implement IPv4 and IPv6 config options

This commit is contained in:
Kay Marquardt (Gnadelwartz)
2017-07-01 15:41:18 +02:00
parent 5a4e9302e8
commit 4af91a52e5
4 changed files with 30 additions and 26 deletions

View File

@@ -1,4 +1,4 @@
line0=Configurable options,11
line0=Configurable global options,11
perpage=Number of rules to display per page,3,50
view_condition=Display condition in rules list?,1,1-Yes,0-No
view_comment=Display comment in rules list?,1,1-Yes,0-No
@@ -8,9 +8,11 @@ before_cmd=Command to run before changing rules,3,None
after_cmd=Command to run after changing rules,3,None
before_apply_cmd=Command to run before applying configuration,3,None
after_apply_cmd=Command to run after applying configuration,3,None
line1=System configuration,11
force_init=Always start firewall from init script on Debian,1,1-Yes,0-No
save_file=File to save/edit <tt>IPv4</tt> rules,3,Use operating system or Webmin default
save_file6=File to save/edit <tt>IPv6</tt> rules,3,Use operating system or Webmin default
direct=Directly edit firewall rules instead of save file?,1,1-Yes,0-No
filter_chain=Comma sepeated list of regexes to filter out chains not managed by firewall,0
line2=IPv4 configuration,11
save_file=File to save/edit <tt>IPv4</tt> rules,3,Use operating system or Webmin default
direct=Directly edit firewall <tt>IPv4</tt> rules instead of save file?,1,1-Yes,0-No
line3=IPv6 configuration,11
save_file6=File to save/edit <tt>IPv6</tt> rules,3,Use operating system or Webmin default
direct6=Directly edit firewall <tt>IPv6</tt> rules instead of save file?,1,1-Yes,0-No

View File

@@ -1,4 +1,5 @@
line0=Konfigurierbare Optionen,11
line0=Konfigurierbare globale Optionen,11
perpage=Anzahl der anzuzeigenden Regeln pro Seite,3,50
view_condition=Zeige Zustand in Regelliste?,1,1-Ja,0-Nein
view_comment=Zeige Kommentare in Regelliste an?,1,1-Ja,0-Nein
comment_mod=Speichere Kommentare als,1,0-# Kommentar in Datei speichern,1-&#45;&#45; Kommentaroption
@@ -8,9 +9,11 @@ before_cmd=Befehle zum Ausf&#252;hren vor &#196;nderung der Regeln,3,Keiner
after_cmd=Befehle zum Ausf&#252;hren nach &#196;nderung der Regeln,3,Keiner
before_apply_cmd=Befehle zum Ausf&#252;hren vor Anwenden der Konfiguration,3,Keiner
after_apply_cmd=Befehle zum Anwendung der Konfiguration,3,Keiner
line1=System Konfiguration,11
save_file=Datei zum Speichern/Bearbeiten der <tt>IPv4</tt> Regeln,3,Verwendung des Betriebssystems oder Webmin Standard
save_file6=Datei zum Speichern/Bearbeiten der <tt>IPv6</tt> Regeln,3,Verwendung des Betriebssystems oder Webmin Standard
direct=Direktes Bearbeiten der Firewall-Regeln anstatt von gespeicherter Datei?,1,1-Ja,0-Nein
filter_chain=Komma getrennte Liste von Regex zum Ausfiltern von Ketten die nicht von Firewall verwaltet werden,0
line2=IPv4 Konfiguration,11
save_file=Datei zum Speichern/Bearbeiten der <tt>IPv4</tt> Regeln,3,Verwendung des Betriebssystems oder Webmin Standard
direct=Bearbeite <tt>IPv4</tt> Firewall-Regeln direkt anstatt in Datei?,1,1-Ja,0-Nein
line3=IPv6 Konfiguration,11
save_file6=File to save/edit <tt>IPv6</tt> rules,3,Use operating system or Webmin default
save_file6=Datei zum Speichern/Bearbeiten der <tt>IPv6</tt> Regeln,3,Verwendung des Betriebssystems oder Webmin Standard
direct6=Bearbeite <tt>IPv6</tt> Firewall-Regeln direkt anstatt in Datei?,1,1-Ja,0-Nein

