2005-05-17 02:26:11 +02:00
|
|
|
remove_old()
|
|
|
|
{
|
|
|
|
# remove the rules from PREROUTING
|
|
|
|
$IPT -t nat -F $CHAIN_FORWARD_CHECK 2>/dev/null && $IPT -t nat -D PREROUTING -i $IF_SRC -j $CHAIN_FORWARD_CHECK
|
|
|
|
$IPT -t nat -F $CHAIN_REDIRECT 2>/dev/null && $IPT -t nat -D PREROUTING -i $IF_SRC -j $CHAIN_REDIRECT
|
2005-05-17 12:11:28 +02:00
|
|
|
$IPT -t nat -F $CHAIN_SERVICES 2>/dev/null && $IPT -t nat -D PREROUTING -i $IF_SRC -j $CHAIN_SERVICES
|
2005-05-17 02:26:11 +02:00
|
|
|
|
|
|
|
# empty and remove chains if they exist
|
2005-05-17 12:11:28 +02:00
|
|
|
for a in $CHAIN_FORWARD_ACTION $CHAIN_FORWARD_CHECK $CHAIN_REDIRECT $CHAIN_SERVICES
|
2005-05-17 02:26:11 +02:00
|
|
|
do $IPT -t nat -F $a 2>/dev/null && $IPT -t nat -X $a
|
|
|
|
true
|
|
|
|
done
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
init_chains()
|
|
|
|
{
|
|
|
|
# create chains
|
2005-05-17 12:11:28 +02:00
|
|
|
for a in $CHAIN_FORWARD_ACTION $CHAIN_FORWARD_CHECK $CHAIN_REDIRECT $CHAIN_SERVICES
|
2005-05-17 02:26:11 +02:00
|
|
|
do $IPT -t nat -N $a
|
|
|
|
done
|
|
|
|
|
|
|
|
# all packets from the specified interface go to the general chain
|
2005-05-17 12:11:28 +02:00
|
|
|
$IPT -t nat -A PREROUTING -i $IF_SRC -j $CHAIN_SERVICES
|
2005-05-17 02:26:11 +02:00
|
|
|
$IPT -t nat -A PREROUTING -i $IF_SRC -j $CHAIN_FORWARD_CHECK
|
|
|
|
$IPT -t nat -A PREROUTING -i $IF_SRC -j $CHAIN_REDIRECT
|
|
|
|
|
|
|
|
# rules for CHAIN_REDIRECT
|
2005-05-17 12:11:28 +02:00
|
|
|
$IPT -t nat -A $CHAIN_REDIRECT -p tcp --dport 80 -j DNAT --to-destination $INTERN_IP
|
2005-05-17 02:26:11 +02:00
|
|
|
$IPT -t nat -A $CHAIN_REDIRECT -p tcp --dport 80 -j ACCEPT
|
|
|
|
$IPT -t nat -A $CHAIN_REDIRECT -j $REJECT_ACTION
|
|
|
|
|
|
|
|
# all registered senders are simply accepted
|
|
|
|
$IPT -t nat -A $CHAIN_FORWARD_ACTION -j ACCEPT
|
2005-05-17 12:11:28 +02:00
|
|
|
|
|
|
|
# allowed packets (services like dns, dhcp and ssh (to the router only))
|
|
|
|
$IPT -t nat -A $CHAIN_SERVICES -p udp --dport 53 -j ACCEPT
|
|
|
|
$IPT -t nat -A $CHAIN_SERVICES -p udp --dport 67 -j ACCEPT
|
|
|
|
$IPT -t nat -A $CHAIN_SERVICES -p tcp --dport 67 -j ACCEPT
|
|
|
|
$IPT -t nat -A $CHAIN_SERVICES -p tcp -d $INTERN_IP --dport 22 -j ACCEPT
|
|
|
|
|
|
|
|
# user defined "privileged" source IPs
|
|
|
|
for a in $ALLOW_IP_LIST
|
|
|
|
do $IPT -t nat -A $CHAIN_SERVICES -s $a -j ACCEPT
|
|
|
|
done
|
|
|
|
|
|
|
|
# user defined forbidden source IPs
|
|
|
|
for a in $DENY_IP_LIST
|
|
|
|
do $IPT -t nat -I $CHAIN_SERVICES -s $a -j $REJECT_ACTION
|
|
|
|
done
|
2005-05-17 02:26:11 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
get_IPs()
|
|
|
|
# prints out all active forwards line by line
|
|
|
|
# every line consists of: "Number of Packets" and "IP"
|
|
|
|
{
|
|
|
|
iptables -t nat -L "$CHAIN_FORWARD_CHECK" -vnx | sed "1,2d; s/ */ /g" | cut -d " " -f 2,9
|
|
|
|
# get all active forward chains
|
|
|
|
# remove the first two lines
|
|
|
|
# remove multiple spaces
|
|
|
|
# take only the number of packets and the IP
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
register_IP()
|
|
|
|
# add a new allowed IP
|
|
|
|
{
|
|
|
|
eval `echo "$RULE_ADD" | sed "s/_IP_/$1/g"`
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
unregister_IP()
|
|
|
|
# remove the specified IP
|
|
|
|
{
|
|
|
|
eval `echo "$RULE_DEL" | sed "s/_IP_/$1/g"`
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
refresh_IP_list()
|
|
|
|
{
|
|
|
|
local NUM
|
|
|
|
local IP
|
|
|
|
get_IPs | while read NUM IP
|
|
|
|
do [ "$NUM" = "0" ] && unregister_IP "$IP"
|
|
|
|
done
|
|
|
|
}
|
|
|
|
|