diff --git a/.gitignore b/.gitignore
index 1e0cf7679..e043abc0c 100644
--- a/.gitignore
+++ b/.gitignore
@@ -9,9 +9,7 @@ core
*.cache
*.m4
*.fw
-*.fw.orig
*.conf
-*.conf.orig
*.app
*.icns
*.ico
diff --git a/src/res/platform/pix.xml b/src/res/platform/pix.xml
index 7a243b5c4..5b6b49cfe 100644
--- a/src/res/platform/pix.xml
+++ b/src/res/platform/pix.xml
@@ -10,7 +10,7 @@
fwb_pix_diff
pix_os
- 6.1,6.2,6.3,7.0
+ 6.1,6.2,6.3,7.0,8.0,8.3
@@ -340,6 +340,166 @@
+
+
+ true
+ true
+ true
+ true
+ true
+ false
+ true
+ 300
+ true
+ true
+ true
+ false
+ false
+ true
+ true
+
+
+ clear config access-list
+ clear config object-group
+ clear config icmp
+ clear config telnet
+ clear config ssh
+ clear xlate
+ clear config static
+ clear config global
+ clear config nat
+
+
+
+ 3
+ 0
+ 0
+
+ 1
+ 0
+ 0
+
+ 0
+ 2
+ 0
+
+ 0
+ 10
+ 0
+
+ 0
+ 5
+ 0
+
+ 0
+ 30
+ 0
+
+ 0
+ 2
+ 0
+
+ 0
+ 10
+ 0
+
+ 2
+ 0
+ 0
+ True
+ False
+
+ 5
+ 5
+
+
+
+ ctiqbe_fixup,dns_fixup,ftp_fixup,h323_h225_fixup,h323_ras_fixup,http_fixup,icmp_error_fixup,ils_fixup,mgcp_fixup,rsh_fixup,rtsp_fixup,sip_fixup,sip_udp_fixup,skinny_fixup,smtp_fixup,sqlnet_fixup,tftp_fixup
+ true
+
+
+
+
+
+ true
+ true
+ true
+ true
+ true
+ false
+ true
+ 300
+ true
+ true
+ true
+ false
+ false
+ true
+ true
+
+
+ clear config access-list
+ clear config object-group
+ clear config icmp
+ clear config telnet
+ clear config ssh
+ clear xlate
+ clear config static
+ clear config global
+ clear config nat
+
+
+
+ 3
+ 0
+ 0
+
+ 1
+ 0
+ 0
+
+ 0
+ 2
+ 0
+
+ 0
+ 10
+ 0
+
+ 0
+ 5
+ 0
+
+ 0
+ 30
+ 0
+
+ 0
+ 2
+ 0
+
+ 0
+ 10
+ 0
+
+ 2
+ 0
+ 0
+ True
+ False
+
+ 5
+ 5
+
+
+
+ ctiqbe_fixup,dns_fixup,ftp_fixup,h323_h225_fixup,h323_ras_fixup,http_fixup,icmp_error_fixup,ils_fixup,mgcp_fixup,rsh_fixup,rtsp_fixup,sip_fixup,sip_udp_fixup,skinny_fixup,smtp_fixup,sqlnet_fixup,tftp_fixup
+ true
+
+
+
+
+
diff --git a/test/iosacl/auto-interface-test.fw.orig b/test/iosacl/auto-interface-test.fw.orig
new file mode 100755
index 000000000..212f65d09
--- /dev/null
+++ b/test/iosacl/auto-interface-test.fw.orig
@@ -0,0 +1,253 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_iosacl v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:51:09 2011 PST by vadim
+!
+! Compiled for iosacl 12.1
+!
+!# files: * auto-interface-test.fw
+!
+! An example of Cisco router
+
+
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+! temporary access list for "safety net install"
+no ip access-list extended tmp_acl
+ip access-list extended tmp_acl
+ permit ip 192.168.1.1 0.0.0.0 any
+ deny ip any any
+exit
+interface FastEthernet0/0
+ no ip access-group in
+ no ip access-group out
+ ip access-group tmp_acl in
+exit
+
+! ================ IPv4
+
+
+no ip access-list extended e1_0_in
+no ip access-list extended e1_0_out
+no ip access-list extended e1_1_in
+no ip access-list extended e1_1_out
+no ip access-list extended fe0_0_in
+no ip access-list extended fe0_0_out
+
+
+ip access-list extended e1_0_in
+!
+! Rule 0 (global)
+ permit ip 10.1.1.0 0.0.0.255 any
+!
+! Rule 1 (global)
+ permit ip 10.1.1.0 0.0.0.255 any
+!
+! Rule 4 (global)
+ permit ip 10.1.0.0 0.0.255.255 any
+exit
+
+ip access-list extended e1_0_out
+!
+! Rule 0 (global)
+ permit ip 10.1.1.0 0.0.0.255 any
+!
+! Rule 2 (global)
+ permit ip 10.1.2.0 0.0.0.255 any
+!
+! Rule 3 (global)
+ permit ip 10.1.3.0 0.0.0.255 any
+!
+! Rule 4 (global)
+ permit ip 10.1.0.0 0.0.255.255 any
+exit
+
+ip access-list extended e1_1_in
+!
+! Rule 1 (global)
+ permit ip 10.1.1.0 0.0.0.255 any
+!
+! Rule 2 (global)
+ permit ip 10.1.2.0 0.0.0.255 any
+!
+! Rule 4 (global)
+ permit ip 10.1.0.0 0.0.255.255 any
+exit
+
+ip access-list extended e1_1_out
+!
+! Rule 0 (global)
+ permit ip 10.1.1.0 0.0.0.255 any
+!
+! Rule 2 (global)
+ permit ip 10.1.2.0 0.0.0.255 any
+!
+! Rule 3 (global)
+ permit ip 10.1.3.0 0.0.0.255 any
+!
+! Rule 4 (global)
+ permit ip 10.1.0.0 0.0.255.255 any
+exit
+
+ip access-list extended fe0_0_in
+!
+! Rule 1 (global)
+ permit ip 10.1.1.0 0.0.0.255 any
+!
+! Rule 3 (global)
+ permit ip 10.1.3.0 0.0.0.255 any
+!
+! Rule 4 (global)
+ permit ip 10.1.0.0 0.0.255.255 any
+exit
+
+ip access-list extended fe0_0_out
+!
+! Rule 0 (global)
+ permit ip 10.1.1.0 0.0.0.255 any
+!
+! Rule 2 (global)
+ permit ip 10.1.2.0 0.0.0.255 any
+!
+! Rule 3 (global)
+ permit ip 10.1.3.0 0.0.0.255 any
+!
+! Rule 4 (global)
+ permit ip 10.1.0.0 0.0.255.255 any
+exit
+
+
+interface Ethernet1/0
+ ip access-group e1_0_in in
+exit
+interface Ethernet1/0
+ ip access-group e1_0_out out
+exit
+interface Ethernet1/1
+ ip access-group e1_1_in in
+exit
+interface Ethernet1/1
+ ip access-group e1_1_out out
+exit
+interface FastEthernet0/0
+ ip access-group fe0_0_in in
+exit
+interface FastEthernet0/0
+ ip access-group fe0_0_out out
+exit
+
+
+
+! ================ IPv6
+
+
+no ipv6 access-list ipv6_Policy_v6_e1_0_in
+no ipv6 access-list ipv6_Policy_v6_e1_0_out
+no ipv6 access-list ipv6_Policy_v6_e1_1_in
+no ipv6 access-list ipv6_Policy_v6_e1_1_out
+no ipv6 access-list ipv6_Policy_v6_fe0_0_in
+no ipv6 access-list ipv6_Policy_v6_fe0_0_out
+
+
+ipv6 access-list ipv6_Policy_v6_e1_0_in
+!
+! Rule Policy_v6 0 (global)
+ permit ipv6 2001:1234:1::/64 any
+!
+! Rule Policy_v6 1 (global)
+ permit ipv6 2001:1234:1::/64 any
+!
+! Rule Policy_v6 4 (global)
+ permit ipv6 2001:1234::/48 any
+exit
+
+ipv6 access-list ipv6_Policy_v6_e1_0_out
+!
+! Rule Policy_v6 0 (global)
+ permit ipv6 2001:1234:1::/64 any
+!
+! Rule Policy_v6 2 (global)
+ permit ipv6 2001:1234:2::/64 any
+!
+! Rule Policy_v6 3 (global)
+ permit ipv6 2001:1234:3::/64 any
+!
+! Rule Policy_v6 4 (global)
+ permit ipv6 2001:1234::/48 any
+exit
+
+ipv6 access-list ipv6_Policy_v6_e1_1_in
+!
+! Rule Policy_v6 1 (global)
+ permit ipv6 2001:1234:1::/64 any
+!
+! Rule Policy_v6 2 (global)
+ permit ipv6 2001:1234:2::/64 any
+!
+! Rule Policy_v6 4 (global)
+ permit ipv6 2001:1234::/48 any
+exit
+
+ipv6 access-list ipv6_Policy_v6_e1_1_out
+!
+! Rule Policy_v6 0 (global)
+ permit ipv6 2001:1234:1::/64 any
+!
+! Rule Policy_v6 2 (global)
+ permit ipv6 2001:1234:2::/64 any
+!
+! Rule Policy_v6 3 (global)
+ permit ipv6 2001:1234:3::/64 any
+!
+! Rule Policy_v6 4 (global)
+ permit ipv6 2001:1234::/48 any
+exit
+
+ipv6 access-list ipv6_Policy_v6_fe0_0_in
+!
+! Rule Policy_v6 1 (global)
+ permit ipv6 2001:1234:1::/64 any
+!
+! Rule Policy_v6 3 (global)
+ permit ipv6 2001:1234:3::/64 any
+!
+! Rule Policy_v6 4 (global)
+ permit ipv6 2001:1234::/48 any
+exit
+
+ipv6 access-list ipv6_Policy_v6_fe0_0_out
+!
+! Rule Policy_v6 0 (global)
+ permit ipv6 2001:1234:1::/64 any
+!
+! Rule Policy_v6 2 (global)
+ permit ipv6 2001:1234:2::/64 any
+!
+! Rule Policy_v6 3 (global)
+ permit ipv6 2001:1234:3::/64 any
+!
+! Rule Policy_v6 4 (global)
+ permit ipv6 2001:1234::/48 any
+exit
+
+
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/iosacl/c3620.fw.orig b/test/iosacl/c3620.fw.orig
new file mode 100755
index 000000000..c5a451a50
--- /dev/null
+++ b/test/iosacl/c3620.fw.orig
@@ -0,0 +1,278 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_iosacl v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:51:09 2011 PST by vadim
+!
+! Compiled for iosacl 12.1
+!
+!# files: * c3620.fw
+!
+
+
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+no service timestamp log datetime localtime
+logging buffered 6
+logging console 6
+
+
+
+! ================ IPv4
+
+
+no ip access-list extended e1_0_in
+no ip access-list extended e1_0_out
+no ip access-list extended e1_1_in
+no ip access-list extended e1_1_out
+no ip access-list extended fe0_0_in
+no ip access-list extended fe0_0_out
+
+
+ip access-list extended e1_0_in
+!
+! Rule -1 backup ssh access rule (automatic)
+ remark -1 backup ssh access rule (automatic)
+ permit tcp host 10.3.14.41 host 0.0.0.0 eq 22
+ permit tcp host 10.3.14.41 host 0.0.0.0 eq 22
+ permit tcp host 10.3.14.41 host 0.0.0.0 eq 22
+ permit tcp host 10.3.14.41 host 10.3.14.201 eq 22
+ permit tcp host 10.3.14.41 host 192.168.171.2 eq 22
+!
+! Rule 1 (Ethernet1/0)
+ remark 1 (Ethernet1/0)
+ permit tcp any any eq 80
+!
+! Rule 2 (Ethernet1/0)
+ remark 2 (Ethernet1/0)
+ permit tcp any any eq 443
+!
+! Rule 5 (Ethernet1/0)
+ remark 5 (Ethernet1/0)
+ permit ip any 10.3.14.0 0.0.0.255
+!
+! Rule 7 (global)
+ remark 7 (global)
+ permit tcp any 10.3.14.0 0.0.0.255 established
+!
+! Rule 8 (global)
+ remark 8 (global)
+ permit tcp any 10.3.14.0 0.0.0.255 eq 22
+ permit udp any 10.3.14.0 0.0.0.255 eq 53
+ permit tcp any 10.3.14.0 0.0.0.255 established
+!
+! Rule 9 (global)
+ remark 9 (global)
+ permit tcp any 10.3.14.0 0.0.0.255 established
+!
+! Rule 10 (global)
+ remark 10 (global)
+ permit tcp any eq 80 10.3.14.0 0.0.0.255 established
+exit
+
+ip access-list extended e1_0_out
+!
+! Rule -2 backup ssh access rule (out) (automatic)
+ remark -2 backup ssh access rule (out) (automatic)
+ permit tcp host 0.0.0.0 eq 22 host 10.3.14.41
+ permit tcp host 0.0.0.0 eq 22 host 10.3.14.41
+ permit tcp host 0.0.0.0 eq 22 host 10.3.14.41
+ permit tcp host 10.3.14.201 eq 22 host 10.3.14.41
+ permit tcp host 192.168.171.2 eq 22 host 10.3.14.41
+!
+! Rule 1 (Ethernet1/0)
+ remark 1 (Ethernet1/0)
+ permit tcp any any eq 80
+!
+! Rule 2 (Ethernet1/0)
+ remark 2 (Ethernet1/0)
+ permit tcp any any eq 443
+!
+! Rule 4 (Ethernet1/0)
+ remark 4 (Ethernet1/0)
+ permit ip 10.3.14.0 0.0.0.255 any
+exit
+
+ip access-list extended e1_1_in
+!
+! Rule -1 backup ssh access rule (automatic)
+ remark -1 backup ssh access rule (automatic)
+ permit tcp host 10.3.14.41 host 0.0.0.0 eq 22
+ permit tcp host 10.3.14.41 host 0.0.0.0 eq 22
+ permit tcp host 10.3.14.41 host 0.0.0.0 eq 22
+ permit tcp host 10.3.14.41 host 10.3.14.201 eq 22
+ permit tcp host 10.3.14.41 host 192.168.171.2 eq 22
+!
+! Rule 0 (Ethernet1/1)
+! interface eth 1/1 has only
+! inbound access list
+ remark 0 (Ethernet1/1)
+ remark interface eth 1/1 has only
+ remark inbound access list
+ permit tcp any any eq 80
+!
+! Rule 7 (global)
+ remark 7 (global)
+ permit tcp any 10.3.14.0 0.0.0.255 established
+!
+! Rule 8 (global)
+ remark 8 (global)
+ permit tcp any 10.3.14.0 0.0.0.255 eq 22
+ permit udp any 10.3.14.0 0.0.0.255 eq 53
+ permit tcp any 10.3.14.0 0.0.0.255 established
+!
+! Rule 9 (global)
+ remark 9 (global)
+ permit tcp any 10.3.14.0 0.0.0.255 established
+!
+! Rule 10 (global)
+ remark 10 (global)
+ permit tcp any eq 80 10.3.14.0 0.0.0.255 established
+exit
+
+ip access-list extended e1_1_out
+!
+! Rule -2 backup ssh access rule (out) (automatic)
+ remark -2 backup ssh access rule (out) (automatic)
+ permit tcp host 0.0.0.0 eq 22 host 10.3.14.41
+ permit tcp host 0.0.0.0 eq 22 host 10.3.14.41
+ permit tcp host 0.0.0.0 eq 22 host 10.3.14.41
+ permit tcp host 10.3.14.201 eq 22 host 10.3.14.41
+ permit tcp host 192.168.171.2 eq 22 host 10.3.14.41
+exit
+
+ip access-list extended fe0_0_in
+!
+! Rule -1 backup ssh access rule (automatic)
+ remark -1 backup ssh access rule (automatic)
+ permit tcp host 10.3.14.41 host 0.0.0.0 eq 22
+ permit tcp host 10.3.14.41 host 0.0.0.0 eq 22
+ permit tcp host 10.3.14.41 host 0.0.0.0 eq 22
+ permit tcp host 10.3.14.41 host 10.3.14.201 eq 22
+ permit tcp host 10.3.14.41 host 192.168.171.2 eq 22
+!
+! Rule 3 (FastEthernet0/0)
+ remark 3 (FastEthernet0/0)
+ permit ip 10.3.14.0 0.0.0.255 any
+!
+! Rule 7 (global)
+ remark 7 (global)
+ permit tcp any 10.3.14.0 0.0.0.255 established
+!
+! Rule 8 (global)
+ remark 8 (global)
+ permit tcp any 10.3.14.0 0.0.0.255 eq 22
+ permit udp any 10.3.14.0 0.0.0.255 eq 53
+ permit tcp any 10.3.14.0 0.0.0.255 established
+!
+! Rule 9 (global)
+ remark 9 (global)
+ permit tcp any 10.3.14.0 0.0.0.255 established
+!
+! Rule 10 (global)
+ remark 10 (global)
+ permit tcp any eq 80 10.3.14.0 0.0.0.255 established
+exit
+
+ip access-list extended fe0_0_out
+!
+! Rule -2 backup ssh access rule (out) (automatic)
+ remark -2 backup ssh access rule (out) (automatic)
+ permit tcp host 0.0.0.0 eq 22 host 10.3.14.41
+ permit tcp host 0.0.0.0 eq 22 host 10.3.14.41
+ permit tcp host 0.0.0.0 eq 22 host 10.3.14.41
+ permit tcp host 10.3.14.201 eq 22 host 10.3.14.41
+ permit tcp host 192.168.171.2 eq 22 host 10.3.14.41
+!
+! Rule 6 (FastEthernet0/0)
+ remark 6 (FastEthernet0/0)
+ permit ip any 10.3.14.0 0.0.0.255
+!
+! Rule 7 (global)
+ remark 7 (global)
+ permit tcp any 10.3.14.0 0.0.0.255 established
+!
+! Rule 8 (global)
+ remark 8 (global)
+ permit tcp any 10.3.14.0 0.0.0.255 eq 22
+ permit udp any 10.3.14.0 0.0.0.255 eq 53
+ permit tcp any 10.3.14.0 0.0.0.255 established
+!
+! Rule 9 (global)
+ remark 9 (global)
+ permit tcp any 10.3.14.0 0.0.0.255 established
+!
+! Rule 10 (global)
+ remark 10 (global)
+ permit tcp any eq 80 10.3.14.0 0.0.0.255 established
+exit
+
+
+interface Ethernet1/0
+ ip access-group e1_0_in in
+exit
+interface Ethernet1/0
+ ip access-group e1_0_out out
+exit
+interface Ethernet1/1
+ ip access-group e1_1_in in
+exit
+interface Ethernet1/1
+ ip access-group e1_1_out out
+exit
+interface FastEthernet0/0
+ ip access-group fe0_0_in in
+exit
+interface FastEthernet0/0
+ ip access-group fe0_0_out out
+exit
+
+
+
+!
+! Rule 0 (main)
+!
+! "Routing rule 0 (main)"
+!
+!
+!
+ip route 10.10.10.0 255.255.255.0 10.3.14.254 1
+!
+! Rule 1 (main)
+!
+! "Routing rule 1 (main)"
+!
+!
+!
+ip route 10.10.11.0 255.255.255.0 FastEthernet0/0 1
+!
+! Rule 2 (main)
+!
+! "Routing rule 2 (main)"
+!
+!
+!
+ip route 10.10.12.0 255.255.255.0 FastEthernet0/0 1
+!
+! Rule 3 (main)
+!
+! "Routing rule 3 (main)"
+!
+!
+!
+ip route 0.0.0.0 0.0.0.0 Ethernet1/0 1
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/iosacl/ccie4u-r1.fw.orig b/test/iosacl/ccie4u-r1.fw.orig
new file mode 100755
index 000000000..a474d3048
--- /dev/null
+++ b/test/iosacl/ccie4u-r1.fw.orig
@@ -0,0 +1,393 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_iosacl v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:51:10 2011 PST by vadim
+!
+! Compiled for iosacl 12.1
+!
+!# files: * ccie4u-r1.fw
+!
+! CCIE4U router R1
+! 2600
+
+! ccie4u-r1:r1-ipv6:1: error: Rule 'r1-ipv6 1 (global)' shadows rule 'r1-ipv6 3 (global)' below it
+! ccie4u-r1:r1-ipv6:1: error: Rule 'r1-ipv6 1 (global)' shadows rule 'r1-ipv6 4 (global)' below it
+! ccie4u-r1:r1-ipv6:3: error: Rule 'r1-ipv6 3 (global)' shadows rule 'r1-ipv6 4 (global)' below it
+! ccie4u-r1:r1-ipv6:1: error: Rule 'r1-ipv6 1 (global)' shadows rule 'r1-ipv6 5 (global)' below it
+! ccie4u-r1:r1-ipv6:3: error: Rule 'r1-ipv6 3 (global)' shadows rule 'r1-ipv6 5 (global)' below it
+! ccie4u-r1:r1-ipv6:2: error: Rule 'r1-ipv6 2 (global)' shadows rule 'r1-ipv6 5 (global)' below it
+! ccie4u-r1:r1-ipv6:1: error: Rule 'r1-ipv6 1 (global)' shadows rule 'r1-ipv6 6 (global)' below it
+! ccie4u-r1:r1-ipv6:2: error: Rule 'r1-ipv6 2 (global)' shadows rule 'r1-ipv6 6 (global)' below it
+! ccie4u-r1:r1-ipv6:9: error: Rule 'r1-ipv6 9 (global)' shadows rule 'r1-ipv6 10 (global)' below it
+! ccie4u-r1:r1-ipv6:9: error: Rule 'r1-ipv6 9 (global)' shadows rule 'r1-ipv6 10 (global)' below it
+! ccie4u-r1:r1-ipv6:9: error: Rule 'r1-ipv6 9 (global)' shadows rule 'r1-ipv6 11 (global)' below it
+! ccie4u-r1:r1-ipv6:9: error: Rule 'r1-ipv6 9 (global)' shadows rule 'r1-ipv6 11 (global)' below it
+! ccie4u-r1:r1-ipv6:9: error: Rule 'r1-ipv6 9 (global)' shadows rule 'r1-ipv6 11 (global)' below it
+! ccie4u-r1:r1-ipv6:9: error: Rule 'r1-ipv6 9 (global)' shadows rule 'r1-ipv6 11 (global)' below it
+! ccie4u-r1:r1-ipv6:9: error: Rule 'r1-ipv6 9 (global)' shadows rule 'r1-ipv6 12 (global)' below it
+! ccie4u-r1:r1-ipv6:9: error: Rule 'r1-ipv6 9 (global)' shadows rule 'r1-ipv6 12 (global)' below it
+! ccie4u-r1:r1-ipv6:9: error: Rule 'r1-ipv6 9 (global)' shadows rule 'r1-ipv6 13 (global)' below it
+! ccie4u-r1:r1-ipv6:1: error: Rule 'r1-ipv6 1 (global)' shadows rule 'r1-ipv6 13 (global)' below it
+! ccie4u-r1:r1-ipv6:9: error: Rule 'r1-ipv6 9 (global)' shadows rule 'r1-ipv6 13 (global)' below it
+! ccie4u-r1:r1-ipv6:9: error: Rule 'r1-ipv6 9 (global)' shadows rule 'r1-ipv6 13 (global)' below it
+! ccie4u-r1:r1-ipv6:9: error: Rule 'r1-ipv6 9 (global)' shadows rule 'r1-ipv6 13 (global)' below it
+! ccie4u-r1:r1-ipv6:9: error: Rule 'r1-ipv6 9 (global)' shadows rule 'r1-ipv6 13 (global)' below it
+! ccie4u-r1:r1-ipv6:3: error: Rule 'r1-ipv6 3 (global)' shadows rule 'r1-ipv6 13 (global)' below it
+! ccie4u-r1:r1-ipv6:9: error: Rule 'r1-ipv6 9 (global)' shadows rule 'r1-ipv6 13 (global)' below it
+! ccie4u-r1:r1-ipv6:9: error: Rule 'r1-ipv6 9 (global)' shadows rule 'r1-ipv6 13 (global)' below it
+! ccie4u-r1:r1-ipv6:9: error: Rule 'r1-ipv6 9 (global)' shadows rule 'r1-ipv6 13 (global)' below it
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+! temporary access list for "safety net install"
+no ip access-list extended tmp_acl
+ip access-list extended tmp_acl
+ permit ip 10.1.1.0 0.0.0.0 any
+ deny ip any any
+exit
+interface FastEthernet0/0
+ no ip access-group in
+ no ip access-group out
+ ip access-group tmp_acl in
+exit
+
+! ================ IPv4
+
+
+no ip access-list extended r1-ipv4_fe0_0_in
+no ip access-list extended r1-ipv4_fe0_0_out
+no ip access-list extended r1-ipv4_fe0_1_in
+no ip access-list extended r1-ipv4_fe0_1_out
+
+
+ip access-list extended r1-ipv4_fe0_0_in
+!
+! Rule -1 backup ssh access rule (automatic)
+ permit tcp host 10.1.1.100 host 10.1.1.1 eq 22
+ permit tcp host 10.1.1.100 host 10.1.2.1 eq 22
+!
+! Rule r1-ipv4 1 (global)
+ permit icmp any host 61.150.47.112 8
+ permit icmp any host 192.168.1.0 8
+ permit 50 any host 61.150.47.112 dscp af12
+ permit 50 any host 192.168.1.0 dscp af12
+!
+! Rule r1-ipv4 2 (global)
+ permit icmp host 61.150.47.112 any 8
+ permit icmp host 192.168.1.0 any 8
+exit
+
+ip access-list extended r1-ipv4_fe0_0_out
+!
+! Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 10.1.1.1 eq 22 host 10.1.1.100
+ permit tcp host 10.1.2.1 eq 22 host 10.1.1.100
+!
+! Rule r1-ipv4 1 (global)
+ permit icmp any host 61.150.47.112 8
+ permit icmp any host 192.168.1.0 8
+ permit 50 any host 61.150.47.112 dscp af12
+ permit 50 any host 192.168.1.0 dscp af12
+!
+! Rule r1-ipv4 2 (global)
+ permit icmp host 61.150.47.112 any 8
+ permit icmp host 192.168.1.0 any 8
+exit
+
+ip access-list extended r1-ipv4_fe0_1_in
+!
+! Rule -1 backup ssh access rule (automatic)
+ permit tcp host 10.1.1.100 host 10.1.1.1 eq 22
+ permit tcp host 10.1.1.100 host 10.1.2.1 eq 22
+!
+! Rule r1-ipv4 1 (global)
+ permit icmp any host 61.150.47.112 8
+ permit icmp any host 192.168.1.0 8
+ permit 50 any host 61.150.47.112 dscp af12
+ permit 50 any host 192.168.1.0 dscp af12
+!
+! Rule r1-ipv4 2 (global)
+ permit icmp host 61.150.47.112 any 8
+ permit icmp host 192.168.1.0 any 8
+exit
+
+ip access-list extended r1-ipv4_fe0_1_out
+!
+! Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 10.1.1.1 eq 22 host 10.1.1.100
+ permit tcp host 10.1.2.1 eq 22 host 10.1.1.100
+!
+! Rule r1-ipv4 1 (global)
+ permit icmp any host 61.150.47.112 8
+ permit icmp any host 192.168.1.0 8
+ permit 50 any host 61.150.47.112 dscp af12
+ permit 50 any host 192.168.1.0 dscp af12
+!
+! Rule r1-ipv4 2 (global)
+ permit icmp host 61.150.47.112 any 8
+ permit icmp host 192.168.1.0 any 8
+exit
+
+
+
+
+
+! ================ IPv6
+
+
+no ipv6 access-list ipv6_fe0_0_in
+no ipv6 access-list ipv6_fe0_0_out
+no ipv6 access-list ipv6_fe0_1_in
+no ipv6 access-list ipv6_fe0_1_out
+
+
+ipv6 access-list ipv6_fe0_0_in
+!
+! Rule r1-ipv6 0 (global)
+ permit tcp fe80::/64 any eq 22
+!
+! Rule r1-ipv6 1 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22
+!
+! Rule r1-ipv6 2 (global)
+ permit tcp host 3ffe:1200:2001:1:8000::1 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+!
+! Rule r1-ipv6 3 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22 log
+ permit tcp 3ffe:1200:2000::/36 any eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22 log
+!
+! Rule r1-ipv6 4 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22 log
+!
+! Rule r1-ipv6 5 (global)
+ permit tcp host 2001:5c0:0:2::24 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+ permit tcp 3ffe:1200:2000::/36 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+!
+! Rule r1-ipv6 6 (global)
+ permit tcp host 2001:5c0:0:2::24 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+!
+! Rule r1-ipv6 7 (global)
+ permit ipv6 any host fe80::21d:9ff:fe8b:8e94 log
+!
+! Rule r1-ipv6 8 (global)
+ permit ipv6 fe80::/64 any log
+!
+! Rule r1-ipv6 9 (global)
+ permit ipv6 host 2001:5c0:0:2::24 any log
+ permit ipv6 3ffe:1200:2000::/36 any log
+ permit ipv6 host 3ffe:1200:2001:1:8000::1 any log
+!
+! Rule r1-ipv6 10 (global)
+ permit ipv6 host 2001:5c0:0:2::24 any log
+ permit ipv6 host 3ffe:1200:2001:1:8000::1 any log
+!
+! Rule r1-ipv6 11 (global)
+ permit 50 host 2001:5c0:0:2::24 any dscp af11
+ permit 50 host 3ffe:1200:2001:1:8000::1 any dscp af11
+!
+! Rule r1-ipv6 12 (global)
+ permit tcp host 2001:5c0:0:2::24 any established
+ permit tcp host 3ffe:1200:2001:1:8000::1 any established
+!
+! Rule r1-ipv6 13 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22
+ permit udp host 2001:5c0:0:2::24 any eq 161
+ permit udp host 3ffe:1200:2001:1:8000::1 any eq 161
+ permit icmp host 2001:5c0:0:2::24 any 128
+ permit icmp host 3ffe:1200:2001:1:8000::1 any 128
+ permit tcp host 2001:5c0:0:2::24 any established
+ permit tcp host 3ffe:1200:2001:1:8000::1 any established
+exit
+
+ipv6 access-list ipv6_fe0_0_out
+!
+! Rule r1-ipv6 0 (global)
+ permit tcp fe80::/64 any eq 22
+!
+! Rule r1-ipv6 1 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22
+!
+! Rule r1-ipv6 3 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22 log
+ permit tcp 3ffe:1200:2000::/36 any eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22 log
+!
+! Rule r1-ipv6 4 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22 log
+!
+! Rule r1-ipv6 8 (global)
+ permit ipv6 fe80::/64 any log
+!
+! Rule r1-ipv6 9 (global)
+ permit ipv6 host 2001:5c0:0:2::24 any log
+ permit ipv6 3ffe:1200:2000::/36 any log
+ permit ipv6 host 3ffe:1200:2001:1:8000::1 any log
+!
+! Rule r1-ipv6 10 (global)
+ permit ipv6 host 2001:5c0:0:2::24 any log
+ permit ipv6 host 3ffe:1200:2001:1:8000::1 any log
+!
+! Rule r1-ipv6 11 (global)
+ permit 50 host 2001:5c0:0:2::24 any dscp af11
+ permit 50 host 3ffe:1200:2001:1:8000::1 any dscp af11
+!
+! Rule r1-ipv6 12 (global)
+ permit tcp host 2001:5c0:0:2::24 any established
+ permit tcp host 3ffe:1200:2001:1:8000::1 any established
+!
+! Rule r1-ipv6 13 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22
+ permit udp host 2001:5c0:0:2::24 any eq 161
+ permit udp host 3ffe:1200:2001:1:8000::1 any eq 161
+ permit icmp host 2001:5c0:0:2::24 any 128
+ permit icmp host 3ffe:1200:2001:1:8000::1 any 128
+ permit tcp host 2001:5c0:0:2::24 any established
+ permit tcp host 3ffe:1200:2001:1:8000::1 any established
+exit
+
+ipv6 access-list ipv6_fe0_1_in
+!
+! Rule r1-ipv6 1 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22
+!
+! Rule r1-ipv6 2 (global)
+ permit tcp host 3ffe:1200:2001:1:8000::1 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+!
+! Rule r1-ipv6 3 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22 log
+ permit tcp 3ffe:1200:2000::/36 any eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22 log
+!
+! Rule r1-ipv6 4 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22 log
+!
+! Rule r1-ipv6 5 (global)
+ permit tcp host 2001:5c0:0:2::24 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+ permit tcp 3ffe:1200:2000::/36 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+!
+! Rule r1-ipv6 6 (global)
+ permit tcp host 2001:5c0:0:2::24 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+!
+! Rule r1-ipv6 7 (global)
+ permit ipv6 any host fe80::21d:9ff:fe8b:8e94 log
+!
+! Rule r1-ipv6 9 (global)
+ permit ipv6 host 2001:5c0:0:2::24 any log
+ permit ipv6 3ffe:1200:2000::/36 any log
+ permit ipv6 host 3ffe:1200:2001:1:8000::1 any log
+!
+! Rule r1-ipv6 10 (global)
+ permit ipv6 host 2001:5c0:0:2::24 any log
+ permit ipv6 host 3ffe:1200:2001:1:8000::1 any log
+!
+! Rule r1-ipv6 11 (global)
+ permit 50 host 2001:5c0:0:2::24 any dscp af11
+ permit 50 host 3ffe:1200:2001:1:8000::1 any dscp af11
+!
+! Rule r1-ipv6 12 (global)
+ permit tcp host 2001:5c0:0:2::24 any established
+ permit tcp host 3ffe:1200:2001:1:8000::1 any established
+!
+! Rule r1-ipv6 13 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22
+ permit udp host 2001:5c0:0:2::24 any eq 161
+ permit udp host 3ffe:1200:2001:1:8000::1 any eq 161
+ permit icmp host 2001:5c0:0:2::24 any 128
+ permit icmp host 3ffe:1200:2001:1:8000::1 any 128
+ permit tcp host 2001:5c0:0:2::24 any established
+ permit tcp host 3ffe:1200:2001:1:8000::1 any established
+exit
+
+ipv6 access-list ipv6_fe0_1_out
+!
+! Rule r1-ipv6 0 (global)
+ permit tcp fe80::/64 any eq 22
+!
+! Rule r1-ipv6 1 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22
+!
+! Rule r1-ipv6 3 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22 log
+ permit tcp 3ffe:1200:2000::/36 any eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22 log
+!
+! Rule r1-ipv6 4 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22 log
+!
+! Rule r1-ipv6 8 (global)
+ permit ipv6 fe80::/64 any log
+!
+! Rule r1-ipv6 9 (global)
+ permit ipv6 host 2001:5c0:0:2::24 any log
+ permit ipv6 3ffe:1200:2000::/36 any log
+ permit ipv6 host 3ffe:1200:2001:1:8000::1 any log
+!
+! Rule r1-ipv6 10 (global)
+ permit ipv6 host 2001:5c0:0:2::24 any log
+ permit ipv6 host 3ffe:1200:2001:1:8000::1 any log
+!
+! Rule r1-ipv6 11 (global)
+ permit 50 host 2001:5c0:0:2::24 any dscp af11
+ permit 50 host 3ffe:1200:2001:1:8000::1 any dscp af11
+!
+! Rule r1-ipv6 12 (global)
+ permit tcp host 2001:5c0:0:2::24 any established
+ permit tcp host 3ffe:1200:2001:1:8000::1 any established
+!
+! Rule r1-ipv6 13 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22
+ permit udp host 2001:5c0:0:2::24 any eq 161
+ permit udp host 3ffe:1200:2001:1:8000::1 any eq 161
+ permit icmp host 2001:5c0:0:2::24 any 128
+ permit icmp host 3ffe:1200:2001:1:8000::1 any 128
+ permit tcp host 2001:5c0:0:2::24 any established
+ permit tcp host 3ffe:1200:2001:1:8000::1 any established
+exit
+
+
+interface FastEthernet0/0
+ ipv6 traffic-filter ipv6_fe0_0_in in
+exit
+interface FastEthernet0/0
+ ipv6 traffic-filter ipv6_fe0_0_out out
+exit
+interface FastEthernet0/1
+ ipv6 traffic-filter ipv6_fe0_1_in in
+exit
+interface FastEthernet0/1
+ ipv6 traffic-filter ipv6_fe0_1_out out
+exit
+
+
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/iosacl/dynamips1-og.fw.orig b/test/iosacl/dynamips1-og.fw.orig
new file mode 100755
index 000000000..37f73c598
--- /dev/null
+++ b/test/iosacl/dynamips1-og.fw.orig
@@ -0,0 +1,194 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_iosacl v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:51:10 2011 PST by vadim
+!
+! Compiled for iosacl 12.4
+!
+!# files: * dynamips1-og.fw
+!
+! IOS 12.4 with object-groups
+
+
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+
+! ================ IPv4
+
+
+no ip access-list extended fe0_0_in
+no ip access-list extended fe0_0_out
+
+no object-group network id29216X37699.src.net.0
+no object-group service id29216X37699.srv.udp.0
+no object-group network id18740X37673.dst.net.0
+no object-group network id18964X37673.src.net.0
+
+
+object-group network id29216X37699.src.net.0
+ host 61.150.47.112
+ host 192.168.1.0
+exit
+
+
+object-group service id29216X37699.srv.udp.0
+ udp eq 161
+ udp range 1024 65535
+exit
+
+
+object-group network id18740X37673.dst.net.0
+ 10.3.14.0 /24
+ host 192.0.2.1
+ host 192.0.2.2
+ host 192.0.2.3
+exit
+
+
+object-group network id18964X37673.src.net.0
+ host 192.0.2.1
+ host 192.0.2.2
+ host 192.0.2.3
+exit
+
+ip access-list extended fe0_0_in
+!
+! Rule -1 backup ssh access rule (automatic)
+ permit tcp 10.3.14.0 0.0.0.255 host 10.3.14.114 eq 22
+!
+! Rule 1 (FastEthernet0/0)
+! object-groups can not be used for ipv6
+ permit icmp object-group id29216X37699.src.net.0 host 10.3.14.114 8
+ permit object-group id29216X37699.srv.udp.0 object-group id29216X37699.src.net.0 host 10.3.14.114
+!
+! Rule 2 (FastEthernet0/0)
+ permit icmp any object-group id18740X37673.dst.net.0 8
+ permit object-group id29216X37699.srv.udp.0 any object-group id18740X37673.dst.net.0
+!
+! Rule 3 (FastEthernet0/0)
+ permit icmp any object-group id18740X37673.dst.net.0 8 log
+ permit udp any object-group id18740X37673.dst.net.0 eq 161 log
+!
+! Rule 4 (FastEthernet0/0)
+ permit icmp any host 10.3.14.40 8 log
+ permit object-group id29216X37699.srv.udp.0 any host 10.3.14.40 log
+!
+! Rule 5 (FastEthernet0/0)
+ permit icmp any 10.3.14.0 0.0.0.255 8 log
+ permit object-group id29216X37699.srv.udp.0 any 10.3.14.0 0.0.0.255 log
+!
+! Rule 6 (global)
+ permit icmp object-group id18740X37673.dst.net.0 any 8 log
+ permit object-group id29216X37699.srv.udp.0 object-group id18740X37673.dst.net.0 any log
+!
+! Rule 7 (global)
+ permit icmp object-group id18740X37673.dst.net.0 any 8 log
+ permit object-group id29216X37699.srv.udp.0 object-group id18740X37673.dst.net.0 any log
+!
+! Rule 8 (global)
+ permit icmp host 10.3.14.40 any 8 log
+ permit object-group id29216X37699.srv.udp.0 host 10.3.14.40 any log
+!
+! Rule 9 (FastEthernet0/0)
+ permit udp object-group id18964X37673.src.net.0 any eq 161
+!
+! Rule 10 (FastEthernet0/0)
+ permit object-group id29216X37699.srv.udp.0 object-group id18964X37673.src.net.0 any
+!
+! Rule 11 (global)
+ deny ip 10.3.14.0 0.0.0.255 any log
+!
+! Rule 12 (global)
+ permit ip any host 10.3.14.114
+exit
+
+ip access-list extended fe0_0_out
+!
+! Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 10.3.14.114 eq 22 10.3.14.0 0.0.0.255
+!
+! Rule 0 (FastEthernet0/0)
+ permit ip host 10.3.14.114 any
+!
+! Rule 6 (global)
+ permit icmp object-group id18740X37673.dst.net.0 any 8 log
+ permit object-group id29216X37699.srv.udp.0 object-group id18740X37673.dst.net.0 any log
+!
+! Rule 7 (global)
+ permit icmp object-group id18740X37673.dst.net.0 any 8 log
+ permit object-group id29216X37699.srv.udp.0 object-group id18740X37673.dst.net.0 any log
+!
+! Rule 8 (global)
+ permit icmp host 10.3.14.40 any 8 log
+ permit object-group id29216X37699.srv.udp.0 host 10.3.14.40 any log
+!
+! Rule 11 (global)
+ deny ip 10.3.14.0 0.0.0.255 any log
+exit
+
+
+interface FastEthernet0/0
+ ip access-group fe0_0_in in
+exit
+interface FastEthernet0/0
+ ip access-group fe0_0_out out
+exit
+
+
+
+! ================ IPv6
+
+
+no ipv6 access-list ipv6_fe0_0_in
+no ipv6 access-list ipv6_fe0_0_out
+
+
+ipv6 access-list ipv6_fe0_0_in
+!
+! Rule 1 (FastEthernet0/0)
+! object-groups can not be used for ipv6
+ permit udp host 2001:5c0:0:2::24 host fe80::21d:9ff:fe8b:8e94 eq 161
+ permit udp host 2001:5c0:0:2::24 host fe80::21d:9ff:fe8b:8e94 gt 1024
+ permit udp host 3ffe:1200:2001:1:8000::1 host fe80::21d:9ff:fe8b:8e94 eq 161
+ permit udp host 3ffe:1200:2001:1:8000::1 host fe80::21d:9ff:fe8b:8e94 gt 1024
+!
+! Rule 12 (global)
+ permit ipv6 any host fe80::21d:9ff:fe8b:8e94
+exit
+
+ipv6 access-list ipv6_fe0_0_out
+!
+! Rule 0 (FastEthernet0/0)
+ permit ipv6 host fe80::21d:9ff:fe8b:8e94 any
+exit
+
+
+interface FastEthernet0/0
+ ipv6 traffic-filter ipv6_fe0_0_in in
+exit
+interface FastEthernet0/0
+ ipv6 traffic-filter ipv6_fe0_0_out out
+exit
+
+
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/iosacl/firewall-ipv6-1.fw.orig b/test/iosacl/firewall-ipv6-1.fw.orig
new file mode 100755
index 000000000..c6759dbdd
--- /dev/null
+++ b/test/iosacl/firewall-ipv6-1.fw.orig
@@ -0,0 +1,221 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_iosacl v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:51:10 2011 PST by vadim
+!
+! Compiled for iosacl 12.1
+!
+!# files: * firewall-ipv6-1.fw
+!
+
+! firewall-ipv6-1:fw-ipv6-1-ipv6:1: error: Rule 'fw-ipv6-1-ipv6 1 (global)' shadows rule 'fw-ipv6-1-ipv6 3 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:1: error: Rule 'fw-ipv6-1-ipv6 1 (global)' shadows rule 'fw-ipv6-1-ipv6 4 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:3: error: Rule 'fw-ipv6-1-ipv6 3 (global)' shadows rule 'fw-ipv6-1-ipv6 4 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:1: error: Rule 'fw-ipv6-1-ipv6 1 (global)' shadows rule 'fw-ipv6-1-ipv6 5 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:3: error: Rule 'fw-ipv6-1-ipv6 3 (global)' shadows rule 'fw-ipv6-1-ipv6 5 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:2: error: Rule 'fw-ipv6-1-ipv6 2 (global)' shadows rule 'fw-ipv6-1-ipv6 5 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:1: error: Rule 'fw-ipv6-1-ipv6 1 (global)' shadows rule 'fw-ipv6-1-ipv6 6 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:2: error: Rule 'fw-ipv6-1-ipv6 2 (global)' shadows rule 'fw-ipv6-1-ipv6 6 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:9: error: Rule 'fw-ipv6-1-ipv6 9 (global)' shadows rule 'fw-ipv6-1-ipv6 10 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:9: error: Rule 'fw-ipv6-1-ipv6 9 (global)' shadows rule 'fw-ipv6-1-ipv6 10 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:9: error: Rule 'fw-ipv6-1-ipv6 9 (global)' shadows rule 'fw-ipv6-1-ipv6 11 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:9: error: Rule 'fw-ipv6-1-ipv6 9 (global)' shadows rule 'fw-ipv6-1-ipv6 11 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:9: error: Rule 'fw-ipv6-1-ipv6 9 (global)' shadows rule 'fw-ipv6-1-ipv6 11 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:9: error: Rule 'fw-ipv6-1-ipv6 9 (global)' shadows rule 'fw-ipv6-1-ipv6 11 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:9: error: Rule 'fw-ipv6-1-ipv6 9 (global)' shadows rule 'fw-ipv6-1-ipv6 12 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:9: error: Rule 'fw-ipv6-1-ipv6 9 (global)' shadows rule 'fw-ipv6-1-ipv6 12 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:9: error: Rule 'fw-ipv6-1-ipv6 9 (global)' shadows rule 'fw-ipv6-1-ipv6 13 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:1: error: Rule 'fw-ipv6-1-ipv6 1 (global)' shadows rule 'fw-ipv6-1-ipv6 13 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:9: error: Rule 'fw-ipv6-1-ipv6 9 (global)' shadows rule 'fw-ipv6-1-ipv6 13 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:9: error: Rule 'fw-ipv6-1-ipv6 9 (global)' shadows rule 'fw-ipv6-1-ipv6 13 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:9: error: Rule 'fw-ipv6-1-ipv6 9 (global)' shadows rule 'fw-ipv6-1-ipv6 13 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:9: error: Rule 'fw-ipv6-1-ipv6 9 (global)' shadows rule 'fw-ipv6-1-ipv6 13 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:3: error: Rule 'fw-ipv6-1-ipv6 3 (global)' shadows rule 'fw-ipv6-1-ipv6 13 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:9: error: Rule 'fw-ipv6-1-ipv6 9 (global)' shadows rule 'fw-ipv6-1-ipv6 13 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:9: error: Rule 'fw-ipv6-1-ipv6 9 (global)' shadows rule 'fw-ipv6-1-ipv6 13 (global)' below it
+! firewall-ipv6-1:fw-ipv6-1-ipv6:9: error: Rule 'fw-ipv6-1-ipv6 9 (global)' shadows rule 'fw-ipv6-1-ipv6 13 (global)' below it
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+! temporary access list for "safety net install"
+no ipv6 access-list tmp_acl
+ipv6 access-list tmp_acl
+ permit ipv6 host fe80::21d:9ff:aaaa:bbbb any
+ permit icmp any any
+ deny ipv6 any any
+exit
+interface Ethernet0/0
+ no ipv6 traffic-filter in
+ no ipv6 traffic-filter out
+ ipv6 traffic-filter tmp_acl in
+exit
+
+! ================ IPv4
+
+
+no ip access-list extended fw-ipv6-1-ipv4_e0_0_in
+no ip access-list extended fw-ipv6-1-ipv4_e0_0_out
+
+
+ip access-list extended fw-ipv6-1-ipv4_e0_0_in
+!
+! Rule fw-ipv6-1-ipv4 1 (global)
+ permit 50 host 61.150.47.112 any dscp af12
+ permit 50 host 192.168.1.0 any dscp af12
+exit
+
+ip access-list extended fw-ipv6-1-ipv4_e0_0_out
+ permit 50 host 61.150.47.112 any dscp af12
+ permit 50 host 192.168.1.0 any dscp af12
+exit
+
+
+
+
+
+! ================ IPv6
+
+
+no ipv6 access-list ipv6_e0_0_in
+no ipv6 access-list ipv6_e0_0_out
+
+
+ipv6 access-list ipv6_e0_0_in
+!
+! Rule fw-ipv6-1-ipv6 0 (global)
+ permit tcp fe80::/64 any eq 22
+!
+! Rule fw-ipv6-1-ipv6 1 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22
+!
+! Rule fw-ipv6-1-ipv6 2 (global)
+ permit tcp host 3ffe:1200:2001:1:8000::1 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+!
+! Rule fw-ipv6-1-ipv6 3 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22 log
+ permit tcp 3ffe:1200:2000::/36 any eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22 log
+!
+! Rule fw-ipv6-1-ipv6 4 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22 log
+!
+! Rule fw-ipv6-1-ipv6 5 (global)
+ permit tcp host 2001:5c0:0:2::24 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+ permit tcp 3ffe:1200:2000::/36 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+!
+! Rule fw-ipv6-1-ipv6 6 (global)
+ permit tcp host 2001:5c0:0:2::24 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+!
+! Rule fw-ipv6-1-ipv6 7 (global)
+ permit ipv6 any host fe80::21d:9ff:fe8b:8e94 log
+!
+! Rule fw-ipv6-1-ipv6 8 (global)
+ permit ipv6 fe80::/64 any log
+!
+! Rule fw-ipv6-1-ipv6 9 (global)
+ permit ipv6 host 2001:5c0:0:2::24 any log
+ permit ipv6 3ffe:1200:2000::/36 any log
+ permit ipv6 host 3ffe:1200:2001:1:8000::1 any log
+!
+! Rule fw-ipv6-1-ipv6 10 (global)
+ permit ipv6 host 2001:5c0:0:2::24 any log
+ permit ipv6 host 3ffe:1200:2001:1:8000::1 any log
+!
+! Rule fw-ipv6-1-ipv6 11 (global)
+ permit 50 host 2001:5c0:0:2::24 any dscp af11
+ permit 50 host 3ffe:1200:2001:1:8000::1 any dscp af11
+!
+! Rule fw-ipv6-1-ipv6 12 (global)
+ permit tcp host 2001:5c0:0:2::24 any established
+ permit tcp host 3ffe:1200:2001:1:8000::1 any established
+!
+! Rule fw-ipv6-1-ipv6 13 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22
+ permit udp host 2001:5c0:0:2::24 any eq 161
+ permit udp host 3ffe:1200:2001:1:8000::1 any eq 161
+ permit icmp host 2001:5c0:0:2::24 any 128
+ permit icmp host 3ffe:1200:2001:1:8000::1 any 128
+ permit tcp host 2001:5c0:0:2::24 any established
+ permit tcp host 3ffe:1200:2001:1:8000::1 any established
+exit
+
+ipv6 access-list ipv6_e0_0_out
+!
+! Rule fw-ipv6-1-ipv6 0 (global)
+ permit tcp fe80::/64 any eq 22
+!
+! Rule fw-ipv6-1-ipv6 1 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22
+!
+! Rule fw-ipv6-1-ipv6 3 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22 log
+ permit tcp 3ffe:1200:2000::/36 any eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22 log
+!
+! Rule fw-ipv6-1-ipv6 4 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22 log
+!
+! Rule fw-ipv6-1-ipv6 8 (global)
+ permit ipv6 fe80::/64 any log
+!
+! Rule fw-ipv6-1-ipv6 9 (global)
+ permit ipv6 host 2001:5c0:0:2::24 any log
+ permit ipv6 3ffe:1200:2000::/36 any log
+ permit ipv6 host 3ffe:1200:2001:1:8000::1 any log
+!
+! Rule fw-ipv6-1-ipv6 10 (global)
+ permit ipv6 host 2001:5c0:0:2::24 any log
+ permit ipv6 host 3ffe:1200:2001:1:8000::1 any log
+!
+! Rule fw-ipv6-1-ipv6 11 (global)
+ permit 50 host 2001:5c0:0:2::24 any dscp af11
+ permit 50 host 3ffe:1200:2001:1:8000::1 any dscp af11
+!
+! Rule fw-ipv6-1-ipv6 12 (global)
+ permit tcp host 2001:5c0:0:2::24 any established
+ permit tcp host 3ffe:1200:2001:1:8000::1 any established
+!
+! Rule fw-ipv6-1-ipv6 13 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22
+ permit udp host 2001:5c0:0:2::24 any eq 161
+ permit udp host 3ffe:1200:2001:1:8000::1 any eq 161
+ permit icmp host 2001:5c0:0:2::24 any 128
+ permit icmp host 3ffe:1200:2001:1:8000::1 any 128
+ permit tcp host 2001:5c0:0:2::24 any established
+ permit tcp host 3ffe:1200:2001:1:8000::1 any established
+exit
+
+
+interface Ethernet0/0
+ ipv6 traffic-filter ipv6_e0_0_in in
+exit
+interface Ethernet0/0
+ ipv6 traffic-filter ipv6_e0_0_out out
+exit
+
+
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/iosacl/firewall-ipv6-2.fw.orig b/test/iosacl/firewall-ipv6-2.fw.orig
new file mode 100755
index 000000000..6aa5391f9
--- /dev/null
+++ b/test/iosacl/firewall-ipv6-2.fw.orig
@@ -0,0 +1,228 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_iosacl v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:51:11 2011 PST by vadim
+!
+! Compiled for iosacl 12.1
+!
+!# files: * firewall-ipv6-2.fw
+!
+
+! firewall-ipv6-2:fw-ipv6-2-ipv6:1: error: Rule 'fw-ipv6-2-ipv6 1 (global)' shadows rule 'fw-ipv6-2-ipv6 3 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:1: error: Rule 'fw-ipv6-2-ipv6 1 (global)' shadows rule 'fw-ipv6-2-ipv6 4 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:3: error: Rule 'fw-ipv6-2-ipv6 3 (global)' shadows rule 'fw-ipv6-2-ipv6 4 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:1: error: Rule 'fw-ipv6-2-ipv6 1 (global)' shadows rule 'fw-ipv6-2-ipv6 5 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:3: error: Rule 'fw-ipv6-2-ipv6 3 (global)' shadows rule 'fw-ipv6-2-ipv6 5 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:2: error: Rule 'fw-ipv6-2-ipv6 2 (global)' shadows rule 'fw-ipv6-2-ipv6 5 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:1: error: Rule 'fw-ipv6-2-ipv6 1 (global)' shadows rule 'fw-ipv6-2-ipv6 6 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:2: error: Rule 'fw-ipv6-2-ipv6 2 (global)' shadows rule 'fw-ipv6-2-ipv6 6 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:9: error: Rule 'fw-ipv6-2-ipv6 9 (global)' shadows rule 'fw-ipv6-2-ipv6 10 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:9: error: Rule 'fw-ipv6-2-ipv6 9 (global)' shadows rule 'fw-ipv6-2-ipv6 10 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:9: error: Rule 'fw-ipv6-2-ipv6 9 (global)' shadows rule 'fw-ipv6-2-ipv6 11 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:9: error: Rule 'fw-ipv6-2-ipv6 9 (global)' shadows rule 'fw-ipv6-2-ipv6 11 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:9: error: Rule 'fw-ipv6-2-ipv6 9 (global)' shadows rule 'fw-ipv6-2-ipv6 11 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:9: error: Rule 'fw-ipv6-2-ipv6 9 (global)' shadows rule 'fw-ipv6-2-ipv6 11 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:9: error: Rule 'fw-ipv6-2-ipv6 9 (global)' shadows rule 'fw-ipv6-2-ipv6 12 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:9: error: Rule 'fw-ipv6-2-ipv6 9 (global)' shadows rule 'fw-ipv6-2-ipv6 12 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:9: error: Rule 'fw-ipv6-2-ipv6 9 (global)' shadows rule 'fw-ipv6-2-ipv6 13 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:1: error: Rule 'fw-ipv6-2-ipv6 1 (global)' shadows rule 'fw-ipv6-2-ipv6 13 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:9: error: Rule 'fw-ipv6-2-ipv6 9 (global)' shadows rule 'fw-ipv6-2-ipv6 13 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:9: error: Rule 'fw-ipv6-2-ipv6 9 (global)' shadows rule 'fw-ipv6-2-ipv6 13 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:9: error: Rule 'fw-ipv6-2-ipv6 9 (global)' shadows rule 'fw-ipv6-2-ipv6 13 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:9: error: Rule 'fw-ipv6-2-ipv6 9 (global)' shadows rule 'fw-ipv6-2-ipv6 13 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:3: error: Rule 'fw-ipv6-2-ipv6 3 (global)' shadows rule 'fw-ipv6-2-ipv6 13 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:9: error: Rule 'fw-ipv6-2-ipv6 9 (global)' shadows rule 'fw-ipv6-2-ipv6 13 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:9: error: Rule 'fw-ipv6-2-ipv6 9 (global)' shadows rule 'fw-ipv6-2-ipv6 13 (global)' below it
+! firewall-ipv6-2:fw-ipv6-2-ipv6:9: error: Rule 'fw-ipv6-2-ipv6 9 (global)' shadows rule 'fw-ipv6-2-ipv6 13 (global)' below it
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+! temporary access list for "safety net install"
+no ip access-list extended tmp_acl
+ip access-list extended tmp_acl
+ permit ip 1.1.1.0 0.0.0.255 any
+ deny ip any any
+exit
+interface Ethernet0/0
+ no ip access-group in
+ no ip access-group out
+ ip access-group tmp_acl in
+exit
+
+! ================ IPv4
+
+
+no ip access-list extended fw-ipv6-2-ipv4_e0_0_in
+no ip access-list extended fw-ipv6-2-ipv4_e0_0_out
+
+
+ip access-list extended fw-ipv6-2-ipv4_e0_0_in
+!
+! Rule -1 backup ssh access rule (automatic)
+ permit tcp host 1.1.1.100 host 1.1.1.1 eq 22
+!
+! Rule fw-ipv6-2-ipv4 1 (global)
+ permit 50 host 61.150.47.112 any dscp af12
+ permit 50 host 192.168.1.0 any dscp af12
+exit
+
+ip access-list extended fw-ipv6-2-ipv4_e0_0_out
+!
+! Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 1.1.1.1 eq 22 host 1.1.1.100
+!
+! Rule fw-ipv6-2-ipv4 1 (global)
+ permit 50 host 61.150.47.112 any dscp af12
+ permit 50 host 192.168.1.0 any dscp af12
+exit
+
+
+
+
+
+! ================ IPv6
+
+
+no ipv6 access-list ipv6_e0_0_in
+no ipv6 access-list ipv6_e0_0_out
+
+
+ipv6 access-list ipv6_e0_0_in
+!
+! Rule fw-ipv6-2-ipv6 0 (global)
+ permit tcp fe80::/64 any eq 22
+!
+! Rule fw-ipv6-2-ipv6 1 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22
+!
+! Rule fw-ipv6-2-ipv6 2 (global)
+ permit tcp host 3ffe:1200:2001:1:8000::1 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+!
+! Rule fw-ipv6-2-ipv6 3 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22 log
+ permit tcp 3ffe:1200:2000::/36 any eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22 log
+!
+! Rule fw-ipv6-2-ipv6 4 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22 log
+!
+! Rule fw-ipv6-2-ipv6 5 (global)
+ permit tcp host 2001:5c0:0:2::24 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+ permit tcp 3ffe:1200:2000::/36 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+!
+! Rule fw-ipv6-2-ipv6 6 (global)
+ permit tcp host 2001:5c0:0:2::24 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 host fe80::21d:9ff:fe8b:8e94 eq 22 log
+!
+! Rule fw-ipv6-2-ipv6 7 (global)
+ permit ipv6 any host fe80::21d:9ff:fe8b:8e94 log
+!
+! Rule fw-ipv6-2-ipv6 8 (global)
+ permit ipv6 fe80::/64 any log
+!
+! Rule fw-ipv6-2-ipv6 9 (global)
+ permit ipv6 host 2001:5c0:0:2::24 any log
+ permit ipv6 3ffe:1200:2000::/36 any log
+ permit ipv6 host 3ffe:1200:2001:1:8000::1 any log
+!
+! Rule fw-ipv6-2-ipv6 10 (global)
+ permit ipv6 host 2001:5c0:0:2::24 any log
+ permit ipv6 host 3ffe:1200:2001:1:8000::1 any log
+!
+! Rule fw-ipv6-2-ipv6 11 (global)
+ permit 50 host 2001:5c0:0:2::24 any dscp af11
+ permit 50 host 3ffe:1200:2001:1:8000::1 any dscp af11
+!
+! Rule fw-ipv6-2-ipv6 12 (global)
+ permit tcp host 2001:5c0:0:2::24 any established
+ permit tcp host 3ffe:1200:2001:1:8000::1 any established
+!
+! Rule fw-ipv6-2-ipv6 13 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22
+ permit udp host 2001:5c0:0:2::24 any eq 161
+ permit udp host 3ffe:1200:2001:1:8000::1 any eq 161
+ permit icmp host 2001:5c0:0:2::24 any 128
+ permit icmp host 3ffe:1200:2001:1:8000::1 any 128
+ permit tcp host 2001:5c0:0:2::24 any established
+ permit tcp host 3ffe:1200:2001:1:8000::1 any established
+exit
+
+ipv6 access-list ipv6_e0_0_out
+!
+! Rule fw-ipv6-2-ipv6 0 (global)
+ permit tcp fe80::/64 any eq 22
+!
+! Rule fw-ipv6-2-ipv6 1 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22
+!
+! Rule fw-ipv6-2-ipv6 3 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22 log
+ permit tcp 3ffe:1200:2000::/36 any eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22 log
+!
+! Rule fw-ipv6-2-ipv6 4 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22 log
+!
+! Rule fw-ipv6-2-ipv6 8 (global)
+ permit ipv6 fe80::/64 any log
+!
+! Rule fw-ipv6-2-ipv6 9 (global)
+ permit ipv6 host 2001:5c0:0:2::24 any log
+ permit ipv6 3ffe:1200:2000::/36 any log
+ permit ipv6 host 3ffe:1200:2001:1:8000::1 any log
+!
+! Rule fw-ipv6-2-ipv6 10 (global)
+ permit ipv6 host 2001:5c0:0:2::24 any log
+ permit ipv6 host 3ffe:1200:2001:1:8000::1 any log
+!
+! Rule fw-ipv6-2-ipv6 11 (global)
+ permit 50 host 2001:5c0:0:2::24 any dscp af11
+ permit 50 host 3ffe:1200:2001:1:8000::1 any dscp af11
+!
+! Rule fw-ipv6-2-ipv6 12 (global)
+ permit tcp host 2001:5c0:0:2::24 any established
+ permit tcp host 3ffe:1200:2001:1:8000::1 any established
+!
+! Rule fw-ipv6-2-ipv6 13 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22
+ permit udp host 2001:5c0:0:2::24 any eq 161
+ permit udp host 3ffe:1200:2001:1:8000::1 any eq 161
+ permit icmp host 2001:5c0:0:2::24 any 128
+ permit icmp host 3ffe:1200:2001:1:8000::1 any 128
+ permit tcp host 2001:5c0:0:2::24 any established
+ permit tcp host 3ffe:1200:2001:1:8000::1 any established
+exit
+
+
+interface Ethernet0/0
+ ipv6 traffic-filter ipv6_e0_0_in in
+exit
+interface Ethernet0/0
+ ipv6 traffic-filter ipv6_e0_0_out out
+exit
+
+
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/iosacl/firewall-ipv6-3.fw.orig b/test/iosacl/firewall-ipv6-3.fw.orig
new file mode 100755
index 000000000..6d929bd65
--- /dev/null
+++ b/test/iosacl/firewall-ipv6-3.fw.orig
@@ -0,0 +1,135 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_iosacl v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:51:11 2011 PST by vadim
+!
+! Compiled for iosacl 12.1
+!
+!# files: * firewall-ipv6-3.fw
+!
+! test "safety net" install in case when there are many rulesets
+
+
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+! temporary access list for "safety net install"
+no ipv6 access-list tmp_acl
+ipv6 access-list tmp_acl
+ permit ipv6 fe80::21d:9ff:aaaa:bbbb/64 any
+ permit icmp any any
+ deny ipv6 any any
+exit
+interface Ethernet0/0
+ no ipv6 traffic-filter in
+ no ipv6 traffic-filter out
+ ipv6 traffic-filter tmp_acl in
+exit
+
+! ================ IPv4
+
+
+no ip access-list extended e0_0_in
+no ip access-list extended e0_0_out
+
+
+ip access-list extended e0_0_in
+!
+! Rule fw-ipv6-3-ipv4 1 (global)
+ permit 50 host 61.150.47.112 any dscp af12
+ permit 50 host 192.168.1.0 any dscp af12
+exit
+
+ip access-list extended e0_0_out
+ permit 50 host 61.150.47.112 any dscp af12
+ permit 50 host 192.168.1.0 any dscp af12
+exit
+
+
+interface Ethernet0/0
+ ip access-group e0_0_in in
+exit
+interface Ethernet0/0
+ ip access-group e0_0_out out
+exit
+
+
+
+! ================ IPv6
+
+
+no ipv6 access-list ipv6_e0_0_in
+no ipv6 access-list ipv6_e0_0_out
+
+
+ipv6 access-list ipv6_e0_0_in
+!
+! Rule fw-ipv6-3-ipv6-1 0 (global)
+ permit tcp fe80::/64 any eq 22
+!
+! Rule fw-ipv6-3-ipv6-1 1 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22 log
+ permit tcp 3ffe:1200:2000::/36 any eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22 log
+exit
+
+ipv6 access-list ipv6_e0_0_out
+!
+! Rule fw-ipv6-3-ipv6-1 0 (global)
+ permit tcp fe80::/64 any eq 22
+!
+! Rule fw-ipv6-3-ipv6-1 1 (global)
+ permit tcp host 2001:5c0:0:2::24 any eq 22 log
+ permit tcp 3ffe:1200:2000::/36 any eq 22 log
+ permit tcp host 3ffe:1200:2001:1:8000::1 any eq 22 log
+exit
+
+
+interface Ethernet0/0
+ ipv6 traffic-filter ipv6_e0_0_in in
+exit
+interface Ethernet0/0
+ ipv6 traffic-filter ipv6_e0_0_out out
+exit
+
+
+
+! ================ IPv6
+
+
+no ipv6 access-list ipv6_fw-ipv6-3-ipv6-2_e0_0_in
+no ipv6 access-list ipv6_fw-ipv6-3-ipv6-2_e0_0_out
+
+
+ipv6 access-list ipv6_fw-ipv6-3-ipv6-2_e0_0_in
+!
+! Rule fw-ipv6-3-ipv6-2 0 (global)
+ permit 50 host 2001:5c0:0:2::24 any dscp af11
+ permit 50 host 3ffe:1200:2001:1:8000::1 any dscp af11
+exit
+
+ipv6 access-list ipv6_fw-ipv6-3-ipv6-2_e0_0_out
+ permit 50 host 2001:5c0:0:2::24 any dscp af11
+ permit 50 host 3ffe:1200:2001:1:8000::1 any dscp af11
+exit
+
+
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/iosacl/testios1-1.fw.orig b/test/iosacl/testios1-1.fw.orig
new file mode 100755
index 000000000..39361794b
--- /dev/null
+++ b/test/iosacl/testios1-1.fw.orig
@@ -0,0 +1,342 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_iosacl v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:51:12 2011 PST by vadim
+!
+! Compiled for iosacl 12.1
+!
+!# files: * testios1-1.fw
+!
+! dynamic interface eth0
+
+
+
+!
+! Prolog script:
+!
+! This is prolog
+!
+! End of prolog script:
+!
+
+hostname testios1-1
+
+! temporary access list for "safety net install"
+no ip access-list extended tmp_acl
+ip access-list extended tmp_acl
+ permit ip 10.10.10.1 0.0.0.0 any
+ deny ip any any
+exit
+interface ethernet0
+ no ip access-group in
+ no ip access-group out
+ ip access-group tmp_acl in
+exit
+
+! ================ IPv4
+
+
+no ip access-list extended e0_in
+no ip access-list extended e0_out
+no ip access-list extended e1_in
+no ip access-list extended e1_out
+
+
+ip access-list extended e0_in
+!
+! Rule 0 (ethernet0)
+! anti-spoofing
+ deny ip 10.10.10.0 0.0.0.255 any log
+ deny ip 10.10.11.0 0.0.0.255 any log
+ deny ip 10.10.12.0 0.0.0.255 any log
+!
+! Rule 1 (global)
+! комментарий по-русски
+ deny ip any any log fragments
+!
+! Rule 2 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 3 (ethernet0,ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 4 (testios1 itf)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 6 (ethernet0)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 7 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 9 (ethernet0)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 10 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+!
+! Rule 12 (ethernet0)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+!
+! Rule 13 (global)
+! interface ethernet1 has address on network 10.10.10.0/24,
+! therefore net-10.10.10 is behind the router and we do
+! not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+!
+! Rule 14 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+!
+! Rule 15 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+!
+! Rule 16 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+!
+! Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+!
+! Rule 18 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+!
+! Rule 19 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+!
+! Rule 20 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 dscp af11
+!
+! Rule 21 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 dscp af12
+!
+! Rule 22 (global)
+ deny ip any any log
+exit
+
+ip access-list extended e0_out
+!
+! Rule 1 (global)
+! комментарий по-русски
+ deny ip any any log fragments
+!
+! Rule 2 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 3 (ethernet0,ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 4 (testios1 itf)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 6 (ethernet0)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 10 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+!
+! Rule 12 (ethernet0)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+!
+! Rule 13 (global)
+! interface ethernet1 has address on network 10.10.10.0/24,
+! therefore net-10.10.10 is behind the router and we do
+! not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+!
+! Rule 14 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+!
+! Rule 15 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+!
+! Rule 16 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+!
+! Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+!
+! Rule 18 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+!
+! Rule 19 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+!
+! Rule 20 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 dscp af11
+!
+! Rule 21 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 dscp af12
+!
+! Rule 22 (global)
+ deny ip any any log
+exit
+
+ip access-list extended e1_in
+!
+! Rule 3 (ethernet0,ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 4 (testios1 itf)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 5 (ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 8 (ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 11 (ethernet1)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+exit
+
+ip access-list extended e1_out
+!
+! Rule 3 (ethernet0,ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 4 (testios1 itf)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 5 (ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 11 (ethernet1)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+exit
+
+
+interface ethernet0
+ ip access-group e0_in in
+exit
+interface ethernet0
+ ip access-group e0_out out
+exit
+interface ethernet1
+ ip access-group e1_in in
+exit
+interface ethernet1
+ ip access-group e1_out out
+exit
+
+
+
+!
+! Rule 0 (main)
+!
+! "Routing rule 0 (main)"
+!
+! ip route 0.0.0.0 0.0.0.0
+!
+ip route 0.0.0.0 0.0.0.0 ethernet0 1
+
+!
+! Epilog script:
+!
+! This is epilog for testing
+! End of epilog script:
+!
diff --git a/test/iosacl/testios1.fw.orig b/test/iosacl/testios1.fw.orig
new file mode 100755
index 000000000..f8382da18
--- /dev/null
+++ b/test/iosacl/testios1.fw.orig
@@ -0,0 +1,344 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_iosacl v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:51:11 2011 PST by vadim
+!
+! Compiled for iosacl 12.1
+!
+!# files: * testios1.fw
+!
+
+
+
+!
+! Prolog script:
+!
+! This is prolog
+!
+! End of prolog script:
+!
+
+hostname testios1
+
+! temporary access list for "safety net install"
+no ip access-list extended tmp_acl
+ip access-list extended tmp_acl
+ permit ip 10.10.10.1 0.0.0.0 any
+ deny ip any any
+exit
+interface ethernet0
+ no ip access-group in
+ no ip access-group out
+ ip access-group tmp_acl in
+exit
+
+! ================ IPv4
+
+
+no ip access-list extended e0_in
+no ip access-list extended e0_out
+no ip access-list extended e1_in
+no ip access-list extended e1_out
+
+
+ip access-list extended e0_in
+!
+! Rule -1 backup ssh access rule (automatic)
+ permit tcp host 1.1.1.100 host 1.1.1.1 eq 22
+ permit tcp host 1.1.1.100 host 3.3.3.3 eq 22
+ permit tcp host 1.1.1.100 host 10.10.10.1 eq 22
+!
+! Rule 0 (ethernet0)
+! anti-spoofing
+ deny ip 10.10.10.0 0.0.0.255 any log
+ deny ip 10.10.11.0 0.0.0.255 any log
+ deny ip 10.10.12.0 0.0.0.255 any log
+!
+! Rule 1 (global)
+! комментарий по-русски
+ deny ip any any log fragments
+!
+! Rule 2 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 3 (ethernet0,ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 4 (testios1 itf)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 6 (ethernet0)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 7 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 9 (ethernet0)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 10 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+!
+! Rule 12 (ethernet0)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+!
+! Rule 13 (global)
+! interface ethernet1 has address on network 10.10.10.0/24,
+! therefore net-10.10.10 is behind the router and we do
+! not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+!
+! Rule 14 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+!
+! Rule 15 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+!
+! Rule 16 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+!
+! Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+!
+! Rule 18 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+!
+! Rule 19 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+!
+! Rule 20 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 dscp af11
+!
+! Rule 21 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 dscp af12
+!
+! Rule 22 (global)
+ deny ip any any log
+exit
+
+ip access-list extended e0_out
+!
+! Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 1.1.1.1 eq 22 host 1.1.1.100
+ permit tcp host 3.3.3.3 eq 22 host 1.1.1.100
+ permit tcp host 10.10.10.1 eq 22 host 1.1.1.100
+!
+! Rule 1 (global)
+! комментарий по-русски
+ deny ip any any log fragments
+!
+! Rule 2 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 3 (ethernet0,ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 4 (testios1 itf)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 6 (ethernet0)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 10 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+!
+! Rule 12 (ethernet0)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+!
+! Rule 13 (global)
+! interface ethernet1 has address on network 10.10.10.0/24,
+! therefore net-10.10.10 is behind the router and we do
+! not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+!
+! Rule 14 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+!
+! Rule 15 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+!
+! Rule 16 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+!
+! Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+!
+! Rule 18 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+!
+! Rule 19 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+!
+! Rule 20 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 dscp af11
+!
+! Rule 21 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 dscp af12
+!
+! Rule 22 (global)
+ deny ip any any log
+exit
+
+ip access-list extended e1_in
+!
+! Rule 3 (ethernet0,ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 4 (testios1 itf)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 5 (ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 8 (ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 11 (ethernet1)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+exit
+
+ip access-list extended e1_out
+!
+! Rule 3 (ethernet0,ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 4 (testios1 itf)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 5 (ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 11 (ethernet1)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+exit
+
+
+interface ethernet0
+ ip access-group e0_in in
+exit
+interface ethernet0
+ ip access-group e0_out out
+exit
+interface ethernet1
+ ip access-group e1_in in
+exit
+interface ethernet1
+ ip access-group e1_out out
+exit
+
+
+
+
+
+!
+! Epilog script:
+!
+! This is epilog for testing
+! End of epilog script:
+!
diff --git a/test/iosacl/testios2.fw.orig b/test/iosacl/testios2.fw.orig
new file mode 100755
index 000000000..c4e86bc1e
--- /dev/null
+++ b/test/iosacl/testios2.fw.orig
@@ -0,0 +1,389 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_iosacl v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:51:12 2011 PST by vadim
+!
+! Compiled for iosacl 12.1
+!
+!# files: * testios2.fw
+!
+
+! testios2:Routing:0: error: Object "test-addr-1" used as gateway in the routing rule 0 (main) is not reachable because it is not in any local network of the firewall
+! testios2:Routing:1: error: Can not use both gateway address and interface in IOS routing rule
+! testios2:Routing:0: error: MultiPath routing not supported by platform
+! testios2:Routing:1: error: MultiPath routing not supported by platform
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+hostname testios2
+
+! temporary access list for "safety net install"
+no ip access-list extended tmp_acl
+ip access-list extended tmp_acl
+ permit ip 10.10.10.0 0.0.0.255 any
+ deny ip any any
+exit
+interface ethernet1
+ no ip access-group in
+ no ip access-group out
+ ip access-group tmp_acl in
+exit
+
+! ================ IPv4
+
+
+no ip access-list extended e0_in
+no ip access-list extended e0_out
+no ip access-list extended e1_in
+no ip access-list extended e1_out
+
+
+ip access-list extended e0_in
+!
+! Rule -1 backup ssh access rule (automatic)
+ permit tcp 10.10.10.0 0.0.0.255 host 1.1.1.1 eq 22
+ permit tcp 10.10.10.0 0.0.0.255 host 10.10.10.1 eq 22
+!
+! Rule 0 (ethernet0)
+! anti-spoofing
+ deny ip 10.10.10.0 0.0.0.255 any log
+ deny ip 10.10.11.0 0.0.0.255 any log
+ deny ip 10.10.12.0 0.0.0.255 any log
+!
+! Rule 1 (global)
+ deny ip any any log fragments
+!
+! Rule 2 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 3 (ethernet0,ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 5 (ethernet0)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 6 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 8 (ethernet0)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 9 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+!
+! Rule 11 (ethernet0)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+!
+! Rule 12 (global)
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+!
+! Rule 13 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+!
+! Rule 14 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+!
+! Rule 15 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+!
+! Rule 16 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+!
+! Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+!
+! Rule 18 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+!
+! Rule 19 (global)
+ deny ip any any log
+exit
+
+ip access-list extended e0_out
+!
+! Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 1.1.1.1 eq 22 10.10.10.0 0.0.0.255
+ permit tcp host 10.10.10.1 eq 22 10.10.10.0 0.0.0.255
+!
+! Rule 1 (global)
+ deny ip any any log fragments
+!
+! Rule 3 (ethernet0,ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 5 (ethernet0)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 11 (ethernet0)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+!
+! Rule 19 (global)
+ deny ip any any log
+exit
+
+ip access-list extended e1_in
+!
+! Rule -1 backup ssh access rule (automatic)
+ permit tcp 10.10.10.0 0.0.0.255 host 1.1.1.1 eq 22
+ permit tcp 10.10.10.0 0.0.0.255 host 10.10.10.1 eq 22
+!
+! Rule 1 (global)
+ deny ip any any log fragments
+!
+! Rule 2 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 3 (ethernet0,ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 4 (ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 6 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 7 (ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 9 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+!
+! Rule 10 (ethernet1)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+!
+! Rule 12 (global)
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+!
+! Rule 13 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+!
+! Rule 14 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+!
+! Rule 15 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+!
+! Rule 16 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+!
+! Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+!
+! Rule 18 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+!
+! Rule 19 (global)
+ deny ip any any log
+exit
+
+ip access-list extended e1_out
+!
+! Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 1.1.1.1 eq 22 10.10.10.0 0.0.0.255
+ permit tcp host 10.10.10.1 eq 22 10.10.10.0 0.0.0.255
+!
+! Rule 1 (global)
+ deny ip any any log fragments
+!
+! Rule 2 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 3 (ethernet0,ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 4 (ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 9 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+!
+! Rule 10 (ethernet1)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+!
+! Rule 12 (global)
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+!
+! Rule 13 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+!
+! Rule 14 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+!
+! Rule 15 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+!
+! Rule 16 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+!
+! Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+!
+! Rule 18 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+!
+! Rule 19 (global)
+ deny ip any any log
+exit
+
+
+interface ethernet0
+ ip access-group e0_in in
+exit
+interface ethernet0
+ ip access-group e0_out out
+exit
+interface ethernet1
+ ip access-group e1_in in
+exit
+interface ethernet1
+ ip access-group e1_out out
+exit
+
+
+
+!
+! Rule 0 (main)
+!
+! "Routing rule 0 (main)"
+!
+# testios2:Routing:0: error: Object "test-addr-1" used as gateway in the routing rule 0 (main) is not reachable because it is not in any local network of the firewall
+!
+! Rule 1 (main)
+!
+! "Routing rule 1 (main)"
+!
+# testios2:Routing:1: error: Can not use both gateway address and interface in IOS routing rule
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/iosacl/testios20-v12.3.fw.orig b/test/iosacl/testios20-v12.3.fw.orig
new file mode 100755
index 000000000..66fdf7cb5
--- /dev/null
+++ b/test/iosacl/testios20-v12.3.fw.orig
@@ -0,0 +1,215 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_iosacl v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:51:13 2011 PST by vadim
+!
+! Compiled for iosacl 12.3
+!
+!# files: * testios20-v12.3.fw
+!
+
+! testios20-v12.3:Policy:10: error: IP options match requires IOS v12.4 or later.
+! testios20-v12.3:Policy:10: error: IP options match requires IOS v12.4 or later.
+! testios20-v12.3:Policy:10: error: IP options match requires IOS v12.4 or later.
+! testios20-v12.3:Policy:10: error: IP options match requires IOS v12.4 or later.
+! testios20-v12.3:Policy:11: error: IP options match requires IOS v12.4 or later.
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+hostname testios20-v12.3
+
+
+
+! ================ IPv4
+
+
+no ip access-list extended e0_in
+no ip access-list extended e0_out
+no ip access-list extended e1_in
+no ip access-list extended e1_out
+
+
+ip access-list extended e0_in
+!
+! Rule 0 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 2 (ethernet0)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 3 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 5 (ethernet0)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 6 (global)
+ permit ip any any tos 16
+!
+! Rule 7 (global)
+ permit ip any any dscp 16
+!
+! Rule 8 (global)
+ permit ip any any dscp af11
+!
+! Rule 9 (global)
+ permit ip any any dscp 16
+ permit ip any any dscp af11
+!
+! Rule 10 (ethernet0)
+ permit ip any any option lsr
+ permit ip any any option record-route
+ permit ip any any option ssr
+ permit ip any any
+!
+! Rule 11 (ethernet0)
+ permit ip any any option any-options
+!
+! Rule 12 (global)
+ permit ip any any
+!
+! Rule 13 (global)
+ deny ip any any log
+exit
+
+ip access-list extended e0_out
+!
+! Rule 2 (ethernet0)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 6 (global)
+ permit ip any any tos 16
+!
+! Rule 7 (global)
+ permit ip any any dscp 16
+!
+! Rule 8 (global)
+ permit ip any any dscp af11
+!
+! Rule 9 (global)
+ permit ip any any dscp 16
+ permit ip any any dscp af11
+!
+! Rule 12 (global)
+ permit ip any any
+!
+! Rule 13 (global)
+ deny ip any any log
+exit
+
+ip access-list extended e1_in
+!
+! Rule 0 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 1 (ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 3 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 4 (ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 6 (global)
+ permit ip any any tos 16
+!
+! Rule 7 (global)
+ permit ip any any dscp 16
+!
+! Rule 8 (global)
+ permit ip any any dscp af11
+!
+! Rule 9 (global)
+ permit ip any any dscp 16
+ permit ip any any dscp af11
+!
+! Rule 12 (global)
+ permit ip any any
+!
+! Rule 13 (global)
+ deny ip any any log
+exit
+
+ip access-list extended e1_out
+!
+! Rule 0 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 1 (ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 6 (global)
+ permit ip any any tos 16
+!
+! Rule 7 (global)
+ permit ip any any dscp 16
+!
+! Rule 8 (global)
+ permit ip any any dscp af11
+!
+! Rule 9 (global)
+ permit ip any any dscp 16
+ permit ip any any dscp af11
+!
+! Rule 12 (global)
+ permit ip any any
+!
+! Rule 13 (global)
+ deny ip any any log
+exit
+
+
+interface ethernet0
+ ip access-group e0_in in
+exit
+interface ethernet0
+ ip access-group e0_out out
+exit
+interface ethernet1
+ ip access-group e1_in in
+exit
+interface ethernet1
+ ip access-group e1_out out
+exit
+
+
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/iosacl/testios20.fw.orig b/test/iosacl/testios20.fw.orig
new file mode 100755
index 000000000..30d9e15a7
--- /dev/null
+++ b/test/iosacl/testios20.fw.orig
@@ -0,0 +1,221 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_iosacl v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:51:12 2011 PST by vadim
+!
+! Compiled for iosacl 12.4
+!
+!# files: * testios20.fw
+!
+
+
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+hostname testios20
+
+
+
+! ================ IPv4
+
+
+no ip access-list extended e0_in
+no ip access-list extended e0_out
+no ip access-list extended e1_in
+no ip access-list extended e1_out
+
+
+ip access-list extended e0_in
+!
+! Rule 0 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 2 (ethernet0)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 3 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 5 (ethernet0)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 6 (global)
+ permit ip any any tos 16
+!
+! Rule 7 (global)
+ permit ip any any dscp 16
+!
+! Rule 8 (global)
+ permit ip any any dscp af11
+!
+! Rule 9 (global)
+ permit ip any any dscp 16
+ permit ip any any dscp af11
+!
+! Rule 10 (ethernet0)
+ permit ip any any option lsr
+ permit ip any any option record-route
+ permit ip any any option ssr
+ permit ip any any
+!
+! Rule 11 (ethernet0)
+ permit ip any any option any-options
+!
+! Rule 12 (ethernet0)
+ permit tcp any any match-all -urg +ack -psh -rst -syn -fin
+!
+! Rule 13 (ethernet0)
+ permit tcp any any match-all -urg +ack -psh -rst -syn -fin
+ permit tcp any any match-all -urg -ack -psh -rst +syn -fin
+!
+! Rule 14 (ethernet0)
+ permit tcp any any match-all -urg +ack -psh -rst +syn -fin
+!
+! Rule 15 (global)
+ permit ip any any
+!
+! Rule 16 (global)
+ deny ip any any log
+exit
+
+ip access-list extended e0_out
+!
+! Rule 2 (ethernet0)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 6 (global)
+ permit ip any any tos 16
+!
+! Rule 7 (global)
+ permit ip any any dscp 16
+!
+! Rule 8 (global)
+ permit ip any any dscp af11
+!
+! Rule 9 (global)
+ permit ip any any dscp 16
+ permit ip any any dscp af11
+!
+! Rule 15 (global)
+ permit ip any any
+!
+! Rule 16 (global)
+ deny ip any any log
+exit
+
+ip access-list extended e1_in
+!
+! Rule 0 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 1 (ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 3 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 4 (ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 6 (global)
+ permit ip any any tos 16
+!
+! Rule 7 (global)
+ permit ip any any dscp 16
+!
+! Rule 8 (global)
+ permit ip any any dscp af11
+!
+! Rule 9 (global)
+ permit ip any any dscp 16
+ permit ip any any dscp af11
+!
+! Rule 15 (global)
+ permit ip any any
+!
+! Rule 16 (global)
+ deny ip any any log
+exit
+
+ip access-list extended e1_out
+!
+! Rule 0 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 1 (ethernet1)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+!
+! Rule 6 (global)
+ permit ip any any tos 16
+!
+! Rule 7 (global)
+ permit ip any any dscp 16
+!
+! Rule 8 (global)
+ permit ip any any dscp af11
+!
+! Rule 9 (global)
+ permit ip any any dscp 16
+ permit ip any any dscp af11
+!
+! Rule 15 (global)
+ permit ip any any
+!
+! Rule 16 (global)
+ deny ip any any log
+exit
+
+
+interface ethernet0
+ ip access-group e0_in in
+exit
+interface ethernet0
+ ip access-group e0_out out
+exit
+interface ethernet1
+ ip access-group e1_in in
+exit
+interface ethernet1
+ ip access-group e1_out out
+exit
+
+
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/iosacl/testios3.fw.orig b/test/iosacl/testios3.fw.orig
new file mode 100755
index 000000000..0f17c3de6
--- /dev/null
+++ b/test/iosacl/testios3.fw.orig
@@ -0,0 +1,471 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_iosacl v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:51:13 2011 PST by vadim
+!
+! Compiled for iosacl 12.1
+!
+!# files: * testios3.fw
+!
+
+! testios3:Policy:3: error: File not found for Address Table: missing table (file_does_not_exist.tbl) Using dummy address in test mode
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+hostname testios3
+
+! temporary access list for "safety net install"
+no ip access-list extended tmp_acl
+ip access-list extended tmp_acl
+ permit ip 10.10.10.0 0.0.0.255 any
+ deny ip any any
+exit
+interface ethernet1
+ no ip access-group in
+ no ip access-group out
+ ip access-group tmp_acl in
+exit
+
+! ================ IPv4
+
+
+no ip access-list extended e0_in
+no ip access-list extended e0_out
+no ip access-list extended e1_in
+no ip access-list extended e1_out
+
+
+ip access-list extended e0_in
+!
+! Rule -1 backup ssh access rule (automatic)
+ permit tcp 10.10.10.0 0.0.0.255 host 1.1.1.1 eq 22
+ permit tcp 10.10.10.0 0.0.0.255 host 10.10.10.1 eq 22
+!
+! Rule 4 (global)
+ deny ip any any log
+exit
+
+ip access-list extended e0_out
+!
+! Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 1.1.1.1 eq 22 10.10.10.0 0.0.0.255
+ permit tcp host 10.10.10.1 eq 22 10.10.10.0 0.0.0.255
+!
+! Rule 0 (ethernet0)
+ deny ip 10.10.10.0 0.0.0.255 host 192.168.1.1 log
+ deny ip 10.10.10.0 0.0.0.255 host 192.168.1.2 log
+ deny ip 10.10.10.0 0.0.0.255 192.168.1.3 0.0.0.3 log
+ deny ip 10.10.10.0 0.0.0.255 host 192.168.1.200 log
+ deny ip 10.10.10.0 0.0.0.255 host 192.168.1.201 log
+ deny ip 10.10.10.0 0.0.0.255 192.168.2.128 0.0.0.127 log
+ deny ip 10.10.11.0 0.0.0.255 host 192.168.1.1 log
+ deny ip 10.10.11.0 0.0.0.255 host 192.168.1.2 log
+ deny ip 10.10.11.0 0.0.0.255 192.168.1.3 0.0.0.3 log
+ deny ip 10.10.11.0 0.0.0.255 host 192.168.1.200 log
+ deny ip 10.10.11.0 0.0.0.255 host 192.168.1.201 log
+ deny ip 10.10.11.0 0.0.0.255 192.168.2.128 0.0.0.127 log
+ deny ip 10.10.12.0 0.0.0.255 host 192.168.1.1 log
+ deny ip 10.10.12.0 0.0.0.255 host 192.168.1.2 log
+ deny ip 10.10.12.0 0.0.0.255 192.168.1.3 0.0.0.3 log
+ deny ip 10.10.12.0 0.0.0.255 host 192.168.1.200 log
+ deny ip 10.10.12.0 0.0.0.255 host 192.168.1.201 log
+ deny ip 10.10.12.0 0.0.0.255 192.168.2.128 0.0.0.127 log
+!
+! Rule 1 (ethernet0)
+ deny ip 10.10.10.0 0.0.0.255 host 58.33.181.83 log
+ deny ip 10.10.10.0 0.0.0.255 host 58.53.82.190 log
+ deny ip 10.10.10.0 0.0.0.255 host 58.231.13.78 log
+ deny ip 10.10.10.0 0.0.0.255 host 61.150.47.112 log
+ deny ip 10.10.10.0 0.0.0.255 host 61.184.14.102 log
+ deny ip 10.10.10.0 0.0.0.255 host 64.106.85.186 log
+ deny ip 10.10.10.0 0.0.0.255 host 70.228.60.100 log
+ deny ip 10.10.10.0 0.0.0.255 host 80.51.236.6 log
+ deny ip 10.10.10.0 0.0.0.255 host 80.243.72.149 log
+ deny ip 10.10.10.0 0.0.0.255 host 80.249.77.34 log
+ deny ip 10.10.10.0 0.0.0.255 host 81.2.36.254 log
+ deny ip 10.10.10.0 0.0.0.255 host 81.196.74.125 log
+ deny ip 10.10.10.0 0.0.0.255 host 82.77.37.174 log
+ deny ip 10.10.10.0 0.0.0.255 host 82.117.221.205 log
+ deny ip 10.10.10.0 0.0.0.255 host 82.143.196.17 log
+ deny ip 10.10.10.0 0.0.0.255 host 84.90.8.198 log
+ deny ip 10.10.10.0 0.0.0.255 host 151.8.224.178 log
+ deny ip 10.10.10.0 0.0.0.255 host 168.156.76.20 log
+ deny ip 10.10.10.0 0.0.0.255 host 193.207.126.36 log
+ deny ip 10.10.10.0 0.0.0.255 host 195.136.186.35 log
+ deny ip 10.10.10.0 0.0.0.255 host 196.15.136.15 log
+ deny ip 10.10.10.0 0.0.0.255 host 201.10.180.138 log
+ deny ip 10.10.10.0 0.0.0.255 host 201.17.93.16 log
+ deny ip 10.10.10.0 0.0.0.255 host 201.36.156.121 log
+ deny ip 10.10.10.0 0.0.0.255 host 202.96.112.93 log
+ deny ip 10.10.10.0 0.0.0.255 host 202.103.25.253 log
+ deny ip 10.10.10.0 0.0.0.255 host 203.162.3.209 log
+ deny ip 10.10.10.0 0.0.0.255 host 203.209.124.144 log
+ deny ip 10.10.10.0 0.0.0.255 host 210.106.193.237 log
+ deny ip 10.10.10.0 0.0.0.255 host 210.222.114.102 log
+ deny ip 10.10.10.0 0.0.0.255 host 211.144.143.143 log
+ deny ip 10.10.10.0 0.0.0.255 host 211.172.218.237 log
+ deny ip 10.10.10.0 0.0.0.255 host 211.250.16.132 log
+ deny ip 10.10.10.0 0.0.0.255 host 212.21.241.31 log
+ deny ip 10.10.10.0 0.0.0.255 host 212.100.212.100 log
+ deny ip 10.10.10.0 0.0.0.255 host 218.18.72.252 log
+ deny ip 10.10.10.0 0.0.0.255 host 218.39.114.122 log
+ deny ip 10.10.10.0 0.0.0.255 host 218.55.115.43 log
+ deny ip 10.10.10.0 0.0.0.255 host 218.104.138.146 log
+ deny ip 10.10.10.0 0.0.0.255 host 219.132.104.160 log
+ deny ip 10.10.10.0 0.0.0.255 host 220.71.17.86 log
+ deny ip 10.10.10.0 0.0.0.255 host 220.81.50.105 log
+ deny ip 10.10.10.0 0.0.0.255 host 220.91.99.46 log
+ deny ip 10.10.10.0 0.0.0.255 host 221.14.249.242 log
+ deny ip 10.10.10.0 0.0.0.255 host 221.166.177.135 log
+ deny ip 10.10.10.0 0.0.0.255 host 221.198.33.38 log
+ deny ip 10.10.10.0 0.0.0.255 host 221.202.160.233 log
+ deny ip 10.10.10.0 0.0.0.255 host 221.205.54.125 log
+ deny ip 10.10.10.0 0.0.0.255 host 221.217.44.248 log
+ deny ip 10.10.10.0 0.0.0.255 host 222.100.212.223 log
+ deny ip 10.10.10.0 0.0.0.255 host 222.121.118.144 log
+ deny ip 10.10.10.0 0.0.0.255 host 222.174.113.2 log
+ deny ip 10.10.11.0 0.0.0.255 host 58.33.181.83 log
+ deny ip 10.10.11.0 0.0.0.255 host 58.53.82.190 log
+ deny ip 10.10.11.0 0.0.0.255 host 58.231.13.78 log
+ deny ip 10.10.11.0 0.0.0.255 host 61.150.47.112 log
+ deny ip 10.10.11.0 0.0.0.255 host 61.184.14.102 log
+ deny ip 10.10.11.0 0.0.0.255 host 64.106.85.186 log
+ deny ip 10.10.11.0 0.0.0.255 host 70.228.60.100 log
+ deny ip 10.10.11.0 0.0.0.255 host 80.51.236.6 log
+ deny ip 10.10.11.0 0.0.0.255 host 80.243.72.149 log
+ deny ip 10.10.11.0 0.0.0.255 host 80.249.77.34 log
+ deny ip 10.10.11.0 0.0.0.255 host 81.2.36.254 log
+ deny ip 10.10.11.0 0.0.0.255 host 81.196.74.125 log
+ deny ip 10.10.11.0 0.0.0.255 host 82.77.37.174 log
+ deny ip 10.10.11.0 0.0.0.255 host 82.117.221.205 log
+ deny ip 10.10.11.0 0.0.0.255 host 82.143.196.17 log
+ deny ip 10.10.11.0 0.0.0.255 host 84.90.8.198 log
+ deny ip 10.10.11.0 0.0.0.255 host 151.8.224.178 log
+ deny ip 10.10.11.0 0.0.0.255 host 168.156.76.20 log
+ deny ip 10.10.11.0 0.0.0.255 host 193.207.126.36 log
+ deny ip 10.10.11.0 0.0.0.255 host 195.136.186.35 log
+ deny ip 10.10.11.0 0.0.0.255 host 196.15.136.15 log
+ deny ip 10.10.11.0 0.0.0.255 host 201.10.180.138 log
+ deny ip 10.10.11.0 0.0.0.255 host 201.17.93.16 log
+ deny ip 10.10.11.0 0.0.0.255 host 201.36.156.121 log
+ deny ip 10.10.11.0 0.0.0.255 host 202.96.112.93 log
+ deny ip 10.10.11.0 0.0.0.255 host 202.103.25.253 log
+ deny ip 10.10.11.0 0.0.0.255 host 203.162.3.209 log
+ deny ip 10.10.11.0 0.0.0.255 host 203.209.124.144 log
+ deny ip 10.10.11.0 0.0.0.255 host 210.106.193.237 log
+ deny ip 10.10.11.0 0.0.0.255 host 210.222.114.102 log
+ deny ip 10.10.11.0 0.0.0.255 host 211.144.143.143 log
+ deny ip 10.10.11.0 0.0.0.255 host 211.172.218.237 log
+ deny ip 10.10.11.0 0.0.0.255 host 211.250.16.132 log
+ deny ip 10.10.11.0 0.0.0.255 host 212.21.241.31 log
+ deny ip 10.10.11.0 0.0.0.255 host 212.100.212.100 log
+ deny ip 10.10.11.0 0.0.0.255 host 218.18.72.252 log
+ deny ip 10.10.11.0 0.0.0.255 host 218.39.114.122 log
+ deny ip 10.10.11.0 0.0.0.255 host 218.55.115.43 log
+ deny ip 10.10.11.0 0.0.0.255 host 218.104.138.146 log
+ deny ip 10.10.11.0 0.0.0.255 host 219.132.104.160 log
+ deny ip 10.10.11.0 0.0.0.255 host 220.71.17.86 log
+ deny ip 10.10.11.0 0.0.0.255 host 220.81.50.105 log
+ deny ip 10.10.11.0 0.0.0.255 host 220.91.99.46 log
+ deny ip 10.10.11.0 0.0.0.255 host 221.14.249.242 log
+ deny ip 10.10.11.0 0.0.0.255 host 221.166.177.135 log
+ deny ip 10.10.11.0 0.0.0.255 host 221.198.33.38 log
+ deny ip 10.10.11.0 0.0.0.255 host 221.202.160.233 log
+ deny ip 10.10.11.0 0.0.0.255 host 221.205.54.125 log
+ deny ip 10.10.11.0 0.0.0.255 host 221.217.44.248 log
+ deny ip 10.10.11.0 0.0.0.255 host 222.100.212.223 log
+ deny ip 10.10.11.0 0.0.0.255 host 222.121.118.144 log
+ deny ip 10.10.11.0 0.0.0.255 host 222.174.113.2 log
+ deny ip 10.10.12.0 0.0.0.255 host 58.33.181.83 log
+ deny ip 10.10.12.0 0.0.0.255 host 58.53.82.190 log
+ deny ip 10.10.12.0 0.0.0.255 host 58.231.13.78 log
+ deny ip 10.10.12.0 0.0.0.255 host 61.150.47.112 log
+ deny ip 10.10.12.0 0.0.0.255 host 61.184.14.102 log
+ deny ip 10.10.12.0 0.0.0.255 host 64.106.85.186 log
+ deny ip 10.10.12.0 0.0.0.255 host 70.228.60.100 log
+ deny ip 10.10.12.0 0.0.0.255 host 80.51.236.6 log
+ deny ip 10.10.12.0 0.0.0.255 host 80.243.72.149 log
+ deny ip 10.10.12.0 0.0.0.255 host 80.249.77.34 log
+ deny ip 10.10.12.0 0.0.0.255 host 81.2.36.254 log
+ deny ip 10.10.12.0 0.0.0.255 host 81.196.74.125 log
+ deny ip 10.10.12.0 0.0.0.255 host 82.77.37.174 log
+ deny ip 10.10.12.0 0.0.0.255 host 82.117.221.205 log
+ deny ip 10.10.12.0 0.0.0.255 host 82.143.196.17 log
+ deny ip 10.10.12.0 0.0.0.255 host 84.90.8.198 log
+ deny ip 10.10.12.0 0.0.0.255 host 151.8.224.178 log
+ deny ip 10.10.12.0 0.0.0.255 host 168.156.76.20 log
+ deny ip 10.10.12.0 0.0.0.255 host 193.207.126.36 log
+ deny ip 10.10.12.0 0.0.0.255 host 195.136.186.35 log
+ deny ip 10.10.12.0 0.0.0.255 host 196.15.136.15 log
+ deny ip 10.10.12.0 0.0.0.255 host 201.10.180.138 log
+ deny ip 10.10.12.0 0.0.0.255 host 201.17.93.16 log
+ deny ip 10.10.12.0 0.0.0.255 host 201.36.156.121 log
+ deny ip 10.10.12.0 0.0.0.255 host 202.96.112.93 log
+ deny ip 10.10.12.0 0.0.0.255 host 202.103.25.253 log
+ deny ip 10.10.12.0 0.0.0.255 host 203.162.3.209 log
+ deny ip 10.10.12.0 0.0.0.255 host 203.209.124.144 log
+ deny ip 10.10.12.0 0.0.0.255 host 210.106.193.237 log
+ deny ip 10.10.12.0 0.0.0.255 host 210.222.114.102 log
+ deny ip 10.10.12.0 0.0.0.255 host 211.144.143.143 log
+ deny ip 10.10.12.0 0.0.0.255 host 211.172.218.237 log
+ deny ip 10.10.12.0 0.0.0.255 host 211.250.16.132 log
+ deny ip 10.10.12.0 0.0.0.255 host 212.21.241.31 log
+ deny ip 10.10.12.0 0.0.0.255 host 212.100.212.100 log
+ deny ip 10.10.12.0 0.0.0.255 host 218.18.72.252 log
+ deny ip 10.10.12.0 0.0.0.255 host 218.39.114.122 log
+ deny ip 10.10.12.0 0.0.0.255 host 218.55.115.43 log
+ deny ip 10.10.12.0 0.0.0.255 host 218.104.138.146 log
+ deny ip 10.10.12.0 0.0.0.255 host 219.132.104.160 log
+ deny ip 10.10.12.0 0.0.0.255 host 220.71.17.86 log
+ deny ip 10.10.12.0 0.0.0.255 host 220.81.50.105 log
+ deny ip 10.10.12.0 0.0.0.255 host 220.91.99.46 log
+ deny ip 10.10.12.0 0.0.0.255 host 221.14.249.242 log
+ deny ip 10.10.12.0 0.0.0.255 host 221.166.177.135 log
+ deny ip 10.10.12.0 0.0.0.255 host 221.198.33.38 log
+ deny ip 10.10.12.0 0.0.0.255 host 221.202.160.233 log
+ deny ip 10.10.12.0 0.0.0.255 host 221.205.54.125 log
+ deny ip 10.10.12.0 0.0.0.255 host 221.217.44.248 log
+ deny ip 10.10.12.0 0.0.0.255 host 222.100.212.223 log
+ deny ip 10.10.12.0 0.0.0.255 host 222.121.118.144 log
+ deny ip 10.10.12.0 0.0.0.255 host 222.174.113.2 log
+!
+! Rule 2 (ethernet0)
+ deny ip 10.10.10.0 0.0.0.255 host 58.33.181.83 log
+ deny ip 10.10.10.0 0.0.0.255 host 58.53.82.190 log
+ deny ip 10.10.10.0 0.0.0.255 host 58.231.13.78 log
+ deny ip 10.10.10.0 0.0.0.255 host 61.150.47.112 log
+ deny ip 10.10.10.0 0.0.0.255 host 61.184.14.102 log
+ deny ip 10.10.10.0 0.0.0.255 host 64.106.85.186 log
+ deny ip 10.10.10.0 0.0.0.255 host 70.228.60.100 log
+ deny ip 10.10.10.0 0.0.0.255 host 80.51.236.6 log
+ deny ip 10.10.10.0 0.0.0.255 host 80.243.72.149 log
+ deny ip 10.10.10.0 0.0.0.255 host 80.249.77.34 log
+ deny ip 10.10.10.0 0.0.0.255 host 81.2.36.254 log
+ deny ip 10.10.10.0 0.0.0.255 host 81.196.74.125 log
+ deny ip 10.10.10.0 0.0.0.255 host 82.77.37.174 log
+ deny ip 10.10.10.0 0.0.0.255 host 82.117.221.205 log
+ deny ip 10.10.10.0 0.0.0.255 host 82.143.196.17 log
+ deny ip 10.10.10.0 0.0.0.255 host 84.90.8.198 log
+ deny ip 10.10.10.0 0.0.0.255 host 151.8.224.178 log
+ deny ip 10.10.10.0 0.0.0.255 host 168.156.76.20 log
+ deny ip 10.10.10.0 0.0.0.255 host 192.168.1.1 log
+ deny ip 10.10.10.0 0.0.0.255 host 192.168.1.2 log
+ deny ip 10.10.10.0 0.0.0.255 192.168.1.3 0.0.0.3 log
+ deny ip 10.10.10.0 0.0.0.255 host 192.168.1.200 log
+ deny ip 10.10.10.0 0.0.0.255 host 192.168.1.201 log
+ deny ip 10.10.10.0 0.0.0.255 192.168.2.128 0.0.0.127 log
+ deny ip 10.10.10.0 0.0.0.255 host 193.207.126.36 log
+ deny ip 10.10.10.0 0.0.0.255 host 195.136.186.35 log
+ deny ip 10.10.10.0 0.0.0.255 host 196.15.136.15 log
+ deny ip 10.10.10.0 0.0.0.255 host 201.10.180.138 log
+ deny ip 10.10.10.0 0.0.0.255 host 201.17.93.16 log
+ deny ip 10.10.10.0 0.0.0.255 host 201.36.156.121 log
+ deny ip 10.10.10.0 0.0.0.255 host 202.96.112.93 log
+ deny ip 10.10.10.0 0.0.0.255 host 202.103.25.253 log
+ deny ip 10.10.10.0 0.0.0.255 host 203.162.3.209 log
+ deny ip 10.10.10.0 0.0.0.255 host 203.209.124.144 log
+ deny ip 10.10.10.0 0.0.0.255 host 210.106.193.237 log
+ deny ip 10.10.10.0 0.0.0.255 host 210.222.114.102 log
+ deny ip 10.10.10.0 0.0.0.255 host 211.144.143.143 log
+ deny ip 10.10.10.0 0.0.0.255 host 211.172.218.237 log
+ deny ip 10.10.10.0 0.0.0.255 host 211.250.16.132 log
+ deny ip 10.10.10.0 0.0.0.255 host 212.21.241.31 log
+ deny ip 10.10.10.0 0.0.0.255 host 212.100.212.100 log
+ deny ip 10.10.10.0 0.0.0.255 host 218.18.72.252 log
+ deny ip 10.10.10.0 0.0.0.255 host 218.39.114.122 log
+ deny ip 10.10.10.0 0.0.0.255 host 218.55.115.43 log
+ deny ip 10.10.10.0 0.0.0.255 host 218.104.138.146 log
+ deny ip 10.10.10.0 0.0.0.255 host 219.132.104.160 log
+ deny ip 10.10.10.0 0.0.0.255 host 220.71.17.86 log
+ deny ip 10.10.10.0 0.0.0.255 host 220.81.50.105 log
+ deny ip 10.10.10.0 0.0.0.255 host 220.91.99.46 log
+ deny ip 10.10.10.0 0.0.0.255 host 221.14.249.242 log
+ deny ip 10.10.10.0 0.0.0.255 host 221.166.177.135 log
+ deny ip 10.10.10.0 0.0.0.255 host 221.198.33.38 log
+ deny ip 10.10.10.0 0.0.0.255 host 221.202.160.233 log
+ deny ip 10.10.10.0 0.0.0.255 host 221.205.54.125 log
+ deny ip 10.10.10.0 0.0.0.255 host 221.217.44.248 log
+ deny ip 10.10.10.0 0.0.0.255 host 222.100.212.223 log
+ deny ip 10.10.10.0 0.0.0.255 host 222.121.118.144 log
+ deny ip 10.10.10.0 0.0.0.255 host 222.174.113.2 log
+ deny ip 10.10.11.0 0.0.0.255 host 58.33.181.83 log
+ deny ip 10.10.11.0 0.0.0.255 host 58.53.82.190 log
+ deny ip 10.10.11.0 0.0.0.255 host 58.231.13.78 log
+ deny ip 10.10.11.0 0.0.0.255 host 61.150.47.112 log
+ deny ip 10.10.11.0 0.0.0.255 host 61.184.14.102 log
+ deny ip 10.10.11.0 0.0.0.255 host 64.106.85.186 log
+ deny ip 10.10.11.0 0.0.0.255 host 70.228.60.100 log
+ deny ip 10.10.11.0 0.0.0.255 host 80.51.236.6 log
+ deny ip 10.10.11.0 0.0.0.255 host 80.243.72.149 log
+ deny ip 10.10.11.0 0.0.0.255 host 80.249.77.34 log
+ deny ip 10.10.11.0 0.0.0.255 host 81.2.36.254 log
+ deny ip 10.10.11.0 0.0.0.255 host 81.196.74.125 log
+ deny ip 10.10.11.0 0.0.0.255 host 82.77.37.174 log
+ deny ip 10.10.11.0 0.0.0.255 host 82.117.221.205 log
+ deny ip 10.10.11.0 0.0.0.255 host 82.143.196.17 log
+ deny ip 10.10.11.0 0.0.0.255 host 84.90.8.198 log
+ deny ip 10.10.11.0 0.0.0.255 host 151.8.224.178 log
+ deny ip 10.10.11.0 0.0.0.255 host 168.156.76.20 log
+ deny ip 10.10.11.0 0.0.0.255 host 192.168.1.1 log
+ deny ip 10.10.11.0 0.0.0.255 host 192.168.1.2 log
+ deny ip 10.10.11.0 0.0.0.255 192.168.1.3 0.0.0.3 log
+ deny ip 10.10.11.0 0.0.0.255 host 192.168.1.200 log
+ deny ip 10.10.11.0 0.0.0.255 host 192.168.1.201 log
+ deny ip 10.10.11.0 0.0.0.255 192.168.2.128 0.0.0.127 log
+ deny ip 10.10.11.0 0.0.0.255 host 193.207.126.36 log
+ deny ip 10.10.11.0 0.0.0.255 host 195.136.186.35 log
+ deny ip 10.10.11.0 0.0.0.255 host 196.15.136.15 log
+ deny ip 10.10.11.0 0.0.0.255 host 201.10.180.138 log
+ deny ip 10.10.11.0 0.0.0.255 host 201.17.93.16 log
+ deny ip 10.10.11.0 0.0.0.255 host 201.36.156.121 log
+ deny ip 10.10.11.0 0.0.0.255 host 202.96.112.93 log
+ deny ip 10.10.11.0 0.0.0.255 host 202.103.25.253 log
+ deny ip 10.10.11.0 0.0.0.255 host 203.162.3.209 log
+ deny ip 10.10.11.0 0.0.0.255 host 203.209.124.144 log
+ deny ip 10.10.11.0 0.0.0.255 host 210.106.193.237 log
+ deny ip 10.10.11.0 0.0.0.255 host 210.222.114.102 log
+ deny ip 10.10.11.0 0.0.0.255 host 211.144.143.143 log
+ deny ip 10.10.11.0 0.0.0.255 host 211.172.218.237 log
+ deny ip 10.10.11.0 0.0.0.255 host 211.250.16.132 log
+ deny ip 10.10.11.0 0.0.0.255 host 212.21.241.31 log
+ deny ip 10.10.11.0 0.0.0.255 host 212.100.212.100 log
+ deny ip 10.10.11.0 0.0.0.255 host 218.18.72.252 log
+ deny ip 10.10.11.0 0.0.0.255 host 218.39.114.122 log
+ deny ip 10.10.11.0 0.0.0.255 host 218.55.115.43 log
+ deny ip 10.10.11.0 0.0.0.255 host 218.104.138.146 log
+ deny ip 10.10.11.0 0.0.0.255 host 219.132.104.160 log
+ deny ip 10.10.11.0 0.0.0.255 host 220.71.17.86 log
+ deny ip 10.10.11.0 0.0.0.255 host 220.81.50.105 log
+ deny ip 10.10.11.0 0.0.0.255 host 220.91.99.46 log
+ deny ip 10.10.11.0 0.0.0.255 host 221.14.249.242 log
+ deny ip 10.10.11.0 0.0.0.255 host 221.166.177.135 log
+ deny ip 10.10.11.0 0.0.0.255 host 221.198.33.38 log
+ deny ip 10.10.11.0 0.0.0.255 host 221.202.160.233 log
+ deny ip 10.10.11.0 0.0.0.255 host 221.205.54.125 log
+ deny ip 10.10.11.0 0.0.0.255 host 221.217.44.248 log
+ deny ip 10.10.11.0 0.0.0.255 host 222.100.212.223 log
+ deny ip 10.10.11.0 0.0.0.255 host 222.121.118.144 log
+ deny ip 10.10.11.0 0.0.0.255 host 222.174.113.2 log
+ deny ip 10.10.12.0 0.0.0.255 host 58.33.181.83 log
+ deny ip 10.10.12.0 0.0.0.255 host 58.53.82.190 log
+ deny ip 10.10.12.0 0.0.0.255 host 58.231.13.78 log
+ deny ip 10.10.12.0 0.0.0.255 host 61.150.47.112 log
+ deny ip 10.10.12.0 0.0.0.255 host 61.184.14.102 log
+ deny ip 10.10.12.0 0.0.0.255 host 64.106.85.186 log
+ deny ip 10.10.12.0 0.0.0.255 host 70.228.60.100 log
+ deny ip 10.10.12.0 0.0.0.255 host 80.51.236.6 log
+ deny ip 10.10.12.0 0.0.0.255 host 80.243.72.149 log
+ deny ip 10.10.12.0 0.0.0.255 host 80.249.77.34 log
+ deny ip 10.10.12.0 0.0.0.255 host 81.2.36.254 log
+ deny ip 10.10.12.0 0.0.0.255 host 81.196.74.125 log
+ deny ip 10.10.12.0 0.0.0.255 host 82.77.37.174 log
+ deny ip 10.10.12.0 0.0.0.255 host 82.117.221.205 log
+ deny ip 10.10.12.0 0.0.0.255 host 82.143.196.17 log
+ deny ip 10.10.12.0 0.0.0.255 host 84.90.8.198 log
+ deny ip 10.10.12.0 0.0.0.255 host 151.8.224.178 log
+ deny ip 10.10.12.0 0.0.0.255 host 168.156.76.20 log
+ deny ip 10.10.12.0 0.0.0.255 host 192.168.1.1 log
+ deny ip 10.10.12.0 0.0.0.255 host 192.168.1.2 log
+ deny ip 10.10.12.0 0.0.0.255 192.168.1.3 0.0.0.3 log
+ deny ip 10.10.12.0 0.0.0.255 host 192.168.1.200 log
+ deny ip 10.10.12.0 0.0.0.255 host 192.168.1.201 log
+ deny ip 10.10.12.0 0.0.0.255 192.168.2.128 0.0.0.127 log
+ deny ip 10.10.12.0 0.0.0.255 host 193.207.126.36 log
+ deny ip 10.10.12.0 0.0.0.255 host 195.136.186.35 log
+ deny ip 10.10.12.0 0.0.0.255 host 196.15.136.15 log
+ deny ip 10.10.12.0 0.0.0.255 host 201.10.180.138 log
+ deny ip 10.10.12.0 0.0.0.255 host 201.17.93.16 log
+ deny ip 10.10.12.0 0.0.0.255 host 201.36.156.121 log
+ deny ip 10.10.12.0 0.0.0.255 host 202.96.112.93 log
+ deny ip 10.10.12.0 0.0.0.255 host 202.103.25.253 log
+ deny ip 10.10.12.0 0.0.0.255 host 203.162.3.209 log
+ deny ip 10.10.12.0 0.0.0.255 host 203.209.124.144 log
+ deny ip 10.10.12.0 0.0.0.255 host 210.106.193.237 log
+ deny ip 10.10.12.0 0.0.0.255 host 210.222.114.102 log
+ deny ip 10.10.12.0 0.0.0.255 host 211.144.143.143 log
+ deny ip 10.10.12.0 0.0.0.255 host 211.172.218.237 log
+ deny ip 10.10.12.0 0.0.0.255 host 211.250.16.132 log
+ deny ip 10.10.12.0 0.0.0.255 host 212.21.241.31 log
+ deny ip 10.10.12.0 0.0.0.255 host 212.100.212.100 log
+ deny ip 10.10.12.0 0.0.0.255 host 218.18.72.252 log
+ deny ip 10.10.12.0 0.0.0.255 host 218.39.114.122 log
+ deny ip 10.10.12.0 0.0.0.255 host 218.55.115.43 log
+ deny ip 10.10.12.0 0.0.0.255 host 218.104.138.146 log
+ deny ip 10.10.12.0 0.0.0.255 host 219.132.104.160 log
+ deny ip 10.10.12.0 0.0.0.255 host 220.71.17.86 log
+ deny ip 10.10.12.0 0.0.0.255 host 220.81.50.105 log
+ deny ip 10.10.12.0 0.0.0.255 host 220.91.99.46 log
+ deny ip 10.10.12.0 0.0.0.255 host 221.14.249.242 log
+ deny ip 10.10.12.0 0.0.0.255 host 221.166.177.135 log
+ deny ip 10.10.12.0 0.0.0.255 host 221.198.33.38 log
+ deny ip 10.10.12.0 0.0.0.255 host 221.202.160.233 log
+ deny ip 10.10.12.0 0.0.0.255 host 221.205.54.125 log
+ deny ip 10.10.12.0 0.0.0.255 host 221.217.44.248 log
+ deny ip 10.10.12.0 0.0.0.255 host 222.100.212.223 log
+ deny ip 10.10.12.0 0.0.0.255 host 222.121.118.144 log
+ deny ip 10.10.12.0 0.0.0.255 host 222.174.113.2 log
+!
+! Rule 3 (ethernet0)
+! testios3:Policy:3: error: File not found for Address Table: missing table (file_does_not_exist.tbl) Using dummy address in test mode
+ deny ip 10.10.10.0 0.0.0.255 192.0.2.0 0.0.0.255 log
+! testios3:Policy:3: error: File not found for Address Table: missing table (file_does_not_exist.tbl) Using dummy address in test mode
+ deny ip 10.10.11.0 0.0.0.255 192.0.2.0 0.0.0.255 log
+! testios3:Policy:3: error: File not found for Address Table: missing table (file_does_not_exist.tbl) Using dummy address in test mode
+ deny ip 10.10.12.0 0.0.0.255 192.0.2.0 0.0.0.255 log
+!
+! Rule 4 (global)
+ deny ip any any log
+exit
+
+ip access-list extended e1_in
+!
+! Rule -1 backup ssh access rule (automatic)
+ permit tcp 10.10.10.0 0.0.0.255 host 1.1.1.1 eq 22
+ permit tcp 10.10.10.0 0.0.0.255 host 10.10.10.1 eq 22
+!
+! Rule 4 (global)
+ deny ip any any log
+exit
+
+ip access-list extended e1_out
+!
+! Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 1.1.1.1 eq 22 10.10.10.0 0.0.0.255
+ permit tcp host 10.10.10.1 eq 22 10.10.10.0 0.0.0.255
+!
+! Rule 4 (global)
+ deny ip any any log
+exit
+
+
+interface ethernet0
+ ip access-group e0_in in
+exit
+interface ethernet0
+ ip access-group e0_out out
+exit
+interface ethernet1
+ ip access-group e1_in in
+exit
+interface ethernet1
+ ip access-group e1_out out
+exit
+
+
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/iosacl/testios4.fw.orig b/test/iosacl/testios4.fw.orig
new file mode 100755
index 000000000..6f10186ca
--- /dev/null
+++ b/test/iosacl/testios4.fw.orig
@@ -0,0 +1,265 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_iosacl v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:51:13 2011 PST by vadim
+!
+! Compiled for iosacl 12.4
+!
+!# files: * testios4.fw
+!
+! using object-groups
+
+! testios4:Policy:3: error: File not found for Address Table: missing table (file_does_not_exist.tbl) Using dummy address in test mode
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+hostname testios4
+
+! temporary access list for "safety net install"
+no ip access-list extended tmp_acl
+ip access-list extended tmp_acl
+ permit ip 10.10.10.0 0.0.0.255 any
+ deny ip any any
+exit
+interface ethernet1
+ no ip access-group in
+ no ip access-group out
+ ip access-group tmp_acl in
+exit
+
+! ================ IPv4
+
+
+no ip access-list extended e0_in
+no ip access-list extended e0_out
+no ip access-list extended e1_in
+no ip access-list extended e1_out
+
+no object-group network .src.net.0
+no object-group network id47180X84238.src.net.0
+no object-group network id47180X84238.dst.net.0
+no object-group network id47192X84238.dst.net.0
+no object-group network id47204X84238.dst.net.0
+
+
+object-group network .src.net.0
+ host 1.1.1.1
+ host 10.10.10.1
+exit
+
+
+object-group network id47180X84238.src.net.0
+ 10.10.10.0 /24
+ 10.10.11.0 /24
+ 10.10.12.0 /24
+exit
+
+
+object-group network id47180X84238.dst.net.0
+ 192.168.1.1 /32
+ 192.168.1.2 /32
+ 192.168.1.3 /30
+ 192.168.1.200 /32
+ 192.168.1.201 /32
+ 192.168.2.128 /25
+exit
+
+
+object-group network id47192X84238.dst.net.0
+ 58.33.181.83 /32
+ 58.53.82.190 /32
+ 58.231.13.78 /32
+ 61.150.47.112 /32
+ 61.184.14.102 /32
+ 64.106.85.186 /32
+ 70.228.60.100 /32
+ 80.51.236.6 /32
+ 80.243.72.149 /32
+ 80.249.77.34 /32
+ 81.2.36.254 /32
+ 81.196.74.125 /32
+ 82.77.37.174 /32
+ 82.117.221.205 /32
+ 82.143.196.17 /32
+ 84.90.8.198 /32
+ 151.8.224.178 /32
+ 168.156.76.20 /32
+ 193.207.126.36 /32
+ 195.136.186.35 /32
+ 196.15.136.15 /32
+ 201.10.180.138 /32
+ 201.17.93.16 /32
+ 201.36.156.121 /32
+ 202.96.112.93 /32
+ 202.103.25.253 /32
+ 203.162.3.209 /32
+ 203.209.124.144 /32
+ 210.106.193.237 /32
+ 210.222.114.102 /32
+ 211.144.143.143 /32
+ 211.172.218.237 /32
+ 211.250.16.132 /32
+ 212.21.241.31 /32
+ 212.100.212.100 /32
+ 218.18.72.252 /32
+ 218.39.114.122 /32
+ 218.55.115.43 /32
+ 218.104.138.146 /32
+ 219.132.104.160 /32
+ 220.71.17.86 /32
+ 220.81.50.105 /32
+ 220.91.99.46 /32
+ 221.14.249.242 /32
+ 221.166.177.135 /32
+ 221.198.33.38 /32
+ 221.202.160.233 /32
+ 221.205.54.125 /32
+ 221.217.44.248 /32
+ 222.100.212.223 /32
+ 222.121.118.144 /32
+ 222.174.113.2 /32
+exit
+
+
+object-group network id47204X84238.dst.net.0
+ 58.33.181.83 /32
+ 58.53.82.190 /32
+ 58.231.13.78 /32
+ 61.150.47.112 /32
+ 61.184.14.102 /32
+ 64.106.85.186 /32
+ 70.228.60.100 /32
+ 80.51.236.6 /32
+ 80.243.72.149 /32
+ 80.249.77.34 /32
+ 81.2.36.254 /32
+ 81.196.74.125 /32
+ 82.77.37.174 /32
+ 82.117.221.205 /32
+ 82.143.196.17 /32
+ 84.90.8.198 /32
+ 151.8.224.178 /32
+ 168.156.76.20 /32
+ 192.168.1.1 /32
+ 192.168.1.2 /32
+ 192.168.1.3 /30
+ 192.168.1.200 /32
+ 192.168.1.201 /32
+ 192.168.2.128 /25
+ 193.207.126.36 /32
+ 195.136.186.35 /32
+ 196.15.136.15 /32
+ 201.10.180.138 /32
+ 201.17.93.16 /32
+ 201.36.156.121 /32
+ 202.96.112.93 /32
+ 202.103.25.253 /32
+ 203.162.3.209 /32
+ 203.209.124.144 /32
+ 210.106.193.237 /32
+ 210.222.114.102 /32
+ 211.144.143.143 /32
+ 211.172.218.237 /32
+ 211.250.16.132 /32
+ 212.21.241.31 /32
+ 212.100.212.100 /32
+ 218.18.72.252 /32
+ 218.39.114.122 /32
+ 218.55.115.43 /32
+ 218.104.138.146 /32
+ 219.132.104.160 /32
+ 220.71.17.86 /32
+ 220.81.50.105 /32
+ 220.91.99.46 /32
+ 221.14.249.242 /32
+ 221.166.177.135 /32
+ 221.198.33.38 /32
+ 221.202.160.233 /32
+ 221.205.54.125 /32
+ 221.217.44.248 /32
+ 222.100.212.223 /32
+ 222.121.118.144 /32
+ 222.174.113.2 /32
+exit
+
+ip access-list extended e0_in
+!
+! Rule -1 backup ssh access rule (automatic)
+ permit tcp 10.10.10.0 0.0.0.255 object-group .src.net.0 eq 22
+!
+! Rule 4 (global)
+ deny ip any any log
+exit
+
+ip access-list extended e0_out
+!
+! Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp object-group .src.net.0 eq 22 10.10.10.0 0.0.0.255
+!
+! Rule 0 (ethernet0)
+ deny ip object-group id47180X84238.src.net.0 object-group id47180X84238.dst.net.0 log
+!
+! Rule 1 (ethernet0)
+ deny ip object-group id47180X84238.src.net.0 object-group id47192X84238.dst.net.0 log
+!
+! Rule 2 (ethernet0)
+ deny ip object-group id47180X84238.src.net.0 object-group id47204X84238.dst.net.0 log
+!
+! Rule 3 (ethernet0)
+! testios4:Policy:3: error: File not found for Address Table: missing table (file_does_not_exist.tbl) Using dummy address in test mode
+ deny ip object-group id47180X84238.src.net.0 192.0.2.0 0.0.0.255 log
+!
+! Rule 4 (global)
+ deny ip any any log
+exit
+
+ip access-list extended e1_in
+!
+! Rule -1 backup ssh access rule (automatic)
+ permit tcp 10.10.10.0 0.0.0.255 object-group .src.net.0 eq 22
+!
+! Rule 4 (global)
+ deny ip any any log
+exit
+
+ip access-list extended e1_out
+!
+! Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp object-group .src.net.0 eq 22 10.10.10.0 0.0.0.255
+!
+! Rule 4 (global)
+ deny ip any any log
+exit
+
+
+interface ethernet0
+ ip access-group e0_in in
+exit
+interface ethernet0
+ ip access-group e0_out out
+exit
+interface ethernet1
+ ip access-group e1_in in
+exit
+interface ethernet1
+ ip access-group e1_out out
+exit
+
+
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/iosacl/testios5-1.fw.orig b/test/iosacl/testios5-1.fw.orig
new file mode 100755
index 000000000..1fdeff38f
--- /dev/null
+++ b/test/iosacl/testios5-1.fw.orig
@@ -0,0 +1,223 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_iosacl v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:51:14 2011 PST by vadim
+!
+! Compiled for iosacl 12.4
+!
+!# files: * testios5-1.fw
+!
+! mirrored rules, using object-groups
+
+
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+hostname testios5-1
+
+! temporary access list for "safety net install"
+no ip access-list extended tmp_acl
+ip access-list extended tmp_acl
+ permit ip 10.10.10.0 0.0.0.255 any
+ deny ip any any
+exit
+interface ethernet1
+ no ip access-group in
+ no ip access-group out
+ ip access-group tmp_acl in
+exit
+
+! ================ IPv4
+
+
+no ip access-list extended e0_in
+no ip access-list extended e0_out
+no ip access-list extended e1_in
+no ip access-list extended e1_out
+
+no object-group network .src.net.0
+no object-group network id115999X79820.src.net.0
+no object-group network id115999X79820.dst.net.0
+no object-group service id116125X79820.srv.tcp.0
+no object-group service id91445X81725.srv.tcp.0
+
+
+object-group network .src.net.0
+ host 1.1.1.1
+ host 10.10.10.1
+exit
+
+
+object-group network id115999X79820.src.net.0
+ 22.22.21.0 /24
+ 22.22.22.0 /24
+exit
+
+
+object-group network id115999X79820.dst.net.0
+ 10.10.10.0 /24
+ 10.10.11.0 /24
+exit
+
+
+object-group service id116125X79820.srv.tcp.0
+ tcp eq 80
+ tcp eq 443
+exit
+
+
+object-group service id91445X81725.srv.tcp.0
+ tcp range 0 65535
+ tcp eq 80
+exit
+
+ip access-list extended e0_in
+!
+! Rule -1 backup ssh access rule (automatic)
+ permit tcp 10.10.10.0 0.0.0.255 object-group .src.net.0 eq 22
+!
+! Rule 0 (ethernet0)
+ permit ip object-group id115999X79820.src.net.0 object-group id115999X79820.dst.net.0
+!
+! Rule 1 (ethernet0)
+ permit ip object-group id115999X79820.dst.net.0 object-group id115999X79820.src.net.0
+!
+! Rule 2 (ethernet0)
+ permit ip object-group id115999X79820.src.net.0 object-group id115999X79820.dst.net.0
+ permit ip object-group id115999X79820.dst.net.0 object-group id115999X79820.src.net.0
+!
+! Rule 3 (ethernet0)
+ deny ip object-group id115999X79820.src.net.0 object-group id115999X79820.dst.net.0
+!
+! Rule 4 (ethernet0)
+ permit tcp object-group id115999X79820.src.net.0 eq 80 object-group id115999X79820.dst.net.0 established
+!
+! Rule 5 (ethernet0)
+ permit tcp object-group id115999X79820.dst.net.0 object-group id115999X79820.src.net.0 eq 80
+!
+! Rule 6 (ethernet0)
+ permit tcp object-group id115999X79820.src.net.0 object-group id115999X79820.dst.net.0 eq 80
+!
+! Rule 7 (ethernet0)
+ permit udp object-group id115999X79820.src.net.0 eq 123 object-group id115999X79820.dst.net.0
+!
+! Rule 8 (ethernet0)
+ permit icmp object-group id115999X79820.src.net.0 object-group id115999X79820.dst.net.0 0
+!
+! Rule 9 (ethernet0)
+ permit icmp object-group id115999X79820.src.net.0 object-group id115999X79820.dst.net.0 0
+ permit tcp object-group id115999X79820.src.net.0 eq 80 object-group id115999X79820.dst.net.0 established
+ permit tcp object-group id115999X79820.src.net.0 eq 443 object-group id115999X79820.dst.net.0 established
+ permit ip object-group id115999X79820.src.net.0 object-group id115999X79820.dst.net.0
+ permit udp object-group id115999X79820.src.net.0 eq 123 object-group id115999X79820.dst.net.0
+!
+! Rule 10 (ethernet0)
+ permit tcp object-group id115999X79820.src.net.0 object-group id115999X79820.dst.net.0 match-all -urg +ack -psh -rst -syn -fin
+ permit tcp object-group id115999X79820.src.net.0 object-group id115999X79820.dst.net.0 match-all -urg +ack -psh -rst +syn -fin
+ permit tcp object-group id115999X79820.src.net.0 eq 80 object-group id115999X79820.dst.net.0 established
+ permit tcp object-group id115999X79820.src.net.0 eq 443 object-group id115999X79820.dst.net.0 established
+ permit ip object-group id115999X79820.src.net.0 object-group id115999X79820.dst.net.0
+!
+! Rule 11 (ethernet0)
+ permit object-group id91445X81725.srv.tcp.0 object-group id115999X79820.src.net.0 object-group id115999X79820.dst.net.0
+!
+! Rule 12 (ethernet0)
+ permit ip object-group id115999X79820.src.net.0 object-group id115999X79820.dst.net.0
+exit
+
+ip access-list extended e0_out
+!
+! Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp object-group .src.net.0 eq 22 10.10.10.0 0.0.0.255
+!
+! Rule 0 (ethernet0)
+ permit ip object-group id115999X79820.dst.net.0 object-group id115999X79820.src.net.0
+!
+! Rule 1 (ethernet0)
+ permit ip object-group id115999X79820.src.net.0 object-group id115999X79820.dst.net.0
+!
+! Rule 2 (ethernet0)
+ permit ip object-group id115999X79820.src.net.0 object-group id115999X79820.dst.net.0
+ permit ip object-group id115999X79820.dst.net.0 object-group id115999X79820.src.net.0
+!
+! Rule 3 (ethernet0)
+ deny ip object-group id115999X79820.dst.net.0 object-group id115999X79820.src.net.0
+!
+! Rule 4 (ethernet0)
+ permit tcp object-group id115999X79820.dst.net.0 object-group id115999X79820.src.net.0 eq 80
+!
+! Rule 5 (ethernet0)
+ permit tcp object-group id115999X79820.src.net.0 eq 80 object-group id115999X79820.dst.net.0 established
+!
+! Rule 6 (ethernet0)
+ permit tcp object-group id115999X79820.dst.net.0 eq 80 object-group id115999X79820.src.net.0 established
+!
+! Rule 7 (ethernet0)
+ permit udp object-group id115999X79820.dst.net.0 object-group id115999X79820.src.net.0 eq 123
+!
+! Rule 8 (ethernet0)
+ permit icmp object-group id115999X79820.dst.net.0 object-group id115999X79820.src.net.0 8
+!
+! Rule 9 (ethernet0)
+ permit icmp object-group id115999X79820.dst.net.0 object-group id115999X79820.src.net.0 8
+ permit object-group id116125X79820.srv.tcp.0 object-group id115999X79820.dst.net.0 object-group id115999X79820.src.net.0
+ permit udp object-group id115999X79820.dst.net.0 object-group id115999X79820.src.net.0 eq 123
+!
+! Rule 10 (ethernet0)
+ permit tcp object-group id115999X79820.dst.net.0 object-group id115999X79820.src.net.0 match-all -urg +ack -psh -rst -syn -fin
+ permit tcp object-group id115999X79820.dst.net.0 object-group id115999X79820.src.net.0 match-all -urg +ack -psh -rst +syn -fin
+ permit object-group id116125X79820.srv.tcp.0 object-group id115999X79820.dst.net.0 object-group id115999X79820.src.net.0
+!
+! Rule 11 (ethernet0)
+ permit tcp object-group id115999X79820.dst.net.0 object-group id115999X79820.src.net.0 established
+ permit tcp object-group id115999X79820.dst.net.0 eq 80 object-group id115999X79820.src.net.0 established
+ permit ip object-group id115999X79820.dst.net.0 object-group id115999X79820.src.net.0
+!
+! Rule 12 (ethernet0)
+ permit ip object-group id115999X79820.dst.net.0 object-group id115999X79820.src.net.0
+exit
+
+ip access-list extended e1_in
+!
+! Rule -1 backup ssh access rule (automatic)
+ permit tcp 10.10.10.0 0.0.0.255 object-group .src.net.0 eq 22
+exit
+
+ip access-list extended e1_out
+!
+! Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp object-group .src.net.0 eq 22 10.10.10.0 0.0.0.255
+exit
+
+
+interface ethernet0
+ ip access-group e0_in in
+exit
+interface ethernet0
+ ip access-group e0_out out
+exit
+interface ethernet1
+ ip access-group e1_in in
+exit
+interface ethernet1
+ ip access-group e1_out out
+exit
+
+
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/iosacl/testios5.fw.orig b/test/iosacl/testios5.fw.orig
new file mode 100755
index 000000000..ac6f9ff50
--- /dev/null
+++ b/test/iosacl/testios5.fw.orig
@@ -0,0 +1,346 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_iosacl v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:51:14 2011 PST by vadim
+!
+! Compiled for iosacl 12.4
+!
+!# files: * testios5.fw
+!
+! mirrored rules, not using object-groups
+
+
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+hostname testios5
+
+! temporary access list for "safety net install"
+no ip access-list extended tmp_acl
+ip access-list extended tmp_acl
+ permit ip 10.10.10.0 0.0.0.255 any
+ deny ip any any
+exit
+interface ethernet1
+ no ip access-group in
+ no ip access-group out
+ ip access-group tmp_acl in
+exit
+
+! ================ IPv4
+
+
+no ip access-list extended e0_in
+no ip access-list extended e0_out
+no ip access-list extended e1_in
+no ip access-list extended e1_out
+
+
+ip access-list extended e0_in
+!
+! Rule -1 backup ssh access rule (automatic)
+ permit tcp 10.10.10.0 0.0.0.255 host 1.1.1.1 eq 22
+ permit tcp 10.10.10.0 0.0.0.255 host 10.10.10.1 eq 22
+!
+! Rule 0 (ethernet0)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+!
+! Rule 1 (ethernet0)
+ permit ip 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255
+ permit ip 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255
+ permit ip 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255
+ permit ip 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255
+!
+! Rule 2 (ethernet0)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255
+ permit ip 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255
+ permit ip 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255
+ permit ip 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255
+!
+! Rule 3 (ethernet0)
+ deny ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ deny ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ deny ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ deny ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+!
+! Rule 4 (ethernet0)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.11.0 0.0.0.255 established
+ permit tcp 22.22.22.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+ permit tcp 22.22.22.0 0.0.0.255 eq 80 10.10.11.0 0.0.0.255 established
+!
+! Rule 5 (ethernet0)
+ permit tcp 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255 eq 80
+ permit tcp 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255 eq 80
+ permit tcp 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255 eq 80
+ permit tcp 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255 eq 80
+!
+! Rule 6 (ethernet0)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+ permit tcp 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255 eq 80
+ permit tcp 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+ permit tcp 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255 eq 80
+!
+! Rule 7 (ethernet0)
+ permit udp 22.22.21.0 0.0.0.255 eq 123 10.10.10.0 0.0.0.255
+ permit udp 22.22.21.0 0.0.0.255 eq 123 10.10.11.0 0.0.0.255
+ permit udp 22.22.22.0 0.0.0.255 eq 123 10.10.10.0 0.0.0.255
+ permit udp 22.22.22.0 0.0.0.255 eq 123 10.10.11.0 0.0.0.255
+!
+! Rule 8 (ethernet0)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit icmp 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255 0
+ permit icmp 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit icmp 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255 0
+!
+! Rule 9 (ethernet0)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit icmp 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255 0
+ permit icmp 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit icmp 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.11.0 0.0.0.255 established
+ permit tcp 22.22.22.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+ permit tcp 22.22.22.0 0.0.0.255 eq 80 10.10.11.0 0.0.0.255 established
+ permit udp 22.22.21.0 0.0.0.255 eq 123 10.10.10.0 0.0.0.255
+ permit udp 22.22.21.0 0.0.0.255 eq 123 10.10.11.0 0.0.0.255
+ permit udp 22.22.22.0 0.0.0.255 eq 123 10.10.10.0 0.0.0.255
+ permit udp 22.22.22.0 0.0.0.255 eq 123 10.10.11.0 0.0.0.255
+!
+! Rule 10 (ethernet0)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 match-all -urg +ack -psh -rst -syn -fin
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 match-all -urg +ack -psh -rst +syn -fin
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+ permit tcp 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255 match-all -urg +ack -psh -rst -syn -fin
+ permit tcp 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255 match-all -urg +ack -psh -rst +syn -fin
+ permit tcp 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255 eq 80
+ permit tcp 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255 match-all -urg +ack -psh -rst -syn -fin
+ permit tcp 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255 match-all -urg +ack -psh -rst +syn -fin
+ permit tcp 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+ permit tcp 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255 match-all -urg +ack -psh -rst -syn -fin
+ permit tcp 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255 match-all -urg +ack -psh -rst +syn -fin
+ permit tcp 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255 eq 80
+!
+! Rule 11 (ethernet0)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit tcp 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit tcp 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit tcp 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+!
+! Rule 12 (ethernet0)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 option any-options
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 dscp 16
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255 option any-options
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255 dscp 16
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255 option any-options
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255 dscp 16
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255 option any-options
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255 dscp 16
+!
+! Rule 13 (ethernet0)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit icmp 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255 0
+ permit icmp 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit icmp 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 eq 179 10.10.10.0 0.0.0.255 established
+ permit tcp 22.22.21.0 0.0.0.255 eq 79 10.10.10.0 0.0.0.255 established
+ permit tcp 22.22.21.0 0.0.0.255 eq 179 10.10.11.0 0.0.0.255 established
+ permit tcp 22.22.21.0 0.0.0.255 eq 79 10.10.11.0 0.0.0.255 established
+ permit tcp 22.22.22.0 0.0.0.255 eq 179 10.10.10.0 0.0.0.255 established
+ permit tcp 22.22.22.0 0.0.0.255 eq 79 10.10.10.0 0.0.0.255 established
+ permit tcp 22.22.22.0 0.0.0.255 eq 179 10.10.11.0 0.0.0.255 established
+ permit tcp 22.22.22.0 0.0.0.255 eq 79 10.10.11.0 0.0.0.255 established
+ permit udp 22.22.21.0 0.0.0.255 eq 123 10.10.10.0 0.0.0.255
+ permit udp 22.22.21.0 0.0.0.255 eq 26000 10.10.10.0 0.0.0.255
+ permit udp 22.22.21.0 0.0.0.255 eq 123 10.10.11.0 0.0.0.255
+ permit udp 22.22.21.0 0.0.0.255 eq 26000 10.10.11.0 0.0.0.255
+ permit udp 22.22.22.0 0.0.0.255 eq 123 10.10.10.0 0.0.0.255
+ permit udp 22.22.22.0 0.0.0.255 eq 26000 10.10.10.0 0.0.0.255
+ permit udp 22.22.22.0 0.0.0.255 eq 123 10.10.11.0 0.0.0.255
+ permit udp 22.22.22.0 0.0.0.255 eq 26000 10.10.11.0 0.0.0.255
+exit
+
+ip access-list extended e0_out
+!
+! Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 1.1.1.1 eq 22 10.10.10.0 0.0.0.255
+ permit tcp host 10.10.10.1 eq 22 10.10.10.0 0.0.0.255
+!
+! Rule 0 (ethernet0)
+ permit ip 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255
+ permit ip 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255
+ permit ip 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255
+ permit ip 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255
+!
+! Rule 1 (ethernet0)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+!
+! Rule 2 (ethernet0)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255
+ permit ip 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255
+ permit ip 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255
+ permit ip 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255
+!
+! Rule 3 (ethernet0)
+ deny ip 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255
+ deny ip 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255
+ deny ip 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255
+ deny ip 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255
+!
+! Rule 4 (ethernet0)
+ permit tcp 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255 eq 80
+ permit tcp 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255 eq 80
+ permit tcp 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255 eq 80
+ permit tcp 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255 eq 80
+!
+! Rule 5 (ethernet0)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.11.0 0.0.0.255 established
+ permit tcp 22.22.22.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+ permit tcp 22.22.22.0 0.0.0.255 eq 80 10.10.11.0 0.0.0.255 established
+!
+! Rule 6 (ethernet0)
+ permit tcp 10.10.10.0 0.0.0.255 eq 80 22.22.21.0 0.0.0.255 established
+ permit tcp 10.10.10.0 0.0.0.255 eq 80 22.22.22.0 0.0.0.255 established
+ permit tcp 10.10.11.0 0.0.0.255 eq 80 22.22.21.0 0.0.0.255 established
+ permit tcp 10.10.11.0 0.0.0.255 eq 80 22.22.22.0 0.0.0.255 established
+!
+! Rule 7 (ethernet0)
+ permit udp 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255 eq 123
+ permit udp 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255 eq 123
+ permit udp 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255 eq 123
+ permit udp 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255 eq 123
+!
+! Rule 8 (ethernet0)
+ permit icmp 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255 8
+ permit icmp 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255 8
+ permit icmp 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255 8
+ permit icmp 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255 8
+!
+! Rule 9 (ethernet0)
+ permit icmp 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255 8
+ permit icmp 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255 8
+ permit icmp 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255 8
+ permit icmp 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255 8
+ permit tcp 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255 eq 80
+ permit tcp 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255 eq 80
+ permit tcp 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255 eq 80
+ permit tcp 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255 eq 80
+ permit udp 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255 eq 123
+ permit udp 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255 eq 123
+ permit udp 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255 eq 123
+ permit udp 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255 eq 123
+!
+! Rule 10 (ethernet0)
+ permit tcp 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255 match-all -urg +ack -psh -rst -syn -fin
+ permit tcp 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255 match-all -urg +ack -psh -rst +syn -fin
+ permit tcp 10.10.10.0 0.0.0.255 eq 80 22.22.21.0 0.0.0.255 established
+ permit tcp 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255 match-all -urg +ack -psh -rst -syn -fin
+ permit tcp 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255 match-all -urg +ack -psh -rst +syn -fin
+ permit tcp 10.10.10.0 0.0.0.255 eq 80 22.22.22.0 0.0.0.255 established
+ permit tcp 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255 match-all -urg +ack -psh -rst -syn -fin
+ permit tcp 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255 match-all -urg +ack -psh -rst +syn -fin
+ permit tcp 10.10.11.0 0.0.0.255 eq 80 22.22.21.0 0.0.0.255 established
+ permit tcp 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255 match-all -urg +ack -psh -rst -syn -fin
+ permit tcp 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255 match-all -urg +ack -psh -rst +syn -fin
+ permit tcp 10.10.11.0 0.0.0.255 eq 80 22.22.22.0 0.0.0.255 established
+!
+! Rule 11 (ethernet0)
+ permit tcp 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255 established
+ permit tcp 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255 established
+ permit tcp 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255 established
+ permit tcp 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255 established
+!
+! Rule 12 (ethernet0)
+ permit ip 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255 option any-options
+ permit ip 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255 dscp 16
+ permit ip 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255 option any-options
+ permit ip 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255 dscp 16
+ permit ip 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255 option any-options
+ permit ip 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255 dscp 16
+ permit ip 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255 option any-options
+ permit ip 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255 dscp 16
+!
+! Rule 13 (ethernet0)
+ permit icmp 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255 0
+ permit icmp 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255 0
+ permit icmp 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255 0
+ permit icmp 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255 0
+ permit tcp 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255 eq 179
+ permit tcp 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255 eq 79
+ permit tcp 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255 eq 179
+ permit tcp 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255 eq 79
+ permit tcp 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255 eq 179
+ permit tcp 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255 eq 79
+ permit tcp 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255 eq 179
+ permit tcp 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255 eq 79
+ permit udp 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255 eq 123
+ permit udp 10.10.10.0 0.0.0.255 22.22.21.0 0.0.0.255 eq 26000
+ permit udp 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255 eq 123
+ permit udp 10.10.10.0 0.0.0.255 22.22.22.0 0.0.0.255 eq 26000
+ permit udp 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255 eq 123
+ permit udp 10.10.11.0 0.0.0.255 22.22.21.0 0.0.0.255 eq 26000
+ permit udp 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255 eq 123
+ permit udp 10.10.11.0 0.0.0.255 22.22.22.0 0.0.0.255 eq 26000
+exit
+
+ip access-list extended e1_in
+!
+! Rule -1 backup ssh access rule (automatic)
+ permit tcp 10.10.10.0 0.0.0.255 host 1.1.1.1 eq 22
+ permit tcp 10.10.10.0 0.0.0.255 host 10.10.10.1 eq 22
+exit
+
+ip access-list extended e1_out
+!
+! Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 1.1.1.1 eq 22 10.10.10.0 0.0.0.255
+ permit tcp host 10.10.10.1 eq 22 10.10.10.0 0.0.0.255
+exit
+
+
+interface ethernet0
+ ip access-group e0_in in
+exit
+interface ethernet0
+ ip access-group e0_out out
+exit
+interface ethernet1
+ ip access-group e1_in in
+exit
+interface ethernet1
+ ip access-group e1_out out
+exit
+
+
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/ipf/firewall-ipf.conf.orig b/test/ipf/firewall-ipf.conf.orig
new file mode 100755
index 000000000..c7593eec8
--- /dev/null
+++ b/test/ipf/firewall-ipf.conf.orig
@@ -0,0 +1,460 @@
+# Policy compiler errors and warnings:
+# firewall:Policy:4: warning: Changing rule direction due to self reference
+# firewall:Policy:8: warning: Changing rule direction due to self reference
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+# firewall:Policy:20: warning: Changing rule direction due to self reference
+# firewall:Policy:: warning: ipfilter can not match "any IP option"
+# firewall:Policy:: warning: ipfilter can not match "any IP option"
+#
+# Rule backup ssh access rule
+# backup ssh access rule
+pass in quick proto tcp from 192.168.1.100 to 192.168.1.1 port = 22 flags S keep state
+pass in quick proto tcp from 192.168.1.100 to 222.222.222.222 port = 22 flags S keep state
+#
+# Rule 0 (eth1)
+block in log level local0.warning quick on eth1 from any to 192.168.1.1 with short
+block in log level local0.warning quick on eth1 from any to 222.222.222.222 with short
+#
+# Rule 1 (eth1)
+# Automatically generated rule blocking short fragments
+block in log level local0.warning quick on eth1 from any to any with short
+#
+# Rule 2 (eth1)
+# Automatically generated anti-spoofing rule
+block in log level local0.warning quick on eth1 from 192.168.1.1 to any
+block in log level local0.warning quick on eth1 from 222.222.222.222 to any
+block in log level local0.warning quick on eth1 from 192.168.1.0/24 to any
+#
+# Rule 3 (eth1)
+# комментарий по-русски
+pass in quick on eth1 proto icmp from 22.22.22.0/24 to any keep state
+pass in quick on eth1 proto icmp from 33.33.33.0/24 to any keep state
+pass in quick on eth1 proto tcp from 22.22.22.0/24 to any flags S keep state
+pass in quick on eth1 proto tcp from 33.33.33.0/24 to any flags S keep state
+pass in quick on eth1 proto udp from 22.22.22.0/24 to any keep state
+pass in quick on eth1 proto udp from 33.33.33.0/24 to any keep state
+pass in quick on eth1 from 22.22.22.0/24 to any
+pass in quick on eth1 from 33.33.33.0/24 to any
+#
+# Rule 4 (eth0)
+# firewall:Policy:4: warning: Changing rule direction due to self reference
+pass in quick on eth0 proto udp from 192.168.1.0/24 to 192.168.1.1 port = 53 keep state
+# firewall:Policy:4: warning: Changing rule direction due to self reference
+pass in quick on eth0 proto udp from 192.168.1.0/24 to 222.222.222.222 port = 53 keep state
+#
+# Rule 5 (eth0)
+block in log level local0.warning quick on eth0 proto udp from any to 192.168.1.255 port = 53
+#
+# Rule 6 (global)
+block in log level local0.warning quick proto icmp from any to any
+block in log level local0.warning quick proto tcp from any to any flags S/UAPRSF
+block in log level local0.warning quick proto tcp from any to any flags ARSF/UAPRSF
+block out log level local0.warning quick proto icmp from any to any
+block out log level local0.warning quick proto tcp from any to any flags S/UAPRSF
+block out log level local0.warning quick proto tcp from any to any flags ARSF/UAPRSF
+#
+# Rule 7 (global)
+block return-icmp-as-dest (3) in log level local0.warning quick from any to any with opt rr
+block return-icmp-as-dest (3) in log level local0.warning quick from any to any with opt lsrr opt ssrr
+block return-icmp-as-dest (3) in log level local0.warning quick from any to any with opt ts
+block return-icmp-as-dest (3) in log level local0.warning quick from any to any
+block out log level local0.warning quick from any to any with opt rr
+block out log level local0.warning quick from any to any with opt lsrr opt ssrr
+block out log level local0.warning quick from any to any with opt ts
+block out log level local0.warning quick from any to any
+#
+# Rule 8 (global)
+# firewall:Policy:8: warning: Changing rule direction due to self reference
+block return-icmp-as-dest (3) in quick proto 50 from any to 192.168.1.1
+# firewall:Policy:8: warning: Changing rule direction due to self reference
+block return-icmp-as-dest (3) in quick proto 50 from any to 222.222.222.222
+#
+# Rule 11 (global)
+pass in quick proto tcp from 211.11.11.11 to 192.168.1.10 port = 53 flags S keep state
+pass in quick proto tcp from 211.22.22.22 to 192.168.1.10 port = 53 flags S keep state
+pass out quick proto tcp from 211.11.11.11 to 192.168.1.10 port = 53 flags S keep state
+pass out quick proto tcp from 211.22.22.22 to 192.168.1.10 port = 53 flags S keep state
+#
+# Rule 12 (global)
+pass in quick proto tcp from any to 192.168.1.10 port 9999 >< 10041 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 6667 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 3128 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 113 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 53 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 21 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 80 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 119 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 25 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 22 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 23 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 540 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 70 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 13 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 2105 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 443 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 143 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 993 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 543 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 544 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 389 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 98 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 3306 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 2049 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 110 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 5432 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 515 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 26000 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 512 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 513 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 514 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 4321 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 465 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 1080 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 111 flags S keep state
+pass in quick proto tcp from any to 192.168.1.10 port = 7100 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port 9999 >< 10041 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 6667 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 3128 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 113 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 53 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 21 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 80 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 119 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 25 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 22 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 23 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 540 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 70 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 13 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 2105 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 443 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 143 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 993 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 543 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 544 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 389 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 98 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 3306 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 2049 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 110 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 5432 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 515 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 26000 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 512 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 513 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 514 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 4321 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 465 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 1080 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 111 flags S keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 7100 flags S keep state
+#
+# Rule 13 (global)
+pass in quick proto icmp from any to 192.168.1.0/24 icmp-type 11 code 0 keep state
+pass in quick proto icmp from any to 192.168.1.0/24 icmp-type 11 code 1 keep state
+pass in quick proto icmp from any to 192.168.1.0/24 icmp-type 0 code 0 keep state
+pass in quick proto icmp from any to 192.168.1.0/24 icmp-type 3 keep state
+pass in quick proto tcp from any to 192.168.1.0/24 port = 3128 flags S keep state
+pass out quick proto icmp from any to 192.168.1.0/24 icmp-type 11 code 0 keep state
+pass out quick proto icmp from any to 192.168.1.0/24 icmp-type 11 code 1 keep state
+pass out quick proto icmp from any to 192.168.1.0/24 icmp-type 0 code 0 keep state
+pass out quick proto icmp from any to 192.168.1.0/24 icmp-type 3 keep state
+pass out quick proto tcp from any to 192.168.1.0/24 port = 3128 flags S keep state
+#
+# Rule 14 (global)
+skip 2 in from any to 192.168.1.11
+skip 1 in from any to 192.168.1.12/30
+skip 8 in from any to any
+pass in quick proto tcp from any to any port = 113 flags S keep state
+pass in quick proto tcp from any to any port = 80 flags S keep state
+pass in quick proto tcp from any to any port = 25 flags S keep state
+pass in quick proto tcp from any to any port = 22 flags S keep state
+pass in quick proto tcp from any to any port = 540 flags S keep state
+pass in quick proto tcp from any to any port = 443 flags S keep state
+pass in quick proto tcp from any to any port = 143 flags S keep state
+pass in quick proto tcp from any to any port = 3128 flags S keep state
+skip 2 out from any to 192.168.1.11
+skip 1 out from any to 192.168.1.12/30
+skip 8 out from any to any
+pass out quick proto tcp from any to any port = 113 flags S keep state
+pass out quick proto tcp from any to any port = 80 flags S keep state
+pass out quick proto tcp from any to any port = 25 flags S keep state
+pass out quick proto tcp from any to any port = 22 flags S keep state
+pass out quick proto tcp from any to any port = 540 flags S keep state
+pass out quick proto tcp from any to any port = 443 flags S keep state
+pass out quick proto tcp from any to any port = 143 flags S keep state
+pass out quick proto tcp from any to any port = 3128 flags S keep state
+#
+# Rule 15 (global)
+pass in quick proto tcp from any to 192.168.1.11 port = 113 flags S keep state
+pass in quick proto tcp from any to 192.168.1.11 port = 80 flags S keep state
+pass in quick proto tcp from any to 192.168.1.11 port = 25 flags S keep state
+pass in quick proto tcp from any to 192.168.1.11 port = 22 flags S keep state
+pass in quick proto tcp from any to 192.168.1.11 port = 540 flags S keep state
+pass in quick proto tcp from any to 192.168.1.11 port = 443 flags S keep state
+pass in quick proto tcp from any to 192.168.1.11 port = 143 flags S keep state
+pass in quick proto tcp from any to 192.168.1.11 port = 3128 flags S keep state
+pass out quick proto tcp from any to 192.168.1.11 port = 113 flags S keep state
+pass out quick proto tcp from any to 192.168.1.11 port = 80 flags S keep state
+pass out quick proto tcp from any to 192.168.1.11 port = 25 flags S keep state
+pass out quick proto tcp from any to 192.168.1.11 port = 22 flags S keep state
+pass out quick proto tcp from any to 192.168.1.11 port = 540 flags S keep state
+pass out quick proto tcp from any to 192.168.1.11 port = 443 flags S keep state
+pass out quick proto tcp from any to 192.168.1.11 port = 143 flags S keep state
+pass out quick proto tcp from any to 192.168.1.11 port = 3128 flags S keep state
+#
+# Rule 16 (global)
+skip 5 in from any to 192.168.1.11
+skip 4 in from any to 192.168.1.12
+skip 3 in from any to 192.168.1.13
+skip 2 in from any to 192.168.1.14
+skip 1 in from any to 192.168.1.15
+skip 8 in from any to any
+pass in quick proto tcp from any to any port = 113 flags S keep state
+pass in quick proto tcp from any to any port = 80 flags S keep state
+pass in quick proto tcp from any to any port = 25 flags S keep state
+pass in quick proto tcp from any to any port = 22 flags S keep state
+pass in quick proto tcp from any to any port = 540 flags S keep state
+pass in quick proto tcp from any to any port = 443 flags S keep state
+pass in quick proto tcp from any to any port = 143 flags S keep state
+pass in quick proto tcp from any to any port = 3128 flags S keep state
+skip 5 out from any to 192.168.1.11
+skip 4 out from any to 192.168.1.12
+skip 3 out from any to 192.168.1.13
+skip 2 out from any to 192.168.1.14
+skip 1 out from any to 192.168.1.15
+skip 8 out from any to any
+pass out quick proto tcp from any to any port = 113 flags S keep state
+pass out quick proto tcp from any to any port = 80 flags S keep state
+pass out quick proto tcp from any to any port = 25 flags S keep state
+pass out quick proto tcp from any to any port = 22 flags S keep state
+pass out quick proto tcp from any to any port = 540 flags S keep state
+pass out quick proto tcp from any to any port = 443 flags S keep state
+pass out quick proto tcp from any to any port = 143 flags S keep state
+pass out quick proto tcp from any to any port = 3128 flags S keep state
+#
+# Rule 17 (global)
+pass in log level local0.warning quick proto icmp from 192.168.1.1 to 192.168.1.1 keep state
+pass in log level local0.warning quick proto icmp from 192.168.1.1 to 222.222.222.222 keep state
+pass in log level local0.warning quick proto icmp from 222.222.222.222 to 192.168.1.1 keep state
+pass in log level local0.warning quick proto icmp from 222.222.222.222 to 222.222.222.222 keep state
+pass in log level local0.warning quick proto tcp from 192.168.1.1 to 192.168.1.1 flags S keep state
+pass in log level local0.warning quick proto tcp from 192.168.1.1 to 222.222.222.222 flags S keep state
+pass in log level local0.warning quick proto tcp from 222.222.222.222 to 192.168.1.1 flags S keep state
+pass in log level local0.warning quick proto tcp from 222.222.222.222 to 222.222.222.222 flags S keep state
+pass in log level local0.warning quick proto udp from 192.168.1.1 to 192.168.1.1 keep state
+pass in log level local0.warning quick proto udp from 192.168.1.1 to 222.222.222.222 keep state
+pass in log level local0.warning quick proto udp from 222.222.222.222 to 192.168.1.1 keep state
+pass in log level local0.warning quick proto udp from 222.222.222.222 to 222.222.222.222 keep state
+pass in log level local0.warning quick from 192.168.1.1 to 192.168.1.1
+pass in log level local0.warning quick from 192.168.1.1 to 222.222.222.222
+pass in log level local0.warning quick from 222.222.222.222 to 192.168.1.1
+pass in log level local0.warning quick from 222.222.222.222 to 222.222.222.222
+pass out log level local0.warning quick proto icmp from 192.168.1.1 to 192.168.1.1 keep state
+pass out log level local0.warning quick proto icmp from 192.168.1.1 to 222.222.222.222 keep state
+pass out log level local0.warning quick proto icmp from 222.222.222.222 to 192.168.1.1 keep state
+pass out log level local0.warning quick proto icmp from 222.222.222.222 to 222.222.222.222 keep state
+pass out log level local0.warning quick proto tcp from 192.168.1.1 to 192.168.1.1 flags S keep state
+pass out log level local0.warning quick proto tcp from 192.168.1.1 to 222.222.222.222 flags S keep state
+pass out log level local0.warning quick proto tcp from 222.222.222.222 to 192.168.1.1 flags S keep state
+pass out log level local0.warning quick proto tcp from 222.222.222.222 to 222.222.222.222 flags S keep state
+pass out log level local0.warning quick proto udp from 192.168.1.1 to 192.168.1.1 keep state
+pass out log level local0.warning quick proto udp from 192.168.1.1 to 222.222.222.222 keep state
+pass out log level local0.warning quick proto udp from 222.222.222.222 to 192.168.1.1 keep state
+pass out log level local0.warning quick proto udp from 222.222.222.222 to 222.222.222.222 keep state
+pass out log level local0.warning quick from 192.168.1.1 to 192.168.1.1
+pass out log level local0.warning quick from 192.168.1.1 to 222.222.222.222
+pass out log level local0.warning quick from 222.222.222.222 to 192.168.1.1
+pass out log level local0.warning quick from 222.222.222.222 to 222.222.222.222
+#
+# Rule 19 (global)
+pass in quick proto icmp from 192.168.1.1 to 192.168.1.1 keep state
+pass in quick proto icmp from 192.168.1.1 to 222.222.222.222 keep state
+pass in quick proto icmp from 222.222.222.222 to 192.168.1.1 keep state
+pass in quick proto icmp from 222.222.222.222 to 222.222.222.222 keep state
+pass in quick proto tcp from 192.168.1.1 to 192.168.1.1 flags S keep state
+pass in quick proto tcp from 192.168.1.1 to 222.222.222.222 flags S keep state
+pass in quick proto tcp from 222.222.222.222 to 192.168.1.1 flags S keep state
+pass in quick proto tcp from 222.222.222.222 to 222.222.222.222 flags S keep state
+pass in quick proto udp from 192.168.1.1 to 192.168.1.1 keep state
+pass in quick proto udp from 192.168.1.1 to 222.222.222.222 keep state
+pass in quick proto udp from 222.222.222.222 to 192.168.1.1 keep state
+pass in quick proto udp from 222.222.222.222 to 222.222.222.222 keep state
+pass in quick from 192.168.1.1 to 192.168.1.1
+pass in quick from 192.168.1.1 to 222.222.222.222
+pass in quick from 222.222.222.222 to 192.168.1.1
+pass in quick from 222.222.222.222 to 222.222.222.222
+pass out quick proto icmp from 192.168.1.1 to 192.168.1.1 keep state
+pass out quick proto icmp from 192.168.1.1 to 222.222.222.222 keep state
+pass out quick proto icmp from 222.222.222.222 to 192.168.1.1 keep state
+pass out quick proto icmp from 222.222.222.222 to 222.222.222.222 keep state
+pass out quick proto tcp from 192.168.1.1 to 192.168.1.1 flags S keep state
+pass out quick proto tcp from 192.168.1.1 to 222.222.222.222 flags S keep state
+pass out quick proto tcp from 222.222.222.222 to 192.168.1.1 flags S keep state
+pass out quick proto tcp from 222.222.222.222 to 222.222.222.222 flags S keep state
+pass out quick proto udp from 192.168.1.1 to 192.168.1.1 keep state
+pass out quick proto udp from 192.168.1.1 to 222.222.222.222 keep state
+pass out quick proto udp from 222.222.222.222 to 192.168.1.1 keep state
+pass out quick proto udp from 222.222.222.222 to 222.222.222.222 keep state
+pass out quick from 192.168.1.1 to 192.168.1.1
+pass out quick from 192.168.1.1 to 222.222.222.222
+pass out quick from 222.222.222.222 to 192.168.1.1
+pass out quick from 222.222.222.222 to 222.222.222.222
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass out quick proto icmp from 192.168.1.1 to 33.33.33.33 keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass out quick proto icmp from 192.168.1.1 to 33.33.33.34 keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass out quick proto icmp from 222.222.222.222 to 33.33.33.33 keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass out quick proto icmp from 222.222.222.222 to 33.33.33.34 keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass out quick proto tcp from 192.168.1.1 to 33.33.33.33 flags S keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass out quick proto tcp from 192.168.1.1 to 33.33.33.34 flags S keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass out quick proto tcp from 222.222.222.222 to 33.33.33.33 flags S keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass out quick proto tcp from 222.222.222.222 to 33.33.33.34 flags S keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass out quick proto udp from 192.168.1.1 to 33.33.33.33 keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass out quick proto udp from 192.168.1.1 to 33.33.33.34 keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass out quick proto udp from 222.222.222.222 to 33.33.33.33 keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass out quick proto udp from 222.222.222.222 to 33.33.33.34 keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass out quick from 192.168.1.1 to 33.33.33.33
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass out quick from 192.168.1.1 to 33.33.33.34
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass out quick from 222.222.222.222 to 33.33.33.33
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass out quick from 222.222.222.222 to 33.33.33.34
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass in quick proto icmp from 33.33.33.33 to 192.168.1.1 keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass in quick proto icmp from 33.33.33.33 to 222.222.222.222 keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass in quick proto icmp from 33.33.33.34 to 192.168.1.1 keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass in quick proto icmp from 33.33.33.34 to 222.222.222.222 keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass in quick proto tcp from 33.33.33.33 to 192.168.1.1 flags S keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass in quick proto tcp from 33.33.33.33 to 222.222.222.222 flags S keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass in quick proto tcp from 33.33.33.34 to 192.168.1.1 flags S keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass in quick proto tcp from 33.33.33.34 to 222.222.222.222 flags S keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass in quick proto udp from 33.33.33.33 to 192.168.1.1 keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass in quick proto udp from 33.33.33.33 to 222.222.222.222 keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass in quick proto udp from 33.33.33.34 to 192.168.1.1 keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass in quick proto udp from 33.33.33.34 to 222.222.222.222 keep state
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass in quick from 33.33.33.33 to 192.168.1.1
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass in quick from 33.33.33.33 to 222.222.222.222
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass in quick from 33.33.33.34 to 192.168.1.1
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+pass in quick from 33.33.33.34 to 222.222.222.222
+skip 3 in from 33.33.33.33 to any
+skip 2 in from 33.33.33.34 to any
+skip 1 in from 192.168.1.1 to any
+skip 24 in from any to any
+pass in quick proto icmp from any to 33.33.33.33 keep state
+pass in quick proto icmp from any to 33.33.33.34 keep state
+pass in quick proto icmp from any to 192.168.1.1 keep state
+skip 3 in from 33.33.33.33 to any
+skip 2 in from 33.33.33.34 to any
+skip 1 in from 192.168.1.1 to any
+skip 17 in from any to any
+pass in quick proto tcp from any to 33.33.33.33 flags S keep state
+pass in quick proto tcp from any to 33.33.33.34 flags S keep state
+pass in quick proto tcp from any to 192.168.1.1 flags S keep state
+skip 3 in from 33.33.33.33 to any
+skip 2 in from 33.33.33.34 to any
+skip 1 in from 192.168.1.1 to any
+skip 10 in from any to any
+pass in quick proto udp from any to 33.33.33.33 keep state
+pass in quick proto udp from any to 33.33.33.34 keep state
+pass in quick proto udp from any to 192.168.1.1 keep state
+skip 3 in from 33.33.33.33 to any
+skip 2 in from 33.33.33.34 to any
+skip 1 in from 192.168.1.1 to any
+skip 3 in from any to any
+pass in quick from any to 33.33.33.33
+pass in quick from any to 33.33.33.34
+pass in quick from any to 192.168.1.1
+skip 3 out from 33.33.33.33 to any
+skip 2 out from 33.33.33.34 to any
+skip 1 out from 192.168.1.1 to any
+skip 24 out from any to any
+pass out quick proto icmp from any to 33.33.33.33 keep state
+pass out quick proto icmp from any to 33.33.33.34 keep state
+pass out quick proto icmp from any to 192.168.1.1 keep state
+skip 3 out from 33.33.33.33 to any
+skip 2 out from 33.33.33.34 to any
+skip 1 out from 192.168.1.1 to any
+skip 17 out from any to any
+pass out quick proto tcp from any to 33.33.33.33 flags S keep state
+pass out quick proto tcp from any to 33.33.33.34 flags S keep state
+pass out quick proto tcp from any to 192.168.1.1 flags S keep state
+skip 3 out from 33.33.33.33 to any
+skip 2 out from 33.33.33.34 to any
+skip 1 out from 192.168.1.1 to any
+skip 10 out from any to any
+pass out quick proto udp from any to 33.33.33.33 keep state
+pass out quick proto udp from any to 33.33.33.34 keep state
+pass out quick proto udp from any to 192.168.1.1 keep state
+skip 3 out from 33.33.33.33 to any
+skip 2 out from 33.33.33.34 to any
+skip 1 out from 192.168.1.1 to any
+skip 3 out from any to any
+pass out quick from any to 33.33.33.33
+pass out quick from any to 33.33.33.34
+pass out quick from any to 192.168.1.1
+#
+# Rule 20 (global)
+# Automatically generated 'masquerading' rule
+# firewall:Policy:20: warning: Changing rule direction due to self reference
+pass out quick proto icmp from 192.168.1.1 to any keep state
+# firewall:Policy:20: warning: Changing rule direction due to self reference
+pass out quick proto icmp from 222.222.222.222 to any keep state
+# firewall:Policy:20: warning: Changing rule direction due to self reference
+pass out quick proto tcp from 192.168.1.1 to any flags S keep state
+# firewall:Policy:20: warning: Changing rule direction due to self reference
+pass out quick proto tcp from 222.222.222.222 to any flags S keep state
+# firewall:Policy:20: warning: Changing rule direction due to self reference
+pass out quick proto udp from 192.168.1.1 to any keep state
+# firewall:Policy:20: warning: Changing rule direction due to self reference
+pass out quick proto udp from 222.222.222.222 to any keep state
+# firewall:Policy:20: warning: Changing rule direction due to self reference
+pass out quick from 192.168.1.1 to any
+# firewall:Policy:20: warning: Changing rule direction due to self reference
+pass out quick from 222.222.222.222 to any
+pass in quick proto icmp from 192.168.1.0/24 to any keep state
+pass in quick proto tcp from 192.168.1.0/24 to any flags S keep state
+pass in quick proto udp from 192.168.1.0/24 to any keep state
+pass in quick from 192.168.1.0/24 to any
+pass out quick proto icmp from 192.168.1.0/24 to any keep state
+pass out quick proto tcp from 192.168.1.0/24 to any flags S keep state
+pass out quick proto udp from 192.168.1.0/24 to any keep state
+pass out quick from 192.168.1.0/24 to any
+#
+# Rule 21 (global)
+# Automatically generated 'catch all' rule
+block in log level daemon.alert quick from any to any
+block out log level daemon.alert quick from any to any
+#
+# Rule fallback rule
+# fallback rule
+block in quick from any to any
+block out quick from any to any
diff --git a/test/ipf/firewall-nat.conf.orig b/test/ipf/firewall-nat.conf.orig
new file mode 100755
index 000000000..72eb8dda7
--- /dev/null
+++ b/test/ipf/firewall-nat.conf.orig
@@ -0,0 +1,23 @@
+#
+# Rule 0 (NAT)
+# comment : rule 0
+map eth0 from 192.168.1.0/24 to any -> 192.168.1.1/32 portmap tcp/udp auto
+map eth0 from 192.168.1.0/24 to any -> 192.168.1.1/32
+map eth1 from 192.168.1.0/24 to any -> 222.222.222.222/32 portmap tcp/udp auto
+map eth1 from 192.168.1.0/24 to any -> 222.222.222.222/32
+#
+# Rule 1 (NAT)
+rdr from any to 192.168.1.1/32 port = 25 -> 192.168.1.10 port 25 tcp
+rdr from any to 222.222.222.222/32 port = 25 -> 192.168.1.10 port 25 tcp
+#
+# Rule 2 (NAT)
+rdr eth1 from any to any port = 80 -> 222.222.222.222 port 3128 tcp
+rdr eth0 from any to any port = 80 -> 192.168.1.1 port 3128 tcp
+#
+# Rule 3 (NAT)
+rdr eth0 from 192.168.1.0/24 to any port = 80 -> 192.168.1.1 port 3128 tcp
+rdr eth0 from 192.168.1.0/24 to any port = 443 -> 192.168.1.1 port 3128 tcp
+#
+# Rule 4 (NAT)
+rdr eth0 from 192.168.1.0/24 to any port = 80 -> 222.222.222.222 port 3128 tcp
+rdr eth0 from 192.168.1.0/24 to any port = 443 -> 222.222.222.222 port 3128 tcp
diff --git a/test/ipf/firewall.fw.orig b/test/ipf/firewall.fw.orig
new file mode 100755
index 000000000..6d71305e5
--- /dev/null
+++ b/test/ipf/firewall.fw.orig
@@ -0,0 +1,190 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:52:45 2011 PST by vadim
+#
+# files: * firewall.fw ipf.fw
+# files: firewall-ipf.conf ipf.conf
+# files: firewall-nat.conf nat.conf
+#
+# Compiled for ipf
+#
+# this is simple firewall with two interfaces. Test regular policy rules, including IP_fragments rule
+
+# firewall:Policy:4: warning: Changing rule direction due to self reference
+# firewall:Policy:8: warning: Changing rule direction due to self reference
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+# firewall:Policy:19: warning: Changing rule direction due to self reference
+# firewall:Policy:20: warning: Changing rule direction due to self reference
+# firewall:Policy:: warning: ipfilter can not match "any IP option"
+# firewall:Policy:: warning: ipfilter can not match "any IP option"
+
+FWDIR=`dirname $0`
+
+
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ update_addresses_of_interface "eth0 192.168.1.1/0xffffff00" ""
+ update_addresses_of_interface "eth1 222.222.222.222/0xffffff00" ""
+ update_addresses_of_interface "lo 127.0.0.1/0xff000000" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:52:45 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$IPF -Fa
+$IPNAT -C
+
+$IPF -I -f ${FWDIR}/ipf.conf
+$IPNAT -f ${FWDIR}/nat.conf
+
+
+$IPF -s
+
+
+epilog_commands
+
+/sbin/kldstat -n ipl.ko > /dev/null 2>&1 || $IPF -E
\ No newline at end of file
diff --git a/test/ipf/firewall1-ipf.conf.orig b/test/ipf/firewall1-ipf.conf.orig
new file mode 100755
index 000000000..7a8e2f15f
--- /dev/null
+++ b/test/ipf/firewall1-ipf.conf.orig
@@ -0,0 +1,211 @@
+# Policy compiler errors and warnings:
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+# firewall1:Policy:10: warning: Changing rule direction due to self reference
+# firewall1:Policy:12: warning: Changing rule direction due to self reference
+#
+# Rule 0 (eth0)
+skip 11 in on eth0 proto icmp from 22.22.22.22 to 22.22.22.22
+skip 10 in on eth0 proto icmp from 22.22.22.22 to 192.168.1.1
+skip 9 in on eth0 proto icmp from 192.168.1.1 to 22.22.22.22
+skip 8 in on eth0 proto icmp from 192.168.1.1 to 192.168.1.1
+skip 7 in on eth0 proto 50 from 22.22.22.22 to 22.22.22.22
+skip 6 in on eth0 proto 50 from 22.22.22.22 to 192.168.1.1
+skip 5 in on eth0 proto 50 from 192.168.1.1 to 22.22.22.22
+skip 4 in on eth0 proto 50 from 192.168.1.1 to 192.168.1.1
+skip 11 out on eth0 proto icmp from 22.22.22.22 to 22.22.22.22
+skip 10 out on eth0 proto icmp from 22.22.22.22 to 192.168.1.1
+skip 9 out on eth0 proto icmp from 192.168.1.1 to 22.22.22.22
+skip 8 out on eth0 proto icmp from 192.168.1.1 to 192.168.1.1
+skip 7 out on eth0 proto 50 from 22.22.22.22 to 22.22.22.22
+skip 6 out on eth0 proto 50 from 22.22.22.22 to 192.168.1.1
+skip 5 out on eth0 proto 50 from 192.168.1.1 to 22.22.22.22
+skip 4 out on eth0 proto 50 from 192.168.1.1 to 192.168.1.1
+block in log quick on eth0 proto icmp from 22.22.22.22 to any
+block in log quick on eth0 proto icmp from 192.168.1.1 to any
+block in log quick on eth0 proto 50 from 22.22.22.22 to any
+block in log quick on eth0 proto 50 from 192.168.1.1 to any
+block out log quick on eth0 proto icmp from 22.22.22.22 to any
+block out log quick on eth0 proto icmp from 192.168.1.1 to any
+block out log quick on eth0 proto 50 from 22.22.22.22 to any
+block out log quick on eth0 proto 50 from 192.168.1.1 to any
+#
+# Rule 1 (eth0)
+skip 11 in on eth0 proto icmp from 192.168.1.10 to 192.168.1.10
+skip 10 in on eth0 proto icmp from 192.168.1.10 to 192.168.1.20
+skip 9 in on eth0 proto icmp from 192.168.1.20 to 192.168.1.10
+skip 8 in on eth0 proto icmp from 192.168.1.20 to 192.168.1.20
+skip 7 in on eth0 proto 50 from 192.168.1.10 to 192.168.1.10
+skip 6 in on eth0 proto 50 from 192.168.1.10 to 192.168.1.20
+skip 5 in on eth0 proto 50 from 192.168.1.20 to 192.168.1.10
+skip 4 in on eth0 proto 50 from 192.168.1.20 to 192.168.1.20
+skip 11 out on eth0 proto icmp from 192.168.1.10 to 192.168.1.10
+skip 10 out on eth0 proto icmp from 192.168.1.10 to 192.168.1.20
+skip 9 out on eth0 proto icmp from 192.168.1.20 to 192.168.1.10
+skip 8 out on eth0 proto icmp from 192.168.1.20 to 192.168.1.20
+skip 7 out on eth0 proto 50 from 192.168.1.10 to 192.168.1.10
+skip 6 out on eth0 proto 50 from 192.168.1.10 to 192.168.1.20
+skip 5 out on eth0 proto 50 from 192.168.1.20 to 192.168.1.10
+skip 4 out on eth0 proto 50 from 192.168.1.20 to 192.168.1.20
+block in quick on eth0 proto icmp from 192.168.1.10 to any
+block in quick on eth0 proto icmp from 192.168.1.20 to any
+block in quick on eth0 proto 50 from 192.168.1.10 to any
+block in quick on eth0 proto 50 from 192.168.1.20 to any
+block out quick on eth0 proto icmp from 192.168.1.10 to any
+block out quick on eth0 proto icmp from 192.168.1.20 to any
+block out quick on eth0 proto 50 from 192.168.1.10 to any
+block out quick on eth0 proto 50 from 192.168.1.20 to any
+#
+# Rule 2 (eth1)
+# Anti-spoofing rule
+block in log quick on eth1 from 22.22.22.22 to any
+block in log quick on eth1 from 22.22.23.23 to any
+block in log quick on eth1 from 192.168.1.1 to any
+block in log quick on eth1 from 192.168.2.1 to any
+block in log quick on eth1 from 192.168.1.0/24 to any
+#
+# Rule 3 (eth1)
+# Anti-spoofing rule
+skip 1 out on eth1 from 192.168.1.0/24 to any
+block out log quick on eth1 from any to any
+#
+# Rule 4 (lo)
+pass in quick on lo proto icmp from any to any keep state
+pass in quick on lo proto tcp from any to any keep state
+pass in quick on lo proto udp from any to any keep state
+pass in quick on lo from any to any
+pass out quick on lo proto icmp from any to any keep state
+pass out quick on lo proto tcp from any to any keep state
+pass out quick on lo proto udp from any to any keep state
+pass out quick on lo from any to any
+#
+# Rule 5 (global)
+block in log quick proto tcp from any to any flags S/UAPRSF
+block out log quick proto tcp from any to any flags S/UAPRSF
+#
+# Rule 7 (global)
+# hostF has the same IP address as firewal.
