
noiptrace)
|
|
|
|
get_config
|
|
|
|
shift
|
2011-12-06 16:47:34 +01:00
|
|
|
noiptrace_command $@
|
2010-06-07 18:16:56 +02:00
|
|
|
;;
|
2008-12-07 19:17:26 +01:00
|
|
|
*)
|
2011-12-06 21:54:51 +01:00
|
|
|
if [ -z "$g_lite" ]; then
|
|
|
|
compiler_command $@
|
|
|
|
else
|
|
|
|
usage 1
|
|
|
|
fi
|
|
|
|
;;
|
2008-12-07 19:17:26 +01:00
|
|
|
esac
|