4 .
/lib
/functions
/network.sh
6 if [ "$ACTION" = "remove" ]; then
8 delete_rules_by_comment
() {
13 iptables
-t "$table" --line-numbers -nL "$chain" 2>/dev
/null | \
17 \#^[0-9]\+ .* /\* '"$comment"' \*/.*$# {
23 ' |
xargs -n1 iptables
-t "$table" -D "$chain" 2>/dev
/null
26 delete_rules_by_comment nat nat_reflection_in
"$INTERFACE"
27 delete_rules_by_comment nat nat_reflection_out
"$INTERFACE"
28 delete_rules_by_comment filter nat_reflection_fwd
"$INTERFACE"
30 elif [ "$ACTION" = "add" ]; then
33 iptables
-t nat
-N nat_reflection_in
2>/dev
/null
&& {
34 iptables
-t nat
-A prerouting_rule
-j nat_reflection_in
37 iptables
-t nat
-N nat_reflection_out
2>/dev
/null
&& {
38 iptables
-t nat
-A postrouting_rule
-j nat_reflection_out
41 iptables
-t filter
-N nat_reflection_fwd
2>/dev
/null
&& {
42 iptables
-t filter
-A forwarding_rule
-j nat_reflection_fwd
50 local need_masq
="${3:-0}"
53 config_get name
"$cfg" name
56 config_get_bool masq
"$cfg" masq
0
58 [ "$name" = "$zone" ] && [ "$masq" -ge "$need_masq" ] && {
60 config_get network
"$cfg" network
62 echo ${network:-$zone}
67 config_foreach find_networks_cb zone
"$1"
74 config_get_bool reflection
"$cfg" reflection
1
75 [ "$reflection" == 1 ] ||
return
78 config_get src
"$cfg" src
79 [ "$src" == "$ZONE" ] ||
return
82 config_get dest
"$cfg" dest
83 [ "$dest" != "*" ] ||
return
86 config_get target
"$cfg" target DNAT
87 [ "$target" = DNAT
] ||
return
92 for net
in $
(find_networks
"$dest" 0); do
94 network_get_subnet intnet
"$net" ||
continue
97 config_get proto
"$cfg" proto
99 local epmin epmax extport
100 config_get extport
"$cfg" src_dport
"1-65535"
101 [ -n "$extport" ] ||
return
103 epmin
="${extport%[-:]*}"; epmax
="${extport#*[-:]}"
104 [ "${epmin#!}" != "$epmax" ] || epmax
=""
106 local ipmin ipmax intport
107 config_get intport
"$cfg" dest_port
"$extport"
109 ipmin
="${intport%[-:]*}"; ipmax
="${intport#*[-:]}"
110 [ "${ipmin#!}" != "$ipmax" ] || ipmax
=""
113 config_get exthost
"$cfg" src_dip
"$extip"
116 config_get inthost
"$cfg" dest_ip
117 [ -n "$inthost" ] ||
return
119 [ "$proto" = all
] && proto
="tcp udp"
120 [ "$proto" = tcpudp
] && proto
="tcp udp"
122 [ "${inthost#!}" = "$inthost" ] ||
return 0
123 [ "${exthost#!}" = "$exthost" ] ||
return 0
125 [ "${epmin#!}" != "$epmin" ] && \
126 extport
="! --dport ${epmin#!}${epmax:+:$epmax}" || \
127 extport
="--dport $epmin${epmax:+:$epmax}"
129 [ "${ipmin#!}" != "$ipmin" ] && \
130 intport
="! --dport ${ipmin#!}${ipmax:+:$ipmax}" || \
131 intport
="--dport $ipmin${ipmax:+:$ipmax}"
134 for p
in ${proto:-tcp udp}; do
137 iptables
-t nat
-A nat_reflection_in \
138 -s $intnet -d $exthost \
140 -m comment
--comment "$INTERFACE" \
141 -j DNAT
--to $inthost:${ipmin#!}${ipmax:+-$ipmax}
143 iptables
-t nat
-A nat_reflection_out \
144 -s $intnet -d $inthost \
146 -m comment
--comment "$INTERFACE" \
147 -j SNAT
--to-source ${intnet%%/*}
149 iptables
-t filter
-A nat_reflection_fwd \
150 -s $intnet -d $inthost \
152 -m comment
--comment "$INTERFACE" \
162 local is_masq_zone
="$(find_networks "$ZONE" 1)"
163 [ -n "$is_masq_zone" ] ||
exit 0
166 network_get_ipaddr extip
"$INTERFACE" ||
exit 0
168 config_foreach setup_fwd redirect