+pass in log quick proto icmp from any to 192.168.1.1 icmp-type 8 code 0 keep state
+pass out log quick proto icmp from any to 192.168.1.1 icmp-type 8 code 0 keep state
+#
+# Rule 8 (global)
+# testing negation in the policy rule
+skip 2 in proto icmp from 192.168.1.10 to any icmp-type 3
+skip 1 in proto icmp from 192.168.1.20 to any icmp-type 3
+skip 2 out proto icmp from 192.168.1.10 to any icmp-type 3
+skip 1 out proto icmp from 192.168.1.20 to any icmp-type 3
+block in log quick proto icmp from any to any icmp-type 3
+block out log quick proto icmp from any to any icmp-type 3
+#
+# Rule 9 (global)
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+skip 11 in proto icmp from 192.168.1.10 to 22.22.22.22 icmp-type 3
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+skip 10 in proto icmp from 192.168.1.10 to 22.22.23.23 icmp-type 3
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+skip 9 in proto icmp from 192.168.1.10 to 192.168.1.1 icmp-type 3
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+skip 8 in proto icmp from 192.168.1.10 to 192.168.2.1 icmp-type 3
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+skip 7 in proto icmp from 192.168.1.20 to 22.22.22.22 icmp-type 3
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+skip 6 in proto icmp from 192.168.1.20 to 22.22.23.23 icmp-type 3
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+skip 5 in proto icmp from 192.168.1.20 to 192.168.1.1 icmp-type 3
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+skip 4 in proto icmp from 192.168.1.20 to 192.168.2.1 icmp-type 3
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+block in log quick proto icmp from any to 22.22.22.22 icmp-type 3
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+block in log quick proto icmp from any to 22.22.23.23 icmp-type 3
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+block in log quick proto icmp from any to 192.168.1.1 icmp-type 3
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+block in log quick proto icmp from any to 192.168.2.1 icmp-type 3
+#
+# Rule 10 (global)
+# firewall1:Policy:10: warning: Changing rule direction due to self reference
+skip 5 out from 22.22.22.22 to 192.168.1.0/24
+# firewall1:Policy:10: warning: Changing rule direction due to self reference
+skip 4 out from 22.22.23.23 to 192.168.1.0/24
+# firewall1:Policy:10: warning: Changing rule direction due to self reference
+skip 3 out from 192.168.1.1 to 192.168.1.0/24
+# firewall1:Policy:10: warning: Changing rule direction due to self reference
+skip 2 out from 192.168.2.1 to 192.168.1.0/24
+skip 1 in from 192.168.2.0/24 to 192.168.1.0/24
+skip 1 out from 192.168.2.0/24 to 192.168.1.0/24
+block in log quick from any to 192.168.1.0/24
+block out log quick from any to 192.168.1.0/24
+#
+# Rule 11 (global)
+skip 5 in from 192.168.1.0/24 to 192.168.1.10
+skip 4 in from 192.168.1.0/24 to 192.168.1.20
+skip 3 in from 192.168.2.0/24 to 192.168.1.10
+skip 2 in from 192.168.2.0/24 to 192.168.1.20
+skip 5 out from 192.168.1.0/24 to 192.168.1.10
+skip 4 out from 192.168.1.0/24 to 192.168.1.20
+skip 3 out from 192.168.2.0/24 to 192.168.1.10
+skip 2 out from 192.168.2.0/24 to 192.168.1.20
+block in log quick from 192.168.1.0/24 to any
+block in log quick from 192.168.2.0/24 to any
+block out log quick from 192.168.1.0/24 to any
+block out log quick from 192.168.2.0/24 to any
+#
+# Rule 12 (global)
+# firewall1:Policy:12: warning: Changing rule direction due to self reference
+skip 4 in from any to 22.22.22.22
+# firewall1:Policy:12: warning: Changing rule direction due to self reference
+skip 3 in from any to 22.22.23.23
+# firewall1:Policy:12: warning: Changing rule direction due to self reference
+skip 2 in from any to 192.168.1.1
+# firewall1:Policy:12: warning: Changing rule direction due to self reference
+skip 1 in from any to 192.168.2.1
+block in quick from any to any
+block out quick from any to any
+#
+# Rule 15 (global)
+skip 11 in proto icmp from 22.22.22.22 to 22.22.22.22
+skip 10 in proto icmp from 22.22.22.22 to 192.168.1.1
+skip 9 in proto icmp from 192.168.1.1 to 22.22.22.22
+skip 8 in proto icmp from 192.168.1.1 to 192.168.1.1
+skip 7 in proto 50 from 22.22.22.22 to 22.22.22.22
+skip 6 in proto 50 from 22.22.22.22 to 192.168.1.1
+skip 5 in proto 50 from 192.168.1.1 to 22.22.22.22
+skip 4 in proto 50 from 192.168.1.1 to 192.168.1.1
+skip 11 out proto icmp from 22.22.22.22 to 22.22.22.22
+skip 10 out proto icmp from 22.22.22.22 to 192.168.1.1
+skip 9 out proto icmp from 192.168.1.1 to 22.22.22.22
+skip 8 out proto icmp from 192.168.1.1 to 192.168.1.1
+skip 7 out proto 50 from 22.22.22.22 to 22.22.22.22
+skip 6 out proto 50 from 22.22.22.22 to 192.168.1.1
+skip 5 out proto 50 from 192.168.1.1 to 22.22.22.22
+skip 4 out proto 50 from 192.168.1.1 to 192.168.1.1
+block in log quick proto icmp from 22.22.22.22 to any
+block in log quick proto icmp from 192.168.1.1 to any
+block in log quick proto 50 from 22.22.22.22 to any
+block in log quick proto 50 from 192.168.1.1 to any
+block out log quick proto icmp from 22.22.22.22 to any
+block out log quick proto icmp from 192.168.1.1 to any
+block out log quick proto 50 from 22.22.22.22 to any
+block out log quick proto 50 from 192.168.1.1 to any
+#
+# Rule 16 (global)
+# 'masquerading' rule
+pass in quick proto icmp from 192.168.1.0/24 to any keep state
+pass in quick proto tcp from 192.168.1.0/24 to any keep state
+pass in quick proto udp from 192.168.1.0/24 to any keep state
+pass in quick from 192.168.1.0/24 to any
+pass out quick proto icmp from 192.168.1.0/24 to any keep state
+pass out quick proto tcp from 192.168.1.0/24 to any keep state
+pass out quick proto udp from 192.168.1.0/24 to any keep state
+pass out quick from 192.168.1.0/24 to any
+#
+# Rule 17 (global)
+# 'catch all' rule
+block in log quick from any to any
+block out log quick from any to any
+#
+# Rule fallback rule
+# fallback rule
+block in quick from any to any
+block out quick from any to any
diff --git a/test/ipf/firewall1-nat.conf.orig b/test/ipf/firewall1-nat.conf.orig
new file mode 100755
index 000000000..1151212bb
--- /dev/null
+++ b/test/ipf/firewall1-nat.conf.orig
@@ -0,0 +1,26 @@
+#
+# Rule 1 (NAT)
+map eth0 from 192.168.1.10/32 to any -> 22.22.22.23/32 portmap tcp/udp auto
+map eth1 from 192.168.1.10/32 to any -> 22.22.22.23/32 portmap tcp/udp auto
+map eth2 from 192.168.1.10/32 to any -> 22.22.22.23/32 portmap tcp/udp auto
+map eth3 from 192.168.1.10/32 to any -> 22.22.22.23/32 portmap tcp/udp auto
+map eth0 from 192.168.1.10/32 to any -> 22.22.22.23/32
+map eth1 from 192.168.1.10/32 to any -> 22.22.22.23/32
+map eth2 from 192.168.1.10/32 to any -> 22.22.22.23/32
+map eth3 from 192.168.1.10/32 to any -> 22.22.22.23/32
+#
+# Rule 3 (NAT)
+map eth1 from 192.168.1.0/24 to any -> 22.22.22.22/32 portmap tcp/udp auto
+map eth1 from 192.168.1.0/24 to any -> 22.22.22.22/32
+map eth3 from 192.168.1.0/24 to any -> 22.22.23.23/32 portmap tcp/udp auto
+map eth3 from 192.168.1.0/24 to any -> 22.22.23.23/32
+map eth0 from 192.168.1.0/24 to any -> 192.168.1.1/32 portmap tcp/udp auto
+map eth0 from 192.168.1.0/24 to any -> 192.168.1.1/32
+map eth2 from 192.168.1.0/24 to any -> 192.168.2.1/32 portmap tcp/udp auto
+map eth2 from 192.168.1.0/24 to any -> 192.168.2.1/32
+#
+# Rule 4 (NAT)
+map eth1 from 192.168.1.0/24 to any -> 22.22.22.22/32 portmap tcp/udp auto
+map eth1 from 192.168.1.0/24 to any -> 22.22.22.22/32
+map eth3 from 192.168.1.0/24 to any -> 22.22.23.23/32 portmap tcp/udp auto
+map eth3 from 192.168.1.0/24 to any -> 22.22.23.23/32
diff --git a/test/ipf/firewall1.fw.orig b/test/ipf/firewall1.fw.orig
new file mode 100755
index 000000000..0f56b7076
--- /dev/null
+++ b/test/ipf/firewall1.fw.orig
@@ -0,0 +1,104 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:52:46 2011 PST by vadim
+#
+# files: * firewall1.fw /etc/ipf.fw
+# files: firewall1-ipf.conf /etc/fw/ipf.conf
+# files: firewall1-nat.conf /etc/fw/nat.conf
+#
+# Compiled for ipf
+#
+# this object is used to test all kinds of negation in policy rules
+
+# Currently negation in NAT is not supported for ipf, therefore all rules in NAT with
+# negation are disabled
+
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+# firewall1:Policy:10: warning: Changing rule direction due to self reference
+# firewall1:Policy:12: warning: Changing rule direction due to self reference
+
+FWDIR=`dirname $0`
+
+
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:52:46 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$IPF -Fa
+$IPNAT -C
+
+$IPF -I -f /etc/fw/ipf.conf
+$IPNAT -f /etc/fw/nat.conf
+
+
+$IPF -s
+
+
+epilog_commands
+
+/sbin/kldstat -n ipl.ko > /dev/null 2>&1 || $IPF -E
\ No newline at end of file
diff --git a/test/ipf/firewall10-ipf.conf.orig b/test/ipf/firewall10-ipf.conf.orig
new file mode 100755
index 000000000..0008c55a5
--- /dev/null
+++ b/test/ipf/firewall10-ipf.conf.orig
@@ -0,0 +1,193 @@
+# Policy compiler errors and warnings:
+# firewall10:Policy:2: warning: Changing rule direction due to self reference
+#
+# Rule 0 (global)
+count in from any to any
+count out from any to any
+#
+# Rule 1 (global)
+skip 5 in from 192.168.1.10 to any
+skip 4 in from 192.168.1.20 to any
+skip 3 in from 192.168.1.100 to any
+skip 2 in from 192.168.1.110 to any
+skip 1 in from 192.168.1.120 to any
+skip 18 in from any to any
+skip 4 in from any to 192.168.2.10
+skip 3 in from any to 192.168.2.20
+skip 2 in from any to 192.168.2.30
+skip 1 in from any to 192.168.2.40
+skip 13 in from any to any
+skip 12 in proto tcp from any to any port = 80
+skip 11 in proto tcp from any to any port = 21
+skip 10 in proto tcp from any to any port = 25
+skip 9 in proto tcp from any to any port = 119
+skip 5 out from 192.168.1.10 to any
+skip 4 out from 192.168.1.20 to any
+skip 3 out from 192.168.1.100 to any
+skip 2 out from 192.168.1.110 to any
+skip 1 out from 192.168.1.120 to any
+skip 18 out from any to any
+skip 4 out from any to 192.168.2.10
+skip 3 out from any to 192.168.2.20
+skip 2 out from any to 192.168.2.30
+skip 1 out from any to 192.168.2.40
+skip 13 out from any to any
+skip 12 out proto tcp from any to any port = 80
+skip 11 out proto tcp from any to any port = 21
+skip 10 out proto tcp from any to any port = 25
+skip 9 out proto tcp from any to any port = 119
+skip 4 in from any to 192.168.2.10
+skip 3 in from any to 192.168.2.20
+skip 2 in from any to 192.168.2.30
+skip 1 in from any to 192.168.2.40
+skip 4 in from any to any
+pass in quick proto tcp from any to any port = 80 flags S keep state
+pass in quick proto tcp from any to any port = 21 flags S keep state
+pass in quick proto tcp from any to any port = 25 flags S keep state
+pass in quick proto tcp from any to any port = 119 flags S keep state
+skip 4 out from any to 192.168.2.10
+skip 3 out from any to 192.168.2.20
+skip 2 out from any to 192.168.2.30
+skip 1 out from any to 192.168.2.40
+skip 4 out from any to any
+pass out quick proto tcp from any to any port = 80 flags S keep state
+pass out quick proto tcp from any to any port = 21 flags S keep state
+pass out quick proto tcp from any to any port = 25 flags S keep state
+pass out quick proto tcp from any to any port = 119 flags S keep state
+#
+# Rule 2 (global)
+# firewall10:Policy:2: warning: Changing rule direction due to self reference
+skip 1 in from 192.168.1.0/24 to any
+# firewall10:Policy:2: warning: Changing rule direction due to self reference
+skip 11 in from any to any
+# firewall10:Policy:2: warning: Changing rule direction due to self reference
+skip 3 in from any to 22.22.22.22
+# firewall10:Policy:2: warning: Changing rule direction due to self reference
+skip 2 in from any to 192.168.1.1
+# firewall10:Policy:2: warning: Changing rule direction due to self reference
+skip 1 in from any to 192.168.2.0
+# firewall10:Policy:2: warning: Changing rule direction due to self reference
+skip 7 in from any to any
+# firewall10:Policy:2: warning: Changing rule direction due to self reference
+pass in quick proto icmp from any to any icmp-type 11 code 0 keep state
+# firewall10:Policy:2: warning: Changing rule direction due to self reference
+pass in quick proto icmp from any to any icmp-type 11 code 1 keep state
+# firewall10:Policy:2: warning: Changing rule direction due to self reference
+pass in quick proto icmp from any to any icmp-type 0 code 0 keep state
+# firewall10:Policy:2: warning: Changing rule direction due to self reference
+pass in quick proto icmp from any to any icmp-type 3 keep state
+# firewall10:Policy:2: warning: Changing rule direction due to self reference
+pass in quick proto tcp from 192.168.1.0/24 to 22.22.22.22 port = 22 flags S keep state
+# firewall10:Policy:2: warning: Changing rule direction due to self reference
+pass in quick proto tcp from 192.168.1.0/24 to 192.168.1.1 port = 22 flags S keep state
+# firewall10:Policy:2: warning: Changing rule direction due to self reference
+pass in quick proto tcp from 192.168.1.0/24 to 192.168.2.0 port = 22 flags S keep state
+#
+# Rule 3 (global)
+skip 5 in from 192.168.1.10 to any
+skip 4 in from 192.168.1.20 to any
+skip 3 in from 192.168.1.100 to any
+skip 2 in from 192.168.1.110 to any
+skip 1 in from 192.168.1.120 to any
+skip 9 in from any to any
+skip 4 in from any to 192.168.2.10
+skip 3 in from any to 192.168.2.20
+skip 2 in from any to 192.168.2.30
+skip 1 in from any to 192.168.2.40
+skip 4 in from any to any
+block in quick proto tcp from any to any port = 80
+block in quick proto tcp from any to any port = 21
+block in quick proto tcp from any to any port = 25
+block in quick proto tcp from any to any port = 119
+skip 5 out from 192.168.1.10 to any
+skip 4 out from 192.168.1.20 to any
+skip 3 out from 192.168.1.100 to any
+skip 2 out from 192.168.1.110 to any
+skip 1 out from 192.168.1.120 to any
+skip 9 out from any to any
+skip 4 out from any to 192.168.2.10
+skip 3 out from any to 192.168.2.20
+skip 2 out from any to 192.168.2.30
+skip 1 out from any to 192.168.2.40
+skip 4 out from any to any
+block out quick proto tcp from any to any port = 80
+block out quick proto tcp from any to any port = 21
+block out quick proto tcp from any to any port = 25
+block out quick proto tcp from any to any port = 119
+#
+# Rule 4 (global)
+skip 1 in from 192.168.1.10 to any
+skip 9 in from any to any
+skip 4 in from any to 192.168.2.10
+skip 3 in from any to 192.168.2.20
+skip 2 in from any to 192.168.2.30
+skip 1 in from any to 192.168.2.40
+skip 4 in from any to any
+block in quick proto tcp from any to any port = 80
+block in quick proto tcp from any to any port = 21
+block in quick proto tcp from any to any port = 25
+block in quick proto tcp from any to any port = 119
+skip 1 out from 192.168.1.10 to any
+skip 9 out from any to any
+skip 4 out from any to 192.168.2.10
+skip 3 out from any to 192.168.2.20
+skip 2 out from any to 192.168.2.30
+skip 1 out from any to 192.168.2.40
+skip 4 out from any to any
+block out quick proto tcp from any to any port = 80
+block out quick proto tcp from any to any port = 21
+block out quick proto tcp from any to any port = 25
+block out quick proto tcp from any to any port = 119
+#
+# Rule 5 (global)
+skip 5 in from 192.168.1.10 to any
+skip 4 in from 192.168.1.20 to any
+skip 3 in from 192.168.1.100 to any
+skip 2 in from 192.168.1.110 to any
+skip 1 in from 192.168.1.120 to any
+skip 4 in from any to any
+block in quick proto tcp from any to 192.168.2.10 port = 80
+block in quick proto tcp from any to 192.168.2.10 port = 21
+block in quick proto tcp from any to 192.168.2.10 port = 25
+block in quick proto tcp from any to 192.168.2.10 port = 119
+skip 5 out from 192.168.1.10 to any
+skip 4 out from 192.168.1.20 to any
+skip 3 out from 192.168.1.100 to any
+skip 2 out from 192.168.1.110 to any
+skip 1 out from 192.168.1.120 to any
+skip 4 out from any to any
+block out quick proto tcp from any to 192.168.2.10 port = 80
+block out quick proto tcp from any to 192.168.2.10 port = 21
+block out quick proto tcp from any to 192.168.2.10 port = 25
+block out quick proto tcp from any to 192.168.2.10 port = 119
+#
+# Rule 6 (global)
+skip 5 in from 192.168.1.10 to any
+skip 4 in from 192.168.1.20 to any
+skip 3 in from 192.168.1.100 to any
+skip 2 in from 192.168.1.110 to any
+skip 1 in from 192.168.1.120 to any
+skip 4 in from any to any
+block in quick proto tcp from any to 192.168.2.10 port = 80
+block in quick proto tcp from any to 192.168.2.20 port = 80
+block in quick proto tcp from any to 192.168.2.30 port = 80
+block in quick proto tcp from any to 192.168.2.40 port = 80
+skip 5 out from 192.168.1.10 to any
+skip 4 out from 192.168.1.20 to any
+skip 3 out from 192.168.1.100 to any
+skip 2 out from 192.168.1.110 to any
+skip 1 out from 192.168.1.120 to any
+skip 4 out from any to any
+block out quick proto tcp from any to 192.168.2.10 port = 80
+block out quick proto tcp from any to 192.168.2.20 port = 80
+block out quick proto tcp from any to 192.168.2.30 port = 80
+block out quick proto tcp from any to 192.168.2.40 port = 80
+#
+# Rule 7 (global)
+block in log quick from any to any
+block out log quick from any to any
+#
+# Rule fallback rule
+# fallback rule
+block in quick from any to any
+block out quick from any to any
diff --git a/test/ipf/firewall10.fw.orig b/test/ipf/firewall10.fw.orig
new file mode 100755
index 000000000..0841dfb85
--- /dev/null
+++ b/test/ipf/firewall10.fw.orig
@@ -0,0 +1,95 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:52:46 2011 PST by vadim
+#
+# files: * firewall10.fw
+# files: firewall10-ipf.conf
+#
+# Compiled for ipf
+#
+
+# firewall10:Policy:2: warning: Changing rule direction due to self reference
+
+FWDIR=`dirname $0`
+
+
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:52:46 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$IPF -Fa
+$IPNAT -C
+
+$IPF -I -f ${FWDIR}/firewall10-ipf.conf
+
+
+$IPF -s
+
+
+epilog_commands
+
+/sbin/kldstat -n ipl.ko > /dev/null 2>&1 || $IPF -E
\ No newline at end of file
diff --git a/test/ipf/firewall11-ipf.conf.orig b/test/ipf/firewall11-ipf.conf.orig
new file mode 100755
index 000000000..cc727ecd1
--- /dev/null
+++ b/test/ipf/firewall11-ipf.conf.orig
@@ -0,0 +1,33 @@
+# Policy compiler errors and warnings:
+# firewall11:Policy:1: warning: Changing rule direction due to self reference
+#
+# Rule 0 (ng0)
+pass in quick on ng0 proto icmp from any to keep state
+pass in quick on ng0 proto tcp from any to keep state
+pass in quick on ng0 proto udp from any to keep state
+pass in quick on ng0 from any to
+#
+# Rule 1 (global)
+# firewall11:Policy:1: warning: Changing rule direction due to self reference
+pass in quick proto icmp from any to 10.0.0.1 keep state
+# firewall11:Policy:1: warning: Changing rule direction due to self reference
+pass in quick proto tcp from any to 10.0.0.1 keep state
+# firewall11:Policy:1: warning: Changing rule direction due to self reference
+pass in quick proto udp from any to 10.0.0.1 keep state
+# firewall11:Policy:1: warning: Changing rule direction due to self reference
+pass in quick from any to 10.0.0.1
+#
+# Rule 2 (global)
+pass in quick proto icmp from any to keep state
+pass in quick proto tcp from any to keep state
+pass in quick proto udp from any to keep state
+pass in quick from any to
+pass out quick proto icmp from any to keep state
+pass out quick proto tcp from any to keep state
+pass out quick proto udp from any to keep state
+pass out quick from any to
+#
+# Rule fallback rule
+# fallback rule
+block in quick from any to any
+block out quick from any to any
diff --git a/test/ipf/firewall11-nat.conf.orig b/test/ipf/firewall11-nat.conf.orig
new file mode 100755
index 000000000..3308be771
--- /dev/null
+++ b/test/ipf/firewall11-nat.conf.orig
@@ -0,0 +1,5 @@
+#
+# Rule 0 (NAT)
+rdr from any to any -> 10.0.0.1 ip
+rdr from any to any -> 10.0.0.1 ip
+rdr from any to 10.0.0.1/32 -> 10.0.0.1 ip
diff --git a/test/ipf/firewall11.fw.orig b/test/ipf/firewall11.fw.orig
new file mode 100755
index 000000000..bfdc924ad
--- /dev/null
+++ b/test/ipf/firewall11.fw.orig
@@ -0,0 +1,182 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:52:46 2011 PST by vadim
+#
+# files: * firewall11.fw
+# files: firewall11-ipf.conf
+# files: firewall11-nat.conf
+#
+# Compiled for ipf
+#
+
+# firewall11:Policy:1: warning: Changing rule direction due to self reference
+
+FWDIR=`dirname $0`
+
+
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ update_addresses_of_interface "fxp0 10.0.0.1/0xffffff00" ""
+ update_addresses_of_interface "lo0 127.0.0.1/0xff000000" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:52:46 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$IPF -Fa
+$IPNAT -C
+
+$IPF -I -f ${FWDIR}/firewall11-ipf.conf
+$IPNAT -f ${FWDIR}/firewall11-nat.conf
+
+
+$IPF -s
+
+
+epilog_commands
+
+/sbin/kldstat -n ipl.ko > /dev/null 2>&1 || $IPF -E
\ No newline at end of file
diff --git a/test/ipf/firewall2-ipf.conf.orig b/test/ipf/firewall2-ipf.conf.orig
new file mode 100755
index 000000000..f4f7b39ec
--- /dev/null
+++ b/test/ipf/firewall2-ipf.conf.orig
@@ -0,0 +1,105 @@
+# Policy compiler errors and warnings:
+# firewall2:Policy:9: warning: Changing rule direction due to self reference
+#
+# Rule 0 (eth1)
+# Anti-spoofing rule
+block in log quick on eth1 from 22.22.22.22 to any
+block in log quick on eth1 from 22.22.23.23 to any
+block in log quick on eth1 from 192.168.1.1 to any
+block in log quick on eth1 from 192.168.2.1 to any
+block in log quick on eth1 from 192.168.1.0/24 to any
+#
+# Rule 1 (eth1)
+# Anti-spoofing rule
+skip 5 out on eth1 from 22.22.22.22 to any
+skip 4 out on eth1 from 22.22.23.23 to any
+skip 3 out on eth1 from 192.168.1.1 to any
+skip 2 out on eth1 from 192.168.2.1 to any
+skip 1 out on eth1 from 192.168.1.0/24 to any
+block out log quick on eth1 from any to any
+#
+# Rule 2 (global)
+# block fragments
+block in log quick from any to any with short
+block out log quick from any to any with short
+#
+# Rule 3 (global)
+# sends TCP RST and makes custom record in the log
+block return-rst in log quick proto tcp from any to any port = 113
+block out log quick proto tcp from any to any port = 113
+#
+# Rule 4 (global)
+# sends TCP RST and makes custom record in the log
+block return-icmp-as-dest (0) in log quick proto udp from any to any port = 161
+block out log quick proto udp from any to any port = 161
+#
+# Rule 5 (global)
+pass in quick proto icmp from 192.168.1.10 to 200.200.200.200 keep state
+pass in quick proto icmp from 192.168.1.20 to 200.200.200.200 keep state
+pass in quick proto tcp from 192.168.1.10 to 200.200.200.200 keep state
+pass in quick proto tcp from 192.168.1.20 to 200.200.200.200 keep state
+pass in quick proto udp from 192.168.1.10 to 200.200.200.200 keep state
+pass in quick proto udp from 192.168.1.20 to 200.200.200.200 keep state
+pass in quick from 192.168.1.10 to 200.200.200.200
+pass in quick from 192.168.1.20 to 200.200.200.200
+pass out quick proto icmp from 192.168.1.10 to 200.200.200.200 keep state
+pass out quick proto icmp from 192.168.1.20 to 200.200.200.200 keep state
+pass out quick proto tcp from 192.168.1.10 to 200.200.200.200 keep state
+pass out quick proto tcp from 192.168.1.20 to 200.200.200.200 keep state
+pass out quick proto udp from 192.168.1.10 to 200.200.200.200 keep state
+pass out quick proto udp from 192.168.1.20 to 200.200.200.200 keep state
+pass out quick from 192.168.1.10 to 200.200.200.200
+pass out quick from 192.168.1.20 to 200.200.200.200
+#
+# Rule 6 (global)
+pass in quick proto icmp from 200.200.200.200 to 192.168.1.10 keep state
+pass in quick proto icmp from 200.200.200.200 to 192.168.1.20 keep state
+pass in quick proto tcp from 200.200.200.200 to 192.168.1.10 keep state
+pass in quick proto tcp from 200.200.200.200 to 192.168.1.20 keep state
+pass in quick proto udp from 200.200.200.200 to 192.168.1.10 keep state
+pass in quick proto udp from 200.200.200.200 to 192.168.1.20 keep state
+pass in quick from 200.200.200.200 to 192.168.1.10
+pass in quick from 200.200.200.200 to 192.168.1.20
+pass out quick proto icmp from 200.200.200.200 to 192.168.1.10 keep state
+pass out quick proto icmp from 200.200.200.200 to 192.168.1.20 keep state
+pass out quick proto tcp from 200.200.200.200 to 192.168.1.10 keep state
+pass out quick proto tcp from 200.200.200.200 to 192.168.1.20 keep state
+pass out quick proto udp from 200.200.200.200 to 192.168.1.10 keep state
+pass out quick proto udp from 200.200.200.200 to 192.168.1.20 keep state
+pass out quick from 200.200.200.200 to 192.168.1.10
+pass out quick from 200.200.200.200 to 192.168.1.20
+#
+# Rule 7 (global)
+# 'masquerading' rule
+pass in quick proto icmp from 192.168.1.0/24 to any keep state
+pass in quick proto tcp from 192.168.1.0/24 to any keep state
+pass in quick proto udp from 192.168.1.0/24 to any keep state
+pass in quick from 192.168.1.0/24 to any
+pass out quick proto icmp from 192.168.1.0/24 to any keep state
+pass out quick proto tcp from 192.168.1.0/24 to any keep state
+pass out quick proto udp from 192.168.1.0/24 to any keep state
+pass out quick from 192.168.1.0/24 to any
+#
+# Rule 8 (global)
+# host-fw2 has the same address as
+# one of the firewall's interfaces
+pass in log quick proto tcp from any to 22.22.22.22 port = 21 keep state
+pass out log quick proto tcp from any to 22.22.22.22 port = 21 keep state
+#
+# Rule 9 (global)
+# firewall2:Policy:9: warning: Changing rule direction due to self reference
+pass in log quick proto tcp from any to 22.22.23.23 port = 21 keep state
+# firewall2:Policy:9: warning: Changing rule direction due to self reference
+pass in log quick proto tcp from any to 192.168.1.1 port = 21 keep state
+# firewall2:Policy:9: warning: Changing rule direction due to self reference
+pass in log quick proto tcp from any to 192.168.2.1 port = 21 keep state
+#
+# Rule 10 (global)
+# 'catch all' rule
+block in log quick from any to any
+block out log quick from any to any
+#
+# Rule fallback rule
+# fallback rule
+block in quick from any to any
+block out quick from any to any
diff --git a/test/ipf/firewall2-nat.conf.orig b/test/ipf/firewall2-nat.conf.orig
new file mode 100755
index 000000000..47dace3bc
--- /dev/null
+++ b/test/ipf/firewall2-nat.conf.orig
@@ -0,0 +1,464 @@
+# NAT compiler errors and warnings:
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+#
+# Rule 0 (NAT)
+map eth1 from 192.168.1.0/24 to any -> 22.22.22.22/32 portmap tcp/udp auto
+map eth1 from 192.168.1.0/24 to any -> 22.22.22.22/32
+map eth3 from 192.168.1.0/24 to any -> 22.22.23.23/32 portmap tcp/udp auto
+map eth3 from 192.168.1.0/24 to any -> 22.22.23.23/32
+map eth0 from 192.168.1.0/24 to any -> 192.168.1.1/32 portmap tcp/udp auto
+map eth0 from 192.168.1.0/24 to any -> 192.168.1.1/32
+map eth2 from 192.168.1.0/24 to any -> 192.168.2.1/32 portmap tcp/udp auto
+map eth2 from 192.168.1.0/24 to any -> 192.168.2.1/32
+#
+# Rule 1 (NAT)
+map eth0 from 192.168.1.10/32 to any -> 22.22.22.23/32 portmap tcp/udp auto
+map eth1 from 192.168.1.10/32 to any -> 22.22.22.23/32 portmap tcp/udp auto
+map eth3 from 192.168.1.10/32 to any -> 22.22.22.23/32 portmap tcp/udp auto
+map eth2 from 192.168.1.10/32 to any -> 22.22.22.23/32 portmap tcp/udp auto
+map eth0 from 192.168.1.10/32 to any -> 22.22.22.23/32
+map eth1 from 192.168.1.10/32 to any -> 22.22.22.23/32
+map eth3 from 192.168.1.10/32 to any -> 22.22.22.23/32
+map eth2 from 192.168.1.10/32 to any -> 22.22.22.23/32
+map eth0 from 192.168.1.20/32 to any -> 22.22.22.23/32 portmap tcp/udp auto
+map eth1 from 192.168.1.20/32 to any -> 22.22.22.23/32 portmap tcp/udp auto
+map eth3 from 192.168.1.20/32 to any -> 22.22.22.23/32 portmap tcp/udp auto
+map eth2 from 192.168.1.20/32 to any -> 22.22.22.23/32 portmap tcp/udp auto
+map eth0 from 192.168.1.20/32 to any -> 22.22.22.23/32
+map eth1 from 192.168.1.20/32 to any -> 22.22.22.23/32
+map eth3 from 192.168.1.20/32 to any -> 22.22.22.23/32
+map eth2 from 192.168.1.20/32 to any -> 22.22.22.23/32
+#
+# Rule 2 (NAT)
+map eth1 from 192.168.1.0/24 to any port = 22 -> 22.22.22.22/32 portmap tcp/udp auto
+map eth3 from 192.168.1.0/24 to any port = 22 -> 22.22.23.23/32 portmap tcp/udp auto
+map eth0 from 192.168.1.0/24 to any port = 22 -> 192.168.1.1/32 portmap tcp/udp auto
+map eth2 from 192.168.1.0/24 to any port = 22 -> 192.168.2.1/32 portmap tcp/udp auto
+map eth1 from 192.168.1.0/24 to any -> 22.22.22.22/32 proxy port 21 ftp/tcp
+map eth3 from 192.168.1.0/24 to any -> 22.22.23.23/32 proxy port 21 ftp/tcp
+map eth0 from 192.168.1.0/24 to any -> 192.168.1.1/32 proxy port 21 ftp/tcp
+map eth2 from 192.168.1.0/24 to any -> 192.168.2.1/32 proxy port 21 ftp/tcp
+#
+# Rule 3 (NAT)
+map eth1 from 192.168.1.0/24 to any port = 22 -> 22.22.22.22/32 portmap tcp/udp auto
+#
+# Rule 4 (NAT)
+map eth1 from 192.168.1.0/24 to any -> 22.22.22.22/32 proxy port 500 ipsec/udp
+#
+# Rule 5 (NAT)
+map eth0 from 192.168.1.0/24 to 192.168.1.10/32 -> 192.168.1.1/32 portmap tcp/udp auto
+map eth1 from 192.168.1.0/24 to 192.168.1.10/32 -> 192.168.1.1/32 portmap tcp/udp auto
+map eth3 from 192.168.1.0/24 to 192.168.1.10/32 -> 192.168.1.1/32 portmap tcp/udp auto
+map eth2 from 192.168.1.0/24 to 192.168.1.10/32 -> 192.168.1.1/32 portmap tcp/udp auto
+map eth0 from 192.168.1.0/24 to 192.168.1.10/32 -> 192.168.1.1/32
+map eth1 from 192.168.1.0/24 to 192.168.1.10/32 -> 192.168.1.1/32
+map eth3 from 192.168.1.0/24 to 192.168.1.10/32 -> 192.168.1.1/32
+map eth2 from 192.168.1.0/24 to 192.168.1.10/32 -> 192.168.1.1/32
+map eth0 from 192.168.1.0/24 to 192.168.1.20/32 -> 192.168.1.1/32 portmap tcp/udp auto
+map eth1 from 192.168.1.0/24 to 192.168.1.20/32 -> 192.168.1.1/32 portmap tcp/udp auto
+map eth3 from 192.168.1.0/24 to 192.168.1.20/32 -> 192.168.1.1/32 portmap tcp/udp auto
+map eth2 from 192.168.1.0/24 to 192.168.1.20/32 -> 192.168.1.1/32 portmap tcp/udp auto
+map eth0 from 192.168.1.0/24 to 192.168.1.20/32 -> 192.168.1.1/32
+map eth1 from 192.168.1.0/24 to 192.168.1.20/32 -> 192.168.1.1/32
+map eth3 from 192.168.1.0/24 to 192.168.1.20/32 -> 192.168.1.1/32
+map eth2 from 192.168.1.0/24 to 192.168.1.20/32 -> 192.168.1.1/32
+#
+# Rule 7 (NAT)
+rdr eth1 from any to 22.22.22.23/32 port = 80 -> 192.168.1.10 port 80 tcp
+rdr eth1 from any to 22.22.22.23/32 port = 119 -> 192.168.1.10 port 119 tcp
+#
+# Rule 8 (NAT)
+# load balancing rule
+rdr eth1 from any to 22.22.22.23/32 port = 80 -> 192.168.1.10,192.168.1.20 port 80 tcp round-robin
+rdr eth1 from any to 22.22.22.23/32 port = 80 -> 192.168.1.100 port 80 tcp round-robin
+#
+# Rule 9 (NAT)
+# load balancing rule
+rdr eth1 from any to 22.22.22.23/32 port = 80 -> 192.168.1.10,192.168.1.20 port 80 tcp round-robin
+rdr eth1 from any to 22.22.22.23/32 port = 80 -> 192.168.1.100 port 80 tcp round-robin
+#
+# Rule 10 (NAT)
+map eth0 from 192.168.1.0/24 to 192.168.2.10/32 -> 192.168.2.1/32 portmap tcp/udp auto
+map eth1 from 192.168.1.0/24 to 192.168.2.10/32 -> 192.168.2.1/32 portmap tcp/udp auto
+map eth3 from 192.168.1.0/24 to 192.168.2.10/32 -> 192.168.2.1/32 portmap tcp/udp auto
+map eth2 from 192.168.1.0/24 to 192.168.2.10/32 -> 192.168.2.1/32 portmap tcp/udp auto
+map eth0 from 192.168.1.0/24 to 192.168.2.10/32 -> 192.168.2.1/32
+map eth1 from 192.168.1.0/24 to 192.168.2.10/32 -> 192.168.2.1/32
+map eth3 from 192.168.1.0/24 to 192.168.2.10/32 -> 192.168.2.1/32
+map eth2 from 192.168.1.0/24 to 192.168.2.10/32 -> 192.168.2.1/32
+#
+# Rule 11 (NAT)
+rdr eth1 from any to 22.22.22.24/32 port = 80 -> 192.168.2.10 port 80 tcp
+#
+# Rule 12 (NAT)
+rdr eth1 from any to 22.22.22.22/32 port = 119 -> 192.168.1.10 port 119 tcp
+#
+# Rule 13 (NAT)
+map eth0 from 192.168.1.20/32 to any -> 22.22.23.24/32 portmap tcp/udp auto
+map eth1 from 192.168.1.20/32 to any -> 22.22.23.24/32 portmap tcp/udp auto
+map eth3 from 192.168.1.20/32 to any -> 22.22.23.24/32 portmap tcp/udp auto
+map eth2 from 192.168.1.20/32 to any -> 22.22.23.24/32 portmap tcp/udp auto
+map eth0 from 192.168.1.20/32 to any -> 22.22.23.24/32
+map eth1 from 192.168.1.20/32 to any -> 22.22.23.24/32
+map eth3 from 192.168.1.20/32 to any -> 22.22.23.24/32
+map eth2 from 192.168.1.20/32 to any -> 22.22.23.24/32
+#
+# Rule 15 (NAT)
+# NETMAP
+map eth0 from 192.168.1.0/24 to any -> 22.22.22.0/24 portmap tcp/udp auto
+map eth1 from 192.168.1.0/24 to any -> 22.22.22.0/24 portmap tcp/udp auto
+map eth3 from 192.168.1.0/24 to any -> 22.22.22.0/24 portmap tcp/udp auto
+map eth2 from 192.168.1.0/24 to any -> 22.22.22.0/24 portmap tcp/udp auto
+map eth0 from 192.168.1.0/24 to any -> 22.22.22.0/24
+map eth1 from 192.168.1.0/24 to any -> 22.22.22.0/24
+map eth3 from 192.168.1.0/24 to any -> 22.22.22.0/24
+map eth2 from 192.168.1.0/24 to any -> 22.22.22.0/24
+#
+# Rule 17 (NAT)
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10000 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10000 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10000 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10000 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10001 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10001 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10001 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10001 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10002 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10002 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10002 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10002 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10003 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10003 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10003 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10003 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10004 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10004 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10004 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10004 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10005 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10005 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10005 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10005 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10006 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10006 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10006 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10006 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10007 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10007 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10007 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10007 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10008 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10008 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10008 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10008 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10009 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10009 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10009 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10009 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10010 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10010 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10010 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10010 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10011 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10011 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10011 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10011 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10012 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10012 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10012 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10012 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10013 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10013 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10013 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10013 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10014 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10014 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10014 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10014 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10015 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10015 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10015 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10015 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10016 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10016 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10016 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10016 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10017 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10017 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10017 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10017 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10018 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10018 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10018 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10018 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10019 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10019 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10019 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10019 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10020 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10020 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10020 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10020 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10021 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10021 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10021 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10021 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10022 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10022 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10022 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10022 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10023 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10023 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10023 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10023 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10024 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10024 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10024 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10024 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10025 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10025 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10025 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10025 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10026 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10026 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10026 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10026 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10027 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10027 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10027 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10027 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10028 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10028 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10028 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10028 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10029 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10029 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10029 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10029 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10030 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10030 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10030 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10030 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10031 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10031 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10031 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10031 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10032 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10032 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10032 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10032 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10033 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10033 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10033 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10033 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10034 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10034 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10034 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10034 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10035 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10035 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10035 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10035 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10036 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10036 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10036 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10036 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10037 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10037 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10037 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10037 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10038 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10038 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10038 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10038 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10039 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10039 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10039 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10039 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.22.22/32 port = 10040 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 22.22.23.23/32 port = 10040 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.1.1/32 port = 10040 -> 192.168.1.10 port 10000 tcp
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+rdr from any to 192.168.2.1/32 port = 10040 -> 192.168.1.10 port 10000 tcp
+#
+# Rule 18 (NAT)
+rdr eth1 from any to 22.22.22.23/32 port = 80 -> 192.168.1.10 port 25 tcp
+#
+# Rule 19 (NAT)
+map eth2 from 192.168.1.0/24 to 192.168.2.0/24 -> 0/0 proxy port 21 ftp/tcp
+#
+# Rule 20 (NAT)
+map eth2 from 192.168.1.0/24 to 192.168.2.0/24 -> 0/0 proxy port 21 ftp/tcp
+map eth2 from 192.168.1.0/24 to 192.168.2.0/24 -> 0/0 proxy port 1720 h323/tcp
+#
+# Rule 21 (NAT)
+map eth2 from 192.168.1.0/24 to 192.168.2.0/24 port = 80 -> 0/0
+#
+# Rule 22 (NAT)
+map eth2 from 192.168.1.0/24 to 192.168.2.0/24 -> 0/0
+#
+# Rule 23 (NAT)
+map eth2 from 192.168.1.0/24 to 192.168.2.0/24 -> 0/0
diff --git a/test/ipf/firewall2.fw.orig b/test/ipf/firewall2.fw.orig
new file mode 100755
index 000000000..2ee2a4f8b
--- /dev/null
+++ b/test/ipf/firewall2.fw.orig
@@ -0,0 +1,100 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:52:47 2011 PST by vadim
+#
+# files: * firewall2.fw
+# files: firewall2-ipf.conf
+# files: firewall2-nat.conf
+#
+# Compiled for ipf
+#
+# this object has several interfaces and shows different rules for NAT. Also testing policy rule options
+
+# firewall2:Policy:9: warning: Changing rule direction due to self reference
+
+# firewall2:NAT:17: warning: Expanding port range test-TCP creates 41 rules
+
+FWDIR=`dirname $0`
+
+
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:52:47 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$IPF -Fa
+$IPNAT -C
+
+$IPF -I -f ${FWDIR}/firewall2-ipf.conf
+$IPNAT -f ${FWDIR}/firewall2-nat.conf
+
+
+$IPF -s
+
+
+epilog_commands
+
+/sbin/kldstat -n ipl.ko > /dev/null 2>&1 || $IPF -E
\ No newline at end of file
diff --git a/test/ipf/firewall34-ipf.conf.orig b/test/ipf/firewall34-ipf.conf.orig
new file mode 100755
index 000000000..b4b1c4866
--- /dev/null
+++ b/test/ipf/firewall34-ipf.conf.orig
@@ -0,0 +1,73 @@
+#
+# Rule 0 (global)
+pass in quick proto icmp from any to 192.168.1.1 keep state
+pass in quick proto icmp from any to 192.168.1.2 keep state
+pass in quick proto icmp from any to 192.168.1.3/30 keep state
+pass in quick proto icmp from any to 192.168.1.200 keep state
+pass in quick proto icmp from any to 192.168.1.201 keep state
+pass in quick proto icmp from any to 192.168.2.128/25 keep state
+pass in quick proto tcp from any to 192.168.1.1 keep state
+pass in quick proto tcp from any to 192.168.1.2 keep state
+pass in quick proto tcp from any to 192.168.1.3/30 keep state
+pass in quick proto tcp from any to 192.168.1.200 keep state
+pass in quick proto tcp from any to 192.168.1.201 keep state
+pass in quick proto tcp from any to 192.168.2.128/25 keep state
+pass in quick proto udp from any to 192.168.1.1 keep state
+pass in quick proto udp from any to 192.168.1.2 keep state
+pass in quick proto udp from any to 192.168.1.3/30 keep state
+pass in quick proto udp from any to 192.168.1.200 keep state
+pass in quick proto udp from any to 192.168.1.201 keep state
+pass in quick proto udp from any to 192.168.2.128/25 keep state
+pass in quick from any to 192.168.1.1
+pass in quick from any to 192.168.1.2
+pass in quick from any to 192.168.1.3/30
+pass in quick from any to 192.168.1.200
+pass in quick from any to 192.168.1.201
+pass in quick from any to 192.168.2.128/25
+pass out quick proto icmp from any to 192.168.1.1 keep state
+pass out quick proto icmp from any to 192.168.1.2 keep state
+pass out quick proto icmp from any to 192.168.1.3/30 keep state
+pass out quick proto icmp from any to 192.168.1.200 keep state
+pass out quick proto icmp from any to 192.168.1.201 keep state
+pass out quick proto icmp from any to 192.168.2.128/25 keep state
+pass out quick proto tcp from any to 192.168.1.1 keep state
+pass out quick proto tcp from any to 192.168.1.2 keep state
+pass out quick proto tcp from any to 192.168.1.3/30 keep state
+pass out quick proto tcp from any to 192.168.1.200 keep state
+pass out quick proto tcp from any to 192.168.1.201 keep state
+pass out quick proto tcp from any to 192.168.2.128/25 keep state
+pass out quick proto udp from any to 192.168.1.1 keep state
+pass out quick proto udp from any to 192.168.1.2 keep state
+pass out quick proto udp from any to 192.168.1.3/30 keep state
+pass out quick proto udp from any to 192.168.1.200 keep state
+pass out quick proto udp from any to 192.168.1.201 keep state
+pass out quick proto udp from any to 192.168.2.128/25 keep state
+pass out quick from any to 192.168.1.1
+pass out quick from any to 192.168.1.2
+pass out quick from any to 192.168.1.3/30
+pass out quick from any to 192.168.1.200
+pass out quick from any to 192.168.1.201
+pass out quick from any to 192.168.2.128/25
+#
+# Rule 7 (global)
+pass in quick proto tcp from any to 192.168.1.10 port = 25 keep state
+pass out quick proto tcp from any to 192.168.1.10 port = 25 keep state
+#
+# Rule 8 (global)
+pass in quick proto icmp from 192.168.1.0/24 to any keep state
+pass in quick proto tcp from 192.168.1.0/24 to any keep state
+pass in quick proto udp from 192.168.1.0/24 to any keep state
+pass in quick from 192.168.1.0/24 to any
+pass out quick proto icmp from 192.168.1.0/24 to any keep state
+pass out quick proto tcp from 192.168.1.0/24 to any keep state
+pass out quick proto udp from 192.168.1.0/24 to any keep state
+pass out quick from 192.168.1.0/24 to any
+#
+# Rule 9 (global)
+block in log quick from any to any
+block out log quick from any to any
+#
+# Rule fallback rule
+# fallback rule
+block in quick from any to any
+block out quick from any to any
diff --git a/test/ipf/firewall34-nat.conf.orig b/test/ipf/firewall34-nat.conf.orig
new file mode 100755
index 000000000..e69de29bb
diff --git a/test/ipf/firewall34.fw.orig b/test/ipf/firewall34.fw.orig
new file mode 100755
index 000000000..c794a90b1
--- /dev/null
+++ b/test/ipf/firewall34.fw.orig
@@ -0,0 +1,183 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:52:48 2011 PST by vadim
+#
+# files: * firewall34.fw
+# files: firewall34-ipf.conf
+# files: firewall34-nat.conf
+#
+# Compiled for ipf
+#
+# testing AddressTable object
+
+
+
+FWDIR=`dirname $0`
+
+
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ update_addresses_of_interface "eth1 192.168.1.100/0xffffff00" ""
+ update_addresses_of_interface "lo 127.0.0.1/0xff000000" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:52:48 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$IPF -Fa
+$IPNAT -C
+
+$IPF -I -f ${FWDIR}/firewall34-ipf.conf
+$IPNAT -f ${FWDIR}/firewall34-nat.conf
+
+
+$IPF -s
+
+
+epilog_commands
+
+/sbin/kldstat -n ipl.ko > /dev/null 2>&1 || $IPF -E
\ No newline at end of file
diff --git a/test/ipf/firewall35-ipf.conf.orig b/test/ipf/firewall35-ipf.conf.orig
new file mode 100755
index 000000000..4fbcfe393
--- /dev/null
+++ b/test/ipf/firewall35-ipf.conf.orig
@@ -0,0 +1,22 @@
+#
+# Rule 0 (le1)
+auth in quick on le1 from 192.168.1.0/24 to any
+#
+# Rule 1 (le1)
+skip 1 in on le1 from 192.168.1.0/24 to any
+auth in quick on le1 from any to any
+#
+# Rule 2 (le1)
+pass in quick on le1 proto icmp from 192.168.1.0/24 to any keep state
+pass in quick on le1 proto tcp from 192.168.1.0/24 to any flags S keep state
+pass in quick on le1 proto udp from 192.168.1.0/24 to any keep state
+pass in quick on le1 from 192.168.1.0/24 to any
+#
+# Rule 3 (global)
+block in log quick from any to any
+block out log quick from any to any
+#
+# Rule fallback rule
+# fallback rule
+block in quick from any to any
+block out quick from any to any
diff --git a/test/ipf/firewall35-nat.conf.orig b/test/ipf/firewall35-nat.conf.orig
new file mode 100755
index 000000000..953be51c7
--- /dev/null
+++ b/test/ipf/firewall35-nat.conf.orig
@@ -0,0 +1,39 @@
+#
+# Rule 0 (NAT)
+map le1 from 192.168.1.0/24 to any -> 22.22.22.22/32 portmap tcp/udp auto
+map le1 from 192.168.1.0/24 to any -> 22.22.22.22/32
+map le0 from 192.168.1.0/24 to any -> 192.168.1.1/32 portmap tcp/udp auto
+map le0 from 192.168.1.0/24 to any -> 192.168.1.1/32
+#
+# Rule 1 (NAT)
+map le1 from 192.168.1.0/24 to any -> 22.22.22.22/32 portmap tcp/udp auto
+map le1 from 192.168.1.0/24 to any -> 22.22.22.22/32
+#
+# Rule 2 (NAT)
+map le0 from 192.168.1.0/24 to any -> 0/0
+#
+# Rule 3 (NAT)
+rdr from any to 22.22.22.22/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 192.168.1.1/32 port = 22 -> 192.168.1.100 port 22 tcp
+#
+# Rule 4 (NAT)
+rdr from any to 22.22.22.22/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 192.168.1.1/32 port = 22 -> 192.168.1.100 port 22 tcp
+#
+# Rule 5 (NAT)
+rdr from any to 22.22.22.22/32 port = 22 -> 192.168.1.1 port 22 tcp
+rdr from any to 192.168.1.1/32 port = 22 -> 192.168.1.1 port 22 tcp
+#
+# Rule 6 (NAT)
+rdr from any to 22.22.22.22/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 192.168.1.1/32 port = 22 -> 192.168.1.100 port 22 tcp
+#
+# Rule 7 (NAT)
+rdr le1 from any to 22.22.22.22/32 port = 22 -> 192.168.1.100 port 22 tcp
+#
+# Rule 8 (NAT)
+rdr le1 from any to 22.22.22.22/32 port = 22 -> 192.168.1.1 port 22 tcp
+#
+# Rule 9 (NAT)
+rdr le0 from any to any port = 22 -> 192.168.1.100 port 22 tcp
+rdr le1 from any to any port = 22 -> 192.168.1.100 port 22 tcp
diff --git a/test/ipf/firewall35.fw.orig b/test/ipf/firewall35.fw.orig
new file mode 100755
index 000000000..6131fde3f
--- /dev/null
+++ b/test/ipf/firewall35.fw.orig
@@ -0,0 +1,98 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:52:48 2011 PST by vadim
+#
+# files: * firewall35.fw
+# files: firewall35-ipf.conf
+# files: firewall35-nat.conf
+#
+# Compiled for ipf
+#
+# Testing action Custom
+
+
+
+FWDIR=`dirname $0`
+
+
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:52:48 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$IPF -Fa
+$IPNAT -C
+
+$IPF -I -f ${FWDIR}/firewall35-ipf.conf
+$IPNAT -f ${FWDIR}/firewall35-nat.conf
+
+
+$IPF -s
+
+
+epilog_commands
+
+/sbin/kldstat -n ipl.ko > /dev/null 2>&1 || $IPF -E
\ No newline at end of file
diff --git a/test/ipf/firewall4-ipf.conf.orig b/test/ipf/firewall4-ipf.conf.orig
new file mode 100755
index 000000000..afa788423
--- /dev/null
+++ b/test/ipf/firewall4-ipf.conf.orig
@@ -0,0 +1,83 @@
+# Policy compiler errors and warnings:
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+#
+# Rule 0 (eth1)
+# Anti-spoofing rule
+block in log quick on eth1 from 192.168.1.1 to any
+block in log quick on eth1 from 192.168.2.1 to any
+block in log quick on eth1 from 222.222.222.222 to any
+block in log quick on eth1 from 192.168.1.0/24 to any
+#
+# Rule 1 (eth1)
+# Anti-spoofing rule
+skip 4 out on eth1 from 192.168.1.1 to any
+skip 3 out on eth1 from 192.168.2.1 to any
+skip 2 out on eth1 from 222.222.222.222 to any
+skip 1 out on eth1 from 192.168.1.0/24 to any
+block out log quick on eth1 from any to any
+#
+# Rule 2 (eth1)
+block in log quick on eth1 proto icmp from any to any icmp-type 8 code 0
+block out log quick on eth1 proto icmp from any to any icmp-type 8 code 0
+#
+# Rule 3 (eth1)
+skip 1 in on eth1 proto icmp from 192.168.2.0/24 to any icmp-type 8 code 0
+skip 1 out on eth1 proto icmp from 192.168.2.0/24 to any icmp-type 8 code 0
+block in log quick on eth1 proto icmp from any to any icmp-type 8 code 0
+block out log quick on eth1 proto icmp from any to any icmp-type 8 code 0
+#
+# Rule 4 (global)
+# hostF has the same IP address as firewal.
+pass in log quick proto icmp from any to 192.168.1.1 icmp-type 8 code 0 keep state
+pass out log quick proto icmp from any to 192.168.1.1 icmp-type 8 code 0 keep state
+#
+# Rule 5 (global)
+# testing negation in the policy rule
+skip 2 in proto icmp from 192.168.1.10 to any icmp-type 3
+skip 1 in proto icmp from 192.168.1.20 to any icmp-type 3
+skip 2 out proto icmp from 192.168.1.10 to any icmp-type 3
+skip 1 out proto icmp from 192.168.1.20 to any icmp-type 3
+block in log quick proto icmp from any to any icmp-type 3
+block out log quick proto icmp from any to any icmp-type 3
+#
+# Rule 6 (global)
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+skip 8 in proto icmp from 192.168.1.10 to 192.168.1.1 icmp-type 3
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+skip 7 in proto icmp from 192.168.1.10 to 192.168.2.1 icmp-type 3
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+skip 6 in proto icmp from 192.168.1.10 to 222.222.222.222 icmp-type 3
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+skip 5 in proto icmp from 192.168.1.20 to 192.168.1.1 icmp-type 3
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+skip 4 in proto icmp from 192.168.1.20 to 192.168.2.1 icmp-type 3
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+skip 3 in proto icmp from 192.168.1.20 to 222.222.222.222 icmp-type 3
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+block in log quick proto icmp from any to 192.168.1.1 icmp-type 3
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+block in log quick proto icmp from any to 192.168.2.1 icmp-type 3
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+block in log quick proto icmp from any to 222.222.222.222 icmp-type 3
+#
+# Rule 8 (global)
+# 'masquerading' rule
+pass in quick proto icmp from 192.168.1.0/24 to any keep state
+pass in quick proto tcp from 192.168.1.0/24 to any keep state
+pass in quick proto udp from 192.168.1.0/24 to any keep state
+pass in quick from 192.168.1.0/24 to any
+pass out quick proto icmp from 192.168.1.0/24 to any keep state
+pass out quick proto tcp from 192.168.1.0/24 to any keep state
+pass out quick proto udp from 192.168.1.0/24 to any keep state
+pass out quick from 192.168.1.0/24 to any
+#
+# Rule 10 (global)
+# 'catch all' rule
+block in log quick from any to any
+block out log quick from any to any
+#
+# Rule fallback rule
+# fallback rule
+block in quick from any to any
+block out quick from any to any
diff --git a/test/ipf/firewall4-nat.conf.orig b/test/ipf/firewall4-nat.conf.orig
new file mode 100755
index 000000000..d417aaf8d
--- /dev/null
+++ b/test/ipf/firewall4-nat.conf.orig
@@ -0,0 +1,52 @@
+#
+# Rule 0 (NAT)
+map eth1 from 192.168.1.10/32 to any -> 0/32 portmap tcp/udp auto
+map eth1 from 192.168.1.10/32 to any -> 0/32
+map eth0 from 192.168.1.10/32 to any -> 192.168.1.1/32 portmap tcp/udp auto
+map eth0 from 192.168.1.10/32 to any -> 192.168.1.1/32
+map eth2 from 192.168.1.10/32 to any -> 192.168.2.1/32 portmap tcp/udp auto
+map eth2 from 192.168.1.10/32 to any -> 192.168.2.1/32
+map eth3 from 192.168.1.10/32 to any -> 222.222.222.222/32 portmap tcp/udp auto
+map eth3 from 192.168.1.10/32 to any -> 222.222.222.222/32
+#
+# Rule 1 (NAT)
+map eth3 from 192.168.1.10/32 to any -> 222.222.222.222/32 portmap tcp/udp auto
+map eth3 from 192.168.1.10/32 to any -> 222.222.222.222/32
+#
+# Rule 2 (NAT)
+map eth3 from 192.168.1.10/32 to any -> 222.222.222.222/32 portmap tcp/udp auto
+map eth3 from 192.168.1.10/32 to any -> 222.222.222.222/32
+#
+# Rule 3 (NAT)
+map eth1 from 192.168.1.10/32 to any -> 0/32 portmap tcp/udp auto
+map eth1 from 192.168.1.10/32 to any -> 0/32
+#
+# Rule 5 (NAT)
+rdr from any to any port = 22 -> 192.168.1.10 port 22 tcp
+rdr from any to 192.168.1.1/32 port = 22 -> 192.168.1.10 port 22 tcp
+rdr from any to 192.168.2.1/32 port = 22 -> 192.168.1.10 port 22 tcp
+rdr from any to 222.222.222.222/32 port = 22 -> 192.168.1.10 port 22 tcp
+#
+# Rule 6 (NAT)
+rdr eth0 from 192.168.1.0/24 to any port = 80 -> 192.168.2.1 port 3128 tcp
+rdr eth0 from 192.168.1.0/24 to any port = 443 -> 192.168.2.1 port 3128 tcp
+#
+# Rule 7 (NAT)
+rdr eth0 from 192.168.1.0/24 to any port = 80 -> 192.168.2.1 port 3128 tcp
+rdr eth0 from 192.168.1.0/24 to any port = 443 -> 192.168.2.1 port 3128 tcp
+#
+# Rule 8 (NAT)
+rdr eth0 from any to any port = 80 -> 192.168.1.1 port 3128 tcp
+rdr eth1 from any to any port = 80 -> 0/32 port 3128 tcp
+rdr eth2 from any to any port = 80 -> 192.168.2.1 port 3128 tcp
+rdr eth3 from any to any port = 80 -> 222.222.222.222 port 3128 tcp
+rdr eth0 from any to any port = 443 -> 192.168.1.1 port 3128 tcp
+rdr eth1 from any to any port = 443 -> 0/32 port 3128 tcp
+rdr eth2 from any to any port = 443 -> 192.168.2.1 port 3128 tcp
+rdr eth3 from any to any port = 443 -> 222.222.222.222 port 3128 tcp
+#
+# Rule 10 (NAT)
+map eth1 from any to any -> 0/32 proxy port 514 rcmd/tcp
+#
+# Rule 11 (NAT)
+map eth1 from 192.168.1.0/24 to any -> 0/32 proxy port 21 ftp/tcp
diff --git a/test/ipf/firewall4.fw.orig b/test/ipf/firewall4.fw.orig
new file mode 100755
index 000000000..b42d721f5
--- /dev/null
+++ b/test/ipf/firewall4.fw.orig
@@ -0,0 +1,101 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:52:48 2011 PST by vadim
+#
+# files: * firewall4.fw
+# files: firewall4-ipf.conf
+# files: firewall4-nat.conf
+#
+# Compiled for ipf
+#
+# this object is used to test a configuration where firewall has dynamic address
+
+# firewall4::: error: Dynamic interface eth1 should not have an IP address object attached to it. This IP address object will be ignored.
+
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+
+FWDIR=`dirname $0`
+
+
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/usr/sbin/ipf"
+IPNAT="/usr/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:52:48 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$IPF -Fa
+$IPNAT -C
+
+$IPF -I -f ${FWDIR}/firewall4-ipf.conf
+$IPNAT -f ${FWDIR}/firewall4-nat.conf
+
+
+$IPF -s
+
+
+epilog_commands
+
+/sbin/kldstat -n ipl.ko > /dev/null 2>&1 || $IPF -E
\ No newline at end of file
diff --git a/test/ipf/firewall5-ipf.conf.orig b/test/ipf/firewall5-ipf.conf.orig
new file mode 100755
index 000000000..9c189980a
--- /dev/null
+++ b/test/ipf/firewall5-ipf.conf.orig
@@ -0,0 +1,27 @@
+# Policy compiler errors and warnings:
+# firewall5:Policy:0: warning: Changing rule direction due to self reference
+#
+# Rule 0 (global)
+# firewall5:Policy:0: warning: Changing rule direction due to self reference
+pass in quick proto tcp from any to 33.33.33.33 port = 22 flags S keep state
+# firewall5:Policy:0: warning: Changing rule direction due to self reference
+pass in quick proto tcp from any to 33.33.33.34 port = 22 flags S keep state
+# firewall5:Policy:0: warning: Changing rule direction due to self reference
+pass in quick proto tcp from any to 192.168.1.1 port = 22 flags S keep state
+#
+# Rule 1 (global)
+pass in quick proto tcp from any to (ppp0) port = 22 flags S keep state
+pass out quick proto tcp from any to (ppp0) port = 22 flags S keep state
+#
+# Rule 2 (global)
+pass out quick proto tcp from any to 33.33.33.33 port = 22 flags S keep state
+pass out quick proto tcp from any to 33.33.33.34 port = 22 flags S keep state
+#
+# Rule 5 (global)
+block in log quick from any to any
+block out log quick from any to any
+#
+# Rule fallback rule
+# fallback rule
+block in quick from any to any
+block out quick from any to any
diff --git a/test/ipf/firewall5-nat.conf.orig b/test/ipf/firewall5-nat.conf.orig
new file mode 100755
index 000000000..72c13f049
--- /dev/null
+++ b/test/ipf/firewall5-nat.conf.orig
@@ -0,0 +1,51 @@
+#
+# Rule 0 (NAT)
+map ppp0 from 192.168.1.0/24 to any -> 0/32 portmap tcp/udp auto
+map ppp0 from 192.168.1.0/24 to any -> 0/32
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.33/32 portmap tcp/udp auto
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.33/32
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.34/32 portmap tcp/udp auto
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.34/32
+map eth0 from 192.168.1.0/24 to any -> 192.168.1.1/32 portmap tcp/udp auto
+map eth0 from 192.168.1.0/24 to any -> 192.168.1.1/32
+#
+# Rule 1 (NAT)
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.33/32 portmap tcp/udp auto
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.33/32
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.34/32 portmap tcp/udp auto
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.34/32
+#
+# Rule 2 (NAT)
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.33/32 portmap tcp/udp auto
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.33/32
+#
+# Rule 3 (NAT)
+rdr from any to (ppp0) port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 33.33.33.33/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 33.33.33.34/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 192.168.1.1/32 port = 22 -> 192.168.1.100 port 22 tcp
+#
+# Rule 4 (NAT)
+rdr from any to (ppp0) port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 33.33.33.33/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 33.33.33.34/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 192.168.1.1/32 port = 22 -> 192.168.1.100 port 22 tcp
+#
+# Rule 5 (NAT)
+rdr from any to (ppp0) port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 33.33.33.33/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 33.33.33.34/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 192.168.1.1/32 port = 22 -> 192.168.1.100 port 22 tcp
+#
+# Rule 6 (NAT)
+rdr from any to (ppp0) port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 33.33.33.33/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 33.33.33.34/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 192.168.1.1/32 port = 22 -> 192.168.1.100 port 22 tcp
+#
+# Rule 7 (NAT)
+rdr eth1 from any to 33.33.33.33/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr eth1 from any to 33.33.33.34/32 port = 22 -> 192.168.1.100 port 22 tcp
+#
+# Rule 8 (NAT)
+rdr eth1 from any to 33.33.33.34/32 port = 22 -> 192.168.1.100 port 22 tcp
diff --git a/test/ipf/firewall5.fw.orig b/test/ipf/firewall5.fw.orig
new file mode 100755
index 000000000..c67891e58
--- /dev/null
+++ b/test/ipf/firewall5.fw.orig
@@ -0,0 +1,113 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:52:49 2011 PST by vadim
+#
+# files: * firewall5.fw
+# files: firewall5-ipf.conf
+# files: firewall5-nat.conf
+#
+# Compiled for ipf
+#
+# Dynamic interface ppp0
+
+# firewall5:Policy:0: warning: Changing rule direction due to self reference
+
+FWDIR=`dirname $0`
+
+
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+getaddr() {
+ intf=$1
+ varname=$2
+ L=`ifconfig $1 | grep 'inet '`
+ if [ -z "$L" ]; then
+ L="inet 0.0.0.0/32"
+ fi
+ set $L
+ a=$2
+ eval "$varname=$a"
+}
+
+getaddr ppp0 i_ppp0
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:52:49 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$IPF -Fa
+$IPNAT -C
+
+cat ${FWDIR}/firewall5-ipf.conf | grep -v '#' | sed "s/ (ppp0) / $i_ppp0 /" | $IPF -I -f -
+cat ${FWDIR}/firewall5-nat.conf | grep -v '#' | sed "s/ (ppp0) / $i_ppp0 /" | $IPNAT -f -
+
+
+$IPF -s
+
+
+epilog_commands
+
+/sbin/kldstat -n ipl.ko > /dev/null 2>&1 || $IPF -E
\ No newline at end of file
diff --git a/test/ipf/firewall7-ipf.conf.orig b/test/ipf/firewall7-ipf.conf.orig
new file mode 100755
index 000000000..56f95a273
--- /dev/null
+++ b/test/ipf/firewall7-ipf.conf.orig
@@ -0,0 +1,18 @@
+#
+# Rule 0 (eth0)
+block in log quick on eth0 from any to 192.168.1.255
+#
+# Rule 1 (eth1)
+block in log quick on eth1 from any to 22.22.22.22
+block in log quick on eth1 from any to 22.22.23.23
+block in log quick on eth1 from any to 192.168.1.1
+block in log quick on eth1 from any to 192.168.2.1
+#
+# Rule 2 (global)
+pass in quick proto udp from any to 192.168.1.255 port = 68 keep state
+pass out quick proto udp from any to 192.168.1.255 port = 68 keep state
+#
+# Rule fallback rule
+# fallback rule
+block in quick from any to any
+block out quick from any to any
diff --git a/test/ipf/firewall7.fw.orig b/test/ipf/firewall7.fw.orig
new file mode 100755
index 000000000..2d447469f
--- /dev/null
+++ b/test/ipf/firewall7.fw.orig
@@ -0,0 +1,96 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:52:49 2011 PST by vadim
+#
+# files: * firewall7.fw
+# files: firewall7-ipf.conf
+#
+# Compiled for ipf
+#
+# testing rules with broadcasts
+
+
+
+FWDIR=`dirname $0`
+
+
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:52:49 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$IPF -Fa
+$IPNAT -C
+
+$IPF -I -f ${FWDIR}/firewall7-ipf.conf
+
+
+$IPF -s
+
+
+epilog_commands
+
+/sbin/kldstat -n ipl.ko > /dev/null 2>&1 || $IPF -E
\ No newline at end of file
diff --git a/test/ipf/firewall8-ipf.conf.orig b/test/ipf/firewall8-ipf.conf.orig
new file mode 100755
index 000000000..c75217482
--- /dev/null
+++ b/test/ipf/firewall8-ipf.conf.orig
@@ -0,0 +1,23 @@
+# Policy compiler errors and warnings:
+# firewall8:Policy:0: warning: Changing rule direction due to self reference
+#
+# Rule 0 (global)
+# firewall8:Policy:0: warning: Changing rule direction due to self reference
+pass in quick proto tcp from any to 33.33.33.33 port = 22 flags S keep state
+# firewall8:Policy:0: warning: Changing rule direction due to self reference
+pass in quick proto tcp from any to 33.33.33.34 port = 22 flags S keep state
+# firewall8:Policy:0: warning: Changing rule direction due to self reference
+pass in quick proto tcp from any to 192.168.1.1 port = 22 flags S keep state
+#
+# Rule 1 (global)
+pass out quick proto tcp from any to 33.33.33.33 port = 22 flags S keep state
+pass out quick proto tcp from any to 33.33.33.34 port = 22 flags S keep state
+#
+# Rule 4 (global)
+block in log quick from any to any
+block out log quick from any to any
+#
+# Rule fallback rule
+# fallback rule
+block in quick from any to any
+block out quick from any to any
diff --git a/test/ipf/firewall8-nat.conf.orig b/test/ipf/firewall8-nat.conf.orig
new file mode 100755
index 000000000..d4de2956f
--- /dev/null
+++ b/test/ipf/firewall8-nat.conf.orig
@@ -0,0 +1,51 @@
+#
+# Rule 0 (NAT)
+map ppp0 from 192.168.1.0/24 to any -> 0/32 portmap tcp/udp auto
+map ppp0 from 192.168.1.0/24 to any -> 0/32
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.33/32 portmap tcp/udp auto
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.33/32
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.34/32 portmap tcp/udp auto
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.34/32
+map eth0 from 192.168.1.0/24 to any -> 192.168.1.1/32 portmap tcp/udp auto
+map eth0 from 192.168.1.0/24 to any -> 192.168.1.1/32
+#
+# Rule 1 (NAT)
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.33/32 portmap tcp/udp auto
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.33/32
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.34/32 portmap tcp/udp auto
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.34/32
+#
+# Rule 2 (NAT)
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.33/32 portmap tcp/udp auto
+map eth1 from 192.168.1.0/24 to any -> 33.33.33.33/32
+#
+# Rule 3 (NAT)
+rdr from any to any port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 33.33.33.33/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 33.33.33.34/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 192.168.1.1/32 port = 22 -> 192.168.1.100 port 22 tcp
+#
+# Rule 4 (NAT)
+rdr from any to any port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 33.33.33.33/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 33.33.33.34/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 192.168.1.1/32 port = 22 -> 192.168.1.100 port 22 tcp
+#
+# Rule 5 (NAT)
+rdr from any to any port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 33.33.33.33/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 33.33.33.34/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 192.168.1.1/32 port = 22 -> 192.168.1.100 port 22 tcp
+#
+# Rule 6 (NAT)
+rdr from any to any port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 33.33.33.33/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 33.33.33.34/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 192.168.1.1/32 port = 22 -> 192.168.1.100 port 22 tcp
+#
+# Rule 7 (NAT)
+rdr eth1 from any to 33.33.33.33/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr eth1 from any to 33.33.33.34/32 port = 22 -> 192.168.1.100 port 22 tcp
+#
+# Rule 8 (NAT)
+rdr eth1 from any to 33.33.33.34/32 port = 22 -> 192.168.1.100 port 22 tcp
diff --git a/test/ipf/firewall8.fw.orig b/test/ipf/firewall8.fw.orig
new file mode 100755
index 000000000..c197a1bcd
--- /dev/null
+++ b/test/ipf/firewall8.fw.orig
@@ -0,0 +1,97 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:52:49 2011 PST by vadim
+#
+# files: * firewall8.fw
+# files: firewall8-ipf.conf
+# files: firewall8-nat.conf
+#
+# Compiled for ipf
+#
+
+# firewall8:Policy:0: warning: Changing rule direction due to self reference
+
+FWDIR=`dirname $0`
+
+
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:52:49 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$IPF -Fa
+$IPNAT -C
+
+$IPF -I -f ${FWDIR}/firewall8-ipf.conf
+$IPNAT -f ${FWDIR}/firewall8-nat.conf
+
+
+$IPF -s
+
+
+epilog_commands
+
+/sbin/kldstat -n ipl.ko > /dev/null 2>&1 || $IPF -E
\ No newline at end of file
diff --git a/test/ipf/firewall9-ipf.conf.orig b/test/ipf/firewall9-ipf.conf.orig
new file mode 100755
index 000000000..425048542
--- /dev/null
+++ b/test/ipf/firewall9-ipf.conf.orig
@@ -0,0 +1,55 @@
+# Policy compiler errors and warnings:
+# firewall9:Policy:5: warning: Changing rule direction due to self reference
+#
+# Rule 0 (le1)
+skip 1 in on le1 from 33.33.33.0/24 to any
+block in log quick on le1 from any to any
+#
+# Rule 1 (le1)
+pass in quick on le1 proto icmp from 33.33.33.0/24 to 192.168.1.10 icmp-type 11 code 0 keep state
+pass in quick on le1 proto icmp from 33.33.33.0/24 to 192.168.1.10 icmp-type 11 code 1 keep state
+pass in quick on le1 proto icmp from 33.33.33.0/24 to 192.168.1.10 icmp-type 0 code 0 keep state
+pass in quick on le1 proto icmp from 33.33.33.0/24 to 192.168.1.10 icmp-type 3 keep state
+pass in quick on le1 proto tcp from 33.33.33.0/24 to 192.168.1.10 port = 22 flags S keep state
+#
+# Rule 2 (le1)
+skip 6 in on le1 from 22.22.22.22 to any
+skip 5 in on le1 from 192.168.1.1 to any
+skip 4 in on le1 from 192.168.1.0/24 to any
+pass in quick on le1 proto icmp from any to any keep state
+pass in quick on le1 proto tcp from any to any flags S keep state
+pass in quick on le1 proto udp from any to any keep state
+pass in quick on le1 from any to any
+#
+# Rule 3 (global)
+count in from any to any
+count out from any to any
+#
+# Rule 4 (global)
+count in log from any to any
+count out log from any to any
+#
+# Rule 5 (global)
+# firewall9:Policy:5: warning: Changing rule direction due to self reference
+pass in quick proto tcp from any to 22.22.22.22 port = 22 flags S keep state
+# firewall9:Policy:5: warning: Changing rule direction due to self reference
+pass in quick proto tcp from any to 192.168.1.1 port = 22 flags S keep state
+#
+# Rule 6 (global)
+pass in quick proto icmp from 192.168.1.0/24 to any keep state
+pass in quick proto tcp from 192.168.1.0/24 to any flags S keep state
+pass in quick proto udp from 192.168.1.0/24 to any keep state
+pass in quick from 192.168.1.0/24 to any
+pass out quick proto icmp from 192.168.1.0/24 to any keep state
+pass out quick proto tcp from 192.168.1.0/24 to any flags S keep state
+pass out quick proto udp from 192.168.1.0/24 to any keep state
+pass out quick from 192.168.1.0/24 to any
+#
+# Rule 7 (global)
+block in log quick from any to any
+block out log quick from any to any
+#
+# Rule fallback rule
+# fallback rule
+block in quick from any to any
+block out quick from any to any
diff --git a/test/ipf/firewall9-nat.conf.orig b/test/ipf/firewall9-nat.conf.orig
new file mode 100755
index 000000000..953be51c7
--- /dev/null
+++ b/test/ipf/firewall9-nat.conf.orig
@@ -0,0 +1,39 @@
+#
+# Rule 0 (NAT)
+map le1 from 192.168.1.0/24 to any -> 22.22.22.22/32 portmap tcp/udp auto
+map le1 from 192.168.1.0/24 to any -> 22.22.22.22/32
+map le0 from 192.168.1.0/24 to any -> 192.168.1.1/32 portmap tcp/udp auto
+map le0 from 192.168.1.0/24 to any -> 192.168.1.1/32
+#
+# Rule 1 (NAT)
+map le1 from 192.168.1.0/24 to any -> 22.22.22.22/32 portmap tcp/udp auto
+map le1 from 192.168.1.0/24 to any -> 22.22.22.22/32
+#
+# Rule 2 (NAT)
+map le0 from 192.168.1.0/24 to any -> 0/0
+#
+# Rule 3 (NAT)
+rdr from any to 22.22.22.22/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 192.168.1.1/32 port = 22 -> 192.168.1.100 port 22 tcp
+#
+# Rule 4 (NAT)
+rdr from any to 22.22.22.22/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 192.168.1.1/32 port = 22 -> 192.168.1.100 port 22 tcp
+#
+# Rule 5 (NAT)
+rdr from any to 22.22.22.22/32 port = 22 -> 192.168.1.1 port 22 tcp
+rdr from any to 192.168.1.1/32 port = 22 -> 192.168.1.1 port 22 tcp
+#
+# Rule 6 (NAT)
+rdr from any to 22.22.22.22/32 port = 22 -> 192.168.1.100 port 22 tcp
+rdr from any to 192.168.1.1/32 port = 22 -> 192.168.1.100 port 22 tcp
+#
+# Rule 7 (NAT)
+rdr le1 from any to 22.22.22.22/32 port = 22 -> 192.168.1.100 port 22 tcp
+#
+# Rule 8 (NAT)
+rdr le1 from any to 22.22.22.22/32 port = 22 -> 192.168.1.1 port 22 tcp
+#
+# Rule 9 (NAT)
+rdr le0 from any to any port = 22 -> 192.168.1.100 port 22 tcp
+rdr le1 from any to any port = 22 -> 192.168.1.100 port 22 tcp
diff --git a/test/ipf/firewall9.fw.orig b/test/ipf/firewall9.fw.orig
new file mode 100755
index 000000000..e8c199287
--- /dev/null
+++ b/test/ipf/firewall9.fw.orig
@@ -0,0 +1,97 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:52:50 2011 PST by vadim
+#
+# files: * firewall9.fw
+# files: firewall9-ipf.conf
+# files: firewall9-nat.conf
+#
+# Compiled for ipf
+#
+
+# firewall9:Policy:5: warning: Changing rule direction due to self reference
+
+FWDIR=`dirname $0`
+
+
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:52:50 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$IPF -Fa
+$IPNAT -C
+
+$IPF -I -f ${FWDIR}/firewall9-ipf.conf
+$IPNAT -f ${FWDIR}/firewall9-nat.conf
+
+
+$IPF -s
+
+
+epilog_commands
+
+/sbin/kldstat -n ipl.ko > /dev/null 2>&1 || $IPF -E
\ No newline at end of file
diff --git a/test/ipf/host-ipf.conf.orig b/test/ipf/host-ipf.conf.orig
new file mode 100755
index 000000000..7f96b6fd2
--- /dev/null
+++ b/test/ipf/host-ipf.conf.orig
@@ -0,0 +1,110 @@
+# Policy compiler errors and warnings:
+# host:Policy:4: warning: Changing rule direction due to self reference
+# host:Policy:5: warning: Changing rule direction due to self reference
+# host:Policy:6: warning: Changing rule direction due to self reference
+#
+# Rule 0 (eth0)
+pass in log quick on eth0 proto icmp from 22.22.22.22 to 22.22.22.22 keep state
+pass in log quick on eth0 proto tcp from 22.22.22.22 to 22.22.22.22 keep state
+pass in log quick on eth0 proto udp from 22.22.22.22 to 22.22.22.22 keep state
+pass in log quick on eth0 from 22.22.22.22 to 22.22.22.22
+pass out log quick on eth0 proto icmp from 22.22.22.22 to 22.22.22.22 keep state
+pass out log quick on eth0 proto tcp from 22.22.22.22 to 22.22.22.22 keep state
+pass out log quick on eth0 proto udp from 22.22.22.22 to 22.22.22.22 keep state
+pass out log quick on eth0 from 22.22.22.22 to 22.22.22.22
+#
+# Rule 1 (lo)
+# allow everything on loopback
+pass in quick on lo proto icmp from any to 22.22.22.22 keep state
+pass in quick on lo proto icmp from any to 127.0.0.1 keep state
+pass in quick on lo proto tcp from any to 22.22.22.22 keep state
+pass in quick on lo proto tcp from any to 127.0.0.1 keep state
+pass in quick on lo proto udp from any to 22.22.22.22 keep state
+pass in quick on lo proto udp from any to 127.0.0.1 keep state
+pass in quick on lo from any to 22.22.22.22
+pass in quick on lo from any to 127.0.0.1
+#
+# Rule 2 (lo)
+# allow everything on loopback
+pass out quick on lo proto icmp from 22.22.22.22 to any keep state
+pass out quick on lo proto icmp from 127.0.0.1 to any keep state
+pass out quick on lo proto tcp from 22.22.22.22 to any keep state
+pass out quick on lo proto tcp from 127.0.0.1 to any keep state
+pass out quick on lo proto udp from 22.22.22.22 to any keep state
+pass out quick on lo proto udp from 127.0.0.1 to any keep state
+pass out quick on lo from 22.22.22.22 to any
+pass out quick on lo from 127.0.0.1 to any
+#
+# Rule 3 (lo)
+pass in log quick on lo proto icmp from 22.22.22.22 to 22.22.22.22 keep state
+pass in log quick on lo proto icmp from 22.22.22.22 to 127.0.0.1 keep state
+pass in log quick on lo proto icmp from 127.0.0.1 to 22.22.22.22 keep state
+pass in log quick on lo proto icmp from 127.0.0.1 to 127.0.0.1 keep state
+pass in log quick on lo proto tcp from 22.22.22.22 to 22.22.22.22 keep state
+pass in log quick on lo proto tcp from 22.22.22.22 to 127.0.0.1 keep state
+pass in log quick on lo proto tcp from 127.0.0.1 to 22.22.22.22 keep state
+pass in log quick on lo proto tcp from 127.0.0.1 to 127.0.0.1 keep state
+pass in log quick on lo proto udp from 22.22.22.22 to 22.22.22.22 keep state
+pass in log quick on lo proto udp from 22.22.22.22 to 127.0.0.1 keep state
+pass in log quick on lo proto udp from 127.0.0.1 to 22.22.22.22 keep state
+pass in log quick on lo proto udp from 127.0.0.1 to 127.0.0.1 keep state
+pass in log quick on lo from 22.22.22.22 to 22.22.22.22
+pass in log quick on lo from 22.22.22.22 to 127.0.0.1
+pass in log quick on lo from 127.0.0.1 to 22.22.22.22
+pass in log quick on lo from 127.0.0.1 to 127.0.0.1
+pass out log quick on lo proto icmp from 22.22.22.22 to 22.22.22.22 keep state
+pass out log quick on lo proto icmp from 22.22.22.22 to 127.0.0.1 keep state
+pass out log quick on lo proto icmp from 127.0.0.1 to 22.22.22.22 keep state
+pass out log quick on lo proto icmp from 127.0.0.1 to 127.0.0.1 keep state
+pass out log quick on lo proto tcp from 22.22.22.22 to 22.22.22.22 keep state
+pass out log quick on lo proto tcp from 22.22.22.22 to 127.0.0.1 keep state
+pass out log quick on lo proto tcp from 127.0.0.1 to 22.22.22.22 keep state
+pass out log quick on lo proto tcp from 127.0.0.1 to 127.0.0.1 keep state
+pass out log quick on lo proto udp from 22.22.22.22 to 22.22.22.22 keep state
+pass out log quick on lo proto udp from 22.22.22.22 to 127.0.0.1 keep state
+pass out log quick on lo proto udp from 127.0.0.1 to 22.22.22.22 keep state
+pass out log quick on lo proto udp from 127.0.0.1 to 127.0.0.1 keep state
+pass out log quick on lo from 22.22.22.22 to 22.22.22.22
+pass out log quick on lo from 22.22.22.22 to 127.0.0.1
+pass out log quick on lo from 127.0.0.1 to 22.22.22.22
+pass out log quick on lo from 127.0.0.1 to 127.0.0.1
+#
+# Rule 4 (global)
+# block fragments
+# host:Policy:4: warning: Changing rule direction due to self reference
+block in log quick from any to 22.22.22.22 with short
+#
+# Rule 5 (global)
+# host:Policy:5: warning: Changing rule direction due to self reference
+pass in quick proto icmp from any to 22.22.22.22 icmp-type 3 keep state
+# host:Policy:5: warning: Changing rule direction due to self reference
+pass in quick proto tcp from any to 22.22.22.22 port = 25 keep state
+# host:Policy:5: warning: Changing rule direction due to self reference
+pass in quick proto tcp from any to 22.22.22.22 port = 80 keep state
+# host:Policy:5: warning: Changing rule direction due to self reference
+pass in quick proto tcp from any to 22.22.22.22 port = 22 keep state
+# host:Policy:5: warning: Changing rule direction due to self reference
+pass in quick proto tcp from any to 22.22.22.22 port = 21 keep state
+# host:Policy:5: warning: Changing rule direction due to self reference
+pass in quick proto tcp from any to 22.22.22.22 port = 23 keep state
+#
+# Rule 6 (global)
+# allow all outgoing connections
+# host:Policy:6: warning: Changing rule direction due to self reference
+pass out quick proto icmp from 22.22.22.22 to any keep state
+# host:Policy:6: warning: Changing rule direction due to self reference
+pass out quick proto tcp from 22.22.22.22 to any keep state
+# host:Policy:6: warning: Changing rule direction due to self reference
+pass out quick proto udp from 22.22.22.22 to any keep state
+# host:Policy:6: warning: Changing rule direction due to self reference
+pass out quick from 22.22.22.22 to any
+#
+# Rule 7 (global)
+# 'catch all' rule
+block in log quick from any to any
+block out log quick from any to any
+#
+# Rule fallback rule
+# fallback rule
+block in quick from any to any
+block out quick from any to any
diff --git a/test/ipf/host.fw.orig b/test/ipf/host.fw.orig
new file mode 100755
index 000000000..b89d7e126
--- /dev/null
+++ b/test/ipf/host.fw.orig
@@ -0,0 +1,98 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:52:50 2011 PST by vadim
+#
+# files: * host.fw
+# files: host-ipf.conf
+#
+# Compiled for ipf
+#
+# firewall protects host it is running on
+
+# host:Policy:4: warning: Changing rule direction due to self reference
+# host:Policy:5: warning: Changing rule direction due to self reference
+# host:Policy:6: warning: Changing rule direction due to self reference
+
+FWDIR=`dirname $0`
+
+
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:52:50 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$IPF -Fa
+$IPNAT -C
+
+$IPF -I -f ${FWDIR}/host-ipf.conf
+
+
+$IPF -s
+
+
+epilog_commands
+
+/sbin/kldstat -n ipl.ko > /dev/null 2>&1 || $IPF -E
\ No newline at end of file
diff --git a/test/ipfw/firewall.fw.orig b/test/ipfw/firewall.fw.orig
new file mode 100755
index 000000000..9d81fa525
--- /dev/null
+++ b/test/ipfw/firewall.fw.orig
@@ -0,0 +1,198 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipfw v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:04 2011 PST by vadim
+#
+# files: * firewall.fw ipfw.fw
+#
+#
+#
+# Compiled for ipfw
+#
+# this is simple firewall with two interfaces. Test regular policy rules, including IP_fragments rule
+
+# firewall:Policy:3: warning: Changing rule direction due to self reference
+# firewall:Policy:9: warning: Changing rule direction due to self reference
+# firewall:Policy:20: warning: Changing rule direction due to self reference
+# firewall:Policy:6: warning: ipfw can not match "any IP option"
+# firewall:Policy:8: warning: ipfw can not match "any IP option"
+
+set -x
+
+cd /etc/fw || exit 1
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/usr/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:53:04 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+"$IPFW" set disable 1
+"$IPFW" add 1 set 1 check-state ip from any to any
+
+
+
+
+# ================ IPv4
+
+
+# ================ Rule set Policy
+#
+# Rule backup ssh access rule
+# backup ssh access rule
+"$IPFW" add 9 set 1 permit tcp from me to 192.168.1.100 out established keep-state
+"$IPFW" add 10 set 1 permit tcp from 192.168.1.100 to me 22 in setup keep-state || exit 1
+#
+# Rule 0 (eth1)
+"$IPFW" add 20 set 1 drop log all from any to me frag in recv eth1 || exit 1
+#
+# Rule 1 (eth1)
+# Automatically generated rule blocking short fragments
+"$IPFW" add 30 set 1 drop log all from any to any frag in recv eth1 || exit 1
+#
+# Rule 2 (eth1)
+# Automatically generated anti-spoofing rule
+"$IPFW" add 40 set 1 drop log all from me to any in recv eth1 || exit 1
+"$IPFW" add 50 set 1 drop log all from 192.168.1.0/24 to any in recv eth1 || exit 1
+#
+# Rule 3 (eth0)
+# комментарий по-русски
+# firewall:Policy:3: warning: Changing rule direction due to self reference
+"$IPFW" add 60 set 1 permit udp from 192.168.1.0/24 to me 53 in recv eth0 keep-state || exit 1
+#
+# Rule 4 (eth0)
+"$IPFW" add 70 set 1 drop log udp from any to 192.168.1.255 53 in recv eth0 || exit 1
+#
+# Rule 5 (global)
+"$IPFW" add 80 set 1 drop log tcp from any to any tcpflags !fin,syn,!rst,!psh,!ack,!urg || exit 1
+"$IPFW" add 90 set 1 drop log tcp from any to any tcpflags fin,syn,rst,!psh,ack,!urg || exit 1
+#
+# Rule 6 (global)
+"$IPFW" add 100 set 1 unreach port log all from any to any || exit 1
+#
+# Rule 7 (global)
+"$IPFW" add 110 set 1 unreach port log all from any to any ipoptions rr || exit 1
+#
+# Rule 8 (global)
+"$IPFW" add 120 set 1 unreach port log all from any to any ipoptions rr || exit 1
+"$IPFW" add 130 set 1 unreach port log all from any to any ipoptions lsrr,ssrr || exit 1
+"$IPFW" add 140 set 1 unreach port log all from any to any ipoptions ts || exit 1
+"$IPFW" add 150 set 1 unreach port log all from any to any || exit 1
+"$IPFW" add 160 set 1 unreach port log all from any to any || exit 1
+#
+# Rule 9 (global)
+# firewall:Policy:9: warning: Changing rule direction due to self reference
+"$IPFW" add 170 set 1 unreach port 50 from any to me in || exit 1
+#
+# Rule 12 (global)
+"$IPFW" add 180 set 1 permit tcp from 211.11.11.11 to 192.168.1.10 53 setup keep-state || exit 1
+"$IPFW" add 190 set 1 permit tcp from 211.22.22.22 to 192.168.1.10 53 setup keep-state || exit 1
+#
+# Rule 13 (global)
+"$IPFW" add 200 set 1 permit tcp from any to 192.168.1.10 10000-11000,6667,3128,113,53,21,80,119,25,22,23,540,70,13,2105,443,143,993,6667,543,544,389,98,3306,2049,110,5432,515,26000,512,513,514,4321,465,1080,111,7100 setup keep-state || exit 1
+#
+# Rule 14 (global)
+"$IPFW" add 210 set 1 permit tcp from any to 192.168.1.11 113,80,25,22,540,443,143,3128 setup keep-state || exit 1
+#
+# Rule 15 (global)
+"$IPFW" add 220 set 1 permit tcp from any to 192.168.1.11 113,80,25,22,540,443,143,3128 setup keep-state || exit 1
+"$IPFW" add 230 set 1 permit tcp from any to 192.168.1.12/30 113,80,25,22,540,443,143,3128 setup keep-state || exit 1
+#
+# Rule 16 (global)
+"$IPFW" add 240 set 1 permit tcp from any to 192.168.1.11 113,80,25,22,540,443,143,3128 setup keep-state || exit 1
+"$IPFW" add 250 set 1 permit tcp from any to 192.168.1.12 113,80,25,22,540,443,143,3128 setup keep-state || exit 1
+"$IPFW" add 260 set 1 permit tcp from any to 192.168.1.13 113,80,25,22,540,443,143,3128 setup keep-state || exit 1
+"$IPFW" add 270 set 1 permit tcp from any to 192.168.1.14 113,80,25,22,540,443,143,3128 setup keep-state || exit 1
+"$IPFW" add 280 set 1 permit tcp from any to 192.168.1.15 113,80,25,22,540,443,143,3128 setup keep-state || exit 1
+#
+# Rule 17 (global)
+"$IPFW" add 290 set 1 permit icmp from any to 192.168.1.0/24 icmptypes 11,11,0,3 keep-state || exit 1
+"$IPFW" add 300 set 1 permit tcp from any to 192.168.1.0/24 3128 setup keep-state || exit 1
+#
+# Rule 18 (global)
+"$IPFW" add 310 set 1 permit icmp from any to 192.168.1.0/24 icmptypes 11,11,0,3 keep-state || exit 1
+"$IPFW" add 320 set 1 permit tcp from any 20 to 192.168.1.0/24 1024-65535 setup keep-state || exit 1
+"$IPFW" add 330 set 1 permit tcp from any to 192.168.1.0/24 10000-11000 setup keep-state || exit 1
+"$IPFW" add 340 set 1 permit tcp from any to 192.168.1.0/24 6000-6063,3128,6667,113,53,21,80,119,25,22,23,540,70,13,2105,443,143,993,6667,543,544,389,98,3306,2049,110,5432,515,26000,512,513,514,4321,465,1080,111,7100 setup keep-state || exit 1
+#
+# Rule 19 (global)
+"$IPFW" add 350 set 1 permit log all from me to me keep-state || exit 1
+#
+# Rule 20 (global)
+# Automatically generated 'masquerading' rule
+# firewall:Policy:20: warning: Changing rule direction due to self reference
+"$IPFW" add 360 set 1 permit all from me to any out keep-state || exit 1
+"$IPFW" add 370 set 1 permit all from 192.168.1.0/24 to any keep-state || exit 1
+#
+# Rule 21 (global)
+# Automatically generated 'catch all' rule
+"$IPFW" add 380 set 1 drop log all from any to any || exit 1
+#
+# Rule fallback rule
+# fallback rule
+"$IPFW" add 390 set 1 drop all from any to any || exit 1
+
+epilog_commands
+
+"$IPFW" set swap 0 1 || exit 1
+"$IPFW" delete set 1
\ No newline at end of file
diff --git a/test/ipfw/firewall1.fw.orig b/test/ipfw/firewall1.fw.orig
new file mode 100755
index 000000000..b6290238d
--- /dev/null
+++ b/test/ipfw/firewall1.fw.orig
@@ -0,0 +1,218 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipfw v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:05 2011 PST by vadim
+#
+# files: * firewall1.fw
+#
+#
+#
+# Compiled for ipfw
+#
+# this object is used to test all kinds of negation in policy rules
+
+# Currently negation in NAT is not supported for ipf, therefore all rules in NAT with
+# negation are disabled
+
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+# firewall1:Policy:10: warning: Changing rule direction due to self reference
+# firewall1:Policy:13: warning: Changing rule direction due to self reference
+
+
+
+cd /etc || exit 1
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/Library/Application Support/PeerGuardian/ipfwFast"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:53:05 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+"$IPFW" set disable 1
+"$IPFW" add 1 set 1 check-state ip from any to any
+
+
+
+
+# ================ IPv4
+
+
+# ================ Rule set Policy
+#
+# Rule 0 (eth0)
+"$IPFW" add 10 set 1 skipto 130 icmp from 22.22.22.22 to 22.22.22.22 via eth0 || exit 1
+"$IPFW" add 20 set 1 skipto 130 icmp from 22.22.22.22 to 192.168.1.1 via eth0 || exit 1
+"$IPFW" add 30 set 1 skipto 130 icmp from 192.168.1.1 to 22.22.22.22 via eth0 || exit 1
+"$IPFW" add 40 set 1 skipto 130 icmp from 192.168.1.1 to 192.168.1.1 via eth0 || exit 1
+"$IPFW" add 50 set 1 skipto 130 50 from 22.22.22.22 to 22.22.22.22 via eth0 || exit 1
+"$IPFW" add 60 set 1 skipto 130 50 from 22.22.22.22 to 192.168.1.1 via eth0 || exit 1
+"$IPFW" add 70 set 1 skipto 130 50 from 192.168.1.1 to 22.22.22.22 via eth0 || exit 1
+"$IPFW" add 80 set 1 skipto 130 50 from 192.168.1.1 to 192.168.1.1 via eth0 || exit 1
+"$IPFW" add 90 set 1 drop log icmp from 22.22.22.22 to any via eth0 || exit 1
+"$IPFW" add 100 set 1 drop log icmp from 192.168.1.1 to any via eth0 || exit 1
+"$IPFW" add 110 set 1 drop log 50 from 22.22.22.22 to any via eth0 || exit 1
+"$IPFW" add 120 set 1 drop log 50 from 192.168.1.1 to any via eth0 || exit 1
+#
+# Rule 1 (eth0)
+"$IPFW" add 130 set 1 skipto 250 icmp from 192.168.1.10 to 192.168.1.10 via eth0 || exit 1
+"$IPFW" add 140 set 1 skipto 250 icmp from 192.168.1.10 to 192.168.1.20 via eth0 || exit 1
+"$IPFW" add 150 set 1 skipto 250 icmp from 192.168.1.20 to 192.168.1.10 via eth0 || exit 1
+"$IPFW" add 160 set 1 skipto 250 icmp from 192.168.1.20 to 192.168.1.20 via eth0 || exit 1
+"$IPFW" add 170 set 1 skipto 250 50 from 192.168.1.10 to 192.168.1.10 via eth0 || exit 1
+"$IPFW" add 180 set 1 skipto 250 50 from 192.168.1.10 to 192.168.1.20 via eth0 || exit 1
+"$IPFW" add 190 set 1 skipto 250 50 from 192.168.1.20 to 192.168.1.10 via eth0 || exit 1
+"$IPFW" add 200 set 1 skipto 250 50 from 192.168.1.20 to 192.168.1.20 via eth0 || exit 1
+"$IPFW" add 210 set 1 drop icmp from 192.168.1.10 to any via eth0 || exit 1
+"$IPFW" add 220 set 1 drop icmp from 192.168.1.20 to any via eth0 || exit 1
+"$IPFW" add 230 set 1 drop 50 from 192.168.1.10 to any via eth0 || exit 1
+"$IPFW" add 240 set 1 drop 50 from 192.168.1.20 to any via eth0 || exit 1
+#
+# Rule 2 (eth1)
+# Anti-spoofing rule
+"$IPFW" add 250 set 1 drop log all from me to any in recv eth1 || exit 1
+"$IPFW" add 260 set 1 drop log all from 192.168.1.0/24 to any in recv eth1 || exit 1
+#
+# Rule 3 (eth1)
+# Anti-spoofing rule
+"$IPFW" add 270 set 1 skipto 290 all from 192.168.1.0/24 to any out xmit eth1 || exit 1
+"$IPFW" add 280 set 1 drop log all from any to any out xmit eth1 || exit 1
+#
+# Rule 4 (lo)
+"$IPFW" add 290 set 1 permit all from any to any via lo keep-state || exit 1
+#
+# Rule 5 (global)
+"$IPFW" add 300 set 1 drop log tcp from any to any tcpflags !fin,syn,!rst,!psh,!ack,!urg || exit 1
+#
+# Rule 7 (global)
+# hostF has the same IP address as firewal.
+"$IPFW" add 310 set 1 permit log icmp from any to 192.168.1.1 icmptypes 8 keep-state || exit 1
+#
+# Rule 8 (global)
+# testing negation in the policy rule
+"$IPFW" add 320 set 1 skipto 350 icmp from 192.168.1.10 to any icmptypes 3 || exit 1
+"$IPFW" add 330 set 1 skipto 350 icmp from 192.168.1.20 to any icmptypes 3 || exit 1
+"$IPFW" add 340 set 1 drop log icmp from any to any icmptypes 3 || exit 1
+#
+# Rule 9 (global)
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+"$IPFW" add 350 set 1 skipto 380 icmp from 192.168.1.10 to me icmptypes 3 in || exit 1
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+"$IPFW" add 360 set 1 skipto 380 icmp from 192.168.1.20 to me icmptypes 3 in || exit 1
+# firewall1:Policy:9: warning: Changing rule direction due to self reference
+"$IPFW" add 370 set 1 drop log icmp from any to me icmptypes 3 in || exit 1
+#
+# Rule 10 (global)
+# firewall1:Policy:10: warning: Changing rule direction due to self reference
+"$IPFW" add 380 set 1 skipto 410 all from me to 192.168.1.0/24 out || exit 1
+"$IPFW" add 390 set 1 skipto 410 all from 192.168.2.0/24 to 192.168.1.0/24 || exit 1
+"$IPFW" add 400 set 1 drop log all from any to 192.168.1.0/24 || exit 1
+#
+# Rule 11 (global)
+"$IPFW" add 410 set 1 skipto 440 tcp from 22.22.22.0/24 to 192.168.1.10 80 || exit 1
+"$IPFW" add 420 set 1 skipto 440 tcp from 33.33.33.0/24 to 192.168.1.10 80 || exit 1
+"$IPFW" add 430 set 1 permit tcp from any to 192.168.1.10 80 setup keep-state || exit 1
+#
+# Rule 12 (global)
+"$IPFW" add 440 set 1 skipto 500 all from 192.168.1.0/24 to 192.168.1.10 || exit 1
+"$IPFW" add 450 set 1 skipto 500 all from 192.168.1.0/24 to 192.168.1.20 || exit 1
+"$IPFW" add 460 set 1 skipto 500 all from 192.168.2.0/24 to 192.168.1.10 || exit 1
+"$IPFW" add 470 set 1 skipto 500 all from 192.168.2.0/24 to 192.168.1.20 || exit 1
+"$IPFW" add 480 set 1 drop log all from 192.168.1.0/24 to any || exit 1
+"$IPFW" add 490 set 1 drop log all from 192.168.2.0/24 to any || exit 1
+#
+# Rule 13 (global)
+# firewall1:Policy:13: warning: Changing rule direction due to self reference
+"$IPFW" add 500 set 1 skipto 520 all from any to me in || exit 1
+"$IPFW" add 510 set 1 drop all from any to any || exit 1
+#
+# Rule 16 (global)
+"$IPFW" add 520 set 1 skipto 640 icmp from 22.22.22.22 to 22.22.22.22 || exit 1
+"$IPFW" add 530 set 1 skipto 640 icmp from 22.22.22.22 to 192.168.1.1 || exit 1
+"$IPFW" add 540 set 1 skipto 640 icmp from 192.168.1.1 to 22.22.22.22 || exit 1
+"$IPFW" add 550 set 1 skipto 640 icmp from 192.168.1.1 to 192.168.1.1 || exit 1
+"$IPFW" add 560 set 1 skipto 640 50 from 22.22.22.22 to 22.22.22.22 || exit 1
+"$IPFW" add 570 set 1 skipto 640 50 from 22.22.22.22 to 192.168.1.1 || exit 1
+"$IPFW" add 580 set 1 skipto 640 50 from 192.168.1.1 to 22.22.22.22 || exit 1
+"$IPFW" add 590 set 1 skipto 640 50 from 192.168.1.1 to 192.168.1.1 || exit 1
+"$IPFW" add 600 set 1 drop log icmp from 22.22.22.22 to any || exit 1
+"$IPFW" add 610 set 1 drop log icmp from 192.168.1.1 to any || exit 1
+"$IPFW" add 620 set 1 drop log 50 from 22.22.22.22 to any || exit 1
+"$IPFW" add 630 set 1 drop log 50 from 192.168.1.1 to any || exit 1
+#
+# Rule 17 (global)
+# 'masquerading' rule
+"$IPFW" add 640 set 1 permit all from 192.168.1.0/24 to any keep-state || exit 1
+#
+# Rule 18 (global)
+# 'catch all' rule
+"$IPFW" add 650 set 1 drop log all from any to any || exit 1
+#
+# Rule fallback rule
+# fallback rule
+"$IPFW" add 660 set 1 drop all from any to any || exit 1
+
+epilog_commands
+
+"$IPFW" set swap 0 1 || exit 1
+"$IPFW" delete set 1
\ No newline at end of file
diff --git a/test/ipfw/firewall2.fw.orig b/test/ipfw/firewall2.fw.orig
new file mode 100755
index 000000000..4e995f342
--- /dev/null
+++ b/test/ipfw/firewall2.fw.orig
@@ -0,0 +1,161 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipfw v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:05 2011 PST by vadim
+#
+# files: * firewall2.fw
+#
+#
+#
+# Compiled for ipfw
+#
+# this object has several interfaces and shows different rules for NAT. Also testing policy rule options
+
+# firewall2:Policy:12: warning: Changing rule direction due to self reference
+
+
+
+cd /etc || exit 1
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:53:05 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+"$IPFW" set disable 1
+"$IPFW" add 1 set 1 check-state ip from any to any
+
+
+
+
+# ================ IPv4
+
+
+# ================ Rule set Policy
+#
+# Rule 0 (eth1)
+"$IPFW" add 10 set 1 permit tcp from any to any established in recv eth1 keep-state || exit 1
+#
+# Rule 1 (eth1)
+"$IPFW" add 20 set 1 permit tcp from any to any established in recv eth1 || exit 1
+#
+# Rule 2 (eth1)
+"$IPFW" add 30 set 1 permit tcp from any 80 to any established in recv eth1 || exit 1
+#
+# Rule 3 (eth1)
+# Anti-spoofing rule
+"$IPFW" add 40 set 1 drop log all from me to any in recv eth1 || exit 1
+"$IPFW" add 50 set 1 drop log all from 192.168.1.0/24 to any in recv eth1 || exit 1
+#
+# Rule 4 (eth1)
+# Anti-spoofing rule
+"$IPFW" add 60 set 1 skipto 90 all from me to any out xmit eth1 || exit 1
+"$IPFW" add 70 set 1 skipto 90 all from 192.168.1.0/24 to any out xmit eth1 || exit 1
+"$IPFW" add 80 set 1 drop log all from any to any out xmit eth1 || exit 1
+#
+# Rule 5 (global)
+# block fragments
+"$IPFW" add 90 set 1 drop log all from any to any frag || exit 1
+#
+# Rule 6 (global)
+# sends TCP RST and makes custom record in the log
+"$IPFW" add 100 set 1 reset log tcp from any to any 113 || exit 1
+#
+# Rule 7 (global)
+# sends TCP RST and makes custom record in the log
+"$IPFW" add 110 set 1 unreach net log udp from any to any 161 || exit 1
+#
+# Rule 8 (global)
+"$IPFW" add 120 set 1 permit all from 192.168.1.10 to 200.200.200.200 keep-state || exit 1
+"$IPFW" add 130 set 1 permit all from 192.168.1.20 to 200.200.200.200 keep-state || exit 1
+#
+# Rule 9 (global)
+"$IPFW" add 140 set 1 permit all from 200.200.200.200 to 192.168.1.10 keep-state || exit 1
+"$IPFW" add 150 set 1 permit all from 200.200.200.200 to 192.168.1.20 keep-state || exit 1
+#
+# Rule 10 (global)
+# 'masquerading' rule
+"$IPFW" add 160 set 1 permit all from 192.168.1.0/24 to any keep-state || exit 1
+#
+# Rule 11 (global)
+# host-fw2 has the same address as
+# one of the firewall's interfaces
+"$IPFW" add 170 set 1 permit log tcp from any to 22.22.22.22 21 setup keep-state || exit 1
+#
+# Rule 12 (global)
+# firewall2:Policy:12: warning: Changing rule direction due to self reference
+"$IPFW" add 180 set 1 permit log tcp from any to me 21 in setup keep-state || exit 1
+#
+# Rule 13 (global)
+# 'catch all' rule
+"$IPFW" add 190 set 1 drop log all from any to any || exit 1
+#
+# Rule fallback rule
+# fallback rule
+"$IPFW" add 200 set 1 drop all from any to any || exit 1
+
+epilog_commands
+
+"$IPFW" set swap 0 1 || exit 1
+"$IPFW" delete set 1
\ No newline at end of file
diff --git a/test/ipfw/firewall33.fw.orig b/test/ipfw/firewall33.fw.orig
new file mode 100755
index 000000000..1aac4a4b6
--- /dev/null
+++ b/test/ipfw/firewall33.fw.orig
@@ -0,0 +1,261 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipfw v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:05 2011 PST by vadim
+#
+# files: * firewall33.fw
+#
+#
+#
+# Compiled for ipfw
+#
+# testing DNSName object
+
+# firewall33:Policy:2: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+# firewall33:Policy:6: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+
+
+
+cd /etc/fw || exit 1
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ update_addresses_of_interface "eth1 192.168.1.100/0xffffff00" ""
+ update_addresses_of_interface "lo 127.0.0.1/0xff000000" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:53:05 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+"$IPFW" set disable 1
+"$IPFW" add 1 set 1 check-state ip from any to any
+
+
+
+
+# ================ IPv4
+
+
+# ================ Rule set Policy
+#
+# Rule 0 (global)
+"$IPFW" add 10 set 1 permit all from 157.166.224.25 to any keep-state || exit 1
+"$IPFW" add 20 set 1 permit all from 157.166.224.26 to any keep-state || exit 1
+"$IPFW" add 30 set 1 permit all from 157.166.226.25 to any keep-state || exit 1
+"$IPFW" add 40 set 1 permit all from 157.166.226.26 to any keep-state || exit 1
+"$IPFW" add 50 set 1 permit all from 157.166.255.18 to any keep-state || exit 1
+"$IPFW" add 60 set 1 permit all from 157.166.255.19 to any keep-state || exit 1
+#
+# Rule 1 (global)
+"$IPFW" add 70 set 1 permit all from www.cnn.com to any keep-state || exit 1
+#
+# Rule 2 (global)
+# firewall33:Policy:2: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+"$IPFW" add 80 set 1 permit all from 192.0.2.1 to any keep-state || exit 1
+#
+# Rule 3 (global)
+"$IPFW" add 90 set 1 permit all from buildmaster to any keep-state || exit 1
+#
+# Rule 4 (global)
+"$IPFW" add 100 set 1 skipto 170 all from any to 157.166.224.25 || exit 1
+"$IPFW" add 110 set 1 skipto 170 all from any to 157.166.224.26 || exit 1
+"$IPFW" add 120 set 1 skipto 170 all from any to 157.166.226.25 || exit 1
+"$IPFW" add 130 set 1 skipto 170 all from any to 157.166.226.26 || exit 1
+"$IPFW" add 140 set 1 skipto 170 all from any to 157.166.255.18 || exit 1
+"$IPFW" add 150 set 1 skipto 170 all from any to 157.166.255.19 || exit 1
+"$IPFW" add 160 set 1 drop all from any to any || exit 1
+#
+# Rule 5 (global)
+"$IPFW" add 170 set 1 skipto 190 all from any to www.cnn.com || exit 1
+"$IPFW" add 180 set 1 drop all from any to any || exit 1
+#
+# Rule 6 (global)
+# firewall33:Policy:6: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+"$IPFW" add 190 set 1 skipto 210 all from any to 192.0.2.1 || exit 1
+"$IPFW" add 200 set 1 permit all from any to any keep-state || exit 1
+#
+# Rule 7 (global)
+"$IPFW" add 210 set 1 skipto 230 all from any to buildmaster || exit 1
+"$IPFW" add 220 set 1 permit all from any to any keep-state || exit 1
+#
+# Rule 8 (global)
+"$IPFW" add 230 set 1 skipto 340 all from any to 74.125.19.99 || exit 1
+"$IPFW" add 240 set 1 skipto 340 all from any to 74.125.19.103 || exit 1
+"$IPFW" add 250 set 1 skipto 340 all from any to 74.125.19.104 || exit 1
+"$IPFW" add 260 set 1 skipto 340 all from any to 74.125.19.147 || exit 1
+"$IPFW" add 270 set 1 skipto 340 all from any to 157.166.224.25 || exit 1
+"$IPFW" add 280 set 1 skipto 340 all from any to 157.166.224.26 || exit 1
+"$IPFW" add 290 set 1 skipto 340 all from any to 157.166.226.25 || exit 1
+"$IPFW" add 300 set 1 skipto 340 all from any to 157.166.226.26 || exit 1
+"$IPFW" add 310 set 1 skipto 340 all from any to 157.166.255.18 || exit 1
+"$IPFW" add 320 set 1 skipto 340 all from any to 157.166.255.19 || exit 1
+"$IPFW" add 330 set 1 permit all from any to any keep-state || exit 1
+#
+# Rule 9 (global)
+"$IPFW" add 340 set 1 skipto 370 all from any to www.google.com || exit 1
+"$IPFW" add 350 set 1 skipto 370 all from any to www.cnn.com || exit 1
+"$IPFW" add 360 set 1 permit all from any to any keep-state || exit 1
+#
+# Rule 10 (global)
+"$IPFW" add 370 set 1 skipto 450 all from any to www.google.com || exit 1
+"$IPFW" add 380 set 1 skipto 450 all from any to 157.166.224.25 || exit 1
+"$IPFW" add 390 set 1 skipto 450 all from any to 157.166.224.26 || exit 1
+"$IPFW" add 400 set 1 skipto 450 all from any to 157.166.226.25 || exit 1
+"$IPFW" add 410 set 1 skipto 450 all from any to 157.166.226.26 || exit 1
+"$IPFW" add 420 set 1 skipto 450 all from any to 157.166.255.18 || exit 1
+"$IPFW" add 430 set 1 skipto 450 all from any to 157.166.255.19 || exit 1
+"$IPFW" add 440 set 1 permit all from any to any keep-state || exit 1
+#
+# Rule 11 (global)
+"$IPFW" add 450 set 1 drop log all from any to any || exit 1
+#
+# Rule fallback rule
+# fallback rule
+"$IPFW" add 460 set 1 drop all from any to any || exit 1
+
+epilog_commands
+
+"$IPFW" set swap 0 1 || exit 1
+"$IPFW" delete set 1
\ No newline at end of file
diff --git a/test/ipfw/firewall34.fw.orig b/test/ipfw/firewall34.fw.orig
new file mode 100755
index 000000000..a3da00e44
--- /dev/null
+++ b/test/ipfw/firewall34.fw.orig
@@ -0,0 +1,126 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipfw v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:05 2011 PST by vadim
+#
+# files: * firewall34.fw
+#
+#
+#
+# Compiled for ipfw
+#
+# Testing actions Pipe, Classify, Custom
+
+
+
+
+
+cd /etc || exit 1
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:53:05 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+"$IPFW" set disable 1
+
+
+
+
+# ================ IPv4
+
+
+# ================ Rule set Policy
+#
+# Rule 0 (rl1)
+# port 8668 is natd
+"$IPFW" add 10 set 1 divert 8668 all from 192.168.1.0/24 to any via rl1 || exit 1
+#
+# Rule 1 (global)
+# rule doing divert to natd (8668) should go before check-state
+"$IPFW" add 20 set 1 check-state all from any to any || exit 1
+#
+# Rule 2 (global)
+"$IPFW" add 30 set 1 divert 1234 tcp from 192.168.1.0/24 to any 22 || exit 1
+#
+# Rule 3 (global)
+"$IPFW" add 40 set 1 queue 2 tcp from 192.168.1.0/24 to any 22 || exit 1
+#
+# Rule 4 (global)
+"$IPFW" add 50 set 1 pipe 1 tcp from 192.168.1.0/24 to any 80 || exit 1
+#
+# Rule 5 (global)
+"$IPFW" add 60 set 1 prob .80 log all from 192.168.1.0/24 to any || exit 1
+#
+# Rule 6 (global)
+"$IPFW" add 70 set 1 drop log all from any to any || exit 1
+#
+# Rule fallback rule
+# fallback rule
+"$IPFW" add 80 set 1 drop all from any to any || exit 1
+
+epilog_commands
+
+"$IPFW" set swap 0 1 || exit 1
+"$IPFW" delete set 1
\ No newline at end of file
diff --git a/test/ipfw/firewall4.fw.orig b/test/ipfw/firewall4.fw.orig
new file mode 100755
index 000000000..0699e099a
--- /dev/null
+++ b/test/ipfw/firewall4.fw.orig
@@ -0,0 +1,151 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipfw v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:06 2011 PST by vadim
+#
+# files: * firewall4.fw
+#
+#
+#
+# Compiled for ipfw
+#
+# this object is used to test a configuration where firewall has dynamic address
+
+# firewall4::: error: Dynamic interface eth1 should not have an IP address object attached to it. This IP address object will be ignored.
+
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+
+
+
+cd /etc || exit 1
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/usr/sbin/ipf"
+IPNAT="/usr/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:53:06 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+"$IPFW" set disable 1
+"$IPFW" add 1 set 1 check-state ip from any to any
+
+
+
+
+# ================ IPv4
+
+
+# ================ Rule set Policy
+#
+# Rule 0 (eth1)
+# Anti-spoofing rule
+"$IPFW" add 10 set 1 drop log all from me to any in recv eth1 || exit 1
+"$IPFW" add 20 set 1 drop log all from 192.168.1.0/24 to any in recv eth1 || exit 1
+#
+# Rule 1 (eth1)
+# Anti-spoofing rule
+"$IPFW" add 30 set 1 skipto 60 all from me to any out xmit eth1 || exit 1
+"$IPFW" add 40 set 1 skipto 60 all from 192.168.1.0/24 to any out xmit eth1 || exit 1
+"$IPFW" add 50 set 1 drop log all from any to any out xmit eth1 || exit 1
+#
+# Rule 2 (eth1)
+"$IPFW" add 60 set 1 drop log icmp from any to any icmptypes 8 via eth1 || exit 1
+#
+# Rule 3 (eth1)
+"$IPFW" add 70 set 1 skipto 90 icmp from 192.168.2.0/24 to any icmptypes 8 via eth1 || exit 1
+"$IPFW" add 80 set 1 drop log icmp from any to any icmptypes 8 via eth1 || exit 1
+#
+# Rule 4 (global)
+# hostF has the same IP address as firewal.
+"$IPFW" add 90 set 1 permit log icmp from any to 192.168.1.1 icmptypes 8 keep-state || exit 1
+#
+# Rule 5 (global)
+# testing negation in the policy rule
+"$IPFW" add 100 set 1 skipto 130 icmp from 192.168.1.10 to any icmptypes 3 || exit 1
+"$IPFW" add 110 set 1 skipto 130 icmp from 192.168.1.20 to any icmptypes 3 || exit 1
+"$IPFW" add 120 set 1 drop log icmp from any to any icmptypes 3 || exit 1
+#
+# Rule 6 (global)
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+"$IPFW" add 130 set 1 skipto 160 icmp from 192.168.1.10 to me icmptypes 3 in || exit 1
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+"$IPFW" add 140 set 1 skipto 160 icmp from 192.168.1.20 to me icmptypes 3 in || exit 1
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+"$IPFW" add 150 set 1 drop log icmp from any to me icmptypes 3 in || exit 1
+#
+# Rule 8 (global)
+# 'masquerading' rule
+"$IPFW" add 160 set 1 permit all from 192.168.1.0/24 to any keep-state || exit 1
+#
+# Rule 10 (global)
+# 'catch all' rule
+"$IPFW" add 170 set 1 drop log all from any to any || exit 1
+#
+# Rule fallback rule
+# fallback rule
+"$IPFW" add 180 set 1 drop all from any to any || exit 1
+
+epilog_commands
+
+"$IPFW" set swap 0 1 || exit 1
+"$IPFW" delete set 1
\ No newline at end of file
diff --git a/test/ipfw/firewall7.fw.orig b/test/ipfw/firewall7.fw.orig
new file mode 100755
index 000000000..c9eba8ea4
--- /dev/null
+++ b/test/ipfw/firewall7.fw.orig
@@ -0,0 +1,113 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipfw v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:06 2011 PST by vadim
+#
+# files: * firewall7.fw
+#
+#
+#
+# Compiled for ipfw
+#
+# testing rules with broadcasts
+
+
+
+
+
+cd /etc || exit 1
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:53:06 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+"$IPFW" set disable 1
+"$IPFW" add 1 set 1 check-state ip from any to any
+
+
+
+
+# ================ IPv4
+
+
+# ================ Rule set Policy
+#
+# Rule 0 (eth0)
+"$IPFW" add 10 set 1 drop log all from any to 192.168.1.255 in recv eth0 || exit 1
+#
+# Rule 1 (eth1)
+"$IPFW" add 20 set 1 drop log all from any to me in recv eth1 || exit 1
+#
+# Rule 2 (global)
+"$IPFW" add 30 set 1 permit udp from any to 192.168.1.255 68 keep-state || exit 1
+#
+# Rule fallback rule
+# fallback rule
+"$IPFW" add 40 set 1 drop all from any to any || exit 1
+
+epilog_commands
+
+"$IPFW" set swap 0 1 || exit 1
+"$IPFW" delete set 1
\ No newline at end of file
diff --git a/test/ipfw/firewall8.fw.orig b/test/ipfw/firewall8.fw.orig
new file mode 100755
index 000000000..dd28f3710
--- /dev/null
+++ b/test/ipfw/firewall8.fw.orig
@@ -0,0 +1,120 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipfw v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:06 2011 PST by vadim
+#
+# files: * firewall8.fw
+#
+#
+#
+# Compiled for ipfw
+#
+
+# firewall8:Policy:0: warning: Changing rule direction due to self reference
+
+
+
+cd /etc || exit 1
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:53:06 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+"$IPFW" set disable 1
+"$IPFW" add 1 set 1 check-state ip from any to any
+
+
+
+
+# ================ IPv4
+
+
+# ================ Rule set Policy
+#
+# Rule 0 (global)
+# firewall8:Policy:0: warning: Changing rule direction due to self reference
+"$IPFW" add 10 set 1 permit tcp from any to me 22 in setup keep-state || exit 1
+#
+# Rule 1 (global)
+"$IPFW" add 20 set 1 permit tcp from any to 33.33.33.33 22 setup keep-state || exit 1
+"$IPFW" add 30 set 1 permit tcp from any to 33.33.33.34 22 setup keep-state || exit 1
+#
+# Rule 2 (global)
+"$IPFW" add 40 set 1 permit tcp from any to 33.33.33.33 22 setup keep-state || exit 1
+#
+# Rule 3 (global)
+"$IPFW" add 50 set 1 permit tcp from any to 33.33.33.34 22 setup keep-state || exit 1
+#
+# Rule 4 (global)
+"$IPFW" add 60 set 1 drop log all from any to any || exit 1
+#
+# Rule fallback rule
+# fallback rule
+"$IPFW" add 70 set 1 drop all from any to any || exit 1
+
+epilog_commands
+
+"$IPFW" set swap 0 1 || exit 1
+"$IPFW" delete set 1
\ No newline at end of file
diff --git a/test/ipfw/firewall9.fw.orig b/test/ipfw/firewall9.fw.orig
new file mode 100755
index 000000000..622b8498b
--- /dev/null
+++ b/test/ipfw/firewall9.fw.orig
@@ -0,0 +1,135 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipfw v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:06 2011 PST by vadim
+#
+# files: * firewall9.fw
+#
+#
+#
+# Compiled for ipfw
+#
+
+# firewall9:Policy:5: warning: Changing rule direction due to self reference
+
+
+
+cd /etc || exit 1
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:53:06 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+"$IPFW" set disable 1
+"$IPFW" add 1 set 1 check-state ip from any to any
+
+
+
+
+# ================ IPv4
+
+
+# ================ Rule set Policy
+#
+# Rule 0 (firewall9:eth1)
+"$IPFW" add 10 set 1 skipto 30 all from 33.33.33.0/24 to any in recv firewall9:eth1 || exit 1
+"$IPFW" add 20 set 1 drop log all from any to any in recv firewall9:eth1 || exit 1
+#
+# Rule 1 (firewall9:eth1)
+"$IPFW" add 30 set 1 permit icmp from 33.33.33.0/24 to 192.168.1.10 icmptypes 11,11,0,3 in recv firewall9:eth1 keep-state || exit 1
+"$IPFW" add 40 set 1 permit tcp from 33.33.33.0/24 to 192.168.1.10 22 in recv firewall9:eth1 setup keep-state || exit 1
+#
+# Rule 2 (firewall9:eth1)
+"$IPFW" add 50 set 1 skipto 80 all from me to any in recv firewall9:eth1 || exit 1
+"$IPFW" add 60 set 1 skipto 80 all from 192.168.1.0/24 to any in recv firewall9:eth1 || exit 1
+"$IPFW" add 70 set 1 permit all from any to any in recv firewall9:eth1 keep-state || exit 1
+#
+# Rule 3 (global)
+"$IPFW" add 80 set 1 count all from any to any || exit 1
+#
+# Rule 4 (global)
+"$IPFW" add 90 set 1 count log all from any to any || exit 1
+#
+# Rule 5 (global)
+# firewall9:Policy:5: warning: Changing rule direction due to self reference
+"$IPFW" add 100 set 1 permit tcp from any to me 22 in setup keep-state || exit 1
+#
+# Rule 6 (global)
+"$IPFW" add 110 set 1 permit all from 192.168.1.0/24 to any keep-state || exit 1
+#
+# Rule 7 (global)
+"$IPFW" add 120 set 1 permit tcp from any to any established || exit 1
+#
+# Rule 8 (global)
+"$IPFW" add 130 set 1 drop log all from any to any || exit 1
+#
+# Rule fallback rule
+# fallback rule
+"$IPFW" add 140 set 1 drop all from any to any || exit 1
+
+epilog_commands
+
+"$IPFW" set swap 0 1 || exit 1
+"$IPFW" delete set 1
\ No newline at end of file
diff --git a/test/ipfw/host.fw.orig b/test/ipfw/host.fw.orig
new file mode 100755
index 000000000..ed3add1eb
--- /dev/null
+++ b/test/ipfw/host.fw.orig
@@ -0,0 +1,140 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipfw v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:07 2011 PST by vadim
+#
+# files: * host.fw
+#
+#
+#
+# Compiled for ipfw
+#
+# firewall protects host it is running on
+
+# host:Policy:4: warning: Changing rule direction due to self reference
+# host:Policy:5: warning: Changing rule direction due to self reference
+# host:Policy:6: warning: Changing rule direction due to self reference
+
+
+
+cd /etc || exit 1
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:53:07 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+"$IPFW" set disable 1
+"$IPFW" add 1 set 1 check-state ip from any to any
+
+
+
+
+# ================ IPv4
+
+
+# ================ Rule set Policy
+#
+# Rule 0 (eth0)
+"$IPFW" add 10 set 1 permit log all from me to me via eth0 keep-state || exit 1
+#
+# Rule 1 (lo)
+# allow everything on loopback
+"$IPFW" add 20 set 1 permit all from any to me in recv lo keep-state || exit 1
+#
+# Rule 2 (lo)
+# allow everything on loopback
+"$IPFW" add 30 set 1 permit all from me to any out xmit lo keep-state || exit 1
+#
+# Rule 3 (lo)
+"$IPFW" add 40 set 1 permit log all from me to me via lo keep-state || exit 1
+#
+# Rule 4 (global)
+# block fragments
+# host:Policy:4: warning: Changing rule direction due to self reference
+"$IPFW" add 50 set 1 drop log all from any to me frag in || exit 1
+#
+# Rule 5 (global)
+# host:Policy:5: warning: Changing rule direction due to self reference
+"$IPFW" add 60 set 1 permit icmp from any to me icmptypes 3 in keep-state || exit 1
+# host:Policy:5: warning: Changing rule direction due to self reference
+"$IPFW" add 70 set 1 permit tcp from any to me 25,80,22,21,23 in setup keep-state || exit 1
+#
+# Rule 6 (global)
+# allow all outgoing connections
+# host:Policy:6: warning: Changing rule direction due to self reference
+"$IPFW" add 80 set 1 permit all from me to any out keep-state || exit 1
+#
+# Rule 7 (global)
+# 'catch all' rule
+"$IPFW" add 90 set 1 drop log all from any to any || exit 1
+#
+# Rule fallback rule
+# fallback rule
+"$IPFW" add 100 set 1 drop all from any to any || exit 1
+
+epilog_commands
+
+"$IPFW" set swap 0 1 || exit 1
+"$IPFW" delete set 1
\ No newline at end of file
diff --git a/test/ipfw/mac.fw.orig b/test/ipfw/mac.fw.orig
new file mode 100755
index 000000000..adce9235f
--- /dev/null
+++ b/test/ipfw/mac.fw.orig
@@ -0,0 +1,134 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipfw v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:07 2011 PST by vadim
+#
+# files: * mac.fw
+#
+#
+#
+# Compiled for ipfw
+#
+
+# mac:Policy:1: warning: Changing rule direction due to self reference
+# mac:Policy:3: warning: Changing rule direction due to self reference
+# mac:Policy:4: warning: Changing rule direction due to self reference
+
+set -x
+
+cd /etc || exit 1
+
+IFCONFIG="/sbin/ifconfig"
+IPFW="/sbin/ipfw"
+SYSCTL="/usr/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+ $SYSCTL -w net.inet.ip.sourceroute=0
+ $SYSCTL -w net.inet.ip.redirect=0
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:53:07 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+"$IPFW" set disable 1
+"$IPFW" add 1 set 1 check-state ip from any to any
+
+
+
+
+# ================ IPv4
+
+
+# ================ Rule set Policy
+#
+# Rule 0 (lo0)
+"$IPFW" add 10 set 1 permit all from any to any via lo0 keep-state || exit 1
+#
+# Rule 1 (global)
+# mac:Policy:1: warning: Changing rule direction due to self reference
+"$IPFW" add 20 set 1 permit tcp from any to me established in keep-state || exit 1
+#
+# Rule 2 (global)
+"$IPFW" add 30 set 1 drop log all from any to any frag || exit 1
+"$IPFW" add 40 set 1 drop log tcp from any to any tcpflags fin,syn,!rst,psh,ack,urg || exit 1
+#
+# Rule 3 (global)
+# mac:Policy:3: warning: Changing rule direction due to self reference
+"$IPFW" add 50 set 1 permit icmp from any to me icmptypes 11,11,0,3 in keep-state || exit 1
+# mac:Policy:3: warning: Changing rule direction due to self reference
+"$IPFW" add 60 set 1 permit tcp from any to me 22,25 in setup keep-state || exit 1
+# mac:Policy:3: warning: Changing rule direction due to self reference
+"$IPFW" add 70 set 1 permit udp from any to me in keep-state || exit 1
+#
+# Rule 4 (global)
+# mac:Policy:4: warning: Changing rule direction due to self reference
+"$IPFW" add 80 set 1 permit icmp from me to any icmptypes 11,11,0,3 out keep-state || exit 1
+# mac:Policy:4: warning: Changing rule direction due to self reference
+"$IPFW" add 90 set 1 permit tcp from me to any out setup keep-state || exit 1
+# mac:Policy:4: warning: Changing rule direction due to self reference
+"$IPFW" add 100 set 1 permit udp from me to any 53,68,67 out keep-state || exit 1
+#
+# Rule 5 (global)
+"$IPFW" add 110 set 1 drop log all from any to any || exit 1
+#
+# Rule fallback rule
+# fallback rule
+"$IPFW" add 120 set 1 drop all from any to any || exit 1
+
+epilog_commands
+
+"$IPFW" set swap 0 1 || exit 1
+"$IPFW" delete set 1
\ No newline at end of file
diff --git a/test/ipt/cluster1_secuwall-1.fw.orig b/test/ipt/cluster1_secuwall-1.fw.orig
new file mode 100755
index 000000000..8cefa358f
--- /dev/null
+++ b/test/ipt/cluster1_secuwall-1.fw.orig
@@ -0,0 +1,647 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:13 2011 PST by vadim
+#
+# files: * cluster1_secuwall-1.fw
+#
+# Compiled for iptables (any version)
+#
+# This firewall has two interfaces. Eth0 faces outside and has a dynamic address; eth1 faces inside.
+# Policy includes basic rules to permit unrestricted outbound access and anti-spoofing rules. Access to the firewall is permitted only from internal network and only using SSH. The firewall uses one of the machines on internal network for DNS. Internal network is configured with address 192.168.1.0/255.255.255.0
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/bin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ echo "Modules are loaded only at startup!"
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo"
+ for i in eth0 eth1 lo ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ for runstop in keepalived conntrackd network ; do
+ /etc/init.d/${runstop} stop
+ done
+
+ /sbin/ifclear all
+
+ for runstart in management network keepalived conntrackd ; do
+ /etc/init.d/${runstart} start
+ done
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+
+
+
+
+ # client DNS for the firewall
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 172.24.0.1
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j REDIRECT --to-ports 3128
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule -8 VRRP (automatic)
+ #
+ echo "Rule -8 VRRP (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o lo -p vrrp -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -7 VRRP (automatic)
+ #
+ echo "Rule -7 VRRP (automatic)"
+ #
+ $IPTABLES -A INPUT -i lo -p vrrp -s 127.0.0.1 -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -6 VRRP (automatic)
+ #
+ echo "Rule -6 VRRP (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth1 -p vrrp -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -5 VRRP (automatic)
+ #
+ echo "Rule -5 VRRP (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p vrrp -s 192.168.1.3 -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -4 VRRP (automatic)
+ #
+ echo "Rule -4 VRRP (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p vrrp -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -3 VRRP (automatic)
+ #
+ echo "Rule -3 VRRP (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p vrrp -s 172.24.0.3 -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -2 CONNTRACK (automatic)
+ #
+ echo "Rule -2 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 225.0.0.50 --dport 3780 -j ACCEPT
+ #
+ # Rule -1 CONNTRACK (automatic)
+ #
+ echo "Rule -1 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 225.0.0.50 --dport 3780 -j ACCEPT
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ # anti spoofing rule
+ $IPTABLES -N In_RULE_0
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.2 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.2 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.2 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.2 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A In_RULE_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A In_RULE_0 -j DROP
+ #
+ # Rule 1 (lo)
+ #
+ echo "Rule 1 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (eth0)
+ #
+ echo "Rule 2 (eth0)"
+ #
+ $IPTABLES -A INPUT -i ! eth0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i ! eth0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o ! eth0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o ! eth0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (eth0)
+ #
+ echo "Rule 3 (eth0)"
+ #
+ # "firewall is part of any" OFF
+ $IPTABLES -A FORWARD -i ! eth0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o ! eth0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (eth0)
+ #
+ echo "Rule 4 (eth0)"
+ #
+ # "firewall is part of any" OFF
+ $IPTABLES -A FORWARD -i eth0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o eth0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (eth0,eth1)
+ #
+ echo "Rule 5 (eth0,eth1)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth1 -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -N Cid8117X67022.0
+ $IPTABLES -A OUTPUT -o eth0 -p tcp -m tcp --dport 22 -m state --state NEW -j Cid8117X67022.0
+ $IPTABLES -A Cid8117X67022.0 -d 172.24.0.1 -j ACCEPT
+ $IPTABLES -A Cid8117X67022.0 -d 172.24.0.2 -j ACCEPT
+ $IPTABLES -A Cid8117X67022.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid8117X67022.0 -d 192.168.1.2 -j ACCEPT
+ $IPTABLES -N Cid8117X67022.1
+ $IPTABLES -A OUTPUT -o eth1 -p tcp -m tcp --dport 22 -m state --state NEW -j Cid8117X67022.1
+ $IPTABLES -A Cid8117X67022.1 -d 172.24.0.1 -j ACCEPT
+ $IPTABLES -A Cid8117X67022.1 -d 172.24.0.2 -j ACCEPT
+ $IPTABLES -A Cid8117X67022.1 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid8117X67022.1 -d 192.168.1.2 -j ACCEPT
+ #
+ # Rule 6 (cl1 intf 0,1)
+ #
+ echo "Rule 6 (cl1 intf 0,1)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth1 -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -N Cid39519X67022.0
+ $IPTABLES -A OUTPUT -o eth0 -p tcp -m tcp --dport 22 -m state --state NEW -j Cid39519X67022.0
+ $IPTABLES -A Cid39519X67022.0 -d 172.24.0.1 -j ACCEPT
+ $IPTABLES -A Cid39519X67022.0 -d 172.24.0.2 -j ACCEPT
+ $IPTABLES -A Cid39519X67022.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid39519X67022.0 -d 192.168.1.2 -j ACCEPT
+ $IPTABLES -N Cid39519X67022.1
+ $IPTABLES -A OUTPUT -o eth1 -p tcp -m tcp --dport 22 -m state --state NEW -j Cid39519X67022.1
+ $IPTABLES -A Cid39519X67022.1 -d 172.24.0.1 -j ACCEPT
+ $IPTABLES -A Cid39519X67022.1 -d 172.24.0.2 -j ACCEPT
+ $IPTABLES -A Cid39519X67022.1 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid39519X67022.1 -d 192.168.1.2 -j ACCEPT
+ #
+ # Rule 7 (eth0,eth1)
+ #
+ echo "Rule 7 (eth0,eth1)"
+ #
+ # "firewall is part of any" OFF
+ $IPTABLES -A INPUT -i eth0 -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth1 -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 8 (cl1 intf 0,1)
+ #
+ echo "Rule 8 (cl1 intf 0,1)"
+ #
+ # "firewall is part of any" OFF
+ $IPTABLES -A INPUT -i eth0 -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth1 -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ # Firewall uses one of the machines
+ # on internal network for DNS
+ $IPTABLES -N RULE_10
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_10
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_10
+ $IPTABLES -A RULE_10 -j LOG --log-level info --log-prefix "RULE 10 -- ACCEPT "
+ $IPTABLES -A RULE_10 -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ # All other attempts to connect to
+ # the firewall are denied and logged
+ $IPTABLES -N RULE_11
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -m state --state NEW -j RULE_11
+ $IPTABLES -A OUTPUT -d 172.24.0.2 -m state --state NEW -j RULE_11
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -m state --state NEW -j RULE_11
+ $IPTABLES -A OUTPUT -d 192.168.1.2 -m state --state NEW -j RULE_11
+ $IPTABLES -A INPUT -m state --state NEW -j RULE_11
+ $IPTABLES -A RULE_11 -j LOG --log-level info --log-prefix "RULE 11 -- DENY "
+ $IPTABLES -A RULE_11 -j DROP
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ $IPTABLES -N RULE_13
+ $IPTABLES -A OUTPUT -m state --state NEW -j RULE_13
+ $IPTABLES -A INPUT -m state --state NEW -j RULE_13
+ $IPTABLES -A FORWARD -m state --state NEW -j RULE_13
+ $IPTABLES -A RULE_13 -j LOG --log-level info --log-prefix "RULE 13 -- DENY "
+ $IPTABLES -A RULE_13 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:13 2011 by vadim"
+ log "Database was cluster-tests.fwb"
+ check_tools
+ check_run_time_address_table_files
+
+ prolog_commands
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ *)
+ echo "Usage $0 {start|stop|status|block|reload|interfaces|test_interfaces}"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall-base-rulesets.fw.orig b/test/ipt/firewall-base-rulesets.fw.orig
new file mode 100755
index 000000000..2102929bd
--- /dev/null
+++ b/test/ipt/firewall-base-rulesets.fw.orig
@@ -0,0 +1,505 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:53 2011 PST by vadim
+#
+# files: * firewall-base-rulesets.fw
+#
+# Compiled for iptables (any version)
+#
+# this firewall is used to test a rule in the global policy of object "firewall"
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 33.33.33.33/24" ""
+ update_addresses_of_interface "eth1 172.16.1.1/24" ""
+ update_addresses_of_interface "eth2 192.168.100.1/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set web_server_inbound
+ #
+ # Rule web_server_inbound 0 (global)
+ #
+ echo "Rule web_server_inbound 0 (global)"
+ #
+ $IPTABLES -N web_server_inbound
+ $IPTABLES -A web_server_inbound -i + -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
+ #
+ # Rule web_server_inbound 1 (global)
+ #
+ echo "Rule web_server_inbound 1 (global)"
+ #
+ $IPTABLES -A web_server_inbound -i + -p icmp -m icmp --icmp-type 3 -m state --state NEW -j ACCEPT
+ $IPTABLES -A web_server_inbound -i + -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ #
+ # Rule web_server_inbound 2 (global)
+ #
+ echo "Rule web_server_inbound 2 (global)"
+ #
+ $IPTABLES -N web_server_inbound_2
+ $IPTABLES -A web_server_inbound -p tcp -m tcp --dport 3306 -j web_server_inbound_2
+ $IPTABLES -A web_server_inbound_2 -j LOG --log-level info --log-prefix "web_server_inbound/2 -- DENY"
+ $IPTABLES -A web_server_inbound_2 -j DROP
+ # ================ Table 'filter', rule set mail_server_inbound
+ #
+ # Rule mail_server_inbound 0 (global)
+ #
+ echo "Rule mail_server_inbound 0 (global)"
+ #
+ $IPTABLES -N mail_server_inbound
+ $IPTABLES -A mail_server_inbound -i + -p tcp -m tcp --dport 25 -m state --state NEW -j ACCEPT
+ #
+ # Rule mail_server_inbound 1 (global)
+ #
+ echo "Rule mail_server_inbound 1 (global)"
+ #
+ $IPTABLES -A mail_server_inbound -i + -p icmp -m icmp --icmp-type 3 -m state --state NEW -j ACCEPT
+ $IPTABLES -A mail_server_inbound -i + -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ # ================ Table 'filter', rule set mail_server_outbound
+ #
+ # Rule mail_server_outbound 0 (global)
+ #
+ echo "Rule mail_server_outbound 0 (global)"
+ #
+ $IPTABLES -N mail_server_outbound
+ $IPTABLES -A mail_server_outbound -o + -p tcp -m tcp -m multiport --dports 53,25 -m state --state NEW -j ACCEPT
+ $IPTABLES -A mail_server_outbound -o + -p udp -m udp --dport 53 -m state --state NEW -j ACCEPT
+ #
+ # Rule mail_server_outbound 1 (global)
+ #
+ echo "Rule mail_server_outbound 1 (global)"
+ #
+ $IPTABLES -A mail_server_outbound -o + -p icmp -m icmp --icmp-type 3 -m state --state NEW -j ACCEPT
+ $IPTABLES -A mail_server_outbound -o + -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ # ================ Table 'filter', rule set web_server_outbound
+ #
+ # Rule web_server_outbound 0 (global)
+ #
+ echo "Rule web_server_outbound 0 (global)"
+ #
+ $IPTABLES -N web_server_outbound
+ $IPTABLES -A web_server_outbound -o + -p icmp -m icmp --icmp-type 3 -m state --state NEW -j ACCEPT
+ $IPTABLES -A web_server_outbound -o + -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ #
+ # Rule web_server_outbound 1 (global)
+ #
+ echo "Rule web_server_outbound 1 (global)"
+ #
+ $IPTABLES -A web_server_outbound -o + -p tcp -m tcp --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A web_server_outbound -o + -p udp -m udp --dport 53 -m state --state NEW -j ACCEPT
+ # ================ Table 'filter', rule set base-ruleset
+ #
+ # Rule base-ruleset 0 (global)
+ #
+ echo "Rule base-ruleset 0 (global)"
+ #
+ $IPTABLES -N base-ruleset
+ $IPTABLES -N Cid41961X1271.0
+ $IPTABLES -A base-ruleset -p tcp -m tcp --dport 22 -m state --state NEW -j Cid41961X1271.0
+ $IPTABLES -A Cid41961X1271.0 -d 33.33.33.33 -j ACCEPT
+ $IPTABLES -A Cid41961X1271.0 -d 172.16.1.1 -j ACCEPT
+ $IPTABLES -A Cid41961X1271.0 -d 192.168.100.1 -j ACCEPT
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:53 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall-ipv6-1.fw.orig b/test/ipt/firewall-ipv6-1.fw.orig
new file mode 100755
index 000000000..5e627edfe
--- /dev/null
+++ b/test/ipt/firewall-ipv6-1.fw.orig
@@ -0,0 +1,747 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:59 2011 PST by vadim
+#
+# files: * firewall-ipv6-1.fw
+#
+# Compiled for iptables (any version)
+#
+# Using ULOG globally, but ipv6 rules
+# should fall back to LOG because
+# there is no ULOG for ip6tables yet
+# Bug 2141911
+
+# firewall-ipv6-1:Policy:4: error: Rule '4 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-1:Policy:4: error: Rule '4 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-1:Policy:13: error: Rule '13 (global)' shadows rule '15 (global)' below it
+# firewall-ipv6-1:Policy:14: error: Rule '14 (global)' shadows rule '16 (global)' below it
+# firewall-ipv6-1:Policy:14: error: Rule '14 (global)' shadows rule '17 (global)' below it
+# firewall-ipv6-1:Policy:13: error: Rule '13 (global)' shadows rule '17 (global)' below it
+# firewall-ipv6-1:Policy:21: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-1:Policy:21: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-1:Policy:21: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+
+# firewall-ipv6-1:Policy_ipv6:2: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-1:Policy_ipv6:6: error: Rule 'Policy_ipv6 6 (global)' shadows rule 'Policy_ipv6 7 (global)' below it
+# firewall-ipv6-1:Policy_ipv6:6: error: Rule 'Policy_ipv6 6 (global)' shadows rule 'Policy_ipv6 9 (global)' below it
+# firewall-ipv6-1:Policy_ipv6:6: error: Rule 'Policy_ipv6 6 (global)' shadows rule 'Policy_ipv6 10 (global)' below it
+# firewall-ipv6-1:Policy_ipv6:6: error: Rule 'Policy_ipv6 6 (global)' shadows rule 'Policy_ipv6 11 (global)' below it
+# firewall-ipv6-1:Policy_ipv6:6: error: Rule 'Policy_ipv6 6 (global)' shadows rule 'Policy_ipv6 12 (global)' below it
+# firewall-ipv6-1:Policy_ipv6:8: error: Rule 'Policy_ipv6 8 (global)' shadows rule 'Policy_ipv6 13 (global)' below it
+# firewall-ipv6-1:Policy_ipv6:0: error: Rule 'Policy_ipv6 0 (global)' shadows rule 'Policy_ipv6 14 (global)' below it
+# firewall-ipv6-1:Policy_ipv6:2: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-1:Policy_ipv6:2: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-1:Policy_ipv6:6: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-1:Policy_ipv6:6: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-1:Policy_ipv6:7: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-1:Policy_ipv6:8: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-1:Policy_ipv6:8: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-1:Policy_ipv6:8: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-1:Policy_ipv6:9: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-1:Policy_ipv6:10: warning: Making rule stateless because it matches ICMPv6
+
+# firewall-ipv6-1:Policy_ipv6:: warning: Backup ssh access rule could not be added to IPv6 policy because specified address '1.1.1.2' is invalid
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0"
+ for i in eth0 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 fe80::21d:9ff:fe8b:8e94/64 1.1.1.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # backup ssh access
+ $IPTABLES -A INPUT -p tcp -m tcp -s 1.1.1.2/255.255.255.255 --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 1.1.1.2/255.255.255.255 --sport 22 -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop packets that do not match any valid state and log them
+ $IPTABLES -N drop_invalid
+ $IPTABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IPTABLES -A drop_invalid -j ULOG --ulog-nlgroup 1 --ulog-qthreshold 1 --ulog-prefix "INVALID state -- DENY "
+ $IPTABLES -A drop_invalid -j DROP
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -N Cid4834D3108571.0
+ $IPTABLES -A INPUT -p tcp -m tcp -d 1.1.1.1 --dport 22 -m state --state NEW -j Cid4834D3108571.0
+ $IPTABLES -N RULE_4
+ $IPTABLES -A Cid4834D3108571.0 -s 61.150.47.112 -j RULE_4
+ $IPTABLES -A Cid4834D3108571.0 -s 192.168.1.0 -j RULE_4
+ $IPTABLES -A RULE_4 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 4 -- ACCEPT " --ulog-qthreshold 1
+ $IPTABLES -A RULE_4 -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -N Cid4835041F8571.0
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid4835041F8571.0
+ $IPTABLES -N RULE_6
+ $IPTABLES -A Cid4835041F8571.0 -s 61.150.47.112 -j RULE_6
+ $IPTABLES -A Cid4835041F8571.0 -s 192.168.1.0 -j RULE_6
+ $IPTABLES -A RULE_6 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 6 -- ACCEPT " --ulog-qthreshold 1
+ $IPTABLES -A RULE_6 -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -N In_RULE_7
+ $IPTABLES -A INPUT -m state --state NEW -j In_RULE_7
+ $IPTABLES -A In_RULE_7 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 7 -- ACCEPT " --ulog-qthreshold 1
+ $IPTABLES -A In_RULE_7 -j ACCEPT
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ $IPTABLES -N RULE_10
+ $IPTABLES -A INPUT -s 61.150.47.112 -m state --state NEW -j RULE_10
+ $IPTABLES -A INPUT -s 192.168.1.0 -m state --state NEW -j RULE_10
+ $IPTABLES -A FORWARD -s 61.150.47.112 -m state --state NEW -j RULE_10
+ $IPTABLES -A FORWARD -s 192.168.1.0 -m state --state NEW -j RULE_10
+ $IPTABLES -A RULE_10 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 10 -- ACCEPT " --ulog-qthreshold 1
+ $IPTABLES -A RULE_10 -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ $IPTABLES -A INPUT -p icmp -m icmp -s 1.1.1.1 --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p icmp -m icmp -s 1.1.1.1 --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ $IPTABLES -A OUTPUT -p icmp -m icmp --icmp-type any -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type any -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p icmp -m icmp --icmp-type any -m state --state NEW -j ACCEPT
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ $IPTABLES -A OUTPUT -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 17 (global)
+ #
+ echo "Rule 17 (global)"
+ #
+ $IPTABLES -A OUTPUT -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 18 (global)
+ #
+ echo "Rule 18 (global)"
+ #
+ # INPUT, OUTPUT, FORWARD
+ $IPTABLES -A INPUT -s 1.1.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 1.1.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 1.1.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ # INPUT, OUTPUT, FORWARD
+ $IPTABLES -A OUTPUT -d 1.1.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 1.1.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 1.1.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 20 (global)
+ #
+ echo "Rule 20 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 6bone.net -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -d ny6ix.net -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 6bone.net -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d ny6ix.net -m state --state NEW -j ACCEPT
+ #
+ # Rule 21 (global)
+ #
+ echo "Rule 21 (global)"
+ #
+ # firewall-ipv6-1:Policy:21: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ $IPTABLES -N RULE_21
+ $IPTABLES -A OUTPUT -d 192.0.2.1 -j RULE_21
+ $IPTABLES -A OUTPUT -d 207.251.84.150 -j RULE_21
+ # firewall-ipv6-1:Policy:21: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ $IPTABLES -A FORWARD -d 192.0.2.1 -j RULE_21
+ $IPTABLES -A FORWARD -d 207.251.84.150 -j RULE_21
+ $IPTABLES -A RULE_21 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 21 -- DENY " --ulog-qthreshold 1
+ $IPTABLES -A RULE_21 -j DROP
+
+
+ # ================ IPv6
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # rules to permit IPv6 Neighbor discovery
+ $IP6TABLES -A INPUT -p ipv6-icmp -m icmp6 --icmpv6-type router-solicitation -m hl --hl-eq 255 -j ACCEPT
+ $IP6TABLES -A OUTPUT -p ipv6-icmp -m icmp6 --icmpv6-type router-solicitation -m hl --hl-eq 255 -j ACCEPT
+ $IP6TABLES -A INPUT -p ipv6-icmp -m icmp6 --icmpv6-type router-advertisement -m hl --hl-eq 255 -j ACCEPT
+ $IP6TABLES -A OUTPUT -p ipv6-icmp -m icmp6 --icmpv6-type router-advertisement -m hl --hl-eq 255 -j ACCEPT
+ $IP6TABLES -A INPUT -p ipv6-icmp -m icmp6 --icmpv6-type neighbour-solicitation -m hl --hl-eq 255 -j ACCEPT
+ $IP6TABLES -A OUTPUT -p ipv6-icmp -m icmp6 --icmpv6-type neighbour-solicitation -m hl --hl-eq 255 -j ACCEPT
+ $IP6TABLES -A INPUT -p ipv6-icmp -m icmp6 --icmpv6-type neighbour-advertisement -m hl --hl-eq 255 -j ACCEPT
+ $IP6TABLES -A OUTPUT -p ipv6-icmp -m icmp6 --icmpv6-type neighbour-advertisement -m hl --hl-eq 255 -j ACCEPT
+ # drop packets that do not match any valid state and log them
+ $IP6TABLES -N drop_invalid
+ $IP6TABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IP6TABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IP6TABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IP6TABLES -A drop_invalid -j LOG --log-level debug --log-prefix "INVALID state -- DENY "
+ $IP6TABLES -A drop_invalid -j DROP
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy_ipv6
+ #
+ # Rule Policy_ipv6 0 (global)
+ #
+ echo "Rule Policy_ipv6 0 (global)"
+ #
+ # for bug 2047082
+ $IP6TABLES -A OUTPUT -m state --state NEW -j ACCEPT
+ #
+ # Rule Policy_ipv6 1 (global)
+ #
+ echo "Rule Policy_ipv6 1 (global)"
+ #
+ $IP6TABLES -A OUTPUT -d 6bone.net -m state --state NEW -j ACCEPT
+ $IP6TABLES -A OUTPUT -d ny6ix.net -m state --state NEW -j ACCEPT
+ $IP6TABLES -A FORWARD -d 6bone.net -m state --state NEW -j ACCEPT
+ $IP6TABLES -A FORWARD -d ny6ix.net -m state --state NEW -j ACCEPT
+ #
+ # Rule Policy_ipv6 2 (global)
+ #
+ echo "Rule Policy_ipv6 2 (global)"
+ #
+ # firewall-ipv6-1:Policy_ipv6:2: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ $IP6TABLES -N Policy_ipv6_2
+ $IP6TABLES -A OUTPUT -d 2001:db8::1 -j Policy_ipv6_2
+ # firewall-ipv6-1:Policy_ipv6:2: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ $IP6TABLES -A FORWARD -d 2001:db8::1 -j Policy_ipv6_2
+ $IP6TABLES -A Policy_ipv6_2 -j LOG --log-level info --log-prefix "RULE 2 -- DENY "
+ $IP6TABLES -A Policy_ipv6_2 -j DROP
+ #
+ # Rule Policy_ipv6 3 (global)
+ #
+ echo "Rule Policy_ipv6 3 (global)"
+ #
+ # INPUT, OUTPUT, FORWARD
+ $IP6TABLES -A INPUT -s fe80::/64 -m state --state NEW -j ACCEPT
+ $IP6TABLES -A OUTPUT -s fe80::/64 -m state --state NEW -j ACCEPT
+ $IP6TABLES -A FORWARD -s fe80::/64 -m state --state NEW -j ACCEPT
+ #
+ # Rule Policy_ipv6 4 (global)
+ #
+ echo "Rule Policy_ipv6 4 (global)"
+ #
+ # INPUT, OUTPUT, FORWARD
+ $IP6TABLES -A OUTPUT -d fe80::/64 -m state --state NEW -j ACCEPT
+ $IP6TABLES -A INPUT -d fe80::/64 -m state --state NEW -j ACCEPT
+ $IP6TABLES -A FORWARD -d fe80::/64 -m state --state NEW -j ACCEPT
+ #
+ # Rule Policy_ipv6 5 (global)
+ #
+ echo "Rule Policy_ipv6 5 (global)"
+ #
+ # for bug 2462927, ipv6 networks with /32
+ # netmask
+ $IP6TABLES -A INPUT -s 2001:db8::/32 -j DROP
+ $IP6TABLES -A INPUT -s 3fff:ffff::/32 -j DROP
+ $IP6TABLES -A INPUT -s 3fff:ffff::/16 -j DROP
+ #
+ # Rule Policy_ipv6 6 (global)
+ #
+ echo "Rule Policy_ipv6 6 (global)"
+ #
+ # firewall-ipv6-1:Policy_ipv6:6: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A OUTPUT -p ipv6-icmp -d fe80::21d:9ff:fe8b:8e94 -j ACCEPT
+ # firewall-ipv6-1:Policy_ipv6:6: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A INPUT -p ipv6-icmp -j ACCEPT
+ #
+ # Rule Policy_ipv6 7 (global)
+ #
+ echo "Rule Policy_ipv6 7 (global)"
+ #
+ # firewall-ipv6-1:Policy_ipv6:7: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A INPUT -p ipv6-icmp -j ACCEPT
+ #
+ # Rule Policy_ipv6 8 (global)
+ #
+ echo "Rule Policy_ipv6 8 (global)"
+ #
+ # firewall-ipv6-1:Policy_ipv6:8: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A OUTPUT -p ipv6-icmp -j ACCEPT
+ # firewall-ipv6-1:Policy_ipv6:8: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A INPUT -p ipv6-icmp -j ACCEPT
+ # firewall-ipv6-1:Policy_ipv6:8: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A FORWARD -p ipv6-icmp -j ACCEPT
+ #
+ # Rule Policy_ipv6 9 (global)
+ #
+ echo "Rule Policy_ipv6 9 (global)"
+ #
+ $IP6TABLES -A INPUT -p tcp -m tcp --dport 993 -m state --state NEW -j ACCEPT
+ # firewall-ipv6-1:Policy_ipv6:9: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A INPUT -p ipv6-icmp -j ACCEPT
+ #
+ # Rule Policy_ipv6 10 (global)
+ #
+ echo "Rule Policy_ipv6 10 (global)"
+ #
+ $IP6TABLES -A INPUT -p tcp -m tcp -m multiport --dports 139,135,42,445,88,389,636,3268,3269,53 -m state --state NEW -j ACCEPT
+ $IP6TABLES -A INPUT -p udp -m udp -m multiport --dports 138,137,53,88 -m state --state NEW -j ACCEPT
+ # firewall-ipv6-1:Policy_ipv6:10: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A INPUT -p ipv6-icmp -j ACCEPT
+ #
+ # Rule Policy_ipv6 11 (global)
+ #
+ echo "Rule Policy_ipv6 11 (global)"
+ #
+ $IP6TABLES -A OUTPUT -p ipv6-icmp -d fe80::21d:9ff:fe8b:8e94 -j ACCEPT
+ $IP6TABLES -A INPUT -p ipv6-icmp -j ACCEPT
+ #
+ # Rule Policy_ipv6 12 (global)
+ #
+ echo "Rule Policy_ipv6 12 (global)"
+ #
+ $IP6TABLES -A INPUT -p ipv6-icmp -j ACCEPT
+ #
+ # Rule Policy_ipv6 13 (global)
+ #
+ echo "Rule Policy_ipv6 13 (global)"
+ #
+ $IP6TABLES -A OUTPUT -p ipv6-icmp -j ACCEPT
+ $IP6TABLES -A INPUT -p ipv6-icmp -j ACCEPT
+ $IP6TABLES -A FORWARD -p ipv6-icmp -j ACCEPT
+ #
+ # Rule Policy_ipv6 14 (global)
+ #
+ echo "Rule Policy_ipv6 14 (global)"
+ #
+ $IP6TABLES -A OUTPUT -s fe80::21d:9ff:fe8b:8e94 -m state --state NEW -j ACCEPT
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:59 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " ipv6"
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall-ipv6-2.fw.orig b/test/ipt/firewall-ipv6-2.fw.orig
new file mode 100755
index 000000000..68b799479
--- /dev/null
+++ b/test/ipt/firewall-ipv6-2.fw.orig
@@ -0,0 +1,990 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:57:05 2011 PST by vadim
+#
+# files: * firewall-ipv6-2.fw
+#
+# Compiled for iptables (any version)
+#
+# Using ULOG globally, but ipv6 rules
+# should fall back to LOG because
+# there is no ULOG for ip6tables yet
+# Bug 2141911
+
+# firewall-ipv6-2:Policy:4: error: Rule '4 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-2:Policy:4: error: Rule '4 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-2:Policy:8: error: Rule '8 (global)' shadows rule '9 (global)' below it
+# firewall-ipv6-2:Policy:15: error: Rule '15 (global)' shadows rule '17 (global)' below it
+# firewall-ipv6-2:Policy:16: error: Rule '16 (global)' shadows rule '18 (global)' below it
+# firewall-ipv6-2:Policy:16: error: Rule '16 (global)' shadows rule '19 (global)' below it
+# firewall-ipv6-2:Policy:15: error: Rule '15 (global)' shadows rule '19 (global)' below it
+# firewall-ipv6-2:Policy:20: error: Rule '20 (global)' shadows rule '22 (global)' below it
+# firewall-ipv6-2:Policy:24: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-2:Policy:7: error: Rule '7 (global)' shadows rule '27 (global)' below it
+# firewall-ipv6-2:Policy:7: error: Rule '7 (global)' shadows rule '28 (global)' below it
+# firewall-ipv6-2:Policy:16: error: Rule '16 (global)' shadows rule '29 (global)' below it
+# firewall-ipv6-2:Policy:20: error: Rule '20 (global)' shadows rule '30 (global)' below it
+# firewall-ipv6-2:Policy:24: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-2:Policy:24: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+
+# firewall-ipv6-2:Policy:1: error: Rule '1 (global)' shadows rule '3 (global)' below it
+# firewall-ipv6-2:Policy:2: error: Rule '2 (global)' shadows rule '3 (global)' below it
+# firewall-ipv6-2:Policy:1: error: Rule '1 (global)' shadows rule '4 (global)' below it
+# firewall-ipv6-2:Policy:2: error: Rule '2 (global)' shadows rule '4 (global)' below it
+# firewall-ipv6-2:Policy:1: error: Rule '1 (global)' shadows rule '5 (global)' below it
+# firewall-ipv6-2:Policy:3: error: Rule '3 (global)' shadows rule '5 (global)' below it
+# firewall-ipv6-2:Policy:2: error: Rule '2 (global)' shadows rule '5 (global)' below it
+# firewall-ipv6-2:Policy:1: error: Rule '1 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-2:Policy:2: error: Rule '2 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-2:Policy:8: error: Rule '8 (global)' shadows rule '9 (global)' below it
+# firewall-ipv6-2:Policy:11: error: Rule '11 (global)' shadows rule '12 (global)' below it
+# firewall-ipv6-2:Policy:11: error: Rule '11 (global)' shadows rule '12 (global)' below it
+# firewall-ipv6-2:Policy:13: error: Rule '13 (global)' shadows rule '14 (global)' below it
+# firewall-ipv6-2:Policy:15: error: Rule '15 (global)' shadows rule '17 (global)' below it
+# firewall-ipv6-2:Policy:16: error: Rule '16 (global)' shadows rule '18 (global)' below it
+# firewall-ipv6-2:Policy:16: error: Rule '16 (global)' shadows rule '19 (global)' below it
+# firewall-ipv6-2:Policy:15: error: Rule '15 (global)' shadows rule '19 (global)' below it
+# firewall-ipv6-2:Policy:24: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-2:Policy:10: error: Rule '10 (global)' shadows rule '25 (global)' below it
+# firewall-ipv6-2:Policy:7: error: Rule '7 (global)' shadows rule '27 (global)' below it
+# firewall-ipv6-2:Policy:7: error: Rule '7 (global)' shadows rule '28 (global)' below it
+# firewall-ipv6-2:Policy:16: error: Rule '16 (global)' shadows rule '29 (global)' below it
+# firewall-ipv6-2:Policy:22: error: Rule '22 (global)' shadows rule '30 (global)' below it
+# firewall-ipv6-2:Policy:16: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-2:Policy:16: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-2:Policy:16: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-2:Policy:18: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-2:Policy:18: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-2:Policy:18: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-2:Policy:19: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-2:Policy:19: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-2:Policy:19: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-2:Policy:24: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-2:Policy:24: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-2:Policy:27: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-2:Policy:27: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-2:Policy:28: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-2:Policy:29: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-2:Policy:29: warning: Making rule stateless because it matches ICMPv6
+# firewall-ipv6-2:Policy:29: warning: Making rule stateless because it matches ICMPv6
+
+# firewall-ipv6-2:Policy:: warning: Backup ssh access rule could not be added to IPv6 policy because specified address '1.1.1.2' is invalid
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0"
+ for i in eth0 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 fe80::21d:9ff:fe8b:8e94/64 1.1.1.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # backup ssh access
+ $IPTABLES -A INPUT -p tcp -m tcp -s 1.1.1.2/255.255.255.255 --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 1.1.1.2/255.255.255.255 --sport 22 -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop packets that do not match any valid state and log them
+ $IPTABLES -N drop_invalid
+ $IPTABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IPTABLES -A drop_invalid -j ULOG --ulog-nlgroup 1 --ulog-qthreshold 1 --ulog-prefix "INVALID state -- DENY "
+ $IPTABLES -A drop_invalid -j DROP
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -N Cid56136X87590.0
+ $IPTABLES -A INPUT -p tcp -m tcp -d 1.1.1.1 --dport 22 -m state --state NEW -j Cid56136X87590.0
+ $IPTABLES -N RULE_4
+ $IPTABLES -A Cid56136X87590.0 -s 61.150.47.112 -j RULE_4
+ $IPTABLES -A Cid56136X87590.0 -s 192.168.1.0 -j RULE_4
+ $IPTABLES -A RULE_4 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 4 -- ACCEPT " --ulog-qthreshold 1
+ $IPTABLES -A RULE_4 -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -N Cid56160X87590.0
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid56160X87590.0
+ $IPTABLES -N RULE_6
+ $IPTABLES -A Cid56160X87590.0 -s 61.150.47.112 -j RULE_6
+ $IPTABLES -A Cid56160X87590.0 -s 192.168.1.0 -j RULE_6
+ $IPTABLES -A RULE_6 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 6 -- ACCEPT " --ulog-qthreshold 1
+ $IPTABLES -A RULE_6 -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -N In_RULE_7
+ $IPTABLES -A INPUT -m state --state NEW -j In_RULE_7
+ $IPTABLES -A In_RULE_7 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 7 -- ACCEPT " --ulog-qthreshold 1
+ $IPTABLES -A In_RULE_7 -j ACCEPT
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ $IPTABLES -N RULE_12
+ $IPTABLES -A INPUT -s 61.150.47.112 -m state --state NEW -j RULE_12
+ $IPTABLES -A INPUT -s 192.168.1.0 -m state --state NEW -j RULE_12
+ $IPTABLES -A FORWARD -s 61.150.47.112 -m state --state NEW -j RULE_12
+ $IPTABLES -A FORWARD -s 192.168.1.0 -m state --state NEW -j RULE_12
+ $IPTABLES -A RULE_12 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 12 -- ACCEPT " --ulog-qthreshold 1
+ $IPTABLES -A RULE_12 -j ACCEPT
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ $IPTABLES -A INPUT -p icmp -m icmp -s 1.1.1.1 --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p icmp -m icmp -s 1.1.1.1 --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ $IPTABLES -A OUTPUT -p icmp -m icmp --icmp-type any -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type any -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p icmp -m icmp --icmp-type any -m state --state NEW -j ACCEPT
+ #
+ # Rule 17 (global)
+ #
+ echo "Rule 17 (global)"
+ #
+ $IPTABLES -A OUTPUT -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ $IPTABLES -A OUTPUT -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 20 (global)
+ #
+ echo "Rule 20 (global)"
+ #
+ # INPUT, OUTPUT, FORWARD
+ $IPTABLES -A INPUT -s 1.1.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 1.1.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 1.1.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 21 (global)
+ #
+ echo "Rule 21 (global)"
+ #
+ # INPUT, OUTPUT, FORWARD
+ $IPTABLES -A OUTPUT -d 1.1.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 1.1.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 1.1.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 22 (global)
+ #
+ echo "Rule 22 (global)"
+ #
+ # for bug 2047082
+ $IPTABLES -A OUTPUT -m state --state NEW -j ACCEPT
+ #
+ # Rule 23 (global)
+ #
+ echo "Rule 23 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 6bone.net -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -d ny6ix.net -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 6bone.net -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d ny6ix.net -m state --state NEW -j ACCEPT
+ #
+ # Rule 24 (global)
+ #
+ echo "Rule 24 (global)"
+ #
+ # firewall-ipv6-2:Policy:24: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ $IPTABLES -N RULE_24
+ $IPTABLES -A OUTPUT -d 192.0.2.1 -j RULE_24
+ $IPTABLES -A OUTPUT -d 207.251.84.150 -j RULE_24
+ # firewall-ipv6-2:Policy:24: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ $IPTABLES -A FORWARD -d 192.0.2.1 -j RULE_24
+ $IPTABLES -A FORWARD -d 207.251.84.150 -j RULE_24
+ $IPTABLES -A RULE_24 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 24 -- DENY " --ulog-qthreshold 1
+ $IPTABLES -A RULE_24 -j DROP
+ #
+ # Rule 30 (global)
+ #
+ echo "Rule 30 (global)"
+ #
+ $IPTABLES -A OUTPUT -s 1.1.1.1 -m state --state NEW -j ACCEPT
+ #
+ # Rule 32 (global)
+ #
+ echo "Rule 32 (global)"
+ #
+ # ipv4 address range for bug 2820152
+ $IPTABLES -N RULE_32
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j RULE_32
+ $IPTABLES -A OUTPUT -d 192.168.1.2/31 -j RULE_32
+ $IPTABLES -A OUTPUT -d 192.168.1.4/30 -j RULE_32
+ $IPTABLES -A OUTPUT -d 192.168.1.8/29 -j RULE_32
+ $IPTABLES -A OUTPUT -d 192.168.1.16/28 -j RULE_32
+ $IPTABLES -A OUTPUT -d 192.168.1.32/27 -j RULE_32
+ $IPTABLES -A OUTPUT -d 192.168.1.64/27 -j RULE_32
+ $IPTABLES -A OUTPUT -d 192.168.1.96/30 -j RULE_32
+ $IPTABLES -A OUTPUT -d 192.168.1.100 -j RULE_32
+ $IPTABLES -A FORWARD -d 192.168.1.1 -j RULE_32
+ $IPTABLES -A FORWARD -d 192.168.1.2/31 -j RULE_32
+ $IPTABLES -A FORWARD -d 192.168.1.4/30 -j RULE_32
+ $IPTABLES -A FORWARD -d 192.168.1.8/29 -j RULE_32
+ $IPTABLES -A FORWARD -d 192.168.1.16/28 -j RULE_32
+ $IPTABLES -A FORWARD -d 192.168.1.32/27 -j RULE_32
+ $IPTABLES -A FORWARD -d 192.168.1.64/27 -j RULE_32
+ $IPTABLES -A FORWARD -d 192.168.1.96/30 -j RULE_32
+ $IPTABLES -A FORWARD -d 192.168.1.100 -j RULE_32
+ $IPTABLES -A RULE_32 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 32 -- DENY " --ulog-qthreshold 1
+ $IPTABLES -A RULE_32 -j DROP
+ #
+ # Rule 33 (global)
+ #
+ echo "Rule 33 (global)"
+ #
+ # ipv4 address range for bug 2820152
+ $IPTABLES -N RULE_33
+ $IPTABLES -A OUTPUT -d 255.255.255.255 -j RULE_33
+ $IPTABLES -A INPUT -d 255.255.255.255 -j RULE_33
+ $IPTABLES -A RULE_33 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 33 -- DENY " --ulog-qthreshold 1
+ $IPTABLES -A RULE_33 -j DROP
+ #
+ # Rule 34 (global)
+ #
+ echo "Rule 34 (global)"
+ #
+ $IPTABLES -N RULE_34
+ $IPTABLES -A OUTPUT -j RULE_34
+ $IPTABLES -A INPUT -j RULE_34
+ $IPTABLES -A FORWARD -j RULE_34
+ $IPTABLES -A RULE_34 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 34 -- DENY " --ulog-qthreshold 1
+ $IPTABLES -A RULE_34 -j DROP
+
+
+ # ================ IPv6
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop packets that do not match any valid state and log them
+ $IP6TABLES -N drop_invalid
+ $IP6TABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IP6TABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IP6TABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IP6TABLES -A drop_invalid -j LOG --log-level debug --log-prefix "INVALID state -- DENY "
+ $IP6TABLES -A drop_invalid -j DROP
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ # this rule shadows the next.
+ # Note that we add command line
+ # flag -xt to the compiler
+ $IP6TABLES -A INPUT -p tcp -m tcp -s fe80::/64 -d fe80::21d:9ff:fe8b:8e94 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IP6TABLES -A INPUT -p tcp -m tcp -s 2001:5c0:0:2::24 -d fe80::21d:9ff:fe8b:8e94 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IP6TABLES -N RULE_2
+ $IP6TABLES -A INPUT -p tcp -m tcp -s 3ffe:1200:2001:1:8000::1 --dport 22 -m state --state NEW -j RULE_2
+ $IP6TABLES -A RULE_2 -j LOG --log-level info --log-prefix "RULE 2 -- ACCEPT "
+ $IP6TABLES -A RULE_2 -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IP6TABLES -N Cid56124X87590.0
+ $IP6TABLES -A INPUT -p tcp -m tcp -d fe80::21d:9ff:fe8b:8e94 --dport 22 -m state --state NEW -j Cid56124X87590.0
+ $IP6TABLES -N RULE_3
+ $IP6TABLES -A Cid56124X87590.0 -s 2001:5c0:0:2::24 -j RULE_3
+ $IP6TABLES -A Cid56124X87590.0 -s 3ffe:1200:2000::/36 -j RULE_3
+ $IP6TABLES -A Cid56124X87590.0 -s 3ffe:1200:2001:1:8000::1 -j RULE_3
+ $IP6TABLES -A RULE_3 -j LOG --log-level info --log-prefix "RULE 3 -- ACCEPT "
+ $IP6TABLES -A RULE_3 -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IP6TABLES -N Cid56136X87590.0
+ $IP6TABLES -A INPUT -p tcp -m tcp -d fe80::21d:9ff:fe8b:8e94 --dport 22 -m state --state NEW -j Cid56136X87590.0
+ $IP6TABLES -N RULE_4
+ $IP6TABLES -A Cid56136X87590.0 -s 2001:5c0:0:2::24 -j RULE_4
+ $IP6TABLES -A Cid56136X87590.0 -s 3ffe:1200:2001:1:8000::1 -j RULE_4
+ $IP6TABLES -A RULE_4 -j LOG --log-level info --log-prefix "RULE 4 -- ACCEPT "
+ $IP6TABLES -A RULE_4 -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IP6TABLES -N Cid56148X87590.0
+ $IP6TABLES -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid56148X87590.0
+ $IP6TABLES -N RULE_5
+ $IP6TABLES -A Cid56148X87590.0 -s 2001:5c0:0:2::24 -j RULE_5
+ $IP6TABLES -A Cid56148X87590.0 -s 3ffe:1200:2000::/36 -j RULE_5
+ $IP6TABLES -A Cid56148X87590.0 -s 3ffe:1200:2001:1:8000::1 -j RULE_5
+ $IP6TABLES -A RULE_5 -j LOG --log-level info --log-prefix "RULE 5 -- ACCEPT "
+ $IP6TABLES -A RULE_5 -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IP6TABLES -N Cid56160X87590.0
+ $IP6TABLES -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid56160X87590.0
+ $IP6TABLES -N RULE_6
+ $IP6TABLES -A Cid56160X87590.0 -s 2001:5c0:0:2::24 -j RULE_6
+ $IP6TABLES -A Cid56160X87590.0 -s 3ffe:1200:2001:1:8000::1 -j RULE_6
+ $IP6TABLES -A RULE_6 -j LOG --log-level info --log-prefix "RULE 6 -- ACCEPT "
+ $IP6TABLES -A RULE_6 -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IP6TABLES -N In_RULE_7
+ $IP6TABLES -A INPUT -m state --state NEW -j In_RULE_7
+ $IP6TABLES -A In_RULE_7 -j LOG --log-level info --log-prefix "RULE 7 -- ACCEPT "
+ $IP6TABLES -A In_RULE_7 -j ACCEPT
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IP6TABLES -A OUTPUT -d e80::21d:9ff:fe8b:8e94 -m state --state NEW -j ACCEPT
+ $IP6TABLES -A FORWARD -d e80::21d:9ff:fe8b:8e94 -m state --state NEW -j ACCEPT
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IP6TABLES -A OUTPUT -d e80::21d:9ff:fe8b:8e94 -m state --state NEW -j ACCEPT
+ $IP6TABLES -A FORWARD -d e80::21d:9ff:fe8b:8e94 -m state --state NEW -j ACCEPT
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ $IP6TABLES -N RULE_10
+ $IP6TABLES -A INPUT -s fe80::/64 -m state --state NEW -j RULE_10
+ $IP6TABLES -A OUTPUT -s fe80::/64 -m state --state NEW -j RULE_10
+ $IP6TABLES -A FORWARD -s fe80::/64 -m state --state NEW -j RULE_10
+ $IP6TABLES -A RULE_10 -j LOG --log-level info --log-prefix "RULE 10 -- ACCEPT "
+ $IP6TABLES -A RULE_10 -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ $IP6TABLES -N RULE_11
+ $IP6TABLES -A INPUT -s 2001:5c0:0:2::24 -m state --state NEW -j RULE_11
+ $IP6TABLES -A INPUT -s 3ffe:1200:2000::/36 -m state --state NEW -j RULE_11
+ $IP6TABLES -A INPUT -s 3ffe:1200:2001:1:8000::1 -m state --state NEW -j RULE_11
+ $IP6TABLES -A FORWARD -s 2001:5c0:0:2::24 -m state --state NEW -j RULE_11
+ $IP6TABLES -A FORWARD -s 3ffe:1200:2000::/36 -m state --state NEW -j RULE_11
+ $IP6TABLES -A FORWARD -s 3ffe:1200:2001:1:8000::1 -m state --state NEW -j RULE_11
+ $IP6TABLES -A RULE_11 -j LOG --log-level info --log-prefix "RULE 11 -- ACCEPT "
+ $IP6TABLES -A RULE_11 -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ $IP6TABLES -N RULE_12
+ $IP6TABLES -A INPUT -s 2001:5c0:0:2::24 -m state --state NEW -j RULE_12
+ $IP6TABLES -A INPUT -s 3ffe:1200:2001:1:8000::1 -m state --state NEW -j RULE_12
+ $IP6TABLES -A FORWARD -s 2001:5c0:0:2::24 -m state --state NEW -j RULE_12
+ $IP6TABLES -A FORWARD -s 3ffe:1200:2001:1:8000::1 -m state --state NEW -j RULE_12
+ $IP6TABLES -A RULE_12 -j LOG --log-level info --log-prefix "RULE 12 -- ACCEPT "
+ $IP6TABLES -A RULE_12 -j ACCEPT
+ #
+ # Rule 16 (global)
+ #
+ echo "Rule 16 (global)"
+ #
+ # firewall-ipv6-2:Policy:16: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A OUTPUT -p ipv6-icmp -j ACCEPT
+ # firewall-ipv6-2:Policy:16: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A INPUT -p ipv6-icmp -j ACCEPT
+ # firewall-ipv6-2:Policy:16: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A FORWARD -p ipv6-icmp -j ACCEPT
+ #
+ # Rule 18 (global)
+ #
+ echo "Rule 18 (global)"
+ #
+ # firewall-ipv6-2:Policy:18: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A OUTPUT -p ipv6-icmp -m icmp6 --icmpv6-type 128/0 -j ACCEPT
+ # firewall-ipv6-2:Policy:18: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A INPUT -p ipv6-icmp -m icmp6 --icmpv6-type 128/0 -j ACCEPT
+ # firewall-ipv6-2:Policy:18: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A FORWARD -p ipv6-icmp -m icmp6 --icmpv6-type 128/0 -j ACCEPT
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ # firewall-ipv6-2:Policy:19: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A OUTPUT -p ipv6-icmp -m icmp6 --icmpv6-type 128/0 -j ACCEPT
+ # firewall-ipv6-2:Policy:19: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A INPUT -p ipv6-icmp -m icmp6 --icmpv6-type 128/0 -j ACCEPT
+ # firewall-ipv6-2:Policy:19: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A FORWARD -p ipv6-icmp -m icmp6 --icmpv6-type 128/0 -j ACCEPT
+ #
+ # Rule 22 (global)
+ #
+ echo "Rule 22 (global)"
+ #
+ # for bug 2047082
+ $IP6TABLES -A OUTPUT -m state --state NEW -j ACCEPT
+ #
+ # Rule 23 (global)
+ #
+ echo "Rule 23 (global)"
+ #
+ $IP6TABLES -A OUTPUT -d 6bone.net -m state --state NEW -j ACCEPT
+ $IP6TABLES -A OUTPUT -d ny6ix.net -m state --state NEW -j ACCEPT
+ $IP6TABLES -A FORWARD -d 6bone.net -m state --state NEW -j ACCEPT
+ $IP6TABLES -A FORWARD -d ny6ix.net -m state --state NEW -j ACCEPT
+ #
+ # Rule 24 (global)
+ #
+ echo "Rule 24 (global)"
+ #
+ # firewall-ipv6-2:Policy:24: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ $IP6TABLES -N RULE_24
+ $IP6TABLES -A OUTPUT -d 2001:db8::1 -j RULE_24
+ # firewall-ipv6-2:Policy:24: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ $IP6TABLES -A FORWARD -d 2001:db8::1 -j RULE_24
+ $IP6TABLES -A RULE_24 -j LOG --log-level info --log-prefix "RULE 24 -- DENY "
+ $IP6TABLES -A RULE_24 -j DROP
+ #
+ # Rule 25 (global)
+ #
+ echo "Rule 25 (global)"
+ #
+ # INPUT, OUTPUT, FORWARD
+ $IP6TABLES -A INPUT -s fe80::/64 -m state --state NEW -j ACCEPT
+ $IP6TABLES -A OUTPUT -s fe80::/64 -m state --state NEW -j ACCEPT
+ $IP6TABLES -A FORWARD -s fe80::/64 -m state --state NEW -j ACCEPT
+ #
+ # Rule 26 (global)
+ #
+ echo "Rule 26 (global)"
+ #
+ # INPUT, OUTPUT, FORWARD
+ $IP6TABLES -A OUTPUT -d fe80::/64 -m state --state NEW -j ACCEPT
+ $IP6TABLES -A INPUT -d fe80::/64 -m state --state NEW -j ACCEPT
+ $IP6TABLES -A FORWARD -d fe80::/64 -m state --state NEW -j ACCEPT
+ #
+ # Rule 27 (global)
+ #
+ echo "Rule 27 (global)"
+ #
+ # firewall-ipv6-2:Policy:27: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A OUTPUT -p ipv6-icmp -d fe80::21d:9ff:fe8b:8e94 -j ACCEPT
+ # firewall-ipv6-2:Policy:27: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A INPUT -p ipv6-icmp -j ACCEPT
+ #
+ # Rule 28 (global)
+ #
+ echo "Rule 28 (global)"
+ #
+ # firewall-ipv6-2:Policy:28: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A INPUT -p ipv6-icmp -j ACCEPT
+ #
+ # Rule 29 (global)
+ #
+ echo "Rule 29 (global)"
+ #
+ # firewall-ipv6-2:Policy:29: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A OUTPUT -p ipv6-icmp -j ACCEPT
+ # firewall-ipv6-2:Policy:29: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A INPUT -p ipv6-icmp -j ACCEPT
+ # firewall-ipv6-2:Policy:29: warning: Making rule stateless because it matches ICMPv6
+ $IP6TABLES -A FORWARD -p ipv6-icmp -j ACCEPT
+ #
+ # Rule 30 (global)
+ #
+ echo "Rule 30 (global)"
+ #
+ $IP6TABLES -A OUTPUT -s fe80::21d:9ff:fe8b:8e94 -m state --state NEW -j ACCEPT
+ #
+ # Rule 31 (global)
+ #
+ echo "Rule 31 (global)"
+ #
+ # test for bug 2463048
+ # "custom services should have IPv4/v6 setting"
+ # rule should compile for ipv6 b/c custom service
+ # object "ipv6 source route" is configured as "ipv6"
+ $IP6TABLES -N RULE_31
+ $IP6TABLES -A OUTPUT -m rt --rt-type 0 -j RULE_31
+ $IP6TABLES -A INPUT -m rt --rt-type 0 -j RULE_31
+ $IP6TABLES -A FORWARD -m rt --rt-type 0 -j RULE_31
+ $IP6TABLES -A RULE_31 -j LOG --log-level info --log-prefix "RULE 31 -- DENY "
+ $IP6TABLES -A RULE_31 -j DROP
+ #
+ # Rule 34 (global)
+ #
+ echo "Rule 34 (global)"
+ #
+ $IP6TABLES -N RULE_34
+ $IP6TABLES -A OUTPUT -j RULE_34
+ $IP6TABLES -A INPUT -j RULE_34
+ $IP6TABLES -A FORWARD -j RULE_34
+ $IP6TABLES -A RULE_34 -j LOG --log-level info --log-prefix "RULE 34 -- DENY "
+ $IP6TABLES -A RULE_34 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+ # backup ssh access
+ $IPTABLES -A INPUT -p tcp -m tcp -s 1.1.1.2/255.255.255.255 --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 1.1.1.2/255.255.255.255 --sport 22 -m state --state ESTABLISHED,RELATED -j ACCEPT
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:57:05 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " ipv6"
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall-ipv6-3.fw.orig b/test/ipt/firewall-ipv6-3.fw.orig
new file mode 100755
index 000000000..2e43e57a7
--- /dev/null
+++ b/test/ipt/firewall-ipv6-3.fw.orig
@@ -0,0 +1,652 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:57:10 2011 PST by vadim
+#
+# files: * firewall-ipv6-3.fw
+#
+# Compiled for iptables (any version)
+#
+# Simple policy that makes sense in ipv4 but translates into a few wide-matching rules in ipv6. Policy is configured as dual address family
+
+# firewall-ipv6-3:fw-ipv6-3:2: error: Rule 'fw-ipv6-3 2 (global)' shadows rule 'fw-ipv6-3 3 (global)' below it
+# firewall-ipv6-3:fw-ipv6-3:4: error: Rule 'fw-ipv6-3 4 (global)' shadows rule 'fw-ipv6-3 6 (global)' below it
+# firewall-ipv6-3:fw-ipv6-3:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-3:fw-ipv6-3:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-3:fw-ipv6-3:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+
+# firewall-ipv6-3:fw-ipv6-3:2: error: Rule 'fw-ipv6-3 2 (global)' shadows rule 'fw-ipv6-3 3 (global)' below it
+# firewall-ipv6-3:fw-ipv6-3:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-3:fw-ipv6-3:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-3:fw-ipv6-3:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 fe80::21d:9ff:fe8b:8e94/64 1.1.1.1/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop packets that do not match any valid state and log them
+ $IPTABLES -N drop_invalid
+ $IPTABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IPTABLES -A drop_invalid -j ULOG --ulog-nlgroup 1 --ulog-qthreshold 1 --ulog-prefix "INVALID state -- DENY "
+ $IPTABLES -A drop_invalid -j DROP
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 1.1.1.0/24 -j SNAT --to-source 22.22.22.22
+
+
+
+ # ================ Table 'filter', rule set fw-ipv6-3
+ #
+ # Rule fw-ipv6-3 0 (global)
+ #
+ echo "Rule fw-ipv6-3 0 (global)"
+ #
+ $IPTABLES -N In_fw-ipv6-3_0
+ $IPTABLES -A INPUT -m state --state NEW -j In_fw-ipv6-3_0
+ $IPTABLES -A In_fw-ipv6-3_0 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 0 -- ACCEPT " --ulog-qthreshold 1
+ $IPTABLES -A In_fw-ipv6-3_0 -j ACCEPT
+ #
+ # Rule fw-ipv6-3 1 (global)
+ #
+ echo "Rule fw-ipv6-3 1 (global)"
+ #
+ $IPTABLES -A INPUT -p icmp -m icmp -s 1.1.1.1 --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p icmp -m icmp -s 1.1.1.1 --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ #
+ # Rule fw-ipv6-3 2 (global)
+ #
+ echo "Rule fw-ipv6-3 2 (global)"
+ #
+ $IPTABLES -A OUTPUT -p icmp -m icmp --icmp-type any -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type any -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p icmp -m icmp --icmp-type any -m state --state NEW -j ACCEPT
+ #
+ # Rule fw-ipv6-3 3 (global)
+ #
+ echo "Rule fw-ipv6-3 3 (global)"
+ #
+ $IPTABLES -A OUTPUT -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ #
+ # Rule fw-ipv6-3 4 (global)
+ #
+ echo "Rule fw-ipv6-3 4 (global)"
+ #
+ # INPUT, OUTPUT, FORWARD
+ $IPTABLES -A INPUT -s 1.1.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 1.1.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 1.1.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule fw-ipv6-3 5 (global)
+ #
+ echo "Rule fw-ipv6-3 5 (global)"
+ #
+ # INPUT, OUTPUT, FORWARD
+ $IPTABLES -A OUTPUT -d 1.1.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 1.1.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 1.1.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule fw-ipv6-3 6 (global)
+ #
+ echo "Rule fw-ipv6-3 6 (global)"
+ #
+ # for bug 2047082
+ $IPTABLES -A OUTPUT -m state --state NEW -j ACCEPT
+ #
+ # Rule fw-ipv6-3 7 (global)
+ #
+ echo "Rule fw-ipv6-3 7 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 6bone.net -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -d ny6ix.net -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 6bone.net -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d ny6ix.net -m state --state NEW -j ACCEPT
+ #
+ # Rule fw-ipv6-3 8 (global)
+ #
+ echo "Rule fw-ipv6-3 8 (global)"
+ #
+ # firewall-ipv6-3:fw-ipv6-3:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ $IPTABLES -N fw-ipv6-3_8
+ $IPTABLES -A OUTPUT -d 192.0.2.1 -j fw-ipv6-3_8
+ $IPTABLES -A OUTPUT -d 207.251.84.150 -j fw-ipv6-3_8
+ # firewall-ipv6-3:fw-ipv6-3:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ $IPTABLES -A FORWARD -d 192.0.2.1 -j fw-ipv6-3_8
+ $IPTABLES -A FORWARD -d 207.251.84.150 -j fw-ipv6-3_8
+ $IPTABLES -A fw-ipv6-3_8 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 8 -- DENY " --ulog-qthreshold 1
+ $IPTABLES -A fw-ipv6-3_8 -j DROP
+ #
+ # Rule fw-ipv6-3 9 (global)
+ #
+ echo "Rule fw-ipv6-3 9 (global)"
+ #
+ # ipv4 address range for bug 2820152
+ $IPTABLES -N fw-ipv6-3_9
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j fw-ipv6-3_9
+ $IPTABLES -A OUTPUT -d 192.168.1.2/31 -j fw-ipv6-3_9
+ $IPTABLES -A OUTPUT -d 192.168.1.4/30 -j fw-ipv6-3_9
+ $IPTABLES -A OUTPUT -d 192.168.1.8/29 -j fw-ipv6-3_9
+ $IPTABLES -A OUTPUT -d 192.168.1.16/28 -j fw-ipv6-3_9
+ $IPTABLES -A OUTPUT -d 192.168.1.32/27 -j fw-ipv6-3_9
+ $IPTABLES -A OUTPUT -d 192.168.1.64/27 -j fw-ipv6-3_9
+ $IPTABLES -A OUTPUT -d 192.168.1.96/30 -j fw-ipv6-3_9
+ $IPTABLES -A OUTPUT -d 192.168.1.100 -j fw-ipv6-3_9
+ $IPTABLES -A FORWARD -d 192.168.1.1 -j fw-ipv6-3_9
+ $IPTABLES -A FORWARD -d 192.168.1.2/31 -j fw-ipv6-3_9
+ $IPTABLES -A FORWARD -d 192.168.1.4/30 -j fw-ipv6-3_9
+ $IPTABLES -A FORWARD -d 192.168.1.8/29 -j fw-ipv6-3_9
+ $IPTABLES -A FORWARD -d 192.168.1.16/28 -j fw-ipv6-3_9
+ $IPTABLES -A FORWARD -d 192.168.1.32/27 -j fw-ipv6-3_9
+ $IPTABLES -A FORWARD -d 192.168.1.64/27 -j fw-ipv6-3_9
+ $IPTABLES -A FORWARD -d 192.168.1.96/30 -j fw-ipv6-3_9
+ $IPTABLES -A FORWARD -d 192.168.1.100 -j fw-ipv6-3_9
+ $IPTABLES -A fw-ipv6-3_9 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 9 -- DENY " --ulog-qthreshold 1
+ $IPTABLES -A fw-ipv6-3_9 -j DROP
+ #
+ # Rule fw-ipv6-3 10 (global)
+ #
+ echo "Rule fw-ipv6-3 10 (global)"
+ #
+ # ipv4 address range for bug 2820152
+ $IPTABLES -N fw-ipv6-3_10
+ $IPTABLES -A OUTPUT -d 255.255.255.255 -j fw-ipv6-3_10
+ $IPTABLES -A INPUT -d 255.255.255.255 -j fw-ipv6-3_10
+ $IPTABLES -A fw-ipv6-3_10 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 10 -- DENY " --ulog-qthreshold 1
+ $IPTABLES -A fw-ipv6-3_10 -j DROP
+ #
+ # Rule fw-ipv6-3 11 (global)
+ #
+ echo "Rule fw-ipv6-3 11 (global)"
+ #
+ $IPTABLES -N fw-ipv6-3_11
+ $IPTABLES -A OUTPUT -j fw-ipv6-3_11
+ $IPTABLES -A INPUT -j fw-ipv6-3_11
+ $IPTABLES -A FORWARD -j fw-ipv6-3_11
+ $IPTABLES -A fw-ipv6-3_11 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 11 -- DENY " --ulog-qthreshold 1
+ $IPTABLES -A fw-ipv6-3_11 -j DROP
+
+
+ # ================ IPv6
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop packets that do not match any valid state and log them
+ $IP6TABLES -N drop_invalid
+ $IP6TABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IP6TABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IP6TABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IP6TABLES -A drop_invalid -j LOG --log-level debug --log-prefix "INVALID state -- DENY "
+ $IP6TABLES -A drop_invalid -j DROP
+
+
+
+
+
+
+ # ================ Table 'filter', rule set fw-ipv6-3
+ #
+ # Rule fw-ipv6-3 0 (global)
+ #
+ echo "Rule fw-ipv6-3 0 (global)"
+ #
+ $IP6TABLES -N In_fw-ipv6-3_0
+ $IP6TABLES -A INPUT -m state --state NEW -j In_fw-ipv6-3_0
+ $IP6TABLES -A In_fw-ipv6-3_0 -j LOG --log-level info --log-prefix "RULE 0 -- ACCEPT "
+ $IP6TABLES -A In_fw-ipv6-3_0 -j ACCEPT
+ #
+ # Rule fw-ipv6-3 6 (global)
+ #
+ echo "Rule fw-ipv6-3 6 (global)"
+ #
+ # for bug 2047082
+ $IP6TABLES -A OUTPUT -m state --state NEW -j ACCEPT
+ #
+ # Rule fw-ipv6-3 7 (global)
+ #
+ echo "Rule fw-ipv6-3 7 (global)"
+ #
+ $IP6TABLES -A OUTPUT -d 6bone.net -m state --state NEW -j ACCEPT
+ $IP6TABLES -A OUTPUT -d ny6ix.net -m state --state NEW -j ACCEPT
+ $IP6TABLES -A FORWARD -d 6bone.net -m state --state NEW -j ACCEPT
+ $IP6TABLES -A FORWARD -d ny6ix.net -m state --state NEW -j ACCEPT
+ #
+ # Rule fw-ipv6-3 8 (global)
+ #
+ echo "Rule fw-ipv6-3 8 (global)"
+ #
+ # firewall-ipv6-3:fw-ipv6-3:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ $IP6TABLES -N fw-ipv6-3_8
+ $IP6TABLES -A OUTPUT -d 2001:db8::1 -j fw-ipv6-3_8
+ # firewall-ipv6-3:fw-ipv6-3:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ $IP6TABLES -A FORWARD -d 2001:db8::1 -j fw-ipv6-3_8
+ $IP6TABLES -A fw-ipv6-3_8 -j LOG --log-level info --log-prefix "RULE 8 -- DENY "
+ $IP6TABLES -A fw-ipv6-3_8 -j DROP
+ #
+ # Rule fw-ipv6-3 11 (global)
+ #
+ echo "Rule fw-ipv6-3 11 (global)"
+ #
+ $IP6TABLES -N fw-ipv6-3_11
+ $IP6TABLES -A OUTPUT -j fw-ipv6-3_11
+ $IP6TABLES -A INPUT -j fw-ipv6-3_11
+ $IP6TABLES -A FORWARD -j fw-ipv6-3_11
+ $IP6TABLES -A fw-ipv6-3_11 -j LOG --log-level info --log-prefix "RULE 11 -- DENY "
+ $IP6TABLES -A fw-ipv6-3_11 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:57:10 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat ipv6"
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall-ipv6-4-1.fw.orig b/test/ipt/firewall-ipv6-4-1.fw.orig
new file mode 100755
index 000000000..08baaca1e
--- /dev/null
+++ b/test/ipt/firewall-ipv6-4-1.fw.orig
@@ -0,0 +1,599 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:57:22 2011 PST by vadim
+#
+# files: * firewall-ipv6-4-1.fw
+#
+# Compiled for iptables 1.4.0
+#
+# Policy is configured as dual address family. Using iptables-restore. Firewall is NOT part of any
+
+# firewall-ipv6-4-1:Policy:2: error: Rule '2 (global)' shadows rule '3 (global)' below it
+# firewall-ipv6-4-1:Policy:4: error: Rule '4 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-4-1:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-4-1:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-4-1:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-4-1:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+
+# firewall-ipv6-4-1:Policy:2: error: Rule '2 (global)' shadows rule '3 (global)' below it
+# firewall-ipv6-4-1:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-4-1:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-4-1:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-4-1:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IPTABLES_RESTORE
+ find_program $IP6TABLES_RESTORE
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 fe80::21d:9ff:fe8b:8e94/64 1.1.1.1/24" ""
+ getaddr eth1 i_eth1
+ getaddr6 eth1 i_eth1_v6
+}
+
+script_body() {
+ # ================ IPv4
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # drop packets that do not match any valid state and log them
+ echo ":drop_invalid - [0:0]"
+ echo "-A OUTPUT -m state --state INVALID -j drop_invalid "
+ echo "-A INPUT -m state --state INVALID -j drop_invalid "
+ echo "-A FORWARD -m state --state INVALID -j drop_invalid "
+ echo "-A drop_invalid -j ULOG --ulog-nlgroup 1 --ulog-qthreshold 1 --ulog-prefix \"INVALID state -- DENY \""
+ echo "-A drop_invalid -j DROP "
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ echo ":In_RULE_0 - [0:0]"
+ echo "-A INPUT -m state --state NEW -j In_RULE_0 "
+ echo "-A In_RULE_0 -j ULOG --ulog-nlgroup 1 --ulog-prefix \"RULE 0 -- ACCEPT \" --ulog-qthreshold 1 "
+ echo "-A In_RULE_0 -j ACCEPT "
+ #
+ # Rule 1 (global)
+ echo "-A OUTPUT -p icmp -m icmp -s 1.1.1.1 --icmp-type 8/0 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 2 (global)
+ echo "-A FORWARD -p icmp -m icmp --icmp-type any -m state --state NEW -j ACCEPT "
+ #
+ # Rule 3 (global)
+ echo "-A FORWARD -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 4 (global)
+ # INPUT, OUTPUT, FORWARD
+ echo "-A FORWARD -s 1.1.1.0/24 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 5 (global)
+ # INPUT, OUTPUT, FORWARD
+ echo "-A FORWARD -d 1.1.1.0/24 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 6 (global)
+ # for bug 2047082
+ #
+ echo "-A OUTPUT -m state --state NEW -j ACCEPT "
+ #
+ # Rule 7 (global)
+ echo "-A FORWARD -d 6bone.net -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d ny6ix.net -m state --state NEW -j ACCEPT "
+ #
+ # Rule 8 (global)
+ # firewall-ipv6-4-1:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ echo ":RULE_8 - [0:0]"
+ echo "-A FORWARD -d 192.0.2.1 -j RULE_8 "
+ echo "-A FORWARD -d 207.251.84.150 -j RULE_8 "
+ echo "-A RULE_8 -j ULOG --ulog-nlgroup 1 --ulog-prefix \"RULE 8 -- DENY \" --ulog-qthreshold 1 "
+ echo "-A RULE_8 -j DROP "
+ #
+ # Rule 9 (global)
+ # ipv4 address range for bug 2820152
+ echo "-A FORWARD -m iprange --dst-range 192.168.1.1-192.168.1.100 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 10 (global)
+ # ipv4 address range for bug 2820152
+ echo "-A INPUT -d 255.255.255.255 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 11 (global)
+ echo ":RULE_11 - [0:0]"
+ echo "-A FORWARD -j RULE_11 "
+ echo "-A RULE_11 -j ULOG --ulog-nlgroup 1 --ulog-prefix \"RULE 11 -- DENY \" --ulog-qthreshold 1 "
+ echo "-A RULE_11 -j DROP "
+ #
+ echo COMMIT
+
+
+
+ echo '*nat'
+ # ================ Table 'nat', rule set NAT
+ echo :PREROUTING ACCEPT [0:0]
+ echo :POSTROUTING ACCEPT [0:0]
+ echo :OUTPUT ACCEPT [0:0]
+ #
+ # Rule 0 (NAT)
+ echo "-A POSTROUTING -o eth1 -s 1.1.1.0/24 -j MASQUERADE "
+ #
+ echo COMMIT
+
+
+ ) | $IPTABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+
+
+
+
+ # ================ IPv6
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # drop packets that do not match any valid state and log them
+ echo ":drop_invalid - [0:0]"
+ echo "-A OUTPUT -m state --state INVALID -j drop_invalid "
+ echo "-A INPUT -m state --state INVALID -j drop_invalid "
+ echo "-A FORWARD -m state --state INVALID -j drop_invalid "
+ echo "-A drop_invalid -j LOG --log-level debug --log-prefix \"INVALID state -- DENY \""
+ echo "-A drop_invalid -j DROP "
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ echo ":In_RULE_0 - [0:0]"
+ echo "-A INPUT -m state --state NEW -j In_RULE_0 "
+ echo "-A In_RULE_0 -j LOG --log-level info --log-prefix \"RULE 0 -- ACCEPT \""
+ echo "-A In_RULE_0 -j ACCEPT "
+ #
+ # Rule 6 (global)
+ # for bug 2047082
+ #
+ echo "-A OUTPUT -m state --state NEW -j ACCEPT "
+ #
+ # Rule 7 (global)
+ echo "-A FORWARD -d 6bone.net -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d ny6ix.net -m state --state NEW -j ACCEPT "
+ #
+ # Rule 8 (global)
+ # firewall-ipv6-4-1:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ echo ":RULE_8 - [0:0]"
+ echo "-A FORWARD -d 2001:db8::1 -j RULE_8 "
+ echo "-A RULE_8 -j LOG --log-level info --log-prefix \"RULE 8 -- DENY \""
+ echo "-A RULE_8 -j DROP "
+ #
+ # Rule 11 (global)
+ echo ":RULE_11 - [0:0]"
+ echo "-A FORWARD -j RULE_11 "
+ echo "-A RULE_11 -j LOG --log-level info --log-prefix \"RULE 11 -- DENY \""
+ echo "-A RULE_11 -j DROP "
+ #
+ echo COMMIT
+
+
+
+ echo '*nat'
+ # ================ Table 'nat', rule set NAT
+ echo :PREROUTING ACCEPT [0:0]
+ echo :POSTROUTING ACCEPT [0:0]
+ echo :OUTPUT ACCEPT [0:0]
+ #
+ # Rule 0 (NAT)
+ echo "-A POSTROUTING -o eth1 -s fe80::/64 -j MASQUERADE "
+ #
+ echo COMMIT
+
+
+
+ ) | $IP6TABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:57:22 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat ipv6"
+ configure_interfaces
+ verify_interfaces
+
+
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall-ipv6-4.fw.orig b/test/ipt/firewall-ipv6-4.fw.orig
new file mode 100755
index 000000000..a31303285
--- /dev/null
+++ b/test/ipt/firewall-ipv6-4.fw.orig
@@ -0,0 +1,637 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:57:16 2011 PST by vadim
+#
+# files: * firewall-ipv6-4.fw
+#
+# Compiled for iptables (any version)
+#
+# Simple policy that makes sense in ipv4 but translates into a few wide-matching rules in ipv6. Policy is configured as dual address family. Using iptables-restore.
