From d68e09200e223c466a03242307c97abd25849d82 Mon Sep 17 00:00:00 2001 From: Jo-Philipp Wich Date: Sat, 31 Jul 2010 13:06:14 +0000 Subject: firewall: add basic NAT reflection/NAT loopback support SVN-Revision: 22441 --- package/firewall/files/reflection.hotplug | 79 +++++++++++++++++++++++++++++++ 1 file changed, 79 insertions(+) create mode 100644 package/firewall/files/reflection.hotplug (limited to 'package/firewall/files') diff --git a/package/firewall/files/reflection.hotplug b/package/firewall/files/reflection.hotplug new file mode 100644 index 0000000000..605ac7c991 --- /dev/null +++ b/package/firewall/files/reflection.hotplug @@ -0,0 +1,79 @@ +#!/bin/sh +# Setup NAT reflection rules + +. /etc/functions.sh + +if [ "$ACTION" = "ifup" ] && [ "$INTERFACE" = "wan" ]; then + local wanip=$(uci -P/var/state get network.wan.ipaddr) + + iptables -t nat -F nat_reflection_in 2>/dev/null || { + iptables -t nat -N nat_reflection_in + iptables -t nat -A prerouting_rule -j nat_reflection_in + } + + iptables -t nat -F nat_reflection_out 2>/dev/null || { + iptables -t nat -N nat_reflection_out + iptables -t nat -A postrouting_rule -j nat_reflection_out + } + + setup_fwd() { + local cfg="$1" + + local src + config_get src "$cfg" src + + [ "$src" = wan ] && { + local dest + config_get dest "$cfg" dest "lan" + + local lanip=$(uci -P/var/state get network.$dest.ipaddr) + local lanmk=$(uci -P/var/state get network.$dest.netmask) + + local proto + config_get proto "$cfg" proto + + local epmin epmax extport + config_get extport "$cfg" src_dport + [ -n "$extport" ] || return + + epmin="${extport%[-:]*}"; epmax="${extport#*[-:]}" + [ "$epmin" != "$epmax" ] || epmax="" + + local ipmin ipmax intport + config_get intport "$cfg" dest_port "$extport" + + ipmin="${intport%[-:]*}"; ipmax="${intport#*[-:]}" + [ "$ipmin" != "$ipmax" ] || ipmax="" + + local exthost + config_get exthost "$cfg" src_dip "$wanip" + + local inthost + config_get inthost "$cfg" dest_ip + [ -n "$inthost" ] || return + + [ "$proto" = tcpudp ] && proto="tcp udp" + + local p + for p in ${proto:-tcp udp}; do + case "$p" in + tcp|udp) + iptables -t nat -A nat_reflection_in \ + -s $lanip/$lanmk -d $exthost \ + -p $p --dport $epmin${epmax:+:$epmax} \ + -j DNAT --to $inthost:$ipmin${ipmax:+-$ipmax} + + iptables -t nat -A nat_reflection_out \ + -s $lanip/$lanmk -d $inthost \ + -p $p --dport $ipmin${ipmax:+:$ipmax} \ + -j SNAT --to-source $lanip + ;; + esac + done + } + } + + config_load firewall + config_foreach setup_fwd redirect +fi + -- cgit v1.2.3