1 /* Shared library add-on to iptables to add TTL matching support
2 * (C) 2000 by Harald Welte <laforge@gnumonks.org>
4 * $Id: libipt_ttl.c 4544 2005-11-18 17:59:56Z /C=DE/ST=Berlin/L=Berlin/O=Netfilter Project/OU=Development/CN=kaber/emailAddress=kaber@netfilter.org $
6 * This program is released under the terms of GNU GPL */
14 #include <linux/netfilter_ipv4/ip_tables.h>
15 #include <linux/netfilter_ipv4/ipt_ttl.h>
17 static void help(void)
20 "TTL match v%s options:\n"
21 " --ttl-eq value Match time to live value\n"
22 " --ttl-lt value Match TTL < value\n"
23 " --ttl-gt value Match TTL > value\n"
27 static int parse(int c, char **argv, int invert, unsigned int *flags,
28 const struct ipt_entry *entry, unsigned int *nfcache,
29 struct ipt_entry_match **match)
31 struct ipt_ttl_info *info = (struct ipt_ttl_info *) (*match)->data;
34 check_inverse(optarg, &invert, &optind, 0);
38 if (string_to_number(optarg, 0, 255, &value) == -1)
39 exit_error(PARAMETER_PROBLEM,
40 "ttl: Expected value between 0 and 255");
43 info->mode = IPT_TTL_NE;
45 info->mode = IPT_TTL_EQ;
51 if (string_to_number(optarg, 0, 255, &value) == -1)
52 exit_error(PARAMETER_PROBLEM,
53 "ttl: Expected value between 0 and 255");
56 exit_error(PARAMETER_PROBLEM,
57 "ttl: unexpected `!'");
59 info->mode = IPT_TTL_LT;
63 if (string_to_number(optarg, 0, 255, &value) == -1)
64 exit_error(PARAMETER_PROBLEM,
65 "ttl: Expected value between 0 and 255");
68 exit_error(PARAMETER_PROBLEM,
69 "ttl: unexpected `!'");
71 info->mode = IPT_TTL_GT;
80 exit_error(PARAMETER_PROBLEM,
81 "Can't specify TTL option twice");
87 static void final_check(unsigned int flags)
90 exit_error(PARAMETER_PROBLEM,
91 "TTL match: You must specify one of "
92 "`--ttl-eq', `--ttl-lt', `--ttl-gt");
95 static void print(const struct ipt_ip *ip,
96 const struct ipt_entry_match *match,
99 const struct ipt_ttl_info *info =
100 (struct ipt_ttl_info *) match->data;
102 printf("TTL match ");
103 switch (info->mode) {
117 printf("%u ", info->ttl);
120 static void save(const struct ipt_ip *ip,
121 const struct ipt_entry_match *match)
123 const struct ipt_ttl_info *info =
124 (struct ipt_ttl_info *) match->data;
126 switch (info->mode) {
131 printf("! --ttl-eq ");
143 printf("%u ", info->ttl);
146 static struct option opts[] = {
147 { "ttl", 1, 0, '2' },
148 { "ttl-eq", 1, 0, '2'},
149 { "ttl-lt", 1, 0, '3'},
150 { "ttl-gt", 1, 0, '4'},
154 static struct iptables_match ttl = {
157 .version = IPTABLES_VERSION,
158 .size = IPT_ALIGN(sizeof(struct ipt_ttl_info)),
159 .userspacesize = IPT_ALIGN(sizeof(struct ipt_ttl_info)),
162 .final_check = &final_check,
171 register_match(&ttl);