+
+# firewall-ipv6-4:Policy:2: error: Rule '2 (global)' shadows rule '3 (global)' below it
+# firewall-ipv6-4:Policy:4: error: Rule '4 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-4:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-4:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-4:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+
+# firewall-ipv6-4:Policy:2: error: Rule '2 (global)' shadows rule '3 (global)' below it
+# firewall-ipv6-4:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-4:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall-ipv6-4:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IPTABLES_RESTORE
+ find_program $IP6TABLES_RESTORE
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 fe80::21d:9ff:fe8b:8e94/64 1.1.1.1/24" ""
+ getaddr eth1 i_eth1
+ getaddr6 eth1 i_eth1_v6
+}
+
+script_body() {
+ # ================ IPv4
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # drop packets that do not match any valid state and log them
+ echo ":drop_invalid - [0:0]"
+ echo "-A OUTPUT -m state --state INVALID -j drop_invalid "
+ echo "-A INPUT -m state --state INVALID -j drop_invalid "
+ echo "-A FORWARD -m state --state INVALID -j drop_invalid "
+ echo "-A drop_invalid -j ULOG --ulog-nlgroup 1 --ulog-qthreshold 1 --ulog-prefix \"INVALID state -- DENY \""
+ echo "-A drop_invalid -j DROP "
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ echo ":In_RULE_0 - [0:0]"
+ echo "-A INPUT -m state --state NEW -j In_RULE_0 "
+ echo "-A In_RULE_0 -j ULOG --ulog-nlgroup 1 --ulog-prefix \"RULE 0 -- ACCEPT \" --ulog-qthreshold 1 "
+ echo "-A In_RULE_0 -j ACCEPT "
+ #
+ # Rule 1 (global)
+ echo "-A INPUT -p icmp -m icmp -s 1.1.1.1 --icmp-type 8/0 -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -p icmp -m icmp -s 1.1.1.1 --icmp-type 8/0 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 2 (global)
+ echo "-A OUTPUT -p icmp -m icmp --icmp-type any -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -p icmp -m icmp --icmp-type any -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -p icmp -m icmp --icmp-type any -m state --state NEW -j ACCEPT "
+ #
+ # Rule 3 (global)
+ echo "-A OUTPUT -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 4 (global)
+ # INPUT, OUTPUT, FORWARD
+ echo "-A INPUT -s 1.1.1.0/24 -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -s 1.1.1.0/24 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -s 1.1.1.0/24 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 5 (global)
+ # INPUT, OUTPUT, FORWARD
+ echo "-A OUTPUT -d 1.1.1.0/24 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -d 1.1.1.0/24 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 1.1.1.0/24 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 6 (global)
+ # for bug 2047082
+ #
+ echo "-A OUTPUT -m state --state NEW -j ACCEPT "
+ #
+ # Rule 7 (global)
+ echo "-A OUTPUT -d 6bone.net -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -d ny6ix.net -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 6bone.net -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d ny6ix.net -m state --state NEW -j ACCEPT "
+ #
+ # Rule 8 (global)
+ # firewall-ipv6-4:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ echo ":RULE_8 - [0:0]"
+ echo "-A OUTPUT -d 192.0.2.1 -j RULE_8 "
+ echo "-A OUTPUT -d 207.251.84.150 -j RULE_8 "
+ # firewall-ipv6-4:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ echo "-A FORWARD -d 192.0.2.1 -j RULE_8 "
+ echo "-A FORWARD -d 207.251.84.150 -j RULE_8 "
+ echo "-A RULE_8 -j ULOG --ulog-nlgroup 1 --ulog-prefix \"RULE 8 -- DENY \" --ulog-qthreshold 1 "
+ echo "-A RULE_8 -j DROP "
+ #
+ # Rule 9 (global)
+ # ipv4 address range for bug 2820152
+ echo "-A OUTPUT -d 192.168.1.1 -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -d 192.168.1.2/31 -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -d 192.168.1.4/30 -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -d 192.168.1.8/29 -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -d 192.168.1.16/28 -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -d 192.168.1.32/27 -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -d 192.168.1.64/27 -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -d 192.168.1.96/30 -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -d 192.168.1.100 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 192.168.1.1 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 192.168.1.2/31 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 192.168.1.4/30 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 192.168.1.8/29 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 192.168.1.16/28 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 192.168.1.32/27 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 192.168.1.64/27 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 192.168.1.96/30 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 192.168.1.100 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 10 (global)
+ # ipv4 address range for bug 2820152
+ echo "-A OUTPUT -d 255.255.255.255 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -d 255.255.255.255 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 11 (global)
+ echo ":RULE_11 - [0:0]"
+ echo "-A OUTPUT -j RULE_11 "
+ echo "-A INPUT -j RULE_11 "
+ echo "-A FORWARD -j RULE_11 "
+ echo "-A RULE_11 -j ULOG --ulog-nlgroup 1 --ulog-prefix \"RULE 11 -- DENY \" --ulog-qthreshold 1 "
+ echo "-A RULE_11 -j DROP "
+ #
+ echo COMMIT
+
+
+
+ echo '*nat'
+ # ================ Table 'nat', rule set NAT
+ echo :PREROUTING ACCEPT [0:0]
+ echo :POSTROUTING ACCEPT [0:0]
+ echo :OUTPUT ACCEPT [0:0]
+ #
+ # Rule 0 (NAT)
+ echo "-A POSTROUTING -o eth1 -s 1.1.1.0/24 -j MASQUERADE "
+ #
+ echo COMMIT
+
+
+ ) | $IPTABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+
+
+
+
+ # ================ IPv6
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # drop packets that do not match any valid state and log them
+ echo ":drop_invalid - [0:0]"
+ echo "-A OUTPUT -m state --state INVALID -j drop_invalid "
+ echo "-A INPUT -m state --state INVALID -j drop_invalid "
+ echo "-A FORWARD -m state --state INVALID -j drop_invalid "
+ echo "-A drop_invalid -j LOG --log-level debug --log-prefix \"INVALID state -- DENY \""
+ echo "-A drop_invalid -j DROP "
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ echo ":In_RULE_0 - [0:0]"
+ echo "-A INPUT -m state --state NEW -j In_RULE_0 "
+ echo "-A In_RULE_0 -j LOG --log-level info --log-prefix \"RULE 0 -- ACCEPT \""
+ echo "-A In_RULE_0 -j ACCEPT "
+ #
+ # Rule 6 (global)
+ # for bug 2047082
+ #
+ echo "-A OUTPUT -m state --state NEW -j ACCEPT "
+ #
+ # Rule 7 (global)
+ echo "-A OUTPUT -d 6bone.net -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -d ny6ix.net -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 6bone.net -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d ny6ix.net -m state --state NEW -j ACCEPT "
+ #
+ # Rule 8 (global)
+ # firewall-ipv6-4:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ echo ":RULE_8 - [0:0]"
+ echo "-A OUTPUT -d 2001:db8::1 -j RULE_8 "
+ # firewall-ipv6-4:Policy:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ echo "-A FORWARD -d 2001:db8::1 -j RULE_8 "
+ echo "-A RULE_8 -j LOG --log-level info --log-prefix \"RULE 8 -- DENY \""
+ echo "-A RULE_8 -j DROP "
+ #
+ # Rule 11 (global)
+ echo ":RULE_11 - [0:0]"
+ echo "-A OUTPUT -j RULE_11 "
+ echo "-A INPUT -j RULE_11 "
+ echo "-A FORWARD -j RULE_11 "
+ echo "-A RULE_11 -j LOG --log-level info --log-prefix \"RULE 11 -- DENY \""
+ echo "-A RULE_11 -j DROP "
+ #
+ echo COMMIT
+
+
+
+ echo '*nat'
+ # ================ Table 'nat', rule set NAT
+ echo :PREROUTING ACCEPT [0:0]
+ echo :POSTROUTING ACCEPT [0:0]
+ echo :OUTPUT ACCEPT [0:0]
+ #
+ # Rule 0 (NAT)
+ echo "-A POSTROUTING -o eth1 -s fe80::/64 -j MASQUERADE "
+ #
+ echo COMMIT
+
+
+
+ ) | $IP6TABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:57:16 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat ipv6"
+ configure_interfaces
+ verify_interfaces
+
+
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall-ipv6-5.fw.orig b/test/ipt/firewall-ipv6-5.fw.orig
new file mode 100755
index 000000000..049ffecfe
--- /dev/null
+++ b/test/ipt/firewall-ipv6-5.fw.orig
@@ -0,0 +1,472 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:57:24 2011 PST by vadim
+#
+# files: * firewall-ipv6-5.fw
+#
+# Compiled for iptables (any version)
+#
+# two interfaces, one has ipv4 address, another ipv6
+# Combined ipv6+ipv6 ruleset. Only interface with address
+# that matches address family should be used in generated rule
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 1.1.1.1/24" ""
+ update_addresses_of_interface "eth1 fe80::21d:9ff:fe8b:8e94/64" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p tcp -m tcp --dport 22 -j ACCEPT
+ #
+ # Rule 2 (eth1,eth0)
+ #
+ echo "Rule 2 (eth1,eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p tcp -m tcp --dport 22 -j ACCEPT
+
+
+ # ================ IPv6
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 1 (eth1)
+ #
+ echo "Rule 1 (eth1)"
+ #
+ $IP6TABLES -A INPUT -i eth1 -p tcp -m tcp --dport 22 -j ACCEPT
+ #
+ # Rule 2 (eth1,eth0)
+ #
+ echo "Rule 2 (eth1,eth0)"
+ #
+ $IP6TABLES -A INPUT -i eth1 -p tcp -m tcp --dport 22 -j ACCEPT
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:57:24 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " ipv6"
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall-ipv6-6.fw.orig b/test/ipt/firewall-ipv6-6.fw.orig
new file mode 100755
index 000000000..7ad9de9d2
--- /dev/null
+++ b/test/ipt/firewall-ipv6-6.fw.orig
@@ -0,0 +1,459 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:57:27 2011 PST by vadim
+#
+# files: * firewall-ipv6-6.fw
+#
+# Compiled for iptables (any version)
+#
+# one interfaces with both ipv4 and ipv6 addresses
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 fe80::21d:9ff:fe8b:8e94/64 1.1.1.1/24" ""
+ getaddr eth1 i_eth1
+ getaddr6 eth1 i_eth1_v6
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p tcp -m tcp --dport 22 -j ACCEPT
+
+
+ # ================ IPv6
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy_v6
+ #
+ # Rule Policy_v6 0 (eth0)
+ #
+ echo "Rule Policy_v6 0 (eth0)"
+ #
+ $IP6TABLES -A INPUT -i eth0 -p tcp -m tcp --dport 22 -j ACCEPT
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:57:27 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " ipv6"
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall-ipv6-7.fw.orig b/test/ipt/firewall-ipv6-7.fw.orig
new file mode 100755
index 000000000..95315ae57
--- /dev/null
+++ b/test/ipt/firewall-ipv6-7.fw.orig
@@ -0,0 +1,503 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:57:30 2011 PST by vadim
+#
+# files: * firewall-ipv6-7.fw
+#
+# Compiled for iptables 1.4.0
+#
+# one interface has dynamic address, testing functions that get the address at run time
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IPTABLES_RESTORE
+ find_program $IP6TABLES_RESTORE
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 fe80::21d:9ff:fe8b:8e94/64 1.1.1.1/24" ""
+ getaddr eth1 i_eth1
+ getaddr6 eth1 i_eth1_v6
+}
+
+script_body() {
+ # ================ IPv4
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # drop packets that do not match any valid state and log them
+ echo ":drop_invalid - [0:0]"
+ echo "-A OUTPUT -m state --state INVALID -j drop_invalid "
+ echo "-A INPUT -m state --state INVALID -j drop_invalid "
+ echo "-A FORWARD -m state --state INVALID -j drop_invalid "
+ echo "-A drop_invalid -j ULOG --ulog-nlgroup 1 --ulog-qthreshold 1 --ulog-prefix \"INVALID state -- DENY \""
+ echo "-A drop_invalid -j DROP "
+
+ echo COMMIT
+
+
+ echo '*mangle'
+ # ================ Table 'mangle', automatic rules
+ echo "-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu"
+
+ echo COMMIT
+
+
+
+ ) | $IPTABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+
+
+
+
+ # ================ IPv6
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # rules to permit IPv6 Neighbor discovery
+ echo "-A INPUT -p ipv6-icmp -m icmp6 --icmpv6-type router-solicitation -m hl --hl-eq 255 -j ACCEPT "
+ echo "-A OUTPUT -p ipv6-icmp -m icmp6 --icmpv6-type router-solicitation -m hl --hl-eq 255 -j ACCEPT "
+ echo "-A INPUT -p ipv6-icmp -m icmp6 --icmpv6-type router-advertisement -m hl --hl-eq 255 -j ACCEPT "
+ echo "-A OUTPUT -p ipv6-icmp -m icmp6 --icmpv6-type router-advertisement -m hl --hl-eq 255 -j ACCEPT "
+ echo "-A INPUT -p ipv6-icmp -m icmp6 --icmpv6-type neighbour-solicitation -m hl --hl-eq 255 -j ACCEPT "
+ echo "-A OUTPUT -p ipv6-icmp -m icmp6 --icmpv6-type neighbour-solicitation -m hl --hl-eq 255 -j ACCEPT "
+ echo "-A INPUT -p ipv6-icmp -m icmp6 --icmpv6-type neighbour-advertisement -m hl --hl-eq 255 -j ACCEPT "
+ echo "-A OUTPUT -p ipv6-icmp -m icmp6 --icmpv6-type neighbour-advertisement -m hl --hl-eq 255 -j ACCEPT "
+ # drop packets that do not match any valid state and log them
+ echo ":drop_invalid - [0:0]"
+ echo "-A OUTPUT -m state --state INVALID -j drop_invalid "
+ echo "-A INPUT -m state --state INVALID -j drop_invalid "
+ echo "-A FORWARD -m state --state INVALID -j drop_invalid "
+ echo "-A drop_invalid -j LOG --log-level debug --log-prefix \"INVALID state -- DENY \""
+ echo "-A drop_invalid -j DROP "
+
+ echo COMMIT
+
+
+ echo '*mangle'
+ # ================ Table 'mangle', automatic rules
+ echo "-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu"
+
+ echo COMMIT
+
+
+
+
+ ) | $IP6TABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:57:30 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " ipv6"
+ configure_interfaces
+ verify_interfaces
+
+
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall-ipv6-8.fw.orig b/test/ipt/firewall-ipv6-8.fw.orig
new file mode 100755
index 000000000..86d311ca7
--- /dev/null
+++ b/test/ipt/firewall-ipv6-8.fw.orig
@@ -0,0 +1,544 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:57:33 2011 PST by vadim
+#
+# files: * firewall-ipv6-8.fw
+#
+# Compiled for iptables 1.4.0
+#
+# matching multicast with different directions
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IPTABLES_RESTORE
+ find_program $IP6TABLES_RESTORE
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 fe80::21d:9ff:fe8b:8e94/64 1.1.1.1/24" ""
+ getaddr eth1 i_eth1
+ getaddr6 eth1 i_eth1_v6
+}
+
+script_body() {
+ # ================ IPv6
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # rules to permit IPv6 Neighbor discovery
+ echo "-A INPUT -p ipv6-icmp -m icmp6 --icmpv6-type router-solicitation -m hl --hl-eq 255 -j ACCEPT "
+ echo "-A OUTPUT -p ipv6-icmp -m icmp6 --icmpv6-type router-solicitation -m hl --hl-eq 255 -j ACCEPT "
+ echo "-A INPUT -p ipv6-icmp -m icmp6 --icmpv6-type router-advertisement -m hl --hl-eq 255 -j ACCEPT "
+ echo "-A OUTPUT -p ipv6-icmp -m icmp6 --icmpv6-type router-advertisement -m hl --hl-eq 255 -j ACCEPT "
+ echo "-A INPUT -p ipv6-icmp -m icmp6 --icmpv6-type neighbour-solicitation -m hl --hl-eq 255 -j ACCEPT "
+ echo "-A OUTPUT -p ipv6-icmp -m icmp6 --icmpv6-type neighbour-solicitation -m hl --hl-eq 255 -j ACCEPT "
+ echo "-A INPUT -p ipv6-icmp -m icmp6 --icmpv6-type neighbour-advertisement -m hl --hl-eq 255 -j ACCEPT "
+ echo "-A OUTPUT -p ipv6-icmp -m icmp6 --icmpv6-type neighbour-advertisement -m hl --hl-eq 255 -j ACCEPT "
+ # drop packets that do not match any valid state and log them
+ echo ":drop_invalid - [0:0]"
+ echo "-A OUTPUT -m state --state INVALID -j drop_invalid "
+ echo "-A INPUT -m state --state INVALID -j drop_invalid "
+ echo "-A FORWARD -m state --state INVALID -j drop_invalid "
+ echo "-A drop_invalid -j LOG --log-level debug --log-prefix \"INVALID state -- DENY \""
+ echo "-A drop_invalid -j DROP "
+ # ================ Table 'filter', rule set Policy_OSPF
+ #
+ # Rule Policy_OSPF 0 (eth0)
+ echo ":Policy_OSPF - [0:0]"
+ echo "-A Policy_OSPF -i eth0 -s fe80::/10 -d ff00::/8 -j ACCEPT "
+ echo "-A Policy_OSPF -i eth0 -s fe80::/10 -d fe80::/10 -j ACCEPT "
+ echo "-A Policy_OSPF -o eth0 -s fe80::/10 -d ff00::/8 -j ACCEPT "
+ echo "-A Policy_OSPF -o eth0 -s fe80::/10 -d fe80::/10 -j ACCEPT "
+ #
+ # Rule Policy_OSPF 1 (global)
+ echo "-A Policy_OSPF -s fe80::/10 -d ff00::/8 -j ACCEPT "
+ echo "-A Policy_OSPF -s fe80::/10 -d fe80::/10 -j ACCEPT "
+ #
+ # ================ Table 'filter', rule set Policy_v6
+ #
+ # Rule Policy_v6 0 (eth0)
+ # see #1523
+ echo "-A INPUT -i eth0 -s fe80::/10 -d ff00::/8 -j ACCEPT "
+ echo "-A FORWARD -i eth0 -s fe80::/10 -d fe80::/10 -j ACCEPT "
+ echo "-A FORWARD -o eth0 -s fe80::/10 -d ff00::/8 -j ACCEPT "
+ echo "-A FORWARD -o eth0 -s fe80::/10 -d fe80::/10 -j ACCEPT "
+ #
+ # Rule Policy_v6 1 (eth0)
+ # see #1523
+ echo "-A INPUT -i eth0 -s fe80::/10 -d ff00::/8 -j ACCEPT "
+ #
+ # Rule Policy_v6 2 (eth0)
+ # see #1523
+ echo "-A FORWARD -o eth0 -s fe80::/10 -d ff00::/8 -j ACCEPT "
+ #
+ # Rule Policy_v6 3 (eth0)
+ # see #1523
+ echo "-A FORWARD -o eth0 -s fe80::21d:9ff:fe8b:aaaa -d ff00::/8 -j ACCEPT "
+ #
+ # Rule Policy_v6 4 (eth0)
+ # see #1523
+ echo "-A OUTPUT -o eth0 -d ff00::/8 -j ACCEPT "
+ #
+ # Rule Policy_v6 5 (eth0)
+ # see #1523
+ echo "-A OUTPUT -o eth0 -s fe80::21d:9ff:fe8b:8e94 -d ff00::/8 -j ACCEPT "
+ #
+ # Rule Policy_v6 6 (eth0)
+ # see #1523
+ echo "-A OUTPUT -o eth0 -s fe80::21d:9ff:fe8b:8e94 -d ff00::/8 -j ACCEPT "
+ #
+ # Rule Policy_v6 7 (eth0)
+ # see #1523
+ echo "-A INPUT -i eth0 -s fe80::/10 -d ff00::/8 -j ACCEPT "
+ echo "-A INPUT -i eth0 -s fe80::/10 -d fe80::/10 -j ACCEPT "
+ echo "-A FORWARD -i eth0 -s fe80::/10 -d fe80::/10 -j ACCEPT "
+ echo "-A OUTPUT -o eth0 -s fe80::/10 -d ff00::/8 -j ACCEPT "
+ echo "-A OUTPUT -o eth0 -s fe80::/10 -d fe80::/10 -j ACCEPT "
+ echo "-A FORWARD -o eth0 -s fe80::/10 -d fe80::/10 -j ACCEPT "
+ #
+ # Rule Policy_v6 8 (eth0)
+ # see #1523
+ echo "-A INPUT -i eth0 -s fe80::/10 -d ff00::/8 -j ACCEPT "
+ #
+ # Rule Policy_v6 9 (eth0)
+ # see #1523
+ echo "-A OUTPUT -o eth0 -s fe80::/10 -d ff00::/8 -j ACCEPT "
+ #
+ # Rule Policy_v6 11 (eth0)
+ # see #1523
+ echo "-A OUTPUT -o eth0 -d ff00::/8 -j ACCEPT "
+ #
+ # Rule Policy_v6 12 (eth0)
+ # see #1523
+ echo "-A OUTPUT -o eth0 -s fe80::21d:9ff:fe8b:8e94 -d ff00::/8 -j ACCEPT "
+ #
+ # Rule Policy_v6 13 (eth0)
+ # see #1523
+ echo "-A OUTPUT -o eth0 -s fe80::21d:9ff:fe8b:8e94 -d ff00::/8 -j ACCEPT "
+ #
+ # Rule Policy_v6 14 (global)
+ echo "-A OUTPUT -p 89 -j Policy_OSPF "
+ echo "-A INPUT -p 89 -j Policy_OSPF "
+ echo "-A FORWARD -p 89 -j Policy_OSPF "
+ #
+ # Rule Policy_v6 15 (eth0)
+ echo "-A INPUT -i eth0 -p 89 -j Policy_OSPF "
+ echo "-A FORWARD -i eth0 -p 89 -j Policy_OSPF "
+ echo "-A OUTPUT -o eth0 -p 89 -j Policy_OSPF "
+ echo "-A FORWARD -o eth0 -p 89 -j Policy_OSPF "
+ #
+ echo COMMIT
+
+
+ echo '*mangle'
+ # ================ Table 'mangle', automatic rules
+ echo "-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu"
+
+ echo COMMIT
+
+
+
+
+ ) | $IP6TABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
+}
+
+reset_all() {
+ :
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:57:33 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " ipv6"
+ configure_interfaces
+ verify_interfaces
+
+
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall-ipv6-ipt-reset-prolog-after-flush.fw.orig b/test/ipt/firewall-ipv6-ipt-reset-prolog-after-flush.fw.orig
new file mode 100755
index 000000000..a3475862a
--- /dev/null
+++ b/test/ipt/firewall-ipv6-ipt-reset-prolog-after-flush.fw.orig
@@ -0,0 +1,510 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:57:36 2011 PST by vadim
+#
+# files: * firewall-ipv6-ipt-reset-prolog-after-flush.fw
+#
+# Compiled for iptables (any version)
+#
+# Policy is configured as dual address family. Usigng iptables-restore. Prolog is after iptables reset and flush
+
+# Prolog place "after policy reset" can not be used when policy is activated with iptables-restore
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IPTABLES_RESTORE
+ find_program $IP6TABLES_RESTORE
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+ echo "This is prolog"
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 fe80::21d:9ff:fe8b:8e94/64 1.1.1.1/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # drop packets that do not match any valid state and log them
+ echo ":drop_invalid - [0:0]"
+ echo "-A OUTPUT -m state --state INVALID -j drop_invalid "
+ echo "-A INPUT -m state --state INVALID -j drop_invalid "
+ echo "-A FORWARD -m state --state INVALID -j drop_invalid "
+ echo "-A drop_invalid -j ULOG --ulog-nlgroup 1 --ulog-qthreshold 1 --ulog-prefix \"INVALID state -- DENY \""
+ echo "-A drop_invalid -j DROP "
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ echo "-A INPUT -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -i + -m state --state NEW -j ACCEPT "
+ #
+ echo COMMIT
+
+
+
+ echo '*nat'
+ # ================ Table 'nat', rule set NAT
+ echo :PREROUTING ACCEPT [0:0]
+ echo :POSTROUTING ACCEPT [0:0]
+ echo :OUTPUT ACCEPT [0:0]
+ #
+ # Rule 0 (NAT)
+ echo "-A POSTROUTING -o eth1 -s 1.1.1.0/24 -j SNAT --to-source 22.22.22.22 "
+ #
+ echo COMMIT
+
+
+ ) | $IPTABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+
+
+
+
+ # ================ IPv6
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # drop packets that do not match any valid state and log them
+ echo ":drop_invalid - [0:0]"
+ echo "-A OUTPUT -m state --state INVALID -j drop_invalid "
+ echo "-A INPUT -m state --state INVALID -j drop_invalid "
+ echo "-A FORWARD -m state --state INVALID -j drop_invalid "
+ echo "-A drop_invalid -j LOG --log-level debug --log-prefix \"INVALID state -- DENY \""
+ echo "-A drop_invalid -j DROP "
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ echo "-A INPUT -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -i + -m state --state NEW -j ACCEPT "
+ #
+ echo COMMIT
+
+
+
+ echo '*nat'
+ # ================ Table 'nat', rule set NAT
+ echo :PREROUTING ACCEPT [0:0]
+ echo :POSTROUTING ACCEPT [0:0]
+ echo :OUTPUT ACCEPT [0:0]
+ #
+ echo COMMIT
+
+
+
+ ) | $IP6TABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:57:36 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat ipv6"
+ configure_interfaces
+ verify_interfaces
+
+
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall-ipv6-ipt-reset-prolog-after-interfaces.fw.orig b/test/ipt/firewall-ipv6-ipt-reset-prolog-after-interfaces.fw.orig
new file mode 100755
index 000000000..e009a2872
--- /dev/null
+++ b/test/ipt/firewall-ipv6-ipt-reset-prolog-after-interfaces.fw.orig
@@ -0,0 +1,510 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:57:38 2011 PST by vadim
+#
+# files: * firewall-ipv6-ipt-reset-prolog-after-interfaces.fw
+#
+# Compiled for iptables (any version)
+#
+# Policy is configured as dual address family. Usigng iptables-restore. Prolog is after configuration of interfaces
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IPTABLES_RESTORE
+ find_program $IP6TABLES_RESTORE
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+ echo "This is prolog"
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 fe80::21d:9ff:fe8b:8e94/64 1.1.1.1/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # drop packets that do not match any valid state and log them
+ echo ":drop_invalid - [0:0]"
+ echo "-A OUTPUT -m state --state INVALID -j drop_invalid "
+ echo "-A INPUT -m state --state INVALID -j drop_invalid "
+ echo "-A FORWARD -m state --state INVALID -j drop_invalid "
+ echo "-A drop_invalid -j ULOG --ulog-nlgroup 1 --ulog-qthreshold 1 --ulog-prefix \"INVALID state -- DENY \""
+ echo "-A drop_invalid -j DROP "
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ echo "-A INPUT -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -i + -m state --state NEW -j ACCEPT "
+ #
+ echo COMMIT
+
+
+
+ echo '*nat'
+ # ================ Table 'nat', rule set NAT
+ echo :PREROUTING ACCEPT [0:0]
+ echo :POSTROUTING ACCEPT [0:0]
+ echo :OUTPUT ACCEPT [0:0]
+ #
+ # Rule 0 (NAT)
+ echo "-A POSTROUTING -o eth1 -s 1.1.1.0/24 -j SNAT --to-source 22.22.22.22 "
+ #
+ echo COMMIT
+
+
+ ) | $IPTABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+
+
+
+
+ # ================ IPv6
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # drop packets that do not match any valid state and log them
+ echo ":drop_invalid - [0:0]"
+ echo "-A OUTPUT -m state --state INVALID -j drop_invalid "
+ echo "-A INPUT -m state --state INVALID -j drop_invalid "
+ echo "-A FORWARD -m state --state INVALID -j drop_invalid "
+ echo "-A drop_invalid -j LOG --log-level debug --log-prefix \"INVALID state -- DENY \""
+ echo "-A drop_invalid -j DROP "
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ echo "-A INPUT -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -i + -m state --state NEW -j ACCEPT "
+ #
+ echo COMMIT
+
+
+
+ echo '*nat'
+ # ================ Table 'nat', rule set NAT
+ echo :PREROUTING ACCEPT [0:0]
+ echo :POSTROUTING ACCEPT [0:0]
+ echo :OUTPUT ACCEPT [0:0]
+ #
+ echo COMMIT
+
+
+
+ ) | $IP6TABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:57:38 2011 by vadim"
+ check_tools
+
+ check_run_time_address_table_files
+
+ load_modules "nat ipv6"
+ configure_interfaces
+ verify_interfaces
+ prolog_commands
+
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall-ipv6-ipt-reset-prolog-top.fw.orig b/test/ipt/firewall-ipv6-ipt-reset-prolog-top.fw.orig
new file mode 100755
index 000000000..11a636f50
--- /dev/null
+++ b/test/ipt/firewall-ipv6-ipt-reset-prolog-top.fw.orig
@@ -0,0 +1,510 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:57:41 2011 PST by vadim
+#
+# files: * firewall-ipv6-ipt-reset-prolog-top.fw
+#
+# Compiled for iptables (any version)
+#
+# Policy is configured as dual address family. Usigng iptables-restore. Prolog is on top of the policy
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IPTABLES_RESTORE
+ find_program $IP6TABLES_RESTORE
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+ echo "This is prolog"
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 fe80::21d:9ff:fe8b:8e94/64 1.1.1.1/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # drop packets that do not match any valid state and log them
+ echo ":drop_invalid - [0:0]"
+ echo "-A OUTPUT -m state --state INVALID -j drop_invalid "
+ echo "-A INPUT -m state --state INVALID -j drop_invalid "
+ echo "-A FORWARD -m state --state INVALID -j drop_invalid "
+ echo "-A drop_invalid -j ULOG --ulog-nlgroup 1 --ulog-qthreshold 1 --ulog-prefix \"INVALID state -- DENY \""
+ echo "-A drop_invalid -j DROP "
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ echo "-A INPUT -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -i + -m state --state NEW -j ACCEPT "
+ #
+ echo COMMIT
+
+
+
+ echo '*nat'
+ # ================ Table 'nat', rule set NAT
+ echo :PREROUTING ACCEPT [0:0]
+ echo :POSTROUTING ACCEPT [0:0]
+ echo :OUTPUT ACCEPT [0:0]
+ #
+ # Rule 0 (NAT)
+ echo "-A POSTROUTING -o eth1 -s 1.1.1.0/24 -j SNAT --to-source 22.22.22.22 "
+ #
+ echo COMMIT
+
+
+ ) | $IPTABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+
+
+
+
+ # ================ IPv6
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # drop packets that do not match any valid state and log them
+ echo ":drop_invalid - [0:0]"
+ echo "-A OUTPUT -m state --state INVALID -j drop_invalid "
+ echo "-A INPUT -m state --state INVALID -j drop_invalid "
+ echo "-A FORWARD -m state --state INVALID -j drop_invalid "
+ echo "-A drop_invalid -j LOG --log-level debug --log-prefix \"INVALID state -- DENY \""
+ echo "-A drop_invalid -j DROP "
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ echo "-A INPUT -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -i + -m state --state NEW -j ACCEPT "
+ #
+ echo COMMIT
+
+
+
+ echo '*nat'
+ # ================ Table 'nat', rule set NAT
+ echo :PREROUTING ACCEPT [0:0]
+ echo :POSTROUTING ACCEPT [0:0]
+ echo :OUTPUT ACCEPT [0:0]
+ #
+ echo COMMIT
+
+
+
+ ) | $IP6TABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:57:41 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat ipv6"
+ configure_interfaces
+ verify_interfaces
+
+
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall-ipv6-prolog-after-flush.fw.orig b/test/ipt/firewall-ipv6-prolog-after-flush.fw.orig
new file mode 100755
index 000000000..ff98a0a95
--- /dev/null
+++ b/test/ipt/firewall-ipv6-prolog-after-flush.fw.orig
@@ -0,0 +1,480 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:57:44 2011 PST by vadim
+#
+# files: * firewall-ipv6-prolog-after-flush.fw
+#
+# Compiled for iptables (any version)
+#
+# Policy is configured as dual address family. Prolog is after iptables reset and flush
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+ echo "This is prolog"
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 fe80::21d:9ff:fe8b:8e94/64 1.1.1.1/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop packets that do not match any valid state and log them
+ $IPTABLES -N drop_invalid
+ $IPTABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IPTABLES -A drop_invalid -j ULOG --ulog-nlgroup 1 --ulog-qthreshold 1 --ulog-prefix "INVALID state -- DENY "
+ $IPTABLES -A drop_invalid -j DROP
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 1.1.1.0/24 -j SNAT --to-source 22.22.22.22
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -A INPUT -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i + -m state --state NEW -j ACCEPT
+
+
+ # ================ IPv6
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop packets that do not match any valid state and log them
+ $IP6TABLES -N drop_invalid
+ $IP6TABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IP6TABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IP6TABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IP6TABLES -A drop_invalid -j LOG --log-level debug --log-prefix "INVALID state -- DENY "
+ $IP6TABLES -A drop_invalid -j DROP
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IP6TABLES -A INPUT -m state --state NEW -j ACCEPT
+ $IP6TABLES -A FORWARD -i + -m state --state NEW -j ACCEPT
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:57:44 2011 by vadim"
+ check_tools
+
+ check_run_time_address_table_files
+
+ load_modules "nat ipv6"
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+ prolog_commands
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall-ipv6-prolog-after-interfaces.fw.orig b/test/ipt/firewall-ipv6-prolog-after-interfaces.fw.orig
new file mode 100755
index 000000000..e44ef0277
--- /dev/null
+++ b/test/ipt/firewall-ipv6-prolog-after-interfaces.fw.orig
@@ -0,0 +1,480 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:57:46 2011 PST by vadim
+#
+# files: * firewall-ipv6-prolog-after-interfaces.fw
+#
+# Compiled for iptables (any version)
+#
+# Policy is configured as dual address family. Prolog is after configuration of interfaces
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+ echo "This is prolog"
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 fe80::21d:9ff:fe8b:8e94/64 1.1.1.1/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop packets that do not match any valid state and log them
+ $IPTABLES -N drop_invalid
+ $IPTABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IPTABLES -A drop_invalid -j ULOG --ulog-nlgroup 1 --ulog-qthreshold 1 --ulog-prefix "INVALID state -- DENY "
+ $IPTABLES -A drop_invalid -j DROP
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 1.1.1.0/24 -j SNAT --to-source 22.22.22.22
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -A INPUT -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i + -m state --state NEW -j ACCEPT
+
+
+ # ================ IPv6
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop packets that do not match any valid state and log them
+ $IP6TABLES -N drop_invalid
+ $IP6TABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IP6TABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IP6TABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IP6TABLES -A drop_invalid -j LOG --log-level debug --log-prefix "INVALID state -- DENY "
+ $IP6TABLES -A drop_invalid -j DROP
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IP6TABLES -A INPUT -m state --state NEW -j ACCEPT
+ $IP6TABLES -A FORWARD -i + -m state --state NEW -j ACCEPT
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:57:46 2011 by vadim"
+ check_tools
+
+ check_run_time_address_table_files
+
+ load_modules "nat ipv6"
+ configure_interfaces
+ verify_interfaces
+ prolog_commands
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall-ipv6-prolog-top.fw.orig b/test/ipt/firewall-ipv6-prolog-top.fw.orig
new file mode 100755
index 000000000..97fece1b9
--- /dev/null
+++ b/test/ipt/firewall-ipv6-prolog-top.fw.orig
@@ -0,0 +1,480 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:57:49 2011 PST by vadim
+#
+# files: * firewall-ipv6-prolog-top.fw
+#
+# Compiled for iptables (any version)
+#
+# Policy is configured as dual address family. Prolog is on top of the policy
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+ echo "This is prolog"
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 fe80::21d:9ff:fe8b:8e94/64 1.1.1.1/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop packets that do not match any valid state and log them
+ $IPTABLES -N drop_invalid
+ $IPTABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IPTABLES -A drop_invalid -j ULOG --ulog-nlgroup 1 --ulog-qthreshold 1 --ulog-prefix "INVALID state -- DENY "
+ $IPTABLES -A drop_invalid -j DROP
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 1.1.1.0/24 -j SNAT --to-source 22.22.22.22
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -A INPUT -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i + -m state --state NEW -j ACCEPT
+
+
+ # ================ IPv6
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop packets that do not match any valid state and log them
+ $IP6TABLES -N drop_invalid
+ $IP6TABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IP6TABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IP6TABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IP6TABLES -A drop_invalid -j LOG --log-level debug --log-prefix "INVALID state -- DENY "
+ $IP6TABLES -A drop_invalid -j DROP
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IP6TABLES -A INPUT -m state --state NEW -j ACCEPT
+ $IP6TABLES -A FORWARD -i + -m state --state NEW -j ACCEPT
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:57:49 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat ipv6"
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall-server-1-s.fw.orig b/test/ipt/firewall-server-1-s.fw.orig
new file mode 100755
index 000000000..ca48f73ff
--- /dev/null
+++ b/test/ipt/firewall-server-1-s.fw.orig
@@ -0,0 +1,453 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:57:51 2011 PST by vadim
+#
+# files: * firewall-server-1-s.fw
+#
+# Compiled for iptables (any version)
+#
+# fw is part of any is OFF
+# ip forwarding is OFF
+
+# firewall-server-1-s:Policy:0: error: Rule '0 (eth0)' shadows rule '1 (eth0)' below it
+# firewall-server-1-s:Policy:0: error: Rule '0 (eth0)' shadows rule '2 (eth0)' below it
+# firewall-server-1-s:Policy:0: error: Rule '0 (eth0)' shadows rule '3 (eth0)' below it
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: lo eth0"
+ for i in lo eth0 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ # ticket #1338: local override of "Assume fw is part of any"
+ # only INPUT chain because ip forwarding is off
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.1 -j DROP
+ #
+ # Rule 2 (eth0)
+ #
+ echo "Rule 2 (eth0)"
+ #
+ # ticket #1338: "assume fw is part of any" is off, ip forwarding is off
+ $IPTABLES -N Cid2293081X29313.0
+ $IPTABLES -A INPUT -i eth0 -s 127.0.0.1 -j Cid2293081X29313.0
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.1 -j Cid2293081X29313.0
+ $IPTABLES -A Cid2293081X29313.0 -d 127.0.0.1 -j DROP
+ $IPTABLES -A Cid2293081X29313.0 -d 192.168.1.1 -j DROP
+ #
+ # Rule 3 (eth0)
+ #
+ echo "Rule 3 (eth0)"
+ #
+ # ticket #1338: "assume fw is part of any" is off, ip forwarding is off
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.1 -d 192.168.1.1 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 0 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:57:51 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall.fw.orig b/test/ipt/firewall.fw.orig
new file mode 100755
index 000000000..f39d70955
--- /dev/null
+++ b/test/ipt/firewall.fw.orig
@@ -0,0 +1,1401 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:22 2011 PST by vadim
+#
+# files: * firewall.fw
+#
+# Compiled for iptables (any version)
+#
+# this is simple firewall with two interfaces. Test regular policy rules, including IP_fragments rule
+
+# firewall:NAT:2: warning: Adding of virtual address for address range is not implemented (object r-222.222.222.0)
+# firewall:NAT:2: warning: Adding of virtual address for address range is not implemented (object r-222.222.222.0)
+# firewall:NAT:2: warning: Adding of virtual address for address range is not implemented (object r-222.222.222.0)
+# firewall:NAT:2: warning: Adding of virtual address for address range is not implemented (object r-222.222.222.0)
+# firewall:NAT:2: warning: Adding of virtual address for address range is not implemented (object r-222.222.222.0)
+# firewall:NAT:2: warning: Adding of virtual address for address range is not implemented (object r-222.222.222.0)
+# firewall:NAT:2: warning: Adding of virtual address for address range is not implemented (object r-222.222.222.0)
+# firewall:NAT:11: warning: SNAT rule can not match MAC address. Object CA(host-with-mac-1:1) removed from the rule
+# firewall:NAT:: warning: Empty inet address in object id3BF1B3E8-pa
+# firewall:NAT:: warning: Empty inet address in object id3BF1B3E8-pa
+
+# firewall:Policy:36: warning: Empty MAC address in rule
+# firewall:Policy:37: warning: Empty MAC address in rule
+# firewall:Policy:38: warning: Empty MAC address in rule
+# firewall:Policy:39: warning: Empty MAC address in rule
+# firewall:Policy:40: warning: Empty MAC address in rule
+# firewall:Policy:40: warning: Empty MAC address in rule
+# firewall:Policy:41: warning: Can not match MAC address of the firewall (chain OUTPUT)
+# firewall:Policy:36: warning: Empty MAC address in rule
+# firewall:Policy:37: warning: Empty MAC address in rule
+# firewall:Policy:38: warning: Empty MAC address in rule
+# firewall:Policy:39: warning: Empty MAC address in rule
+# firewall:Policy:40: warning: Empty MAC address in rule
+# firewall:Policy:40: warning: Empty MAC address in rule
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/usr/local/sbin/modprobe"
+IPTABLES="/usr/local/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/usr/local/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth1 eth0"
+ for i in eth1 eth0 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth1 222.222.222.222/24 222.222.222.0/32 222.222.222.1/32 222.222.222.2/32 222.222.222.3/32 222.222.222.4/32 222.222.222.5/32 222.222.222.6/32 222.222.222.7/32 222.222.222.8/32 222.222.222.9/32 222.222.222.10/32 222.222.222.11/32 222.222.222.12/32 222.222.222.13/32 222.222.222.14/32 222.222.222.15/32 222.222.222.16/32 222.222.222.17/32 222.222.222.18/32 222.222.222.19/32 222.222.222.20/32 222.222.222.21/32 222.222.222.22/32 222.222.222.23/32 222.222.222.24/32 222.222.222.25/32 222.222.222.26/32 222.222.222.27/32 222.222.222.28/32 222.222.222.29/32 222.222.222.30/32 222.222.222.31/32 222.222.222.32/32 222.222.222.33/32 222.222.222.34/32 222.222.222.35/32 222.222.222.36/32 222.222.222.37/32 222.222.222.38/32 222.222.222.39/32 222.222.222.40/32 222.222.222.41/32 222.222.222.42/32 222.222.222.43/32 222.222.222.44/32 222.222.222.45/32 222.222.222.46/32 222.222.222.47/32 222.222.222.48/32 222.222.222.49/32 222.222.222.50/32 222.222.222.51/32 222.222.222.52/32 222.222.222.53/32 222.222.222.54/32 222.222.222.55/32 222.222.222.56/32 222.222.222.57/32 222.222.222.58/32 222.222.222.59/32 222.222.222.60/32 222.222.222.61/32 222.222.222.62/32 222.222.222.63/32 222.222.222.64/32 222.222.222.65/32 222.222.222.66/32 222.222.222.67/32 222.222.222.68/32 222.222.222.69/32 222.222.222.70/32 222.222.222.71/32 222.222.222.72/32 222.222.222.73/32 222.222.222.74/32 222.222.222.75/32 222.222.222.76/32 222.222.222.77/32 222.222.222.78/32 222.222.222.79/32 222.222.222.80/32 222.222.222.81/32 222.222.222.82/32 222.222.222.83/32 222.222.222.84/32 222.222.222.85/32 222.222.222.86/32 222.222.222.87/32 222.222.222.88/32 222.222.222.89/32 222.222.222.90/32 222.222.222.91/32 222.222.222.92/32 222.222.222.93/32 222.222.222.94/32 222.222.222.95/32 222.222.222.96/32 222.222.222.97/32 222.222.222.98/32 222.222.222.99/32 222.222.222.100/32 222.222.222.101/32 222.222.222.102/32 222.222.222.103/32 222.222.222.104/32 222.222.222.105/32 222.222.222.106/32 222.222.222.107/32 222.222.222.108/32 222.222.222.109/32 222.222.222.110/32 222.222.222.111/32 222.222.222.112/32 222.222.222.113/32 222.222.222.114/32 222.222.222.115/32 222.222.222.116/32 222.222.222.117/32 222.222.222.118/32 222.222.222.119/32 222.222.222.120/32 222.222.222.121/32 222.222.222.122/32 222.222.222.123/32 222.222.222.124/32 222.222.222.125/32 222.222.222.126/32 222.222.222.127/32 222.222.222.128/32 222.222.222.129/32 222.222.222.130/32 222.222.222.131/32 222.222.222.132/32 222.222.222.133/32 222.222.222.134/32 222.222.222.135/32 222.222.222.136/32 222.222.222.137/32 222.222.222.138/32 222.222.222.139/32 222.222.222.140/32 222.222.222.141/32 222.222.222.142/32 222.222.222.143/32 222.222.222.144/32 222.222.222.145/32 222.222.222.146/32 222.222.222.147/32 222.222.222.148/32 222.222.222.149/32 222.222.222.150/32 222.222.222.151/32 222.222.222.152/32 222.222.222.153/32 222.222.222.154/32 222.222.222.155/32 222.222.222.156/32 222.222.222.157/32 222.222.222.158/32 222.222.222.159/32 222.222.222.160/32 222.222.222.161/32 222.222.222.162/32 222.222.222.163/32 222.222.222.164/32 222.222.222.165/32 222.222.222.166/32 222.222.222.167/32 222.222.222.168/32 222.222.222.169/32 222.222.222.170/32 222.222.222.171/32 222.222.222.172/32 222.222.222.173/32 222.222.222.174/32 222.222.222.175/32 222.222.222.176/32 222.222.222.177/32 222.222.222.178/32 222.222.222.179/32 222.222.222.180/32 222.222.222.181/32 222.222.222.182/32 222.222.222.183/32 222.222.222.184/32 222.222.222.185/32 222.222.222.186/32 222.222.222.187/32 222.222.222.188/32 222.222.222.189/32 222.222.222.190/32 222.222.222.191/32 222.222.222.192/32 222.222.222.193/32 222.222.222.194/32 222.222.222.195/32 222.222.222.196/32 222.222.222.197/32 222.222.222.198/32 222.222.222.199/32 222.222.222.200/32 222.222.222.201/32 222.222.222.202/32 222.222.222.203/32 222.222.222.204/32 222.222.222.205/32 222.222.222.206/32 222.222.222.207/32 222.222.222.208/32 222.222.222.209/32 222.222.222.210/32 222.222.222.211/32 222.222.222.212/32 222.222.222.213/32 222.222.222.214/32 222.222.222.215/32 222.222.222.216/32 222.222.222.217/32 222.222.222.218/32 222.222.222.219/32 222.222.222.220/32 222.222.222.221/32 222.222.222.222/32 222.222.222.223/32 222.222.222.224/32 222.222.222.225/32 222.222.222.226/32 222.222.222.227/32 222.222.222.228/32 222.222.222.229/32 222.222.222.230/32 222.222.222.231/32 222.222.222.232/32 222.222.222.233/32 222.222.222.234/32 222.222.222.235/32 222.222.222.236/32 222.222.222.237/32 222.222.222.238/32 222.222.222.239/32 222.222.222.240/32 222.222.222.241/32 222.222.222.242/32 222.222.222.243/32 222.222.222.244/32 222.222.222.245/32 222.222.222.246/32 222.222.222.247/32 222.222.222.248/32 222.222.222.249/32 222.222.222.250/32 222.222.222.251/32 222.222.222.252/32 222.222.222.253/32 222.222.222.254/32 222.222.222.40/24 222.222.222.41/24" ""
+ update_addresses_of_interface "eth0 192.168.1.1/24 192.168.1.20/24 192.168.1.10/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # backup ssh access
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.100/255.255.255.255 --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.100/255.255.255.255 --sport 22 -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop TCP sessions opened prior firewall restart
+ $IPTABLES -A INPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ $IPTABLES -A OUTPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ $IPTABLES -A FORWARD -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ # drop packets that do not match any valid state and log them
+ $IPTABLES -N drop_invalid
+ $IPTABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IPTABLES -A drop_invalid -j LOG --log-level debug --log-prefix "INVALID state -- DENY "
+ $IPTABLES -A drop_invalid -j DROP
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j SNAT --to-source 222.222.222.222
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.0/24 -j NETMAP --to 222.222.222.0/24
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ # firewall:NAT:2: warning: Adding of virtual address for address range is not implemented (object r-222.222.222.0)
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10/31 -j SNAT --to-source 222.222.222.10-222.222.222.100
+ # firewall:NAT:2: warning: Adding of virtual address for address range is not implemented (object r-222.222.222.0)
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.12/30 -j SNAT --to-source 222.222.222.10-222.222.222.100
+ # firewall:NAT:2: warning: Adding of virtual address for address range is not implemented (object r-222.222.222.0)
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.16/28 -j SNAT --to-source 222.222.222.10-222.222.222.100
+ # firewall:NAT:2: warning: Adding of virtual address for address range is not implemented (object r-222.222.222.0)
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.32/27 -j SNAT --to-source 222.222.222.10-222.222.222.100
+ # firewall:NAT:2: warning: Adding of virtual address for address range is not implemented (object r-222.222.222.0)
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.64/27 -j SNAT --to-source 222.222.222.10-222.222.222.100
+ # firewall:NAT:2: warning: Adding of virtual address for address range is not implemented (object r-222.222.222.0)
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.96/30 -j SNAT --to-source 222.222.222.10-222.222.222.100
+ # firewall:NAT:2: warning: Adding of virtual address for address range is not implemented (object r-222.222.222.0)
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.100 -j SNAT --to-source 222.222.222.10-222.222.222.100
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.20 --dport 80 -j DNAT --to-destination :3128
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -p tcp -m tcp -s 192.168.1.0/24 --dport 3128 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -p tcp -m tcp -d 22.22.22.23 --dport 4000:4010 -j SNAT --to-source 192.168.1.10
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -p tcp -m tcp -d 22.22.22.23 --dport 3128 -j SNAT --to-source 192.168.1.10
+ #
+ # Rule 6 (NAT)
+ #
+ echo "Rule 6 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 25 -j DNAT --to-destination 192.168.1.10:25
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 222.222.222.222 --dport 25 -j DNAT --to-destination 192.168.1.10:25
+ #
+ # Rule 7 (NAT)
+ #
+ echo "Rule 7 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 192.168.1.1 --icmp-type 8/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 222.222.222.222 --icmp-type 8/0 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 8 (NAT)
+ #
+ echo "Rule 8 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 192.168.1.1 --icmp-type 8/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 222.222.222.222 --icmp-type 8/0 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 9 (NAT)
+ #
+ echo "Rule 9 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --sport 1000:1010 -d 192.168.1.1 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --sport 1000:1010 -d 222.222.222.222 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 10 (NAT)
+ #
+ echo "Rule 10 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --sport 1000:1010 -j SNAT --to-source 222.222.222.222:1000-1010
+ #
+ # Rule 11 (NAT)
+ #
+ echo "Rule 11 (NAT)"
+ #
+ # firewall:NAT:11: warning: SNAT rule can not match MAC address. Object CA(host-with-mac-1:1) removed from the rule
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --dport 25 -j SNAT --to-source 222.222.222.222
+ #
+ # Rule 12 (NAT)
+ #
+ echo "Rule 12 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m mac --mac-source 00:10:4b:de:e9:70 -d 222.222.222.40 --dport 25 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m mac --mac-source 00:10:4b:de:e9:70 -d 222.222.222.41 --dport 25 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 13 (NAT)
+ #
+ echo "Rule 13 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m mac --mac-source aa:bb:cc:dd:ee:ff -s 192.168.1.15 -d 222.222.222.40 --dport 25 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m mac --mac-source aa:bb:cc:dd:ee:ff -s 192.168.1.15 -d 222.222.222.41 --dport 25 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 14 (NAT)
+ #
+ echo "Rule 14 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid445F52DE31658.0
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --dport 80 -j Cid445F52DE31658.0
+ $IPTABLES -t nat -A Cid445F52DE31658.0 -d 61.150.47.112 -j RETURN
+ $IPTABLES -t nat -A Cid445F52DE31658.0 -d 223.223.223.223 -j RETURN
+ $IPTABLES -t nat -A Cid445F52DE31658.0 -p tcp -m tcp --dport 80 -j SNAT --to-source 222.222.222.222
+ #
+ # Rule 15 (NAT)
+ #
+ echo "Rule 15 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --sport 1024:65535 -d 192.168.1.1 --dport 80 -j DNAT --to-destination 192.168.1.10:80
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --sport 1024:65535 -d 222.222.222.222 --dport 80 -j DNAT --to-destination 192.168.1.10:80
+ #
+ # Rule 16 (NAT)
+ #
+ echo "Rule 16 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --sport 53 -d 192.168.1.1 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --sport 53 -d 222.222.222.222 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 17 (NAT)
+ #
+ echo "Rule 17 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 4000:4010 -j DNAT --to-destination 192.168.1.10:4000-4010
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 222.222.222.222 --dport 4000:4010 -j DNAT --to-destination 192.168.1.10:4000-4010
+ #
+ # Rule 18 (NAT)
+ #
+ echo "Rule 18 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --dport 4000:4010 -j SNAT --to-source 222.222.222.222
+ #
+ # Rule 19 (NAT)
+ #
+ echo "Rule 19 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.10 --dport 3128 -j DNAT --to-destination :80
+ #
+ # Rule 20 (NAT)
+ #
+ echo "Rule 20 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 3128 -j DNAT --to-destination :80
+ #
+ # Rule 21 (NAT)
+ #
+ echo "Rule 21 (NAT)"
+ #
+ # should use multiport
+ # and account for
+ # no more than 15 ports
+ # per rule
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 222.222.222.222 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 222.222.222.222 --dports 6667,3128,113,53,21,80,119,25,22,23,540,70,13,2105,443 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 222.222.222.222 --dports 143,993,6667,543,544,389,98,3306,2049,110,5432,515,26000,512,513 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 222.222.222.222 --dports 514,4321,465,1080,111,7100 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 22 (NAT)
+ #
+ echo "Rule 22 (NAT)"
+ #
+ # should use multiport
+ # and account for
+ # no more than 15 ports
+ # per rule
+ $IPTABLES -t nat -N Cid3EF4288E.0
+ $IPTABLES -t nat -A PREROUTING -d 222.222.222.222 -j Cid3EF4288E.0
+ $IPTABLES -t nat -A Cid3EF4288E.0 -p tcp -m tcp --dport 10000:11000 -j RETURN
+ $IPTABLES -t nat -A Cid3EF4288E.0 -p tcp -m tcp -m multiport --dports 6667,3128,113,53,21,80,119,25,22,23,540,70,13,2105,443 -j RETURN
+ $IPTABLES -t nat -A Cid3EF4288E.0 -p tcp -m tcp -m multiport --dports 143,993,6667,543,544,389,98,3306,2049,110,5432,515,26000,512,513 -j RETURN
+ $IPTABLES -t nat -A Cid3EF4288E.0 -p tcp -m tcp -m multiport --dports 514,4321,465,1080,111,7100 -j RETURN
+ $IPTABLES -t nat -A Cid3EF4288E.0 -j DNAT --to-destination 192.168.1.10
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth1)
+ #
+ echo "Rule 0 (eth1)"
+ #
+ # Automatically generated rule blocking short fragments
+ $IPTABLES -N In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -p all -f -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -p all -f -j In_RULE_0
+ $IPTABLES -A In_RULE_0 -m limit --limit 5/second -j LOG --log-level 7 --log-prefix "CUSTOM LOGGING"
+ $IPTABLES -A In_RULE_0 -j DROP
+ #
+ # Rule 1 (eth1)
+ #
+ echo "Rule 1 (eth1)"
+ #
+ # тестовый комментарий по-русски. Проверяем конвертацию из/в Utf8
+ $IPTABLES -N Cid3B09D29D.0
+ $IPTABLES -A INPUT -i eth1 -p all -f -j Cid3B09D29D.0
+ $IPTABLES -N In_RULE_1
+ $IPTABLES -A Cid3B09D29D.0 -d 192.168.1.1 -j In_RULE_1
+ $IPTABLES -A Cid3B09D29D.0 -d 222.222.222.222 -j In_RULE_1
+ $IPTABLES -A In_RULE_1 -m limit --limit 5/second -j LOG --log-level 7 --log-prefix "CUSTOM LOGGING"
+ $IPTABLES -A In_RULE_1 -j DROP
+ #
+ # Rule 2 (eth1)
+ #
+ echo "Rule 2 (eth1)"
+ #
+ # Automatically generated anti-spoofing rule
+ $IPTABLES -N In_RULE_2
+ $IPTABLES -A INPUT -i eth1 -s 192.168.1.1 -j In_RULE_2
+ $IPTABLES -A INPUT -i eth1 -s 222.222.222.222 -j In_RULE_2
+ $IPTABLES -A INPUT -i eth1 -s 192.168.1.0/24 -j In_RULE_2
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.1.1 -j In_RULE_2
+ $IPTABLES -A FORWARD -i eth1 -s 222.222.222.222 -j In_RULE_2
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.1.0/24 -j In_RULE_2
+ $IPTABLES -A In_RULE_2 -m limit --limit 5/second -j LOG --log-level 7 --log-prefix "CUSTOM LOGGING"
+ $IPTABLES -A In_RULE_2 -j DROP
+ #
+ # Rule 3 (eth1)
+ #
+ echo "Rule 3 (eth1)"
+ #
+ $IPTABLES -N Cid47421X33852.0
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp --dport 53 -m state --state NEW -j Cid47421X33852.0
+ $IPTABLES -A Cid47421X33852.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid47421X33852.0 -d 222.222.222.222 -j ACCEPT
+ $IPTABLES -N Cid47421X33852.1
+ $IPTABLES -A OUTPUT -o eth1 -p udp -m udp --dport 53 -m state --state NEW -j Cid47421X33852.1
+ $IPTABLES -A Cid47421X33852.1 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid47421X33852.1 -d 222.222.222.222 -j ACCEPT
+ #
+ # Rule 4 (eth1)
+ #
+ echo "Rule 4 (eth1)"
+ #
+ # rule in FORWARD chain with
+ # -o eth1 and dest address of the firewall
+ # is pretty much impossible
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -d 222.222.222.222 --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth1 -p udp -m udp -d 222.222.222.222 --dport 53 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (eth1)
+ #
+ echo "Rule 5 (eth1)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -d 222.222.222.222 --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i eth1 -p udp -m udp -d 192.168.1.10 --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth1 -p udp -m udp -d 222.222.222.222 --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth1 -p udp -m udp -d 192.168.1.10 --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o eth1 -p udp -m udp -d 192.168.1.10 --dport 53 -m state --state NEW -j ACCEPT
+ #
+ # Rule 6 (eth1)
+ #
+ echo "Rule 6 (eth1)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -d 222.222.222.222 --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i eth1 -p udp -m udp -d 192.168.1.10 --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth1 -p udp -m udp -d 222.222.222.222 --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth1 -p udp -m udp -d 192.168.1.10 --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o eth1 -p udp -m udp -d 192.168.1.10 --dport 53 -m state --state NEW -j ACCEPT
+ #
+ # Rule 7 (eth1)
+ #
+ echo "Rule 7 (eth1)"
+ #
+ $IPTABLES -N Cid112281X33852.0
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp --dport 53 -m state --state NEW -j Cid112281X33852.0
+ $IPTABLES -A Cid112281X33852.0 -s 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid112281X33852.0 -s 222.222.222.222 -j ACCEPT
+ $IPTABLES -N Cid112281X33852.1
+ $IPTABLES -A FORWARD -i eth1 -p udp -m udp --dport 53 -m state --state NEW -j Cid112281X33852.1
+ $IPTABLES -A Cid112281X33852.1 -s 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid112281X33852.1 -s 222.222.222.222 -j ACCEPT
+ $IPTABLES -N Cid112281X33852.2
+ $IPTABLES -A OUTPUT -o eth1 -p udp -m udp --dport 53 -m state --state NEW -j Cid112281X33852.2
+ $IPTABLES -A Cid112281X33852.2 -s 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid112281X33852.2 -s 222.222.222.222 -j ACCEPT
+ #
+ # Rule 8 (eth1)
+ #
+ echo "Rule 8 (eth1)"
+ #
+ # keep FORWARD chain
+ # because it is needed for anti-spoofing rules
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -s 222.222.222.222 --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i eth1 -p udp -m udp -s 222.222.222.222 --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth1 -p udp -m udp -s 222.222.222.222 --dport 53 -m state --state NEW -j ACCEPT
+ #
+ # Rule 9 (eth1)
+ #
+ echo "Rule 9 (eth1)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -s 222.222.222.222 --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -s 192.168.1.10 --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i eth1 -p udp -m udp -s 222.222.222.222 --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i eth1 -p udp -m udp -s 192.168.1.10 --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth1 -p udp -m udp -s 222.222.222.222 --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o eth1 -p udp -m udp -s 192.168.1.10 --dport 53 -m state --state NEW -j ACCEPT
+ #
+ # Rule 10 (eth0)
+ #
+ echo "Rule 10 (eth0)"
+ #
+ $IPTABLES -N Cid3B92DFC5.0
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -s 192.168.1.0/24 --dport 53 -m state --state NEW -j Cid3B92DFC5.0
+ $IPTABLES -A Cid3B92DFC5.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3B92DFC5.0 -d 222.222.222.222 -j ACCEPT
+ $IPTABLES -N Cid3B92DFC5.1
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -s 192.168.1.0/24 --dport 53 -m state --state NEW -j Cid3B92DFC5.1
+ $IPTABLES -A Cid3B92DFC5.1 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3B92DFC5.1 -d 222.222.222.222 -j ACCEPT
+ #
+ # Rule 11 (eth0)
+ #
+ echo "Rule 11 (eth0)"
+ #
+ # code should go into INPUT chain with
+ # address in destination for comparison
+ $IPTABLES -N In_RULE_11
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 192.168.1.255 --dport 53 -j In_RULE_11
+ $IPTABLES -A In_RULE_11 -m limit --limit 5/second -j LOG --log-level 7 --log-prefix "CUSTOM LOGGING"
+ $IPTABLES -A In_RULE_11 -j DROP
+ #
+ # Rule 12 (eth0)
+ #
+ echo "Rule 12 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i eth0 -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
+ #
+ # Rule 13 (eth0,eth1)
+ #
+ echo "Rule 13 (eth0,eth1)"
+ #
+ # reject using connlimit
+ $IPTABLES -A INPUT -i eth0 -d 192.168.1.1 -m connlimit --connlimit-above 2 --connlimit-mask 24 -j DROP
+ $IPTABLES -A INPUT -i eth0 -d 222.222.222.222 -m connlimit --connlimit-above 2 --connlimit-mask 24 -j DROP
+ $IPTABLES -A INPUT -i eth1 -d 192.168.1.1 -m connlimit --connlimit-above 2 --connlimit-mask 24 -j DROP
+ $IPTABLES -A INPUT -i eth1 -d 222.222.222.222 -m connlimit --connlimit-above 2 --connlimit-mask 24 -j DROP
+ #
+ # Rule 14 (eth0,eth1)
+ #
+ echo "Rule 14 (eth0,eth1)"
+ #
+ # reject using connlimit
+ $IPTABLES -A INPUT -i eth0 -d 192.168.1.1 -m dstlimit --dstlimit 2/second --dstlimit-burst 5 --dstlimit-mode destip --dstlimit-name htable_rule_14 -j DROP
+ $IPTABLES -A INPUT -i eth0 -d 222.222.222.222 -m dstlimit --dstlimit 2/second --dstlimit-burst 5 --dstlimit-mode destip --dstlimit-name htable_rule_14 -j DROP
+ $IPTABLES -A INPUT -i eth1 -d 192.168.1.1 -m dstlimit --dstlimit 2/second --dstlimit-burst 5 --dstlimit-mode destip --dstlimit-name htable_rule_14 -j DROP
+ $IPTABLES -A INPUT -i eth1 -d 222.222.222.222 -m dstlimit --dstlimit 2/second --dstlimit-burst 5 --dstlimit-mode destip --dstlimit-name htable_rule_14 -j DROP
+ #
+ # Rule 15 (eth0,eth1)
+ #
+ echo "Rule 15 (eth0,eth1)"
+ #
+ $IPTABLES -A INPUT -i eth0 -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth0 -d 222.222.222.222 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth1 -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth1 -d 222.222.222.222 -m state --state NEW -j ACCEPT
+ #
+ # Rule 16 (global)
+ #
+ echo "Rule 16 (global)"
+ #
+ # OUTPUT
+ $IPTABLES -N Cid469F1D0830391.0
+ $IPTABLES -A OUTPUT -d 1.1.1.1 -j Cid469F1D0830391.0
+ $IPTABLES -A Cid469F1D0830391.0 -s 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid469F1D0830391.0 -s 222.222.222.222 -j ACCEPT
+ #
+ # Rule 17 (global)
+ #
+ echo "Rule 17 (global)"
+ #
+ # INTPUT with "-i +"
+ # "-i +" is redundant if chain is INPUT,
+ # optimization removes it
+ $IPTABLES -N Cid469F1CF730391.0
+ $IPTABLES -A INPUT -s 1.1.1.1 -j Cid469F1CF730391.0
+ $IPTABLES -A Cid469F1CF730391.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid469F1CF730391.0 -d 222.222.222.222 -j ACCEPT
+ #
+ # Rule 18 (global)
+ #
+ echo "Rule 18 (global)"
+ #
+ # OUTPUT + FORWARD
+ $IPTABLES -A OUTPUT -d 1.1.1.1 -j ACCEPT
+ $IPTABLES -A FORWARD -o + -d 1.1.1.1 -j ACCEPT
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ # INPUT + FORWARD
+ $IPTABLES -A INPUT -s 1.1.1.1 -j ACCEPT
+ $IPTABLES -A FORWARD -i + -s 1.1.1.1 -j ACCEPT
+ #
+ # Rule 20 (global)
+ #
+ echo "Rule 20 (global)"
+ #
+ # OUTPUT + FORWARD
+ $IPTABLES -A OUTPUT -d 1.1.1.1 -j ACCEPT
+ $IPTABLES -A FORWARD -d 1.1.1.1 -j ACCEPT
+ #
+ # Rule 21 (global)
+ #
+ echo "Rule 21 (global)"
+ #
+ # INPUT + FORWARD
+ $IPTABLES -A INPUT -s 1.1.1.1 -j ACCEPT
+ $IPTABLES -A FORWARD -s 1.1.1.1 -j ACCEPT
+ #
+ # Rule 22 (global)
+ #
+ echo "Rule 22 (global)"
+ #
+ $IPTABLES -N RULE_22
+ $IPTABLES -A OUTPUT -p icmp -m icmp --icmp-type any -j RULE_22
+ $IPTABLES -A OUTPUT -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j RULE_22
+ $IPTABLES -A OUTPUT -p tcp -m tcp --tcp-flags ALL ACK,RST,SYN,FIN -j RULE_22
+ $IPTABLES -A OUTPUT -p tcp -m tcp --tcp-flags ALL NONE -j RULE_22
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type any -j RULE_22
+ $IPTABLES -A INPUT -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j RULE_22
+ $IPTABLES -A INPUT -p tcp -m tcp --tcp-flags ALL ACK,RST,SYN,FIN -j RULE_22
+ $IPTABLES -A INPUT -p tcp -m tcp --tcp-flags ALL NONE -j RULE_22
+ $IPTABLES -A FORWARD -p icmp -m icmp --icmp-type any -j RULE_22
+ $IPTABLES -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j RULE_22
+ $IPTABLES -A FORWARD -p tcp -m tcp --tcp-flags ALL ACK,RST,SYN,FIN -j RULE_22
+ $IPTABLES -A FORWARD -p tcp -m tcp --tcp-flags ALL NONE -j RULE_22
+ $IPTABLES -A RULE_22 -m limit --limit 5/second -j LOG --log-level 7 --log-prefix "CUSTOM LOGGING"
+ $IPTABLES -A RULE_22 -j DROP
+ #
+ # Rule 23 (global)
+ #
+ echo "Rule 23 (global)"
+ #
+ $IPTABLES -A OUTPUT -p all -m ipv4options --rr -j DROP
+ $IPTABLES -A OUTPUT -p all -m ipv4options --lsrr --ssrr -j DROP
+ $IPTABLES -A OUTPUT -p all -m ipv4options --ts -j DROP
+ $IPTABLES -A INPUT -p all -m ipv4options --rr -j DROP
+ $IPTABLES -A INPUT -p all -m ipv4options --lsrr --ssrr -j DROP
+ $IPTABLES -A INPUT -p all -m ipv4options --ts -j DROP
+ $IPTABLES -A FORWARD -p all -m ipv4options --rr -j DROP
+ $IPTABLES -A FORWARD -p all -m ipv4options --lsrr --ssrr -j DROP
+ $IPTABLES -A FORWARD -p all -m ipv4options --ts -j DROP
+ #
+ # Rule 24 (global)
+ #
+ echo "Rule 24 (global)"
+ #
+ $IPTABLES -A OUTPUT -p all -m ipv4options --any-opt -j DROP
+ $IPTABLES -A INPUT -p all -m ipv4options --any-opt -j DROP
+ $IPTABLES -A FORWARD -p all -m ipv4options --any-opt -j DROP
+ #
+ # Rule 25 (global)
+ #
+ echo "Rule 25 (global)"
+ #
+ $IPTABLES -A OUTPUT -p all -m dscp --dscp-class AF4 -m ipv4options --lsrr --ra -j DROP
+ $IPTABLES -A INPUT -p all -m dscp --dscp-class AF4 -m ipv4options --lsrr --ra -j DROP
+ $IPTABLES -A FORWARD -p all -m dscp --dscp-class AF4 -m ipv4options --lsrr --ra -j DROP
+ #
+ # Rule 26 (global)
+ #
+ echo "Rule 26 (global)"
+ #
+ $IPTABLES -N RULE_26
+ $IPTABLES -A OUTPUT -p tcp -m state --state ESTABLISHED --tcp-flags SYN,ACK,RST,URG ACK -j RULE_26
+ $IPTABLES -A OUTPUT -p tcp -m state --state ESTABLISHED --tcp-flags SYN,FIN,RST,URG,PSH RST -j RULE_26
+ $IPTABLES -A INPUT -p tcp -m state --state ESTABLISHED --tcp-flags SYN,ACK,RST,URG ACK -j RULE_26
+ $IPTABLES -A INPUT -p tcp -m state --state ESTABLISHED --tcp-flags SYN,FIN,RST,URG,PSH RST -j RULE_26
+ $IPTABLES -A FORWARD -p tcp -m state --state ESTABLISHED --tcp-flags SYN,ACK,RST,URG ACK -j RULE_26
+ $IPTABLES -A FORWARD -p tcp -m state --state ESTABLISHED --tcp-flags SYN,FIN,RST,URG,PSH RST -j RULE_26
+ $IPTABLES -A RULE_26 -m limit --limit 5/second -j LOG --log-level 7 --log-prefix "CUSTOM LOGGING"
+ $IPTABLES -A RULE_26 -j DROP
+ #
+ # Rule 28 (global)
+ #
+ echo "Rule 28 (global)"
+ #
+ # both src and dst have multiple interfaces
+ $IPTABLES -N Cid3EE24E9C.0
+ $IPTABLES -A INPUT -s 192.168.1.1 -m state --state NEW -j Cid3EE24E9C.0
+ $IPTABLES -A INPUT -s 222.222.222.222 -m state --state NEW -j Cid3EE24E9C.0
+ $IPTABLES -A Cid3EE24E9C.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3EE24E9C.0 -d 222.222.222.222 -j ACCEPT
+ $IPTABLES -N Cid3EE24E9C.1
+ $IPTABLES -A OUTPUT -s 192.168.1.1 -m state --state NEW -j Cid3EE24E9C.1
+ $IPTABLES -A OUTPUT -s 222.222.222.222 -m state --state NEW -j Cid3EE24E9C.1
+ $IPTABLES -A Cid3EE24E9C.1 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3EE24E9C.1 -d 222.222.222.222 -j ACCEPT
+ $IPTABLES -N Cid3EE24E9C.2
+ $IPTABLES -A OUTPUT -s 192.168.1.1 -m state --state NEW -j Cid3EE24E9C.2
+ $IPTABLES -A OUTPUT -s 222.222.222.222 -m state --state NEW -j Cid3EE24E9C.2
+ $IPTABLES -A Cid3EE24E9C.2 -d 33.33.33.33 -j ACCEPT
+ $IPTABLES -A Cid3EE24E9C.2 -d 172.16.1.1 -j ACCEPT
+ $IPTABLES -A Cid3EE24E9C.2 -d 192.168.100.1 -j ACCEPT
+ $IPTABLES -N Cid3EE24E9C.3
+ $IPTABLES -A INPUT -d 192.168.1.1 -m state --state NEW -j Cid3EE24E9C.3
+ $IPTABLES -A INPUT -d 222.222.222.222 -m state --state NEW -j Cid3EE24E9C.3
+ $IPTABLES -A Cid3EE24E9C.3 -s 33.33.33.33 -j ACCEPT
+ $IPTABLES -A Cid3EE24E9C.3 -s 172.16.1.1 -j ACCEPT
+ $IPTABLES -A Cid3EE24E9C.3 -s 192.168.100.1 -j ACCEPT
+ $IPTABLES -N Cid3EE24E9C.4
+ $IPTABLES -A FORWARD -s 33.33.33.33 -m state --state NEW -j Cid3EE24E9C.4
+ $IPTABLES -A FORWARD -s 172.16.1.1 -m state --state NEW -j Cid3EE24E9C.4
+ $IPTABLES -A FORWARD -s 192.168.100.1 -m state --state NEW -j Cid3EE24E9C.4
+ $IPTABLES -A Cid3EE24E9C.4 -d 33.33.33.33 -j ACCEPT
+ $IPTABLES -A Cid3EE24E9C.4 -d 172.16.1.1 -j ACCEPT
+ $IPTABLES -A Cid3EE24E9C.4 -d 192.168.100.1 -j ACCEPT
+ #
+ # Rule 29 (global)
+ #
+ echo "Rule 29 (global)"
+ #
+ $IPTABLES -A FORWARD -m mac --mac-source 00:10:4b:de:e9:6f -s 192.168.1.10 -d 192.168.1.10 -m state --state NEW -j ACCEPT
+ #
+ # Rule 30 (global)
+ #
+ echo "Rule 30 (global)"
+ #
+ $IPTABLES -N Cid3E0AA611.0
+ $IPTABLES -A INPUT -m mac --mac-source 00:10:4b:de:e9:6f -s 192.168.1.10 -m state --state NEW -j Cid3E0AA611.0
+ $IPTABLES -A Cid3E0AA611.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3E0AA611.0 -d 222.222.222.222 -j ACCEPT
+ #
+ # Rule 31 (global)
+ #
+ echo "Rule 31 (global)"
+ #
+ $IPTABLES -A FORWARD -m mac --mac-source 00:10:4b:de:e9:70 -d 192.168.1.10 -m state --state NEW -j ACCEPT
+ #
+ # Rule 32 (global)
+ #
+ echo "Rule 32 (global)"
+ #
+ $IPTABLES -N Cid3E0AA504.0
+ $IPTABLES -A INPUT -m mac --mac-source 00:10:4b:de:e9:70 -m state --state NEW -j Cid3E0AA504.0
+ $IPTABLES -A Cid3E0AA504.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3E0AA504.0 -d 222.222.222.222 -j ACCEPT
+ #
+ # Rule 33 (global)
+ #
+ echo "Rule 33 (global)"
+ #
+ $IPTABLES -A FORWARD -m mac --mac-source 00:10:4b:de:e9:70 -d 200.200.200.200 -m state --state NEW -j ACCEPT
+ #
+ # Rule 34 (global)
+ #
+ echo "Rule 34 (global)"
+ #
+ $IPTABLES -N Cid3E0F40D5.0
+ $IPTABLES -A INPUT -m mac --mac-source aa:bb:cc:dd:ee:ff -s 192.168.1.15 -m state --state NEW -j Cid3E0F40D5.0
+ $IPTABLES -A Cid3E0F40D5.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3E0F40D5.0 -d 222.222.222.222 -j ACCEPT
+ #
+ # Rule 35 (global)
+ #
+ echo "Rule 35 (global)"
+ #
+ $IPTABLES -N Cid3E0F452C.0
+ $IPTABLES -A INPUT -m mac --mac-source aa:bb:cc:dd:ee:ff -m state --state NEW -j Cid3E0F452C.0
+ $IPTABLES -A Cid3E0F452C.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3E0F452C.0 -d 222.222.222.222 -j ACCEPT
+ #
+ # Rule 36 (global)
+ #
+ echo "Rule 36 (global)"
+ #
+ $IPTABLES -N Cid3DB0B422.0
+ $IPTABLES -A FORWARD -d 192.168.1.10 -m state --state NEW -j Cid3DB0B422.0
+ $IPTABLES -A Cid3DB0B422.0 -m mac --mac-source 00:10:4b:de:e9:70 -j ACCEPT
+ $IPTABLES -A Cid3DB0B422.0 -m mac --mac-source 00:10:4b:de:e9:71 -j ACCEPT
+ # firewall:Policy:36: warning: Empty MAC address in rule
+ $IPTABLES -A Cid3DB0B422.0 -m mac --mac-source 00:00:00:00:00:00 -j ACCEPT
+ $IPTABLES -A Cid3DB0B422.0 -m mac --mac-source 00:10:4b:de:e9:6f -s 192.168.1.10 -j ACCEPT
+ #
+ # Rule 37 (global)
+ #
+ echo "Rule 37 (global)"
+ #
+ $IPTABLES -N Cid3DB0B628.0
+ $IPTABLES -A FORWARD -d 192.168.1.10 -m state --state NEW -j Cid3DB0B628.0
+ $IPTABLES -A Cid3DB0B628.0 -m mac --mac-source 00:10:4b:de:e9:70 -j ACCEPT
+ $IPTABLES -A Cid3DB0B628.0 -m mac --mac-source 00:10:4b:de:e9:71 -j ACCEPT
+ # firewall:Policy:37: warning: Empty MAC address in rule
+ $IPTABLES -A Cid3DB0B628.0 -m mac --mac-source 00:00:00:00:00:00 -j ACCEPT
+ $IPTABLES -A Cid3DB0B628.0 -m mac --mac-source 00:10:4b:de:e9:6f -s 192.168.1.10 -j ACCEPT
+ $IPTABLES -A Cid3DB0B628.0 -s 192.168.1.20 -j ACCEPT
+ #
+ # Rule 38 (global)
+ #
+ echo "Rule 38 (global)"
+ #
+ $IPTABLES -N Cid3DE474B7.0
+ $IPTABLES -A FORWARD -p tcp -m tcp --sport 53 -d 192.168.1.10 -m state --state NEW -j Cid3DE474B7.0
+ $IPTABLES -A Cid3DE474B7.0 -m mac --mac-source 00:10:4b:de:e9:70 -j ACCEPT
+ $IPTABLES -A Cid3DE474B7.0 -m mac --mac-source 00:10:4b:de:e9:71 -j ACCEPT
+ # firewall:Policy:38: warning: Empty MAC address in rule
+ $IPTABLES -A Cid3DE474B7.0 -m mac --mac-source 00:00:00:00:00:00 -j ACCEPT
+ $IPTABLES -A Cid3DE474B7.0 -m mac --mac-source 00:10:4b:de:e9:6f -s 192.168.1.10 -j ACCEPT
+ #
+ # Rule 39 (global)
+ #
+ echo "Rule 39 (global)"
+ #
+ $IPTABLES -N Cpol-firewall2-2.0
+ $IPTABLES -A FORWARD -p tcp -m tcp -d 192.168.1.10 --dport 10000:11000 -m state --state NEW -j Cpol-firewall2-2.0
+ $IPTABLES -A FORWARD -p tcp -m tcp -m multiport -d 192.168.1.10 --dports 6667,3128,113,53,21,80,119,25,22,23,540,70,13,2105,443 -m state --state NEW -j Cpol-firewall2-2.0
+ $IPTABLES -A FORWARD -p tcp -m tcp -m multiport -d 192.168.1.10 --dports 143,993,6667,543,544,389,98,3306,2049,110,5432,515,26000,512,513 -m state --state NEW -j Cpol-firewall2-2.0
+ $IPTABLES -A FORWARD -p tcp -m tcp -m multiport -d 192.168.1.10 --dports 514,4321,465,1080,111,7100 -m state --state NEW -j Cpol-firewall2-2.0
+ $IPTABLES -A Cpol-firewall2-2.0 -m mac --mac-source 00:10:4b:de:e9:70 -j ACCEPT
+ $IPTABLES -A Cpol-firewall2-2.0 -m mac --mac-source 00:10:4b:de:e9:71 -j ACCEPT
+ # firewall:Policy:39: warning: Empty MAC address in rule
+ $IPTABLES -A Cpol-firewall2-2.0 -m mac --mac-source 00:00:00:00:00:00 -j ACCEPT
+ $IPTABLES -A Cpol-firewall2-2.0 -m mac --mac-source 00:10:4b:de:e9:6f -s 192.168.1.10 -j ACCEPT
+ #
+ # Rule 40 (global)
+ #
+ echo "Rule 40 (global)"
+ #
+ $IPTABLES -N Cid445FAA6D31658.0
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 80 -m state --state NEW -j Cid445FAA6D31658.0
+ $IPTABLES -A Cid445FAA6D31658.0 -m mac --mac-source 00:10:4b:de:e9:70 -j ACCEPT
+ $IPTABLES -A Cid445FAA6D31658.0 -m mac --mac-source 00:10:4b:de:e9:71 -j ACCEPT
+ # firewall:Policy:40: warning: Empty MAC address in rule
+ $IPTABLES -A Cid445FAA6D31658.0 -m mac --mac-source 00:00:00:00:00:00 -j ACCEPT
+ $IPTABLES -A Cid445FAA6D31658.0 -m mac --mac-source 00:10:4b:de:e9:6f -s 192.168.1.10 -j ACCEPT
+ $IPTABLES -N Cid445FAA6D31658.1
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 80 -m state --state NEW -j Cid445FAA6D31658.1
+ $IPTABLES -A Cid445FAA6D31658.1 -m mac --mac-source 00:10:4b:de:e9:70 -j ACCEPT
+ $IPTABLES -A Cid445FAA6D31658.1 -m mac --mac-source 00:10:4b:de:e9:71 -j ACCEPT
+ # firewall:Policy:40: warning: Empty MAC address in rule
+ $IPTABLES -A Cid445FAA6D31658.1 -m mac --mac-source 00:00:00:00:00:00 -j ACCEPT
+ $IPTABLES -A Cid445FAA6D31658.1 -m mac --mac-source 00:10:4b:de:e9:6f -s 192.168.1.10 -j ACCEPT
+ #
+ # Rule 41 (global)
+ #
+ echo "Rule 41 (global)"
+ #
+ # firewall:Policy:41: warning: Can not match MAC address of the firewall (chain OUTPUT)
+ $IPTABLES -A OUTPUT -s 192.168.1.1 -d 192.168.1.10 -m state --state NEW -j ACCEPT
+ #
+ # Rule 42 (global)
+ #
+ echo "Rule 42 (global)"
+ #
+ $IPTABLES -N Cpol-firewall2-3.0
+ $IPTABLES -A FORWARD -d 192.168.1.10 -m state --state NEW -j Cpol-firewall2-3.0
+ $IPTABLES -N Cpol-firewall2-3.1
+ $IPTABLES -A Cpol-firewall2-3.0 -s 211.11.11.11 -j Cpol-firewall2-3.1
+ $IPTABLES -A Cpol-firewall2-3.0 -s 211.22.22.22 -j Cpol-firewall2-3.1
+ $IPTABLES -N RULE_42
+ $IPTABLES -A Cpol-firewall2-3.1 -m time --timestart 18:00 --timestop 23:59 -j RULE_42
+ $IPTABLES -A Cpol-firewall2-3.1 -m time --timestart 00:00 --timestop 23:59 --days Sat -j RULE_42
+ $IPTABLES -A Cpol-firewall2-3.1 -m time --timestart 00:00 --timestop 23:59 --days Sun -j RULE_42
+ $IPTABLES -A Cpol-firewall2-3.1 -m time --timestart 01:01 --timestop 02:02 --days Sun,Mon -j RULE_42
+ $IPTABLES -A RULE_42 -m limit --limit 5/second -j LOG --log-level 7 --log-prefix "CUSTOM LOGGING"
+ $IPTABLES -A RULE_42 -j ACCEPT
+ #
+ # Rule 43 (global)
+ #
+ echo "Rule 43 (global)"
+ #
+ $IPTABLES -N Cid3FB8455E.0
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 10000:11000 -m state --state NEW -j Cid3FB8455E.0
+ $IPTABLES -A FORWARD -p tcp -m tcp -m multiport --dports 6667,3128,113,53,21,80,119,25,22,23,540,70,13,2105,443 -m state --state NEW -j Cid3FB8455E.0
+ $IPTABLES -A FORWARD -p tcp -m tcp -m multiport --dports 143,993,6667,543,544,389,98,3306,2049,110,5432,515,26000,512,513 -m state --state NEW -j Cid3FB8455E.0
+ $IPTABLES -A FORWARD -p tcp -m tcp -m multiport --dports 514,4321,465,1080,111,7100 -m state --state NEW -j Cid3FB8455E.0
+ $IPTABLES -N Cid3FB8455E.1
+ $IPTABLES -A Cid3FB8455E.0 -s 211.11.11.11 -j Cid3FB8455E.1
+ $IPTABLES -A Cid3FB8455E.0 -s 211.22.22.22 -j Cid3FB8455E.1
+ $IPTABLES -A Cid3FB8455E.1 -d 192.168.1.10 -j ACCEPT
+ $IPTABLES -A Cid3FB8455E.1 -d 192.168.1.20 -j ACCEPT
+ #
+ # Rule 44 (global)
+ #
+ echo "Rule 44 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp --sport 1024:65535 -d 192.168.1.10 --dport 80 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp --sport 1024:65535 -d 192.168.1.10 --dport 80 -m state --state NEW -j ACCEPT
+ #
+ # Rule 45 (global)
+ #
+ echo "Rule 45 (global)"
+ #
+ # Rule #20 test: from Rock
+ $IPTABLES -A OUTPUT -p tcp -m tcp --sport 1024:65535 -d 192.168.1.10 --dport 80 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp --sport 53 -d 192.168.1.10 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp -m multiport -d 192.168.1.10 --dports 53,3128 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp --sport 1024:65535 -d 192.168.1.10 --dport 80 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp --sport 53 -d 192.168.1.10 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -m multiport -d 192.168.1.10 --dports 53,3128 -m state --state NEW -j ACCEPT
+ #
+ # Rule 46 (global)
+ #
+ echo "Rule 46 (global)"
+ #
+ $IPTABLES -N Cpol-firewall2-4.0
+ $IPTABLES -A OUTPUT -d 192.168.1.0/24 -m state --state NEW -j Cpol-firewall2-4.0
+ $IPTABLES -A Cpol-firewall2-4.0 -p icmp -m icmp --icmp-type 11/0 -j ACCEPT
+ $IPTABLES -A Cpol-firewall2-4.0 -p icmp -m icmp --icmp-type 11/1 -j ACCEPT
+ $IPTABLES -A Cpol-firewall2-4.0 -p icmp -m icmp --icmp-type 0/0 -j ACCEPT
+ $IPTABLES -A Cpol-firewall2-4.0 -p icmp -m icmp --icmp-type 3 -j ACCEPT
+ $IPTABLES -A Cpol-firewall2-4.0 -m ip_conntrack_talk -m ip_nat_talk -j ACCEPT
+ $IPTABLES -N Cpol-firewall2-4.1
+ $IPTABLES -A INPUT -d 192.168.1.0/24 -m state --state NEW -j Cpol-firewall2-4.1
+ $IPTABLES -A Cpol-firewall2-4.1 -p icmp -m icmp --icmp-type 11/0 -j ACCEPT
+ $IPTABLES -A Cpol-firewall2-4.1 -p icmp -m icmp --icmp-type 11/1 -j ACCEPT
+ $IPTABLES -A Cpol-firewall2-4.1 -p icmp -m icmp --icmp-type 0/0 -j ACCEPT
+ $IPTABLES -A Cpol-firewall2-4.1 -p icmp -m icmp --icmp-type 3 -j ACCEPT
+ $IPTABLES -A Cpol-firewall2-4.1 -m ip_conntrack_talk -m ip_nat_talk -j ACCEPT
+ $IPTABLES -N Cpol-firewall2-4.2
+ $IPTABLES -A FORWARD -d 192.168.1.0/24 -m state --state NEW -j Cpol-firewall2-4.2
+ $IPTABLES -A Cpol-firewall2-4.2 -p icmp -m icmp --icmp-type 11/0 -j ACCEPT
+ $IPTABLES -A Cpol-firewall2-4.2 -p icmp -m icmp --icmp-type 11/1 -j ACCEPT
+ $IPTABLES -A Cpol-firewall2-4.2 -p icmp -m icmp --icmp-type 0/0 -j ACCEPT
+ $IPTABLES -A Cpol-firewall2-4.2 -p icmp -m icmp --icmp-type 3 -j ACCEPT
+ $IPTABLES -A Cpol-firewall2-4.2 -m ip_conntrack_talk -m ip_nat_talk -j ACCEPT
+ #
+ # Rule 47 (global)
+ #
+ echo "Rule 47 (global)"
+ #
+ $IPTABLES -N Cid3CD8770E.0
+ $IPTABLES -A OUTPUT -d 192.168.1.11 -m state --state NEW -j Cid3CD8770E.0
+ $IPTABLES -A OUTPUT -d 192.168.1.12/30 -m state --state NEW -j Cid3CD8770E.0
+ $IPTABLES -A Cid3CD8770E.0 -p tcp -m tcp -m multiport --dports 113,80,25,22,540,443,143 -j ACCEPT
+ $IPTABLES -A Cid3CD8770E.0 -m ip_conntrack_talk -m ip_nat_talk -j ACCEPT
+ $IPTABLES -N Cid3CD8770E.1
+ $IPTABLES -A INPUT -d 192.168.1.11 -m state --state NEW -j Cid3CD8770E.1
+ $IPTABLES -A INPUT -d 192.168.1.12/30 -m state --state NEW -j Cid3CD8770E.1
+ $IPTABLES -A Cid3CD8770E.1 -p tcp -m tcp -m multiport --dports 113,80,25,22,540,443,143 -j ACCEPT
+ $IPTABLES -A Cid3CD8770E.1 -m ip_conntrack_talk -m ip_nat_talk -j ACCEPT
+ $IPTABLES -N Cid3CD8770E.2
+ $IPTABLES -A FORWARD -d 192.168.1.11 -m state --state NEW -j Cid3CD8770E.2
+ $IPTABLES -A FORWARD -d 192.168.1.12/30 -m state --state NEW -j Cid3CD8770E.2
+ $IPTABLES -A Cid3CD8770E.2 -p tcp -m tcp -m multiport --dports 113,80,25,22,540,443,143 -j ACCEPT
+ $IPTABLES -A Cid3CD8770E.2 -m ip_conntrack_talk -m ip_nat_talk -j ACCEPT
+ #
+ # Rule 48 (global)
+ #
+ echo "Rule 48 (global)"
+ #
+ $IPTABLES -N Cid3CD87B1E.0
+ $IPTABLES -A OUTPUT -d 192.168.1.11 -m state --state NEW -j Cid3CD87B1E.0
+ $IPTABLES -A OUTPUT -d 192.168.1.12 -m state --state NEW -j Cid3CD87B1E.0
+ $IPTABLES -A OUTPUT -d 192.168.1.13 -m state --state NEW -j Cid3CD87B1E.0
+ $IPTABLES -A OUTPUT -d 192.168.1.14 -m state --state NEW -j Cid3CD87B1E.0
+ $IPTABLES -A OUTPUT -d 192.168.1.15 -m state --state NEW -j Cid3CD87B1E.0
+ $IPTABLES -A Cid3CD87B1E.0 -p tcp -m tcp -m multiport --dports 113,80,25,22,540,443,143 -j ACCEPT
+ $IPTABLES -A Cid3CD87B1E.0 -m ip_conntrack_talk -m ip_nat_talk -j ACCEPT
+ $IPTABLES -N Cid3CD87B1E.1
+ $IPTABLES -A FORWARD -d 192.168.1.11 -m state --state NEW -j Cid3CD87B1E.1
+ $IPTABLES -A FORWARD -d 192.168.1.12 -m state --state NEW -j Cid3CD87B1E.1
+ $IPTABLES -A FORWARD -d 192.168.1.13 -m state --state NEW -j Cid3CD87B1E.1
+ $IPTABLES -A FORWARD -d 192.168.1.14 -m state --state NEW -j Cid3CD87B1E.1
+ $IPTABLES -A FORWARD -d 192.168.1.15 -m state --state NEW -j Cid3CD87B1E.1
+ $IPTABLES -A Cid3CD87B1E.1 -p tcp -m tcp -m multiport --dports 113,80,25,22,540,443,143 -j ACCEPT
+ $IPTABLES -A Cid3CD87B1E.1 -m ip_conntrack_talk -m ip_nat_talk -j ACCEPT
+ #
+ # Rule 49 (global)
+ #
+ echo "Rule 49 (global)"
+ #
+ # group "special combined srv"
+ # has couple of UDP services,
+ # plus "ALL UDP" service, which has
+ # empty ports specs. This is special
+ # case for multiport.
+ $IPTABLES -N Cid3E1FD93A.0
+ $IPTABLES -A INPUT -p udp -m udp -s 192.168.1.0/24 -m state --state NEW -j Cid3E1FD93A.0
+ $IPTABLES -A INPUT -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -m state --state NEW -j Cid3E1FD93A.0
+ $IPTABLES -A Cid3E1FD93A.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3E1FD93A.0 -d 222.222.222.222 -j ACCEPT
+ #
+ # Rule 50 (global)
+ #
+ echo "Rule 50 (global)"
+ #
+ # another test case for multiport: this rule
+ # has 16 TCP services and should be split onto
+ # two rules. If both rules use "-m multiport", then
+ # rule with a single service should use "--dports".
+ # It may be acceptable to not use multiport
+ # in the rule with a single service at all.
+ $IPTABLES -N Cid41D0F052.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 10000:11000 -m state --state NEW -j Cid41D0F052.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -m multiport -s 192.168.1.0/24 --dports 6667,3128,113,53,21,80,119,25,22,23,540,70,13,2105,443 -m state --state NEW -j Cid41D0F052.0
+ $IPTABLES -N RULE_50
+ $IPTABLES -A Cid41D0F052.0 -d 192.168.1.11 -j RULE_50
+ $IPTABLES -A Cid41D0F052.0 -d 192.168.1.12/30 -j RULE_50
+ $IPTABLES -N Cid41D0F052.1
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 10000:11000 -m state --state NEW -j Cid41D0F052.1
+ $IPTABLES -A INPUT -p tcp -m tcp -m multiport -s 192.168.1.0/24 --dports 6667,3128,113,53,21,80,119,25,22,23,540,70,13,2105,443 -m state --state NEW -j Cid41D0F052.1
+ $IPTABLES -A Cid41D0F052.1 -d 192.168.1.11 -j RULE_50
+ $IPTABLES -A Cid41D0F052.1 -d 192.168.1.12/30 -j RULE_50
+ $IPTABLES -N Cid41D0F052.2
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 --dport 10000:11000 -m state --state NEW -j Cid41D0F052.2
+ $IPTABLES -A FORWARD -p tcp -m tcp -m multiport -s 192.168.1.0/24 --dports 6667,3128,113,53,21,80,119,25,22,23,540,70,13,2105,443 -m state --state NEW -j Cid41D0F052.2
+ $IPTABLES -A Cid41D0F052.2 -d 192.168.1.11 -j RULE_50
+ $IPTABLES -A Cid41D0F052.2 -d 192.168.1.12/30 -j RULE_50
+ $IPTABLES -A RULE_50 -m limit --limit 5/second -j LOG --log-level 7 --log-prefix "CUSTOM LOGGING"
+ $IPTABLES -A RULE_50 -j ACCEPT
+ #
+ # Rule 51 (global)
+ #
+ echo "Rule 51 (global)"
+ #
+ $IPTABLES -N Cid3B58E180.0
+ $IPTABLES -A INPUT -s 192.168.1.1 -m state --state NEW -j Cid3B58E180.0
+ $IPTABLES -A INPUT -s 222.222.222.222 -m state --state NEW -j Cid3B58E180.0
+ $IPTABLES -N RULE_51
+ $IPTABLES -A Cid3B58E180.0 -d 192.168.1.1 -j RULE_51
+ $IPTABLES -A Cid3B58E180.0 -d 222.222.222.222 -j RULE_51
+ $IPTABLES -N Cid3B58E180.1
+ $IPTABLES -A OUTPUT -s 192.168.1.1 -m state --state NEW -j Cid3B58E180.1
+ $IPTABLES -A OUTPUT -s 222.222.222.222 -m state --state NEW -j Cid3B58E180.1
+ $IPTABLES -A Cid3B58E180.1 -d 192.168.1.1 -j RULE_51
+ $IPTABLES -A Cid3B58E180.1 -d 222.222.222.222 -j RULE_51
+ $IPTABLES -A RULE_51 -m limit --limit 5/second -j LOG --log-level 7 --log-prefix "CUSTOM LOGGING"
+ $IPTABLES -A RULE_51 -j ACCEPT
+ #
+ # Rule 52 (global)
+ #
+ echo "Rule 52 (global)"
+ #
+ $IPTABLES -N Cid3D41A4F4.0
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid3D41A4F4.0
+ $IPTABLES -N Cid3D41A4F4.1
+ $IPTABLES -A Cid3D41A4F4.0 -s 192.168.1.1 -j Cid3D41A4F4.1
+ $IPTABLES -A Cid3D41A4F4.0 -s 222.222.222.222 -j Cid3D41A4F4.1
+ $IPTABLES -A Cid3D41A4F4.1 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3D41A4F4.1 -d 222.222.222.222 -j ACCEPT
+ $IPTABLES -N Cid3D41A4F4.2
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid3D41A4F4.2
+ $IPTABLES -N Cid3D41A4F4.3
+ $IPTABLES -A Cid3D41A4F4.2 -s 192.168.1.1 -j Cid3D41A4F4.3
+ $IPTABLES -A Cid3D41A4F4.2 -s 222.222.222.222 -j Cid3D41A4F4.3
+ $IPTABLES -A Cid3D41A4F4.3 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3D41A4F4.3 -d 222.222.222.222 -j ACCEPT
+ $IPTABLES -N Cid3D41A4F4.4
+ $IPTABLES -A OUTPUT -p udp -m udp -d 200.200.200.200 --dport 161 -m state --state NEW -j Cid3D41A4F4.4
+ $IPTABLES -A Cid3D41A4F4.4 -s 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3D41A4F4.4 -s 222.222.222.222 -j ACCEPT
+ #
+ # Rule 53 (global)
+ #
+ echo "Rule 53 (global)"
+ #
+ # Automatically generated 'masquerading' rule
+ $IPTABLES -A INPUT -s 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -s 222.222.222.222 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 222.222.222.222 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 54 (global)
+ #
+ echo "Rule 54 (global)"
+ #
+ # similar to a standard 'masquerading'
+ # rule, but not so permissive as it does
+ # not allow access to the firewall
+ $IPTABLES -N Cid3CE894DA.0
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j Cid3CE894DA.0
+ $IPTABLES -A Cid3CE894DA.0 -d 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid3CE894DA.0 -d 222.222.222.222 -j RETURN
+ $IPTABLES -A Cid3CE894DA.0 -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 55 (global)
+ #
+ echo "Rule 55 (global)"
+ #
+ $IPTABLES -N Cid40F1CFA3.0
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j Cid40F1CFA3.0
+ $IPTABLES -A Cid40F1CFA3.0 -d 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid40F1CFA3.0 -d 222.222.222.222 -j RETURN
+ $IPTABLES -A Cid40F1CFA3.0 -j ACCEPT
+ $IPTABLES -N Cid40F1CFA3.1
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j Cid40F1CFA3.1
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j Cid40F1CFA3.1
+ $IPTABLES -A Cid40F1CFA3.1 -d 33.33.33.0/24 -j RETURN
+ $IPTABLES -A Cid40F1CFA3.1 -j ACCEPT
+ #
+ # Rule 56 (global)
+ #
+ echo "Rule 56 (global)"
+ #
+ $IPTABLES -N Cid413D6500.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 10000:11000 -m state --state NEW -j Cid413D6500.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 113 -m state --state NEW -j Cid413D6500.0
+ $IPTABLES -A OUTPUT -p udp -m udp -m multiport --dports 53,161 -m state --state NEW -j Cid413D6500.0
+ $IPTABLES -N Cid413D6500.1
+ $IPTABLES -A Cid413D6500.0 -s 192.168.1.0/24 -j Cid413D6500.1
+ $IPTABLES -A Cid413D6500.0 -s 192.168.2.0/24 -j Cid413D6500.1
+ $IPTABLES -A Cid413D6500.1 -d 192.168.1.0/24 -j ACCEPT
+ $IPTABLES -A Cid413D6500.1 -d 192.168.2.0/24 -j ACCEPT
+ $IPTABLES -N Cid413D6500.2
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 10000:11000 -m state --state NEW -j Cid413D6500.2
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 113 -m state --state NEW -j Cid413D6500.2
+ $IPTABLES -A INPUT -p udp -m udp -m multiport --dports 53,161 -m state --state NEW -j Cid413D6500.2
+ $IPTABLES -N Cid413D6500.3
+ $IPTABLES -A Cid413D6500.2 -s 192.168.1.0/24 -j Cid413D6500.3
+ $IPTABLES -A Cid413D6500.2 -s 192.168.2.0/24 -j Cid413D6500.3
+ $IPTABLES -A Cid413D6500.3 -d 192.168.1.0/24 -j ACCEPT
+ $IPTABLES -A Cid413D6500.3 -d 192.168.2.0/24 -j ACCEPT
+ $IPTABLES -N Cid413D6500.4
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 10000:11000 -m state --state NEW -j Cid413D6500.4
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 113 -m state --state NEW -j Cid413D6500.4
+ $IPTABLES -A FORWARD -p udp -m udp -m multiport --dports 53,161 -m state --state NEW -j Cid413D6500.4
+ $IPTABLES -N Cid413D6500.5
+ $IPTABLES -A Cid413D6500.4 -s 192.168.1.0/24 -j Cid413D6500.5
+ $IPTABLES -A Cid413D6500.4 -s 192.168.2.0/24 -j Cid413D6500.5
+ $IPTABLES -A Cid413D6500.5 -d 192.168.1.0/24 -j ACCEPT
+ $IPTABLES -A Cid413D6500.5 -d 192.168.2.0/24 -j ACCEPT
+ #
+ # Rule 57 (global)
+ #
+ echo "Rule 57 (global)"
+ #
+ # Automatically generated 'catch all' rule
+ $IPTABLES -N RULE_57
+ $IPTABLES -A OUTPUT -j RULE_57
+ $IPTABLES -A INPUT -j RULE_57
+ $IPTABLES -A FORWARD -j RULE_57
+ $IPTABLES -A RULE_57 -m limit --limit 5/second -j LOG --log-level 7 --log-prefix "CUSTOM LOGGING"
+ $IPTABLES -A RULE_57 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+ # backup ssh access
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.100/255.255.255.255 --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.100/255.255.255.255 --sport 22 -m state --state ESTABLISHED,RELATED -j ACCEPT
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:53:22 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall1.fw.orig b/test/ipt/firewall1.fw.orig
new file mode 100755
index 000000000..ea5de3ba9
--- /dev/null
+++ b/test/ipt/firewall1.fw.orig
@@ -0,0 +1,1312 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:25 2011 PST by vadim
+#
+# files: * firewall1.fw
+#
+# Compiled for iptables (any version)
+#
+# this object is used to test all kinds of negation in policy and NAT rules.
+# Assume firewall is part of any is ON
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24 192.168.1.0/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24 22.22.22.23/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24 192.168.2.0/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth3 22.22.23.23/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop packets that do not match any valid state and log them
+ $IPTABLES -N drop_invalid
+ $IPTABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IPTABLES -A drop_invalid -j LOG --log-level debug --log-prefix "INVALID state -- DENY "
+ $IPTABLES -A drop_invalid -j DROP
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.0/24 -d 192.168.2.0/24 -j ACCEPT
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.0/24 -d 192.168.2.0/24 -j ACCEPT
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 22.22.22.23
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s ! 192.168.1.0/24 -d 200.200.200.200 -j SNAT --to-source 22.22.22.23
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -p tcp -m tcp -s ! 192.168.1.0/24 -d 200.200.200.200 --dport 80 -j SNAT --to-source 22.22.22.23
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.23
+ #
+ # Rule 6 (NAT)
+ #
+ echo "Rule 6 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -d ! 192.168.2.0/24 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -d ! 192.168.2.0/24 -j SNAT --to-source 22.22.23.23
+ #
+ # Rule 7 (NAT)
+ #
+ echo "Rule 7 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.0/24 -d ! 192.168.2.0/24 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p tcp -m tcp -s 192.168.1.0/24 -d ! 192.168.2.0/24 --dport 80 -j SNAT --to-source 22.22.23.23
+ #
+ # Rule 8 (NAT)
+ #
+ echo "Rule 8 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid3CCA1B57.0
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j Cid3CCA1B57.0
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j Cid3CCA1B57.0
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -j Cid3CCA1B57.0
+ $IPTABLES -t nat -A Cid3CCA1B57.0 -d 192.168.1.0/24 -j RETURN
+ $IPTABLES -t nat -A Cid3CCA1B57.0 -d 192.168.2.0/24 -j RETURN
+ $IPTABLES -t nat -A Cid3CCA1B57.0 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A Cid3CCA1B57.0 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A Cid3CCA1B57.0 -j SNAT --to-source 192.168.2.1
+ #
+ # Rule 9 (NAT)
+ #
+ echo "Rule 9 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid3EB38983.0
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j Cid3EB38983.0
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j Cid3EB38983.0
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -j Cid3EB38983.0
+ $IPTABLES -t nat -A Cid3EB38983.0 -d 192.168.1.0/24 -j RETURN
+ $IPTABLES -t nat -A Cid3EB38983.0 -d 192.168.2.0/24 -j RETURN
+ $IPTABLES -t nat -A Cid3EB38983.0 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A Cid3EB38983.0 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A Cid3EB38983.0 -j SNAT --to-source 192.168.2.1
+ #
+ # Rule 10 (NAT)
+ #
+ echo "Rule 10 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s ! 192.168.2.0/24 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s ! 192.168.2.0/24 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s ! 192.168.2.0/24 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 11 (NAT)
+ #
+ echo "Rule 11 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid3BD8D94B.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j Cid3BD8D94B.0
+ $IPTABLES -t nat -A Cid3BD8D94B.0 -d 22.22.22.22 -j RETURN
+ $IPTABLES -t nat -A Cid3BD8D94B.0 -d 22.22.23.23 -j RETURN
+ $IPTABLES -t nat -A Cid3BD8D94B.0 -d 192.168.1.1 -j RETURN
+ $IPTABLES -t nat -A Cid3BD8D94B.0 -d 192.168.2.1 -j RETURN
+ $IPTABLES -t nat -A Cid3BD8D94B.0 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
+ #
+ # Rule 12 (NAT)
+ #
+ echo "Rule 12 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid3BD8D9DD.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j Cid3BD8D9DD.0
+ $IPTABLES -t nat -A Cid3BD8D9DD.0 -d 192.168.1.1 -j RETURN
+ $IPTABLES -t nat -A Cid3BD8D9DD.0 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
+ #
+ # Rule 13 (NAT)
+ #
+ echo "Rule 13 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid3BBC0EA4.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.10 --dport 80 -j Cid3BBC0EA4.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.20 --dport 80 -j Cid3BBC0EA4.0
+ $IPTABLES -t nat -A Cid3BBC0EA4.0 -d 192.168.1.0/24 -j RETURN
+ $IPTABLES -t nat -A Cid3BBC0EA4.0 -d 192.168.2.0/24 -j RETURN
+ $IPTABLES -t nat -A Cid3BBC0EA4.0 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
+ #
+ # Rule 14 (NAT)
+ #
+ echo "Rule 14 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid3BBC0F93.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.0/24 --dport 80 -j Cid3BBC0F93.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.0/24 --dport 80 -j Cid3BBC0F93.0
+ $IPTABLES -t nat -A Cid3BBC0F93.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid3BBC0F93.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid3BBC0F93.0 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
+ #
+ # Rule 15 (NAT)
+ #
+ echo "Rule 15 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s ! 192.168.1.10 --dport 80 -j REDIRECT --to-ports 3128
+ #
+ # Rule 16 (NAT)
+ #
+ echo "Rule 16 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --sport 5000 -d 22.22.22.23 --dport 5000:5010 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.23 --dport 4000:4010 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --sport 9000 -d 22.22.22.23 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 22.22.22.23 --dports 6667,3128 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 17 (NAT)
+ #
+ echo "Rule 17 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.0/24 --dport 80 -j DNAT --to-destination :3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.0/24 --dport 80 -j DNAT --to-destination :3128
+ #
+ # Rule 18 (NAT)
+ #
+ echo "Rule 18 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid3EB38A91.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j Cid3EB38A91.0
+ $IPTABLES -t nat -A Cid3EB38A91.0 -d 192.168.1.0/24 -j RETURN
+ $IPTABLES -t nat -A Cid3EB38A91.0 -d 192.168.2.0/24 -j RETURN
+ $IPTABLES -t nat -A Cid3EB38A91.0 -p tcp -m tcp --dport 80 -j DNAT --to-destination :3128
+
+
+
+ # ================ Table 'filter', rule set GOOD_GUYS
+ #
+ # Rule GOOD_GUYS 0 (global)
+ #
+ echo "Rule GOOD_GUYS 0 (global)"
+ #
+ $IPTABLES -N GOOD_GUYS
+ $IPTABLES -N Cid40710X74808.0
+ $IPTABLES -A GOOD_GUYS -j Cid40710X74808.0
+ $IPTABLES -A Cid40710X74808.0 -s 1.1.1.0/24 -j RETURN
+ $IPTABLES -A Cid40710X74808.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -N GOOD_GUYS_0_3
+ $IPTABLES -A Cid40710X74808.0 -j GOOD_GUYS_0_3
+ $IPTABLES -A GOOD_GUYS_0_3 -j LOG --log-level debug
+ $IPTABLES -A GOOD_GUYS_0_3 -j DROP
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -N Cid3C5987DC.1
+ $IPTABLES -A INPUT -i eth0 -s 22.22.22.22 -j Cid3C5987DC.1
+ $IPTABLES -N Cid3C5987DC.0
+ $IPTABLES -A Cid3C5987DC.1 -p icmp -j Cid3C5987DC.0
+ $IPTABLES -A Cid3C5987DC.1 -p 50 -j Cid3C5987DC.0
+ $IPTABLES -N Cid3C5987DC.2
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.1 -j Cid3C5987DC.2
+ $IPTABLES -A Cid3C5987DC.2 -p icmp -j Cid3C5987DC.0
+ $IPTABLES -A Cid3C5987DC.2 -p 50 -j Cid3C5987DC.0
+ $IPTABLES -N Cid3C5987DC.3
+ $IPTABLES -A FORWARD -i eth0 -s 22.22.22.22 -j Cid3C5987DC.3
+ $IPTABLES -A Cid3C5987DC.3 -p icmp -j Cid3C5987DC.0
+ $IPTABLES -A Cid3C5987DC.3 -p 50 -j Cid3C5987DC.0
+ $IPTABLES -N Cid3C5987DC.4
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.1 -j Cid3C5987DC.4
+ $IPTABLES -A Cid3C5987DC.4 -p icmp -j Cid3C5987DC.0
+ $IPTABLES -A Cid3C5987DC.4 -p 50 -j Cid3C5987DC.0
+ $IPTABLES -A Cid3C5987DC.0 -d 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid3C5987DC.0 -d 192.168.1.1 -j RETURN
+ $IPTABLES -N In_RULE_0_3
+ $IPTABLES -A Cid3C5987DC.0 -m hashlimit --hashlimit 1/hour --hashlimit-burst 2 --hashlimit-mode srcip,srcport --hashlimit-name htable_rule_0 -j In_RULE_0_3
+ $IPTABLES -A In_RULE_0_3 -j LOG --log-level debug
+ $IPTABLES -A In_RULE_0_3 -j DROP
+ $IPTABLES -N Cid3C5987DC.6
+ $IPTABLES -A OUTPUT -o eth0 -s 22.22.22.22 -j Cid3C5987DC.6
+ $IPTABLES -N Cid3C5987DC.5
+ $IPTABLES -A Cid3C5987DC.6 -p icmp -j Cid3C5987DC.5
+ $IPTABLES -A Cid3C5987DC.6 -p 50 -j Cid3C5987DC.5
+ $IPTABLES -N Cid3C5987DC.7
+ $IPTABLES -A OUTPUT -o eth0 -s 192.168.1.1 -j Cid3C5987DC.7
+ $IPTABLES -A Cid3C5987DC.7 -p icmp -j Cid3C5987DC.5
+ $IPTABLES -A Cid3C5987DC.7 -p 50 -j Cid3C5987DC.5
+ $IPTABLES -A Cid3C5987DC.5 -d 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid3C5987DC.5 -d 192.168.1.1 -j RETURN
+ $IPTABLES -N Out_RULE_0_3
+ $IPTABLES -A Cid3C5987DC.5 -m hashlimit --hashlimit 1/hour --hashlimit-burst 2 --hashlimit-mode srcip,srcport --hashlimit-name htable_rule_0 -j Out_RULE_0_3
+ $IPTABLES -A Out_RULE_0_3 -j LOG --log-level debug
+ $IPTABLES -A Out_RULE_0_3 -j DROP
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ $IPTABLES -N Cid3CD34BEF.1
+ $IPTABLES -A INPUT -i eth0 -p icmp -j Cid3CD34BEF.1
+ $IPTABLES -A INPUT -i eth0 -p 50 -j Cid3CD34BEF.1
+ $IPTABLES -N Cid3CD34BEF.0
+ $IPTABLES -A Cid3CD34BEF.1 -s 192.168.1.10 -j Cid3CD34BEF.0
+ $IPTABLES -A Cid3CD34BEF.1 -s 192.168.1.20 -j Cid3CD34BEF.0
+ $IPTABLES -N Cid3CD34BEF.2
+ $IPTABLES -A FORWARD -i eth0 -p icmp -j Cid3CD34BEF.2
+ $IPTABLES -A FORWARD -i eth0 -p 50 -j Cid3CD34BEF.2
+ $IPTABLES -A Cid3CD34BEF.2 -s 192.168.1.10 -j Cid3CD34BEF.0
+ $IPTABLES -A Cid3CD34BEF.2 -s 192.168.1.20 -j Cid3CD34BEF.0
+ $IPTABLES -A Cid3CD34BEF.0 -d 192.168.1.10 -j RETURN
+ $IPTABLES -A Cid3CD34BEF.0 -d 192.168.1.20 -j RETURN
+ $IPTABLES -A Cid3CD34BEF.0 -m hashlimit --hashlimit 1/hour --hashlimit-burst 2 --hashlimit-mode dstip,dstport --hashlimit-name htable_rule_1 -j DROP
+ $IPTABLES -N Cid3CD34BEF.4
+ $IPTABLES -A FORWARD -o eth0 -p icmp -j Cid3CD34BEF.4
+ $IPTABLES -A FORWARD -o eth0 -p 50 -j Cid3CD34BEF.4
+ $IPTABLES -N Cid3CD34BEF.3
+ $IPTABLES -A Cid3CD34BEF.4 -s 192.168.1.10 -j Cid3CD34BEF.3
+ $IPTABLES -A Cid3CD34BEF.4 -s 192.168.1.20 -j Cid3CD34BEF.3
+ $IPTABLES -A Cid3CD34BEF.3 -d 192.168.1.10 -j RETURN
+ $IPTABLES -A Cid3CD34BEF.3 -d 192.168.1.20 -j RETURN
+ $IPTABLES -A Cid3CD34BEF.3 -m hashlimit --hashlimit 1/hour --hashlimit-burst 2 --hashlimit-mode dstip,dstport --hashlimit-name htable_rule_1 -j DROP
+ #
+ # Rule 2 (eth1)
+ #
+ echo "Rule 2 (eth1)"
+ #
+ # Anti-spoofing rule
+ $IPTABLES -N In_RULE_2
+ $IPTABLES -A INPUT -i eth1 -s 22.22.22.22 -j In_RULE_2
+ $IPTABLES -A INPUT -i eth1 -s 22.22.23.23 -j In_RULE_2
+ $IPTABLES -A INPUT -i eth1 -s 192.168.1.1 -j In_RULE_2
+ $IPTABLES -A INPUT -i eth1 -s 192.168.2.1 -j In_RULE_2
+ $IPTABLES -A INPUT -i eth1 -s 192.168.1.0/24 -j In_RULE_2
+ $IPTABLES -A FORWARD -i eth1 -s 22.22.22.22 -j In_RULE_2
+ $IPTABLES -A FORWARD -i eth1 -s 22.22.23.23 -j In_RULE_2
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.1.1 -j In_RULE_2
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.2.1 -j In_RULE_2
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.1.0/24 -j In_RULE_2
+ $IPTABLES -A In_RULE_2 -j LOG --log-level debug
+ $IPTABLES -A In_RULE_2 -j DROP
+ #
+ # Rule 3 (eth1)
+ #
+ echo "Rule 3 (eth1)"
+ #
+ # Anti-spoofing rule
+ $IPTABLES -N Out_RULE_3
+ $IPTABLES -A OUTPUT -o eth1 -s ! 192.168.1.0/24 -j Out_RULE_3
+ $IPTABLES -A FORWARD -o eth1 -s ! 192.168.1.0/24 -j Out_RULE_3
+ $IPTABLES -A Out_RULE_3 -j LOG --log-level debug
+ $IPTABLES -A Out_RULE_3 -j DROP
+ #
+ # Rule 4 (eth1)
+ #
+ echo "Rule 4 (eth1)"
+ #
+ # Anti-spoofing rule
+ $IPTABLES -N Cid40DBCD36.0
+ $IPTABLES -A OUTPUT -o eth1 -j Cid40DBCD36.0
+ $IPTABLES -A Cid40DBCD36.0 -s 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid40DBCD36.0 -s 22.22.23.23 -j RETURN
+ $IPTABLES -A Cid40DBCD36.0 -s 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid40DBCD36.0 -s 192.168.2.1 -j RETURN
+ $IPTABLES -N Out_RULE_4_3
+ $IPTABLES -A Cid40DBCD36.0 -j Out_RULE_4_3
+ $IPTABLES -A Out_RULE_4_3 -j LOG --log-level debug
+ $IPTABLES -A Out_RULE_4_3 -j DROP
+ $IPTABLES -N Cid40DBCD36.1
+ $IPTABLES -A FORWARD -o eth1 -j Cid40DBCD36.1
+ $IPTABLES -A Cid40DBCD36.1 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid40DBCD36.1 -j Out_RULE_4_3
+ #
+ # Rule 5 (eth2)
+ #
+ echo "Rule 5 (eth2)"
+ #
+ $IPTABLES -A INPUT -i eth2 -s 192.168.2.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i eth2 -s 192.168.2.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth2 -s 192.168.2.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o eth2 -s 192.168.2.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 6 (eth2)
+ #
+ echo "Rule 6 (eth2)"
+ #
+ $IPTABLES -N In_RULE_6
+ $IPTABLES -A INPUT -i ! eth2 -s 192.168.2.0/24 -j In_RULE_6
+ $IPTABLES -A FORWARD -i ! eth2 -s 192.168.2.0/24 -j In_RULE_6
+ $IPTABLES -A In_RULE_6 -j LOG --log-level debug
+ $IPTABLES -A In_RULE_6 -j DROP
+ #
+ # Rule 7 (eth1,eth3)
+ #
+ echo "Rule 7 (eth1,eth3)"
+ #
+ $IPTABLES -N In_RULE_7
+ $IPTABLES -A INPUT -i eth0 -s 22.22.23.128/25 -j In_RULE_7
+ $IPTABLES -A INPUT -i eth0 -s 33.33.33.0/24 -j In_RULE_7
+ $IPTABLES -A INPUT -i eth2 -s 22.22.23.128/25 -j In_RULE_7
+ $IPTABLES -A INPUT -i eth2 -s 33.33.33.0/24 -j In_RULE_7
+ $IPTABLES -A FORWARD -i eth0 -s 22.22.23.128/25 -j In_RULE_7
+ $IPTABLES -A FORWARD -i eth0 -s 33.33.33.0/24 -j In_RULE_7
+ $IPTABLES -A FORWARD -i eth2 -s 22.22.23.128/25 -j In_RULE_7
+ $IPTABLES -A FORWARD -i eth2 -s 33.33.33.0/24 -j In_RULE_7
+ $IPTABLES -A In_RULE_7 -j LOG --log-level debug
+ $IPTABLES -A In_RULE_7 -j DROP
+ #
+ # Rule 8 (lo)
+ #
+ echo "Rule 8 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 9 (eth0,eth2)
+ #
+ echo "Rule 9 (eth0,eth2)"
+ #
+ $IPTABLES -N Cid433D045026912.0
+ $IPTABLES -A INPUT -i eth0 -j Cid433D045026912.0
+ $IPTABLES -A INPUT -i eth2 -j Cid433D045026912.0
+ $IPTABLES -A FORWARD -i eth0 -j Cid433D045026912.0
+ $IPTABLES -A FORWARD -i eth2 -j Cid433D045026912.0
+ $IPTABLES -A Cid433D045026912.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid433D045026912.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -N In_RULE_9_3
+ $IPTABLES -A Cid433D045026912.0 -j In_RULE_9_3
+ $IPTABLES -A In_RULE_9_3 -j LOG --log-level debug
+ $IPTABLES -A In_RULE_9_3 -j DROP
+ #
+ # Rule 10 (eth1,eth3)
+ #
+ echo "Rule 10 (eth1,eth3)"
+ #
+ $IPTABLES -N Cid434D389E26912.0
+ $IPTABLES -A INPUT -i eth1 -m state --state NEW -j Cid434D389E26912.0
+ $IPTABLES -A INPUT -i eth3 -m state --state NEW -j Cid434D389E26912.0
+ $IPTABLES -A FORWARD -i eth1 -m state --state NEW -j Cid434D389E26912.0
+ $IPTABLES -A FORWARD -i eth3 -m state --state NEW -j Cid434D389E26912.0
+ $IPTABLES -A Cid434D389E26912.0 -s 22.22.23.128/25 -j RETURN
+ $IPTABLES -A Cid434D389E26912.0 -s 33.33.33.0/24 -j RETURN
+ $IPTABLES -A Cid434D389E26912.0 -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ $IPTABLES -N Out_RULE_11
+ $IPTABLES -A Out_RULE_11 -j RETURN
+ $IPTABLES -A OUTPUT -j Out_RULE_11
+ $IPTABLES -N In_RULE_11
+ $IPTABLES -A In_RULE_11 -j RETURN
+ $IPTABLES -A INPUT -j In_RULE_11
+ $IPTABLES -N RULE_11
+ $IPTABLES -A RULE_11 -j RETURN
+ $IPTABLES -A FORWARD -j RULE_11
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ $IPTABLES -N RULE_12
+ $IPTABLES -A OUTPUT -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j RULE_12
+ $IPTABLES -A INPUT -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j RULE_12
+ $IPTABLES -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j RULE_12
+ $IPTABLES -A RULE_12 -j LOG --log-level debug
+ $IPTABLES -A RULE_12 -j DROP
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ $IPTABLES -N Cid3B9AB902.0
+ $IPTABLES -A OUTPUT -j Cid3B9AB902.0
+ $IPTABLES -A INPUT -j Cid3B9AB902.0
+ $IPTABLES -A FORWARD -j Cid3B9AB902.0
+ $IPTABLES -A Cid3B9AB902.0 -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j RETURN
+ $IPTABLES -N RULE_13_3
+ $IPTABLES -A Cid3B9AB902.0 -j RULE_13_3
+ $IPTABLES -A RULE_13_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_13_3 -j DROP
+ #
+ # Rule 14 (global)
+ #
+ echo "Rule 14 (global)"
+ #
+ # hostF has the same IP address as firewal.
+ $IPTABLES -N RULE_14
+ $IPTABLES -A OUTPUT -p icmp -m icmp -d 192.168.1.1 --icmp-type 8/0 -m state --state NEW -j RULE_14
+ $IPTABLES -A INPUT -p icmp -m icmp -d 192.168.1.1 --icmp-type 8/0 -m state --state NEW -j RULE_14
+ $IPTABLES -A RULE_14 -j LOG --log-level debug
+ $IPTABLES -A RULE_14 -j ACCEPT
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ $IPTABLES -N Cid434B03D526912.0
+ $IPTABLES -A OUTPUT -m state --state NEW -j Cid434B03D526912.0
+ $IPTABLES -A INPUT -m state --state NEW -j Cid434B03D526912.0
+ $IPTABLES -A FORWARD -m state --state NEW -j Cid434B03D526912.0
+ $IPTABLES -A Cid434B03D526912.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid434B03D526912.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -A Cid434B03D526912.0 -j ACCEPT
+ #
+ # Rule 16 (global)
+ #
+ echo "Rule 16 (global)"
+ #
+ # testing negation in the policy rule
+ $IPTABLES -N Cid3B021E10.0
+ $IPTABLES -A OUTPUT -p icmp -m icmp --icmp-type 3 -j Cid3B021E10.0
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type 3 -j Cid3B021E10.0
+ $IPTABLES -A FORWARD -p icmp -m icmp --icmp-type 3 -j Cid3B021E10.0
+ $IPTABLES -A Cid3B021E10.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -A Cid3B021E10.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -N RULE_16_3
+ $IPTABLES -A Cid3B021E10.0 -m limit --limit 10/minute -j RULE_16_3
+ $IPTABLES -A RULE_16_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_16_3 -j DROP
+ #
+ # Rule 17 (global)
+ #
+ echo "Rule 17 (global)"
+ #
+ # testing negation in the policy rule
+ $IPTABLES -N Cid40C0D096.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -m multiport --dports 80,443 -j Cid40C0D096.0
+ $IPTABLES -A INPUT -p tcp -m tcp -m multiport --dports 80,443 -j Cid40C0D096.0
+ $IPTABLES -A FORWARD -p tcp -m tcp -m multiport --dports 80,443 -j Cid40C0D096.0
+ $IPTABLES -A Cid40C0D096.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -A Cid40C0D096.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -N RULE_17_3
+ $IPTABLES -A Cid40C0D096.0 -m limit --limit 10/minute -j RULE_17_3
+ $IPTABLES -A RULE_17_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_17_3 -j RETURN
+ #
+ # Rule 18 (global)
+ #
+ echo "Rule 18 (global)"
+ #
+ # testing negation in the policy rule
+ $IPTABLES -N Cid40C0D10A.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -m multiport --dports 80,443 -m state --state NEW -j Cid40C0D10A.0
+ $IPTABLES -A INPUT -p tcp -m tcp -m multiport --dports 80,443 -m state --state NEW -j Cid40C0D10A.0
+ $IPTABLES -A FORWARD -p tcp -m tcp -m multiport --dports 80,443 -m state --state NEW -j Cid40C0D10A.0
+ $IPTABLES -A Cid40C0D10A.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -A Cid40C0D10A.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -N RULE_18_3
+ $IPTABLES -A Cid40C0D10A.0 -m limit --limit 10/minute -j RULE_18_3
+ $IPTABLES -A RULE_18_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_18_3 -j ACCEPT
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ $IPTABLES -N Cid3B0B4A13.1
+ $IPTABLES -A OUTPUT -p icmp -m icmp --icmp-type 3 -j Cid3B0B4A13.1
+ $IPTABLES -N Cid3B0B4A13.0
+ $IPTABLES -A Cid3B0B4A13.1 -d 22.22.22.22 -j Cid3B0B4A13.0
+ $IPTABLES -A Cid3B0B4A13.1 -d 22.22.23.23 -j Cid3B0B4A13.0
+ $IPTABLES -A Cid3B0B4A13.1 -d 192.168.1.1 -j Cid3B0B4A13.0
+ $IPTABLES -A Cid3B0B4A13.1 -d 192.168.2.1 -j Cid3B0B4A13.0
+ $IPTABLES -N Cid3B0B4A13.2
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type 3 -j Cid3B0B4A13.2
+ $IPTABLES -A Cid3B0B4A13.2 -d 22.22.22.22 -j Cid3B0B4A13.0
+ $IPTABLES -A Cid3B0B4A13.2 -d 22.22.23.23 -j Cid3B0B4A13.0
+ $IPTABLES -A Cid3B0B4A13.2 -d 192.168.1.1 -j Cid3B0B4A13.0
+ $IPTABLES -A Cid3B0B4A13.2 -d 192.168.2.1 -j Cid3B0B4A13.0
+ $IPTABLES -A Cid3B0B4A13.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -A Cid3B0B4A13.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -N RULE_19_3
+ $IPTABLES -A Cid3B0B4A13.0 -j RULE_19_3
+ $IPTABLES -A RULE_19_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_19_3 -j DROP
+ #
+ # Rule 20 (global)
+ #
+ echo "Rule 20 (global)"
+ #
+ $IPTABLES -N Cid3B5535B7.0
+ $IPTABLES -A OUTPUT -d 192.168.1.0/24 -j Cid3B5535B7.0
+ $IPTABLES -A Cid3B5535B7.0 -s 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid3B5535B7.0 -s 22.22.23.23 -j RETURN
+ $IPTABLES -A Cid3B5535B7.0 -s 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid3B5535B7.0 -s 192.168.2.1 -j RETURN
+ $IPTABLES -N Out_RULE_20_3
+ $IPTABLES -A Cid3B5535B7.0 -j Out_RULE_20_3
+ $IPTABLES -A Out_RULE_20_3 -j LOG --log-level debug
+ $IPTABLES -A Out_RULE_20_3 -j DROP
+ $IPTABLES -N Cid3B5535B7.1
+ $IPTABLES -A INPUT -d 192.168.1.0/24 -j Cid3B5535B7.1
+ $IPTABLES -A FORWARD -d 192.168.1.0/24 -j Cid3B5535B7.1
+ $IPTABLES -A Cid3B5535B7.1 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -N RULE_20_3
+ $IPTABLES -A Cid3B5535B7.1 -j RULE_20_3
+ $IPTABLES -A RULE_20_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_20_3 -j DROP
+ #
+ # Rule 21 (global)
+ #
+ echo "Rule 21 (global)"
+ #
+ $IPTABLES -N Cid40F1D905.0
+ $IPTABLES -A OUTPUT -d 192.168.1.0/24 -j Cid40F1D905.0
+ $IPTABLES -A Cid40F1D905.0 -s 192.168.1.1 -j RETURN
+ $IPTABLES -N Out_RULE_21_3
+ $IPTABLES -A Cid40F1D905.0 -j Out_RULE_21_3
+ $IPTABLES -A Out_RULE_21_3 -j LOG --log-level debug
+ $IPTABLES -A Out_RULE_21_3 -j DROP
+ $IPTABLES -N Cid40F1D905.1
+ $IPTABLES -A INPUT -d 192.168.1.0/24 -j Cid40F1D905.1
+ $IPTABLES -A FORWARD -d 192.168.1.0/24 -j Cid40F1D905.1
+ $IPTABLES -A Cid40F1D905.1 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -N RULE_21_3
+ $IPTABLES -A Cid40F1D905.1 -j RULE_21_3
+ $IPTABLES -A RULE_21_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_21_3 -j DROP
+ #
+ # Rule 22 (global)
+ #
+ echo "Rule 22 (global)"
+ #
+ $IPTABLES -N Cid3E74DF71.0
+ $IPTABLES -A INPUT -s 222.222.222.40 -j Cid3E74DF71.0
+ $IPTABLES -A INPUT -s 222.222.222.41 -j Cid3E74DF71.0
+ $IPTABLES -A FORWARD -s 222.222.222.40 -j Cid3E74DF71.0
+ $IPTABLES -A FORWARD -s 222.222.222.41 -j Cid3E74DF71.0
+ $IPTABLES -A Cid3E74DF71.0 -d 192.168.1.10 -j RETURN
+ $IPTABLES -A Cid3E74DF71.0 -d 192.168.1.20 -j RETURN
+ $IPTABLES -N RULE_22_3
+ $IPTABLES -A Cid3E74DF71.0 -j RULE_22_3
+ $IPTABLES -A RULE_22_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_22_3 -j DROP
+ #
+ # Rule 23 (global)
+ #
+ echo "Rule 23 (global)"
+ #
+ $IPTABLES -N Cid3B11F63D.0
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -j Cid3B11F63D.0
+ $IPTABLES -A INPUT -s 192.168.2.0/24 -j Cid3B11F63D.0
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -j Cid3B11F63D.0
+ $IPTABLES -A OUTPUT -s 192.168.2.0/24 -j Cid3B11F63D.0
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -j Cid3B11F63D.0
+ $IPTABLES -A FORWARD -s 192.168.2.0/24 -j Cid3B11F63D.0
+ $IPTABLES -A Cid3B11F63D.0 -d 192.168.1.10 -j RETURN
+ $IPTABLES -A Cid3B11F63D.0 -d 192.168.1.20 -j RETURN
+ $IPTABLES -N RULE_23_3
+ $IPTABLES -A Cid3B11F63D.0 -j RULE_23_3
+ $IPTABLES -A RULE_23_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_23_3 -j DROP
+ #
+ # Rule 24 (global)
+ #
+ echo "Rule 24 (global)"
+ #
+ # testing negation in service field
+ $IPTABLES -N Cid3B021E6F.0
+ $IPTABLES -A OUTPUT -d 192.168.1.10 -j Cid3B021E6F.0
+ $IPTABLES -A OUTPUT -d 192.168.1.20 -j Cid3B021E6F.0
+ $IPTABLES -A FORWARD -d 192.168.1.10 -j Cid3B021E6F.0
+ $IPTABLES -A FORWARD -d 192.168.1.20 -j Cid3B021E6F.0
+ $IPTABLES -A Cid3B021E6F.0 -p tcp -m tcp -m multiport --dports 25,22 -j RETURN
+ $IPTABLES -N RULE_24_3
+ $IPTABLES -A Cid3B021E6F.0 -j RULE_24_3
+ $IPTABLES -A RULE_24_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_24_3 -j DROP
+ #
+ # Rule 25 (global)
+ #
+ echo "Rule 25 (global)"
+ #
+ # testing negation in service field
+ $IPTABLES -N Cid3CCA2CF4.0
+ $IPTABLES -A OUTPUT -d 192.168.1.10 -m state --state NEW -j Cid3CCA2CF4.0
+ $IPTABLES -A OUTPUT -d 192.168.1.20 -m state --state NEW -j Cid3CCA2CF4.0
+ $IPTABLES -A FORWARD -d 192.168.1.10 -m state --state NEW -j Cid3CCA2CF4.0
+ $IPTABLES -A FORWARD -d 192.168.1.20 -m state --state NEW -j Cid3CCA2CF4.0
+ $IPTABLES -A Cid3CCA2CF4.0 -p tcp -m tcp -m multiport --dports 25,22 -j RETURN
+ $IPTABLES -N RULE_25_3
+ $IPTABLES -A Cid3CCA2CF4.0 -j RULE_25_3
+ $IPTABLES -A RULE_25_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_25_3 -j ACCEPT
+ #
+ # Rule 26 (global)
+ #
+ echo "Rule 26 (global)"
+ #
+ # testing negation in service field
+ $IPTABLES -N Cid3EA925F1.0
+ $IPTABLES -A OUTPUT -d 192.168.1.10 -m state --state NEW -j Cid3EA925F1.0
+ $IPTABLES -A OUTPUT -d 192.168.1.20 -m state --state NEW -j Cid3EA925F1.0
+ $IPTABLES -A FORWARD -d 192.168.1.10 -m state --state NEW -j Cid3EA925F1.0
+ $IPTABLES -A FORWARD -d 192.168.1.20 -m state --state NEW -j Cid3EA925F1.0
+ $IPTABLES -A Cid3EA925F1.0 -p tcp -m tcp --dport 25 -j RETURN
+ $IPTABLES -N RULE_26_3
+ $IPTABLES -A Cid3EA925F1.0 -j RULE_26_3
+ $IPTABLES -A RULE_26_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_26_3 -j ACCEPT
+ #
+ # Rule 27 (global)
+ #
+ echo "Rule 27 (global)"
+ #
+ # testing negation in service field
+ $IPTABLES -N Cid3EA9225C.0
+ $IPTABLES -A OUTPUT -d 192.168.1.10 -m state --state NEW -j Cid3EA9225C.0
+ $IPTABLES -A OUTPUT -d 192.168.1.20 -m state --state NEW -j Cid3EA9225C.0
+ $IPTABLES -A FORWARD -d 192.168.1.10 -m state --state NEW -j Cid3EA9225C.0
+ $IPTABLES -A FORWARD -d 192.168.1.20 -m state --state NEW -j Cid3EA9225C.0
+ $IPTABLES -A Cid3EA9225C.0 -p icmp -m icmp --icmp-type any -j RETURN
+ $IPTABLES -N RULE_27_3
+ $IPTABLES -A Cid3EA9225C.0 -j RULE_27_3
+ $IPTABLES -A RULE_27_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_27_3 -j ACCEPT
+ #
+ # Rule 28 (global)
+ #
+ echo "Rule 28 (global)"
+ #
+ # testing negation in service field
+ $IPTABLES -N Cid4144E299.1
+ $IPTABLES -A OUTPUT -m state --state NEW -j Cid4144E299.1
+ $IPTABLES -A INPUT -m state --state NEW -j Cid4144E299.1
+ $IPTABLES -A FORWARD -m state --state NEW -j Cid4144E299.1
+ $IPTABLES -A Cid4144E299.1 -d 192.168.1.10 -j RETURN
+ $IPTABLES -A Cid4144E299.1 -d 192.168.1.20 -j RETURN
+ $IPTABLES -N Cid4144E299.0
+ $IPTABLES -A Cid4144E299.1 -j Cid4144E299.0
+ $IPTABLES -A Cid4144E299.0 -p icmp -m icmp --icmp-type any -j RETURN
+ $IPTABLES -A Cid4144E299.0 -j ACCEPT
+ #
+ # Rule 29 (global)
+ #
+ echo "Rule 29 (global)"
+ #
+ # testing negation in service field
+ $IPTABLES -N Cid41449248.1
+ $IPTABLES -A OUTPUT -m state --state NEW -m time --timestart 09:00 --timestop 17:00 --days Mon,Tue,Wed,Thu,Fri -j Cid41449248.1
+ $IPTABLES -N Cid41449248.0
+ $IPTABLES -A Cid41449248.1 -d 192.168.1.10 -j Cid41449248.0
+ $IPTABLES -A Cid41449248.1 -d 192.168.1.20 -j Cid41449248.0
+ $IPTABLES -N Cid41449248.2
+ $IPTABLES -A FORWARD -m state --state NEW -m time --timestart 09:00 --timestop 17:00 --days Mon,Tue,Wed,Thu,Fri -j Cid41449248.2
+ $IPTABLES -A Cid41449248.2 -d 192.168.1.10 -j Cid41449248.0
+ $IPTABLES -A Cid41449248.2 -d 192.168.1.20 -j Cid41449248.0
+ $IPTABLES -A Cid41449248.0 -p tcp -m tcp --dport 80 -j RETURN
+ $IPTABLES -A Cid41449248.0 -j ACCEPT
+ #
+ # Rule 30 (global)
+ #
+ echo "Rule 30 (global)"
+ #
+ # testing negation in service field
+ $IPTABLES -N Cid414532F3.1
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 80 -m state --state NEW -j Cid414532F3.1
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 80 -m state --state NEW -j Cid414532F3.1
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 80 -m state --state NEW -j Cid414532F3.1
+ $IPTABLES -A Cid414532F3.1 -m time --timestart 09:00 --timestop 17:00 --days Mon,Tue,Wed,Thu,Fri -j RETURN
+ $IPTABLES -N Cid414532F3.0
+ $IPTABLES -A Cid414532F3.1 -j Cid414532F3.0
+ $IPTABLES -A Cid414532F3.0 -d 192.168.1.10 -j RETURN
+ $IPTABLES -A Cid414532F3.0 -d 192.168.1.20 -j RETURN
+ $IPTABLES -A Cid414532F3.0 -j ACCEPT
+ #
+ # Rule 31 (global)
+ #
+ echo "Rule 31 (global)"
+ #
+ # testing negation in service field
+ $IPTABLES -N Cid41449257.1
+ $IPTABLES -A OUTPUT -d 192.168.1.10 -m state --state NEW -j Cid41449257.1
+ $IPTABLES -A OUTPUT -d 192.168.1.20 -m state --state NEW -j Cid41449257.1
+ $IPTABLES -A FORWARD -d 192.168.1.10 -m state --state NEW -j Cid41449257.1
+ $IPTABLES -A FORWARD -d 192.168.1.20 -m state --state NEW -j Cid41449257.1
+ $IPTABLES -A Cid41449257.1 -m time --timestart 09:00 --timestop 17:00 --days Mon,Tue,Wed,Thu,Fri -j RETURN
+ $IPTABLES -N Cid41449257.0
+ $IPTABLES -A Cid41449257.1 -j Cid41449257.0
+ $IPTABLES -A Cid41449257.0 -p tcp -m tcp --dport 80 -j RETURN
+ $IPTABLES -A Cid41449257.0 -j ACCEPT
+ #
+ # Rule 32 (global)
+ #
+ echo "Rule 32 (global)"
+ #
+ $IPTABLES -N Cid4368F08A15884.1
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 80 -m state --state NEW -j Cid4368F08A15884.1
+ $IPTABLES -N Cid4368F08A15884.0
+ $IPTABLES -A Cid4368F08A15884.1 -s 22.22.22.22 -j Cid4368F08A15884.0
+ $IPTABLES -A Cid4368F08A15884.1 -s 22.22.23.23 -j Cid4368F08A15884.0
+ $IPTABLES -A Cid4368F08A15884.1 -s 192.168.1.1 -j Cid4368F08A15884.0
+ $IPTABLES -A Cid4368F08A15884.1 -s 192.168.2.1 -j Cid4368F08A15884.0
+ $IPTABLES -A Cid4368F08A15884.0 -d 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid4368F08A15884.0 -d 22.22.23.23 -j RETURN
+ $IPTABLES -A Cid4368F08A15884.0 -d 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid4368F08A15884.0 -d 192.168.2.1 -j RETURN
+ $IPTABLES -A Cid4368F08A15884.0 -j ACCEPT
+ $IPTABLES -N Cid4368F08A15884.2
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 80 -m state --state NEW -j Cid4368F08A15884.2
+ $IPTABLES -A Cid4368F08A15884.2 -s 22.22.22.22 -j ACCEPT
+ $IPTABLES -A Cid4368F08A15884.2 -s 22.22.23.23 -j ACCEPT
+ $IPTABLES -A Cid4368F08A15884.2 -s 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid4368F08A15884.2 -s 192.168.2.1 -j ACCEPT
+ #
+ # Rule 33 (global)
+ #
+ echo "Rule 33 (global)"
+ #
+ $IPTABLES -N Cid3E74D8BB.1
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid3E74D8BB.1
+ $IPTABLES -N Cid3E74D8BB.0
+ $IPTABLES -A Cid3E74D8BB.1 -s 22.22.22.22 -j Cid3E74D8BB.0
+ $IPTABLES -A Cid3E74D8BB.1 -s 22.22.23.23 -j Cid3E74D8BB.0
+ $IPTABLES -A Cid3E74D8BB.1 -s 192.168.1.1 -j Cid3E74D8BB.0
+ $IPTABLES -A Cid3E74D8BB.1 -s 192.168.2.1 -j Cid3E74D8BB.0
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.2.0/24 --dport 22 -m state --state NEW -j Cid3E74D8BB.0
+ $IPTABLES -A Cid3E74D8BB.0 -d 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid3E74D8BB.0 -d 22.22.23.23 -j RETURN
+ $IPTABLES -A Cid3E74D8BB.0 -d 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid3E74D8BB.0 -d 192.168.2.1 -j RETURN
+ $IPTABLES -A Cid3E74D8BB.0 -j ACCEPT
+ $IPTABLES -N Cid3E74D8BB.3
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid3E74D8BB.3
+ $IPTABLES -N Cid3E74D8BB.2
+ $IPTABLES -A Cid3E74D8BB.3 -s 22.22.22.22 -j Cid3E74D8BB.2
+ $IPTABLES -A Cid3E74D8BB.3 -s 22.22.23.23 -j Cid3E74D8BB.2
+ $IPTABLES -A Cid3E74D8BB.3 -s 192.168.1.1 -j Cid3E74D8BB.2
+ $IPTABLES -A Cid3E74D8BB.3 -s 192.168.2.1 -j Cid3E74D8BB.2
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.2.0/24 --dport 22 -m state --state NEW -j Cid3E74D8BB.2
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.2.0/24 --dport 22 -m state --state NEW -j Cid3E74D8BB.2
+ $IPTABLES -A Cid3E74D8BB.2 -d 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid3E74D8BB.2 -j ACCEPT
+ #
+ # Rule 34 (global)
+ #
+ echo "Rule 34 (global)"
+ #
+ $IPTABLES -N Cid3B45739A.1
+ $IPTABLES -A INPUT -s 22.22.22.22 -j Cid3B45739A.1
+ $IPTABLES -N Cid3B45739A.0
+ $IPTABLES -A Cid3B45739A.1 -p icmp -j Cid3B45739A.0
+ $IPTABLES -A Cid3B45739A.1 -p 50 -j Cid3B45739A.0
+ $IPTABLES -N Cid3B45739A.2
+ $IPTABLES -A INPUT -s 192.168.1.1 -j Cid3B45739A.2
+ $IPTABLES -A Cid3B45739A.2 -p icmp -j Cid3B45739A.0
+ $IPTABLES -A Cid3B45739A.2 -p 50 -j Cid3B45739A.0
+ $IPTABLES -N Cid3B45739A.3
+ $IPTABLES -A OUTPUT -s 22.22.22.22 -j Cid3B45739A.3
+ $IPTABLES -A Cid3B45739A.3 -p icmp -j Cid3B45739A.0
+ $IPTABLES -A Cid3B45739A.3 -p 50 -j Cid3B45739A.0
+ $IPTABLES -N Cid3B45739A.4
+ $IPTABLES -A OUTPUT -s 192.168.1.1 -j Cid3B45739A.4
+ $IPTABLES -A Cid3B45739A.4 -p icmp -j Cid3B45739A.0
+ $IPTABLES -A Cid3B45739A.4 -p 50 -j Cid3B45739A.0
+ $IPTABLES -A Cid3B45739A.0 -d 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid3B45739A.0 -d 192.168.1.1 -j RETURN
+ $IPTABLES -N RULE_34_3
+ $IPTABLES -A Cid3B45739A.0 -j RULE_34_3
+ $IPTABLES -A RULE_34_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_34_3 -j DROP
+ #
+ # Rule 35 (global)
+ #
+ echo "Rule 35 (global)"
+ #
+ # double negation rule
+ $IPTABLES -N Cid4067B2C2.1
+ $IPTABLES -A OUTPUT -j Cid4067B2C2.1
+ $IPTABLES -A INPUT -j Cid4067B2C2.1
+ $IPTABLES -A FORWARD -j Cid4067B2C2.1
+ $IPTABLES -A Cid4067B2C2.1 -d 192.168.1.10 -j RETURN
+ $IPTABLES -A Cid4067B2C2.1 -d 192.168.1.20 -j RETURN
+ $IPTABLES -N Cid4067B2C2.0
+ $IPTABLES -A Cid4067B2C2.1 -j Cid4067B2C2.0
+ $IPTABLES -A Cid4067B2C2.0 -p tcp -m tcp -m multiport --dports 3128,8080 -j RETURN
+ $IPTABLES -N RULE_35_3
+ $IPTABLES -A Cid4067B2C2.0 -j RULE_35_3
+ $IPTABLES -A RULE_35_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_35_3 -j DROP
+ #
+ # Rule 36 (global)
+ #
+ echo "Rule 36 (global)"
+ #
+ $IPTABLES -N Cid41A88DF6.0
+ $IPTABLES -A INPUT -m state --state NEW -j Cid41A88DF6.0
+ $IPTABLES -A Cid41A88DF6.0 -d 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid41A88DF6.0 -d 192.168.2.1 -j RETURN
+ $IPTABLES -A Cid41A88DF6.0 -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state NEW -j ACCEPT
+ #
+ # Rule 37 (global)
+ #
+ echo "Rule 37 (global)"
+ #
+ $IPTABLES -N Cid41B5176E.0
+ $IPTABLES -A OUTPUT -d 192.168.1.0/24 -m state --state NEW -j Cid41B5176E.0
+ $IPTABLES -A Cid41B5176E.0 -s 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid41B5176E.0 -s 192.168.2.1 -j RETURN
+ $IPTABLES -A Cid41B5176E.0 -j ACCEPT
+ $IPTABLES -A INPUT -d 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 38 (global)
+ #
+ echo "Rule 38 (global)"
+ #
+ $IPTABLES -N Cid4143BD3F.0
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 25 -m state --state NEW -j Cid4143BD3F.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 25 -m state --state NEW -j Cid4143BD3F.0
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 --dport 25 -m state --state NEW -j Cid4143BD3F.0
+ $IPTABLES -A Cid4143BD3F.0 -m time --timestart 00:00 --timestop 23:59 --days Sat -j RETURN
+ $IPTABLES -A Cid4143BD3F.0 -m time --timestart 00:00 --timestop 23:59 --days Sun -j RETURN
+ $IPTABLES -A Cid4143BD3F.0 -j ACCEPT
+ #
+ # Rule 39 (global)
+ #
+ echo "Rule 39 (global)"
+ #
+ $IPTABLES -N Cid4143BD1A.0
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -m state --state NEW -j Cid4143BD1A.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -m state --state NEW -j Cid4143BD1A.0
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -m state --state NEW -j Cid4143BD1A.0
+ $IPTABLES -A Cid4143BD1A.0 -m time --timestart 09:00 --timestop 17:00 --days Mon,Tue,Wed,Thu,Fri -j RETURN
+ $IPTABLES -A Cid4143BD1A.0 -j ACCEPT
+ #
+ # Rule 40 (global)
+ #
+ echo "Rule 40 (global)"
+ #
+ $IPTABLES -N Cid1515316X29460.0
+ $IPTABLES -A INPUT -p tcp -m tcp -d ! 192.168.1.0/24 --dport 80 -j Cid1515316X29460.0
+ $IPTABLES -A Cid1515316X29460.0 -s 22.22.22.22 -j DROP
+ $IPTABLES -A Cid1515316X29460.0 -s 22.22.23.23 -j DROP
+ $IPTABLES -A Cid1515316X29460.0 -s 192.168.1.1 -j DROP
+ $IPTABLES -A Cid1515316X29460.0 -s 192.168.2.1 -j DROP
+ $IPTABLES -N Cid1515316X29460.1
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d ! 192.168.1.0/24 --dport 80 -j Cid1515316X29460.1
+ $IPTABLES -A Cid1515316X29460.1 -s 22.22.22.22 -j DROP
+ $IPTABLES -A Cid1515316X29460.1 -s 22.22.23.23 -j DROP
+ $IPTABLES -A Cid1515316X29460.1 -s 192.168.1.1 -j DROP
+ $IPTABLES -A Cid1515316X29460.1 -s 192.168.2.1 -j DROP
+ #
+ # Rule 41 (global)
+ #
+ echo "Rule 41 (global)"
+ #
+ $IPTABLES -N Cid1515397X29460.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s ! 192.168.1.0/24 --dport 80 -j Cid1515397X29460.0
+ $IPTABLES -A Cid1515397X29460.0 -d 22.22.22.22 -j DROP
+ $IPTABLES -A Cid1515397X29460.0 -d 22.22.23.23 -j DROP
+ $IPTABLES -A Cid1515397X29460.0 -d 192.168.1.1 -j DROP
+ $IPTABLES -A Cid1515397X29460.0 -d 192.168.2.1 -j DROP
+ $IPTABLES -N Cid1515397X29460.1
+ $IPTABLES -A INPUT -p tcp -m tcp -s ! 192.168.1.0/24 --dport 80 -j Cid1515397X29460.1
+ $IPTABLES -A Cid1515397X29460.1 -d 22.22.22.22 -j DROP
+ $IPTABLES -A Cid1515397X29460.1 -d 22.22.23.23 -j DROP
+ $IPTABLES -A Cid1515397X29460.1 -d 192.168.1.1 -j DROP
+ $IPTABLES -A Cid1515397X29460.1 -d 192.168.2.1 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:53:25 2011 by vadim"
+ check_tools
+
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+ prolog_commands
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall10.fw.orig b/test/ipt/firewall10.fw.orig
new file mode 100755
index 000000000..fd79a8adc
--- /dev/null
+++ b/test/ipt/firewall10.fw.orig
@@ -0,0 +1,533 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:28 2011 PST by vadim
+#
+# files: * firewall10.fw
+#
+# Compiled for iptables 1.2.9
+#
+# testing rules with action-on-reject "TCP reset"
+# in this firewall, unlike in firewall9, this option is set globally instead of setting it
+# in the rule options
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ $IPTABLES -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
+
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -N Cid3D4F0A58.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 6667 -j Cid3D4F0A58.0
+ $IPTABLES -N RULE_0
+ $IPTABLES -A Cid3D4F0A58.0 -d 22.22.22.22 -j RULE_0
+ $IPTABLES -A Cid3D4F0A58.0 -d 192.168.1.1 -j RULE_0
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 6667 -j RULE_0
+ $IPTABLES -A RULE_0 -j LOG --log-level debug
+ $IPTABLES -A RULE_0 -j REJECT --reject-with icmp-admin-prohibited
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -N Cid3D4F0A62.0
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 53 -j Cid3D4F0A62.0
+ $IPTABLES -N RULE_1
+ $IPTABLES -A Cid3D4F0A62.0 -d 22.22.22.22 -j RULE_1
+ $IPTABLES -A Cid3D4F0A62.0 -d 192.168.1.1 -j RULE_1
+ $IPTABLES -A INPUT -p udp -m udp --dport 53 -j RULE_1
+ $IPTABLES -A RULE_1 -j LOG --log-level debug
+ $IPTABLES -A RULE_1 -j REJECT --reject-with icmp-host-unreachable
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -N Cid3D4F0A6C.0
+ $IPTABLES -A OUTPUT -p icmp -j Cid3D4F0A6C.0
+ $IPTABLES -A OUTPUT -p 50 -j Cid3D4F0A6C.0
+ $IPTABLES -N RULE_2
+ $IPTABLES -A Cid3D4F0A6C.0 -d 22.22.22.22 -j RULE_2
+ $IPTABLES -A Cid3D4F0A6C.0 -d 192.168.1.1 -j RULE_2
+ $IPTABLES -A INPUT -p icmp -j RULE_2
+ $IPTABLES -A INPUT -p 50 -j RULE_2
+ $IPTABLES -A RULE_2 -j LOG --log-level debug
+ $IPTABLES -A RULE_2 -j REJECT --reject-with icmp-host-unreachable
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -N Cid3D4F0A76.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 10000:11000 -j Cid3D4F0A76.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 113 -j Cid3D4F0A76.0
+ $IPTABLES -A OUTPUT -p udp -m udp -m multiport --dports 53,161 -j Cid3D4F0A76.0
+ $IPTABLES -N RULE_3
+ $IPTABLES -A Cid3D4F0A76.0 -d 22.22.22.22 -j RULE_3
+ $IPTABLES -A Cid3D4F0A76.0 -d 192.168.1.1 -j RULE_3
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 10000:11000 -j RULE_3
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 113 -j RULE_3
+ $IPTABLES -A INPUT -p udp -m udp -m multiport --dports 53,161 -j RULE_3
+ $IPTABLES -A RULE_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_3 -j REJECT --reject-with icmp-host-unreachable
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -N Cid3D4F0A80.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 10000:11000 -j Cid3D4F0A80.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 113 -j Cid3D4F0A80.0
+ $IPTABLES -A OUTPUT -p udp -m udp -m multiport --dports 53,161 -j Cid3D4F0A80.0
+ $IPTABLES -A Cid3D4F0A80.0 -d 22.22.22.22 -j REJECT --reject-with icmp-host-unreachable
+ $IPTABLES -A Cid3D4F0A80.0 -d 192.168.1.1 -j REJECT --reject-with icmp-host-unreachable
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 10000:11000 -j REJECT --reject-with icmp-host-unreachable
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 113 -j REJECT --reject-with icmp-host-unreachable
+ $IPTABLES -A INPUT -p udp -m udp -m multiport --dports 53,161 -j REJECT --reject-with icmp-host-unreachable
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -N Cid3D4F0A8A.0
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 10000:11000 -j Cid3D4F0A8A.0
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 113 -j Cid3D4F0A8A.0
+ $IPTABLES -A INPUT -p udp -m udp -m multiport --dports 53,161 -j Cid3D4F0A8A.0
+ $IPTABLES -A Cid3D4F0A8A.0 -d 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid3D4F0A8A.0 -d 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid3D4F0A8A.0 -j REJECT --reject-with icmp-host-unreachable
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 10000:11000 -j REJECT --reject-with icmp-host-unreachable
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 113 -j REJECT --reject-with icmp-host-unreachable
+ $IPTABLES -A OUTPUT -p udp -m udp -m multiport --dports 53,161 -j REJECT --reject-with icmp-host-unreachable
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 10000:11000 -j REJECT --reject-with icmp-host-unreachable
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 113 -j REJECT --reject-with icmp-host-unreachable
+ $IPTABLES -A FORWARD -p udp -m udp -m multiport --dports 53,161 -j REJECT --reject-with icmp-host-unreachable
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -N Cid3D4F0A94.0
+ $IPTABLES -A OUTPUT -d 22.22.22.22 -j Cid3D4F0A94.0
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j Cid3D4F0A94.0
+ $IPTABLES -A INPUT -j Cid3D4F0A94.0
+ $IPTABLES -A Cid3D4F0A94.0 -p tcp -m tcp --dport 10000:11000 -j RETURN
+ $IPTABLES -A Cid3D4F0A94.0 -p tcp -m tcp --dport 113 -j RETURN
+ $IPTABLES -A Cid3D4F0A94.0 -p udp -m udp -m multiport --dports 53,161 -j RETURN
+ $IPTABLES -A Cid3D4F0A94.0 -j REJECT --reject-with icmp-host-unreachable
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -N Cid3D4F0A9E.0
+ $IPTABLES -A OUTPUT -d 22.22.22.22 -j Cid3D4F0A9E.0
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j Cid3D4F0A9E.0
+ $IPTABLES -A INPUT -j Cid3D4F0A9E.0
+ $IPTABLES -A Cid3D4F0A9E.0 -p tcp -m tcp --dport 10000:11000 -j RETURN
+ $IPTABLES -A Cid3D4F0A9E.0 -p tcp -m tcp --dport 113 -j RETURN
+ $IPTABLES -A Cid3D4F0A9E.0 -p udp -m udp -m multiport --dports 53,161 -j RETURN
+ $IPTABLES -N RULE_7_3
+ $IPTABLES -A Cid3D4F0A9E.0 -j RULE_7_3
+ $IPTABLES -A RULE_7_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_7_3 -j REJECT --reject-with icmp-host-unreachable
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:53:28 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall11.fw.orig b/test/ipt/firewall11.fw.orig
new file mode 100755
index 000000000..4595791cb
--- /dev/null
+++ b/test/ipt/firewall11.fw.orig
@@ -0,0 +1,649 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:30 2011 PST by vadim
+#
+# files: * firewall11.fw
+#
+# Compiled for iptables (any version)
+#
+# testing rules with broadcasts and multicasts and action-on-reject 'TCP reset'.
+
+# This is BRIDGING FIREWALL
+# Firewall is part of any is OFF
+
+# Interfaces eth0 and eth1 are parts of the bridge; Interface eth2 is external interface (doing NAT and routing on this interface) Interface eth3 is connected to protected network and is used to manage firewall. This is rather realistic configuration for the bridging firewall
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth3 10.1.1.1/32" ""
+ getaddr eth2 i_eth2
+ getaddr6 eth2 i_eth2_v6
+ getaddr br0 i_br0
+ getaddr6 br0 i_br0_v6
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -j MASQUERADE
+ $IPTABLES -t nat -A POSTROUTING -o br0 -s 192.168.1.0/24 -j MASQUERADE
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 10.1.1.1
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ # see bug #1693 , SF bug 3048516
+ # combination of using SNAT instead of MASQ,
+ # source port translation and dynamic interface
+ for i_br0 in $i_br0_list
+ do
+ test -n "$i_br0" && $IPTABLES -t nat -A POSTROUTING -o br0 -p tcp -m tcp -s 192.168.1.0/24 --sport 1000:1010 -j SNAT --to-source $i_br0:1000-1010
+ done
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ # see SF bug 3057503
+ for i_br0 in $i_br0_list
+ do
+ test -n "$i_br0" && $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j DNAT --to-destination $i_br0:3128
+ done
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -A FORWARD -i eth0 -d 192.168.1.255 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ $IPTABLES -A FORWARD -i eth0 -d 255.255.255.255 -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (eth0)
+ #
+ echo "Rule 2 (eth0)"
+ #
+ $IPTABLES -A FORWARD -o eth0 -d 255.255.255.255 -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (eth0)
+ #
+ echo "Rule 3 (eth0)"
+ #
+ $IPTABLES -A FORWARD -i eth0 -d 255.255.255.255 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o eth0 -d 255.255.255.255 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (eth0)
+ #
+ echo "Rule 4 (eth0)"
+ #
+ $IPTABLES -A FORWARD -i eth0 -d 224.0.1.141 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (eth0)
+ #
+ echo "Rule 5 (eth0)"
+ #
+ $IPTABLES -A FORWARD -i eth0 -d 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 6 (eth0)
+ #
+ echo "Rule 6 (eth0)"
+ #
+ $IPTABLES -A FORWARD -i eth0 -d ! 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 7 (br0)
+ #
+ echo "Rule 7 (br0)"
+ #
+ $IPTABLES -A INPUT -i br0 -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 8 (br0)
+ #
+ echo "Rule 8 (br0)"
+ #
+ $IPTABLES -A INPUT -i br0 -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 9 (br0)
+ #
+ echo "Rule 9 (br0)"
+ #
+ for i_br0 in $i_br0_list
+ do
+ test -n "$i_br0" && $IPTABLES -A INPUT -i br0 -p tcp -m tcp -d $i_br0 --dport 22 -m state --state NEW -j ACCEPT
+ done
+ #
+ # Rule 10 (br0)
+ #
+ echo "Rule 10 (br0)"
+ #
+ $IPTABLES -N In_RULE_10
+ $IPTABLES -A INPUT -i br0 -j In_RULE_10
+ $IPTABLES -A FORWARD -i br0 -j In_RULE_10
+ $IPTABLES -A In_RULE_10 -j LOG --log-level debug
+ $IPTABLES -A In_RULE_10 -j DROP
+ $IPTABLES -N Out_RULE_10
+ $IPTABLES -A OUTPUT -o br0 -j Out_RULE_10
+ $IPTABLES -A FORWARD -o br0 -j Out_RULE_10
+ $IPTABLES -A Out_RULE_10 -j LOG --log-level debug
+ $IPTABLES -A Out_RULE_10 -j DROP
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ $IPTABLES -A FORWARD -p udp -m udp -d 255.255.255.255 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p udp -m udp -d 255.255.255.255 --dport 68 -m state --state NEW -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ $IPTABLES -N Cid3D94D513.0
+ $IPTABLES -A FORWARD -p udp -m udp --dport 68 -m state --state NEW -j Cid3D94D513.0
+ $IPTABLES -A Cid3D94D513.0 -d 192.168.1.10 -j ACCEPT
+ $IPTABLES -A Cid3D94D513.0 -d 192.168.1.255 -j ACCEPT
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ $IPTABLES -A FORWARD -p udp -m udp -d 192.168.1.0 --dport 68 -m state --state NEW -j ACCEPT
+ #
+ # Rule 14 (global)
+ #
+ echo "Rule 14 (global)"
+ #
+ $IPTABLES -A FORWARD -d 224.0.1.141 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 224.0.1.141 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 192.168.1.20 -m state --state NEW -j ACCEPT
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ $IPTABLES -A FORWARD -d 224.0.0.5 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 224.0.0.5 -m state --state NEW -j ACCEPT
+ #
+ # Rule 16 (global)
+ #
+ echo "Rule 16 (global)"
+ #
+ $IPTABLES -A FORWARD -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ #
+ # Rule 17 (global)
+ #
+ echo "Rule 17 (global)"
+ #
+ $IPTABLES -A FORWARD -p tcp -m tcp -d 192.168.1.10 --dport 6667 -m state --state NEW -j ACCEPT
+ #
+ # Rule 18 (global)
+ #
+ echo "Rule 18 (global)"
+ #
+ $IPTABLES -N RULE_18
+ $IPTABLES -A FORWARD -d 192.168.1.10 -j RULE_18
+ $IPTABLES -A RULE_18 -j LOG --log-level debug
+ $IPTABLES -A RULE_18 -j DROP
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ # this rule should generate commands
+ # in both INPUT and FORWARD chains
+ # because this is a bridging firewall
+ # see bug #811860
+ $IPTABLES -N Cid3DD4BBC7.0
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j Cid3DD4BBC7.0
+ for i_br0 in $i_br0_list
+ do
+ test -n "$i_br0" && $IPTABLES -A Cid3DD4BBC7.0 -d $i_br0 -j ACCEPT
+ done
+ for i_eth2 in $i_eth2_list
+ do
+ test -n "$i_eth2" && $IPTABLES -A Cid3DD4BBC7.0 -d $i_eth2 -j ACCEPT
+ done
+ $IPTABLES -A Cid3DD4BBC7.0 -d 10.1.1.1 -j ACCEPT
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 20 (global)
+ #
+ echo "Rule 20 (global)"
+ #
+ for i_br0 in $i_br0_list
+ do
+ test -n "$i_br0" && $IPTABLES -A FORWARD -d $i_br0 -m state --state NEW -j ACCEPT
+ done
+ for i_eth2 in $i_eth2_list
+ do
+ test -n "$i_eth2" && $IPTABLES -A FORWARD -d $i_eth2 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A FORWARD -d 10.1.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -m state --state NEW -j ACCEPT
+ #
+ # Rule 21 (global)
+ #
+ echo "Rule 21 (global)"
+ #
+ $IPTABLES -A FORWARD -d 10.1.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 10.1.1.1 -m state --state NEW -j ACCEPT
+ #
+ # Rule 23 (global)
+ #
+ echo "Rule 23 (global)"
+ #
+ $IPTABLES -N RULE_23
+ $IPTABLES -A FORWARD -j RULE_23
+ $IPTABLES -A RULE_23 -j LOG --log-level debug
+ $IPTABLES -A RULE_23 -j DROP
+ #
+ # Rule 24 (global)
+ #
+ echo "Rule 24 (global)"
+ #
+ $IPTABLES -N RULE_24
+ $IPTABLES -A OUTPUT -j RULE_24
+ $IPTABLES -A INPUT -j RULE_24
+ $IPTABLES -A FORWARD -j RULE_24
+ $IPTABLES -A RULE_24 -j LOG --log-level debug
+ $IPTABLES -A RULE_24 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:53:30 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall12.fw.orig b/test/ipt/firewall12.fw.orig
new file mode 100755
index 000000000..1d6eb1229
--- /dev/null
+++ b/test/ipt/firewall12.fw.orig
@@ -0,0 +1,571 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:32 2011 PST by vadim
+#
+# files: * firewall12.fw
+#
+# Compiled for iptables (any version)
+#
+# This firewall does not do NAT for addresses, but translates port for a server
+
+# firewall12:NAT:16: error: NAT rule can not change service types: TCPService to UDPService
+# firewall12:NAT:16: error: Translated Service should be either 'Original' or should contain object of the same type as Original Service.
+
+# firewall12::: warning: Can not add virtual address for object fw1:eth0:ip
+# firewall12::: warning: Can not add virtual address for object fw1:eth1:ip
+# firewall12::: warning: Can not add virtual address for object fw1:eth0:ip
+# firewall12::: warning: Can not add virtual address for object fw1:eth1:ip
+# firewall12::: warning: Can not add virtual address for object fw1:eth0:ip
+# firewall12::: warning: Can not add virtual address for object fw1:eth1:ip
+# firewall12::: warning: Can not add virtual address for object fw1:eth0:ip
+# firewall12::: warning: Can not add virtual address for object fw1:eth1:ip
+# firewall12::: warning: Can not add virtual address for object fw1:eth0:ip
+# firewall12::: warning: Can not add virtual address for object fw1:eth1:ip
+# firewall12::: warning: Can not add virtual address for object fw1:eth0:ip
+# firewall12::: warning: Can not add virtual address for object fw1:eth1:ip
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 22.22.22.22/24 22.22.22.23/24" ""
+ update_addresses_of_interface "eth1 22.22.23.22/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.23 --dport 80 -j DNAT --to-destination :8080
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.22 --dport 80 -j DNAT --to-destination :8080
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.22 --dport 80 -j DNAT --to-destination :8080
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 80 -j REDIRECT --to-ports 8080
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.22 --dport 80 -j REDIRECT --to-ports 8080
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 80 -j REDIRECT --to-ports 8080
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.22 --dport 80 -j REDIRECT --to-ports 8080
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 80 -j DNAT --to-destination 22.22.22.22:8080
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.22 --dport 80 -j DNAT --to-destination 22.22.22.22:8080
+ #
+ # Rule 6 (NAT)
+ #
+ echo "Rule 6 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j DNAT --to-destination :8080
+ #
+ # Rule 7 (NAT)
+ #
+ echo "Rule 7 (NAT)"
+ #
+ # port-only translation
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -p udp -m udp --sport 6767 -j SNAT --to-source :67
+ #
+ # Rule 8 (NAT)
+ #
+ echo "Rule 8 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p udp -m udp --sport 6767 -j SNAT --to-source 22.22.23.22:67
+ #
+ # Rule 9 (NAT)
+ #
+ echo "Rule 9 (NAT)"
+ #
+ # port-only translation
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j DNAT --to-destination :8080
+ #
+ # Rule 10 (NAT)
+ #
+ echo "Rule 10 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 8080
+ #
+ # Rule 11 (NAT)
+ #
+ echo "Rule 11 (NAT)"
+ #
+ # SDNAT
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.0.2.1 --dport 22 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 22 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -p tcp -m tcp -d 192.168.1.10 --dport 22 -j SNAT --to-source 192.0.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -p tcp -m tcp -d 192.168.1.10 --dport 22 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 12 (NAT)
+ #
+ echo "Rule 12 (NAT)"
+ #
+ # SDNAT with source port
+ $IPTABLES -t nat -A PREROUTING -p udp -m udp --sport 123 -d 192.0.2.1 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p udp -m udp --sport 123 -d 192.168.1.1 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -p udp -m udp --sport 123 -d 192.168.1.10 -j SNAT --to-source 192.0.2.1:5050
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -p udp -m udp --sport 123 -d 192.168.1.10 -j SNAT --to-source 192.168.1.1:5050
+ #
+ # Rule 13 (NAT)
+ #
+ echo "Rule 13 (NAT)"
+ #
+ # SDNAT with dest port
+ $IPTABLES -t nat -A PREROUTING -p udp -m udp -s 192.168.1.0/24 --dport 53 -j DNAT --to-destination 192.168.1.10:1053
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -p udp -m udp -s 192.168.1.0/24 -d 192.168.1.10 --dport 1053 -j SNAT --to-source 192.0.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -p udp -m udp -s 192.168.1.0/24 -d 192.168.1.10 --dport 1053 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 14 (NAT)
+ #
+ echo "Rule 14 (NAT)"
+ #
+ # SDNAT
+ # translate src and dst addresses
+ # and src and dst ports
+ $IPTABLES -t nat -A PREROUTING -p udp -m udp -s 192.168.1.0/24 --sport 1024:65535 --dport 53 -j DNAT --to-destination 192.168.1.10:1053
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -p udp -m udp -s 192.168.1.0/24 -d 192.168.1.10 --dport 1053 -j SNAT --to-source 192.0.2.1:32767-65535
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -p udp -m udp -s 192.168.1.0/24 -d 192.168.1.10 --dport 1053 -j SNAT --to-source 192.168.1.1:32767-65535
+ #
+ # Rule 15 (NAT)
+ #
+ echo "Rule 15 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -p udp -m udp -s 192.168.1.0/24 --dport 53 -j SNAT --to-source :5050
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 22.22.22.23 --dport 8080 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -d 22.22.22.23 --dport 8080 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -N RULE_1
+ $IPTABLES -A OUTPUT -j RULE_1
+ $IPTABLES -A INPUT -j RULE_1
+ $IPTABLES -A FORWARD -j RULE_1
+ $IPTABLES -A RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A RULE_1 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:53:32 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall13.fw.orig b/test/ipt/firewall13.fw.orig
new file mode 100755
index 000000000..dff8d0233
--- /dev/null
+++ b/test/ipt/firewall13.fw.orig
@@ -0,0 +1,445 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:34 2011 PST by vadim
+#
+# files: * firewall13.fw
+#
+# Compiled for iptables (any version)
+#
+# Testing empty groups thing
+
+# firewall13:NAT:0: warning: Empty group or address table object 'empty Ogroup'
+# firewall13:NAT:0: warning: After removal of all empty groups and address table objects rule element OSrc becomes 'any' in the rule 0 (NAT)
+# Dropping rule 0 (NAT) because option 'Ignore rules with empty groups' is in effect
+# firewall13:NAT:1: warning: Empty group or address table object 'empty Ogroup2'
+# firewall13:NAT:1: warning: After removal of all empty groups and address table objects rule element OSrc becomes 'any' in the rule 1 (NAT)
+# Dropping rule 1 (NAT) because option 'Ignore rules with empty groups' is in effect
+
+# firewall13:Policy:0: warning: Empty group or address table object 'empty Ogroup2'
+# firewall13:Policy:0: warning: After removal of all empty groups and address table objects rule element Src becomes 'any' in the rule 0 (global)
+# Dropping rule 0 (global) because option 'Ignore rules with empty groups' is in effect
+# firewall13:Policy:1: warning: Empty group or address table object 'empty Sgroup'
+# firewall13:Policy:1: warning: After removal of all empty groups and address table objects rule element Srv becomes 'any' in the rule 1 (global)
+# Dropping rule 1 (global) because option 'Ignore rules with empty groups' is in effect
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 22.22.22.22/24" ""
+ update_addresses_of_interface "eth1 22.22.23.22/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -N RULE_2
+ $IPTABLES -A OUTPUT -j RULE_2
+ $IPTABLES -A INPUT -j RULE_2
+ $IPTABLES -A FORWARD -j RULE_2
+ $IPTABLES -A RULE_2 -j LOG --log-level info --log-prefix "RULE 2 -- DENY "
+ $IPTABLES -A RULE_2 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:53:34 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall14.fw.orig b/test/ipt/firewall14.fw.orig
new file mode 100755
index 000000000..751bac973
--- /dev/null
+++ b/test/ipt/firewall14.fw.orig
@@ -0,0 +1,464 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:36 2011 PST by vadim
+#
+# files: * firewall14.fw
+#
+# Compiled for iptables (any version)
+#
+# special configuration with overlapping subnets on external and dmz interfaces
+# testing NAT rules (especially choice of interfaces for -o )
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.22/24" ""
+ update_addresses_of_interface "eth1 22.22.23.22/24 22.22.23.160/24 22.22.23.40/24" ""
+ update_addresses_of_interface "eth2 22.22.23.132/25" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.160
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -d ! 22.22.23.128/25 -j SNAT --to-source 22.22.23.160
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -d 22.22.23.128/25 -j SNAT --to-source 22.22.23.132
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -d 22.22.23.128/25 -j SNAT --to-source 22.22.23.132
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ # I guess this rule does not make much sense
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -d 22.22.23.128/25 -j SNAT --to-source 22.22.23.22
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -d 22.22.23.128/25 -j SNAT --to-source 22.22.23.160
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -d 22.22.23.128/25 -j SNAT --to-source 22.22.23.22
+ #
+ # Rule 6 (NAT)
+ #
+ echo "Rule 6 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -d 22.22.23.128/25 -j SNAT --to-source 22.22.23.40
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:53:36 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall15.fw.orig b/test/ipt/firewall15.fw.orig
new file mode 100755
index 000000000..db59615f6
--- /dev/null
+++ b/test/ipt/firewall15.fw.orig
@@ -0,0 +1,448 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:38 2011 PST by vadim
+#
+# files: * firewall15.fw
+#
+# Compiled for iptables (any version)
+#
+# Testing "Accept TCP sessions opened prior to firewall restart flag"
+# in combination with "Assume firewall is part of any" - both
+# flags are OFF here
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 22.22.22.22/24" ""
+ update_addresses_of_interface "eth1 22.22.23.22/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop TCP sessions opened prior firewall restart
+ $IPTABLES -A INPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ $IPTABLES -A OUTPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ $IPTABLES -A FORWARD -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (lo)
+ #
+ echo "Rule 0 (lo)"
+ #
+ # option 'assume firewall is part of any'
+ # is off, but this rule should go into
+ # INPUT/OUTPUT chains anyway
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -N RULE_1
+ $IPTABLES -A FORWARD -j RULE_1
+ $IPTABLES -A RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A RULE_1 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:53:38 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall16.fw.orig b/test/ipt/firewall16.fw.orig
new file mode 100755
index 000000000..78427e223
--- /dev/null
+++ b/test/ipt/firewall16.fw.orig
@@ -0,0 +1,552 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:40 2011 PST by vadim
+#
+# files: * firewall16.fw
+#
+# Compiled for iptables (any version)
+#
+# testing translation from outside to the web server on DMZ, need to see what happens if clients on internal net connect to the NATted address of this server. This is a kind of "NAT back to the same subnet" with a twist.
+
+# This firewall also has option "local NAT" enabled. NAT rules 0,2-7 should generate code in the OUTPUT and POSTROUTING chains.
