1 /* Shared library add-on to iptables to add TTL matching support
2 * (C) 2000 by Harald Welte <laforge@gnumonks.org>
4 * $Id: libipt_ttl.c 3687 2005-02-14 13:13:04Z /C=DE/ST=Berlin/L=Berlin/O=Netfilter Project/OU=Development/CN=kaber/emailAddress=kaber@netfilter.org $
6 * This program is released under the terms of GNU GPL */
14 #include <linux/netfilter_ipv4/ip_tables.h>
15 #include <linux/netfilter_ipv4/ipt_ttl.h>
17 static void help(void)
20 "TTL match v%s options:\n"
21 " --ttl-eq value Match time to live value\n"
22 " --ttl-lt value Match TTL < value\n"
23 " --ttl-gt value Match TTL > value\n"
27 static int parse(int c, char **argv, int invert, unsigned int *flags,
28 const struct ipt_entry *entry, unsigned int *nfcache,
29 struct ipt_entry_match **match)
31 struct ipt_ttl_info *info = (struct ipt_ttl_info *) (*match)->data;
34 check_inverse(optarg, &invert, &optind, 0);
36 if (string_to_number(optarg, 0, 255, &value) == -1)
37 exit_error(PARAMETER_PROBLEM,
38 "ttl: Expected value between 0 and 255");
43 info->mode = IPT_TTL_NE;
45 info->mode = IPT_TTL_EQ;
52 exit_error(PARAMETER_PROBLEM,
53 "ttl: unexpected `!'");
55 info->mode = IPT_TTL_LT;
60 exit_error(PARAMETER_PROBLEM,
61 "ttl: unexpected `!'");
63 info->mode = IPT_TTL_GT;
72 exit_error(PARAMETER_PROBLEM,
73 "Can't specify TTL option twice");
79 static void final_check(unsigned int flags)
82 exit_error(PARAMETER_PROBLEM,
83 "TTL match: You must specify one of "
84 "`--ttl-eq', `--ttl-lt', `--ttl-gt");
87 static void print(const struct ipt_ip *ip,
88 const struct ipt_entry_match *match,
91 const struct ipt_ttl_info *info =
92 (struct ipt_ttl_info *) match->data;
109 printf("%u ", info->ttl);
112 static void save(const struct ipt_ip *ip,
113 const struct ipt_entry_match *match)
115 const struct ipt_ttl_info *info =
116 (struct ipt_ttl_info *) match->data;
118 switch (info->mode) {
123 printf("! --ttl-eq ");
135 printf("%u ", info->ttl);
138 static struct option opts[] = {
139 { "ttl", 1, 0, '2' },
140 { "ttl-eq", 1, 0, '2'},
141 { "ttl-lt", 1, 0, '3'},
142 { "ttl-gt", 1, 0, '4'},
146 static struct iptables_match ttl = {
149 .version = IPTABLES_VERSION,
150 .size = IPT_ALIGN(sizeof(struct ipt_ttl_info)),
151 .userspacesize = IPT_ALIGN(sizeof(struct ipt_ttl_info)),
154 .final_check = &final_check,
163 register_match(&ttl);