View File

@@ -56,7 +56,7 @@ sub get_iptables_save
local (@rv, $table, %got);
local $lnum = 0;
open(FILE, $_[0] || ($config{'direct'} ? "ip${ipvx}tables-save 2>/dev/null |"
open(FILE, $_[0] || ($config{"direct${ipvx}"} ? "ip${ipvx}tables-save 2>/dev/null |"
: $ipvx_save));
local $cmt;
LINE:
@@ -64,7 +64,7 @@ while(<FILE>) {
local $read_comment;
s/\r|\n//g;
# regex to filter out chains not managed by firewall, i.e. fail2ban
if ($config{'direct'} && $config{'filter_chain'}) {
if ($config{"direct${ipvx}"} && $config{'filter_chain'}) {
foreach $filter (split(',', $config{'filter_chain'})) {
# NOTE: keep ":chain ..." as reference to avoid error when rebuild active config
# -A|-I chain ... -j chain -> skip line if machtes filter_chain
@@ -154,7 +154,7 @@ return @rv;
sub save_table
{
local $lref;
if ($config{'direct'}) {
if ($config{"direct${ipvx}"}) {
# Read in the current iptables-save output
$lref = &read_file_lines("ip${ipvx}tables-save 2>/dev/null |", 1);
}
@@ -199,7 +199,7 @@ else {
# Append new table to file
push(@$lref, "# Generated by webmin", @lines, "# Completed");
}
if ($config{'direct'}) {
if ($config{"direct${ipvx}"}) {
# Pass new lines to iptables-restore
open(SAVE, "| ip${ipvx}tables-restore");
print SAVE map { $_."\n" } @$lref;
@@ -497,14 +497,14 @@ return if (!$config{'servers'}); # no servers defined
return if (!$_[0] && $config{'cluster_mode'}); # only push out when applying
local $s;
local $ltemp;
if ($config{'direct'}) {
if ($config{"direct${ipvx}"}) {
# Dump current configuration
$ltemp = &transname();
system("ip${ipvx}tables-save >$ltemp 2>/dev/null");
}
foreach $s (&list_cluster_servers()) {
&remote_foreign_require($s, "firewall", $ipvx_lib);
if ($config{'direct'}) {
if ($config{"direct${ipvx}"}) {
# Directly activate on remote server!
local $rtemp = &remote_write($s, $ltemp);
unlink($ltemp);

View File

@@ -1,4 +1,4 @@
#!/usr/local/bin/perl
#!/usr/bin/perl
# index.cgi
# Display current iptables firewall configuration from save file
# unified for IPV4 and IPV6
@@ -46,7 +46,7 @@ if ($?) {
}
# Check if the distro supports iptables
if (!$config{'direct'} && defined(&check_iptables) &&
if (!$config{"direct${ipvx}"} && defined(&check_iptables) &&
($err = &check_iptables())) {
print "<p>$err</p>\n";
&ui_print_footer("/", $text{'index'});
@@ -54,7 +54,7 @@ if (!$config{'direct'} && defined(&check_iptables) &&
}
# Check if firewall is being started at boot
if (!$config{'direct'} && &foreign_check("init")) {
if (!$config{"direct${ipvx}"} && &foreign_check("init")) {
$init_support++;
if (defined(&started_at_boot)) {
$atboot = &started_at_boot();
@@ -71,8 +71,7 @@ if (!$config{'direct'} && &foreign_check("init")) {
# Display warnings about active external firewalls!
&external_firewall_message(\@livetables);
if (!$config{'direct'} &&
(!-s $ipvx_save || $in{'reset'}) && $access{'setup'}) {
if (!$config{"direct${ipvx}"} && $in{'reset'} && $access{'setup'}) {
@tables = @livetables;
foreach $t (@tables) {
$rules++ if (@{$t->{'rules'}});
@@ -129,7 +128,7 @@ if (!$config{'direct'} &&
else {
$form = 0;
@tables = &get_iptables_save();
if (!$config{'direct'}) {
if (!$config{"direct${ipvx}"}) {
# Verify that all known tables exist, and if not add them to the
# save file
foreach $t (@tables) {
@@ -150,7 +149,7 @@ else {
}
# Check if the current config is valid
if (!$config{'direct'}) {
if (!$config{"direct${ipvx}"}) {
my $err = &validate_iptables_config();
if ($err) {
print "<b>",&text('index_evalid',
@@ -466,7 +465,7 @@ else {
print &ui_hr();
print &ui_buttons_start();
if (!$config{'direct'}) {
if (!$config{"direct${ipvx}"}) {
# Buttons to apply and reset the config
if (&foreign_check("servers")) {
@servers = &list_cluster_servers();
@@ -544,7 +543,7 @@ sub external_firewall_message
$fwname.='fail2ban ';
}
# warning about not using direct
if($fwname && !$config{'direct'}) {
if($fwname && !$config{"direct${ipvx}"}) {
print "<b><center>",
&text('index_filter_nodirect', $fwconfig),
"</b></center><p>\n";