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.22/24" ""
+ update_addresses_of_interface "eth1 22.22.23.22/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ # should generate code in both PREROUTING
+ # and OUTPUT chain because option "local NAT"
+ # is enabled
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.22 --dport 80 -j DNAT --to-destination 192.168.2.10:80
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.22 --dport 80 -j DNAT --to-destination 192.168.2.10:80
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 80 -j DNAT --to-destination 192.168.2.10:80
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.23.22 --dport 80 -j DNAT --to-destination 192.168.2.10:80
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 192.168.1.22 --dport 80 -j DNAT --to-destination 192.168.2.10:80
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 192.168.2.1 --dport 80 -j DNAT --to-destination 192.168.2.10:80
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.22
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 8080 -j DNAT --to-destination 192.168.1.10:3128
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 8080 -j DNAT --to-destination 192.168.1.10:3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.0/24 --dport 8080 -j DNAT --to-destination 192.168.1.10:3128
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -s 192.168.2.1 --dport 8080 -j DNAT --to-destination 192.168.1.10:3128
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -s 192.168.2.1 --dport 8080 -j DNAT --to-destination 192.168.1.10:3128
+ #
+ # Rule 6 (NAT)
+ #
+ echo "Rule 6 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 22.22.23.22 -j SNAT --to-source 22.22.23.22
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.22 -j SNAT --to-source 22.22.23.22
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.2.1 -j SNAT --to-source 22.22.23.22
+ #
+ # Rule 7 (NAT)
+ #
+ echo "Rule 7 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 22.22.23.22 -j SNAT --to-source 22.22.23.22
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.22 -j SNAT --to-source 22.22.23.22
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.2.1 -j SNAT --to-source 22.22.23.22
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.22
+ #
+ # Rule 8 (NAT)
+ #
+ echo "Rule 8 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.2.1 -j SNAT --to-source 22.22.23.22
+ #
+ # Rule 9 (NAT)
+ #
+ echo "Rule 9 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.2.1 -j SNAT --to-source 22.22.23.22
+ #
+ # Rule 10 (NAT)
+ #
+ echo "Rule 10 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -s 22.22.23.22 -j ACCEPT
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.22 -j ACCEPT
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.2.1 -j ACCEPT
+ $IPTABLES -t nat -A OUTPUT -j ACCEPT
+ #
+ # Rule 11 (NAT)
+ #
+ echo "Rule 11 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -s 22.22.23.22 -j ACCEPT
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.22 -j ACCEPT
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.2.1 -j ACCEPT
+ $IPTABLES -t nat -A OUTPUT -j ACCEPT
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.0/24 -j ACCEPT
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.0/24 -j ACCEPT
+ #
+ # Rule 12 (NAT)
+ #
+ echo "Rule 12 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.2.1 -j ACCEPT
+ $IPTABLES -t nat -A OUTPUT -s 192.168.2.1 -j ACCEPT
+ #
+ # Rule 13 (NAT)
+ #
+ echo "Rule 13 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.2.1 -j ACCEPT
+ $IPTABLES -t nat -A OUTPUT -s 192.168.2.1 -j ACCEPT
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.2.10 --dport 80 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -d 192.168.2.10 --dport 80 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -N RULE_1
+ $IPTABLES -A OUTPUT -j RULE_1
+ $IPTABLES -A INPUT -j RULE_1
+ $IPTABLES -A FORWARD -j RULE_1
+ $IPTABLES -A RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A RULE_1 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:53:40 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall17.fw.orig b/test/ipt/firewall17.fw.orig
new file mode 100755
index 000000000..912651692
--- /dev/null
+++ b/test/ipt/firewall17.fw.orig
@@ -0,0 +1,531 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:42 2011 PST by vadim
+#
+# files: * firewall17.fw
+#
+# Compiled for iptables (any version)
+#
+# doing SNAT with virtual addresses of two external interface
+
+# firewall17:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall17:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall17:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall17:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall17:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall17:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall17:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall17:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall17:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall17:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall17:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall17:Policy:: warning: Log prefix has been truncated to 29 characters
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24 33.33.33.33/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth3 22.22.23.23/24 44.44.44.44/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ # compiler should add "-o eth2"
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j SNAT --to-source 33.33.33.33
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ # compiler should add "-o eth2"
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 44.44.44.44
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth1)
+ #
+ echo "Rule 0 (eth1)"
+ #
+ $IPTABLES -N Cid3E1C6BE3.0
+ $IPTABLES -A INPUT -i eth1 -j Cid3E1C6BE3.0
+ $IPTABLES -A Cid3E1C6BE3.0 -d 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid3E1C6BE3.0 -d 22.22.23.23 -j RETURN
+ $IPTABLES -A Cid3E1C6BE3.0 -d 33.33.33.33 -j RETURN
+ $IPTABLES -A Cid3E1C6BE3.0 -d 44.44.44.44 -j RETURN
+ $IPTABLES -A Cid3E1C6BE3.0 -d 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid3E1C6BE3.0 -d 192.168.2.1 -j RETURN
+ $IPTABLES -N In_RULE_0_3
+ $IPTABLES -A Cid3E1C6BE3.0 -j In_RULE_0_3
+ $IPTABLES -A In_RULE_0_3 -j LOG --log-level debug --log-prefix "RULE 0 -- DENY on interface g"
+ $IPTABLES -A In_RULE_0_3 -j DROP
+ $IPTABLES -N In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -j In_RULE_0
+ $IPTABLES -A In_RULE_0 -j LOG --log-level debug --log-prefix "RULE 0 -- DENY on interface g"
+ $IPTABLES -A In_RULE_0 -j DROP
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -N rule0acct
+ $IPTABLES -A rule0acct -j RETURN
+ $IPTABLES -A OUTPUT -j rule0acct
+ $IPTABLES -A INPUT -j rule0acct
+ $IPTABLES -A FORWARD -j rule0acct
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -N RULE_2
+ $IPTABLES -A OUTPUT -j RULE_2
+ $IPTABLES -A INPUT -j RULE_2
+ $IPTABLES -A FORWARD -j RULE_2
+ $IPTABLES -A RULE_2 -j LOG --log-level debug --log-prefix "RULE 2 -- ACCOUNTING on inter"
+ $IPTABLES -N rule1acct
+ $IPTABLES -A rule1acct -j RETURN
+ $IPTABLES -A RULE_2 -j rule1acct
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -N RULE_3
+ $IPTABLES -A OUTPUT -j RULE_3
+ $IPTABLES -A INPUT -j RULE_3
+ $IPTABLES -A FORWARD -j RULE_3
+ $IPTABLES -A RULE_3 -j LOG --log-level debug --log-prefix "RULE 3 -- ACCOUNTING on inter"
+ $IPTABLES -A RULE_3 -j RETURN
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -N RULE_4
+ $IPTABLES -A RULE_4 -j RETURN
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.11 -d 192.168.2.10 --dport 4000:4010 -j RULE_4
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.11 -d 192.168.2.10 --dport 22 -j RULE_4
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -N Cid3E1C6BC9.0
+ $IPTABLES -A INPUT -j Cid3E1C6BC9.0
+ $IPTABLES -A Cid3E1C6BC9.0 -d 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid3E1C6BC9.0 -d 22.22.23.23 -j RETURN
+ $IPTABLES -A Cid3E1C6BC9.0 -d 33.33.33.33 -j RETURN
+ $IPTABLES -A Cid3E1C6BC9.0 -d 44.44.44.44 -j RETURN
+ $IPTABLES -A Cid3E1C6BC9.0 -d 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid3E1C6BC9.0 -d 192.168.2.1 -j RETURN
+ $IPTABLES -N In_RULE_5_3
+ $IPTABLES -A Cid3E1C6BC9.0 -j In_RULE_5_3
+ $IPTABLES -A In_RULE_5_3 -j LOG --log-level debug --log-prefix "RULE 5 -- DENY on interface g"
+ $IPTABLES -A In_RULE_5_3 -j DROP
+ $IPTABLES -N RULE_5
+ $IPTABLES -A OUTPUT -j RULE_5
+ $IPTABLES -A FORWARD -j RULE_5
+ $IPTABLES -A RULE_5 -j LOG --log-level debug --log-prefix "RULE 5 -- DENY on interface g"
+ $IPTABLES -A RULE_5 -j DROP
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:53:42 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall18.fw.orig b/test/ipt/firewall18.fw.orig
new file mode 100755
index 000000000..7ecc2ab2c
--- /dev/null
+++ b/test/ipt/firewall18.fw.orig
@@ -0,0 +1,564 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:45 2011 PST by vadim
+#
+# files: * firewall18.fw
+#
+# Compiled for iptables (any version)
+#
+# this firewall translates outgoing connections using address of the particular interface (not external one). Also testing different cmbinations of objects in the policy rules on loopback interface. Finally, testing for a situation when dynamic interface "shades" a rule with old broadcast
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth2 eth0 eth1 lo ppp0"
+ for i in eth2 eth0 eth1 lo ppp0 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth2 66.66.66.1/25" ""
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth1 66.66.66.130/25" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ getaddr ppp0 i_ppp0
+ getaddr6 ppp0 i_ppp0_v6
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -t nat -A POSTROUTING -o eth1 -s $i_ppp0 -j SNAT --to-source 66.66.66.130
+ done
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 66.66.66.1 -j SNAT --to-source 66.66.66.130
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 66.66.66.130 -j SNAT --to-source 66.66.66.130
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.1 -j SNAT --to-source 66.66.66.130
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -t nat -A POSTROUTING -o eth1 -s $i_ppp0 -j SNAT --to-source 66.66.66.130
+ done
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 66.66.66.1 -j SNAT --to-source 66.66.66.130
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 66.66.66.130 -j SNAT --to-source 66.66.66.130
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.1 -j SNAT --to-source 66.66.66.130
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j SNAT --to-source 66.66.66.130
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j SNAT --to-source 66.66.66.130
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -t nat -A POSTROUTING -o eth+ -s $i_ppp0 -j SNAT --to-source 66.66.66.130
+ done
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -t nat -A POSTROUTING -o ppp+ -s $i_ppp0 -j SNAT --to-source 66.66.66.130
+ done
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 66.66.66.1 -j SNAT --to-source 66.66.66.130
+ $IPTABLES -t nat -A POSTROUTING -o ppp+ -s 66.66.66.1 -j SNAT --to-source 66.66.66.130
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 66.66.66.130 -j SNAT --to-source 66.66.66.130
+ $IPTABLES -t nat -A POSTROUTING -o ppp+ -s 66.66.66.130 -j SNAT --to-source 66.66.66.130
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.1 -j SNAT --to-source 66.66.66.130
+ $IPTABLES -t nat -A POSTROUTING -o ppp+ -s 192.168.1.1 -j SNAT --to-source 66.66.66.130
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 66.66.66.130
+ $IPTABLES -t nat -A POSTROUTING -o ppp+ -s 192.168.1.0/24 -j SNAT --to-source 66.66.66.130
+ #
+ # Rule 6 (NAT)
+ #
+ echo "Rule 6 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 66.66.66.1 -j SNAT --to-source 66.66.66.130
+ $IPTABLES -t nat -A POSTROUTING -o ppp+ -s 66.66.66.1 -j SNAT --to-source 66.66.66.130
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ # using address range object
+ # 255.255.255.255-255.255.255.255
+ $IPTABLES -N In_RULE_0
+ $IPTABLES -A INPUT -i eth0 -d 255.255.255.255 -j In_RULE_0
+ $IPTABLES -A In_RULE_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A In_RULE_0 -j DROP
+ $IPTABLES -N Out_RULE_0
+ $IPTABLES -A OUTPUT -o eth0 -d 255.255.255.255 -j Out_RULE_0
+ $IPTABLES -A Out_RULE_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A Out_RULE_0 -j DROP
+ #
+ # Rule 1 (lo)
+ #
+ echo "Rule 1 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (ppp0)
+ #
+ echo "Rule 2 (ppp0)"
+ #
+ # anti-spoofing rule
+ $IPTABLES -N In_RULE_2
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -A INPUT -i ppp0 -s $i_ppp0 -j In_RULE_2
+ done
+ $IPTABLES -A INPUT -i ppp0 -s 66.66.66.1 -j In_RULE_2
+ $IPTABLES -A INPUT -i ppp0 -s 66.66.66.130 -j In_RULE_2
+ $IPTABLES -A INPUT -i ppp0 -s 192.168.1.1 -j In_RULE_2
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -A FORWARD -i ppp0 -s $i_ppp0 -j In_RULE_2
+ done
+ $IPTABLES -A FORWARD -i ppp0 -s 66.66.66.1 -j In_RULE_2
+ $IPTABLES -A FORWARD -i ppp0 -s 66.66.66.130 -j In_RULE_2
+ $IPTABLES -A FORWARD -i ppp0 -s 192.168.1.1 -j In_RULE_2
+ $IPTABLES -A In_RULE_2 -j LOG --log-level info --log-prefix "RULE 2 -- DENY "
+ $IPTABLES -A In_RULE_2 -j DROP
+ #
+ # Rule 3 (ppp0)
+ #
+ echo "Rule 3 (ppp0)"
+ #
+ # but old broadcast is permitted
+ $IPTABLES -A INPUT -i ppp0 -s 0.0.0.0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -N RULE_4
+ $IPTABLES -A OUTPUT -j RULE_4
+ $IPTABLES -A INPUT -j RULE_4
+ $IPTABLES -A FORWARD -j RULE_4
+ $IPTABLES -A RULE_4 -j LOG --log-level info --log-prefix "RULE 4 -- DENY "
+ $IPTABLES -A RULE_4 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:53:45 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall19.fw.orig b/test/ipt/firewall19.fw.orig
new file mode 100755
index 000000000..088ffa521
--- /dev/null
+++ b/test/ipt/firewall19.fw.orig
@@ -0,0 +1,569 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:47 2011 PST by vadim
+#
+# files: * firewall19.fw
+#
+# Compiled for iptables (any version)
+#
+# testing different cmbinations of objects in the policy rules on loopback interface
+
+# firewall19:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth2 eth0 eth1 lo ppp0"
+ for i in eth2 eth0 eth1 lo ppp0 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth2 66.66.66.1/25" ""
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth1 66.66.66.130/25" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ getaddr ppp0 i_ppp0
+ getaddr6 ppp0 i_ppp0_v6
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (lo)
+ #
+ echo "Rule 0 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -A OUTPUT -o lo -d $i_ppp0 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A OUTPUT -o lo -d 66.66.66.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -d 66.66.66.130 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -d 127.0.0.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (lo)
+ #
+ echo "Rule 1 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -d 66.66.66.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i lo -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i lo -d 66.66.66.130 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i lo -d 127.0.0.1 -m state --state NEW -j ACCEPT
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -A INPUT -i lo -d $i_ppp0 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A OUTPUT -o lo -d 66.66.66.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -d 66.66.66.130 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -d 127.0.0.1 -m state --state NEW -j ACCEPT
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -A OUTPUT -o lo -d $i_ppp0 -m state --state NEW -j ACCEPT
+ done
+ #
+ # Rule 2 (lo)
+ #
+ echo "Rule 2 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (lo)
+ #
+ echo "Rule 3 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -m limit --limit 2/second -j ACCEPT
+ $IPTABLES -A INPUT -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -m limit --limit 2/second -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -m limit --limit 2/second -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -N RULE_5
+ $IPTABLES -A OUTPUT -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j RULE_5
+ $IPTABLES -A INPUT -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j RULE_5
+ $IPTABLES -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j RULE_5
+ $IPTABLES -A RULE_5 -j LOG --log-level info --log-prefix "RULE 5 -- DENY "
+ $IPTABLES -A RULE_5 -j DROP
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -N Cid3EFBA6FE.0
+ $IPTABLES -A OUTPUT -j Cid3EFBA6FE.0
+ $IPTABLES -A INPUT -j Cid3EFBA6FE.0
+ $IPTABLES -A FORWARD -j Cid3EFBA6FE.0
+ $IPTABLES -A Cid3EFBA6FE.0 -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j RETURN
+ $IPTABLES -A Cid3EFBA6FE.0 -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 5190 --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 5190 --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 --dport 5190 --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j ACCEPT
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 5190 --tcp-flags SYN,RST,ACK SYN -j REJECT --reject-with icmp-host-prohibited
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 5190 --tcp-flags SYN,RST,ACK SYN -j REJECT --reject-with icmp-host-prohibited
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 --dport 5190 --tcp-flags SYN,RST,ACK SYN -j REJECT --reject-with icmp-host-prohibited
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -N Cid40038EB9.0
+ $IPTABLES -A OUTPUT -j Cid40038EB9.0
+ $IPTABLES -A INPUT -j Cid40038EB9.0
+ $IPTABLES -A FORWARD -j Cid40038EB9.0
+ $IPTABLES -A Cid40038EB9.0 -p tcp -m tcp --dport 5190 --tcp-flags SYN,RST,ACK SYN -j RETURN
+ $IPTABLES -A Cid40038EB9.0 -j REJECT --reject-with icmp-host-prohibited
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ # firewall19:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -p tcp ! --syn -dport 5190 -m state --state NEW -j REJECT --reject-with icmp-host-prohibited
+ # firewall19:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -p tcp ! --syn -dport 5190 -m state --state NEW -j REJECT --reject-with icmp-host-prohibited
+ # firewall19:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -p tcp ! --syn -dport 5190 -m state --state NEW -j REJECT --reject-with icmp-host-prohibited
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 127.0.0.1 --dport 3128 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 66.66.66.130 --dport 3128 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p tcp -m tcp -d 127.0.0.1 --dport 3128 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p tcp -m tcp -d 66.66.66.130 --dport 3128 -m state --state NEW -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ $IPTABLES -N RULE_12
+ $IPTABLES -A OUTPUT -j RULE_12
+ $IPTABLES -A INPUT -j RULE_12
+ $IPTABLES -A FORWARD -j RULE_12
+ $IPTABLES -A RULE_12 -j LOG --log-level info --log-prefix "RULE 12 -- DENY "
+ $IPTABLES -A RULE_12 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:53:47 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall2-1.fw.orig b/test/ipt/firewall2-1.fw.orig
new file mode 100755
index 000000000..6fddbe241
--- /dev/null
+++ b/test/ipt/firewall2-1.fw.orig
@@ -0,0 +1,1480 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:00 2011 PST by vadim
+#
+# files: * firewall2-1.fw
+#
+# Compiled for iptables lt_1.2.6
+#
+# copy of firewall2 but old iptables version
+
+# firewall2-1:NAT:20: warning: Adding of virtual address for address range is not implemented (object ext_range)
+
+# firewall2-1:Policy:0: error: Rule '0 (eth1)' shadows rule '3 (eth1,eth3)' below it
+# firewall2-1:Policy:0: error: Rule '0 (eth1)' shadows rule '3 (eth1,eth3)' below it
+# firewall2-1:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '5 (eth1,eth3)' below it
+# firewall2-1:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '5 (eth1,eth3)' below it
+# firewall2-1:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '5 (eth1,eth3)' below it
+# firewall2-1:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '5 (eth1,eth3)' below it
+# firewall2-1:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '6 (eth1,eth3)' below it
+# firewall2-1:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '6 (eth1,eth3)' below it
+# firewall2-1:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '6 (eth1,eth3)' below it
+# firewall2-1:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '6 (eth1,eth3)' below it
+# firewall2-1:Policy:10: error: Rule '10 (global)' shadows rule '11 (global)' below it
+# firewall2-1:Policy:10: error: Rule '10 (global)' shadows rule '12 (global)' below it
+# firewall2-1:Policy:10: error: Rule '10 (global)' shadows rule '13 (global)' below it
+# firewall2-1:Policy:10: error: Rule '10 (global)' shadows rule '14 (global)' below it
+# firewall2-1:Policy:10: error: Rule '10 (global)' shadows rule '20 (global)' below it
+# firewall2-1:Policy:25: error: Rule '25 (global)' shadows rule '26 (global)' below it
+# firewall2-1:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall2-1:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall2-1:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall2-1:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+# firewall2-1:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall2-1:Policy:: warning: Log prefix has been truncated to 29 characters
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24 192.168.1.10/24 192.168.1.50/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24 22.22.22.23/24 22.22.22.24/24 22.22.22.25/24 22.22.22.0/32 22.22.22.1/32 22.22.22.2/32 22.22.22.3/32 22.22.22.4/32 22.22.22.5/32 22.22.22.6/32 22.22.22.7/32 22.22.22.8/32 22.22.22.9/32 22.22.22.10/32 22.22.22.11/32 22.22.22.12/32 22.22.22.13/32 22.22.22.14/32 22.22.22.15/32 22.22.22.16/32 22.22.22.17/32 22.22.22.18/32 22.22.22.19/32 22.22.22.20/32 22.22.22.21/32 22.22.22.22/32 22.22.22.23/32 22.22.22.24/32 22.22.22.25/32 22.22.22.26/32 22.22.22.27/32 22.22.22.28/32 22.22.22.29/32 22.22.22.30/32 22.22.22.31/32 22.22.22.32/32 22.22.22.33/32 22.22.22.34/32 22.22.22.35/32 22.22.22.36/32 22.22.22.37/32 22.22.22.38/32 22.22.22.39/32 22.22.22.40/32 22.22.22.41/32 22.22.22.42/32 22.22.22.43/32 22.22.22.44/32 22.22.22.45/32 22.22.22.46/32 22.22.22.47/32 22.22.22.48/32 22.22.22.49/32 22.22.22.50/32 22.22.22.51/32 22.22.22.52/32 22.22.22.53/32 22.22.22.54/32 22.22.22.55/32 22.22.22.56/32 22.22.22.57/32 22.22.22.58/32 22.22.22.59/32 22.22.22.60/32 22.22.22.61/32 22.22.22.62/32 22.22.22.63/32 22.22.22.64/32 22.22.22.65/32 22.22.22.66/32 22.22.22.67/32 22.22.22.68/32 22.22.22.69/32 22.22.22.70/32 22.22.22.71/32 22.22.22.72/32 22.22.22.73/32 22.22.22.74/32 22.22.22.75/32 22.22.22.76/32 22.22.22.77/32 22.22.22.78/32 22.22.22.79/32 22.22.22.80/32 22.22.22.81/32 22.22.22.82/32 22.22.22.83/32 22.22.22.84/32 22.22.22.85/32 22.22.22.86/32 22.22.22.87/32 22.22.22.88/32 22.22.22.89/32 22.22.22.90/32 22.22.22.91/32 22.22.22.92/32 22.22.22.93/32 22.22.22.94/32 22.22.22.95/32 22.22.22.96/32 22.22.22.97/32 22.22.22.98/32 22.22.22.99/32 22.22.22.100/32 22.22.22.101/32 22.22.22.102/32 22.22.22.103/32 22.22.22.104/32 22.22.22.105/32 22.22.22.106/32 22.22.22.107/32 22.22.22.108/32 22.22.22.109/32 22.22.22.110/32 22.22.22.111/32 22.22.22.112/32 22.22.22.113/32 22.22.22.114/32 22.22.22.115/32 22.22.22.116/32 22.22.22.117/32 22.22.22.118/32 22.22.22.119/32 22.22.22.120/32 22.22.22.121/32 22.22.22.122/32 22.22.22.123/32 22.22.22.124/32 22.22.22.125/32 22.22.22.126/32 22.22.22.127/32 22.22.22.128/32 22.22.22.129/32 22.22.22.130/32 22.22.22.131/32 22.22.22.132/32 22.22.22.133/32 22.22.22.134/32 22.22.22.135/32 22.22.22.136/32 22.22.22.137/32 22.22.22.138/32 22.22.22.139/32 22.22.22.140/32 22.22.22.141/32 22.22.22.142/32 22.22.22.143/32 22.22.22.144/32 22.22.22.145/32 22.22.22.146/32 22.22.22.147/32 22.22.22.148/32 22.22.22.149/32 22.22.22.150/32 22.22.22.151/32 22.22.22.152/32 22.22.22.153/32 22.22.22.154/32 22.22.22.155/32 22.22.22.156/32 22.22.22.157/32 22.22.22.158/32 22.22.22.159/32 22.22.22.160/32 22.22.22.161/32 22.22.22.162/32 22.22.22.163/32 22.22.22.164/32 22.22.22.165/32 22.22.22.166/32 22.22.22.167/32 22.22.22.168/32 22.22.22.169/32 22.22.22.170/32 22.22.22.171/32 22.22.22.172/32 22.22.22.173/32 22.22.22.174/32 22.22.22.175/32 22.22.22.176/32 22.22.22.177/32 22.22.22.178/32 22.22.22.179/32 22.22.22.180/32 22.22.22.181/32 22.22.22.182/32 22.22.22.183/32 22.22.22.184/32 22.22.22.185/32 22.22.22.186/32 22.22.22.187/32 22.22.22.188/32 22.22.22.189/32 22.22.22.190/32 22.22.22.191/32 22.22.22.192/32 22.22.22.193/32 22.22.22.194/32 22.22.22.195/32 22.22.22.196/32 22.22.22.197/32 22.22.22.198/32 22.22.22.199/32 22.22.22.200/32 22.22.22.201/32 22.22.22.202/32 22.22.22.203/32 22.22.22.204/32 22.22.22.205/32 22.22.22.206/32 22.22.22.207/32 22.22.22.208/32 22.22.22.209/32 22.22.22.210/32 22.22.22.211/32 22.22.22.212/32 22.22.22.213/32 22.22.22.214/32 22.22.22.215/32 22.22.22.216/32 22.22.22.217/32 22.22.22.218/32 22.22.22.219/32 22.22.22.220/32 22.22.22.221/32 22.22.22.222/32 22.22.22.223/32 22.22.22.224/32 22.22.22.225/32 22.22.22.226/32 22.22.22.227/32 22.22.22.228/32 22.22.22.229/32 22.22.22.230/32 22.22.22.231/32 22.22.22.232/32 22.22.22.233/32 22.22.22.234/32 22.22.22.235/32 22.22.22.236/32 22.22.22.237/32 22.22.22.238/32 22.22.22.239/32 22.22.22.240/32 22.22.22.241/32 22.22.22.242/32 22.22.22.243/32 22.22.22.244/32 22.22.22.245/32 22.22.22.246/32 22.22.22.247/32 22.22.22.248/32 22.22.22.249/32 22.22.22.250/32 22.22.22.251/32 22.22.22.252/32 22.22.22.253/32 22.22.22.254/32" ""
+ update_addresses_of_interface "eth3 22.22.23.23/24 22.22.25.50/24 22.22.23.24/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24 192.168.2.40/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ echo 1 > /proc/sys/net/ipv4/conf/all/rp_filter
+ echo 0 > /proc/sys/net/ipv4/conf/all/accept_source_route
+ echo 0 > /proc/sys/net/ipv4/conf/all/accept_redirects
+ echo 1 > /proc/sys/net/ipv4/conf/all/log_martians
+ echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_all
+ echo 1 > /proc/sys/net/ipv4/icmp_ignore_bogus_error_responses
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ $IPTABLES -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
+
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop TCP sessions opened prior firewall restart
+ $IPTABLES -A INPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ $IPTABLES -A OUTPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ $IPTABLES -A FORWARD -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ # drop packets that do not match any valid state and log them
+ $IPTABLES -N drop_invalid
+ $IPTABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IPTABLES -A drop_invalid -j ULOG --ulog-nlgroup 1 --ulog-qthreshold 1 --ulog-prefix "INVALID state -- DENY "
+ $IPTABLES -A drop_invalid -j DROP
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.40
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 192.168.2.40
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.40
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ #
+ # Rule 6 (NAT)
+ #
+ echo "Rule 6 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 22.22.22.23
+ #
+ # Rule 7 (NAT)
+ #
+ echo "Rule 7 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 22.22.22.23
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 22.22.22.24
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 22.22.22.25
+ #
+ # Rule 8 (NAT)
+ #
+ echo "Rule 8 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -d 192.168.1.10 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 9 (NAT)
+ #
+ echo "Rule 9 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid31547X1798.0
+ $IPTABLES -t nat -A POSTROUTING -d 192.168.2.10 -j Cid31547X1798.0
+ $IPTABLES -t nat -A POSTROUTING -d 192.168.2.11 -j Cid31547X1798.0
+ $IPTABLES -t nat -A Cid31547X1798.0 -s 22.22.22.22 -j ACCEPT
+ $IPTABLES -t nat -A Cid31547X1798.0 -s 22.22.23.23 -j ACCEPT
+ $IPTABLES -t nat -A Cid31547X1798.0 -s 22.22.25.50 -j ACCEPT
+ $IPTABLES -t nat -A Cid31547X1798.0 -s 192.168.1.1 -j ACCEPT
+ $IPTABLES -t nat -A Cid31547X1798.0 -s 192.168.2.1 -j ACCEPT
+ $IPTABLES -t nat -A Cid31547X1798.0 -s 192.168.2.40 -j ACCEPT
+ $IPTABLES -t nat -A OUTPUT -d 192.168.2.10 -j ACCEPT
+ $IPTABLES -t nat -A OUTPUT -d 192.168.2.11 -j ACCEPT
+ $IPTABLES -t nat -N Cid31547X1798.1
+ $IPTABLES -t nat -A POSTROUTING -d 192.168.2.10 -j Cid31547X1798.1
+ $IPTABLES -t nat -A POSTROUTING -d 192.168.2.11 -j Cid31547X1798.1
+ $IPTABLES -t nat -A Cid31547X1798.1 -s 192.168.1.10 -j ACCEPT
+ $IPTABLES -t nat -A Cid31547X1798.1 -s 192.168.1.20 -j ACCEPT
+ $IPTABLES -t nat -N Cid31547X1798.2
+ $IPTABLES -t nat -A PREROUTING -d 192.168.2.10 -j Cid31547X1798.2
+ $IPTABLES -t nat -A PREROUTING -d 192.168.2.11 -j Cid31547X1798.2
+ $IPTABLES -t nat -A Cid31547X1798.2 -s 192.168.1.10 -j ACCEPT
+ $IPTABLES -t nat -A Cid31547X1798.2 -s 192.168.1.20 -j ACCEPT
+ #
+ # Rule 10 (NAT)
+ #
+ echo "Rule 10 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid31565X1798.0
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.10 -j Cid31565X1798.0
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.20 -j Cid31565X1798.0
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.10 -j Cid31565X1798.0
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.20 -j Cid31565X1798.0
+ $IPTABLES -t nat -A Cid31565X1798.0 -d 192.168.2.10 -j RETURN
+ $IPTABLES -t nat -A Cid31565X1798.0 -d 192.168.2.11 -j RETURN
+ $IPTABLES -t nat -A Cid31565X1798.0 -j ACCEPT
+ #
+ # Rule 11 (NAT)
+ #
+ echo "Rule 11 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/1 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 22.22.22.23 --icmp-type 0/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 22.22.22.23 --icmp-type 3 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 22.22.22.23 --destination-port 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p 50 -d 22.22.22.23 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p 88 -d 22.22.22.23 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/1 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 0/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 3 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.23 --destination-port 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p 50 -d 22.22.22.23 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p 88 -d 22.22.22.23 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 12 (NAT)
+ #
+ echo "Rule 12 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/1 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 0/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 3 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.23 --destination-port 80,119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 13 (NAT)
+ #
+ echo "Rule 13 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -s 22.22.23.23 -d 22.22.22.23 --destination-port 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -s 22.22.25.50 -d 22.22.22.23 --destination-port 80,119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 14 (NAT)
+ #
+ echo "Rule 14 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.23 --destination-port 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -s 200.200.200.200 -d 22.22.22.23 --destination-port 80,119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 16 (NAT)
+ #
+ echo "Rule 16 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 22.22.22.23 --destination-port 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 22.22.22.24 --destination-port 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 22.22.22.25 --destination-port 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.23 --destination-port 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.24 --destination-port 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.25 --destination-port 80,119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 17 (NAT)
+ #
+ echo "Rule 17 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 18 (NAT)
+ #
+ echo "Rule 18 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.20 -j SNAT --to-source 22.22.23.24
+ #
+ # Rule 19 (NAT)
+ #
+ echo "Rule 19 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -d 22.22.23.24 -j DNAT --to-destination 192.168.1.20
+ $IPTABLES -t nat -A OUTPUT -d 22.22.23.24 -j DNAT --to-destination 192.168.1.20
+ #
+ # Rule 20 (NAT)
+ #
+ echo "Rule 20 (NAT)"
+ #
+ # firewall2-1:NAT:20: warning: Adding of virtual address for address range is not implemented (object ext_range)
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.100-22.22.22.110
+ #
+ # Rule 21 (NAT)
+ #
+ echo "Rule 21 (NAT)"
+ #
+ # NETMAP
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.0/24 -j NETMAP --to 22.22.22.0/24
+ #
+ # Rule 22 (NAT)
+ #
+ echo "Rule 22 (NAT)"
+ #
+ # NETMAP
+ $IPTABLES -t nat -A PREROUTING -d 22.22.22.0/24 -j NETMAP --to 192.168.1.0/24
+ #
+ # Rule 23 (NAT)
+ #
+ echo "Rule 23 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.23 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.25.50 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.40 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.23.23 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.25.50 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 192.168.1.1 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 192.168.2.1 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 192.168.2.40 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ #
+ # Rule 24 (NAT)
+ #
+ echo "Rule 24 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.23 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.25.50 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.23.23 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.25.50 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -d 192.168.1.10 --dport 80 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 25 (NAT)
+ #
+ echo "Rule 25 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.23 --dport 80 -j DNAT --to-destination 192.168.1.10:25
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.23 --dport 80 -j DNAT --to-destination 192.168.1.10:25
+ #
+ # Rule 26 (NAT)
+ #
+ echo "Rule 26 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.23 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.25.50 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.40 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.23 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.25.50 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.40 --dport 443 -j REDIRECT --to-ports 3128
+ #
+ # Rule 27 (NAT)
+ #
+ echo "Rule 27 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 8080 -j DNAT --to-destination 192.168.1.10-192.168.1.100
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 8080 -j DNAT --to-destination 192.168.1.10-192.168.1.100
+ #
+ # Rule 28 (NAT)
+ #
+ echo "Rule 28 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 8080 -j DNAT --to-destination 192.168.1.11-192.168.1.15
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 8080 -j DNAT --to-destination 192.168.1.11-192.168.1.15
+ #
+ # Rule 29 (NAT)
+ #
+ echo "Rule 29 (NAT)"
+ #
+ # transparent proxy rule
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.0/24 -d ! 22.22.22.23 -j DNAT --to-destination 192.168.2.10
+ #
+ # Rule 31 (NAT)
+ #
+ echo "Rule 31 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j DNAT --to-destination :8080
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j DNAT --to-destination :8080
+ #
+ # Rule 32 (NAT)
+ #
+ echo "Rule 32 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.10 --dport 80 -j DNAT --to-destination 192.168.1.10:8080
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 192.168.1.10 --dport 80 -j DNAT --to-destination 192.168.1.10:8080
+ #
+ # Rule 33 (NAT)
+ #
+ echo "Rule 33 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --dport 80 -j SNAT --to-source 22.22.22.22
+ #
+ # Rule 34 (NAT)
+ #
+ echo "Rule 34 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s ! 192.168.1.10 --dport 80 -j DNAT --to-destination 192.168.1.10:3128
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.10:3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s ! 192.168.1.10 --dport 80 -j DNAT --to-destination 192.168.1.10:3128
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -s ! 192.168.1.10 -d 192.168.1.10 --dport 3128 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 35 (NAT)
+ #
+ echo "Rule 35 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid31935X1798.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d ! 192.168.1.50 --dport 80 -j Cid31935X1798.0
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d ! 192.168.1.50 --dport 80 -j Cid31935X1798.0
+ $IPTABLES -t nat -A Cid31935X1798.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid31935X1798.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid31935X1798.0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.50:3128
+ #
+ # Rule 36 (NAT)
+ #
+ echo "Rule 36 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid31949X1798.1
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -j Cid31949X1798.1
+ $IPTABLES -t nat -A Cid31949X1798.1 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid31949X1798.1 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -N Cid31949X1798.0
+ $IPTABLES -t nat -A Cid31949X1798.1 -j Cid31949X1798.0
+ $IPTABLES -t nat -A Cid31949X1798.0 -p tcp -m tcp --dport 80 -j RETURN
+ $IPTABLES -t nat -A Cid31949X1798.0 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 37 (NAT)
+ #
+ echo "Rule 37 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j DNAT --to-destination 192.168.1.10:3128
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.10 --dport 3128 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 38 (NAT)
+ #
+ echo "Rule 38 (NAT)"
+ #
+ # this is the "exception" rule
+ # used in support req. originally
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.20 --dport 80 -j SNAT --to-source 22.22.22.22
+ #
+ # Rule 39 (NAT)
+ #
+ echo "Rule 39 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j DNAT --to-destination 192.168.1.1:3128
+ #
+ # Rule 40 (NAT)
+ #
+ echo "Rule 40 (NAT)"
+ #
+ # "exception" rule in the pair
+ # from a support req.
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.20 --dport 80 -j SNAT --to-source 22.22.22.22
+ #
+ # Rule 41 (NAT)
+ #
+ echo "Rule 41 (NAT)"
+ #
+ # testing transparent proxy
+ # roules for a support req.
+ $IPTABLES -t nat -N Cid32019X1798.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j Cid32019X1798.0
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j Cid32019X1798.0
+ $IPTABLES -t nat -A Cid32019X1798.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid32019X1798.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid32019X1798.0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.1:3128
+ #
+ # Rule 42 (NAT)
+ #
+ echo "Rule 42 (NAT)"
+ #
+ # testing transparent proxy
+ # roules for a support req.
+ $IPTABLES -t nat -N Cid32033X1798.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j Cid32033X1798.0
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j Cid32033X1798.0
+ $IPTABLES -t nat -A Cid32033X1798.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid32033X1798.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid32033X1798.0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.1:3128
+ #
+ # Rule 43 (NAT)
+ #
+ echo "Rule 43 (NAT)"
+ #
+ # testing transparent proxy
+ # roules for a support req.
+ $IPTABLES -t nat -N Cid32047X1798.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j Cid32047X1798.0
+ $IPTABLES -t nat -A Cid32047X1798.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid32047X1798.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid32047X1798.0 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
+ #
+ # Rule 44 (NAT)
+ #
+ echo "Rule 44 (NAT)"
+ #
+ # "exception" rule in the pair
+ # from a support req.
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.20 --dport 80 -j SNAT --to-source 22.22.22.22
+ #
+ # Rule 45 (NAT)
+ #
+ echo "Rule 45 (NAT)"
+ #
+ # testing transparent proxy
+ # roules for a support req.
+ $IPTABLES -t nat -N Cid32075X1798.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j Cid32075X1798.0
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j Cid32075X1798.0
+ $IPTABLES -t nat -A Cid32075X1798.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid32075X1798.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid32075X1798.0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.50:3128
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth1)
+ #
+ echo "Rule 0 (eth1)"
+ #
+ # Anti-spoofing rule
+ $IPTABLES -N In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 22.22.22.22 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 22.22.23.23 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 22.22.25.50 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 192.168.1.1 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 192.168.2.1 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 192.168.2.40 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 192.168.1.0/24 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 22.22.22.22 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 22.22.23.23 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 22.22.25.50 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.1.1 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.2.1 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.2.40 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.1.0/24 -j In_RULE_0
+ $IPTABLES -A In_RULE_0 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "Iface: global RULE 0 -- DENY " --ulog-qthreshold 1
+ $IPTABLES -A In_RULE_0 -j DROP
+ #
+ # Rule 1 (eth1)
+ #
+ echo "Rule 1 (eth1)"
+ #
+ # Anti-spoofing rule
+ $IPTABLES -N Cid31178X1798.0
+ $IPTABLES -A OUTPUT -o eth1 -j Cid31178X1798.0
+ $IPTABLES -A Cid31178X1798.0 -s 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid31178X1798.0 -s 22.22.23.23 -j RETURN
+ $IPTABLES -A Cid31178X1798.0 -s 22.22.25.50 -j RETURN
+ $IPTABLES -A Cid31178X1798.0 -s 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid31178X1798.0 -s 192.168.2.1 -j RETURN
+ $IPTABLES -A Cid31178X1798.0 -s 192.168.2.40 -j RETURN
+ $IPTABLES -N Out_RULE_1_3
+ $IPTABLES -A Cid31178X1798.0 -j Out_RULE_1_3
+ $IPTABLES -A Out_RULE_1_3 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "Iface: global RULE 1 -- DENY " --ulog-qthreshold 1
+ $IPTABLES -A Out_RULE_1_3 -j DROP
+ $IPTABLES -N Cid31178X1798.1
+ $IPTABLES -A FORWARD -o eth1 -j Cid31178X1798.1
+ $IPTABLES -A Cid31178X1798.1 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid31178X1798.1 -j Out_RULE_1_3
+ #
+ # Rule 2 (fw2i1,3)
+ #
+ echo "Rule 2 (fw2i1,3)"
+ #
+ # testing group in "interface"
+ # this rule should be identical to rule 3
+ $IPTABLES -N In_RULE_2
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 --destination-port 68,67 -j In_RULE_2
+ $IPTABLES -A INPUT -i eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 --destination-port 68,67 -j In_RULE_2
+ $IPTABLES -A FORWARD -i eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 --destination-port 68,67 -j In_RULE_2
+ $IPTABLES -A FORWARD -i eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 --destination-port 68,67 -j In_RULE_2
+ $IPTABLES -A In_RULE_2 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 2 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A In_RULE_2 -j DROP
+ #
+ # Rule 3 (eth1,eth3)
+ #
+ echo "Rule 3 (eth1,eth3)"
+ #
+ $IPTABLES -N In_RULE_3
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 --destination-port 68,67 -j In_RULE_3
+ $IPTABLES -A INPUT -i eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 --destination-port 68,67 -j In_RULE_3
+ $IPTABLES -A FORWARD -i eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 --destination-port 68,67 -j In_RULE_3
+ $IPTABLES -A FORWARD -i eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 --destination-port 68,67 -j In_RULE_3
+ $IPTABLES -A In_RULE_3 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 3 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A In_RULE_3 -j DROP
+ #
+ # Rule 4 (eth1,eth3)
+ #
+ echo "Rule 4 (eth1,eth3)"
+ #
+ # testing choice of chains in case when several
+ # interfaces are used and rule matches 'any' or
+ # broadcast
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -m multiport -d 255.255.255.255 --destination-port 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth3 -p udp -m udp -m multiport -d 255.255.255.255 --destination-port 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth1 -p udp -m udp -m multiport -d 255.255.255.255 --destination-port 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth3 -p udp -m udp -m multiport -d 255.255.255.255 --destination-port 68,67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (eth1,eth3)
+ #
+ echo "Rule 5 (eth1,eth3)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -m multiport -s 0.0.0.0 -d 255.255.255.255 --destination-port 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth3 -p udp -m udp -m multiport -s 0.0.0.0 -d 255.255.255.255 --destination-port 68,67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 6 (eth1,eth3)
+ #
+ echo "Rule 6 (eth1,eth3)"
+ #
+ $IPTABLES -A OUTPUT -o eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 -d 255.255.255.255 --destination-port 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 -d 255.255.255.255 --destination-port 68,67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -N Cid31255X1798.0
+ $IPTABLES -A OUTPUT -j Cid31255X1798.0
+ $IPTABLES -A INPUT -j Cid31255X1798.0
+ $IPTABLES -A FORWARD -j Cid31255X1798.0
+ $IPTABLES -A Cid31255X1798.0 -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j RETURN
+ $IPTABLES -N RULE_7_3
+ $IPTABLES -A Cid31255X1798.0 -j RULE_7_3
+ $IPTABLES -A RULE_7_3 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 7 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_7_3 -j DROP
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ # block fragments
+ $IPTABLES -N RULE_8
+ $IPTABLES -A OUTPUT -p all -f -j RULE_8
+ $IPTABLES -A INPUT -p all -f -j RULE_8
+ $IPTABLES -A FORWARD -p all -f -j RULE_8
+ $IPTABLES -A RULE_8 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 8 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_8 -j DROP
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ # sends TCP RST and makes custom record
+ # in the log
+ $IPTABLES -N RULE_9
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 113 -j RULE_9
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 113 -j RULE_9
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 113 -j RULE_9
+ $IPTABLES -A RULE_9 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "IDENT" --ulog-qthreshold 1
+ $IPTABLES -A RULE_9 -p tcp -m tcp -j REJECT --reject-with tcp-reset
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ # firewall2-1:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -N RULE_10
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -j RULE_10
+ # firewall2-1:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -j RULE_10
+ # firewall2-1:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -j RULE_10
+ # firewall2-1:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A RULE_10 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 10 - REJECT **" --ulog-qthreshold 1
+ # firewall2-1:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A RULE_10 -j REJECT --reject-with icmp-net-unreachable
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid112778X70161.0
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid112778X70161.0
+ $IPTABLES -A Cid112778X70161.0 -d 192.168.1.10/31 -j ACCEPT
+ $IPTABLES -A Cid112778X70161.0 -d 192.168.1.12/30 -j ACCEPT
+ $IPTABLES -A Cid112778X70161.0 -d 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid112778X70161.0 -d 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid112778X70161.0 -d 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid112778X70161.0 -d 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid112778X70161.0 -d 192.168.1.100 -j ACCEPT
+ $IPTABLES -N Cid112778X70161.1
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid112778X70161.1
+ $IPTABLES -A Cid112778X70161.1 -d 192.168.1.10/31 -j ACCEPT
+ $IPTABLES -A Cid112778X70161.1 -d 192.168.1.12/30 -j ACCEPT
+ $IPTABLES -A Cid112778X70161.1 -d 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid112778X70161.1 -d 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid112778X70161.1 -d 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid112778X70161.1 -d 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid112778X70161.1 -d 192.168.1.100 -j ACCEPT
+ $IPTABLES -N Cid112778X70161.2
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid112778X70161.2
+ $IPTABLES -A Cid112778X70161.2 -d 192.168.1.10/31 -j ACCEPT
+ $IPTABLES -A Cid112778X70161.2 -d 192.168.1.12/30 -j ACCEPT
+ $IPTABLES -A Cid112778X70161.2 -d 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid112778X70161.2 -d 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid112778X70161.2 -d 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid112778X70161.2 -d 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid112778X70161.2 -d 192.168.1.100 -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid94383X70161.0
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid94383X70161.0
+ $IPTABLES -A Cid94383X70161.0 -s 192.168.1.10/31 -j ACCEPT
+ $IPTABLES -A Cid94383X70161.0 -s 192.168.1.12/30 -j ACCEPT
+ $IPTABLES -A Cid94383X70161.0 -s 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid94383X70161.0 -s 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid94383X70161.0 -s 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid94383X70161.0 -s 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid94383X70161.0 -s 192.168.1.100 -j ACCEPT
+ $IPTABLES -N Cid94383X70161.1
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid94383X70161.1
+ $IPTABLES -A Cid94383X70161.1 -s 192.168.1.10/31 -j ACCEPT
+ $IPTABLES -A Cid94383X70161.1 -s 192.168.1.12/30 -j ACCEPT
+ $IPTABLES -A Cid94383X70161.1 -s 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid94383X70161.1 -s 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid94383X70161.1 -s 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid94383X70161.1 -s 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid94383X70161.1 -s 192.168.1.100 -j ACCEPT
+ $IPTABLES -N Cid94383X70161.2
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid94383X70161.2
+ $IPTABLES -A Cid94383X70161.2 -s 192.168.1.10/31 -j ACCEPT
+ $IPTABLES -A Cid94383X70161.2 -s 192.168.1.12/30 -j ACCEPT
+ $IPTABLES -A Cid94383X70161.2 -s 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid94383X70161.2 -s 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid94383X70161.2 -s 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid94383X70161.2 -s 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid94383X70161.2 -s 192.168.1.100 -j ACCEPT
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid131133X70161.0
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid131133X70161.0
+ $IPTABLES -N Cid131133X70161.1
+ $IPTABLES -A Cid131133X70161.0 -s 222.222.222.10/31 -j Cid131133X70161.1
+ $IPTABLES -A Cid131133X70161.0 -s 222.222.222.12/30 -j Cid131133X70161.1
+ $IPTABLES -A Cid131133X70161.0 -s 222.222.222.16/28 -j Cid131133X70161.1
+ $IPTABLES -A Cid131133X70161.0 -s 222.222.222.32/27 -j Cid131133X70161.1
+ $IPTABLES -A Cid131133X70161.0 -s 222.222.222.64/27 -j Cid131133X70161.1
+ $IPTABLES -A Cid131133X70161.0 -s 222.222.222.96/30 -j Cid131133X70161.1
+ $IPTABLES -A Cid131133X70161.0 -s 222.222.222.100 -j Cid131133X70161.1
+ $IPTABLES -A Cid131133X70161.1 -d 192.168.1.10/31 -j ACCEPT
+ $IPTABLES -A Cid131133X70161.1 -d 192.168.1.12/30 -j ACCEPT
+ $IPTABLES -A Cid131133X70161.1 -d 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid131133X70161.1 -d 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid131133X70161.1 -d 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid131133X70161.1 -d 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid131133X70161.1 -d 192.168.1.100 -j ACCEPT
+ $IPTABLES -N Cid131133X70161.2
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid131133X70161.2
+ $IPTABLES -N Cid131133X70161.3
+ $IPTABLES -A Cid131133X70161.2 -s 222.222.222.10/31 -j Cid131133X70161.3
+ $IPTABLES -A Cid131133X70161.2 -s 222.222.222.12/30 -j Cid131133X70161.3
+ $IPTABLES -A Cid131133X70161.2 -s 222.222.222.16/28 -j Cid131133X70161.3
+ $IPTABLES -A Cid131133X70161.2 -s 222.222.222.32/27 -j Cid131133X70161.3
+ $IPTABLES -A Cid131133X70161.2 -s 222.222.222.64/27 -j Cid131133X70161.3
+ $IPTABLES -A Cid131133X70161.2 -s 222.222.222.96/30 -j Cid131133X70161.3
+ $IPTABLES -A Cid131133X70161.2 -s 222.222.222.100 -j Cid131133X70161.3
+ $IPTABLES -A Cid131133X70161.3 -d 192.168.1.10/31 -j ACCEPT
+ $IPTABLES -A Cid131133X70161.3 -d 192.168.1.12/30 -j ACCEPT
+ $IPTABLES -A Cid131133X70161.3 -d 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid131133X70161.3 -d 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid131133X70161.3 -d 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid131133X70161.3 -d 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid131133X70161.3 -d 192.168.1.100 -j ACCEPT
+ #
+ # Rule 14 (global)
+ #
+ echo "Rule 14 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid131116X70161.0
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid131116X70161.0
+ $IPTABLES -N Cid131116X70161.1
+ $IPTABLES -A Cid131116X70161.0 -s 192.168.1.10/31 -j Cid131116X70161.1
+ $IPTABLES -A Cid131116X70161.0 -s 192.168.1.12/30 -j Cid131116X70161.1
+ $IPTABLES -A Cid131116X70161.0 -s 192.168.1.16/28 -j Cid131116X70161.1
+ $IPTABLES -A Cid131116X70161.0 -s 192.168.1.32/27 -j Cid131116X70161.1
+ $IPTABLES -A Cid131116X70161.0 -s 192.168.1.64/27 -j Cid131116X70161.1
+ $IPTABLES -A Cid131116X70161.0 -s 192.168.1.96/30 -j Cid131116X70161.1
+ $IPTABLES -A Cid131116X70161.0 -s 192.168.1.100 -j Cid131116X70161.1
+ $IPTABLES -A Cid131116X70161.1 -d 222.222.222.10/31 -j ACCEPT
+ $IPTABLES -A Cid131116X70161.1 -d 222.222.222.12/30 -j ACCEPT
+ $IPTABLES -A Cid131116X70161.1 -d 222.222.222.16/28 -j ACCEPT
+ $IPTABLES -A Cid131116X70161.1 -d 222.222.222.32/27 -j ACCEPT
+ $IPTABLES -A Cid131116X70161.1 -d 222.222.222.64/27 -j ACCEPT
+ $IPTABLES -A Cid131116X70161.1 -d 222.222.222.96/30 -j ACCEPT
+ $IPTABLES -A Cid131116X70161.1 -d 222.222.222.100 -j ACCEPT
+ $IPTABLES -N Cid131116X70161.2
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid131116X70161.2
+ $IPTABLES -N Cid131116X70161.3
+ $IPTABLES -A Cid131116X70161.2 -s 192.168.1.10/31 -j Cid131116X70161.3
+ $IPTABLES -A Cid131116X70161.2 -s 192.168.1.12/30 -j Cid131116X70161.3
+ $IPTABLES -A Cid131116X70161.2 -s 192.168.1.16/28 -j Cid131116X70161.3
+ $IPTABLES -A Cid131116X70161.2 -s 192.168.1.32/27 -j Cid131116X70161.3
+ $IPTABLES -A Cid131116X70161.2 -s 192.168.1.64/27 -j Cid131116X70161.3
+ $IPTABLES -A Cid131116X70161.2 -s 192.168.1.96/30 -j Cid131116X70161.3
+ $IPTABLES -A Cid131116X70161.2 -s 192.168.1.100 -j Cid131116X70161.3
+ $IPTABLES -A Cid131116X70161.3 -d 222.222.222.10/31 -j ACCEPT
+ $IPTABLES -A Cid131116X70161.3 -d 222.222.222.12/30 -j ACCEPT
+ $IPTABLES -A Cid131116X70161.3 -d 222.222.222.16/28 -j ACCEPT
+ $IPTABLES -A Cid131116X70161.3 -d 222.222.222.32/27 -j ACCEPT
+ $IPTABLES -A Cid131116X70161.3 -d 222.222.222.64/27 -j ACCEPT
+ $IPTABLES -A Cid131116X70161.3 -d 222.222.222.96/30 -j ACCEPT
+ $IPTABLES -A Cid131116X70161.3 -d 222.222.222.100 -j ACCEPT
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid94366X70161.0
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid94366X70161.0
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid94366X70161.0
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid94366X70161.0
+ $IPTABLES -A Cid94366X70161.0 -d 192.168.1.10/31 -j RETURN
+ $IPTABLES -A Cid94366X70161.0 -d 192.168.1.12/30 -j RETURN
+ $IPTABLES -A Cid94366X70161.0 -d 192.168.1.16/28 -j RETURN
+ $IPTABLES -A Cid94366X70161.0 -d 192.168.1.32/27 -j RETURN
+ $IPTABLES -A Cid94366X70161.0 -d 192.168.1.64/27 -j RETURN
+ $IPTABLES -A Cid94366X70161.0 -d 192.168.1.96/30 -j RETURN
+ $IPTABLES -A Cid94366X70161.0 -d 192.168.1.100 -j RETURN
+ $IPTABLES -A Cid94366X70161.0 -j ACCEPT
+ #
+ # Rule 16 (global)
+ #
+ echo "Rule 16 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid94349X70161.0
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid94349X70161.0
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid94349X70161.0
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid94349X70161.0
+ $IPTABLES -A Cid94349X70161.0 -s 192.168.1.10/31 -j RETURN
+ $IPTABLES -A Cid94349X70161.0 -s 192.168.1.12/30 -j RETURN
+ $IPTABLES -A Cid94349X70161.0 -s 192.168.1.16/28 -j RETURN
+ $IPTABLES -A Cid94349X70161.0 -s 192.168.1.32/27 -j RETURN
+ $IPTABLES -A Cid94349X70161.0 -s 192.168.1.64/27 -j RETURN
+ $IPTABLES -A Cid94349X70161.0 -s 192.168.1.96/30 -j RETURN
+ $IPTABLES -A Cid94349X70161.0 -s 192.168.1.100 -j RETURN
+ $IPTABLES -A Cid94349X70161.0 -j ACCEPT
+ #
+ # Rule 17 (global)
+ #
+ echo "Rule 17 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid94331X70161.0
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid94331X70161.0
+ $IPTABLES -A Cid94331X70161.0 -d 192.168.1.0 -j RETURN
+ $IPTABLES -A Cid94331X70161.0 -j ACCEPT
+ $IPTABLES -N Cid94331X70161.1
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid94331X70161.1
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid94331X70161.1
+ $IPTABLES -A Cid94331X70161.1 -d 192.168.1.10/31 -j RETURN
+ $IPTABLES -A Cid94331X70161.1 -d 192.168.1.12/30 -j RETURN
+ $IPTABLES -A Cid94331X70161.1 -d 192.168.1.16/28 -j RETURN
+ $IPTABLES -A Cid94331X70161.1 -d 192.168.1.32/27 -j RETURN
+ $IPTABLES -A Cid94331X70161.1 -d 192.168.1.64/27 -j RETURN
+ $IPTABLES -A Cid94331X70161.1 -d 192.168.1.96/30 -j RETURN
+ $IPTABLES -A Cid94331X70161.1 -d 192.168.1.100 -j RETURN
+ $IPTABLES -A Cid94331X70161.1 -j ACCEPT
+ #
+ # Rule 18 (global)
+ #
+ echo "Rule 18 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid94313X70161.0
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid94313X70161.0
+ $IPTABLES -A Cid94313X70161.0 -s 192.168.1.0 -j RETURN
+ $IPTABLES -A Cid94313X70161.0 -j ACCEPT
+ $IPTABLES -N Cid94313X70161.1
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid94313X70161.1
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid94313X70161.1
+ $IPTABLES -A Cid94313X70161.1 -s 192.168.1.10/31 -j RETURN
+ $IPTABLES -A Cid94313X70161.1 -s 192.168.1.12/30 -j RETURN
+ $IPTABLES -A Cid94313X70161.1 -s 192.168.1.16/28 -j RETURN
+ $IPTABLES -A Cid94313X70161.1 -s 192.168.1.32/27 -j RETURN
+ $IPTABLES -A Cid94313X70161.1 -s 192.168.1.64/27 -j RETURN
+ $IPTABLES -A Cid94313X70161.1 -s 192.168.1.96/30 -j RETURN
+ $IPTABLES -A Cid94313X70161.1 -s 192.168.1.100 -j RETURN
+ $IPTABLES -A Cid94313X70161.1 -j ACCEPT
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ # also test for bug #2526173
+ $IPTABLES -N RULE_19
+ $IPTABLES -A INPUT -s 0.0.0.0 -j RULE_19
+ $IPTABLES -A FORWARD -s 0.0.0.0 -j RULE_19
+ $IPTABLES -A RULE_19 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 19 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_19 -j DROP
+ #
+ # Rule 20 (global)
+ #
+ echo "Rule 20 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -A INPUT -p udp -m udp -s 192.168.1.1 --dport 161 -m state --state NEW -j ACCEPT
+ $IPTABLES -N Cid80837X35957.0
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid80837X35957.0
+ $IPTABLES -A Cid80837X35957.0 -s 192.168.1.2/31 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.0 -s 192.168.1.4/30 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.0 -s 192.168.1.8/29 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.0 -s 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.0 -s 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.0 -s 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.0 -s 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.0 -s 192.168.1.100 -j ACCEPT
+ $IPTABLES -A OUTPUT -p udp -m udp -s 192.168.1.1 --dport 161 -m state --state NEW -j ACCEPT
+ $IPTABLES -N Cid80837X35957.1
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid80837X35957.1
+ $IPTABLES -A Cid80837X35957.1 -s 192.168.1.2/31 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.1 -s 192.168.1.4/30 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.1 -s 192.168.1.8/29 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.1 -s 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.1 -s 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.1 -s 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.1 -s 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.1 -s 192.168.1.100 -j ACCEPT
+ $IPTABLES -N Cid80837X35957.2
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid80837X35957.2
+ $IPTABLES -A Cid80837X35957.2 -s 192.168.1.2/31 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.2 -s 192.168.1.4/30 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.2 -s 192.168.1.8/29 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.2 -s 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.2 -s 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.2 -s 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.2 -s 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid80837X35957.2 -s 192.168.1.100 -j ACCEPT
+ #
+ # Rule 21 (global)
+ #
+ echo "Rule 21 (global)"
+ #
+ $IPTABLES -N Cid31303X1798.0
+ $IPTABLES -A INPUT -p icmp -s 192.168.2.0/24 -m state --state NEW -j Cid31303X1798.0
+ $IPTABLES -N RULE_21
+ $IPTABLES -A Cid31303X1798.0 -d 192.168.2.1 -j RULE_21
+ $IPTABLES -A Cid31303X1798.0 -d 192.168.2.40 -j RULE_21
+ $IPTABLES -A RULE_21 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 21 - ACCEPT **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_21 -j ACCEPT
+ #
+ # Rule 22 (global)
+ #
+ echo "Rule 22 (global)"
+ #
+ $IPTABLES -N Cid31315X1798.0
+ $IPTABLES -A FORWARD -d 211.11.11.11 -m state --state NEW -j Cid31315X1798.0
+ $IPTABLES -A Cid31315X1798.0 -s 192.168.1.10 -j ACCEPT
+ $IPTABLES -A Cid31315X1798.0 -s 192.168.1.20 -j ACCEPT
+ #
+ # Rule 23 (global)
+ #
+ echo "Rule 23 (global)"
+ #
+ $IPTABLES -N Cid31328X1798.0
+ $IPTABLES -A FORWARD -s 211.11.11.11 -m state --state NEW -j Cid31328X1798.0
+ $IPTABLES -A Cid31328X1798.0 -d 192.168.1.10 -j ACCEPT
+ $IPTABLES -A Cid31328X1798.0 -d 192.168.1.20 -j ACCEPT
+ #
+ # Rule 24 (global)
+ #
+ echo "Rule 24 (global)"
+ #
+ $IPTABLES -N Cid31341X1798.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -j Cid31341X1798.0
+ $IPTABLES -A INPUT -p tcp -m tcp -j Cid31341X1798.0
+ $IPTABLES -A FORWARD -p tcp -m tcp -j Cid31341X1798.0
+ $IPTABLES -A Cid31341X1798.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid31341X1798.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -A Cid31341X1798.0 -p tcp -m tcp -j REJECT --reject-with tcp-reset
+ $IPTABLES -N Cid31341X1798.1
+ $IPTABLES -A OUTPUT -j Cid31341X1798.1
+ $IPTABLES -A INPUT -j Cid31341X1798.1
+ $IPTABLES -A FORWARD -j Cid31341X1798.1
+ $IPTABLES -A Cid31341X1798.1 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid31341X1798.1 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -A Cid31341X1798.1 -j REJECT --reject-with icmp-net-unreachable
+ #
+ # Rule 25 (global)
+ #
+ echo "Rule 25 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -s 192.168.2.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.2.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.2.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 26 (global)
+ #
+ echo "Rule 26 (global)"
+ #
+ $IPTABLES -N RULE_26
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -j RULE_26
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -j RULE_26
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -j RULE_26
+ $IPTABLES -A RULE_26 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 26 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_26 -j DROP
+ #
+ # Rule 27 (global)
+ #
+ echo "Rule 27 (global)"
+ #
+ # host-fw2 has the same address as
+ # one of the firewall's interfaces
+ $IPTABLES -N RULE_27
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 21 -m state --state NEW -m limit --limit 5/minute --limit-burst 10 -j RULE_27
+ $IPTABLES -A INPUT -p tcp -m tcp -d 22.22.22.22 --dport 21 -m state --state NEW -m limit --limit 5/minute --limit-burst 10 -j RULE_27
+ $IPTABLES -A RULE_27 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 27 - ACCEPT **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_27 -j ACCEPT
+ #
+ # Rule 28 (global)
+ #
+ echo "Rule 28 (global)"
+ #
+ $IPTABLES -N Cid31391X1798.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 21 -m state --state NEW -j Cid31391X1798.0
+ $IPTABLES -N RULE_28
+ $IPTABLES -A Cid31391X1798.0 -d 22.22.22.22 -j RULE_28
+ $IPTABLES -A Cid31391X1798.0 -d 22.22.23.23 -j RULE_28
+ $IPTABLES -A Cid31391X1798.0 -d 22.22.25.50 -j RULE_28
+ $IPTABLES -A Cid31391X1798.0 -d 192.168.1.1 -j RULE_28
+ $IPTABLES -A Cid31391X1798.0 -d 192.168.2.1 -j RULE_28
+ $IPTABLES -A Cid31391X1798.0 -d 192.168.2.40 -j RULE_28
+ $IPTABLES -N Cid31391X1798.1
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 21 -m state --state NEW -j Cid31391X1798.1
+ $IPTABLES -A Cid31391X1798.1 -d 22.22.22.22 -j RULE_28
+ $IPTABLES -A Cid31391X1798.1 -d 22.22.23.23 -j RULE_28
+ $IPTABLES -A Cid31391X1798.1 -d 22.22.25.50 -j RULE_28
+ $IPTABLES -A Cid31391X1798.1 -d 192.168.1.1 -j RULE_28
+ $IPTABLES -A Cid31391X1798.1 -d 192.168.2.1 -j RULE_28
+ $IPTABLES -A Cid31391X1798.1 -d 192.168.2.40 -j RULE_28
+ $IPTABLES -A RULE_28 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 28 - ACCEPT **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_28 -j ACCEPT
+ #
+ # Rule 29 (global)
+ #
+ echo "Rule 29 (global)"
+ #
+ # 'catch all' rule
+ $IPTABLES -N RULE_29
+ $IPTABLES -A OUTPUT -j RULE_29
+ $IPTABLES -A INPUT -j RULE_29
+ $IPTABLES -A FORWARD -j RULE_29
+ $IPTABLES -A RULE_29 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 29 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_29 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:00 2011 by vadim"
+ check_tools
+
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+ prolog_commands
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall2-2.fw.orig b/test/ipt/firewall2-2.fw.orig
new file mode 100755
index 000000000..f5fe8643a
--- /dev/null
+++ b/test/ipt/firewall2-2.fw.orig
@@ -0,0 +1,1309 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:07 2011 PST by vadim
+#
+# files: * firewall2-2.fw
+#
+# Compiled for iptables 1.4.0
+#
+# another copy of firewall2 but new iptables version
+
+# firewall2-2:NAT:20: warning: Adding of virtual address for address range is not implemented (object ext_range)
+
+# firewall2-2:Policy:0: error: Rule '0 (eth1)' shadows rule '3 (eth1,eth3)' below it
+# firewall2-2:Policy:0: error: Rule '0 (eth1)' shadows rule '3 (eth1,eth3)' below it
+# firewall2-2:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '5 (eth1,eth3)' below it
+# firewall2-2:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '5 (eth1,eth3)' below it
+# firewall2-2:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '5 (eth1,eth3)' below it
+# firewall2-2:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '5 (eth1,eth3)' below it
+# firewall2-2:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '6 (eth1,eth3)' below it
+# firewall2-2:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '6 (eth1,eth3)' below it
+# firewall2-2:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '6 (eth1,eth3)' below it
+# firewall2-2:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '6 (eth1,eth3)' below it
+# firewall2-2:Policy:10: error: Rule '10 (global)' shadows rule '11 (global)' below it
+# firewall2-2:Policy:10: error: Rule '10 (global)' shadows rule '12 (global)' below it
+# firewall2-2:Policy:10: error: Rule '10 (global)' shadows rule '13 (global)' below it
+# firewall2-2:Policy:10: error: Rule '10 (global)' shadows rule '14 (global)' below it
+# firewall2-2:Policy:10: error: Rule '10 (global)' shadows rule '20 (global)' below it
+# firewall2-2:Policy:25: error: Rule '25 (global)' shadows rule '26 (global)' below it
+# firewall2-2:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall2-2:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall2-2:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall2-2:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+# firewall2-2:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall2-2:Policy:: warning: Log prefix has been truncated to 29 characters
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24 192.168.1.10/24 192.168.1.50/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24 22.22.22.23/24 22.22.22.24/24 22.22.22.25/24 22.22.22.0/32 22.22.22.1/32 22.22.22.2/32 22.22.22.3/32 22.22.22.4/32 22.22.22.5/32 22.22.22.6/32 22.22.22.7/32 22.22.22.8/32 22.22.22.9/32 22.22.22.10/32 22.22.22.11/32 22.22.22.12/32 22.22.22.13/32 22.22.22.14/32 22.22.22.15/32 22.22.22.16/32 22.22.22.17/32 22.22.22.18/32 22.22.22.19/32 22.22.22.20/32 22.22.22.21/32 22.22.22.22/32 22.22.22.23/32 22.22.22.24/32 22.22.22.25/32 22.22.22.26/32 22.22.22.27/32 22.22.22.28/32 22.22.22.29/32 22.22.22.30/32 22.22.22.31/32 22.22.22.32/32 22.22.22.33/32 22.22.22.34/32 22.22.22.35/32 22.22.22.36/32 22.22.22.37/32 22.22.22.38/32 22.22.22.39/32 22.22.22.40/32 22.22.22.41/32 22.22.22.42/32 22.22.22.43/32 22.22.22.44/32 22.22.22.45/32 22.22.22.46/32 22.22.22.47/32 22.22.22.48/32 22.22.22.49/32 22.22.22.50/32 22.22.22.51/32 22.22.22.52/32 22.22.22.53/32 22.22.22.54/32 22.22.22.55/32 22.22.22.56/32 22.22.22.57/32 22.22.22.58/32 22.22.22.59/32 22.22.22.60/32 22.22.22.61/32 22.22.22.62/32 22.22.22.63/32 22.22.22.64/32 22.22.22.65/32 22.22.22.66/32 22.22.22.67/32 22.22.22.68/32 22.22.22.69/32 22.22.22.70/32 22.22.22.71/32 22.22.22.72/32 22.22.22.73/32 22.22.22.74/32 22.22.22.75/32 22.22.22.76/32 22.22.22.77/32 22.22.22.78/32 22.22.22.79/32 22.22.22.80/32 22.22.22.81/32 22.22.22.82/32 22.22.22.83/32 22.22.22.84/32 22.22.22.85/32 22.22.22.86/32 22.22.22.87/32 22.22.22.88/32 22.22.22.89/32 22.22.22.90/32 22.22.22.91/32 22.22.22.92/32 22.22.22.93/32 22.22.22.94/32 22.22.22.95/32 22.22.22.96/32 22.22.22.97/32 22.22.22.98/32 22.22.22.99/32 22.22.22.100/32 22.22.22.101/32 22.22.22.102/32 22.22.22.103/32 22.22.22.104/32 22.22.22.105/32 22.22.22.106/32 22.22.22.107/32 22.22.22.108/32 22.22.22.109/32 22.22.22.110/32 22.22.22.111/32 22.22.22.112/32 22.22.22.113/32 22.22.22.114/32 22.22.22.115/32 22.22.22.116/32 22.22.22.117/32 22.22.22.118/32 22.22.22.119/32 22.22.22.120/32 22.22.22.121/32 22.22.22.122/32 22.22.22.123/32 22.22.22.124/32 22.22.22.125/32 22.22.22.126/32 22.22.22.127/32 22.22.22.128/32 22.22.22.129/32 22.22.22.130/32 22.22.22.131/32 22.22.22.132/32 22.22.22.133/32 22.22.22.134/32 22.22.22.135/32 22.22.22.136/32 22.22.22.137/32 22.22.22.138/32 22.22.22.139/32 22.22.22.140/32 22.22.22.141/32 22.22.22.142/32 22.22.22.143/32 22.22.22.144/32 22.22.22.145/32 22.22.22.146/32 22.22.22.147/32 22.22.22.148/32 22.22.22.149/32 22.22.22.150/32 22.22.22.151/32 22.22.22.152/32 22.22.22.153/32 22.22.22.154/32 22.22.22.155/32 22.22.22.156/32 22.22.22.157/32 22.22.22.158/32 22.22.22.159/32 22.22.22.160/32 22.22.22.161/32 22.22.22.162/32 22.22.22.163/32 22.22.22.164/32 22.22.22.165/32 22.22.22.166/32 22.22.22.167/32 22.22.22.168/32 22.22.22.169/32 22.22.22.170/32 22.22.22.171/32 22.22.22.172/32 22.22.22.173/32 22.22.22.174/32 22.22.22.175/32 22.22.22.176/32 22.22.22.177/32 22.22.22.178/32 22.22.22.179/32 22.22.22.180/32 22.22.22.181/32 22.22.22.182/32 22.22.22.183/32 22.22.22.184/32 22.22.22.185/32 22.22.22.186/32 22.22.22.187/32 22.22.22.188/32 22.22.22.189/32 22.22.22.190/32 22.22.22.191/32 22.22.22.192/32 22.22.22.193/32 22.22.22.194/32 22.22.22.195/32 22.22.22.196/32 22.22.22.197/32 22.22.22.198/32 22.22.22.199/32 22.22.22.200/32 22.22.22.201/32 22.22.22.202/32 22.22.22.203/32 22.22.22.204/32 22.22.22.205/32 22.22.22.206/32 22.22.22.207/32 22.22.22.208/32 22.22.22.209/32 22.22.22.210/32 22.22.22.211/32 22.22.22.212/32 22.22.22.213/32 22.22.22.214/32 22.22.22.215/32 22.22.22.216/32 22.22.22.217/32 22.22.22.218/32 22.22.22.219/32 22.22.22.220/32 22.22.22.221/32 22.22.22.222/32 22.22.22.223/32 22.22.22.224/32 22.22.22.225/32 22.22.22.226/32 22.22.22.227/32 22.22.22.228/32 22.22.22.229/32 22.22.22.230/32 22.22.22.231/32 22.22.22.232/32 22.22.22.233/32 22.22.22.234/32 22.22.22.235/32 22.22.22.236/32 22.22.22.237/32 22.22.22.238/32 22.22.22.239/32 22.22.22.240/32 22.22.22.241/32 22.22.22.242/32 22.22.22.243/32 22.22.22.244/32 22.22.22.245/32 22.22.22.246/32 22.22.22.247/32 22.22.22.248/32 22.22.22.249/32 22.22.22.250/32 22.22.22.251/32 22.22.22.252/32 22.22.22.253/32 22.22.22.254/32" ""
+ update_addresses_of_interface "eth3 22.22.23.23/24 22.22.25.50/24 22.22.23.24/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24 192.168.2.40/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ echo 1 > /proc/sys/net/ipv4/conf/all/rp_filter
+ echo 0 > /proc/sys/net/ipv4/conf/all/accept_source_route
+ echo 0 > /proc/sys/net/ipv4/conf/all/accept_redirects
+ echo 1 > /proc/sys/net/ipv4/conf/all/log_martians
+ echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_all
+ echo 1 > /proc/sys/net/ipv4/icmp_ignore_bogus_error_responses
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop TCP sessions opened prior firewall restart
+ $IPTABLES -A INPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ $IPTABLES -A OUTPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ $IPTABLES -A FORWARD -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ # drop packets that do not match any valid state and log them
+ $IPTABLES -N drop_invalid
+ $IPTABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IPTABLES -A drop_invalid -j ULOG --ulog-nlgroup 1 --ulog-qthreshold 1 --ulog-prefix "INVALID state -- DENY "
+ $IPTABLES -A drop_invalid -j DROP
+ # ================ Table 'mangle', automatic rules
+ $IPTABLES -t mangle -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.40
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 192.168.2.40
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.40
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ #
+ # Rule 6 (NAT)
+ #
+ echo "Rule 6 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 22.22.22.23
+ #
+ # Rule 7 (NAT)
+ #
+ echo "Rule 7 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 22.22.22.23
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 22.22.22.24
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 22.22.22.25
+ #
+ # Rule 8 (NAT)
+ #
+ echo "Rule 8 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -d 192.168.1.10 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 9 (NAT)
+ #
+ echo "Rule 9 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid32503X1798.0
+ $IPTABLES -t nat -A POSTROUTING -d 192.168.2.10 -j Cid32503X1798.0
+ $IPTABLES -t nat -A POSTROUTING -d 192.168.2.11 -j Cid32503X1798.0
+ $IPTABLES -t nat -A Cid32503X1798.0 -s 22.22.22.22 -j ACCEPT
+ $IPTABLES -t nat -A Cid32503X1798.0 -s 22.22.23.23 -j ACCEPT
+ $IPTABLES -t nat -A Cid32503X1798.0 -s 22.22.25.50 -j ACCEPT
+ $IPTABLES -t nat -A Cid32503X1798.0 -s 192.168.1.1 -j ACCEPT
+ $IPTABLES -t nat -A Cid32503X1798.0 -s 192.168.2.1 -j ACCEPT
+ $IPTABLES -t nat -A Cid32503X1798.0 -s 192.168.2.40 -j ACCEPT
+ $IPTABLES -t nat -A OUTPUT -d 192.168.2.10 -j ACCEPT
+ $IPTABLES -t nat -A OUTPUT -d 192.168.2.11 -j ACCEPT
+ $IPTABLES -t nat -N Cid32503X1798.1
+ $IPTABLES -t nat -A POSTROUTING -d 192.168.2.10 -j Cid32503X1798.1
+ $IPTABLES -t nat -A POSTROUTING -d 192.168.2.11 -j Cid32503X1798.1
+ $IPTABLES -t nat -A Cid32503X1798.1 -s 192.168.1.10 -j ACCEPT
+ $IPTABLES -t nat -A Cid32503X1798.1 -s 192.168.1.20 -j ACCEPT
+ $IPTABLES -t nat -N Cid32503X1798.2
+ $IPTABLES -t nat -A PREROUTING -d 192.168.2.10 -j Cid32503X1798.2
+ $IPTABLES -t nat -A PREROUTING -d 192.168.2.11 -j Cid32503X1798.2
+ $IPTABLES -t nat -A Cid32503X1798.2 -s 192.168.1.10 -j ACCEPT
+ $IPTABLES -t nat -A Cid32503X1798.2 -s 192.168.1.20 -j ACCEPT
+ #
+ # Rule 10 (NAT)
+ #
+ echo "Rule 10 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid32521X1798.0
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.10 -j Cid32521X1798.0
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.20 -j Cid32521X1798.0
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.10 -j Cid32521X1798.0
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.20 -j Cid32521X1798.0
+ $IPTABLES -t nat -A Cid32521X1798.0 -d 192.168.2.10 -j RETURN
+ $IPTABLES -t nat -A Cid32521X1798.0 -d 192.168.2.11 -j RETURN
+ $IPTABLES -t nat -A Cid32521X1798.0 -j ACCEPT
+ #
+ # Rule 11 (NAT)
+ #
+ echo "Rule 11 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/1 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 22.22.22.23 --icmp-type 0/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 22.22.22.23 --icmp-type 3 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p 50 -d 22.22.22.23 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p 88 -d 22.22.22.23 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/1 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 0/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 3 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p 50 -d 22.22.22.23 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p 88 -d 22.22.22.23 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 12 (NAT)
+ #
+ echo "Rule 12 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/1 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 0/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 3 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 13 (NAT)
+ #
+ echo "Rule 13 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -s 22.22.23.23 -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -s 22.22.25.50 -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 14 (NAT)
+ #
+ echo "Rule 14 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -s 200.200.200.200 -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 16 (NAT)
+ #
+ echo "Rule 16 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 22.22.22.24 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 22.22.22.25 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.24 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.25 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 17 (NAT)
+ #
+ echo "Rule 17 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 18 (NAT)
+ #
+ echo "Rule 18 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.20 -j SNAT --to-source 22.22.23.24
+ #
+ # Rule 19 (NAT)
+ #
+ echo "Rule 19 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -d 22.22.23.24 -j DNAT --to-destination 192.168.1.20
+ $IPTABLES -t nat -A OUTPUT -d 22.22.23.24 -j DNAT --to-destination 192.168.1.20
+ #
+ # Rule 20 (NAT)
+ #
+ echo "Rule 20 (NAT)"
+ #
+ # firewall2-2:NAT:20: warning: Adding of virtual address for address range is not implemented (object ext_range)
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.100-22.22.22.110
+ #
+ # Rule 21 (NAT)
+ #
+ echo "Rule 21 (NAT)"
+ #
+ # NETMAP
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.0/24 -j NETMAP --to 22.22.22.0/24
+ #
+ # Rule 22 (NAT)
+ #
+ echo "Rule 22 (NAT)"
+ #
+ # NETMAP
+ $IPTABLES -t nat -A PREROUTING -d 22.22.22.0/24 -j NETMAP --to 192.168.1.0/24
+ #
+ # Rule 23 (NAT)
+ #
+ echo "Rule 23 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.23 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.25.50 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.40 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.23.23 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.25.50 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 192.168.1.1 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 192.168.2.1 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 192.168.2.40 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ #
+ # Rule 24 (NAT)
+ #
+ echo "Rule 24 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.23 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.25.50 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.23.23 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.25.50 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -d 192.168.1.10 --dport 80 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 25 (NAT)
+ #
+ echo "Rule 25 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.23 --dport 80 -j DNAT --to-destination 192.168.1.10:25
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.23 --dport 80 -j DNAT --to-destination 192.168.1.10:25
+ #
+ # Rule 26 (NAT)
+ #
+ echo "Rule 26 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.23 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.25.50 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.40 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.23 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.25.50 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.40 --dport 443 -j REDIRECT --to-ports 3128
+ #
+ # Rule 27 (NAT)
+ #
+ echo "Rule 27 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 8080 -j DNAT --to-destination 192.168.1.10-192.168.1.100
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 8080 -j DNAT --to-destination 192.168.1.10-192.168.1.100
+ #
+ # Rule 28 (NAT)
+ #
+ echo "Rule 28 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 8080 -j DNAT --to-destination 192.168.1.11-192.168.1.15
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 8080 -j DNAT --to-destination 192.168.1.11-192.168.1.15
+ #
+ # Rule 29 (NAT)
+ #
+ echo "Rule 29 (NAT)"
+ #
+ # transparent proxy rule
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.0/24 -d ! 22.22.22.23 -j DNAT --to-destination 192.168.2.10
+ #
+ # Rule 31 (NAT)
+ #
+ echo "Rule 31 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j DNAT --to-destination :8080
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j DNAT --to-destination :8080
+ #
+ # Rule 32 (NAT)
+ #
+ echo "Rule 32 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.10 --dport 80 -j DNAT --to-destination 192.168.1.10:8080
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 192.168.1.10 --dport 80 -j DNAT --to-destination 192.168.1.10:8080
+ #
+ # Rule 33 (NAT)
+ #
+ echo "Rule 33 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --dport 80 -j SNAT --to-source 22.22.22.22
+ #
+ # Rule 34 (NAT)
+ #
+ echo "Rule 34 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s ! 192.168.1.10 --dport 80 -j DNAT --to-destination 192.168.1.10:3128
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.10:3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s ! 192.168.1.10 --dport 80 -j DNAT --to-destination 192.168.1.10:3128
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -s ! 192.168.1.10 -d 192.168.1.10 --dport 3128 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 35 (NAT)
+ #
+ echo "Rule 35 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid32891X1798.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d ! 192.168.1.50 --dport 80 -j Cid32891X1798.0
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d ! 192.168.1.50 --dport 80 -j Cid32891X1798.0
+ $IPTABLES -t nat -A Cid32891X1798.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid32891X1798.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid32891X1798.0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.50:3128
+ #
+ # Rule 36 (NAT)
+ #
+ echo "Rule 36 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid32905X1798.1
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -j Cid32905X1798.1
+ $IPTABLES -t nat -A Cid32905X1798.1 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid32905X1798.1 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -N Cid32905X1798.0
+ $IPTABLES -t nat -A Cid32905X1798.1 -j Cid32905X1798.0
+ $IPTABLES -t nat -A Cid32905X1798.0 -p tcp -m tcp --dport 80 -j RETURN
+ $IPTABLES -t nat -A Cid32905X1798.0 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 37 (NAT)
+ #
+ echo "Rule 37 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j DNAT --to-destination 192.168.1.10:3128
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.10 --dport 3128 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 38 (NAT)
+ #
+ echo "Rule 38 (NAT)"
+ #
+ # this is the "exception" rule
+ # used in support req. originally
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.20 --dport 80 -j SNAT --to-source 22.22.22.22
+ #
+ # Rule 39 (NAT)
+ #
+ echo "Rule 39 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j DNAT --to-destination 192.168.1.1:3128
+ #
+ # Rule 40 (NAT)
+ #
+ echo "Rule 40 (NAT)"
+ #
+ # "exception" rule in the pair
+ # from a support req.
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.20 --dport 80 -j SNAT --to-source 22.22.22.22
+ #
+ # Rule 41 (NAT)
+ #
+ echo "Rule 41 (NAT)"
+ #
+ # testing transparent proxy
+ # roules for a support req.
+ $IPTABLES -t nat -N Cid32975X1798.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j Cid32975X1798.0
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j Cid32975X1798.0
+ $IPTABLES -t nat -A Cid32975X1798.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid32975X1798.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid32975X1798.0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.1:3128
+ #
+ # Rule 42 (NAT)
+ #
+ echo "Rule 42 (NAT)"
+ #
+ # testing transparent proxy
+ # roules for a support req.
+ $IPTABLES -t nat -N Cid32989X1798.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j Cid32989X1798.0
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j Cid32989X1798.0
+ $IPTABLES -t nat -A Cid32989X1798.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid32989X1798.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid32989X1798.0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.1:3128
+ #
+ # Rule 43 (NAT)
+ #
+ echo "Rule 43 (NAT)"
+ #
+ # testing transparent proxy
+ # roules for a support req.
+ $IPTABLES -t nat -N Cid33003X1798.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j Cid33003X1798.0
+ $IPTABLES -t nat -A Cid33003X1798.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid33003X1798.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid33003X1798.0 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
+ #
+ # Rule 44 (NAT)
+ #
+ echo "Rule 44 (NAT)"
+ #
+ # "exception" rule in the pair
+ # from a support req.
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.20 --dport 80 -j SNAT --to-source 22.22.22.22
+ #
+ # Rule 45 (NAT)
+ #
+ echo "Rule 45 (NAT)"
+ #
+ # testing transparent proxy
+ # roules for a support req.
+ $IPTABLES -t nat -N Cid33031X1798.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j Cid33031X1798.0
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j Cid33031X1798.0
+ $IPTABLES -t nat -A Cid33031X1798.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid33031X1798.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid33031X1798.0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.50:3128
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth1)
+ #
+ echo "Rule 0 (eth1)"
+ #
+ # Anti-spoofing rule
+ $IPTABLES -N In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 22.22.22.22 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 22.22.23.23 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 22.22.25.50 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 192.168.1.1 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 192.168.2.1 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 192.168.2.40 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 192.168.1.0/24 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 22.22.22.22 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 22.22.23.23 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 22.22.25.50 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.1.1 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.2.1 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.2.40 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.1.0/24 -j In_RULE_0
+ $IPTABLES -A In_RULE_0 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "Iface: global RULE 0 -- DENY " --ulog-qthreshold 1
+ $IPTABLES -A In_RULE_0 -j DROP
+ #
+ # Rule 1 (eth1)
+ #
+ echo "Rule 1 (eth1)"
+ #
+ # Anti-spoofing rule
+ $IPTABLES -N Cid32134X1798.0
+ $IPTABLES -A OUTPUT -o eth1 -j Cid32134X1798.0
+ $IPTABLES -A Cid32134X1798.0 -s 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid32134X1798.0 -s 22.22.23.23 -j RETURN
+ $IPTABLES -A Cid32134X1798.0 -s 22.22.25.50 -j RETURN
+ $IPTABLES -A Cid32134X1798.0 -s 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid32134X1798.0 -s 192.168.2.1 -j RETURN
+ $IPTABLES -A Cid32134X1798.0 -s 192.168.2.40 -j RETURN
+ $IPTABLES -N Out_RULE_1_3
+ $IPTABLES -A Cid32134X1798.0 -j Out_RULE_1_3
+ $IPTABLES -A Out_RULE_1_3 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "Iface: global RULE 1 -- DENY " --ulog-qthreshold 1
+ $IPTABLES -A Out_RULE_1_3 -j DROP
+ $IPTABLES -N Cid32134X1798.1
+ $IPTABLES -A FORWARD -o eth1 -j Cid32134X1798.1
+ $IPTABLES -A Cid32134X1798.1 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid32134X1798.1 -j Out_RULE_1_3
+ #
+ # Rule 2 (fw2i1,3)
+ #
+ echo "Rule 2 (fw2i1,3)"
+ #
+ # testing group in "interface"
+ # this rule should be identical to rule 3
+ $IPTABLES -N In_RULE_2
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_2
+ $IPTABLES -A INPUT -i eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_2
+ $IPTABLES -A FORWARD -i eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_2
+ $IPTABLES -A FORWARD -i eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_2
+ $IPTABLES -A In_RULE_2 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 2 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A In_RULE_2 -j DROP
+ #
+ # Rule 3 (eth1,eth3)
+ #
+ echo "Rule 3 (eth1,eth3)"
+ #
+ $IPTABLES -N In_RULE_3
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_3
+ $IPTABLES -A INPUT -i eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_3
+ $IPTABLES -A FORWARD -i eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_3
+ $IPTABLES -A FORWARD -i eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_3
+ $IPTABLES -A In_RULE_3 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 3 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A In_RULE_3 -j DROP
+ #
+ # Rule 4 (eth1,eth3)
+ #
+ echo "Rule 4 (eth1,eth3)"
+ #
+ # testing choice of chains in case when several
+ # interfaces are used and rule matches 'any' or
+ # broadcast
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth3 -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth1 -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth3 -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (eth1,eth3)
+ #
+ echo "Rule 5 (eth1,eth3)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -m multiport -s 0.0.0.0 -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth3 -p udp -m udp -m multiport -s 0.0.0.0 -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 6 (eth1,eth3)
+ #
+ echo "Rule 6 (eth1,eth3)"
+ #
+ $IPTABLES -A OUTPUT -o eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -N Cid32211X1798.0
+ $IPTABLES -A OUTPUT -j Cid32211X1798.0
+ $IPTABLES -A INPUT -j Cid32211X1798.0
+ $IPTABLES -A FORWARD -j Cid32211X1798.0
+ $IPTABLES -A Cid32211X1798.0 -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j RETURN
+ $IPTABLES -N RULE_7_3
+ $IPTABLES -A Cid32211X1798.0 -j RULE_7_3
+ $IPTABLES -A RULE_7_3 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 7 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_7_3 -j DROP
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ # block fragments
+ $IPTABLES -N RULE_8
+ $IPTABLES -A OUTPUT -p all -f -j RULE_8
+ $IPTABLES -A INPUT -p all -f -j RULE_8
+ $IPTABLES -A FORWARD -p all -f -j RULE_8
+ $IPTABLES -A RULE_8 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 8 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_8 -j DROP
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ # sends TCP RST and makes custom record
+ # in the log
+ $IPTABLES -N RULE_9
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 113 -j RULE_9
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 113 -j RULE_9
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 113 -j RULE_9
+ $IPTABLES -A RULE_9 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "IDENT" --ulog-qthreshold 1
+ $IPTABLES -A RULE_9 -p tcp -m tcp -j REJECT --reject-with tcp-reset
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ # firewall2-2:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -N RULE_10
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -j RULE_10
+ # firewall2-2:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -j RULE_10
+ # firewall2-2:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -j RULE_10
+ # firewall2-2:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A RULE_10 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 10 - REJECT **" --ulog-qthreshold 1
+ # firewall2-2:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A RULE_10 -j REJECT --reject-with icmp-net-unreachable
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -A OUTPUT -p udp -m udp -m iprange --dst-range 192.168.1.10-192.168.1.100 --dport 161 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p udp -m udp -m iprange --dst-range 192.168.1.10-192.168.1.100 --dport 161 -m state --state NEW -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -A INPUT -p udp -m udp -m iprange --src-range 192.168.1.10-192.168.1.100 --dport 161 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p udp -m udp -m iprange --src-range 192.168.1.10-192.168.1.100 --dport 161 -m state --state NEW -j ACCEPT
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -A FORWARD -p udp -m udp -m iprange --src-range 222.222.222.10-222.222.222.100 --dst-range 192.168.1.10-192.168.1.100 --dport 161 -m state --state NEW -j ACCEPT
+ #
+ # Rule 14 (global)
+ #
+ echo "Rule 14 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -A FORWARD -p udp -m udp -m iprange --src-range 192.168.1.10-192.168.1.100 --dst-range 222.222.222.10-222.222.222.100 --dport 161 -m state --state NEW -j ACCEPT
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid94453X70161.0
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid94453X70161.0
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid94453X70161.0
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid94453X70161.0
+ $IPTABLES -A Cid94453X70161.0 -m iprange --dst-range 192.168.1.10-192.168.1.100 -j RETURN
+ $IPTABLES -A Cid94453X70161.0 -j ACCEPT
+ #
+ # Rule 16 (global)
+ #
+ echo "Rule 16 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid94436X70161.0
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid94436X70161.0
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid94436X70161.0
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid94436X70161.0
+ $IPTABLES -A Cid94436X70161.0 -m iprange --src-range 192.168.1.10-192.168.1.100 -j RETURN
+ $IPTABLES -A Cid94436X70161.0 -j ACCEPT
+ #
+ # Rule 17 (global)
+ #
+ echo "Rule 17 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid94418X70161.0
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid94418X70161.0
+ $IPTABLES -A Cid94418X70161.0 -d 192.168.1.0 -j RETURN
+ $IPTABLES -A Cid94418X70161.0 -j ACCEPT
+ $IPTABLES -N Cid94418X70161.1
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid94418X70161.1
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid94418X70161.1
+ $IPTABLES -A Cid94418X70161.1 -m iprange --dst-range 192.168.1.10-192.168.1.100 -j RETURN
+ $IPTABLES -A Cid94418X70161.1 -j ACCEPT
+ #
+ # Rule 18 (global)
+ #
+ echo "Rule 18 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid94400X70161.0
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid94400X70161.0
+ $IPTABLES -A Cid94400X70161.0 -s 192.168.1.0 -j RETURN
+ $IPTABLES -A Cid94400X70161.0 -j ACCEPT
+ $IPTABLES -N Cid94400X70161.1
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid94400X70161.1
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid94400X70161.1
+ $IPTABLES -A Cid94400X70161.1 -m iprange --src-range 192.168.1.10-192.168.1.100 -j RETURN
+ $IPTABLES -A Cid94400X70161.1 -j ACCEPT
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ # also test for bug #2526173
+ $IPTABLES -N RULE_19
+ $IPTABLES -A INPUT -s 0.0.0.0 -j RULE_19
+ $IPTABLES -A FORWARD -s 0.0.0.0 -j RULE_19
+ $IPTABLES -A RULE_19 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 19 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_19 -j DROP
+ #
+ # Rule 20 (global)
+ #
+ echo "Rule 20 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -A INPUT -p udp -m udp -m iprange --src-range 192.168.1.1-192.168.1.100 --dport 161 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p udp -m udp -m iprange --src-range 192.168.1.1-192.168.1.100 --dport 161 -m state --state NEW -j ACCEPT
+ #
+ # Rule 21 (global)
+ #
+ echo "Rule 21 (global)"
+ #
+ $IPTABLES -N Cid32259X1798.0
+ $IPTABLES -A INPUT -p icmp -m icmp -s 192.168.2.0/24 --icmp-type any -m state --state NEW -j Cid32259X1798.0
+ $IPTABLES -N RULE_21
+ $IPTABLES -A Cid32259X1798.0 -d 192.168.2.1 -j RULE_21
+ $IPTABLES -A Cid32259X1798.0 -d 192.168.2.40 -j RULE_21
+ $IPTABLES -A RULE_21 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 21 - ACCEPT **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_21 -j ACCEPT
+ #
+ # Rule 22 (global)
+ #
+ echo "Rule 22 (global)"
+ #
+ $IPTABLES -N Cid32271X1798.0
+ $IPTABLES -A FORWARD -d 211.11.11.11 -m state --state NEW -j Cid32271X1798.0
+ $IPTABLES -A Cid32271X1798.0 -s 192.168.1.10 -j ACCEPT
+ $IPTABLES -A Cid32271X1798.0 -s 192.168.1.20 -j ACCEPT
+ #
+ # Rule 23 (global)
+ #
+ echo "Rule 23 (global)"
+ #
+ $IPTABLES -N Cid32284X1798.0
+ $IPTABLES -A FORWARD -s 211.11.11.11 -m state --state NEW -j Cid32284X1798.0
+ $IPTABLES -A Cid32284X1798.0 -d 192.168.1.10 -j ACCEPT
+ $IPTABLES -A Cid32284X1798.0 -d 192.168.1.20 -j ACCEPT
+ #
+ # Rule 24 (global)
+ #
+ echo "Rule 24 (global)"
+ #
+ $IPTABLES -N Cid32297X1798.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -j Cid32297X1798.0
+ $IPTABLES -A INPUT -p tcp -m tcp -j Cid32297X1798.0
+ $IPTABLES -A FORWARD -p tcp -m tcp -j Cid32297X1798.0
+ $IPTABLES -A Cid32297X1798.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid32297X1798.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -A Cid32297X1798.0 -p tcp -m tcp -j REJECT --reject-with tcp-reset
+ $IPTABLES -N Cid32297X1798.1
+ $IPTABLES -A OUTPUT -j Cid32297X1798.1
+ $IPTABLES -A INPUT -j Cid32297X1798.1
+ $IPTABLES -A FORWARD -j Cid32297X1798.1
+ $IPTABLES -A Cid32297X1798.1 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid32297X1798.1 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -A Cid32297X1798.1 -j REJECT --reject-with icmp-net-unreachable
+ #
+ # Rule 25 (global)
+ #
+ echo "Rule 25 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -s 192.168.2.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.2.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.2.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 26 (global)
+ #
+ echo "Rule 26 (global)"
+ #
+ $IPTABLES -N RULE_26
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -j RULE_26
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -j RULE_26
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -j RULE_26
+ $IPTABLES -A RULE_26 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 26 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_26 -j DROP
+ #
+ # Rule 27 (global)
+ #
+ echo "Rule 27 (global)"
+ #
+ # host-fw2 has the same address as
+ # one of the firewall's interfaces
+ $IPTABLES -N RULE_27
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 21 -m state --state NEW -m limit --limit 5/minute --limit-burst 10 -j RULE_27
+ $IPTABLES -A INPUT -p tcp -m tcp -d 22.22.22.22 --dport 21 -m state --state NEW -m limit --limit 5/minute --limit-burst 10 -j RULE_27
+ $IPTABLES -A RULE_27 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 27 - ACCEPT **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_27 -j ACCEPT
+ #
+ # Rule 28 (global)
+ #
+ echo "Rule 28 (global)"
+ #
+ $IPTABLES -N Cid32347X1798.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 21 -m state --state NEW -j Cid32347X1798.0
+ $IPTABLES -N RULE_28
+ $IPTABLES -A Cid32347X1798.0 -d 22.22.22.22 -j RULE_28
+ $IPTABLES -A Cid32347X1798.0 -d 22.22.23.23 -j RULE_28
+ $IPTABLES -A Cid32347X1798.0 -d 22.22.25.50 -j RULE_28
+ $IPTABLES -A Cid32347X1798.0 -d 192.168.1.1 -j RULE_28
+ $IPTABLES -A Cid32347X1798.0 -d 192.168.2.1 -j RULE_28
+ $IPTABLES -A Cid32347X1798.0 -d 192.168.2.40 -j RULE_28
+ $IPTABLES -N Cid32347X1798.1
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 21 -m state --state NEW -j Cid32347X1798.1
+ $IPTABLES -A Cid32347X1798.1 -d 22.22.22.22 -j RULE_28
+ $IPTABLES -A Cid32347X1798.1 -d 22.22.23.23 -j RULE_28
+ $IPTABLES -A Cid32347X1798.1 -d 22.22.25.50 -j RULE_28
+ $IPTABLES -A Cid32347X1798.1 -d 192.168.1.1 -j RULE_28
+ $IPTABLES -A Cid32347X1798.1 -d 192.168.2.1 -j RULE_28
+ $IPTABLES -A Cid32347X1798.1 -d 192.168.2.40 -j RULE_28
+ $IPTABLES -A RULE_28 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 28 - ACCEPT **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_28 -j ACCEPT
+ #
+ # Rule 29 (global)
+ #
+ echo "Rule 29 (global)"
+ #
+ # 'catch all' rule
+ $IPTABLES -N RULE_29
+ $IPTABLES -A OUTPUT -j RULE_29
+ $IPTABLES -A INPUT -j RULE_29
+ $IPTABLES -A FORWARD -j RULE_29
+ $IPTABLES -A RULE_29 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 29 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_29 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:07 2011 by vadim"
+ check_tools
+
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+ prolog_commands
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall2-3.fw.orig b/test/ipt/firewall2-3.fw.orig
new file mode 100755
index 000000000..1d83517ed
--- /dev/null
+++ b/test/ipt/firewall2-3.fw.orig
@@ -0,0 +1,1180 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:12 2011 PST by vadim
+#
+# files: * firewall2-3.fw
+#
+# Compiled for iptables ge_1.2.6
+#
+# copy of firewall2, version >= 1.2.6
+
+# firewall2-3:NAT:20: warning: Adding of virtual address for address range is not implemented (object ext_range)
+
+# firewall2-3:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall2-3:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall2-3:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall2-3:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+# firewall2-3:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall2-3:Policy:: warning: Log prefix has been truncated to 29 characters
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24 192.168.1.10/24 192.168.1.50/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24 22.22.22.23/24 22.22.22.24/24 22.22.22.25/24 22.22.22.0/32 22.22.22.1/32 22.22.22.2/32 22.22.22.3/32 22.22.22.4/32 22.22.22.5/32 22.22.22.6/32 22.22.22.7/32 22.22.22.8/32 22.22.22.9/32 22.22.22.10/32 22.22.22.11/32 22.22.22.12/32 22.22.22.13/32 22.22.22.14/32 22.22.22.15/32 22.22.22.16/32 22.22.22.17/32 22.22.22.18/32 22.22.22.19/32 22.22.22.20/32 22.22.22.21/32 22.22.22.22/32 22.22.22.23/32 22.22.22.24/32 22.22.22.25/32 22.22.22.26/32 22.22.22.27/32 22.22.22.28/32 22.22.22.29/32 22.22.22.30/32 22.22.22.31/32 22.22.22.32/32 22.22.22.33/32 22.22.22.34/32 22.22.22.35/32 22.22.22.36/32 22.22.22.37/32 22.22.22.38/32 22.22.22.39/32 22.22.22.40/32 22.22.22.41/32 22.22.22.42/32 22.22.22.43/32 22.22.22.44/32 22.22.22.45/32 22.22.22.46/32 22.22.22.47/32 22.22.22.48/32 22.22.22.49/32 22.22.22.50/32 22.22.22.51/32 22.22.22.52/32 22.22.22.53/32 22.22.22.54/32 22.22.22.55/32 22.22.22.56/32 22.22.22.57/32 22.22.22.58/32 22.22.22.59/32 22.22.22.60/32 22.22.22.61/32 22.22.22.62/32 22.22.22.63/32 22.22.22.64/32 22.22.22.65/32 22.22.22.66/32 22.22.22.67/32 22.22.22.68/32 22.22.22.69/32 22.22.22.70/32 22.22.22.71/32 22.22.22.72/32 22.22.22.73/32 22.22.22.74/32 22.22.22.75/32 22.22.22.76/32 22.22.22.77/32 22.22.22.78/32 22.22.22.79/32 22.22.22.80/32 22.22.22.81/32 22.22.22.82/32 22.22.22.83/32 22.22.22.84/32 22.22.22.85/32 22.22.22.86/32 22.22.22.87/32 22.22.22.88/32 22.22.22.89/32 22.22.22.90/32 22.22.22.91/32 22.22.22.92/32 22.22.22.93/32 22.22.22.94/32 22.22.22.95/32 22.22.22.96/32 22.22.22.97/32 22.22.22.98/32 22.22.22.99/32 22.22.22.100/32 22.22.22.101/32 22.22.22.102/32 22.22.22.103/32 22.22.22.104/32 22.22.22.105/32 22.22.22.106/32 22.22.22.107/32 22.22.22.108/32 22.22.22.109/32 22.22.22.110/32 22.22.22.111/32 22.22.22.112/32 22.22.22.113/32 22.22.22.114/32 22.22.22.115/32 22.22.22.116/32 22.22.22.117/32 22.22.22.118/32 22.22.22.119/32 22.22.22.120/32 22.22.22.121/32 22.22.22.122/32 22.22.22.123/32 22.22.22.124/32 22.22.22.125/32 22.22.22.126/32 22.22.22.127/32 22.22.22.128/32 22.22.22.129/32 22.22.22.130/32 22.22.22.131/32 22.22.22.132/32 22.22.22.133/32 22.22.22.134/32 22.22.22.135/32 22.22.22.136/32 22.22.22.137/32 22.22.22.138/32 22.22.22.139/32 22.22.22.140/32 22.22.22.141/32 22.22.22.142/32 22.22.22.143/32 22.22.22.144/32 22.22.22.145/32 22.22.22.146/32 22.22.22.147/32 22.22.22.148/32 22.22.22.149/32 22.22.22.150/32 22.22.22.151/32 22.22.22.152/32 22.22.22.153/32 22.22.22.154/32 22.22.22.155/32 22.22.22.156/32 22.22.22.157/32 22.22.22.158/32 22.22.22.159/32 22.22.22.160/32 22.22.22.161/32 22.22.22.162/32 22.22.22.163/32 22.22.22.164/32 22.22.22.165/32 22.22.22.166/32 22.22.22.167/32 22.22.22.168/32 22.22.22.169/32 22.22.22.170/32 22.22.22.171/32 22.22.22.172/32 22.22.22.173/32 22.22.22.174/32 22.22.22.175/32 22.22.22.176/32 22.22.22.177/32 22.22.22.178/32 22.22.22.179/32 22.22.22.180/32 22.22.22.181/32 22.22.22.182/32 22.22.22.183/32 22.22.22.184/32 22.22.22.185/32 22.22.22.186/32 22.22.22.187/32 22.22.22.188/32 22.22.22.189/32 22.22.22.190/32 22.22.22.191/32 22.22.22.192/32 22.22.22.193/32 22.22.22.194/32 22.22.22.195/32 22.22.22.196/32 22.22.22.197/32 22.22.22.198/32 22.22.22.199/32 22.22.22.200/32 22.22.22.201/32 22.22.22.202/32 22.22.22.203/32 22.22.22.204/32 22.22.22.205/32 22.22.22.206/32 22.22.22.207/32 22.22.22.208/32 22.22.22.209/32 22.22.22.210/32 22.22.22.211/32 22.22.22.212/32 22.22.22.213/32 22.22.22.214/32 22.22.22.215/32 22.22.22.216/32 22.22.22.217/32 22.22.22.218/32 22.22.22.219/32 22.22.22.220/32 22.22.22.221/32 22.22.22.222/32 22.22.22.223/32 22.22.22.224/32 22.22.22.225/32 22.22.22.226/32 22.22.22.227/32 22.22.22.228/32 22.22.22.229/32 22.22.22.230/32 22.22.22.231/32 22.22.22.232/32 22.22.22.233/32 22.22.22.234/32 22.22.22.235/32 22.22.22.236/32 22.22.22.237/32 22.22.22.238/32 22.22.22.239/32 22.22.22.240/32 22.22.22.241/32 22.22.22.242/32 22.22.22.243/32 22.22.22.244/32 22.22.22.245/32 22.22.22.246/32 22.22.22.247/32 22.22.22.248/32 22.22.22.249/32 22.22.22.250/32 22.22.22.251/32 22.22.22.252/32 22.22.22.253/32 22.22.22.254/32" ""
+ update_addresses_of_interface "eth3 22.22.23.23/24 22.22.25.50/24 22.22.23.24/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24 192.168.2.40/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ echo 1 > /proc/sys/net/ipv4/conf/all/rp_filter
+ echo 0 > /proc/sys/net/ipv4/conf/all/accept_source_route
+ echo 0 > /proc/sys/net/ipv4/conf/all/accept_redirects
+ echo 1 > /proc/sys/net/ipv4/conf/all/log_martians
+ echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_all
+ echo 1 > /proc/sys/net/ipv4/icmp_ignore_bogus_error_responses
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ $IPTABLES -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
+
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop TCP sessions opened prior firewall restart
+ $IPTABLES -A INPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ $IPTABLES -A OUTPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ $IPTABLES -A FORWARD -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ # drop packets that do not match any valid state and log them
+ $IPTABLES -N drop_invalid
+ $IPTABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IPTABLES -A drop_invalid -j ULOG --ulog-nlgroup 1 --ulog-qthreshold 1 --ulog-prefix "INVALID state -- DENY "
+ $IPTABLES -A drop_invalid -j DROP
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.40
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 192.168.2.40
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.40
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ #
+ # Rule 6 (NAT)
+ #
+ echo "Rule 6 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 22.22.22.23
+ #
+ # Rule 7 (NAT)
+ #
+ echo "Rule 7 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 22.22.22.23
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 22.22.22.24
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 22.22.22.25
+ #
+ # Rule 8 (NAT)
+ #
+ echo "Rule 8 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -d 192.168.1.10 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 9 (NAT)
+ #
+ echo "Rule 9 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid35496X1833.0
+ $IPTABLES -t nat -A POSTROUTING -d 192.168.2.10 -j Cid35496X1833.0
+ $IPTABLES -t nat -A POSTROUTING -d 192.168.2.11 -j Cid35496X1833.0
+ $IPTABLES -t nat -A Cid35496X1833.0 -s 22.22.22.22 -j ACCEPT
+ $IPTABLES -t nat -A Cid35496X1833.0 -s 22.22.23.23 -j ACCEPT
+ $IPTABLES -t nat -A Cid35496X1833.0 -s 22.22.25.50 -j ACCEPT
+ $IPTABLES -t nat -A Cid35496X1833.0 -s 192.168.1.1 -j ACCEPT
+ $IPTABLES -t nat -A Cid35496X1833.0 -s 192.168.2.1 -j ACCEPT
+ $IPTABLES -t nat -A Cid35496X1833.0 -s 192.168.2.40 -j ACCEPT
+ $IPTABLES -t nat -A OUTPUT -d 192.168.2.10 -j ACCEPT
+ $IPTABLES -t nat -A OUTPUT -d 192.168.2.11 -j ACCEPT
+ $IPTABLES -t nat -N Cid35496X1833.1
+ $IPTABLES -t nat -A POSTROUTING -d 192.168.2.10 -j Cid35496X1833.1
+ $IPTABLES -t nat -A POSTROUTING -d 192.168.2.11 -j Cid35496X1833.1
+ $IPTABLES -t nat -A Cid35496X1833.1 -s 192.168.1.10 -j ACCEPT
+ $IPTABLES -t nat -A Cid35496X1833.1 -s 192.168.1.20 -j ACCEPT
+ $IPTABLES -t nat -N Cid35496X1833.2
+ $IPTABLES -t nat -A PREROUTING -d 192.168.2.10 -j Cid35496X1833.2
+ $IPTABLES -t nat -A PREROUTING -d 192.168.2.11 -j Cid35496X1833.2
+ $IPTABLES -t nat -A Cid35496X1833.2 -s 192.168.1.10 -j ACCEPT
+ $IPTABLES -t nat -A Cid35496X1833.2 -s 192.168.1.20 -j ACCEPT
+ #
+ # Rule 10 (NAT)
+ #
+ echo "Rule 10 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid35514X1833.0
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.10 -j Cid35514X1833.0
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.20 -j Cid35514X1833.0
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.10 -j Cid35514X1833.0
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.20 -j Cid35514X1833.0
+ $IPTABLES -t nat -A Cid35514X1833.0 -d 192.168.2.10 -j RETURN
+ $IPTABLES -t nat -A Cid35514X1833.0 -d 192.168.2.11 -j RETURN
+ $IPTABLES -t nat -A Cid35514X1833.0 -j ACCEPT
+ #
+ # Rule 11 (NAT)
+ #
+ echo "Rule 11 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/1 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 22.22.22.23 --icmp-type 0/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 22.22.22.23 --icmp-type 3 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p 50 -d 22.22.22.23 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p 88 -d 22.22.22.23 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/1 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 0/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 3 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p 50 -d 22.22.22.23 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p 88 -d 22.22.22.23 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 12 (NAT)
+ #
+ echo "Rule 12 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/1 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 0/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 3 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 13 (NAT)
+ #
+ echo "Rule 13 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -s 22.22.23.23 -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -s 22.22.25.50 -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 14 (NAT)
+ #
+ echo "Rule 14 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -s 200.200.200.200 -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 16 (NAT)
+ #
+ echo "Rule 16 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 22.22.22.24 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 22.22.22.25 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.24 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.25 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 17 (NAT)
+ #
+ echo "Rule 17 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 18 (NAT)
+ #
+ echo "Rule 18 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.20 -j SNAT --to-source 22.22.23.24
+ #
+ # Rule 19 (NAT)
+ #
+ echo "Rule 19 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -d 22.22.23.24 -j DNAT --to-destination 192.168.1.20
+ $IPTABLES -t nat -A OUTPUT -d 22.22.23.24 -j DNAT --to-destination 192.168.1.20
+ #
+ # Rule 20 (NAT)
+ #
+ echo "Rule 20 (NAT)"
+ #
+ # firewall2-3:NAT:20: warning: Adding of virtual address for address range is not implemented (object ext_range)
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.100-22.22.22.110
+ #
+ # Rule 21 (NAT)
+ #
+ echo "Rule 21 (NAT)"
+ #
+ # NETMAP
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.0/24 -j NETMAP --to 22.22.22.0/24
+ #
+ # Rule 22 (NAT)
+ #
+ echo "Rule 22 (NAT)"
+ #
+ # NETMAP
+ $IPTABLES -t nat -A PREROUTING -d 22.22.22.0/24 -j NETMAP --to 192.168.1.0/24
+ #
+ # Rule 23 (NAT)
+ #
+ echo "Rule 23 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.23 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.25.50 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.40 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.23.23 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.25.50 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 192.168.1.1 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 192.168.2.1 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 192.168.2.40 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ #
+ # Rule 24 (NAT)
+ #
+ echo "Rule 24 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.23 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.25.50 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.23.23 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.25.50 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -d 192.168.1.10 --dport 80 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 25 (NAT)
+ #
+ echo "Rule 25 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.23 --dport 80 -j DNAT --to-destination 192.168.1.10:25
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.23 --dport 80 -j DNAT --to-destination 192.168.1.10:25
+ #
+ # Rule 26 (NAT)
+ #
+ echo "Rule 26 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.23 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.25.50 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.40 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.23 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.25.50 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.40 --dport 443 -j REDIRECT --to-ports 3128
+ #
+ # Rule 27 (NAT)
+ #
+ echo "Rule 27 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 8080 -j DNAT --to-destination 192.168.1.10-192.168.1.100
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 8080 -j DNAT --to-destination 192.168.1.10-192.168.1.100
+ #
+ # Rule 28 (NAT)
+ #
+ echo "Rule 28 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 8080 -j DNAT --to-destination 192.168.1.11-192.168.1.15
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 8080 -j DNAT --to-destination 192.168.1.11-192.168.1.15
+ #
+ # Rule 29 (NAT)
+ #
+ echo "Rule 29 (NAT)"
+ #
+ # transparent proxy rule
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.0/24 -d ! 22.22.22.23 -j DNAT --to-destination 192.168.2.10
+ #
+ # Rule 31 (NAT)
+ #
+ echo "Rule 31 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j DNAT --to-destination :8080
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j DNAT --to-destination :8080
+ #
+ # Rule 32 (NAT)
+ #
+ echo "Rule 32 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.10 --dport 80 -j DNAT --to-destination 192.168.1.10:8080
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 192.168.1.10 --dport 80 -j DNAT --to-destination 192.168.1.10:8080
+ #
+ # Rule 33 (NAT)
+ #
+ echo "Rule 33 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --dport 80 -j SNAT --to-source 22.22.22.22
+ #
+ # Rule 34 (NAT)
+ #
+ echo "Rule 34 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s ! 192.168.1.10 --dport 80 -j DNAT --to-destination 192.168.1.10:3128
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.10:3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s ! 192.168.1.10 --dport 80 -j DNAT --to-destination 192.168.1.10:3128
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -s ! 192.168.1.10 -d 192.168.1.10 --dport 3128 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 35 (NAT)
+ #
+ echo "Rule 35 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid35884X1833.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d ! 192.168.1.50 --dport 80 -j Cid35884X1833.0
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d ! 192.168.1.50 --dport 80 -j Cid35884X1833.0
+ $IPTABLES -t nat -A Cid35884X1833.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid35884X1833.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid35884X1833.0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.50:3128
+ #
+ # Rule 36 (NAT)
+ #
+ echo "Rule 36 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid35898X1833.1
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -j Cid35898X1833.1
+ $IPTABLES -t nat -A Cid35898X1833.1 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid35898X1833.1 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -N Cid35898X1833.0
+ $IPTABLES -t nat -A Cid35898X1833.1 -j Cid35898X1833.0
+ $IPTABLES -t nat -A Cid35898X1833.0 -p tcp -m tcp --dport 80 -j RETURN
+ $IPTABLES -t nat -A Cid35898X1833.0 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 37 (NAT)
+ #
+ echo "Rule 37 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j DNAT --to-destination 192.168.1.10:3128
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.10 --dport 3128 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 38 (NAT)
+ #
+ echo "Rule 38 (NAT)"
+ #
+ # this is the "exception" rule
+ # used in support req. originally
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.20 --dport 80 -j SNAT --to-source 22.22.22.22
+ #
+ # Rule 39 (NAT)
+ #
+ echo "Rule 39 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j DNAT --to-destination 192.168.1.1:3128
+ #
+ # Rule 40 (NAT)
+ #
+ echo "Rule 40 (NAT)"
+ #
+ # "exception" rule in the pair
+ # from a support req.
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.20 --dport 80 -j SNAT --to-source 22.22.22.22
+ #
+ # Rule 41 (NAT)
+ #
+ echo "Rule 41 (NAT)"
+ #
+ # testing transparent proxy
+ # roules for a support req.
+ $IPTABLES -t nat -N Cid35968X1833.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j Cid35968X1833.0
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j Cid35968X1833.0
+ $IPTABLES -t nat -A Cid35968X1833.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid35968X1833.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid35968X1833.0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.1:3128
+ #
+ # Rule 42 (NAT)
+ #
+ echo "Rule 42 (NAT)"
+ #
+ # testing transparent proxy
+ # roules for a support req.
+ $IPTABLES -t nat -N Cid35982X1833.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j Cid35982X1833.0
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j Cid35982X1833.0
+ $IPTABLES -t nat -A Cid35982X1833.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid35982X1833.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid35982X1833.0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.1:3128
+ #
+ # Rule 43 (NAT)
+ #
+ echo "Rule 43 (NAT)"
+ #
+ # testing transparent proxy
+ # roules for a support req.
+ $IPTABLES -t nat -N Cid35996X1833.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j Cid35996X1833.0
+ $IPTABLES -t nat -A Cid35996X1833.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid35996X1833.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid35996X1833.0 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
+ #
+ # Rule 44 (NAT)
+ #
+ echo "Rule 44 (NAT)"
+ #
+ # "exception" rule in the pair
+ # from a support req.
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.20 --dport 80 -j SNAT --to-source 22.22.22.22
+ #
+ # Rule 45 (NAT)
+ #
+ echo "Rule 45 (NAT)"
+ #
+ # testing transparent proxy
+ # roules for a support req.
+ $IPTABLES -t nat -N Cid36024X1833.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j Cid36024X1833.0
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j Cid36024X1833.0
+ $IPTABLES -t nat -A Cid36024X1833.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid36024X1833.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid36024X1833.0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.50:3128
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth1)
+ #
+ echo "Rule 0 (eth1)"
+ #
+ # Anti-spoofing rule
+ $IPTABLES -N In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 22.22.22.22 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 22.22.23.23 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 22.22.25.50 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 192.168.1.1 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 192.168.2.1 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 192.168.2.40 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 192.168.1.0/24 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 22.22.22.22 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 22.22.23.23 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 22.22.25.50 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.1.1 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.2.1 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.2.40 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.1.0/24 -j In_RULE_0
+ $IPTABLES -A In_RULE_0 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "Iface: global RULE 0 -- DENY " --ulog-qthreshold 1
+ $IPTABLES -A In_RULE_0 -j DROP
+ #
+ # Rule 1 (eth1)
+ #
+ echo "Rule 1 (eth1)"
+ #
+ # Anti-spoofing rule
+ $IPTABLES -N Cid35127X1833.0
+ $IPTABLES -A OUTPUT -o eth1 -j Cid35127X1833.0
+ $IPTABLES -A Cid35127X1833.0 -s 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid35127X1833.0 -s 22.22.23.23 -j RETURN
+ $IPTABLES -A Cid35127X1833.0 -s 22.22.25.50 -j RETURN
+ $IPTABLES -A Cid35127X1833.0 -s 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid35127X1833.0 -s 192.168.2.1 -j RETURN
+ $IPTABLES -A Cid35127X1833.0 -s 192.168.2.40 -j RETURN
+ $IPTABLES -N Out_RULE_1_3
+ $IPTABLES -A Cid35127X1833.0 -j Out_RULE_1_3
+ $IPTABLES -A Out_RULE_1_3 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "Iface: global RULE 1 -- DENY " --ulog-qthreshold 1
+ $IPTABLES -A Out_RULE_1_3 -j DROP
+ $IPTABLES -N Cid35127X1833.1
+ $IPTABLES -A FORWARD -o eth1 -j Cid35127X1833.1
+ $IPTABLES -A Cid35127X1833.1 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid35127X1833.1 -j Out_RULE_1_3
+ #
+ # Rule 2 (fw2i1,3)
+ #
+ echo "Rule 2 (fw2i1,3)"
+ #
+ # testing group in "interface"
+ # this rule should be identical to rule 3
+ $IPTABLES -N In_RULE_2
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_2
+ $IPTABLES -A INPUT -i eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_2
+ $IPTABLES -A FORWARD -i eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_2
+ $IPTABLES -A FORWARD -i eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_2
+ $IPTABLES -A In_RULE_2 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 2 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A In_RULE_2 -j DROP
+ #
+ # Rule 3 (eth1,eth3)
+ #
+ echo "Rule 3 (eth1,eth3)"
+ #
+ $IPTABLES -N In_RULE_3
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_3
+ $IPTABLES -A INPUT -i eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_3
+ $IPTABLES -A FORWARD -i eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_3
+ $IPTABLES -A FORWARD -i eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_3
+ $IPTABLES -A In_RULE_3 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 3 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A In_RULE_3 -j DROP
+ #
+ # Rule 4 (eth1,eth3)
+ #
+ echo "Rule 4 (eth1,eth3)"
+ #
+ # testing choice of chains in case when several
+ # interfaces are used and rule matches 'any' or
+ # broadcast
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth3 -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth1 -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth3 -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (eth1,eth3)
+ #
+ echo "Rule 5 (eth1,eth3)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -m multiport -s 0.0.0.0 -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth3 -p udp -m udp -m multiport -s 0.0.0.0 -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 6 (eth1,eth3)
+ #
+ echo "Rule 6 (eth1,eth3)"
+ #
+ $IPTABLES -A OUTPUT -o eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -N Cid35204X1833.0
+ $IPTABLES -A OUTPUT -j Cid35204X1833.0
+ $IPTABLES -A INPUT -j Cid35204X1833.0
+ $IPTABLES -A FORWARD -j Cid35204X1833.0
+ $IPTABLES -A Cid35204X1833.0 -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j RETURN
+ $IPTABLES -N RULE_7_3
+ $IPTABLES -A Cid35204X1833.0 -j RULE_7_3
+ $IPTABLES -A RULE_7_3 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 7 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_7_3 -j DROP
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ # block fragments
+ $IPTABLES -N RULE_8
+ $IPTABLES -A OUTPUT -p all -f -j RULE_8
+ $IPTABLES -A INPUT -p all -f -j RULE_8
+ $IPTABLES -A FORWARD -p all -f -j RULE_8
+ $IPTABLES -A RULE_8 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 8 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_8 -j DROP
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ # sends TCP RST and makes custom record
+ # in the log
+ $IPTABLES -N RULE_9
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 113 -j RULE_9
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 113 -j RULE_9
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 113 -j RULE_9
+ $IPTABLES -A RULE_9 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "IDENT" --ulog-qthreshold 1
+ $IPTABLES -A RULE_9 -p tcp -m tcp -j REJECT --reject-with tcp-reset
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ # firewall2-3:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -N RULE_10
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -j RULE_10
+ # firewall2-3:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -j RULE_10
+ # firewall2-3:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -j RULE_10
+ # firewall2-3:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A RULE_10 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 10 - REJECT **" --ulog-qthreshold 1
+ # firewall2-3:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A RULE_10 -j REJECT --reject-with icmp-net-unreachable
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ $IPTABLES -N Cid35252X1833.0
+ $IPTABLES -A INPUT -p icmp -s 192.168.2.0/24 -m state --state NEW -j Cid35252X1833.0
+ $IPTABLES -N RULE_11
+ $IPTABLES -A Cid35252X1833.0 -d 192.168.2.1 -j RULE_11
+ $IPTABLES -A Cid35252X1833.0 -d 192.168.2.40 -j RULE_11
+ $IPTABLES -A RULE_11 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 11 - ACCEPT **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_11 -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ $IPTABLES -N Cid35264X1833.0
+ $IPTABLES -A FORWARD -d 211.11.11.11 -m state --state NEW -j Cid35264X1833.0
+ $IPTABLES -A Cid35264X1833.0 -s 192.168.1.10 -j ACCEPT
+ $IPTABLES -A Cid35264X1833.0 -s 192.168.1.20 -j ACCEPT
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ $IPTABLES -N Cid35277X1833.0
+ $IPTABLES -A FORWARD -s 211.11.11.11 -m state --state NEW -j Cid35277X1833.0
+ $IPTABLES -A Cid35277X1833.0 -d 192.168.1.10 -j ACCEPT
+ $IPTABLES -A Cid35277X1833.0 -d 192.168.1.20 -j ACCEPT
+ #
+ # Rule 14 (global)
+ #
+ echo "Rule 14 (global)"
+ #
+ $IPTABLES -N Cid35290X1833.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -j Cid35290X1833.0
+ $IPTABLES -A INPUT -p tcp -m tcp -j Cid35290X1833.0
+ $IPTABLES -A FORWARD -p tcp -m tcp -j Cid35290X1833.0
+ $IPTABLES -A Cid35290X1833.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid35290X1833.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -A Cid35290X1833.0 -p tcp -m tcp -j REJECT --reject-with tcp-reset
+ $IPTABLES -N Cid35290X1833.1
+ $IPTABLES -A OUTPUT -j Cid35290X1833.1
+ $IPTABLES -A INPUT -j Cid35290X1833.1
+ $IPTABLES -A FORWARD -j Cid35290X1833.1
+ $IPTABLES -A Cid35290X1833.1 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid35290X1833.1 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -A Cid35290X1833.1 -j REJECT --reject-with icmp-net-unreachable
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -s 192.168.2.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.2.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.2.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 16 (global)
+ #
+ echo "Rule 16 (global)"
+ #
+ $IPTABLES -N RULE_16
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -j RULE_16
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -j RULE_16
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -j RULE_16
+ $IPTABLES -A RULE_16 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 16 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_16 -j DROP
+ #
+ # Rule 17 (global)
+ #
+ echo "Rule 17 (global)"
+ #
+ # host-fw2 has the same address as
+ # one of the firewall's interfaces
+ $IPTABLES -N RULE_17
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 21 -m state --state NEW -m limit --limit 5/minute --limit-burst 10 -j RULE_17
+ $IPTABLES -A INPUT -p tcp -m tcp -d 22.22.22.22 --dport 21 -m state --state NEW -m limit --limit 5/minute --limit-burst 10 -j RULE_17
+ $IPTABLES -A RULE_17 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 17 - ACCEPT **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_17 -j ACCEPT
+ #
+ # Rule 18 (global)
+ #
+ echo "Rule 18 (global)"
+ #
+ $IPTABLES -N Cid35340X1833.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 21 -m state --state NEW -j Cid35340X1833.0
+ $IPTABLES -N RULE_18
+ $IPTABLES -A Cid35340X1833.0 -d 22.22.22.22 -j RULE_18
+ $IPTABLES -A Cid35340X1833.0 -d 22.22.23.23 -j RULE_18
+ $IPTABLES -A Cid35340X1833.0 -d 22.22.25.50 -j RULE_18
+ $IPTABLES -A Cid35340X1833.0 -d 192.168.1.1 -j RULE_18
+ $IPTABLES -A Cid35340X1833.0 -d 192.168.2.1 -j RULE_18
+ $IPTABLES -A Cid35340X1833.0 -d 192.168.2.40 -j RULE_18
+ $IPTABLES -N Cid35340X1833.1
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 21 -m state --state NEW -j Cid35340X1833.1
+ $IPTABLES -A Cid35340X1833.1 -d 22.22.22.22 -j RULE_18
+ $IPTABLES -A Cid35340X1833.1 -d 22.22.23.23 -j RULE_18
+ $IPTABLES -A Cid35340X1833.1 -d 22.22.25.50 -j RULE_18
+ $IPTABLES -A Cid35340X1833.1 -d 192.168.1.1 -j RULE_18
+ $IPTABLES -A Cid35340X1833.1 -d 192.168.2.1 -j RULE_18
+ $IPTABLES -A Cid35340X1833.1 -d 192.168.2.40 -j RULE_18
+ $IPTABLES -A RULE_18 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 18 - ACCEPT **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_18 -j ACCEPT
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ # 'catch all' rule
+ $IPTABLES -N RULE_19
+ $IPTABLES -A OUTPUT -j RULE_19
+ $IPTABLES -A INPUT -j RULE_19
+ $IPTABLES -A FORWARD -j RULE_19
+ $IPTABLES -A RULE_19 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 19 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_19 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:12 2011 by vadim"
+ check_tools
+
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+ prolog_commands
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall2-4.fw.orig b/test/ipt/firewall2-4.fw.orig
new file mode 100755
index 000000000..bb916f8bd
--- /dev/null
+++ b/test/ipt/firewall2-4.fw.orig
@@ -0,0 +1,484 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:18 2011 PST by vadim
+#
+# files: * firewall2-4.fw
+#
+# Compiled for iptables (any version)
+#
+# tests for error conditions in NATCompiler_ipt::VerifyRules
+
+# firewall2-4:NAT:0: error: Can not use negation in translated source
+# firewall2-4:NAT:1: error: Can not use negation in translated destination.
+# firewall2-4:NAT:2: error: Can not use negation in translated service.
+# firewall2-4:NAT:3: error: Translated service should be 'Original' or should contain single object.
+# firewall2-4:NAT:4: error: Translated service should be 'Original' or should contain single object.
+# firewall2-4:NAT:5: error: Non-contiguous address range in Translated Destination in load balancing NAT rule
+# firewall2-4:NAT:7: error: Action 'Branch' needs NAT rule set to point to
+# firewall2-4:NAT:9: error: Can not use unnumbered interface in Translated Source of a Source translation rule.
+# firewall2-4:NAT:10: error: Original and translated source should both be networks of the same size.
+# firewall2-4:NAT:12: error: Can not use service object in Translated Service if Original Service is 'Any'.
+# firewall2-4:NAT:13: error: NAT rule can not change service types: UDPService to TCPService
+# firewall2-4:NAT:13: error: Translated Service should be either 'Original' or should contain object of the same type as Original Service.
+# firewall2-4:NAT:14: error: NAT rule can not change service types: UDPService to TCPService
+# firewall2-4:NAT:14: error: Translated Service should be either 'Original' or should contain object of the same type as Original Service.
+# firewall2-4:NAT:14: error: Translated Service should be either 'Original' or should contain object of the same type as Original Service.
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24 192.168.1.10/24 192.168.1.20/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24 22.22.22.0/32 22.22.22.1/32 22.22.22.2/32 22.22.22.3/32 22.22.22.4/32 22.22.22.5/32 22.22.22.6/32 22.22.22.7/32 22.22.22.8/32 22.22.22.9/32 22.22.22.10/32 22.22.22.11/32 22.22.22.12/32 22.22.22.13/32 22.22.22.14/32 22.22.22.15/32 22.22.22.16/32 22.22.22.17/32 22.22.22.18/32 22.22.22.19/32 22.22.22.20/32 22.22.22.21/32 22.22.22.22/32 22.22.22.23/32 22.22.22.24/32 22.22.22.25/32 22.22.22.26/32 22.22.22.27/32 22.22.22.28/32 22.22.22.29/32 22.22.22.30/32 22.22.22.31/32 22.22.22.32/32 22.22.22.33/32 22.22.22.34/32 22.22.22.35/32 22.22.22.36/32 22.22.22.37/32 22.22.22.38/32 22.22.22.39/32 22.22.22.40/32 22.22.22.41/32 22.22.22.42/32 22.22.22.43/32 22.22.22.44/32 22.22.22.45/32 22.22.22.46/32 22.22.22.47/32 22.22.22.48/32 22.22.22.49/32 22.22.22.50/32 22.22.22.51/32 22.22.22.52/32 22.22.22.53/32 22.22.22.54/32 22.22.22.55/32 22.22.22.56/32 22.22.22.57/32 22.22.22.58/32 22.22.22.59/32 22.22.22.60/32 22.22.22.61/32 22.22.22.62/32 22.22.22.63/32 22.22.22.64/32 22.22.22.65/32 22.22.22.66/32 22.22.22.67/32 22.22.22.68/32 22.22.22.69/32 22.22.22.70/32 22.22.22.71/32 22.22.22.72/32 22.22.22.73/32 22.22.22.74/32 22.22.22.75/32 22.22.22.76/32 22.22.22.77/32 22.22.22.78/32 22.22.22.79/32 22.22.22.80/32 22.22.22.81/32 22.22.22.82/32 22.22.22.83/32 22.22.22.84/32 22.22.22.85/32 22.22.22.86/32 22.22.22.87/32 22.22.22.88/32 22.22.22.89/32 22.22.22.90/32 22.22.22.91/32 22.22.22.92/32 22.22.22.93/32 22.22.22.94/32 22.22.22.95/32 22.22.22.96/32 22.22.22.97/32 22.22.22.98/32 22.22.22.99/32 22.22.22.100/32 22.22.22.101/32 22.22.22.102/32 22.22.22.103/32 22.22.22.104/32 22.22.22.105/32 22.22.22.106/32 22.22.22.107/32 22.22.22.108/32 22.22.22.109/32 22.22.22.110/32 22.22.22.111/32 22.22.22.112/32 22.22.22.113/32 22.22.22.114/32 22.22.22.115/32 22.22.22.116/32 22.22.22.117/32 22.22.22.118/32 22.22.22.119/32 22.22.22.120/32 22.22.22.121/32 22.22.22.122/32 22.22.22.123/32 22.22.22.124/32 22.22.22.125/32 22.22.22.126/32 22.22.22.127/32 22.22.22.128/32 22.22.22.129/32 22.22.22.130/32 22.22.22.131/32 22.22.22.132/32 22.22.22.133/32 22.22.22.134/32 22.22.22.135/32 22.22.22.136/32 22.22.22.137/32 22.22.22.138/32 22.22.22.139/32 22.22.22.140/32 22.22.22.141/32 22.22.22.142/32 22.22.22.143/32 22.22.22.144/32 22.22.22.145/32 22.22.22.146/32 22.22.22.147/32 22.22.22.148/32 22.22.22.149/32 22.22.22.150/32 22.22.22.151/32 22.22.22.152/32 22.22.22.153/32 22.22.22.154/32 22.22.22.155/32 22.22.22.156/32 22.22.22.157/32 22.22.22.158/32 22.22.22.159/32 22.22.22.160/32 22.22.22.161/32 22.22.22.162/32 22.22.22.163/32 22.22.22.164/32 22.22.22.165/32 22.22.22.166/32 22.22.22.167/32 22.22.22.168/32 22.22.22.169/32 22.22.22.170/32 22.22.22.171/32 22.22.22.172/32 22.22.22.173/32 22.22.22.174/32 22.22.22.175/32 22.22.22.176/32 22.22.22.177/32 22.22.22.178/32 22.22.22.179/32 22.22.22.180/32 22.22.22.181/32 22.22.22.182/32 22.22.22.183/32 22.22.22.184/32 22.22.22.185/32 22.22.22.186/32 22.22.22.187/32 22.22.22.188/32 22.22.22.189/32 22.22.22.190/32 22.22.22.191/32 22.22.22.192/32 22.22.22.193/32 22.22.22.194/32 22.22.22.195/32 22.22.22.196/32 22.22.22.197/32 22.22.22.198/32 22.22.22.199/32 22.22.22.200/32 22.22.22.201/32 22.22.22.202/32 22.22.22.203/32 22.22.22.204/32 22.22.22.205/32 22.22.22.206/32 22.22.22.207/32 22.22.22.208/32 22.22.22.209/32 22.22.22.210/32 22.22.22.211/32 22.22.22.212/32 22.22.22.213/32 22.22.22.214/32 22.22.22.215/32 22.22.22.216/32 22.22.22.217/32 22.22.22.218/32 22.22.22.219/32 22.22.22.220/32 22.22.22.221/32 22.22.22.222/32 22.22.22.223/32 22.22.22.224/32 22.22.22.225/32 22.22.22.226/32 22.22.22.227/32 22.22.22.228/32 22.22.22.229/32 22.22.22.230/32 22.22.22.231/32 22.22.22.232/32 22.22.22.233/32 22.22.22.234/32 22.22.22.235/32 22.22.22.236/32 22.22.22.237/32 22.22.22.238/32 22.22.22.239/32 22.22.22.240/32 22.22.22.241/32 22.22.22.242/32 22.22.22.243/32 22.22.22.244/32 22.22.22.245/32 22.22.22.246/32 22.22.22.247/32 22.22.22.248/32 22.22.22.249/32 22.22.22.250/32 22.22.22.251/32 22.22.22.252/32 22.22.22.253/32 22.22.22.254/32" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24 192.168.2.40/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ echo 1 > /proc/sys/net/ipv4/conf/all/rp_filter
+ echo 0 > /proc/sys/net/ipv4/conf/all/accept_source_route
+ echo 0 > /proc/sys/net/ipv4/conf/all/accept_redirects
+ echo 1 > /proc/sys/net/ipv4/conf/all/log_martians
+ echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_all
+ echo 1 > /proc/sys/net/ipv4/icmp_ignore_bogus_error_responses
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ $IPTABLES -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
+
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop TCP sessions opened prior firewall restart
+ $IPTABLES -A INPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ $IPTABLES -A OUTPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ $IPTABLES -A FORWARD -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ # drop packets that do not match any valid state and log them
+ $IPTABLES -N drop_invalid
+ $IPTABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IPTABLES -A drop_invalid -j ULOG --ulog-nlgroup 1 --ulog-qthreshold 1 --ulog-prefix "INVALID state -- DENY "
+ $IPTABLES -A drop_invalid -j DROP
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ # firewall2-4:NAT:5: error: Non-contiguous address range in Translated Destination in load balancing NAT rule
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 80 -j DNAT --to-destination 192.168.1.10-192.168.1.20
+ # firewall2-4:NAT:5: error: Non-contiguous address range in Translated Destination in load balancing NAT rule
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 80 -j DNAT --to-destination 192.168.1.10-192.168.1.20
+ #
+ # Rule 6 (NAT)
+ #
+ echo "Rule 6 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 192.168.1.10
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 192.168.1.20
+ #
+ # Rule 8 (NAT)
+ #
+ echo "Rule 8 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j NETMAP --to 22.22.22.0/24
+ #
+ # Rule 11 (NAT)
+ #
+ echo "Rule 11 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -d 192.168.2.0/24 -j SNAT --to-source 192.168.2.1
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ # 'catch all' rule
+ $IPTABLES -N RULE_0
+ $IPTABLES -A OUTPUT -j RULE_0
+ $IPTABLES -A INPUT -j RULE_0
+ $IPTABLES -A FORWARD -j RULE_0
+ $IPTABLES -A RULE_0 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 0 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_0 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:18 2011 by vadim"
+ check_tools
+
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+ prolog_commands
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall2-5.fw.orig b/test/ipt/firewall2-5.fw.orig
new file mode 100755
index 000000000..74bdc7348
--- /dev/null
+++ b/test/ipt/firewall2-5.fw.orig
@@ -0,0 +1,513 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:23 2011 PST by vadim
+#
+# files: * firewall2-5.fw
+#
+# Compiled for iptables (any version)
+#
+# various tests for the "-o itf" clause in SNAT rules
+
+# firewall2-5:NAT:4: warning: Adding of virtual address for address range is not implemented (object r-222.222.222.0)
+# firewall2-5:NAT:6: error: Original and translated source should both be networks of the same size.
+# firewall2-5:NAT:7: warning: Adding of virtual address for address range is not implemented (object range 33 30-33)
+
+# firewall2-5::: warning: Can not add virtual address 22.22.22.0 (object external_net)
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth1 222.222.222.222/24 222.222.222.40/24 222.222.222.41/24" ""
+ update_addresses_of_interface "eth3 33.33.33.25/29" ""
+ update_addresses_of_interface "eth2 33.33.33.3/29 33.33.33.4/29" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ echo 1 > /proc/sys/net/ipv4/conf/all/rp_filter
+ echo 0 > /proc/sys/net/ipv4/conf/all/accept_source_route
+ echo 0 > /proc/sys/net/ipv4/conf/all/accept_redirects
+ echo 1 > /proc/sys/net/ipv4/conf/all/log_martians
+ echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_all
+ echo 1 > /proc/sys/net/ipv4/icmp_ignore_bogus_error_responses
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ $IPTABLES -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
+
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop TCP sessions opened prior firewall restart
+ $IPTABLES -A INPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ $IPTABLES -A OUTPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ $IPTABLES -A FORWARD -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ # drop packets that do not match any valid state and log them
+ $IPTABLES -N drop_invalid
+ $IPTABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IPTABLES -A drop_invalid -j ULOG --ulog-nlgroup 1 --ulog-qthreshold 1 --ulog-prefix "INVALID state -- DENY "
+ $IPTABLES -A drop_invalid -j DROP
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ # NETMAP and no -o itf
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.0/24 -j NETMAP --to 22.22.22.0/24
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 222.222.222.40
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 222.222.222.41
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 222.222.222.222
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j SNAT --to-source 222.222.222.222
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ # should be -o eth1
+ # firewall2-5:NAT:4: warning: Adding of virtual address for address range is not implemented (object r-222.222.222.0)
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 222.222.222.10-222.222.222.100
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ # should be -o eth2
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 33.33.33.1-33.33.33.3
+ #
+ # Rule 7 (NAT)
+ #
+ echo "Rule 7 (NAT)"
+ #
+ # partially matches eth3
+ # firewall2-5:NAT:7: warning: Adding of virtual address for address range is not implemented (object range 33 30-33)
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 33.33.33.30-33.33.33.33
+ #
+ # Rule 8 (NAT)
+ #
+ echo "Rule 8 (NAT)"
+ #
+ # should be two rules: -o eth2 and -o eth3
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 33.33.33.1-33.33.33.33
+ #
+ # Rule 9 (NAT)
+ #
+ echo "Rule 9 (NAT)"
+ #
+ # should be -o eth2
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 33.33.33.3
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 33.33.33.4
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ # 'catch all' rule
+ $IPTABLES -N RULE_0
+ $IPTABLES -A OUTPUT -j RULE_0
+ $IPTABLES -A INPUT -j RULE_0
+ $IPTABLES -A FORWARD -j RULE_0
+ $IPTABLES -A RULE_0 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 0 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_0 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:23 2011 by vadim"
+ check_tools
+
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+ prolog_commands
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall2.fw.orig b/test/ipt/firewall2.fw.orig
new file mode 100755
index 000000000..62edaf450
--- /dev/null
+++ b/test/ipt/firewall2.fw.orig
@@ -0,0 +1,1530 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:50 2011 PST by vadim
+#
+# files: * firewall2.fw
+#
+# Compiled for iptables (any version)
+#
+# this object has several interfaces and shows different rules for NAT. Also testing policy rule options
+
+# firewall2:NAT:22: warning: Adding of virtual address for address range is not implemented (object ext_range)
+# firewall2:NAT:51: error: NAT rule can not change service types: CustomService to TCPService
+# firewall2:NAT:51: error: Translated Service should be either 'Original' or should contain object of the same type as Original Service.
+
+# firewall2:Policy:0: error: Rule '0 (eth1)' shadows rule '2 (fw2i1,3)' below it
+# firewall2:Policy:0: error: Rule '0 (eth1)' shadows rule '2 (fw2i1,3)' below it
+# firewall2:Policy:0: error: Rule '0 (eth1)' shadows rule '3 (eth1,eth3)' below it
+# firewall2:Policy:0: error: Rule '0 (eth1)' shadows rule '3 (eth1,eth3)' below it
+# firewall2:Policy:2: error: Rule '2 (fw2i1,3)' shadows rule '3 (eth1,eth3)' below it
+# firewall2:Policy:2: error: Rule '2 (fw2i1,3)' shadows rule '3 (eth1,eth3)' below it
+# firewall2:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '5 (eth1,eth3)' below it
+# firewall2:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '5 (eth1,eth3)' below it
+# firewall2:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '5 (eth1,eth3)' below it
+# firewall2:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '5 (eth1,eth3)' below it
+# firewall2:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '6 (eth1,eth3)' below it
+# firewall2:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '6 (eth1,eth3)' below it
+# firewall2:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '6 (eth1,eth3)' below it
+# firewall2:Policy:4: error: Rule '4 (eth1,eth3)' shadows rule '6 (eth1,eth3)' below it
+# firewall2:Policy:10: error: Rule '10 (global)' shadows rule '11 (global)' below it
+# firewall2:Policy:10: error: Rule '10 (global)' shadows rule '12 (global)' below it
+# firewall2:Policy:10: error: Rule '10 (global)' shadows rule '13 (global)' below it
+# firewall2:Policy:10: error: Rule '10 (global)' shadows rule '14 (global)' below it
+# firewall2:Policy:10: error: Rule '10 (global)' shadows rule '20 (global)' below it
+# firewall2:Policy:25: error: Rule '25 (global)' shadows rule '26 (global)' below it
+# firewall2:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall2:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall2:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall2:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+# firewall2:Policy:29: error: Object 'net-err' has address or netmask 0.0.0.0, which is equivalent to 'any'. This is likely an error.
+# firewall2:Policy:29: error: Object 'net-err' has address or netmask 0.0.0.0, which is equivalent to 'any'. This is likely an error.
+# firewall2:Policy:29: error: Object 'net-err' has address or netmask 0.0.0.0, which is equivalent to 'any'. This is likely an error.
+# firewall2:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall2:Policy:: warning: Log prefix has been truncated to 29 characters
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24 192.168.1.10/24 192.168.1.50/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24 22.22.22.23/24 22.22.22.24/24 22.22.22.25/24 22.22.22.0/32 22.22.22.1/32 22.22.22.2/32 22.22.22.3/32 22.22.22.4/32 22.22.22.5/32 22.22.22.6/32 22.22.22.7/32 22.22.22.8/32 22.22.22.9/32 22.22.22.10/32 22.22.22.11/32 22.22.22.12/32 22.22.22.13/32 22.22.22.14/32 22.22.22.15/32 22.22.22.16/32 22.22.22.17/32 22.22.22.18/32 22.22.22.19/32 22.22.22.20/32 22.22.22.21/32 22.22.22.22/32 22.22.22.23/32 22.22.22.24/32 22.22.22.25/32 22.22.22.26/32 22.22.22.27/32 22.22.22.28/32 22.22.22.29/32 22.22.22.30/32 22.22.22.31/32 22.22.22.32/32 22.22.22.33/32 22.22.22.34/32 22.22.22.35/32 22.22.22.36/32 22.22.22.37/32 22.22.22.38/32 22.22.22.39/32 22.22.22.40/32 22.22.22.41/32 22.22.22.42/32 22.22.22.43/32 22.22.22.44/32 22.22.22.45/32 22.22.22.46/32 22.22.22.47/32 22.22.22.48/32 22.22.22.49/32 22.22.22.50/32 22.22.22.51/32 22.22.22.52/32 22.22.22.53/32 22.22.22.54/32 22.22.22.55/32 22.22.22.56/32 22.22.22.57/32 22.22.22.58/32 22.22.22.59/32 22.22.22.60/32 22.22.22.61/32 22.22.22.62/32 22.22.22.63/32 22.22.22.64/32 22.22.22.65/32 22.22.22.66/32 22.22.22.67/32 22.22.22.68/32 22.22.22.69/32 22.22.22.70/32 22.22.22.71/32 22.22.22.72/32 22.22.22.73/32 22.22.22.74/32 22.22.22.75/32 22.22.22.76/32 22.22.22.77/32 22.22.22.78/32 22.22.22.79/32 22.22.22.80/32 22.22.22.81/32 22.22.22.82/32 22.22.22.83/32 22.22.22.84/32 22.22.22.85/32 22.22.22.86/32 22.22.22.87/32 22.22.22.88/32 22.22.22.89/32 22.22.22.90/32 22.22.22.91/32 22.22.22.92/32 22.22.22.93/32 22.22.22.94/32 22.22.22.95/32 22.22.22.96/32 22.22.22.97/32 22.22.22.98/32 22.22.22.99/32 22.22.22.100/32 22.22.22.101/32 22.22.22.102/32 22.22.22.103/32 22.22.22.104/32 22.22.22.105/32 22.22.22.106/32 22.22.22.107/32 22.22.22.108/32 22.22.22.109/32 22.22.22.110/32 22.22.22.111/32 22.22.22.112/32 22.22.22.113/32 22.22.22.114/32 22.22.22.115/32 22.22.22.116/32 22.22.22.117/32 22.22.22.118/32 22.22.22.119/32 22.22.22.120/32 22.22.22.121/32 22.22.22.122/32 22.22.22.123/32 22.22.22.124/32 22.22.22.125/32 22.22.22.126/32 22.22.22.127/32 22.22.22.128/32 22.22.22.129/32 22.22.22.130/32 22.22.22.131/32 22.22.22.132/32 22.22.22.133/32 22.22.22.134/32 22.22.22.135/32 22.22.22.136/32 22.22.22.137/32 22.22.22.138/32 22.22.22.139/32 22.22.22.140/32 22.22.22.141/32 22.22.22.142/32 22.22.22.143/32 22.22.22.144/32 22.22.22.145/32 22.22.22.146/32 22.22.22.147/32 22.22.22.148/32 22.22.22.149/32 22.22.22.150/32 22.22.22.151/32 22.22.22.152/32 22.22.22.153/32 22.22.22.154/32 22.22.22.155/32 22.22.22.156/32 22.22.22.157/32 22.22.22.158/32 22.22.22.159/32 22.22.22.160/32 22.22.22.161/32 22.22.22.162/32 22.22.22.163/32 22.22.22.164/32 22.22.22.165/32 22.22.22.166/32 22.22.22.167/32 22.22.22.168/32 22.22.22.169/32 22.22.22.170/32 22.22.22.171/32 22.22.22.172/32 22.22.22.173/32 22.22.22.174/32 22.22.22.175/32 22.22.22.176/32 22.22.22.177/32 22.22.22.178/32 22.22.22.179/32 22.22.22.180/32 22.22.22.181/32 22.22.22.182/32 22.22.22.183/32 22.22.22.184/32 22.22.22.185/32 22.22.22.186/32 22.22.22.187/32 22.22.22.188/32 22.22.22.189/32 22.22.22.190/32 22.22.22.191/32 22.22.22.192/32 22.22.22.193/32 22.22.22.194/32 22.22.22.195/32 22.22.22.196/32 22.22.22.197/32 22.22.22.198/32 22.22.22.199/32 22.22.22.200/32 22.22.22.201/32 22.22.22.202/32 22.22.22.203/32 22.22.22.204/32 22.22.22.205/32 22.22.22.206/32 22.22.22.207/32 22.22.22.208/32 22.22.22.209/32 22.22.22.210/32 22.22.22.211/32 22.22.22.212/32 22.22.22.213/32 22.22.22.214/32 22.22.22.215/32 22.22.22.216/32 22.22.22.217/32 22.22.22.218/32 22.22.22.219/32 22.22.22.220/32 22.22.22.221/32 22.22.22.222/32 22.22.22.223/32 22.22.22.224/32 22.22.22.225/32 22.22.22.226/32 22.22.22.227/32 22.22.22.228/32 22.22.22.229/32 22.22.22.230/32 22.22.22.231/32 22.22.22.232/32 22.22.22.233/32 22.22.22.234/32 22.22.22.235/32 22.22.22.236/32 22.22.22.237/32 22.22.22.238/32 22.22.22.239/32 22.22.22.240/32 22.22.22.241/32 22.22.22.242/32 22.22.22.243/32 22.22.22.244/32 22.22.22.245/32 22.22.22.246/32 22.22.22.247/32 22.22.22.248/32 22.22.22.249/32 22.22.22.250/32 22.22.22.251/32 22.22.22.252/32 22.22.22.253/32 22.22.22.254/32" ""
+ update_addresses_of_interface "eth3 22.22.23.23/24 22.22.25.50/24 22.22.23.24/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24 192.168.2.40/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ echo 1 > /proc/sys/net/ipv4/conf/all/rp_filter
+ echo 0 > /proc/sys/net/ipv4/conf/all/accept_source_route
+ echo 0 > /proc/sys/net/ipv4/conf/all/accept_redirects
+ echo 1 > /proc/sys/net/ipv4/conf/all/log_martians
+ echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_all
+ echo 1 > /proc/sys/net/ipv4/icmp_ignore_bogus_error_responses
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ $IPTABLES -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
+
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop TCP sessions opened prior firewall restart
+ $IPTABLES -A INPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ $IPTABLES -A OUTPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ $IPTABLES -A FORWARD -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
+ # drop packets that do not match any valid state and log them
+ $IPTABLES -N drop_invalid
+ $IPTABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IPTABLES -A drop_invalid -j ULOG --ulog-nlgroup 1 --ulog-qthreshold 1 --ulog-prefix "INVALID state -- DENY "
+ $IPTABLES -A drop_invalid -j DROP
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.40
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 192.168.2.40
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/0 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 11/1 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 3 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p 50 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.40
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -p 88 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.40
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 22.22.25.50
+ #
+ # Rule 6 (NAT)
+ #
+ echo "Rule 6 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 22.22.22.23
+ #
+ # Rule 7 (NAT)
+ #
+ echo "Rule 7 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 22.22.22.23 --random
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 22.22.22.24 --random
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 22.22.22.25 --random
+ #
+ # Rule 8 (NAT)
+ #
+ echo "Rule 8 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -d 192.168.1.10 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 9 (NAT)
+ #
+ echo "Rule 9 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -d 192.168.2.0/24 -j SNAT --to-source 192.168.2.1
+ #
+ # Rule 10 (NAT)
+ #
+ echo "Rule 10 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -d 192.168.2.0/24 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -d 192.168.2.0/24 -j SNAT --to-source 192.168.2.40
+ #
+ # Rule 11 (NAT)
+ #
+ echo "Rule 11 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid3D1519E8.0
+ $IPTABLES -t nat -A POSTROUTING -d 192.168.2.10 -j Cid3D1519E8.0
+ $IPTABLES -t nat -A POSTROUTING -d 192.168.2.11 -j Cid3D1519E8.0
+ $IPTABLES -t nat -A Cid3D1519E8.0 -s 22.22.22.22 -j ACCEPT
+ $IPTABLES -t nat -A Cid3D1519E8.0 -s 22.22.23.23 -j ACCEPT
+ $IPTABLES -t nat -A Cid3D1519E8.0 -s 22.22.25.50 -j ACCEPT
+ $IPTABLES -t nat -A Cid3D1519E8.0 -s 192.168.1.1 -j ACCEPT
+ $IPTABLES -t nat -A Cid3D1519E8.0 -s 192.168.2.1 -j ACCEPT
+ $IPTABLES -t nat -A Cid3D1519E8.0 -s 192.168.2.40 -j ACCEPT
+ $IPTABLES -t nat -A OUTPUT -d 192.168.2.10 -j ACCEPT
+ $IPTABLES -t nat -A OUTPUT -d 192.168.2.11 -j ACCEPT
+ $IPTABLES -t nat -N Cid3D1519E8.1
+ $IPTABLES -t nat -A POSTROUTING -d 192.168.2.10 -j Cid3D1519E8.1
+ $IPTABLES -t nat -A POSTROUTING -d 192.168.2.11 -j Cid3D1519E8.1
+ $IPTABLES -t nat -A Cid3D1519E8.1 -s 192.168.1.10 -j ACCEPT
+ $IPTABLES -t nat -A Cid3D1519E8.1 -s 192.168.1.20 -j ACCEPT
+ $IPTABLES -t nat -N Cid3D1519E8.2
+ $IPTABLES -t nat -A PREROUTING -d 192.168.2.10 -j Cid3D1519E8.2
+ $IPTABLES -t nat -A PREROUTING -d 192.168.2.11 -j Cid3D1519E8.2
+ $IPTABLES -t nat -A Cid3D1519E8.2 -s 192.168.1.10 -j ACCEPT
+ $IPTABLES -t nat -A Cid3D1519E8.2 -s 192.168.1.20 -j ACCEPT
+ #
+ # Rule 12 (NAT)
+ #
+ echo "Rule 12 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid3D151BA0.0
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.10 -j Cid3D151BA0.0
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.20 -j Cid3D151BA0.0
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.10 -j Cid3D151BA0.0
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.20 -j Cid3D151BA0.0
+ $IPTABLES -t nat -A Cid3D151BA0.0 -d 192.168.2.10 -j RETURN
+ $IPTABLES -t nat -A Cid3D151BA0.0 -d 192.168.2.11 -j RETURN
+ $IPTABLES -t nat -A Cid3D151BA0.0 -j ACCEPT
+ #
+ # Rule 13 (NAT)
+ #
+ echo "Rule 13 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/1 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 22.22.22.23 --icmp-type 0/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p icmp -m icmp -d 22.22.22.23 --icmp-type 3 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p 50 -d 22.22.22.23 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p 88 -d 22.22.22.23 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/1 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 0/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 3 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p 50 -d 22.22.22.23 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p 88 -d 22.22.22.23 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 14 (NAT)
+ #
+ echo "Rule 14 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 11/1 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 0/0 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p icmp -m icmp -d 22.22.22.23 --icmp-type 3 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 15 (NAT)
+ #
+ echo "Rule 15 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -s 22.22.23.23 -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -s 22.22.25.50 -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 16 (NAT)
+ #
+ echo "Rule 16 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -s 200.200.200.200 -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 18 (NAT)
+ #
+ echo "Rule 18 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 22.22.22.24 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -m multiport -d 22.22.22.25 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.23 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.24 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m multiport -d 22.22.22.25 --dports 80,119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 19 (NAT)
+ #
+ echo "Rule 19 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 119 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 119 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 20 (NAT)
+ #
+ echo "Rule 20 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.20 -j SNAT --to-source 22.22.23.24
+ #
+ # Rule 21 (NAT)
+ #
+ echo "Rule 21 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -d 22.22.23.24 -j DNAT --to-destination 192.168.1.20
+ $IPTABLES -t nat -A OUTPUT -d 22.22.23.24 -j DNAT --to-destination 192.168.1.20
+ #
+ # Rule 22 (NAT)
+ #
+ echo "Rule 22 (NAT)"
+ #
+ # firewall2:NAT:22: warning: Adding of virtual address for address range is not implemented (object ext_range)
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.100-22.22.22.110
+ #
+ # Rule 23 (NAT)
+ #
+ echo "Rule 23 (NAT)"
+ #
+ # NETMAP
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.0/24 -j NETMAP --to 22.22.22.0/24
+ #
+ # Rule 24 (NAT)
+ #
+ echo "Rule 24 (NAT)"
+ #
+ # NETMAP
+ $IPTABLES -t nat -A PREROUTING -d 22.22.22.0/24 -j NETMAP --to 192.168.1.0/24
+ #
+ # Rule 25 (NAT)
+ #
+ echo "Rule 25 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.23 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.25.50 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.40 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.23.23 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.25.50 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 192.168.1.1 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 192.168.2.1 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 192.168.2.40 --dport 10000:11000 -j DNAT --to-destination 192.168.1.10:10000-11000
+ #
+ # Rule 26 (NAT)
+ #
+ echo "Rule 26 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.23 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.25.50 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.23.23 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.25.50 --dport 80 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -d 192.168.1.10 --dport 80 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 27 (NAT)
+ #
+ echo "Rule 27 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.23 --dport 80 -j DNAT --to-destination 192.168.1.10:25
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.23 --dport 80 -j DNAT --to-destination 192.168.1.10:25
+ #
+ # Rule 28 (NAT)
+ #
+ echo "Rule 28 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.23 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.25.50 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.40 --dport 80 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.23 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.25.50 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 443 -j REDIRECT --to-ports 3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.40 --dport 443 -j REDIRECT --to-ports 3128
+ #
+ # Rule 29 (NAT)
+ #
+ echo "Rule 29 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 8080 -j DNAT --to-destination 192.168.1.10-192.168.1.100
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 8080 -j DNAT --to-destination 192.168.1.10-192.168.1.100
+ #
+ # Rule 30 (NAT)
+ #
+ echo "Rule 30 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 8080 -j DNAT --to-destination 192.168.1.11-192.168.1.15
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 8080 -j DNAT --to-destination 192.168.1.11-192.168.1.15
+ #
+ # Rule 31 (NAT)
+ #
+ echo "Rule 31 (NAT)"
+ #
+ # transparent proxy rule
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.0/24 -d ! 22.22.22.23 -j DNAT --to-destination 192.168.2.10
+ #
+ # Rule 33 (NAT)
+ #
+ echo "Rule 33 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j DNAT --to-destination :8080
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j DNAT --to-destination :8080
+ #
+ # Rule 34 (NAT)
+ #
+ echo "Rule 34 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.10 --dport 80 -j DNAT --to-destination 192.168.1.10:8080
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d 192.168.1.10 --dport 80 -j DNAT --to-destination 192.168.1.10:8080
+ #
+ # Rule 35 (NAT)
+ #
+ echo "Rule 35 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --dport 80 -j SNAT --to-source 22.22.22.22
+ #
+ # Rule 36 (NAT)
+ #
+ echo "Rule 36 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s ! 192.168.1.10 --dport 80 -j DNAT --to-destination 192.168.1.10:3128
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.10:3128
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s ! 192.168.1.10 --dport 80 -j DNAT --to-destination 192.168.1.10:3128
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -s ! 192.168.1.10 -d 192.168.1.10 --dport 3128 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 37 (NAT)
+ #
+ echo "Rule 37 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid40F195C3.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d ! 192.168.1.50 --dport 80 -j Cid40F195C3.0
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -d ! 192.168.1.50 --dport 80 -j Cid40F195C3.0
+ $IPTABLES -t nat -A Cid40F195C3.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid40F195C3.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid40F195C3.0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.50:3128
+ #
+ # Rule 38 (NAT)
+ #
+ echo "Rule 38 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid40F1C52F.1
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -j Cid40F1C52F.1
+ $IPTABLES -t nat -A Cid40F1C52F.1 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid40F1C52F.1 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -N Cid40F1C52F.0
+ $IPTABLES -t nat -A Cid40F1C52F.1 -j Cid40F1C52F.0
+ $IPTABLES -t nat -A Cid40F1C52F.0 -p tcp -m tcp --dport 80 -j RETURN
+ $IPTABLES -t nat -A Cid40F1C52F.0 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 39 (NAT)
+ #
+ echo "Rule 39 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j DNAT --to-destination 192.168.1.10:3128
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.10 --dport 3128 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 40 (NAT)
+ #
+ echo "Rule 40 (NAT)"
+ #
+ # this is the "exception" rule
+ # used in support req. originally
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.20 --dport 80 -j SNAT --to-source 22.22.22.22
+ #
+ # Rule 41 (NAT)
+ #
+ echo "Rule 41 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j DNAT --to-destination 192.168.1.1:3128
+ #
+ # Rule 42 (NAT)
+ #
+ echo "Rule 42 (NAT)"
+ #
+ # "exception" rule in the pair
+ # from a support req.
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.20 --dport 80 -j SNAT --to-source 22.22.22.22
+ #
+ # Rule 43 (NAT)
+ #
+ echo "Rule 43 (NAT)"
+ #
+ # testing transparent proxy
+ # roules for a support req.
+ $IPTABLES -t nat -N Cid46D67A4324736.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j Cid46D67A4324736.0
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j Cid46D67A4324736.0
+ $IPTABLES -t nat -A Cid46D67A4324736.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid46D67A4324736.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid46D67A4324736.0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.1:3128
+ #
+ # Rule 44 (NAT)
+ #
+ echo "Rule 44 (NAT)"
+ #
+ # testing transparent proxy
+ # roules for a support req.
+ $IPTABLES -t nat -N Cid46D67A5924736.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j Cid46D67A5924736.0
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j Cid46D67A5924736.0
+ $IPTABLES -t nat -A Cid46D67A5924736.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid46D67A5924736.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid46D67A5924736.0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.1:3128
+ #
+ # Rule 45 (NAT)
+ #
+ echo "Rule 45 (NAT)"
+ #
+ # testing transparent proxy
+ # roules for a support req.
+ $IPTABLES -t nat -N Cid46D49F3624736.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j Cid46D49F3624736.0
+ $IPTABLES -t nat -A Cid46D49F3624736.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid46D49F3624736.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid46D49F3624736.0 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
+ #
+ # Rule 46 (NAT)
+ #
+ echo "Rule 46 (NAT)"
+ #
+ # "exception" rule in the pair
+ # from a support req.
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.10 --dport 80 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.20 --dport 80 -j SNAT --to-source 22.22.22.22
+ #
+ # Rule 47 (NAT)
+ #
+ echo "Rule 47 (NAT)"
+ #
+ # testing transparent proxy
+ # roules for a support req.
+ $IPTABLES -t nat -N Cid46D6AA2F24736.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp --dport 80 -j Cid46D6AA2F24736.0
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 80 -j Cid46D6AA2F24736.0
+ $IPTABLES -t nat -A Cid46D6AA2F24736.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -t nat -A Cid46D6AA2F24736.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -t nat -A Cid46D6AA2F24736.0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.50:3128
+ #
+ # Rule 48 (NAT)
+ #
+ echo "Rule 48 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.0/24 --dport 3050:3051 -j DNAT --to-destination :700
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -p tcp -m tcp -s 192.168.1.0/24 --dport 700 -j SNAT --to-source 192.168.1.10
+ #
+ # Rule 49 (NAT)
+ #
+ echo "Rule 49 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp --dport 9040 -j REDIRECT --to-ports 9040
+ #
+ # Rule 50 (NAT)
+ #
+ echo "Rule 50 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m owner --uid-owner anonymous -j REDIRECT --to-ports 9040
+ #
+ # Rule 52 (NAT)
+ #
+ echo "Rule 52 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p udp -m udp -m owner --uid-owner anonymous -j REDIRECT --to-ports 53
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth1)
+ #
+ echo "Rule 0 (eth1)"
+ #
+ # Anti-spoofing rule
+ $IPTABLES -N In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 22.22.22.22 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 22.22.23.23 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 22.22.25.50 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 192.168.1.1 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 192.168.2.1 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 192.168.2.40 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 192.168.1.0/24 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 22.22.22.22 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 22.22.23.23 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 22.22.25.50 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.1.1 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.2.1 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.2.40 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.1.0/24 -j In_RULE_0
+ $IPTABLES -A In_RULE_0 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "Iface: global RULE 0 -- DENY " --ulog-qthreshold 1
+ $IPTABLES -A In_RULE_0 -j DROP
+ #
+ # Rule 1 (eth1)
+ #
+ echo "Rule 1 (eth1)"
+ #
+ # Anti-spoofing rule
+ $IPTABLES -N Cid3AFB6710.0
+ $IPTABLES -A OUTPUT -o eth1 -j Cid3AFB6710.0
+ $IPTABLES -A Cid3AFB6710.0 -s 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid3AFB6710.0 -s 22.22.23.23 -j RETURN
+ $IPTABLES -A Cid3AFB6710.0 -s 22.22.25.50 -j RETURN
+ $IPTABLES -A Cid3AFB6710.0 -s 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid3AFB6710.0 -s 192.168.2.1 -j RETURN
+ $IPTABLES -A Cid3AFB6710.0 -s 192.168.2.40 -j RETURN
+ $IPTABLES -N Out_RULE_1_3
+ $IPTABLES -A Cid3AFB6710.0 -j Out_RULE_1_3
+ $IPTABLES -A Out_RULE_1_3 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "Iface: global RULE 1 -- DENY " --ulog-qthreshold 1
+ $IPTABLES -A Out_RULE_1_3 -j DROP
+ $IPTABLES -N Cid3AFB6710.1
+ $IPTABLES -A FORWARD -o eth1 -j Cid3AFB6710.1
+ $IPTABLES -A Cid3AFB6710.1 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid3AFB6710.1 -j Out_RULE_1_3
+ #
+ # Rule 2 (fw2i1,3)
+ #
+ echo "Rule 2 (fw2i1,3)"
+ #
+ # testing group in "interface"
+ # this rule should be identical to rule 3
+ $IPTABLES -N In_RULE_2
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_2
+ $IPTABLES -A INPUT -i eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_2
+ $IPTABLES -A FORWARD -i eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_2
+ $IPTABLES -A FORWARD -i eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_2
+ $IPTABLES -A In_RULE_2 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 2 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A In_RULE_2 -j DROP
+ #
+ # Rule 3 (eth1,eth3)
+ #
+ echo "Rule 3 (eth1,eth3)"
+ #
+ $IPTABLES -N In_RULE_3
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_3
+ $IPTABLES -A INPUT -i eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_3
+ $IPTABLES -A FORWARD -i eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_3
+ $IPTABLES -A FORWARD -i eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_3
+ $IPTABLES -A In_RULE_3 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 3 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A In_RULE_3 -j DROP
+ #
+ # Rule 4 (eth1,eth3)
+ #
+ echo "Rule 4 (eth1,eth3)"
+ #
+ # testing choice of chains in case when several
+ # interfaces are used and rule matches 'any' or
+ # broadcast
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth3 -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth1 -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth3 -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (eth1,eth3)
+ #
+ echo "Rule 5 (eth1,eth3)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -m multiport -s 0.0.0.0 -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth3 -p udp -m udp -m multiport -s 0.0.0.0 -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 6 (eth1,eth3)
+ #
+ echo "Rule 6 (eth1,eth3)"
+ #
+ $IPTABLES -A OUTPUT -o eth1 -p udp -m udp -m multiport -s 192.168.1.0/24 -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth3 -p udp -m udp -m multiport -s 192.168.1.0/24 -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -N Cid3D6748D9.0
+ $IPTABLES -A OUTPUT -j Cid3D6748D9.0
+ $IPTABLES -A INPUT -j Cid3D6748D9.0
+ $IPTABLES -A FORWARD -j Cid3D6748D9.0
+ $IPTABLES -A Cid3D6748D9.0 -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j RETURN
+ $IPTABLES -N RULE_7_3
+ $IPTABLES -A Cid3D6748D9.0 -j RULE_7_3
+ $IPTABLES -A RULE_7_3 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 7 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_7_3 -j DROP
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ # block fragments
+ $IPTABLES -N RULE_8
+ $IPTABLES -A OUTPUT -p all -f -j RULE_8
+ $IPTABLES -A INPUT -p all -f -j RULE_8
+ $IPTABLES -A FORWARD -p all -f -j RULE_8
+ $IPTABLES -A RULE_8 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 8 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_8 -j DROP
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ # sends TCP RST and makes custom record
+ # in the log
+ $IPTABLES -N RULE_9
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 113 -j RULE_9
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 113 -j RULE_9
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 113 -j RULE_9
+ $IPTABLES -A RULE_9 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "IDENT" --ulog-qthreshold 1
+ $IPTABLES -A RULE_9 -p tcp -m tcp -j REJECT --reject-with tcp-reset
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ # firewall2:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -N RULE_10
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -j RULE_10
+ # firewall2:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -j RULE_10
+ # firewall2:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -j RULE_10
+ # firewall2:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A RULE_10 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 10 - REJECT **" --ulog-qthreshold 1
+ # firewall2:Policy:10: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A RULE_10 -j REJECT --reject-with icmp-net-unreachable
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid39895X70161.0
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid39895X70161.0
+ $IPTABLES -A Cid39895X70161.0 -d 192.168.1.10/31 -j ACCEPT
+ $IPTABLES -A Cid39895X70161.0 -d 192.168.1.12/30 -j ACCEPT
+ $IPTABLES -A Cid39895X70161.0 -d 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid39895X70161.0 -d 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid39895X70161.0 -d 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid39895X70161.0 -d 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid39895X70161.0 -d 192.168.1.100 -j ACCEPT
+ $IPTABLES -N Cid39895X70161.1
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid39895X70161.1
+ $IPTABLES -A Cid39895X70161.1 -d 192.168.1.10/31 -j ACCEPT
+ $IPTABLES -A Cid39895X70161.1 -d 192.168.1.12/30 -j ACCEPT
+ $IPTABLES -A Cid39895X70161.1 -d 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid39895X70161.1 -d 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid39895X70161.1 -d 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid39895X70161.1 -d 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid39895X70161.1 -d 192.168.1.100 -j ACCEPT
+ $IPTABLES -N Cid39895X70161.2
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid39895X70161.2
+ $IPTABLES -A Cid39895X70161.2 -d 192.168.1.10/31 -j ACCEPT
+ $IPTABLES -A Cid39895X70161.2 -d 192.168.1.12/30 -j ACCEPT
+ $IPTABLES -A Cid39895X70161.2 -d 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid39895X70161.2 -d 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid39895X70161.2 -d 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid39895X70161.2 -d 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid39895X70161.2 -d 192.168.1.100 -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid39909X70161.0
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid39909X70161.0
+ $IPTABLES -A Cid39909X70161.0 -s 192.168.1.10/31 -j ACCEPT
+ $IPTABLES -A Cid39909X70161.0 -s 192.168.1.12/30 -j ACCEPT
+ $IPTABLES -A Cid39909X70161.0 -s 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid39909X70161.0 -s 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid39909X70161.0 -s 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid39909X70161.0 -s 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid39909X70161.0 -s 192.168.1.100 -j ACCEPT
+ $IPTABLES -N Cid39909X70161.1
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid39909X70161.1
+ $IPTABLES -A Cid39909X70161.1 -s 192.168.1.10/31 -j ACCEPT
+ $IPTABLES -A Cid39909X70161.1 -s 192.168.1.12/30 -j ACCEPT
+ $IPTABLES -A Cid39909X70161.1 -s 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid39909X70161.1 -s 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid39909X70161.1 -s 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid39909X70161.1 -s 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid39909X70161.1 -s 192.168.1.100 -j ACCEPT
+ $IPTABLES -N Cid39909X70161.2
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid39909X70161.2
+ $IPTABLES -A Cid39909X70161.2 -s 192.168.1.10/31 -j ACCEPT
+ $IPTABLES -A Cid39909X70161.2 -s 192.168.1.12/30 -j ACCEPT
+ $IPTABLES -A Cid39909X70161.2 -s 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid39909X70161.2 -s 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid39909X70161.2 -s 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid39909X70161.2 -s 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid39909X70161.2 -s 192.168.1.100 -j ACCEPT
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid131093X70161.0
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid131093X70161.0
+ $IPTABLES -N Cid131093X70161.1
+ $IPTABLES -A Cid131093X70161.0 -s 222.222.222.10/31 -j Cid131093X70161.1
+ $IPTABLES -A Cid131093X70161.0 -s 222.222.222.12/30 -j Cid131093X70161.1
+ $IPTABLES -A Cid131093X70161.0 -s 222.222.222.16/28 -j Cid131093X70161.1
+ $IPTABLES -A Cid131093X70161.0 -s 222.222.222.32/27 -j Cid131093X70161.1
+ $IPTABLES -A Cid131093X70161.0 -s 222.222.222.64/27 -j Cid131093X70161.1
+ $IPTABLES -A Cid131093X70161.0 -s 222.222.222.96/30 -j Cid131093X70161.1
+ $IPTABLES -A Cid131093X70161.0 -s 222.222.222.100 -j Cid131093X70161.1
+ $IPTABLES -A Cid131093X70161.1 -d 192.168.1.10/31 -j ACCEPT
+ $IPTABLES -A Cid131093X70161.1 -d 192.168.1.12/30 -j ACCEPT
+ $IPTABLES -A Cid131093X70161.1 -d 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid131093X70161.1 -d 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid131093X70161.1 -d 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid131093X70161.1 -d 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid131093X70161.1 -d 192.168.1.100 -j ACCEPT
+ $IPTABLES -N Cid131093X70161.2
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid131093X70161.2
+ $IPTABLES -N Cid131093X70161.3
+ $IPTABLES -A Cid131093X70161.2 -s 222.222.222.10/31 -j Cid131093X70161.3
+ $IPTABLES -A Cid131093X70161.2 -s 222.222.222.12/30 -j Cid131093X70161.3
+ $IPTABLES -A Cid131093X70161.2 -s 222.222.222.16/28 -j Cid131093X70161.3
+ $IPTABLES -A Cid131093X70161.2 -s 222.222.222.32/27 -j Cid131093X70161.3
+ $IPTABLES -A Cid131093X70161.2 -s 222.222.222.64/27 -j Cid131093X70161.3
+ $IPTABLES -A Cid131093X70161.2 -s 222.222.222.96/30 -j Cid131093X70161.3
+ $IPTABLES -A Cid131093X70161.2 -s 222.222.222.100 -j Cid131093X70161.3
+ $IPTABLES -A Cid131093X70161.3 -d 192.168.1.10/31 -j ACCEPT
+ $IPTABLES -A Cid131093X70161.3 -d 192.168.1.12/30 -j ACCEPT
+ $IPTABLES -A Cid131093X70161.3 -d 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid131093X70161.3 -d 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid131093X70161.3 -d 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid131093X70161.3 -d 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid131093X70161.3 -d 192.168.1.100 -j ACCEPT
+ #
+ # Rule 14 (global)
+ #
+ echo "Rule 14 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid131076X70161.0
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid131076X70161.0
+ $IPTABLES -N Cid131076X70161.1
+ $IPTABLES -A Cid131076X70161.0 -s 192.168.1.10/31 -j Cid131076X70161.1
+ $IPTABLES -A Cid131076X70161.0 -s 192.168.1.12/30 -j Cid131076X70161.1
+ $IPTABLES -A Cid131076X70161.0 -s 192.168.1.16/28 -j Cid131076X70161.1
+ $IPTABLES -A Cid131076X70161.0 -s 192.168.1.32/27 -j Cid131076X70161.1
+ $IPTABLES -A Cid131076X70161.0 -s 192.168.1.64/27 -j Cid131076X70161.1
+ $IPTABLES -A Cid131076X70161.0 -s 192.168.1.96/30 -j Cid131076X70161.1
+ $IPTABLES -A Cid131076X70161.0 -s 192.168.1.100 -j Cid131076X70161.1
+ $IPTABLES -A Cid131076X70161.1 -d 222.222.222.10/31 -j ACCEPT
+ $IPTABLES -A Cid131076X70161.1 -d 222.222.222.12/30 -j ACCEPT
+ $IPTABLES -A Cid131076X70161.1 -d 222.222.222.16/28 -j ACCEPT
+ $IPTABLES -A Cid131076X70161.1 -d 222.222.222.32/27 -j ACCEPT
+ $IPTABLES -A Cid131076X70161.1 -d 222.222.222.64/27 -j ACCEPT
+ $IPTABLES -A Cid131076X70161.1 -d 222.222.222.96/30 -j ACCEPT
+ $IPTABLES -A Cid131076X70161.1 -d 222.222.222.100 -j ACCEPT
+ $IPTABLES -N Cid131076X70161.2
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid131076X70161.2
+ $IPTABLES -N Cid131076X70161.3
+ $IPTABLES -A Cid131076X70161.2 -s 192.168.1.10/31 -j Cid131076X70161.3
+ $IPTABLES -A Cid131076X70161.2 -s 192.168.1.12/30 -j Cid131076X70161.3
+ $IPTABLES -A Cid131076X70161.2 -s 192.168.1.16/28 -j Cid131076X70161.3
+ $IPTABLES -A Cid131076X70161.2 -s 192.168.1.32/27 -j Cid131076X70161.3
+ $IPTABLES -A Cid131076X70161.2 -s 192.168.1.64/27 -j Cid131076X70161.3
+ $IPTABLES -A Cid131076X70161.2 -s 192.168.1.96/30 -j Cid131076X70161.3
+ $IPTABLES -A Cid131076X70161.2 -s 192.168.1.100 -j Cid131076X70161.3
+ $IPTABLES -A Cid131076X70161.3 -d 222.222.222.10/31 -j ACCEPT
+ $IPTABLES -A Cid131076X70161.3 -d 222.222.222.12/30 -j ACCEPT
+ $IPTABLES -A Cid131076X70161.3 -d 222.222.222.16/28 -j ACCEPT
+ $IPTABLES -A Cid131076X70161.3 -d 222.222.222.32/27 -j ACCEPT
+ $IPTABLES -A Cid131076X70161.3 -d 222.222.222.64/27 -j ACCEPT
+ $IPTABLES -A Cid131076X70161.3 -d 222.222.222.96/30 -j ACCEPT
+ $IPTABLES -A Cid131076X70161.3 -d 222.222.222.100 -j ACCEPT
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid57999X70161.0
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid57999X70161.0
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid57999X70161.0
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid57999X70161.0
+ $IPTABLES -A Cid57999X70161.0 -d 192.168.1.10/31 -j RETURN
+ $IPTABLES -A Cid57999X70161.0 -d 192.168.1.12/30 -j RETURN
+ $IPTABLES -A Cid57999X70161.0 -d 192.168.1.16/28 -j RETURN
+ $IPTABLES -A Cid57999X70161.0 -d 192.168.1.32/27 -j RETURN
+ $IPTABLES -A Cid57999X70161.0 -d 192.168.1.64/27 -j RETURN
+ $IPTABLES -A Cid57999X70161.0 -d 192.168.1.96/30 -j RETURN
+ $IPTABLES -A Cid57999X70161.0 -d 192.168.1.100 -j RETURN
+ $IPTABLES -A Cid57999X70161.0 -j ACCEPT
+ #
+ # Rule 16 (global)
+ #
+ echo "Rule 16 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid58016X70161.0
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid58016X70161.0
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid58016X70161.0
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid58016X70161.0
+ $IPTABLES -A Cid58016X70161.0 -s 192.168.1.10/31 -j RETURN
+ $IPTABLES -A Cid58016X70161.0 -s 192.168.1.12/30 -j RETURN
+ $IPTABLES -A Cid58016X70161.0 -s 192.168.1.16/28 -j RETURN
+ $IPTABLES -A Cid58016X70161.0 -s 192.168.1.32/27 -j RETURN
+ $IPTABLES -A Cid58016X70161.0 -s 192.168.1.64/27 -j RETURN
+ $IPTABLES -A Cid58016X70161.0 -s 192.168.1.96/30 -j RETURN
+ $IPTABLES -A Cid58016X70161.0 -s 192.168.1.100 -j RETURN
+ $IPTABLES -A Cid58016X70161.0 -j ACCEPT
+ #
+ # Rule 17 (global)
+ #
+ echo "Rule 17 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid76132X70161.0
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid76132X70161.0
+ $IPTABLES -A Cid76132X70161.0 -d 192.168.1.0 -j RETURN
+ $IPTABLES -A Cid76132X70161.0 -j ACCEPT
+ $IPTABLES -N Cid76132X70161.1
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid76132X70161.1
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid76132X70161.1
+ $IPTABLES -A Cid76132X70161.1 -d 192.168.1.10/31 -j RETURN
+ $IPTABLES -A Cid76132X70161.1 -d 192.168.1.12/30 -j RETURN
+ $IPTABLES -A Cid76132X70161.1 -d 192.168.1.16/28 -j RETURN
+ $IPTABLES -A Cid76132X70161.1 -d 192.168.1.32/27 -j RETURN
+ $IPTABLES -A Cid76132X70161.1 -d 192.168.1.64/27 -j RETURN
+ $IPTABLES -A Cid76132X70161.1 -d 192.168.1.96/30 -j RETURN
+ $IPTABLES -A Cid76132X70161.1 -d 192.168.1.100 -j RETURN
+ $IPTABLES -A Cid76132X70161.1 -j ACCEPT
+ #
+ # Rule 18 (global)
+ #
+ echo "Rule 18 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -N Cid76149X70161.0
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid76149X70161.0
+ $IPTABLES -A Cid76149X70161.0 -s 192.168.1.0 -j RETURN
+ $IPTABLES -A Cid76149X70161.0 -j ACCEPT
+ $IPTABLES -N Cid76149X70161.1
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid76149X70161.1
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid76149X70161.1
+ $IPTABLES -A Cid76149X70161.1 -s 192.168.1.10/31 -j RETURN
+ $IPTABLES -A Cid76149X70161.1 -s 192.168.1.12/30 -j RETURN
+ $IPTABLES -A Cid76149X70161.1 -s 192.168.1.16/28 -j RETURN
+ $IPTABLES -A Cid76149X70161.1 -s 192.168.1.32/27 -j RETURN
+ $IPTABLES -A Cid76149X70161.1 -s 192.168.1.64/27 -j RETURN
+ $IPTABLES -A Cid76149X70161.1 -s 192.168.1.96/30 -j RETURN
+ $IPTABLES -A Cid76149X70161.1 -s 192.168.1.100 -j RETURN
+ $IPTABLES -A Cid76149X70161.1 -j ACCEPT
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ # also test for bug #2526173
+ $IPTABLES -N RULE_19
+ $IPTABLES -A INPUT -s 0.0.0.0 -j RULE_19
+ $IPTABLES -A FORWARD -s 0.0.0.0 -j RULE_19
+ $IPTABLES -A RULE_19 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 19 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_19 -j DROP
+ #
+ # Rule 20 (global)
+ #
+ echo "Rule 20 (global)"
+ #
+ # using module iprange if
+ # iptables version is >= 1.2.11
+ $IPTABLES -A INPUT -p udp -m udp -s 192.168.1.1 --dport 161 -m state --state NEW -j ACCEPT
+ $IPTABLES -N Cid42387X35957.0
+ $IPTABLES -A INPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid42387X35957.0
+ $IPTABLES -A Cid42387X35957.0 -s 192.168.1.2/31 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.0 -s 192.168.1.4/30 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.0 -s 192.168.1.8/29 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.0 -s 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.0 -s 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.0 -s 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.0 -s 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.0 -s 192.168.1.100 -j ACCEPT
+ $IPTABLES -A OUTPUT -p udp -m udp -s 192.168.1.1 --dport 161 -m state --state NEW -j ACCEPT
+ $IPTABLES -N Cid42387X35957.1
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 161 -m state --state NEW -j Cid42387X35957.1
+ $IPTABLES -A Cid42387X35957.1 -s 192.168.1.2/31 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.1 -s 192.168.1.4/30 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.1 -s 192.168.1.8/29 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.1 -s 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.1 -s 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.1 -s 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.1 -s 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.1 -s 192.168.1.100 -j ACCEPT
+ $IPTABLES -N Cid42387X35957.2
+ $IPTABLES -A FORWARD -p udp -m udp --dport 161 -m state --state NEW -j Cid42387X35957.2
+ $IPTABLES -A Cid42387X35957.2 -s 192.168.1.2/31 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.2 -s 192.168.1.4/30 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.2 -s 192.168.1.8/29 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.2 -s 192.168.1.16/28 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.2 -s 192.168.1.32/27 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.2 -s 192.168.1.64/27 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.2 -s 192.168.1.96/30 -j ACCEPT
+ $IPTABLES -A Cid42387X35957.2 -s 192.168.1.100 -j ACCEPT
+ #
+ # Rule 21 (global)
+ #
+ echo "Rule 21 (global)"
+ #
+ $IPTABLES -N Cid3DD1E1E0.0
+ $IPTABLES -A INPUT -p icmp -m icmp -s 192.168.2.0/24 --icmp-type any -m state --state NEW -j Cid3DD1E1E0.0
+ $IPTABLES -N RULE_21
+ $IPTABLES -A Cid3DD1E1E0.0 -d 192.168.2.1 -j RULE_21
+ $IPTABLES -A Cid3DD1E1E0.0 -d 192.168.2.40 -j RULE_21
+ $IPTABLES -A RULE_21 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 21 - ACCEPT **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_21 -j ACCEPT
+ #
+ # Rule 22 (global)
+ #
+ echo "Rule 22 (global)"
+ #
+ $IPTABLES -N Cid3D8FC846.0
+ $IPTABLES -A FORWARD -d 211.11.11.11 -m state --state NEW -j Cid3D8FC846.0
+ $IPTABLES -A Cid3D8FC846.0 -s 192.168.1.10 -j ACCEPT
+ $IPTABLES -A Cid3D8FC846.0 -s 192.168.1.20 -j ACCEPT
+ #
+ # Rule 23 (global)
+ #
+ echo "Rule 23 (global)"
+ #
+ $IPTABLES -N Cid3D8FC984.0
+ $IPTABLES -A FORWARD -s 211.11.11.11 -m state --state NEW -j Cid3D8FC984.0
+ $IPTABLES -A Cid3D8FC984.0 -d 192.168.1.10 -j ACCEPT
+ $IPTABLES -A Cid3D8FC984.0 -d 192.168.1.20 -j ACCEPT
+ #
+ # Rule 24 (global)
+ #
+ echo "Rule 24 (global)"
+ #
+ $IPTABLES -N Cid3DCBFEA0.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -j Cid3DCBFEA0.0
+ $IPTABLES -A INPUT -p tcp -m tcp -j Cid3DCBFEA0.0
+ $IPTABLES -A FORWARD -p tcp -m tcp -j Cid3DCBFEA0.0
+ $IPTABLES -A Cid3DCBFEA0.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid3DCBFEA0.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -A Cid3DCBFEA0.0 -p tcp -m tcp -j REJECT --reject-with tcp-reset
+ $IPTABLES -N Cid3DCBFEA0.1
+ $IPTABLES -A OUTPUT -j Cid3DCBFEA0.1
+ $IPTABLES -A INPUT -j Cid3DCBFEA0.1
+ $IPTABLES -A FORWARD -j Cid3DCBFEA0.1
+ $IPTABLES -A Cid3DCBFEA0.1 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid3DCBFEA0.1 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -A Cid3DCBFEA0.1 -j REJECT --reject-with icmp-net-unreachable
+ #
+ # Rule 25 (global)
+ #
+ echo "Rule 25 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -s 192.168.2.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.2.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.2.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 26 (global)
+ #
+ echo "Rule 26 (global)"
+ #
+ $IPTABLES -N RULE_26
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -j RULE_26
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -j RULE_26
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -j RULE_26
+ $IPTABLES -A RULE_26 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 26 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_26 -j DROP
+ #
+ # Rule 27 (global)
+ #
+ echo "Rule 27 (global)"
+ #
+ # host-fw2 has the same address as
+ # one of the firewall's interfaces
+ $IPTABLES -N RULE_27
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 22.22.22.22 --dport 21 -m state --state NEW -m limit --limit 5/minute --limit-burst 10 -j RULE_27
+ $IPTABLES -A INPUT -p tcp -m tcp -d 22.22.22.22 --dport 21 -m state --state NEW -m limit --limit 5/minute --limit-burst 10 -j RULE_27
+ $IPTABLES -A RULE_27 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 27 - ACCEPT **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_27 -j ACCEPT
+ #
+ # Rule 28 (global)
+ #
+ echo "Rule 28 (global)"
+ #
+ $IPTABLES -N Cid3C447BCB.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 21 -m state --state NEW -j Cid3C447BCB.0
+ $IPTABLES -N RULE_28
+ $IPTABLES -A Cid3C447BCB.0 -d 22.22.22.22 -j RULE_28
+ $IPTABLES -A Cid3C447BCB.0 -d 22.22.23.23 -j RULE_28
+ $IPTABLES -A Cid3C447BCB.0 -d 22.22.25.50 -j RULE_28
+ $IPTABLES -A Cid3C447BCB.0 -d 192.168.1.1 -j RULE_28
+ $IPTABLES -A Cid3C447BCB.0 -d 192.168.2.1 -j RULE_28
+ $IPTABLES -A Cid3C447BCB.0 -d 192.168.2.40 -j RULE_28
+ $IPTABLES -N Cid3C447BCB.1
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 21 -m state --state NEW -j Cid3C447BCB.1
+ $IPTABLES -A Cid3C447BCB.1 -d 22.22.22.22 -j RULE_28
+ $IPTABLES -A Cid3C447BCB.1 -d 22.22.23.23 -j RULE_28
+ $IPTABLES -A Cid3C447BCB.1 -d 22.22.25.50 -j RULE_28
+ $IPTABLES -A Cid3C447BCB.1 -d 192.168.1.1 -j RULE_28
+ $IPTABLES -A Cid3C447BCB.1 -d 192.168.2.1 -j RULE_28
+ $IPTABLES -A Cid3C447BCB.1 -d 192.168.2.40 -j RULE_28
+ $IPTABLES -A RULE_28 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 28 - ACCEPT **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_28 -j ACCEPT
+ #
+ # Rule 29 (global)
+ #
+ echo "Rule 29 (global)"
+ #
+ # 'catch all' rule
+ # firewall2:Policy:29: error: Object 'net-err' has address or netmask 0.0.0.0, which is equivalent to 'any'. This is likely an error.
+ $IPTABLES -N RULE_29
+ $IPTABLES -A INPUT -s 1.2.3.0/0 -j RULE_29
+ # firewall2:Policy:29: error: Object 'net-err' has address or netmask 0.0.0.0, which is equivalent to 'any'. This is likely an error.
+ $IPTABLES -A OUTPUT -s 1.2.3.0/0 -j RULE_29
+ # firewall2:Policy:29: error: Object 'net-err' has address or netmask 0.0.0.0, which is equivalent to 'any'. This is likely an error.
+ $IPTABLES -A FORWARD -s 1.2.3.0/0 -j RULE_29
+ $IPTABLES -A RULE_29 -m limit --limit 5/second -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 29 - DENY **" --ulog-qthreshold 1
+ $IPTABLES -A RULE_29 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:53:50 2011 by vadim"
+ check_tools
+
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+ prolog_commands
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall20-ipv6.fw.orig b/test/ipt/firewall20-ipv6.fw.orig
new file mode 100755
index 000000000..2e8f6d2a1
--- /dev/null
+++ b/test/ipt/firewall20-ipv6.fw.orig
@@ -0,0 +1,516 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:54 2011 PST by vadim
+#
+# files: * firewall20-ipv6.fw
+#
+# Compiled for iptables (any version)
+#
+# testing firewall_is_part_of_any_and_networks
+# also testing SNAT and DNAT rules when external interface has dynamic address
+
+# dynamic interface ppp0 has an address object attached to it (interface used to be static and had an address, then got converted to dynamic but address object is still there). Compiler should ignore this address object and issue a warning.
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth2"
+ for i in eth0 eth2 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 fe80::1/64 192.168.1.1/24" ""
+ update_addresses_of_interface "eth2 2001:470:1f05:590::1/64 192.168.2.1/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+
+
+
+
+
+
+
+ # ================ IPv6
+
+
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 1 (ppp*)
+ #
+ echo "Rule 1 (ppp*)"
+ #
+ # ppp clients can not connect to the firewall
+ $IP6TABLES -N In_RULE_1
+ getinterfaces ppp | while read I; do
+ ivar=$(getInterfaceVarName $I)
+ getaddr6 $I $ivar
+ cmd="$"${ivar}_list
+ eval "addr_list=$cmd"
+ for addr in $addr_list
+ do
+ test -n "$addr" && $IP6TABLES -A INPUT -i ppp+ -d $addr -j In_RULE_1
+ done
+ done
+ $IP6TABLES -A In_RULE_1 -j LOG
+ $IP6TABLES -A In_RULE_1 -j DROP
+ #
+ # Rule 2 (ppp*)
+ #
+ echo "Rule 2 (ppp*)"
+ #
+ $IP6TABLES -N In_RULE_2
+ $IP6TABLES -A INPUT -i ppp+ -j In_RULE_2
+ $IP6TABLES -A In_RULE_2 -j LOG
+ $IP6TABLES -A In_RULE_2 -j DROP
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IP6TABLES -N Cid30296X26784.0
+ $IP6TABLES -A OUTPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid30296X26784.0
+ getinterfaces ppp | while read I; do
+ ivar=$(getInterfaceVarName $I)
+ getaddr6 $I $ivar
+ cmd="$"${ivar}_list
+ eval "addr_list=$cmd"
+ for addr in $addr_list
+ do
+ test -n "$addr" && $IP6TABLES -A Cid30296X26784.0 -d $addr -j ACCEPT
+ done
+ done
+ $IP6TABLES -A Cid30296X26784.0 -d 2001:470:1f05:590::1 -j ACCEPT
+ $IP6TABLES -A Cid30296X26784.0 -d fe80::1 -j ACCEPT
+ $IP6TABLES -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ getinterfaces ppp | while read I; do
+ ivar=$(getInterfaceVarName $I)
+ getaddr6 $I $ivar
+ cmd="$"${ivar}_list
+ eval "addr_list=$cmd"
+ for addr in $addr_list
+ do
+ test -n "$addr" && $IP6TABLES -A OUTPUT -p tcp -m tcp -d $addr --dport 22 -m state --state NEW -j ACCEPT
+ done
+ done
+ getinterfaces ppp | while read I; do
+ ivar=$(getInterfaceVarName $I)
+ getaddr6 $I $ivar
+ cmd="$"${ivar}_list
+ eval "addr_list=$cmd"
+ for addr in $addr_list
+ do
+ test -n "$addr" && $IP6TABLES -A INPUT -p tcp -m tcp -d $addr --dport 22 -m state --state NEW -j ACCEPT
+ done
+ done
+ #
+ # Rule 18 (global)
+ #
+ echo "Rule 18 (global)"
+ #
+ $IP6TABLES -N RULE_18
+ $IP6TABLES -A OUTPUT -m rt --rt-type 0 -j RULE_18
+ $IP6TABLES -A INPUT -m rt --rt-type 0 -j RULE_18
+ $IP6TABLES -A FORWARD -m rt --rt-type 0 -j RULE_18
+ $IP6TABLES -A RULE_18 -j LOG
+ $IP6TABLES -A RULE_18 -j DROP
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ # Automatically generated 'catch all' rule
+ $IP6TABLES -N RULE_19
+ $IP6TABLES -A OUTPUT -j RULE_19
+ $IP6TABLES -A INPUT -j RULE_19
+ $IP6TABLES -A FORWARD -j RULE_19
+ $IP6TABLES -A RULE_19 -j LOG
+ $IP6TABLES -A RULE_19 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:53:54 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat ipv6"
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall20.fw.orig b/test/ipt/firewall20.fw.orig
new file mode 100755
index 000000000..6cce23368
--- /dev/null
+++ b/test/ipt/firewall20.fw.orig
@@ -0,0 +1,734 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:52 2011 PST by vadim
+#
+# files: * firewall20.fw
+#
+# Compiled for iptables (any version)
+#
+# testing firewall_is_part_of_any_and_networks
+# also testing SNAT and DNAT rules when external interface
+# has dynamic address
+
+# dynamic interface ppp0 has an address object attached to it
+# (interface used to be static and had an address, then got
+# converted to dynamic but address object is still there). Compiler
+# should ignore this address object and issue a warning.
+
+# firewall20::: error: Dynamic interface ppp* should not have an IP address object attached to it. This IP address object will be ignored.
