1 /* Shared library add-on to iptables to add ROUTE target support.
2 * Author : Cedric de Launois, <delaunois@info.ucl.ac.be>
12 #include <sys/socket.h>
13 #include <netinet/in.h>
14 #include <arpa/inet.h>
15 #include <linux/netfilter_ipv4/ip_tables.h>
16 #include <linux/netfilter_ipv4/ipt_ROUTE.h>
18 /* compile IPT_ROUTE_TEE support even if kernel headers are unpatched */
20 #define IPT_ROUTE_TEE 0x02
23 /* Function which prints out usage message. */
28 "ROUTE target v%s options:\n"
29 " --oif \tifname \t\tRoute packet through `ifname' network interface\n"
30 " --iif \tifname \t\tChange packet's incoming interface to `ifname'\n"
31 " --gw \tip \t\tRoute packet via this gateway `ip'\n"
32 " --continue\t \t\tRoute packet and continue traversing the\n"
33 " \t \t\trules. Not valid with --iif or --tee.\n"
34 " --tee\t \t\tDuplicate packet, route the duplicate,\n"
35 " \t \t\tcontinue traversing with original packet.\n"
36 " \t \t\tNot valid with --iif or --continue.\n"
41 static struct option opts[] = {
45 { "continue", 0, 0, '4' },
50 /* Initialize the target. */
52 init(struct ipt_entry_target *t, unsigned int *nfcache)
54 struct ipt_route_target_info *route_info =
55 (struct ipt_route_target_info*)t->data;
57 route_info->oif[0] = '\0';
58 route_info->iif[0] = '\0';
60 route_info->flags = 0;
64 #define IPT_ROUTE_OPT_OIF 0x01
65 #define IPT_ROUTE_OPT_IIF 0x02
66 #define IPT_ROUTE_OPT_GW 0x04
67 #define IPT_ROUTE_OPT_CONTINUE 0x08
68 #define IPT_ROUTE_OPT_TEE 0x10
70 /* Function which parses command options; returns true if it
73 parse(int c, char **argv, int invert, unsigned int *flags,
74 const struct ipt_entry *entry,
75 struct ipt_entry_target **target)
77 struct ipt_route_target_info *route_info =
78 (struct ipt_route_target_info*)(*target)->data;
82 if (*flags & IPT_ROUTE_OPT_OIF)
83 exit_error(PARAMETER_PROBLEM,
84 "Can't specify --oif twice");
86 if (*flags & IPT_ROUTE_OPT_IIF)
87 exit_error(PARAMETER_PROBLEM,
88 "Can't use --oif and --iif together");
90 if (check_inverse(optarg, &invert, NULL, 0))
91 exit_error(PARAMETER_PROBLEM,
92 "Unexpected `!' after --oif");
94 if (strlen(optarg) > sizeof(route_info->oif) - 1)
95 exit_error(PARAMETER_PROBLEM,
96 "Maximum interface name length %u",
97 sizeof(route_info->oif) - 1);
99 strcpy(route_info->oif, optarg);
100 *flags |= IPT_ROUTE_OPT_OIF;
104 if (*flags & IPT_ROUTE_OPT_IIF)
105 exit_error(PARAMETER_PROBLEM,
106 "Can't specify --iif twice");
108 if (*flags & IPT_ROUTE_OPT_OIF)
109 exit_error(PARAMETER_PROBLEM,
110 "Can't use --iif and --oif together");
112 if (check_inverse(optarg, &invert, NULL, 0))
113 exit_error(PARAMETER_PROBLEM,
114 "Unexpected `!' after --iif");
116 if (strlen(optarg) > sizeof(route_info->iif) - 1)
117 exit_error(PARAMETER_PROBLEM,
118 "Maximum interface name length %u",
119 sizeof(route_info->iif) - 1);
121 strcpy(route_info->iif, optarg);
122 *flags |= IPT_ROUTE_OPT_IIF;
126 if (*flags & IPT_ROUTE_OPT_GW)
127 exit_error(PARAMETER_PROBLEM,
128 "Can't specify --gw twice");
130 if (check_inverse(optarg, &invert, NULL, 0))
131 exit_error(PARAMETER_PROBLEM,
132 "Unexpected `!' after --gw");
134 if (!inet_aton(optarg, (struct in_addr*)&route_info->gw)) {
135 exit_error(PARAMETER_PROBLEM,
136 "Invalid IP address %s",
140 *flags |= IPT_ROUTE_OPT_GW;
144 if (*flags & IPT_ROUTE_OPT_CONTINUE)
145 exit_error(PARAMETER_PROBLEM,
146 "Can't specify --continue twice");
147 if (*flags & IPT_ROUTE_OPT_TEE)
148 exit_error(PARAMETER_PROBLEM,
149 "Can't specify --continue AND --tee");
151 route_info->flags |= IPT_ROUTE_CONTINUE;
152 *flags |= IPT_ROUTE_OPT_CONTINUE;
157 if (*flags & IPT_ROUTE_OPT_TEE)
158 exit_error(PARAMETER_PROBLEM,
159 "Can't specify --tee twice");
160 if (*flags & IPT_ROUTE_OPT_CONTINUE)
161 exit_error(PARAMETER_PROBLEM,
162 "Can't specify --tee AND --continue");
164 route_info->flags |= IPT_ROUTE_TEE;
165 *flags |= IPT_ROUTE_OPT_TEE;
178 final_check(unsigned int flags)
181 exit_error(PARAMETER_PROBLEM,
182 "ROUTE target: oif, iif or gw option required");
184 if ((flags & (IPT_ROUTE_OPT_CONTINUE|IPT_ROUTE_OPT_TEE)) && (flags & IPT_ROUTE_OPT_IIF))
185 exit_error(PARAMETER_PROBLEM,
186 "ROUTE target: can't continue traversing the rules with iif option");
190 /* Prints out the targinfo. */
192 print(const struct ipt_ip *ip,
193 const struct ipt_entry_target *target,
196 const struct ipt_route_target_info *route_info
197 = (const struct ipt_route_target_info *)target->data;
201 if (route_info->oif[0])
202 printf("oif:%s ", route_info->oif);
204 if (route_info->iif[0])
205 printf("iif:%s ", route_info->iif);
207 if (route_info->gw) {
208 struct in_addr ip = { route_info->gw };
209 printf("gw:%s ", inet_ntoa(ip));
212 if (route_info->flags & IPT_ROUTE_CONTINUE)
215 if (route_info->flags & IPT_ROUTE_TEE)
221 static void save(const struct ipt_ip *ip,
222 const struct ipt_entry_target *target)
224 const struct ipt_route_target_info *route_info
225 = (const struct ipt_route_target_info *)target->data;
227 if (route_info->oif[0])
228 printf("--oif %s ", route_info->oif);
230 if (route_info->iif[0])
231 printf("--iif %s ", route_info->iif);
233 if (route_info->gw) {
234 struct in_addr ip = { route_info->gw };
235 printf("--gw %s ", inet_ntoa(ip));
238 if (route_info->flags & IPT_ROUTE_CONTINUE)
239 printf("--continue ");
241 if (route_info->flags & IPT_ROUTE_TEE)
246 static struct iptables_target route = {
249 .version = IPTABLES_VERSION,
250 .size = IPT_ALIGN(sizeof(struct ipt_route_target_info)),
251 .userspacesize = IPT_ALIGN(sizeof(struct ipt_route_target_info)),
255 .final_check = &final_check,
263 register_target(&route);