+
+# firewall20::: warning: Can not add virtual address for object address
+# firewall20::: warning: Can not add virtual address for object address
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth2"
+ for i in eth0 eth2 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o ppp+ -s 192.168.1.0/24 -j MASQUERADE
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.23
+ $IPTABLES -t nat -A POSTROUTING -o ppp+ -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.23
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o ppp+ -s 192.168.1.0/24 -j MASQUERADE
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o ppp+ -s 192.168.1.0/24 -j MASQUERADE --random
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ getinterfaces ppp | while read I; do
+ ivar=$(getInterfaceVarName $I)
+ getaddr $I $ivar
+ cmd="$"${ivar}_list
+ eval "addr_list=$cmd"
+ for addr in $addr_list
+ do
+ test -n "$addr" && $IPTABLES -t nat -A POSTROUTING -o ppp+ -s 192.168.1.0/24 -j SNAT --to-source $addr
+ done
+ done
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ getinterfaces ppp | while read I; do
+ ivar=$(getInterfaceVarName $I)
+ getaddr $I $ivar
+ cmd="$"${ivar}_list
+ eval "addr_list=$cmd"
+ for addr in $addr_list
+ do
+ test -n "$addr" && $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d $addr --dport 22 -j DNAT --to-destination 192.168.1.10:22
+ done
+ done
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 22 -j DNAT --to-destination 192.168.1.10:22
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 22 -j DNAT --to-destination 192.168.1.10:22
+ #
+ # Rule 6 (NAT)
+ #
+ echo "Rule 6 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.0/24 -d ! 200.200.200.200 -j DNAT --to-destination 192.168.2.10
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -d 192.168.2.10 -j SNAT --to-source 192.168.2.1
+ #
+ # Rule 7 (NAT)
+ #
+ echo "Rule 7 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 22 -j DNAT --to-destination 192.168.1.10
+ getinterfaces ppp | while read I; do
+ ivar=$(getInterfaceVarName $I)
+ getaddr $I $ivar
+ cmd="$"${ivar}_list
+ eval "addr_list=$cmd"
+ for addr in $addr_list
+ do
+ test -n "$addr" && $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d $addr --dport 22 -j DNAT --to-destination 192.168.1.10
+ done
+ done
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (ppp*)
+ #
+ echo "Rule 0 (ppp*)"
+ #
+ # ppp clients get addresses on 10.1.1.0
+ $IPTABLES -N In_RULE_0
+ $IPTABLES -A INPUT -i ppp+ -s ! 10.1.1.0/24 -j In_RULE_0
+ $IPTABLES -A FORWARD -i ppp+ -s ! 10.1.1.0/24 -j In_RULE_0
+ $IPTABLES -A In_RULE_0 -j LOG
+ $IPTABLES -A In_RULE_0 -j DROP
+ #
+ # Rule 1 (ppp*)
+ #
+ echo "Rule 1 (ppp*)"
+ #
+ # ppp clients can not connect to the firewall
+ $IPTABLES -N In_RULE_1
+ getinterfaces ppp | while read I; do
+ ivar=$(getInterfaceVarName $I)
+ getaddr $I $ivar
+ cmd="$"${ivar}_list
+ eval "addr_list=$cmd"
+ for addr in $addr_list
+ do
+ test -n "$addr" && $IPTABLES -A INPUT -i ppp+ -d $addr -j In_RULE_1
+ done
+ done
+ $IPTABLES -A In_RULE_1 -j LOG
+ $IPTABLES -A In_RULE_1 -j DROP
+ #
+ # Rule 2 (ppp*)
+ #
+ echo "Rule 2 (ppp*)"
+ #
+ $IPTABLES -N In_RULE_2
+ $IPTABLES -A INPUT -i ppp+ -j In_RULE_2
+ $IPTABLES -A In_RULE_2 -j LOG
+ $IPTABLES -A In_RULE_2 -j DROP
+ #
+ # Rule 3 (ppp*)
+ #
+ echo "Rule 3 (ppp*)"
+ #
+ # ppp clients can only connect to the mail
+ # server and web proxy on DMZ
+ $IPTABLES -A FORWARD -i ppp+ -p tcp -m tcp -m multiport -d 192.168.2.10 --dports 25,3128 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (ppp*)
+ #
+ echo "Rule 4 (ppp*)"
+ #
+ # ppp clients can not connect to
+ # anything else on DMZ and
+ # internal net
+ $IPTABLES -N In_RULE_4
+ $IPTABLES -A INPUT -i ppp+ -d 192.168.1.0/24 -j In_RULE_4
+ $IPTABLES -A INPUT -i ppp+ -d 192.168.2.0/24 -j In_RULE_4
+ $IPTABLES -A FORWARD -i ppp+ -d 192.168.1.0/24 -j In_RULE_4
+ $IPTABLES -A FORWARD -i ppp+ -d 192.168.2.0/24 -j In_RULE_4
+ $IPTABLES -A In_RULE_4 -j LOG
+ $IPTABLES -A In_RULE_4 -j DROP
+ #
+ # Rule 5 (ppp*)
+ #
+ echo "Rule 5 (ppp*)"
+ #
+ $IPTABLES -A INPUT -i ppp+ -s ! 33.33.33.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i ppp+ -s ! 33.33.33.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 6 (eth2)
+ #
+ echo "Rule 6 (eth2)"
+ #
+ $IPTABLES -N In_RULE_6
+ $IPTABLES -A INPUT -i eth2 -s ! 192.168.2.0/24 -j In_RULE_6
+ $IPTABLES -A FORWARD -i eth2 -s ! 192.168.2.0/24 -j In_RULE_6
+ $IPTABLES -A In_RULE_6 -j LOG
+ $IPTABLES -A In_RULE_6 -j DROP
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ # hostF has the same IP address as firewal.
+ $IPTABLES -N RULE_7
+ $IPTABLES -A OUTPUT -p icmp -m icmp -d 192.168.1.1 --icmp-type 8/0 -m state --state NEW -j RULE_7
+ $IPTABLES -A INPUT -p icmp -m icmp -d 192.168.1.1 --icmp-type 8/0 -m state --state NEW -j RULE_7
+ $IPTABLES -A RULE_7 -j LOG
+ $IPTABLES -A RULE_7 -j ACCEPT
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -N Cid3EFBC67F.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid3EFBC67F.0
+ getinterfaces ppp | while read I; do
+ ivar=$(getInterfaceVarName $I)
+ getaddr $I $ivar
+ cmd="$"${ivar}_list
+ eval "addr_list=$cmd"
+ for addr in $addr_list
+ do
+ test -n "$addr" && $IPTABLES -A Cid3EFBC67F.0 -d $addr -j ACCEPT
+ done
+ done
+ $IPTABLES -A Cid3EFBC67F.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3EFBC67F.0 -d 192.168.2.1 -j ACCEPT
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ getinterfaces ppp | while read I; do
+ ivar=$(getInterfaceVarName $I)
+ getaddr $I $ivar
+ cmd="$"${ivar}_list
+ eval "addr_list=$cmd"
+ for addr in $addr_list
+ do
+ test -n "$addr" && $IPTABLES -A OUTPUT -p tcp -m tcp -d $addr --dport 22 -m state --state NEW -j ACCEPT
+ done
+ done
+ getinterfaces ppp | while read I; do
+ ivar=$(getInterfaceVarName $I)
+ getaddr $I $ivar
+ cmd="$"${ivar}_list
+ eval "addr_list=$cmd"
+ for addr in $addr_list
+ do
+ test -n "$addr" && $IPTABLES -A INPUT -p tcp -m tcp -d $addr --dport 22 -m state --state NEW -j ACCEPT
+ done
+ done
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.1 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p tcp -m tcp -d 192.168.1.1 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -m multiport -d 192.168.1.1 --dports 22,23 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p tcp -m tcp -m multiport -d 192.168.1.1 --dports 22,23 -m state --state NEW -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ $IPTABLES -N Cid3EFBC6A8.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid3EFBC6A8.0
+ $IPTABLES -A Cid3EFBC6A8.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3EFBC6A8.0 -d 192.168.2.1 -j ACCEPT
+ $IPTABLES -N Cid3EFBC6A8.1
+ $IPTABLES -A INPUT -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid3EFBC6A8.1
+ $IPTABLES -A Cid3EFBC6A8.1 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3EFBC6A8.1 -d 192.168.2.1 -j ACCEPT
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ $IPTABLES -N Cid3EFBC6B3.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid3EFBC6B3.0
+ $IPTABLES -N RULE_13
+ $IPTABLES -A Cid3EFBC6B3.0 -d 192.168.1.1 -j RULE_13
+ $IPTABLES -A Cid3EFBC6B3.0 -d 192.168.2.1 -j RULE_13
+ $IPTABLES -N Cid3EFBC6B3.1
+ $IPTABLES -A INPUT -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid3EFBC6B3.1
+ $IPTABLES -A Cid3EFBC6B3.1 -d 192.168.1.1 -j RULE_13
+ $IPTABLES -A Cid3EFBC6B3.1 -d 192.168.2.1 -j RULE_13
+ $IPTABLES -A RULE_13 -j LOG
+ $IPTABLES -A RULE_13 -j ACCEPT
+ #
+ # Rule 14 (global)
+ #
+ echo "Rule 14 (global)"
+ #
+ # firewall is part of Any, so compiler should
+ # generate code in both FORWARD and
+ # OUTPUT chains
+ $IPTABLES -A OUTPUT -d 200.200.200.200 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 200.200.200.200 -m state --state NEW -j ACCEPT
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ # firewall is part of Any, compiler should
+ # generate code for both FORWARD and
+ # INPUT chains
+ $IPTABLES -A INPUT -s 200.200.200.200 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 200.200.200.200 -m state --state NEW -j ACCEPT
+ #
+ # Rule 16 (global)
+ #
+ echo "Rule 16 (global)"
+ #
+ # because firewall has interface on network
+ # internal_net, compiler should generate code
+ # for both FORWARD and INPUT chains
+ $IPTABLES -A INPUT -s 192.168.1.10 -d 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.10 -d 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 17 (global)
+ #
+ echo "Rule 17 (global)"
+ #
+ $IPTABLES -N Cid3EFBC6DC.0
+ $IPTABLES -A OUTPUT -d 200.200.200.200 -m state --state NEW -j Cid3EFBC6DC.0
+ $IPTABLES -A Cid3EFBC6DC.0 -s 192.168.1.0/24 -j ACCEPT
+ $IPTABLES -A Cid3EFBC6DC.0 -s 192.168.2.0/24 -j ACCEPT
+ $IPTABLES -N Cid3EFBC6DC.1
+ $IPTABLES -A FORWARD -d 200.200.200.200 -m state --state NEW -j Cid3EFBC6DC.1
+ $IPTABLES -A Cid3EFBC6DC.1 -s 192.168.1.0/24 -j ACCEPT
+ $IPTABLES -A Cid3EFBC6DC.1 -s 192.168.2.0/24 -j ACCEPT
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ # Automatically generated 'catch all' rule
+ $IPTABLES -N RULE_19
+ $IPTABLES -A OUTPUT -j RULE_19
+ $IPTABLES -A INPUT -j RULE_19
+ $IPTABLES -A FORWARD -j RULE_19
+ $IPTABLES -A RULE_19 -j LOG
+ $IPTABLES -A RULE_19 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:53:52 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall21-1.fw.orig b/test/ipt/firewall21-1.fw.orig
new file mode 100755
index 000000000..27006da16
--- /dev/null
+++ b/test/ipt/firewall21-1.fw.orig
@@ -0,0 +1,530 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:02 2011 PST by vadim
+#
+# files: * firewall21-1.fw
+#
+# Compiled for iptables 1.4.3
+#
+# two dynamic interfaces in the same policy or NAT rule
+# iptables v1.4.3
+
+# firewall21-1:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall21-1:Policy:: warning: Log prefix has been truncated to 29 characters
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth2 192.168.1.100/24" ""
+ getaddr eth0 i_eth0
+ getaddr6 eth0 i_eth0_v6
+ getaddr eth1 i_eth1
+ getaddr6 eth1 i_eth1_v6
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -t nat -A PREROUTING -d $i_eth0 -j DNAT --to-destination 192.168.1.10
+ done
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -t nat -A PREROUTING -d $i_eth1 -j DNAT --to-destination 192.168.1.10
+ done
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -t nat -A PREROUTING -d $i_eth0 -j DNAT --to-destination 192.168.1.10 --random --persistent
+ done
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -t nat -A PREROUTING -d $i_eth1 -j DNAT --to-destination 192.168.1.10 --random --persistent
+ done
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j MASQUERADE
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j MASQUERADE --random
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source $i_eth0 --persistent
+ done
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source $i_eth0 --random --persistent
+ done
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -o eth0 -s $i_eth0 -m state --state NEW -j ACCEPT
+ done
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A INPUT -s $i_eth0 -m state --state NEW -j ACCEPT
+ done
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -A INPUT -s $i_eth1 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -s $i_eth0 -m state --state NEW -j ACCEPT
+ done
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -A OUTPUT -s $i_eth1 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -A OUTPUT -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -p udp -m udp -m multiport -d $i_eth0 --dports 68,67 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A INPUT -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A INPUT -p udp -m udp -m multiport -d $i_eth0 --dports 68,67 -m state --state NEW -j ACCEPT
+ done
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -N RULE_3
+ $IPTABLES -A OUTPUT -j RULE_3
+ $IPTABLES -A INPUT -j RULE_3
+ $IPTABLES -A FORWARD -j RULE_3
+ $IPTABLES -A RULE_3 -j LOG --log-level debug --log-prefix "RULE 3 -- DENY on interface g"
+ $IPTABLES -A RULE_3 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:02 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall21.fw.orig b/test/ipt/firewall21.fw.orig
new file mode 100755
index 000000000..e79084046
--- /dev/null
+++ b/test/ipt/firewall21.fw.orig
@@ -0,0 +1,529 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:53:56 2011 PST by vadim
+#
+# files: * firewall21.fw
+#
+# Compiled for iptables (any version)
+#
+# two dynamic interfaces in the same policy or NAT rule
+
+# firewall21:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall21:Policy:: warning: Log prefix has been truncated to 29 characters
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth2 192.168.1.100/24" ""
+ getaddr eth0 i_eth0
+ getaddr6 eth0 i_eth0_v6
+ getaddr eth1 i_eth1
+ getaddr6 eth1 i_eth1_v6
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -t nat -A PREROUTING -d $i_eth0 -j DNAT --to-destination 192.168.1.10
+ done
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -t nat -A PREROUTING -d $i_eth1 -j DNAT --to-destination 192.168.1.10
+ done
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -t nat -A PREROUTING -d $i_eth0 -j DNAT --to-destination 192.168.1.10 --random
+ done
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -t nat -A PREROUTING -d $i_eth1 -j DNAT --to-destination 192.168.1.10 --random
+ done
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j MASQUERADE
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j MASQUERADE --random
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source $i_eth0
+ done
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source $i_eth0 --random
+ done
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -o eth0 -s $i_eth0 -m state --state NEW -j ACCEPT
+ done
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A INPUT -s $i_eth0 -m state --state NEW -j ACCEPT
+ done
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -A INPUT -s $i_eth1 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -s $i_eth0 -m state --state NEW -j ACCEPT
+ done
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -A OUTPUT -s $i_eth1 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -A OUTPUT -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -p udp -m udp -m multiport -d $i_eth0 --dports 68,67 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A INPUT -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A INPUT -p udp -m udp -m multiport -d $i_eth0 --dports 68,67 -m state --state NEW -j ACCEPT
+ done
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -N RULE_3
+ $IPTABLES -A OUTPUT -j RULE_3
+ $IPTABLES -A INPUT -j RULE_3
+ $IPTABLES -A FORWARD -j RULE_3
+ $IPTABLES -A RULE_3 -j LOG --log-level debug --log-prefix "RULE 3 -- DENY on interface g"
+ $IPTABLES -A RULE_3 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:53:56 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall22.fw.orig b/test/ipt/firewall22.fw.orig
new file mode 100755
index 000000000..82081407c
--- /dev/null
+++ b/test/ipt/firewall22.fw.orig
@@ -0,0 +1,450 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:04 2011 PST by vadim
+#
+# files: * firewall22.fw
+#
+# Compiled for iptables 1.2.9
+#
+# testing NAT rules using custom services
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth1 192.168.2.1/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -m string --string test_pattern -j SNAT --to-source 192.168.2.1
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -d 192.168.2.1 -m string --string test_pattern -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.0/24 -m string --string test_pattern -j DNAT --to-destination 200.200.200.200
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -d 200.200.200.200 -m string --string test_pattern -j SNAT --to-source 192.168.2.1
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth1)
+ #
+ echo "Rule 0 (eth1)"
+ #
+ $IPTABLES -N In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s ! 192.168.2.0/24 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s ! 192.168.2.0/24 -j In_RULE_0
+ $IPTABLES -A In_RULE_0 -j LOG
+ $IPTABLES -A In_RULE_0 -j DROP
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -N RULE_1
+ $IPTABLES -A OUTPUT -j RULE_1
+ $IPTABLES -A INPUT -j RULE_1
+ $IPTABLES -A FORWARD -j RULE_1
+ $IPTABLES -A RULE_1 -j LOG --log-level error
+ $IPTABLES -A RULE_1 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:04 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall23-1.fw.orig b/test/ipt/firewall23-1.fw.orig
new file mode 100755
index 000000000..354015694
--- /dev/null
+++ b/test/ipt/firewall23-1.fw.orig
@@ -0,0 +1,624 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:14 2011 PST by vadim
+#
+# files: * firewall23-1.fw
+#
+# Compiled for iptables 1.3.0
+#
+# This is BRIDGING FIREWALL
+# Testing module physdev
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "br0 192.168.1.1/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # ================ Table 'mangle', automatic rules
+ $IPTABLES -t mangle -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
+
+
+
+ # ================ Table 'mangle', rule set Policy
+ #
+ # Rule 13 (eth2)
+ #
+ echo "Rule 13 (eth2)"
+ #
+ $IPTABLES -t mangle -A POSTROUTING -m physdev --physdev-out eth2 -p tcp -m tcp -d 192.168.1.0/24 --dport 22 -j CLASSIFY --set-class 1:12
+ #
+ # Rule 14 (eth3)
+ #
+ echo "Rule 14 (eth3)"
+ #
+ $IPTABLES -t mangle -A POSTROUTING -m physdev --physdev-out eth3 -p tcp -m tcp -d 192.168.1.0/24 --dport 22 -j CLASSIFY --set-class 2:12
+ #
+ # Rule 15 (eth2)
+ #
+ echo "Rule 15 (eth2)"
+ #
+ $IPTABLES -N Out_RULE_15 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -m physdev --physdev-out eth2 -p tcp -m tcp -d 192.168.1.0/24 --dport 22 -j Out_RULE_15
+ $IPTABLES -t mangle -A Out_RULE_15 -j LOG --log-level debug
+ $IPTABLES -t mangle -A Out_RULE_15 -j CLASSIFY --set-class 1:12
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth2,eth3)
+ #
+ echo "Rule 0 (eth2,eth3)"
+ #
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth2 -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth3 -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -m physdev --physdev-in eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -m physdev --physdev-in eth3 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (eth2,eth3)
+ #
+ echo "Rule 1 (eth2,eth3)"
+ #
+ $IPTABLES -A INPUT -m physdev --physdev-in eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -m physdev --physdev-in eth3 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth3 -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (eth2,eth3)
+ #
+ echo "Rule 2 (eth2,eth3)"
+ #
+ $IPTABLES -N In_RULE_2
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth2 -d 192.168.1.10 -m state --state NEW -j In_RULE_2
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth2 -d 192.168.1.20 -m state --state NEW -j In_RULE_2
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth3 -d 192.168.1.10 -m state --state NEW -j In_RULE_2
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth3 -d 192.168.1.20 -m state --state NEW -j In_RULE_2
+ $IPTABLES -A In_RULE_2 -j LOG --log-level debug
+ $IPTABLES -A In_RULE_2 -j ACCEPT
+ #
+ # Rule 3 (eth2,eth3)
+ #
+ echo "Rule 3 (eth2,eth3)"
+ #
+ # testing for bug 1593221
+ $IPTABLES -N Cid45546AAE30629.0
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth2 -s 192.168.1.0/24 -m state --state NEW -j Cid45546AAE30629.0
+ $IPTABLES -N In_RULE_3
+ $IPTABLES -A Cid45546AAE30629.0 -d 192.168.1.10 -j In_RULE_3
+ $IPTABLES -A Cid45546AAE30629.0 -d 192.168.1.20 -j In_RULE_3
+ $IPTABLES -N Cid45546AAE30629.1
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth3 -s 192.168.1.0/24 -m state --state NEW -j Cid45546AAE30629.1
+ $IPTABLES -A Cid45546AAE30629.1 -d 192.168.1.10 -j In_RULE_3
+ $IPTABLES -A Cid45546AAE30629.1 -d 192.168.1.20 -j In_RULE_3
+ $IPTABLES -A In_RULE_3 -j LOG --log-level debug
+ $IPTABLES -A In_RULE_3 -j ACCEPT
+ #
+ # Rule 4 (eth2,eth3)
+ #
+ echo "Rule 4 (eth2,eth3)"
+ #
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth2 -d 192.168.1.255 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth3 -d 192.168.1.255 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (eth2,eth3)
+ #
+ echo "Rule 5 (eth2,eth3)"
+ #
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth2 -d 255.255.255.255 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth3 -d 255.255.255.255 -m state --state NEW -j ACCEPT
+ #
+ # Rule 6 (eth2,eth3)
+ #
+ echo "Rule 6 (eth2,eth3)"
+ #
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth2 -d 224.0.1.141 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth3 -d 224.0.1.141 -m state --state NEW -j ACCEPT
+ #
+ # Rule 7 (eth2,eth3)
+ #
+ echo "Rule 7 (eth2,eth3)"
+ #
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth2 -d 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth3 -d 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 8 (eth2,eth3)
+ #
+ echo "Rule 8 (eth2,eth3)"
+ #
+ $IPTABLES -A OUTPUT -m physdev --physdev-out eth2 -d 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -m physdev --physdev-out eth3 -d 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -m physdev --physdev-out eth2 -d 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -m physdev --physdev-out eth3 -d 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 9 (eth2,eth3)
+ #
+ echo "Rule 9 (eth2,eth3)"
+ #
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth2 -d ! 192.168.1.0/24 -j DROP
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth3 -d ! 192.168.1.0/24 -j DROP
+ #
+ # Rule 10 (eth2)
+ #
+ echo "Rule 10 (eth2)"
+ #
+ $IPTABLES -A OUTPUT -m physdev --physdev-out eth2 -d 224.0.0.0/4 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -m physdev --physdev-out eth2 -d 224.0.0.0/4 -m state --state NEW -j ACCEPT
+ #
+ # Rule 11 (eth2)
+ #
+ echo "Rule 11 (eth2)"
+ #
+ $IPTABLES -A FORWARD -m physdev --physdev-in eth2 -s 192.168.1.10 -d 224.0.0.0/4 -m state --state NEW -j ACCEPT
+ #
+ # Rule 12 (eth3)
+ #
+ echo "Rule 12 (eth3)"
+ #
+ $IPTABLES -A FORWARD -m physdev --physdev-out eth3 -s 192.168.1.10 -d 224.0.0.0/4 -m state --state NEW -j ACCEPT
+ #
+ # Rule 16 (global)
+ #
+ echo "Rule 16 (global)"
+ #
+ $IPTABLES -A OUTPUT -p udp -m udp -d 255.255.255.255 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p udp -m udp -d 255.255.255.255 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p udp -m udp -d 255.255.255.255 --dport 68 -m state --state NEW -j ACCEPT
+ #
+ # Rule 17 (global)
+ #
+ echo "Rule 17 (global)"
+ #
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.255 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.10 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p udp -m udp -d 192.168.1.255 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p udp -m udp -d 192.168.1.255 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p udp -m udp -d 192.168.1.10 --dport 68 -m state --state NEW -j ACCEPT
+ #
+ # Rule 18 (global)
+ #
+ echo "Rule 18 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 224.0.1.141 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -d 192.168.1.20 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 224.0.1.141 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 224.0.1.141 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 192.168.1.20 -m state --state NEW -j ACCEPT
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 224.0.0.5 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 224.0.0.5 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 224.0.0.5 -m state --state NEW -j ACCEPT
+ #
+ # Rule 20 (global)
+ #
+ echo "Rule 20 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.10 --dport 6667 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -d 192.168.1.10 --dport 6667 -m state --state NEW -j ACCEPT
+ #
+ # Rule 21 (global)
+ #
+ echo "Rule 21 (global)"
+ #
+ $IPTABLES -N RULE_21
+ $IPTABLES -A OUTPUT -d 192.168.1.10 -j RULE_21
+ $IPTABLES -A FORWARD -d 192.168.1.10 -j RULE_21
+ $IPTABLES -A RULE_21 -j LOG --log-level debug
+ $IPTABLES -A RULE_21 -j DROP
+ #
+ # Rule 22 (global)
+ #
+ echo "Rule 22 (global)"
+ #
+ # this rule should generate commands
+ # in both INPUT and FORWARD chains
+ # because this is a bridging firewall
+ # see bug #811860
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.1 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 23 (global)
+ #
+ echo "Rule 23 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -m state --state NEW -j ACCEPT
+ #
+ # Rule 24 (global)
+ #
+ echo "Rule 24 (global)"
+ #
+ # interface of another firewall
+ # (firewall11)
+ # Why do we need to test for this?
+ $IPTABLES -A OUTPUT -d 10.1.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 10.1.1.1 -m state --state NEW -j ACCEPT
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:14 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall23.fw.orig b/test/ipt/firewall23.fw.orig
new file mode 100755
index 000000000..71324e494
--- /dev/null
+++ b/test/ipt/firewall23.fw.orig
@@ -0,0 +1,536 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:09 2011 PST by vadim
+#
+# files: * firewall23.fw
+#
+# Compiled for iptables (any version)
+#
+# This is BRIDGING FIREWALL
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "br0 192.168.1.1/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ $IPTABLES -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
+
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth*)
+ #
+ echo "Rule 0 (eth*)"
+ #
+ $IPTABLES -A INPUT -i eth+ -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (eth*)
+ #
+ echo "Rule 1 (eth*)"
+ #
+ $IPTABLES -A INPUT -i eth+ -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i eth+ -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (eth*)
+ #
+ echo "Rule 2 (eth*)"
+ #
+ $IPTABLES -A FORWARD -i eth+ -d 192.168.1.255 -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (eth*)
+ #
+ echo "Rule 3 (eth*)"
+ #
+ $IPTABLES -A FORWARD -i eth+ -d 255.255.255.255 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (eth*)
+ #
+ echo "Rule 4 (eth*)"
+ #
+ $IPTABLES -A FORWARD -i eth+ -d 224.0.1.141 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (eth*)
+ #
+ echo "Rule 5 (eth*)"
+ #
+ $IPTABLES -A FORWARD -i eth+ -d 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 6 (eth*)
+ #
+ echo "Rule 6 (eth*)"
+ #
+ $IPTABLES -A FORWARD -i eth+ -d ! 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -A OUTPUT -p udp -m udp -d 255.255.255.255 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p udp -m udp -d 255.255.255.255 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p udp -m udp -d 255.255.255.255 --dport 68 -m state --state NEW -j ACCEPT
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.255 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.10 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p udp -m udp -d 192.168.1.255 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p udp -m udp -d 192.168.1.255 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p udp -m udp -d 192.168.1.10 --dport 68 -m state --state NEW -j ACCEPT
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 224.0.1.141 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -d 192.168.1.20 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 224.0.1.141 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 224.0.1.141 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 192.168.1.20 -m state --state NEW -j ACCEPT
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 224.0.0.5 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 224.0.0.5 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 224.0.0.5 -m state --state NEW -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.10 --dport 6667 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -d 192.168.1.10 --dport 6667 -m state --state NEW -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ $IPTABLES -N RULE_12
+ $IPTABLES -A OUTPUT -d 192.168.1.10 -j RULE_12
+ $IPTABLES -A FORWARD -d 192.168.1.10 -j RULE_12
+ $IPTABLES -A RULE_12 -j LOG --log-level debug
+ $IPTABLES -A RULE_12 -j DROP
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ # this rule should generate commands
+ # in both INPUT and FORWARD chains
+ # because this is a bridging firewall
+ # see bug #811860
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.1 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 14 (global)
+ #
+ echo "Rule 14 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -m state --state NEW -j ACCEPT
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ # interface of another firewall
+ # (firewall11)
+ # Why do we need to test for this?
+ $IPTABLES -A OUTPUT -d 10.1.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 10.1.1.1 -m state --state NEW -j ACCEPT
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:09 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall24.fw.orig b/test/ipt/firewall24.fw.orig
new file mode 100755
index 000000000..426924e95
--- /dev/null
+++ b/test/ipt/firewall24.fw.orig
@@ -0,0 +1,553 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:16 2011 PST by vadim
+#
+# files: * firewall24.fw
+#
+# Compiled for iptables (any version)
+#
+# testing rules on unnumbered interface tun*
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (tun*)
+ #
+ echo "Rule 0 (tun*)"
+ #
+ $IPTABLES -A INPUT -i tun+ -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (tun*)
+ #
+ echo "Rule 1 (tun*)"
+ #
+ $IPTABLES -A INPUT -i tun+ -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i tun+ -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (tun*)
+ #
+ echo "Rule 2 (tun*)"
+ #
+ $IPTABLES -A OUTPUT -o tun+ -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o tun+ -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (tun*)
+ #
+ echo "Rule 3 (tun*)"
+ #
+ $IPTABLES -A INPUT -i tun+ -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i tun+ -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o tun+ -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o tun+ -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (tun*)
+ #
+ echo "Rule 4 (tun*)"
+ #
+ $IPTABLES -A INPUT -i tun+ -p udp -m udp -m multiport --dports 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i tun+ -p udp -m udp -m multiport --dports 68,67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (tun*)
+ #
+ echo "Rule 5 (tun*)"
+ #
+ $IPTABLES -A INPUT -i tun+ -d 192.168.1.255 -m state --state NEW -j ACCEPT
+ #
+ # Rule 6 (tun*)
+ #
+ echo "Rule 6 (tun*)"
+ #
+ $IPTABLES -A INPUT -i tun+ -d 255.255.255.255 -m state --state NEW -j ACCEPT
+ #
+ # Rule 7 (tun*)
+ #
+ echo "Rule 7 (tun*)"
+ #
+ $IPTABLES -A INPUT -i tun+ -d 224.0.1.141 -m state --state NEW -j ACCEPT
+ #
+ # Rule 8 (tun*)
+ #
+ echo "Rule 8 (tun*)"
+ #
+ $IPTABLES -A INPUT -i tun+ -d 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i tun+ -d 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 9 (tun*)
+ #
+ echo "Rule 9 (tun*)"
+ #
+ $IPTABLES -A INPUT -i tun+ -d ! 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i tun+ -d ! 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ $IPTABLES -A OUTPUT -p udp -m udp -d 255.255.255.255 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p udp -m udp -d 255.255.255.255 --dport 68 -m state --state NEW -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.255 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.10 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p udp -m udp -d 192.168.1.255 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p udp -m udp -d 192.168.1.10 --dport 68 -m state --state NEW -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.0 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p udp -m udp -d 192.168.1.0 --dport 68 -m state --state NEW -j ACCEPT
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 224.0.1.141 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -d 192.168.1.20 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 224.0.1.141 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 192.168.1.20 -m state --state NEW -j ACCEPT
+ #
+ # Rule 14 (global)
+ #
+ echo "Rule 14 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 224.0.0.5 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 224.0.0.5 -m state --state NEW -j ACCEPT
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.10 --dport 6667 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -d 192.168.1.10 --dport 6667 -m state --state NEW -j ACCEPT
+ #
+ # Rule 16 (global)
+ #
+ echo "Rule 16 (global)"
+ #
+ $IPTABLES -N RULE_16
+ $IPTABLES -A OUTPUT -d 192.168.1.10 -j RULE_16
+ $IPTABLES -A FORWARD -d 192.168.1.10 -j RULE_16
+ $IPTABLES -A RULE_16 -j LOG --log-level debug
+ $IPTABLES -A RULE_16 -j DROP
+ #
+ # Rule 17 (global)
+ #
+ echo "Rule 17 (global)"
+ #
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 18 (global)
+ #
+ echo "Rule 18 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -m state --state NEW -j ACCEPT
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 192.168.1.1 -m state --state NEW -j ACCEPT
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:16 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall25.fw.orig b/test/ipt/firewall25.fw.orig
new file mode 100755
index 000000000..d64dca739
--- /dev/null
+++ b/test/ipt/firewall25.fw.orig
@@ -0,0 +1,747 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:21 2011 PST by vadim
+#
+# files: * firewall25.fw
+#
+# Compiled for iptables 1.4.0
+#
+# this firewall uses iptables-restore format. Firewall has wildcard interface ppp*; script is generated dynamically and then piped to iptables-restore
+
+# two rule sets for the filter table, to make sure there is only
+# one COMMIT for both
+
+# firewall25::: error: Dynamic interface ppp* should not have an IP address object attached to it. This IP address object will be ignored.
+
+# firewall25:policy_2_mangle:1: error: Action Reject is not allowed in mangle table
+
+# firewall25::: warning: Can not add virtual address for object address
+# firewall25::: warning: Can not add virtual address for object address
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IPTABLES_RESTORE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth2"
+ for i in eth0 eth2 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # backup ssh access
+ echo "-A INPUT -p tcp -m tcp -s 192.168.1.1/255.255.255.255 --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT "
+ echo "-A OUTPUT -p tcp -m tcp -d 192.168.1.1/255.255.255.255 --sport 22 -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # drop TCP sessions opened prior firewall restart
+ echo "-A INPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP "
+ echo "-A OUTPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP "
+ echo "-A FORWARD -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP "
+ # drop packets that do not match any valid state
+ echo "-A OUTPUT -m state --state INVALID -j DROP "
+ echo "-A INPUT -m state --state INVALID -j DROP "
+ echo "-A FORWARD -m state --state INVALID -j DROP "
+ # ================ Table 'filter', rule set policy_2
+ #
+ # Rule policy_2 0 (eth2)
+ echo ":policy_2 - [0:0]"
+ echo "-A policy_2 -o eth2 -m state --state NEW -j ACCEPT "
+ #
+ # Rule policy_2 1 (global)
+ echo ":policy_2_1 - [0:0]"
+ echo "-A policy_2 -j policy_2_1 "
+ echo "-A policy_2_1 -j LOG "
+ echo "-A policy_2_1 -j DROP "
+ #
+ # ================ Table 'filter', rule set mangle_ruleset
+ #
+ # Rule mangle_ruleset 0 (global)
+ echo ":mangle_ruleset - [0:0]"
+ echo ":mangle_ruleset_0 - [0:0]"
+ echo "-A mangle_ruleset -j mangle_ruleset_0 "
+ echo "-A mangle_ruleset_0 -j LOG "
+ echo "-A mangle_ruleset_0 -j DROP "
+ #
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (ppp*)
+ # ppp clients get addresses on 10.1.1.0
+ echo ":In_RULE_0 - [0:0]"
+ echo "-A INPUT -i ppp+ -s ! 10.1.1.0/24 -j In_RULE_0 "
+ echo "-A FORWARD -i ppp+ -s ! 10.1.1.0/24 -j In_RULE_0 "
+ echo "-A In_RULE_0 -j LOG "
+ echo "-A In_RULE_0 -j DROP "
+ #
+ # Rule 1 (ppp*)
+ # ppp clients can not connect to the firewall
+ echo ":In_RULE_1 - [0:0]"
+ getinterfaces ppp | while read I; do
+ ivar=$(getInterfaceVarName $I)
+ getaddr $I $ivar
+ cmd="$"${ivar}_list
+ eval "addr_list=$cmd"
+ for addr in $addr_list
+ do
+ test -n "$addr" && echo "-A INPUT -i ppp+ -d $addr -j In_RULE_1 "
+ done
+ done
+ echo "-A In_RULE_1 -j LOG "
+ echo "-A In_RULE_1 -j DROP "
+ #
+ # Rule 2 (ppp*)
+ echo ":In_RULE_2 - [0:0]"
+ echo "-A INPUT -i ppp+ -j In_RULE_2 "
+ echo "-A In_RULE_2 -j LOG "
+ echo "-A In_RULE_2 -j DROP "
+ #
+ # Rule 3 (ppp*)
+ # ppp clients can only connect to the mail
+ # server and web proxy on DMZ
+ echo "-A FORWARD -i ppp+ -p tcp -m tcp -m multiport -d 192.168.2.10 --dports 25,3128 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 4 (ppp*)
+ # ppp clients can not connect to
+ # anything else on DMZ and
+ # internal net
+ echo ":In_RULE_4 - [0:0]"
+ echo "-A INPUT -i ppp+ -d 192.168.1.0/24 -j In_RULE_4 "
+ echo "-A INPUT -i ppp+ -d 192.168.2.0/24 -j In_RULE_4 "
+ echo "-A FORWARD -i ppp+ -d 192.168.1.0/24 -j In_RULE_4 "
+ echo "-A FORWARD -i ppp+ -d 192.168.2.0/24 -j In_RULE_4 "
+ echo "-A In_RULE_4 -j LOG "
+ echo "-A In_RULE_4 -j DROP "
+ #
+ # Rule 5 (eth2)
+ echo ":In_RULE_5 - [0:0]"
+ echo "-A INPUT -i eth2 -s ! 192.168.2.0/24 -j In_RULE_5 "
+ echo "-A FORWARD -i eth2 -s ! 192.168.2.0/24 -j In_RULE_5 "
+ echo "-A In_RULE_5 -j LOG "
+ echo "-A In_RULE_5 -j DROP "
+ #
+ # Rule 6 (global)
+ # hostF has the same IP address as firewal.
+ echo ":RULE_6 - [0:0]"
+ echo "-A OUTPUT -p icmp -m icmp -d 192.168.1.1 --icmp-type 8/0 -m state --state NEW -j RULE_6 "
+ echo "-A INPUT -p icmp -m icmp -d 192.168.1.1 --icmp-type 8/0 -m state --state NEW -j RULE_6 "
+ echo "-A RULE_6 -j LOG "
+ echo "-A RULE_6 -j ACCEPT "
+ #
+ # Rule 7 (global)
+ echo ":Cid417C681B.0 - [0:0]"
+ echo "-A OUTPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid417C681B.0 "
+ getinterfaces ppp | while read I; do
+ ivar=$(getInterfaceVarName $I)
+ getaddr $I $ivar
+ cmd="$"${ivar}_list
+ eval "addr_list=$cmd"
+ for addr in $addr_list
+ do
+ test -n "$addr" && echo "-A Cid417C681B.0 -d $addr -j ACCEPT "
+ done
+ done
+ echo "-A Cid417C681B.0 -d 192.168.1.1 -j ACCEPT "
+ echo "-A Cid417C681B.0 -d 192.168.2.1 -j ACCEPT "
+ echo "-A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 8 (global)
+ getinterfaces ppp | while read I; do
+ ivar=$(getInterfaceVarName $I)
+ getaddr $I $ivar
+ cmd="$"${ivar}_list
+ eval "addr_list=$cmd"
+ for addr in $addr_list
+ do
+ test -n "$addr" && echo "-A OUTPUT -p tcp -m tcp -d $addr --dport 22 -m state --state NEW -j ACCEPT "
+ done
+ done
+ getinterfaces ppp | while read I; do
+ ivar=$(getInterfaceVarName $I)
+ getaddr $I $ivar
+ cmd="$"${ivar}_list
+ eval "addr_list=$cmd"
+ for addr in $addr_list
+ do
+ test -n "$addr" && echo "-A INPUT -p tcp -m tcp -d $addr --dport 22 -m state --state NEW -j ACCEPT "
+ done
+ done
+ #
+ # Rule 9 (global)
+ echo "-A OUTPUT -p tcp -m tcp -d 192.168.1.1 --dport 22 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -p tcp -m tcp -d 192.168.1.1 --dport 22 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 10 (global)
+ echo "-A OUTPUT -p tcp -m tcp -m multiport -d 192.168.1.1 --dports 22,23 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -p tcp -m tcp -m multiport -d 192.168.1.1 --dports 22,23 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 11 (global)
+ echo ":Cid417C6844.0 - [0:0]"
+ echo "-A OUTPUT -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid417C6844.0 "
+ echo "-A Cid417C6844.0 -d 192.168.1.1 -j ACCEPT "
+ echo "-A Cid417C6844.0 -d 192.168.2.1 -j ACCEPT "
+ echo ":Cid417C6844.1 - [0:0]"
+ echo "-A INPUT -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid417C6844.1 "
+ echo "-A Cid417C6844.1 -d 192.168.1.1 -j ACCEPT "
+ echo "-A Cid417C6844.1 -d 192.168.2.1 -j ACCEPT "
+ #
+ # Rule 12 (global)
+ echo ":Cid417C684F.0 - [0:0]"
+ echo "-A OUTPUT -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid417C684F.0 "
+ echo ":RULE_12 - [0:0]"
+ echo "-A Cid417C684F.0 -d 192.168.1.1 -j RULE_12 "
+ echo "-A Cid417C684F.0 -d 192.168.2.1 -j RULE_12 "
+ echo ":Cid417C684F.1 - [0:0]"
+ echo "-A INPUT -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid417C684F.1 "
+ echo "-A Cid417C684F.1 -d 192.168.1.1 -j RULE_12 "
+ echo "-A Cid417C684F.1 -d 192.168.2.1 -j RULE_12 "
+ echo "-A RULE_12 -j LOG "
+ echo "-A RULE_12 -j ACCEPT "
+ #
+ # Rule 13 (global)
+ # firewall is part of Any, so compiler should
+ # generate code in both FORWARD and
+ # OUTPUT chains
+ echo "-A OUTPUT -d 200.200.200.200 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 200.200.200.200 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 14 (global)
+ # firewall is part of Any, compiler should
+ # generate code for both FORWARD and
+ # INPUT chains
+ echo "-A INPUT -s 200.200.200.200 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -s 200.200.200.200 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 15 (global)
+ # because firewall has interface on network
+ # internal_net, compiler should generate code
+ # for both FORWARD and INPUT chains
+ echo "-A INPUT -s 192.168.1.10 -d 192.168.1.0/24 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -s 192.168.1.10 -d 192.168.1.0/24 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 16 (global)
+ echo ":Cid417C6878.0 - [0:0]"
+ echo "-A OUTPUT -d 200.200.200.200 -m state --state NEW -j Cid417C6878.0 "
+ echo "-A Cid417C6878.0 -s 192.168.1.0/24 -j ACCEPT "
+ echo "-A Cid417C6878.0 -s 192.168.2.0/24 -j ACCEPT "
+ echo ":Cid417C6878.1 - [0:0]"
+ echo "-A FORWARD -d 200.200.200.200 -m state --state NEW -j Cid417C6878.1 "
+ echo "-A Cid417C6878.1 -s 192.168.1.0/24 -j ACCEPT "
+ echo "-A Cid417C6878.1 -s 192.168.2.0/24 -j ACCEPT "
+ #
+ # Rule 18 (global)
+ echo "-A OUTPUT -j policy_2 "
+ echo "-A INPUT -j policy_2 "
+ echo "-A FORWARD -j policy_2 "
+ #
+ # Rule 20 (eth0)
+ echo "-A INPUT -i eth0 -j policy_2 "
+ echo "-A FORWARD -i eth0 -j policy_2 "
+ #
+ # Rule 22 (global)
+ # Automatically generated 'catch all' rule
+ echo ":RULE_22 - [0:0]"
+ echo "-A OUTPUT -j RULE_22 "
+ echo "-A INPUT -j RULE_22 "
+ echo "-A FORWARD -j RULE_22 "
+ echo "-A RULE_22 -j LOG "
+ echo "-A RULE_22 -j DROP "
+ #
+ echo COMMIT
+
+
+ echo '*mangle'
+ # ================ Table 'mangle', automatic rules
+ echo "-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu"
+ # ================ Table 'mangle', rule set policy_2
+ #
+ # Rule policy_2 0 (eth2)
+ echo ":policy_2 - [0:0]"
+ echo "-A policy_2 -o eth2 -m state --state NEW -j ACCEPT "
+ #
+ # Rule policy_2 1 (global)
+ echo ":policy_2_1 - [0:0]"
+ echo "-A policy_2 -j policy_2_1 "
+ echo "-A policy_2_1 -j LOG "
+ echo "-A policy_2_1 -j DROP "
+ #
+ # ================ Table 'mangle', rule set policy_2_mangle
+ #
+ # Rule policy_2_mangle 0 (eth2)
+ echo ":policy_2_mangle - [0:0]"
+ echo "-A policy_2_mangle -o eth2 -m state --state NEW -j ACCEPT "
+ #
+ # Rule policy_2_mangle 1 (global)
+ # SF bug report 3034628
+ # "iptables does not allow target REJECT in mangle table"
+ echo ":policy_2_mangle_1 - [0:0]"
+ echo "-A policy_2_mangle -p tcp -m tcp --dport 70 -j policy_2_mangle_1 "
+ echo "-A policy_2_mangle_1 -j LOG "
+ #
+ # Rule policy_2_mangle 2 (global)
+ echo ":policy_2_mangle_2 - [0:0]"
+ echo "-A policy_2_mangle -j policy_2_mangle_2 "
+ echo "-A policy_2_mangle_2 -j LOG "
+ echo "-A policy_2_mangle_2 -j DROP "
+ #
+ # ================ Table 'mangle', rule set Policy
+ #
+ # Rule 17 (global)
+ # this rule should go to mangle table,
+ # since we also have default rule that goes to mangle (TCPMSS)
+ # and pure mangle ruleset, making sure all rules for
+ # mangle table end up with one COMMIT
+ echo ":RULE_17 - [0:0]"
+ echo "-A OUTPUT -m state --state NEW -j RULE_17 "
+ echo "-A PREROUTING -m state --state NEW -j RULE_17 "
+ echo "-A RULE_17 -j LOG "
+ echo "-A RULE_17 -j MARK --set-mark 10"
+ #
+ # Rule 18 (global)
+ echo "-A PREROUTING -j policy_2 "
+ echo "-A POSTROUTING -j policy_2 "
+ echo "-A FORWARD -j policy_2 "
+ #
+ # Rule 19 (global)
+ echo "-A PREROUTING -j policy_2_mangle "
+ echo "-A POSTROUTING -j policy_2_mangle "
+ echo "-A FORWARD -j policy_2_mangle "
+ #
+ # Rule 20 (eth0)
+ echo "-A PREROUTING -i eth0 -j policy_2 "
+ echo "-A FORWARD -i eth0 -j policy_2 "
+ #
+ # Rule 21 (eth0)
+ echo "-A PREROUTING -i eth0 -j policy_2_mangle "
+ echo "-A FORWARD -i eth0 -j policy_2_mangle "
+ #
+ echo COMMIT
+
+
+ echo '*nat'
+ # ================ Table 'nat', rule set NAT
+ echo :PREROUTING ACCEPT [0:0]
+ echo :POSTROUTING ACCEPT [0:0]
+ echo :OUTPUT ACCEPT [0:0]
+ #
+ # Rule 0 (NAT)
+ echo "-A POSTROUTING -o ppp+ -s 192.168.1.0/24 -j MASQUERADE "
+ echo "-A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1 "
+ #
+ # Rule 1 (NAT)
+ echo "-A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.23 "
+ echo "-A POSTROUTING -o ppp+ -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.23 "
+ #
+ # Rule 2 (NAT)
+ getinterfaces ppp | while read I; do
+ ivar=$(getInterfaceVarName $I)
+ getaddr $I $ivar
+ cmd="$"${ivar}_list
+ eval "addr_list=$cmd"
+ for addr in $addr_list
+ do
+ test -n "$addr" && echo "-A PREROUTING -p tcp -m tcp -d $addr --dport 22 -j DNAT --to-destination 192.168.1.10:22 "
+ done
+ done
+ echo "-A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 22 -j DNAT --to-destination 192.168.1.10:22 "
+ echo "-A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 22 -j DNAT --to-destination 192.168.1.10:22 "
+ #
+ # Rule 3 (NAT)
+ echo "-A PREROUTING -s 192.168.1.0/24 -d ! 200.200.200.200 -j DNAT --to-destination 192.168.2.10 "
+ echo "-A POSTROUTING -o eth2 -s 192.168.1.0/24 -d 192.168.2.10 -j SNAT --to-source 192.168.2.1 "
+ #
+ echo COMMIT
+
+
+ ) | $IPTABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:21 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall26.fw.orig b/test/ipt/firewall26.fw.orig
new file mode 100755
index 000000000..75954ad24
--- /dev/null
+++ b/test/ipt/firewall26.fw.orig
@@ -0,0 +1,622 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:26 2011 PST by vadim
+#
+# files: * firewall26.fw
+#
+# Compiled for iptables 1.4.0
+#
+# this firewall uses iptables-restore format
+# One interface has dynamic address, script uses echo to generated iptables commands and then pipes them to iptables-restore
+
+# firewall26::: warning: Can not add virtual address for object address
+# firewall26::: warning: Can not add virtual address for object address
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IPTABLES_RESTORE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: ppp eth0 eth2"
+ for i in ppp eth0 eth2 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+ getaddr ppp i_ppp
+ getaddr6 ppp i_ppp_v6
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # backup ssh access
+ echo "-A INPUT -p tcp -m tcp -s 192.168.1.1/255.255.255.255 --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT "
+ echo "-A OUTPUT -p tcp -m tcp -d 192.168.1.1/255.255.255.255 --sport 22 -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # drop TCP sessions opened prior firewall restart
+ echo "-A INPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP "
+ echo "-A OUTPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP "
+ echo "-A FORWARD -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP "
+ # drop packets that do not match any valid state
+ echo "-A OUTPUT -m state --state INVALID -j DROP "
+ echo "-A INPUT -m state --state INVALID -j DROP "
+ echo "-A FORWARD -m state --state INVALID -j DROP "
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (ppp)
+ # ppp clients get addresses on 10.1.1.0
+ echo ":In_RULE_0 - [0:0]"
+ echo "-A INPUT -i ppp -s ! 10.1.1.0/24 -j In_RULE_0 "
+ echo "-A FORWARD -i ppp -s ! 10.1.1.0/24 -j In_RULE_0 "
+ echo "-A In_RULE_0 -j LOG "
+ echo "-A In_RULE_0 -j DROP "
+ #
+ # Rule 1 (ppp)
+ # ppp clients can not connect to the firewall
+ echo ":In_RULE_1 - [0:0]"
+ for i_ppp in $i_ppp_list
+ do
+ test -n "$i_ppp" && echo "-A INPUT -i ppp -d $i_ppp -j In_RULE_1 "
+ done
+ echo "-A In_RULE_1 -j LOG "
+ echo "-A In_RULE_1 -j DROP "
+ #
+ # Rule 2 (ppp)
+ echo ":In_RULE_2 - [0:0]"
+ echo "-A INPUT -i ppp -j In_RULE_2 "
+ echo "-A In_RULE_2 -j LOG "
+ echo "-A In_RULE_2 -j DROP "
+ #
+ # Rule 3 (ppp)
+ # ppp clients can only connect to the mail
+ # server and web proxy on DMZ
+ echo "-A FORWARD -i ppp -p tcp -m tcp -m multiport -d 192.168.2.10 --dports 25,3128 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 4 (ppp)
+ # ppp clients can not connect to
+ # anything else on DMZ and
+ # internal net
+ echo ":In_RULE_4 - [0:0]"
+ echo "-A INPUT -i ppp -d 192.168.1.0/24 -j In_RULE_4 "
+ echo "-A INPUT -i ppp -d 192.168.2.0/24 -j In_RULE_4 "
+ echo "-A FORWARD -i ppp -d 192.168.1.0/24 -j In_RULE_4 "
+ echo "-A FORWARD -i ppp -d 192.168.2.0/24 -j In_RULE_4 "
+ echo "-A In_RULE_4 -j LOG "
+ echo "-A In_RULE_4 -j DROP "
+ #
+ # Rule 5 (eth2)
+ echo ":In_RULE_5 - [0:0]"
+ echo "-A INPUT -i eth2 -s ! 192.168.2.0/24 -j In_RULE_5 "
+ echo "-A FORWARD -i eth2 -s ! 192.168.2.0/24 -j In_RULE_5 "
+ echo "-A In_RULE_5 -j LOG "
+ echo "-A In_RULE_5 -j DROP "
+ #
+ # Rule 6 (global)
+ # hostF has the same IP address as firewal.
+ echo ":RULE_6 - [0:0]"
+ echo "-A OUTPUT -p icmp -m icmp -d 192.168.1.1 --icmp-type 8/0 -m state --state NEW -j RULE_6 "
+ echo "-A INPUT -p icmp -m icmp -d 192.168.1.1 --icmp-type 8/0 -m state --state NEW -j RULE_6 "
+ echo "-A RULE_6 -j LOG "
+ echo "-A RULE_6 -j ACCEPT "
+ #
+ # Rule 7 (global)
+ echo ":Cid418C4619.0 - [0:0]"
+ echo "-A OUTPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid418C4619.0 "
+ for i_ppp in $i_ppp_list
+ do
+ test -n "$i_ppp" && echo "-A Cid418C4619.0 -d $i_ppp -j ACCEPT "
+ done
+ echo "-A Cid418C4619.0 -d 192.168.1.1 -j ACCEPT "
+ echo "-A Cid418C4619.0 -d 192.168.2.1 -j ACCEPT "
+ echo "-A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 8 (global)
+ for i_ppp in $i_ppp_list
+ do
+ test -n "$i_ppp" && echo "-A OUTPUT -p tcp -m tcp -d $i_ppp --dport 22 -m state --state NEW -j ACCEPT "
+ done
+ for i_ppp in $i_ppp_list
+ do
+ test -n "$i_ppp" && echo "-A INPUT -p tcp -m tcp -d $i_ppp --dport 22 -m state --state NEW -j ACCEPT "
+ done
+ #
+ # Rule 9 (global)
+ echo "-A OUTPUT -p tcp -m tcp -d 192.168.1.1 --dport 22 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -p tcp -m tcp -d 192.168.1.1 --dport 22 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 10 (global)
+ echo "-A OUTPUT -p tcp -m tcp -m multiport -d 192.168.1.1 --dports 22,23 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -p tcp -m tcp -m multiport -d 192.168.1.1 --dports 22,23 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 11 (global)
+ echo ":Cid418C4642.0 - [0:0]"
+ echo "-A OUTPUT -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid418C4642.0 "
+ echo "-A Cid418C4642.0 -d 192.168.1.1 -j ACCEPT "
+ echo "-A Cid418C4642.0 -d 192.168.2.1 -j ACCEPT "
+ echo ":Cid418C4642.1 - [0:0]"
+ echo "-A INPUT -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid418C4642.1 "
+ echo "-A Cid418C4642.1 -d 192.168.1.1 -j ACCEPT "
+ echo "-A Cid418C4642.1 -d 192.168.2.1 -j ACCEPT "
+ #
+ # Rule 12 (global)
+ echo ":Cid418C464D.0 - [0:0]"
+ echo "-A OUTPUT -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid418C464D.0 "
+ echo ":RULE_12 - [0:0]"
+ echo "-A Cid418C464D.0 -d 192.168.1.1 -j RULE_12 "
+ echo "-A Cid418C464D.0 -d 192.168.2.1 -j RULE_12 "
+ echo ":Cid418C464D.1 - [0:0]"
+ echo "-A INPUT -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid418C464D.1 "
+ echo "-A Cid418C464D.1 -d 192.168.1.1 -j RULE_12 "
+ echo "-A Cid418C464D.1 -d 192.168.2.1 -j RULE_12 "
+ echo "-A RULE_12 -j LOG "
+ echo "-A RULE_12 -j ACCEPT "
+ #
+ # Rule 13 (global)
+ # firewall is part of Any, so compiler should
+ # generate code in both FORWARD and
+ # OUTPUT chains
+ echo "-A OUTPUT -d 200.200.200.200 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 200.200.200.200 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 14 (global)
+ # firewall is part of Any, compiler should
+ # generate code for both FORWARD and
+ # INPUT chains
+ echo "-A INPUT -s 200.200.200.200 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -s 200.200.200.200 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 15 (global)
+ # because firewall has interface on network
+ # internal_net, compiler should generate code
+ # for both FORWARD and INPUT chains
+ echo "-A INPUT -s 192.168.1.10 -d 192.168.1.0/24 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -s 192.168.1.10 -d 192.168.1.0/24 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 16 (global)
+ echo ":Cid418C4676.0 - [0:0]"
+ echo "-A OUTPUT -d 200.200.200.200 -m state --state NEW -j Cid418C4676.0 "
+ echo "-A Cid418C4676.0 -s 192.168.1.0/24 -j ACCEPT "
+ echo "-A Cid418C4676.0 -s 192.168.2.0/24 -j ACCEPT "
+ echo ":Cid418C4676.1 - [0:0]"
+ echo "-A FORWARD -d 200.200.200.200 -m state --state NEW -j Cid418C4676.1 "
+ echo "-A Cid418C4676.1 -s 192.168.1.0/24 -j ACCEPT "
+ echo "-A Cid418C4676.1 -s 192.168.2.0/24 -j ACCEPT "
+ #
+ # Rule 17 (global)
+ # Automatically generated 'catch all' rule
+ echo ":RULE_17 - [0:0]"
+ echo "-A OUTPUT -j RULE_17 "
+ echo "-A INPUT -j RULE_17 "
+ echo "-A FORWARD -j RULE_17 "
+ echo "-A RULE_17 -j LOG "
+ echo "-A RULE_17 -j DROP "
+ #
+ echo COMMIT
+
+
+ echo '*mangle'
+ # ================ Table 'mangle', automatic rules
+ echo "-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu"
+
+ echo COMMIT
+
+
+ echo '*nat'
+ # ================ Table 'nat', rule set NAT
+ echo :PREROUTING ACCEPT [0:0]
+ echo :POSTROUTING ACCEPT [0:0]
+ echo :OUTPUT ACCEPT [0:0]
+ #
+ # Rule 0 (NAT)
+ echo "-A POSTROUTING -o ppp -s 192.168.1.0/24 -j MASQUERADE "
+ echo "-A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1 "
+ #
+ # Rule 1 (NAT)
+ echo "-A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.23 "
+ echo "-A POSTROUTING -o ppp -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.23 "
+ #
+ # Rule 2 (NAT)
+ for i_ppp in $i_ppp_list
+ do
+ test -n "$i_ppp" && echo "-A PREROUTING -p tcp -m tcp -d $i_ppp --dport 22 -j DNAT --to-destination 192.168.1.10:22 "
+ done
+ echo "-A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 22 -j DNAT --to-destination 192.168.1.10:22 "
+ echo "-A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 22 -j DNAT --to-destination 192.168.1.10:22 "
+ #
+ # Rule 3 (NAT)
+ echo "-A PREROUTING -s 192.168.1.0/24 -d ! 200.200.200.200 -j DNAT --to-destination 192.168.2.10 "
+ echo "-A POSTROUTING -o eth2 -s 192.168.1.0/24 -d 192.168.2.10 -j SNAT --to-source 192.168.2.1 "
+ #
+ echo COMMIT
+
+
+ ) | $IPTABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:26 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall27.fw.orig b/test/ipt/firewall27.fw.orig
new file mode 100755
index 000000000..c4d987a0d
--- /dev/null
+++ b/test/ipt/firewall27.fw.orig
@@ -0,0 +1,606 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:28 2011 PST by vadim
+#
+# files: * firewall27.fw
+#
+# Compiled for iptables 1.4.0
+#
+# this firewall uses iptables-restore format
+# all interfaces have static addresses, script pipes iptables commands straight to iptables-restore
+
+# firewall27::: warning: Can not add virtual address for object address
+# firewall27::: warning: Can not add virtual address for object address
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IPTABLES_RESTORE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: ppp eth0 eth2"
+ for i in ppp eth0 eth2 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "ppp 192.0.2.1/24" ""
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # backup ssh access
+ echo "-A INPUT -p tcp -m tcp -s 192.168.1.1/255.255.255.255 --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT "
+ echo "-A OUTPUT -p tcp -m tcp -d 192.168.1.1/255.255.255.255 --sport 22 -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # drop TCP sessions opened prior firewall restart
+ echo "-A INPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP "
+ echo "-A OUTPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP "
+ echo "-A FORWARD -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP "
+ # drop packets that do not match any valid state
+ echo "-A OUTPUT -m state --state INVALID -j DROP "
+ echo "-A INPUT -m state --state INVALID -j DROP "
+ echo "-A FORWARD -m state --state INVALID -j DROP "
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (ppp)
+ # ppp clients get addresses on 10.1.1.0
+ echo ":In_RULE_0 - [0:0]"
+ echo "-A INPUT -i ppp -s ! 10.1.1.0/24 -j In_RULE_0 "
+ echo "-A FORWARD -i ppp -s ! 10.1.1.0/24 -j In_RULE_0 "
+ echo "-A In_RULE_0 -j LOG "
+ echo "-A In_RULE_0 -j DROP "
+ #
+ # Rule 1 (ppp)
+ # ppp clients can not connect to the firewall
+ echo ":In_RULE_1 - [0:0]"
+ echo "-A INPUT -i ppp -d 192.0.2.1 -j In_RULE_1 "
+ echo "-A In_RULE_1 -j LOG "
+ echo "-A In_RULE_1 -j DROP "
+ #
+ # Rule 2 (ppp)
+ echo ":In_RULE_2 - [0:0]"
+ echo "-A INPUT -i ppp -j In_RULE_2 "
+ echo "-A In_RULE_2 -j LOG "
+ echo "-A In_RULE_2 -j DROP "
+ #
+ # Rule 3 (ppp)
+ # ppp clients can only connect to the mail
+ # server and web proxy on DMZ
+ echo "-A FORWARD -i ppp -p tcp -m tcp -m multiport -d 192.168.2.10 --dports 25,3128 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 4 (ppp)
+ # ppp clients can not connect to
+ # anything else on DMZ and
+ # internal net
+ echo ":In_RULE_4 - [0:0]"
+ echo "-A INPUT -i ppp -d 192.168.1.0/24 -j In_RULE_4 "
+ echo "-A INPUT -i ppp -d 192.168.2.0/24 -j In_RULE_4 "
+ echo "-A FORWARD -i ppp -d 192.168.1.0/24 -j In_RULE_4 "
+ echo "-A FORWARD -i ppp -d 192.168.2.0/24 -j In_RULE_4 "
+ echo "-A In_RULE_4 -j LOG "
+ echo "-A In_RULE_4 -j DROP "
+ #
+ # Rule 5 (eth2)
+ echo ":In_RULE_5 - [0:0]"
+ echo "-A INPUT -i eth2 -s ! 192.168.2.0/24 -j In_RULE_5 "
+ echo "-A FORWARD -i eth2 -s ! 192.168.2.0/24 -j In_RULE_5 "
+ echo "-A In_RULE_5 -j LOG "
+ echo "-A In_RULE_5 -j DROP "
+ #
+ # Rule 6 (global)
+ # hostF has the same IP address as firewal.
+ echo ":RULE_6 - [0:0]"
+ echo "-A OUTPUT -p icmp -m icmp -d 192.168.1.1 --icmp-type 8/0 -m state --state NEW -j RULE_6 "
+ echo "-A INPUT -p icmp -m icmp -d 192.168.1.1 --icmp-type 8/0 -m state --state NEW -j RULE_6 "
+ echo "-A RULE_6 -j LOG "
+ echo "-A RULE_6 -j ACCEPT "
+ #
+ # Rule 7 (global)
+ echo ":Cid4183D051.0 - [0:0]"
+ echo "-A OUTPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid4183D051.0 "
+ echo "-A Cid4183D051.0 -d 192.0.2.1 -j ACCEPT "
+ echo "-A Cid4183D051.0 -d 192.168.1.1 -j ACCEPT "
+ echo "-A Cid4183D051.0 -d 192.168.2.1 -j ACCEPT "
+ echo "-A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 8 (global)
+ echo "-A OUTPUT -p tcp -m tcp -d 192.0.2.1 --dport 22 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -p tcp -m tcp -d 192.0.2.1 --dport 22 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 9 (global)
+ echo "-A OUTPUT -p tcp -m tcp -d 192.168.1.1 --dport 22 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -p tcp -m tcp -d 192.168.1.1 --dport 22 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 10 (global)
+ echo "-A OUTPUT -p tcp -m tcp -m multiport -d 192.168.1.1 --dports 22,23 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -p tcp -m tcp -m multiport -d 192.168.1.1 --dports 22,23 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 11 (global)
+ echo ":Cid4183D07A.0 - [0:0]"
+ echo "-A OUTPUT -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid4183D07A.0 "
+ echo "-A Cid4183D07A.0 -d 192.168.1.1 -j ACCEPT "
+ echo "-A Cid4183D07A.0 -d 192.168.2.1 -j ACCEPT "
+ echo ":Cid4183D07A.1 - [0:0]"
+ echo "-A INPUT -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid4183D07A.1 "
+ echo "-A Cid4183D07A.1 -d 192.168.1.1 -j ACCEPT "
+ echo "-A Cid4183D07A.1 -d 192.168.2.1 -j ACCEPT "
+ #
+ # Rule 12 (global)
+ echo ":Cid4183D085.0 - [0:0]"
+ echo "-A OUTPUT -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid4183D085.0 "
+ echo ":RULE_12 - [0:0]"
+ echo "-A Cid4183D085.0 -d 192.168.1.1 -j RULE_12 "
+ echo "-A Cid4183D085.0 -d 192.168.2.1 -j RULE_12 "
+ echo ":Cid4183D085.1 - [0:0]"
+ echo "-A INPUT -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid4183D085.1 "
+ echo "-A Cid4183D085.1 -d 192.168.1.1 -j RULE_12 "
+ echo "-A Cid4183D085.1 -d 192.168.2.1 -j RULE_12 "
+ echo "-A RULE_12 -j LOG "
+ echo "-A RULE_12 -j ACCEPT "
+ #
+ # Rule 13 (global)
+ # firewall is part of Any, so compiler should
+ # generate code in both FORWARD and
+ # OUTPUT chains
+ echo "-A OUTPUT -d 200.200.200.200 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 200.200.200.200 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 14 (global)
+ # firewall is part of Any, compiler should
+ # generate code for both FORWARD and
+ # INPUT chains
+ echo "-A INPUT -s 200.200.200.200 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -s 200.200.200.200 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 15 (global)
+ # because firewall has interface on network
+ # internal_net, compiler should generate code
+ # for both FORWARD and INPUT chains
+ echo "-A INPUT -s 192.168.1.10 -d 192.168.1.0/24 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -s 192.168.1.10 -d 192.168.1.0/24 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 16 (global)
+ echo ":Cid4183D0AE.0 - [0:0]"
+ echo "-A OUTPUT -d 200.200.200.200 -m state --state NEW -j Cid4183D0AE.0 "
+ echo "-A Cid4183D0AE.0 -s 192.168.1.0/24 -j ACCEPT "
+ echo "-A Cid4183D0AE.0 -s 192.168.2.0/24 -j ACCEPT "
+ echo ":Cid4183D0AE.1 - [0:0]"
+ echo "-A FORWARD -d 200.200.200.200 -m state --state NEW -j Cid4183D0AE.1 "
+ echo "-A Cid4183D0AE.1 -s 192.168.1.0/24 -j ACCEPT "
+ echo "-A Cid4183D0AE.1 -s 192.168.2.0/24 -j ACCEPT "
+ #
+ # Rule 17 (global)
+ # Automatically generated 'catch all' rule
+ echo ":RULE_17 - [0:0]"
+ echo "-A OUTPUT -j RULE_17 "
+ echo "-A INPUT -j RULE_17 "
+ echo "-A FORWARD -j RULE_17 "
+ echo "-A RULE_17 -j LOG "
+ echo "-A RULE_17 -j DROP "
+ #
+ echo COMMIT
+
+
+ echo '*mangle'
+ # ================ Table 'mangle', automatic rules
+ echo "-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu"
+
+ echo COMMIT
+
+
+ echo '*nat'
+ # ================ Table 'nat', rule set NAT
+ echo :PREROUTING ACCEPT [0:0]
+ echo :POSTROUTING ACCEPT [0:0]
+ echo :OUTPUT ACCEPT [0:0]
+ #
+ # Rule 0 (NAT)
+ echo "-A POSTROUTING -o ppp -s 192.168.1.0/24 -j SNAT --to-source 192.0.2.1 "
+ echo "-A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1 "
+ #
+ # Rule 1 (NAT)
+ echo "-A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.23 "
+ echo "-A POSTROUTING -o ppp -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.23 "
+ #
+ # Rule 2 (NAT)
+ echo "-A PREROUTING -p tcp -m tcp -d 192.0.2.1 --dport 22 -j DNAT --to-destination 192.168.1.10:22 "
+ echo "-A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 22 -j DNAT --to-destination 192.168.1.10:22 "
+ echo "-A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 22 -j DNAT --to-destination 192.168.1.10:22 "
+ #
+ # Rule 3 (NAT)
+ echo "-A PREROUTING -s 192.168.1.0/24 -d ! 200.200.200.200 -j DNAT --to-destination 192.168.2.10 "
+ echo "-A POSTROUTING -o eth2 -s 192.168.1.0/24 -d 192.168.2.10 -j SNAT --to-source 192.168.2.1 "
+ #
+ echo COMMIT
+
+
+ ) | $IPTABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:28 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall28.fw.orig b/test/ipt/firewall28.fw.orig
new file mode 100755
index 000000000..d7ebae782
--- /dev/null
+++ b/test/ipt/firewall28.fw.orig
@@ -0,0 +1,467 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:30 2011 PST by vadim
+#
+# files: * firewall28.fw
+#
+# Compiled for iptables (any version)
+#
+
+# firewall28:Policy:0: error: Rule '0 (global)' shadows rule '1 (global)' below it
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.0/24" ""
+ update_addresses_of_interface "eth1 22.22.23.22/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.22
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ # this rule should shadow rule #1 because
+ # it uses IPService object with protocol 0
+ $IPTABLES -A OUTPUT -p all -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p all -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p all -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -N RULE_1
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 6667 -j RULE_1
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 6667 -j RULE_1
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 --dport 6667 -j RULE_1
+ $IPTABLES -A RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A RULE_1 -j DROP
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -N RULE_3
+ $IPTABLES -A OUTPUT -j RULE_3
+ $IPTABLES -A INPUT -j RULE_3
+ $IPTABLES -A FORWARD -j RULE_3
+ $IPTABLES -A RULE_3 -j LOG --log-level info --log-prefix "RULE 3 -- DENY "
+ $IPTABLES -A RULE_3 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:30 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall29.fw.orig b/test/ipt/firewall29.fw.orig
new file mode 100755
index 000000000..ee5e5e314
--- /dev/null
+++ b/test/ipt/firewall29.fw.orig
@@ -0,0 +1,500 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:32 2011 PST by vadim
+#
+# files: * firewall29.fw
+#
+# Compiled for iptables (any version)
+#
+# two dynamic interfaces in the same policy or NAT rule. Interfaces have a dot in their names
+
+# firewall29:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall29:Policy:: warning: Log prefix has been truncated to 29 characters
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth1 192.168.1.100/24" ""
+ getaddr eth0.200 i_eth0_200
+ getaddr6 eth0.200 i_eth0_200_v6
+ getaddr eth0.100 i_eth0_100
+ getaddr6 eth0.100 i_eth0_100_v6
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ for i_eth0_200 in $i_eth0_200_list
+ do
+ test -n "$i_eth0_200" && $IPTABLES -t nat -A PREROUTING -d $i_eth0_200 -j DNAT --to-destination 192.168.1.10
+ done
+ for i_eth0_100 in $i_eth0_100_list
+ do
+ test -n "$i_eth0_100" && $IPTABLES -t nat -A PREROUTING -d $i_eth0_100 -j DNAT --to-destination 192.168.1.10
+ done
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth0.200)
+ #
+ echo "Rule 0 (eth0.200)"
+ #
+ for i_eth0_200 in $i_eth0_200_list
+ do
+ test -n "$i_eth0_200" && $IPTABLES -A OUTPUT -o eth0.200 -s $i_eth0_200 -m state --state NEW -j ACCEPT
+ done
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ for i_eth0_200 in $i_eth0_200_list
+ do
+ test -n "$i_eth0_200" && $IPTABLES -A INPUT -s $i_eth0_200 -m state --state NEW -j ACCEPT
+ done
+ for i_eth0_100 in $i_eth0_100_list
+ do
+ test -n "$i_eth0_100" && $IPTABLES -A INPUT -s $i_eth0_100 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ for i_eth0_200 in $i_eth0_200_list
+ do
+ test -n "$i_eth0_200" && $IPTABLES -A OUTPUT -s $i_eth0_200 -m state --state NEW -j ACCEPT
+ done
+ for i_eth0_100 in $i_eth0_100_list
+ do
+ test -n "$i_eth0_100" && $IPTABLES -A OUTPUT -s $i_eth0_100 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -A OUTPUT -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ for i_eth0_200 in $i_eth0_200_list
+ do
+ test -n "$i_eth0_200" && $IPTABLES -A OUTPUT -p udp -m udp -m multiport -d $i_eth0_200 --dports 68,67 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A INPUT -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ for i_eth0_200 in $i_eth0_200_list
+ do
+ test -n "$i_eth0_200" && $IPTABLES -A INPUT -p udp -m udp -m multiport -d $i_eth0_200 --dports 68,67 -m state --state NEW -j ACCEPT
+ done
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ # should be --connlimit-above 10
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -m connlimit --connlimit-above 10 -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ # should be ! --connlimit-above 10
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -m connlimit \! --connlimit-above 10 -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -N RULE_5
+ $IPTABLES -A OUTPUT -j RULE_5
+ $IPTABLES -A INPUT -j RULE_5
+ $IPTABLES -A FORWARD -j RULE_5
+ $IPTABLES -A RULE_5 -j LOG --log-level debug --log-prefix "RULE 5 -- DENY on interface g"
+ $IPTABLES -A RULE_5 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:32 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall3.fw.orig b/test/ipt/firewall3.fw.orig
new file mode 100755
index 000000000..76cad900e
--- /dev/null
+++ b/test/ipt/firewall3.fw.orig
@@ -0,0 +1,638 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:34 2011 PST by vadim
+#
+# files: * firewall3.fw
+#
+# Compiled for iptables (any version)
+#
+# this object is used to test negation in policy rules with "Assume firewall is part of 'Any'" turned OFF
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 22.22.22.23
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (lo)
+ #
+ echo "Rule 0 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (eth1)
+ #
+ echo "Rule 1 (eth1)"
+ #
+ $IPTABLES -N In_RULE_1
+ $IPTABLES -A FORWARD -i eth1 -p all -f -j In_RULE_1
+ $IPTABLES -A In_RULE_1 -j LOG --log-level debug
+ $IPTABLES -A In_RULE_1 -j DROP
+ #
+ # Rule 2 (eth0)
+ #
+ echo "Rule 2 (eth0)"
+ #
+ $IPTABLES -N In_RULE_2
+ $IPTABLES -A FORWARD -i eth0 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_2
+ $IPTABLES -A In_RULE_2 -j LOG --log-level debug
+ $IPTABLES -A In_RULE_2 -j DROP
+ #
+ # Rule 3 (eth0,eth2)
+ #
+ echo "Rule 3 (eth0,eth2)"
+ #
+ $IPTABLES -N In_RULE_3
+ $IPTABLES -A FORWARD -i eth0 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_3
+ $IPTABLES -A FORWARD -i eth2 -p udp -m udp -m multiport -s 192.168.1.0/24 --dports 68,67 -j In_RULE_3
+ $IPTABLES -A In_RULE_3 -j LOG --log-level debug
+ $IPTABLES -A In_RULE_3 -j DROP
+ #
+ # Rule 4 (eth0)
+ #
+ echo "Rule 4 (eth0)"
+ #
+ # testing choice of chains in case when several interfaces
+ # are used and rule matches on any or broadcast
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (eth0,eth2)
+ #
+ echo "Rule 5 (eth0,eth2)"
+ #
+ # testing choice of chains in case when several interfaces
+ # are used and rule matches on any or broadcast
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth2 -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 6 (eth0)
+ #
+ echo "Rule 6 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -m multiport -s 0.0.0.0 -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 7 (eth0,eth2)
+ #
+ echo "Rule 7 (eth0,eth2)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -m multiport -s 0.0.0.0 -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth2 -p udp -m udp -m multiport -s 0.0.0.0 -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 10 (eth1)
+ #
+ echo "Rule 10 (eth1)"
+ #
+ # Anti-spoofing rule
+ $IPTABLES -N In_RULE_10
+ $IPTABLES -A FORWARD -i eth1 -s 22.22.22.22 -j In_RULE_10
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.1.1 -j In_RULE_10
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.2.1 -j In_RULE_10
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.1.0/24 -j In_RULE_10
+ $IPTABLES -A In_RULE_10 -j LOG --log-level debug
+ $IPTABLES -A In_RULE_10 -j DROP
+ #
+ # Rule 11 (eth1)
+ #
+ echo "Rule 11 (eth1)"
+ #
+ # Anti-spoofing rule
+ $IPTABLES -N Cid3B02271D.0
+ $IPTABLES -A OUTPUT -o eth1 -j Cid3B02271D.0
+ $IPTABLES -A Cid3B02271D.0 -s 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid3B02271D.0 -s 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid3B02271D.0 -s 192.168.2.1 -j RETURN
+ $IPTABLES -N Out_RULE_11_3
+ $IPTABLES -A Cid3B02271D.0 -j Out_RULE_11_3
+ $IPTABLES -A Out_RULE_11_3 -j LOG --log-level debug
+ $IPTABLES -A Out_RULE_11_3 -j DROP
+ $IPTABLES -N Cid3B02271D.1
+ $IPTABLES -A FORWARD -o eth1 -j Cid3B02271D.1
+ $IPTABLES -A Cid3B02271D.1 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid3B02271D.1 -j Out_RULE_11_3
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ # hostF has the same IP address as firewal.
+ $IPTABLES -N RULE_12
+ $IPTABLES -A INPUT -p icmp -m icmp -d 192.168.1.1 --icmp-type 8/0 -m state --state NEW -j RULE_12
+ $IPTABLES -A RULE_12 -j LOG --log-level debug
+ $IPTABLES -A RULE_12 -j ACCEPT
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 14 (global)
+ #
+ echo "Rule 14 (global)"
+ #
+ # testing negation in the policy rule
+ $IPTABLES -N Cid3B0226DF.0
+ $IPTABLES -A FORWARD -p icmp -m icmp --icmp-type 3 -j Cid3B0226DF.0
+ $IPTABLES -A Cid3B0226DF.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -A Cid3B0226DF.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -N RULE_14_3
+ $IPTABLES -A Cid3B0226DF.0 -j RULE_14_3
+ $IPTABLES -A RULE_14_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_14_3 -j DROP
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ $IPTABLES -A FORWARD -d ! 33.33.33.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 16 (global)
+ #
+ echo "Rule 16 (global)"
+ #
+ $IPTABLES -N Cid40F57E72.0
+ $IPTABLES -A FORWARD -m state --state NEW -j Cid40F57E72.0
+ $IPTABLES -A Cid40F57E72.0 -d 33.33.33.0/24 -j RETURN
+ $IPTABLES -A Cid40F57E72.0 -d 222.222.222.0/24 -j RETURN
+ $IPTABLES -A Cid40F57E72.0 -j ACCEPT
+ #
+ # Rule 17 (global)
+ #
+ echo "Rule 17 (global)"
+ #
+ $IPTABLES -N Cid41A8EF1D.0
+ $IPTABLES -A INPUT -m state --state NEW -j Cid41A8EF1D.0
+ $IPTABLES -A Cid41A8EF1D.0 -d 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid41A8EF1D.0 -d 192.168.2.1 -j RETURN
+ $IPTABLES -A Cid41A8EF1D.0 -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state NEW -j ACCEPT
+ #
+ # Rule 18 (global)
+ #
+ echo "Rule 18 (global)"
+ #
+ # testing negation in service field
+ $IPTABLES -N Cid3B0226EA.0
+ $IPTABLES -A FORWARD -d 192.168.1.10 -j Cid3B0226EA.0
+ $IPTABLES -A FORWARD -d 192.168.1.20 -j Cid3B0226EA.0
+ $IPTABLES -A Cid3B0226EA.0 -p tcp -m tcp -m multiport --dports 25,22 -j RETURN
+ $IPTABLES -N RULE_18_3
+ $IPTABLES -A Cid3B0226EA.0 -j RULE_18_3
+ $IPTABLES -A RULE_18_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_18_3 -j DROP
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ # 'masquerading' rule
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 20 (global)
+ #
+ echo "Rule 20 (global)"
+ #
+ # 'catch all' rule
+ $IPTABLES -N RULE_20
+ $IPTABLES -A FORWARD -j RULE_20
+ $IPTABLES -A RULE_20 -j LOG --log-level debug
+ $IPTABLES -A RULE_20 -j DROP
+ #
+ # Rule 21 (global)
+ #
+ echo "Rule 21 (global)"
+ #
+ $IPTABLES -N Cid440D600617760.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 22 -m state --state NEW -j Cid440D600617760.0
+ $IPTABLES -A Cid440D600617760.0 -s 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid440D600617760.0 -s 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid440D600617760.0 -s 192.168.2.1 -j RETURN
+ $IPTABLES -A Cid440D600617760.0 -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -d 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 22 (global)
+ #
+ echo "Rule 22 (global)"
+ #
+ $IPTABLES -N Cid440D880417760.0
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j Cid440D880417760.0
+ $IPTABLES -A Cid440D880417760.0 -d 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid440D880417760.0 -d 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid440D880417760.0 -d 192.168.2.1 -j RETURN
+ $IPTABLES -A Cid440D880417760.0 -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 23 (eth1,eth0,eth2)
+ #
+ echo "Rule 23 (eth1,eth0,eth2)"
+ #
+ # this rule should go only to the FORWARD
+ # chain but should have "-i eth" clause
+ $IPTABLES -A FORWARD -i eth1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i eth0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i eth2 -m state --state NEW -j ACCEPT
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:34 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall30.fw.orig b/test/ipt/firewall30.fw.orig
new file mode 100755
index 000000000..dba413edd
--- /dev/null
+++ b/test/ipt/firewall30.fw.orig
@@ -0,0 +1,435 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:36 2011 PST by vadim
+#
+# files: * firewall30.fw
+#
+# Compiled for iptables (any version)
+#
+# testing shading of rules using MAC addresses
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -A INPUT -m mac --mac-source 00:10:4b:de:e9:6f -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -m mac --mac-source 00:10:4b:de:e9:6f -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -A INPUT -m mac --mac-source 00:10:4b:de:e9:70 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -m mac --mac-source 00:10:4b:de:e9:70 -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -N RULE_2
+ $IPTABLES -A OUTPUT -j RULE_2
+ $IPTABLES -A INPUT -j RULE_2
+ $IPTABLES -A FORWARD -j RULE_2
+ $IPTABLES -A RULE_2 -j LOG --log-level debug --log-prefix "RULE 2 -- DENY global"
+ $IPTABLES -A RULE_2 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:36 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall31.fw.orig b/test/ipt/firewall31.fw.orig
new file mode 100755
index 000000000..f7d4cf60c
--- /dev/null
+++ b/test/ipt/firewall31.fw.orig
@@ -0,0 +1,505 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:39 2011 PST by vadim
+#
+# files: * firewall31.fw
+#
+# Compiled for iptables (any version)
+#
+# used to test time matching rules
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 33.33.33.33/24" ""
+ update_addresses_of_interface "eth1 192.168.1.1/24" ""
+ getaddr ppp0 i_ppp0
+ getaddr6 ppp0 i_ppp0_v6
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -N RULE_0
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m time --timestart 00:00 --timestop 23:59 --days Sat -j RULE_0
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m time --timestart 00:00 --timestop 23:59 --days Sat -j RULE_0
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m time --timestart 00:00 --timestop 23:59 --days Sat -j RULE_0
+ $IPTABLES -A RULE_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A RULE_0 -j DROP
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -N RULE_1
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -m time --timestart 18:00 --timestop 23:59 -j RULE_1
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -m time --timestart 18:00 --timestop 23:59 -j RULE_1
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -m time --timestart 18:00 --timestop 23:59 -j RULE_1
+ $IPTABLES -A RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- ACCEPT "
+ $IPTABLES -A RULE_1 -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -m time --timestart 00:00 --timestop 23:59 --days Sat,Sun -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -m time --timestart 00:00 --timestop 23:59 --days Sat,Sun -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -m time --timestart 00:00 --timestop 23:59 --days Sat,Sun -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -N RULE_3
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -m time --timestart 09:00 --timestop 17:00 --days Mon,Tue,Wed,Thu,Fri -j RULE_3
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -m time --timestart 09:00 --timestop 17:00 --days Mon,Tue,Wed,Thu,Fri -j RULE_3
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -m time --timestart 09:00 --timestop 17:00 --days Mon,Tue,Wed,Thu,Fri -j RULE_3
+ $IPTABLES -A RULE_3 -j LOG --log-level info --log-prefix "RULE 3 -- ACCEPT "
+ $IPTABLES -A RULE_3 -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -N Cid4299E23B.0
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j Cid4299E23B.0
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j Cid4299E23B.0
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j Cid4299E23B.0
+ $IPTABLES -A Cid4299E23B.0 -m time --timestart 00:00 --timestop 23:59 --days Sat,Sun -j RETURN
+ $IPTABLES -N RULE_4_3
+ $IPTABLES -A Cid4299E23B.0 -j RULE_4_3
+ $IPTABLES -A RULE_4_3 -j LOG --log-level info --log-prefix "RULE 4 -- ACCEPT "
+ $IPTABLES -A RULE_4_3 -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -N Cid4299E247.0
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j Cid4299E247.0
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j Cid4299E247.0
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j Cid4299E247.0
+ $IPTABLES -A Cid4299E247.0 -m time --timestart 00:00 --timestop 23:59 --days Sat -j RETURN
+ $IPTABLES -A Cid4299E247.0 -m time --timestart 00:00 --timestop 23:59 --days Sun -j RETURN
+ $IPTABLES -N RULE_5_3
+ $IPTABLES -A Cid4299E247.0 -j RULE_5_3
+ $IPTABLES -A RULE_5_3 -j LOG --log-level info --log-prefix "RULE 5 -- ACCEPT "
+ $IPTABLES -A RULE_5_3 -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -N RULE_6
+ $IPTABLES -A OUTPUT -j RULE_6
+ $IPTABLES -A INPUT -j RULE_6
+ $IPTABLES -A FORWARD -j RULE_6
+ $IPTABLES -A RULE_6 -j LOG --log-level info --log-prefix "RULE 6 -- DENY "
+ $IPTABLES -A RULE_6 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:39 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall32.fw.orig b/test/ipt/firewall32.fw.orig
new file mode 100755
index 000000000..c3cfa35de
--- /dev/null
+++ b/test/ipt/firewall32.fw.orig
@@ -0,0 +1,476 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:41 2011 PST by vadim
+#
+# files: * firewall32.fw
+#
+# Compiled for iptables (any version)
+#
+# testing AddressTable
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth1 192.168.1.100/24" ""
+ getaddr eth0.100 i_eth0_100
+ getaddr6 eth0.100 i_eth0_100_v6
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ for i_eth0_100 in $i_eth0_100_list
+ do
+ test -n "$i_eth0_100" && $IPTABLES -t nat -A PREROUTING -d $i_eth0_100 -j DNAT --to-destination 192.168.1.10
+ done
+
+
+
+ # ================ Table 'filter', rule set Policy_fw32
+ #
+ # Rule Policy_fw32 0 (eth0.100)
+ #
+ echo "Rule Policy_fw32 0 (eth0.100)"
+ #
+ for i_eth0_100 in $i_eth0_100_list
+ do
+ test -n "$i_eth0_100" && $IPTABLES -A INPUT -i eth0.100 -s $i_eth0_100 -j DROP
+ done
+ $IPTABLES -A INPUT -i eth0.100 -s 192.168.1.0/24 -j DROP
+ for i_eth0_100 in $i_eth0_100_list
+ do
+ test -n "$i_eth0_100" && $IPTABLES -A FORWARD -i eth0.100 -s $i_eth0_100 -j DROP
+ done
+ $IPTABLES -A FORWARD -i eth0.100 -s 192.168.1.0/24 -j DROP
+ #
+ # Rule Policy_fw32 1 (global)
+ #
+ echo "Rule Policy_fw32 1 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -s 192.168.1.2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -s 192.168.1.3/30 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -s 192.168.1.200 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -s 192.168.1.201 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -s 192.168.2.128/25 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.3/30 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.200 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.201 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.2.128/25 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.3/30 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.200 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.201 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.2.128/25 -m state --state NEW -j ACCEPT
+ #
+ # Rule Policy_fw32 2 (global)
+ #
+ echo "Rule Policy_fw32 2 (global)"
+ #
+ $IPTABLES -A OUTPUT -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p udp -m udp -m multiport -d 255.255.255.255 --dports 68,67 -m state --state NEW -j ACCEPT
+ #
+ # Rule Policy_fw32 3 (global)
+ #
+ echo "Rule Policy_fw32 3 (global)"
+ #
+ $IPTABLES -N Policy_fw32_3
+ $IPTABLES -A OUTPUT -j Policy_fw32_3
+ $IPTABLES -A INPUT -j Policy_fw32_3
+ $IPTABLES -A FORWARD -j Policy_fw32_3
+ $IPTABLES -A Policy_fw32_3 -j LOG --log-level debug --log-prefix "RULE 3 -- DENY on global "
+ $IPTABLES -A Policy_fw32_3 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:41 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall33-1.fw.orig b/test/ipt/firewall33-1.fw.orig
new file mode 100755
index 000000000..b0317817f
--- /dev/null
+++ b/test/ipt/firewall33-1.fw.orig
@@ -0,0 +1,581 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:49 2011 PST by vadim
+#
+# files: * firewall33-1.fw
+#
+# Compiled for iptables (any version)
+#
+
+# firewall33-1:Policy:2: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+# firewall33-1:Policy:6: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+# firewall33-1:Policy:12: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall33-1:Policy:2: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+# firewall33-1:Policy:6: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+# firewall33-1:Policy:12: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.0.2.1/24" ""
+ update_addresses_of_interface "eth1 192.168.1.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -N Policy
+ $IPTABLES -A Policy -s 157.166.224.25 -m state --state NEW -j ACCEPT
+ $IPTABLES -A Policy -s 157.166.224.26 -m state --state NEW -j ACCEPT
+ $IPTABLES -A Policy -s 157.166.226.25 -m state --state NEW -j ACCEPT
+ $IPTABLES -A Policy -s 157.166.226.26 -m state --state NEW -j ACCEPT
+ $IPTABLES -A Policy -s 157.166.255.18 -m state --state NEW -j ACCEPT
+ $IPTABLES -A Policy -s 157.166.255.19 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -A Policy -s www.cnn.com -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ # firewall33-1:Policy:2: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+ $IPTABLES -A Policy -s 192.0.2.1 -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -A Policy -s buildmaster -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -N Cid4386E38318346.0
+ $IPTABLES -A Policy -j Cid4386E38318346.0
+ $IPTABLES -A Cid4386E38318346.0 -d 157.166.224.25 -j RETURN
+ $IPTABLES -A Cid4386E38318346.0 -d 157.166.224.26 -j RETURN
+ $IPTABLES -A Cid4386E38318346.0 -d 157.166.226.25 -j RETURN
+ $IPTABLES -A Cid4386E38318346.0 -d 157.166.226.26 -j RETURN
+ $IPTABLES -A Cid4386E38318346.0 -d 157.166.255.18 -j RETURN
+ $IPTABLES -A Cid4386E38318346.0 -d 157.166.255.19 -j RETURN
+ $IPTABLES -A Cid4386E38318346.0 -j DROP
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -N Cid4386E37718346.0
+ $IPTABLES -A Policy -j Cid4386E37718346.0
+ $IPTABLES -A Cid4386E37718346.0 -d www.cnn.com -j RETURN
+ $IPTABLES -A Cid4386E37718346.0 -j DROP
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -N Cid43867C3018346.0
+ $IPTABLES -A Policy -m state --state NEW -j Cid43867C3018346.0
+ # firewall33-1:Policy:6: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+ $IPTABLES -A Cid43867C3018346.0 -d 192.0.2.1 -j RETURN
+ $IPTABLES -A Cid43867C3018346.0 -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -N Cid4386C10D18346.0
+ $IPTABLES -A Policy -m state --state NEW -j Cid4386C10D18346.0
+ $IPTABLES -A Cid4386C10D18346.0 -d buildmaster -j RETURN
+ $IPTABLES -A Cid4386C10D18346.0 -j ACCEPT
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -N Cid438728A918346.0
+ $IPTABLES -A Policy -m state --state NEW -j Cid438728A918346.0
+ $IPTABLES -A Cid438728A918346.0 -d 74.125.19.99 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -d 74.125.19.103 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -d 74.125.19.104 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -d 74.125.19.147 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -d 157.166.224.25 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -d 157.166.224.26 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -d 157.166.226.25 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -d 157.166.226.26 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -d 157.166.255.18 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -d 157.166.255.19 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -j ACCEPT
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -N Cid438728BA18346.0
+ $IPTABLES -A Policy -m state --state NEW -j Cid438728BA18346.0
+ $IPTABLES -A Cid438728BA18346.0 -d www.cnn.com -j RETURN
+ $IPTABLES -A Cid438728BA18346.0 -d www.google.com -j RETURN
+ $IPTABLES -A Cid438728BA18346.0 -j ACCEPT
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ $IPTABLES -N Cid438728CD18346.0
+ $IPTABLES -A Policy -m state --state NEW -j Cid438728CD18346.0
+ $IPTABLES -A Cid438728CD18346.0 -d www.google.com -j RETURN
+ $IPTABLES -A Cid438728CD18346.0 -d 157.166.224.25 -j RETURN
+ $IPTABLES -A Cid438728CD18346.0 -d 157.166.224.26 -j RETURN
+ $IPTABLES -A Cid438728CD18346.0 -d 157.166.226.25 -j RETURN
+ $IPTABLES -A Cid438728CD18346.0 -d 157.166.226.26 -j RETURN
+ $IPTABLES -A Cid438728CD18346.0 -d 157.166.255.18 -j RETURN
+ $IPTABLES -A Cid438728CD18346.0 -d 157.166.255.19 -j RETURN
+ $IPTABLES -A Cid438728CD18346.0 -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ # test for bug #1905718
+ # Group of DNS Name objects considered empty
+ $IPTABLES -A Policy -d 6bone.net -m state --state NEW -j ACCEPT
+ $IPTABLES -A Policy -d ny6ix.net -m state --state NEW -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ # firewall33-1:Policy:12: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ $IPTABLES -A Policy -d 192.0.2.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A Policy -d 207.251.84.150 -m state --state NEW -j ACCEPT
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ $IPTABLES -N RULE_13
+ $IPTABLES -A Policy -j RULE_13
+ $IPTABLES -A RULE_13 -j LOG --log-level info --log-prefix "RULE 13 -- DENY "
+ $IPTABLES -A RULE_13 -j DROP
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ # branches to firewall33:Policy which uses DNSName objects
+ # testing for bug 1485
+ $IPTABLES -A OUTPUT -j Policy
+ $IPTABLES -A INPUT -j Policy
+ $IPTABLES -A FORWARD -j Policy
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:49 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall33.fw.orig b/test/ipt/firewall33.fw.orig
new file mode 100755
index 000000000..781605de2
--- /dev/null
+++ b/test/ipt/firewall33.fw.orig
@@ -0,0 +1,630 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:45 2011 PST by vadim
+#
+# files: * firewall33.fw
+#
+# Compiled for iptables (any version)
+#
+# testing DNSName object
+
+# firewall33:Policy:2: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+# firewall33:Policy:2: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+# firewall33:Policy:6: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+# firewall33:Policy:12: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall33:Policy:12: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth1 192.168.1.100/24" ""
+ getaddr eth0.100 i_eth0_100
+ getaddr6 eth0.100 i_eth0_100_v6
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ for i_eth0_100 in $i_eth0_100_list
+ do
+ test -n "$i_eth0_100" && $IPTABLES -t nat -A PREROUTING -d $i_eth0_100 -j DNAT --to-destination 192.168.1.10
+ done
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0.100 -d 157.166.224.25 -j MASQUERADE
+ $IPTABLES -t nat -A POSTROUTING -o eth0.100 -d 157.166.224.26 -j MASQUERADE
+ $IPTABLES -t nat -A POSTROUTING -o eth0.100 -d 157.166.226.25 -j MASQUERADE
+ $IPTABLES -t nat -A POSTROUTING -o eth0.100 -d 157.166.226.26 -j MASQUERADE
+ $IPTABLES -t nat -A POSTROUTING -o eth0.100 -d 157.166.255.18 -j MASQUERADE
+ $IPTABLES -t nat -A POSTROUTING -o eth0.100 -d 157.166.255.19 -j MASQUERADE
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0.100 -d www.cnn.com -j MASQUERADE
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0.100 -d www.google.com -j MASQUERADE
+ $IPTABLES -t nat -A POSTROUTING -o eth0.100 -d www.cnn.com -j MASQUERADE
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid43876E7B18346.0
+ $IPTABLES -t nat -A POSTROUTING -o eth0.100 -j Cid43876E7B18346.0
+ $IPTABLES -t nat -A Cid43876E7B18346.0 -d www.google.com -j RETURN
+ $IPTABLES -t nat -A Cid43876E7B18346.0 -d www.cnn.com -j RETURN
+ $IPTABLES -t nat -A Cid43876E7B18346.0 -j MASQUERADE
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -A INPUT -s 157.166.224.25 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -s 157.166.224.26 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -s 157.166.226.25 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -s 157.166.226.26 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -s 157.166.255.18 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -s 157.166.255.19 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 157.166.224.25 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 157.166.224.26 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 157.166.226.25 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 157.166.226.26 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 157.166.255.18 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 157.166.255.19 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -A INPUT -s www.cnn.com -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s www.cnn.com -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ # firewall33:Policy:2: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+ $IPTABLES -A INPUT -s 192.0.2.1 -m state --state NEW -j ACCEPT
+ # firewall33:Policy:2: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+ $IPTABLES -A FORWARD -s 192.0.2.1 -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -A INPUT -s buildmaster -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s buildmaster -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -N Cid4386E38318346.0
+ $IPTABLES -A OUTPUT -j Cid4386E38318346.0
+ $IPTABLES -A INPUT -j Cid4386E38318346.0
+ $IPTABLES -A FORWARD -j Cid4386E38318346.0
+ $IPTABLES -A Cid4386E38318346.0 -d 157.166.224.25 -j RETURN
+ $IPTABLES -A Cid4386E38318346.0 -d 157.166.224.26 -j RETURN
+ $IPTABLES -A Cid4386E38318346.0 -d 157.166.226.25 -j RETURN
+ $IPTABLES -A Cid4386E38318346.0 -d 157.166.226.26 -j RETURN
+ $IPTABLES -A Cid4386E38318346.0 -d 157.166.255.18 -j RETURN
+ $IPTABLES -A Cid4386E38318346.0 -d 157.166.255.19 -j RETURN
+ $IPTABLES -A Cid4386E38318346.0 -j DROP
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -N Cid4386E37718346.0
+ $IPTABLES -A OUTPUT -j Cid4386E37718346.0
+ $IPTABLES -A INPUT -j Cid4386E37718346.0
+ $IPTABLES -A FORWARD -j Cid4386E37718346.0
+ $IPTABLES -A Cid4386E37718346.0 -d www.cnn.com -j RETURN
+ $IPTABLES -A Cid4386E37718346.0 -j DROP
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -N Cid43867C3018346.0
+ $IPTABLES -A OUTPUT -m state --state NEW -j Cid43867C3018346.0
+ $IPTABLES -A INPUT -m state --state NEW -j Cid43867C3018346.0
+ $IPTABLES -A FORWARD -m state --state NEW -j Cid43867C3018346.0
+ # firewall33:Policy:6: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+ $IPTABLES -A Cid43867C3018346.0 -d 192.0.2.1 -j RETURN
+ $IPTABLES -A Cid43867C3018346.0 -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -N Cid4386C10D18346.0
+ $IPTABLES -A OUTPUT -m state --state NEW -j Cid4386C10D18346.0
+ $IPTABLES -A INPUT -m state --state NEW -j Cid4386C10D18346.0
+ $IPTABLES -A FORWARD -m state --state NEW -j Cid4386C10D18346.0
+ $IPTABLES -A Cid4386C10D18346.0 -d buildmaster -j RETURN
+ $IPTABLES -A Cid4386C10D18346.0 -j ACCEPT
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -N Cid438728A918346.0
+ $IPTABLES -A OUTPUT -m state --state NEW -j Cid438728A918346.0
+ $IPTABLES -A INPUT -m state --state NEW -j Cid438728A918346.0
+ $IPTABLES -A FORWARD -m state --state NEW -j Cid438728A918346.0
+ $IPTABLES -A Cid438728A918346.0 -d 74.125.19.99 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -d 74.125.19.103 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -d 74.125.19.104 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -d 74.125.19.147 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -d 157.166.224.25 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -d 157.166.224.26 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -d 157.166.226.25 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -d 157.166.226.26 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -d 157.166.255.18 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -d 157.166.255.19 -j RETURN
+ $IPTABLES -A Cid438728A918346.0 -j ACCEPT
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -N Cid438728BA18346.0
+ $IPTABLES -A OUTPUT -m state --state NEW -j Cid438728BA18346.0
+ $IPTABLES -A INPUT -m state --state NEW -j Cid438728BA18346.0
+ $IPTABLES -A FORWARD -m state --state NEW -j Cid438728BA18346.0
+ $IPTABLES -A Cid438728BA18346.0 -d www.cnn.com -j RETURN
+ $IPTABLES -A Cid438728BA18346.0 -d www.google.com -j RETURN
+ $IPTABLES -A Cid438728BA18346.0 -j ACCEPT
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ $IPTABLES -N Cid438728CD18346.0
+ $IPTABLES -A OUTPUT -m state --state NEW -j Cid438728CD18346.0
+ $IPTABLES -A INPUT -m state --state NEW -j Cid438728CD18346.0
+ $IPTABLES -A FORWARD -m state --state NEW -j Cid438728CD18346.0
+ $IPTABLES -A Cid438728CD18346.0 -d www.google.com -j RETURN
+ $IPTABLES -A Cid438728CD18346.0 -d 157.166.224.25 -j RETURN
+ $IPTABLES -A Cid438728CD18346.0 -d 157.166.224.26 -j RETURN
+ $IPTABLES -A Cid438728CD18346.0 -d 157.166.226.25 -j RETURN
+ $IPTABLES -A Cid438728CD18346.0 -d 157.166.226.26 -j RETURN
+ $IPTABLES -A Cid438728CD18346.0 -d 157.166.255.18 -j RETURN
+ $IPTABLES -A Cid438728CD18346.0 -d 157.166.255.19 -j RETURN
+ $IPTABLES -A Cid438728CD18346.0 -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ # test for bug #1905718
+ # Group of DNS Name objects considered empty
+ $IPTABLES -A OUTPUT -d 6bone.net -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -d ny6ix.net -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 6bone.net -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d ny6ix.net -m state --state NEW -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ # firewall33:Policy:12: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ $IPTABLES -A OUTPUT -d 192.0.2.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -d 207.251.84.150 -m state --state NEW -j ACCEPT
+ # firewall33:Policy:12: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ $IPTABLES -A FORWARD -d 192.0.2.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 207.251.84.150 -m state --state NEW -j ACCEPT
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ $IPTABLES -N RULE_13
+ $IPTABLES -A OUTPUT -j RULE_13
+ $IPTABLES -A INPUT -j RULE_13
+ $IPTABLES -A FORWARD -j RULE_13
+ $IPTABLES -A RULE_13 -j LOG --log-level debug --log-prefix "RULE 13 -- DENY on global "
+ $IPTABLES -A RULE_13 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:45 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall34.fw.orig b/test/ipt/firewall34.fw.orig
new file mode 100755
index 000000000..3f3c95956
--- /dev/null
+++ b/test/ipt/firewall34.fw.orig
@@ -0,0 +1,696 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:51 2011 PST by vadim
+#
+# files: * firewall34.fw
+#
+# Compiled for iptables (any version)
+#
+# testing AddressTable object
+
+# firewall34:Policy:12: warning: Empty group or address table object 'empty table'
+# firewall34:Policy:12: warning: After removal of all empty groups and address table objects rule element Dst becomes 'any' in the rule 12 (global)
+# Dropping rule 12 (global) because option 'Ignore rules with empty groups' is in effect
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+ check_file "block_these" "block-hosts.tbl"
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth1 192.168.1.100/24" ""
+ getaddr eth0.100 i_eth0_100
+ getaddr6 eth0.100 i_eth0_100_v6
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid4389EEB018346.0
+ for i_eth0_100 in $i_eth0_100_list
+ do
+ test -n "$i_eth0_100" && $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d $i_eth0_100 --dport 25 -j Cid4389EEB018346.0
+ done
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; $IPTABLES -t nat -A Cid4389EEB018346.0 -s $at_block_these -j RETURN
+ done
+ $IPTABLES -t nat -A Cid4389EEB018346.0 -p tcp -m tcp --dport 25 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid43891B6E674.0
+ $IPTABLES -t nat -A POSTROUTING -o eth0.100 -s 192.168.1.0/24 -j Cid43891B6E674.0
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; $IPTABLES -t nat -A Cid43891B6E674.0 -d $at_block_these -j RETURN
+ done
+ $IPTABLES -t nat -A Cid43891B6E674.0 -j MASQUERADE
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -d 192.168.1.2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -d 192.168.1.3/30 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -d 192.168.1.200 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -d 192.168.1.201 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -d 192.168.2.128/25 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 192.168.1.2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 192.168.1.3/30 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 192.168.1.200 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 192.168.1.201 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 192.168.2.128/25 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 192.168.1.2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 192.168.1.3/30 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 192.168.1.200 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 192.168.1.201 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 192.168.2.128/25 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -N RULE_1
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; $IPTABLES -A OUTPUT -d $at_block_these -j RULE_1
+ done
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; $IPTABLES -A FORWARD -d $at_block_these -j RULE_1
+ done
+ $IPTABLES -A RULE_1 -j LOG --log-level debug --log-prefix "RULE 1 -- DENY on global "
+ $IPTABLES -A RULE_1 -j DROP
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -N RULE_2
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; $IPTABLES -A OUTPUT -d $at_block_these -j RULE_2
+ done
+ $IPTABLES -A OUTPUT -d 61.150.47.112 -j RULE_2
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; $IPTABLES -A FORWARD -d $at_block_these -j RULE_2
+ done
+ $IPTABLES -A FORWARD -d 61.150.47.112 -j RULE_2
+ $IPTABLES -A RULE_2 -j LOG --log-level debug --log-prefix "RULE 2 -- DENY on global "
+ $IPTABLES -A RULE_2 -j DROP
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; $IPTABLES -A OUTPUT -p tcp -m tcp -d $at_block_these --dport 25 -j DROP
+ done
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 61.150.47.112 --dport 25 -j DROP
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; $IPTABLES -A FORWARD -p tcp -m tcp -d $at_block_these --dport 25 -j DROP
+ done
+ $IPTABLES -A FORWARD -p tcp -m tcp -d 61.150.47.112 --dport 25 -j DROP
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ for i_eth0_100 in $i_eth0_100_list
+ do
+ test -n "$i_eth0_100" && {
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; $IPTABLES -A OUTPUT -p tcp -m tcp -s $i_eth0_100 -d $at_block_these --dport 25 -j DROP
+ done
+ }
+ done
+ for i_eth0_100 in $i_eth0_100_list
+ do
+ test -n "$i_eth0_100" && $IPTABLES -A OUTPUT -p tcp -m tcp -s $i_eth0_100 -d 61.150.47.112 --dport 25 -j DROP
+ done
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -N RULE_5
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; $IPTABLES -A INPUT -s $at_block_these -j RULE_5
+ done
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; $IPTABLES -A FORWARD -s $at_block_these -j RULE_5
+ done
+ $IPTABLES -A RULE_5 -j LOG --log-level debug --log-prefix "RULE 5 -- DENY on global "
+ $IPTABLES -A RULE_5 -j DROP
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -N RULE_6
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; $IPTABLES -A INPUT -s $at_block_these -j RULE_6
+ done
+ $IPTABLES -A INPUT -s 61.150.47.112 -j RULE_6
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; $IPTABLES -A FORWARD -s $at_block_these -j RULE_6
+ done
+ $IPTABLES -A FORWARD -s 61.150.47.112 -j RULE_6
+ $IPTABLES -A RULE_6 -j LOG --log-level debug --log-prefix "RULE 6 -- DENY on global "
+ $IPTABLES -A RULE_6 -j DROP
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -N Cid4388F5A9674.0
+ $IPTABLES -A OUTPUT -m state --state NEW -j Cid4388F5A9674.0
+ $IPTABLES -A INPUT -m state --state NEW -j Cid4388F5A9674.0
+ $IPTABLES -A FORWARD -m state --state NEW -j Cid4388F5A9674.0
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; $IPTABLES -A Cid4388F5A9674.0 -s $at_block_these -j RETURN
+ done
+ $IPTABLES -A Cid4388F5A9674.0 -s 61.150.47.112 -j RETURN
+ $IPTABLES -A Cid4388F5A9674.0 -j ACCEPT
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -N Cid4392312525682.0
+ for i_eth0_100 in $i_eth0_100_list
+ do
+ test -n "$i_eth0_100" && $IPTABLES -A INPUT -s $i_eth0_100 -m state --state NEW -j Cid4392312525682.0
+ done
+ for i_eth0_100 in $i_eth0_100_list
+ do
+ test -n "$i_eth0_100" && $IPTABLES -A OUTPUT -s $i_eth0_100 -m state --state NEW -j Cid4392312525682.0
+ done
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; $IPTABLES -A Cid4392312525682.0 -d $at_block_these -j RETURN
+ done
+ $IPTABLES -A Cid4392312525682.0 -d 61.150.47.112 -j RETURN
+ $IPTABLES -A Cid4392312525682.0 -j ACCEPT
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.10 --dport 25 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -d 192.168.1.10 --dport 25 -m state --state NEW -j ACCEPT
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ $IPTABLES -N RULE_11
+ $IPTABLES -A OUTPUT -j RULE_11
+ $IPTABLES -A INPUT -j RULE_11
+ $IPTABLES -A FORWARD -j RULE_11
+ $IPTABLES -A RULE_11 -j LOG --log-level debug --log-prefix "RULE 11 -- DENY on global "
+ $IPTABLES -A RULE_11 -j DROP
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ # using address table
+ # object with no addresses
+ $IPTABLES -N RULE_13
+ $IPTABLES -A OUTPUT -d 22.22.22.0/24 -j RULE_13
+ $IPTABLES -A FORWARD -d 22.22.22.0/24 -j RULE_13
+ $IPTABLES -A RULE_13 -j LOG --log-level debug --log-prefix "RULE 13 -- DENY on global "
+ $IPTABLES -A RULE_13 -j DROP
+ #
+ # Rule 14 (global)
+ #
+ echo "Rule 14 (global)"
+ #
+ # using connlimit
+ # option. Connlimit
+ # is only valid in combination
+ # with "-p tcp -m tcp"
+ $IPTABLES -N Cid45948F957794.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 25 -m state --state NEW -m connlimit --connlimit-above 2 -j Cid45948F957794.0
+ $IPTABLES -A Cid45948F957794.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid45948F957794.0 -d 192.168.1.2 -j ACCEPT
+ $IPTABLES -A Cid45948F957794.0 -d 192.168.1.3/30 -j ACCEPT
+ $IPTABLES -A Cid45948F957794.0 -d 192.168.1.200 -j ACCEPT
+ $IPTABLES -A Cid45948F957794.0 -d 192.168.1.201 -j ACCEPT
+ $IPTABLES -A Cid45948F957794.0 -d 192.168.2.128/25 -j ACCEPT
+ $IPTABLES -N Cid45948F957794.1
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 25 -m state --state NEW -m connlimit --connlimit-above 2 -j Cid45948F957794.1
+ $IPTABLES -A Cid45948F957794.1 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid45948F957794.1 -d 192.168.1.2 -j ACCEPT
+ $IPTABLES -A Cid45948F957794.1 -d 192.168.1.3/30 -j ACCEPT
+ $IPTABLES -A Cid45948F957794.1 -d 192.168.1.200 -j ACCEPT
+ $IPTABLES -A Cid45948F957794.1 -d 192.168.1.201 -j ACCEPT
+ $IPTABLES -A Cid45948F957794.1 -d 192.168.2.128/25 -j ACCEPT
+ $IPTABLES -N Cid45948F957794.2
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 --dport 25 -m state --state NEW -m connlimit --connlimit-above 2 -j Cid45948F957794.2
+ $IPTABLES -A Cid45948F957794.2 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid45948F957794.2 -d 192.168.1.2 -j ACCEPT
+ $IPTABLES -A Cid45948F957794.2 -d 192.168.1.3/30 -j ACCEPT
+ $IPTABLES -A Cid45948F957794.2 -d 192.168.1.200 -j ACCEPT
+ $IPTABLES -A Cid45948F957794.2 -d 192.168.1.201 -j ACCEPT
+ $IPTABLES -A Cid45948F957794.2 -d 192.168.2.128/25 -j ACCEPT
+
+
+ # ================ IPv6
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy_ipv6
+ #
+ # Rule Policy_ipv6 0 (global)
+ #
+ echo "Rule Policy_ipv6 0 (global)"
+ #
+ $IP6TABLES -A OUTPUT -d 2001:458:20:100:250:b7ff:fe00:2af -m state --state NEW -j ACCEPT
+ $IP6TABLES -A OUTPUT -d fe80::21d:9ff:fe8b:8e94/64 -m state --state NEW -j ACCEPT
+ $IP6TABLES -A FORWARD -d 2001:458:20:100:250:b7ff:fe00:2af -m state --state NEW -j ACCEPT
+ $IP6TABLES -A FORWARD -d fe80::21d:9ff:fe8b:8e94/64 -m state --state NEW -j ACCEPT
+ #
+ # Rule Policy_ipv6 1 (global)
+ #
+ echo "Rule Policy_ipv6 1 (global)"
+ #
+ $IP6TABLES -N Policy_ipv6_1
+ $IP6TABLES -A OUTPUT -j Policy_ipv6_1
+ $IP6TABLES -A INPUT -j Policy_ipv6_1
+ $IP6TABLES -A FORWARD -j Policy_ipv6_1
+ $IP6TABLES -A Policy_ipv6_1 -j LOG --log-level debug --log-prefix "RULE 1 -- DENY on global "
+ $IP6TABLES -A Policy_ipv6_1 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:51 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat ipv6"
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall35.fw.orig b/test/ipt/firewall35.fw.orig
new file mode 100755
index 000000000..1eb666af2
--- /dev/null
+++ b/test/ipt/firewall35.fw.orig
@@ -0,0 +1,600 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:54 2011 PST by vadim
+#
+# files: * firewall35.fw
+#
+# Compiled for iptables (any version)
+#
+# testing AddressTable object
+
+# like firewall34, but uses different script format
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IPTABLES_RESTORE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+ check_file "block_these" "block-hosts.tbl"
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth1 192.168.1.100/24" ""
+ getaddr eth0.100 i_eth0_100
+ getaddr6 eth0.100 i_eth0_100_v6
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ echo "-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu"
+
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # ================ Table 'filter', rule set block_local_bcast
+ #
+ # Rule block_local_bcast 0 (global)
+ # an attempt to build rule blocking local broadcast packets on the subnet where firewall has dynamic interface
+ echo ":block_local_bcast - [0:0]"
+ echo "-A block_local_bcast -d 192.168.222.255 -j DROP "
+ #
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ echo "-A OUTPUT -d 192.168.1.1 -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -d 192.168.1.2 -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -d 192.168.1.3/30 -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -d 192.168.1.200 -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -d 192.168.1.201 -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -d 192.168.2.128/25 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -d 192.168.1.1 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -d 192.168.1.2 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -d 192.168.1.3/30 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -d 192.168.1.200 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -d 192.168.1.201 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -d 192.168.2.128/25 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 192.168.1.1 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 192.168.1.2 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 192.168.1.3/30 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 192.168.1.200 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 192.168.1.201 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -d 192.168.2.128/25 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 1 (global)
+ echo ":RULE_1 - [0:0]"
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; echo "-A OUTPUT -d $at_block_these -j RULE_1 "
+ done
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; echo "-A FORWARD -d $at_block_these -j RULE_1 "
+ done
+ echo "-A RULE_1 -j LOG --log-level debug --log-prefix \"RULE 1 -- DENY on global \""
+ echo "-A RULE_1 -j DROP "
+ #
+ # Rule 2 (global)
+ echo ":RULE_2 - [0:0]"
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; echo "-A OUTPUT -d $at_block_these -j RULE_2 "
+ done
+ echo "-A OUTPUT -d 61.150.47.112 -j RULE_2 "
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; echo "-A FORWARD -d $at_block_these -j RULE_2 "
+ done
+ echo "-A FORWARD -d 61.150.47.112 -j RULE_2 "
+ echo "-A RULE_2 -j LOG --log-level debug --log-prefix \"RULE 2 -- DENY on global \""
+ echo "-A RULE_2 -j DROP "
+ #
+ # Rule 3 (global)
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; echo "-A OUTPUT -p tcp -m tcp -d $at_block_these --dport 25 -j DROP "
+ done
+ echo "-A OUTPUT -p tcp -m tcp -d 61.150.47.112 --dport 25 -j DROP "
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; echo "-A FORWARD -p tcp -m tcp -d $at_block_these --dport 25 -j DROP "
+ done
+ echo "-A FORWARD -p tcp -m tcp -d 61.150.47.112 --dport 25 -j DROP "
+ #
+ # Rule 4 (global)
+ for i_eth0_100 in $i_eth0_100_list
+ do
+ test -n "$i_eth0_100" && {
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; echo "-A OUTPUT -p tcp -m tcp -s $i_eth0_100 -d $at_block_these --dport 25 -j DROP "
+ done
+ }
+ done
+ for i_eth0_100 in $i_eth0_100_list
+ do
+ test -n "$i_eth0_100" && echo "-A OUTPUT -p tcp -m tcp -s $i_eth0_100 -d 61.150.47.112 --dport 25 -j DROP "
+ done
+ #
+ # Rule 5 (global)
+ # test rule for the discussion
+ # https://sourceforge.net/projects/fwbuilder/forums/forum/16372/topic/3733964/index/page/1
+ echo "-A INPUT -j block_local_bcast "
+ #
+ # Rule 6 (global)
+ echo ":RULE_6 - [0:0]"
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; echo "-A INPUT -s $at_block_these -j RULE_6 "
+ done
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; echo "-A FORWARD -s $at_block_these -j RULE_6 "
+ done
+ echo "-A RULE_6 -j LOG --log-level debug --log-prefix \"RULE 6 -- DENY on global \""
+ echo "-A RULE_6 -j DROP "
+ #
+ # Rule 7 (global)
+ echo ":RULE_7 - [0:0]"
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; echo "-A INPUT -s $at_block_these -j RULE_7 "
+ done
+ echo "-A INPUT -s 61.150.47.112 -j RULE_7 "
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; echo "-A FORWARD -s $at_block_these -j RULE_7 "
+ done
+ echo "-A FORWARD -s 61.150.47.112 -j RULE_7 "
+ echo "-A RULE_7 -j LOG --log-level debug --log-prefix \"RULE 7 -- DENY on global \""
+ echo "-A RULE_7 -j DROP "
+ #
+ # Rule 8 (global)
+ echo ":Cid4392555025682.0 - [0:0]"
+ echo "-A OUTPUT -m state --state NEW -j Cid4392555025682.0 "
+ echo "-A INPUT -m state --state NEW -j Cid4392555025682.0 "
+ echo "-A FORWARD -m state --state NEW -j Cid4392555025682.0 "
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; echo "-A Cid4392555025682.0 -s $at_block_these -j RETURN "
+ done
+ echo "-A Cid4392555025682.0 -s 61.150.47.112 -j RETURN "
+ echo "-A Cid4392555025682.0 -j ACCEPT "
+ #
+ # Rule 9 (global)
+ echo ":Cid4392555D25682.0 - [0:0]"
+ for i_eth0_100 in $i_eth0_100_list
+ do
+ test -n "$i_eth0_100" && echo "-A INPUT -s $i_eth0_100 -m state --state NEW -j Cid4392555D25682.0 "
+ done
+ for i_eth0_100 in $i_eth0_100_list
+ do
+ test -n "$i_eth0_100" && echo "-A OUTPUT -s $i_eth0_100 -m state --state NEW -j Cid4392555D25682.0 "
+ done
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; echo "-A Cid4392555D25682.0 -d $at_block_these -j RETURN "
+ done
+ echo "-A Cid4392555D25682.0 -d 61.150.47.112 -j RETURN "
+ echo "-A Cid4392555D25682.0 -j ACCEPT "
+ #
+ # Rule 10 (global)
+ echo "-A OUTPUT -p tcp -m tcp -d 192.168.1.10 --dport 25 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -p tcp -m tcp -d 192.168.1.10 --dport 25 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 11 (global)
+ echo "-A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 12 (global)
+ echo ":RULE_12 - [0:0]"
+ echo "-A OUTPUT -j RULE_12 "
+ echo "-A INPUT -j RULE_12 "
+ echo "-A FORWARD -j RULE_12 "
+ echo "-A RULE_12 -j LOG --log-level debug --log-prefix \"RULE 12 -- DENY on global \""
+ echo "-A RULE_12 -j DROP "
+ #
+ echo COMMIT
+
+
+
+ echo '*nat'
+ # ================ Table 'nat', rule set NAT
+ echo :PREROUTING ACCEPT [0:0]
+ echo :POSTROUTING ACCEPT [0:0]
+ echo :OUTPUT ACCEPT [0:0]
+ #
+ # Rule 0 (NAT)
+ echo ":Cid4392558F25682.0 - [0:0]"
+ for i_eth0_100 in $i_eth0_100_list
+ do
+ test -n "$i_eth0_100" && echo "-A PREROUTING -p tcp -m tcp -d $i_eth0_100 --dport 25 -j Cid4392558F25682.0 "
+ done
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; echo "-A Cid4392558F25682.0 -s $at_block_these -j RETURN "
+ done
+ echo "-A Cid4392558F25682.0 -p tcp -m tcp --dport 25 -j DNAT --to-destination 192.168.1.10 "
+ #
+ # Rule 1 (NAT)
+ echo ":Cid4392559D25682.0 - [0:0]"
+ echo "-A POSTROUTING -o eth0.100 -s 192.168.1.0/24 -j Cid4392559D25682.0 "
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; echo "-A Cid4392559D25682.0 -d $at_block_these -j RETURN "
+ done
+ echo "-A Cid4392559D25682.0 -j MASQUERADE "
+ #
+ echo COMMIT
+
+
+ ) | $IPTABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:54 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall36-1.fw.orig b/test/ipt/firewall36-1.fw.orig
new file mode 100755
index 000000000..aec77397d
--- /dev/null
+++ b/test/ipt/firewall36-1.fw.orig
@@ -0,0 +1,493 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:58 2011 PST by vadim
+#
+# files: * firewall36-1.fw
+#
+# Compiled for iptables (any version)
+#
+# Testing routing configuration where routing rules do not install default route
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo eth2"
+ for i in eth0 eth1 lo eth2 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.0.2.1/24" ""
+ update_addresses_of_interface "eth1 192.168.1.1/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth2 192.0.100.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+ # ============== ROUTING RULES ==============
+
+ TMPDIRNAME="/tmp/.fwbuilder.tempdir.$$"
+ TMPFILENAME="$TMPDIRNAME/.fwbuilder.out"
+ (umask 077 && mkdir $TMPDIRNAME) || exit 1
+
+ #
+ # This function stops stdout redirection
+ # and sends previously saved output to terminal
+ restore_script_output()
+ {
+ exec 1>&3 2>&1
+ cat $TMPFILENAME
+ rm -rf $TMPDIRNAME
+ }
+
+ # if any routing rule fails we do our best to prevent freezing the firewall
+ route_command_error()
+ {
+ echo "Error: Routing rule $1 couldn't be activated"
+ echo "Recovering previous routing configuration..."
+ # delete current routing rules
+ $IP route show | while read route ; do $IP route del $route ; done
+ # restore old routing rules
+ (IFS="
+ "; for route in $oldRoutes; do (IFS=' '; $IP route add $route); done)
+ echo "...done"
+ restore_script_output
+ epilog_commands
+ exit 1
+ }
+
+ # redirect output to prevent ssh session from stalling
+ exec 3>&1
+ exec 1> $TMPFILENAME
+ exec 2>&1
+
+ # store previous routing configuration (sort: 'via' GW has to be
+ # inserted after device routes)
+ oldRoutes=$($IP route show | sort -k 2)
+
+ echo "Deleting routing rules previously set by user space processes..."
+ $IP route show | grep -v '\( proto kernel \)\|\(default via \)' | \
+ while read route ; do $IP route del $route ; done
+
+ echo "Activating non-ecmp routing rules..."
+ #
+ # Rule 0 (main)
+ #
+ echo "Routing rule 0 (main)"
+ #
+ #
+ #
+ $IP route add 192.168.2.0/24 via 192.168.1.254 dev eth1 \
+ || route_command_error "0 (main)"
+
+
+ restore_script_output
+ echo "...done."
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:58 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall36-2.fw.orig b/test/ipt/firewall36-2.fw.orig
new file mode 100755
index 000000000..fd916301b
--- /dev/null
+++ b/test/ipt/firewall36-2.fw.orig
@@ -0,0 +1,493 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:00 2011 PST by vadim
+#
+# files: * firewall36-2.fw
+#
+# Compiled for iptables (any version)
+#
+# Testing routing configuration where routing rules install simple (not ECMP) default route
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo eth2"
+ for i in eth0 eth1 lo eth2 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.0.2.1/24" ""
+ update_addresses_of_interface "eth1 192.168.1.1/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth2 192.0.100.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+ # ============== ROUTING RULES ==============
+
+ TMPDIRNAME="/tmp/.fwbuilder.tempdir.$$"
+ TMPFILENAME="$TMPDIRNAME/.fwbuilder.out"
+ (umask 077 && mkdir $TMPDIRNAME) || exit 1
+
+ #
+ # This function stops stdout redirection
+ # and sends previously saved output to terminal
+ restore_script_output()
+ {
+ exec 1>&3 2>&1
+ cat $TMPFILENAME
+ rm -rf $TMPDIRNAME
+ }
+
+ # if any routing rule fails we do our best to prevent freezing the firewall
+ route_command_error()
+ {
+ echo "Error: Routing rule $1 couldn't be activated"
+ echo "Recovering previous routing configuration..."
+ # delete current routing rules
+ $IP route show | while read route ; do $IP route del $route ; done
+ # restore old routing rules
+ (IFS="
+ "; for route in $oldRoutes; do (IFS=' '; $IP route add $route); done)
+ echo "...done"
+ restore_script_output
+ epilog_commands
+ exit 1
+ }
+
+ # redirect output to prevent ssh session from stalling
+ exec 3>&1
+ exec 1> $TMPFILENAME
+ exec 2>&1
+
+ # store previous routing configuration (sort: 'via' GW has to be
+ # inserted after device routes)
+ oldRoutes=$($IP route show | sort -k 2)
+
+ echo "Deleting routing rules previously set by user space processes..."
+ $IP route show | grep -v 'proto kernel' | \
+ while read route ; do $IP route del $route ; done
+
+ echo "Activating non-ecmp routing rules..."
+ #
+ # Rule 0 (main)
+ #
+ echo "Routing rule 0 (main)"
+ #
+ #
+ #
+ $IP route add default via 192.0.2.100 dev eth0 \
+ || route_command_error "0 (main)"
+
+
+ restore_script_output
+ echo "...done."
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:55:00 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall36.fw.orig b/test/ipt/firewall36.fw.orig
new file mode 100755
index 000000000..54c8444ce
--- /dev/null
+++ b/test/ipt/firewall36.fw.orig
@@ -0,0 +1,595 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:54:56 2011 PST by vadim
+#
+# files: * firewall36.fw
+#
+# Compiled for iptables (any version)
+#
+# testing routing rules - both actually routing and ROUTE target
+
+# routing ruleset installs ECMP default
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo eth2"
+ for i in eth0 eth1 lo eth2 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.0.2.1/24" ""
+ update_addresses_of_interface "eth1 192.168.1.1/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth2 192.0.100.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+ # ================ Table 'mangle', rule set Policy
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -t mangle -A POSTROUTING -p icmp -m icmp --icmp-type any -j ROUTE --oif eth1
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -t mangle -A POSTROUTING -p tcp -m tcp --dport 80 -j ROUTE --oif eth1 --continue
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -t mangle -A POSTROUTING -p tcp -m tcp --dport 22 -j ROUTE --gw 1.2.3.4 --continue
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -t mangle -A PREROUTING -p icmp -m icmp --icmp-type any -j ROUTE --iif eth1
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -t mangle -A POSTROUTING -p tcp -m tcp --dport 13 -j ROUTE --gw 1.2.3.4 --tee
+ $IPTABLES -t mangle -A PREROUTING -p tcp -m tcp --dport 13 -j ROUTE --gw 1.2.3.4 --tee
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ # This permits access from internal net
+ # to the Internet and DMZ
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -N RULE_6
+ $IPTABLES -A OUTPUT -j RULE_6
+ $IPTABLES -A INPUT -j RULE_6
+ $IPTABLES -A FORWARD -j RULE_6
+ $IPTABLES -A RULE_6 -j LOG --log-level info --log-prefix "RULE 6 -- DENY "
+ $IPTABLES -A RULE_6 -j DROP
+
+
+
+
+
+
+
+
+ # ============== ROUTING RULES ==============
+
+ TMPDIRNAME="/tmp/.fwbuilder.tempdir.$$"
+ TMPFILENAME="$TMPDIRNAME/.fwbuilder.out"
+ (umask 077 && mkdir $TMPDIRNAME) || exit 1
+
+ #
+ # This function stops stdout redirection
+ # and sends previously saved output to terminal
+ restore_script_output()
+ {
+ exec 1>&3 2>&1
+ cat $TMPFILENAME
+ rm -rf $TMPDIRNAME
+ }
+
+ # if any routing rule fails we do our best to prevent freezing the firewall
+ route_command_error()
+ {
+ echo "Error: Routing rule $1 couldn't be activated"
+ echo "Recovering previous routing configuration..."
+ # delete current routing rules
+ $IP route show | while read route ; do $IP route del $route ; done
+ # restore old routing rules
+ (IFS="
+ "; for route in $oldRoutes; do (IFS=' '; $IP route add $route); done)
+ echo "...done"
+ restore_script_output
+ epilog_commands
+ exit 1
+ }
+
+ # redirect output to prevent ssh session from stalling
+ exec 3>&1
+ exec 1> $TMPFILENAME
+ exec 2>&1
+
+ # store previous routing configuration (sort: 'via' GW has to be
+ # inserted after device routes)
+ oldRoutes=$($IP route show | sort -k 2)
+
+ echo "Deleting routing rules previously set by user space processes..."
+ $IP route show | grep -v 'proto kernel' | \
+ while read route ; do $IP route del $route ; done
+
+ echo "Activating non-ecmp routing rules..."
+ #
+ # Rule 0 (main)
+ #
+ echo "Routing rule 0 (main)"
+ #
+ # Some sub rules belonging to an ECMP (Equal Cost Multi Path) rule were placed in the ECMP section below.
+ #
+ # Rule 1 (main)
+ #
+ echo "Routing rule 1 (main)"
+ #
+ # Some sub rules belonging to an ECMP (Equal Cost Multi Path) rule were placed in the ECMP section below.
+ #
+ # Rule 2 (main)
+ #
+ echo "Routing rule 2 (main)"
+ #
+ #
+ #
+ $IP route add 192.168.2.0/24 via 192.168.1.254 dev eth1 \
+ || route_command_error "2 (main)"
+
+ #
+ # Rule 3 (main)
+ #
+ echo "Routing rule 3 (main)"
+ #
+ #
+ #
+ $IP route add 22.22.22.100/30 via 192.168.1.254 dev eth1 \
+ || route_command_error "3 (main)"
+
+ $IP route add 22.22.22.104/30 via 192.168.1.254 dev eth1 \
+ || route_command_error "3 (main)"
+
+ $IP route add 22.22.22.108/31 via 192.168.1.254 dev eth1 \
+ || route_command_error "3 (main)"
+
+ $IP route add 22.22.22.110 via 192.168.1.254 dev eth1 \
+ || route_command_error "3 (main)"
+
+
+ #
+ # ============== EQUAL COST MULTI PATH ============
+ #
+ echo "Activating ecmp routing rules..."
+ #
+ # Multipath Rule derived from the following routing rules:
+ #
+ # Rule 0 (main)
+ #
+ # Rule 1 (main)
+ #
+ #
+ $IP route add default \
+ nexthop dev eth0 \
+ nexthop dev eth2 \
+ || route_command_error "1"
+
+ restore_script_output
+ echo "...done."
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:54:56 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall37-1.fw.orig b/test/ipt/firewall37-1.fw.orig
new file mode 100755
index 000000000..b488a84ed
--- /dev/null
+++ b/test/ipt/firewall37-1.fw.orig
@@ -0,0 +1,829 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:07 2011 PST by vadim
+#
+# files: * firewall37-1.fw
+#
+# Compiled for iptables (any version)
+#
+# testing TAG and CLASSIFY rules
+
+# same as firewall37 except rules are made to be terminating
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.22/24" ""
+ update_addresses_of_interface "eth1 22.22.23.22/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # ================ Table 'mangle', automatic rules
+ $IPTABLES -t mangle -A PREROUTING -j CONNMARK --restore-mark
+ $IPTABLES -t mangle -A OUTPUT -j CONNMARK --restore-mark
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -s 22.22.23.22 -j ACCEPT
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.22 -j ACCEPT
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.2.1 -j ACCEPT
+ $IPTABLES -t nat -A OUTPUT -j ACCEPT
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.0/24 -j ACCEPT
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.0/24 -j ACCEPT
+
+ # ================ Table 'mangle', rule set rule27_branch
+ #
+ # Rule rule27_branch 0 (global)
+ #
+ echo "Rule rule27_branch 0 (global)"
+ #
+ $IPTABLES -N rule27_branch -t mangle
+ $IPTABLES -N Cid45AB5C2E25451.0 -t mangle
+ $IPTABLES -t mangle -A rule27_branch -p tcp -m tcp --tcp-flags ALL ACK -j Cid45AB5C2E25451.0
+ $IPTABLES -t mangle -A Cid45AB5C2E25451.0 -j CLASSIFY --set-class 1:16
+ $IPTABLES -t mangle -A Cid45AB5C2E25451.0 -j ACCEPT
+ #
+ # Rule rule27_branch 1 (global)
+ #
+ echo "Rule rule27_branch 1 (global)"
+ #
+ $IPTABLES -N rule27_branch_1 -t mangle
+ $IPTABLES -t mangle -A rule27_branch -p tcp -m tcp --dport 80 -m state --state NEW -j rule27_branch_1
+ $IPTABLES -t mangle -A rule27_branch_1 -j LOG --log-level info --log-prefix "RULE 1 -- ACCEPT "
+ $IPTABLES -t mangle -A rule27_branch_1 -j ACCEPT
+ # ================ Table 'mangle', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ # terminating target
+ $IPTABLES -N Cid45AB5AAD25451.0 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -p 50 -m state --state NEW -j Cid45AB5AAD25451.0
+ $IPTABLES -t mangle -A Cid45AB5AAD25451.0 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid45AB5AAD25451.0 -j ACCEPT
+ $IPTABLES -N Cid45AB5AAD25451.1 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -p ah -m state --state NEW -j Cid45AB5AAD25451.1
+ $IPTABLES -t mangle -A Cid45AB5AAD25451.1 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid45AB5AAD25451.1 -j ACCEPT
+ $IPTABLES -N Cid45AB5AAD25451.2 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -p 50 -m state --state NEW -j Cid45AB5AAD25451.2
+ $IPTABLES -t mangle -A Cid45AB5AAD25451.2 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid45AB5AAD25451.2 -j ACCEPT
+ $IPTABLES -N Cid45AB5AAD25451.3 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -p ah -m state --state NEW -j Cid45AB5AAD25451.3
+ $IPTABLES -t mangle -A Cid45AB5AAD25451.3 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid45AB5AAD25451.3 -j ACCEPT
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ # terminating target
+ $IPTABLES -N RULE_1 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -p 50 -m state --state NEW -j RULE_1
+ $IPTABLES -t mangle -A OUTPUT -p ah -m state --state NEW -j RULE_1
+ $IPTABLES -t mangle -A PREROUTING -p 50 -m state --state NEW -j RULE_1
+ $IPTABLES -t mangle -A PREROUTING -p ah -m state --state NEW -j RULE_1
+ $IPTABLES -t mangle -A RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- TAG "
+ $IPTABLES -t mangle -A RULE_1 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A RULE_1 -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ # terminating target
+ $IPTABLES -N Cid45AB5AC525451.0 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -p 50 -m state --state NEW -j Cid45AB5AC525451.0
+ $IPTABLES -t mangle -A OUTPUT -p ah -m state --state NEW -j Cid45AB5AC525451.0
+ $IPTABLES -t mangle -A PREROUTING -p 50 -m state --state NEW -j Cid45AB5AC525451.0
+ $IPTABLES -t mangle -A PREROUTING -p ah -m state --state NEW -j Cid45AB5AC525451.0
+ $IPTABLES -t mangle -A Cid45AB5AC525451.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -t mangle -A Cid45AB5AC525451.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -N RULE_2_3 -t mangle
+ $IPTABLES -t mangle -A Cid45AB5AC525451.0 -j RULE_2_3
+ $IPTABLES -t mangle -A RULE_2_3 -j LOG --log-level info --log-prefix "RULE 2 -- TAG "
+ $IPTABLES -t mangle -A RULE_2_3 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A RULE_2_3 -j ACCEPT
+ #
+ # Rule 3 (eth1)
+ #
+ echo "Rule 3 (eth1)"
+ #
+ # terminating target
+ $IPTABLES -N Cid45AB5AD225451.0 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -i eth1 -p 50 -m state --state NEW -j Cid45AB5AD225451.0
+ $IPTABLES -t mangle -A Cid45AB5AD225451.0 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid45AB5AD225451.0 -j ACCEPT
+ $IPTABLES -N Cid45AB5AD225451.1 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -i eth1 -p ah -m state --state NEW -j Cid45AB5AD225451.1
+ $IPTABLES -t mangle -A Cid45AB5AD225451.1 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid45AB5AD225451.1 -j ACCEPT
+ #
+ # Rule 4 (eth1)
+ #
+ echo "Rule 4 (eth1)"
+ #
+ # temrinating target
+ $IPTABLES -N Cid45AB5ADE25451.0 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -p 50 -m state --state NEW -j Cid45AB5ADE25451.0
+ $IPTABLES -t mangle -A Cid45AB5ADE25451.0 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid45AB5ADE25451.0 -j ACCEPT
+ $IPTABLES -N Cid45AB5ADE25451.1 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -p ah -m state --state NEW -j Cid45AB5ADE25451.1
+ $IPTABLES -t mangle -A Cid45AB5ADE25451.1 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid45AB5ADE25451.1 -j ACCEPT
+ $IPTABLES -N Cid45AB5ADE25451.2 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth1 -p 50 -m state --state NEW -j Cid45AB5ADE25451.2
+ $IPTABLES -t mangle -A Cid45AB5ADE25451.2 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid45AB5ADE25451.2 -j ACCEPT
+ $IPTABLES -N Cid45AB5ADE25451.3 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth1 -p ah -m state --state NEW -j Cid45AB5ADE25451.3
+ $IPTABLES -t mangle -A Cid45AB5ADE25451.3 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid45AB5ADE25451.3 -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ # terminating and CONNMARK
+ $IPTABLES -N RULE_5 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -p 50 -m state --state NEW -j RULE_5
+ $IPTABLES -t mangle -A OUTPUT -p ah -m state --state NEW -j RULE_5
+ $IPTABLES -t mangle -A PREROUTING -p 50 -m state --state NEW -j RULE_5
+ $IPTABLES -t mangle -A PREROUTING -p ah -m state --state NEW -j RULE_5
+ $IPTABLES -t mangle -A RULE_5 -j MARK --set-mark 10
+ $IPTABLES -t mangle -A RULE_5 -j CONNMARK --save-mark
+ $IPTABLES -t mangle -A RULE_5 -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ # terminating and CONNMARK
+ $IPTABLES -N RULE_6 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -p 50 -m state --state NEW -j RULE_6
+ $IPTABLES -t mangle -A OUTPUT -p ah -m state --state NEW -j RULE_6
+ $IPTABLES -t mangle -A PREROUTING -p 50 -m state --state NEW -j RULE_6
+ $IPTABLES -t mangle -A PREROUTING -p ah -m state --state NEW -j RULE_6
+ $IPTABLES -t mangle -A RULE_6 -j LOG --log-level info --log-prefix "RULE 6 -- TAG "
+ $IPTABLES -t mangle -A RULE_6 -j MARK --set-mark 10
+ $IPTABLES -t mangle -A RULE_6 -j CONNMARK --save-mark
+ $IPTABLES -t mangle -A RULE_6 -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ # terminating and CONNMARK
+ $IPTABLES -N Cid45AB5B0225451.0 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -p 50 -m state --state NEW -j Cid45AB5B0225451.0
+ $IPTABLES -t mangle -A OUTPUT -p ah -m state --state NEW -j Cid45AB5B0225451.0
+ $IPTABLES -t mangle -A PREROUTING -p 50 -m state --state NEW -j Cid45AB5B0225451.0
+ $IPTABLES -t mangle -A PREROUTING -p ah -m state --state NEW -j Cid45AB5B0225451.0
+ $IPTABLES -t mangle -A Cid45AB5B0225451.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -t mangle -A Cid45AB5B0225451.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -N RULE_7 -t mangle
+ $IPTABLES -t mangle -A Cid45AB5B0225451.0 -j RULE_7
+ $IPTABLES -t mangle -A RULE_7 -j LOG --log-level info --log-prefix "RULE 7 -- TAG "
+ $IPTABLES -t mangle -A RULE_7 -j MARK --set-mark 10
+ $IPTABLES -t mangle -A RULE_7 -j CONNMARK --save-mark
+ $IPTABLES -t mangle -A RULE_7 -j ACCEPT
+ #
+ # Rule 8 (eth1)
+ #
+ echo "Rule 8 (eth1)"
+ #
+ # terminating and CONNMARK
+ $IPTABLES -N In_RULE_8 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -i eth1 -p 50 -m state --state NEW -j In_RULE_8
+ $IPTABLES -t mangle -A PREROUTING -i eth1 -p ah -m state --state NEW -j In_RULE_8
+ $IPTABLES -t mangle -A In_RULE_8 -i eth1 -j MARK --set-mark 8
+ $IPTABLES -t mangle -A In_RULE_8 -i eth1 -j CONNMARK --save-mark
+ $IPTABLES -t mangle -A In_RULE_8 -i eth1 -j ACCEPT
+ #
+ # Rule 9 (eth1)
+ #
+ echo "Rule 9 (eth1)"
+ #
+ # terminating and CONNMARK
+ $IPTABLES -N Out_RULE_9 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -p 50 -m state --state NEW -j Out_RULE_9
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -p ah -m state --state NEW -j Out_RULE_9
+ $IPTABLES -t mangle -A POSTROUTING -o eth1 -p 50 -m state --state NEW -j Out_RULE_9
+ $IPTABLES -t mangle -A POSTROUTING -o eth1 -p ah -m state --state NEW -j Out_RULE_9
+ $IPTABLES -t mangle -A Out_RULE_9 -o eth1 -j MARK --set-mark 9
+ $IPTABLES -t mangle -A Out_RULE_9 -o eth1 -j CONNMARK --save-mark
+ $IPTABLES -t mangle -A Out_RULE_9 -o eth1 -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ # testing for bug #1618381
+ # this rule, and the next one, should place
+ # CLASSIFY rule in a separate chain
+ # and pass control to it using -g
+ $IPTABLES -N Cid45AB5B9525451.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -p icmp -m icmp --icmp-type 3 -j Cid45AB5B9525451.0
+ $IPTABLES -t mangle -A Cid45AB5B9525451.0 -j CLASSIFY --set-class 1:10
+ $IPTABLES -t mangle -A Cid45AB5B9525451.0 -j ACCEPT
+ #
+ # Rule 12 (eth0)
+ #
+ echo "Rule 12 (eth0)"
+ #
+ # second rule for bug #1618381
+ $IPTABLES -N Cid45AB5BA125451.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth0 -j Cid45AB5BA125451.0
+ $IPTABLES -t mangle -A Cid45AB5BA125451.0 -j CLASSIFY --set-class 1:11
+ $IPTABLES -t mangle -A Cid45AB5BA125451.0 -j ACCEPT
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ # testing for bug #1618381
+ $IPTABLES -N Cid45AB5BAD25451.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -p icmp -m icmp --icmp-type 3 -j Cid45AB5BAD25451.0
+ $IPTABLES -t mangle -A Cid45AB5BAD25451.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -t mangle -A Cid45AB5BAD25451.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -t mangle -A Cid45AB5BAD25451.0 -j CLASSIFY --set-class 1:10
+ $IPTABLES -t mangle -A Cid45AB5BAD25451.0 -j ACCEPT
+ #
+ # Rule 14 (global)
+ #
+ echo "Rule 14 (global)"
+ #
+ # testing for bug #1618381
+ $IPTABLES -N Cid45AB5BBA25451.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -p icmp -m icmp --icmp-type 3 -j Cid45AB5BBA25451.0
+ $IPTABLES -t mangle -A POSTROUTING -p tcp -m tcp --dport 80 -j Cid45AB5BBA25451.0
+ $IPTABLES -t mangle -A Cid45AB5BBA25451.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -t mangle -A Cid45AB5BBA25451.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -t mangle -A Cid45AB5BBA25451.0 -j CLASSIFY --set-class 1:10
+ $IPTABLES -t mangle -A Cid45AB5BBA25451.0 -j ACCEPT
+ #
+ # Rule 15 (eth0)
+ #
+ echo "Rule 15 (eth0)"
+ #
+ # bug #1618381
+ # this rule uses multiport
+ # and has to be split because
+ # of that
+ $IPTABLES -N Cid45AB5BC825451.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth0 -p tcp -m tcp --dport 10000:11000 -j Cid45AB5BC825451.0
+ $IPTABLES -t mangle -A Cid45AB5BC825451.0 -j CLASSIFY --set-class 1:11
+ $IPTABLES -t mangle -A Cid45AB5BC825451.0 -j ACCEPT
+ $IPTABLES -N Cid45AB5BC825451.1 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth0 -p tcp -m tcp -m multiport --dports 6667,3128,113,53,21,80,119,25,22,23,540,70,13,2105,443 -j Cid45AB5BC825451.1
+ $IPTABLES -t mangle -A Cid45AB5BC825451.1 -j CLASSIFY --set-class 1:11
+ $IPTABLES -t mangle -A Cid45AB5BC825451.1 -j ACCEPT
+ $IPTABLES -N Cid45AB5BC825451.2 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth0 -p udp -m udp -m multiport --dports 53,161 -j Cid45AB5BC825451.2
+ $IPTABLES -t mangle -A Cid45AB5BC825451.2 -j CLASSIFY --set-class 1:11
+ $IPTABLES -t mangle -A Cid45AB5BC825451.2 -j ACCEPT
+ #
+ # Rule 16 (global)
+ #
+ echo "Rule 16 (global)"
+ #
+ # testing for bug #1618381
+ # this rule, and the next one, should place
+ # CLASSIFY rule in a separate chain
+ # and pass control to it using -g
+ $IPTABLES -N Cid45AB5BD525451.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -p icmp -m icmp --icmp-type 3 -j Cid45AB5BD525451.0
+ $IPTABLES -t mangle -A Cid45AB5BD525451.0 -j CLASSIFY --set-class 1:10
+ $IPTABLES -t mangle -A Cid45AB5BD525451.0 -j ACCEPT
+ #
+ # Rule 17 (eth0)
+ #
+ echo "Rule 17 (eth0)"
+ #
+ # second rule for bug #1618381
+ $IPTABLES -N Cid45AB5BE125451.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth0 -j Cid45AB5BE125451.0
+ $IPTABLES -t mangle -A Cid45AB5BE125451.0 -j CLASSIFY --set-class 1:11
+ $IPTABLES -t mangle -A Cid45AB5BE125451.0 -j ACCEPT
+ #
+ # Rule 18 (eth0)
+ #
+ echo "Rule 18 (eth0)"
+ #
+ $IPTABLES -N Out_RULE_18 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j Out_RULE_18
+ $IPTABLES -t mangle -A Out_RULE_18 -j LOG --log-level info --log-prefix "RULE 18 -- CLASSIFY "
+ $IPTABLES -t mangle -A Out_RULE_18 -j CLASSIFY --set-class 1:11
+ $IPTABLES -t mangle -A Out_RULE_18 -j ACCEPT
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ # testing for bug #1618381
+ $IPTABLES -N Cid45AB5BF925451.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -p icmp -m icmp --icmp-type 3 -j Cid45AB5BF925451.0
+ $IPTABLES -t mangle -A Cid45AB5BF925451.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -t mangle -A Cid45AB5BF925451.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -t mangle -A Cid45AB5BF925451.0 -j CLASSIFY --set-class 1:10
+ $IPTABLES -t mangle -A Cid45AB5BF925451.0 -j ACCEPT
+ #
+ # Rule 20 (global)
+ #
+ echo "Rule 20 (global)"
+ #
+ # testing for bug #1618381
+ $IPTABLES -N Cid45AB5C0625451.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -p icmp -m icmp --icmp-type 3 -j Cid45AB5C0625451.0
+ $IPTABLES -t mangle -A POSTROUTING -p tcp -m tcp --dport 80 -j Cid45AB5C0625451.0
+ $IPTABLES -t mangle -A Cid45AB5C0625451.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -t mangle -A Cid45AB5C0625451.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -t mangle -A Cid45AB5C0625451.0 -j CLASSIFY --set-class 1:10
+ $IPTABLES -t mangle -A Cid45AB5C0625451.0 -j ACCEPT
+ #
+ # Rule 21 (eth0)
+ #
+ echo "Rule 21 (eth0)"
+ #
+ # bug #1618381
+ # this rule uses multiport
+ # and has to be split because
+ # of that
+ $IPTABLES -N Cid45AB5C1425451.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth0 -p tcp -m tcp --dport 10000:11000 -j Cid45AB5C1425451.0
+ $IPTABLES -t mangle -A Cid45AB5C1425451.0 -j CLASSIFY --set-class 1:11
+ $IPTABLES -t mangle -A Cid45AB5C1425451.0 -j ACCEPT
+ $IPTABLES -N Cid45AB5C1425451.1 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth0 -p tcp -m tcp -m multiport --dports 6667,3128,113,53,21,80,119,25,22,23,540,70,13,2105,443 -j Cid45AB5C1425451.1
+ $IPTABLES -t mangle -A Cid45AB5C1425451.1 -j CLASSIFY --set-class 1:11
+ $IPTABLES -t mangle -A Cid45AB5C1425451.1 -j ACCEPT
+ $IPTABLES -N Cid45AB5C1425451.2 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth0 -p udp -m udp -m multiport --dports 53,161 -j Cid45AB5C1425451.2
+ $IPTABLES -t mangle -A Cid45AB5C1425451.2 -j CLASSIFY --set-class 1:11
+ $IPTABLES -t mangle -A Cid45AB5C1425451.2 -j ACCEPT
+ #
+ # Rule 22 (global)
+ #
+ echo "Rule 22 (global)"
+ #
+ # bug #1618381
+ # should generate branching code
+ # in both filter and mangle tables
+ $IPTABLES -t mangle -A PREROUTING -p tcp -m tcp -j rule27_branch
+ $IPTABLES -t mangle -A POSTROUTING -p tcp -m tcp -j rule27_branch
+ $IPTABLES -t mangle -A FORWARD -p tcp -m tcp -j rule27_branch
+
+ # ================ Table 'filter', rule set rule27_branch
+ #
+ # Rule rule27_branch 1 (global)
+ #
+ echo "Rule rule27_branch 1 (global)"
+ #
+ $IPTABLES -N rule27_branch
+ $IPTABLES -N rule27_branch_1
+ $IPTABLES -A rule27_branch -p tcp -m tcp --dport 80 -m state --state NEW -j rule27_branch_1
+ $IPTABLES -A rule27_branch_1 -j LOG --log-level info --log-prefix "RULE 1 -- ACCEPT "
+ $IPTABLES -A rule27_branch_1 -j ACCEPT
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.2.10 --dport 80 -j QUEUE
+ $IPTABLES -A FORWARD -p tcp -m tcp -d 192.168.2.10 --dport 80 -j QUEUE
+ #
+ # Rule 22 (global)
+ #
+ echo "Rule 22 (global)"
+ #
+ # bug #1618381
+ # should generate branching code
+ # in both filter and mangle tables
+ $IPTABLES -A OUTPUT -p tcp -m tcp -j rule27_branch
+ $IPTABLES -A INPUT -p tcp -m tcp -j rule27_branch
+ $IPTABLES -A FORWARD -p tcp -m tcp -j rule27_branch
+ #
+ # Rule 23 (global)
+ #
+ echo "Rule 23 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -j TCPMSS --set-mss 1400
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -j TCPMSS --set-mss 1400
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -j TCPMSS --set-mss 1400
+ #
+ # Rule 24 (global)
+ #
+ echo "Rule 24 (global)"
+ #
+ $IPTABLES -N RULE_24
+ $IPTABLES -A OUTPUT -j RULE_24
+ $IPTABLES -A INPUT -j RULE_24
+ $IPTABLES -A FORWARD -j RULE_24
+ $IPTABLES -A RULE_24 -j LOG --log-level info --log-prefix "RULE 24 -- DENY "
+ $IPTABLES -A RULE_24 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:55:07 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall37.fw.orig b/test/ipt/firewall37.fw.orig
new file mode 100755
index 000000000..edc7fb1de
--- /dev/null
+++ b/test/ipt/firewall37.fw.orig
@@ -0,0 +1,1109 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:05 2011 PST by vadim
+#
+# files: * firewall37.fw
+#
+# Compiled for iptables (any version)
+#
+# testing TAG and CLASSIFY rules
+
+# normal script mode (not using iptables-restore)
+
+# firewall37:mangle_rules:4: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall37:mangle_rules:4: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+# firewall37:mangle_rules:7: warning: Empty group or address table object 'empty Ogroup'
+# firewall37:mangle_rules:7: warning: After removal of all empty groups and address table objects rule element Src becomes 'any' in the rule mangle_rules 7 (global)
+# Dropping rule mangle_rules 7 (global) because option 'Ignore rules with empty groups' is in effect
+# firewall37:mangle_rules:13: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.22/24" ""
+ update_addresses_of_interface "eth1 22.22.23.22/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # ================ Table 'mangle', automatic rules
+ $IPTABLES -t mangle -A PREROUTING -j CONNMARK --restore-mark
+ $IPTABLES -t mangle -A OUTPUT -j CONNMARK --restore-mark
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -s 22.22.23.22 -j ACCEPT
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.22 -j ACCEPT
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.2.1 -j ACCEPT
+ $IPTABLES -t nat -A OUTPUT -j ACCEPT
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.0/24 -j ACCEPT
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.0/24 -j ACCEPT
+
+ # ================ Table 'mangle', rule set mymark
+ #
+ # Rule mymark 0 (global)
+ #
+ echo "Rule mymark 0 (global)"
+ #
+ $IPTABLES -N mymark -t mangle
+ $IPTABLES -N Cid29866X28575.0 -t mangle
+ $IPTABLES -t mangle -A mymark -d 192.168.2.0/24 -m state --state NEW -j Cid29866X28575.0
+ $IPTABLES -t mangle -A Cid29866X28575.0 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid29866X28575.0 -j ACCEPT
+ #
+ # Rule mymark 1 (global)
+ #
+ echo "Rule mymark 1 (global)"
+ #
+ $IPTABLES -t mangle -A mymark -j MARK --set-mark 2
+ $IPTABLES -t mangle -A mymark -j ACCEPT
+ # ================ Table 'mangle', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -N Cid43BBA6A09745.0 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -p 50 -m state --state NEW -j Cid43BBA6A09745.0
+ $IPTABLES -t mangle -A Cid43BBA6A09745.0 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid43BBA6A09745.0 -j ACCEPT
+ $IPTABLES -N Cid43BBA6A09745.1 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -p ah -m state --state NEW -j Cid43BBA6A09745.1
+ $IPTABLES -t mangle -A Cid43BBA6A09745.1 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid43BBA6A09745.1 -j ACCEPT
+ $IPTABLES -N Cid43BBA6A09745.2 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -p 50 -m state --state NEW -j Cid43BBA6A09745.2
+ $IPTABLES -t mangle -A Cid43BBA6A09745.2 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid43BBA6A09745.2 -j ACCEPT
+ $IPTABLES -N Cid43BBA6A09745.3 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -p ah -m state --state NEW -j Cid43BBA6A09745.3
+ $IPTABLES -t mangle -A Cid43BBA6A09745.3 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid43BBA6A09745.3 -j ACCEPT
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -N RULE_1 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -p 50 -m state --state NEW -j RULE_1
+ $IPTABLES -t mangle -A OUTPUT -p ah -m state --state NEW -j RULE_1
+ $IPTABLES -t mangle -A PREROUTING -p 50 -m state --state NEW -j RULE_1
+ $IPTABLES -t mangle -A PREROUTING -p ah -m state --state NEW -j RULE_1
+ $IPTABLES -t mangle -A RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- TAG "
+ $IPTABLES -t mangle -A RULE_1 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A RULE_1 -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -N Cid483502D710047.0 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -p 50 -m state --state NEW -j Cid483502D710047.0
+ $IPTABLES -t mangle -A Cid483502D710047.0 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid483502D710047.0 -j ACCEPT
+ $IPTABLES -N Cid483502D710047.1 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -p ah -m state --state NEW -j Cid483502D710047.1
+ $IPTABLES -t mangle -A Cid483502D710047.1 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid483502D710047.1 -j ACCEPT
+ #
+ # Rule 3 (eth1)
+ #
+ echo "Rule 3 (eth1)"
+ #
+ $IPTABLES -N Cid30009X2275.0 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -p 50 -m state --state NEW -j Cid30009X2275.0
+ $IPTABLES -t mangle -A Cid30009X2275.0 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid30009X2275.0 -j ACCEPT
+ $IPTABLES -N Cid30009X2275.1 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -p ah -m state --state NEW -j Cid30009X2275.1
+ $IPTABLES -t mangle -A Cid30009X2275.1 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid30009X2275.1 -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -N RULE_4 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -p 50 -m state --state NEW -j RULE_4
+ $IPTABLES -t mangle -A OUTPUT -p ah -m state --state NEW -j RULE_4
+ $IPTABLES -t mangle -A RULE_4 -j LOG --log-level info --log-prefix "RULE 4 -- TAG "
+ $IPTABLES -t mangle -A RULE_4 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A RULE_4 -j ACCEPT
+ #
+ # Rule 5 (eth1)
+ #
+ echo "Rule 5 (eth1)"
+ #
+ $IPTABLES -N Cid43501X5007.0 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -s 22.22.23.22 -m state --state NEW -j Cid43501X5007.0
+ $IPTABLES -N Cid43501X5007.1 -t mangle
+ $IPTABLES -t mangle -A Cid43501X5007.0 -p 50 -j Cid43501X5007.1
+ $IPTABLES -t mangle -A Cid43501X5007.1 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid43501X5007.1 -j ACCEPT
+ $IPTABLES -N Cid43501X5007.2 -t mangle
+ $IPTABLES -t mangle -A Cid43501X5007.0 -p ah -j Cid43501X5007.2
+ $IPTABLES -t mangle -A Cid43501X5007.2 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid43501X5007.2 -j ACCEPT
+ #
+ # Rule 6 (eth1)
+ #
+ echo "Rule 6 (eth1)"
+ #
+ $IPTABLES -N Cid43518X5007.0 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -s 22.22.23.22 -m state --state NEW -j Cid43518X5007.0
+ $IPTABLES -N Cid43518X5007.1 -t mangle
+ $IPTABLES -t mangle -A Cid43518X5007.0 -p 50 -j Cid43518X5007.1
+ $IPTABLES -t mangle -A Cid43518X5007.1 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid43518X5007.1 -j ACCEPT
+ $IPTABLES -N Cid43518X5007.2 -t mangle
+ $IPTABLES -t mangle -A Cid43518X5007.0 -p ah -j Cid43518X5007.2
+ $IPTABLES -t mangle -A Cid43518X5007.2 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid43518X5007.2 -j ACCEPT
+ #
+ # Rule 7 (eth1)
+ #
+ echo "Rule 7 (eth1)"
+ #
+ $IPTABLES -N Cid43535X5007.0 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -p 50 -m state --state NEW -j Cid43535X5007.0
+ $IPTABLES -t mangle -A Cid43535X5007.0 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid43535X5007.0 -j ACCEPT
+ $IPTABLES -N Cid43535X5007.1 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -p ah -m state --state NEW -j Cid43535X5007.1
+ $IPTABLES -t mangle -A Cid43535X5007.1 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid43535X5007.1 -j ACCEPT
+ #
+ # Rule 8 (eth1)
+ #
+ echo "Rule 8 (eth1)"
+ #
+ $IPTABLES -N Cid43554X5007.0 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -s 22.22.23.22 -j Cid43554X5007.0
+ $IPTABLES -N Cid43554X5007.1 -t mangle
+ $IPTABLES -t mangle -A Cid43554X5007.0 -p 50 -j Cid43554X5007.1
+ $IPTABLES -t mangle -A Cid43554X5007.1 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid43554X5007.1 -j ACCEPT
+ $IPTABLES -N Cid43554X5007.2 -t mangle
+ $IPTABLES -t mangle -A Cid43554X5007.0 -p ah -j Cid43554X5007.2
+ $IPTABLES -t mangle -A Cid43554X5007.2 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid43554X5007.2 -j ACCEPT
+ #
+ # Rule 9 (eth1)
+ #
+ echo "Rule 9 (eth1)"
+ #
+ $IPTABLES -N Cid43571X5007.0 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -s 22.22.23.22 -j Cid43571X5007.0
+ $IPTABLES -N Cid43571X5007.1 -t mangle
+ $IPTABLES -t mangle -A Cid43571X5007.0 -p 50 -j Cid43571X5007.1
+ $IPTABLES -t mangle -A Cid43571X5007.1 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid43571X5007.1 -j ACCEPT
+ $IPTABLES -N Cid43571X5007.2 -t mangle
+ $IPTABLES -t mangle -A Cid43571X5007.0 -p ah -j Cid43571X5007.2
+ $IPTABLES -t mangle -A Cid43571X5007.2 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid43571X5007.2 -j ACCEPT
+ #
+ # Rule 10 (eth1)
+ #
+ echo "Rule 10 (eth1)"
+ #
+ $IPTABLES -N Cid43588X5007.0 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -p 50 -j Cid43588X5007.0
+ $IPTABLES -t mangle -A Cid43588X5007.0 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid43588X5007.0 -j ACCEPT
+ $IPTABLES -N Cid43588X5007.1 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -p ah -j Cid43588X5007.1
+ $IPTABLES -t mangle -A Cid43588X5007.1 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid43588X5007.1 -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ $IPTABLES -N Cid43BBCC139745.0 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -p 50 -m state --state NEW -j Cid43BBCC139745.0
+ $IPTABLES -t mangle -A OUTPUT -p ah -m state --state NEW -j Cid43BBCC139745.0
+ $IPTABLES -t mangle -A PREROUTING -p 50 -m state --state NEW -j Cid43BBCC139745.0
+ $IPTABLES -t mangle -A PREROUTING -p ah -m state --state NEW -j Cid43BBCC139745.0
+ $IPTABLES -t mangle -A Cid43BBCC139745.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -t mangle -A Cid43BBCC139745.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -N RULE_11_3 -t mangle
+ $IPTABLES -t mangle -A Cid43BBCC139745.0 -j RULE_11_3
+ $IPTABLES -t mangle -A RULE_11_3 -j LOG --log-level info --log-prefix "RULE 11 -- TAG "
+ $IPTABLES -t mangle -A RULE_11_3 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A RULE_11_3 -j ACCEPT
+ #
+ # Rule 12 (eth1)
+ #
+ echo "Rule 12 (eth1)"
+ #
+ $IPTABLES -N Cid4665E24F7765.0 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -i eth1 -p 50 -m state --state NEW -j Cid4665E24F7765.0
+ $IPTABLES -t mangle -A Cid4665E24F7765.0 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid4665E24F7765.0 -j ACCEPT
+ $IPTABLES -N Cid4665E24F7765.1 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -i eth1 -p ah -m state --state NEW -j Cid4665E24F7765.1
+ $IPTABLES -t mangle -A Cid4665E24F7765.1 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid4665E24F7765.1 -j ACCEPT
+ $IPTABLES -N Cid4665E24F7765.2 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -p 50 -m state --state NEW -j Cid4665E24F7765.2
+ $IPTABLES -t mangle -A Cid4665E24F7765.2 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid4665E24F7765.2 -j ACCEPT
+ $IPTABLES -N Cid4665E24F7765.3 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -p ah -m state --state NEW -j Cid4665E24F7765.3
+ $IPTABLES -t mangle -A Cid4665E24F7765.3 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid4665E24F7765.3 -j ACCEPT
+ $IPTABLES -N Cid4665E24F7765.4 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth1 -p 50 -m state --state NEW -j Cid4665E24F7765.4
+ $IPTABLES -t mangle -A Cid4665E24F7765.4 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid4665E24F7765.4 -j ACCEPT
+ $IPTABLES -N Cid4665E24F7765.5 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth1 -p ah -m state --state NEW -j Cid4665E24F7765.5
+ $IPTABLES -t mangle -A Cid4665E24F7765.5 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid4665E24F7765.5 -j ACCEPT
+ #
+ # Rule 13 (eth1)
+ #
+ echo "Rule 13 (eth1)"
+ #
+ $IPTABLES -N Cid43BBCC3D9745.0 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -i eth1 -p 50 -m state --state NEW -j Cid43BBCC3D9745.0
+ $IPTABLES -t mangle -A Cid43BBCC3D9745.0 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid43BBCC3D9745.0 -j ACCEPT
+ $IPTABLES -N Cid43BBCC3D9745.1 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -i eth1 -p ah -m state --state NEW -j Cid43BBCC3D9745.1
+ $IPTABLES -t mangle -A Cid43BBCC3D9745.1 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid43BBCC3D9745.1 -j ACCEPT
+ #
+ # Rule 14 (eth1)
+ #
+ echo "Rule 14 (eth1)"
+ #
+ $IPTABLES -N Cid459E471C10946.0 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -p 50 -m state --state NEW -j Cid459E471C10946.0
+ $IPTABLES -t mangle -A Cid459E471C10946.0 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid459E471C10946.0 -j ACCEPT
+ $IPTABLES -N Cid459E471C10946.1 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -p ah -m state --state NEW -j Cid459E471C10946.1
+ $IPTABLES -t mangle -A Cid459E471C10946.1 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid459E471C10946.1 -j ACCEPT
+ $IPTABLES -N Cid459E471C10946.2 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth1 -p 50 -m state --state NEW -j Cid459E471C10946.2
+ $IPTABLES -t mangle -A Cid459E471C10946.2 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid459E471C10946.2 -j ACCEPT
+ $IPTABLES -N Cid459E471C10946.3 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth1 -p ah -m state --state NEW -j Cid459E471C10946.3
+ $IPTABLES -t mangle -A Cid459E471C10946.3 -j MARK --set-mark 16
+ $IPTABLES -t mangle -A Cid459E471C10946.3 -j ACCEPT
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ # using CONNMARK
+ $IPTABLES -N RULE_15 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -p 50 -m state --state NEW -j RULE_15
+ $IPTABLES -t mangle -A OUTPUT -p ah -m state --state NEW -j RULE_15
+ $IPTABLES -t mangle -A PREROUTING -p 50 -m state --state NEW -j RULE_15
+ $IPTABLES -t mangle -A PREROUTING -p ah -m state --state NEW -j RULE_15
+ $IPTABLES -t mangle -A RULE_15 -j MARK --set-mark 10
+ $IPTABLES -t mangle -A RULE_15 -j CONNMARK --save-mark
+ $IPTABLES -t mangle -A RULE_15 -j ACCEPT
+ #
+ # Rule 16 (global)
+ #
+ echo "Rule 16 (global)"
+ #
+ # using CONNMARK
+ $IPTABLES -N RULE_16 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -p 50 -m state --state NEW -j RULE_16
+ $IPTABLES -t mangle -A OUTPUT -p ah -m state --state NEW -j RULE_16
+ $IPTABLES -t mangle -A PREROUTING -p 50 -m state --state NEW -j RULE_16
+ $IPTABLES -t mangle -A PREROUTING -p ah -m state --state NEW -j RULE_16
+ $IPTABLES -t mangle -A RULE_16 -j LOG --log-level info --log-prefix "RULE 16 -- TAG "
+ $IPTABLES -t mangle -A RULE_16 -j MARK --set-mark 10
+ $IPTABLES -t mangle -A RULE_16 -j CONNMARK --save-mark
+ $IPTABLES -t mangle -A RULE_16 -j ACCEPT
+ #
+ # Rule 17 (global)
+ #
+ echo "Rule 17 (global)"
+ #
+ # using CONNMARK
+ $IPTABLES -N Cid4483A4DF1810.0 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -p 50 -m state --state NEW -j Cid4483A4DF1810.0
+ $IPTABLES -t mangle -A OUTPUT -p ah -m state --state NEW -j Cid4483A4DF1810.0
+ $IPTABLES -t mangle -A PREROUTING -p 50 -m state --state NEW -j Cid4483A4DF1810.0
+ $IPTABLES -t mangle -A PREROUTING -p ah -m state --state NEW -j Cid4483A4DF1810.0
+ $IPTABLES -t mangle -A Cid4483A4DF1810.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -t mangle -A Cid4483A4DF1810.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -N RULE_17 -t mangle
+ $IPTABLES -t mangle -A Cid4483A4DF1810.0 -j RULE_17
+ $IPTABLES -t mangle -A RULE_17 -j LOG --log-level info --log-prefix "RULE 17 -- TAG "
+ $IPTABLES -t mangle -A RULE_17 -j MARK --set-mark 10
+ $IPTABLES -t mangle -A RULE_17 -j CONNMARK --save-mark
+ $IPTABLES -t mangle -A RULE_17 -j ACCEPT
+ #
+ # Rule 18 (eth1)
+ #
+ echo "Rule 18 (eth1)"
+ #
+ # using CONNMARK
+ $IPTABLES -N In_RULE_18 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -i eth1 -p 50 -m state --state NEW -j In_RULE_18
+ $IPTABLES -t mangle -A PREROUTING -i eth1 -p ah -m state --state NEW -j In_RULE_18
+ $IPTABLES -t mangle -A In_RULE_18 -i eth1 -j MARK --set-mark 10
+ $IPTABLES -t mangle -A In_RULE_18 -i eth1 -j CONNMARK --save-mark
+ $IPTABLES -t mangle -A In_RULE_18 -i eth1 -j ACCEPT
+ #
+ # Rule 19 (eth1)
+ #
+ echo "Rule 19 (eth1)"
+ #
+ # using CONNMARK
+ $IPTABLES -N Out_RULE_19 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -p 50 -m state --state NEW -j Out_RULE_19
+ $IPTABLES -t mangle -A OUTPUT -o eth1 -p ah -m state --state NEW -j Out_RULE_19
+ $IPTABLES -t mangle -A POSTROUTING -o eth1 -p 50 -m state --state NEW -j Out_RULE_19
+ $IPTABLES -t mangle -A POSTROUTING -o eth1 -p ah -m state --state NEW -j Out_RULE_19
+ $IPTABLES -t mangle -A Out_RULE_19 -o eth1 -j MARK --set-mark 10
+ $IPTABLES -t mangle -A Out_RULE_19 -o eth1 -j CONNMARK --save-mark
+ $IPTABLES -t mangle -A Out_RULE_19 -o eth1 -j ACCEPT
+ #
+ # Rule 22 (global)
+ #
+ echo "Rule 22 (global)"
+ #
+ $IPTABLES -N Cid43BB81879745.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -s 192.168.1.0/24 -j Cid43BB81879745.0
+ $IPTABLES -t mangle -A Cid43BB81879745.0 -j CLASSIFY --set-class 1:2
+ $IPTABLES -t mangle -A Cid43BB81879745.0 -j ACCEPT
+ #
+ # Rule 23 (global)
+ #
+ echo "Rule 23 (global)"
+ #
+ $IPTABLES -N RULE_23 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -s 192.168.1.0/24 -j RULE_23
+ $IPTABLES -t mangle -A RULE_23 -j LOG --log-level info --log-prefix "RULE 23 -- CLASSIFY "
+ $IPTABLES -t mangle -A RULE_23 -j CLASSIFY --set-class 1:2
+ $IPTABLES -t mangle -A RULE_23 -j ACCEPT
+ #
+ # Rule 24 (global)
+ #
+ echo "Rule 24 (global)"
+ #
+ $IPTABLES -N Cid451E56936383.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -j Cid451E56936383.0
+ $IPTABLES -t mangle -A Cid451E56936383.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -t mangle -A Cid451E56936383.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -t mangle -A Cid451E56936383.0 -j CLASSIFY --set-class 1:2
+ $IPTABLES -t mangle -A Cid451E56936383.0 -j ACCEPT
+ #
+ # Rule 25 (global)
+ #
+ echo "Rule 25 (global)"
+ #
+ $IPTABLES -N Cid451E56A46383.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -j Cid451E56A46383.0
+ $IPTABLES -t mangle -A Cid451E56A46383.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -t mangle -A Cid451E56A46383.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -N RULE_25_3 -t mangle
+ $IPTABLES -t mangle -A Cid451E56A46383.0 -j RULE_25_3
+ $IPTABLES -t mangle -A RULE_25_3 -j LOG --log-level info --log-prefix "RULE 25 -- CLASSIFY "
+ $IPTABLES -t mangle -A RULE_25_3 -j CLASSIFY --set-class 1:2
+ $IPTABLES -t mangle -A RULE_25_3 -j ACCEPT
+ #
+ # Rule 26 (eth1)
+ #
+ echo "Rule 26 (eth1)"
+ #
+ $IPTABLES -N Cid451EAD596383.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j Cid451EAD596383.0
+ $IPTABLES -t mangle -A Cid451EAD596383.0 -j CLASSIFY --set-class 1:2
+ $IPTABLES -t mangle -A Cid451EAD596383.0 -j ACCEPT
+ #
+ # Rule 27 (eth1)
+ #
+ echo "Rule 27 (eth1)"
+ #
+ $IPTABLES -N Out_RULE_27 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j Out_RULE_27
+ $IPTABLES -t mangle -A Out_RULE_27 -j LOG --log-level info --log-prefix "RULE 27 -- CLASSIFY "
+ $IPTABLES -t mangle -A Out_RULE_27 -j CLASSIFY --set-class 1:2
+ $IPTABLES -t mangle -A Out_RULE_27 -j ACCEPT
+ #
+ # Rule 28 (eth1)
+ #
+ echo "Rule 28 (eth1)"
+ #
+ $IPTABLES -N Cid451ED8E76383.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o ! eth1 -s 192.168.1.0/24 -j Cid451ED8E76383.0
+ $IPTABLES -t mangle -A Cid451ED8E76383.0 -j CLASSIFY --set-class 1:2
+ $IPTABLES -t mangle -A Cid451ED8E76383.0 -j ACCEPT
+ #
+ # Rule 29 (eth1)
+ #
+ echo "Rule 29 (eth1)"
+ #
+ $IPTABLES -N Out_RULE_29 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o ! eth1 -s 192.168.1.0/24 -j Out_RULE_29
+ $IPTABLES -t mangle -A Out_RULE_29 -j LOG --log-level info --log-prefix "RULE 29 -- CLASSIFY "
+ $IPTABLES -t mangle -A Out_RULE_29 -j CLASSIFY --set-class 1:2
+ $IPTABLES -t mangle -A Out_RULE_29 -j ACCEPT
+ #
+ # Rule 30 (global)
+ #
+ echo "Rule 30 (global)"
+ #
+ # testing for bug #1618381
+ # classify action is non-terminating
+ # in this firewall object
+ $IPTABLES -N Cid4599A9DC19324.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -p icmp -m icmp --icmp-type 3 -j Cid4599A9DC19324.0
+ $IPTABLES -t mangle -A Cid4599A9DC19324.0 -j CLASSIFY --set-class 1:10
+ $IPTABLES -t mangle -A Cid4599A9DC19324.0 -j ACCEPT
+ #
+ # Rule 31 (eth0)
+ #
+ echo "Rule 31 (eth0)"
+ #
+ # second rule for bug #1618381
+ $IPTABLES -N Cid4599A9E919324.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth0 -j Cid4599A9E919324.0
+ $IPTABLES -t mangle -A Cid4599A9E919324.0 -j CLASSIFY --set-class 1:11
+ $IPTABLES -t mangle -A Cid4599A9E919324.0 -j ACCEPT
+ #
+ # Rule 32 (global)
+ #
+ echo "Rule 32 (global)"
+ #
+ # testing for bug #1618381
+ $IPTABLES -N Cid459A026219324.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -p icmp -m icmp --icmp-type 3 -j Cid459A026219324.0
+ $IPTABLES -t mangle -A Cid459A026219324.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -t mangle -A Cid459A026219324.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -t mangle -A Cid459A026219324.0 -j CLASSIFY --set-class 1:10
+ $IPTABLES -t mangle -A Cid459A026219324.0 -j ACCEPT
+ #
+ # Rule 33 (global)
+ #
+ echo "Rule 33 (global)"
+ #
+ # testing for bug #1618381
+ $IPTABLES -N Cid459A5AFB19324.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -p icmp -m icmp --icmp-type 3 -j Cid459A5AFB19324.0
+ $IPTABLES -t mangle -A POSTROUTING -p tcp -m tcp --dport 80 -j Cid459A5AFB19324.0
+ $IPTABLES -t mangle -A Cid459A5AFB19324.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -t mangle -A Cid459A5AFB19324.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -t mangle -A Cid459A5AFB19324.0 -j CLASSIFY --set-class 1:10
+ $IPTABLES -t mangle -A Cid459A5AFB19324.0 -j ACCEPT
+ #
+ # Rule 34 (eth0)
+ #
+ echo "Rule 34 (eth0)"
+ #
+ # bug #1618381
+ # this rule uses multiport
+ # and has to be split because
+ # of that
+ $IPTABLES -N Cid459A875F19324.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth0 -p tcp -m tcp --dport 10000:11000 -j Cid459A875F19324.0
+ $IPTABLES -t mangle -A Cid459A875F19324.0 -j CLASSIFY --set-class 1:11
+ $IPTABLES -t mangle -A Cid459A875F19324.0 -j ACCEPT
+ $IPTABLES -N Cid459A875F19324.1 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth0 -p tcp -m tcp -m multiport --dports 6667,3128,113,53,21,80,119,25,22,23,540,70,13,2105,443 -j Cid459A875F19324.1
+ $IPTABLES -t mangle -A Cid459A875F19324.1 -j CLASSIFY --set-class 1:11
+ $IPTABLES -t mangle -A Cid459A875F19324.1 -j ACCEPT
+ $IPTABLES -N Cid459A875F19324.2 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o eth0 -p udp -m udp -m multiport --dports 53,161 -j Cid459A875F19324.2
+ $IPTABLES -t mangle -A Cid459A875F19324.2 -j CLASSIFY --set-class 1:11
+ $IPTABLES -t mangle -A Cid459A875F19324.2 -j ACCEPT
+ #
+ # Rule 36 (global)
+ #
+ echo "Rule 36 (global)"
+ #
+ $IPTABLES -N RULE_36 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -j RULE_36
+ $IPTABLES -t mangle -A RULE_36 -j LOG --log-level info --log-prefix "RULE 36 -- BRANCH "
+ $IPTABLES -t mangle -A RULE_36 -j mymark
+ $IPTABLES -t mangle -A POSTROUTING -j RULE_36
+ $IPTABLES -t mangle -A FORWARD -j RULE_36
+ # ================ Table 'mangle', rule set mangle_rules
+ #
+ # Rule mangle_rules 0 (global)
+ #
+ echo "Rule mangle_rules 0 (global)"
+ #
+ $IPTABLES -t mangle -A OUTPUT -m mark ! --mark 0 -m state --state NEW -j ACCEPT
+ $IPTABLES -t mangle -A INPUT -m mark ! --mark 0 -m state --state NEW -j ACCEPT
+ $IPTABLES -t mangle -A PREROUTING -m mark ! --mark 0 -m state --state NEW -j ACCEPT
+ #
+ # Rule mangle_rules 1 (global)
+ #
+ echo "Rule mangle_rules 1 (global)"
+ #
+ $IPTABLES -N mangle_rules_1 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -p tcp -m tcp --dport 80 -m state --state NEW -j mangle_rules_1
+ $IPTABLES -t mangle -A PREROUTING -p tcp -m tcp --dport 80 -m state --state NEW -j mangle_rules_1
+ $IPTABLES -t mangle -A mangle_rules_1 -j MARK --set-mark 1
+ $IPTABLES -t mangle -A mangle_rules_1 -j CONNMARK --save-mark
+ $IPTABLES -t mangle -A mangle_rules_1 -j ACCEPT
+ #
+ # Rule mangle_rules 2 (global)
+ #
+ echo "Rule mangle_rules 2 (global)"
+ #
+ $IPTABLES -N Cid56817X29169.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -m mark --mark 1 -j Cid56817X29169.0
+ $IPTABLES -t mangle -A Cid56817X29169.0 -j CLASSIFY --set-class 1:12
+ $IPTABLES -t mangle -A Cid56817X29169.0 -j ACCEPT
+ #
+ # Rule mangle_rules 4 (global)
+ #
+ echo "Rule mangle_rules 4 (global)"
+ #
+ # firewall37:mangle_rules:4: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ $IPTABLES -t mangle -A INPUT -s 192.0.2.1 -m mark --mark 1 -m state --state NEW -j ACCEPT
+ # firewall37:mangle_rules:4: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ $IPTABLES -t mangle -A PREROUTING -s 192.0.2.1 -m mark --mark 1 -m state --state NEW -j ACCEPT
+ #
+ # Rule mangle_rules 5 (global)
+ #
+ echo "Rule mangle_rules 5 (global)"
+ #
+ $IPTABLES -t mangle -A INPUT -s 6bone.net -m mark --mark 1 -m state --state NEW -j ACCEPT
+ $IPTABLES -t mangle -A PREROUTING -s 6bone.net -m mark --mark 1 -m state --state NEW -j ACCEPT
+ #
+ # Rule mangle_rules 6 (global)
+ #
+ echo "Rule mangle_rules 6 (global)"
+ #
+ $IPTABLES -N Cid122277X13558.0 -t mangle
+ $IPTABLES -t mangle -A INPUT -m mark --mark 1 -m state --state NEW -j Cid122277X13558.0
+ $IPTABLES -t mangle -A Cid122277X13558.0 -s 6bone.net -j ACCEPT
+ $IPTABLES -t mangle -A Cid122277X13558.0 -s ny6ix.net -j ACCEPT
+ $IPTABLES -N Cid122277X13558.1 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -m mark --mark 1 -m state --state NEW -j Cid122277X13558.1
+ $IPTABLES -t mangle -A Cid122277X13558.1 -s 6bone.net -j ACCEPT
+ $IPTABLES -t mangle -A Cid122277X13558.1 -s ny6ix.net -j ACCEPT
+ #
+ # Rule mangle_rules 8 (global)
+ #
+ echo "Rule mangle_rules 8 (global)"
+ #
+ $IPTABLES -t mangle -A OUTPUT -m mark --mark 1 -m state --state NEW -j ACCEPT
+ #
+ # Rule mangle_rules 9 (global)
+ #
+ echo "Rule mangle_rules 9 (global)"
+ #
+ $IPTABLES -t mangle -A OUTPUT -s 22.22.23.22 -m mark --mark 1 -m state --state NEW -j ACCEPT
+ #
+ # Rule mangle_rules 10 (global)
+ #
+ echo "Rule mangle_rules 10 (global)"
+ #
+ $IPTABLES -N Cid207332X13558.0 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -m mark --mark 1 -m state --state NEW -j Cid207332X13558.0
+ $IPTABLES -t mangle -A Cid207332X13558.0 -d 22.22.23.22 -j ACCEPT
+ $IPTABLES -t mangle -A Cid207332X13558.0 -d 192.168.1.22 -j ACCEPT
+ $IPTABLES -t mangle -A Cid207332X13558.0 -d 192.168.2.1 -j ACCEPT
+ $IPTABLES -t mangle -A INPUT -m mark --mark 1 -m state --state NEW -j ACCEPT
+ #
+ # Rule mangle_rules 11 (global)
+ #
+ echo "Rule mangle_rules 11 (global)"
+ #
+ $IPTABLES -t mangle -A PREROUTING -i + -s ! 192.168.1.0/24 -m mark --mark 1 -m state --state NEW -j ACCEPT
+ #
+ # Rule mangle_rules 12 (global)
+ #
+ echo "Rule mangle_rules 12 (global)"
+ #
+ $IPTABLES -t mangle -A PREROUTING -i + -s ! 1.1.1.1 -m mark --mark 1 -m state --state NEW -j ACCEPT
+ #
+ # Rule mangle_rules 13 (global)
+ #
+ echo "Rule mangle_rules 13 (global)"
+ #
+ $IPTABLES -N Cid480281X13558.0 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -i + -m mark --mark 1 -m state --state NEW -j Cid480281X13558.0
+ # firewall37:mangle_rules:13: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
+ $IPTABLES -t mangle -A Cid480281X13558.0 -i + -s 192.0.2.1 -j RETURN
+ $IPTABLES -t mangle -A Cid480281X13558.0 -i + -j ACCEPT
+ #
+ # Rule mangle_rules 14 (global)
+ #
+ echo "Rule mangle_rules 14 (global)"
+ #
+ $IPTABLES -N Cid480300X13558.0 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -i + -m mark --mark 1 -m state --state NEW -j Cid480300X13558.0
+ $IPTABLES -t mangle -A Cid480300X13558.0 -i + -s 6bone.net -j RETURN
+ $IPTABLES -t mangle -A Cid480300X13558.0 -i + -j ACCEPT
+ #
+ # Rule mangle_rules 15 (global)
+ #
+ echo "Rule mangle_rules 15 (global)"
+ #
+ # rules in mangle-only ruleset with action
+ # Accept normally go to PREROUTING,
+ # but if direction is set to outbound,
+ # they go to POSTROUTING. This is just
+ # a convention since there is no better
+ # criteria as to how to tell the compiler
+ # that such rule should be placed in
+ # POSTROUTING.
+ $IPTABLES -N Cid43052X80179.0 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -o + -m mark --mark 1 -m state --state NEW -j Cid43052X80179.0
+ $IPTABLES -t mangle -A Cid43052X80179.0 -s 6bone.net -j ACCEPT
+ $IPTABLES -t mangle -A Cid43052X80179.0 -s ny6ix.net -j ACCEPT
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 20 (global)
+ #
+ echo "Rule 20 (global)"
+ #
+ # tag 0 matches packet that has not been marked yet.
+ $IPTABLES -A OUTPUT -m mark ! --mark 0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -m mark ! --mark 0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -m mark ! --mark 0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 21 (global)
+ #
+ echo "Rule 21 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.2.10 --dport 80 -j QUEUE
+ $IPTABLES -A FORWARD -p tcp -m tcp -d 192.168.2.10 --dport 80 -j QUEUE
+ #
+ # Rule 35 (global)
+ #
+ echo "Rule 35 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -j TCPMSS --set-mss 1400
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -j TCPMSS --set-mss 1400
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -j TCPMSS --set-mss 1400
+ #
+ # Rule 36 (global)
+ #
+ echo "Rule 36 (global)"
+ #
+ $IPTABLES -N RULE_36
+ $IPTABLES -A OUTPUT -j RULE_36
+ $IPTABLES -A INPUT -j RULE_36
+ $IPTABLES -A FORWARD -j RULE_36
+ $IPTABLES -A RULE_36 -j LOG --log-level info --log-prefix "RULE 36 -- BRANCH "
+ $IPTABLES -N mymark
+ $IPTABLES -A RULE_36 -j mymark
+ #
+ # Rule 37 (global)
+ #
+ echo "Rule 37 (global)"
+ #
+ $IPTABLES -N RULE_37
+ $IPTABLES -A OUTPUT -j RULE_37
+ $IPTABLES -A INPUT -j RULE_37
+ $IPTABLES -A FORWARD -j RULE_37
+ $IPTABLES -A RULE_37 -j LOG --log-level info --log-prefix "RULE 37 -- DENY "
+ $IPTABLES -A RULE_37 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:55:05 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall38.fw.orig b/test/ipt/firewall38.fw.orig
new file mode 100755
index 000000000..879a8a2c6
--- /dev/null
+++ b/test/ipt/firewall38.fw.orig
@@ -0,0 +1,558 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:09 2011 PST by vadim
+#
+# files: * firewall38.fw
+#
+# Compiled for iptables 1.3.0
+#
+# testing TAG rules
+
+# using iptables-restore
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IPTABLES_RESTORE
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.22/24" ""
+ update_addresses_of_interface "eth1 22.22.23.22/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 9 (global)
+ echo "-A OUTPUT -m mark --mark 16 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -m mark --mark 16 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -m mark --mark 16 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 10 (global)
+ echo "-A OUTPUT -m mark ! --mark 16 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -m mark ! --mark 16 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -m mark ! --mark 16 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 11 (global)
+ echo "-A OUTPUT -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -m mark --mark 16 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT "
+ echo "-A INPUT -m mark --mark 16 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -m mark --mark 16 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 12 (global)
+ echo ":Cid43EC87C832486.0 - [0:0]"
+ echo "-A OUTPUT -m state --state NEW -j Cid43EC87C832486.0 "
+ echo "-A INPUT -m state --state NEW -j Cid43EC87C832486.0 "
+ echo "-A FORWARD -m state --state NEW -j Cid43EC87C832486.0 "
+ echo "-A Cid43EC87C832486.0 -p tcp -m tcp --dport 80 -j RETURN "
+ echo "-A Cid43EC87C832486.0 -m mark --mark 16 -j RETURN "
+ echo "-A Cid43EC87C832486.0 -j ACCEPT "
+ #
+ # Rule 13 (global)
+ echo "-A OUTPUT -p tcp -m tcp -d 192.168.2.10 --dport 80 -j QUEUE "
+ echo "-A FORWARD -p tcp -m tcp -d 192.168.2.10 --dport 80 -j QUEUE "
+ #
+ # Rule 14 (global)
+ echo "-A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT "
+ echo "-A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT "
+ echo "-A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT "
+ #
+ # Rule 15 (global)
+ echo ":RULE_15 - [0:0]"
+ echo "-A OUTPUT -j RULE_15 "
+ echo "-A INPUT -j RULE_15 "
+ echo "-A FORWARD -j RULE_15 "
+ echo "-A RULE_15 -j LOG --log-level info --log-prefix \"RULE 15 -- DENY \""
+ echo "-A RULE_15 -j DROP "
+ #
+ echo COMMIT
+
+
+ echo '*mangle'
+ # ================ Table 'mangle', automatic rules
+ echo "-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu"
+ # ================ Table 'mangle', rule set Policy
+ #
+ # Rule 0 (global)
+ echo "-A OUTPUT -p 50 -m state --state NEW -j MARK --set-mark 16"
+ echo "-A OUTPUT -p ah -m state --state NEW -j MARK --set-mark 16"
+ echo "-A PREROUTING -p 50 -m state --state NEW -j MARK --set-mark 16"
+ echo "-A PREROUTING -p ah -m state --state NEW -j MARK --set-mark 16"
+ #
+ # Rule 1 (global)
+ echo ":RULE_1 - [0:0]"
+ echo "-A OUTPUT -p 50 -m state --state NEW -j RULE_1 "
+ echo "-A OUTPUT -p ah -m state --state NEW -j RULE_1 "
+ echo "-A PREROUTING -p 50 -m state --state NEW -j RULE_1 "
+ echo "-A PREROUTING -p ah -m state --state NEW -j RULE_1 "
+ echo "-A RULE_1 -j LOG --log-level info --log-prefix \"RULE 1 -- TAG \""
+ echo "-A RULE_1 -j MARK --set-mark 16"
+ #
+ # Rule 2 (global)
+ echo ":Cid43BBF1AD9745.0 - [0:0]"
+ echo "-A OUTPUT -s ! 192.168.1.0/24 -m state --state NEW -j Cid43BBF1AD9745.0 "
+ echo ":RULE_2 - [0:0]"
+ echo "-A Cid43BBF1AD9745.0 -p 50 -j RULE_2 "
+ echo "-A Cid43BBF1AD9745.0 -p ah -j RULE_2 "
+ echo ":Cid43BBF1AD9745.1 - [0:0]"
+ echo "-A PREROUTING -s ! 192.168.1.0/24 -m state --state NEW -j Cid43BBF1AD9745.1 "
+ echo "-A Cid43BBF1AD9745.1 -p 50 -j RULE_2 "
+ echo "-A Cid43BBF1AD9745.1 -p ah -j RULE_2 "
+ echo "-A RULE_2 -j LOG --log-level info --log-prefix \"RULE 2 -- TAG \""
+ echo "-A RULE_2 -j MARK --set-mark 16"
+ #
+ # Rule 3 (eth1)
+ echo "-A PREROUTING -i eth1 -p 50 -m state --state NEW -j MARK --set-mark 16"
+ echo "-A PREROUTING -i eth1 -p ah -m state --state NEW -j MARK --set-mark 16"
+ #
+ # Rule 4 (global)
+ # rule comment: rule 4
+ echo "-A OUTPUT -p tcp -m tcp --dport 80 -m state --state NEW -j MARK --set-mark 2"
+ #
+ # Rule 5 (global)
+ echo ":RULE_5 - [0:0]"
+ echo "-A OUTPUT -p tcp -m tcp -s 22.22.23.22 --dport 80 -m state --state NEW -j RULE_5 "
+ echo "-A RULE_5 -j LOG --log-level info --log-prefix \"RULE 5 -- TAG \""
+ echo "-A RULE_5 -j MARK --set-mark 2"
+ #
+ # Rule 6 (eth1)
+ echo "-A OUTPUT -o eth1 -p tcp -m tcp -s 22.22.23.22 --dport 80 -m state --state NEW -j MARK --set-mark 2"
+ #
+ # Rule 7 (eth1)
+ echo "-A PREROUTING -i eth1 -p tcp -m tcp -s 22.22.23.22 --dport 80 -m state --state NEW -j MARK --set-mark 2"
+ #
+ # Rule 8 (eth1)
+ echo ":Cid462EA8B230547.0 - [0:0]"
+ echo "-A OUTPUT -o eth1 -p tcp -m tcp --dport 80 -m state --state NEW -j Cid462EA8B230547.0 "
+ echo "-A Cid462EA8B230547.0 -s 22.22.23.22 -j RETURN "
+ echo "-A Cid462EA8B230547.0 -j MARK --set-mark 2"
+ echo "-A POSTROUTING -o eth1 -p tcp -m tcp --dport 80 -m state --state NEW -j MARK --set-mark 2"
+ #
+ echo COMMIT
+
+
+ echo '*nat'
+ # ================ Table 'nat', rule set NAT
+ echo :PREROUTING ACCEPT [0:0]
+ echo :POSTROUTING ACCEPT [0:0]
+ echo :OUTPUT ACCEPT [0:0]
+ #
+ # Rule 0 (NAT)
+ echo "-A POSTROUTING -o eth1 -s 22.22.23.22 -j SNAT --to-source 22.22.23.22 "
+ echo "-A POSTROUTING -o eth1 -s 192.168.1.22 -j SNAT --to-source 22.22.23.22 "
+ echo "-A POSTROUTING -o eth1 -s 192.168.2.1 -j SNAT --to-source 22.22.23.22 "
+ echo "-A POSTROUTING -o eth1 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.22 "
+ #
+ # Rule 1 (NAT)
+ echo "-A POSTROUTING -o eth1 -s 192.168.1.0/24 -m mark --mark 16 -j SNAT --to-source 22.22.23.22 "
+ #
+ echo COMMIT
+
+
+ ) | $IPTABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:55:09 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall39.fw.orig b/test/ipt/firewall39.fw.orig
new file mode 100755
index 000000000..75fdcd766
--- /dev/null
+++ b/test/ipt/firewall39.fw.orig
@@ -0,0 +1,936 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:16 2011 PST by vadim
+#
+# files: * firewall39.fw
+#
+# Compiled for iptables (any version)
+#
+# testing branching rules
+
+# normal script mode (not using iptables-restore)
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.22/24" ""
+ update_addresses_of_interface "eth1 22.22.23.22/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -s 22.22.23.22 -j ACCEPT
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.22 -j ACCEPT
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.2.1 -j ACCEPT
+ $IPTABLES -t nat -A OUTPUT -j ACCEPT
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.0/24 -j ACCEPT
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.0/24 -j ACCEPT
+
+ # ================ Table 'mangle', rule set rule0_branch
+ #
+ # Rule rule0_branch 0 (global)
+ #
+ echo "Rule rule0_branch 0 (global)"
+ #
+ $IPTABLES -N rule0_branch -t mangle
+ $IPTABLES -N rule0_branch_0 -t mangle
+ $IPTABLES -t mangle -A rule0_branch -m state --state NEW -j rule0_branch_0
+ $IPTABLES -t mangle -A rule0_branch_0 -j LOG --log-level info --log-prefix "RULE 0 -- ACCEPT "
+ $IPTABLES -t mangle -A rule0_branch_0 -j ACCEPT
+ # ================ Table 'mangle', rule set rule1_branch
+ #
+ # Rule rule1_branch 0 (global)
+ #
+ echo "Rule rule1_branch 0 (global)"
+ #
+ $IPTABLES -N rule1_branch -t mangle
+ $IPTABLES -N rule1_branch_0 -t mangle
+ $IPTABLES -t mangle -A rule1_branch -d 192.168.2.10 -j rule1_branch_0
+ $IPTABLES -t mangle -A rule1_branch_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -t mangle -A rule1_branch_0 -j DROP
+ #
+ # Rule rule1_branch 1 (global)
+ #
+ echo "Rule rule1_branch 1 (global)"
+ #
+ $IPTABLES -t mangle -A rule1_branch -m state --state NEW -j ACCEPT
+ # ================ Table 'mangle', rule set rule2_branch
+ #
+ # Rule rule2_branch 0 (global)
+ #
+ echo "Rule rule2_branch 0 (global)"
+ #
+ $IPTABLES -N rule2_branch -t mangle
+ $IPTABLES -N rule2_branch_0 -t mangle
+ $IPTABLES -t mangle -A rule2_branch -d ! 192.168.2.10 -j rule2_branch_0
+ $IPTABLES -t mangle -A rule2_branch_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -t mangle -A rule2_branch_0 -j DROP
+ #
+ # Rule rule2_branch 1 (global)
+ #
+ echo "Rule rule2_branch 1 (global)"
+ #
+ $IPTABLES -t mangle -A rule2_branch -s 222.222.222.0/24 -d 192.168.2.10 -m state --state NEW -j ACCEPT
+ #
+ # Rule rule2_branch 2 (global)
+ #
+ echo "Rule rule2_branch 2 (global)"
+ #
+ $IPTABLES -N rule2_branch_2 -t mangle
+ $IPTABLES -t mangle -A rule2_branch -j rule2_branch_2
+ $IPTABLES -t mangle -A rule2_branch_2 -j LOG --log-level info --log-prefix "RULE 2 -- DENY "
+ $IPTABLES -t mangle -A rule2_branch_2 -j DROP
+ # ================ Table 'mangle', rule set rule3_branch
+ #
+ # Rule rule3_branch 0 (eth1)
+ #
+ echo "Rule rule3_branch 0 (eth1)"
+ #
+ $IPTABLES -N rule3_branch -t mangle
+ $IPTABLES -t mangle -A rule3_branch -i eth1 -d 22.22.23.22 -m state --state NEW -j ACCEPT
+ $IPTABLES -t mangle -A rule3_branch -i eth1 -d 192.168.1.22 -m state --state NEW -j ACCEPT
+ $IPTABLES -t mangle -A rule3_branch -i eth1 -d 192.168.2.1 -m state --state NEW -j ACCEPT
+ #
+ # Rule rule3_branch 1 (global)
+ #
+ echo "Rule rule3_branch 1 (global)"
+ #
+ $IPTABLES -N rule3_branch_1 -t mangle
+ $IPTABLES -t mangle -A rule3_branch -j rule3_branch_1
+ $IPTABLES -t mangle -A rule3_branch_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -t mangle -A rule3_branch_1 -j DROP
+ # ================ Table 'mangle', rule set rule4_branch
+ #
+ # Rule rule4_branch 0 (eth1)
+ #
+ echo "Rule rule4_branch 0 (eth1)"
+ #
+ $IPTABLES -N rule4_branch -t mangle
+ $IPTABLES -N In_rule4_branch_0 -t mangle
+ $IPTABLES -t mangle -A rule4_branch -i eth1 -j In_rule4_branch_0
+ $IPTABLES -t mangle -A In_rule4_branch_0 -j LOG --log-level info --log-prefix "RULE 0 -- BRANCH "
+ $IPTABLES -N rule_4_0_branch -t mangle
+ $IPTABLES -t mangle -A In_rule4_branch_0 -j rule_4_0_branch
+ #
+ # Rule rule4_branch 1 (eth0)
+ #
+ echo "Rule rule4_branch 1 (eth0)"
+ #
+ $IPTABLES -N In_rule4_branch_1 -t mangle
+ $IPTABLES -t mangle -A rule4_branch -i eth0 -j In_rule4_branch_1
+ $IPTABLES -t mangle -A In_rule4_branch_1 -j LOG --log-level info --log-prefix "RULE 1 -- BRANCH "
+ $IPTABLES -N rule_4_1_branch -t mangle
+ $IPTABLES -t mangle -A In_rule4_branch_1 -j rule_4_1_branch
+ # ================ Table 'mangle', rule set Policy
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ # green rules branch
+ # also in mangle table
+ $IPTABLES -t mangle -A PREROUTING -p 50 -j rule0_branch
+ $IPTABLES -t mangle -A PREROUTING -p ah -j rule0_branch
+ $IPTABLES -t mangle -A POSTROUTING -p 50 -j rule0_branch
+ $IPTABLES -t mangle -A POSTROUTING -p ah -j rule0_branch
+ $IPTABLES -t mangle -A FORWARD -p 50 -j rule0_branch
+ $IPTABLES -t mangle -A FORWARD -p ah -j rule0_branch
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -N RULE_8 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -p 50 -j RULE_8
+ $IPTABLES -t mangle -A PREROUTING -p ah -j RULE_8
+ $IPTABLES -t mangle -A RULE_8 -j LOG --log-level info --log-prefix "RULE 8 -- BRANCH "
+ $IPTABLES -t mangle -A RULE_8 -j rule1_branch
+ $IPTABLES -t mangle -A POSTROUTING -p 50 -j RULE_8
+ $IPTABLES -t mangle -A POSTROUTING -p ah -j RULE_8
+ $IPTABLES -t mangle -A FORWARD -p 50 -j RULE_8
+ $IPTABLES -t mangle -A FORWARD -p ah -j RULE_8
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -N Cid464C29BB3999.0 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -s ! 192.168.1.0/24 -j Cid464C29BB3999.0
+ $IPTABLES -N RULE_9 -t mangle
+ $IPTABLES -t mangle -A Cid464C29BB3999.0 -p 50 -j RULE_9
+ $IPTABLES -t mangle -A Cid464C29BB3999.0 -p ah -j RULE_9
+ $IPTABLES -t mangle -A RULE_9 -j LOG --log-level info --log-prefix "RULE 9 -- BRANCH "
+ $IPTABLES -t mangle -A RULE_9 -j rule2_branch
+ $IPTABLES -N Cid464C29BB3999.1 -t mangle
+ $IPTABLES -t mangle -A POSTROUTING -s ! 192.168.1.0/24 -j Cid464C29BB3999.1
+ $IPTABLES -t mangle -A Cid464C29BB3999.1 -p 50 -j RULE_9
+ $IPTABLES -t mangle -A Cid464C29BB3999.1 -p ah -j RULE_9
+ $IPTABLES -N Cid464C29BB3999.2 -t mangle
+ $IPTABLES -t mangle -A FORWARD -s ! 192.168.1.0/24 -j Cid464C29BB3999.2
+ $IPTABLES -t mangle -A Cid464C29BB3999.2 -p 50 -j RULE_9
+ $IPTABLES -t mangle -A Cid464C29BB3999.2 -p ah -j RULE_9
+ #
+ # Rule 10 (eth1)
+ #
+ echo "Rule 10 (eth1)"
+ #
+ $IPTABLES -t mangle -A PREROUTING -i eth1 -p 50 -j rule3_branch
+ $IPTABLES -t mangle -A PREROUTING -i eth1 -p ah -j rule3_branch
+ $IPTABLES -t mangle -A FORWARD -i eth1 -p 50 -j rule3_branch
+ $IPTABLES -t mangle -A FORWARD -i eth1 -p ah -j rule3_branch
+ #
+ # Rule 11 (eth1)
+ #
+ echo "Rule 11 (eth1)"
+ #
+ $IPTABLES -t mangle -A POSTROUTING -o eth1 -p 50 -j rule3_branch
+ $IPTABLES -t mangle -A POSTROUTING -o eth1 -p ah -j rule3_branch
+ $IPTABLES -t mangle -A FORWARD -o eth1 -p 50 -j rule3_branch
+ $IPTABLES -t mangle -A FORWARD -o eth1 -p ah -j rule3_branch
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ $IPTABLES -t mangle -A PREROUTING -p tcp -m tcp -d 192.168.2.10 --dport 80 -j rule4_branch
+ $IPTABLES -t mangle -A POSTROUTING -p tcp -m tcp -d 192.168.2.10 --dport 80 -j rule4_branch
+ $IPTABLES -t mangle -A FORWARD -p tcp -m tcp -d 192.168.2.10 --dport 80 -j rule4_branch
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ $IPTABLES -N rule5_branch -t mangle
+ $IPTABLES -t mangle -A PREROUTING -s 192.168.1.0/24 -j rule5_branch
+ $IPTABLES -t mangle -A POSTROUTING -s 192.168.1.0/24 -j rule5_branch
+ $IPTABLES -t mangle -A FORWARD -s 192.168.1.0/24 -j rule5_branch
+
+ # ================ Table 'filter', rule set rule_4_0_branch
+ #
+ # Rule rule_4_0_branch 0 (eth2)
+ #
+ echo "Rule rule_4_0_branch 0 (eth2)"
+ #
+ $IPTABLES -N rule_4_0_branch
+ $IPTABLES -A rule_4_0_branch -o eth2 -m state --state NEW -j ACCEPT
+ #
+ # Rule rule_4_0_branch 1 (global)
+ #
+ echo "Rule rule_4_0_branch 1 (global)"
+ #
+ $IPTABLES -N rule_4_0_branch_1
+ $IPTABLES -A rule_4_0_branch -j rule_4_0_branch_1
+ $IPTABLES -A rule_4_0_branch_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A rule_4_0_branch_1 -j DROP
+ # ================ Table 'filter', rule set rule_4_1_branch
+ #
+ # Rule rule_4_1_branch 0 (eth2)
+ #
+ echo "Rule rule_4_1_branch 0 (eth2)"
+ #
+ $IPTABLES -N rule_4_1_branch
+ $IPTABLES -A rule_4_1_branch -o eth2 -m state --state NEW -j ACCEPT
+ #
+ # Rule rule_4_1_branch 1 (global)
+ #
+ echo "Rule rule_4_1_branch 1 (global)"
+ #
+ $IPTABLES -N rule_4_1_branch_1
+ $IPTABLES -A rule_4_1_branch -j rule_4_1_branch_1
+ $IPTABLES -A rule_4_1_branch_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A rule_4_1_branch_1 -j DROP
+ # ================ Table 'filter', rule set rule0_branch
+ #
+ # Rule rule0_branch 0 (global)
+ #
+ echo "Rule rule0_branch 0 (global)"
+ #
+ $IPTABLES -N rule0_branch
+ $IPTABLES -N rule0_branch_0
+ $IPTABLES -A rule0_branch -m state --state NEW -j rule0_branch_0
+ $IPTABLES -A rule0_branch_0 -j LOG --log-level info --log-prefix "RULE 0 -- ACCEPT "
+ $IPTABLES -A rule0_branch_0 -j ACCEPT
+ # ================ Table 'filter', rule set rule1_branch
+ #
+ # Rule rule1_branch 0 (global)
+ #
+ echo "Rule rule1_branch 0 (global)"
+ #
+ $IPTABLES -N rule1_branch
+ $IPTABLES -N rule1_branch_0
+ $IPTABLES -A rule1_branch -d 192.168.2.10 -j rule1_branch_0
+ $IPTABLES -A rule1_branch_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A rule1_branch_0 -j DROP
+ #
+ # Rule rule1_branch 1 (global)
+ #
+ echo "Rule rule1_branch 1 (global)"
+ #
+ $IPTABLES -A rule1_branch -m state --state NEW -j ACCEPT
+ # ================ Table 'filter', rule set rule2_branch
+ #
+ # Rule rule2_branch 0 (global)
+ #
+ echo "Rule rule2_branch 0 (global)"
+ #
+ $IPTABLES -N rule2_branch
+ $IPTABLES -N rule2_branch_0
+ $IPTABLES -A rule2_branch -d ! 192.168.2.10 -j rule2_branch_0
+ $IPTABLES -A rule2_branch_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A rule2_branch_0 -j DROP
+ #
+ # Rule rule2_branch 1 (global)
+ #
+ echo "Rule rule2_branch 1 (global)"
+ #
+ $IPTABLES -A rule2_branch -s 222.222.222.0/24 -d 192.168.2.10 -m state --state NEW -j ACCEPT
+ #
+ # Rule rule2_branch 2 (global)
+ #
+ echo "Rule rule2_branch 2 (global)"
+ #
+ $IPTABLES -N rule2_branch_2
+ $IPTABLES -A rule2_branch -j rule2_branch_2
+ $IPTABLES -A rule2_branch_2 -j LOG --log-level info --log-prefix "RULE 2 -- DENY "
+ $IPTABLES -A rule2_branch_2 -j DROP
+ # ================ Table 'filter', rule set rule3_branch
+ #
+ # Rule rule3_branch 0 (eth1)
+ #
+ echo "Rule rule3_branch 0 (eth1)"
+ #
+ $IPTABLES -N rule3_branch
+ $IPTABLES -A rule3_branch -i eth1 -d 22.22.23.22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A rule3_branch -i eth1 -d 192.168.1.22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A rule3_branch -i eth1 -d 192.168.2.1 -m state --state NEW -j ACCEPT
+ #
+ # Rule rule3_branch 1 (global)
+ #
+ echo "Rule rule3_branch 1 (global)"
+ #
+ $IPTABLES -N rule3_branch_1
+ $IPTABLES -A rule3_branch -j rule3_branch_1
+ $IPTABLES -A rule3_branch_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A rule3_branch_1 -j DROP
+ # ================ Table 'filter', rule set rule4_branch
+ #
+ # Rule rule4_branch 0 (eth1)
+ #
+ echo "Rule rule4_branch 0 (eth1)"
+ #
+ $IPTABLES -N rule4_branch
+ $IPTABLES -N In_rule4_branch_0
+ $IPTABLES -A rule4_branch -i eth1 -j In_rule4_branch_0
+ $IPTABLES -A In_rule4_branch_0 -j LOG --log-level info --log-prefix "RULE 0 -- BRANCH "
+ $IPTABLES -A In_rule4_branch_0 -j rule_4_0_branch
+ #
+ # Rule rule4_branch 1 (eth0)
+ #
+ echo "Rule rule4_branch 1 (eth0)"
+ #
+ $IPTABLES -N In_rule4_branch_1
+ $IPTABLES -A rule4_branch -i eth0 -j In_rule4_branch_1
+ $IPTABLES -A In_rule4_branch_1 -j LOG --log-level info --log-prefix "RULE 1 -- BRANCH "
+ $IPTABLES -A In_rule4_branch_1 -j rule_4_1_branch
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -A OUTPUT -p 50 -j rule0_branch
+ $IPTABLES -A OUTPUT -p ah -j rule0_branch
+ $IPTABLES -A INPUT -p 50 -j rule0_branch
+ $IPTABLES -A INPUT -p ah -j rule0_branch
+ $IPTABLES -A FORWARD -p 50 -j rule0_branch
+ $IPTABLES -A FORWARD -p ah -j rule0_branch
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -N RULE_1
+ $IPTABLES -A OUTPUT -p 50 -j RULE_1
+ $IPTABLES -A OUTPUT -p ah -j RULE_1
+ $IPTABLES -A INPUT -p 50 -j RULE_1
+ $IPTABLES -A INPUT -p ah -j RULE_1
+ $IPTABLES -A FORWARD -p 50 -j RULE_1
+ $IPTABLES -A FORWARD -p ah -j RULE_1
+ $IPTABLES -A RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- BRANCH "
+ $IPTABLES -A RULE_1 -j rule1_branch
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -N Cid445DA31230753.0
+ $IPTABLES -A OUTPUT -s ! 192.168.1.0/24 -j Cid445DA31230753.0
+ $IPTABLES -N RULE_2
+ $IPTABLES -A Cid445DA31230753.0 -p 50 -j RULE_2
+ $IPTABLES -A Cid445DA31230753.0 -p ah -j RULE_2
+ $IPTABLES -N Cid445DA31230753.1
+ $IPTABLES -A INPUT -s ! 192.168.1.0/24 -j Cid445DA31230753.1
+ $IPTABLES -A Cid445DA31230753.1 -p 50 -j RULE_2
+ $IPTABLES -A Cid445DA31230753.1 -p ah -j RULE_2
+ $IPTABLES -N Cid445DA31230753.2
+ $IPTABLES -A OUTPUT -s ! 192.168.1.0/24 -j Cid445DA31230753.2
+ $IPTABLES -A Cid445DA31230753.2 -p 50 -j RULE_2
+ $IPTABLES -A Cid445DA31230753.2 -p ah -j RULE_2
+ $IPTABLES -N Cid445DA31230753.3
+ $IPTABLES -A FORWARD -s ! 192.168.1.0/24 -j Cid445DA31230753.3
+ $IPTABLES -A Cid445DA31230753.3 -p 50 -j RULE_2
+ $IPTABLES -A Cid445DA31230753.3 -p ah -j RULE_2
+ $IPTABLES -A RULE_2 -j LOG --log-level info --log-prefix "RULE 2 -- BRANCH "
+ $IPTABLES -A RULE_2 -j rule2_branch
+ #
+ # Rule 3 (eth1)
+ #
+ echo "Rule 3 (eth1)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p 50 -j rule3_branch
+ $IPTABLES -A INPUT -i eth1 -p ah -j rule3_branch
+ $IPTABLES -A FORWARD -i eth1 -p 50 -j rule3_branch
+ $IPTABLES -A FORWARD -i eth1 -p ah -j rule3_branch
+ #
+ # Rule 4 (eth1)
+ #
+ echo "Rule 4 (eth1)"
+ #
+ $IPTABLES -A OUTPUT -o eth1 -p 50 -j rule3_branch
+ $IPTABLES -A OUTPUT -o eth1 -p ah -j rule3_branch
+ $IPTABLES -A FORWARD -o eth1 -p 50 -j rule3_branch
+ $IPTABLES -A FORWARD -o eth1 -p ah -j rule3_branch
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.2.10 --dport 80 -j rule4_branch
+ $IPTABLES -A FORWARD -p tcp -m tcp -d 192.168.2.10 --dport 80 -j rule4_branch
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -N rule5_branch
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -j rule5_branch
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -j rule5_branch
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -j rule5_branch
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ # green rules branch
+ # also in mangle table
+ $IPTABLES -A OUTPUT -p 50 -j rule0_branch
+ $IPTABLES -A OUTPUT -p ah -j rule0_branch
+ $IPTABLES -A INPUT -p 50 -j rule0_branch
+ $IPTABLES -A INPUT -p ah -j rule0_branch
+ $IPTABLES -A FORWARD -p 50 -j rule0_branch
+ $IPTABLES -A FORWARD -p ah -j rule0_branch
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -N RULE_8
+ $IPTABLES -A OUTPUT -p 50 -j RULE_8
+ $IPTABLES -A OUTPUT -p ah -j RULE_8
+ $IPTABLES -A INPUT -p 50 -j RULE_8
+ $IPTABLES -A INPUT -p ah -j RULE_8
+ $IPTABLES -A FORWARD -p 50 -j RULE_8
+ $IPTABLES -A FORWARD -p ah -j RULE_8
+ $IPTABLES -A RULE_8 -j LOG --log-level info --log-prefix "RULE 8 -- BRANCH "
+ $IPTABLES -A RULE_8 -j rule1_branch
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -N Cid464C29BB3999.0
+ $IPTABLES -A OUTPUT -s ! 192.168.1.0/24 -j Cid464C29BB3999.0
+ $IPTABLES -N RULE_9
+ $IPTABLES -A Cid464C29BB3999.0 -p 50 -j RULE_9
+ $IPTABLES -A Cid464C29BB3999.0 -p ah -j RULE_9
+ $IPTABLES -N Cid464C29BB3999.1
+ $IPTABLES -A INPUT -s ! 192.168.1.0/24 -j Cid464C29BB3999.1
+ $IPTABLES -A Cid464C29BB3999.1 -p 50 -j RULE_9
+ $IPTABLES -A Cid464C29BB3999.1 -p ah -j RULE_9
+ $IPTABLES -N Cid464C29BB3999.2
+ $IPTABLES -A OUTPUT -s ! 192.168.1.0/24 -j Cid464C29BB3999.2
+ $IPTABLES -A Cid464C29BB3999.2 -p 50 -j RULE_9
+ $IPTABLES -A Cid464C29BB3999.2 -p ah -j RULE_9
+ $IPTABLES -N Cid464C29BB3999.3
+ $IPTABLES -A FORWARD -s ! 192.168.1.0/24 -j Cid464C29BB3999.3
+ $IPTABLES -A Cid464C29BB3999.3 -p 50 -j RULE_9
+ $IPTABLES -A Cid464C29BB3999.3 -p ah -j RULE_9
+ $IPTABLES -A RULE_9 -j LOG --log-level info --log-prefix "RULE 9 -- BRANCH "
+ $IPTABLES -A RULE_9 -j rule2_branch
+ #
+ # Rule 10 (eth1)
+ #
+ echo "Rule 10 (eth1)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p 50 -j rule3_branch
+ $IPTABLES -A INPUT -i eth1 -p ah -j rule3_branch
+ $IPTABLES -A FORWARD -i eth1 -p 50 -j rule3_branch
+ $IPTABLES -A FORWARD -i eth1 -p ah -j rule3_branch
+ #
+ # Rule 11 (eth1)
+ #
+ echo "Rule 11 (eth1)"
+ #
+ $IPTABLES -A OUTPUT -o eth1 -p 50 -j rule3_branch
+ $IPTABLES -A OUTPUT -o eth1 -p ah -j rule3_branch
+ $IPTABLES -A FORWARD -o eth1 -p 50 -j rule3_branch
+ $IPTABLES -A FORWARD -o eth1 -p ah -j rule3_branch
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.2.10 --dport 80 -j rule4_branch
+ $IPTABLES -A FORWARD -p tcp -m tcp -d 192.168.2.10 --dport 80 -j rule4_branch
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -j rule5_branch
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -j rule5_branch
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -j rule5_branch
+ #
+ # Rule 14 (global)
+ #
+ echo "Rule 14 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -j TCPMSS --set-mss 1400
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -j TCPMSS --set-mss 1400
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -j TCPMSS --set-mss 1400
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ $IPTABLES -N RULE_15
+ $IPTABLES -A INPUT -s 222.222.222.0/24 -j RULE_15
+ $IPTABLES -A FORWARD -s 222.222.222.0/24 -j RULE_15
+ $IPTABLES -A RULE_15 -j LOG --log-level info --log-prefix "RULE 15 -- CUSTOM "
+ $IPTABLES -A RULE_15 -j TARPIT
+ #
+ # Rule 16 (global)
+ #
+ echo "Rule 16 (global)"
+ #
+ $IPTABLES -N RULE_16
+ $IPTABLES -A OUTPUT -j RULE_16
+ $IPTABLES -A INPUT -j RULE_16
+ $IPTABLES -A FORWARD -j RULE_16
+ $IPTABLES -A RULE_16 -j LOG --log-level info --log-prefix "RULE 16 -- DENY "
+ $IPTABLES -A RULE_16 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:55:16 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall4.fw.orig b/test/ipt/firewall4.fw.orig
new file mode 100755
index 000000000..a3bbf4fa6
--- /dev/null
+++ b/test/ipt/firewall4.fw.orig
@@ -0,0 +1,770 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:18 2011 PST by vadim
+#
+# files: * firewall4.fw
+#
+# Compiled for iptables (any version)
+#
+# this object is used to test a configuration where firewall has dynamic address
+
+# firewall4::: error: Dynamic interface eth1 should not have an IP address object attached to it. This IP address object will be ignored.
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth3 222.222.222.222/24 222.222.222.40/24 222.222.222.41/24" ""
+ getaddr eth1 i_eth1
+ getaddr6 eth1 i_eth1_v6
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.10 -j MASQUERADE
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.10 -j SNAT --to-source 192.168.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.10 -j SNAT --to-source 222.222.222.222
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 222.222.222.40
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 222.222.222.41
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 222.222.222.40
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.10 -j SNAT --to-source 222.222.222.41
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -d ! 192.168.2.0/24 -j MASQUERADE
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -d ! 192.168.2.0/24 -j SNAT --to-source 222.222.222.222
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -t nat -A POSTROUTING -o eth1 -s $i_eth1 -j MASQUERADE
+ done
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j MASQUERADE
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.1 -j MASQUERADE
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.2.1 -j MASQUERADE
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 222.222.222.222 -j MASQUERADE
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d $i_eth1 --dport 22 -j DNAT --to-destination 192.168.1.10:22
+ done
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 22 -j DNAT --to-destination 192.168.1.10:22
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 22 -j DNAT --to-destination 192.168.1.10:22
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 222.222.222.222 --dport 22 -j DNAT --to-destination 192.168.1.10:22
+ #
+ # Rule 6 (NAT)
+ #
+ echo "Rule 6 (NAT)"
+ #
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d $i_eth1 --dport 22 -j DNAT --to-destination 192.168.1.10:22
+ done
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth1)
+ #
+ echo "Rule 0 (eth1)"
+ #
+ # Anti-spoofing rule
+ $IPTABLES -N In_RULE_0
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -A INPUT -i eth1 -s $i_eth1 -j In_RULE_0
+ done
+ $IPTABLES -A INPUT -i eth1 -s 192.168.1.1 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 192.168.2.1 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 222.222.222.222 -j In_RULE_0
+ $IPTABLES -A INPUT -i eth1 -s 192.168.1.0/24 -j In_RULE_0
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -A FORWARD -i eth1 -s $i_eth1 -j In_RULE_0
+ done
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.1.1 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.2.1 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 222.222.222.222 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -s 192.168.1.0/24 -j In_RULE_0
+ $IPTABLES -A In_RULE_0 -j ULOG --ulog-nlgroup 7 --ulog-cprange 64 --ulog-qthreshold 1
+ $IPTABLES -A In_RULE_0 -j DROP
+ #
+ # Rule 1 (eth1)
+ #
+ echo "Rule 1 (eth1)"
+ #
+ # Anti-spoofing rule
+ $IPTABLES -N Cid3B0C63EB.0
+ $IPTABLES -A OUTPUT -o eth1 -j Cid3B0C63EB.0
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -A Cid3B0C63EB.0 -s $i_eth1 -j RETURN
+ done
+ $IPTABLES -A Cid3B0C63EB.0 -s 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid3B0C63EB.0 -s 192.168.2.1 -j RETURN
+ $IPTABLES -A Cid3B0C63EB.0 -s 222.222.222.222 -j RETURN
+ $IPTABLES -N Out_RULE_1_3
+ $IPTABLES -A Cid3B0C63EB.0 -j Out_RULE_1_3
+ $IPTABLES -A Out_RULE_1_3 -j ULOG --ulog-nlgroup 7 --ulog-cprange 64 --ulog-qthreshold 1
+ $IPTABLES -A Out_RULE_1_3 -j DROP
+ $IPTABLES -N Cid3B0C63EB.1
+ $IPTABLES -A FORWARD -o eth1 -j Cid3B0C63EB.1
+ $IPTABLES -A Cid3B0C63EB.1 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid3B0C63EB.1 -j Out_RULE_1_3
+ #
+ # Rule 2 (eth1)
+ #
+ echo "Rule 2 (eth1)"
+ #
+ $IPTABLES -N In_RULE_2
+ $IPTABLES -A INPUT -i eth1 -p icmp -m icmp -s ! 192.168.2.0/24 --icmp-type 8/0 -j In_RULE_2
+ $IPTABLES -A FORWARD -i eth1 -p icmp -m icmp -s ! 192.168.2.0/24 --icmp-type 8/0 -j In_RULE_2
+ $IPTABLES -A In_RULE_2 -j ULOG --ulog-nlgroup 7 --ulog-cprange 64 --ulog-qthreshold 1
+ $IPTABLES -A In_RULE_2 -j DROP
+ $IPTABLES -N Out_RULE_2
+ $IPTABLES -A OUTPUT -o eth1 -p icmp -m icmp -s ! 192.168.2.0/24 --icmp-type 8/0 -j Out_RULE_2
+ $IPTABLES -A FORWARD -o eth1 -p icmp -m icmp -s ! 192.168.2.0/24 --icmp-type 8/0 -j Out_RULE_2
+ $IPTABLES -A Out_RULE_2 -j ULOG --ulog-nlgroup 7 --ulog-cprange 64 --ulog-qthreshold 1
+ $IPTABLES -A Out_RULE_2 -j DROP
+ #
+ # Rule 3 (eth1)
+ #
+ echo "Rule 3 (eth1)"
+ #
+ $IPTABLES -N Cid3E49FEF2.0
+ $IPTABLES -A INPUT -i eth1 -p tcp -m tcp --dport 22 -m state --state NEW -j Cid3E49FEF2.0
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -A Cid3E49FEF2.0 -d $i_eth1 -j ACCEPT
+ done
+ $IPTABLES -A Cid3E49FEF2.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3E49FEF2.0 -d 192.168.2.1 -j ACCEPT
+ $IPTABLES -A Cid3E49FEF2.0 -d 222.222.222.222 -j ACCEPT
+ #
+ # Rule 4 (eth1)
+ #
+ echo "Rule 4 (eth1)"
+ #
+ $IPTABLES -N In_RULE_4
+ $IPTABLES -A INPUT -i eth1 -p icmp -m icmp --icmp-type 8/0 -j In_RULE_4
+ $IPTABLES -A FORWARD -i eth1 -p icmp -m icmp --icmp-type 8/0 -j In_RULE_4
+ $IPTABLES -A In_RULE_4 -j ULOG --ulog-nlgroup 7 --ulog-cprange 64 --ulog-qthreshold 1
+ $IPTABLES -A In_RULE_4 -j DROP
+ $IPTABLES -N Out_RULE_4
+ $IPTABLES -A OUTPUT -o eth1 -p icmp -m icmp --icmp-type 8/0 -j Out_RULE_4
+ $IPTABLES -A FORWARD -o eth1 -p icmp -m icmp --icmp-type 8/0 -j Out_RULE_4
+ $IPTABLES -A Out_RULE_4 -j ULOG --ulog-nlgroup 7 --ulog-cprange 64 --ulog-qthreshold 1
+ $IPTABLES -A Out_RULE_4 -j DROP
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ # OUTPUT
+ $IPTABLES -N Cid469EDB0514508.0
+ $IPTABLES -A OUTPUT -d 1.1.1.1 -j Cid469EDB0514508.0
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -A Cid469EDB0514508.0 -s $i_eth1 -j ACCEPT
+ done
+ $IPTABLES -A Cid469EDB0514508.0 -s 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid469EDB0514508.0 -s 192.168.2.1 -j ACCEPT
+ $IPTABLES -A Cid469EDB0514508.0 -s 222.222.222.222 -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ # INTPUT with "-i +"
+ # the "-i +" option is redundant if chain is INPUT,
+ # it should be removed by optimization
+ $IPTABLES -N Cid469F02B014773.0
+ $IPTABLES -A INPUT -s 1.1.1.1 -j Cid469F02B014773.0
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -A Cid469F02B014773.0 -d $i_eth1 -j ACCEPT
+ done
+ $IPTABLES -A Cid469F02B014773.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid469F02B014773.0 -d 192.168.2.1 -j ACCEPT
+ $IPTABLES -A Cid469F02B014773.0 -d 222.222.222.222 -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ # OUTPUT + FORWARD
+ $IPTABLES -A OUTPUT -d 1.1.1.1 -j ACCEPT
+ $IPTABLES -A FORWARD -o + -d 1.1.1.1 -j ACCEPT
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ # INPUT + FORWARD
+ $IPTABLES -A INPUT -s 1.1.1.1 -j ACCEPT
+ $IPTABLES -A FORWARD -i + -s 1.1.1.1 -j ACCEPT
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ # OUTPUT + FORWARD
+ $IPTABLES -A OUTPUT -d 1.1.1.1 -j ACCEPT
+ $IPTABLES -A FORWARD -d 1.1.1.1 -j ACCEPT
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ # INPUT + FORWARD
+ $IPTABLES -A INPUT -s 1.1.1.1 -j ACCEPT
+ $IPTABLES -A FORWARD -s 1.1.1.1 -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ $IPTABLES -N Cid3B0C63B4.1
+ $IPTABLES -A OUTPUT -p icmp -m icmp --icmp-type 3 -j Cid3B0C63B4.1
+ $IPTABLES -N Cid3B0C63B4.0
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -A Cid3B0C63B4.1 -d $i_eth1 -j Cid3B0C63B4.0
+ done
+ $IPTABLES -A Cid3B0C63B4.1 -d 192.168.1.1 -j Cid3B0C63B4.0
+ $IPTABLES -A Cid3B0C63B4.1 -d 192.168.2.1 -j Cid3B0C63B4.0
+ $IPTABLES -A Cid3B0C63B4.1 -d 222.222.222.222 -j Cid3B0C63B4.0
+ $IPTABLES -N Cid3B0C63B4.2
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type 3 -j Cid3B0C63B4.2
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -A Cid3B0C63B4.2 -d $i_eth1 -j Cid3B0C63B4.0
+ done
+ $IPTABLES -A Cid3B0C63B4.2 -d 192.168.1.1 -j Cid3B0C63B4.0
+ $IPTABLES -A Cid3B0C63B4.2 -d 192.168.2.1 -j Cid3B0C63B4.0
+ $IPTABLES -A Cid3B0C63B4.2 -d 222.222.222.222 -j Cid3B0C63B4.0
+ $IPTABLES -A Cid3B0C63B4.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -A Cid3B0C63B4.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -N RULE_11_3
+ $IPTABLES -A Cid3B0C63B4.0 -j RULE_11_3
+ $IPTABLES -A RULE_11_3 -j ULOG --ulog-nlgroup 7 --ulog-cprange 64 --ulog-qthreshold 1
+ $IPTABLES -A RULE_11_3 -j DROP
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ # testing negation in the policy rule
+ $IPTABLES -N Cid3B0C63A9.0
+ $IPTABLES -A OUTPUT -p icmp -m icmp --icmp-type 3 -j Cid3B0C63A9.0
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type 3 -j Cid3B0C63A9.0
+ $IPTABLES -A FORWARD -p icmp -m icmp --icmp-type 3 -j Cid3B0C63A9.0
+ $IPTABLES -A Cid3B0C63A9.0 -s 192.168.1.10 -j RETURN
+ $IPTABLES -A Cid3B0C63A9.0 -s 192.168.1.20 -j RETURN
+ $IPTABLES -N RULE_12_3
+ $IPTABLES -A Cid3B0C63A9.0 -j RULE_12_3
+ $IPTABLES -A RULE_12_3 -j ULOG --ulog-nlgroup 7 --ulog-cprange 64 --ulog-qthreshold 1
+ $IPTABLES -A RULE_12_3 -j DROP
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ # testing negation in service field
+ $IPTABLES -N Cid3B0C63BF.1
+ $IPTABLES -A OUTPUT -m time --timestart 01:01 --timestop 02:02 --days Sun,Mon -j Cid3B0C63BF.1
+ $IPTABLES -N Cid3B0C63BF.0
+ $IPTABLES -A Cid3B0C63BF.1 -d 192.168.1.10 -j Cid3B0C63BF.0
+ $IPTABLES -A Cid3B0C63BF.1 -d 192.168.1.20 -j Cid3B0C63BF.0
+ $IPTABLES -N Cid3B0C63BF.2
+ $IPTABLES -A FORWARD -m time --timestart 01:01 --timestop 02:02 --days Sun,Mon -j Cid3B0C63BF.2
+ $IPTABLES -A Cid3B0C63BF.2 -d 192.168.1.10 -j Cid3B0C63BF.0
+ $IPTABLES -A Cid3B0C63BF.2 -d 192.168.1.20 -j Cid3B0C63BF.0
+ $IPTABLES -A Cid3B0C63BF.0 -p tcp -m tcp -m multiport --dports 25,22 -j RETURN
+ $IPTABLES -N RULE_13_3
+ $IPTABLES -A Cid3B0C63BF.0 -j RULE_13_3
+ $IPTABLES -A RULE_13_3 -j ULOG --ulog-nlgroup 7 --ulog-cprange 64 --ulog-qthreshold 1
+ $IPTABLES -A RULE_13_3 -j DROP
+ #
+ # Rule 14 (global)
+ #
+ echo "Rule 14 (global)"
+ #
+ $IPTABLES -N RULE_14
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.10 --dport 25 -m time --timestart 01:01 --timestop 02:02 --days Sun,Mon -j RULE_14
+ $IPTABLES -A FORWARD -p tcp -m tcp -d 192.168.1.10 --dport 25 -m time --timestart 01:01 --timestop 02:02 --days Sun,Mon -j RULE_14
+ $IPTABLES -A RULE_14 -j ULOG --ulog-nlgroup 7 --ulog-cprange 64 --ulog-qthreshold 1
+ $IPTABLES -A RULE_14 -j DROP
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ # should permit access to all
+ # addresses that belong to
+ # the firewall, but not to those
+ # that are used in NAT rules
+ # and are added as virtual
+ # addresses
+ $IPTABLES -N Cid3E4DD6AD.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 25 -m state --state NEW -j Cid3E4DD6AD.0
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -A Cid3E4DD6AD.0 -d $i_eth1 -j ACCEPT
+ done
+ $IPTABLES -A Cid3E4DD6AD.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3E4DD6AD.0 -d 192.168.2.1 -j ACCEPT
+ $IPTABLES -A Cid3E4DD6AD.0 -d 222.222.222.222 -j ACCEPT
+ $IPTABLES -N Cid3E4DD6AD.1
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 25 -m state --state NEW -j Cid3E4DD6AD.1
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -A Cid3E4DD6AD.1 -d $i_eth1 -j ACCEPT
+ done
+ $IPTABLES -A Cid3E4DD6AD.1 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3E4DD6AD.1 -d 192.168.2.1 -j ACCEPT
+ $IPTABLES -A Cid3E4DD6AD.1 -d 222.222.222.222 -j ACCEPT
+ #
+ # Rule 17 (global)
+ #
+ echo "Rule 17 (global)"
+ #
+ # 'masquerading' rule
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 18 (global)
+ #
+ echo "Rule 18 (global)"
+ #
+ $IPTABLES -N Cid3E20A8E1.0
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j Cid3E20A8E1.0
+ for i_eth1 in $i_eth1_list
+ do
+ test -n "$i_eth1" && $IPTABLES -A Cid3E20A8E1.0 -d $i_eth1 -j RETURN
+ done
+ $IPTABLES -A Cid3E20A8E1.0 -d 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid3E20A8E1.0 -d 192.168.2.1 -j RETURN
+ $IPTABLES -A Cid3E20A8E1.0 -d 222.222.222.222 -j RETURN
+ $IPTABLES -A Cid3E20A8E1.0 -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ # 'catch all' rule
+ $IPTABLES -N RULE_19
+ $IPTABLES -A OUTPUT -j RULE_19
+ $IPTABLES -A INPUT -j RULE_19
+ $IPTABLES -A FORWARD -j RULE_19
+ $IPTABLES -A RULE_19 -j ULOG --ulog-nlgroup 7 --ulog-cprange 64 --ulog-qthreshold 1
+ $IPTABLES -A RULE_19 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:55:18 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall40-1.fw.orig b/test/ipt/firewall40-1.fw.orig
new file mode 100755
index 000000000..2f12a56a0
--- /dev/null
+++ b/test/ipt/firewall40-1.fw.orig
@@ -0,0 +1,510 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:23 2011 PST by vadim
+#
+# files: * firewall40-1.fw
+#
+# Compiled for iptables 1.4.0
+#
+# more complex and realistic combination of Tag and Route rules that are in the separate Policy rule set
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 lo eth2 eth1"
+ for i in eth0 lo eth2 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.0.2.1/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth2 192.0.100.1/24" ""
+ update_addresses_of_interface "eth1 192.168.1.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # ================ Table 'mangle', automatic rules
+ $IPTABLES -t mangle -A PREROUTING -j CONNMARK --restore-mark
+ $IPTABLES -t mangle -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ # Translate source address
+ # for outgoing connections
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 192.0.2.1
+
+ # ================ Table 'mangle', rule set Policy_1
+ #
+ # Rule Policy_1 0 (eth0)
+ #
+ echo "Rule Policy_1 0 (eth0)"
+ #
+ $IPTABLES -N Policy_1 -t mangle
+ $IPTABLES -N In_Policy_1_0 -t mangle
+ $IPTABLES -t mangle -A Policy_1 -i eth0 -m state --state NEW -j In_Policy_1_0
+ $IPTABLES -t mangle -A In_Policy_1_0 -i eth0 -j MARK --set-mark 1
+ $IPTABLES -t mangle -A In_Policy_1_0 -i eth0 -j CONNMARK --save-mark
+ #
+ # Rule Policy_1 1 (eth2)
+ #
+ echo "Rule Policy_1 1 (eth2)"
+ #
+ $IPTABLES -N In_Policy_1_1 -t mangle
+ $IPTABLES -t mangle -A Policy_1 -i eth2 -m state --state NEW -j In_Policy_1_1
+ $IPTABLES -t mangle -A In_Policy_1_1 -i eth2 -j MARK --set-mark 2
+ $IPTABLES -t mangle -A In_Policy_1_1 -i eth2 -j CONNMARK --save-mark
+ #
+ # Rule Policy_1 3 (global)
+ #
+ echo "Rule Policy_1 3 (global)"
+ #
+ $IPTABLES -t mangle -A POSTROUTING -m mark --mark 1 -j ROUTE --oif eth0 --continue
+ #
+ # Rule Policy_1 4 (global)
+ #
+ echo "Rule Policy_1 4 (global)"
+ #
+ $IPTABLES -t mangle -A POSTROUTING -m mark --mark 2 -j ROUTE --oif eth2 --continue
+ #
+ # Rule Policy_1 6 (global)
+ #
+ echo "Rule Policy_1 6 (global)"
+ #
+ $IPTABLES -N Cid55038X29165.0 -t mangle
+ $IPTABLES -t mangle -A Policy_1 -s 192.168.1.0/24 -m state --state NEW -j Cid55038X29165.0
+ $IPTABLES -N Policy_1_6 -t mangle
+ $IPTABLES -t mangle -A Cid55038X29165.0 -d 22.22.22.0/24 -j Policy_1_6
+ $IPTABLES -t mangle -A Cid55038X29165.0 -d 33.33.33.0/24 -j Policy_1_6
+ $IPTABLES -t mangle -A Policy_1_6 -j LOG --log-level info --log-prefix "RULE 6 -- TAG "
+ $IPTABLES -t mangle -A Policy_1_6 -j MARK --set-mark 8
+
+ # ================ Table 'filter', rule set Policy_1
+ #
+ # Rule Policy_1 2 (global)
+ #
+ echo "Rule Policy_1 2 (global)"
+ #
+ # This permits access from internal net
+ # to the Internet and DMZ
+ $IPTABLES -N Policy_1
+ $IPTABLES -A Policy_1 -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule Policy_1 5 (global)
+ #
+ echo "Rule Policy_1 5 (global)"
+ #
+ $IPTABLES -N Policy_1_5
+ $IPTABLES -A Policy_1 -j Policy_1_5
+ $IPTABLES -A Policy_1_5 -j LOG --log-level info --log-prefix "RULE 5 -- DENY "
+ $IPTABLES -A Policy_1_5 -j DROP
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ # any rule here to make top Policy ruleset non-empty
+ $IPTABLES -N RULE_0
+ $IPTABLES -A OUTPUT -j RULE_0
+ $IPTABLES -A INPUT -j RULE_0
+ $IPTABLES -A FORWARD -j RULE_0
+ $IPTABLES -A RULE_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A RULE_0 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:55:23 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall40-2.fw.orig b/test/ipt/firewall40-2.fw.orig
new file mode 100755
index 000000000..602d58647
--- /dev/null
+++ b/test/ipt/firewall40-2.fw.orig
@@ -0,0 +1,497 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:25 2011 PST by vadim
+#
+# files: * firewall40-2.fw
+#
+# Compiled for iptables 1.4.0
+#
+# more complex and realistic combination of Tag and Route rules that are in the separate Policy rule set. Here the top Policy rule set is empty
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 lo eth2 eth1"
+ for i in eth0 lo eth2 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.0.2.1/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth2 192.0.100.1/24" ""
+ update_addresses_of_interface "eth1 192.168.1.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # ================ Table 'mangle', automatic rules
+ $IPTABLES -t mangle -A PREROUTING -j CONNMARK --restore-mark
+ $IPTABLES -t mangle -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ # Translate source address
+ # for outgoing connections
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 192.0.2.1
+
+ # ================ Table 'mangle', rule set Policy_1
+ #
+ # Rule Policy_1 0 (eth0)
+ #
+ echo "Rule Policy_1 0 (eth0)"
+ #
+ $IPTABLES -N Policy_1 -t mangle
+ $IPTABLES -N In_Policy_1_0 -t mangle
+ $IPTABLES -t mangle -A Policy_1 -i eth0 -m state --state NEW -j In_Policy_1_0
+ $IPTABLES -t mangle -A In_Policy_1_0 -i eth0 -j MARK --set-mark 1
+ $IPTABLES -t mangle -A In_Policy_1_0 -i eth0 -j CONNMARK --save-mark
+ #
+ # Rule Policy_1 1 (eth2)
+ #
+ echo "Rule Policy_1 1 (eth2)"
+ #
+ $IPTABLES -N In_Policy_1_1 -t mangle
+ $IPTABLES -t mangle -A Policy_1 -i eth2 -m state --state NEW -j In_Policy_1_1
+ $IPTABLES -t mangle -A In_Policy_1_1 -i eth2 -j MARK --set-mark 2
+ $IPTABLES -t mangle -A In_Policy_1_1 -i eth2 -j CONNMARK --save-mark
+ #
+ # Rule Policy_1 3 (global)
+ #
+ echo "Rule Policy_1 3 (global)"
+ #
+ $IPTABLES -t mangle -A POSTROUTING -m mark --mark 1 -j ROUTE --oif eth0 --continue
+ #
+ # Rule Policy_1 4 (global)
+ #
+ echo "Rule Policy_1 4 (global)"
+ #
+ $IPTABLES -t mangle -A POSTROUTING -m mark --mark 2 -j ROUTE --oif eth2 --continue
+ #
+ # Rule Policy_1 6 (global)
+ #
+ echo "Rule Policy_1 6 (global)"
+ #
+ $IPTABLES -N Cid55227X22068.0 -t mangle
+ $IPTABLES -t mangle -A Policy_1 -s 192.168.1.0/24 -m state --state NEW -j Cid55227X22068.0
+ $IPTABLES -N Policy_1_6 -t mangle
+ $IPTABLES -t mangle -A Cid55227X22068.0 -d 22.22.22.0/24 -j Policy_1_6
+ $IPTABLES -t mangle -A Cid55227X22068.0 -d 33.33.33.0/24 -j Policy_1_6
+ $IPTABLES -t mangle -A Policy_1_6 -j LOG --log-level info --log-prefix "RULE 6 -- TAG "
+ $IPTABLES -t mangle -A Policy_1_6 -j MARK --set-mark 8
+
+ # ================ Table 'filter', rule set Policy_1
+ #
+ # Rule Policy_1 2 (global)
+ #
+ echo "Rule Policy_1 2 (global)"
+ #
+ # This permits access from internal net
+ # to the Internet and DMZ
+ $IPTABLES -N Policy_1
+ $IPTABLES -A Policy_1 -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule Policy_1 5 (global)
+ #
+ echo "Rule Policy_1 5 (global)"
+ #
+ $IPTABLES -N Policy_1_5
+ $IPTABLES -A Policy_1 -j Policy_1_5
+ $IPTABLES -A Policy_1_5 -j LOG --log-level info --log-prefix "RULE 5 -- DENY "
+ $IPTABLES -A Policy_1_5 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:55:25 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall40.fw.orig b/test/ipt/firewall40.fw.orig
new file mode 100755
index 000000000..138e761af
--- /dev/null
+++ b/test/ipt/firewall40.fw.orig
@@ -0,0 +1,499 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:21 2011 PST by vadim
+#
+# files: * firewall40.fw
+#
+# Compiled for iptables 1.4.0
+#
+# more complex and realistic combination of Tag and Route rules
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 lo eth2 eth1"
+ for i in eth0 lo eth2 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.0.2.1/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth2 192.0.100.1/24" ""
+ update_addresses_of_interface "eth1 192.168.1.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # ================ Table 'mangle', automatic rules
+ $IPTABLES -t mangle -A PREROUTING -j CONNMARK --restore-mark
+ $IPTABLES -t mangle -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ # Translate source address
+ # for outgoing connections
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 192.0.2.1
+
+ # ================ Table 'mangle', rule set Policy
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -N In_RULE_0 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -i eth0 -m state --state NEW -j In_RULE_0
+ $IPTABLES -t mangle -A In_RULE_0 -i eth0 -j MARK --set-mark 1
+ $IPTABLES -t mangle -A In_RULE_0 -i eth0 -j CONNMARK --save-mark
+ #
+ # Rule 1 (eth2)
+ #
+ echo "Rule 1 (eth2)"
+ #
+ $IPTABLES -N In_RULE_1 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -i eth2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -t mangle -A In_RULE_1 -i eth2 -j MARK --set-mark 2
+ $IPTABLES -t mangle -A In_RULE_1 -i eth2 -j CONNMARK --save-mark
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -t mangle -A POSTROUTING -m mark --mark 1 -j ROUTE --oif eth0 --continue
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -t mangle -A POSTROUTING -m mark --mark 2 -j ROUTE --oif eth2 --continue
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -N Cid37084X26841.0 -t mangle
+ $IPTABLES -t mangle -A PREROUTING -s 192.168.1.0/24 -m state --state NEW -j Cid37084X26841.0
+ $IPTABLES -N RULE_6 -t mangle
+ $IPTABLES -t mangle -A Cid37084X26841.0 -d 22.22.22.0/24 -j RULE_6
+ $IPTABLES -t mangle -A Cid37084X26841.0 -d 33.33.33.0/24 -j RULE_6
+ $IPTABLES -t mangle -A RULE_6 -j LOG --log-level info --log-prefix "RULE 6 -- TAG "
+ $IPTABLES -t mangle -A RULE_6 -j MARK --set-mark 8
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ # This permits access from internal net
+ # to the Internet and DMZ
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -N RULE_5
+ $IPTABLES -A OUTPUT -j RULE_5
+ $IPTABLES -A INPUT -j RULE_5
+ $IPTABLES -A FORWARD -j RULE_5
+ $IPTABLES -A RULE_5 -j LOG --log-level info --log-prefix "RULE 5 -- DENY "
+ $IPTABLES -A RULE_5 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:55:21 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall41-1.fw.orig b/test/ipt/firewall41-1.fw.orig
new file mode 100755
index 000000000..a8de74f62
--- /dev/null
+++ b/test/ipt/firewall41-1.fw.orig
@@ -0,0 +1,654 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:35 2011 PST by vadim
+#
+# files: * firewall41-1.fw
+#
+# Compiled for iptables 1.4.1.1
+#
+# testing run time address table objects with module set
+
+# firewall41-1::: warning: Can not add virtual address for object atbl.1
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+ find_program $IPSET
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_module_ipset() {
+ $IPSET --list > /dev/null 2>&1 || {
+ echo "Detected an error with ipset utility :"
+ $IPSET -V
+ exit 1
+ }
+}
+
+reload_address_table() {
+ addrtbl_name=$1
+ data_file=$2
+
+ test -z "$addrtbl_name" -o -z "$data_file" && {
+ echo "Usage: reload_address_table address_table_object_name file_name"
+ exit 1
+ }
+
+ $IPSET -X tmp_fwb_set:ip -q
+ $IPSET -X tmp_fwb_set:net -q
+
+ $IPSET -N tmp_fwb_set:ip iphash
+ $IPSET -N tmp_fwb_set:net nethash
+
+ grep -Ev '^#|^;|^\s*$' $data_file | while read L ; do
+ set $L
+ addr=$1
+ if echo $addr | grep -q "/"
+ then
+ $IPSET -A tmp_fwb_set:net $addr
+ else
+ $IPSET -A tmp_fwb_set:ip $addr
+ fi
+ done
+
+ $IPSET --list ${addrtbl_name}:ip >/dev/null || $IPSET -N ${addrtbl_name}:ip iphash
+ $IPSET --list ${addrtbl_name}:net >/dev/null || $IPSET -N ${addrtbl_name}:net nethash
+
+ $IPSET -W ${addrtbl_name}:ip tmp_fwb_set:ip
+ $IPSET -W ${addrtbl_name}:net tmp_fwb_set:net
+
+ $IPSET --list ${addrtbl_name} >/dev/null || {
+ $IPSET -N ${addrtbl_name} setlist
+ }
+
+ $IPSET --list ${addrtbl_name} | grep -q ${addrtbl_name}:ip || {
+ $IPSET -A ${addrtbl_name} ${addrtbl_name}:ip
+ }
+
+ $IPSET --list ${addrtbl_name} | grep -q ${addrtbl_name}:net || {
+ $IPSET -A ${addrtbl_name} ${addrtbl_name}:net
+ }
+
+ $IPSET -X tmp_fwb_set:ip
+ $IPSET -X tmp_fwb_set:net
+}
+
+add_to_address_table() {
+ addrtbl_name=$1
+ data_file=$2
+ address=$3
+
+ test -z "$addrtbl_name" -o -z "$data_file" -o -z "$address" && {
+ echo "Usage: add_to_address_table address_table_object_name file_name address"
+ exit 1
+ }
+
+ echo $address >> $data_file
+
+ if echo $address | grep -q "/"
+ then
+ $IPSET -A ${addrtbl_name}:net $address
+ else
+ $IPSET -A ${addrtbl_name}:ip $address
+ fi
+}
+
+remove_from_address_table() {
+ addrtbl_name=$1
+ data_file=$2
+ address=$3
+
+ test -z "$addrtbl_name" -o -z "$data_file" -o -z "$address" && {
+ echo "Usage: remove_from_address_table address_table_object_name file_name address"
+ exit 1
+ }
+
+ escaped_addr=$(echo $address | sed 's!/!\\/!')
+ sed -i "/^ *$escaped_addr *\$/d" $data_file
+
+ if echo $address | grep -q "/"
+ then
+ $IPSET -D ${addrtbl_name}:net $address
+ else
+ $IPSET -D ${addrtbl_name}:ip $address
+ fi
+}
+
+test_address_table() {
+ addrtbl_name=$1
+ address=$2
+
+ test -z "$addrtbl_name" -o -z "$address" && {
+ echo "Usage: test_address_table address_table_object_name address"
+ exit 1
+ }
+
+ if echo $address | grep -q "/"
+ then
+ $IPSET -T ${addrtbl_name}:net $address
+ else
+ $IPSET -T ${addrtbl_name}:ip $address
+ fi
+}
+
+
+load_run_time_address_table_files() {
+ :
+ reload_address_table "atbl.1" "addr-table-1.tbl"
+reload_address_table "block_these" "block-hosts.tbl"
+}
+
+
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+ check_file "atbl.1" "addr-table-1.tbl"
+check_file "block_these" "block-hosts.tbl"
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 1.1.1.1/24" ""
+ update_addresses_of_interface "eth1 2.2.2.2/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -m set --set atbl.1 src -j SNAT --to-source 1.1.1.1
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid2287813X9995.0
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -j Cid2287813X9995.0
+ $IPTABLES -t nat -A Cid2287813X9995.0 -m set --set atbl.1 src -j RETURN
+ $IPTABLES -t nat -A Cid2287813X9995.0 -j SNAT --to-source 1.1.1.1
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -m set --set atbl.1 dst -j DNAT --to-destination 192.168.1.10
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -A OUTPUT -m set --set atbl.1 dst -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -N Cid1162747X27867.0
+ $IPTABLES -A INPUT -m set ! --set atbl.1 dst -m state --state NEW -j Cid1162747X27867.0
+ $IPTABLES -A Cid1162747X27867.0 -s 1.1.1.1 -j ACCEPT
+ $IPTABLES -A Cid1162747X27867.0 -s 2.2.2.2 -j ACCEPT
+ $IPTABLES -A OUTPUT -m set ! --set atbl.1 dst -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -A OUTPUT -m set ! --set atbl.1 dst -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -A OUTPUT -m set --set atbl.1 dst -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -m set --set block_these dst -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -A INPUT -m set --set atbl.1 src -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -N Cid1162799X27867.0
+ $IPTABLES -A OUTPUT -m set ! --set atbl.1 src -m state --state NEW -j Cid1162799X27867.0
+ $IPTABLES -A Cid1162799X27867.0 -d 1.1.1.1 -j ACCEPT
+ $IPTABLES -A Cid1162799X27867.0 -d 2.2.2.2 -j ACCEPT
+ $IPTABLES -A INPUT -m set ! --set atbl.1 src -m state --state NEW -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -A INPUT -m set ! --set atbl.1 src -m state --state NEW -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -A INPUT -m set --set atbl.1 src -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -m set --set block_these src -m state --state NEW -j ACCEPT
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -A OUTPUT -m set --set atbl.1 dst -j DROP
+ $IPTABLES -A FORWARD -m set --set atbl.1 dst -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:55:35 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ check_module_ipset
+ load_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+ reload_address_table)
+ reload_address_table $2 $3
+ ;;
+
+ add_to_address_table)
+ add_to_address_table $2 $3 $4
+ ;;
+
+ remove_from_address_table)
+ remove_from_address_table $2 $3 $4
+ ;;
+
+ test_address_table)
+ test_address_table $2 $3
+ ;;
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces|reload_address_table|add_to_address_table|remove_from_address_table|test_address_table]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall41-2.fw.orig b/test/ipt/firewall41-2.fw.orig
new file mode 100755
index 000000000..f7221dbc3
--- /dev/null
+++ b/test/ipt/firewall41-2.fw.orig
@@ -0,0 +1,517 @@
+#!/bin/sh /etc/rc.common
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:37 2011 PST by vadim
+#
+# files: * firewall41-2.fw
+#
+# Compiled for iptables 1.4.3
+#
+# testing run time address table objects with module set
+# use module set is turned off
+
+# firewall41-2::: warning: Can not add virtual address for object atbl.1
+
+START=46
+
+EXTRA_COMMANDS="status interfaces test_interfaces"
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE=""
+IPTABLES="/usr/sbin/iptables"
+IP6TABLES="/usr/sbin/ip6tables"
+IPTABLES_RESTORE="/usr/sbin/iptables-restore"
+IP6TABLES_RESTORE="/usr/sbin/ip6tables-restore"
+IP="/usr/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/usr/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM >/dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+ check_file "atbl.1" "addr-table-1.tbl"
+check_file "block_these" "block-hosts.tbl"
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ insmod ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 1.1.1.1/24" ""
+ update_addresses_of_interface "eth1 2.2.2.2/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ grep -Ev '^#|^;|^\s*$' addr-table-1.tbl | while read L ; do
+ set $L; at_atbl_1=$1; $IPTABLES -t nat -A POSTROUTING -o eth+ -s $at_atbl_1 -j SNAT --to-source 1.1.1.1
+ done
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid2101361X9995.0
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -j Cid2101361X9995.0
+ grep -Ev '^#|^;|^\s*$' addr-table-1.tbl | while read L ; do
+ set $L; at_atbl_1=$1; $IPTABLES -t nat -A Cid2101361X9995.0 -s $at_atbl_1 -j RETURN
+ done
+ $IPTABLES -t nat -A Cid2101361X9995.0 -o eth+ -j SNAT --to-source 1.1.1.1
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ grep -Ev '^#|^;|^\s*$' addr-table-1.tbl | while read L ; do
+ set $L; at_atbl_1=$1; $IPTABLES -t nat -A PREROUTING -d $at_atbl_1 -j DNAT --to-destination 192.168.1.10
+ done
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ grep -Ev '^#|^;|^\s*$' addr-table-1.tbl | while read L ; do
+ set $L; at_atbl_1=$1; $IPTABLES -A OUTPUT -d $at_atbl_1 -m state --state NEW -j ACCEPT
+ done
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -N Cid4374297X29460.0
+ $IPTABLES -A INPUT -s 1.1.1.1 -m state --state NEW -j Cid4374297X29460.0
+ $IPTABLES -A INPUT -s 2.2.2.2 -m state --state NEW -j Cid4374297X29460.0
+ $IPTABLES -A OUTPUT -s 1.1.1.1 -m state --state NEW -j Cid4374297X29460.0
+ $IPTABLES -A OUTPUT -s 2.2.2.2 -m state --state NEW -j Cid4374297X29460.0
+ grep -Ev '^#|^;|^\s*$' addr-table-1.tbl | while read L ; do
+ set $L; at_atbl_1=$1; $IPTABLES -A Cid4374297X29460.0 -d $at_atbl_1 -j RETURN
+ done
+ $IPTABLES -A Cid4374297X29460.0 -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -N Cid4374309X29460.0
+ $IPTABLES -A OUTPUT -s 1.1.1.1 -m state --state NEW -j Cid4374309X29460.0
+ $IPTABLES -A OUTPUT -s 2.2.2.2 -m state --state NEW -j Cid4374309X29460.0
+ grep -Ev '^#|^;|^\s*$' addr-table-1.tbl | while read L ; do
+ set $L; at_atbl_1=$1; $IPTABLES -A Cid4374309X29460.0 -d $at_atbl_1 -j RETURN
+ done
+ $IPTABLES -A Cid4374309X29460.0 -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ grep -Ev '^#|^;|^\s*$' addr-table-1.tbl | while read L ; do
+ set $L; at_atbl_1=$1; $IPTABLES -A OUTPUT -d $at_atbl_1 -m state --state NEW -j ACCEPT
+ done
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; $IPTABLES -A OUTPUT -d $at_block_these -m state --state NEW -j ACCEPT
+ done
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ grep -Ev '^#|^;|^\s*$' addr-table-1.tbl | while read L ; do
+ set $L; at_atbl_1=$1; $IPTABLES -A INPUT -s $at_atbl_1 -m state --state NEW -j ACCEPT
+ done
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -N Cid4374346X29460.0
+ $IPTABLES -A OUTPUT -d 1.1.1.1 -m state --state NEW -j Cid4374346X29460.0
+ $IPTABLES -A OUTPUT -d 2.2.2.2 -m state --state NEW -j Cid4374346X29460.0
+ $IPTABLES -A INPUT -d 1.1.1.1 -m state --state NEW -j Cid4374346X29460.0
+ $IPTABLES -A INPUT -d 2.2.2.2 -m state --state NEW -j Cid4374346X29460.0
+ grep -Ev '^#|^;|^\s*$' addr-table-1.tbl | while read L ; do
+ set $L; at_atbl_1=$1; $IPTABLES -A Cid4374346X29460.0 -s $at_atbl_1 -j RETURN
+ done
+ $IPTABLES -A Cid4374346X29460.0 -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -N Cid4374358X29460.0
+ $IPTABLES -A INPUT -d 1.1.1.1 -m state --state NEW -j Cid4374358X29460.0
+ $IPTABLES -A INPUT -d 2.2.2.2 -m state --state NEW -j Cid4374358X29460.0
+ grep -Ev '^#|^;|^\s*$' addr-table-1.tbl | while read L ; do
+ set $L; at_atbl_1=$1; $IPTABLES -A Cid4374358X29460.0 -s $at_atbl_1 -j RETURN
+ done
+ $IPTABLES -A Cid4374358X29460.0 -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ grep -Ev '^#|^;|^\s*$' addr-table-1.tbl | while read L ; do
+ set $L; at_atbl_1=$1; $IPTABLES -A INPUT -s $at_atbl_1 -m state --state NEW -j ACCEPT
+ done
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; $IPTABLES -A INPUT -s $at_block_these -m state --state NEW -j ACCEPT
+ done
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ grep -Ev '^#|^;|^\s*$' addr-table-1.tbl | while read L ; do
+ set $L; at_atbl_1=$1; $IPTABLES -A OUTPUT -d $at_atbl_1 -j DROP
+ done
+ grep -Ev '^#|^;|^\s*$' addr-table-1.tbl | while read L ; do
+ set $L; at_atbl_1=$1; $IPTABLES -A FORWARD -d $at_atbl_1 -j DROP
+ done
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+start() {
+ log "Activating firewall script generated Mon Jan 3 12:55:37 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+}
+
+stop() {
+ stop_action
+}
+
+status() {
+ status_action
+}
+
+interfaces() {
+ configure_interfaces
+}
+
+test_interfaces() {
+ FWBDEBUG="echo"
+ configure_interfaces
+}
diff --git a/test/ipt/firewall41.fw.orig b/test/ipt/firewall41.fw.orig
new file mode 100755
index 000000000..77418e0bd
--- /dev/null
+++ b/test/ipt/firewall41.fw.orig
@@ -0,0 +1,516 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:33 2011 PST by vadim
+#
+# files: * firewall41.fw
+#
+# Compiled for iptables (any version)
+#
+# testing rule shadowing with run-time objects, rules with such objects should be ignored
+
+# firewall41:Policy:5: error: File not found for Address Table: missing table (this_table_does_not_exist.tbl) Using dummy address in test mode
+# firewall41:Policy:5: error: File not found for Address Table: missing table (this_table_does_not_exist.tbl) Using dummy address in test mode
+# firewall41:Policy:6: error: DNSName object "does not resolve" (compile time) can not resolve dns name "does_not_resolve.local" (AF_INET): Host or network 'does_not_resolve.local' not found; last error: Unknown error Using dummy address in test mode
+# firewall41:Policy:5: error: Rule '5 (global)' shadows rule '6 (global)' below it
+# firewall41:Policy:6: error: DNSName object "does not resolve" (compile time) can not resolve dns name "does_not_resolve.local" (AF_INET): Host or network 'does_not_resolve.local' not found; last error: Unknown error Using dummy address in test mode
+# firewall41:Policy:5: error: Rule '5 (global)' shadows rule '6 (global)' below it
+# firewall41:Policy:5: error: File not found for Address Table: missing table (this_table_does_not_exist.tbl) Using dummy address in test mode
+# firewall41:Policy:6: error: DNSName object "does not resolve" (compile time) can not resolve dns name "does_not_resolve.local" (AF_INET): Host or network 'does_not_resolve.local' not found; last error: Unknown error Using dummy address in test mode
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+ check_file "atbl.1" "addr-table-1.tbl"
+check_file "block_these" "block-hosts.tbl"
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 1.1.1.1/24" ""
+ update_addresses_of_interface "eth1 2.2.2.2/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -N RULE_0
+ $IPTABLES -A OUTPUT -d www.heise.de -m state --state NEW -j RULE_0
+ $IPTABLES -A RULE_0 -j LOG --log-level info --log-prefix "RULE 0 -- ACCEPT "
+ $IPTABLES -A RULE_0 -j ACCEPT
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -N RULE_1
+ grep -Ev '^#|^;|^\s*$' addr-table-1.tbl | while read L ; do
+ set $L; at_atbl_1=$1; $IPTABLES -A OUTPUT -d $at_atbl_1 -m state --state NEW -j RULE_1
+ done
+ $IPTABLES -A RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- ACCEPT "
+ $IPTABLES -A RULE_1 -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -N Cid44F707E428576.0
+ $IPTABLES -A INPUT -d 1.1.1.1 -m state --state NEW -j Cid44F707E428576.0
+ $IPTABLES -N RULE_2
+ $IPTABLES -A Cid44F707E428576.0 -s 1.1.1.1 -j RULE_2
+ $IPTABLES -A Cid44F707E428576.0 -s 2.2.2.2 -j RULE_2
+ $IPTABLES -A OUTPUT -d 1.1.1.1 -m state --state NEW -j RULE_2
+ $IPTABLES -A RULE_2 -j LOG --log-level info --log-prefix "RULE 2 -- ACCEPT "
+ $IPTABLES -A RULE_2 -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -N RULE_3
+ grep -Ev '^#|^;|^\s*$' addr-table-1.tbl | while read L ; do
+ set $L; at_atbl_1=$1; $IPTABLES -A OUTPUT -d $at_atbl_1 -j RULE_3
+ done
+ grep -Ev '^#|^;|^\s*$' addr-table-1.tbl | while read L ; do
+ set $L; at_atbl_1=$1; $IPTABLES -A FORWARD -d $at_atbl_1 -j RULE_3
+ done
+ $IPTABLES -A RULE_3 -j LOG --log-level info --log-prefix "RULE 3 -- DENY "
+ $IPTABLES -A RULE_3 -j DROP
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ # testing for bug #1086
+ # when two run-time objects are used in the rule, compiler adds blank command that blocks (permits) any to any
+ $IPTABLES -N RULE_4
+ grep -Ev '^#|^;|^\s*$' addr-table-1.tbl | while read L ; do
+ set $L; at_atbl_1=$1; $IPTABLES -A OUTPUT -d $at_atbl_1 -m state --state NEW -j RULE_4
+ done
+ grep -Ev '^#|^;|^\s*$' block-hosts.tbl | while read L ; do
+ set $L; at_block_these=$1; $IPTABLES -A OUTPUT -d $at_block_these -m state --state NEW -j RULE_4
+ done
+ $IPTABLES -A RULE_4 -j LOG --log-level info --log-prefix "RULE 4 -- ACCEPT "
+ $IPTABLES -A RULE_4 -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ # there should be warning saying the table could not be found
+ # firewall41:Policy:5: error: File not found for Address Table: missing table (this_table_does_not_exist.tbl) Using dummy address in test mode
+ $IPTABLES -N RULE_5
+ $IPTABLES -A OUTPUT -d 192.0.2.0/24 -j RULE_5
+ $IPTABLES -A RULE_5 -j LOG --log-level info --log-prefix "RULE 5 -- DENY "
+ $IPTABLES -A RULE_5 -j DROP
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ # firewall41:Policy:6: error: DNSName object "does not resolve" (compile time) can not resolve dns name "does_not_resolve.local" (AF_INET): Host or network 'does_not_resolve.local' not found; last error: Unknown error Using dummy address in test mode
+ $IPTABLES -N RULE_6
+ $IPTABLES -A OUTPUT -d 192.0.2.1 -j RULE_6
+ $IPTABLES -A RULE_6 -j LOG --log-level info --log-prefix "RULE 6 -- DENY "
+ $IPTABLES -A RULE_6 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:55:33 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall42.fw.orig b/test/ipt/firewall42.fw.orig
new file mode 100755
index 000000000..41c439965
--- /dev/null
+++ b/test/ipt/firewall42.fw.orig
@@ -0,0 +1,442 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:39 2011 PST by vadim
+#
+# files: * firewall42.fw
+#
+# Compiled for iptables (any version)
+#
+# simple test for a rule that matches local broadcast and should go into INPUT chain, but internal interface of the firewall is dynamic so compiler can not determine that given address is broadcast. Using fake interface to make this address match.
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ getaddr eth0 i_eth0
+ getaddr6 eth0 i_eth0_v6
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 192.168.1.255 --dport 67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 255.255.255.255 --dport 67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (eth0)
+ #
+ echo "Rule 2 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 224.0.1.141 --dport 67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (eth0)
+ #
+ echo "Rule 3 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -s 0.0.0.0 -d 255.255.255.255 --dport 67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (eth0)
+ #
+ echo "Rule 4 (eth0)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -s $i_eth0 -d 255.255.255.255 --dport 68 -m state --state NEW -j ACCEPT
+ done
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:55:39 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall5.fw.orig b/test/ipt/firewall5.fw.orig
new file mode 100755
index 000000000..4ee609118
--- /dev/null
+++ b/test/ipt/firewall5.fw.orig
@@ -0,0 +1,682 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:41 2011 PST by vadim
+#
+# files: * firewall5.fw
+#
+# Compiled for iptables (any version)
+#
+# testing firewall_is_part_of_any_and_networks. Also testing SNAT and DNAT rules when external interface has dynamic address.
+
+# dynamic interface ppp0 has an address object attached to it (interface used to be static and had an address, then got converted to dynamic but address object is still there). Compiler should ignore this address object and issue a warning.
+
+# All "configure interfaces" options are off, testing shell functions for this case.
+
+# firewall5::: error: Dynamic interface ppp0 should not have an IP address object attached to it. This IP address object will be ignored.
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ getaddr ppp0 i_ppp0
+ getaddr6 ppp0 i_ppp0_v6
+ getaddr ppp1 i_ppp1
+ getaddr6 ppp1 i_ppp1_v6
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o ppp0 -s 192.168.1.0/24 -j MASQUERADE
+ $IPTABLES -t nat -A POSTROUTING -o ppp1 -s 192.168.1.0/24 -j MASQUERADE
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.23
+ $IPTABLES -t nat -A POSTROUTING -o ppp+ -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.23
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 77.77.77.77 -j SNAT --to-source 22.22.22.23
+ $IPTABLES -t nat -A POSTROUTING -o ppp+ -s 77.77.77.77 -j SNAT --to-source 22.22.22.23
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.1.1 -j SNAT --to-source 22.22.22.23
+ $IPTABLES -t nat -A POSTROUTING -o ppp+ -s 192.168.1.1 -j SNAT --to-source 22.22.22.23
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s 192.168.2.1 -j SNAT --to-source 22.22.22.23
+ $IPTABLES -t nat -A POSTROUTING -o ppp+ -s 192.168.2.1 -j SNAT --to-source 22.22.22.23
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d $i_ppp0 --dport 22 -j DNAT --to-destination 192.168.1.10:22
+ done
+ for i_ppp1 in $i_ppp1_list
+ do
+ test -n "$i_ppp1" && $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d $i_ppp1 --dport 22 -j DNAT --to-destination 192.168.1.10:22
+ done
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 22 -j DNAT --to-destination 192.168.1.10:22
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 22 -j DNAT --to-destination 192.168.1.10:22
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (ppp0)
+ #
+ echo "Rule 0 (ppp0)"
+ #
+ $IPTABLES -N Cid3E4A05B9.0
+ $IPTABLES -A INPUT -i ppp0 -j Cid3E4A05B9.0
+ $IPTABLES -A FORWARD -i ppp0 -j Cid3E4A05B9.0
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -A Cid3E4A05B9.0 -s $i_ppp0 -j RETURN
+ done
+ $IPTABLES -A Cid3E4A05B9.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -N In_RULE_0_3
+ $IPTABLES -A Cid3E4A05B9.0 -j In_RULE_0_3
+ $IPTABLES -A In_RULE_0_3 -j LOG
+ $IPTABLES -A In_RULE_0_3 -j DROP
+ #
+ # Rule 1 (ppp1)
+ #
+ echo "Rule 1 (ppp1)"
+ #
+ $IPTABLES -N Cid3E8F5B72.0
+ $IPTABLES -A INPUT -i ppp1 -j Cid3E8F5B72.0
+ $IPTABLES -A FORWARD -i ppp1 -j Cid3E8F5B72.0
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -A Cid3E8F5B72.0 -s $i_ppp0 -j RETURN
+ done
+ $IPTABLES -A Cid3E8F5B72.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -N In_RULE_1_3
+ $IPTABLES -A Cid3E8F5B72.0 -j In_RULE_1_3
+ $IPTABLES -A In_RULE_1_3 -j LOG
+ $IPTABLES -A In_RULE_1_3 -j DROP
+ #
+ # Rule 2 (ppp1,ppp0)
+ #
+ echo "Rule 2 (ppp1,ppp0)"
+ #
+ $IPTABLES -N Cid212010X42308.0
+ $IPTABLES -A INPUT -i ppp1 -j Cid212010X42308.0
+ $IPTABLES -A INPUT -i ppp0 -j Cid212010X42308.0
+ $IPTABLES -A FORWARD -i ppp1 -j Cid212010X42308.0
+ $IPTABLES -A FORWARD -i ppp0 -j Cid212010X42308.0
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -A Cid212010X42308.0 -s $i_ppp0 -j RETURN
+ done
+ for i_ppp1 in $i_ppp1_list
+ do
+ test -n "$i_ppp1" && $IPTABLES -A Cid212010X42308.0 -s $i_ppp1 -j RETURN
+ done
+ $IPTABLES -A Cid212010X42308.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -N In_RULE_2_3
+ $IPTABLES -A Cid212010X42308.0 -j In_RULE_2_3
+ $IPTABLES -A In_RULE_2_3 -j LOG
+ $IPTABLES -A In_RULE_2_3 -j DROP
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -N RULE_3
+ for i_ppp0 in $i_ppp0_list
+ do
+ for i_ppp1 in $i_ppp1_list
+ do
+ test -n "$i_ppp0" && test -n "$i_ppp1" && $IPTABLES -A INPUT -s $i_ppp0 -d $i_ppp1 -j RULE_3
+ done
+ done
+ for i_ppp0 in $i_ppp0_list
+ do
+ for i_ppp1 in $i_ppp1_list
+ do
+ test -n "$i_ppp0" && test -n "$i_ppp1" && $IPTABLES -A OUTPUT -s $i_ppp0 -d $i_ppp1 -j RULE_3
+ done
+ done
+ $IPTABLES -A RULE_3 -j LOG
+ $IPTABLES -A RULE_3 -j DROP
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -A OUTPUT -p tcp -m tcp -d $i_ppp0 --dport 22 -m state --state NEW -j ACCEPT
+ done
+ for i_ppp1 in $i_ppp1_list
+ do
+ test -n "$i_ppp1" && $IPTABLES -A OUTPUT -p tcp -m tcp -d $i_ppp1 --dport 22 -m state --state NEW -j ACCEPT
+ done
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -A INPUT -p tcp -m tcp -d $i_ppp0 --dport 22 -m state --state NEW -j ACCEPT
+ done
+ for i_ppp1 in $i_ppp1_list
+ do
+ test -n "$i_ppp1" && $IPTABLES -A INPUT -p tcp -m tcp -d $i_ppp1 --dport 22 -m state --state NEW -j ACCEPT
+ done
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ # hostF has the same IP address as firewal.
+ $IPTABLES -N RULE_5
+ $IPTABLES -A OUTPUT -p icmp -m icmp -d 192.168.1.1 --icmp-type 8/0 -m state --state NEW -j RULE_5
+ $IPTABLES -A INPUT -p icmp -m icmp -d 192.168.1.1 --icmp-type 8/0 -m state --state NEW -j RULE_5
+ $IPTABLES -A RULE_5 -j LOG
+ $IPTABLES -A RULE_5 -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -N Cid3E4A0454.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid3E4A0454.0
+ for i_ppp1 in $i_ppp1_list
+ do
+ test -n "$i_ppp1" && $IPTABLES -A Cid3E4A0454.0 -d $i_ppp1 -j ACCEPT
+ done
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -A Cid3E4A0454.0 -d $i_ppp0 -j ACCEPT
+ done
+ $IPTABLES -A Cid3E4A0454.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3E4A0454.0 -d 192.168.2.1 -j ACCEPT
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.1 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p tcp -m tcp -d 192.168.1.1 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -m multiport -d 192.168.1.1 --dports 22,23 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p tcp -m tcp -m multiport -d 192.168.1.1 --dports 22,23 -m state --state NEW -j ACCEPT
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -N Cid3E987157.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid3E987157.0
+ $IPTABLES -A Cid3E987157.0 -d 77.77.77.77 -j ACCEPT
+ $IPTABLES -A Cid3E987157.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3E987157.0 -d 192.168.2.1 -j ACCEPT
+ $IPTABLES -N Cid3E987157.1
+ $IPTABLES -A FORWARD -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid3E987157.1
+ $IPTABLES -A Cid3E987157.1 -d 77.77.77.77 -j ACCEPT
+ $IPTABLES -A Cid3E987157.1 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3E987157.1 -d 192.168.2.1 -j ACCEPT
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ $IPTABLES -N Cid3E9871F4.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid3E9871F4.0
+ $IPTABLES -N RULE_10
+ $IPTABLES -A Cid3E9871F4.0 -d 77.77.77.77 -j RULE_10
+ $IPTABLES -A Cid3E9871F4.0 -d 192.168.1.1 -j RULE_10
+ $IPTABLES -A Cid3E9871F4.0 -d 192.168.2.1 -j RULE_10
+ $IPTABLES -N Cid3E9871F4.1
+ $IPTABLES -A FORWARD -p tcp -m tcp -m multiport --dports 22,23 -m state --state NEW -j Cid3E9871F4.1
+ $IPTABLES -A Cid3E9871F4.1 -d 77.77.77.77 -j RULE_10
+ $IPTABLES -A Cid3E9871F4.1 -d 192.168.1.1 -j RULE_10
+ $IPTABLES -A Cid3E9871F4.1 -d 192.168.2.1 -j RULE_10
+ $IPTABLES -A RULE_10 -j LOG
+ $IPTABLES -A RULE_10 -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ # firewall is part of Any, so compiler should
+ # generate code in both FORWARD and
+ # OUTPUT chains
+ $IPTABLES -A OUTPUT -d 200.200.200.200 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 200.200.200.200 -m state --state NEW -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ # firewall is part of Any, compiler should
+ # generate code for both FORWARD and
+ # INPUT chains
+ $IPTABLES -A INPUT -s 200.200.200.200 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 200.200.200.200 -m state --state NEW -j ACCEPT
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ # because firewall has interface on network
+ # internal_net, compiler should generate code
+ # for both FORWARD and INPUT chains
+ $IPTABLES -A INPUT -s 192.168.1.10 -d 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.10 -d 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 14 (global)
+ #
+ echo "Rule 14 (global)"
+ #
+ $IPTABLES -N Cid3B19C5CA.0
+ $IPTABLES -A OUTPUT -d 200.200.200.200 -m state --state NEW -j Cid3B19C5CA.0
+ $IPTABLES -A Cid3B19C5CA.0 -s 192.168.1.0/24 -j ACCEPT
+ $IPTABLES -A Cid3B19C5CA.0 -s 192.168.2.0/24 -j ACCEPT
+ $IPTABLES -N Cid3B19C5CA.1
+ $IPTABLES -A FORWARD -d 200.200.200.200 -m state --state NEW -j Cid3B19C5CA.1
+ $IPTABLES -A Cid3B19C5CA.1 -s 192.168.1.0/24 -j ACCEPT
+ $IPTABLES -A Cid3B19C5CA.1 -s 192.168.2.0/24 -j ACCEPT
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ # Automatically generated 'catch all' rule
+ $IPTABLES -N RULE_15
+ $IPTABLES -A OUTPUT -j RULE_15
+ $IPTABLES -A INPUT -j RULE_15
+ $IPTABLES -A FORWARD -j RULE_15
+ $IPTABLES -A RULE_15 -j LOG
+ $IPTABLES -A RULE_15 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:55:41 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall50.fw.orig b/test/ipt/firewall50.fw.orig
new file mode 100755
index 000000000..c814605c0
--- /dev/null
+++ b/test/ipt/firewall50.fw.orig
@@ -0,0 +1,467 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:44 2011 PST by vadim
+#
+# files: * firewall50.fw
+#
+# Compiled for iptables (any version)
+#
+# testing action 'Continue'
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set rule2_branch
+ #
+ # Rule rule2_branch 0 (global)
+ #
+ echo "Rule rule2_branch 0 (global)"
+ #
+ $IPTABLES -N rule2_branch
+ $IPTABLES -N Cid4734305F19714.0
+ $IPTABLES -A rule2_branch -j Cid4734305F19714.0
+ $IPTABLES -A Cid4734305F19714.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid4734305F19714.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -N rule2_branch_0_3
+ $IPTABLES -A Cid4734305F19714.0 -j rule2_branch_0_3
+ $IPTABLES -A rule2_branch_0_3 -j LOG --log-level debug
+ $IPTABLES -A rule2_branch_0_3 -j DROP
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -N RULE_1
+ $IPTABLES -A INPUT -s 192.168.0.0/16 -j RULE_1
+ $IPTABLES -A OUTPUT -s 192.168.0.0/16 -j RULE_1
+ $IPTABLES -A FORWARD -s 192.168.0.0/16 -j RULE_1
+ $IPTABLES -A RULE_1 -j LOG --log-level debug
+ $IPTABLES -A RULE_1 -j DROP
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.0.0/16 -j rule2_branch
+ $IPTABLES -A OUTPUT -s 192.168.0.0/16 -j rule2_branch
+ $IPTABLES -A FORWARD -s 192.168.0.0/16 -j rule2_branch
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -N Cid4733CF6F19714.0
+ $IPTABLES -A OUTPUT -j Cid4733CF6F19714.0
+ $IPTABLES -A INPUT -j Cid4733CF6F19714.0
+ $IPTABLES -A FORWARD -j Cid4733CF6F19714.0
+ $IPTABLES -A Cid4733CF6F19714.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid4733CF6F19714.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -N RULE_3_3
+ $IPTABLES -A Cid4733CF6F19714.0 -j RULE_3_3
+ $IPTABLES -A RULE_3_3 -j LOG --log-level debug
+ $IPTABLES -A RULE_3_3 -j DROP
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -N RULE_4
+ $IPTABLES -A OUTPUT -j RULE_4
+ $IPTABLES -A INPUT -j RULE_4
+ $IPTABLES -A FORWARD -j RULE_4
+ $IPTABLES -A RULE_4 -j LOG --log-level debug
+ $IPTABLES -A RULE_4 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:55:44 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall51.fw.orig b/test/ipt/firewall51.fw.orig
new file mode 100755
index 000000000..51093f2cf
--- /dev/null
+++ b/test/ipt/firewall51.fw.orig
@@ -0,0 +1,551 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:48 2011 PST by vadim
+#
+# files: * firewall51.fw
+#
+# Compiled for iptables (any version)
+#
+# testing branching rules that point
+# at rule sets defined in object
+# firewall-base-rulesets
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set rule2_branch
+ #
+ # Rule rule2_branch 0 (global)
+ #
+ echo "Rule rule2_branch 0 (global)"
+ #
+ $IPTABLES -N rule2_branch
+ $IPTABLES -N Cid484A060A4626.0
+ $IPTABLES -A rule2_branch -j Cid484A060A4626.0
+ $IPTABLES -A Cid484A060A4626.0 -s 192.168.1.0/24 -j RETURN
+ $IPTABLES -A Cid484A060A4626.0 -s 192.168.2.0/24 -j RETURN
+ $IPTABLES -N rule2_branch_0_3
+ $IPTABLES -A Cid484A060A4626.0 -j rule2_branch_0_3
+ $IPTABLES -A rule2_branch_0_3 -j LOG --log-level debug
+ $IPTABLES -A rule2_branch_0_3 -j DROP
+ # ================ Table 'filter', rule set mail_server_inbound
+ #
+ # Rule mail_server_inbound 0 (global)
+ #
+ echo "Rule mail_server_inbound 0 (global)"
+ #
+ $IPTABLES -N mail_server_inbound
+ $IPTABLES -A mail_server_inbound -i + -p tcp -m tcp --dport 25 -m state --state NEW -j ACCEPT
+ #
+ # Rule mail_server_inbound 1 (global)
+ #
+ echo "Rule mail_server_inbound 1 (global)"
+ #
+ $IPTABLES -A mail_server_inbound -i + -p icmp -m icmp --icmp-type 3 -m state --state NEW -j ACCEPT
+ $IPTABLES -A mail_server_inbound -i + -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ # ================ Table 'filter', rule set mail_server_outbound
+ #
+ # Rule mail_server_outbound 0 (global)
+ #
+ echo "Rule mail_server_outbound 0 (global)"
+ #
+ $IPTABLES -N mail_server_outbound
+ $IPTABLES -A mail_server_outbound -o + -p tcp -m tcp -m multiport --dports 53,25 -m state --state NEW -j ACCEPT
+ $IPTABLES -A mail_server_outbound -o + -p udp -m udp --dport 53 -m state --state NEW -j ACCEPT
+ #
+ # Rule mail_server_outbound 1 (global)
+ #
+ echo "Rule mail_server_outbound 1 (global)"
+ #
+ $IPTABLES -A mail_server_outbound -o + -p icmp -m icmp --icmp-type 3 -m state --state NEW -j ACCEPT
+ $IPTABLES -A mail_server_outbound -o + -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ # ================ Table 'filter', rule set web_server_inbound
+ #
+ # Rule web_server_inbound 0 (global)
+ #
+ echo "Rule web_server_inbound 0 (global)"
+ #
+ $IPTABLES -N web_server_inbound
+ $IPTABLES -A web_server_inbound -i + -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
+ #
+ # Rule web_server_inbound 1 (global)
+ #
+ echo "Rule web_server_inbound 1 (global)"
+ #
+ $IPTABLES -A web_server_inbound -i + -p icmp -m icmp --icmp-type 3 -m state --state NEW -j ACCEPT
+ $IPTABLES -A web_server_inbound -i + -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ #
+ # Rule web_server_inbound 2 (global)
+ #
+ echo "Rule web_server_inbound 2 (global)"
+ #
+ $IPTABLES -N web_server_inbound_2
+ $IPTABLES -A web_server_inbound -p tcp -m tcp --dport 3306 -j web_server_inbound_2
+ $IPTABLES -A web_server_inbound_2 -j LOG --log-level debug --log-prefix "web_server_inbound/2 -- DENY"
+ $IPTABLES -A web_server_inbound_2 -j DROP
+ # ================ Table 'filter', rule set web_server_outbound
+ #
+ # Rule web_server_outbound 0 (global)
+ #
+ echo "Rule web_server_outbound 0 (global)"
+ #
+ $IPTABLES -N web_server_outbound
+ $IPTABLES -A web_server_outbound -o + -p icmp -m icmp --icmp-type 3 -m state --state NEW -j ACCEPT
+ $IPTABLES -A web_server_outbound -o + -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ #
+ # Rule web_server_outbound 1 (global)
+ #
+ echo "Rule web_server_outbound 1 (global)"
+ #
+ $IPTABLES -A web_server_outbound -o + -p tcp -m tcp --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A web_server_outbound -o + -p udp -m udp --dport 53 -m state --state NEW -j ACCEPT
+ # ================ Table 'filter', rule set base-ruleset
+ #
+ # Rule base-ruleset 0 (global)
+ #
+ echo "Rule base-ruleset 0 (global)"
+ #
+ $IPTABLES -N base-ruleset
+ $IPTABLES -N Cid41961X1271.0
+ $IPTABLES -A base-ruleset -p tcp -m tcp --dport 22 -m state --state NEW -j Cid41961X1271.0
+ $IPTABLES -A Cid41961X1271.0 -d 33.33.33.33 -j ACCEPT
+ $IPTABLES -A Cid41961X1271.0 -d 172.16.1.1 -j ACCEPT
+ $IPTABLES -A Cid41961X1271.0 -d 192.168.100.1 -j ACCEPT
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 192.168.1.10 -j mail_server_inbound
+ $IPTABLES -A FORWARD -d 192.168.1.10 -j mail_server_inbound
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.10 -j mail_server_outbound
+ $IPTABLES -A FORWARD -s 192.168.1.10 -j mail_server_outbound
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 192.168.1.20 -j web_server_inbound
+ $IPTABLES -A FORWARD -d 192.168.1.20 -j web_server_inbound
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.20 -j web_server_outbound
+ $IPTABLES -A FORWARD -s 192.168.1.20 -j web_server_outbound
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -A OUTPUT -j base-ruleset
+ $IPTABLES -A INPUT -j base-ruleset
+ $IPTABLES -A FORWARD -j base-ruleset
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -j rule2_branch
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -j rule2_branch
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -j rule2_branch
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:55:48 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall6.fw.orig b/test/ipt/firewall6.fw.orig
new file mode 100755
index 000000000..b81a39c96
--- /dev/null
+++ b/test/ipt/firewall6.fw.orig
@@ -0,0 +1,573 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:50 2011 PST by vadim
+#
+# files: * firewall6.fw
+#
+# Compiled for iptables (any version)
+#
+# testing rule with firewall in dst and negation
+# also testing "Destination NAT Onto the Same Network" per Turorial chapter 3.5
+# testing a rule with src=dst=firewall6 in the global policy (should use all interfaces including loopback)
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth3 22.22.23.23/24 22.22.23.24/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.20 --dport 80 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.24 --dport 80 -j DNAT --to-destination 192.168.1.20
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ # this is SDNAT rule, it translates
+ # both source and destination
+ # this rule should be equivalent to two rules above
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.0/24 -d 22.22.23.24 --dport 80 -j DNAT --to-destination 192.168.1.20
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.20 --dport 80 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 80 -j DNAT --to-destination 192.168.1.11-192.168.1.12
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -d 192.168.1.11 --dport 80 -j SNAT --to-source 192.168.1.1
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -d 192.168.1.12 --dport 80 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 80 -j DNAT --to-destination 192.168.1.11-192.168.1.12
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -d 192.168.1.11 --dport 80 -j SNAT --to-source 192.168.1.1
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -d 192.168.1.12 --dport 80 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.22.22 --dport 80 -j DNAT --to-destination 192.168.1.11-192.168.1.12
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 22.22.23.23 --dport 80 -j DNAT --to-destination 192.168.1.11-192.168.1.12
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 80 -j DNAT --to-destination 192.168.1.11-192.168.1.12
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.2.1 --dport 80 -j DNAT --to-destination 192.168.1.11-192.168.1.12
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -d 192.168.1.11 --dport 80 -j SNAT --to-source 192.168.1.1
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -d 192.168.1.12 --dport 80 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 6 (NAT)
+ #
+ echo "Rule 6 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s ! 192.168.1.100 --dport 80 -j DNAT --to-destination 192.168.1.100:3128
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -s ! 192.168.1.100 -d 192.168.1.100 --dport 3128 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 7 (NAT)
+ #
+ echo "Rule 7 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid3F9F8382.0
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j Cid3F9F8382.0
+ $IPTABLES -t nat -A Cid3F9F8382.0 -d 222.222.222.40 -j RETURN
+ $IPTABLES -t nat -A Cid3F9F8382.0 -d 222.222.222.41 -j RETURN
+ $IPTABLES -t nat -A Cid3F9F8382.0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.100:3128
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.100 --dport 3128 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 8 (NAT)
+ #
+ echo "Rule 8 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -d 192.168.2.0/24 -j SNAT --to-source 192.168.2.1
+ #
+ # Rule 9 (NAT)
+ #
+ echo "Rule 9 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j SNAT --to-source 22.22.22.22
+ $IPTABLES -t nat -A POSTROUTING -o eth3 -s 192.168.1.0/24 -j SNAT --to-source 22.22.23.23
+ $IPTABLES -t nat -A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth1)
+ #
+ echo "Rule 0 (eth1)"
+ #
+ $IPTABLES -N Cid3C699028.0
+ $IPTABLES -A INPUT -i eth1 -j Cid3C699028.0
+ $IPTABLES -A Cid3C699028.0 -d 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid3C699028.0 -d 22.22.23.23 -j RETURN
+ $IPTABLES -A Cid3C699028.0 -d 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid3C699028.0 -d 192.168.2.1 -j RETURN
+ $IPTABLES -N In_RULE_0_3
+ $IPTABLES -A Cid3C699028.0 -j In_RULE_0_3
+ $IPTABLES -A In_RULE_0_3 -j LOG --log-level debug --log-prefix "RULE 0 -- DENY global"
+ $IPTABLES -A In_RULE_0_3 -j DROP
+ $IPTABLES -N In_RULE_0
+ $IPTABLES -A FORWARD -i eth1 -j In_RULE_0
+ $IPTABLES -A In_RULE_0 -j LOG --log-level debug --log-prefix "RULE 0 -- DENY global"
+ $IPTABLES -A In_RULE_0 -j DROP
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -N Cid3C698FB2.0
+ $IPTABLES -A INPUT -j Cid3C698FB2.0
+ $IPTABLES -A Cid3C698FB2.0 -d 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid3C698FB2.0 -d 22.22.23.23 -j RETURN
+ $IPTABLES -A Cid3C698FB2.0 -d 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid3C698FB2.0 -d 192.168.2.1 -j RETURN
+ $IPTABLES -N In_RULE_1_3
+ $IPTABLES -A Cid3C698FB2.0 -j In_RULE_1_3
+ $IPTABLES -A In_RULE_1_3 -j LOG --log-level debug --log-prefix "RULE 1 -- DENY global"
+ $IPTABLES -A In_RULE_1_3 -j DROP
+ $IPTABLES -N RULE_1
+ $IPTABLES -A OUTPUT -j RULE_1
+ $IPTABLES -A FORWARD -j RULE_1
+ $IPTABLES -A RULE_1 -j LOG --log-level debug --log-prefix "RULE 1 -- DENY global"
+ $IPTABLES -A RULE_1 -j DROP
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -N Cid3E9C86DD.0
+ $IPTABLES -A INPUT -s 22.22.22.22 -m state --state NEW -j Cid3E9C86DD.0
+ $IPTABLES -A INPUT -s 22.22.23.23 -m state --state NEW -j Cid3E9C86DD.0
+ $IPTABLES -A INPUT -s 127.0.0.1 -m state --state NEW -j Cid3E9C86DD.0
+ $IPTABLES -A INPUT -s 192.168.1.1 -m state --state NEW -j Cid3E9C86DD.0
+ $IPTABLES -A INPUT -s 192.168.2.1 -m state --state NEW -j Cid3E9C86DD.0
+ $IPTABLES -A Cid3E9C86DD.0 -d 22.22.22.22 -j ACCEPT
+ $IPTABLES -A Cid3E9C86DD.0 -d 22.22.23.23 -j ACCEPT
+ $IPTABLES -A Cid3E9C86DD.0 -d 127.0.0.1 -j ACCEPT
+ $IPTABLES -A Cid3E9C86DD.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3E9C86DD.0 -d 192.168.2.1 -j ACCEPT
+ $IPTABLES -N Cid3E9C86DD.1
+ $IPTABLES -A OUTPUT -s 22.22.22.22 -m state --state NEW -j Cid3E9C86DD.1
+ $IPTABLES -A OUTPUT -s 22.22.23.23 -m state --state NEW -j Cid3E9C86DD.1
+ $IPTABLES -A OUTPUT -s 127.0.0.1 -m state --state NEW -j Cid3E9C86DD.1
+ $IPTABLES -A OUTPUT -s 192.168.1.1 -m state --state NEW -j Cid3E9C86DD.1
+ $IPTABLES -A OUTPUT -s 192.168.2.1 -m state --state NEW -j Cid3E9C86DD.1
+ $IPTABLES -A Cid3E9C86DD.1 -d 22.22.22.22 -j ACCEPT
+ $IPTABLES -A Cid3E9C86DD.1 -d 22.22.23.23 -j ACCEPT
+ $IPTABLES -A Cid3E9C86DD.1 -d 127.0.0.1 -j ACCEPT
+ $IPTABLES -A Cid3E9C86DD.1 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid3E9C86DD.1 -d 192.168.2.1 -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -N Cid141025X15403.0
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j Cid141025X15403.0
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j Cid141025X15403.0
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j Cid141025X15403.0
+ $IPTABLES -A Cid141025X15403.0 -d 222.222.222.40 -j RETURN
+ $IPTABLES -A Cid141025X15403.0 -d 222.222.222.41 -j RETURN
+ $IPTABLES -A Cid141025X15403.0 -j ACCEPT
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:55:50 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall60.fw.orig b/test/ipt/firewall60.fw.orig
new file mode 100755
index 000000000..760b1b27f
--- /dev/null
+++ b/test/ipt/firewall60.fw.orig
@@ -0,0 +1,479 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:52 2011 PST by vadim
+#
+# files: * firewall60.fw
+#
+# Compiled for iptables (any version)
+#
+# testing time litmiting for iptables < 1.4.0
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth1 222.222.222.222/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -N RULE_0
+ $IPTABLES -A OUTPUT -m time --timestart 00:00 --timestop 23:59 --days Sat -j RULE_0
+ $IPTABLES -A INPUT -m time --timestart 00:00 --timestop 23:59 --days Sat -j RULE_0
+ $IPTABLES -A FORWARD -m time --timestart 00:00 --timestop 23:59 --days Sat -j RULE_0
+ $IPTABLES -A RULE_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A RULE_0 -j DROP
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -N RULE_1
+ $IPTABLES -A OUTPUT -m time --timestart 00:00 --timestop 23:59 --days Sun -j RULE_1
+ $IPTABLES -A INPUT -m time --timestart 00:00 --timestop 23:59 --days Sun -j RULE_1
+ $IPTABLES -A FORWARD -m time --timestart 00:00 --timestop 23:59 --days Sun -j RULE_1
+ $IPTABLES -A RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A RULE_1 -j DROP
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -N RULE_2
+ $IPTABLES -A OUTPUT -m time --timestart 18:00 --timestop 23:59 -j RULE_2
+ $IPTABLES -A INPUT -m time --timestart 18:00 --timestop 23:59 -j RULE_2
+ $IPTABLES -A FORWARD -m time --timestart 18:00 --timestop 23:59 -j RULE_2
+ $IPTABLES -A RULE_2 -j LOG --log-level info --log-prefix "RULE 2 -- DENY "
+ $IPTABLES -A RULE_2 -j DROP
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -N RULE_3
+ $IPTABLES -A OUTPUT -m time --timestart 00:00 --timestop 23:59 --days Sat,Sun -j RULE_3
+ $IPTABLES -A INPUT -m time --timestart 00:00 --timestop 23:59 --days Sat,Sun -j RULE_3
+ $IPTABLES -A FORWARD -m time --timestart 00:00 --timestop 23:59 --days Sat,Sun -j RULE_3
+ $IPTABLES -A RULE_3 -j LOG --log-level info --log-prefix "RULE 3 -- DENY "
+ $IPTABLES -A RULE_3 -j DROP
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -N RULE_4
+ $IPTABLES -A OUTPUT -m time --timestart 09:00 --timestop 17:00 --days Mon,Tue,Wed,Thu,Fri -j RULE_4
+ $IPTABLES -A INPUT -m time --timestart 09:00 --timestop 17:00 --days Mon,Tue,Wed,Thu,Fri -j RULE_4
+ $IPTABLES -A FORWARD -m time --timestart 09:00 --timestop 17:00 --days Mon,Tue,Wed,Thu,Fri -j RULE_4
+ $IPTABLES -A RULE_4 -j LOG --log-level info --log-prefix "RULE 4 -- DENY "
+ $IPTABLES -A RULE_4 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:55:52 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall61-1.2.5.fw.orig b/test/ipt/firewall61-1.2.5.fw.orig
new file mode 100755
index 000000000..0e0b013d5
--- /dev/null
+++ b/test/ipt/firewall61-1.2.5.fw.orig
@@ -0,0 +1,559 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:55 2011 PST by vadim
+#
+# files: * firewall61-1.2.5.fw
+#
+# Compiled for iptables lt_1.2.6
+#
+# testing time litmiting for iptables 1.2.5
+
+# firewall61-1.2.5:Policy_ipv6:: warning: target TCPMSS is not supported by ip6tables before v1.3.8
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth1 222.222.222.222/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ $IPTABLES -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
+
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+ # ================ Table 'mangle', rule set fw61-Policy
+ #
+ # Rule fw61-Policy 0 (global)
+ #
+ echo "Rule fw61-Policy 0 (global)"
+ #
+ $IPTABLES -N fw61-Policy_0 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -m time --timestart 00:00 --timestop 23:59 --days Sat -j fw61-Policy_0
+ $IPTABLES -t mangle -A INPUT -m time --timestart 00:00 --timestop 23:59 --days Sat -j fw61-Policy_0
+ $IPTABLES -t mangle -A FORWARD -m time --timestart 00:00 --timestop 23:59 --days Sat -j fw61-Policy_0
+ $IPTABLES -t mangle -A fw61-Policy_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_0 -j DROP
+ #
+ # Rule fw61-Policy 1 (global)
+ #
+ echo "Rule fw61-Policy 1 (global)"
+ #
+ $IPTABLES -N fw61-Policy_1 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -m time --timestart 00:00 --timestop 23:59 --days Sun -j fw61-Policy_1
+ $IPTABLES -t mangle -A INPUT -m time --timestart 00:00 --timestop 23:59 --days Sun -j fw61-Policy_1
+ $IPTABLES -t mangle -A FORWARD -m time --timestart 00:00 --timestop 23:59 --days Sun -j fw61-Policy_1
+ $IPTABLES -t mangle -A fw61-Policy_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_1 -j DROP
+ #
+ # Rule fw61-Policy 2 (global)
+ #
+ echo "Rule fw61-Policy 2 (global)"
+ #
+ $IPTABLES -N fw61-Policy_2 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -m time --timestart 18:00 --timestop 23:59 -j fw61-Policy_2
+ $IPTABLES -t mangle -A INPUT -m time --timestart 18:00 --timestop 23:59 -j fw61-Policy_2
+ $IPTABLES -t mangle -A FORWARD -m time --timestart 18:00 --timestop 23:59 -j fw61-Policy_2
+ $IPTABLES -t mangle -A fw61-Policy_2 -j LOG --log-level info --log-prefix "RULE 2 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_2 -j DROP
+ #
+ # Rule fw61-Policy 3 (global)
+ #
+ echo "Rule fw61-Policy 3 (global)"
+ #
+ $IPTABLES -N fw61-Policy_3 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -m time --timestart 00:00 --timestop 23:59 --days Sat,Sun -j fw61-Policy_3
+ $IPTABLES -t mangle -A INPUT -m time --timestart 00:00 --timestop 23:59 --days Sat,Sun -j fw61-Policy_3
+ $IPTABLES -t mangle -A FORWARD -m time --timestart 00:00 --timestop 23:59 --days Sat,Sun -j fw61-Policy_3
+ $IPTABLES -t mangle -A fw61-Policy_3 -j LOG --log-level info --log-prefix "RULE 3 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_3 -j DROP
+ #
+ # Rule fw61-Policy 4 (global)
+ #
+ echo "Rule fw61-Policy 4 (global)"
+ #
+ $IPTABLES -N fw61-Policy_4 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -m time --timestart 09:00 --timestop 17:00 --days Mon,Tue,Wed,Thu,Fri -j fw61-Policy_4
+ $IPTABLES -t mangle -A INPUT -m time --timestart 09:00 --timestop 17:00 --days Mon,Tue,Wed,Thu,Fri -j fw61-Policy_4
+ $IPTABLES -t mangle -A FORWARD -m time --timestart 09:00 --timestop 17:00 --days Mon,Tue,Wed,Thu,Fri -j fw61-Policy_4
+ $IPTABLES -t mangle -A fw61-Policy_4 -j LOG --log-level info --log-prefix "RULE 4 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_4 -j DROP
+ #
+ # Rule fw61-Policy 5 (global)
+ #
+ echo "Rule fw61-Policy 5 (global)"
+ #
+ $IPTABLES -N fw61-Policy_5 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -m time --timestart 01:01 --timestop 02:02 --days Sun,Mon -j fw61-Policy_5
+ $IPTABLES -t mangle -A INPUT -m time --timestart 01:01 --timestop 02:02 --days Sun,Mon -j fw61-Policy_5
+ $IPTABLES -t mangle -A FORWARD -m time --timestart 01:01 --timestop 02:02 --days Sun,Mon -j fw61-Policy_5
+ $IPTABLES -t mangle -A fw61-Policy_5 -j LOG --log-level info --log-prefix "RULE 5 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_5 -j DROP
+ #
+ # Rule fw61-Policy 6 (global)
+ #
+ echo "Rule fw61-Policy 6 (global)"
+ #
+ $IPTABLES -N fw61-Policy_6 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -m time --timestart 01:01 --timestop 02:02 --days Sun,Mon -j fw61-Policy_6
+ $IPTABLES -t mangle -A INPUT -m time --timestart 01:01 --timestop 02:02 --days Sun,Mon -j fw61-Policy_6
+ $IPTABLES -t mangle -A FORWARD -m time --timestart 01:01 --timestop 02:02 --days Sun,Mon -j fw61-Policy_6
+ $IPTABLES -t mangle -A fw61-Policy_6 -j LOG --log-level info --log-prefix "RULE 6 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_6 -j DROP
+ #
+ # Rule fw61-Policy 7 (global)
+ #
+ echo "Rule fw61-Policy 7 (global)"
+ #
+ $IPTABLES -N fw61-Policy_7 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -m time --timestart 00:00 --timestop 01:00 --days Fri,Sat -j fw61-Policy_7
+ $IPTABLES -t mangle -A INPUT -m time --timestart 00:00 --timestop 01:00 --days Fri,Sat -j fw61-Policy_7
+ $IPTABLES -t mangle -A FORWARD -m time --timestart 00:00 --timestop 01:00 --days Fri,Sat -j fw61-Policy_7
+ $IPTABLES -t mangle -A fw61-Policy_7 -j LOG --log-level info --log-prefix "RULE 7 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_7 -j DROP
+ #
+ # Rule fw61-Policy 8 (global)
+ #
+ echo "Rule fw61-Policy 8 (global)"
+ #
+ $IPTABLES -N fw61-Policy_8 -t mangle
+ $IPTABLES -t mangle -A OUTPUT -m time --timestart 01:00 --timestop 02:00 --days Fri,Sat -j fw61-Policy_8
+ $IPTABLES -t mangle -A INPUT -m time --timestart 01:00 --timestop 02:00 --days Fri,Sat -j fw61-Policy_8
+ $IPTABLES -t mangle -A FORWARD -m time --timestart 01:00 --timestop 02:00 --days Fri,Sat -j fw61-Policy_8
+ $IPTABLES -t mangle -A fw61-Policy_8 -j LOG --log-level info --log-prefix "RULE 8 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_8 -j DROP
+
+
+
+
+ # ================ IPv6
+
+
+ # ================ Table 'filter', automatic rules
+ # target TCPMSS is not supported by ip6tables before v1.3.8
+
+ # accept established sessions
+ $IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy_ipv6
+ #
+ # Rule Policy_ipv6 0 (global)
+ #
+ echo "Rule Policy_ipv6 0 (global)"
+ #
+ $IP6TABLES -N Policy_ipv6_0
+ $IP6TABLES -A OUTPUT -j Policy_ipv6_0
+ $IP6TABLES -A INPUT -j Policy_ipv6_0
+ $IP6TABLES -A FORWARD -j Policy_ipv6_0
+ $IP6TABLES -A Policy_ipv6_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IP6TABLES -A Policy_ipv6_0 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:55:55 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " ipv6"
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall61-1.2.6.fw.orig b/test/ipt/firewall61-1.2.6.fw.orig
new file mode 100755
index 000000000..add8ad229
--- /dev/null
+++ b/test/ipt/firewall61-1.2.6.fw.orig
@@ -0,0 +1,565 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:55:57 2011 PST by vadim
+#
+# files: * firewall61-1.2.6.fw
+#
+# Compiled for iptables ge_1.2.6
+#
+# testing time litmiting for iptables 1.2.6
+
+# firewall61-1.2.6:Policy_ipv6:: warning: target TCPMSS is not supported by ip6tables before v1.3.8
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth1 222.222.222.222/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ $IPTABLES -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
+
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+ # ================ Table 'mangle', rule set fw61-Policy
+ #
+ # Rule fw61-Policy 0 (global)
+ #
+ echo "Rule fw61-Policy 0 (global)"
+ #
+ $IPTABLES -N fw61-Policy -t mangle
+ $IPTABLES -N fw61-Policy_0 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 00:00 --timestop 23:59 --days Sat -j fw61-Policy_0
+ $IPTABLES -t mangle -A fw61-Policy_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_0 -j DROP
+ #
+ # Rule fw61-Policy 1 (global)
+ #
+ echo "Rule fw61-Policy 1 (global)"
+ #
+ $IPTABLES -N fw61-Policy_1 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 00:00 --timestop 23:59 --days Sun -j fw61-Policy_1
+ $IPTABLES -t mangle -A fw61-Policy_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_1 -j DROP
+ #
+ # Rule fw61-Policy 2 (global)
+ #
+ echo "Rule fw61-Policy 2 (global)"
+ #
+ $IPTABLES -N fw61-Policy_2 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 18:00 --timestop 23:59 -j fw61-Policy_2
+ $IPTABLES -t mangle -A fw61-Policy_2 -j LOG --log-level info --log-prefix "RULE 2 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_2 -j DROP
+ #
+ # Rule fw61-Policy 3 (global)
+ #
+ echo "Rule fw61-Policy 3 (global)"
+ #
+ $IPTABLES -N fw61-Policy_3 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 00:00 --timestop 23:59 --days Sat,Sun -j fw61-Policy_3
+ $IPTABLES -t mangle -A fw61-Policy_3 -j LOG --log-level info --log-prefix "RULE 3 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_3 -j DROP
+ #
+ # Rule fw61-Policy 4 (global)
+ #
+ echo "Rule fw61-Policy 4 (global)"
+ #
+ $IPTABLES -N fw61-Policy_4 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 09:00 --timestop 17:00 --days Mon,Tue,Wed,Thu,Fri -j fw61-Policy_4
+ $IPTABLES -t mangle -A fw61-Policy_4 -j LOG --log-level info --log-prefix "RULE 4 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_4 -j DROP
+ #
+ # Rule fw61-Policy 5 (global)
+ #
+ echo "Rule fw61-Policy 5 (global)"
+ #
+ $IPTABLES -N fw61-Policy_5 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 01:01 --timestop 02:02 --days Sun,Mon -j fw61-Policy_5
+ $IPTABLES -t mangle -A fw61-Policy_5 -j LOG --log-level info --log-prefix "RULE 5 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_5 -j DROP
+ #
+ # Rule fw61-Policy 6 (global)
+ #
+ echo "Rule fw61-Policy 6 (global)"
+ #
+ $IPTABLES -N fw61-Policy_6 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 01:01 --timestop 02:02 --days Sun,Mon -j fw61-Policy_6
+ $IPTABLES -t mangle -A fw61-Policy_6 -j LOG --log-level info --log-prefix "RULE 6 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_6 -j DROP
+ #
+ # Rule fw61-Policy 7 (global)
+ #
+ echo "Rule fw61-Policy 7 (global)"
+ #
+ $IPTABLES -N fw61-Policy_7 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 00:00 --timestop 01:00 --days Fri,Sat -j fw61-Policy_7
+ $IPTABLES -t mangle -A fw61-Policy_7 -j LOG --log-level info --log-prefix "RULE 7 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_7 -j DROP
+ #
+ # Rule fw61-Policy 8 (global)
+ #
+ echo "Rule fw61-Policy 8 (global)"
+ #
+ $IPTABLES -N fw61-Policy_8 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 01:00 --timestop 02:00 --days Fri,Sat -j fw61-Policy_8
+ $IPTABLES -t mangle -A fw61-Policy_8 -j LOG --log-level info --log-prefix "RULE 8 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_8 -j DROP
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -N RULE_0
+ $IPTABLES -A OUTPUT -j RULE_0
+ $IPTABLES -A INPUT -j RULE_0
+ $IPTABLES -A FORWARD -j RULE_0
+ $IPTABLES -A RULE_0 -j LOG --log-level info --log-prefix "RULE 0 -- BRANCH "
+ $IPTABLES -N fw61-Policy
+ $IPTABLES -A RULE_0 -j fw61-Policy
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -N RULE_1
+ $IPTABLES -A OUTPUT -m time --timestart 00:00 --timestop 23:59 --days Sat -j RULE_1
+ $IPTABLES -A INPUT -m time --timestart 00:00 --timestop 23:59 --days Sat -j RULE_1
+ $IPTABLES -A FORWARD -m time --timestart 00:00 --timestop 23:59 --days Sat -j RULE_1
+ $IPTABLES -A RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A RULE_1 -j DROP
+
+
+ # ================ IPv6
+
+
+ # ================ Table 'filter', automatic rules
+ # target TCPMSS is not supported by ip6tables before v1.3.8
+
+ # accept established sessions
+ $IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy_ipv6
+ #
+ # Rule Policy_ipv6 0 (global)
+ #
+ echo "Rule Policy_ipv6 0 (global)"
+ #
+ $IP6TABLES -N Policy_ipv6_0
+ $IP6TABLES -A OUTPUT -j Policy_ipv6_0
+ $IP6TABLES -A INPUT -j Policy_ipv6_0
+ $IP6TABLES -A FORWARD -j Policy_ipv6_0
+ $IP6TABLES -A Policy_ipv6_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IP6TABLES -A Policy_ipv6_0 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:55:57 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " ipv6"
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall61-1.3.x.fw.orig b/test/ipt/firewall61-1.3.x.fw.orig
new file mode 100755
index 000000000..84c128ac0
--- /dev/null
+++ b/test/ipt/firewall61-1.3.x.fw.orig
@@ -0,0 +1,552 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:00 2011 PST by vadim
+#
+# files: * firewall61-1.3.x.fw
+#
+# Compiled for iptables 1.3.0
+#
+# testing time litmiting for iptables 1.3.x
+
+# firewall61-1.3.x:Policy_ipv6:: warning: target TCPMSS is not supported by ip6tables before v1.3.8
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth1 222.222.222.222/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # ================ Table 'mangle', automatic rules
+ $IPTABLES -t mangle -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
+
+
+
+ # ================ Table 'mangle', rule set fw61-Policy
+ #
+ # Rule fw61-Policy 0 (global)
+ #
+ echo "Rule fw61-Policy 0 (global)"
+ #
+ $IPTABLES -N fw61-Policy -t mangle
+ $IPTABLES -N fw61-Policy_0 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 00:00 --timestop 23:59 --days Sat -j fw61-Policy_0
+ $IPTABLES -t mangle -A fw61-Policy_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_0 -j DROP
+ #
+ # Rule fw61-Policy 1 (global)
+ #
+ echo "Rule fw61-Policy 1 (global)"
+ #
+ $IPTABLES -N fw61-Policy_1 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 00:00 --timestop 23:59 --days Sun -j fw61-Policy_1
+ $IPTABLES -t mangle -A fw61-Policy_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_1 -j DROP
+ #
+ # Rule fw61-Policy 2 (global)
+ #
+ echo "Rule fw61-Policy 2 (global)"
+ #
+ $IPTABLES -N fw61-Policy_2 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 18:00 --timestop 23:59 -j fw61-Policy_2
+ $IPTABLES -t mangle -A fw61-Policy_2 -j LOG --log-level info --log-prefix "RULE 2 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_2 -j DROP
+ #
+ # Rule fw61-Policy 3 (global)
+ #
+ echo "Rule fw61-Policy 3 (global)"
+ #
+ $IPTABLES -N fw61-Policy_3 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 00:00 --timestop 23:59 --days Sat,Sun -j fw61-Policy_3
+ $IPTABLES -t mangle -A fw61-Policy_3 -j LOG --log-level info --log-prefix "RULE 3 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_3 -j DROP
+ #
+ # Rule fw61-Policy 4 (global)
+ #
+ echo "Rule fw61-Policy 4 (global)"
+ #
+ $IPTABLES -N fw61-Policy_4 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 09:00 --timestop 17:00 --days Mon,Tue,Wed,Thu,Fri -j fw61-Policy_4
+ $IPTABLES -t mangle -A fw61-Policy_4 -j LOG --log-level info --log-prefix "RULE 4 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_4 -j DROP
+ #
+ # Rule fw61-Policy 5 (global)
+ #
+ echo "Rule fw61-Policy 5 (global)"
+ #
+ $IPTABLES -N fw61-Policy_5 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 01:01 --timestop 02:02 --days Sun,Mon -j fw61-Policy_5
+ $IPTABLES -t mangle -A fw61-Policy_5 -j LOG --log-level info --log-prefix "RULE 5 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_5 -j DROP
+ #
+ # Rule fw61-Policy 6 (global)
+ #
+ echo "Rule fw61-Policy 6 (global)"
+ #
+ $IPTABLES -N fw61-Policy_6 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 01:01 --timestop 02:02 --days Sun,Mon -j fw61-Policy_6
+ $IPTABLES -t mangle -A fw61-Policy_6 -j LOG --log-level info --log-prefix "RULE 6 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_6 -j DROP
+ #
+ # Rule fw61-Policy 7 (global)
+ #
+ echo "Rule fw61-Policy 7 (global)"
+ #
+ $IPTABLES -N fw61-Policy_7 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 00:00 --timestop 01:00 --days Fri,Sat -j fw61-Policy_7
+ $IPTABLES -t mangle -A fw61-Policy_7 -j LOG --log-level info --log-prefix "RULE 7 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_7 -j DROP
+ #
+ # Rule fw61-Policy 8 (global)
+ #
+ echo "Rule fw61-Policy 8 (global)"
+ #
+ $IPTABLES -N fw61-Policy_8 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 01:00 --timestop 02:00 --days Fri,Sat -j fw61-Policy_8
+ $IPTABLES -t mangle -A fw61-Policy_8 -j LOG --log-level info --log-prefix "RULE 8 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_8 -j DROP
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -N RULE_0
+ $IPTABLES -A OUTPUT -j RULE_0
+ $IPTABLES -A INPUT -j RULE_0
+ $IPTABLES -A FORWARD -j RULE_0
+ $IPTABLES -A RULE_0 -j LOG --log-level info --log-prefix "RULE 0 -- BRANCH "
+ $IPTABLES -N fw61-Policy
+ $IPTABLES -A RULE_0 -j fw61-Policy
+
+
+ # ================ IPv6
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # ================ Table 'mangle', automatic rules
+ # target TCPMSS is not supported by ip6tables before v1.3.8
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy_ipv6
+ #
+ # Rule Policy_ipv6 0 (global)
+ #
+ echo "Rule Policy_ipv6 0 (global)"
+ #
+ $IP6TABLES -N Policy_ipv6_0
+ $IP6TABLES -A OUTPUT -j Policy_ipv6_0
+ $IP6TABLES -A INPUT -j Policy_ipv6_0
+ $IP6TABLES -A FORWARD -j Policy_ipv6_0
+ $IP6TABLES -A Policy_ipv6_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IP6TABLES -A Policy_ipv6_0 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:00 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " ipv6"
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall61-1.4.fw.orig b/test/ipt/firewall61-1.4.fw.orig
new file mode 100755
index 000000000..156e9b021
--- /dev/null
+++ b/test/ipt/firewall61-1.4.fw.orig
@@ -0,0 +1,553 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:03 2011 PST by vadim
+#
+# files: * firewall61-1.4.fw
+#
+# Compiled for iptables 1.4.0
+#
+# testing time litmiting for iptables 1.4.0
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth1 222.222.222.222/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # ================ Table 'mangle', automatic rules
+ $IPTABLES -t mangle -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
+
+
+
+ # ================ Table 'mangle', rule set fw61-Policy
+ #
+ # Rule fw61-Policy 0 (global)
+ #
+ echo "Rule fw61-Policy 0 (global)"
+ #
+ $IPTABLES -N fw61-Policy -t mangle
+ $IPTABLES -N fw61-Policy_0 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 00:00 --timestop 23:59 --weekdays Sat -j fw61-Policy_0
+ $IPTABLES -t mangle -A fw61-Policy_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_0 -j DROP
+ #
+ # Rule fw61-Policy 1 (global)
+ #
+ echo "Rule fw61-Policy 1 (global)"
+ #
+ $IPTABLES -N fw61-Policy_1 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 00:00 --timestop 23:59 --weekdays Sun -j fw61-Policy_1
+ $IPTABLES -t mangle -A fw61-Policy_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_1 -j DROP
+ #
+ # Rule fw61-Policy 2 (global)
+ #
+ echo "Rule fw61-Policy 2 (global)"
+ #
+ $IPTABLES -N fw61-Policy_2 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 18:00 --timestop 23:59 -j fw61-Policy_2
+ $IPTABLES -t mangle -A fw61-Policy_2 -j LOG --log-level info --log-prefix "RULE 2 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_2 -j DROP
+ #
+ # Rule fw61-Policy 3 (global)
+ #
+ echo "Rule fw61-Policy 3 (global)"
+ #
+ $IPTABLES -N fw61-Policy_3 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 00:00 --timestop 23:59 --weekdays Sat,Sun -j fw61-Policy_3
+ $IPTABLES -t mangle -A fw61-Policy_3 -j LOG --log-level info --log-prefix "RULE 3 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_3 -j DROP
+ #
+ # Rule fw61-Policy 4 (global)
+ #
+ echo "Rule fw61-Policy 4 (global)"
+ #
+ $IPTABLES -N fw61-Policy_4 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 09:00 --timestop 17:00 --weekdays Mon,Tue,Wed,Thu,Fri -j fw61-Policy_4
+ $IPTABLES -t mangle -A fw61-Policy_4 -j LOG --log-level info --log-prefix "RULE 4 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_4 -j DROP
+ #
+ # Rule fw61-Policy 5 (global)
+ #
+ echo "Rule fw61-Policy 5 (global)"
+ #
+ $IPTABLES -N fw61-Policy_5 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 01:01 --timestop 02:02 --weekdays Sun,Mon -j fw61-Policy_5
+ $IPTABLES -t mangle -A fw61-Policy_5 -j LOG --log-level info --log-prefix "RULE 5 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_5 -j DROP
+ #
+ # Rule fw61-Policy 6 (global)
+ #
+ echo "Rule fw61-Policy 6 (global)"
+ #
+ $IPTABLES -N fw61-Policy_6 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --datestart 2008-03-13T01:01:00 --datestop 2010-01-01T02:02:00 --weekdays Sun,Mon -j fw61-Policy_6
+ $IPTABLES -t mangle -A fw61-Policy_6 -j LOG --log-level info --log-prefix "RULE 6 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_6 -j DROP
+ #
+ # Rule fw61-Policy 7 (global)
+ #
+ echo "Rule fw61-Policy 7 (global)"
+ #
+ $IPTABLES -N fw61-Policy_7 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --datestart 2008-03-13T00:00:00 --datestop 2010-01-01T01:00:00 --weekdays Fri,Sat -j fw61-Policy_7
+ $IPTABLES -t mangle -A fw61-Policy_7 -j LOG --log-level info --log-prefix "RULE 7 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_7 -j DROP
+ #
+ # Rule fw61-Policy 8 (global)
+ #
+ echo "Rule fw61-Policy 8 (global)"
+ #
+ $IPTABLES -N fw61-Policy_8 -t mangle
+ $IPTABLES -t mangle -A fw61-Policy -m time --timestart 01:00 --timestop 02:00 --weekdays Fri,Sat -j fw61-Policy_8
+ $IPTABLES -t mangle -A fw61-Policy_8 -j LOG --log-level info --log-prefix "RULE 8 -- DENY "
+ $IPTABLES -t mangle -A fw61-Policy_8 -j DROP
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -N RULE_0
+ $IPTABLES -A OUTPUT -j RULE_0
+ $IPTABLES -A INPUT -j RULE_0
+ $IPTABLES -A FORWARD -j RULE_0
+ $IPTABLES -A RULE_0 -j LOG --log-level info --log-prefix "RULE 0 -- BRANCH "
+ $IPTABLES -N fw61-Policy
+ $IPTABLES -A RULE_0 -j fw61-Policy
+
+
+ # ================ IPv6
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # ================ Table 'mangle', automatic rules
+ $IP6TABLES -t mangle -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy_ipv6
+ #
+ # Rule Policy_ipv6 0 (global)
+ #
+ echo "Rule Policy_ipv6 0 (global)"
+ #
+ $IP6TABLES -N Policy_ipv6_0
+ $IP6TABLES -A OUTPUT -j Policy_ipv6_0
+ $IP6TABLES -A INPUT -j Policy_ipv6_0
+ $IP6TABLES -A FORWARD -j Policy_ipv6_0
+ $IP6TABLES -A Policy_ipv6_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IP6TABLES -A Policy_ipv6_0 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:03 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " ipv6"
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall62.fw.orig b/test/ipt/firewall62.fw.orig
new file mode 100755
index 000000000..3626717c6
--- /dev/null
+++ b/test/ipt/firewall62.fw.orig
@@ -0,0 +1,603 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:05 2011 PST by vadim
+#
+# files: * firewall62.fw
+#
+# Compiled for iptables 1.4.0
+#
+# testing rules using UserService object
+# Note that iptables does not allow entering
+# iptables command that tries to match using module 'owner' in any chain
+# other than OUTPUT. This includes user defined chains too (it checks
+# how control passes to user defined chain and blocks command if
+# it appears that user defined chain gets control not from OUTPUT)
+
+# firewall62:Policy:0: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:2: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:4: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:5: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:5: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:6: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:7: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:8: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:8: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:9: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:9: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:10: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:10: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:11: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:11: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:12: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:13: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:16: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:16: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:17: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+# firewall62:Policy:17: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth1 222.222.222.222/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # ================ Table 'mangle', automatic rules
+ $IPTABLES -t mangle -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -A OUTPUT -m owner --uid-owner 2000 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -m owner --uid-owner 2000 -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -N Cid484A599620246.0
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 80 -m state --state NEW -j Cid484A599620246.0
+ $IPTABLES -A Cid484A599620246.0 -s 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid484A599620246.0 -s 222.222.222.222 -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -m owner --uid-owner 2000 -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -m owner --uid-owner 2000 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -A OUTPUT -s 192.168.1.1 -m owner --uid-owner 2000 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m owner --uid-owner 2000 -m state --state NEW -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -N Cid4848F1BB20246.0
+ $IPTABLES -A OUTPUT -m owner --uid-owner 2000 -m state --state NEW -j Cid4848F1BB20246.0
+ $IPTABLES -A Cid4848F1BB20246.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid4848F1BB20246.0 -d 222.222.222.222 -j ACCEPT
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -A OUTPUT -s ! 192.168.1.0/24 -m owner --uid-owner 2000 -m state --state NEW -j ACCEPT
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -A OUTPUT -m owner --uid-owner 2000 -m state --state NEW -j ACCEPT
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ # bug 2186568
+ $IPTABLES -A OUTPUT -m owner --uid-owner 500 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -m owner --uid-owner 2000 -m state --state NEW -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ # bug 2186568
+ $IPTABLES -N Cid55369X1137.0
+ $IPTABLES -A OUTPUT -m owner --uid-owner 500 -m state --state NEW -j Cid55369X1137.0
+ $IPTABLES -A OUTPUT -m owner --uid-owner 2000 -m state --state NEW -j Cid55369X1137.0
+ $IPTABLES -A Cid55369X1137.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid55369X1137.0 -d 222.222.222.222 -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ # bug 2186568
+ $IPTABLES -A OUTPUT -m owner ! --uid-owner 2000 -m state --state NEW -j ACCEPT
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ # bug 2186568
+ $IPTABLES -N Cid72626X1137.0
+ $IPTABLES -A OUTPUT -m owner ! --uid-owner 2000 -m state --state NEW -j Cid72626X1137.0
+ $IPTABLES -A Cid72626X1137.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid72626X1137.0 -d 222.222.222.222 -j ACCEPT
+ #
+ # Rule 14 (global)
+ #
+ echo "Rule 14 (global)"
+ #
+ # bug 2186568
+ $IPTABLES -N Cid124556X1137.0
+ $IPTABLES -A INPUT -s 192.168.1.1 -m state --state NEW -j Cid124556X1137.0
+ $IPTABLES -A INPUT -s 222.222.222.222 -m state --state NEW -j Cid124556X1137.0
+ $IPTABLES -A OUTPUT -m state --state NEW -j Cid124556X1137.0
+ $IPTABLES -A Cid124556X1137.0 -m owner --uid-owner 500 -j RETURN
+ $IPTABLES -A Cid124556X1137.0 -m owner --uid-owner 2000 -j RETURN
+ $IPTABLES -A Cid124556X1137.0 -j ACCEPT
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ # bug 2186568
+ $IPTABLES -N Cid124573X1137.0
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -m state --state NEW -j Cid124573X1137.0
+ $IPTABLES -A OUTPUT -d 222.222.222.222 -m state --state NEW -j Cid124573X1137.0
+ $IPTABLES -A INPUT -m state --state NEW -j Cid124573X1137.0
+ $IPTABLES -A Cid124573X1137.0 -m owner --uid-owner 500 -j RETURN
+ $IPTABLES -A Cid124573X1137.0 -m owner --uid-owner 2000 -j RETURN
+ $IPTABLES -A Cid124573X1137.0 -j ACCEPT
+ #
+ # Rule 16 (global)
+ #
+ echo "Rule 16 (global)"
+ #
+ # bug 2186568
+ $IPTABLES -A OUTPUT -m owner --uid-owner 2000 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -m owner --uid-owner 500 -m state --state NEW -j ACCEPT
+ #
+ # Rule 17 (global)
+ #
+ echo "Rule 17 (global)"
+ #
+ # bug 2186568
+ $IPTABLES -N Cid89930X1137.0
+ $IPTABLES -A OUTPUT -m owner --uid-owner 2000 -m state --state NEW -j Cid89930X1137.0
+ $IPTABLES -A OUTPUT -m owner --uid-owner 500 -m state --state NEW -j Cid89930X1137.0
+ $IPTABLES -A Cid89930X1137.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid89930X1137.0 -d 222.222.222.222 -j ACCEPT
+ #
+ # Rule 18 (global)
+ #
+ echo "Rule 18 (global)"
+ #
+ $IPTABLES -A OUTPUT -j DROP
+ $IPTABLES -A INPUT -j DROP
+ $IPTABLES -A FORWARD -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:05 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall63.fw.orig b/test/ipt/firewall63.fw.orig
new file mode 100755
index 000000000..a59759e12
--- /dev/null
+++ b/test/ipt/firewall63.fw.orig
@@ -0,0 +1,449 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:07 2011 PST by vadim
+#
+# files: * firewall63.fw
+#
+# Compiled for iptables 1.4.0
+#
+# testing TOS and DSCP matching
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth1 222.222.222.222/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # ================ Table 'mangle', automatic rules
+ $IPTABLES -t mangle -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -A OUTPUT -p all -m tos --tos 0x20 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p all -m tos --tos 0x20 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p all -m tos --tos 0x20 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -A OUTPUT -p all -m dscp --dscp 0x20 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p all -m dscp --dscp 0x20 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p all -m dscp --dscp 0x20 -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -A OUTPUT -p all -m dscp --dscp-class BE -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p all -m dscp --dscp-class BE -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p all -m dscp --dscp-class BE -m state --state NEW -j ACCEPT
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:07 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall7.fw.orig b/test/ipt/firewall7.fw.orig
new file mode 100755
index 000000000..d93c084a5
--- /dev/null
+++ b/test/ipt/firewall7.fw.orig
@@ -0,0 +1,533 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:10 2011 PST by vadim
+#
+# files: * firewall7.fw
+#
+# Compiled for iptables (any version)
+#
+# testing rules with broadcasts and multicasts and action-on-reject "TCP reset"
+
+# testing rules used for DHCP relay running on the firewall between interfaces eth0 and eth2
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth3 22.22.23.23/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 192.168.1.255 --dport 67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 255.255.255.255 --dport 67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (eth0)
+ #
+ echo "Rule 2 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 224.0.1.141 --dport 67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (eth0)
+ #
+ echo "Rule 3 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -s 0.0.0.0 -d 255.255.255.255 --dport 67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (eth0)
+ #
+ echo "Rule 4 (eth0)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -s 192.168.1.1 -d 255.255.255.255 --dport 68 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (eth2)
+ #
+ echo "Rule 5 (eth2)"
+ #
+ $IPTABLES -A OUTPUT -o eth2 -p udp -m udp -s 192.168.2.1 -d 192.168.2.10 --dport 67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 6 (eth2)
+ #
+ echo "Rule 6 (eth2)"
+ #
+ $IPTABLES -A INPUT -i eth2 -p udp -m udp -s 192.168.2.10 -d 192.168.1.1 --dport 67 -m state --state NEW -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -N RULE_7
+ $IPTABLES -A OUTPUT -d 255.255.255.255 -j RULE_7
+ $IPTABLES -A OUTPUT -d 192.168.1.255 -j RULE_7
+ $IPTABLES -A INPUT -d 255.255.255.255 -j RULE_7
+ $IPTABLES -A INPUT -d 192.168.1.255 -j RULE_7
+ $IPTABLES -A RULE_7 -j LOG --log-level debug
+ $IPTABLES -A RULE_7 -j DROP
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ # compiler should place rule in INPUT chain because this is broadcast destination
+ $IPTABLES -A OUTPUT -p udp -m udp -d 255.255.255.255 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p udp -m udp -d 255.255.255.255 --dport 68 -m state --state NEW -j ACCEPT
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ # compiler should place rule in INPUT chain because this is broadcast destination
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.255 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p udp -m udp -d 192.168.1.255 --dport 68 -m state --state NEW -j ACCEPT
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ # compiler should place rule in INPUT chain because this is broadcast destination
+ $IPTABLES -A OUTPUT -p udp -m udp -d 255.255.255.255 --dport 68 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p udp -m udp -d 255.255.255.255 --dport 68 -m state --state NEW -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ $IPTABLES -N RULE_11
+ $IPTABLES -A OUTPUT -d 224.0.1.141 -m state --state NEW -j RULE_11
+ $IPTABLES -A INPUT -d 224.0.1.141 -m state --state NEW -j RULE_11
+ $IPTABLES -A RULE_11 -j LOG --log-level debug
+ $IPTABLES -A RULE_11 -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ $IPTABLES -N RULE_12
+ $IPTABLES -A OUTPUT -d 224.0.0.5 -m state --state NEW -j RULE_12
+ $IPTABLES -A INPUT -d 224.0.0.5 -m state --state NEW -j RULE_12
+ $IPTABLES -A RULE_12 -j LOG --log-level debug
+ $IPTABLES -A RULE_12 -j ACCEPT
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 224.0.0.5 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 224.0.0.5 -m state --state NEW -j ACCEPT
+ #
+ # Rule 14 (global)
+ #
+ echo "Rule 14 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 224.0.0.0/4 -j DROP
+ $IPTABLES -A INPUT -d 224.0.0.0/4 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:10 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall70.fw.orig b/test/ipt/firewall70.fw.orig
new file mode 100755
index 000000000..7705ef643
--- /dev/null
+++ b/test/ipt/firewall70.fw.orig
@@ -0,0 +1,472 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:12 2011 PST by vadim
+#
+# files: * firewall70.fw iptables.sh
+#
+# Compiled for iptables (any version)
+#
+# this firewall translates outgoing connections using address of the particular interface (not external one). Also testing different cmbinations of objects in the policy rules on loopback interface. Finally, testing for a situation when dynamic interface "shades" a rule with old broadcast
+
+# Also the name of the script on the firewall is different
+
+# firewall70:very_long_ruleset_name_should_be_gt_30_chars:0: error: Chain name 'very_long_ruleset_name_should_be_gt_30_chars' is longer than 30 characters. Rule very_long_ruleset_name_should_be_gt_30_chars 0 (global)
+# firewall70:very_long_ruleset_name_should_be_gt_30_chars:0: error: Chain name 'very_long_ruleset_name_should_be_gt_30_chars_0' is longer than 30 characters. Rule very_long_ruleset_name_should_be_gt_30_chars 0 (global)
+# firewall70:very_long_ruleset_name_should_be_gt_30_chars:0: error: Chain name 'very_long_ruleset_name_should_be_gt_30_chars_0' is longer than 30 characters. Rule very_long_ruleset_name_should_be_gt_30_chars 0 (global)
+# firewall70:very_long_ruleset_name_should_be_gt_30_chars:0: error: Chain name 'very_long_ruleset_name_should_be_gt_30_chars' is longer than 30 characters. Rule very_long_ruleset_name_should_be_gt_30_chars 0 (global)
+# firewall70:very_long_ruleset_name_should_be_gt_30_chars:0: error: Chain name 'very_long_ruleset_name_should_be_gt_30_chars_0' is longer than 30 characters. Rule very_long_ruleset_name_should_be_gt_30_chars 0 (global)
+# firewall70:very_long_ruleset_name_should_be_gt_30_chars:0: error: Chain name 'very_long_ruleset_name_should_be_gt_30_chars_0' is longer than 30 characters. Rule very_long_ruleset_name_should_be_gt_30_chars 0 (global)
+
+# firewall70:not_quite_long_ruleset_name:0: error: Chain name 'not_quite_long_ruleset_name_0_3' is longer than 30 characters. Rule not_quite_long_ruleset_name 0 (global)
+# firewall70:not_quite_long_ruleset_name:0: error: Chain name 'not_quite_long_ruleset_name_0_3' is longer than 30 characters. Rule not_quite_long_ruleset_name 0 (global)
+# firewall70:not_quite_long_ruleset_name:0: error: Chain name 'not_quite_long_ruleset_name_0_3' is longer than 30 characters. Rule not_quite_long_ruleset_name 0 (global)
+# firewall70:not_quite_long_ruleset_name:0: error: Chain name 'not_quite_long_ruleset_name_0_3' is longer than 30 characters. Rule not_quite_long_ruleset_name 0 (global)
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo"
+ for i in eth0 eth1 lo ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth1 66.66.66.130/25" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set very_long_ruleset_name_should_be_gt_30_chars
+ #
+ # Rule very_long_ruleset_name_should_be_gt_30_chars 0 (global)
+ #
+ echo "Rule very_long_ruleset_name_should_be_gt_30_chars 0 (global)"
+ #
+ # firewall70:very_long_ruleset_name_should_be_gt_30_chars:0: error: Chain name 'very_long_ruleset_name_should_be_gt_30_chars' is longer than 30 characters. Rule very_long_ruleset_name_should_be_gt_30_chars 0 (global)
+ $IPTABLES -N very_long_ruleset_name_should_be_gt_30_chars
+ $IPTABLES -N very_long_ruleset_name_should_be_gt_30_chars_0
+ $IPTABLES -A very_long_ruleset_name_should_be_gt_30_chars -j very_long_ruleset_name_should_be_gt_30_chars_0
+ # firewall70:very_long_ruleset_name_should_be_gt_30_chars:0: error: Chain name 'very_long_ruleset_name_should_be_gt_30_chars_0' is longer than 30 characters. Rule very_long_ruleset_name_should_be_gt_30_chars 0 (global)
+ $IPTABLES -A very_long_ruleset_name_should_be_gt_30_chars_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ # firewall70:very_long_ruleset_name_should_be_gt_30_chars:0: error: Chain name 'very_long_ruleset_name_should_be_gt_30_chars_0' is longer than 30 characters. Rule very_long_ruleset_name_should_be_gt_30_chars 0 (global)
+ $IPTABLES -A very_long_ruleset_name_should_be_gt_30_chars_0 -j DROP
+ # ================ Table 'filter', rule set not_quite_long_ruleset_name
+ #
+ # Rule not_quite_long_ruleset_name 0 (global)
+ #
+ echo "Rule not_quite_long_ruleset_name 0 (global)"
+ #
+ $IPTABLES -N not_quite_long_ruleset_name
+ $IPTABLES -N Cid208737X59595.0
+ $IPTABLES -A not_quite_long_ruleset_name -s 22.22.22.0/24 -j Cid208737X59595.0
+ $IPTABLES -A not_quite_long_ruleset_name -s 33.33.33.0/24 -j Cid208737X59595.0
+ $IPTABLES -A Cid208737X59595.0 -d 66.66.66.130 -j RETURN
+ $IPTABLES -A Cid208737X59595.0 -d 192.168.1.1 -j RETURN
+ $IPTABLES -N not_quite_long_ruleset_name_0_3
+ $IPTABLES -A Cid208737X59595.0 -j not_quite_long_ruleset_name_0_3
+ # firewall70:not_quite_long_ruleset_name:0: error: Chain name 'not_quite_long_ruleset_name_0_3' is longer than 30 characters. Rule not_quite_long_ruleset_name 0 (global)
+ $IPTABLES -A not_quite_long_ruleset_name_0_3 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ # firewall70:not_quite_long_ruleset_name:0: error: Chain name 'not_quite_long_ruleset_name_0_3' is longer than 30 characters. Rule not_quite_long_ruleset_name 0 (global)
+ $IPTABLES -A not_quite_long_ruleset_name_0_3 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:12 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall71.fw.orig b/test/ipt/firewall71.fw.orig
new file mode 100755
index 000000000..c4e1ec19c
--- /dev/null
+++ b/test/ipt/firewall71.fw.orig
@@ -0,0 +1,488 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:15 2011 PST by vadim
+#
+# files: * firewall71.fw
+#
+# Compiled for iptables 1.4.0
+#
+# this firewall uses iptables-restore format.
+
+# two rule sets for the filter table, no rules in mangle, to make sure there is only one COMMIT for both
+
+# option "Clamp MSS to MTU" should be off because it puts rule
+# in mangle table.
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IPTABLES_RESTORE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth2"
+ for i in eth0 eth2 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # backup ssh access
+ echo "-A INPUT -p tcp -m tcp -s 192.168.1.1/255.255.255.255 --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT "
+ echo "-A OUTPUT -p tcp -m tcp -d 192.168.1.1/255.255.255.255 --sport 22 -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # drop TCP sessions opened prior firewall restart
+ echo "-A INPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP "
+ echo "-A OUTPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP "
+ echo "-A FORWARD -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP "
+ # drop packets that do not match any valid state
+ echo "-A OUTPUT -m state --state INVALID -j DROP "
+ echo "-A INPUT -m state --state INVALID -j DROP "
+ echo "-A FORWARD -m state --state INVALID -j DROP "
+ # ================ Table 'filter', rule set fw71_policy_2
+ #
+ # Rule fw71_policy_2 0 (global)
+ echo ":fw71_policy_2 - [0:0]"
+ echo ":fw71_policy_2_0 - [0:0]"
+ echo "-A fw71_policy_2 -j fw71_policy_2_0 "
+ echo "-A fw71_policy_2_0 -j LOG "
+ echo "-A fw71_policy_2_0 -j DROP "
+ #
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ echo ":Cid42351X60089.0 - [0:0]"
+ echo "-A OUTPUT -d 200.200.200.200 -m state --state NEW -j Cid42351X60089.0 "
+ echo "-A Cid42351X60089.0 -s 192.168.1.0/24 -j ACCEPT "
+ echo "-A Cid42351X60089.0 -s 192.168.2.0/24 -j ACCEPT "
+ echo ":Cid42351X60089.1 - [0:0]"
+ echo "-A FORWARD -d 200.200.200.200 -m state --state NEW -j Cid42351X60089.1 "
+ echo "-A Cid42351X60089.1 -s 192.168.1.0/24 -j ACCEPT "
+ echo "-A Cid42351X60089.1 -s 192.168.2.0/24 -j ACCEPT "
+ #
+ # Rule 1 (global)
+ echo ":RULE_1 - [0:0]"
+ echo "-A OUTPUT -j RULE_1 "
+ echo "-A INPUT -j RULE_1 "
+ echo "-A FORWARD -j RULE_1 "
+ echo "-A RULE_1 -j LOG "
+ echo "-A RULE_1 -j fw71_policy_2 "
+ #
+ # Rule 2 (global)
+ # Automatically generated 'catch all' rule
+ echo ":RULE_2 - [0:0]"
+ echo "-A OUTPUT -j RULE_2 "
+ echo "-A INPUT -j RULE_2 "
+ echo "-A FORWARD -j RULE_2 "
+ echo "-A RULE_2 -j LOG "
+ echo "-A RULE_2 -j DROP "
+ #
+ echo COMMIT
+
+
+
+ echo '*nat'
+ # ================ Table 'nat', rule set NAT
+ echo :PREROUTING ACCEPT [0:0]
+ echo :POSTROUTING ACCEPT [0:0]
+ echo :OUTPUT ACCEPT [0:0]
+ #
+ # Rule 0 (NAT)
+ echo "-A POSTROUTING -o eth2 -s 192.168.1.0/24 -j SNAT --to-source 192.168.2.1 "
+ #
+ echo COMMIT
+
+
+ ) | $IPTABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:15 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall72-1.3.x.fw.orig b/test/ipt/firewall72-1.3.x.fw.orig
new file mode 100755
index 000000000..25ea59ebb
--- /dev/null
+++ b/test/ipt/firewall72-1.3.x.fw.orig
@@ -0,0 +1,615 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:17 2011 PST by vadim
+#
+# files: * firewall72-1.3.x.fw
+#
+# Compiled for iptables 1.3.0
+#
+# this firewall is used to test a rule in the global policy of object "firewall"
+
+# firewall72-1.3.x:Policy:10: error: Rule '10 (eth1)' shadows rule '13 (eth1)' below it
+# firewall72-1.3.x:Policy:10: error: Rule '10 (eth1)' shadows rule '14 (eth1)' below it
+# firewall72-1.3.x:Policy:15: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+
+# firewall72-1.3.x::: warning: Can not add virtual address for object address
+# firewall72-1.3.x::: warning: Can not add virtual address for object address
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 33.33.33.33/24" ""
+ update_addresses_of_interface "eth1 172.16.1.1/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -s ! 192.168.1.0/24 -d 200.200.200.200 -j SNAT --to-source 22.22.22.23
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -p tcp -m tcp -s ! 192.168.1.0/24 -d 200.200.200.200 --dport 80 -j SNAT --to-source 22.22.22.23
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -d ! 192.168.2.0/24 -j SNAT --to-source 33.33.33.33
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -d ! 192.168.2.0/24 -j SNAT --to-source 172.16.1.1
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -s 192.168.1.0/24 -d ! 192.168.2.0/24 --dport 80 -j SNAT --to-source 33.33.33.33
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.0/24 -d ! 192.168.2.0/24 --dport 80 -j SNAT --to-source 172.16.1.1
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid212911X8629.0
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j Cid212911X8629.0
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j Cid212911X8629.0
+ $IPTABLES -t nat -A Cid212911X8629.0 -d 192.168.1.0/24 -j RETURN
+ $IPTABLES -t nat -A Cid212911X8629.0 -d 192.168.2.0/24 -j RETURN
+ $IPTABLES -t nat -A Cid212911X8629.0 -j SNAT --to-source 172.16.1.1
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.0/24 -d ! 192.168.1.1 --dport 80 -j REDIRECT --to-ports 3128
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (lo)
+ #
+ echo "Rule 0 (lo)"
+ #
+ $IPTABLES -A INPUT -i ! lo -s 127.0.0.1 -j DROP
+ $IPTABLES -A FORWARD -i ! lo -s 127.0.0.1 -j DROP
+ $IPTABLES -A OUTPUT -o ! lo -s 127.0.0.1 -j DROP
+ #
+ # Rule 1 (eth1)
+ #
+ echo "Rule 1 (eth1)"
+ #
+ $IPTABLES -N Cid107355X8629.0
+ $IPTABLES -A OUTPUT -o eth1 -s ! 192.168.1.0/24 -j Cid107355X8629.0
+ $IPTABLES -A Cid107355X8629.0 -d 33.33.33.33 -j DROP
+ $IPTABLES -A Cid107355X8629.0 -d 172.16.1.1 -j DROP
+ $IPTABLES -N Cid107355X8629.1
+ $IPTABLES -A FORWARD -o eth1 -s ! 192.168.1.0/24 -j Cid107355X8629.1
+ $IPTABLES -A Cid107355X8629.1 -d 33.33.33.33 -j DROP
+ $IPTABLES -A Cid107355X8629.1 -d 172.16.1.1 -j DROP
+ #
+ # Rule 2 (eth1)
+ #
+ echo "Rule 2 (eth1)"
+ #
+ $IPTABLES -N Cid107338X8629.0
+ $IPTABLES -A INPUT -i eth1 -d ! 192.168.1.0/24 -j Cid107338X8629.0
+ $IPTABLES -A Cid107338X8629.0 -s 33.33.33.33 -j DROP
+ $IPTABLES -A Cid107338X8629.0 -s 172.16.1.1 -j DROP
+ $IPTABLES -N Cid107338X8629.1
+ $IPTABLES -A FORWARD -i eth1 -d ! 192.168.1.0/24 -j Cid107338X8629.1
+ $IPTABLES -A Cid107338X8629.1 -s 33.33.33.33 -j DROP
+ $IPTABLES -A Cid107338X8629.1 -s 172.16.1.1 -j DROP
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -N Cid107321X8629.0
+ $IPTABLES -A INPUT -d 172.16.1.1 -j Cid107321X8629.0
+ $IPTABLES -A Cid107321X8629.0 -i + -p tcp -m tcp --dport 80 -j RETURN
+ $IPTABLES -A Cid107321X8629.0 -i + -j DROP
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -N Cid107304X8629.0
+ $IPTABLES -A INPUT -d 172.16.1.1 -j Cid107304X8629.0
+ $IPTABLES -A Cid107304X8629.0 -i + -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j RETURN
+ $IPTABLES -A Cid107304X8629.0 -i + -j DROP
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -N Cid107287X8629.0
+ $IPTABLES -A INPUT -d 172.16.1.1 -j Cid107287X8629.0
+ $IPTABLES -A Cid107287X8629.0 -i + -p icmp -m icmp --icmp-type 3/1 -j RETURN
+ $IPTABLES -A Cid107287X8629.0 -i + -j DROP
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -N Cid107270X8629.0
+ $IPTABLES -A INPUT -d 172.16.1.1 -j Cid107270X8629.0
+ $IPTABLES -A Cid107270X8629.0 -i + -p icmp -m icmp --icmp-type 3/1 -j RETURN
+ $IPTABLES -A Cid107270X8629.0 -i + -j DROP
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -N Cid107253X8629.0
+ $IPTABLES -A INPUT -d 172.16.1.1 -j Cid107253X8629.0
+ $IPTABLES -A Cid107253X8629.0 -i + -p 47 -j RETURN
+ $IPTABLES -A Cid107253X8629.0 -i + -j DROP
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -N Cid107236X8629.0
+ $IPTABLES -A INPUT -d 172.16.1.1 -j Cid107236X8629.0
+ $IPTABLES -A Cid107236X8629.0 -i + -p tcp -m tcp --tcp-flags ALL NONE -j RETURN
+ $IPTABLES -A Cid107236X8629.0 -i + -j DROP
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 172.16.1.1 -m mark ! --mark 16 -j DROP
+ $IPTABLES -A INPUT -d 172.16.1.1 -m mark ! --mark 16 -j DROP
+ #
+ # Rule 10 (eth1)
+ #
+ echo "Rule 10 (eth1)"
+ #
+ # Should use ! -i eth1 eventually
+ $IPTABLES -A FORWARD -i ! eth1 -p tcp -m tcp -d 192.168.1.0/24 --tcp-flags ALL NONE -j DROP
+ #
+ # Rule 11 (eth1)
+ #
+ echo "Rule 11 (eth1)"
+ #
+ # Should use ! -i eth1 eventually
+ $IPTABLES -N Cid107185X8629.0
+ $IPTABLES -A FORWARD -i ! eth1 -d 192.168.1.0/24 -j Cid107185X8629.0
+ $IPTABLES -A Cid107185X8629.0 -p tcp -m tcp --tcp-flags ALL NONE -j RETURN
+ $IPTABLES -A Cid107185X8629.0 -j DROP
+ #
+ # Rule 12 (eth1)
+ #
+ echo "Rule 12 (eth1)"
+ #
+ # Should use ! -i eth1 eventually
+ $IPTABLES -A OUTPUT -o ! eth1 -p tcp -m tcp -d 192.168.1.0/24 --tcp-flags ALL NONE -j DROP
+ $IPTABLES -A FORWARD -o ! eth1 -p tcp -m tcp -d 192.168.1.0/24 --tcp-flags ALL NONE -j DROP
+ #
+ # Rule 13 (eth1)
+ #
+ echo "Rule 13 (eth1)"
+ #
+ # Should use ! -i eth1 eventually
+ $IPTABLES -A FORWARD -i ! eth1 -p tcp -m tcp -d 192.168.1.0/24 --tcp-flags ALL NONE -j DROP
+ $IPTABLES -A OUTPUT -o ! eth1 -p tcp -m tcp -d 192.168.1.0/24 --tcp-flags ALL NONE -j DROP
+ $IPTABLES -A FORWARD -o ! eth1 -p tcp -m tcp -d 192.168.1.0/24 --tcp-flags ALL NONE -j DROP
+ #
+ # Rule 14 (eth1)
+ #
+ echo "Rule 14 (eth1)"
+ #
+ # Should use ! -i eth1 eventually
+ $IPTABLES -A FORWARD -i ! eth1 -p tcp -m tcp -d 192.168.1.0/24 --tcp-flags ALL NONE -j DROP
+ $IPTABLES -A OUTPUT -o ! eth1 -p tcp -m tcp -d 192.168.1.0/24 --tcp-flags ALL NONE -j DROP
+ $IPTABLES -A FORWARD -o ! eth1 -p tcp -m tcp -d 192.168.1.0/24 --tcp-flags ALL NONE -j DROP
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 172.16.1.1 -m owner ! --uid-owner 500 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:17 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall72-1.4.3.fw.orig b/test/ipt/firewall72-1.4.3.fw.orig
new file mode 100755
index 000000000..9c8048ad6
--- /dev/null
+++ b/test/ipt/firewall72-1.4.3.fw.orig
@@ -0,0 +1,615 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:19 2011 PST by vadim
+#
+# files: * firewall72-1.4.3.fw
+#
+# Compiled for iptables 1.4.3
+#
+# this firewall is used to test a rule in the global policy of object "firewall"
+
+# firewall72-1.4.3:Policy:10: error: Rule '10 (eth1)' shadows rule '13 (eth1)' below it
+# firewall72-1.4.3:Policy:10: error: Rule '10 (eth1)' shadows rule '14 (eth1)' below it
+# firewall72-1.4.3:Policy:15: warning: Iptables does not support module 'owner' in a chain other than OUTPUT
+
+# firewall72-1.4.3::: warning: Can not add virtual address for object address
+# firewall72-1.4.3::: warning: Can not add virtual address for object address
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 33.33.33.33/24" ""
+ update_addresses_of_interface "eth1 172.16.1.1/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ ! -s 192.168.1.0/24 -d 200.200.200.200 -j SNAT --to-source 22.22.22.23
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -p tcp -m tcp ! -s 192.168.1.0/24 -d 200.200.200.200 --dport 80 -j SNAT --to-source 22.22.22.23
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 ! -d 192.168.2.0/24 -j SNAT --to-source 33.33.33.33
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 ! -d 192.168.2.0/24 -j SNAT --to-source 172.16.1.1
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -p tcp -m tcp -s 192.168.1.0/24 ! -d 192.168.2.0/24 --dport 80 -j SNAT --to-source 33.33.33.33
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -s 192.168.1.0/24 ! -d 192.168.2.0/24 --dport 80 -j SNAT --to-source 172.16.1.1
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ $IPTABLES -t nat -N Cid213031X8629.0
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j Cid213031X8629.0
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -s 192.168.1.0/24 -j Cid213031X8629.0
+ $IPTABLES -t nat -A Cid213031X8629.0 -d 192.168.1.0/24 -j RETURN
+ $IPTABLES -t nat -A Cid213031X8629.0 -d 192.168.2.0/24 -j RETURN
+ $IPTABLES -t nat -A Cid213031X8629.0 -j SNAT --to-source 172.16.1.1
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.168.1.0/24 ! -d 192.168.1.1 --dport 80 -j REDIRECT --to-ports 3128
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (lo)
+ #
+ echo "Rule 0 (lo)"
+ #
+ $IPTABLES -A INPUT ! -i lo -s 127.0.0.1 -j DROP
+ $IPTABLES -A FORWARD ! -i lo -s 127.0.0.1 -j DROP
+ $IPTABLES -A OUTPUT ! -o lo -s 127.0.0.1 -j DROP
+ #
+ # Rule 1 (eth1)
+ #
+ echo "Rule 1 (eth1)"
+ #
+ $IPTABLES -N Cid170430X8629.0
+ $IPTABLES -A OUTPUT -o eth1 ! -s 192.168.1.0/24 -j Cid170430X8629.0
+ $IPTABLES -A Cid170430X8629.0 -d 33.33.33.33 -j DROP
+ $IPTABLES -A Cid170430X8629.0 -d 172.16.1.1 -j DROP
+ $IPTABLES -N Cid170430X8629.1
+ $IPTABLES -A FORWARD -o eth1 ! -s 192.168.1.0/24 -j Cid170430X8629.1
+ $IPTABLES -A Cid170430X8629.1 -d 33.33.33.33 -j DROP
+ $IPTABLES -A Cid170430X8629.1 -d 172.16.1.1 -j DROP
+ #
+ # Rule 2 (eth1)
+ #
+ echo "Rule 2 (eth1)"
+ #
+ $IPTABLES -N Cid170442X8629.0
+ $IPTABLES -A INPUT -i eth1 ! -d 192.168.1.0/24 -j Cid170442X8629.0
+ $IPTABLES -A Cid170442X8629.0 -s 33.33.33.33 -j DROP
+ $IPTABLES -A Cid170442X8629.0 -s 172.16.1.1 -j DROP
+ $IPTABLES -N Cid170442X8629.1
+ $IPTABLES -A FORWARD -i eth1 ! -d 192.168.1.0/24 -j Cid170442X8629.1
+ $IPTABLES -A Cid170442X8629.1 -s 33.33.33.33 -j DROP
+ $IPTABLES -A Cid170442X8629.1 -s 172.16.1.1 -j DROP
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -N Cid170454X8629.0
+ $IPTABLES -A INPUT -d 172.16.1.1 -j Cid170454X8629.0
+ $IPTABLES -A Cid170454X8629.0 -i + -p tcp -m tcp --dport 80 -j RETURN
+ $IPTABLES -A Cid170454X8629.0 -i + -j DROP
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -N Cid170466X8629.0
+ $IPTABLES -A INPUT -d 172.16.1.1 -j Cid170466X8629.0
+ $IPTABLES -A Cid170466X8629.0 -i + -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j RETURN
+ $IPTABLES -A Cid170466X8629.0 -i + -j DROP
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -N Cid170478X8629.0
+ $IPTABLES -A INPUT -d 172.16.1.1 -j Cid170478X8629.0
+ $IPTABLES -A Cid170478X8629.0 -i + -p icmp -m icmp --icmp-type 3/1 -j RETURN
+ $IPTABLES -A Cid170478X8629.0 -i + -j DROP
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -N Cid170490X8629.0
+ $IPTABLES -A INPUT -d 172.16.1.1 -j Cid170490X8629.0
+ $IPTABLES -A Cid170490X8629.0 -i + -p icmp -m icmp --icmp-type 3/1 -j RETURN
+ $IPTABLES -A Cid170490X8629.0 -i + -j DROP
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -N Cid170502X8629.0
+ $IPTABLES -A INPUT -d 172.16.1.1 -j Cid170502X8629.0
+ $IPTABLES -A Cid170502X8629.0 -i + -p 47 -j RETURN
+ $IPTABLES -A Cid170502X8629.0 -i + -j DROP
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -N Cid170514X8629.0
+ $IPTABLES -A INPUT -d 172.16.1.1 -j Cid170514X8629.0
+ $IPTABLES -A Cid170514X8629.0 -i + -p tcp -m tcp --tcp-flags ALL NONE -j RETURN
+ $IPTABLES -A Cid170514X8629.0 -i + -j DROP
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 172.16.1.1 -m mark ! --mark 16 -j DROP
+ $IPTABLES -A INPUT -d 172.16.1.1 -m mark ! --mark 16 -j DROP
+ #
+ # Rule 10 (eth1)
+ #
+ echo "Rule 10 (eth1)"
+ #
+ # Should use ! -i eth1 eventually
+ $IPTABLES -A FORWARD ! -i eth1 -p tcp -m tcp -d 192.168.1.0/24 --tcp-flags ALL NONE -j DROP
+ #
+ # Rule 11 (eth1)
+ #
+ echo "Rule 11 (eth1)"
+ #
+ # Should use ! -i eth1 eventually
+ $IPTABLES -N Cid170550X8629.0
+ $IPTABLES -A FORWARD ! -i eth1 -d 192.168.1.0/24 -j Cid170550X8629.0
+ $IPTABLES -A Cid170550X8629.0 -p tcp -m tcp --tcp-flags ALL NONE -j RETURN
+ $IPTABLES -A Cid170550X8629.0 -j DROP
+ #
+ # Rule 12 (eth1)
+ #
+ echo "Rule 12 (eth1)"
+ #
+ # Should use ! -i eth1 eventually
+ $IPTABLES -A OUTPUT ! -o eth1 -p tcp -m tcp -d 192.168.1.0/24 --tcp-flags ALL NONE -j DROP
+ $IPTABLES -A FORWARD ! -o eth1 -p tcp -m tcp -d 192.168.1.0/24 --tcp-flags ALL NONE -j DROP
+ #
+ # Rule 13 (eth1)
+ #
+ echo "Rule 13 (eth1)"
+ #
+ # Should use ! -i eth1 eventually
+ $IPTABLES -A FORWARD ! -i eth1 -p tcp -m tcp -d 192.168.1.0/24 --tcp-flags ALL NONE -j DROP
+ $IPTABLES -A OUTPUT ! -o eth1 -p tcp -m tcp -d 192.168.1.0/24 --tcp-flags ALL NONE -j DROP
+ $IPTABLES -A FORWARD ! -o eth1 -p tcp -m tcp -d 192.168.1.0/24 --tcp-flags ALL NONE -j DROP
+ #
+ # Rule 14 (eth1)
+ #
+ echo "Rule 14 (eth1)"
+ #
+ # Should use ! -i eth1 eventually
+ $IPTABLES -A FORWARD ! -i eth1 -p tcp -m tcp -d 192.168.1.0/24 --tcp-flags ALL NONE -j DROP
+ $IPTABLES -A OUTPUT ! -o eth1 -p tcp -m tcp -d 192.168.1.0/24 --tcp-flags ALL NONE -j DROP
+ $IPTABLES -A FORWARD ! -o eth1 -p tcp -m tcp -d 192.168.1.0/24 --tcp-flags ALL NONE -j DROP
+ #
+ # Rule 15 (global)
+ #
+ echo "Rule 15 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 172.16.1.1 -m owner ! --uid-owner 500 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:19 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall73.fw.orig b/test/ipt/firewall73.fw.orig
new file mode 100755
index 000000000..2a53d33cb
--- /dev/null
+++ b/test/ipt/firewall73.fw.orig
@@ -0,0 +1,583 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:22 2011 PST by vadim
+#
+# files: * firewall73.fw
+#
+# Compiled for iptables 1.4.3
+#
+# testing for "-i +" that is generated
+# when interface rule element is "any"
+# but direction is inbound. Trying different
+# combinations. Bug 2822098
+# "Firewall is part of any" is on
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 33.33.33.33/24" ""
+ update_addresses_of_interface "eth1 172.16.1.1/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -j DROP
+ $IPTABLES -A FORWARD -i eth0 -j DROP
+ $IPTABLES -A OUTPUT -o eth0 -j DROP
+ $IPTABLES -A FORWARD -o eth0 -j DROP
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -j DROP
+ $IPTABLES -A FORWARD -i eth0 -j DROP
+ #
+ # Rule 2 (eth0)
+ #
+ echo "Rule 2 (eth0)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -j DROP
+ $IPTABLES -A FORWARD -o eth0 -j DROP
+ #
+ # Rule 3 (lo)
+ #
+ echo "Rule 3 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -j DROP
+ $IPTABLES -A OUTPUT -o lo -j DROP
+ #
+ # Rule 4 (lo)
+ #
+ echo "Rule 4 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -j DROP
+ #
+ # Rule 5 (lo)
+ #
+ echo "Rule 5 (lo)"
+ #
+ $IPTABLES -A OUTPUT -o lo -j DROP
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -A OUTPUT -j DROP
+ $IPTABLES -A INPUT -j DROP
+ $IPTABLES -A FORWARD -j DROP
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -A INPUT -j DROP
+ $IPTABLES -A FORWARD -i + -j DROP
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -A OUTPUT -j DROP
+ $IPTABLES -A FORWARD -o + -j DROP
+ #
+ # Rule 9 (eth0)
+ #
+ echo "Rule 9 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -j DROP
+ $IPTABLES -A OUTPUT -o eth0 -d 33.33.33.33 -j DROP
+ $IPTABLES -A OUTPUT -o eth0 -d 172.16.1.1 -j DROP
+ #
+ # Rule 10 (eth0)
+ #
+ echo "Rule 10 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -j DROP
+ #
+ # Rule 11 (eth0)
+ #
+ echo "Rule 11 (eth0)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -d 33.33.33.33 -j DROP
+ $IPTABLES -A OUTPUT -o eth0 -d 172.16.1.1 -j DROP
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 33.33.33.33 -j DROP
+ $IPTABLES -A OUTPUT -d 172.16.1.1 -j DROP
+ $IPTABLES -A INPUT -j DROP
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ $IPTABLES -A INPUT -j DROP
+ #
+ # Rule 14 (global)
+ #
+ echo "Rule 14 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 33.33.33.33 -j DROP
+ $IPTABLES -A OUTPUT -d 172.16.1.1 -j DROP
+ $IPTABLES -A FORWARD -o + -d 33.33.33.33 -j DROP
+ $IPTABLES -A FORWARD -o + -d 172.16.1.1 -j DROP
+ #
+ # Rule 15 (eth0)
+ #
+ echo "Rule 15 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -s 33.33.33.33 -j DROP
+ $IPTABLES -A INPUT -i eth0 -s 172.16.1.1 -j DROP
+ $IPTABLES -A FORWARD -i eth0 -s 33.33.33.33 -j DROP
+ $IPTABLES -A FORWARD -i eth0 -s 172.16.1.1 -j DROP
+ $IPTABLES -A OUTPUT -o eth0 -j DROP
+ #
+ # Rule 16 (eth0)
+ #
+ echo "Rule 16 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -s 33.33.33.33 -j DROP
+ $IPTABLES -A INPUT -i eth0 -s 172.16.1.1 -j DROP
+ $IPTABLES -A FORWARD -i eth0 -s 33.33.33.33 -j DROP
+ $IPTABLES -A FORWARD -i eth0 -s 172.16.1.1 -j DROP
+ #
+ # Rule 17 (eth0)
+ #
+ echo "Rule 17 (eth0)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -j DROP
+ #
+ # Rule 18 (global)
+ #
+ echo "Rule 18 (global)"
+ #
+ $IPTABLES -A INPUT -s 33.33.33.33 -j DROP
+ $IPTABLES -A INPUT -s 172.16.1.1 -j DROP
+ $IPTABLES -A OUTPUT -j DROP
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ $IPTABLES -A INPUT -s 33.33.33.33 -j DROP
+ $IPTABLES -A INPUT -s 172.16.1.1 -j DROP
+ $IPTABLES -A FORWARD -i + -s 33.33.33.33 -j DROP
+ $IPTABLES -A FORWARD -i + -s 172.16.1.1 -j DROP
+ #
+ # Rule 20 (global)
+ #
+ echo "Rule 20 (global)"
+ #
+ $IPTABLES -A OUTPUT -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:22 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall74.fw.orig b/test/ipt/firewall74.fw.orig
new file mode 100755
index 000000000..794171c12
--- /dev/null
+++ b/test/ipt/firewall74.fw.orig
@@ -0,0 +1,435 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:24 2011 PST by vadim
+#
+# files: * firewall74.fw
+#
+# Compiled for iptables 1.4.0
+#
+# this firewall uses iptables-restore format and has no rules
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IPTABLES_RESTORE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth2"
+ for i in eth0 eth2 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+
+ (
+
+ echo '*filter'
+ # ================ Table 'filter', automatic rules
+ echo :INPUT DROP [0:0]
+ echo :FORWARD DROP [0:0]
+ echo :OUTPUT DROP [0:0]
+ # accept established sessions
+ echo "-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ echo "-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # backup ssh access
+ echo "-A INPUT -p tcp -m tcp -s 192.168.1.1/255.255.255.255 --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT "
+ echo "-A OUTPUT -p tcp -m tcp -d 192.168.1.1/255.255.255.255 --sport 22 -m state --state ESTABLISHED,RELATED -j ACCEPT "
+ # drop TCP sessions opened prior firewall restart
+ echo "-A INPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP "
+ echo "-A OUTPUT -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP "
+ echo "-A FORWARD -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP "
+ # drop packets that do not match any valid state
+ echo "-A OUTPUT -m state --state INVALID -j DROP "
+ echo "-A INPUT -m state --state INVALID -j DROP "
+ echo "-A FORWARD -m state --state INVALID -j DROP "
+
+ echo COMMIT
+
+
+
+
+ ) | $IPTABLES_RESTORE; IPTABLES_RESTORE_RES=$?
+ test $IPTABLES_RESTORE_RES != 0 && run_epilog_and_exit $IPTABLES_RESTORE_RES
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:24 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall8.fw.orig b/test/ipt/firewall8.fw.orig
new file mode 100755
index 000000000..8c5972254
--- /dev/null
+++ b/test/ipt/firewall8.fw.orig
@@ -0,0 +1,418 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:26 2011 PST by vadim
+#
+# files: * firewall8.fw
+#
+# Compiled for iptables (any version)
+#
+# this firewall is used to test a rule in the global policy of object "firewall"
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 33.33.33.33/24" ""
+ update_addresses_of_interface "eth1 172.16.1.1/24" ""
+ update_addresses_of_interface "eth2 192.168.100.1/24" ""
+ getaddr ppp0 i_ppp0
+ getaddr6 ppp0 i_ppp0_v6
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:26 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall80.fw.orig b/test/ipt/firewall80.fw.orig
new file mode 100755
index 000000000..6a71f2cbd
--- /dev/null
+++ b/test/ipt/firewall80.fw.orig
@@ -0,0 +1,459 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:28 2011 PST by vadim
+#
+# files: * firewall80.fw
+#
+# Compiled for iptables (any version)
+#
+# Branch rules in NAT
+
+# firewall80:NAT:0: warning: Translated Src, Dst and Srv are ignored in the NAT rule with action 'Branch'
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.0.2.1/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth1 192.168.1.100/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT_1
+ #
+ # Rule NAT_1 0 (NAT)
+ #
+ echo "Rule NAT_1 0 (NAT)"
+ #
+ # DNAT Rule
+ $IPTABLES -t nat -N NAT_1_PREROUTING
+ $IPTABLES -t nat -A NAT_1_PREROUTING -d 192.0.2.1 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A OUTPUT -d 192.0.2.1 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule NAT_1 1 (NAT)
+ #
+ echo "Rule NAT_1 1 (NAT)"
+ #
+ # SNAT rule
+ $IPTABLES -t nat -N NAT_1_POSTROUTING
+ $IPTABLES -t nat -A NAT_1_POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 192.0.2.1
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ # Branch rule with actual translation. Translation is ignored and warning should be issued
+ # firewall80:NAT:0: warning: Translated Src, Dst and Srv are ignored in the NAT rule with action 'Branch'
+ $IPTABLES -t nat -A POSTROUTING -d 192.0.2.1 -j NAT_1_POSTROUTING
+ # firewall80:NAT:0: warning: Translated Src, Dst and Srv are ignored in the NAT rule with action 'Branch'
+ $IPTABLES -t nat -A PREROUTING -d 192.0.2.1 -j NAT_1_PREROUTING
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ # DNAT Rule
+ $IPTABLES -t nat -A POSTROUTING -j NAT_1_POSTROUTING
+ $IPTABLES -t nat -A PREROUTING -j NAT_1_PREROUTING
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ # for #1686
+ $IPTABLES -t nat -A POSTROUTING -p tcp -m tcp -s 192.0.2.1 --dport 10000:11000 -j NAT_1_POSTROUTING
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.0.2.1 --dport 10000:11000 -j NAT_1_PREROUTING
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ # for #1686
+ $IPTABLES -t nat -A POSTROUTING -p tcp -m tcp -s 192.0.2.1 --dport 10000:11000 -j NAT_1_POSTROUTING
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -s 192.0.2.1 --dport 10000:11000 -j NAT_1_PREROUTING
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:28 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall81.fw.orig b/test/ipt/firewall81.fw.orig
new file mode 100755
index 000000000..04e6e4901
--- /dev/null
+++ b/test/ipt/firewall81.fw.orig
@@ -0,0 +1,479 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:31 2011 PST by vadim
+#
+# files: * firewall81.fw
+#
+# Compiled for iptables (any version)
+#
+# This firewall has no "top" rule set objects.
+
+# firewall81::: warning: Missing top level NAT ruleset
+# firewall81::: warning: Missing top level Policy ruleset
+
+# firewall81:NAT_2:0: warning: Translated Src, Dst and Srv are ignored in the NAT rule with action 'Branch'
+# firewall81:NAT_2:0: warning: NAT branching rule does not have information about targets used in the branch ruleset to choose proper chain in the nat table. Will split the rule and place it in both PREROUTNING and POSTROUTING
+# firewall81:NAT_2:1: warning: NAT branching rule does not have information about targets used in the branch ruleset to choose proper chain in the nat table. Will split the rule and place it in both PREROUTNING and POSTROUTING
+
+# firewall81:Policy:: warning: Log prefix has been truncated to 29 characters
+# firewall81:Policy:: warning: Log prefix has been truncated to 29 characters
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.0.2.1/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth1 192.168.1.100/24" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+
+
+ # ================ Table 'nat', rule set NAT_2
+ #
+ # Rule NAT_2 0 (NAT)
+ #
+ echo "Rule NAT_2 0 (NAT)"
+ #
+ # Branch rule with actual translation.
+ # Translation is ignored and warning should be issued
+ # firewall81:NAT_2:0: warning: NAT branching rule does not have information about targets used in the branch ruleset to choose proper chain in the nat table. Will split the rule and place it in both PREROUTNING and POSTROUTING
+ $IPTABLES -t nat -N NAT_1
+ $IPTABLES -t nat -A POSTROUTING -d 192.0.2.1 -j NAT_1
+ # firewall81:NAT_2:0: warning: NAT branching rule does not have information about targets used in the branch ruleset to choose proper chain in the nat table. Will split the rule and place it in both PREROUTNING and POSTROUTING
+ $IPTABLES -t nat -A PREROUTING -d 192.0.2.1 -j NAT_1
+ #
+ # Rule NAT_2 1 (NAT)
+ #
+ echo "Rule NAT_2 1 (NAT)"
+ #
+ # DNAT Rule
+ # firewall81:NAT_2:1: warning: NAT branching rule does not have information about targets used in the branch ruleset to choose proper chain in the nat table. Will split the rule and place it in both PREROUTNING and POSTROUTING
+ $IPTABLES -t nat -A POSTROUTING -j NAT_1
+ # firewall81:NAT_2:1: warning: NAT branching rule does not have information about targets used in the branch ruleset to choose proper chain in the nat table. Will split the rule and place it in both PREROUTNING and POSTROUTING
+ $IPTABLES -t nat -A PREROUTING -j NAT_1
+
+ # ================ Table 'nat', rule set NAT_1
+ #
+ # Rule NAT_1 0 (NAT)
+ #
+ echo "Rule NAT_1 0 (NAT)"
+ #
+ # DNAT Rule
+ $IPTABLES -t nat -N NAT_1_PREROUTING
+ $IPTABLES -t nat -A NAT_1_PREROUTING -d 192.0.2.1 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule NAT_1 1 (NAT)
+ #
+ echo "Rule NAT_1 1 (NAT)"
+ #
+ # SNAT rule
+ $IPTABLES -t nat -N NAT_1_POSTROUTING
+ $IPTABLES -t nat -A NAT_1_POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 192.0.2.1
+
+ # ================ Table 'nat', rule set NAT_1
+ #
+ # Rule NAT_1 0 (NAT)
+ #
+ echo "Rule NAT_1 0 (NAT)"
+ #
+ # DNAT Rule
+ $IPTABLES -t nat -A NAT_1_PREROUTING -d 192.0.2.1 -j DNAT --to-destination 192.168.1.10
+ #
+ # Rule NAT_1 1 (NAT)
+ #
+ echo "Rule NAT_1 1 (NAT)"
+ #
+ # SNAT rule
+ $IPTABLES -t nat -A NAT_1_POSTROUTING -o eth+ -s 192.168.1.0/24 -j SNAT --to-source 192.0.2.1
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -N Policy
+ $IPTABLES -N RULE_0
+ $IPTABLES -A Policy -j RULE_0
+ $IPTABLES -A RULE_0 -j LOG --log-level debug --log-prefix "RULE 0 -- DENY on interface g"
+ $IPTABLES -A RULE_0 -j DROP
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:31 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall82.fw.orig b/test/ipt/firewall82.fw.orig
new file mode 100755
index 000000000..610354340
--- /dev/null
+++ b/test/ipt/firewall82.fw.orig
@@ -0,0 +1,474 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:34 2011 PST by vadim
+#
+# files: * firewall82.fw
+#
+# Compiled for iptables (any version)
+#
+# This firewall has two interfaces. Eth0 faces outside and has a dynamic address; eth1 faces inside.
+# Policy includes basic rules to permit unrestricted outbound access and anti-spoofing rules. Access to the firewall is permitted only from internal network and only using SSH. The firewall uses one of the machines on internal network for DNS. Internal network is configured with address 192.168.1.0/255.255.255.0
+
+# firewall82:Policy:0: warning: Rule set Policy of firewall firewall82 has branching rule that loops back to it
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo"
+ for i in eth0 eth1 lo ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth1 192.168.1.1/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ getaddr eth0 i_eth0
+ getaddr6 eth0 i_eth0_v6
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j MASQUERADE
+
+
+
+ # ================ Table 'filter', rule set Policy_A
+ #
+ # Rule Policy_A 0 (global)
+ #
+ echo "Rule Policy_A 0 (global)"
+ #
+ $IPTABLES -N Policy_A
+ $IPTABLES -N Policy_B
+ $IPTABLES -A Policy_A -j Policy_B
+ #
+ # Rule Policy_A 1 (global)
+ #
+ echo "Rule Policy_A 1 (global)"
+ #
+ # recursive branching
+ $IPTABLES -N Policy
+ $IPTABLES -A Policy_A -j Policy
+ #
+ # Rule Policy_A 2 (global)
+ #
+ echo "Rule Policy_A 2 (global)"
+ #
+ $IPTABLES -A Policy_A -j Policy_A
+ # ================ Table 'filter', rule set Policy_B
+ #
+ # Rule Policy_B 0 (global)
+ #
+ echo "Rule Policy_B 0 (global)"
+ #
+ $IPTABLES -A Policy_B -d 192.0.2.100 -m state --state NEW -j ACCEPT
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ # firewall82:Policy:0: warning: Rule set Policy of firewall firewall82 has branching rule that loops back to it
+ $IPTABLES -A OUTPUT -j Policy_A
+ # firewall82:Policy:0: warning: Rule set Policy of firewall firewall82 has branching rule that loops back to it
+ $IPTABLES -A INPUT -j Policy_A
+ # firewall82:Policy:0: warning: Rule set Policy of firewall firewall82 has branching rule that loops back to it
+ $IPTABLES -A FORWARD -j Policy_A
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:34 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall82_A.fw.orig b/test/ipt/firewall82_A.fw.orig
new file mode 100755
index 000000000..59e384508
--- /dev/null
+++ b/test/ipt/firewall82_A.fw.orig
@@ -0,0 +1,466 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:36 2011 PST by vadim
+#
+# files: * firewall82_A.fw
+#
+# Compiled for iptables (any version)
+#
+# this object is used to hold branch rulesets for firewall82
+
+# firewall82_A:Policy_A:1: warning: Rule set Policy_A of firewall firewall82_A has branching rule that loops back to it
+# firewall82_A:Policy_A:1: warning: Rule set Policy_A of firewall firewall82_A has branching rule that loops back to it
+# firewall82_A:Policy_A:2: warning: Rule set Policy_A of firewall firewall82_A has branching rule that loops back to it
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy_B
+ #
+ # Rule Policy_B 0 (global)
+ #
+ echo "Rule Policy_B 0 (global)"
+ #
+ $IPTABLES -N Policy_B
+ $IPTABLES -A Policy_B -d 192.0.2.100 -m state --state NEW -j ACCEPT
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -N Policy
+ $IPTABLES -N Policy_A
+ $IPTABLES -A Policy -j Policy_A
+ # ================ Table 'filter', rule set Policy_A
+ #
+ # Rule Policy_A 0 (global)
+ #
+ echo "Rule Policy_A 0 (global)"
+ #
+ $IPTABLES -A OUTPUT -j Policy_B
+ $IPTABLES -A INPUT -j Policy_B
+ $IPTABLES -A FORWARD -j Policy_B
+ #
+ # Rule Policy_A 1 (global)
+ #
+ echo "Rule Policy_A 1 (global)"
+ #
+ # recursive branching
+ # firewall82_A:Policy_A:1: warning: Rule set Policy_A of firewall firewall82_A has branching rule that loops back to it
+ $IPTABLES -A OUTPUT -j Policy
+ # firewall82_A:Policy_A:1: warning: Rule set Policy_A of firewall firewall82_A has branching rule that loops back to it
+ $IPTABLES -A INPUT -j Policy
+ # firewall82_A:Policy_A:1: warning: Rule set Policy_A of firewall firewall82_A has branching rule that loops back to it
+ $IPTABLES -A FORWARD -j Policy
+ #
+ # Rule Policy_A 2 (global)
+ #
+ echo "Rule Policy_A 2 (global)"
+ #
+ # firewall82_A:Policy_A:2: warning: Rule set Policy_A of firewall firewall82_A has branching rule that loops back to it
+ $IPTABLES -A OUTPUT -j Policy_A
+ # firewall82_A:Policy_A:2: warning: Rule set Policy_A of firewall firewall82_A has branching rule that loops back to it
+ $IPTABLES -A INPUT -j Policy_A
+ # firewall82_A:Policy_A:2: warning: Rule set Policy_A of firewall firewall82_A has branching rule that loops back to it
+ $IPTABLES -A FORWARD -j Policy_A
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:36 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall82_B.fw.orig b/test/ipt/firewall82_B.fw.orig
new file mode 100755
index 000000000..6895f8493
--- /dev/null
+++ b/test/ipt/firewall82_B.fw.orig
@@ -0,0 +1,423 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:38 2011 PST by vadim
+#
+# files: * firewall82_B.fw
+#
+# Compiled for iptables (any version)
+#
+# this object is used to hold branch rulesets for firewall82 and firewall82_A
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy_B
+ #
+ # Rule Policy_B 0 (global)
+ #
+ echo "Rule Policy_B 0 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 192.0.2.100 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -d 192.0.2.100 -m state --state NEW -j ACCEPT
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:38 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall9.fw.orig b/test/ipt/firewall9.fw.orig
new file mode 100755
index 000000000..77bc3a4a0
--- /dev/null
+++ b/test/ipt/firewall9.fw.orig
@@ -0,0 +1,693 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:41 2011 PST by vadim
+#
+# files: * firewall9.fw
+#
+# Compiled for iptables (any version)
+#
+# testing rules with action-on-reject "TCP reset"
+
+# firewall9:Policy:1: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+# firewall9:Policy:2: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+# firewall9:Policy:6: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+# firewall9:Policy:7: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.168.1.1/24" ""
+ update_addresses_of_interface "eth1 22.22.22.22/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -N Cid3D4DF362.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 6667 -j Cid3D4DF362.0
+ $IPTABLES -N RULE_0
+ $IPTABLES -A Cid3D4DF362.0 -d 22.22.22.22 -j RULE_0
+ $IPTABLES -A Cid3D4DF362.0 -d 192.168.1.1 -j RULE_0
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 6667 -j RULE_0
+ $IPTABLES -A RULE_0 -j LOG --log-level debug --log-prefix "RULE 0 -- REJECT global"
+ $IPTABLES -A RULE_0 -p tcp -m tcp -j REJECT --reject-with tcp-reset
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ # firewall9:Policy:1: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -N Cid3D4DF36C.0
+ $IPTABLES -A OUTPUT -p udp -m udp --dport 53 -j Cid3D4DF36C.0
+ # firewall9:Policy:1: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -N RULE_1
+ $IPTABLES -A Cid3D4DF36C.0 -d 22.22.22.22 -j RULE_1
+ # firewall9:Policy:1: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A Cid3D4DF36C.0 -d 192.168.1.1 -j RULE_1
+ # firewall9:Policy:1: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A INPUT -p udp -m udp --dport 53 -j RULE_1
+ # firewall9:Policy:1: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A RULE_1 -j LOG --log-level debug --log-prefix "RULE 1 -- REJECT global"
+ # firewall9:Policy:1: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A RULE_1 -j REJECT --reject-with icmp-net-unreachable
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ # firewall9:Policy:2: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -N Cid3D4DF376.0
+ $IPTABLES -A OUTPUT -p icmp -j Cid3D4DF376.0
+ # firewall9:Policy:2: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A OUTPUT -p 50 -j Cid3D4DF376.0
+ # firewall9:Policy:2: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -N RULE_2
+ $IPTABLES -A Cid3D4DF376.0 -d 22.22.22.22 -j RULE_2
+ # firewall9:Policy:2: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A Cid3D4DF376.0 -d 192.168.1.1 -j RULE_2
+ # firewall9:Policy:2: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A INPUT -p icmp -j RULE_2
+ # firewall9:Policy:2: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A INPUT -p 50 -j RULE_2
+ # firewall9:Policy:2: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A RULE_2 -j LOG --log-level debug --log-prefix "RULE 2 -- REJECT global"
+ # firewall9:Policy:2: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A RULE_2 -j REJECT --reject-with icmp-net-unreachable
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -N Cid3D4DF380.0
+ $IPTABLES -A OUTPUT -p udp -m udp -m multiport --dports 53,161 -j Cid3D4DF380.0
+ $IPTABLES -N RULE_3_1
+ $IPTABLES -A Cid3D4DF380.0 -d 22.22.22.22 -j RULE_3_1
+ $IPTABLES -A Cid3D4DF380.0 -d 192.168.1.1 -j RULE_3_1
+ $IPTABLES -A INPUT -p udp -m udp -m multiport --dports 53,161 -j RULE_3_1
+ $IPTABLES -A RULE_3_1 -j LOG --log-level debug --log-prefix "RULE 3 -- REJECT global"
+ $IPTABLES -A RULE_3_1 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -N Cid3D4DF380.1
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 10000:11000 -j Cid3D4DF380.1
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 113 -j Cid3D4DF380.1
+ $IPTABLES -N RULE_3_2
+ $IPTABLES -A Cid3D4DF380.1 -d 22.22.22.22 -j RULE_3_2
+ $IPTABLES -A Cid3D4DF380.1 -d 192.168.1.1 -j RULE_3_2
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 10000:11000 -j RULE_3_2
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 113 -j RULE_3_2
+ $IPTABLES -A RULE_3_2 -j LOG --log-level debug --log-prefix "RULE 3 -- REJECT global"
+ $IPTABLES -A RULE_3_2 -p tcp -m tcp -j REJECT --reject-with tcp-reset
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -N Cid3D4DF38A.0
+ $IPTABLES -A OUTPUT -p udp -m udp -m multiport --dports 53,161 -j Cid3D4DF38A.0
+ $IPTABLES -A Cid3D4DF38A.0 -d 22.22.22.22 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -A Cid3D4DF38A.0 -d 192.168.1.1 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -A INPUT -p udp -m udp -m multiport --dports 53,161 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -N Cid3D4DF38A.1
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 10000:11000 -j Cid3D4DF38A.1
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 113 -j Cid3D4DF38A.1
+ $IPTABLES -A Cid3D4DF38A.1 -p tcp -m tcp -d 22.22.22.22 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A Cid3D4DF38A.1 -p tcp -m tcp -d 192.168.1.1 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 10000:11000 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 113 -j REJECT --reject-with tcp-reset
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -N Cid3D4DF394.0
+ $IPTABLES -A INPUT -p udp -m udp -m multiport --dports 53,161 -j Cid3D4DF394.0
+ $IPTABLES -A Cid3D4DF394.0 -d 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid3D4DF394.0 -d 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid3D4DF394.0 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -A OUTPUT -p udp -m udp -m multiport --dports 53,161 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -A FORWARD -p udp -m udp -m multiport --dports 53,161 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -N Cid3D4DF394.1
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 10000:11000 -j Cid3D4DF394.1
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 113 -j Cid3D4DF394.1
+ $IPTABLES -A Cid3D4DF394.1 -d 22.22.22.22 -j RETURN
+ $IPTABLES -A Cid3D4DF394.1 -d 192.168.1.1 -j RETURN
+ $IPTABLES -A Cid3D4DF394.1 -p tcp -m tcp -j REJECT --reject-with tcp-reset
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 10000:11000 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 113 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 10000:11000 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 113 -j REJECT --reject-with tcp-reset
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ # firewall9:Policy:6: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -N Cid3D4DF39E.0
+ $IPTABLES -A OUTPUT -d 22.22.22.22 -j Cid3D4DF39E.0
+ # firewall9:Policy:6: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j Cid3D4DF39E.0
+ # firewall9:Policy:6: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A INPUT -j Cid3D4DF39E.0
+ $IPTABLES -A Cid3D4DF39E.0 -p tcp -m tcp --dport 10000:11000 -j RETURN
+ $IPTABLES -A Cid3D4DF39E.0 -p tcp -m tcp --dport 113 -j RETURN
+ $IPTABLES -A Cid3D4DF39E.0 -p udp -m udp -m multiport --dports 53,161 -j RETURN
+ $IPTABLES -A Cid3D4DF39E.0 -j REJECT --reject-with icmp-net-unreachable
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ # firewall9:Policy:7: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -N Cid3D4DF3A8.0
+ $IPTABLES -A OUTPUT -d 22.22.22.22 -j Cid3D4DF3A8.0
+ # firewall9:Policy:7: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j Cid3D4DF3A8.0
+ # firewall9:Policy:7: warning: Rule action 'Reject' with TCP RST can be used only with TCP services.
+ $IPTABLES -A INPUT -j Cid3D4DF3A8.0
+ $IPTABLES -A Cid3D4DF3A8.0 -p tcp -m tcp --dport 10000:11000 -j RETURN
+ $IPTABLES -A Cid3D4DF3A8.0 -p tcp -m tcp --dport 113 -j RETURN
+ $IPTABLES -A Cid3D4DF3A8.0 -p udp -m udp -m multiport --dports 53,161 -j RETURN
+ $IPTABLES -N RULE_7_3
+ $IPTABLES -A Cid3D4DF3A8.0 -j RULE_7_3
+ $IPTABLES -A RULE_7_3 -j LOG --log-level debug --log-prefix "RULE 7 -- REJECT global"
+ $IPTABLES -A RULE_7_3 -j REJECT --reject-with icmp-net-unreachable
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 --dport 80 -j REJECT --reject-with tcp-reset
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -N Cid4144FFAE.0
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 80 -j Cid4144FFAE.0
+ $IPTABLES -A Cid4144FFAE.0 -p tcp -m tcp -s 192.168.1.0/24 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A Cid4144FFAE.0 -p tcp -m tcp -s 192.168.2.0/24 -j REJECT --reject-with tcp-reset
+ $IPTABLES -N Cid4144FFAE.1
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 80 -j Cid4144FFAE.1
+ $IPTABLES -A Cid4144FFAE.1 -p tcp -m tcp -s 192.168.1.0/24 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A Cid4144FFAE.1 -p tcp -m tcp -s 192.168.2.0/24 -j REJECT --reject-with tcp-reset
+ $IPTABLES -N Cid4144FFAE.2
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 80 -j Cid4144FFAE.2
+ $IPTABLES -A Cid4144FFAE.2 -p tcp -m tcp -s 192.168.1.0/24 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A Cid4144FFAE.2 -p tcp -m tcp -s 192.168.2.0/24 -j REJECT --reject-with tcp-reset
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ $IPTABLES -N Cid41456B50.0
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type 3 -j Cid41456B50.0
+ $IPTABLES -A Cid41456B50.0 -s 192.168.1.0/24 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -A Cid41456B50.0 -s 192.168.2.0/24 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -N Cid41456B50.1
+ $IPTABLES -A OUTPUT -p icmp -m icmp --icmp-type 3 -j Cid41456B50.1
+ $IPTABLES -A Cid41456B50.1 -s 192.168.1.0/24 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -A Cid41456B50.1 -s 192.168.2.0/24 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -N Cid41456B50.2
+ $IPTABLES -A FORWARD -p icmp -m icmp --icmp-type 3 -j Cid41456B50.2
+ $IPTABLES -A Cid41456B50.2 -s 192.168.1.0/24 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -A Cid41456B50.2 -s 192.168.2.0/24 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -N Cid41456B50.3
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 80 -j Cid41456B50.3
+ $IPTABLES -A Cid41456B50.3 -p tcp -m tcp -s 192.168.1.0/24 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A Cid41456B50.3 -p tcp -m tcp -s 192.168.2.0/24 -j REJECT --reject-with tcp-reset
+ $IPTABLES -N Cid41456B50.4
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 80 -j Cid41456B50.4
+ $IPTABLES -A Cid41456B50.4 -p tcp -m tcp -s 192.168.1.0/24 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A Cid41456B50.4 -p tcp -m tcp -s 192.168.2.0/24 -j REJECT --reject-with tcp-reset
+ $IPTABLES -N Cid41456B50.5
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 80 -j Cid41456B50.5
+ $IPTABLES -A Cid41456B50.5 -p tcp -m tcp -s 192.168.1.0/24 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A Cid41456B50.5 -p tcp -m tcp -s 192.168.2.0/24 -j REJECT --reject-with tcp-reset
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ $IPTABLES -N Cid41456B75.0
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type 3 -j Cid41456B75.0
+ $IPTABLES -A Cid41456B75.0 -s 192.168.1.0/24 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -A Cid41456B75.0 -s 192.168.2.0/24 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -N Cid41456B75.1
+ $IPTABLES -A OUTPUT -p icmp -m icmp --icmp-type 3 -j Cid41456B75.1
+ $IPTABLES -A Cid41456B75.1 -s 192.168.1.0/24 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -A Cid41456B75.1 -s 192.168.2.0/24 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -N Cid41456B75.2
+ $IPTABLES -A FORWARD -p icmp -m icmp --icmp-type 3 -j Cid41456B75.2
+ $IPTABLES -A Cid41456B75.2 -s 192.168.1.0/24 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -A Cid41456B75.2 -s 192.168.2.0/24 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -N Cid41456B75.3
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 21 -j Cid41456B75.3
+ $IPTABLES -A Cid41456B75.3 -p tcp -m tcp -s 192.168.1.0/24 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A Cid41456B75.3 -p tcp -m tcp -s 192.168.2.0/24 -j REJECT --reject-with tcp-reset
+ $IPTABLES -N Cid41456B75.4
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 21 -j Cid41456B75.4
+ $IPTABLES -A Cid41456B75.4 -p tcp -m tcp -s 192.168.1.0/24 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A Cid41456B75.4 -p tcp -m tcp -s 192.168.2.0/24 -j REJECT --reject-with tcp-reset
+ $IPTABLES -N Cid41456B75.5
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 21 -j Cid41456B75.5
+ $IPTABLES -A Cid41456B75.5 -p tcp -m tcp -s 192.168.1.0/24 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A Cid41456B75.5 -p tcp -m tcp -s 192.168.2.0/24 -j REJECT --reject-with tcp-reset
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 -m tcp --tcp-flags SYN,ACK SYN,ACK -m state --state NEW -j REJECT --reject-with tcp-reset
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 -m tcp --tcp-flags SYN,ACK SYN,ACK -m state --state NEW -j REJECT --reject-with tcp-reset
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 -m tcp --tcp-flags SYN,ACK SYN,ACK -m state --state NEW -j REJECT --reject-with tcp-reset
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ $IPTABLES -N Cid206275X37109.0
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -j Cid206275X37109.0
+ $IPTABLES -A Cid206275X37109.0 -p tcp -m tcp --dport 80 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A Cid206275X37109.0 -p tcp -m tcp -m tcp --tcp-flags SYN,ACK SYN,ACK -m state --state NEW -j REJECT --reject-with tcp-reset
+ $IPTABLES -N Cid206275X37109.1
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -j Cid206275X37109.1
+ $IPTABLES -A Cid206275X37109.1 -p tcp -m tcp --dport 80 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A Cid206275X37109.1 -p tcp -m tcp -m tcp --tcp-flags SYN,ACK SYN,ACK -m state --state NEW -j REJECT --reject-with tcp-reset
+ $IPTABLES -N Cid206275X37109.2
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -j Cid206275X37109.2
+ $IPTABLES -A Cid206275X37109.2 -p tcp -m tcp --dport 80 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A Cid206275X37109.2 -p tcp -m tcp -m tcp --tcp-flags SYN,ACK SYN,ACK -m state --state NEW -j REJECT --reject-with tcp-reset
+ #
+ # Rule 14 (global)
+ #
+ echo "Rule 14 (global)"
+ #
+ $IPTABLES -A INPUT -p udp -m udp -s 192.168.1.0/24 --dport 53 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -A OUTPUT -p udp -m udp -s 192.168.1.0/24 --dport 53 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -A FORWARD -p udp -m udp -s 192.168.1.0/24 --dport 53 -j REJECT --reject-with icmp-net-unreachable
+ $IPTABLES -N Cid206293X37109.0
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -j Cid206293X37109.0
+ $IPTABLES -A Cid206293X37109.0 -p tcp -m tcp --dport 80 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A Cid206293X37109.0 -p tcp -m tcp -m tcp --tcp-flags SYN,ACK SYN,ACK -m state --state NEW -j REJECT --reject-with tcp-reset
+ $IPTABLES -N Cid206293X37109.1
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -j Cid206293X37109.1
+ $IPTABLES -A Cid206293X37109.1 -p tcp -m tcp --dport 80 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A Cid206293X37109.1 -p tcp -m tcp -m tcp --tcp-flags SYN,ACK SYN,ACK -m state --state NEW -j REJECT --reject-with tcp-reset
+ $IPTABLES -N Cid206293X37109.2
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -j Cid206293X37109.2
+ $IPTABLES -A Cid206293X37109.2 -p tcp -m tcp --dport 80 -j REJECT --reject-with tcp-reset
+ $IPTABLES -A Cid206293X37109.2 -p tcp -m tcp -m tcp --tcp-flags SYN,ACK SYN,ACK -m state --state NEW -j REJECT --reject-with tcp-reset
+}
+
+ip_forward() {
+ :
+
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:41 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall90.fw.orig b/test/ipt/firewall90.fw.orig
new file mode 100755
index 000000000..497b63a6e
--- /dev/null
+++ b/test/ipt/firewall90.fw.orig
@@ -0,0 +1,443 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:43 2011 PST by vadim
+#
+# files: * firewall90.fw
+#
+# Compiled for iptables (any version)
+#
+# test for ipv4options module
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0"
+ for i in eth0 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.0.2.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -A FORWARD -p all -m dscp --dscp-class AF4 -m ipv4options --lsrr --ra -j DROP
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -A FORWARD -p all -m ipv4options --rr -j DROP
+ $IPTABLES -A FORWARD -p all -m ipv4options --lsrr --ssrr -j DROP
+ $IPTABLES -A FORWARD -p all -m ipv4options --ts -j DROP
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -A FORWARD -p all -m ipv4options --any-opt -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:43 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall91.fw.orig b/test/ipt/firewall91.fw.orig
new file mode 100755
index 000000000..c9ce00a4b
--- /dev/null
+++ b/test/ipt/firewall91.fw.orig
@@ -0,0 +1,443 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:45 2011 PST by vadim
+#
+# files: * firewall91.fw
+#
+# Compiled for iptables 1.4.3
+#
+# test for ipv4options module for v1.4.3 and later
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0"
+ for i in eth0 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.0.2.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -A FORWARD -p all -m dscp --dscp-class AF4 -m ipv4options --flags lsrr,router-alert -j DROP
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -A FORWARD -p all -m ipv4options --flags record-route -j DROP
+ $IPTABLES -A FORWARD -p all -m ipv4options --flags lsrr,ssrr -j DROP
+ $IPTABLES -A FORWARD -p all -m ipv4options --flags timestamp -j DROP
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -A FORWARD -p all -m ipv4options --any -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:45 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall92.fw.orig b/test/ipt/firewall92.fw.orig
new file mode 100755
index 000000000..af16211cd
--- /dev/null
+++ b/test/ipt/firewall92.fw.orig
@@ -0,0 +1,479 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:47 2011 PST by vadim
+#
+# files: * firewall92.fw
+#
+# Compiled for iptables (any version)
+#
+# rules for the TOR transparent proxy per
+# https://trac.torproject.org/projects/tor/wiki/TheOnionRouter/TransparentProxy
+# See ticket 1685
+
+# firewall92:NAT:2: error: NAT rule can not change service types: CustomService to TCPService
+# firewall92:NAT:2: error: Translated Service should be either 'Original' or should contain object of the same type as Original Service.
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1"
+ for i in eth0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.0.2.1/24" ""
+ update_addresses_of_interface "eth1 192.168.1.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p udp -m udp -m owner --uid-owner anonymous -j REDIRECT --to-ports 53
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A OUTPUT -p tcp -m tcp -m owner --uid-owner anonymous -j REDIRECT --to-ports 9040
+
+
+
+ # ================ Table 'filter', rule set Policy_1
+ #
+ # Rule Policy_1 0 (global)
+ #
+ echo "Rule Policy_1 0 (global)"
+ #
+ $IPTABLES -N Policy_1
+ $IPTABLES -N Cid1009688X9517.0
+ $IPTABLES -A Policy_1 -o + -p tcp -m tcp --dport 9040 -j Cid1009688X9517.0
+ $IPTABLES -A Policy_1 -o + -p udp -m udp --dport 53 -j Cid1009688X9517.0
+ $IPTABLES -N Out_Policy_1_0
+ $IPTABLES -A Cid1009688X9517.0 -s 192.0.2.1 -j Out_Policy_1_0
+ $IPTABLES -A Cid1009688X9517.0 -s 192.168.1.1 -j Out_Policy_1_0
+ $IPTABLES -A Out_Policy_1_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A Out_Policy_1_0 -j DROP
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -m owner --uid-owner anonymous -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p udp -m udp -m owner --uid-owner anonymous -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ # matching module owner here
+ # and tcp and udp ports in the branch
+ $IPTABLES -A OUTPUT -m owner --uid-owner anonymous -j Policy_1
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ # this only matches module owner
+ $IPTABLES -N Out_RULE_2
+ $IPTABLES -A OUTPUT -m owner --uid-owner anonymous -j Out_RULE_2
+ $IPTABLES -A Out_RULE_2 -j LOG --log-level info --log-prefix "RULE 2 -- DENY "
+ $IPTABLES -A Out_RULE_2 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:47 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/firewall93.fw.orig b/test/ipt/firewall93.fw.orig
new file mode 100755
index 000000000..63682eca5
--- /dev/null
+++ b/test/ipt/firewall93.fw.orig
@@ -0,0 +1,518 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:56:50 2011 PST by vadim
+#
+# files: * firewall93.fw
+#
+# Compiled for iptables (any version)
+#
+# testing shell code generated for dynamic interface with "-" in the name
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 ppp0 ppp-dsl"
+ for i in eth0 ppp0 ppp-dsl ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 fe80::20c:29ff:fe28:c078/64 192.0.2.1/24" ""
+ getaddr ppp0 i_ppp0
+ getaddr6 ppp0 i_ppp0_v6
+ getaddr ppp-dsl i_ppp_dsl
+ getaddr6 ppp-dsl i_ppp_dsl_v6
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (ppp0)
+ #
+ echo "Rule 0 (ppp0)"
+ #
+ for i_ppp_dsl in $i_ppp_dsl_list
+ do
+ test -n "$i_ppp_dsl" && $IPTABLES -A INPUT -i ppp0 -s $i_ppp_dsl -m state --state NEW -j ACCEPT
+ done
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -A INPUT -i ppp0 -s $i_ppp0 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A INPUT -i ppp0 -s 192.0.2.1 -m state --state NEW -j ACCEPT
+ for i_ppp_dsl in $i_ppp_dsl_list
+ do
+ test -n "$i_ppp_dsl" && $IPTABLES -A FORWARD -i ppp0 -s $i_ppp_dsl -m state --state NEW -j ACCEPT
+ done
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -A FORWARD -i ppp0 -s $i_ppp0 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A FORWARD -i ppp0 -s 192.0.2.1 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (ppp-dsl)
+ #
+ echo "Rule 1 (ppp-dsl)"
+ #
+ for i_ppp_dsl in $i_ppp_dsl_list
+ do
+ test -n "$i_ppp_dsl" && $IPTABLES -A INPUT -i ppp-dsl -s $i_ppp_dsl -m state --state NEW -j ACCEPT
+ done
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -A INPUT -i ppp-dsl -s $i_ppp0 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A INPUT -i ppp-dsl -s 192.0.2.1 -m state --state NEW -j ACCEPT
+ for i_ppp_dsl in $i_ppp_dsl_list
+ do
+ test -n "$i_ppp_dsl" && $IPTABLES -A FORWARD -i ppp-dsl -s $i_ppp_dsl -m state --state NEW -j ACCEPT
+ done
+ for i_ppp0 in $i_ppp0_list
+ do
+ test -n "$i_ppp0" && $IPTABLES -A FORWARD -i ppp-dsl -s $i_ppp0 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A FORWARD -i ppp-dsl -s 192.0.2.1 -m state --state NEW -j ACCEPT
+
+
+ # ================ IPv6
+
+
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy_v6
+ #
+ # Rule Policy_v6 0 (ppp-dsl)
+ #
+ echo "Rule Policy_v6 0 (ppp-dsl)"
+ #
+ $IP6TABLES -N Policy_v6
+ for i_ppp_dsl_v6 in $i_ppp_dsl_v6_list
+ do
+ test -n "$i_ppp_dsl_v6" && $IP6TABLES -A Policy_v6 -i ppp-dsl -s $i_ppp_dsl_v6 -m state --state NEW -j ACCEPT
+ done
+ for i_ppp0_v6 in $i_ppp0_v6_list
+ do
+ test -n "$i_ppp0_v6" && $IP6TABLES -A Policy_v6 -i ppp-dsl -s $i_ppp0_v6 -m state --state NEW -j ACCEPT
+ done
+ $IP6TABLES -A Policy_v6 -i ppp-dsl -s fe80::20c:29ff:fe28:c078 -m state --state NEW -j ACCEPT
+ #
+ # Rule Policy_v6 1 (ppp0)
+ #
+ echo "Rule Policy_v6 1 (ppp0)"
+ #
+ for i_ppp_dsl_v6 in $i_ppp_dsl_v6_list
+ do
+ test -n "$i_ppp_dsl_v6" && $IP6TABLES -A Policy_v6 -i ppp0 -s $i_ppp_dsl_v6 -m state --state NEW -j ACCEPT
+ done
+ for i_ppp0_v6 in $i_ppp0_v6_list
+ do
+ test -n "$i_ppp0_v6" && $IP6TABLES -A Policy_v6 -i ppp0 -s $i_ppp0_v6 -m state --state NEW -j ACCEPT
+ done
+ $IP6TABLES -A Policy_v6 -i ppp0 -s fe80::20c:29ff:fe28:c078 -m state --state NEW -j ACCEPT
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:56:50 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " ipv6"
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/fw-A.fw.orig b/test/ipt/fw-A.fw.orig
new file mode 100755
index 000000000..199a6d9af
--- /dev/null
+++ b/test/ipt/fw-A.fw.orig
@@ -0,0 +1,782 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:57:55 2011 PST by vadim
+#
+# files: * fw-A.fw
+#
+# Compiled for iptables 1.3.0
+#
+
+# fw-A:Routing:0: error: Object "gw_200" used as gateway in the routing rule 0 (main) is not reachable because it is not in any local network of the firewall
+# fw-A:Routing:0: error: Object "gw_200" used as gateway in the routing rule 0 (main) is not in the same local network as interface eth3
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+ find_program $VCONFIG
+ find_program $IFENSLAVE
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+missing_vlan() {
+ vlan=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $vlan
+ subint=$1
+ parent=$2
+ IFS=$oldIFS
+
+ vlan_id=$(echo $subint | sed -r 's/(vlan|[^.]*\.)//')
+ test "$cmd" = "add" && {
+ echo $subint | grep -q "vlan" && name_type="VLAN_PLUS_VID" || name_type="DEV_PLUS_VID"
+ test "$vlan_id" \< "1" || name_type="${name_type}_NO_PAD"
+ echo "# Adding VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $VCONFIG set_name_type $name_type
+ $FWBDEBUG $VCONFIG $cmd $parent $vlan_id
+ $FWBDEBUG $IP link set $subint up
+ }
+ test "$cmd" = "rem" && {
+ echo "# Removing VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $VCONFIG $cmd $subint
+ }
+}
+
+parse_fwb_vlans() {
+ set $1
+ vlan_parent_interface=$1
+ shift
+
+ FWB_VLANS=$(
+ for subint in $*; do
+ echo "${subint}@$vlan_parent_interface"
+ done | sort
+ )
+ echo $FWB_VLANS
+}
+
+parse_current_vlans() {
+ vlan_parent_interface=$1
+ CURRENT_VLANS=""
+ PROC_DIR="/proc/net/vlan/"
+ test -d $PROC_DIR || $MODPROBE 8021q || {
+ echo "$PROC_DIR does not exist. Vlan interfaces are not available."
+ exit 1
+ }
+
+ test -f "/proc/net/vlan/config" && {
+ CURRENT_VLANS=$(
+ cat /proc/net/vlan/config | grep -v 'Dev name' | grep $vlan_parent_interface | \
+ while read subint a vlan_id b parent; do
+ echo "${subint}@$parent"
+ done | sort
+ )
+ }
+ echo $CURRENT_VLANS
+}
+
+update_vlans_of_interface() {
+ args="$1"
+ set $1
+ vlan_parent_interface=$1
+
+ FWB_VLANS=$(parse_fwb_vlans "$args")
+ CURRENT_VLANS=$(parse_current_vlans $vlan_parent_interface)
+
+ $IP link set $vlan_parent_interface up
+ diff_intf missing_vlan "$FWB_VLANS" "$CURRENT_VLANS" add
+ diff_intf missing_vlan "$CURRENT_VLANS" "$FWB_VLANS" rem
+}
+
+add_vlans() {
+ args="$1"
+ set $1
+ vlan_parent_interface=$1
+
+ FWB_VLANS=$(parse_fwb_vlans $args)
+ CURRENT_VLANS=$(parse_current_vlans $vlan_parent_interface)
+
+ $IP link set $vlan_parent_interface up
+ diff_intf missing_vlan "$FWB_VLANS" "$CURRENT_VLANS" add
+}
+
+clear_vlans_except_known() {
+ FWB_VLANS=$*
+ CURRENT_VLANS=$(parse_current_vlans '|')
+
+ diff_intf missing_vlan "$CURRENT_VLANS" "$FWB_VLANS" rem
+}
+
+missing_bond() {
+ bond_intf=$1
+ cmd=$2
+
+ test "$cmd" = "down" && {
+ echo "# Bring unconfigured bonding interface $bond_intf down"
+ $FWBDEBUG $IP link set $bond_intf down
+ }
+}
+
+missing_slave() {
+ slave=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $slave
+ intf=$1
+ bond_interface=$2
+ IFS=$oldIFS
+
+ test "$cmd" = "-d" && {
+ echo "# Delete bonding interface slave: $bond_interface $intf"
+ $FWBDEBUG $IFENSLAVE -d $bond_interface $intf
+ } || {
+ echo "# Add bonding interface slave: $bond_interface $intf"
+ $FWBDEBUG $IP link set $bond_interface up
+ $FWBDEBUG $IFENSLAVE $bond_interface $intf
+ }
+}
+
+load_bonding_module() {
+ bonding_interfaces=$1
+ shift
+ module_parameters=$*
+
+ PROC_DIR="/proc/net/bonding/"
+ test -d $PROC_DIR || {
+ cmd="$MODPROBE bonding $module_parameters"
+ test -n "$FWBDEBUG" && echo "# $cmd" || $cmd || {
+ # Module load failed.
+ cat </dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: bond0 eth2 eth3 bond1 lo eth6 eth0 eth1 bond0.2 bond0.1 eth2.201 eth2.202 eth4 eth5"
+ for i in bond0 eth2 eth3 bond1 lo eth6 eth0 eth1 bond0.2 bond0.1 eth2.201 eth2.202 eth4 eth5 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ load_bonding_module "bond0 bond1" max_bonds=2 mode=802.3ad xmit_hash_policy=layer2 miimon=100
+ update_bonding bond0 eth0 eth1
+ update_bonding bond1 eth4 eth5
+ clear_bonding_except_known bond0 bond1
+ update_vlans_of_interface "bond0 bond0.2 bond0.1"
+ update_vlans_of_interface "eth2 eth2.201 eth2.202"
+ clear_vlans_except_known bond0.2@bond0 bond0.1@bond0 eth2.201@eth2 eth2.202@eth2
+ update_addresses_of_interface "eth3 192.0.2.11/24" ""
+ update_addresses_of_interface "bond1 192.168.11.11/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth6 192.168.6.11/24" ""
+ update_addresses_of_interface "bond0.2 192.168.2.11/24" ""
+ update_addresses_of_interface "bond0.1 192.168.1.11/24" ""
+ update_addresses_of_interface "eth2.201 192.168.201.11/24" ""
+ update_addresses_of_interface "eth2.202 192.168.202.11/24" ""
+ clear_addresses_except_known_interfaces bond0 eth2 eth3 bond1 lo eth6 eth0 eth1 bond0.2 bond0.1 eth2.201 eth2.202 eth4 eth5
+}
+
+script_body() {
+ echo 1 > /proc/sys/net/ipv4/ip_dynaddr
+ echo 1 > /proc/sys/net/ipv4/conf/all/rp_filter
+ echo 0 > /proc/sys/net/ipv4/conf/all/accept_source_route
+ echo 0 > /proc/sys/net/ipv4/conf/all/accept_redirects
+ echo 1 > /proc/sys/net/ipv4/conf/all/log_martians
+ echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_broadcasts
+ echo 0 > /proc/sys/net/ipv4/icmp_echo_ignore_all
+ echo 0 > /proc/sys/net/ipv4/icmp_ignore_bogus_error_responses
+ echo 1 > /proc/sys/net/ipv4/tcp_syncookies
+ echo 250000 > /proc/sys/net/ipv4/netfilter/ip_conntrack_max
+ echo 250000 > /sys/module/ip_conntrack/parameters/hashsize
+ echo 1 > /proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_be_liberal
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+ # drop packets that do not match any valid state and log them
+ $IPTABLES -N drop_invalid
+ $IPTABLES -A OUTPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A INPUT -m state --state INVALID -j drop_invalid
+ $IPTABLES -A FORWARD -m state --state INVALID -j drop_invalid
+ $IPTABLES -A drop_invalid -j LOG --log-level debug --log-prefix "INVALID state -- DENY "
+ $IPTABLES -A drop_invalid -j DROP
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+ # ============== ROUTING RULES ==============
+
+ TMPDIRNAME="/tmp/.fwbuilder.tempdir.$$"
+ TMPFILENAME="$TMPDIRNAME/.fwbuilder.out"
+ (umask 077 && mkdir $TMPDIRNAME) || exit 1
+
+ #
+ # This function stops stdout redirection
+ # and sends previously saved output to terminal
+ restore_script_output()
+ {
+ exec 1>&3 2>&1
+ cat $TMPFILENAME
+ rm -rf $TMPDIRNAME
+ }
+
+ # if any routing rule fails we do our best to prevent freezing the firewall
+ route_command_error()
+ {
+ echo "Error: Routing rule $1 couldn't be activated"
+ echo "Recovering previous routing configuration..."
+ # delete current routing rules
+ $IP route show | while read route ; do $IP route del $route ; done
+ # restore old routing rules
+ (IFS="
+ "; for route in $oldRoutes; do (IFS=' '; $IP route add $route); done)
+ echo "...done"
+ restore_script_output
+ epilog_commands
+ exit 1
+ }
+
+ # redirect output to prevent ssh session from stalling
+ exec 3>&1
+ exec 1> $TMPFILENAME
+ exec 2>&1
+
+ # store previous routing configuration (sort: 'via' GW has to be
+ # inserted after device routes)
+ oldRoutes=$($IP route show | sort -k 2)
+
+ echo "Deleting routing rules previously set by user space processes..."
+ $IP route show | grep -v 'proto kernel' | \
+ while read route ; do $IP route del $route ; done
+
+ echo "Activating non-ecmp routing rules..."
+ #
+ # Rule 0 (main)
+ #
+ echo "Routing rule 0 (main)"
+ #
+ #
+ #
+ # fw-A:Routing:0: error: Object "gw_200" used as gateway in the routing rule 0 (main) is not in the same local network as interface eth3
+ $IP route add default via 200.200.200.200 dev eth3 \
+ || route_command_error "0 (main)"
+
+ #
+ # Rule 1 (main)
+ #
+ echo "Routing rule 1 (main)"
+ #
+ # for 1410: gateway matches subnet of a vlan interface
+ #
+ $IP route add 192.168.101.0/24 via 192.168.1.200 dev bond0.1 \
+ || route_command_error "1 (main)"
+
+ #
+ # Rule 2 (main)
+ #
+ echo "Routing rule 2 (main)"
+ #
+ # for 1410: gateway matches subnet of a vlan interface
+ #
+ $IP route add 192.168.102.0/24 via 192.168.2.200 dev bond0.2 \
+ || route_command_error "2 (main)"
+
+ #
+ # Rule 3 (main)
+ #
+ echo "Routing rule 3 (main)"
+ #
+ #
+ #
+ $IP route add 192.168.111.0/24 via 192.168.11.200 dev bond1 \
+ || route_command_error "3 (main)"
+
+ #
+ # Rule 4 (main)
+ #
+ echo "Routing rule 4 (main)"
+ #
+ # for 1410: gateway matches subnet of a vlan interface
+ #
+ $IP route add 192.168.211.0/24 via 192.168.201.200 dev eth2.201 \
+ || route_command_error "4 (main)"
+
+ #
+ # Rule 5 (main)
+ #
+ echo "Routing rule 5 (main)"
+ #
+ # for 1410: gateway matches subnet of a vlan interface
+ #
+ $IP route add 192.168.212.0/24 via 192.168.202.200 dev eth2.202 \
+ || route_command_error "5 (main)"
+
+
+ restore_script_output
+ echo "...done."
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:57:55 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/fw1.fw.orig b/test/ipt/fw1.fw.orig
new file mode 100755
index 000000000..c5644cec9
--- /dev/null
+++ b/test/ipt/fw1.fw.orig
@@ -0,0 +1,579 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:57:53 2011 PST by vadim
+#
+# files: * fw1.fw
+#
+# Compiled for iptables (any version)
+#
+# This firewall has two interfaces. Eth0 faces outside and has a dynamic address; eth1 faces inside.
+# Policy includes basic rules to permit unrestricted outbound access and anti-spoofing rules. Access to the firewall is permitted only from internal network and only using SSH. The firewall uses one of the machines on internal network for DNS. Internal network is configured with address 192.168.1.0/255.255.255.0
+
+# fw1:NAT:8: error: NAT rule can not change service types: TCPService to UDPService
+# fw1:NAT:8: error: Translated Service should be either 'Original' or should contain object of the same type as Original Service.
+
+# fw1:Policy:1: error: Rule '1 (global)' shadows rule '2 (global)' below it
+# fw1:Policy:1: error: Rule '1 (global)' shadows rule '2 (global)' below it
+# fw1:Policy:1: error: Rule '1 (global)' shadows rule '3 (global)' below it
+# fw1:Policy:1: error: Rule '1 (global)' shadows rule '3 (global)' below it
+# fw1:Policy:1: error: Rule '1 (global)' shadows rule '3 (global)' below it
+# fw1:Policy:1: error: Rule '1 (global)' shadows rule '3 (global)' below it
+# fw1:Policy:1: error: Rule '1 (global)' shadows rule '4 (global)' below it
+# fw1:Policy:1: error: Rule '1 (global)' shadows rule '4 (global)' below it
+# fw1:Policy:1: error: Rule '1 (global)' shadows rule '5 (global)' below it
+# fw1:Policy:1: error: Rule '1 (global)' shadows rule '6 (global)' below it
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo"
+ for i in eth0 eth1 lo ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.0.2.1/24" ""
+ update_addresses_of_interface "eth1 fe80::21d:9ff:fe8b:8e94/64 192.168.1.1/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.1.0/24 -j ACCEPT
+ $IPTABLES -t nat -A PREROUTING -s 192.168.1.0/24 -j ACCEPT
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ # source port only
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -p udp -m udp -s 192.168.1.0/24 --sport 123 -j SNAT --to-source :5050
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ # dest port only
+ $IPTABLES -t nat -A PREROUTING -p udp -m udp -s 192.168.1.0/24 --dport 53 -j DNAT --to-destination :1053
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ # SDNAT
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.0.2.1 --dport 22 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p tcp -m tcp -d 192.168.1.1 --dport 22 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p tcp -m tcp -d 192.168.1.10 --dport 22 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ # SDNAT with source port
+ $IPTABLES -t nat -A PREROUTING -p udp -m udp --sport 123 -d 192.0.2.1 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A PREROUTING -p udp -m udp --sport 123 -d 192.168.1.1 -j DNAT --to-destination 192.168.1.10
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p udp -m udp --sport 123 -d 192.168.1.10 -j SNAT --to-source 192.168.1.1:5050
+ #
+ # Rule 5 (NAT)
+ #
+ echo "Rule 5 (NAT)"
+ #
+ # SDNAT with dest port
+ $IPTABLES -t nat -A PREROUTING -p udp -m udp -s 192.168.1.0/24 --dport 53 -j DNAT --to-destination 192.168.1.10:1053
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p udp -m udp -s 192.168.1.0/24 -d 192.168.1.10 --dport 1053 -j SNAT --to-source 192.168.1.1
+ #
+ # Rule 6 (NAT)
+ #
+ echo "Rule 6 (NAT)"
+ #
+ # SDNAT
+ # translate src and dst addresses
+ # and src and dst ports
+ $IPTABLES -t nat -A PREROUTING -p udp -m udp -s 192.168.1.0/24 --sport 1024:65535 --dport 53 -j DNAT --to-destination 192.168.1.10:1053
+ $IPTABLES -t nat -A POSTROUTING -o eth1 -p udp -m udp -s 192.168.1.0/24 -d 192.168.1.10 --dport 1053 -j SNAT --to-source 192.168.1.1:32767-65535
+ #
+ # Rule 7 (NAT)
+ #
+ echo "Rule 7 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth+ -p udp -m udp -s 192.168.1.0/24 --dport 53 -j SNAT --to-source :5050
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ # anti spoofing rule
+ $IPTABLES -N Cid45745X95438.0
+ $IPTABLES -A FORWARD -i + -d 192.168.171.2 -m state --state NEW -j Cid45745X95438.0
+ $IPTABLES -N In_RULE_0
+ $IPTABLES -A Cid45745X95438.0 -s 192.0.2.1 -j In_RULE_0
+ $IPTABLES -A Cid45745X95438.0 -s 192.168.1.1 -j In_RULE_0
+ $IPTABLES -A FORWARD -i + -s 192.168.1.0/24 -d 192.168.171.2 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A In_RULE_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A In_RULE_0 -j DROP
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -A OUTPUT -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ # Firewall uses one of the machines
+ # on internal network for DNS
+ $IPTABLES -N RULE_3
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_3
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_3
+ $IPTABLES -A RULE_3 -j LOG --log-level info --log-prefix "RULE 3 -- ACCEPT "
+ $IPTABLES -A RULE_3 -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ # All other attempts to connect to
+ # the firewall are denied and logged
+ $IPTABLES -N RULE_4
+ $IPTABLES -A OUTPUT -d 192.0.2.1 -m state --state NEW -j RULE_4
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -m state --state NEW -j RULE_4
+ $IPTABLES -A INPUT -m state --state NEW -j RULE_4
+ $IPTABLES -A RULE_4 -j LOG --log-level info --log-prefix "RULE 4 -- DENY "
+ $IPTABLES -A RULE_4 -j DROP
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 1 --tcp-flags SYN SYN -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 1 --tcp-flags SYN SYN -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 --dport 1 --tcp-flags SYN SYN -m state --state NEW -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -N RULE_6
+ $IPTABLES -A OUTPUT -p tcp -m tcp -j RULE_6
+ $IPTABLES -A INPUT -p tcp -m tcp -j RULE_6
+ $IPTABLES -A FORWARD -p tcp -m tcp -j RULE_6
+ $IPTABLES -A RULE_6 -j LOG --log-level info --log-prefix "RULE 6 -- REJECT "
+ $IPTABLES -A RULE_6 -p tcp -m tcp -j REJECT --reject-with tcp-reset
+ $IPTABLES -A OUTPUT -j RULE_6
+ $IPTABLES -A INPUT -j RULE_6
+ $IPTABLES -A FORWARD -j RULE_6
+ $IPTABLES -A RULE_6 -j REJECT
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:57:53 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/heartbeat_cluster_1_d_linux-1-d.fw.orig b/test/ipt/heartbeat_cluster_1_d_linux-1-d.fw.orig
new file mode 100755
index 000000000..e3b1bd45a
--- /dev/null
+++ b/test/ipt/heartbeat_cluster_1_d_linux-1-d.fw.orig
@@ -0,0 +1,780 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:15 2011 PST by vadim
+#
+# files: * heartbeat_cluster_1_d_linux-1-d.fw firewall.sh
+#
+# Compiled for iptables (any version)
+#
+# This firewall has two interfaces. Eth0 faces outside and has a dynamic address; eth1 faces inside.
+# Policy includes basic rules to permit unrestricted outbound access and anti-spoofing rules. Access to the firewall is permitted only from internal network and only using SSH. The firewall uses one of the machines on internal network for DNS. Internal network is configured with address 192.168.1.0/255.255.255.0
+
+# heartbeat_cluster_1_d:Policy:7: error: Can not build rule using dynamic interface 'eth0' of the object 'linux-2-d' because its address in unknown.
+# heartbeat_cluster_1_d:Policy:7: error: Can not build rule using dynamic interface 'eth0' of the object 'linux-2-d' because its address in unknown.
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo eth2 eth2.100"
+ for i in eth0 eth1 lo eth2 eth2.100 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth1 192.168.1.1/24" "192.168.1.254/24"
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth2.100 172.20.0.1/24" ""
+ getaddr eth0 i_eth0
+ getaddr6 eth0 i_eth0_v6
+ getaddr eth0 i_eth0
+ getaddr6 eth0 i_eth0_v6
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j MASQUERADE
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source $i_eth0
+ done
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source $i_eth0 --random
+ done
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -t nat -A PREROUTING -d $i_eth0 -j DNAT --to-destination 192.168.1.100
+ done
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -t nat -A PREROUTING -d $i_eth0 -j DNAT --to-destination 192.168.1.100
+ done
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule -8 heartbeat (automatic)
+ #
+ echo "Rule -8 heartbeat (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth2.100 -p udp -m udp -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -7 heartbeat (automatic)
+ #
+ echo "Rule -7 heartbeat (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth2.100 -p udp -m udp -s 172.20.0.2 -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -6 heartbeat (automatic)
+ #
+ echo "Rule -6 heartbeat (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth1 -p udp -m udp -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -5 heartbeat (automatic)
+ #
+ echo "Rule -5 heartbeat (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -s 192.168.1.2 -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -4 heartbeat (automatic)
+ #
+ echo "Rule -4 heartbeat (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -3 heartbeat (automatic)
+ #
+ echo "Rule -3 heartbeat (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -2 CONNTRACK (automatic)
+ #
+ echo "Rule -2 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 225.0.0.50 --dport 3780 -j ACCEPT
+ #
+ # Rule -1 CONNTRACK (automatic)
+ #
+ echo "Rule -1 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 225.0.0.50 --dport 3780 -j ACCEPT
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ # anti spoofing rule
+ $IPTABLES -N In_RULE_0
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A INPUT -i eth0 -s $i_eth0 -m state --state NEW -j In_RULE_0
+ done
+ $IPTABLES -A INPUT -i eth0 -s 172.20.0.1 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.254 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_0
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A FORWARD -i eth0 -s $i_eth0 -m state --state NEW -j In_RULE_0
+ done
+ $IPTABLES -A FORWARD -i eth0 -s 172.20.0.1 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.254 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A In_RULE_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A In_RULE_0 -j DROP
+ #
+ # Rule 1 (lo)
+ #
+ echo "Rule 1 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ # Firewall uses one of the machines
+ # on internal network for DNS
+ $IPTABLES -N RULE_3
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_3
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_3
+ $IPTABLES -A RULE_3 -j LOG --log-level info --log-prefix "RULE 3 -- ACCEPT "
+ $IPTABLES -A RULE_3 -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ # fw is part of any and networks
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -p tcp -m tcp -s $i_eth0 -d 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ done
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ # fw is NOT part of any and networks
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -p tcp -m tcp -s $i_eth0 -d 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ done
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -p tcp -m tcp -s $i_eth0 -d 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ done
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ # fw is part of any
+ $IPTABLES -N Cid307958X52019.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 22 -m state --state NEW -j Cid307958X52019.0
+ $IPTABLES -A Cid307958X52019.0 -s 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid307958X52019.0 -s 192.168.1.254 -j ACCEPT
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ # fw is not part of any
+ $IPTABLES -N Cid625000X52019.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 22 -m state --state NEW -j Cid625000X52019.0
+ $IPTABLES -A Cid625000X52019.0 -s 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid625000X52019.0 -s 192.168.1.254 -j ACCEPT
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ # fw is not part of any
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.254 -d 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.1 -d 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.2 -d 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.2 -d 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ # All other attempts to connect to
+ # the firewall are denied and logged
+ $IPTABLES -N RULE_12
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -d $i_eth0 -j RULE_12
+ done
+ $IPTABLES -A OUTPUT -d 172.20.0.1 -j RULE_12
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j RULE_12
+ $IPTABLES -A OUTPUT -d 192.168.1.254 -j RULE_12
+ $IPTABLES -A INPUT -j RULE_12
+ $IPTABLES -A RULE_12 -j LOG --log-level info --log-prefix "RULE 12 -- DENY "
+ $IPTABLES -A RULE_12 -j DROP
+ #
+ # Rule 13 (eth0)
+ #
+ echo "Rule 13 (eth0)"
+ #
+ $IPTABLES -A INPUT -i ! eth0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i ! eth0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o ! eth0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o ! eth0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 14 (eth0,eth1)
+ #
+ echo "Rule 14 (eth0,eth1)"
+ #
+ $IPTABLES -A INPUT -i eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth2.100 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i eth2.100 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth2.100 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o eth2.100 -m state --state NEW -j ACCEPT
+ #
+ # Rule 15 (eth0)
+ #
+ echo "Rule 15 (eth0)"
+ #
+ # fw is part of any is OFF
+ $IPTABLES -A FORWARD -i ! eth0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o ! eth0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 16 (eth0,eth1)
+ #
+ echo "Rule 16 (eth0,eth1)"
+ #
+ # fw is part of any is OFF
+ $IPTABLES -A FORWARD -i eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i eth2.100 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o eth2.100 -m state --state NEW -j ACCEPT
+ #
+ # Rule 17 (eth0)
+ #
+ echo "Rule 17 (eth0)"
+ #
+ # fw is part of any is OFF
+ $IPTABLES -A FORWARD -i ! eth0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 18 (eth0,eth1)
+ #
+ echo "Rule 18 (eth0,eth1)"
+ #
+ # fw is part of any is OFF
+ $IPTABLES -A FORWARD -i eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i eth2.100 -m state --state NEW -j ACCEPT
+ #
+ # Rule 19 (eth0)
+ #
+ echo "Rule 19 (eth0)"
+ #
+ # fw is part of any is OFF
+ $IPTABLES -A FORWARD -o ! eth0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 20 (eth0,eth1)
+ #
+ echo "Rule 20 (eth0,eth1)"
+ #
+ # fw is part of any is OFF
+ $IPTABLES -A FORWARD -o eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o eth2.100 -m state --state NEW -j ACCEPT
+ #
+ # Rule 21 (eth0)
+ #
+ echo "Rule 21 (eth0)"
+ #
+ $IPTABLES -A INPUT -i ! eth0 -m state --state NEW -j ACCEPT
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -o ! eth0 -d $i_eth0 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A OUTPUT -o ! eth0 -d 172.20.0.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o ! eth0 -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o ! eth0 -d 192.168.1.254 -m state --state NEW -j ACCEPT
+ #
+ # Rule 22 (eth0,eth1)
+ #
+ echo "Rule 22 (eth0,eth1)"
+ #
+ $IPTABLES -A INPUT -i eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth2.100 -m state --state NEW -j ACCEPT
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -o eth2 -d $i_eth0 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A OUTPUT -o eth2 -d 172.20.0.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth2 -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth2 -d 192.168.1.254 -m state --state NEW -j ACCEPT
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -o eth2.100 -d $i_eth0 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A OUTPUT -o eth2.100 -d 172.20.0.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth2.100 -d 192.168.1.1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth2.100 -d 192.168.1.254 -m state --state NEW -j ACCEPT
+ #
+ # Rule 23 (eth0)
+ #
+ echo "Rule 23 (eth0)"
+ #
+ # fw is part of any is OFF
+ $IPTABLES -A INPUT -i ! eth0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 24 (eth0,eth1)
+ #
+ echo "Rule 24 (eth0,eth1)"
+ #
+ # fw is part of any is OFF
+ $IPTABLES -A INPUT -i eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth2.100 -m state --state NEW -j ACCEPT
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:15 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/heartbeat_cluster_1_d_linux-2-d.fw.orig b/test/ipt/heartbeat_cluster_1_d_linux-2-d.fw.orig
new file mode 100755
index 000000000..58e48beca
--- /dev/null
+++ b/test/ipt/heartbeat_cluster_1_d_linux-2-d.fw.orig
@@ -0,0 +1,783 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:15 2011 PST by vadim
+#
+# files: * heartbeat_cluster_1_d_linux-2-d.fw firewall.sh
+#
+# Compiled for iptables (any version)
+#
+# This firewall has two interfaces. Eth0 faces outside and has a dynamic address; eth1 faces inside.
+# Policy includes basic rules to permit unrestricted outbound access and anti-spoofing rules. Access to the firewall is permitted only from internal network and only using SSH. The firewall uses one of the machines on internal network for DNS. Internal network is configured with address 192.168.1.0/255.255.255.0
+
+# heartbeat_cluster_1_d:NAT:4: error: Can not build rule using dynamic interface 'eth0' of the object 'linux-1-d' because its address in unknown.
+# heartbeat_cluster_1_d:NAT:: warning: Empty inet address in object id57982X27834
+
+# heartbeat_cluster_1_d:Policy:7: error: Can not build rule using dynamic interface 'eth0' of the object 'linux-1-d' because its address in unknown.
+# heartbeat_cluster_1_d:Policy:7: error: Can not build rule using dynamic interface 'eth0' of the object 'linux-1-d' because its address in unknown.
+
+# linux-2-d::: warning: Can not add virtual address for object eth0
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo eth2 eth2.100"
+ for i in eth0 eth1 lo eth2 eth2.100 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth1 192.168.1.2/24" "192.168.1.254/24"
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth2.100 172.20.0.2/24" ""
+ getaddr eth0 i_eth0
+ getaddr6 eth0 i_eth0_v6
+ getaddr eth0 i_eth0
+ getaddr6 eth0 i_eth0_v6
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j MASQUERADE
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source $i_eth0
+ done
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source $i_eth0 --random
+ done
+ #
+ # Rule 3 (NAT)
+ #
+ echo "Rule 3 (NAT)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -t nat -A PREROUTING -d $i_eth0 -j DNAT --to-destination 192.168.1.100
+ done
+ #
+ # Rule 4 (NAT)
+ #
+ echo "Rule 4 (NAT)"
+ #
+ # heartbeat_cluster_1_d:NAT:4: error: Can not build rule using dynamic interface 'eth0' of the object 'linux-1-d' because its address in unknown.
+ $IPTABLES -t nat -A PREROUTING -d -j DNAT --to-destination 192.168.1.100
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule -8 heartbeat (automatic)
+ #
+ echo "Rule -8 heartbeat (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth2.100 -p udp -m udp -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -7 heartbeat (automatic)
+ #
+ echo "Rule -7 heartbeat (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth2.100 -p udp -m udp -s 172.20.0.1 -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -6 heartbeat (automatic)
+ #
+ echo "Rule -6 heartbeat (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth1 -p udp -m udp -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -5 heartbeat (automatic)
+ #
+ echo "Rule -5 heartbeat (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p udp -m udp -s 192.168.1.1 -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -4 heartbeat (automatic)
+ #
+ echo "Rule -4 heartbeat (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -3 heartbeat (automatic)
+ #
+ echo "Rule -3 heartbeat (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -2 CONNTRACK (automatic)
+ #
+ echo "Rule -2 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 225.0.0.50 --dport 3780 -j ACCEPT
+ #
+ # Rule -1 CONNTRACK (automatic)
+ #
+ echo "Rule -1 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 225.0.0.50 --dport 3780 -j ACCEPT
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ # anti spoofing rule
+ $IPTABLES -N In_RULE_0
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A INPUT -i eth0 -s $i_eth0 -m state --state NEW -j In_RULE_0
+ done
+ $IPTABLES -A INPUT -i eth0 -s 172.20.0.2 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.2 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.254 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_0
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A FORWARD -i eth0 -s $i_eth0 -m state --state NEW -j In_RULE_0
+ done
+ $IPTABLES -A FORWARD -i eth0 -s 172.20.0.2 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.2 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.254 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A In_RULE_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A In_RULE_0 -j DROP
+ #
+ # Rule 1 (lo)
+ #
+ echo "Rule 1 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ # Firewall uses one of the machines
+ # on internal network for DNS
+ $IPTABLES -N RULE_3
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_3
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_3
+ $IPTABLES -A RULE_3 -j LOG --log-level info --log-prefix "RULE 3 -- ACCEPT "
+ $IPTABLES -A RULE_3 -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ # fw is part of any and networks
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -p tcp -m tcp -s $i_eth0 -d 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ done
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ # fw is NOT part of any and networks
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -p tcp -m tcp -s $i_eth0 -d 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ done
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -p tcp -m tcp -s $i_eth0 -d 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ done
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ # fw is part of any
+ $IPTABLES -N Cid307958X52019.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 22 -m state --state NEW -j Cid307958X52019.0
+ $IPTABLES -A Cid307958X52019.0 -s 192.168.1.2 -j ACCEPT
+ $IPTABLES -A Cid307958X52019.0 -s 192.168.1.254 -j ACCEPT
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ # fw is not part of any
+ $IPTABLES -N Cid625000X52019.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 22 -m state --state NEW -j Cid625000X52019.0
+ $IPTABLES -A Cid625000X52019.0 -s 192.168.1.2 -j ACCEPT
+ $IPTABLES -A Cid625000X52019.0 -s 192.168.1.254 -j ACCEPT
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ # fw is not part of any
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.254 -d 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.2 -d 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.1 -d 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.1 -d 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ # All other attempts to connect to
+ # the firewall are denied and logged
+ $IPTABLES -N RULE_12
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -d $i_eth0 -j RULE_12
+ done
+ $IPTABLES -A OUTPUT -d 172.20.0.2 -j RULE_12
+ $IPTABLES -A OUTPUT -d 192.168.1.2 -j RULE_12
+ $IPTABLES -A OUTPUT -d 192.168.1.254 -j RULE_12
+ $IPTABLES -A INPUT -j RULE_12
+ $IPTABLES -A RULE_12 -j LOG --log-level info --log-prefix "RULE 12 -- DENY "
+ $IPTABLES -A RULE_12 -j DROP
+ #
+ # Rule 13 (eth0)
+ #
+ echo "Rule 13 (eth0)"
+ #
+ $IPTABLES -A INPUT -i ! eth0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i ! eth0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o ! eth0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o ! eth0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 14 (eth0,eth1)
+ #
+ echo "Rule 14 (eth0,eth1)"
+ #
+ $IPTABLES -A INPUT -i eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth2.100 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i eth2.100 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth2.100 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o eth2.100 -m state --state NEW -j ACCEPT
+ #
+ # Rule 15 (eth0)
+ #
+ echo "Rule 15 (eth0)"
+ #
+ # fw is part of any is OFF
+ $IPTABLES -A FORWARD -i ! eth0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o ! eth0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 16 (eth0,eth1)
+ #
+ echo "Rule 16 (eth0,eth1)"
+ #
+ # fw is part of any is OFF
+ $IPTABLES -A FORWARD -i eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i eth2.100 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o eth2.100 -m state --state NEW -j ACCEPT
+ #
+ # Rule 17 (eth0)
+ #
+ echo "Rule 17 (eth0)"
+ #
+ # fw is part of any is OFF
+ $IPTABLES -A FORWARD -i ! eth0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 18 (eth0,eth1)
+ #
+ echo "Rule 18 (eth0,eth1)"
+ #
+ # fw is part of any is OFF
+ $IPTABLES -A FORWARD -i eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -i eth2.100 -m state --state NEW -j ACCEPT
+ #
+ # Rule 19 (eth0)
+ #
+ echo "Rule 19 (eth0)"
+ #
+ # fw is part of any is OFF
+ $IPTABLES -A FORWARD -o ! eth0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 20 (eth0,eth1)
+ #
+ echo "Rule 20 (eth0,eth1)"
+ #
+ # fw is part of any is OFF
+ $IPTABLES -A FORWARD -o eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o eth2.100 -m state --state NEW -j ACCEPT
+ #
+ # Rule 21 (eth0)
+ #
+ echo "Rule 21 (eth0)"
+ #
+ $IPTABLES -A INPUT -i ! eth0 -m state --state NEW -j ACCEPT
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -o ! eth0 -d $i_eth0 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A OUTPUT -o ! eth0 -d 172.20.0.2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o ! eth0 -d 192.168.1.2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o ! eth0 -d 192.168.1.254 -m state --state NEW -j ACCEPT
+ #
+ # Rule 22 (eth0,eth1)
+ #
+ echo "Rule 22 (eth0,eth1)"
+ #
+ $IPTABLES -A INPUT -i eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth2.100 -m state --state NEW -j ACCEPT
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -o eth2 -d $i_eth0 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A OUTPUT -o eth2 -d 172.20.0.2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth2 -d 192.168.1.2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth2 -d 192.168.1.254 -m state --state NEW -j ACCEPT
+ for i_eth0 in $i_eth0_list
+ do
+ test -n "$i_eth0" && $IPTABLES -A OUTPUT -o eth2.100 -d $i_eth0 -m state --state NEW -j ACCEPT
+ done
+ $IPTABLES -A OUTPUT -o eth2.100 -d 172.20.0.2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth2.100 -d 192.168.1.2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth2.100 -d 192.168.1.254 -m state --state NEW -j ACCEPT
+ #
+ # Rule 23 (eth0)
+ #
+ echo "Rule 23 (eth0)"
+ #
+ # fw is part of any is OFF
+ $IPTABLES -A INPUT -i ! eth0 -m state --state NEW -j ACCEPT
+ #
+ # Rule 24 (eth0,eth1)
+ #
+ echo "Rule 24 (eth0,eth1)"
+ #
+ # fw is part of any is OFF
+ $IPTABLES -A INPUT -i eth2 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -i eth2.100 -m state --state NEW -j ACCEPT
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:15 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/heartbeat_cluster_1_linux-1.fw.orig b/test/ipt/heartbeat_cluster_1_linux-1.fw.orig
new file mode 100755
index 000000000..8d337c41a
--- /dev/null
+++ b/test/ipt/heartbeat_cluster_1_linux-1.fw.orig
@@ -0,0 +1,891 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:14 2011 PST by vadim
+#
+# files: * heartbeat_cluster_1_linux-1.fw
+#
+# Compiled for iptables (any version)
+#
+#
+
+# linux-1:to_fw:: warning: ignoring cluster rule set "to_fw" because member firewall "linux-1" has rule set with the same name.
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+ find_program $VCONFIG
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+missing_vlan() {
+ vlan=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $vlan
+ subint=$1
+ parent=$2
+ IFS=$oldIFS
+
+ vlan_id=$(echo $subint | sed -r 's/(vlan|[^.]*\.)//')
+ test "$cmd" = "add" && {
+ echo $subint | grep -q "vlan" && name_type="VLAN_PLUS_VID" || name_type="DEV_PLUS_VID"
+ test "$vlan_id" \< "1" || name_type="${name_type}_NO_PAD"
+ echo "# Adding VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $VCONFIG set_name_type $name_type
+ $FWBDEBUG $VCONFIG $cmd $parent $vlan_id
+ $FWBDEBUG $IP link set $subint up
+ }
+ test "$cmd" = "rem" && {
+ echo "# Removing VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $VCONFIG $cmd $subint
+ }
+}
+
+parse_fwb_vlans() {
+ set $1
+ vlan_parent_interface=$1
+ shift
+
+ FWB_VLANS=$(
+ for subint in $*; do
+ echo "${subint}@$vlan_parent_interface"
+ done | sort
+ )
+ echo $FWB_VLANS
+}
+
+parse_current_vlans() {
+ vlan_parent_interface=$1
+ CURRENT_VLANS=""
+ PROC_DIR="/proc/net/vlan/"
+ test -d $PROC_DIR || $MODPROBE 8021q || {
+ echo "$PROC_DIR does not exist. Vlan interfaces are not available."
+ exit 1
+ }
+
+ test -f "/proc/net/vlan/config" && {
+ CURRENT_VLANS=$(
+ cat /proc/net/vlan/config | grep -v 'Dev name' | grep $vlan_parent_interface | \
+ while read subint a vlan_id b parent; do
+ echo "${subint}@$parent"
+ done | sort
+ )
+ }
+ echo $CURRENT_VLANS
+}
+
+update_vlans_of_interface() {
+ args="$1"
+ set $1
+ vlan_parent_interface=$1
+
+ FWB_VLANS=$(parse_fwb_vlans "$args")
+ CURRENT_VLANS=$(parse_current_vlans $vlan_parent_interface)
+
+ $IP link set $vlan_parent_interface up
+ diff_intf missing_vlan "$FWB_VLANS" "$CURRENT_VLANS" add
+ diff_intf missing_vlan "$CURRENT_VLANS" "$FWB_VLANS" rem
+}
+
+add_vlans() {
+ args="$1"
+ set $1
+ vlan_parent_interface=$1
+
+ FWB_VLANS=$(parse_fwb_vlans $args)
+ CURRENT_VLANS=$(parse_current_vlans $vlan_parent_interface)
+
+ $IP link set $vlan_parent_interface up
+ diff_intf missing_vlan "$FWB_VLANS" "$CURRENT_VLANS" add
+}
+
+clear_vlans_except_known() {
+ FWB_VLANS=$*
+ CURRENT_VLANS=$(parse_current_vlans '|')
+
+ diff_intf missing_vlan "$CURRENT_VLANS" "$FWB_VLANS" rem
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo eth0.100"
+ for i in eth0 eth1 lo eth0.100 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_vlans_of_interface "eth0 eth0.100"
+ clear_vlans_except_known eth0.100@eth0
+ update_addresses_of_interface "eth0 172.24.0.2/16" "172.24.0.1/16"
+ update_addresses_of_interface "eth1 192.168.1.2/24" "192.168.1.1/24"
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth0.100 192.168.100.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 172.24.0.1
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 172.24.0.1
+
+
+
+ # ================ Table 'filter', rule set to_fw
+ #
+ # Rule to_fw 0 (global)
+ #
+ echo "Rule to_fw 0 (global)"
+ #
+ # hashlimit 10/sec
+ $IPTABLES -N to_fw
+ $IPTABLES -N to_fw_0
+ $IPTABLES -A to_fw -m hashlimit --hashlimit 10/second --hashlimit-name htable_rule_0 -j to_fw_0
+ $IPTABLES -A to_fw_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A to_fw_0 -j DROP
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule -4 heartbeat (automatic)
+ #
+ echo "Rule -4 heartbeat (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -3 heartbeat (automatic)
+ #
+ echo "Rule -3 heartbeat (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -s 172.24.0.3 -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -2 CONNTRACK (automatic)
+ #
+ echo "Rule -2 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 225.0.0.50 --dport 3781 -j ACCEPT
+ #
+ # Rule -1 CONNTRACK (automatic)
+ #
+ echo "Rule -1 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 225.0.0.50 --dport 3781 -j ACCEPT
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ # anti spoofing rule
+ $IPTABLES -N In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.100.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.100.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A In_RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A In_RULE_1 -j DROP
+ #
+ # Rule 2 (lo)
+ #
+ echo "Rule 2 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.2 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.3 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.3 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ # Firewall uses one of the machines
+ # on internal network for DNS
+ $IPTABLES -N RULE_5
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A RULE_5 -j LOG --log-level info --log-prefix "RULE 5 -- ACCEPT "
+ $IPTABLES -A RULE_5 -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ # branch rule set is different in members linux-1 and linux-2
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -j to_fw
+ $IPTABLES -A OUTPUT -d 172.24.0.2 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.1.2 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.100.1 -j to_fw
+ $IPTABLES -A INPUT -j to_fw
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ # branch rule set is different in members linux-1 and linux-2
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -j to_fw
+ $IPTABLES -A OUTPUT -d 172.24.0.2 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.1.2 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.100.1 -j to_fw
+ $IPTABLES -A INPUT -j to_fw
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -j DROP
+ $IPTABLES -A OUTPUT -d 172.24.0.2 -j DROP
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j DROP
+ $IPTABLES -A OUTPUT -d 192.168.1.2 -j DROP
+ $IPTABLES -A OUTPUT -d 192.168.100.1 -j DROP
+ $IPTABLES -A INPUT -j DROP
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -A INPUT -j DROP
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ # fw is part of any
+ $IPTABLES -N Cid997025X96143.0
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid997025X96143.0
+ $IPTABLES -A Cid997025X96143.0 -s 172.24.0.1 -j ACCEPT
+ $IPTABLES -A Cid997025X96143.0 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A Cid997025X96143.0 -s 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid997025X96143.0 -s 192.168.1.2 -j ACCEPT
+ $IPTABLES -A Cid997025X96143.0 -s 192.168.100.1 -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ # fw is NOT part of any
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ # fw is NOT part of any
+ $IPTABLES -N Cid143289X96143.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid143289X96143.0
+ $IPTABLES -A Cid143289X96143.0 -s 172.24.0.1 -j ACCEPT
+ $IPTABLES -A Cid143289X96143.0 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A Cid143289X96143.0 -s 192.168.100.1 -j ACCEPT
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ # fw is NOT part of any
+ $IPTABLES -N Cid1946680X96143.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid1946680X96143.0
+ $IPTABLES -A Cid1946680X96143.0 -s 172.24.0.1 -j ACCEPT
+ $IPTABLES -A Cid1946680X96143.0 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A Cid1946680X96143.0 -s 192.168.100.1 -j ACCEPT
+ #
+ # Rule 14 (eth0)
+ #
+ echo "Rule 14 (eth0)"
+ #
+ # fw is NOT part of any
+ $IPTABLES -N Cid378955X96143.0
+ $IPTABLES -A FORWARD -i eth0 -p tcp -m tcp --dport 22 -m state --state NEW -j Cid378955X96143.0
+ $IPTABLES -A Cid378955X96143.0 -s 172.24.0.1 -j ACCEPT
+ $IPTABLES -A Cid378955X96143.0 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A Cid378955X96143.0 -s 192.168.100.1 -j ACCEPT
+ $IPTABLES -N Cid378955X96143.1
+ $IPTABLES -A OUTPUT -o eth0 -p tcp -m tcp --dport 22 -m state --state NEW -j Cid378955X96143.1
+ $IPTABLES -A Cid378955X96143.1 -s 172.24.0.1 -j ACCEPT
+ $IPTABLES -A Cid378955X96143.1 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A Cid378955X96143.1 -s 192.168.100.1 -j ACCEPT
+ #
+ # Rule 15 (eth0)
+ #
+ echo "Rule 15 (eth0)"
+ #
+ # fw is NOT part of any
+ $IPTABLES -N Cid1801407X96143.0
+ $IPTABLES -A OUTPUT -o eth0 -p tcp -m tcp --dport 22 -m state --state NEW -j Cid1801407X96143.0
+ $IPTABLES -A Cid1801407X96143.0 -s 172.24.0.1 -j ACCEPT
+ $IPTABLES -A Cid1801407X96143.0 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A Cid1801407X96143.0 -s 192.168.100.1 -j ACCEPT
+ #
+ # Rule 16 (global)
+ #
+ echo "Rule 16 (global)"
+ #
+ # fw is NOT part of any
+ $IPTABLES -N Cid143343X96143.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid143343X96143.0
+ $IPTABLES -A Cid143343X96143.0 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A Cid143343X96143.0 -s 192.168.100.1 -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 172.24.0.3 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 17 (eth0)
+ #
+ echo "Rule 17 (eth0)"
+ #
+ # fw is NOT part of any
+ $IPTABLES -N Cid2241935X96143.0
+ $IPTABLES -A FORWARD -i eth0 -p tcp -m tcp --dport 22 -m state --state NEW -j Cid2241935X96143.0
+ $IPTABLES -A Cid2241935X96143.0 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A Cid2241935X96143.0 -s 192.168.100.1 -j ACCEPT
+ $IPTABLES -A FORWARD -i eth0 -p tcp -m tcp -s 172.24.0.3 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -N Cid2241935X96143.1
+ $IPTABLES -A OUTPUT -o eth0 -p tcp -m tcp --dport 22 -m state --state NEW -j Cid2241935X96143.1
+ $IPTABLES -A Cid2241935X96143.1 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A Cid2241935X96143.1 -s 192.168.100.1 -j ACCEPT
+ $IPTABLES -A FORWARD -o eth0 -p tcp -m tcp -s 172.24.0.3 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 18 (eth0)
+ #
+ echo "Rule 18 (eth0)"
+ #
+ # fw is NOT part of any
+ $IPTABLES -N Cid2241981X96143.0
+ $IPTABLES -A OUTPUT -o eth0 -p tcp -m tcp --dport 22 -m state --state NEW -j Cid2241981X96143.0
+ $IPTABLES -A Cid2241981X96143.0 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A Cid2241981X96143.0 -s 192.168.100.1 -j ACCEPT
+ $IPTABLES -A FORWARD -o eth0 -p tcp -m tcp -s 172.24.0.3 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ # using interface of another cluster in the rule
+ $IPTABLES -N Cid8228X45618.0
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid8228X45618.0
+ $IPTABLES -A Cid8228X45618.0 -s 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid8228X45618.0 -s 192.168.1.2 -j ACCEPT
+ $IPTABLES -A Cid8228X45618.0 -s 192.168.1.100 -j ACCEPT
+ #
+ # Rule 20 (global)
+ #
+ echo "Rule 20 (global)"
+ #
+ $IPTABLES -N Cid147047X84105.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid147047X84105.0
+ $IPTABLES -A Cid147047X84105.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid147047X84105.0 -d 192.168.1.2 -j ACCEPT
+ $IPTABLES -A Cid147047X84105.0 -d 192.168.1.100 -j ACCEPT
+ #
+ # Rule 21 (global)
+ #
+ echo "Rule 21 (global)"
+ #
+ $IPTABLES -N RULE_21
+ $IPTABLES -A OUTPUT -m state --state NEW -j RULE_21
+ $IPTABLES -A INPUT -m state --state NEW -j RULE_21
+ $IPTABLES -A FORWARD -m state --state NEW -j RULE_21
+ $IPTABLES -A RULE_21 -j LOG --log-level info --log-prefix "RULE 21 -- DENY "
+ $IPTABLES -A RULE_21 -j DROP
+ #
+ # Rule 22 (global)
+ #
+ echo "Rule 22 (global)"
+ #
+ $IPTABLES -N RULE_22
+ $IPTABLES -A OUTPUT -j RULE_22
+ $IPTABLES -A INPUT -j RULE_22
+ $IPTABLES -A FORWARD -j RULE_22
+ $IPTABLES -A RULE_22 -j LOG --log-level info --log-prefix "RULE 22 -- DENY "
+ $IPTABLES -A RULE_22 -j DROP
+
+
+
+
+
+
+
+
+ # ============== ROUTING RULES ==============
+
+ TMPDIRNAME="/tmp/.fwbuilder.tempdir.$$"
+ TMPFILENAME="$TMPDIRNAME/.fwbuilder.out"
+ (umask 077 && mkdir $TMPDIRNAME) || exit 1
+
+ #
+ # This function stops stdout redirection
+ # and sends previously saved output to terminal
+ restore_script_output()
+ {
+ exec 1>&3 2>&1
+ cat $TMPFILENAME
+ rm -rf $TMPDIRNAME
+ }
+
+ # if any routing rule fails we do our best to prevent freezing the firewall
+ route_command_error()
+ {
+ echo "Error: Routing rule $1 couldn't be activated"
+ echo "Recovering previous routing configuration..."
+ # delete current routing rules
+ $IP route show | while read route ; do $IP route del $route ; done
+ # restore old routing rules
+ (IFS="
+ "; for route in $oldRoutes; do (IFS=' '; $IP route add $route); done)
+ echo "...done"
+ restore_script_output
+ epilog_commands
+ exit 1
+ }
+
+ # redirect output to prevent ssh session from stalling
+ exec 3>&1
+ exec 1> $TMPFILENAME
+ exec 2>&1
+
+ # store previous routing configuration (sort: 'via' GW has to be
+ # inserted after device routes)
+ oldRoutes=$($IP route show | sort -k 2)
+
+ echo "Deleting routing rules previously set by user space processes..."
+ $IP route show | grep -v '\( proto kernel \)\|\(default via \)' | \
+ while read route ; do $IP route del $route ; done
+
+ echo "Activating non-ecmp routing rules..."
+ #
+ # Rule 0 (main)
+ #
+ echo "Routing rule 0 (main)"
+ #
+ #
+ #
+ $IP route add 172.24.1.0/24 via 172.24.0.100 dev eth0 \
+ || route_command_error "0 (main)"
+
+
+ restore_script_output
+ echo "...done."
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:14 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/heartbeat_cluster_1_linux-2.fw.orig b/test/ipt/heartbeat_cluster_1_linux-2.fw.orig
new file mode 100755
index 000000000..7cb8d3ea2
--- /dev/null
+++ b/test/ipt/heartbeat_cluster_1_linux-2.fw.orig
@@ -0,0 +1,789 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:14 2011 PST by vadim
+#
+# files: * heartbeat_cluster_1_linux-2.fw
+#
+# Compiled for iptables (any version)
+#
+
+# linux-2:to_fw:: warning: ignoring cluster rule set "to_fw" because member firewall "linux-2" has rule set with the same name.
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo"
+ for i in eth0 eth1 lo ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 172.24.0.3/16" "172.24.0.1/16"
+ update_addresses_of_interface "eth1 192.168.1.3/24" "192.168.1.1/24"
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 172.24.0.1
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 172.24.0.1
+
+
+
+ # ================ Table 'filter', rule set to_fw
+ #
+ # Rule to_fw 0 (global)
+ #
+ echo "Rule to_fw 0 (global)"
+ #
+ # hashlimit 20/sec
+ $IPTABLES -N to_fw
+ $IPTABLES -N to_fw_0
+ $IPTABLES -A to_fw -m hashlimit --hashlimit 20/second --hashlimit-name htable_rule_0 -j to_fw_0
+ $IPTABLES -A to_fw_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A to_fw_0 -j DROP
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule -4 heartbeat (automatic)
+ #
+ echo "Rule -4 heartbeat (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -3 heartbeat (automatic)
+ #
+ echo "Rule -3 heartbeat (automatic)"
+ #
+ $IPTABLES -N C.0
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 224.0.10.100 --dport 694 -j C.0
+ $IPTABLES -A C.0 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A C.0 -s 192.168.100.1 -j ACCEPT
+ #
+ # Rule -2 CONNTRACK (automatic)
+ #
+ echo "Rule -2 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 225.0.0.50 --dport 3781 -j ACCEPT
+ #
+ # Rule -1 CONNTRACK (automatic)
+ #
+ echo "Rule -1 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 225.0.0.50 --dport 3781 -j ACCEPT
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ # anti spoofing rule
+ $IPTABLES -N In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A In_RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A In_RULE_1 -j DROP
+ #
+ # Rule 2 (lo)
+ #
+ echo "Rule 2 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.3 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.2 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.2 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ # Firewall uses one of the machines
+ # on internal network for DNS
+ $IPTABLES -N RULE_5
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A RULE_5 -j LOG --log-level info --log-prefix "RULE 5 -- ACCEPT "
+ $IPTABLES -A RULE_5 -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ # branch rule set is different in members linux-1 and linux-2
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -j to_fw
+ $IPTABLES -A OUTPUT -d 172.24.0.3 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.1.3 -j to_fw
+ $IPTABLES -A INPUT -j to_fw
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ # branch rule set is different in members linux-1 and linux-2
+ $IPTABLES -A OUTPUT -d 172.24.0.2 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.1.2 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.100.1 -j to_fw
+ $IPTABLES -A FORWARD -d 172.24.0.2 -j to_fw
+ $IPTABLES -A FORWARD -d 192.168.1.2 -j to_fw
+ $IPTABLES -A FORWARD -d 192.168.100.1 -j to_fw
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -j DROP
+ $IPTABLES -A OUTPUT -d 172.24.0.3 -j DROP
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j DROP
+ $IPTABLES -A OUTPUT -d 192.168.1.3 -j DROP
+ $IPTABLES -A INPUT -j DROP
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -A INPUT -j DROP
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ # fw is part of any
+ $IPTABLES -N Cid997025X96143.0
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid997025X96143.0
+ $IPTABLES -A Cid997025X96143.0 -s 172.24.0.1 -j ACCEPT
+ $IPTABLES -A Cid997025X96143.0 -s 172.24.0.3 -j ACCEPT
+ $IPTABLES -A Cid997025X96143.0 -s 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid997025X96143.0 -s 192.168.1.3 -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ # fw is NOT part of any
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 12 (global)
+ #
+ echo "Rule 12 (global)"
+ #
+ # fw is NOT part of any
+ $IPTABLES -N Cid143289X96143.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid143289X96143.0
+ $IPTABLES -A Cid143289X96143.0 -s 172.24.0.1 -j ACCEPT
+ $IPTABLES -A Cid143289X96143.0 -s 172.24.0.3 -j ACCEPT
+ #
+ # Rule 13 (global)
+ #
+ echo "Rule 13 (global)"
+ #
+ # fw is NOT part of any
+ $IPTABLES -N Cid1946680X96143.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid1946680X96143.0
+ $IPTABLES -A Cid1946680X96143.0 -s 172.24.0.1 -j ACCEPT
+ $IPTABLES -A Cid1946680X96143.0 -s 172.24.0.3 -j ACCEPT
+ #
+ # Rule 14 (eth0)
+ #
+ echo "Rule 14 (eth0)"
+ #
+ # fw is NOT part of any
+ $IPTABLES -N Cid378955X96143.0
+ $IPTABLES -A FORWARD -i eth0 -p tcp -m tcp --dport 22 -m state --state NEW -j Cid378955X96143.0
+ $IPTABLES -A Cid378955X96143.0 -s 172.24.0.1 -j ACCEPT
+ $IPTABLES -A Cid378955X96143.0 -s 172.24.0.3 -j ACCEPT
+ $IPTABLES -N Cid378955X96143.1
+ $IPTABLES -A OUTPUT -o eth0 -p tcp -m tcp --dport 22 -m state --state NEW -j Cid378955X96143.1
+ $IPTABLES -A Cid378955X96143.1 -s 172.24.0.1 -j ACCEPT
+ $IPTABLES -A Cid378955X96143.1 -s 172.24.0.3 -j ACCEPT
+ #
+ # Rule 15 (eth0)
+ #
+ echo "Rule 15 (eth0)"
+ #
+ # fw is NOT part of any
+ $IPTABLES -N Cid1801407X96143.0
+ $IPTABLES -A OUTPUT -o eth0 -p tcp -m tcp --dport 22 -m state --state NEW -j Cid1801407X96143.0
+ $IPTABLES -A Cid1801407X96143.0 -s 172.24.0.1 -j ACCEPT
+ $IPTABLES -A Cid1801407X96143.0 -s 172.24.0.3 -j ACCEPT
+ #
+ # Rule 16 (global)
+ #
+ echo "Rule 16 (global)"
+ #
+ # fw is NOT part of any
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 172.24.0.3 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -N Cid143343X96143.0
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 22 -m state --state NEW -j Cid143343X96143.0
+ $IPTABLES -A Cid143343X96143.0 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A Cid143343X96143.0 -s 192.168.100.1 -j ACCEPT
+ #
+ # Rule 17 (eth0)
+ #
+ echo "Rule 17 (eth0)"
+ #
+ # fw is NOT part of any
+ $IPTABLES -A FORWARD -i eth0 -p tcp -m tcp -s 172.24.0.3 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -N Cid2241935X96143.0
+ $IPTABLES -A FORWARD -i eth0 -p tcp -m tcp --dport 22 -m state --state NEW -j Cid2241935X96143.0
+ $IPTABLES -A Cid2241935X96143.0 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A Cid2241935X96143.0 -s 192.168.100.1 -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth0 -p tcp -m tcp -s 172.24.0.3 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -N Cid2241935X96143.1
+ $IPTABLES -A FORWARD -o eth0 -p tcp -m tcp --dport 22 -m state --state NEW -j Cid2241935X96143.1
+ $IPTABLES -A Cid2241935X96143.1 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A Cid2241935X96143.1 -s 192.168.100.1 -j ACCEPT
+ #
+ # Rule 18 (eth0)
+ #
+ echo "Rule 18 (eth0)"
+ #
+ # fw is NOT part of any
+ $IPTABLES -A OUTPUT -o eth0 -p tcp -m tcp -s 172.24.0.3 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -N Cid2241981X96143.0
+ $IPTABLES -A FORWARD -o eth0 -p tcp -m tcp --dport 22 -m state --state NEW -j Cid2241981X96143.0
+ $IPTABLES -A Cid2241981X96143.0 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A Cid2241981X96143.0 -s 192.168.100.1 -j ACCEPT
+ #
+ # Rule 19 (global)
+ #
+ echo "Rule 19 (global)"
+ #
+ # using interface of another cluster in the rule
+ $IPTABLES -N Cid8228X45618.0
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid8228X45618.0
+ $IPTABLES -A Cid8228X45618.0 -s 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid8228X45618.0 -s 192.168.1.2 -j ACCEPT
+ $IPTABLES -A Cid8228X45618.0 -s 192.168.1.100 -j ACCEPT
+ #
+ # Rule 20 (global)
+ #
+ echo "Rule 20 (global)"
+ #
+ $IPTABLES -N Cid147047X84105.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 22 -m state --state NEW -j Cid147047X84105.0
+ $IPTABLES -A Cid147047X84105.0 -d 192.168.1.1 -j ACCEPT
+ $IPTABLES -A Cid147047X84105.0 -d 192.168.1.2 -j ACCEPT
+ $IPTABLES -A Cid147047X84105.0 -d 192.168.1.100 -j ACCEPT
+ #
+ # Rule 21 (global)
+ #
+ echo "Rule 21 (global)"
+ #
+ $IPTABLES -N RULE_21
+ $IPTABLES -A OUTPUT -m state --state NEW -j RULE_21
+ $IPTABLES -A INPUT -m state --state NEW -j RULE_21
+ $IPTABLES -A FORWARD -m state --state NEW -j RULE_21
+ $IPTABLES -A RULE_21 -j LOG --log-level info --log-prefix "RULE 21 -- DENY "
+ $IPTABLES -A RULE_21 -j DROP
+ #
+ # Rule 22 (global)
+ #
+ echo "Rule 22 (global)"
+ #
+ $IPTABLES -N RULE_22
+ $IPTABLES -A OUTPUT -j RULE_22
+ $IPTABLES -A INPUT -j RULE_22
+ $IPTABLES -A FORWARD -j RULE_22
+ $IPTABLES -A RULE_22 -j LOG --log-level info --log-prefix "RULE 22 -- DENY "
+ $IPTABLES -A RULE_22 -j DROP
+
+
+
+
+
+
+
+
+ # ============== ROUTING RULES ==============
+
+ TMPDIRNAME="/tmp/.fwbuilder.tempdir.$$"
+ TMPFILENAME="$TMPDIRNAME/.fwbuilder.out"
+ (umask 077 && mkdir $TMPDIRNAME) || exit 1
+
+ #
+ # This function stops stdout redirection
+ # and sends previously saved output to terminal
+ restore_script_output()
+ {
+ exec 1>&3 2>&1
+ cat $TMPFILENAME
+ rm -rf $TMPDIRNAME
+ }
+
+ # if any routing rule fails we do our best to prevent freezing the firewall
+ route_command_error()
+ {
+ echo "Error: Routing rule $1 couldn't be activated"
+ echo "Recovering previous routing configuration..."
+ # delete current routing rules
+ $IP route show | while read route ; do $IP route del $route ; done
+ # restore old routing rules
+ (IFS="
+ "; for route in $oldRoutes; do (IFS=' '; $IP route add $route); done)
+ echo "...done"
+ restore_script_output
+ epilog_commands
+ exit 1
+ }
+
+ # redirect output to prevent ssh session from stalling
+ exec 3>&1
+ exec 1> $TMPFILENAME
+ exec 2>&1
+
+ # store previous routing configuration (sort: 'via' GW has to be
+ # inserted after device routes)
+ oldRoutes=$($IP route show | sort -k 2)
+
+ echo "Deleting routing rules previously set by user space processes..."
+ $IP route show | grep -v '\( proto kernel \)\|\(default via \)' | \
+ while read route ; do $IP route del $route ; done
+
+ echo "Activating non-ecmp routing rules..."
+ #
+ # Rule 0 (main)
+ #
+ echo "Routing rule 0 (main)"
+ #
+ #
+ #
+ $IP route add 172.24.1.0/24 via 172.24.0.100 dev eth0 \
+ || route_command_error "0 (main)"
+
+
+ restore_script_output
+ echo "...done."
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:14 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/heartbeat_cluster_2_linux-1.fw.orig b/test/ipt/heartbeat_cluster_2_linux-1.fw.orig
new file mode 100755
index 000000000..6cbf8da06
--- /dev/null
+++ b/test/ipt/heartbeat_cluster_2_linux-1.fw.orig
@@ -0,0 +1,767 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:15 2011 PST by vadim
+#
+# files: * heartbeat_cluster_2_linux-1.fw
+#
+# Compiled for iptables (any version)
+#
+#
+
+# linux-1:to_fw:: warning: ignoring cluster rule set "to_fw" because member firewall "linux-1" has rule set with the same name.
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+ find_program $VCONFIG
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+missing_vlan() {
+ vlan=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $vlan
+ subint=$1
+ parent=$2
+ IFS=$oldIFS
+
+ vlan_id=$(echo $subint | sed -r 's/(vlan|[^.]*\.)//')
+ test "$cmd" = "add" && {
+ echo $subint | grep -q "vlan" && name_type="VLAN_PLUS_VID" || name_type="DEV_PLUS_VID"
+ test "$vlan_id" \< "1" || name_type="${name_type}_NO_PAD"
+ echo "# Adding VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $VCONFIG set_name_type $name_type
+ $FWBDEBUG $VCONFIG $cmd $parent $vlan_id
+ $FWBDEBUG $IP link set $subint up
+ }
+ test "$cmd" = "rem" && {
+ echo "# Removing VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $VCONFIG $cmd $subint
+ }
+}
+
+parse_fwb_vlans() {
+ set $1
+ vlan_parent_interface=$1
+ shift
+
+ FWB_VLANS=$(
+ for subint in $*; do
+ echo "${subint}@$vlan_parent_interface"
+ done | sort
+ )
+ echo $FWB_VLANS
+}
+
+parse_current_vlans() {
+ vlan_parent_interface=$1
+ CURRENT_VLANS=""
+ PROC_DIR="/proc/net/vlan/"
+ test -d $PROC_DIR || $MODPROBE 8021q || {
+ echo "$PROC_DIR does not exist. Vlan interfaces are not available."
+ exit 1
+ }
+
+ test -f "/proc/net/vlan/config" && {
+ CURRENT_VLANS=$(
+ cat /proc/net/vlan/config | grep -v 'Dev name' | grep $vlan_parent_interface | \
+ while read subint a vlan_id b parent; do
+ echo "${subint}@$parent"
+ done | sort
+ )
+ }
+ echo $CURRENT_VLANS
+}
+
+update_vlans_of_interface() {
+ args="$1"
+ set $1
+ vlan_parent_interface=$1
+
+ FWB_VLANS=$(parse_fwb_vlans "$args")
+ CURRENT_VLANS=$(parse_current_vlans $vlan_parent_interface)
+
+ $IP link set $vlan_parent_interface up
+ diff_intf missing_vlan "$FWB_VLANS" "$CURRENT_VLANS" add
+ diff_intf missing_vlan "$CURRENT_VLANS" "$FWB_VLANS" rem
+}
+
+add_vlans() {
+ args="$1"
+ set $1
+ vlan_parent_interface=$1
+
+ FWB_VLANS=$(parse_fwb_vlans $args)
+ CURRENT_VLANS=$(parse_current_vlans $vlan_parent_interface)
+
+ $IP link set $vlan_parent_interface up
+ diff_intf missing_vlan "$FWB_VLANS" "$CURRENT_VLANS" add
+}
+
+clear_vlans_except_known() {
+ FWB_VLANS=$*
+ CURRENT_VLANS=$(parse_current_vlans '|')
+
+ diff_intf missing_vlan "$CURRENT_VLANS" "$FWB_VLANS" rem
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo eth0.100"
+ for i in eth0 eth1 lo eth0.100 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_vlans_of_interface "eth0 eth0.100"
+ clear_vlans_except_known eth0.100@eth0
+ update_addresses_of_interface "eth0 172.24.0.2/16" "172.24.0.1/16"
+ update_addresses_of_interface "eth1 192.168.1.2/24" "192.168.1.1/24"
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth0.100 192.168.100.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 172.24.0.1
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 172.24.0.1
+
+
+
+ # ================ Table 'filter', rule set to_fw
+ #
+ # Rule to_fw 0 (global)
+ #
+ echo "Rule to_fw 0 (global)"
+ #
+ # hashlimit 10/sec
+ $IPTABLES -N to_fw
+ $IPTABLES -N to_fw_0
+ $IPTABLES -A to_fw -m hashlimit --hashlimit 10/second --hashlimit-name htable_rule_0 -j to_fw_0
+ $IPTABLES -A to_fw_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A to_fw_0 -j DROP
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule -4 heartbeat (automatic)
+ #
+ echo "Rule -4 heartbeat (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 172.24.0.3 --dport 694 -j ACCEPT
+ #
+ # Rule -3 heartbeat (automatic)
+ #
+ echo "Rule -3 heartbeat (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -s 172.24.0.3 --dport 694 -j ACCEPT
+ #
+ # Rule -2 CONNTRACK (automatic)
+ #
+ echo "Rule -2 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 172.24.0.3 --dport 3781 -j ACCEPT
+ #
+ # Rule -1 CONNTRACK (automatic)
+ #
+ echo "Rule -1 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -s 172.24.0.3 --dport 3781 -j ACCEPT
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ # anti spoofing rule
+ $IPTABLES -N In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.100.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.100.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A In_RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A In_RULE_1 -j DROP
+ #
+ # Rule 2 (lo)
+ #
+ echo "Rule 2 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.2 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.3 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.3 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ # Firewall uses one of the machines
+ # on internal network for DNS
+ $IPTABLES -N RULE_5
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A RULE_5 -j LOG --log-level info --log-prefix "RULE 5 -- ACCEPT "
+ $IPTABLES -A RULE_5 -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ # branch rule set is different in members linux-1 and linux-2
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -j to_fw
+ $IPTABLES -A OUTPUT -d 172.24.0.2 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.1.2 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.100.1 -j to_fw
+ $IPTABLES -A INPUT -j to_fw
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ # branch rule set is different in members linux-1 and linux-2
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -j to_fw
+ $IPTABLES -A OUTPUT -d 172.24.0.2 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.1.2 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.100.1 -j to_fw
+ $IPTABLES -A INPUT -j to_fw
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -N RULE_8
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -j RULE_8
+ $IPTABLES -A OUTPUT -d 172.24.0.2 -j RULE_8
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j RULE_8
+ $IPTABLES -A OUTPUT -d 192.168.1.2 -j RULE_8
+ $IPTABLES -A OUTPUT -d 192.168.100.1 -j RULE_8
+ $IPTABLES -A INPUT -j RULE_8
+ $IPTABLES -A RULE_8 -j LOG --log-level info --log-prefix "RULE 8 -- DENY "
+ $IPTABLES -A RULE_8 -j DROP
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ $IPTABLES -N RULE_10
+ $IPTABLES -A OUTPUT -m state --state NEW -j RULE_10
+ $IPTABLES -A INPUT -m state --state NEW -j RULE_10
+ $IPTABLES -A FORWARD -m state --state NEW -j RULE_10
+ $IPTABLES -A RULE_10 -j LOG --log-level info --log-prefix "RULE 10 -- DENY "
+ $IPTABLES -A RULE_10 -j DROP
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ $IPTABLES -N RULE_11
+ $IPTABLES -A OUTPUT -j RULE_11
+ $IPTABLES -A INPUT -j RULE_11
+ $IPTABLES -A FORWARD -j RULE_11
+ $IPTABLES -A RULE_11 -j LOG --log-level info --log-prefix "RULE 11 -- DENY "
+ $IPTABLES -A RULE_11 -j DROP
+
+
+
+
+
+
+
+
+ # ============== ROUTING RULES ==============
+
+ TMPDIRNAME="/tmp/.fwbuilder.tempdir.$$"
+ TMPFILENAME="$TMPDIRNAME/.fwbuilder.out"
+ (umask 077 && mkdir $TMPDIRNAME) || exit 1
+
+ #
+ # This function stops stdout redirection
+ # and sends previously saved output to terminal
+ restore_script_output()
+ {
+ exec 1>&3 2>&1
+ cat $TMPFILENAME
+ rm -rf $TMPDIRNAME
+ }
+
+ # if any routing rule fails we do our best to prevent freezing the firewall
+ route_command_error()
+ {
+ echo "Error: Routing rule $1 couldn't be activated"
+ echo "Recovering previous routing configuration..."
+ # delete current routing rules
+ $IP route show | while read route ; do $IP route del $route ; done
+ # restore old routing rules
+ (IFS="
+ "; for route in $oldRoutes; do (IFS=' '; $IP route add $route); done)
+ echo "...done"
+ restore_script_output
+ epilog_commands
+ exit 1
+ }
+
+ # redirect output to prevent ssh session from stalling
+ exec 3>&1
+ exec 1> $TMPFILENAME
+ exec 2>&1
+
+ # store previous routing configuration (sort: 'via' GW has to be
+ # inserted after device routes)
+ oldRoutes=$($IP route show | sort -k 2)
+
+ echo "Deleting routing rules previously set by user space processes..."
+ $IP route show | grep -v '\( proto kernel \)\|\(default via \)' | \
+ while read route ; do $IP route del $route ; done
+
+ echo "Activating non-ecmp routing rules..."
+ #
+ # Rule 0 (main)
+ #
+ echo "Routing rule 0 (main)"
+ #
+ #
+ #
+ $IP route add 172.24.1.0/24 via 172.24.0.100 dev eth0 \
+ || route_command_error "0 (main)"
+
+
+ restore_script_output
+ echo "...done."
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:15 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/heartbeat_cluster_2_linux-2.fw.orig b/test/ipt/heartbeat_cluster_2_linux-2.fw.orig
new file mode 100755
index 000000000..b064306c6
--- /dev/null
+++ b/test/ipt/heartbeat_cluster_2_linux-2.fw.orig
@@ -0,0 +1,680 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:16 2011 PST by vadim
+#
+# files: * heartbeat_cluster_2_linux-2.fw
+#
+# Compiled for iptables (any version)
+#
+
+# linux-2:to_fw:: warning: ignoring cluster rule set "to_fw" because member firewall "linux-2" has rule set with the same name.
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo"
+ for i in eth0 eth1 lo ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 172.24.0.3/16" "172.24.0.1/16"
+ update_addresses_of_interface "eth1 192.168.1.3/24" "192.168.1.1/24"
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 172.24.0.1
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 172.24.0.1
+
+
+
+ # ================ Table 'filter', rule set to_fw
+ #
+ # Rule to_fw 0 (global)
+ #
+ echo "Rule to_fw 0 (global)"
+ #
+ # hashlimit 20/sec
+ $IPTABLES -N to_fw
+ $IPTABLES -N to_fw_0
+ $IPTABLES -A to_fw -m hashlimit --hashlimit 20/second --hashlimit-name htable_rule_0 -j to_fw_0
+ $IPTABLES -A to_fw_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A to_fw_0 -j DROP
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule -4 heartbeat (automatic)
+ #
+ echo "Rule -4 heartbeat (automatic)"
+ #
+ $IPTABLES -N C.0
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp --dport 694 -j C.0
+ $IPTABLES -A C.0 -d 172.24.0.2 -j ACCEPT
+ $IPTABLES -A C.0 -d 192.168.100.1 -j ACCEPT
+ #
+ # Rule -3 heartbeat (automatic)
+ #
+ echo "Rule -3 heartbeat (automatic)"
+ #
+ $IPTABLES -N C.1
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp --dport 694 -j C.1
+ $IPTABLES -A C.1 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A C.1 -s 192.168.100.1 -j ACCEPT
+ #
+ # Rule -2 CONNTRACK (automatic)
+ #
+ echo "Rule -2 CONNTRACK (automatic)"
+ #
+ $IPTABLES -N C.2
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp --dport 3781 -j C.2
+ $IPTABLES -A C.2 -d 172.24.0.2 -j ACCEPT
+ $IPTABLES -A C.2 -d 192.168.100.1 -j ACCEPT
+ #
+ # Rule -1 CONNTRACK (automatic)
+ #
+ echo "Rule -1 CONNTRACK (automatic)"
+ #
+ $IPTABLES -N C.3
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp --dport 3781 -j C.3
+ $IPTABLES -A C.3 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A C.3 -s 192.168.100.1 -j ACCEPT
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ # anti spoofing rule
+ $IPTABLES -N In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A In_RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A In_RULE_1 -j DROP
+ #
+ # Rule 2 (lo)
+ #
+ echo "Rule 2 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.3 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.2 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.2 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ # Firewall uses one of the machines
+ # on internal network for DNS
+ $IPTABLES -N RULE_5
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A RULE_5 -j LOG --log-level info --log-prefix "RULE 5 -- ACCEPT "
+ $IPTABLES -A RULE_5 -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ # branch rule set is different in members linux-1 and linux-2
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -j to_fw
+ $IPTABLES -A OUTPUT -d 172.24.0.3 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.1.3 -j to_fw
+ $IPTABLES -A INPUT -j to_fw
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ # branch rule set is different in members linux-1 and linux-2
+ $IPTABLES -A OUTPUT -d 172.24.0.2 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.1.2 -j to_fw
+ $IPTABLES -A OUTPUT -d 192.168.100.1 -j to_fw
+ $IPTABLES -A FORWARD -d 172.24.0.2 -j to_fw
+ $IPTABLES -A FORWARD -d 192.168.1.2 -j to_fw
+ $IPTABLES -A FORWARD -d 192.168.100.1 -j to_fw
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -N RULE_8
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -j RULE_8
+ $IPTABLES -A OUTPUT -d 172.24.0.3 -j RULE_8
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j RULE_8
+ $IPTABLES -A OUTPUT -d 192.168.1.3 -j RULE_8
+ $IPTABLES -A INPUT -j RULE_8
+ $IPTABLES -A RULE_8 -j LOG --log-level info --log-prefix "RULE 8 -- DENY "
+ $IPTABLES -A RULE_8 -j DROP
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ $IPTABLES -N RULE_10
+ $IPTABLES -A OUTPUT -m state --state NEW -j RULE_10
+ $IPTABLES -A INPUT -m state --state NEW -j RULE_10
+ $IPTABLES -A FORWARD -m state --state NEW -j RULE_10
+ $IPTABLES -A RULE_10 -j LOG --log-level info --log-prefix "RULE 10 -- DENY "
+ $IPTABLES -A RULE_10 -j DROP
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ $IPTABLES -N RULE_11
+ $IPTABLES -A OUTPUT -j RULE_11
+ $IPTABLES -A INPUT -j RULE_11
+ $IPTABLES -A FORWARD -j RULE_11
+ $IPTABLES -A RULE_11 -j LOG --log-level info --log-prefix "RULE 11 -- DENY "
+ $IPTABLES -A RULE_11 -j DROP
+
+
+
+
+
+
+
+
+ # ============== ROUTING RULES ==============
+
+ TMPDIRNAME="/tmp/.fwbuilder.tempdir.$$"
+ TMPFILENAME="$TMPDIRNAME/.fwbuilder.out"
+ (umask 077 && mkdir $TMPDIRNAME) || exit 1
+
+ #
+ # This function stops stdout redirection
+ # and sends previously saved output to terminal
+ restore_script_output()
+ {
+ exec 1>&3 2>&1
+ cat $TMPFILENAME
+ rm -rf $TMPDIRNAME
+ }
+
+ # if any routing rule fails we do our best to prevent freezing the firewall
+ route_command_error()
+ {
+ echo "Error: Routing rule $1 couldn't be activated"
+ echo "Recovering previous routing configuration..."
+ # delete current routing rules
+ $IP route show | while read route ; do $IP route del $route ; done
+ # restore old routing rules
+ (IFS="
+ "; for route in $oldRoutes; do (IFS=' '; $IP route add $route); done)
+ echo "...done"
+ restore_script_output
+ epilog_commands
+ exit 1
+ }
+
+ # redirect output to prevent ssh session from stalling
+ exec 3>&1
+ exec 1> $TMPFILENAME
+ exec 2>&1
+
+ # store previous routing configuration (sort: 'via' GW has to be
+ # inserted after device routes)
+ oldRoutes=$($IP route show | sort -k 2)
+
+ echo "Deleting routing rules previously set by user space processes..."
+ $IP route show | grep -v '\( proto kernel \)\|\(default via \)' | \
+ while read route ; do $IP route del $route ; done
+
+ echo "Activating non-ecmp routing rules..."
+ #
+ # Rule 0 (main)
+ #
+ echo "Routing rule 0 (main)"
+ #
+ #
+ #
+ $IP route add 172.24.1.0/24 via 172.24.0.100 dev eth0 \
+ || route_command_error "0 (main)"
+
+
+ restore_script_output
+ echo "...done."
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:16 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/host.fw.orig b/test/ipt/host.fw.orig
new file mode 100755
index 000000000..f28507cba
--- /dev/null
+++ b/test/ipt/host.fw.orig
@@ -0,0 +1,482 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:57:58 2011 PST by vadim
+#
+# files: * host.fw
+#
+# Compiled for iptables (any version)
+#
+# firewall protects host it is running on
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+}
+
+script_body() {
+ echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
+ echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
+
+
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -N In_RULE_0
+ $IPTABLES -A INPUT -i eth0 -s 22.22.22.22 -j In_RULE_0
+ $IPTABLES -A In_RULE_0 -j LOG --log-level debug
+ $IPTABLES -A In_RULE_0 -j DROP
+ #
+ # Rule 1 (lo)
+ #
+ echo "Rule 1 (lo)"
+ #
+ # allow everything on loopback
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (lo)
+ #
+ echo "Rule 2 (lo)"
+ #
+ # allow everything on loopback
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (lo)
+ #
+ echo "Rule 3 (lo)"
+ #
+ $IPTABLES -N Cid3BD8ECC6.0
+ $IPTABLES -A INPUT -i lo -s 22.22.22.22 -m state --state NEW -j Cid3BD8ECC6.0
+ $IPTABLES -A INPUT -i lo -s 127.0.0.1 -m state --state NEW -j Cid3BD8ECC6.0
+ $IPTABLES -N In_RULE_3
+ $IPTABLES -A Cid3BD8ECC6.0 -d 22.22.22.22 -j In_RULE_3
+ $IPTABLES -A Cid3BD8ECC6.0 -d 127.0.0.1 -j In_RULE_3
+ $IPTABLES -A In_RULE_3 -j LOG --log-level debug
+ $IPTABLES -A In_RULE_3 -j ACCEPT
+ $IPTABLES -N Cid3BD8ECC6.1
+ $IPTABLES -A OUTPUT -o lo -s 22.22.22.22 -m state --state NEW -j Cid3BD8ECC6.1
+ $IPTABLES -A OUTPUT -o lo -s 127.0.0.1 -m state --state NEW -j Cid3BD8ECC6.1
+ $IPTABLES -N Out_RULE_3
+ $IPTABLES -A Cid3BD8ECC6.1 -d 22.22.22.22 -j Out_RULE_3
+ $IPTABLES -A Cid3BD8ECC6.1 -d 127.0.0.1 -j Out_RULE_3
+ $IPTABLES -A Out_RULE_3 -j LOG --log-level debug
+ $IPTABLES -A Out_RULE_3 -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -A INPUT -s 22.22.22.22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state NEW -j ACCEPT
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ # 'catch all' rule
+ $IPTABLES -N RULE_8
+ $IPTABLES -A OUTPUT -m limit --limit 10/minute --limit-burst 50 -j RULE_8
+ $IPTABLES -A INPUT -m limit --limit 10/minute --limit-burst 50 -j RULE_8
+ $IPTABLES -A RULE_8 -j LOG --log-level debug --log-prefix "CATCH ALL RULE"
+ $IPTABLES -A RULE_8 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 0 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:57:58 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/ipcop1.fw.orig b/test/ipt/ipcop1.fw.orig
new file mode 100755
index 000000000..889ab35fc
--- /dev/null
+++ b/test/ipt/ipcop1.fw.orig
@@ -0,0 +1,233 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:00 2011 PST by vadim
+#
+# files: * ipcop1.fw
+#
+# Compiled for iptables (any version)
+#
+# Endian firewall appliance, 2 interfaces:
+# br0 is GREEN
+# eth1 is RED
+# Do not forget to change IP addresses to
+# match your firewall.
+
+
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by AddressTable object $1"
+ exit 1
+ }
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+ check_file "atbl.1" "addr-table-1.tbl"
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: et0 eth1"
+ for i in et0 eth1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+script_body() {
+ # ================ IPv4
+
+
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 10.3.14.40 --dport 80 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -d 10.3.14.40 --dport 80 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (global)
+ #
+ echo "Rule 1 (global)"
+ #
+ $IPTABLES -N RULE_1
+ $IPTABLES -A INPUT -s 192.168.1.1 -j RULE_1
+ $IPTABLES -A INPUT -s 192.168.1.2 -j RULE_1
+ $IPTABLES -A INPUT -s 192.168.1.3/30 -j RULE_1
+ $IPTABLES -A INPUT -s 192.168.1.200 -j RULE_1
+ $IPTABLES -A INPUT -s 192.168.1.201 -j RULE_1
+ $IPTABLES -A INPUT -s 192.168.2.128/25 -j RULE_1
+ $IPTABLES -A FORWARD -s 192.168.1.1 -j RULE_1
+ $IPTABLES -A FORWARD -s 192.168.1.2 -j RULE_1
+ $IPTABLES -A FORWARD -s 192.168.1.3/30 -j RULE_1
+ $IPTABLES -A FORWARD -s 192.168.1.200 -j RULE_1
+ $IPTABLES -A FORWARD -s 192.168.1.201 -j RULE_1
+ $IPTABLES -A FORWARD -s 192.168.2.128/25 -j RULE_1
+ $IPTABLES -A RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A RULE_1 -j DROP
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ $IPTABLES -N RULE_2
+ grep -Ev '^#|^;|^\s*$' addr-table-1.tbl | while read L ; do
+ set $L; at_atbl_1=$1; $IPTABLES -A INPUT -s $at_atbl_1 -j RULE_2
+ done
+ grep -Ev '^#|^;|^\s*$' addr-table-1.tbl | while read L ; do
+ set $L; at_atbl_1=$1; $IPTABLES -A FORWARD -s $at_atbl_1 -j RULE_2
+ done
+ $IPTABLES -A RULE_2 -j LOG --log-level info --log-prefix "RULE 2 -- DENY "
+ $IPTABLES -A RULE_2 -j DROP
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+case "$1" in
+ start)
+ check_tools
+ check_run_time_address_table_files
+
+ verify_interfaces
+ prolog_commands
+ script_body
+ epilog_commands
+ ;;
+
+ stop)
+ # on IPCOP "/etc/rc.firewall stop" purges all tables and chains
+ # and then calls this script with command "stop", but there is
+ # nothing left for us to do here.
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ ;;
+
+ *)
+ echo "Usage $0 {start|stop|reload}"
+ ;;
+
+esac
diff --git a/test/ipt/openais_cluster_1_linux-1.fw.orig b/test/ipt/openais_cluster_1_linux-1.fw.orig
new file mode 100755
index 000000000..59cd63f6b
--- /dev/null
+++ b/test/ipt/openais_cluster_1_linux-1.fw.orig
@@ -0,0 +1,767 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:16 2011 PST by vadim
+#
+# files: * openais_cluster_1_linux-1.fw
+#
+# Compiled for iptables (any version)
+#
+#
+
+# openais_cluster_1:Routing:1: error: Object "gw1" used as gateway in the routing rule 1 (main) is not in the same local network as interface eth1
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+ find_program $VCONFIG
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+missing_vlan() {
+ vlan=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $vlan
+ subint=$1
+ parent=$2
+ IFS=$oldIFS
+
+ vlan_id=$(echo $subint | sed -r 's/(vlan|[^.]*\.)//')
+ test "$cmd" = "add" && {
+ echo $subint | grep -q "vlan" && name_type="VLAN_PLUS_VID" || name_type="DEV_PLUS_VID"
+ test "$vlan_id" \< "1" || name_type="${name_type}_NO_PAD"
+ echo "# Adding VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $VCONFIG set_name_type $name_type
+ $FWBDEBUG $VCONFIG $cmd $parent $vlan_id
+ $FWBDEBUG $IP link set $subint up
+ }
+ test "$cmd" = "rem" && {
+ echo "# Removing VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $VCONFIG $cmd $subint
+ }
+}
+
+parse_fwb_vlans() {
+ set $1
+ vlan_parent_interface=$1
+ shift
+
+ FWB_VLANS=$(
+ for subint in $*; do
+ echo "${subint}@$vlan_parent_interface"
+ done | sort
+ )
+ echo $FWB_VLANS
+}
+
+parse_current_vlans() {
+ vlan_parent_interface=$1
+ CURRENT_VLANS=""
+ PROC_DIR="/proc/net/vlan/"
+ test -d $PROC_DIR || $MODPROBE 8021q || {
+ echo "$PROC_DIR does not exist. Vlan interfaces are not available."
+ exit 1
+ }
+
+ test -f "/proc/net/vlan/config" && {
+ CURRENT_VLANS=$(
+ cat /proc/net/vlan/config | grep -v 'Dev name' | grep $vlan_parent_interface | \
+ while read subint a vlan_id b parent; do
+ echo "${subint}@$parent"
+ done | sort
+ )
+ }
+ echo $CURRENT_VLANS
+}
+
+update_vlans_of_interface() {
+ args="$1"
+ set $1
+ vlan_parent_interface=$1
+
+ FWB_VLANS=$(parse_fwb_vlans "$args")
+ CURRENT_VLANS=$(parse_current_vlans $vlan_parent_interface)
+
+ $IP link set $vlan_parent_interface up
+ diff_intf missing_vlan "$FWB_VLANS" "$CURRENT_VLANS" add
+ diff_intf missing_vlan "$CURRENT_VLANS" "$FWB_VLANS" rem
+}
+
+add_vlans() {
+ args="$1"
+ set $1
+ vlan_parent_interface=$1
+
+ FWB_VLANS=$(parse_fwb_vlans $args)
+ CURRENT_VLANS=$(parse_current_vlans $vlan_parent_interface)
+
+ $IP link set $vlan_parent_interface up
+ diff_intf missing_vlan "$FWB_VLANS" "$CURRENT_VLANS" add
+}
+
+clear_vlans_except_known() {
+ FWB_VLANS=$*
+ CURRENT_VLANS=$(parse_current_vlans '|')
+
+ diff_intf missing_vlan "$CURRENT_VLANS" "$FWB_VLANS" rem
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo eth0.100"
+ for i in eth0 eth1 lo eth0.100 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_vlans_of_interface "eth0 eth0.100"
+ clear_vlans_except_known eth0.100@eth0
+ update_addresses_of_interface "eth0 172.24.0.2/16" "172.24.0.1/16"
+ update_addresses_of_interface "eth1 192.168.1.2/24" "192.168.1.1/24"
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth0.100 192.168.100.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 172.24.0.1
+
+
+
+ # ================ Table 'filter', rule set to_fw
+ #
+ # Rule to_fw 0 (global)
+ #
+ echo "Rule to_fw 0 (global)"
+ #
+ # hashlimit 10/sec
+ $IPTABLES -N to_fw
+ $IPTABLES -N to_fw_0
+ $IPTABLES -A to_fw -m hashlimit --hashlimit 10/second --hashlimit-name htable_rule_0 -j to_fw_0
+ $IPTABLES -A to_fw_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A to_fw_0 -j DROP
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule -4 openais (automatic)
+ #
+ echo "Rule -4 openais (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 226.94.1.1 --dport 5405 -j ACCEPT
+ #
+ # Rule -3 openais (automatic)
+ #
+ echo "Rule -3 openais (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -s 172.24.0.3 -d 226.94.1.1 --dport 5405 -j ACCEPT
+ #
+ # Rule -2 CONNTRACK (automatic)
+ #
+ echo "Rule -2 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 225.0.0.50 --dport 3781 -j ACCEPT
+ #
+ # Rule -1 CONNTRACK (automatic)
+ #
+ echo "Rule -1 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 225.0.0.50 --dport 3781 -j ACCEPT
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ # anti spoofing rule
+ $IPTABLES -N In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.100.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.100.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A In_RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A In_RULE_1 -j DROP
+ #
+ # Rule 2 (lo)
+ #
+ echo "Rule 2 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.2 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.3 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.3 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ # Firewall uses one of the machines
+ # on internal network for DNS
+ $IPTABLES -N RULE_5
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A RULE_5 -j LOG --log-level info --log-prefix "RULE 5 -- ACCEPT "
+ $IPTABLES -A RULE_5 -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -j DROP
+ $IPTABLES -A OUTPUT -d 172.24.0.2 -j DROP
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j DROP
+ $IPTABLES -A OUTPUT -d 192.168.1.2 -j DROP
+ $IPTABLES -A OUTPUT -d 192.168.100.1 -j DROP
+ $IPTABLES -A INPUT -j DROP
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -N RULE_7
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -j RULE_7
+ $IPTABLES -A OUTPUT -d 172.24.0.2 -j RULE_7
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j RULE_7
+ $IPTABLES -A OUTPUT -d 192.168.1.2 -j RULE_7
+ $IPTABLES -A OUTPUT -d 192.168.100.1 -j RULE_7
+ $IPTABLES -A INPUT -j RULE_7
+ $IPTABLES -A RULE_7 -j LOG --log-level info --log-prefix "RULE 7 -- DENY "
+ $IPTABLES -A RULE_7 -j DROP
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -N RULE_9
+ $IPTABLES -A OUTPUT -m state --state NEW -j RULE_9
+ $IPTABLES -A INPUT -m state --state NEW -j RULE_9
+ $IPTABLES -A FORWARD -m state --state NEW -j RULE_9
+ $IPTABLES -A RULE_9 -j LOG --log-level info --log-prefix "RULE 9 -- DENY "
+ $IPTABLES -A RULE_9 -j DROP
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ $IPTABLES -N RULE_10
+ $IPTABLES -A OUTPUT -j RULE_10
+ $IPTABLES -A INPUT -j RULE_10
+ $IPTABLES -A FORWARD -j RULE_10
+ $IPTABLES -A RULE_10 -j LOG --log-level info --log-prefix "RULE 10 -- DENY "
+ $IPTABLES -A RULE_10 -j DROP
+
+
+
+
+
+
+
+
+ # ============== ROUTING RULES ==============
+
+ TMPDIRNAME="/tmp/.fwbuilder.tempdir.$$"
+ TMPFILENAME="$TMPDIRNAME/.fwbuilder.out"
+ (umask 077 && mkdir $TMPDIRNAME) || exit 1
+
+ #
+ # This function stops stdout redirection
+ # and sends previously saved output to terminal
+ restore_script_output()
+ {
+ exec 1>&3 2>&1
+ cat $TMPFILENAME
+ rm -rf $TMPDIRNAME
+ }
+
+ # if any routing rule fails we do our best to prevent freezing the firewall
+ route_command_error()
+ {
+ echo "Error: Routing rule $1 couldn't be activated"
+ echo "Recovering previous routing configuration..."
+ # delete current routing rules
+ $IP route show | while read route ; do $IP route del $route ; done
+ # restore old routing rules
+ (IFS="
+ "; for route in $oldRoutes; do (IFS=' '; $IP route add $route); done)
+ echo "...done"
+ restore_script_output
+ epilog_commands
+ exit 1
+ }
+
+ # redirect output to prevent ssh session from stalling
+ exec 3>&1
+ exec 1> $TMPFILENAME
+ exec 2>&1
+
+ # store previous routing configuration (sort: 'via' GW has to be
+ # inserted after device routes)
+ oldRoutes=$($IP route show | sort -k 2)
+
+ echo "Deleting routing rules previously set by user space processes..."
+ $IP route show | grep -v '\( proto kernel \)\|\(default via \)' | \
+ while read route ; do $IP route del $route ; done
+
+ echo "Activating non-ecmp routing rules..."
+ #
+ # Rule 0 (main)
+ #
+ echo "Routing rule 0 (main)"
+ #
+ # Some sub rules belonging to an ECMP (Equal Cost Multi Path) rule were placed in the ECMP section below.
+ #
+ # Rule 1 (main)
+ #
+ echo "Routing rule 1 (main)"
+ #
+ # Some sub rules belonging to an ECMP (Equal Cost Multi Path) rule were placed in the ECMP section below.
+
+ #
+ # ============== EQUAL COST MULTI PATH ============
+ #
+ echo "Activating ecmp routing rules..."
+ #
+ # Multipath Rule derived from the following routing rules:
+ #
+ # Rule 0 (main)
+ #
+ # Rule 1 (main)
+ # interface vrrp1 belongs to a different firewall (cluster)
+ #
+ $IP route add 172.24.1.0/24 \
+ nexthop via 172.24.0.100 dev eth0 \
+ nexthop via 172.24.0.100 dev eth1 \
+ || route_command_error "1"
+
+ restore_script_output
+ echo "...done."
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:16 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/openais_cluster_1_linux-2.fw.orig b/test/ipt/openais_cluster_1_linux-2.fw.orig
new file mode 100755
index 000000000..cea3d034f
--- /dev/null
+++ b/test/ipt/openais_cluster_1_linux-2.fw.orig
@@ -0,0 +1,671 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:16 2011 PST by vadim
+#
+# files: * openais_cluster_1_linux-2.fw
+#
+# Compiled for iptables (any version)
+#
+
+# openais_cluster_1:Routing:1: error: Object "gw1" used as gateway in the routing rule 1 (main) is not in the same local network as interface eth1
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo"
+ for i in eth0 eth1 lo ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 172.24.0.3/16" "172.24.0.1/16"
+ update_addresses_of_interface "eth1 192.168.1.3/24" "192.168.1.1/24"
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 172.24.0.1
+
+
+
+ # ================ Table 'filter', rule set to_fw
+ #
+ # Rule to_fw 0 (global)
+ #
+ echo "Rule to_fw 0 (global)"
+ #
+ # hashlimit 20/sec
+ $IPTABLES -N to_fw
+ $IPTABLES -N to_fw_0
+ $IPTABLES -A to_fw -m hashlimit --hashlimit 20/second --hashlimit-name htable_rule_0 -j to_fw_0
+ $IPTABLES -A to_fw_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A to_fw_0 -j DROP
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule -4 openais (automatic)
+ #
+ echo "Rule -4 openais (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 226.94.1.1 --dport 5405 -j ACCEPT
+ #
+ # Rule -3 openais (automatic)
+ #
+ echo "Rule -3 openais (automatic)"
+ #
+ $IPTABLES -N C.0
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 226.94.1.1 --dport 5405 -j C.0
+ $IPTABLES -A C.0 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A C.0 -s 192.168.100.1 -j ACCEPT
+ #
+ # Rule -2 CONNTRACK (automatic)
+ #
+ echo "Rule -2 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 225.0.0.50 --dport 3781 -j ACCEPT
+ #
+ # Rule -1 CONNTRACK (automatic)
+ #
+ echo "Rule -1 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 225.0.0.50 --dport 3781 -j ACCEPT
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ # anti spoofing rule
+ $IPTABLES -N In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A In_RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A In_RULE_1 -j DROP
+ #
+ # Rule 2 (lo)
+ #
+ echo "Rule 2 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.3 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.2 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.2 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ # Firewall uses one of the machines
+ # on internal network for DNS
+ $IPTABLES -N RULE_5
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A RULE_5 -j LOG --log-level info --log-prefix "RULE 5 -- ACCEPT "
+ $IPTABLES -A RULE_5 -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -j DROP
+ $IPTABLES -A OUTPUT -d 172.24.0.3 -j DROP
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j DROP
+ $IPTABLES -A OUTPUT -d 192.168.1.3 -j DROP
+ $IPTABLES -A INPUT -j DROP
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -N RULE_7
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -j RULE_7
+ $IPTABLES -A OUTPUT -d 172.24.0.3 -j RULE_7
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j RULE_7
+ $IPTABLES -A OUTPUT -d 192.168.1.3 -j RULE_7
+ $IPTABLES -A INPUT -j RULE_7
+ $IPTABLES -A RULE_7 -j LOG --log-level info --log-prefix "RULE 7 -- DENY "
+ $IPTABLES -A RULE_7 -j DROP
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -N RULE_9
+ $IPTABLES -A OUTPUT -m state --state NEW -j RULE_9
+ $IPTABLES -A INPUT -m state --state NEW -j RULE_9
+ $IPTABLES -A FORWARD -m state --state NEW -j RULE_9
+ $IPTABLES -A RULE_9 -j LOG --log-level info --log-prefix "RULE 9 -- DENY "
+ $IPTABLES -A RULE_9 -j DROP
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ $IPTABLES -N RULE_10
+ $IPTABLES -A OUTPUT -j RULE_10
+ $IPTABLES -A INPUT -j RULE_10
+ $IPTABLES -A FORWARD -j RULE_10
+ $IPTABLES -A RULE_10 -j LOG --log-level info --log-prefix "RULE 10 -- DENY "
+ $IPTABLES -A RULE_10 -j DROP
+
+
+
+
+
+
+
+
+ # ============== ROUTING RULES ==============
+
+ TMPDIRNAME="/tmp/.fwbuilder.tempdir.$$"
+ TMPFILENAME="$TMPDIRNAME/.fwbuilder.out"
+ (umask 077 && mkdir $TMPDIRNAME) || exit 1
+
+ #
+ # This function stops stdout redirection
+ # and sends previously saved output to terminal
+ restore_script_output()
+ {
+ exec 1>&3 2>&1
+ cat $TMPFILENAME
+ rm -rf $TMPDIRNAME
+ }
+
+ # if any routing rule fails we do our best to prevent freezing the firewall
+ route_command_error()
+ {
+ echo "Error: Routing rule $1 couldn't be activated"
+ echo "Recovering previous routing configuration..."
+ # delete current routing rules
+ $IP route show | while read route ; do $IP route del $route ; done
+ # restore old routing rules
+ (IFS="
+ "; for route in $oldRoutes; do (IFS=' '; $IP route add $route); done)
+ echo "...done"
+ restore_script_output
+ epilog_commands
+ exit 1
+ }
+
+ # redirect output to prevent ssh session from stalling
+ exec 3>&1
+ exec 1> $TMPFILENAME
+ exec 2>&1
+
+ # store previous routing configuration (sort: 'via' GW has to be
+ # inserted after device routes)
+ oldRoutes=$($IP route show | sort -k 2)
+
+ echo "Deleting routing rules previously set by user space processes..."
+ $IP route show | grep -v '\( proto kernel \)\|\(default via \)' | \
+ while read route ; do $IP route del $route ; done
+
+ echo "Activating non-ecmp routing rules..."
+ #
+ # Rule 0 (main)
+ #
+ echo "Routing rule 0 (main)"
+ #
+ # Some sub rules belonging to an ECMP (Equal Cost Multi Path) rule were placed in the ECMP section below.
+ #
+ # Rule 1 (main)
+ #
+ echo "Routing rule 1 (main)"
+ #
+ # Some sub rules belonging to an ECMP (Equal Cost Multi Path) rule were placed in the ECMP section below.
+
+ #
+ # ============== EQUAL COST MULTI PATH ============
+ #
+ echo "Activating ecmp routing rules..."
+ #
+ # Multipath Rule derived from the following routing rules:
+ #
+ # Rule 0 (main)
+ #
+ # Rule 1 (main)
+ # interface vrrp1 belongs to a different firewall (cluster)
+ #
+ $IP route add 172.24.1.0/24 \
+ nexthop via 172.24.0.100 dev eth0 \
+ nexthop via 172.24.0.100 dev eth1 \
+ || route_command_error "1"
+
+ restore_script_output
+ echo "...done."
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:16 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/rh90.fw.orig b/test/ipt/rh90.fw.orig
new file mode 100755
index 000000000..7f6811e0d
--- /dev/null
+++ b/test/ipt/rh90.fw.orig
@@ -0,0 +1,481 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:02 2011 PST by vadim
+#
+# files: * rh90.fw
+#
+# Compiled for iptables (any version)
+#
+# This is an example of a firewall protecting a host ( a server or a workstation). Only SSH access to the host is permitted. Host has dynamic address.
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 lo"
+ for i in eth0 lo ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 10.3.14.58/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ # anti spoofing rule
+ $IPTABLES -N In_RULE_0
+ $IPTABLES -A INPUT -i eth0 -s 10.3.14.58 -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth0 -s 10.3.14.58 -j In_RULE_0
+ $IPTABLES -A In_RULE_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A In_RULE_0 -j DROP
+ #
+ # Rule 1 (lo)
+ #
+ echo "Rule 1 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ # SSH Access to the host; useful ICMP
+ # types; ping request
+ $IPTABLES -N Cid41528C32.0
+ $IPTABLES -A OUTPUT -d 10.3.14.58 -m state --state NEW -j Cid41528C32.0
+ $IPTABLES -A Cid41528C32.0 -p icmp -m icmp --icmp-type 11/0 -j ACCEPT
+ $IPTABLES -A Cid41528C32.0 -p icmp -m icmp --icmp-type 11/1 -j ACCEPT
+ $IPTABLES -A Cid41528C32.0 -p icmp -m icmp --icmp-type 0/0 -j ACCEPT
+ $IPTABLES -A Cid41528C32.0 -p icmp -m icmp --icmp-type 3 -j ACCEPT
+ $IPTABLES -A Cid41528C32.0 -p icmp -m icmp --icmp-type 8/0 -j ACCEPT
+ $IPTABLES -A Cid41528C32.0 -p tcp -m tcp --dport 22 -j ACCEPT
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type 11/0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type 11/1 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type 0/0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type 3 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -A INPUT -s 10.3.14.58 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -N RULE_4
+ $IPTABLES -A OUTPUT -j RULE_4
+ $IPTABLES -A INPUT -j RULE_4
+ $IPTABLES -A FORWARD -j RULE_4
+ $IPTABLES -A RULE_4 -j LOG --log-level info --log-prefix "RULE 4 -- DENY "
+ $IPTABLES -A RULE_4 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:02 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/secuwall_cluster_1_secuwall-1.fw.orig b/test/ipt/secuwall_cluster_1_secuwall-1.fw.orig
new file mode 100755
index 000000000..ea1c2c904
--- /dev/null
+++ b/test/ipt/secuwall_cluster_1_secuwall-1.fw.orig
@@ -0,0 +1,464 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:17 2011 PST by vadim
+#
+# files: * secuwall_cluster_1_secuwall-1.fw
+#
+# Compiled for iptables (any version)
+#
+# This firewall has two interfaces. Eth0 faces outside and has a dynamic address; eth1 faces inside.
+# Policy includes basic rules to permit unrestricted outbound access and anti-spoofing rules. Access to the firewall is permitted only from internal network and only using SSH. The firewall uses one of the machines on internal network for DNS. Internal network is configured with address 192.168.1.0/255.255.255.0
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/bin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ echo "Modules are loaded only at startup!"
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo vrrp0 vrrp1"
+ for i in eth0 eth1 lo vrrp0 vrrp1 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ for runstop in keepalived conntrackd network ; do
+ /etc/init.d/${runstop} stop
+ done
+
+ /sbin/ifclear all
+
+ for runstart in management network keepalived conntrackd ; do
+ /etc/init.d/${runstart} start
+ done
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+
+
+
+
+ # client DNS for the firewall
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule -6 VRRP (automatic)
+ #
+ echo "Rule -6 VRRP (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth1 -p vrrp -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -5 VRRP (automatic)
+ #
+ echo "Rule -5 VRRP (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p vrrp -s 192.168.1.3 -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -4 VRRP (automatic)
+ #
+ echo "Rule -4 VRRP (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p vrrp -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -3 VRRP (automatic)
+ #
+ echo "Rule -3 VRRP (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p vrrp -s 172.24.0.3 -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -2 CONNTRACK (automatic)
+ #
+ echo "Rule -2 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 225.0.0.50 --dport 3780 -j ACCEPT
+ #
+ # Rule -1 CONNTRACK (automatic)
+ #
+ echo "Rule -1 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 225.0.0.50 --dport 3780 -j ACCEPT
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:17 2011 by vadim"
+ log "Database was cluster-tests.fwb"
+ check_tools
+ check_run_time_address_table_files
+
+ prolog_commands
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ *)
+ echo "Usage $0 {start|stop|status|block|reload|interfaces|test_interfaces}"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/server-cluster-1_server-1.fw.orig b/test/ipt/server-cluster-1_server-1.fw.orig
new file mode 100755
index 000000000..0e9ddd354
--- /dev/null
+++ b/test/ipt/server-cluster-1_server-1.fw.orig
@@ -0,0 +1,458 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:17 2011 PST by vadim
+#
+# files: * server-cluster-1_server-1.fw
+#
+# Compiled for iptables (any version)
+#
+# fw is part of any is OFF
+# ip forwarding is OFF
+
+# server-cluster-1:Policy:0: error: Rule '0 (global)' shadows rule '1 (global)' below it
+# server-cluster-1:Policy:0: error: Rule '0 (global)' shadows rule '1 (global)' below it
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: lo eth0"
+ for i in lo eth0 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth0 192.168.1.1/24" "192.168.1.100/24"
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule -4 heartbeat (automatic)
+ #
+ echo "Rule -4 heartbeat (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o lo -p udp -m udp -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -3 heartbeat (automatic)
+ #
+ echo "Rule -3 heartbeat (automatic)"
+ #
+ $IPTABLES -A INPUT -i lo -p udp -m udp -s 127.0.0.1 -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -2 heartbeat (automatic)
+ #
+ echo "Rule -2 heartbeat (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -1 heartbeat (automatic)
+ #
+ echo "Rule -1 heartbeat (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -s 192.168.1.2 -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ # test for ticket #1338
+ $IPTABLES -A INPUT -s 192.168.1.1 -j DROP
+ $IPTABLES -A INPUT -s 192.168.1.100 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 0 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:17 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/server-cluster-1_server-2.fw.orig b/test/ipt/server-cluster-1_server-2.fw.orig
new file mode 100755
index 000000000..ece53b0e4
--- /dev/null
+++ b/test/ipt/server-cluster-1_server-2.fw.orig
@@ -0,0 +1,457 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:17 2011 PST by vadim
+#
+# files: * server-cluster-1_server-2.fw
+#
+# Compiled for iptables (any version)
+#
+# fw is part of any is OFF
+# ip forwarding is OFF
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: lo eth0"
+ for i in lo eth0 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth0 192.168.1.2/24" "192.168.1.100/24"
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule -4 heartbeat (automatic)
+ #
+ echo "Rule -4 heartbeat (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o lo -p udp -m udp -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -3 heartbeat (automatic)
+ #
+ echo "Rule -3 heartbeat (automatic)"
+ #
+ $IPTABLES -A INPUT -i lo -p udp -m udp -s 127.0.0.1 -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -2 heartbeat (automatic)
+ #
+ echo "Rule -2 heartbeat (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule -1 heartbeat (automatic)
+ #
+ echo "Rule -1 heartbeat (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -s 192.168.1.1 -d 224.0.10.100 --dport 694 -j ACCEPT
+ #
+ # Rule 0 (global)
+ #
+ echo "Rule 0 (global)"
+ #
+ # test for ticket #1338
+ $IPTABLES -A INPUT -s 192.168.1.2 -j DROP
+ $IPTABLES -A INPUT -s 192.168.1.100 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 0 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:17 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/test-shadowing-1.fw.orig b/test/ipt/test-shadowing-1.fw.orig
new file mode 100755
index 000000000..f6c149bfd
--- /dev/null
+++ b/test/ipt/test-shadowing-1.fw.orig
@@ -0,0 +1,521 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:07 2011 PST by vadim
+#
+# files: * test-shadowing-1.fw
+#
+# Compiled for iptables (any version)
+#
+# testing shadowing detection
+# compiler runs with -xt flag
+# firewall is assumed to be part of any
+
+# test-shadowing-1:Policy:0: error: Rule '0 (eth0)' shadows rule '1 (eth0)' below it
+# test-shadowing-1:Policy:2: error: Rule '2 (global)' shadows rule '3 (global)' below it
+# test-shadowing-1:Policy:2: error: Rule '2 (global)' shadows rule '3 (global)' below it
+# test-shadowing-1:Policy:2: error: Rule '2 (global)' shadows rule '3 (global)' below it
+# test-shadowing-1:Policy:4: error: Rule '4 (global)' shadows rule '5 (global)' below it
+# test-shadowing-1:Policy:6: error: Rule '6 (global)' shadows rule '7 (global)' below it
+# test-shadowing-1:Policy:8: error: Rule '8 (global)' shadows rule '9 (global)' below it
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 eth2"
+ for i in eth0 eth1 eth2 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 22.22.22.22/24" ""
+ update_addresses_of_interface "eth1 192.168.1.1/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ # shades rule below
+ $IPTABLES -A OUTPUT -o eth0 -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -o eth0 -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ $IPTABLES -N Out_RULE_1
+ $IPTABLES -A FORWARD -o eth0 -s 192.168.1.10 -j Out_RULE_1
+ $IPTABLES -A Out_RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A Out_RULE_1 -j DROP
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ # firewall is part
+ # of any for this rule
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -N Cid4514B3E62143.0
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 80 -j Cid4514B3E62143.0
+ $IPTABLES -A Cid4514B3E62143.0 -s 22.22.22.22 -j DROP
+ $IPTABLES -A Cid4514B3E62143.0 -s 192.168.1.1 -j DROP
+ $IPTABLES -A Cid4514B3E62143.0 -s 192.168.2.1 -j DROP
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 80 -j DROP
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 21 -j DROP
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 21 -j DROP
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 --dport 21 -j DROP
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -A INPUT -p udp -m udp -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p udp -m udp -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p udp -m udp -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -A INPUT -p udp -m udp -s 192.168.1.0/24 --dport 123 -j DROP
+ $IPTABLES -A OUTPUT -p udp -m udp -s 192.168.1.0/24 --dport 123 -j DROP
+ $IPTABLES -A FORWARD -p udp -m udp -s 192.168.1.0/24 --dport 123 -j DROP
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ # this rule should shadow rule below it because
+ # it uses IPService object with protocol 0
+ $IPTABLES -A INPUT -p all -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p all -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p all -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -A INPUT -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j DROP
+ $IPTABLES -A OUTPUT -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j DROP
+ $IPTABLES -A FORWARD -p icmp -m icmp -s 192.168.1.0/24 --icmp-type 0/0 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:07 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/test-shadowing-2.fw.orig b/test/ipt/test-shadowing-2.fw.orig
new file mode 100755
index 000000000..e53febbad
--- /dev/null
+++ b/test/ipt/test-shadowing-2.fw.orig
@@ -0,0 +1,483 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:09 2011 PST by vadim
+#
+# files: * test-shadowing-2.fw
+#
+# Compiled for iptables (any version)
+#
+# testing shadowing detection
+# compiler runs with -xt flag
+# firewall is NOT assumed to be part of any
+
+# test-shadowing-2:Policy:0: error: Rule '0 (eth0)' shadows rule '1 (eth0)' below it
+# test-shadowing-2:Policy:2: error: Rule '2 (global)' shadows rule '3 (global)' below it
+# test-shadowing-2:Policy:2: error: Rule '2 (global)' shadows rule '3 (global)' below it
+# test-shadowing-2:Policy:2: error: Rule '2 (global)' shadows rule '3 (global)' below it
+# test-shadowing-2:Policy:4: error: Rule '4 (global)' shadows rule '5 (global)' below it
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 eth2"
+ for i in eth0 eth1 eth2 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 22.22.22.22/24" ""
+ update_addresses_of_interface "eth1 192.168.1.1/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ # shades rule below
+ $IPTABLES -A FORWARD -o eth0 -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ $IPTABLES -A FORWARD -o eth0 -s 192.168.1.10 -j DROP
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ # firewall is part
+ # of any for this rule
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 80 -j DROP
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ # this rule should shadow rule below it because
+ # it uses IPService object with protocol 0
+ $IPTABLES -A FORWARD -p all -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 --dport 6667 -j DROP
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ $IPTABLES -N RULE_6
+ $IPTABLES -A FORWARD -j RULE_6
+ $IPTABLES -A RULE_6 -j LOG --log-level info --log-prefix "RULE 6 -- DENY "
+ $IPTABLES -A RULE_6 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:09 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/test-shadowing-3.fw.orig b/test/ipt/test-shadowing-3.fw.orig
new file mode 100755
index 000000000..3aa8a665a
--- /dev/null
+++ b/test/ipt/test-shadowing-3.fw.orig
@@ -0,0 +1,534 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:13 2011 PST by vadim
+#
+# files: * test-shadowing-3.fw
+#
+# Compiled for iptables (any version)
+#
+# testing shadowing detection
+# compiler runs with -xt flag
+# testing shadowing when rules have non-default options
+
+# test-shadowing-3:Policy_3:0: error: Rule 'Policy_3 0 (eth0)' shadows rule 'Policy_3 1 (eth0)' below it
+
+# test-shadowing-3:Policy_5:0: error: Rule 'Policy_5 0 (eth0)' shadows rule 'Policy_5 1 (eth0)' below it
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 eth2"
+ for i in eth0 eth1 eth2 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 22.22.22.22/24" ""
+ update_addresses_of_interface "eth1 192.168.1.1/24" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy_1
+ #
+ # Rule Policy_1 0 (eth0)
+ #
+ echo "Rule Policy_1 0 (eth0)"
+ #
+ # connlimit
+ $IPTABLES -N Policy_1
+ $IPTABLES -A Policy_1 -o eth0 -s 192.168.1.0/24 -m state --state NEW -m connlimit --connlimit-above 10 -j ACCEPT
+ #
+ # Rule Policy_1 1 (eth0)
+ #
+ echo "Rule Policy_1 1 (eth0)"
+ #
+ $IPTABLES -A Policy_1 -o eth0 -s 192.168.1.0/24 -j DROP
+ # ================ Table 'filter', rule set Policy_2
+ #
+ # Rule Policy_2 0 (eth0)
+ #
+ echo "Rule Policy_2 0 (eth0)"
+ #
+ # hashlimit
+ $IPTABLES -N Policy_2
+ $IPTABLES -A Policy_2 -o eth0 -s 192.168.1.0/24 -m state --state NEW -m hashlimit --hashlimit 10/second --hashlimit-name test -j ACCEPT
+ #
+ # Rule Policy_2 1 (eth0)
+ #
+ echo "Rule Policy_2 1 (eth0)"
+ #
+ $IPTABLES -A Policy_2 -o eth0 -s 192.168.1.0/24 -j DROP
+ # ================ Table 'filter', rule set Policy_3
+ #
+ # Rule Policy_3 0 (eth0)
+ #
+ echo "Rule Policy_3 0 (eth0)"
+ #
+ # 50/sec
+ $IPTABLES -N Policy_3
+ $IPTABLES -A Policy_3 -o eth0 -s 192.168.1.0/24 -m state --state NEW -m hashlimit --hashlimit 50/second --hashlimit-mode srcip --hashlimit-name test -j ACCEPT
+ #
+ # Rule Policy_3 1 (eth0)
+ #
+ echo "Rule Policy_3 1 (eth0)"
+ #
+ # 50/sec
+ $IPTABLES -A Policy_3 -o eth0 -s 192.168.1.0/24 -m state --state NEW -m hashlimit --hashlimit 50/second --hashlimit-mode srcip --hashlimit-name test -j ACCEPT
+ # ================ Table 'filter', rule set Policy_4
+ #
+ # Rule Policy_4 0 (eth0)
+ #
+ echo "Rule Policy_4 0 (eth0)"
+ #
+ # 30/sec
+ $IPTABLES -N Policy_4
+ $IPTABLES -A Policy_4 -o eth0 -s 192.168.1.0/24 -m state --state NEW -m hashlimit --hashlimit 30/second --hashlimit-mode srcip --hashlimit-name test -j ACCEPT
+ #
+ # Rule Policy_4 1 (eth0)
+ #
+ echo "Rule Policy_4 1 (eth0)"
+ #
+ # 50/sec
+ $IPTABLES -A Policy_4 -o eth0 -s 192.168.1.0/24 -m state --state NEW -m hashlimit --hashlimit 50/second --hashlimit-mode srcip --hashlimit-name test -j ACCEPT
+ #
+ # Rule Policy_4 2 (eth0)
+ #
+ echo "Rule Policy_4 2 (eth0)"
+ #
+ # htable_rule_4
+ $IPTABLES -A Policy_4 -o eth0 -s 192.168.1.0/24 -m state --state NEW -m hashlimit --hashlimit 10/second --hashlimit-mode srcip --hashlimit-name htable_rule_4 -j ACCEPT
+ #
+ # Rule Policy_4 3 (eth0)
+ #
+ echo "Rule Policy_4 3 (eth0)"
+ #
+ # htable_rule_5
+ $IPTABLES -A Policy_4 -o eth0 -s 192.168.1.0/24 -m state --state NEW -m hashlimit --hashlimit 10/second --hashlimit-mode srcip --hashlimit-name htable_rule_5 -j ACCEPT
+ # ================ Table 'filter', rule set Policy_5
+ #
+ # Rule Policy_5 0 (eth0)
+ #
+ echo "Rule Policy_5 0 (eth0)"
+ #
+ # 50/sec
+ $IPTABLES -N Policy_5
+ $IPTABLES -A Policy_5 -o eth0 -s 192.168.1.0/24 -m state --state NEW -m hashlimit --hashlimit 50/second --hashlimit-mode srcip --hashlimit-name test -j ACCEPT
+ #
+ # Rule Policy_5 1 (eth0)
+ #
+ echo "Rule Policy_5 1 (eth0)"
+ #
+ # 30/sec
+ $IPTABLES -A Policy_5 -o eth0 -s 192.168.1.0/24 -m state --state NEW -m hashlimit --hashlimit 30/second --hashlimit-mode srcip --hashlimit-name test -j ACCEPT
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ # limit
+ $IPTABLES -A FORWARD -o eth0 -s 192.168.1.0/24 -m state --state NEW -m limit --limit 10/second -j ACCEPT
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ $IPTABLES -A FORWARD -o eth0 -s 192.168.1.0/24 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:13 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules " "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/test_fw.fw.orig b/test/ipt/test_fw.fw.orig
new file mode 100755
index 000000000..5a3454405
--- /dev/null
+++ b/test/ipt/test_fw.fw.orig
@@ -0,0 +1,630 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:05 2011 PST by vadim
+#
+# files: * test_fw.fw
+#
+# Compiled for iptables (any version)
+#
+# This firewall has three interfaces. Eth0 faces outside and has a static routable address; eth1 faces inside; eth2 is connected to DMZ subnet.
+# Policy includes basic rules to permit unrestricted outbound access and anti-spoofing rules. Access to the firewall is permitted only from internal network and only using SSH. The firewall uses one of the machines on internal network for DNS. Internal network is configured with address 192.168.1.0/255.255.255.0, DMZ is 192.168.2.0/255.255.255.0. Since DMZ used private IP address, it needs NAT. There is a mail relay host located on DMZ (object 'server on dmz'). Policy rules permit SMTP connections to it from the Internet and allow this server to connect to a host on internal network 'internal server'. All other access from DMZ to internal net is denied. To provide access to the mail relay its private address is mapped to firewall's outside interface address by NAT rule #1.
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo eth2"
+ for i in eth0 eth1 lo eth2 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 192.0.2.1/24" ""
+ update_addresses_of_interface "eth1 fe80::20c:29ff:fed2:cca1/64 192.168.1.1/24" ""
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth2 192.168.2.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ # no need to translate
+ # between DMZ and
+ # internal net
+ $IPTABLES -t nat -A POSTROUTING -s 192.168.2.0/24 -d 192.168.1.0/24 -j ACCEPT
+ $IPTABLES -t nat -A PREROUTING -s 192.168.2.0/24 -d 192.168.1.0/24 -j ACCEPT
+ #
+ # Rule 1 (NAT)
+ #
+ echo "Rule 1 (NAT)"
+ #
+ # Translate source address
+ # for outgoing connections
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 192.0.2.1
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.2.0/24 -j SNAT --to-source 192.0.2.1
+ #
+ # Rule 2 (NAT)
+ #
+ echo "Rule 2 (NAT)"
+ #
+ $IPTABLES -t nat -A PREROUTING -d 192.0.2.1 -j DNAT --to-destination 192.168.2.10
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ # anti spoofing rule
+ $IPTABLES -N In_RULE_0
+ $IPTABLES -A INPUT -i eth0 -s 192.0.2.1 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A INPUT -i eth0 -s 192.168.2.1 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A INPUT -i eth0 -s 192.168.2.0/24 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth0 -s 192.0.2.1 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.2.1 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.2.0/24 -m state --state NEW -j In_RULE_0
+ $IPTABLES -A In_RULE_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A In_RULE_0 -j DROP
+ #
+ # Rule 1 (lo)
+ #
+ echo "Rule 1 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 2 (global)
+ #
+ echo "Rule 2 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ # Firewall uses one of the machines
+ # on internal network for DNS
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.10 --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.10 --dport 53 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ # All other attempts to connect to
+ # the firewall are denied and logged
+ $IPTABLES -N RULE_4
+ $IPTABLES -A OUTPUT -d 192.0.2.1 -m state --state NEW -j RULE_4
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -m state --state NEW -j RULE_4
+ $IPTABLES -A OUTPUT -d 192.168.2.1 -m state --state NEW -j RULE_4
+ $IPTABLES -A INPUT -m state --state NEW -j RULE_4
+ $IPTABLES -A RULE_4 -j LOG --log-level info --log-prefix "RULE 4 -- DENY "
+ $IPTABLES -A RULE_4 -j DROP
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ # Quickly reject attempts to connect
+ # to ident server to avoid SMTP delays
+ $IPTABLES -A OUTPUT -p tcp -m tcp --dport 113 -j REJECT
+ $IPTABLES -A INPUT -p tcp -m tcp --dport 113 -j REJECT
+ $IPTABLES -A FORWARD -p tcp -m tcp --dport 113 -j REJECT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ # Mail relay on DMZ can accept
+ # connections from hosts on the
+ # Internet
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.2.10 --dport 25 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -d 192.168.2.10 --dport 25 -m state --state NEW -j ACCEPT
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ # this rule permits a mail relay
+ # located on DMZ to connect
+ # to internal mail server
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.2.10 -d 192.168.1.10 --dport 25 -m state --state NEW -j ACCEPT
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ # Mail relay needs DNS and can
+ # connect to mail servers on the
+ # Internet
+ $IPTABLES -A INPUT -p tcp -m tcp -m multiport -s 192.168.2.10 -d ! 192.168.1.0/24 --dports 53,25 -m state --state NEW -j ACCEPT
+ $IPTABLES -A INPUT -p udp -m udp -s 192.168.2.10 -d ! 192.168.1.0/24 --dport 53 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -m multiport -s 192.168.2.10 -d ! 192.168.1.0/24 --dports 53,25 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p udp -m udp -s 192.168.2.10 -d ! 192.168.1.0/24 --dport 53 -m state --state NEW -j ACCEPT
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ # All other access from DMZ to
+ # internal net is denied
+ $IPTABLES -N RULE_9
+ $IPTABLES -A OUTPUT -s 192.168.2.0/24 -d 192.168.1.0/24 -j RULE_9
+ $IPTABLES -A INPUT -s 192.168.2.0/24 -d 192.168.1.0/24 -j RULE_9
+ $IPTABLES -A FORWARD -s 192.168.2.0/24 -d 192.168.1.0/24 -j RULE_9
+ $IPTABLES -A RULE_9 -j LOG --log-level info --log-prefix "RULE 9 -- DENY "
+ $IPTABLES -A RULE_9 -j DROP
+ #
+ # Rule 10 (global)
+ #
+ echo "Rule 10 (global)"
+ #
+ # This permits access from internal net
+ # to the Internet and DMZ
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 11 (global)
+ #
+ echo "Rule 11 (global)"
+ #
+ $IPTABLES -N RULE_11
+ $IPTABLES -A OUTPUT -j RULE_11
+ $IPTABLES -A INPUT -j RULE_11
+ $IPTABLES -A FORWARD -j RULE_11
+ $IPTABLES -A RULE_11 -j LOG --log-level info --log-prefix "RULE 11 -- DENY "
+ $IPTABLES -A RULE_11 -j DROP
+
+
+ # ================ IPv6
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+
+
+
+
+ # ================ Table 'filter', rule set Policy_OSPF
+ #
+ # Rule Policy_OSPF 0 (eth1)
+ #
+ echo "Rule Policy_OSPF 0 (eth1)"
+ #
+ $IP6TABLES -N Policy_OSPF
+ $IP6TABLES -A Policy_OSPF -i eth1 -s fe80::/10 -d ff00::/8 -j ACCEPT
+ $IP6TABLES -A Policy_OSPF -i eth1 -s fe80::/10 -d fe80::/10 -j ACCEPT
+ $IP6TABLES -A Policy_OSPF -o eth1 -s fe80::/10 -d ff00::/8 -j ACCEPT
+ $IP6TABLES -A Policy_OSPF -o eth1 -s fe80::/10 -d fe80::/10 -j ACCEPT
+ # ================ Table 'filter', rule set Policy_v6
+ #
+ # Rule Policy_v6 0 (eth1)
+ #
+ echo "Rule Policy_v6 0 (eth1)"
+ #
+ $IP6TABLES -A OUTPUT -o eth1 -s fe80::/10 -d ff00::/8 -j ACCEPT
+ #
+ # Rule Policy_v6 1 (global)
+ #
+ echo "Rule Policy_v6 1 (global)"
+ #
+ $IP6TABLES -A OUTPUT -p 89 -j Policy_OSPF
+ $IP6TABLES -A INPUT -p 89 -j Policy_OSPF
+ $IP6TABLES -A FORWARD -p 89 -j Policy_OSPF
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+ reset_iptables_v6
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+ $IP6TABLES -P OUTPUT ACCEPT
+ $IP6TABLES -P INPUT ACCEPT
+ $IP6TABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:05 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat ipv6"
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/vrrp_cluster_1_linux-1.fw.orig b/test/ipt/vrrp_cluster_1_linux-1.fw.orig
new file mode 100755
index 000000000..3411fcf95
--- /dev/null
+++ b/test/ipt/vrrp_cluster_1_linux-1.fw.orig
@@ -0,0 +1,770 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:18 2011 PST by vadim
+#
+# files: * vrrp_cluster_1_linux-1.fw
+#
+# Compiled for iptables (any version)
+#
+#
+
+# vrrp_cluster_1:Routing:1: error: Object "gw1" used as gateway in the routing rule 1 (main) is not in the same local network as interface eth1
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+ find_program $VCONFIG
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+missing_vlan() {
+ vlan=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $vlan
+ subint=$1
+ parent=$2
+ IFS=$oldIFS
+
+ vlan_id=$(echo $subint | sed -r 's/(vlan|[^.]*\.)//')
+ test "$cmd" = "add" && {
+ echo $subint | grep -q "vlan" && name_type="VLAN_PLUS_VID" || name_type="DEV_PLUS_VID"
+ test "$vlan_id" \< "1" || name_type="${name_type}_NO_PAD"
+ echo "# Adding VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $VCONFIG set_name_type $name_type
+ $FWBDEBUG $VCONFIG $cmd $parent $vlan_id
+ $FWBDEBUG $IP link set $subint up
+ }
+ test "$cmd" = "rem" && {
+ echo "# Removing VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $VCONFIG $cmd $subint
+ }
+}
+
+parse_fwb_vlans() {
+ set $1
+ vlan_parent_interface=$1
+ shift
+
+ FWB_VLANS=$(
+ for subint in $*; do
+ echo "${subint}@$vlan_parent_interface"
+ done | sort
+ )
+ echo $FWB_VLANS
+}
+
+parse_current_vlans() {
+ vlan_parent_interface=$1
+ CURRENT_VLANS=""
+ PROC_DIR="/proc/net/vlan/"
+ test -d $PROC_DIR || $MODPROBE 8021q || {
+ echo "$PROC_DIR does not exist. Vlan interfaces are not available."
+ exit 1
+ }
+
+ test -f "/proc/net/vlan/config" && {
+ CURRENT_VLANS=$(
+ cat /proc/net/vlan/config | grep -v 'Dev name' | grep $vlan_parent_interface | \
+ while read subint a vlan_id b parent; do
+ echo "${subint}@$parent"
+ done | sort
+ )
+ }
+ echo $CURRENT_VLANS
+}
+
+update_vlans_of_interface() {
+ args="$1"
+ set $1
+ vlan_parent_interface=$1
+
+ FWB_VLANS=$(parse_fwb_vlans "$args")
+ CURRENT_VLANS=$(parse_current_vlans $vlan_parent_interface)
+
+ $IP link set $vlan_parent_interface up
+ diff_intf missing_vlan "$FWB_VLANS" "$CURRENT_VLANS" add
+ diff_intf missing_vlan "$CURRENT_VLANS" "$FWB_VLANS" rem
+}
+
+add_vlans() {
+ args="$1"
+ set $1
+ vlan_parent_interface=$1
+
+ FWB_VLANS=$(parse_fwb_vlans $args)
+ CURRENT_VLANS=$(parse_current_vlans $vlan_parent_interface)
+
+ $IP link set $vlan_parent_interface up
+ diff_intf missing_vlan "$FWB_VLANS" "$CURRENT_VLANS" add
+}
+
+clear_vlans_except_known() {
+ FWB_VLANS=$*
+ CURRENT_VLANS=$(parse_current_vlans '|')
+
+ diff_intf missing_vlan "$CURRENT_VLANS" "$FWB_VLANS" rem
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo eth0.100"
+ for i in eth0 eth1 lo eth0.100 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_vlans_of_interface "eth0 eth0.100"
+ clear_vlans_except_known eth0.100@eth0
+ update_addresses_of_interface "eth0 172.24.0.2/16" "172.24.0.1/16"
+ update_addresses_of_interface "eth1 192.168.1.2/24" "192.168.1.1/24"
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth0.100 192.168.100.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 172.24.0.1
+
+
+
+ # ================ Table 'filter', rule set to_fw
+ #
+ # Rule to_fw 0 (global)
+ #
+ echo "Rule to_fw 0 (global)"
+ #
+ # hashlimit 10/sec
+ $IPTABLES -N to_fw
+ $IPTABLES -N to_fw_0
+ $IPTABLES -A to_fw -m hashlimit --hashlimit 10/second --hashlimit-name htable_rule_0 -j to_fw_0
+ $IPTABLES -A to_fw_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A to_fw_0 -j DROP
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule -6 VRRP (automatic)
+ #
+ echo "Rule -6 VRRP (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth1 -p vrrp -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -5 VRRP (automatic)
+ #
+ echo "Rule -5 VRRP (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p vrrp -s 192.168.1.3 -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -4 VRRP (automatic)
+ #
+ echo "Rule -4 VRRP (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p vrrp -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -3 VRRP (automatic)
+ #
+ echo "Rule -3 VRRP (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p vrrp -s 172.24.0.3 -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -2 CONNTRACK (automatic)
+ #
+ echo "Rule -2 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 225.0.0.50 --dport 3780 -j ACCEPT
+ #
+ # Rule -1 CONNTRACK (automatic)
+ #
+ echo "Rule -1 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 225.0.0.50 --dport 3780 -j ACCEPT
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ # anti spoofing rule
+ $IPTABLES -N In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.100.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.100.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A In_RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A In_RULE_1 -j DROP
+ #
+ # Rule 2 (lo)
+ #
+ echo "Rule 2 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.2 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.3 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.3 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ # Firewall uses one of the machines
+ # on internal network for DNS
+ $IPTABLES -N RULE_5
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A RULE_5 -j LOG --log-level info --log-prefix "RULE 5 -- ACCEPT "
+ $IPTABLES -A RULE_5 -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ # All other attempts to connect to
+ # the firewall are denied and logged
+ $IPTABLES -N RULE_6
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -j RULE_6
+ $IPTABLES -A OUTPUT -d 172.24.0.2 -j RULE_6
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j RULE_6
+ $IPTABLES -A OUTPUT -d 192.168.1.2 -j RULE_6
+ $IPTABLES -A OUTPUT -d 192.168.100.1 -j RULE_6
+ $IPTABLES -A INPUT -j RULE_6
+ $IPTABLES -A RULE_6 -j LOG --log-level info --log-prefix "RULE 6 -- DENY "
+ $IPTABLES -A RULE_6 -j DROP
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -N RULE_8
+ $IPTABLES -A OUTPUT -m state --state NEW -j RULE_8
+ $IPTABLES -A INPUT -m state --state NEW -j RULE_8
+ $IPTABLES -A FORWARD -m state --state NEW -j RULE_8
+ $IPTABLES -A RULE_8 -j LOG --log-level info --log-prefix "RULE 8 -- DENY "
+ $IPTABLES -A RULE_8 -j DROP
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -N RULE_9
+ $IPTABLES -A OUTPUT -j RULE_9
+ $IPTABLES -A INPUT -j RULE_9
+ $IPTABLES -A FORWARD -j RULE_9
+ $IPTABLES -A RULE_9 -j LOG --log-level info --log-prefix "RULE 9 -- DENY "
+ $IPTABLES -A RULE_9 -j DROP
+
+
+
+
+
+
+
+
+ # ============== ROUTING RULES ==============
+
+ TMPDIRNAME="/tmp/.fwbuilder.tempdir.$$"
+ TMPFILENAME="$TMPDIRNAME/.fwbuilder.out"
+ (umask 077 && mkdir $TMPDIRNAME) || exit 1
+
+ #
+ # This function stops stdout redirection
+ # and sends previously saved output to terminal
+ restore_script_output()
+ {
+ exec 1>&3 2>&1
+ cat $TMPFILENAME
+ rm -rf $TMPDIRNAME
+ }
+
+ # if any routing rule fails we do our best to prevent freezing the firewall
+ route_command_error()
+ {
+ echo "Error: Routing rule $1 couldn't be activated"
+ echo "Recovering previous routing configuration..."
+ # delete current routing rules
+ $IP route show | while read route ; do $IP route del $route ; done
+ # restore old routing rules
+ (IFS="
+ "; for route in $oldRoutes; do (IFS=' '; $IP route add $route); done)
+ echo "...done"
+ restore_script_output
+ epilog_commands
+ exit 1
+ }
+
+ # redirect output to prevent ssh session from stalling
+ exec 3>&1
+ exec 1> $TMPFILENAME
+ exec 2>&1
+
+ # store previous routing configuration (sort: 'via' GW has to be
+ # inserted after device routes)
+ oldRoutes=$($IP route show | sort -k 2)
+
+ echo "Deleting routing rules previously set by user space processes..."
+ $IP route show | grep -v '\( proto kernel \)\|\(default via \)' | \
+ while read route ; do $IP route del $route ; done
+
+ echo "Activating non-ecmp routing rules..."
+ #
+ # Rule 0 (main)
+ #
+ echo "Routing rule 0 (main)"
+ #
+ # Some sub rules belonging to an ECMP (Equal Cost Multi Path) rule were placed in the ECMP section below.
+ #
+ # Rule 1 (main)
+ #
+ echo "Routing rule 1 (main)"
+ #
+ # Some sub rules belonging to an ECMP (Equal Cost Multi Path) rule were placed in the ECMP section below.
+
+ #
+ # ============== EQUAL COST MULTI PATH ============
+ #
+ echo "Activating ecmp routing rules..."
+ #
+ # Multipath Rule derived from the following routing rules:
+ #
+ # Rule 0 (main)
+ #
+ # Rule 1 (main)
+ #
+ #
+ $IP route add 172.24.1.0/24 \
+ nexthop via 172.24.0.100 dev eth0 \
+ nexthop via 172.24.0.100 dev eth1 \
+ || route_command_error "1"
+
+ restore_script_output
+ echo "...done."
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:18 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/vrrp_cluster_1_linux-2.fw.orig b/test/ipt/vrrp_cluster_1_linux-2.fw.orig
new file mode 100755
index 000000000..a5594578c
--- /dev/null
+++ b/test/ipt/vrrp_cluster_1_linux-2.fw.orig
@@ -0,0 +1,675 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:18 2011 PST by vadim
+#
+# files: * vrrp_cluster_1_linux-2.fw
+#
+# Compiled for iptables (any version)
+#
+
+# vrrp_cluster_1:Routing:1: error: Object "gw1" used as gateway in the routing rule 1 (main) is not in the same local network as interface eth1
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo"
+ for i in eth0 eth1 lo ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 172.24.0.3/16" "172.24.0.1/16"
+ update_addresses_of_interface "eth1 192.168.1.3/24" "192.168.1.1/24"
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 172.24.0.1
+
+
+
+ # ================ Table 'filter', rule set to_fw
+ #
+ # Rule to_fw 0 (global)
+ #
+ echo "Rule to_fw 0 (global)"
+ #
+ # hashlimit 20/sec
+ $IPTABLES -N to_fw
+ $IPTABLES -N to_fw_0
+ $IPTABLES -A to_fw -m hashlimit --hashlimit 20/second --hashlimit-name htable_rule_0 -j to_fw_0
+ $IPTABLES -A to_fw_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A to_fw_0 -j DROP
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule -6 VRRP (automatic)
+ #
+ echo "Rule -6 VRRP (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth1 -p vrrp -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -5 VRRP (automatic)
+ #
+ echo "Rule -5 VRRP (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p vrrp -s 192.168.1.2 -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -4 VRRP (automatic)
+ #
+ echo "Rule -4 VRRP (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p vrrp -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -3 VRRP (automatic)
+ #
+ echo "Rule -3 VRRP (automatic)"
+ #
+ $IPTABLES -N C.0
+ $IPTABLES -A INPUT -i eth0 -p vrrp -d 224.0.0.18 -j C.0
+ $IPTABLES -A C.0 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A C.0 -s 192.168.100.1 -j ACCEPT
+ #
+ # Rule -2 CONNTRACK (automatic)
+ #
+ echo "Rule -2 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 225.0.0.50 --dport 3780 -j ACCEPT
+ #
+ # Rule -1 CONNTRACK (automatic)
+ #
+ echo "Rule -1 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 225.0.0.50 --dport 3780 -j ACCEPT
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ # anti spoofing rule
+ $IPTABLES -N In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A In_RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A In_RULE_1 -j DROP
+ #
+ # Rule 2 (lo)
+ #
+ echo "Rule 2 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.3 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.2 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.2 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ # Firewall uses one of the machines
+ # on internal network for DNS
+ $IPTABLES -N RULE_5
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A RULE_5 -j LOG --log-level info --log-prefix "RULE 5 -- ACCEPT "
+ $IPTABLES -A RULE_5 -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ # All other attempts to connect to
+ # the firewall are denied and logged
+ $IPTABLES -N RULE_6
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -j RULE_6
+ $IPTABLES -A OUTPUT -d 172.24.0.3 -j RULE_6
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j RULE_6
+ $IPTABLES -A OUTPUT -d 192.168.1.3 -j RULE_6
+ $IPTABLES -A INPUT -j RULE_6
+ $IPTABLES -A RULE_6 -j LOG --log-level info --log-prefix "RULE 6 -- DENY "
+ $IPTABLES -A RULE_6 -j DROP
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -N RULE_8
+ $IPTABLES -A OUTPUT -m state --state NEW -j RULE_8
+ $IPTABLES -A INPUT -m state --state NEW -j RULE_8
+ $IPTABLES -A FORWARD -m state --state NEW -j RULE_8
+ $IPTABLES -A RULE_8 -j LOG --log-level info --log-prefix "RULE 8 -- DENY "
+ $IPTABLES -A RULE_8 -j DROP
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -N RULE_9
+ $IPTABLES -A OUTPUT -j RULE_9
+ $IPTABLES -A INPUT -j RULE_9
+ $IPTABLES -A FORWARD -j RULE_9
+ $IPTABLES -A RULE_9 -j LOG --log-level info --log-prefix "RULE 9 -- DENY "
+ $IPTABLES -A RULE_9 -j DROP
+
+
+
+
+
+
+
+
+ # ============== ROUTING RULES ==============
+
+ TMPDIRNAME="/tmp/.fwbuilder.tempdir.$$"
+ TMPFILENAME="$TMPDIRNAME/.fwbuilder.out"
+ (umask 077 && mkdir $TMPDIRNAME) || exit 1
+
+ #
+ # This function stops stdout redirection
+ # and sends previously saved output to terminal
+ restore_script_output()
+ {
+ exec 1>&3 2>&1
+ cat $TMPFILENAME
+ rm -rf $TMPDIRNAME
+ }
+
+ # if any routing rule fails we do our best to prevent freezing the firewall
+ route_command_error()
+ {
+ echo "Error: Routing rule $1 couldn't be activated"
+ echo "Recovering previous routing configuration..."
+ # delete current routing rules
+ $IP route show | while read route ; do $IP route del $route ; done
+ # restore old routing rules
+ (IFS="
+ "; for route in $oldRoutes; do (IFS=' '; $IP route add $route); done)
+ echo "...done"
+ restore_script_output
+ epilog_commands
+ exit 1
+ }
+
+ # redirect output to prevent ssh session from stalling
+ exec 3>&1
+ exec 1> $TMPFILENAME
+ exec 2>&1
+
+ # store previous routing configuration (sort: 'via' GW has to be
+ # inserted after device routes)
+ oldRoutes=$($IP route show | sort -k 2)
+
+ echo "Deleting routing rules previously set by user space processes..."
+ $IP route show | grep -v '\( proto kernel \)\|\(default via \)' | \
+ while read route ; do $IP route del $route ; done
+
+ echo "Activating non-ecmp routing rules..."
+ #
+ # Rule 0 (main)
+ #
+ echo "Routing rule 0 (main)"
+ #
+ # Some sub rules belonging to an ECMP (Equal Cost Multi Path) rule were placed in the ECMP section below.
+ #
+ # Rule 1 (main)
+ #
+ echo "Routing rule 1 (main)"
+ #
+ # Some sub rules belonging to an ECMP (Equal Cost Multi Path) rule were placed in the ECMP section below.
+
+ #
+ # ============== EQUAL COST MULTI PATH ============
+ #
+ echo "Activating ecmp routing rules..."
+ #
+ # Multipath Rule derived from the following routing rules:
+ #
+ # Rule 0 (main)
+ #
+ # Rule 1 (main)
+ #
+ #
+ $IP route add 172.24.1.0/24 \
+ nexthop via 172.24.0.100 dev eth0 \
+ nexthop via 172.24.0.100 dev eth1 \
+ || route_command_error "1"
+
+ restore_script_output
+ echo "...done."
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:18 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/vrrp_cluster_2_linux-1.fw.orig b/test/ipt/vrrp_cluster_2_linux-1.fw.orig
new file mode 100755
index 000000000..980575eb7
--- /dev/null
+++ b/test/ipt/vrrp_cluster_2_linux-1.fw.orig
@@ -0,0 +1,702 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:18 2011 PST by vadim
+#
+# files: * vrrp_cluster_2_linux-1.fw
+#
+# Compiled for iptables (any version)
+#
+#
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+ find_program $VCONFIG
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+missing_vlan() {
+ vlan=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $vlan
+ subint=$1
+ parent=$2
+ IFS=$oldIFS
+
+ vlan_id=$(echo $subint | sed -r 's/(vlan|[^.]*\.)//')
+ test "$cmd" = "add" && {
+ echo $subint | grep -q "vlan" && name_type="VLAN_PLUS_VID" || name_type="DEV_PLUS_VID"
+ test "$vlan_id" \< "1" || name_type="${name_type}_NO_PAD"
+ echo "# Adding VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $VCONFIG set_name_type $name_type
+ $FWBDEBUG $VCONFIG $cmd $parent $vlan_id
+ $FWBDEBUG $IP link set $subint up
+ }
+ test "$cmd" = "rem" && {
+ echo "# Removing VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $VCONFIG $cmd $subint
+ }
+}
+
+parse_fwb_vlans() {
+ set $1
+ vlan_parent_interface=$1
+ shift
+
+ FWB_VLANS=$(
+ for subint in $*; do
+ echo "${subint}@$vlan_parent_interface"
+ done | sort
+ )
+ echo $FWB_VLANS
+}
+
+parse_current_vlans() {
+ vlan_parent_interface=$1
+ CURRENT_VLANS=""
+ PROC_DIR="/proc/net/vlan/"
+ test -d $PROC_DIR || $MODPROBE 8021q || {
+ echo "$PROC_DIR does not exist. Vlan interfaces are not available."
+ exit 1
+ }
+
+ test -f "/proc/net/vlan/config" && {
+ CURRENT_VLANS=$(
+ cat /proc/net/vlan/config | grep -v 'Dev name' | grep $vlan_parent_interface | \
+ while read subint a vlan_id b parent; do
+ echo "${subint}@$parent"
+ done | sort
+ )
+ }
+ echo $CURRENT_VLANS
+}
+
+update_vlans_of_interface() {
+ args="$1"
+ set $1
+ vlan_parent_interface=$1
+
+ FWB_VLANS=$(parse_fwb_vlans "$args")
+ CURRENT_VLANS=$(parse_current_vlans $vlan_parent_interface)
+
+ $IP link set $vlan_parent_interface up
+ diff_intf missing_vlan "$FWB_VLANS" "$CURRENT_VLANS" add
+ diff_intf missing_vlan "$CURRENT_VLANS" "$FWB_VLANS" rem
+}
+
+add_vlans() {
+ args="$1"
+ set $1
+ vlan_parent_interface=$1
+
+ FWB_VLANS=$(parse_fwb_vlans $args)
+ CURRENT_VLANS=$(parse_current_vlans $vlan_parent_interface)
+
+ $IP link set $vlan_parent_interface up
+ diff_intf missing_vlan "$FWB_VLANS" "$CURRENT_VLANS" add
+}
+
+clear_vlans_except_known() {
+ FWB_VLANS=$*
+ CURRENT_VLANS=$(parse_current_vlans '|')
+
+ diff_intf missing_vlan "$CURRENT_VLANS" "$FWB_VLANS" rem
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo eth0.100"
+ for i in eth0 eth1 lo eth0.100 ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_vlans_of_interface "eth0 eth0.100"
+ clear_vlans_except_known eth0.100@eth0
+ update_addresses_of_interface "eth0 172.24.0.2/16" "172.24.0.1/24"
+ update_addresses_of_interface "eth1 192.168.1.2/24" "192.168.1.1/24"
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+ update_addresses_of_interface "eth0.100 192.168.100.1/24" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 172.24.0.1
+
+
+
+ # ================ Table 'filter', rule set to_fw
+ #
+ # Rule to_fw 0 (global)
+ #
+ echo "Rule to_fw 0 (global)"
+ #
+ # hashlimit 10/sec
+ $IPTABLES -N to_fw
+ $IPTABLES -N to_fw_0
+ $IPTABLES -A to_fw -m hashlimit --hashlimit 10/second --hashlimit-name htable_rule_0 -j to_fw_0
+ $IPTABLES -A to_fw_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A to_fw_0 -j DROP
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule -8 VRRP (automatic)
+ #
+ echo "Rule -8 VRRP (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth1 -p vrrp -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -7 VRRP (automatic)
+ #
+ echo "Rule -7 VRRP (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p vrrp -s 192.168.1.4 -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -6 VRRP (automatic)
+ #
+ echo "Rule -6 VRRP (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p vrrp -s 192.168.1.3 -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -5 VRRP (automatic)
+ #
+ echo "Rule -5 VRRP (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p vrrp -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -4 VRRP (automatic)
+ #
+ echo "Rule -4 VRRP (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p vrrp -s 172.24.0.4 -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -3 VRRP (automatic)
+ #
+ echo "Rule -3 VRRP (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p vrrp -s 172.24.0.3 -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -2 CONNTRACK (automatic)
+ #
+ echo "Rule -2 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 225.0.0.50 --dport 3780 -j ACCEPT
+ #
+ # Rule -1 CONNTRACK (automatic)
+ #
+ echo "Rule -1 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 225.0.0.50 --dport 3780 -j ACCEPT
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ # anti spoofing rule
+ $IPTABLES -N In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.100.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.2 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.100.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A In_RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A In_RULE_1 -j DROP
+ #
+ # Rule 2 (lo)
+ #
+ echo "Rule 2 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.2 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -N Cid5188X25627.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j Cid5188X25627.0
+ $IPTABLES -A Cid5188X25627.0 -d 192.168.1.3 -j ACCEPT
+ $IPTABLES -A Cid5188X25627.0 -d 192.168.1.4 -j ACCEPT
+ $IPTABLES -N Cid5188X25627.1
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j Cid5188X25627.1
+ $IPTABLES -A Cid5188X25627.1 -d 192.168.1.3 -j ACCEPT
+ $IPTABLES -A Cid5188X25627.1 -d 192.168.1.4 -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ # Firewall uses one of the machines
+ # on internal network for DNS
+ $IPTABLES -N RULE_5
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A RULE_5 -j LOG --log-level info --log-prefix "RULE 5 -- ACCEPT "
+ $IPTABLES -A RULE_5 -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ # All other attempts to connect to
+ # the firewall are denied and logged
+ $IPTABLES -N RULE_6
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -j RULE_6
+ $IPTABLES -A OUTPUT -d 172.24.0.2 -j RULE_6
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j RULE_6
+ $IPTABLES -A OUTPUT -d 192.168.1.2 -j RULE_6
+ $IPTABLES -A OUTPUT -d 192.168.100.1 -j RULE_6
+ $IPTABLES -A INPUT -j RULE_6
+ $IPTABLES -A RULE_6 -j LOG --log-level info --log-prefix "RULE 6 -- DENY "
+ $IPTABLES -A RULE_6 -j DROP
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -N RULE_8
+ $IPTABLES -A OUTPUT -m state --state NEW -j RULE_8
+ $IPTABLES -A INPUT -m state --state NEW -j RULE_8
+ $IPTABLES -A FORWARD -m state --state NEW -j RULE_8
+ $IPTABLES -A RULE_8 -j LOG --log-level info --log-prefix "RULE 8 -- DENY "
+ $IPTABLES -A RULE_8 -j DROP
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -N RULE_9
+ $IPTABLES -A OUTPUT -j RULE_9
+ $IPTABLES -A INPUT -j RULE_9
+ $IPTABLES -A FORWARD -j RULE_9
+ $IPTABLES -A RULE_9 -j LOG --log-level info --log-prefix "RULE 9 -- DENY "
+ $IPTABLES -A RULE_9 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:18 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/vrrp_cluster_2_linux-2.fw.orig b/test/ipt/vrrp_cluster_2_linux-2.fw.orig
new file mode 100755
index 000000000..557ec91d2
--- /dev/null
+++ b/test/ipt/vrrp_cluster_2_linux-2.fw.orig
@@ -0,0 +1,607 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:18 2011 PST by vadim
+#
+# files: * vrrp_cluster_2_linux-2.fw
+#
+# Compiled for iptables (any version)
+#
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo"
+ for i in eth0 eth1 lo ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 172.24.0.3/16" "172.24.0.1/24"
+ update_addresses_of_interface "eth1 192.168.1.3/24" "192.168.1.1/24"
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 172.24.0.1
+
+
+
+ # ================ Table 'filter', rule set to_fw
+ #
+ # Rule to_fw 0 (global)
+ #
+ echo "Rule to_fw 0 (global)"
+ #
+ # hashlimit 20/sec
+ $IPTABLES -N to_fw
+ $IPTABLES -N to_fw_0
+ $IPTABLES -A to_fw -m hashlimit --hashlimit 20/second --hashlimit-name htable_rule_0 -j to_fw_0
+ $IPTABLES -A to_fw_0 -j LOG --log-level info --log-prefix "RULE 0 -- DENY "
+ $IPTABLES -A to_fw_0 -j DROP
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule -8 VRRP (automatic)
+ #
+ echo "Rule -8 VRRP (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth1 -p vrrp -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -7 VRRP (automatic)
+ #
+ echo "Rule -7 VRRP (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p vrrp -s 192.168.1.4 -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -6 VRRP (automatic)
+ #
+ echo "Rule -6 VRRP (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p vrrp -s 192.168.1.2 -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -5 VRRP (automatic)
+ #
+ echo "Rule -5 VRRP (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p vrrp -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -4 VRRP (automatic)
+ #
+ echo "Rule -4 VRRP (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p vrrp -s 172.24.0.4 -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -3 VRRP (automatic)
+ #
+ echo "Rule -3 VRRP (automatic)"
+ #
+ $IPTABLES -N C.0
+ $IPTABLES -A INPUT -i eth0 -p vrrp -d 224.0.0.18 -j C.0
+ $IPTABLES -A C.0 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A C.0 -s 192.168.100.1 -j ACCEPT
+ #
+ # Rule -2 CONNTRACK (automatic)
+ #
+ echo "Rule -2 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p udp -m udp -d 225.0.0.50 --dport 3780 -j ACCEPT
+ #
+ # Rule -1 CONNTRACK (automatic)
+ #
+ echo "Rule -1 CONNTRACK (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p udp -m udp -d 225.0.0.50 --dport 3780 -j ACCEPT
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ # anti spoofing rule
+ $IPTABLES -N In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.3 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A In_RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A In_RULE_1 -j DROP
+ #
+ # Rule 2 (lo)
+ #
+ echo "Rule 2 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.3 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -N Cid5188X25627.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j Cid5188X25627.0
+ $IPTABLES -A Cid5188X25627.0 -d 192.168.1.2 -j ACCEPT
+ $IPTABLES -A Cid5188X25627.0 -d 192.168.1.4 -j ACCEPT
+ $IPTABLES -N Cid5188X25627.1
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j Cid5188X25627.1
+ $IPTABLES -A Cid5188X25627.1 -d 192.168.1.2 -j ACCEPT
+ $IPTABLES -A Cid5188X25627.1 -d 192.168.1.4 -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ # Firewall uses one of the machines
+ # on internal network for DNS
+ $IPTABLES -N RULE_5
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A RULE_5 -j LOG --log-level info --log-prefix "RULE 5 -- ACCEPT "
+ $IPTABLES -A RULE_5 -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ # All other attempts to connect to
+ # the firewall are denied and logged
+ $IPTABLES -N RULE_6
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -j RULE_6
+ $IPTABLES -A OUTPUT -d 172.24.0.3 -j RULE_6
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j RULE_6
+ $IPTABLES -A OUTPUT -d 192.168.1.3 -j RULE_6
+ $IPTABLES -A INPUT -j RULE_6
+ $IPTABLES -A RULE_6 -j LOG --log-level info --log-prefix "RULE 6 -- DENY "
+ $IPTABLES -A RULE_6 -j DROP
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -N RULE_8
+ $IPTABLES -A OUTPUT -m state --state NEW -j RULE_8
+ $IPTABLES -A INPUT -m state --state NEW -j RULE_8
+ $IPTABLES -A FORWARD -m state --state NEW -j RULE_8
+ $IPTABLES -A RULE_8 -j LOG --log-level info --log-prefix "RULE 8 -- DENY "
+ $IPTABLES -A RULE_8 -j DROP
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -N RULE_9
+ $IPTABLES -A OUTPUT -j RULE_9
+ $IPTABLES -A INPUT -j RULE_9
+ $IPTABLES -A FORWARD -j RULE_9
+ $IPTABLES -A RULE_9 -j LOG --log-level info --log-prefix "RULE 9 -- DENY "
+ $IPTABLES -A RULE_9 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:18 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/ipt/vrrp_cluster_2_linux-3.fw.orig b/test/ipt/vrrp_cluster_2_linux-3.fw.orig
new file mode 100755
index 000000000..c5d3f47bd
--- /dev/null
+++ b/test/ipt/vrrp_cluster_2_linux-3.fw.orig
@@ -0,0 +1,583 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_ipt v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:58:19 2011 PST by vadim
+#
+# files: * vrrp_cluster_2_linux-3.fw
+#
+# Compiled for iptables (any version)
+#
+
+
+
+
+FWBDEBUG=""
+
+PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
+export PATH
+
+
+
+LSMOD="/sbin/lsmod"
+MODPROBE="/sbin/modprobe"
+IPTABLES="/sbin/iptables"
+IP6TABLES="/sbin/ip6tables"
+IPTABLES_RESTORE="/sbin/iptables-restore"
+IP6TABLES_RESTORE="/sbin/ip6tables-restore"
+IP="/sbin/ip"
+IFCONFIG="/sbin/ifconfig"
+VCONFIG="/sbin/vconfig"
+BRCTL="/sbin/brctl"
+IFENSLAVE="/sbin/ifenslave"
+IPSET="/usr/sbin/ipset"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+getInterfaceVarName() {
+ echo $1 | sed 's/\./_/'
+}
+
+getaddr_internal() {
+ dev=$1
+ name=$2
+ af=$3
+ L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
+ test -z "$L" && {
+ eval "$name=''"
+ return
+ }
+ eval "${name}_list=\"$L\""
+}
+
+getaddr() {
+ getaddr_internal $1 $2 "-4"
+}
+
+getaddr6() {
+ getaddr_internal $1 $2 "-6"
+}
+
+# function getinterfaces is used to process wildcard interfaces
+getinterfaces() {
+ NAME=$1
+ $IP link show | grep ": $NAME" | while read L; do
+ OIFS=$IFS
+ IFS=" :"
+ set $L
+ IFS=$OIFS
+ echo $2
+ done
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+find_program() {
+ PGM=$1
+ $PGM /dev/null 2>&1; test $? = 127 && {
+ echo "$PGM not found"
+ exit 1
+ }
+}
+check_tools() {
+ find_program $IPTABLES
+ find_program $MODPROBE
+ find_program $IP
+}
+reset_iptables_v4() {
+ $IPTABLES -P OUTPUT DROP
+ $IPTABLES -P INPUT DROP
+ $IPTABLES -P FORWARD DROP
+
+cat /proc/net/ip_tables_names | while read table; do
+ $IPTABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IPTABLES -t $table -F $chain
+ fi
+ done
+ $IPTABLES -t $table -X
+done
+}
+
+reset_iptables_v6() {
+ $IP6TABLES -P OUTPUT DROP
+ $IP6TABLES -P INPUT DROP
+ $IP6TABLES -P FORWARD DROP
+
+cat /proc/net/ip6_tables_names | while read table; do
+ $IP6TABLES -t $table -L -n | while read c chain rest; do
+ if test "X$c" = "XChain" ; then
+ $IP6TABLES -t $table -F $chain
+ fi
+ done
+ $IP6TABLES -t $table -X
+done
+}
+
+
+P2P_INTERFACE_WARNING=""
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+
+
+ $IP addr show dev $interface | grep -q POINTOPOINT && {
+ test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
+ P2P_INTERFACE_WARNING="yes"
+ return
+ }
+
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ echo $addr | grep -q ':' && {
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ } || {
+ $FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
+ }
+ }
+
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ $FWBDEBUG $IP addr $cmd $addr dev $interface
+ }
+
+ $FWBDEBUG $IP link set $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+ $IP addr ls dev $interface | \
+ awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+}
+
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IP link show dev $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+clear_addresses_except_known_interfaces() {
+ $IP link show | sed 's/://g' | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/state/ && !($2 in ignored_dict)) {print $2;}' | \
+ while read intf; do
+ echo "# Removing addresses not configured in fwbuilder from interface $intf"
+ $FWBDEBUG $IP addr flush dev $intf scope global
+ $FWBDEBUG $IP link set $intf down
+ done
+}
+
+check_file() {
+ test -r "$2" || {
+ echo "Can not find file $2 referenced by address table object $1"
+ exit 1
+ }
+}
+
+check_run_time_address_table_files() {
+ :
+
+}
+
+load_modules() {
+ :
+ OPTS=$1
+ MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
+ MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
+ echo $OPTS | grep -q nat && {
+ MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ echo $OPTS | grep -q ipv6 && {
+ MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
+ }
+ for module in $MODULES; do
+ if $LSMOD | grep ${module} >/dev/null; then continue; fi
+ $MODPROBE ${module} || exit 1
+ done
+}
+
+verify_interfaces() {
+ :
+ echo "Verifying interfaces: eth0 eth1 lo"
+ for i in eth0 eth1 lo ; do
+ $IP link show "$i" > /dev/null 2>&1 || {
+ log "Interface $i does not exist"
+ exit 1
+ }
+ done
+}
+
+prolog_commands() {
+ echo "Running prolog script"
+
+}
+
+epilog_commands() {
+ echo "Running epilog script"
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ # Configure interfaces
+ update_addresses_of_interface "eth0 172.24.0.4/16" "172.24.0.1/24"
+ update_addresses_of_interface "eth1 192.168.1.4/24" "192.168.1.1/24"
+ update_addresses_of_interface "lo 127.0.0.1/8" ""
+}
+
+script_body() {
+ # ================ IPv4
+
+
+ # ================ Table 'filter', automatic rules
+ # accept established sessions
+ $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
+ $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
+
+
+ # ================ Table 'nat', rule set NAT
+ #
+ # Rule 0 (NAT)
+ #
+ echo "Rule 0 (NAT)"
+ #
+ $IPTABLES -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j SNAT --to-source 172.24.0.1
+
+
+
+ # ================ Table 'filter', rule set Policy
+ #
+ # Rule -6 VRRP (automatic)
+ #
+ echo "Rule -6 VRRP (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth1 -p vrrp -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -5 VRRP (automatic)
+ #
+ echo "Rule -5 VRRP (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p vrrp -s 192.168.1.3 -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -4 VRRP (automatic)
+ #
+ echo "Rule -4 VRRP (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth1 -p vrrp -s 192.168.1.2 -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -3 VRRP (automatic)
+ #
+ echo "Rule -3 VRRP (automatic)"
+ #
+ $IPTABLES -A OUTPUT -o eth0 -p vrrp -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -2 VRRP (automatic)
+ #
+ echo "Rule -2 VRRP (automatic)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p vrrp -s 172.24.0.3 -d 224.0.0.18 -j ACCEPT
+ #
+ # Rule -1 VRRP (automatic)
+ #
+ echo "Rule -1 VRRP (automatic)"
+ #
+ $IPTABLES -N C.0
+ $IPTABLES -A INPUT -i eth0 -p vrrp -d 224.0.0.18 -j C.0
+ $IPTABLES -A C.0 -s 172.24.0.2 -j ACCEPT
+ $IPTABLES -A C.0 -s 192.168.100.1 -j ACCEPT
+ #
+ # Rule 0 (eth0)
+ #
+ echo "Rule 0 (eth0)"
+ #
+ $IPTABLES -A INPUT -i eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o eth0 -p vrrp -d 224.0.0.18 -m state --state NEW -j ACCEPT
+ #
+ # Rule 1 (eth0)
+ #
+ echo "Rule 1 (eth0)"
+ #
+ # anti spoofing rule
+ $IPTABLES -N In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 172.24.0.4 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.4 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A INPUT -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 172.24.0.4 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.1 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.4 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A FORWARD -i eth0 -s 192.168.1.0/24 -m state --state NEW -j In_RULE_1
+ $IPTABLES -A In_RULE_1 -j LOG --log-level info --log-prefix "RULE 1 -- DENY "
+ $IPTABLES -A In_RULE_1 -j DROP
+ #
+ # Rule 2 (lo)
+ #
+ echo "Rule 2 (lo)"
+ #
+ $IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -o lo -m state --state NEW -j ACCEPT
+ #
+ # Rule 3 (global)
+ #
+ echo "Rule 3 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j ACCEPT
+ #
+ # Rule 4 (global)
+ #
+ echo "Rule 4 (global)"
+ #
+ # SSH Access to firewall is permitted
+ # only from internal network
+ $IPTABLES -A INPUT -p tcp -m tcp -s 192.168.1.0/24 -d 192.168.1.4 --dport 22 -m state --state NEW -j ACCEPT
+ $IPTABLES -N Cid5188X25627.0
+ $IPTABLES -A OUTPUT -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j Cid5188X25627.0
+ $IPTABLES -A Cid5188X25627.0 -d 192.168.1.2 -j ACCEPT
+ $IPTABLES -A Cid5188X25627.0 -d 192.168.1.3 -j ACCEPT
+ $IPTABLES -N Cid5188X25627.1
+ $IPTABLES -A FORWARD -p tcp -m tcp -s 192.168.1.0/24 --dport 22 -m state --state NEW -j Cid5188X25627.1
+ $IPTABLES -A Cid5188X25627.1 -d 192.168.1.2 -j ACCEPT
+ $IPTABLES -A Cid5188X25627.1 -d 192.168.1.3 -j ACCEPT
+ #
+ # Rule 5 (global)
+ #
+ echo "Rule 5 (global)"
+ #
+ # Firewall uses one of the machines
+ # on internal network for DNS
+ $IPTABLES -N RULE_5
+ $IPTABLES -A OUTPUT -p tcp -m tcp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A OUTPUT -p udp -m udp -d 192.168.1.0/24 --dport 53 -m state --state NEW -j RULE_5
+ $IPTABLES -A RULE_5 -j LOG --log-level info --log-prefix "RULE 5 -- ACCEPT "
+ $IPTABLES -A RULE_5 -j ACCEPT
+ #
+ # Rule 6 (global)
+ #
+ echo "Rule 6 (global)"
+ #
+ # All other attempts to connect to
+ # the firewall are denied and logged
+ $IPTABLES -N RULE_6
+ $IPTABLES -A OUTPUT -d 172.24.0.1 -j RULE_6
+ $IPTABLES -A OUTPUT -d 172.24.0.4 -j RULE_6
+ $IPTABLES -A OUTPUT -d 192.168.1.1 -j RULE_6
+ $IPTABLES -A OUTPUT -d 192.168.1.4 -j RULE_6
+ $IPTABLES -A INPUT -j RULE_6
+ $IPTABLES -A RULE_6 -j LOG --log-level info --log-prefix "RULE 6 -- DENY "
+ $IPTABLES -A RULE_6 -j DROP
+ #
+ # Rule 7 (global)
+ #
+ echo "Rule 7 (global)"
+ #
+ $IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ $IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
+ #
+ # Rule 8 (global)
+ #
+ echo "Rule 8 (global)"
+ #
+ $IPTABLES -N RULE_8
+ $IPTABLES -A OUTPUT -m state --state NEW -j RULE_8
+ $IPTABLES -A INPUT -m state --state NEW -j RULE_8
+ $IPTABLES -A FORWARD -m state --state NEW -j RULE_8
+ $IPTABLES -A RULE_8 -j LOG --log-level info --log-prefix "RULE 8 -- DENY "
+ $IPTABLES -A RULE_8 -j DROP
+ #
+ # Rule 9 (global)
+ #
+ echo "Rule 9 (global)"
+ #
+ $IPTABLES -N RULE_9
+ $IPTABLES -A OUTPUT -j RULE_9
+ $IPTABLES -A INPUT -j RULE_9
+ $IPTABLES -A FORWARD -j RULE_9
+ $IPTABLES -A RULE_9 -j LOG --log-level info --log-prefix "RULE 9 -- DENY "
+ $IPTABLES -A RULE_9 -j DROP
+}
+
+ip_forward() {
+ :
+ echo 1 > /proc/sys/net/ipv4/ip_forward
+}
+
+reset_all() {
+ :
+ reset_iptables_v4
+}
+
+block_action() {
+ reset_all
+}
+
+stop_action() {
+ reset_all
+ $IPTABLES -P OUTPUT ACCEPT
+ $IPTABLES -P INPUT ACCEPT
+ $IPTABLES -P FORWARD ACCEPT
+}
+
+check_iptables() {
+ IP_TABLES="$1"
+ [ ! -e $IP_TABLES ] && return 151
+ NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
+ [ -z "$NF_TABLES" ] && return 152
+ return 0
+}
+status_action() {
+ check_iptables "/proc/net/ip_tables_names"
+ ret_ipv4=$?
+ check_iptables "/proc/net/ip6_tables_names"
+ ret_ipv6=$?
+ [ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
+ [ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
+ echo "iptables modules are not loaded"
+ }
+ [ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
+ echo "Firewall is not configured"
+ }
+ exit 3
+}
+
+# See how we were called.
+# For backwards compatibility missing argument is equivalent to 'start'
+
+cmd=$1
+test -z "$cmd" && {
+ cmd="start"
+}
+
+case "$cmd" in
+ start)
+ log "Activating firewall script generated Mon Jan 3 12:58:19 2011 by vadim"
+ check_tools
+ prolog_commands
+ check_run_time_address_table_files
+
+ load_modules "nat "
+ configure_interfaces
+ verify_interfaces
+
+ reset_all
+
+ script_body
+ ip_forward
+ epilog_commands
+ RETVAL=$?
+ ;;
+
+ stop)
+ stop_action
+ RETVAL=$?
+ ;;
+
+ status)
+ status_action
+ RETVAL=$?
+ ;;
+
+ block)
+ block_action
+ RETVAL=$?
+ ;;
+
+ reload)
+ $0 stop
+ $0 start
+ RETVAL=$?
+ ;;
+
+ interfaces)
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+ test_interfaces)
+ FWBDEBUG="echo"
+ configure_interfaces
+ RETVAL=$?
+ ;;
+
+
+
+ *)
+ echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
+ ;;
+
+esac
+
+exit $RETVAL
\ No newline at end of file
diff --git a/test/pf/firewall-base-rulesets-mail_server_inbound.conf.orig b/test/pf/firewall-base-rulesets-mail_server_inbound.conf.orig
new file mode 100644
index 000000000..11ed6074f
--- /dev/null
+++ b/test/pf/firewall-base-rulesets-mail_server_inbound.conf.orig
@@ -0,0 +1,7 @@
+#
+# Rule mail_server_inbound 0 (global)
+pass in quick inet proto tcp from any to any port 25 keep state label "RULE 0 -- ACCEPT "
+#
+# Rule mail_server_inbound 1 (global)
+pass in quick inet proto icmp from any to any icmp-type { 3 , 8 code 0 } keep state label "RULE 1 -- ACCEPT "
+
diff --git a/test/pf/firewall-base-rulesets-mail_server_outbound.conf.orig b/test/pf/firewall-base-rulesets-mail_server_outbound.conf.orig
new file mode 100644
index 000000000..c6b7ab759
--- /dev/null
+++ b/test/pf/firewall-base-rulesets-mail_server_outbound.conf.orig
@@ -0,0 +1,8 @@
+#
+# Rule mail_server_outbound 0 (global)
+pass out quick inet proto tcp from any to any port { 53, 25 } keep state label "RULE 0 -- ACCEPT "
+pass out quick inet proto udp from any to any port 53 keep state label "RULE 0 -- ACCEPT "
+#
+# Rule mail_server_outbound 1 (global)
+pass out quick inet proto icmp from any to any icmp-type { 3 , 8 code 0 } keep state label "RULE 1 -- ACCEPT "
+
diff --git a/test/pf/firewall-base-rulesets-web_server_inbound.conf.orig b/test/pf/firewall-base-rulesets-web_server_inbound.conf.orig
new file mode 100644
index 000000000..c958c1371
--- /dev/null
+++ b/test/pf/firewall-base-rulesets-web_server_inbound.conf.orig
@@ -0,0 +1,7 @@
+#
+# Rule web_server_inbound 0 (global)
+pass in quick inet proto tcp from any to any port 80 keep state label "RULE 0 -- ACCEPT "
+#
+# Rule web_server_inbound 1 (global)
+pass in quick inet proto icmp from any to any icmp-type { 3 , 8 code 0 } keep state label "RULE 1 -- ACCEPT "
+
diff --git a/test/pf/firewall-base-rulesets-web_server_outbound.conf.orig b/test/pf/firewall-base-rulesets-web_server_outbound.conf.orig
new file mode 100644
index 000000000..4ba19c1e5
--- /dev/null
+++ b/test/pf/firewall-base-rulesets-web_server_outbound.conf.orig
@@ -0,0 +1,8 @@
+#
+# Rule web_server_outbound 0 (global)
+pass out quick inet proto icmp from any to any icmp-type { 3 , 8 code 0 } keep state label "RULE 0 -- ACCEPT "
+#
+# Rule web_server_outbound 1 (global)
+pass out quick inet proto tcp from any to any port 53 keep state label "RULE 1 -- ACCEPT "
+pass out quick inet proto udp from any to any port 53 keep state label "RULE 1 -- ACCEPT "
+
diff --git a/test/pf/firewall-base-rulesets.conf.orig b/test/pf/firewall-base-rulesets.conf.orig
new file mode 100644
index 000000000..b28b04f64
--- /dev/null
+++ b/test/pf/firewall-base-rulesets.conf.orig
@@ -0,0 +1,3 @@
+
+
+
diff --git a/test/pf/firewall-base-rulesets.fw.orig b/test/pf/firewall-base-rulesets.fw.orig
new file mode 100755
index 000000000..c2c3fcb03
--- /dev/null
+++ b/test/pf/firewall-base-rulesets.fw.orig
@@ -0,0 +1,190 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:53 2011 PST by vadim
+#
+# files: * firewall-base-rulesets.fw
+# files: firewall-base-rulesets.conf
+# files: firewall-base-rulesets-mail_server_inbound.conf
+# files: firewall-base-rulesets-mail_server_outbound.conf
+# files: firewall-base-rulesets-web_server_inbound.conf
+# files: firewall-base-rulesets-web_server_outbound.conf
+#
+# Compiled for pf
+#
+# this firewall is used to test a rule in the global policy of object "firewall"
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ update_addresses_of_interface "en0 33.33.33.33/0xffffff00" ""
+ update_addresses_of_interface "en1 172.16.1.1/0xffffff00" ""
+ update_addresses_of_interface "en2 192.168.100.1/0xffffff00" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:53 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall-base-rulesets.conf || exit 1
+$PFCTL -a mail_server_inbound \
+ -f \
+ ${FWDIR}/firewall-base-rulesets-mail_server_inbound.conf || exit 1
+$PFCTL -a mail_server_outbound \
+ -f \
+ ${FWDIR}/firewall-base-rulesets-mail_server_outbound.conf || exit 1
+$PFCTL -a web_server_inbound \
+ -f \
+ ${FWDIR}/firewall-base-rulesets-web_server_inbound.conf || exit 1
+$PFCTL -a web_server_outbound \
+ -f \
+ ${FWDIR}/firewall-base-rulesets-web_server_outbound.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall-ipv6-1-Policy_ipv4.conf.orig b/test/pf/firewall-ipv6-1-Policy_ipv4.conf.orig
new file mode 100644
index 000000000..1eb7616f7
--- /dev/null
+++ b/test/pf/firewall-ipv6-1-Policy_ipv4.conf.orig
@@ -0,0 +1,4 @@
+#
+# Rule Policy_ipv4 0 (lo)
+pass quick on lo inet from any to any keep state label "RULE 0 -- ACCEPT "
+
diff --git a/test/pf/firewall-ipv6-1.conf.orig b/test/pf/firewall-ipv6-1.conf.orig
new file mode 100644
index 000000000..9d522098d
--- /dev/null
+++ b/test/pf/firewall-ipv6-1.conf.orig
@@ -0,0 +1,70 @@
+
+
+
+
+# Tables: (2)
+table { 2001:5c0:0:2::24 , 3ffe:1200:2000::/36 , 3ffe:1200:2001:1:8000::1 }
+table { 2001:5c0:0:2::24 , 3ffe:1200:2001:1:8000::1 }
+
+# Policy compiler errors and warnings:
+# firewall-ipv6-1:Policy:2: error: Rule '2 (global)' shadows rule '4 (global)' below it
+# firewall-ipv6-1:Policy:3: error: Rule '3 (global)' shadows rule '4 (global)' below it
+# firewall-ipv6-1:Policy:2: error: Rule '2 (global)' shadows rule '5 (global)' below it
+# firewall-ipv6-1:Policy:3: error: Rule '3 (global)' shadows rule '5 (global)' below it
+# firewall-ipv6-1:Policy:2: error: Rule '2 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-1:Policy:4: error: Rule '4 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-1:Policy:3: error: Rule '3 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-1:Policy:2: error: Rule '2 (global)' shadows rule '7 (global)' below it
+# firewall-ipv6-1:Policy:3: error: Rule '3 (global)' shadows rule '7 (global)' below it
+# firewall-ipv6-1:Policy:10: error: Rule '10 (global)' shadows rule '11 (global)' below it
+# firewall-ipv6-1:Policy:10: error: Rule '10 (global)' shadows rule '11 (global)' below it
+# firewall-ipv6-1:Policy:3: warning: Changing rule direction due to self reference
+# firewall-ipv6-1:Policy:6: warning: Changing rule direction due to self reference
+# firewall-ipv6-1:Policy:7: warning: Changing rule direction due to self reference
+#
+# Rule 0 (lo)
+pass quick on lo inet6 from any to any keep state label "RULE 0 -- ACCEPT "
+#
+# Rule 1 (global)
+# this rule shadows the next.
+# Note that we add command line
+# flag -xt to the compiler
+pass quick inet6 proto tcp from fe80::/64 to fe80::21d:9ff:fe8b:8e94 port 22 keep state label "RULE 1 -- ACCEPT "
+#
+# Rule 2 (global)
+pass quick inet6 proto tcp from 2001:5c0:0:2::24 to fe80::21d:9ff:fe8b:8e94 port 22 keep state label "RULE 2 -- ACCEPT "
+#
+# Rule 3 (global)
+# firewall-ipv6-1:Policy:3: warning: Changing rule direction due to self reference
+pass in log quick inet6 proto tcp from 3ffe:1200:2001:1:8000::1 to fe80::21d:9ff:fe8b:8e94 port 22 keep state label "RULE 3 -- ACCEPT "
+#
+# Rule 4 (global)
+pass log quick inet6 proto tcp from to fe80::21d:9ff:fe8b:8e94 port 22 keep state label "RULE 4 -- ACCEPT "
+#
+# Rule 5 (global)
+pass log quick inet6 proto tcp from to fe80::21d:9ff:fe8b:8e94 port 22 keep state label "RULE 5 -- ACCEPT "
+#
+# Rule 6 (global)
+# firewall-ipv6-1:Policy:6: warning: Changing rule direction due to self reference
+pass in log quick inet6 proto tcp from to fe80::21d:9ff:fe8b:8e94 port 22 keep state label "RULE 6 -- ACCEPT "
+#
+# Rule 7 (global)
+# firewall-ipv6-1:Policy:7: warning: Changing rule direction due to self reference
+pass in log quick inet6 proto tcp from to fe80::21d:9ff:fe8b:8e94 port 22 keep state label "RULE 7 -- ACCEPT "
+#
+# Rule 8 (global)
+pass in log quick inet6 from any to fe80::21d:9ff:fe8b:8e94 keep state label "RULE 8 -- ACCEPT "
+#
+# Rule 9 (global)
+pass log quick inet6 from fe80::/64 to any keep state label "RULE 9 -- ACCEPT "
+#
+# Rule 10 (global)
+pass log quick inet6 from to any keep state label "RULE 10 -- ACCEPT "
+#
+# Rule 11 (global)
+pass log quick inet6 from to any keep state label "RULE 11 -- ACCEPT "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet6 from any to any label "RULE 10000 -- DROP "
+
diff --git a/test/pf/firewall-ipv6-1.fw.orig b/test/pf/firewall-ipv6-1.fw.orig
new file mode 100755
index 000000000..d0054f8b9
--- /dev/null
+++ b/test/pf/firewall-ipv6-1.fw.orig
@@ -0,0 +1,193 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:54 2011 PST by vadim
+#
+# files: * firewall-ipv6-1.fw pf-ipv6.fw
+# files: firewall-ipv6-1-Policy_ipv4.conf /etc/fw/pf-ipv6-Policy_ipv4.conf
+# files: firewall-ipv6-1.conf /etc/fw/pf-ipv6.conf
+#
+# Compiled for pf
+#
+
+# firewall-ipv6-1:Policy:2: error: Rule '2 (global)' shadows rule '4 (global)' below it
+# firewall-ipv6-1:Policy:3: error: Rule '3 (global)' shadows rule '4 (global)' below it
+# firewall-ipv6-1:Policy:2: error: Rule '2 (global)' shadows rule '5 (global)' below it
+# firewall-ipv6-1:Policy:3: error: Rule '3 (global)' shadows rule '5 (global)' below it
+# firewall-ipv6-1:Policy:2: error: Rule '2 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-1:Policy:4: error: Rule '4 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-1:Policy:3: error: Rule '3 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-1:Policy:2: error: Rule '2 (global)' shadows rule '7 (global)' below it
+# firewall-ipv6-1:Policy:3: error: Rule '3 (global)' shadows rule '7 (global)' below it
+# firewall-ipv6-1:Policy:10: error: Rule '10 (global)' shadows rule '11 (global)' below it
+# firewall-ipv6-1:Policy:10: error: Rule '10 (global)' shadows rule '11 (global)' below it
+# firewall-ipv6-1:Policy:3: warning: Changing rule direction due to self reference
+# firewall-ipv6-1:Policy:6: warning: Changing rule direction due to self reference
+# firewall-ipv6-1:Policy:7: warning: Changing rule direction due to self reference
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+ $SYSCTL -w net.inet6.ip6.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ update_addresses_of_interface "eth0 fe80::21d:9ff:fe8b:8e94/64 1.1.1.1/0xffffff00" ""
+ update_addresses_of_interface "lo ::1/128 127.0.0.1/0xff000000" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:54 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ /etc/fw/pf-ipv6.conf || exit 1
+$PFCTL -a Policy_ipv4 \
+ -f \
+ /etc/fw/pf-ipv6-Policy_ipv4.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall-ipv6-2.conf.orig b/test/pf/firewall-ipv6-2.conf.orig
new file mode 100644
index 000000000..8f11efc9c
--- /dev/null
+++ b/test/pf/firewall-ipv6-2.conf.orig
@@ -0,0 +1,107 @@
+
+
+
+
+# Tables: (5)
+table { 222.222.222.22 , 222.222.222.23 }
+table { 2001:5c0:0:2::24 , 3ffe:1200:2000::/36 , 3ffe:1200:2001:1:8000::1 }
+table { 61.150.47.112 , 74.125.19.99 , 74.125.19.103 , 74.125.19.104 , 74.125.19.147 , 192.168.1.0 }
+table { 2001:5c0:0:2::24 , 3ffe:1200:2001:1:8000::1 }
+table { 61.150.47.112 , 192.168.1.0 }
+
+# Policy compiler errors and warnings:
+# firewall-ipv6-2:Policy:5: error: Rule '5 (global)' shadows rule '7 (global)' below it
+# firewall-ipv6-2:Policy:5: error: Rule '5 (global)' shadows rule '7 (global)' below it
+# firewall-ipv6-2:Policy:7: warning: Changing rule direction due to self reference
+#
+# Rule 0 (lo)
+pass quick on lo inet from any to any keep state label "RULE 0 -- ACCEPT "
+#
+# Rule 4 (global)
+pass log quick inet proto tcp from to 1.1.1.1 port 22 keep state label "RULE 4 -- ACCEPT "
+#
+# Rule 5 (global)
+pass log quick inet proto tcp from to 1.1.1.1 port 22 keep state label "RULE 5 -- ACCEPT "
+#
+# Rule 7 (global)
+# firewall-ipv6-2:Policy:7: warning: Changing rule direction due to self reference
+pass in log quick inet proto tcp from to 1.1.1.1 port 22 keep state label "RULE 7 -- ACCEPT "
+#
+# Rule 8 (global)
+pass in log quick inet from any to 1.1.1.1 keep state label "RULE 8 -- ACCEPT "
+#
+# Rule 11 (global)
+pass log quick inet from to any keep state label "RULE 11 -- ACCEPT "
+#
+# Rule 12 (global)
+pass quick inet proto icmp from any to any icmp-type 8 code 0 keep state label "RULE 12 -- ACCEPT "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any label "RULE 10000 -- DROP "
+
+# Policy compiler errors and warnings:
+# firewall-ipv6-2:Policy:2: error: Rule '2 (global)' shadows rule '4 (global)' below it
+# firewall-ipv6-2:Policy:3: error: Rule '3 (global)' shadows rule '4 (global)' below it
+# firewall-ipv6-2:Policy:2: error: Rule '2 (global)' shadows rule '5 (global)' below it
+# firewall-ipv6-2:Policy:3: error: Rule '3 (global)' shadows rule '5 (global)' below it
+# firewall-ipv6-2:Policy:2: error: Rule '2 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-2:Policy:4: error: Rule '4 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-2:Policy:3: error: Rule '3 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-2:Policy:2: error: Rule '2 (global)' shadows rule '7 (global)' below it
+# firewall-ipv6-2:Policy:3: error: Rule '3 (global)' shadows rule '7 (global)' below it
+# firewall-ipv6-2:Policy:10: error: Rule '10 (global)' shadows rule '11 (global)' below it
+# firewall-ipv6-2:Policy:10: error: Rule '10 (global)' shadows rule '11 (global)' below it
+# firewall-ipv6-2:Policy:3: warning: Changing rule direction due to self reference
+# firewall-ipv6-2:Policy:6: warning: Changing rule direction due to self reference
+# firewall-ipv6-2:Policy:7: warning: Changing rule direction due to self reference
+#
+# Rule 0 (lo)
+pass quick on lo inet6 from any to any keep state label "RULE 0 -- ACCEPT "
+#
+# Rule 1 (global)
+# this rule shadows the next.
+# Note that we add command line
+# flag -xt to the compiler
+pass quick inet6 proto tcp from fe80::/64 to fe80::21d:9ff:fe8b:8e94 port 22 keep state label "RULE 1 -- ACCEPT "
+#
+# Rule 2 (global)
+pass quick inet6 proto tcp from 2001:5c0:0:2::24 to fe80::21d:9ff:fe8b:8e94 port 22 keep state label "RULE 2 -- ACCEPT "
+#
+# Rule 3 (global)
+# firewall-ipv6-2:Policy:3: warning: Changing rule direction due to self reference
+pass in log quick inet6 proto tcp from 3ffe:1200:2001:1:8000::1 to fe80::21d:9ff:fe8b:8e94 port 22 keep state label "RULE 3 -- ACCEPT "
+#
+# Rule 4 (global)
+pass log quick inet6 proto tcp from to fe80::21d:9ff:fe8b:8e94 port 22 keep state label "RULE 4 -- ACCEPT "
+#
+# Rule 5 (global)
+pass log quick inet6 proto tcp from to fe80::21d:9ff:fe8b:8e94 port 22 keep state label "RULE 5 -- ACCEPT "
+#
+# Rule 6 (global)
+# firewall-ipv6-2:Policy:6: warning: Changing rule direction due to self reference
+pass in log quick inet6 proto tcp from to fe80::21d:9ff:fe8b:8e94 port 22 keep state label "RULE 6 -- ACCEPT "
+#
+# Rule 7 (global)
+# firewall-ipv6-2:Policy:7: warning: Changing rule direction due to self reference
+pass in log quick inet6 proto tcp from to fe80::21d:9ff:fe8b:8e94 port 22 keep state label "RULE 7 -- ACCEPT "
+#
+# Rule 8 (global)
+pass in log quick inet6 from any to fe80::21d:9ff:fe8b:8e94 keep state label "RULE 8 -- ACCEPT "
+#
+# Rule 9 (global)
+pass log quick inet6 from fe80::/64 to any keep state label "RULE 9 -- ACCEPT "
+#
+# Rule 10 (global)
+pass log quick inet6 from to any keep state label "RULE 10 -- ACCEPT "
+#
+# Rule 11 (global)
+pass log quick inet6 from to any keep state label "RULE 11 -- ACCEPT "
+#
+# Rule 12 (global)
+pass quick inet6 proto icmp6 from any to any keep state label "RULE 12 -- ACCEPT "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet6 from any to any label "RULE 10000 -- DROP "
+
diff --git a/test/pf/firewall-ipv6-2.fw.orig b/test/pf/firewall-ipv6-2.fw.orig
new file mode 100755
index 000000000..d0642dea4
--- /dev/null
+++ b/test/pf/firewall-ipv6-2.fw.orig
@@ -0,0 +1,194 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:55 2011 PST by vadim
+#
+# files: * firewall-ipv6-2.fw pf.fw
+# files: firewall-ipv6-2.conf pf.conf
+#
+# Compiled for pf
+#
+# Combined ipv4/ipv6 policy ruleset
+
+# firewall-ipv6-2:Policy:5: error: Rule '5 (global)' shadows rule '7 (global)' below it
+# firewall-ipv6-2:Policy:5: error: Rule '5 (global)' shadows rule '7 (global)' below it
+# firewall-ipv6-2:Policy:7: warning: Changing rule direction due to self reference
+
+# firewall-ipv6-2:Policy:2: error: Rule '2 (global)' shadows rule '4 (global)' below it
+# firewall-ipv6-2:Policy:3: error: Rule '3 (global)' shadows rule '4 (global)' below it
+# firewall-ipv6-2:Policy:2: error: Rule '2 (global)' shadows rule '5 (global)' below it
+# firewall-ipv6-2:Policy:3: error: Rule '3 (global)' shadows rule '5 (global)' below it
+# firewall-ipv6-2:Policy:2: error: Rule '2 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-2:Policy:4: error: Rule '4 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-2:Policy:3: error: Rule '3 (global)' shadows rule '6 (global)' below it
+# firewall-ipv6-2:Policy:2: error: Rule '2 (global)' shadows rule '7 (global)' below it
+# firewall-ipv6-2:Policy:3: error: Rule '3 (global)' shadows rule '7 (global)' below it
+# firewall-ipv6-2:Policy:10: error: Rule '10 (global)' shadows rule '11 (global)' below it
+# firewall-ipv6-2:Policy:10: error: Rule '10 (global)' shadows rule '11 (global)' below it
+# firewall-ipv6-2:Policy:3: warning: Changing rule direction due to self reference
+# firewall-ipv6-2:Policy:6: warning: Changing rule direction due to self reference
+# firewall-ipv6-2:Policy:7: warning: Changing rule direction due to self reference
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+ $SYSCTL -w net.inet6.ip6.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ update_addresses_of_interface "eth0 fe80::21d:9ff:fe8b:8e94/64 1.1.1.1/0xffffff00" ""
+ update_addresses_of_interface "lo ::1/128 127.0.0.1/0xff000000" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:55 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/pf.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall.conf.orig b/test/pf/firewall.conf.orig
new file mode 100644
index 000000000..6fa85d9a2
--- /dev/null
+++ b/test/pf/firewall.conf.orig
@@ -0,0 +1,139 @@
+
+set limit { frags 4000, states 10000, src-nodes 1000, tables 1000, table-entries 1000000 }
+set timeout interval 15
+set timeout frag 40
+set timeout tcp.first 120
+set timeout tcp.opening 120
+set timeout tcp.established 86400
+set timeout tcp.closing 60
+set timeout tcp.finwait 60
+set timeout tcp.closed 30
+set timeout udp.first 10
+set timeout udp.single 10
+set timeout udp.multiple 10
+set timeout icmp.first 10
+set timeout icmp.error 10
+set timeout other.first 10
+set timeout other.single 10
+set timeout other.multiple 10
+set timeout adaptive.start 6000
+set timeout adaptive.end 12000
+
+#
+# Scrub rules
+#
+scrub in all fragment reassemble
+
+
+# Tables: (3)
+table { 192.168.1.11 , 192.168.1.12/30 }
+table { 192.168.1.1 , 222.222.222.222 }
+table { 211.11.11.11 , 211.22.22.22 }
+
+#
+# Rule 0 (NAT)
+nat on eth1 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 222.222.222.222
+nat on eth0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.1.1
+#
+# Rule 2 (NAT)
+rdr proto tcp from any to port 25 -> 192.168.1.10 port 25
+#
+# Rule 3 (NAT)
+rdr proto tcp from any to any port 80 -> 127.0.0.1 port 3128
+
+# Policy compiler errors and warnings:
+# firewall:Policy:18: error: Rule '18 (global)' shadows rule '21 (global)' below it
+# firewall:Policy:20: error: Rule '20 (global)' shadows rule '22 (global)' below it
+# firewall:Policy:20: error: Rule '20 (global)' shadows rule '23 (global)' below it
+# firewall:Policy:3: warning: Changing rule direction due to self reference
+# firewall:Policy:18: warning: Changing rule direction due to self reference
+#
+# Rule backup ssh access rule
+# backup ssh access rule
+pass in quick inet proto tcp from 192.168.1.100 to port 22 flags S/SA modulate state label "RULE 9998 - ACCEPT"
+#
+# Rule 0 (eth1)
+block in log quick on eth1 inet from any to fragment label "RULE 0 - DROP"
+#
+# Rule 1 (eth1)
+# Automatically generated rule blocking short fragments
+block in log quick on eth1 inet from any to any fragment label "RULE 1 - DROP"
+#
+# Rule 2 (eth1)
+# Automatically generated anti-spoofing rule
+block in log quick on eth1 inet from to any label "RULE 2 - DROP"
+block in log quick on eth1 inet from 192.168.1.0/24 to any label "RULE 2 - DROP"
+#
+# Rule 3 (eth0)
+# комментарий по-русски, Проверяем конвертацию в Utf-8
+# firewall:Policy:3: warning: Changing rule direction due to self reference
+pass in quick on eth0 inet proto udp from 192.168.1.0/24 to port 53 keep state label "RULE 3 - ACCEPT"
+#
+# Rule 4 (eth0)
+# code should go into INPUT chain with
+# address in destination for comparison
+block in log quick on eth0 inet proto udp from any to 192.168.1.255 port 53 label "RULE 4 - DROP"
+#
+# Rule 5 (global)
+block log quick inet proto tcp from any to any flags S/UAPRSF label "** RULE 5"
+block log quick inet proto tcp from any to any flags ARSF/UAPRSF label "** RULE 5"
+#
+# Rule 6 (global)
+block log quick inet from any to any label "RULE 6 - DROP"
+#
+# Rule 9 (global)
+# this rule is limited to 4 simultaneous
+# connections by rule options
+pass quick inet proto tcp from to 192.168.1.10 port 53 flags S/SA modulate state ( max 4 ) label "RULE 9 - ACCEPT"
+#
+# Rule 10 (global)
+pass quick inet proto tcp from 33.33.33.0/24 port 20 to 192.168.1.10 port >= 1024 flags S/SA modulate state label "RULE 10 - ACCEPT"
+pass quick inet proto tcp from 33.33.33.0/24 to 192.168.1.10 port { 113, 80, 25, 22, 540, 443, 143 } flags S/SA modulate state label "RULE 10 - ACCEPT"
+#
+# Rule 11 (global)
+pass quick inet proto tcp from any to 192.168.1.10 port { 9999 >< 11001, 6667, 3128, 113, 53, 21, 80, 119, 25, 22, 23, 540, 70, 13, 2105, 443, 143, 993, 6667, 543, 544, 389, 98, 3306, 2049, 110, 5432, 515, 26000, 512, 513, 514, 4321, 465, 1080, 111, 7100 } flags S/SA modulate state ( max-src-nodes 10, max-src-states 10, max-src-conn-rate 3/15 ) label "RULE 11 - ACCEPT"
+#
+# Rule 12 (global)
+pass quick inet proto tcp from any to port { 113, 80, 25, 22, 540, 443, 143, 3128 } flags S/SA modulate state ( max 10, max-src-nodes 75, max-src-states 2 ) label "RULE 12 - ACCEPT"
+#
+# Rule 14 (global)
+pass quick inet proto icmp from any to 192.168.1.0/24 icmp-type { 11 code 0 , 11 code 1 , 0 code 0 , 3 } keep state label "RULE 14 - ACCEPT"
+pass quick inet proto tcp from any to 192.168.1.0/24 port 3128 flags S/SA modulate state label "RULE 14 - ACCEPT"
+#
+# Rule 16 (global)
+pass quick inet from any to 192.168.1.10 keep state label "RULE 16 - ACCEPT"
+#
+# Rule 18 (global)
+# Automatically generated 'masquerading' rule
+# firewall:Policy:18: warning: Changing rule direction due to self reference
+pass out quick inet from to any keep state label "RULE 18 - ACCEPT"
+pass quick inet from 192.168.1.0/24 to any keep state label "RULE 18 - ACCEPT"
+#
+# Rule 19 (global)
+# test for bug 1111267: "CustomService should specify protocol and parameters for it"
+# Should generate "proto { tcp udp icmp gre}"
+pass quick inet proto {tcp udp icmp gre} from any to any keep state label "RULE 19 - ACCEPT"
+#
+# Rule 20 (global)
+# bug #2791950 "no way to generate "pass out" rule with no interface"
+# Interface field should be "any", direction "outbound"
+pass out quick inet from any to any keep state label "RULE 20 - ACCEPT"
+#
+# Rule 21 (global)
+# bug #2791950 "no way to generate "pass out" rule with no interface"
+#
+pass out quick inet from 192.168.1.0/24 to any keep state label "RULE 21 - ACCEPT"
+#
+# Rule 22 (global)
+# bug #2791950 "no way to generate "pass out" rule with no interface"
+#
+pass out quick inet from any to 192.168.1.0/24 keep state label "RULE 22 - ACCEPT"
+#
+# Rule 23 (global)
+# Automatically generated 'catch all' rule
+block log quick inet from any to any label "RULE 23 - DROP"
+#
+# Rule fallback rule
+# fallback rule
+block log quick inet from any to any label "RULE 10000 - DROP"
+
diff --git a/test/pf/firewall.fw.orig b/test/pf/firewall.fw.orig
new file mode 100755
index 000000000..555601fe6
--- /dev/null
+++ b/test/pf/firewall.fw.orig
@@ -0,0 +1,182 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:22 2011 PST by vadim
+#
+# files: * firewall.fw /etc/pf.fw
+# files: firewall.conf /etc/pf.conf
+#
+# Compiled for pf
+#
+# this is simple firewall with two interfaces. Test regular policy rules, including IP_fragments rule
+
+# firewall:Policy:18: error: Rule '18 (global)' shadows rule '21 (global)' below it
+# firewall:Policy:20: error: Rule '20 (global)' shadows rule '22 (global)' below it
+# firewall:Policy:20: error: Rule '20 (global)' shadows rule '23 (global)' below it
+# firewall:Policy:3: warning: Changing rule direction due to self reference
+# firewall:Policy:18: warning: Changing rule direction due to self reference
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.directed-broadcast=0
+ $SYSCTL -w net.inet.ip.forwarding=1
+
+ $SYSCTL -w net.inet.ip.sourceroute=0
+ $SYSCTL -w net.inet.ip.redirect=0
+}
+
+prolog_commands() {
+ :
+ echo 'This is prolog script'
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ update_addresses_of_interface "eth0 192.168.1.1/0xffffff00" ""
+ update_addresses_of_interface "eth1 222.222.222.222/0xffffff00" ""
+ update_addresses_of_interface "lo 127.0.0.1/0xff000000" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:22 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ /etc/pf.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall1.conf.orig b/test/pf/firewall1.conf.orig
new file mode 100644
index 000000000..3c635b65b
--- /dev/null
+++ b/test/pf/firewall1.conf.orig
@@ -0,0 +1,176 @@
+
+#
+# Prolog script
+#
+# prolog:
+# some pf command at the very top of the .conf file goes here
+
+
+
+#
+# End of prolog script
+#
+
+
+#
+# Scrub rules
+#
+scrub in all fragment reassemble
+
+
+# Tables: (6)
+table { 22.22.22.22 , 192.168.1.1 }
+table { 192.168.1.10 , 192.168.1.20 }
+table { 22.22.22.22 , 22.22.23.23 , 192.168.1.1 , 192.168.2.0/24 , 192.168.2.1 }
+table { 33.33.33.0/24 , 33.33.44.0/24 }
+table { 192.168.1.0/24 , 192.168.2.0/24 }
+table { 22.22.22.22 , 22.22.23.23 , 192.168.1.1 , 192.168.2.1 }
+
+#
+# Rule 0 (NAT)
+no nat proto {tcp udp icmp} from 192.168.1.0/24 to 192.168.2.0/24
+no rdr proto {tcp udp icmp} from 192.168.1.0/24 to 192.168.2.0/24
+#
+# Rule 1 (NAT)
+nat proto {tcp udp icmp} from 192.168.1.10 to any -> 22.22.22.23
+#
+# Rule 2 (NAT)
+nat proto {tcp udp icmp} from ! 192.168.1.0/24 to 200.200.200.200 -> 22.22.22.23
+#
+# Rule 3 (NAT)
+nat on eth0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.1.1
+nat on eth1 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 22.22.22.22
+nat on eth2 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.2.1
+nat on eth3 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 22.22.23.23
+#
+# Rule 4 (NAT)
+nat on eth1 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 22.22.22.22
+nat on eth3 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 22.22.23.23
+#
+# Rule 5 (NAT)
+# more examples
+# of NAT rules with
+# multiple objects in TSrc
+# in firewall3
+nat proto {tcp udp icmp} from 192.168.1.0/24 to any -> { 22.22.22.50 , 22.22.22.51 }
+#
+# Rule 6 (NAT)
+nat on eth0 proto {tcp udp icmp} from 192.168.1.0/24 to ! 192.168.2.0/24 -> 192.168.1.1
+nat on eth1 proto {tcp udp icmp} from 192.168.1.0/24 to ! 192.168.2.0/24 -> 22.22.22.22
+nat on eth2 proto {tcp udp icmp} from 192.168.1.0/24 to ! 192.168.2.0/24 -> 192.168.2.1
+nat on eth3 proto {tcp udp icmp} from 192.168.1.0/24 to ! 192.168.2.0/24 -> 22.22.23.23
+#
+# Rule 7 (NAT)
+nat on eth0 proto {tcp udp icmp} from 192.168.1.0/24 to ! -> 192.168.1.1
+nat on eth1 proto {tcp udp icmp} from 192.168.1.0/24 to ! -> 22.22.22.22
+nat on eth2 proto {tcp udp icmp} from 192.168.1.0/24 to ! -> 192.168.2.1
+nat on eth3 proto {tcp udp icmp} from 192.168.1.0/24 to ! -> 22.22.23.23
+#
+# Rule 8 (NAT)
+nat on eth0 proto {tcp udp icmp} from ! 192.168.2.0/24 to any -> 192.168.1.1
+nat on eth1 proto {tcp udp icmp} from ! 192.168.2.0/24 to any -> 22.22.22.22
+nat on eth2 proto {tcp udp icmp} from ! 192.168.2.0/24 to any -> 192.168.2.1
+nat on eth3 proto {tcp udp icmp} from ! 192.168.2.0/24 to any -> 22.22.23.23
+#
+# Rule 9 (NAT)
+rdr proto tcp from 192.168.1.0/24 to ! port 80 -> 127.0.0.1 port 3128
+#
+# Rule 10 (NAT)
+rdr proto tcp from 192.168.1.0/24 to ! 192.168.1.1 port 80 -> 127.0.0.1 port 3128
+#
+# Rule 11 (NAT)
+rdr proto tcp from to ! port 80 -> 127.0.0.1 port 3128
+#
+# Rule 12 (NAT)
+rdr proto tcp from ! to port 80 -> 127.0.0.1 port 3128
+#
+# Rule 13 (NAT)
+rdr proto tcp from ! 192.168.1.10 to any port 80 -> 127.0.0.1 port 3128
+#
+# Rule 14 (NAT)
+rdr on eth1 proto tcp from to 22.22.22.22 port 80 -> 192.168.1.10 port 80
+
+# Policy compiler errors and warnings:
+# firewall1:Policy:10: warning: Changing rule direction due to self reference
+# firewall1:Policy:18: warning: Changing rule direction due to self reference
+#
+# Rule 0 (eth0)
+block log quick on eth0 inet proto icmp from to !
+block log quick on eth0 inet proto 50 from to !
+#
+# Rule 1 (eth0)
+block quick on eth0 inet proto icmp from to !
+block quick on eth0 inet proto 50 from to !
+#
+# Rule 2 (eth1)
+# Anti-spoofing rule
+block in log quick on eth1 inet from to any
+block in log quick on eth1 inet from 192.168.1.0/24 to any
+#
+# Rule 3 (eth1)
+# Anti-spoofing rule
+block out log quick on eth1 inet from ! 192.168.1.0/24 to any
+#
+# Rule 4 (eth1)
+# testing rule shading: this rule is not
+# shaded by rule #1
+pass in quick on eth1 inet proto icmp from any to any icmp-type 8 code 0 keep state
+#
+# Rule 5 (global)
+block log quick inet proto tcp from any to any flags S/UAPRSF
+#
+# Rule 7 (global)
+# hostF has the same IP address as firewal.
+pass log quick inet proto icmp from any to 192.168.1.1 icmp-type 8 code 0 keep state
+#
+# Rule 8 (global)
+# testing negation in the policy rule
+block log quick inet proto icmp from ! 192.168.1.10 to any icmp-type 3
+#
+# Rule 9 (global)
+# testing negation in the policy rule
+block log quick inet proto icmp from ! to any icmp-type 3
+#
+# Rule 10 (global)
+# this rule is shaded by rule above.
+# firewall1:Policy:10: warning: Changing rule direction due to self reference
+block in log quick inet proto icmp from ! to icmp-type 3
+#
+# Rule 11 (global)
+# this rule shades rule below
+block log quick inet from ! to 192.168.1.0/24
+#
+# Rule 12 (global)
+block log quick inet from to !
+#
+# Rule 13 (global)
+# testing negation in the policy rule
+block return-icmp log quick inet from 192.168.1.10 to any
+#
+# Rule 16 (global)
+block log quick inet proto icmp from to !
+block log quick inet proto 50 from to !
+#
+# Rule 17 (global)
+# 'masquerading' rule
+pass quick inet from 192.168.1.0/24 to any keep state
+#
+# Rule 18 (global)
+# firewall1:Policy:18: warning: Changing rule direction due to self reference
+pass in quick inet proto tcp from any to port 3128 keep state
+#
+# Rule 19 (eth0)
+# rule from http://www.benzedrine.cx/transquid.html
+# Used to permit connections to transparent
+# squid proxy. Should be "in $int_if" but destination
+# is loopback interface
+pass in quick on eth0 inet proto tcp from any to 127.0.0.1 port 3128 keep state
+#
+# Rule 20 (global)
+# 'catch all' rule
+block log quick inet from any to any
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any
+
diff --git a/test/pf/firewall1.fw.orig b/test/pf/firewall1.fw.orig
new file mode 100755
index 000000000..e71a0a69d
--- /dev/null
+++ b/test/pf/firewall1.fw.orig
@@ -0,0 +1,91 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:23 2011 PST by vadim
+#
+# files: * firewall1.fw
+# files: firewall1.conf
+#
+# Compiled for pf
+#
+# this object is used to test all kinds of negation in policy rules
+# Also using interface policy on eth1 to test specific case with negation and
+# rule shading depection
+
+# firewall1:Policy:10: warning: Changing rule direction due to self reference
+# firewall1:Policy:18: warning: Changing rule direction due to self reference
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:23 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall1.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall10-1.conf.orig b/test/pf/firewall10-1.conf.orig
new file mode 100644
index 000000000..ad54c4c96
--- /dev/null
+++ b/test/pf/firewall10-1.conf.orig
@@ -0,0 +1,33 @@
+
+
+#
+# Scrub rules
+#
+scrub in all fragment reassemble
+
+#
+# Rule 1 (NAT)
+nat on eth0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.1.1
+
+#
+# Rule backup ssh access rule
+# backup ssh access rule
+pass in quick inet proto tcp from 192.168.1.100 to 192.168.1.1 port 22 flags S/SA keep state
+#
+# Rule 0 (eth0)
+pass in quick on eth0 inet proto tcp from 192.168.1.0/24 to any port { 22, 80 } flags S/SA keep state
+#
+# Rule 1 (lo0)
+pass quick on lo0 inet from any to any
+#
+# Rule 2 (enc0)
+# via ipsec
+pass quick on enc0 inet proto tcp from 33.33.33.0/24 to 192.168.1.0/24 port 80 flags S/SA keep state
+#
+# Rule 3 (global)
+block log quick inet from any to any
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any
+
diff --git a/test/pf/firewall10-1.fw.orig b/test/pf/firewall10-1.fw.orig
new file mode 100755
index 000000000..76118e6ae
--- /dev/null
+++ b/test/pf/firewall10-1.fw.orig
@@ -0,0 +1,89 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:23 2011 PST by vadim
+#
+# files: * firewall10-1.fw
+# files: firewall10-1.conf
+#
+# Compiled for pf 3.x
+#
+# PF 3.x, testing
+# "flags S/SA keep state"
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:23 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall10-1.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall10-2.conf.orig b/test/pf/firewall10-2.conf.orig
new file mode 100644
index 000000000..67dbc69ae
--- /dev/null
+++ b/test/pf/firewall10-2.conf.orig
@@ -0,0 +1,34 @@
+
+set skip on lo0
+
+#
+# Scrub rules
+#
+scrub in all fragment reassemble
+
+#
+# Rule 1 (NAT)
+nat on eth0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.1.1
+
+#
+# Rule backup ssh access rule
+# backup ssh access rule
+pass in quick inet proto tcp from 192.168.1.100 to 192.168.1.1 port 22 modulate state
+#
+# Rule 0 (eth0)
+pass in quick on eth0 inet proto tcp from 192.168.1.0/24 to any port { 22, 80 } modulate state
+#
+# Rule 1 (lo0)
+pass quick on lo0 inet from any to any no state
+#
+# Rule 2 (enc0)
+# via ipsec
+pass quick on enc0 inet proto tcp from 33.33.33.0/24 to 192.168.1.0/24 port 80 keep state modulate state
+#
+# Rule 3 (global)
+block log quick inet from any to any no state
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any no state
+
diff --git a/test/pf/firewall10-2.fw.orig b/test/pf/firewall10-2.fw.orig
new file mode 100755
index 000000000..a2b90c0a7
--- /dev/null
+++ b/test/pf/firewall10-2.fw.orig
@@ -0,0 +1,91 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:24 2011 PST by vadim
+#
+# files: * firewall10-2.fw
+# files: firewall10-2.conf
+#
+# Compiled for pf 4.x
+#
+# PF 4.x, testing
+# "flags S/SA keep state"
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:24 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall10-2.conf || exit 1
+
+
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall10-3.conf.orig b/test/pf/firewall10-3.conf.orig
new file mode 100644
index 000000000..8fd0d4815
--- /dev/null
+++ b/test/pf/firewall10-3.conf.orig
@@ -0,0 +1,33 @@
+
+
+#
+# Scrub rules
+#
+scrub in all fragment reassemble
+
+#
+# Rule 1 (NAT)
+nat on eth0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.1.1
+
+#
+# Rule backup ssh access rule
+# backup ssh access rule
+pass in quick inet proto tcp from 192.168.1.100 to 192.168.1.1 port 22 keep state
+#
+# Rule 0 (eth0)
+pass in quick on eth0 inet proto tcp from 192.168.1.0/24 to any port { 22, 80 } keep state
+#
+# Rule 1 (lo0)
+pass quick on lo0 inet from any to any
+#
+# Rule 2 (enc0)
+# via ipsec
+pass quick on enc0 inet proto tcp from 33.33.33.0/24 to 192.168.1.0/24 port 80 keep state
+#
+# Rule 3 (global)
+block log quick inet from any to any
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any
+
diff --git a/test/pf/firewall10-3.fw.orig b/test/pf/firewall10-3.fw.orig
new file mode 100755
index 000000000..57475f83f
--- /dev/null
+++ b/test/pf/firewall10-3.fw.orig
@@ -0,0 +1,91 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:25 2011 PST by vadim
+#
+# files: * firewall10-3.fw
+# files: firewall10-3.conf
+#
+# Compiled for pf 3.x
+#
+# PF 3.x, testing
+# "flags S/SA keep state"
+# "Accept tcp sessions opened
+# prior to restart" ON
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:25 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall10-3.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall10-4.conf.orig b/test/pf/firewall10-4.conf.orig
new file mode 100644
index 000000000..4fa13d7ce
--- /dev/null
+++ b/test/pf/firewall10-4.conf.orig
@@ -0,0 +1,34 @@
+
+set skip on lo0
+
+#
+# Scrub rules
+#
+scrub in all fragment reassemble
+
+#
+# Rule 1 (NAT)
+nat on eth0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.1.1
+
+#
+# Rule backup ssh access rule
+# backup ssh access rule
+pass in quick inet proto tcp from 192.168.1.100 to 192.168.1.1 port 22 flags any
+#
+# Rule 0 (eth0)
+pass in quick on eth0 inet proto tcp from 192.168.1.0/24 to any port { 22, 80 } flags any
+#
+# Rule 1 (lo0)
+pass quick on lo0 inet from any to any no state
+#
+# Rule 2 (enc0)
+# via ipsec
+pass quick on enc0 inet proto tcp from 33.33.33.0/24 to 192.168.1.0/24 port 80 flags any keep state
+#
+# Rule 3 (global)
+block log quick inet from any to any no state
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any no state
+
diff --git a/test/pf/firewall10-4.fw.orig b/test/pf/firewall10-4.fw.orig
new file mode 100755
index 000000000..71a21f617
--- /dev/null
+++ b/test/pf/firewall10-4.fw.orig
@@ -0,0 +1,93 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:26 2011 PST by vadim
+#
+# files: * firewall10-4.fw
+# files: firewall10-4.conf
+#
+# Compiled for pf 4.x
+#
+# PF 4.x, testing
+# "flags S/SA keep state"
+# "Accept tcp sessions opened
+# prior to restart" is ON
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:26 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall10-4.conf || exit 1
+
+
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall10-5.conf.orig b/test/pf/firewall10-5.conf.orig
new file mode 100644
index 000000000..f69c588ce
--- /dev/null
+++ b/test/pf/firewall10-5.conf.orig
@@ -0,0 +1,41 @@
+
+
+#
+# Scrub rules
+#
+scrub in all fragment reassemble
+
+#
+# Rule 1 (NAT)
+nat on eth0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.1.1
+
+#
+# Rule backup ssh access rule
+# backup ssh access rule
+pass in quick inet proto tcp from 192.168.1.100 to 192.168.1.1 port 22 keep state
+#
+# Rule 0 (enc0)
+# This adds "pass out ... keep state"
+# rule that compiler 2.1.14
+# does not add automatically for pf 3.x
+# Note that checkbox "add 'keep state'"
+# is on in options
+pass out quick on enc0 inet from any to any keep state
+#
+# Rule 1 (eth0)
+pass in quick on eth0 inet proto tcp from 192.168.1.0/24 to any port { 22, 80 } keep state
+#
+# Rule 2 (lo0)
+pass quick on lo0 inet from any to any
+#
+# Rule 3 (enc0)
+# via ipsec
+pass quick on enc0 inet proto tcp from 33.33.33.0/24 to 192.168.1.0/24 port 80 keep state
+#
+# Rule 4 (global)
+block log quick inet from any to any
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any
+
diff --git a/test/pf/firewall10-5.fw.orig b/test/pf/firewall10-5.fw.orig
new file mode 100755
index 000000000..0cc65f511
--- /dev/null
+++ b/test/pf/firewall10-5.fw.orig
@@ -0,0 +1,92 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:26 2011 PST by vadim
+#
+# files: * firewall10-5.fw
+# files: firewall10-5.conf
+#
+# Compiled for pf 3.x
+#
+# PF 3.x, testing
+# "flags S/SA keep state"
+# "Accept tcp sessions opened
+# prior to restart" ON
+# Using "pass all outgoing"
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:26 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall10-5.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall10-6.conf.orig b/test/pf/firewall10-6.conf.orig
new file mode 100644
index 000000000..4fa13d7ce
--- /dev/null
+++ b/test/pf/firewall10-6.conf.orig
@@ -0,0 +1,34 @@
+
+set skip on lo0
+
+#
+# Scrub rules
+#
+scrub in all fragment reassemble
+
+#
+# Rule 1 (NAT)
+nat on eth0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.1.1
+
+#
+# Rule backup ssh access rule
+# backup ssh access rule
+pass in quick inet proto tcp from 192.168.1.100 to 192.168.1.1 port 22 flags any
+#
+# Rule 0 (eth0)
+pass in quick on eth0 inet proto tcp from 192.168.1.0/24 to any port { 22, 80 } flags any
+#
+# Rule 1 (lo0)
+pass quick on lo0 inet from any to any no state
+#
+# Rule 2 (enc0)
+# via ipsec
+pass quick on enc0 inet proto tcp from 33.33.33.0/24 to 192.168.1.0/24 port 80 flags any keep state
+#
+# Rule 3 (global)
+block log quick inet from any to any no state
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any no state
+
diff --git a/test/pf/firewall10-6.fw.orig b/test/pf/firewall10-6.fw.orig
new file mode 100755
index 000000000..5f7263774
--- /dev/null
+++ b/test/pf/firewall10-6.fw.orig
@@ -0,0 +1,94 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:27 2011 PST by vadim
+#
+# files: * firewall10-6.fw
+# files: firewall10-6.conf
+#
+# Compiled for pf 4.x
+#
+# PF 4.x, testing
+# "flags S/SA keep state"
+# "Accept tcp sessions opened
+# prior to restart" is ON
+# Using "pass all outgoing"
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:27 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall10-6.conf || exit 1
+
+
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall11.conf.orig b/test/pf/firewall11.conf.orig
new file mode 100644
index 000000000..e7800d61a
--- /dev/null
+++ b/test/pf/firewall11.conf.orig
@@ -0,0 +1,31 @@
+
+
+
+
+# Tables: (3)
+table { ppp0 , 33.33.33.33 , 192.168.1.1 }
+table { 192.168.1.10 , 192.168.1.20 }
+table { 192.168.1.0/24 , 192.168.2.0/24 }
+
+# Policy compiler errors and warnings:
+# firewall11:Policy:0: warning: Changing rule direction due to self reference
+# firewall11:Policy:1: warning: Changing rule direction due to self reference
+#
+# Rule 0 (global)
+# firewall11:Policy:0: warning: Changing rule direction due to self reference
+pass in quick inet proto tcp from to port 22 flags S/SA keep state
+#
+# Rule 1 (global)
+# firewall11:Policy:1: warning: Changing rule direction due to self reference
+block in quick inet from any to
+#
+# Rule 2 (global)
+pass quick inet from to any keep state
+#
+# Rule 3 (global)
+block quick inet from any to any
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any
+
diff --git a/test/pf/firewall11.fw.orig b/test/pf/firewall11.fw.orig
new file mode 100755
index 000000000..eef5ebdff
--- /dev/null
+++ b/test/pf/firewall11.fw.orig
@@ -0,0 +1,92 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:28 2011 PST by vadim
+#
+# files: * firewall11.fw
+# files: firewall11.conf
+#
+# Compiled for pf
+#
+# example to illustrate access to the firewall limited to only few
+# source addresses. Since in PF firewall is always part of "any",
+# have to explcitly add a rule to block ssh to the firewall
+# from other sources.
+
+# firewall11:Policy:0: warning: Changing rule direction due to self reference
+# firewall11:Policy:1: warning: Changing rule direction due to self reference
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/usr/sbin/pfctl"
+SYSCTL="/usr/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:28 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall11.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall12.conf.orig b/test/pf/firewall12.conf.orig
new file mode 100644
index 000000000..c6f26b66d
--- /dev/null
+++ b/test/pf/firewall12.conf.orig
@@ -0,0 +1,60 @@
+
+
+
+
+# Tables: (1)
+table { 22.22.22.22 , 22.22.23.22 }
+
+#
+# Rule 4 (NAT)
+rdr proto tcp from any to port 80 -> 127.0.0.1 port 8080
+#
+# Rule 7 (NAT)
+nat on en0 proto udp from any port 6767 to any -> 22.22.22.22 port 67
+nat on en1 proto udp from any port 6767 to any -> 22.22.23.22 port 67
+#
+# Rule 9 (NAT)
+rdr proto tcp from any to any port 80 -> 127.0.0.1 port 8080
+#
+# Rule 10 (NAT)
+# SDNAT
+rdr proto tcp from any to port 22 -> 192.168.1.10 port 22
+nat on en0 proto tcp from any to 192.168.1.10 port 22 -> 22.22.22.22
+nat on en1 proto tcp from any to 192.168.1.10 port 22 -> 22.22.23.22
+#
+# Rule 11 (NAT)
+# SDNAT with source port
+rdr proto udp from any port 123 to -> 192.168.1.10
+nat on en0 proto udp from any port 123 to 192.168.1.10 -> 22.22.22.22 port 5050
+nat on en1 proto udp from any port 123 to 192.168.1.10 -> 22.22.23.22 port 5050
+#
+# Rule 12 (NAT)
+# SDNAT with dest port
+rdr proto udp from 192.168.1.0/24 to any port 53 -> 192.168.1.10 port 1053
+nat on en0 proto udp from 192.168.1.0/24 to 192.168.1.10 port 1053 -> 22.22.22.22
+nat on en1 proto udp from 192.168.1.0/24 to 192.168.1.10 port 1053 -> 22.22.23.22
+#
+# Rule 13 (NAT)
+# SDNAT
+# translate src and dst addresses
+# and src and dst ports
+rdr proto udp from 192.168.1.0/24 port 1024:65535 to any port 53 -> 192.168.1.10 port 1053
+nat on en0 proto udp from 192.168.1.0/24 to 192.168.1.10 port 1053 -> 22.22.22.22 port 32767:65535
+nat on en1 proto udp from 192.168.1.0/24 to 192.168.1.10 port 1053 -> 22.22.23.22 port 32767:65535
+#
+# Rule 14 (NAT)
+# Matches destination port, translates source port
+nat on en0 proto udp from 192.168.1.0/24 to any port 53 -> 22.22.22.22 port 5050
+nat on en1 proto udp from 192.168.1.0/24 to any port 53 -> 22.22.23.22 port 5050
+
+#
+# Rule 0 (global)
+pass quick inet proto tcp from any to 22.22.22.23 port 8080 flags any label "RULE 0 -- ACCEPT "
+#
+# Rule 1 (global)
+block log quick inet from any to any no state label "RULE 1 -- DROP "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any no state label "RULE 10000 -- DROP "
+
diff --git a/test/pf/firewall12.fw.orig b/test/pf/firewall12.fw.orig
new file mode 100755
index 000000000..8861bf934
--- /dev/null
+++ b/test/pf/firewall12.fw.orig
@@ -0,0 +1,176 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:29 2011 PST by vadim
+#
+# files: * firewall12.fw
+# files: firewall12.conf
+#
+# Compiled for pf 4.x
+#
+# This firewall does not do NAT for addresses, but translates port for a server
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ update_addresses_of_interface "en0 22.22.22.22/0xffffff00" ""
+ update_addresses_of_interface "en1 22.22.23.22/0xffffff00" ""
+ update_addresses_of_interface "lo0 127.0.0.1/0xff000000" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:29 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall12.conf || exit 1
+
+
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall13.conf.orig b/test/pf/firewall13.conf.orig
new file mode 100644
index 000000000..e294f3539
--- /dev/null
+++ b/test/pf/firewall13.conf.orig
@@ -0,0 +1,33 @@
+
+
+
+# NAT compiler errors and warnings:
+# firewall13:NAT:0: warning: Empty group or address table object 'egroup'
+# firewall13:NAT:0: warning: After removal of all empty groups and address table objects rule element OSrc becomes 'any' in the rule 0 (NAT)
+# Dropping rule 0 (NAT) because option 'Ignore rules with empty groups' is in effect
+# firewall13:NAT:1: warning: Empty group or address table object 'egroup'
+# firewall13:NAT:2: warning: Empty group or address table object 'sgroup'
+# firewall13:NAT:2: warning: After removal of all empty groups and address table objects rule element OSrv becomes 'any' in the rule 2 (NAT)
+# Dropping rule 2 (NAT) because option 'Ignore rules with empty groups' is in effect
+#
+# Rule 1 (NAT)
+# firewall13:NAT:1: warning: Empty group or address table object 'egroup'
+rdr proto tcp from 200.200.200.200 to 22.22.22.23 port 6667 -> 192.168.1.10 port 6667
+
+# Policy compiler errors and warnings:
+# firewall13:Policy:0: warning: Empty group or address table object 'egroup2'
+# firewall13:Policy:1: warning: Empty group or address table object 'sgroup'
+# firewall13:Policy:1: warning: After removal of all empty groups and address table objects rule element Srv becomes 'any' in the rule 1 (global)
+# Dropping rule 1 (global) because option 'Ignore rules with empty groups' is in effect
+#
+# Rule 0 (global)
+# firewall13:Policy:0: warning: Empty group or address table object 'egroup2'
+pass quick inet from 200.200.200.200 to 192.168.1.10 keep state
+#
+# Rule 2 (global)
+block log quick inet from any to any
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any
+
diff --git a/test/pf/firewall13.fw.orig b/test/pf/firewall13.fw.orig
new file mode 100755
index 000000000..578b3d243
--- /dev/null
+++ b/test/pf/firewall13.fw.orig
@@ -0,0 +1,103 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:29 2011 PST by vadim
+#
+# files: * firewall13.fw
+# files: firewall13.conf
+#
+# Compiled for pf
+#
+# testing detection of empty groups
+
+# firewall13:NAT:0: warning: Empty group or address table object 'egroup'
+# firewall13:NAT:0: warning: After removal of all empty groups and address table objects rule element OSrc becomes 'any' in the rule 0 (NAT)
+# Dropping rule 0 (NAT) because option 'Ignore rules with empty groups' is in effect
+# firewall13:NAT:1: warning: Empty group or address table object 'egroup'
+# firewall13:NAT:2: warning: Empty group or address table object 'sgroup'
+# firewall13:NAT:2: warning: After removal of all empty groups and address table objects rule element OSrv becomes 'any' in the rule 2 (NAT)
+# Dropping rule 2 (NAT) because option 'Ignore rules with empty groups' is in effect
+
+# firewall13:Policy:0: warning: Empty group or address table object 'egroup2'
+# firewall13:Policy:1: warning: Empty group or address table object 'sgroup'
+# firewall13:Policy:1: warning: After removal of all empty groups and address table objects rule element Srv becomes 'any' in the rule 1 (global)
+# Dropping rule 1 (global) because option 'Ignore rules with empty groups' is in effect
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.directed-broadcast=0
+ $SYSCTL -w net.inet.ip.forwarding=1
+
+ $SYSCTL -w net.inet.ip.sourceroute=0
+ $SYSCTL -w net.inet.ip.redirect=0
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:29 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall13.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall14-1.conf.orig b/test/pf/firewall14-1.conf.orig
new file mode 100644
index 000000000..6a500bc99
--- /dev/null
+++ b/test/pf/firewall14-1.conf.orig
@@ -0,0 +1,24 @@
+
+
+#
+# Scrub rules
+#
+match in all scrub (reassemble tcp no-df )
+match out all scrub (random-id min-ttl 64 max-mss 1460)
+
+
+# Tables: (1)
+table { 10.1.1.50 , 10.3.14.50 , 10.100.101.1 , 10.100.103.1 }
+
+#
+# Rule backup ssh access rule
+# backup ssh access rule
+pass in quick inet proto tcp from 10.3.14.30 to port 22 label "RULE 9998 -- ACCEPT "
+#
+# Rule 0 (global)
+block log quick inet from any to any no state label "RULE 0 -- DROP "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any no state label "RULE 10000 -- DROP "
+
diff --git a/test/pf/firewall14-1.fw.orig b/test/pf/firewall14-1.fw.orig
new file mode 100755
index 000000000..57013044e
--- /dev/null
+++ b/test/pf/firewall14-1.fw.orig
@@ -0,0 +1,261 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:31 2011 PST by vadim
+#
+# files: * firewall14-1.fw
+# files: firewall14-1.conf
+#
+# Compiled for pf 4.6
+#
+# Testing scrub rules format PF 4.6
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+missing_vlan() {
+ vlan=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $vlan
+ subint=$1
+ parent=$2
+ IFS=$oldIFS
+
+ vlan_id=$(echo $subint | sed 's/vlan//')
+ test "$cmd" = "add" && {
+ echo "# Adding VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $IFCONFIG $subint vlan $vlan_id vlandev $parent
+ $FWBDEBUG $IFCONFIG $subint up
+ }
+ test "$cmd" = "rem" && {
+ echo "# Removing VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $IFCONFIG $subint vlan $vlan_id -vlandev
+ $FWBDEBUG $IFCONFIG $subint destroy
+ }
+}
+
+parse_fwb_vlans() {
+ set $1
+ vlan_parent_interface=$1
+ shift
+
+ FWB_VLANS=$(
+ for subint in $*; do
+ echo "${subint}@$vlan_parent_interface"
+ done | sort
+ )
+ echo $FWB_VLANS
+}
+
+parse_current_vlans() {
+ vlan_parent_interface=$1
+ $IFCONFIG -A | grep 'vlan: ' | sed 's/priority:.*parent interface://' | \
+ while read x vlan_id parent
+ do
+ test "$parent" = "$vlan_parent_interface" && echo "vlan$vlan_id@$parent"
+ done | sort
+}
+
+update_vlans_of_interface() {
+ args="$1"
+ set $1
+ vlan_parent_interface=$1
+
+ FWB_VLANS=$(parse_fwb_vlans "$args")
+ CURRENT_VLANS=$(parse_current_vlans $vlan_parent_interface)
+
+ $IFCONFIG $vlan_parent_interface up
+ diff_intf missing_vlan "$FWB_VLANS" "$CURRENT_VLANS" add
+ diff_intf missing_vlan "$CURRENT_VLANS" "$FWB_VLANS" rem
+}
+
+sync_vlan_interfaces() {
+ $IFCONFIG -A | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ii=ignored_arr[a]":"; ignored_dict[ii]=1;}
+ }
+ ($1 ~ /^vlan[0-9]/ && !($1 in ignored_dict)) {print $1;}' | sed 's/://' |\
+ while read intf; do
+ echo "# Deleting vlan interface $intf"
+ $FWBDEBUG $IFCONFIG $intf destroy
+ done
+
+ for intf in $*; do
+ $IFCONFIG $intf >/dev/null 2>&1 || {
+ echo "# Creating vlan interface $intf"
+ $FWBDEBUG $IFCONFIG $intf create
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ sync_vlan_interfaces vlan101 vlan103
+ update_vlans_of_interface "pcn0 "
+ update_vlans_of_interface "em0 vlan101 vlan103 "
+
+
+ update_addresses_of_interface "em0 10.1.1.50/0xffffff00" ""
+ update_addresses_of_interface "pcn0 10.3.14.50/0xffffff00" ""
+ update_addresses_of_interface "vlan101 10.100.101.1/0xffffff00" ""
+ update_addresses_of_interface "vlan103 10.100.103.1/0xffffff00" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:31 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall14-1.conf || exit 1
+
+
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall14.conf.orig b/test/pf/firewall14.conf.orig
new file mode 100644
index 000000000..519d99379
--- /dev/null
+++ b/test/pf/firewall14.conf.orig
@@ -0,0 +1,24 @@
+
+
+#
+# Scrub rules
+#
+scrub in all fragment reassemble no-df
+scrub out all random-id min-ttl 64 max-mss 1460
+
+
+# Tables: (1)
+table { 10.1.1.50 , 10.3.14.50 , 10.100.101.1 , 10.100.103.1 }
+
+#
+# Rule backup ssh access rule
+# backup ssh access rule
+pass in quick inet proto tcp from 10.3.14.30 to port 22 label "RULE 9998 -- ACCEPT "
+#
+# Rule 0 (global)
+block log quick inet from any to any no state label "RULE 0 -- DROP "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any no state label "RULE 10000 -- DROP "
+
diff --git a/test/pf/firewall14.fw.orig b/test/pf/firewall14.fw.orig
new file mode 100755
index 000000000..fd99054e7
--- /dev/null
+++ b/test/pf/firewall14.fw.orig
@@ -0,0 +1,261 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:30 2011 PST by vadim
+#
+# files: * firewall14.fw
+# files: firewall14.conf
+#
+# Compiled for pf 4.0
+#
+# Testing scrub rules format PF < 4.6
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+missing_vlan() {
+ vlan=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $vlan
+ subint=$1
+ parent=$2
+ IFS=$oldIFS
+
+ vlan_id=$(echo $subint | sed 's/vlan//')
+ test "$cmd" = "add" && {
+ echo "# Adding VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $IFCONFIG $subint vlan $vlan_id vlandev $parent
+ $FWBDEBUG $IFCONFIG $subint up
+ }
+ test "$cmd" = "rem" && {
+ echo "# Removing VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $IFCONFIG $subint vlan $vlan_id -vlandev
+ $FWBDEBUG $IFCONFIG $subint destroy
+ }
+}
+
+parse_fwb_vlans() {
+ set $1
+ vlan_parent_interface=$1
+ shift
+
+ FWB_VLANS=$(
+ for subint in $*; do
+ echo "${subint}@$vlan_parent_interface"
+ done | sort
+ )
+ echo $FWB_VLANS
+}
+
+parse_current_vlans() {
+ vlan_parent_interface=$1
+ $IFCONFIG -A | grep 'vlan: ' | sed 's/priority:.*parent interface://' | \
+ while read x vlan_id parent
+ do
+ test "$parent" = "$vlan_parent_interface" && echo "vlan$vlan_id@$parent"
+ done | sort
+}
+
+update_vlans_of_interface() {
+ args="$1"
+ set $1
+ vlan_parent_interface=$1
+
+ FWB_VLANS=$(parse_fwb_vlans "$args")
+ CURRENT_VLANS=$(parse_current_vlans $vlan_parent_interface)
+
+ $IFCONFIG $vlan_parent_interface up
+ diff_intf missing_vlan "$FWB_VLANS" "$CURRENT_VLANS" add
+ diff_intf missing_vlan "$CURRENT_VLANS" "$FWB_VLANS" rem
+}
+
+sync_vlan_interfaces() {
+ $IFCONFIG -A | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ii=ignored_arr[a]":"; ignored_dict[ii]=1;}
+ }
+ ($1 ~ /^vlan[0-9]/ && !($1 in ignored_dict)) {print $1;}' | sed 's/://' |\
+ while read intf; do
+ echo "# Deleting vlan interface $intf"
+ $FWBDEBUG $IFCONFIG $intf destroy
+ done
+
+ for intf in $*; do
+ $IFCONFIG $intf >/dev/null 2>&1 || {
+ echo "# Creating vlan interface $intf"
+ $FWBDEBUG $IFCONFIG $intf create
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ sync_vlan_interfaces vlan101 vlan103
+ update_vlans_of_interface "pcn0 "
+ update_vlans_of_interface "em0 vlan101 vlan103 "
+
+
+ update_addresses_of_interface "em0 10.1.1.50/0xffffff00" ""
+ update_addresses_of_interface "pcn0 10.3.14.50/0xffffff00" ""
+ update_addresses_of_interface "vlan101 10.100.101.1/0xffffff00" ""
+ update_addresses_of_interface "vlan103 10.100.103.1/0xffffff00" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:30 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall14.conf || exit 1
+
+
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall2-1.conf.orig b/test/pf/firewall2-1.conf.orig
new file mode 100644
index 000000000..7e762ae10
--- /dev/null
+++ b/test/pf/firewall2-1.conf.orig
@@ -0,0 +1,76 @@
+
+set limit { frags 5000, states 10000 }
+set optimization aggressive
+set timeout tcp.first 5
+set timeout tcp.opening 5
+set timeout tcp.established 10
+
+
+#
+# Prolog script
+#
+# prolog
+# prolog commands go after set commands
+
+#
+# End of prolog script
+#
+#
+# Scrub rules
+#
+scrub in all fragment reassemble no-df
+scrub out all random-id min-ttl 32 max-mss 1460
+
+
+# Tables: (1)
+table { 22.22.22.22 , 192.168.1.1 , 192.168.2.1 }
+
+# NAT compiler errors and warnings:
+# firewall2-1:NAT:0: error: There should be no more than one object in original destination
+# firewall2-1:NAT:1: error: Negation in original service is not supported.
+# firewall2-1:NAT:2: error: Can not translate 'any' into a specific service.
+# firewall2-1:NAT:3: error: Can not use negation in translated source.
+# firewall2-1:NAT:4: error: Can not use negation in translated destination.
+# firewall2-1:NAT:5: error: Can not use negation in translated service.
+# firewall2-1:NAT:6: error: Translated service should be 'Original' or should contain single object.
+# firewall2-1:NAT:7: error: Translated service should be 'Original' or should contain single object.
+# firewall2-1:NAT:9: error: Can not use unnumbered interface in Translated Source of a Source translation rule.
+# firewall2-1:NAT:12: error: Can not use network or address range object in translated destination.
+# firewall2-1:NAT:13: error: Can not use network or address range object in translated destination.
+# firewall2-1:NAT:15: error: Can not use network or address range object in translated destination.
+# firewall2-1:NAT:16: warning: Translated Src, Dst and Srv are ignored in the NAT rule with action 'Branch'
+# firewall2-1:NAT:16: error: Action 'Branch' needs NAT rule set to point to
+# firewall2-1:NAT:17: warning: Translated Src, Dst and Srv are ignored in the NAT rule with action 'Branch'
+#
+# Rule 8 (NAT)
+no nat proto tcp from 192.168.1.0/24 to any
+no rdr proto tcp from 192.168.1.0/24 to any
+#
+# Rule 10 (NAT)
+no nat proto tcp from any to 22.22.22.22
+no rdr proto tcp from any to 22.22.22.22
+#
+# Rule 11 (NAT)
+rdr proto tcp from any to 22.22.22.22 port 1080 -> { 192.168.1.10 , 192.168.1.20 } port 1080
+#
+# Rule 14 (NAT)
+nat proto {tcp udp icmp} from 192.168.1.0/24 to any -> 22.22.22.0/28
+#
+# Rule 17 (NAT)
+# firewall2-1:NAT:17: warning: Translated Src, Dst and Srv are ignored in the NAT rule with action 'Branch'
+nat-anchor "NAT" proto tcp from 192.168.1.0/24 to any port 1080
+rdr-anchor "NAT" proto tcp from 192.168.1.0/24 to any port 1080
+
+#
+# Rule backup ssh access rule
+# backup ssh access rule
+pass in quick inet proto tcp from 192.168.1.100 to port 22 keep state label "RULE 9998 - ACCEPT **"
+#
+# Rule 0 (global)
+# 'catch all' rule
+block log quick inet from any to any label "RULE 0 - DROP **"
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any label "RULE 10000 - DROP **"
+
diff --git a/test/pf/firewall2-1.fw.orig b/test/pf/firewall2-1.fw.orig
new file mode 100755
index 000000000..6ee1a1829
--- /dev/null
+++ b/test/pf/firewall2-1.fw.orig
@@ -0,0 +1,104 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:34 2011 PST by vadim
+#
+# files: * firewall2-1.fw
+# files: firewall2-1.conf
+#
+# Compiled for pf
+#
+# testing different errors in NATCompiler_pf::VerifyRules
+
+# firewall2-1:NAT:17: warning: Rule set NAT of firewall firewall2-1 has branching rule that loops back to it
+
+# firewall2-1:NAT:0: error: There should be no more than one object in original destination
+# firewall2-1:NAT:1: error: Negation in original service is not supported.
+# firewall2-1:NAT:2: error: Can not translate 'any' into a specific service.
+# firewall2-1:NAT:3: error: Can not use negation in translated source.
+# firewall2-1:NAT:4: error: Can not use negation in translated destination.
+# firewall2-1:NAT:5: error: Can not use negation in translated service.
+# firewall2-1:NAT:6: error: Translated service should be 'Original' or should contain single object.
+# firewall2-1:NAT:7: error: Translated service should be 'Original' or should contain single object.
+# firewall2-1:NAT:9: error: Can not use unnumbered interface in Translated Source of a Source translation rule.
+# firewall2-1:NAT:12: error: Can not use network or address range object in translated destination.
+# firewall2-1:NAT:13: error: Can not use network or address range object in translated destination.
+# firewall2-1:NAT:15: error: Can not use network or address range object in translated destination.
+# firewall2-1:NAT:16: warning: Translated Src, Dst and Srv are ignored in the NAT rule with action 'Branch'
+# firewall2-1:NAT:16: error: Action 'Branch' needs NAT rule set to point to
+# firewall2-1:NAT:17: warning: Translated Src, Dst and Srv are ignored in the NAT rule with action 'Branch'
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:34 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall2-1.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall2.conf.orig b/test/pf/firewall2.conf.orig
new file mode 100644
index 000000000..19f4b1f75
--- /dev/null
+++ b/test/pf/firewall2.conf.orig
@@ -0,0 +1,203 @@
+
+set limit { frags 5000, states 10000 }
+set optimization aggressive
+set timeout tcp.first 5
+set timeout tcp.opening 5
+set timeout tcp.established 10
+
+
+#
+# Prolog script
+#
+# prolog
+# prolog commands go after set commands
+
+#
+# End of prolog script
+#
+#
+# Scrub rules
+#
+scrub in all fragment reassemble no-df
+scrub out all random-id min-ttl 32 max-mss 1460
+
+
+# Tables: (3)
+table { 192.168.1.10 , 192.168.1.20 }
+table { 22.22.22.22 , 22.22.23.23 , 192.168.1.1 , 192.168.2.1 }
+table { 22.22.22.22 , 22.22.23.23 , 192.168.1.0/24 , 192.168.1.1 , 192.168.2.1 }
+
+#
+# Rule 0 (NAT)
+nat on eth0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.1.1
+nat on eth1 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 22.22.22.22
+nat on eth3 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 22.22.23.23
+nat on eth2 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.2.1
+#
+# Rule 1 (NAT)
+nat proto {tcp udp icmp} from to any -> 22.22.22.23
+#
+# Rule 2 (NAT)
+nat proto {tcp udp icmp} from 192.168.1.0/24 to -> 192.168.1.1
+#
+# Rule 3 (NAT)
+nat on eth0 proto tcp from 192.168.1.0/24 to any port 80 -> 192.168.1.1
+nat on eth1 proto tcp from 192.168.1.0/24 to any port 80 -> 22.22.22.22
+nat on eth3 proto tcp from 192.168.1.0/24 to any port 80 -> 22.22.23.23
+nat on eth2 proto tcp from 192.168.1.0/24 to any port 80 -> 192.168.2.1
+#
+# Rule 4 (NAT)
+nat proto tcp from to any port 80 -> 22.22.22.23
+#
+# Rule 5 (NAT)
+nat proto tcp from 192.168.1.0/24 to port 80 -> 192.168.1.1
+#
+# Rule 6 (NAT)
+nat on eth0 proto 47 from 192.168.1.0/24 to any -> 192.168.1.1
+nat on eth1 proto 47 from 192.168.1.0/24 to any -> 22.22.22.22
+nat on eth3 proto 47 from 192.168.1.0/24 to any -> 22.22.23.23
+nat on eth2 proto 47 from 192.168.1.0/24 to any -> 192.168.2.1
+#
+# Rule 7 (NAT)
+nat proto icmp from to any -> 22.22.22.23
+#
+# Rule 8 (NAT)
+nat proto udp from 192.168.1.0/24 to port 53 -> 192.168.1.1
+#
+# Rule 9 (NAT)
+rdr proto {tcp udp icmp} from any to 22.22.22.23 -> 192.168.1.10
+#
+# Rule 10 (NAT)
+rdr proto tcp from any to 22.22.22.23 port 80 -> 192.168.1.10 port 80
+rdr proto tcp from any to 22.22.22.23 port 119 -> 192.168.1.10 port 119
+#
+# Rule 11 (NAT)
+rdr proto tcp from any to 22.22.22.22 port 119 -> 192.168.1.10 port 119
+#
+# Rule 12 (NAT)
+nat proto {tcp udp icmp} from 192.168.1.20 to any -> 22.22.23.24
+#
+# Rule 16 (NAT)
+rdr proto {tcp udp icmp} from any to -> 192.168.1.10
+#
+# Rule 17 (NAT)
+rdr on eth1 proto {tcp udp icmp} from any to 22.22.22.22 -> 192.168.1.10
+#
+# Rule 18 (NAT)
+rdr on eth1 proto {tcp udp icmp} from any to 22.22.22.22 -> 192.168.1.10
+#
+# Rule 19 (NAT)
+rdr proto 47 from any to -> 192.168.1.10
+#
+# Rule 20 (NAT)
+rdr proto tcp from any to port 10000:11000 -> 192.168.1.10 port 10000:*
+#
+# Rule 21 (NAT)
+rdr on eth1 proto tcp from any to 22.22.22.22 port 10000:11000 -> 192.168.1.10 port 10000:*
+#
+# Rule 22 (NAT)
+rdr on eth1 proto tcp from any to 22.22.22.22 port 10000:11000 -> 192.168.1.10 port 10000:*
+#
+# Rule 23 (NAT)
+rdr on eth1 proto tcp from any to 22.22.22.22 port 10000:11000 -> 192.168.1.10 port 10000:*
+nat on eth0 proto tcp from any to 192.168.1.10 port 10000:11000 -> 192.168.1.1
+#
+# Rule 24 (NAT)
+rdr proto tcp from any to 22.22.22.23 port 80 -> 192.168.1.10 port 25
+#
+# Rule 25 (NAT)
+rdr proto tcp from 192.168.1.0/24 to any port 80 -> 127.0.0.1 port 80
+#
+# Rule 26 (NAT)
+rdr proto tcp from 192.168.1.0/24 to any port 80 -> 192.168.1.1 port 80
+#
+# Rule 27 (NAT)
+rdr proto tcp from any to port 1080 -> 127.0.0.1 port 80
+#
+# Rule 28 (NAT)
+# for bug 1111267: this custom service object has
+# "proto ..." in the protocol string, compiler can put
+# it in generated nat command in the right place.
+nat on eth1 proto {tcp udp icmp gre} from 192.168.1.0/24 to any -> 22.22.22.22
+#
+# Rule 29 (NAT)
+# for bug 1111267: this custom service object
+# has "proto .." in the code string but we can't insert
+# it in the generated nat command b/c it would appear
+# in the wrong place, after "from".
+nat on eth1 from 192.168.1.0/24 to any -> 22.22.22.22
+#
+# Rule 30 (NAT)
+nat on eth1 proto 47 from 192.168.1.0/24 to any -> 22.22.22.22
+nat on eth1 proto icmp from 192.168.1.0/24 to any -> 22.22.22.22
+nat on eth1 proto tcp from 192.168.1.0/24 to any -> 22.22.22.22
+nat on eth1 proto udp from 192.168.1.0/24 to any -> 22.22.22.22
+
+# Policy compiler errors and warnings:
+# firewall2:Policy:12: warning: Changing rule direction due to self reference
+#
+# Rule backup ssh access rule
+# backup ssh access rule
+pass in quick inet proto tcp from 192.168.1.100 to port 22 keep state label "RULE 9998 - ACCEPT **"
+#
+# Rule 0 (eth0)
+block in log quick on eth0 inet from ! 192.168.1.0/24 to any label "RULE 0 - DROP **"
+#
+# Rule 1 (eth1)
+# Anti-spoofing rule
+block in log quick on eth1 inet from to any label "Iface: eth1 RULE 1 -- DROP **"
+block in log quick on eth1 inet from 192.168.1.0/24 to any label "Iface: eth1 RULE 1 -- DROP **"
+#
+# Rule 2 (f2i1,3)
+# rules 2,3,4 test group
+# usage in interface
+# all three rules should yield
+# the same config
+block in log quick on { eth1 eth3 } inet from to any label "Iface: eth1 eth3 RULE 2 -- DROP **"
+block in log quick on { eth1 eth3 } inet from 192.168.1.0/24 to any label "Iface: eth1 eth3 RULE 2 -- DROP **"
+#
+# Rule 3 (f2i1,eth3)
+# Anti-spoofing rule
+block in log quick on { eth1 eth3 } inet from to any label "Iface: eth1 eth3 RULE 3 -- DROP **"
+block in log quick on { eth1 eth3 } inet from 192.168.1.0/24 to any label "Iface: eth1 eth3 RULE 3 -- DROP **"
+#
+# Rule 4 (eth1,eth3)
+# Anti-spoofing rule
+block in log quick on { eth1 eth3 } inet from to any label "Iface: eth1 eth3 RULE 4 -- DROP **"
+block in log quick on { eth1 eth3 } inet from 192.168.1.0/24 to any label "Iface: eth1 eth3 RULE 4 -- DROP **"
+#
+# Rule 5 (eth1)
+# Anti-spoofing rule
+block out log quick on eth1 inet from ! to any label "Iface: eth1 RULE 5 -- DROP **"
+#
+# Rule 6 (global)
+# block fragments
+block log quick inet from any to any fragment label "RULE 6 - DROP **"
+#
+# Rule 7 (global)
+# sends TCP RST and makes custom record in the log
+block return-rst log quick inet proto tcp from any to any port 113 label "IDENT"
+#
+# Rule 8 (global)
+pass quick inet from to 200.200.200.200 keep state label "RULE 8 - ACCEPT **"
+#
+# Rule 9 (global)
+pass quick inet from 200.200.200.200 to keep state label "RULE 9 - ACCEPT **"
+#
+# Rule 10 (global)
+# 'masquerading' rule
+pass quick inet from 192.168.1.0/24 to any keep state label "RULE 10 - ACCEPT **"
+#
+# Rule 12 (global)
+# firewall2:Policy:12: warning: Changing rule direction due to self reference
+pass in quick inet proto tcp from any to port { 21, 80, 25 } keep state label "RULE 12 - ACCEPT **"
+pass quick inet proto tcp from any to 192.168.1.10 port { 21, 80, 25 } keep state label "RULE 12 - ACCEPT **"
+#
+# Rule 13 (global)
+# 'catch all' rule
+block log quick inet from any to any label "RULE 13 - DROP **"
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any label "RULE 10000 - DROP **"
+
diff --git a/test/pf/firewall2.fw.orig b/test/pf/firewall2.fw.orig
new file mode 100755
index 000000000..9192e7515
--- /dev/null
+++ b/test/pf/firewall2.fw.orig
@@ -0,0 +1,88 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:32 2011 PST by vadim
+#
+# files: * firewall2.fw
+# files: firewall2.conf
+#
+# Compiled for pf
+#
+# this object has several interfaces and shows different rules for NAT. Also testing policy rule options
+
+# firewall2:Policy:12: warning: Changing rule direction due to self reference
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:32 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall2.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall20.conf.orig b/test/pf/firewall20.conf.orig
new file mode 100644
index 000000000..0328a51b0
--- /dev/null
+++ b/test/pf/firewall20.conf.orig
@@ -0,0 +1,31 @@
+
+
+
+#
+# Rule 0 (NAT)
+nat on dc2 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.1.1
+nat on dc0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> { 10.1.1.1 , 222.222.222.20 , 222.222.222.21 }
+#
+# Rule 1 (NAT)
+nat on dc1 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 222.222.222.20
+#
+# Rule 2 (NAT)
+nat on dc1 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 222.222.222.20
+#
+# Rule 3 (NAT)
+nat on dc0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 222.222.222.21
+
+#
+# Rule 0 (dc0)
+pass in quick on dc0 inet from any to 222.222.222.22 keep state
+#
+# Rule 1 (dc1)
+pass out quick on dc1 inet from any to 222.222.222.22 keep state
+#
+# Rule 2 (global)
+block quick inet from any to any
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any
+
diff --git a/test/pf/firewall20.fw.orig b/test/pf/firewall20.fw.orig
new file mode 100755
index 000000000..fb4d4f617
--- /dev/null
+++ b/test/pf/firewall20.fw.orig
@@ -0,0 +1,88 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:32 2011 PST by vadim
+#
+# files: * firewall20.fw
+# files: firewall20.conf
+#
+# Compiled for pf
+#
+# firewall using proxy arp
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:32 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall20.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall21-NAT_1.conf.orig b/test/pf/firewall21-NAT_1.conf.orig
new file mode 100644
index 000000000..968136b1b
--- /dev/null
+++ b/test/pf/firewall21-NAT_1.conf.orig
@@ -0,0 +1,5 @@
+#
+# Rule NAT_1 0 (NAT)
+nat on en1 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.1.1
+nat on en0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.0.2.1
+
diff --git a/test/pf/firewall21.conf.orig b/test/pf/firewall21.conf.orig
new file mode 100644
index 000000000..2567a02ea
--- /dev/null
+++ b/test/pf/firewall21.conf.orig
@@ -0,0 +1,33 @@
+
+
+
+# NAT compiler errors and warnings:
+# firewall21:NAT:3: warning: Translated Src, Dst and Srv are ignored in the NAT rule with action 'Branch'
+#
+# Rule 0 (NAT)
+nat-anchor "ftp-proxy/*"
+rdr-anchor "ftp-proxy/*"
+#
+# Rule 1 (NAT)
+rdr proto tcp from 192.168.1.0/24 to any port 21 -> 127.0.0.1 port 8021
+#
+# Rule 2 (NAT)
+nat-anchor "NAT_1" proto {tcp udp icmp} from 192.168.1.0/24 to any
+rdr-anchor "NAT_1" proto {tcp udp icmp} from 192.168.1.0/24 to any
+#
+# Rule 3 (NAT)
+# firewall21:NAT:3: warning: Translated Src, Dst and Srv are ignored in the NAT rule with action 'Branch'
+nat-anchor "NAT_1" proto {tcp udp icmp} from 192.168.1.0/24 to any
+rdr-anchor "NAT_1" proto {tcp udp icmp} from 192.168.1.0/24 to any
+
+#
+# Rule 0 (global)
+anchor "ftp-proxy/*" inet from any to any no state
+#
+# Rule 1 (global)
+pass quick inet proto tcp from any to 127.0.0.1 port 8021 flags any
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any no state
+
diff --git a/test/pf/firewall21.fw.orig b/test/pf/firewall21.fw.orig
new file mode 100755
index 000000000..a87835710
--- /dev/null
+++ b/test/pf/firewall21.fw.orig
@@ -0,0 +1,102 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:33 2011 PST by vadim
+#
+# files: * firewall21.fw
+# files: firewall21-NAT_1.conf
+# files: firewall21.conf
+#
+# Compiled for pf 4.0
+#
+# branching in NAT rules
+# PF v4.0-4.2
+
+# firewall21:ftp-proxy/*:: warning: The name of the policy ruleset ftp-proxy/* ends with '/*', assuming it is externally controlled and skipping it.
+# firewall21:ftp-proxy/*:: warning: The name of the policy ruleset ftp-proxy/* ends with '/*', assuming it is externally controlled and skipping it.
+# firewall21:ftp-proxy/*:: warning: The name of the policy ruleset ftp-proxy/* ends with '/*', assuming it is externally controlled and skipping it.
+
+# firewall21:NAT:3: warning: Translated Src, Dst and Srv are ignored in the NAT rule with action 'Branch'
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/usr/local/bin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:33 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall21.conf || exit 1
+$PFCTL -a NAT_1 \
+ -f \
+ ${FWDIR}/firewall21-NAT_1.conf || exit 1
+
+
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall22-NAT_1.conf.orig b/test/pf/firewall22-NAT_1.conf.orig
new file mode 100644
index 000000000..84b9aac32
--- /dev/null
+++ b/test/pf/firewall22-NAT_1.conf.orig
@@ -0,0 +1,5 @@
+#
+# Rule NAT_1 0 (NAT)
+nat proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.1.1
+nat proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.0.2.1
+
diff --git a/test/pf/firewall22.conf.orig b/test/pf/firewall22.conf.orig
new file mode 100644
index 000000000..9575c47b4
--- /dev/null
+++ b/test/pf/firewall22.conf.orig
@@ -0,0 +1,32 @@
+
+set state-policy if-bound
+
+#
+# Scrub rules
+#
+scrub in all fragment reassemble
+
+# NAT compiler errors and warnings:
+# firewall22:NAT:2: warning: Translated Src, Dst and Srv are ignored in the NAT rule with action 'Branch'
+#
+# Rule 0 (NAT)
+nat-anchor "ftp-proxy/*"
+rdr-anchor "ftp-proxy/*"
+#
+# Rule 1 (NAT)
+nat-anchor "NAT_1" proto {tcp udp icmp} from 192.168.1.0/24 to any
+rdr-anchor "NAT_1" proto {tcp udp icmp} from 192.168.1.0/24 to any
+#
+# Rule 2 (NAT)
+# firewall22:NAT:2: warning: Translated Src, Dst and Srv are ignored in the NAT rule with action 'Branch'
+nat-anchor "NAT_1" proto {tcp udp icmp} from 192.168.1.0/24 to any
+rdr-anchor "NAT_1" proto {tcp udp icmp} from 192.168.1.0/24 to any
+
+#
+# Rule 0 (global)
+block log quick inet from any to any no state
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any no state
+
diff --git a/test/pf/firewall22.fw.orig b/test/pf/firewall22.fw.orig
new file mode 100755
index 000000000..947b2cee7
--- /dev/null
+++ b/test/pf/firewall22.fw.orig
@@ -0,0 +1,100 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:35 2011 PST by vadim
+#
+# files: * firewall22.fw
+# files: firewall22-NAT_1.conf
+# files: firewall22.conf
+#
+# Compiled for pf 4.3
+#
+# branching in NAT rules
+# PF v4.3 and later
+
+# firewall22:ftp-proxy/*:: warning: The name of the policy ruleset ftp-proxy/* ends with '/*', assuming it is externally controlled and skipping it.
+
+# firewall22:NAT:2: warning: Translated Src, Dst and Srv are ignored in the NAT rule with action 'Branch'
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/usr/local/bin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:35 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall22.conf || exit 1
+$PFCTL -a NAT_1 \
+ -f \
+ ${FWDIR}/firewall22-NAT_1.conf || exit 1
+
+
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall3.conf.orig b/test/pf/firewall3.conf.orig
new file mode 100644
index 000000000..67c4d1741
--- /dev/null
+++ b/test/pf/firewall3.conf.orig
@@ -0,0 +1,55 @@
+
+set optimization conservative
+
+#
+# Scrub rules
+#
+scrub in all no-df
+scrub out all random-id
+
+
+#
+# Prolog script
+#
+# prolog
+# prolog commands go after scrub commands
+
+#
+# End of prolog script
+#
+
+# Tables: (1)
+table { 22.22.22.21 , 22.22.22.22 , 192.168.1.1 }
+
+#
+# Rule 0 (NAT)
+nat on le0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 22.22.22.21
+#
+# Rule 1 (NAT)
+nat on le0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> { 22.22.22.21 , 22.22.22.22 } bitmask
+#
+# Rule 2 (NAT)
+nat proto {tcp udp icmp} from 192.168.1.0/24 to any -> 22.22.22.0/28 source-hash
+#
+# Rule 3 (NAT)
+nat proto {tcp udp icmp} from 192.168.1.0/24 to any -> { 22.22.22.1 , 22.22.22.2/31 , 22.22.22.4 , 22.22.22.5 } round-robin static-port
+#
+# Rule 4 (NAT)
+rdr proto {tcp udp icmp} from any to 22.22.22.21 -> { 192.168.1.10 , 192.168.1.20 } round-robin
+
+# Policy compiler errors and warnings:
+# firewall3:Policy:0: warning: Changing rule direction due to self reference
+#
+# Rule 0 (global)
+# All other attempts to connect to
+# the firewall are denied and logged
+# firewall3:Policy:0: warning: Changing rule direction due to self reference
+block in log quick inet from any to label "RULE 0 -- DROP "
+#
+# Rule 1 (global)
+pass quick inet from 192.168.1.0/24 to any keep state ( max 1000 ) label "RULE 1 -- ACCEPT "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any label "RULE 10000 -- DROP "
+
diff --git a/test/pf/firewall3.fw.orig b/test/pf/firewall3.fw.orig
new file mode 100755
index 000000000..84ec75ea9
--- /dev/null
+++ b/test/pf/firewall3.fw.orig
@@ -0,0 +1,174 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:36 2011 PST by vadim
+#
+# files: * firewall3.fw
+# files: firewall3.conf
+#
+# Compiled for pf
+#
+# testing NAT rules with multiple objects in TSrc and TDst and NAT rule options
+
+# firewall3:Policy:0: warning: Changing rule direction due to self reference
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ update_addresses_of_interface "le0 22.22.22.21/0xffffff00 22.22.22.22/0xffffff00 22.22.22.0/0xffffff00 22.22.22.1/0xffffff00" ""
+ update_addresses_of_interface "le1 192.168.1.1/0xffffff00" ""
+ update_addresses_of_interface "lo 127.0.0.1/0xff000000" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:36 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall3.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall33.conf.orig b/test/pf/firewall33.conf.orig
new file mode 100644
index 000000000..14e653734
--- /dev/null
+++ b/test/pf/firewall33.conf.orig
@@ -0,0 +1,69 @@
+
+
+
+
+# Tables: (4)
+table { 157.166.224.25 , 157.166.224.26 , 157.166.226.25 , 157.166.226.26 , 157.166.255.18 , 157.166.255.19 }
+table { www.google.com , 157.166.224.25 , 157.166.224.26 , 157.166.226.25 , 157.166.226.26 , 157.166.255.18 , 157.166.255.19 }
+table { www.google.com , www.cnn.com }
+table { 74.125.19.99 , 74.125.19.103 , 74.125.19.104 , 74.125.19.147 , 157.166.224.25 , 157.166.224.26 , 157.166.226.25 , 157.166.226.26 , 157.166.255.18 , 157.166.255.19 }
+
+#
+# Rule 0 (NAT)
+nat on eth0.100 proto {tcp udp icmp} from any to -> (eth0.100)
+#
+# Rule 1 (NAT)
+nat on eth0.100 proto {tcp udp icmp} from any to www.cnn.com -> (eth0.100)
+#
+# Rule 2 (NAT)
+nat on eth0.100 proto {tcp udp icmp} from any to -> (eth0.100)
+#
+# Rule 3 (NAT)
+nat on eth0.100 proto {tcp udp icmp} from any to ! -> (eth0.100)
+
+# Policy compiler errors and warnings:
+# firewall33:Policy:2: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+# firewall33:Policy:6: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+#
+# Rule 0 (global)
+pass quick inet from to any keep state label "RULE 0 -- ACCEPT on global "
+#
+# Rule 1 (global)
+pass quick inet from www.cnn.com to any keep state label "RULE 1 -- ACCEPT on global "
+#
+# Rule 2 (global)
+# firewall33:Policy:2: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+pass quick inet from 192.0.2.1 to any keep state label "RULE 2 -- ACCEPT on global "
+#
+# Rule 3 (global)
+pass quick inet from buildmaster to any keep state label "RULE 3 -- ACCEPT on global "
+#
+# Rule 4 (global)
+block quick inet from any to ! label "RULE 4 -- DROP on global "
+#
+# Rule 5 (global)
+block quick inet from any to ! www.cnn.com label "RULE 5 -- DROP on global "
+#
+# Rule 6 (global)
+# firewall33:Policy:6: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+pass quick inet from any to ! 192.0.2.1 keep state label "RULE 6 -- ACCEPT on global "
+#
+# Rule 7 (global)
+pass quick inet from any to ! buildmaster keep state label "RULE 7 -- ACCEPT on global "
+#
+# Rule 8 (global)
+pass quick inet from any to ! keep state label "RULE 8 -- ACCEPT on global "
+#
+# Rule 9 (global)
+pass quick inet from any to ! keep state label "RULE 9 -- ACCEPT on global "
+#
+# Rule 10 (global)
+pass quick inet from any to ! keep state label "RULE 10 -- ACCEPT on global "
+#
+# Rule 11 (global)
+block log quick inet from any to any label "RULE 11 -- DROP on global "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any label "RULE 10000 -- DROP on global "
+
diff --git a/test/pf/firewall33.fw.orig b/test/pf/firewall33.fw.orig
new file mode 100755
index 000000000..99b1c70c5
--- /dev/null
+++ b/test/pf/firewall33.fw.orig
@@ -0,0 +1,177 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:36 2011 PST by vadim
+#
+# files: * firewall33.fw
+# files: firewall33.conf
+#
+# Compiled for pf
+#
+# testing DNSName object
+
+# firewall33:Policy:2: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+# firewall33:Policy:6: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ update_addresses_of_interface "eth1 192.168.1.100/0xffffff00" ""
+ update_addresses_of_interface "lo 127.0.0.1/0xff000000" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:36 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall33.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall34.conf.orig b/test/pf/firewall34.conf.orig
new file mode 100644
index 000000000..e2e95be31
--- /dev/null
+++ b/test/pf/firewall34.conf.orig
@@ -0,0 +1,75 @@
+
+
+
+
+# Tables: (4)
+table persist file "block-hosts.tbl"
+table persist
+table { 192.168.1.1 , 192.168.1.2 , 192.168.1.3/30 , 192.168.1.200 , 192.168.1.201 , 192.168.2.128/25 }
+table { 7.7.7.7 , 61.150.47.112 , 192.168.1.1 , 192.168.1.2 , 192.168.1.3/30 , 192.168.1.200 , 192.168.1.201 , 192.168.2.128/25 }
+
+#
+# Rule 0 (NAT)
+rdr on eth0.100 proto tcp from ! to (eth0.100) port 25 -> 192.168.1.10 port 25
+#
+# Rule 1 (NAT)
+rdr on eth0.100 proto tcp from to (eth0.100) port 25 -> 192.168.1.10 port 25
+rdr on eth0.100 proto tcp from to (eth0.100) port 25 -> 192.168.1.10 port 25
+#
+# Rule 2 (NAT)
+nat on eth0.100 proto {tcp udp icmp} from 192.168.1.0/24 to ! -> (eth0.100)
+#
+# Rule 3 (NAT)
+rdr proto tcp from any to (eth0.100) port 25 -> { 192.168.1.1 , 192.168.1.2 , 192.168.1.3/30 , 192.168.2.128/25 , 192.168.1.200 , 192.168.1.201 } port 25
+#
+# Rule 4 (NAT)
+rdr proto {tcp udp icmp} from any to (eth0.100) -> { 192.168.1.1 , 192.168.1.2 , 192.168.1.3/30 , 192.168.2.128/25 , 192.168.1.200 , 192.168.1.201 }
+#
+# Rule 5 (NAT)
+no nat proto {tcp udp icmp} from 192.168.1.0/24 to
+no rdr proto {tcp udp icmp} from 192.168.1.0/24 to
+#
+# Rule 6 (NAT)
+rdr proto {tcp udp icmp} from 192.168.1.0/24 to -> 127.0.0.1
+
+#
+# Rule 0 (global)
+pass quick inet from any to keep state label "RULE 0 -- ACCEPT on global "
+#
+# Rule 1 (global)
+block log quick inet from any to label "RULE 1 -- DROP on global "
+#
+# Rule 2 (global)
+block log quick inet from any to label "RULE 2 -- DROP on global "
+block log quick inet from any to label "RULE 2 -- DROP on global "
+#
+# Rule 3 (global)
+block log quick inet from any to label "RULE 3 -- DROP on global "
+#
+# Rule 4 (global)
+block log quick inet from to any label "RULE 4 -- DROP on global "
+#
+# Rule 5 (global)
+block quick inet proto tcp from any to port 25 label "RULE 5 -- DROP on global "
+block quick inet proto tcp from any to 61.150.47.112 port 25 label "RULE 5 -- DROP on global "
+#
+# Rule 6 (global)
+block log quick inet from to any label "RULE 6 -- DROP on global "
+#
+# Rule 7 (global)
+block log quick inet from to any label "RULE 7 -- DROP on global "
+block log quick inet from 61.150.47.112 to any label "RULE 7 -- DROP on global "
+#
+# Rule 9 (global)
+pass quick inet proto tcp from any to 192.168.1.10 port 25 keep state ( max-src-conn 5, overload flush global ) label "RULE 9 -- ACCEPT on global "
+#
+# Rule 10 (global)
+pass quick inet from 192.168.1.0/24 to any keep state label "RULE 10 -- ACCEPT on global "
+#
+# Rule 11 (global)
+block log quick inet from any to any label "RULE 11 -- DROP on global "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any label "RULE 10000 -- DROP on global "
+
diff --git a/test/pf/firewall34.fw.orig b/test/pf/firewall34.fw.orig
new file mode 100755
index 000000000..5fd1d9b4c
--- /dev/null
+++ b/test/pf/firewall34.fw.orig
@@ -0,0 +1,173 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:37 2011 PST by vadim
+#
+# files: * firewall34.fw
+# files: firewall34.conf
+#
+# Compiled for pf
+#
+# testing AddressTable object
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ update_addresses_of_interface "eth1 192.168.1.100/0xffffff00" ""
+ update_addresses_of_interface "lo 127.0.0.1/0xff000000" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:37 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall34.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall38.conf.orig b/test/pf/firewall38.conf.orig
new file mode 100644
index 000000000..65f18bd8d
--- /dev/null
+++ b/test/pf/firewall38.conf.orig
@@ -0,0 +1,53 @@
+
+
+#
+# Scrub rules
+#
+scrub in all fragment reassemble
+
+#
+# Rule 0 (NAT)
+nat on le0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.1.1
+nat on enc1 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.2.1
+#
+# Rule 1 (NAT)
+nat on le0 from 192.168.1.0/24 to any tagged ipsec_tag -> 192.168.1.1
+nat on enc1 from 192.168.1.0/24 to any tagged ipsec_tag -> 192.168.2.1
+
+#
+# Rule 0 (le0)
+pass in on le0 inet from any to any tag INTNET keep state
+#
+# Rule 1 (enc1)
+pass in quick on enc1 inet from any to any keep state
+#
+# Rule 2 (enc0)
+pass out quick on enc0 inet from any to any tagged INTNET keep state
+#
+# Rule 3 (enc0)
+pass out quick on enc0 inet proto tcp from any to any port 80 keep state
+#
+# Rule 4 (lo)
+pass quick on lo inet from any to any keep state
+#
+# Rule 5 (global)
+pass quick inet from any to any tagged ipsec_tag keep state
+#
+# Rule 6 (global)
+pass quick inet from any to any tagged ipsec_tag keep state
+pass quick inet from any to any tagged tag2 keep state
+#
+# Rule 8 (global)
+pass quick inet proto tcp from any to any port 80 keep state
+pass quick inet from any to any tagged ipsec_tag keep state
+#
+# Rule 10 (global)
+pass quick inet proto tcp from 192.168.1.0/24 to any port 25 queue mail
+#
+# Rule 11 (global)
+block log quick inet from any to any
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any
+
diff --git a/test/pf/firewall38.fw.orig b/test/pf/firewall38.fw.orig
new file mode 100755
index 000000000..28bf7488d
--- /dev/null
+++ b/test/pf/firewall38.fw.orig
@@ -0,0 +1,91 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:38 2011 PST by vadim
+#
+# files: * firewall38.fw
+# files: firewall38.conf
+#
+# Compiled for pf
+#
+# testing rules with tag service
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:38 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall38.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall39-rule2_branch.conf.orig b/test/pf/firewall39-rule2_branch.conf.orig
new file mode 100644
index 000000000..7e3416319
--- /dev/null
+++ b/test/pf/firewall39-rule2_branch.conf.orig
@@ -0,0 +1,14 @@
+
+# Tables: (1)
+table { 192.168.1.1 , 192.168.2.1 }
+
+# Policy compiler errors and warnings:
+# firewall39:rule2_branch:0: warning: Changing rule direction due to self reference
+#
+# Rule rule2_branch 0 (global)
+# firewall39:rule2_branch:0: warning: Changing rule direction due to self reference
+pass in quick inet from any to keep state
+#
+# Rule rule2_branch 1 (global)
+block log quick inet from any to any
+
diff --git a/test/pf/firewall39-rule3_branch.conf.orig b/test/pf/firewall39-rule3_branch.conf.orig
new file mode 100644
index 000000000..113c91a79
--- /dev/null
+++ b/test/pf/firewall39-rule3_branch.conf.orig
@@ -0,0 +1,14 @@
+
+# Tables: (1)
+table { 192.168.1.11 , 192.168.1.12 }
+
+#
+# Rule rule3_branch 0 (global)
+pass in quick inet from any to 192.168.1.10 keep state
+#
+# Rule rule3_branch 1 (global)
+pass quick inet from any to ! keep state
+#
+# Rule rule3_branch 2 (global)
+block log quick inet from any to any
+
diff --git a/test/pf/firewall39-rule5_branch.conf.orig b/test/pf/firewall39-rule5_branch.conf.orig
new file mode 100644
index 000000000..e69de29bb
diff --git a/test/pf/firewall39.conf.orig b/test/pf/firewall39.conf.orig
new file mode 100644
index 000000000..da99e6b66
--- /dev/null
+++ b/test/pf/firewall39.conf.orig
@@ -0,0 +1,57 @@
+
+
+#
+# Scrub rules
+#
+scrub in all fragment reassemble
+
+#
+# Rule 0 (NAT)
+nat on le0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.1.1
+nat on enc1 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.2.1
+#
+# Rule 1 (NAT)
+nat on le0 from 192.168.1.0/24 to any tagged ipsec_tag -> 192.168.1.1
+nat on enc1 from 192.168.1.0/24 to any tagged ipsec_tag -> 192.168.2.1
+
+#
+# Rule 0 (le0)
+pass in on le0 inet from any to any tag INTNET keep state
+#
+# Rule 1 (enc1)
+pass in quick on enc1 inet from any to any keep state
+#
+# Rule 2 (enc0)
+# logging is not allowed with 'anchor'
+# compiler should not generate 'log' keyword
+anchor "rule2_branch" in on enc0 inet proto 50 from any to any
+anchor "rule2_branch" in on enc0 inet proto 51 from any to any
+#
+# Rule 3 (enc0)
+anchor "rule3_branch" in on enc0 inet proto tcp from any to any port 80
+#
+# Rule 4 (lo)
+pass quick on lo inet from any to any keep state
+#
+# Rule 5 (global)
+anchor "rule5_branch" inet proto 50 from any to any
+anchor "rule5_branch" inet proto 51 from any to any
+#
+# Rule 6 (global)
+pass quick inet proto 50 from any to any keep state
+pass quick inet proto 51 from any to any keep state
+#
+# Rule 7 (global)
+pass quick inet proto tcp from any to any port 80 keep state
+pass quick inet from any to any tagged ipsec_tag keep state
+#
+# Rule 9 (global)
+pass quick inet proto tcp from 192.168.1.0/24 to any port 25 queue mail
+#
+# Rule 10 (global)
+block log quick inet from any to any
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any
+
diff --git a/test/pf/firewall39.fw.orig b/test/pf/firewall39.fw.orig
new file mode 100755
index 000000000..141c8518b
--- /dev/null
+++ b/test/pf/firewall39.fw.orig
@@ -0,0 +1,103 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:39 2011 PST by vadim
+#
+# files: * firewall39.fw pf.fw
+# files: firewall39.conf pf.conf
+# files: firewall39-rule2_branch.conf pf-rule2_branch.conf
+# files: firewall39-rule3_branch.conf pf-rule3_branch.conf
+# files: firewall39-rule5_branch.conf pf-rule5_branch.conf
+#
+# Compiled for pf
+#
+# testing branching rules
+
+# firewall39:rule2_branch:0: warning: Changing rule direction due to self reference
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:39 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/pf.conf || exit 1
+$PFCTL -a rule2_branch \
+ -f \
+ ${FWDIR}/pf-rule2_branch.conf || exit 1
+$PFCTL -a rule3_branch \
+ -f \
+ ${FWDIR}/pf-rule3_branch.conf || exit 1
+$PFCTL -a rule5_branch \
+ -f \
+ ${FWDIR}/pf-rule5_branch.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall4.conf.orig b/test/pf/firewall4.conf.orig
new file mode 100644
index 000000000..f08fe2606
--- /dev/null
+++ b/test/pf/firewall4.conf.orig
@@ -0,0 +1,92 @@
+
+set optimization high-latency
+
+
+
+# Tables: (3)
+table { eth1 , 192.168.1.1 , 192.168.2.1 , 222.222.222.222 }
+table { eth1 , 192.168.1.0/24 , 192.168.1.1 , 192.168.2.1 , 222.222.222.222 }
+table { 192.168.1.10 , 192.168.1.20 }
+
+
+#
+# Prolog script
+#
+# prolog commands go after table definitions
+
+#
+# End of prolog script
+#
+#
+# Rule 0 (NAT)
+nat on eth0 proto {tcp udp icmp} from 192.168.1.10 to any -> 192.168.1.1
+nat on eth1 proto {tcp udp icmp} from 192.168.1.10 to any -> (eth1)
+nat on eth2 proto {tcp udp icmp} from 192.168.1.10 to any -> 192.168.2.1
+nat on eth3 proto {tcp udp icmp} from 192.168.1.10 to any -> 222.222.222.222
+#
+# Rule 1 (NAT)
+nat on eth0 proto {tcp udp icmp} from 192.168.1.0/24 to ! 192.168.2.0/24 -> 192.168.1.1
+nat on eth1 proto {tcp udp icmp} from 192.168.1.0/24 to ! 192.168.2.0/24 -> (eth1)
+nat on eth2 proto {tcp udp icmp} from 192.168.1.0/24 to ! 192.168.2.0/24 -> 192.168.2.1
+nat on eth3 proto {tcp udp icmp} from 192.168.1.0/24 to ! 192.168.2.0/24 -> 222.222.222.222
+#
+# Rule 2 (NAT)
+rdr proto tcp from any to port 22 -> 192.168.1.10 port 22
+#
+# Rule 3 (NAT)
+# SDNAT rule
+rdr on eth3 proto tcp from 192.168.1.0/24 to 222.222.222.222 port 80 -> 192.168.1.10 port 80
+nat on eth0 proto tcp from 192.168.1.0/24 to 192.168.1.10 port 80 -> 192.168.1.1
+#
+# Rule 4 (NAT)
+nat on eth3 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 222.222.222.222
+#
+# Rule 5 (NAT)
+# eth1 is dynamic
+nat on eth1 proto tcp from 192.168.1.0/24 to any port 22 -> (eth1)
+
+# Policy compiler errors and warnings:
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+#
+# Rule 0 (global)
+anchor "ftp-proxy/*" inet from any to any
+#
+# Rule 1 (global)
+pass log quick inet proto tcp from any to (eth1) port 22 keep state
+#
+# Rule 2 (eth1)
+block log quick on eth1 inet proto icmp from ! 192.168.2.0/24 to any icmp-type 8 code 0
+#
+# Rule 3 (eth1)
+# Anti-spoofing rule
+block in log quick on eth1 inet from to any
+block in log quick on eth1 inet from 192.168.1.0/24 to any
+#
+# Rule 4 (eth1)
+# Anti-spoofing rule
+block out log quick on eth1 inet from ! to any
+#
+# Rule 5 (global)
+# hostF has the same IP address as firewal.
+pass log quick inet proto icmp from any to 192.168.1.1 icmp-type 8 code 0 keep state
+#
+# Rule 6 (global)
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+block in log quick inet proto icmp from ! to icmp-type 3
+#
+# Rule 7 (global)
+# testing negation in the policy rule
+block log quick inet proto icmp from ! to any icmp-type 3
+#
+# Rule 9 (global)
+# 'masquerading' rule
+pass quick inet from 192.168.1.0/24 to any keep state
+#
+# Rule 10 (global)
+# 'catch all' rule
+block log quick inet from any to any
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any
+
diff --git a/test/pf/firewall4.fw.orig b/test/pf/firewall4.fw.orig
new file mode 100755
index 000000000..9fb75873f
--- /dev/null
+++ b/test/pf/firewall4.fw.orig
@@ -0,0 +1,93 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:40 2011 PST by vadim
+#
+# files: * firewall4.fw pf.fw
+# files: firewall4.conf /etc/fw/pf.conf
+#
+# Compiled for pf
+#
+# this object is used to test a configuration where firewall has dynamic address
+
+# firewall4::: error: Dynamic interface eth1 should not have an IP address object attached to it. This IP address object will be ignored.
+# firewall4:ftp-proxy/*:: warning: The name of the policy ruleset ftp-proxy/* ends with '/*', assuming it is externally controlled and skipping it.
+# firewall4:ftp-proxy/*:: warning: The name of the policy ruleset ftp-proxy/* ends with '/*', assuming it is externally controlled and skipping it.
+
+
+# firewall4:Policy:6: warning: Changing rule direction due to self reference
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:40 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ /etc/fw/pf.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall40-1-routes.conf.orig b/test/pf/firewall40-1-routes.conf.orig
new file mode 100644
index 000000000..498e8c731
--- /dev/null
+++ b/test/pf/firewall40-1-routes.conf.orig
@@ -0,0 +1,64 @@
+# Policy compiler errors and warnings:
+# firewall40-1:routes:1: error: Interface specification is required for action Route.
+# firewall40-1:routes:1: error: Only one router specified with load balancing for rule action Route: 'route_reply_through'
+# firewall40-1:routes:2: error: Interface specification is required for action Route.
+# firewall40-1:routes:2: error: Only one router specified with load balancing for rule action Route: 'route_copy_through'
+# firewall40-1:routes:6: error: Interface specification is required for action Route.
+# firewall40-1:routes:6: error: More than one router specified without load balancing for rule action Route: 'route_through'
+# firewall40-1:routes:7: error: Interface specification is required for action Route.
+# firewall40-1:routes:8: error: Interface specification is required for action Route.
+# firewall40-1:routes:9: error: Interface specification is required for action Route.
+# firewall40-1:routes:10: error: Interface specification is required for action Route.
+#
+# Rule routes 0 (fxp0)
+# route_through, load balancing random
+pass in quick on fxp0 route-to { ( le1 192.0.2.1 ) , ( le1 192.0.2.2 ) , ( le1 192.0.2.3 ) } random inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 0 -- "
+#
+# Rule routes 1 (fxp0)
+# error: interface is required
+pass in quick on fxp0 reply-to { ( 192.0.2.1 ) } random inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 1 -- "
+#
+# Rule routes 2 (fxp0)
+# error: interface is required
+pass in quick on fxp0 dup-to { ( 192.0.2.1 ) } random inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 2 -- "
+#
+# Rule routes 3 (fxp0)
+# fastroute
+pass in quick on fxp0 fastroute inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 3 -- "
+#
+# Rule routes 4 (fxp0)
+# fastroute
+pass in quick on fxp0 fastroute inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 4 -- "
+#
+# Rule routes 5 (fxp0)
+# fastroute
+pass in quick on fxp0 fastroute inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 5 -- "
+#
+# Rule routes 6 (fxp0)
+# route_through, load balancing none
+# error: interface is required
+pass in quick on fxp0 route-to { ( 192.0.2.1 ) , ( 192.0.2.2 ) , ( 192.0.2.3 ) } inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 6 -- "
+#
+# Rule routes 7 (fxp0)
+# route_through, load balancing bitmask
+# error: interface is required
+pass in quick on fxp0 route-to { ( 192.0.2.1 ) , ( 192.0.2.2 ) , ( 192.0.2.3 ) } bitmask inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 7 -- "
+#
+# Rule routes 8 (fxp0)
+# route_through, load balancing random
+# error: interface is required
+pass in quick on fxp0 route-to { ( 192.0.2.1 ) , ( 192.0.2.2 ) , ( 192.0.2.3 ) } random inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 8 -- "
+#
+# Rule routes 9 (fxp0)
+# route_through, load balancing source hash
+# error: interface is required
+pass in quick on fxp0 route-to { ( 192.0.2.1 ) , ( 192.0.2.2 ) , ( 192.0.2.3 ) } source-hash inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 9 -- "
+#
+# Rule routes 10 (fxp0)
+# route_through, load balancing round robin
+# error: interface is required
+pass in quick on fxp0 route-to { ( 192.0.2.1 ) , ( 192.0.2.2 ) , ( 192.0.2.3 ) } round-robin inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 10 -- "
+#
+# Rule routes 11 (global)
+block log quick inet from any to any label "RULE 11 -- DROP "
+
diff --git a/test/pf/firewall40-1.conf.orig b/test/pf/firewall40-1.conf.orig
new file mode 100644
index 000000000..9b8030183
--- /dev/null
+++ b/test/pf/firewall40-1.conf.orig
@@ -0,0 +1,74 @@
+
+
+
+#
+# Rule 0 (NAT)
+# Translate source address
+# for outgoing connections
+nat on le1 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.0.2.1
+#
+# Rule 1 (NAT)
+# Translate source address
+# for outgoing connections
+nat on le2 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.0.3.1
+
+# Policy compiler errors and warnings:
+# firewall40-1:Policy:9: error: Only one router specified with load balancing for rule action Route: 'route_through'
+# firewall40-1:Policy:10: error: Only one router specified with load balancing for rule action Route: 'route_through'
+# firewall40-1:Policy:11: error: Illegal IP address for next hop
+# firewall40-1:Policy:11: error: Only one router specified with load balancing for rule action Route: 'route_through'
+#
+# Rule 0 (fxp0)
+pass in quick on fxp0 route-to { ( le1 192.0.2.1 ) , ( le1 192.0.2.2 ) , ( le1 192.0.2.3 ) } random inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 0 -- "
+#
+# Rule 1 (fxp0)
+pass in quick on fxp0 route-to { ( le2 192.0.2.1 ) , ( le2 192.0.2.2 ) , ( le2 192.0.2.3 ) } round-robin inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 1 -- "
+#
+# Rule 2 (fxp0)
+pass in quick on fxp0 route-to { ( le2 192.0.2.1 ) , ( le2 192.0.2.2 ) , ( le2 192.0.2.3 ) } round-robin inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 2 -- "
+#
+# Rule 3 (fxp0)
+pass in quick on fxp0 route-to { ( le1 192.0.2.1 ) , ( le1 192.0.2.2 ) , ( le1 192.0.2.3 ) } round-robin inet proto tcp from 192.168.1.0/24 to any port 80 label "RULE 3 -- "
+#
+# Rule 4 (fxp0)
+pass in quick on fxp0 route-to { ( le2 192.0.2.1 ) , ( le2 192.0.2.2 ) , ( le2 192.0.2.3 ) } round-robin inet proto tcp from 192.168.1.0/24 to any port 80 label "RULE 4 -- "
+#
+# Rule 5 (fxp0)
+pass in quick on fxp0 route-to { ( le2 192.0.2.1 ) , ( le2 192.0.2.2 ) , ( le2 192.0.2.3 ) } round-robin inet proto tcp from 192.168.1.0/24 to any port 80 label "RULE 5 -- "
+#
+# Rule 6 (fxp0)
+pass in quick on fxp0 route-to { ( le1 192.0.2.0/24 ) } random inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 6 -- "
+#
+# Rule 7 (fxp0)
+pass in quick on fxp0 route-to { ( le2 192.0.2.0/24 ) } source-hash inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 7 -- "
+#
+# Rule 8 (fxp0)
+pass in quick on fxp0 route-to { ( le2 192.0.2.0/255.255.255.0 ) } round-robin inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 8 -- "
+#
+# Rule 9 (fxp0)
+# this should fail because
+# it has one address for the next
+# hop and it is /32.
+# Run compiler with
+# command line argument -xt
+# to convert errors to warnings
+# and make it generate .conf
+# file anyway
+pass in quick on fxp0 route-to { ( le2 192.0.2.1 ) } round-robin inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 9 -- "
+#
+# Rule 10 (fxp0)
+# this should fail because
+# it has one address for the next
+# hop and it is /32.
+pass in quick on fxp0 route-to { ( le2 192.0.2.1/32 ) } round-robin inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 10 -- "
+#
+# Rule 11 (fxp0)
+# this should fail because
+# it ip address in next hop
+# is illegal
+pass in quick on fxp0 route-to { ( le2 192.0.300.1/32 ) } round-robin inet proto tcp from 192.168.1.0/24 to any port 80 keep state label "RULE 11 -- "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any label "RULE 10000 -- DROP "
+
diff --git a/test/pf/firewall40-1.fw.orig b/test/pf/firewall40-1.fw.orig
new file mode 100755
index 000000000..176a4454a
--- /dev/null
+++ b/test/pf/firewall40-1.fw.orig
@@ -0,0 +1,194 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:41 2011 PST by vadim
+#
+# files: * firewall40-1.fw
+# files: firewall40-1.conf
+# files: firewall40-1-routes.conf
+#
+# Compiled for pf
+#
+# testing Route action
+# with load balancing
+
+# firewall40-1:Policy:9: error: Only one router specified with load balancing for rule action Route: 'route_through'
+# firewall40-1:Policy:10: error: Only one router specified with load balancing for rule action Route: 'route_through'
+# firewall40-1:Policy:11: error: Illegal IP address for next hop
+# firewall40-1:Policy:11: error: Only one router specified with load balancing for rule action Route: 'route_through'
+
+# firewall40-1:routes:1: error: Interface specification is required for action Route.
+# firewall40-1:routes:1: error: Only one router specified with load balancing for rule action Route: 'route_reply_through'
+# firewall40-1:routes:2: error: Interface specification is required for action Route.
+# firewall40-1:routes:2: error: Only one router specified with load balancing for rule action Route: 'route_copy_through'
+# firewall40-1:routes:6: error: Interface specification is required for action Route.
+# firewall40-1:routes:6: error: More than one router specified without load balancing for rule action Route: 'route_through'
+# firewall40-1:routes:7: error: Interface specification is required for action Route.
+# firewall40-1:routes:8: error: Interface specification is required for action Route.
+# firewall40-1:routes:9: error: Interface specification is required for action Route.
+# firewall40-1:routes:10: error: Interface specification is required for action Route.
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ update_addresses_of_interface "fxp0 192.168.1.1/0xffffff00" ""
+ update_addresses_of_interface "le1 192.0.2.1/0xffffff00" ""
+ update_addresses_of_interface "le2 192.0.3.1/0xffffff00" ""
+ update_addresses_of_interface "lo0 127.0.0.1/0xff000000" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:41 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall40-1.conf || exit 1
+$PFCTL -a routes \
+ -f \
+ ${FWDIR}/firewall40-1-routes.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall40.conf.orig b/test/pf/firewall40.conf.orig
new file mode 100644
index 000000000..08cfd115f
--- /dev/null
+++ b/test/pf/firewall40.conf.orig
@@ -0,0 +1,41 @@
+
+
+
+
+# Tables: (1)
+table { 192.0.2.1 , 192.0.3.1 , 192.168.1.1 }
+
+#
+# Rule 0 (NAT)
+# Translate source address
+# for outgoing connections
+nat on le1 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.0.2.1
+#
+# Rule 1 (NAT)
+# Translate source address
+# for outgoing connections
+nat on le2 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.0.3.1
+
+#
+# Rule 0 (lo0)
+pass quick on lo0 inet from any to any label "RULE 0 -- ACCEPT "
+#
+# Rule 1 (fxp0)
+pass quick on fxp0 inet from 192.168.1.0/24 to 192.168.1.0/24 label "RULE 1 -- ACCEPT "
+#
+# Rule 2 (fxp0)
+pass in quick on fxp0 route-to { ( le1 192.0.2.10 ) } inet proto tcp from 192.168.1.0/24 to any port { 80, 25 } label "RULE 2 -- "
+#
+# Rule 3 (fxp0)
+pass in quick on fxp0 route-to { ( le2 192.0.3.10 ) } inet proto tcp from 192.168.1.0/24 to any port 22 label "RULE 3 -- "
+#
+# Rule 4 (global)
+pass out quick inet from to any keep state label "RULE 4 -- ACCEPT "
+#
+# Rule 5 (global)
+block log quick inet from any to any label "RULE 5 -- DROP "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any label "RULE 10000 -- DROP "
+
diff --git a/test/pf/firewall40.fw.orig b/test/pf/firewall40.fw.orig
new file mode 100755
index 000000000..0e8dc9041
--- /dev/null
+++ b/test/pf/firewall40.fw.orig
@@ -0,0 +1,175 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:40 2011 PST by vadim
+#
+# files: * firewall40.fw
+# files: firewall40.conf
+#
+# Compiled for pf
+#
+# testing Route action
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ update_addresses_of_interface "fxp0 192.168.1.1/0xffffff00" ""
+ update_addresses_of_interface "le1 192.0.2.1/0xffffff00" ""
+ update_addresses_of_interface "le2 192.0.3.1/0xffffff00" ""
+ update_addresses_of_interface "lo0 127.0.0.1/0xff000000" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:40 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall40.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall41.conf.orig b/test/pf/firewall41.conf.orig
new file mode 100644
index 000000000..0ee625c5e
--- /dev/null
+++ b/test/pf/firewall41.conf.orig
@@ -0,0 +1,36 @@
+
+
+
+
+# Tables: (4)
+table persist file "block-hosts.tbl"
+table persist
+table { 1.1.1.1 , 2.2.2.2 }
+table { 192.168.1.1 , 192.168.1.2 , 192.168.1.3/30 , 192.168.1.200 , 192.168.1.201 , 192.168.2.128/25 }
+
+# Policy compiler errors and warnings:
+# firewall41:Policy:3: error: File not found for Address Table: missing table (file_does_not_exist.tbl) Using dummy address in test mode
+# firewall41:Policy:3: error: File not found for Address Table: missing table (file_does_not_exist.tbl) Using dummy address in test mode
+# firewall41:Policy:3: error: File not found for Address Table: missing table (file_does_not_exist.tbl) Using dummy address in test mode
+#
+# Rule 0 (global)
+pass out log quick inet from to www.heise.de keep state label "RULE 0 -- ACCEPT "
+#
+# Rule 1 (global)
+pass out log quick inet from to keep state label "RULE 1 -- ACCEPT "
+#
+# Rule 2 (global)
+pass out log quick inet from to keep state label "RULE 2 -- ACCEPT "
+pass out log quick inet from to keep state label "RULE 2 -- ACCEPT "
+#
+# Rule 3 (global)
+# firewall41:Policy:3: error: File not found for Address Table: missing table (file_does_not_exist.tbl) Using dummy address in test mode
+pass out log quick inet from to 192.0.2.0/24 keep state label "RULE 3 -- ACCEPT "
+#
+# Rule 4 (global)
+pass out log quick inet from to 1.1.1.1 keep state label "RULE 4 -- ACCEPT "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any label "RULE 10000 -- DROP "
+
diff --git a/test/pf/firewall41.fw.orig b/test/pf/firewall41.fw.orig
new file mode 100755
index 000000000..40a864e99
--- /dev/null
+++ b/test/pf/firewall41.fw.orig
@@ -0,0 +1,178 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:42 2011 PST by vadim
+#
+# files: * firewall41.fw
+# files: firewall41.conf
+#
+# Compiled for pf
+#
+# testing rule shadowing with run-time objects, rules with such objects should be ignored
+
+# firewall41:Policy:3: error: File not found for Address Table: missing table (file_does_not_exist.tbl) Using dummy address in test mode
+# firewall41:Policy:3: error: File not found for Address Table: missing table (file_does_not_exist.tbl) Using dummy address in test mode
+# firewall41:Policy:3: error: File not found for Address Table: missing table (file_does_not_exist.tbl) Using dummy address in test mode
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ update_addresses_of_interface "eth0 1.1.1.1/0xffffff00" ""
+ update_addresses_of_interface "eth1 2.2.2.2/0xffffff00" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:42 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall41.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall5.conf.orig b/test/pf/firewall5.conf.orig
new file mode 100644
index 000000000..6e2e41041
--- /dev/null
+++ b/test/pf/firewall5.conf.orig
@@ -0,0 +1,20 @@
+
+set optimization normal
+
+
+#
+# Rule 0 (global)
+block log quick inet from any to any fragment
+block log quick inet proto 50 from any to any
+#
+# Rule 1 (global)
+block log quick inet from any to any fragment
+block log quick inet proto tcp from any to any flags ARSF/UAPRSF
+#
+# Rule 2 (global)
+block log quick inet from any to any
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any
+
diff --git a/test/pf/firewall5.fw.orig b/test/pf/firewall5.fw.orig
new file mode 100755
index 000000000..03160b9cd
--- /dev/null
+++ b/test/pf/firewall5.fw.orig
@@ -0,0 +1,92 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:43 2011 PST by vadim
+#
+# files: * firewall5.fw
+# files: firewall5.conf
+#
+# Compiled for pf
+#
+# testing IP fragments and scrub
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.directed-broadcast=0
+ $SYSCTL -w net.inet.ip.forwarding=1
+
+ $SYSCTL -w net.inet.ip.sourceroute=0
+ $SYSCTL -w net.inet.ip.redirect=0
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:43 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall5.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall51-mail_server_inbound.conf.orig b/test/pf/firewall51-mail_server_inbound.conf.orig
new file mode 100644
index 000000000..bff6b4165
--- /dev/null
+++ b/test/pf/firewall51-mail_server_inbound.conf.orig
@@ -0,0 +1,7 @@
+#
+# Rule mail_server_inbound 0 (global)
+pass in quick inet proto tcp from any to any port 25 keep state
+#
+# Rule mail_server_inbound 1 (global)
+pass in quick inet proto icmp from any to any icmp-type { 3 , 8 code 0 } keep state
+
diff --git a/test/pf/firewall51-mail_server_outbound.conf.orig b/test/pf/firewall51-mail_server_outbound.conf.orig
new file mode 100644
index 000000000..96773f8f6
--- /dev/null
+++ b/test/pf/firewall51-mail_server_outbound.conf.orig
@@ -0,0 +1,8 @@
+#
+# Rule mail_server_outbound 0 (global)
+pass out quick inet proto tcp from any to any port { 53, 25 } keep state
+pass out quick inet proto udp from any to any port 53 keep state
+#
+# Rule mail_server_outbound 1 (global)
+pass out quick inet proto icmp from any to any icmp-type { 3 , 8 code 0 } keep state
+
diff --git a/test/pf/firewall51-rule2_branch.conf.orig b/test/pf/firewall51-rule2_branch.conf.orig
new file mode 100644
index 000000000..9df85d76c
--- /dev/null
+++ b/test/pf/firewall51-rule2_branch.conf.orig
@@ -0,0 +1,8 @@
+
+# Tables: (1)
+table { 192.168.1.0/24 , 192.168.2.0/24 }
+
+#
+# Rule rule2_branch 0 (global)
+block log quick inet from ! to any
+
diff --git a/test/pf/firewall51-web_server_inbound.conf.orig b/test/pf/firewall51-web_server_inbound.conf.orig
new file mode 100644
index 000000000..fb9cb751c
--- /dev/null
+++ b/test/pf/firewall51-web_server_inbound.conf.orig
@@ -0,0 +1,7 @@
+#
+# Rule web_server_inbound 0 (global)
+pass in quick inet proto tcp from any to any port 80 keep state
+#
+# Rule web_server_inbound 1 (global)
+pass in quick inet proto icmp from any to any icmp-type { 3 , 8 code 0 } keep state
+
diff --git a/test/pf/firewall51-web_server_outbound.conf.orig b/test/pf/firewall51-web_server_outbound.conf.orig
new file mode 100644
index 000000000..e9d28a6f1
--- /dev/null
+++ b/test/pf/firewall51-web_server_outbound.conf.orig
@@ -0,0 +1,8 @@
+#
+# Rule web_server_outbound 0 (global)
+pass out quick inet proto icmp from any to any icmp-type { 3 , 8 code 0 } keep state
+#
+# Rule web_server_outbound 1 (global)
+pass out quick inet proto tcp from any to any port 53 keep state
+pass out quick inet proto udp from any to any port 53 keep state
+
diff --git a/test/pf/firewall51.conf.orig b/test/pf/firewall51.conf.orig
new file mode 100644
index 000000000..077f0d3d8
--- /dev/null
+++ b/test/pf/firewall51.conf.orig
@@ -0,0 +1,23 @@
+
+
+
+#
+# Rule 0 (global)
+anchor "mail_server_inbound" inet from any to 192.168.1.10
+#
+# Rule 1 (global)
+anchor "mail_server_outbound" inet from 192.168.1.10 to any
+#
+# Rule 2 (global)
+anchor "web_server_inbound" inet from any to 192.168.1.20
+#
+# Rule 3 (global)
+anchor "web_server_outbound" inet from 192.168.1.20 to any
+#
+# Rule 4 (global)
+anchor "rule2_branch" inet from 192.168.1.0/24 to any
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any
+
diff --git a/test/pf/firewall51.fw.orig b/test/pf/firewall51.fw.orig
new file mode 100755
index 000000000..48f6834b5
--- /dev/null
+++ b/test/pf/firewall51.fw.orig
@@ -0,0 +1,110 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:44 2011 PST by vadim
+#
+# files: * firewall51.fw
+# files: firewall51.conf
+# files: firewall51-mail_server_inbound.conf
+# files: firewall51-mail_server_outbound.conf
+# files: firewall51-rule2_branch.conf
+# files: firewall51-web_server_inbound.conf
+# files: firewall51-web_server_outbound.conf
+#
+# Compiled for pf
+#
+# testing branching rules that point
+# at rule sets defined in object
+# firewall-base-rulesets
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:44 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall51.conf || exit 1
+$PFCTL -a mail_server_inbound \
+ -f \
+ ${FWDIR}/firewall51-mail_server_inbound.conf || exit 1
+$PFCTL -a mail_server_outbound \
+ -f \
+ ${FWDIR}/firewall51-mail_server_outbound.conf || exit 1
+$PFCTL -a rule2_branch \
+ -f \
+ ${FWDIR}/firewall51-rule2_branch.conf || exit 1
+$PFCTL -a web_server_inbound \
+ -f \
+ ${FWDIR}/firewall51-web_server_inbound.conf || exit 1
+$PFCTL -a web_server_outbound \
+ -f \
+ ${FWDIR}/firewall51-web_server_outbound.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall6.conf.orig b/test/pf/firewall6.conf.orig
new file mode 100644
index 000000000..67e33970a
--- /dev/null
+++ b/test/pf/firewall6.conf.orig
@@ -0,0 +1,21 @@
+
+
+
+
+# Tables: (1)
+table { 22.22.22.22 , 22.22.23.23 , 192.168.1.1 , 192.168.2.1 }
+
+# Policy compiler errors and warnings:
+# firewall6:Policy:1: warning: Changing rule direction due to self reference
+#
+# Rule 0 (eth1)
+block in log quick on eth1 inet from any to !
+#
+# Rule 1 (global)
+# firewall6:Policy:1: warning: Changing rule direction due to self reference
+block in quick inet from any to !
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any
+
diff --git a/test/pf/firewall6.fw.orig b/test/pf/firewall6.fw.orig
new file mode 100755
index 000000000..a8445a4fb
--- /dev/null
+++ b/test/pf/firewall6.fw.orig
@@ -0,0 +1,88 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:44 2011 PST by vadim
+#
+# files: * firewall6.fw
+# files: firewall6.conf
+#
+# Compiled for pf
+#
+# testing rule with firewall in dst and negation
+
+# firewall6:Policy:1: warning: Changing rule direction due to self reference
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:44 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall6.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall62.conf.orig b/test/pf/firewall62.conf.orig
new file mode 100644
index 000000000..171b0f049
--- /dev/null
+++ b/test/pf/firewall62.conf.orig
@@ -0,0 +1,91 @@
+
+
+
+
+# Tables: (1)
+table { 192.168.1.1 , 222.222.222.222 }
+
+# Policy compiler errors and warnings:
+# firewall62:Policy:1: error: Rule '1 (global)' shadows rule '2 (global)' below it
+# firewall62:Policy:1: error: Rule '1 (global)' shadows rule '2 (global)' below it
+# firewall62:Policy:1: error: Rule '1 (global)' shadows rule '3 (global)' below it
+# firewall62:Policy:1: error: Rule '1 (global)' shadows rule '3 (global)' below it
+# firewall62:Policy:1: error: Rule '1 (global)' shadows rule '4 (global)' below it
+# firewall62:Policy:3: error: Rule '3 (global)' shadows rule '4 (global)' below it
+# firewall62:Policy:1: error: Rule '1 (global)' shadows rule '4 (global)' below it
+# firewall62:Policy:3: error: Rule '3 (global)' shadows rule '4 (global)' below it
+# firewall62:Policy:1: error: Rule '1 (global)' shadows rule '5 (global)' below it
+# firewall62:Policy:3: error: Rule '3 (global)' shadows rule '5 (global)' below it
+# firewall62:Policy:1: error: Rule '1 (global)' shadows rule '5 (global)' below it
+# firewall62:Policy:3: error: Rule '3 (global)' shadows rule '5 (global)' below it
+# firewall62:Policy:1: error: Rule '1 (global)' shadows rule '6 (global)' below it
+# firewall62:Policy:8: error: Rule '8 (global)' shadows rule '9 (global)' below it
+# firewall62:Policy:8: error: Rule '8 (global)' shadows rule '9 (global)' below it
+# firewall62:Policy:8: error: Rule '8 (global)' shadows rule '10 (global)' below it
+# firewall62:Policy:8: error: Rule '8 (global)' shadows rule '10 (global)' below it
+# firewall62:Policy:1: warning: Changing rule direction due to self reference
+# firewall62:Policy:2: warning: Changing rule direction due to self reference
+# firewall62:Policy:4: warning: Changing rule direction due to self reference
+# firewall62:Policy:8: warning: Changing rule direction due to self reference
+# firewall62:Policy:9: warning: Changing rule direction due to self reference
+# firewall62:Policy:12: warning: Changing rule direction due to self reference
+#
+# Rule 0 (en0)
+# rule from FR 1948872
+# should generate
+# pass in quick on en0 user proxy
+pass in quick on en0 inet from any to any user proxy label "RULE 0 -- ACCEPT "
+#
+# Rule 1 (global)
+# firewall62:Policy:1: warning: Changing rule direction due to self reference
+pass out quick inet from to any user { 2000, 500 } label "RULE 1 -- ACCEPT "
+#
+# Rule 2 (global)
+# firewall62:Policy:2: warning: Changing rule direction due to self reference
+pass out quick inet from to any user 2000 label "RULE 2 -- ACCEPT "
+#
+# Rule 3 (global)
+pass out quick inet proto tcp from to any port 80 flags any label "RULE 3 -- ACCEPT "
+pass out quick inet from to any user 2000 label "RULE 3 -- ACCEPT "
+#
+# Rule 4 (global)
+# firewall62:Policy:4: warning: Changing rule direction due to self reference
+pass out quick inet proto tcp from to any port 80 flags any label "RULE 4 -- ACCEPT "
+# firewall62:Policy:4: warning: Changing rule direction due to self reference
+pass out quick inet from to any user 2000 label "RULE 4 -- ACCEPT "
+#
+# Rule 5 (global)
+pass out quick inet proto tcp from to any port 80 flags any label "RULE 5 -- ACCEPT "
+pass out quick inet from to any user 2000 label "RULE 5 -- ACCEPT "
+#
+# Rule 6 (global)
+pass quick inet from 192.168.1.1 to any user 2000 label "RULE 6 -- ACCEPT "
+#
+# Rule 7 (global)
+pass quick inet from 192.168.1.0/24 to any user 2000 label "RULE 7 -- ACCEPT "
+#
+# Rule 8 (global)
+# firewall62:Policy:8: warning: Changing rule direction due to self reference
+pass in quick inet from any to user 2000 label "RULE 8 -- ACCEPT "
+#
+# Rule 9 (global)
+# firewall62:Policy:9: warning: Changing rule direction due to self reference
+pass in quick inet from any to user { 2000, 500 } label "RULE 9 -- ACCEPT "
+#
+# Rule 10 (global)
+pass in quick inet from any to user 2000 label "RULE 10 -- ACCEPT "
+#
+# Rule 11 (global)
+pass quick inet from ! 192.168.1.0/24 to any user 2000 label "RULE 11 -- ACCEPT "
+#
+# Rule 12 (global)
+# firewall62:Policy:12: warning: Changing rule direction due to self reference
+pass in quick inet from any to ! user 2000 label "RULE 12 -- ACCEPT "
+#
+# Rule 13 (global)
+block quick inet from any to any no state label "RULE 13 -- DROP "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any no state label "RULE 10000 -- DROP "
+
diff --git a/test/pf/firewall62.fw.orig b/test/pf/firewall62.fw.orig
new file mode 100755
index 000000000..a5c11ce2a
--- /dev/null
+++ b/test/pf/firewall62.fw.orig
@@ -0,0 +1,204 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:45 2011 PST by vadim
+#
+# files: * firewall62.fw
+# files: firewall62.conf
+#
+# Compiled for pf 4.x
+#
+# testing rules using UserService object
+# Note that iptables does not allow entering
+# iptables command that tries to match using module 'owner' in any chain
+# other than OUTPUT. This includes user defined chains too (it checks
+# how control passes to user defined chain and blocks command if
+# it appears that user defined chain gets control not from OUTPUT)
+
+# firewall62:Policy:1: error: Rule '1 (global)' shadows rule '2 (global)' below it
+# firewall62:Policy:1: error: Rule '1 (global)' shadows rule '2 (global)' below it
+# firewall62:Policy:1: error: Rule '1 (global)' shadows rule '3 (global)' below it
+# firewall62:Policy:1: error: Rule '1 (global)' shadows rule '3 (global)' below it
+# firewall62:Policy:1: error: Rule '1 (global)' shadows rule '4 (global)' below it
+# firewall62:Policy:3: error: Rule '3 (global)' shadows rule '4 (global)' below it
+# firewall62:Policy:1: error: Rule '1 (global)' shadows rule '4 (global)' below it
+# firewall62:Policy:3: error: Rule '3 (global)' shadows rule '4 (global)' below it
+# firewall62:Policy:1: error: Rule '1 (global)' shadows rule '5 (global)' below it
+# firewall62:Policy:3: error: Rule '3 (global)' shadows rule '5 (global)' below it
+# firewall62:Policy:1: error: Rule '1 (global)' shadows rule '5 (global)' below it
+# firewall62:Policy:3: error: Rule '3 (global)' shadows rule '5 (global)' below it
+# firewall62:Policy:1: error: Rule '1 (global)' shadows rule '6 (global)' below it
+# firewall62:Policy:8: error: Rule '8 (global)' shadows rule '9 (global)' below it
+# firewall62:Policy:8: error: Rule '8 (global)' shadows rule '9 (global)' below it
+# firewall62:Policy:8: error: Rule '8 (global)' shadows rule '10 (global)' below it
+# firewall62:Policy:8: error: Rule '8 (global)' shadows rule '10 (global)' below it
+# firewall62:Policy:1: warning: Changing rule direction due to self reference
+# firewall62:Policy:2: warning: Changing rule direction due to self reference
+# firewall62:Policy:4: warning: Changing rule direction due to self reference
+# firewall62:Policy:8: warning: Changing rule direction due to self reference
+# firewall62:Policy:9: warning: Changing rule direction due to self reference
+# firewall62:Policy:12: warning: Changing rule direction due to self reference
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ update_addresses_of_interface "en0 192.168.1.1/0xffffff00" ""
+ update_addresses_of_interface "en1 222.222.222.222/0xffffff00" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:45 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall62.conf || exit 1
+
+
+
+$PFCTL -F states
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall63.conf.orig b/test/pf/firewall63.conf.orig
new file mode 100644
index 000000000..f70a2fd70
--- /dev/null
+++ b/test/pf/firewall63.conf.orig
@@ -0,0 +1,21 @@
+
+
+
+#
+# Rule 0 (global)
+block log quick inet from any to any tos 0x20
+#
+# Rule 1 (global)
+block log quick inet from any to any tos 0x10
+#
+# Rule 2 (global)
+block log quick inet from any to any tos 0x10
+block log quick inet from any to any tos 0x20
+#
+# Rule 4 (global)
+block log quick inet from any to any
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any
+
diff --git a/test/pf/firewall63.fw.orig b/test/pf/firewall63.fw.orig
new file mode 100755
index 000000000..c7ea1a4bc
--- /dev/null
+++ b/test/pf/firewall63.fw.orig
@@ -0,0 +1,92 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:46 2011 PST by vadim
+#
+# files: * firewall63.fw
+# files: firewall63.conf
+#
+# Compiled for pf
+#
+# testing tos matching
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.directed-broadcast=0
+ $SYSCTL -w net.inet.ip.forwarding=1
+
+ $SYSCTL -w net.inet.ip.sourceroute=0
+ $SYSCTL -w net.inet.ip.redirect=0
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:46 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall63.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall7.conf.orig b/test/pf/firewall7.conf.orig
new file mode 100644
index 000000000..7b1e7304b
--- /dev/null
+++ b/test/pf/firewall7.conf.orig
@@ -0,0 +1,14 @@
+
+
+
+#
+# Rule 0 (eth0)
+block in log quick on eth0 inet from any to 192.168.1.255
+#
+# Rule 1 (global)
+pass quick inet proto udp from any to 192.168.1.255 port 68 keep state
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any
+
diff --git a/test/pf/firewall7.fw.orig b/test/pf/firewall7.fw.orig
new file mode 100755
index 000000000..1612c3641
--- /dev/null
+++ b/test/pf/firewall7.fw.orig
@@ -0,0 +1,88 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:47 2011 PST by vadim
+#
+# files: * firewall7.fw
+# files: firewall7.conf
+#
+# Compiled for pf
+#
+# testing rules with broadcasts
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:47 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall7.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall70.conf.orig b/test/pf/firewall70.conf.orig
new file mode 100644
index 000000000..b31e1e0b0
--- /dev/null
+++ b/test/pf/firewall70.conf.orig
@@ -0,0 +1,43 @@
+
+
+
+
+# Tables: (1)
+table { 22.22.22.22 , 192.0.2.1 , 192.168.1.1 }
+
+# Policy compiler errors and warnings:
+# firewall70:Policy:0: warning: Changing rule direction due to self reference
+# firewall70:Policy:1: warning: Changing rule direction due to self reference
+# firewall70:Policy:2: warning: Changing rule direction due to self reference
+# firewall70:Policy:3: warning: Changing rule direction due to self reference
+# firewall70:Policy:4: warning: Changing rule direction due to self reference
+# firewall70:Policy:5: warning: Changing rule direction due to self reference
+#
+# Rule 0 (global)
+# firewall70:Policy:0: warning: Changing rule direction due to self reference
+pass in quick inet proto tcp from any to port 22 flags S/SA keep state
+#
+# Rule 1 (en0)
+# firewall70:Policy:1: warning: Changing rule direction due to self reference
+pass in quick on en0 inet proto tcp from any to port 22 flags S/SA keep state
+#
+# Rule 2 (en0,en1)
+# firewall70:Policy:2: warning: Changing rule direction due to self reference
+pass in quick on { en0 en1 } inet proto tcp from any to port 22 flags S/SA keep state
+#
+# Rule 3 (en2,en0,en1,en3)
+# firewall70:Policy:3: warning: Changing rule direction due to self reference
+pass in quick on { en2 en0 en1 en3 } inet proto tcp from any to port 22 flags S/SA keep state
+#
+# Rule 4 (en0)
+# firewall70:Policy:4: warning: Changing rule direction due to self reference
+pass in quick on { en1 en2 } inet proto tcp from any to port 22 flags S/SA keep state
+#
+# Rule 5 (en0,en1)
+# firewall70:Policy:5: warning: Changing rule direction due to self reference
+pass in quick on en2 inet proto tcp from any to port 22 flags S/SA keep state
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any
+
diff --git a/test/pf/firewall70.fw.orig b/test/pf/firewall70.fw.orig
new file mode 100755
index 000000000..0341f1341
--- /dev/null
+++ b/test/pf/firewall70.fw.orig
@@ -0,0 +1,97 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:47 2011 PST by vadim
+#
+# files: * firewall70.fw
+# files: firewall70.conf
+#
+# Compiled for pf
+#
+# testing for unpotected interfaces
+
+# firewall70:Policy:0: warning: Changing rule direction due to self reference
+# firewall70:Policy:1: warning: Changing rule direction due to self reference
+# firewall70:Policy:2: warning: Changing rule direction due to self reference
+# firewall70:Policy:3: warning: Changing rule direction due to self reference
+# firewall70:Policy:4: warning: Changing rule direction due to self reference
+# firewall70:Policy:5: warning: Changing rule direction due to self reference
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.directed-broadcast=0
+ $SYSCTL -w net.inet.ip.forwarding=1
+
+ $SYSCTL -w net.inet.ip.sourceroute=0
+ $SYSCTL -w net.inet.ip.redirect=0
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:47 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall70.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall8.conf.orig b/test/pf/firewall8.conf.orig
new file mode 100644
index 000000000..d545af768
--- /dev/null
+++ b/test/pf/firewall8.conf.orig
@@ -0,0 +1,61 @@
+
+
+
+
+# Tables: (2)
+table { ppp0 , 33.33.33.33 , 33.33.33.34 , 192.168.1.1 }
+table { 33.33.33.33 , 33.33.33.34 }
+
+#
+# Rule 0 (NAT)
+nat on eth1 proto {tcp udp icmp} from 192.168.1.0/24 to any -> { 33.33.33.33 , 33.33.33.34 }
+nat on eth0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.1.1
+nat on ppp0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> (ppp0)
+#
+# Rule 1 (NAT)
+nat on eth1 proto {tcp udp icmp} from 192.168.1.0/24 to any -> { 33.33.33.33 , 33.33.33.34 }
+#
+# Rule 2 (NAT)
+nat on eth1 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 33.33.33.33
+#
+# Rule 3 (NAT)
+rdr proto tcp from any to port 22 -> 192.168.1.100 port 22
+#
+# Rule 4 (NAT)
+rdr on eth1 proto tcp from any to 33.33.33.34 port 22 -> 192.168.1.100 port 22
+#
+# Rule 5 (NAT)
+rdr on eth1 proto tcp from any to 33.33.33.34 port 22 -> 192.168.1.100 port 22
+#
+# Rule 6 (NAT)
+rdr on eth1 proto tcp from any to 33.33.33.34 port 22 -> 192.168.1.100 port 22
+#
+# Rule 7 (NAT)
+rdr on eth1 proto tcp from any to 33.33.33.34 port 22 -> 192.168.1.100 port 22
+#
+# Rule 8 (NAT)
+rdr proto tcp from 192.168.1.0/24 to any port 80 -> 33.33.33.34 port 80
+
+#
+# Rule 0 (global)
+pass inet from any to any
+#
+# Rule 1 (global)
+pass log inet from any to any
+#
+# Rule 2 (global)
+pass quick inet proto tcp from any to 33.33.33.33 port 22 flags S/SA keep state
+#
+# Rule 3 (global)
+pass quick inet proto tcp from any to 33.33.33.34 port 22 flags S/SA keep state
+#
+# Rule 4 (global)
+pass quick inet proto tcp from any to port 22 flags S/SA keep state
+#
+# Rule 5 (global)
+block log quick inet from any to any
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any
+
diff --git a/test/pf/firewall8.fw.orig b/test/pf/firewall8.fw.orig
new file mode 100755
index 000000000..074944302
--- /dev/null
+++ b/test/pf/firewall8.fw.orig
@@ -0,0 +1,87 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:48 2011 PST by vadim
+#
+# files: * firewall8.fw
+# files: firewall8.conf
+#
+# Compiled for pf
+#
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/usr/sbin/pfctl"
+SYSCTL="/usr/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:48 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall8.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall80-4.5.conf.orig b/test/pf/firewall80-4.5.conf.orig
new file mode 100644
index 000000000..09db7b092
--- /dev/null
+++ b/test/pf/firewall80-4.5.conf.orig
@@ -0,0 +1,43 @@
+
+
+
+#
+# Rule 0 (global)
+pass quick inet proto tcp from any to 33.33.33.34 port 22 no state
+#
+# Rule 1 (global)
+pass quick inet proto tcp from any to 33.33.33.34 port 22 keep state
+#
+# Rule 2 (global)
+pass quick inet proto tcp from any to 33.33.33.34 port 22
+#
+# Rule 3 (global)
+# activate source tracking
+pass quick inet proto tcp from any to 33.33.33.34 port 22 keep state ( max-src-nodes 10 )
+#
+# Rule 4 (global)
+# modulate state
+pass quick inet proto tcp from any to 33.33.33.34 port 22 modulate state ( max-src-nodes 10 )
+#
+# Rule 5 (global)
+# synproxy
+pass quick inet proto tcp from any to 33.33.33.34 port 22 synproxy state ( max-src-nodes 10 )
+#
+# Rule 6 (global)
+# keep state, no-sync, pflow
+pass quick inet proto tcp from any to 33.33.33.34 port 22 keep state ( no-sync, pflow, max-src-nodes 10 )
+#
+# Rule 7 (global)
+pass quick inet from any to 33.33.33.34
+#
+# Rule 8 (global)
+# synproxy
+pass quick inet from any to any
+#
+# Rule 9 (global)
+block log quick inet from any to any no state
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any no state
+
diff --git a/test/pf/firewall80-4.5.fw.orig b/test/pf/firewall80-4.5.fw.orig
new file mode 100755
index 000000000..1dd1f042c
--- /dev/null
+++ b/test/pf/firewall80-4.5.fw.orig
@@ -0,0 +1,90 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:50 2011 PST by vadim
+#
+# files: * firewall80-4.5.fw
+# files: firewall80-4.5.conf
+#
+# Compiled for pf 4.5
+#
+# Testin state tracking options
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/usr/sbin/pfctl"
+SYSCTL="/usr/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:50 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall80-4.5.conf || exit 1
+
+
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall80.conf.orig b/test/pf/firewall80.conf.orig
new file mode 100644
index 000000000..9e6264abb
--- /dev/null
+++ b/test/pf/firewall80.conf.orig
@@ -0,0 +1,27 @@
+
+
+
+#
+# Rule 0 (global)
+pass quick inet proto tcp from any to 33.33.33.34 port 22
+#
+# Rule 1 (global)
+pass quick inet proto tcp from any to 33.33.33.34 port 22 flags S/SA keep state
+#
+# Rule 2 (global)
+pass quick inet proto tcp from any to 33.33.33.34 port 22 flags S/SA keep state
+#
+# Rule 3 (global)
+pass quick inet proto tcp from any to 33.33.33.34 port 22 flags S/SA keep state ( max-src-nodes 10 )
+#
+# Rule 4 (global)
+# synproxy
+pass quick inet proto tcp from any to 33.33.33.34 port 22 flags S/SA synproxy state
+#
+# Rule 5 (global)
+block log quick inet from any to any
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any
+
diff --git a/test/pf/firewall80.fw.orig b/test/pf/firewall80.fw.orig
new file mode 100755
index 000000000..2ea1f6cea
--- /dev/null
+++ b/test/pf/firewall80.fw.orig
@@ -0,0 +1,88 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:49 2011 PST by vadim
+#
+# files: * firewall80.fw
+# files: firewall80.conf
+#
+# Compiled for pf ge_3.7
+#
+# Testin state tracking options
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/usr/sbin/pfctl"
+SYSCTL="/usr/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:49 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall80.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall9.conf.orig b/test/pf/firewall9.conf.orig
new file mode 100644
index 000000000..5cbe061f3
--- /dev/null
+++ b/test/pf/firewall9.conf.orig
@@ -0,0 +1,24 @@
+
+
+
+#
+# Rule 1 (NAT)
+nat on eth0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 192.168.1.1
+
+#
+# Rule 0 (eth0)
+block in log quick on eth0 inet from any to 192.168.1.255
+#
+# Rule 1 (lo)
+pass quick on lo inet from any to any keep state
+#
+# Rule 3 (global)
+pass quick inet proto udp from any to 192.168.1.255 port 68 keep state
+#
+# Rule 4 (global)
+block log quick inet from any to any
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any
+
diff --git a/test/pf/firewall9.fw.orig b/test/pf/firewall9.fw.orig
new file mode 100755
index 000000000..82ed1cf4e
--- /dev/null
+++ b/test/pf/firewall9.fw.orig
@@ -0,0 +1,91 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:50 2011 PST by vadim
+#
+# files: * firewall9.fw
+# files: firewall9.conf
+#
+# Compiled for pf
+#
+# testing rules with broadcasts
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/usr/local/bin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:50 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/firewall9.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall91.conf.orig b/test/pf/firewall91.conf.orig
new file mode 100644
index 000000000..d175664ab
--- /dev/null
+++ b/test/pf/firewall91.conf.orig
@@ -0,0 +1,19 @@
+
+
+
+
+# Tables: (1)
+table { 10.1.1.50 , 10.3.14.50 , 10.100.101.1 , 10.100.103.1 }
+
+#
+# Rule backup ssh access rule
+# backup ssh access rule
+pass in quick inet proto tcp from 10.3.14.30 to port 22 flags S/SA keep state label "RULE 9998 -- ACCEPT "
+#
+# Rule 0 (global)
+block log quick inet from any to any label "RULE 0 -- DROP "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any label "RULE 10000 -- DROP "
+
diff --git a/test/pf/firewall91.fw.orig b/test/pf/firewall91.fw.orig
new file mode 100755
index 000000000..3447e3ac3
--- /dev/null
+++ b/test/pf/firewall91.fw.orig
@@ -0,0 +1,258 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:51 2011 PST by vadim
+#
+# files: * firewall91.fw /etc/fw/pf.fw
+# files: firewall91.conf /etc/fw/pf.conf
+#
+# Compiled for pf
+#
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+missing_vlan() {
+ vlan=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $vlan
+ subint=$1
+ parent=$2
+ IFS=$oldIFS
+
+ vlan_id=$(echo $subint | sed 's/vlan//')
+ test "$cmd" = "add" && {
+ echo "# Adding VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $IFCONFIG $subint vlan $vlan_id vlandev $parent
+ $FWBDEBUG $IFCONFIG $subint up
+ }
+ test "$cmd" = "rem" && {
+ echo "# Removing VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $IFCONFIG $subint vlan $vlan_id -vlandev
+ $FWBDEBUG $IFCONFIG $subint destroy
+ }
+}
+
+parse_fwb_vlans() {
+ set $1
+ vlan_parent_interface=$1
+ shift
+
+ FWB_VLANS=$(
+ for subint in $*; do
+ echo "${subint}@$vlan_parent_interface"
+ done | sort
+ )
+ echo $FWB_VLANS
+}
+
+parse_current_vlans() {
+ vlan_parent_interface=$1
+ $IFCONFIG -A | grep 'vlan: ' | sed 's/priority:.*parent interface://' | \
+ while read x vlan_id parent
+ do
+ test "$parent" = "$vlan_parent_interface" && echo "vlan$vlan_id@$parent"
+ done | sort
+}
+
+update_vlans_of_interface() {
+ args="$1"
+ set $1
+ vlan_parent_interface=$1
+
+ FWB_VLANS=$(parse_fwb_vlans "$args")
+ CURRENT_VLANS=$(parse_current_vlans $vlan_parent_interface)
+
+ $IFCONFIG $vlan_parent_interface up
+ diff_intf missing_vlan "$FWB_VLANS" "$CURRENT_VLANS" add
+ diff_intf missing_vlan "$CURRENT_VLANS" "$FWB_VLANS" rem
+}
+
+sync_vlan_interfaces() {
+ $IFCONFIG -A | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ii=ignored_arr[a]":"; ignored_dict[ii]=1;}
+ }
+ ($1 ~ /^vlan[0-9]/ && !($1 in ignored_dict)) {print $1;}' | sed 's/://' |\
+ while read intf; do
+ echo "# Deleting vlan interface $intf"
+ $FWBDEBUG $IFCONFIG $intf destroy
+ done
+
+ for intf in $*; do
+ $IFCONFIG $intf >/dev/null 2>&1 || {
+ echo "# Creating vlan interface $intf"
+ $FWBDEBUG $IFCONFIG $intf create
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ sync_vlan_interfaces vlan101 vlan103
+ update_vlans_of_interface "pcn0 "
+ update_vlans_of_interface "em0 vlan101 vlan103 "
+
+
+ update_addresses_of_interface "em0 10.1.1.50/0xffffff00" ""
+ update_addresses_of_interface "pcn0 10.3.14.50/0xffffff00" ""
+ update_addresses_of_interface "vlan101 10.100.101.1/0xffffff00" ""
+ update_addresses_of_interface "vlan103 10.100.103.1/0xffffff00" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:51 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ /etc/fw/pf.conf || exit 1
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/firewall92.conf.orig b/test/pf/firewall92.conf.orig
new file mode 100644
index 000000000..32f19c0f6
--- /dev/null
+++ b/test/pf/firewall92.conf.orig
@@ -0,0 +1,52 @@
+
+set timeout udp.single 5
+
+#
+# Scrub rules
+#
+match in all scrub (reassemble tcp no-df )
+match out all scrub (random-id min-ttl 1 max-mss 1460)
+
+
+# Tables: (1)
+table { 10.1.1.81 , 10.3.14.81 }
+
+# NAT compiler errors and warnings:
+# firewall92:NAT:2: error: No translation rules are not supported for PF 4.7, use negation to implement exclusions
+#
+# Rule 0 (NAT)
+match out on em0 proto {tcp udp icmp} from 10.1.1.0/24 to any nat-to 10.3.14.81
+#
+# Rule 1 (NAT)
+match in on em0 proto udp from ! 10.3.14.41 to 10.3.14.81 port 161 rdr-to 10.1.1.1 port 161
+#
+# Rule 3 (NAT)
+match in on em0 proto udp from any to 10.3.14.81 port 161 rdr-to 10.1.1.1 port 161
+
+# Policy compiler errors and warnings:
+# firewall92:Policy:0: warning: Changing rule direction due to self reference
+#
+# Rule backup ssh access rule
+# backup ssh access rule
+pass in quick inet proto tcp from 10.3.14.30 to port 22 label "RULE 9998 -- ACCEPT "
+#
+# Rule 0 (global)
+# firewall92:Policy:0: warning: Changing rule direction due to self reference
+pass in quick inet proto tcp from 10.3.14.0/24 to port 22 label "RULE 0 -- ACCEPT "
+#
+# Rule 1 (global)
+pass quick inet from 10.1.1.0/24 to any label "RULE 1 -- ACCEPT "
+#
+# Rule 2 (global)
+match inet from any to 10.1.1.1 tag INTNET label "RULE 2 -- "
+#
+# Rule 3 (global)
+pass quick inet proto udp from any to any port 161 label "RULE 3 -- ACCEPT "
+#
+# Rule 4 (global)
+block log quick inet from any to any no state label "RULE 4 -- DROP "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any no state label "RULE 10000 -- DROP "
+
diff --git a/test/pf/firewall92.fw.orig b/test/pf/firewall92.fw.orig
new file mode 100755
index 000000000..c0596f674
--- /dev/null
+++ b/test/pf/firewall92.fw.orig
@@ -0,0 +1,177 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:52 2011 PST by vadim
+#
+# files: * firewall92.fw /etc/fw/pf.fw
+# files: firewall92.conf /etc/fw/path\ with\ space/pf.conf
+#
+# Compiled for pf 4.7
+#
+# syntax of the nat and rdr rules has changed in 4.7
+
+# firewall92:NAT:2: error: No translation rules are not supported for PF 4.7, use negation to implement exclusions
+
+# firewall92:Policy:0: warning: Changing rule direction due to self reference
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ update_addresses_of_interface "em0 10.3.14.81/0xffffff00" ""
+ update_addresses_of_interface "em1 10.1.1.81/0xffffff00" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:52 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ /etc/fw/path\ with\ space/pf.conf || exit 1
+
+
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/pf_cluster_1_openbsd-1.conf.orig b/test/pf/pf_cluster_1_openbsd-1.conf.orig
new file mode 100644
index 000000000..53a164f24
--- /dev/null
+++ b/test/pf/pf_cluster_1_openbsd-1.conf.orig
@@ -0,0 +1,71 @@
+
+
+
+
+# Tables: (2)
+table { 172.24.0.1 , 172.24.0.2 , 192.168.1.1 , 192.168.1.2 }
+table { 172.24.0.1 , 172.24.0.2 }
+
+#
+# Rule 0 (NAT)
+nat on en0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 172.24.0.1
+#
+# Rule 1 (NAT)
+nat on en0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 172.24.0.1
+#
+# Rule 2 (NAT)
+nat proto {tcp udp icmp} from 192.168.1.0/24 to any -> 172.24.0.1
+#
+# Rule 3 (NAT)
+nat on en0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> { 172.24.0.2 , 172.24.0.3 }
+#
+# Rule 4 (NAT)
+nat on en0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 172.24.0.2
+#
+# Rule 5 (NAT)
+nat proto {tcp udp icmp} from 192.168.1.0/24 to any -> 172.24.0.3
+#
+# Rule 6 (NAT)
+rdr on en0 proto tcp from any to 172.24.0.1 port 80 -> 172.24.0.100 port 80
+#
+# Rule 7 (NAT)
+rdr on en0 proto tcp from any to 172.24.0.1 port 80 -> 172.24.0.100 port 80
+#
+# Rule 8 (NAT)
+rdr proto tcp from any to 172.24.0.1 port 80 -> 172.24.0.100 port 80
+
+#
+# Rule -3 pfsync (automatic)
+pass quick on en0 inet proto pfsync from any to any label "RULE -3 -- ACCEPT "
+#
+# Rule -2 CARP (automatic)
+pass quick on en1 inet proto carp from any to any label "RULE -2 -- ACCEPT "
+#
+# Rule -1 CARP (automatic)
+pass quick on en0 inet proto carp from any to any label "RULE -1 -- ACCEPT "
+#
+# Rule 0 (lo)
+pass quick on lo inet from any to any label "RULE 0 -- ACCEPT "
+#
+# Rule 1 (global)
+pass quick inet from any to label "RULE 1 -- ACCEPT "
+#
+# Rule 2 (global)
+pass quick inet from to any label "RULE 2 -- ACCEPT "
+#
+# Rule 3 (global)
+pass quick inet from any to label "RULE 3 -- ACCEPT "
+#
+# Rule 4 (carp0)
+pass in quick on en0 inet from any to any label "RULE 4 -- ACCEPT "
+#
+# Rule 5 (carp0)
+pass in quick on en1 inet from any to any label "RULE 5 -- ACCEPT "
+#
+# Rule 6 (global)
+block log quick inet from any to any no state label "RULE 6 -- DROP "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any no state label "RULE 10000 -- DROP "
+
diff --git a/test/pf/pf_cluster_1_openbsd-1.fw.orig b/test/pf/pf_cluster_1_openbsd-1.fw.orig
new file mode 100755
index 000000000..a85f9fd49
--- /dev/null
+++ b/test/pf/pf_cluster_1_openbsd-1.fw.orig
@@ -0,0 +1,308 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:55 2011 PST by vadim
+#
+# files: * pf_cluster_1_openbsd-1.fw
+# files: pf_cluster_1_openbsd-1.conf
+#
+# Compiled for pf 4.x
+#
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+missing_vlan() {
+ vlan=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $vlan
+ subint=$1
+ parent=$2
+ IFS=$oldIFS
+
+ vlan_id=$(echo $subint | sed 's/vlan//')
+ test "$cmd" = "add" && {
+ echo "# Adding VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $IFCONFIG $subint vlan $vlan_id vlandev $parent
+ $FWBDEBUG $IFCONFIG $subint up
+ }
+ test "$cmd" = "rem" && {
+ echo "# Removing VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $IFCONFIG $subint vlan $vlan_id -vlandev
+ $FWBDEBUG $IFCONFIG $subint destroy
+ }
+}
+
+parse_fwb_vlans() {
+ set $1
+ vlan_parent_interface=$1
+ shift
+
+ FWB_VLANS=$(
+ for subint in $*; do
+ echo "${subint}@$vlan_parent_interface"
+ done | sort
+ )
+ echo $FWB_VLANS
+}
+
+parse_current_vlans() {
+ vlan_parent_interface=$1
+ $IFCONFIG -A | grep 'vlan: ' | sed 's/priority:.*parent interface://' | \
+ while read x vlan_id parent
+ do
+ test "$parent" = "$vlan_parent_interface" && echo "vlan$vlan_id@$parent"
+ done | sort
+}
+
+update_vlans_of_interface() {
+ args="$1"
+ set $1
+ vlan_parent_interface=$1
+
+ FWB_VLANS=$(parse_fwb_vlans "$args")
+ CURRENT_VLANS=$(parse_current_vlans $vlan_parent_interface)
+
+ $IFCONFIG $vlan_parent_interface up
+ diff_intf missing_vlan "$FWB_VLANS" "$CURRENT_VLANS" add
+ diff_intf missing_vlan "$CURRENT_VLANS" "$FWB_VLANS" rem
+}
+
+sync_vlan_interfaces() {
+ $IFCONFIG -A | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ii=ignored_arr[a]":"; ignored_dict[ii]=1;}
+ }
+ ($1 ~ /^vlan[0-9]/ && !($1 in ignored_dict)) {print $1;}' | sed 's/://' |\
+ while read intf; do
+ echo "# Deleting vlan interface $intf"
+ $FWBDEBUG $IFCONFIG $intf destroy
+ done
+
+ for intf in $*; do
+ $IFCONFIG $intf >/dev/null 2>&1 || {
+ echo "# Creating vlan interface $intf"
+ $FWBDEBUG $IFCONFIG $intf create
+ }
+ done
+}
+
+
+sync_carp_interfaces() {
+ $IFCONFIG -A | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ii=ignored_arr[a]":"; ignored_dict[ii]=1;}
+ }
+ ($1 ~ /^carp[0-9]/ && !($1 in ignored_dict)) {print $1;}' | sed 's/://' |\
+ while read intf; do
+ echo "# Deleting carp interface $intf"
+ $FWBDEBUG $IFCONFIG $intf destroy
+ done
+
+ for intf in $*; do
+ $IFCONFIG $intf >/dev/null 2>&1 || {
+ echo "# Creating carp interface $intf"
+ $SYSCTL -w net.inet.carp.allow=1
+ $FWBDEBUG $IFCONFIG $intf create
+ }
+ done
+}
+
+
+sync_pfsync_interfaces() {
+ $IFCONFIG -A | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ii=ignored_arr[a]":"; ignored_dict[ii]=1;}
+ }
+ ($1 ~ /^pfsync[0-9]/ && !($1 in ignored_dict)) {print $1;}' | sed 's/://' |\
+ while read intf; do
+ echo "# Deleting pfsync interface $intf"
+ $FWBDEBUG $IFCONFIG $intf destroy
+ done
+
+ for intf in $*; do
+ $IFCONFIG $intf >/dev/null 2>&1 || {
+ echo "# Creating pfsync interface $intf"
+ $FWBDEBUG $IFCONFIG $intf create
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ sync_vlan_interfaces
+ sync_carp_interfaces carp0 carp1
+ $IFCONFIG carp0 vhid 101 pass secret carpdev en0
+ $IFCONFIG carp1 vhid 100 pass secret carpdev en1
+
+
+ update_addresses_of_interface "en0 172.24.0.2/0xffffff00 172.24.0.3/0xffffff00" ""
+ update_addresses_of_interface "en1 192.168.1.2/0xffffff00" ""
+ update_addresses_of_interface "carp0 172.24.0.1/0xffffff00" ""
+ update_addresses_of_interface "carp1 192.168.1.1/0xffffff00" ""
+
+ sync_pfsync_interfaces pfsync0
+ $IFCONFIG pfsync0 syncdev en0 syncpeer 172.24.0.3
+ $IFCONFIG pfsync0 up
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:55 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/pf_cluster_1_openbsd-1.conf || exit 1
+
+
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/pf_cluster_1_openbsd-2.conf.orig b/test/pf/pf_cluster_1_openbsd-2.conf.orig
new file mode 100644
index 000000000..d138c2284
--- /dev/null
+++ b/test/pf/pf_cluster_1_openbsd-2.conf.orig
@@ -0,0 +1,71 @@
+
+
+
+
+# Tables: (2)
+table { 172.24.0.1 , 172.24.0.3 , 192.168.1.1 , 192.168.1.3 }
+table { 172.24.0.1 , 172.24.0.3 }
+
+#
+# Rule 0 (NAT)
+nat on en0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 172.24.0.1
+#
+# Rule 1 (NAT)
+nat on en0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 172.24.0.1
+#
+# Rule 2 (NAT)
+nat proto {tcp udp icmp} from 192.168.1.0/24 to any -> 172.24.0.1
+#
+# Rule 3 (NAT)
+nat proto {tcp udp icmp} from 192.168.1.0/24 to any -> { 172.24.0.2 , 172.24.0.3 }
+#
+# Rule 4 (NAT)
+nat proto {tcp udp icmp} from 192.168.1.0/24 to any -> 172.24.0.2
+#
+# Rule 5 (NAT)
+nat on en0 proto {tcp udp icmp} from 192.168.1.0/24 to any -> 172.24.0.3
+#
+# Rule 6 (NAT)
+rdr on en0 proto tcp from any to 172.24.0.1 port 80 -> 172.24.0.100 port 80
+#
+# Rule 7 (NAT)
+rdr on en0 proto tcp from any to 172.24.0.1 port 80 -> 172.24.0.100 port 80
+#
+# Rule 8 (NAT)
+rdr proto tcp from any to 172.24.0.1 port 80 -> 172.24.0.100 port 80
+
+#
+# Rule -3 pfsync (automatic)
+pass quick on en0 inet proto pfsync from any to any label "RULE -3 -- ACCEPT "
+#
+# Rule -2 CARP (automatic)
+pass quick on en1 inet proto carp from any to any label "RULE -2 -- ACCEPT "
+#
+# Rule -1 CARP (automatic)
+pass quick on en0 inet proto carp from any to any label "RULE -1 -- ACCEPT "
+#
+# Rule 0 (lo)
+pass quick on lo inet from any to any label "RULE 0 -- ACCEPT "
+#
+# Rule 1 (global)
+pass quick inet from any to label "RULE 1 -- ACCEPT "
+#
+# Rule 2 (global)
+pass quick inet from to any label "RULE 2 -- ACCEPT "
+#
+# Rule 3 (global)
+pass quick inet from any to label "RULE 3 -- ACCEPT "
+#
+# Rule 4 (carp0)
+pass in quick on en0 inet from any to any label "RULE 4 -- ACCEPT "
+#
+# Rule 5 (carp0)
+pass in quick on en1 inet from any to any label "RULE 5 -- ACCEPT "
+#
+# Rule 6 (global)
+block log quick inet from any to any no state label "RULE 6 -- DROP "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any no state label "RULE 10000 -- DROP "
+
diff --git a/test/pf/pf_cluster_1_openbsd-2.fw.orig b/test/pf/pf_cluster_1_openbsd-2.fw.orig
new file mode 100755
index 000000000..0b0c1df21
--- /dev/null
+++ b/test/pf/pf_cluster_1_openbsd-2.fw.orig
@@ -0,0 +1,204 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:55 2011 PST by vadim
+#
+# files: * pf_cluster_1_openbsd-2.fw
+# files: pf_cluster_1_openbsd-2.conf
+#
+# Compiled for pf 4.x
+#
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+
+
+sync_carp_interfaces() {
+ $IFCONFIG -A | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ii=ignored_arr[a]":"; ignored_dict[ii]=1;}
+ }
+ ($1 ~ /^carp[0-9]/ && !($1 in ignored_dict)) {print $1;}' | sed 's/://' |\
+ while read intf; do
+ echo "# Deleting carp interface $intf"
+ $FWBDEBUG $IFCONFIG $intf destroy
+ done
+
+ for intf in $*; do
+ $IFCONFIG $intf >/dev/null 2>&1 || {
+ echo "# Creating carp interface $intf"
+ $SYSCTL -w net.inet.carp.allow=1
+ $FWBDEBUG $IFCONFIG $intf create
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ sync_carp_interfaces carp0 carp1
+ $IFCONFIG carp0 vhid 101 pass secret advskew 1 carpdev en0
+ $IFCONFIG carp1 vhid 100 pass secret advskew 1 carpdev en1
+
+
+ update_addresses_of_interface "en0 172.24.0.3/0xffffff00 172.24.0.2/0xffffff00" ""
+ update_addresses_of_interface "en1 192.168.1.3/0xffffff00" ""
+ update_addresses_of_interface "carp0 172.24.0.1/0xffffff00" ""
+ update_addresses_of_interface "carp1 192.168.1.1/0xffffff00" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:55 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/pf_cluster_1_openbsd-2.conf || exit 1
+
+
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/pf_cluster_2_freebsd-2.conf.orig b/test/pf/pf_cluster_2_freebsd-2.conf.orig
new file mode 100644
index 000000000..c468f1175
--- /dev/null
+++ b/test/pf/pf_cluster_2_freebsd-2.conf.orig
@@ -0,0 +1,20 @@
+
+
+
+#
+# Rule -3 pfsync (automatic)
+pass quick on en0 inet proto pfsync from any to any label "RULE -3 -- ACCEPT "
+#
+# Rule -2 CARP (automatic)
+pass quick on en1 inet proto carp from any to any label "RULE -2 -- ACCEPT "
+#
+# Rule -1 CARP (automatic)
+pass quick on en0 inet proto carp from any to any label "RULE -1 -- ACCEPT "
+#
+# Rule 0 (global)
+block log quick inet from any to any no state label "RULE 0 -- DROP "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any no state label "RULE 10000 -- DROP "
+
diff --git a/test/pf/pf_cluster_2_freebsd-2.fw.orig b/test/pf/pf_cluster_2_freebsd-2.fw.orig
new file mode 100755
index 000000000..253247045
--- /dev/null
+++ b/test/pf/pf_cluster_2_freebsd-2.fw.orig
@@ -0,0 +1,207 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:55 2011 PST by vadim
+#
+# files: * pf_cluster_2_freebsd-2.fw
+# files: pf_cluster_2_freebsd-2.conf
+#
+# Compiled for pf 4.x
+#
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+IPFW="/sbin/ipfw"
+IPF="/sbin/ipf"
+IPNAT="/sbin/ipnat"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+
+
+sync_carp_interfaces() {
+ $IFCONFIG -A | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ii=ignored_arr[a]":"; ignored_dict[ii]=1;}
+ }
+ ($1 ~ /^carp[0-9]/ && !($1 in ignored_dict)) {print $1;}' | sed 's/://' |\
+ while read intf; do
+ echo "# Deleting carp interface $intf"
+ $FWBDEBUG $IFCONFIG $intf destroy
+ done
+
+ for intf in $*; do
+ $IFCONFIG $intf >/dev/null 2>&1 || {
+ echo "# Creating carp interface $intf"
+ $SYSCTL -w net.inet.carp.allow=1
+ $FWBDEBUG $IFCONFIG $intf create
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ sync_carp_interfaces carp0 carp1
+ $IFCONFIG carp0 vhid 101 pass secret advskew 10 carpdev en0
+ $IFCONFIG carp1 vhid 100 pass secret advskew 10 carpdev en1
+
+
+ update_addresses_of_interface "en0 172.24.0.3/0xffffff00" ""
+ update_addresses_of_interface "en1 192.168.1.3/0xffffff00" ""
+ update_addresses_of_interface "carp0 172.24.0.1/0xffffff00 172.24.0.1/0xffffff00" ""
+ update_addresses_of_interface "carp1 192.168.1.1/0xffffff00" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:55 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/pf_cluster_2_freebsd-2.conf || exit 1
+
+
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/pf_cluster_3_openbsd-3.conf.orig b/test/pf/pf_cluster_3_openbsd-3.conf.orig
new file mode 100644
index 000000000..2703f5656
--- /dev/null
+++ b/test/pf/pf_cluster_3_openbsd-3.conf.orig
@@ -0,0 +1,63 @@
+
+
+
+
+# Tables: (1)
+table { 172.20.0.1 , 172.20.0.2 , 172.24.0.1 , 172.24.0.2 , 192.168.1.1 , 192.168.1.2 }
+
+#
+# Rule -4 CARP (automatic)
+pass quick on vlan100 inet proto carp from any to any label "RULE -4 -- ACCEPT "
+#
+# Rule -3 CARP (automatic)
+pass quick on lo inet proto carp from any to any label "RULE -3 -- ACCEPT "
+#
+# Rule -2 CARP (automatic)
+pass quick on en1 inet proto carp from any to any label "RULE -2 -- ACCEPT "
+#
+# Rule -1 CARP (automatic)
+pass quick on en0 inet proto carp from any to any label "RULE -1 -- ACCEPT "
+#
+# Rule 0 (carp0)
+block in log quick on en0 inet from to any no state label "RULE 0 -- DROP "
+#
+# Rule 1 (carp0)
+pass quick on en0 inet from any to any label "RULE 1 -- ACCEPT "
+#
+# Rule 2 (carp0,carp1)
+pass quick on { en0 en1 } inet proto tcp from any to port 22 label "RULE 2 -- ACCEPT "
+#
+# Rule 3 (cl3 itf)
+pass quick on { en0 en1 } inet proto tcp from any to port 22 label "RULE 3 -- ACCEPT "
+#
+# Rule 4 (carp0)
+pass quick on { en1 en2 vlan100 } inet from any to any label "RULE 4 -- ACCEPT "
+#
+# Rule 5 (carp0,carp1)
+pass quick on { en2 vlan100 } inet from any to any label "RULE 5 -- ACCEPT "
+#
+# Rule 6 (carp0,carp1,carp2)
+pass quick on en2 inet from any to any label "RULE 6 -- ACCEPT "
+#
+# Rule 7 (carp0)
+pass in quick on { en1 en2 vlan100 } inet from any to any label "RULE 7 -- ACCEPT "
+#
+# Rule 8 (carp0,carp1)
+pass in quick on { en2 vlan100 } inet from any to any label "RULE 8 -- ACCEPT "
+#
+# Rule 9 (carp0)
+pass out quick on { en1 en2 vlan100 } inet from any to any label "RULE 9 -- ACCEPT "
+#
+# Rule 10 (carp0,carp1)
+pass out quick on { en2 vlan100 } inet from any to any label "RULE 10 -- ACCEPT "
+#
+# Rule 11 (carp0)
+pass quick on { en1 en2 vlan100 } inet from any to label "RULE 11 -- ACCEPT "
+#
+# Rule 12 (carp0,carp1)
+pass quick on { en2 vlan100 } inet from any to label "RULE 12 -- ACCEPT "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any no state label "RULE 10000 -- DROP "
+
diff --git a/test/pf/pf_cluster_3_openbsd-3.fw.orig b/test/pf/pf_cluster_3_openbsd-3.fw.orig
new file mode 100755
index 000000000..584ebb38a
--- /dev/null
+++ b/test/pf/pf_cluster_3_openbsd-3.fw.orig
@@ -0,0 +1,320 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:55 2011 PST by vadim
+#
+# files: * pf_cluster_3_openbsd-3.fw
+# files: pf_cluster_3_openbsd-3.conf
+#
+# Compiled for pf 4.6
+#
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+missing_vlan() {
+ vlan=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $vlan
+ subint=$1
+ parent=$2
+ IFS=$oldIFS
+
+ vlan_id=$(echo $subint | sed 's/vlan//')
+ test "$cmd" = "add" && {
+ echo "# Adding VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $IFCONFIG $subint vlan $vlan_id vlandev $parent
+ $FWBDEBUG $IFCONFIG $subint up
+ }
+ test "$cmd" = "rem" && {
+ echo "# Removing VLAN interface $subint (parent: $parent)"
+ $FWBDEBUG $IFCONFIG $subint vlan $vlan_id -vlandev
+ $FWBDEBUG $IFCONFIG $subint destroy
+ }
+}
+
+parse_fwb_vlans() {
+ set $1
+ vlan_parent_interface=$1
+ shift
+
+ FWB_VLANS=$(
+ for subint in $*; do
+ echo "${subint}@$vlan_parent_interface"
+ done | sort
+ )
+ echo $FWB_VLANS
+}
+
+parse_current_vlans() {
+ vlan_parent_interface=$1
+ $IFCONFIG -A | grep 'vlan: ' | sed 's/priority:.*parent interface://' | \
+ while read x vlan_id parent
+ do
+ test "$parent" = "$vlan_parent_interface" && echo "vlan$vlan_id@$parent"
+ done | sort
+}
+
+update_vlans_of_interface() {
+ args="$1"
+ set $1
+ vlan_parent_interface=$1
+
+ FWB_VLANS=$(parse_fwb_vlans "$args")
+ CURRENT_VLANS=$(parse_current_vlans $vlan_parent_interface)
+
+ $IFCONFIG $vlan_parent_interface up
+ diff_intf missing_vlan "$FWB_VLANS" "$CURRENT_VLANS" add
+ diff_intf missing_vlan "$CURRENT_VLANS" "$FWB_VLANS" rem
+}
+
+sync_vlan_interfaces() {
+ $IFCONFIG -A | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ii=ignored_arr[a]":"; ignored_dict[ii]=1;}
+ }
+ ($1 ~ /^vlan[0-9]/ && !($1 in ignored_dict)) {print $1;}' | sed 's/://' |\
+ while read intf; do
+ echo "# Deleting vlan interface $intf"
+ $FWBDEBUG $IFCONFIG $intf destroy
+ done
+
+ for intf in $*; do
+ $IFCONFIG $intf >/dev/null 2>&1 || {
+ echo "# Creating vlan interface $intf"
+ $FWBDEBUG $IFCONFIG $intf create
+ }
+ done
+}
+
+
+sync_carp_interfaces() {
+ $IFCONFIG -A | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ii=ignored_arr[a]":"; ignored_dict[ii]=1;}
+ }
+ ($1 ~ /^carp[0-9]/ && !($1 in ignored_dict)) {print $1;}' | sed 's/://' |\
+ while read intf; do
+ echo "# Deleting carp interface $intf"
+ $FWBDEBUG $IFCONFIG $intf destroy
+ done
+
+ for intf in $*; do
+ $IFCONFIG $intf >/dev/null 2>&1 || {
+ echo "# Creating carp interface $intf"
+ $SYSCTL -w net.inet.carp.allow=1
+ $FWBDEBUG $IFCONFIG $intf create
+ }
+ done
+}
+
+
+sync_pfsync_interfaces() {
+ $IFCONFIG -A | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ii=ignored_arr[a]":"; ignored_dict[ii]=1;}
+ }
+ ($1 ~ /^pfsync[0-9]/ && !($1 in ignored_dict)) {print $1;}' | sed 's/://' |\
+ while read intf; do
+ echo "# Deleting pfsync interface $intf"
+ $FWBDEBUG $IFCONFIG $intf destroy
+ done
+
+ for intf in $*; do
+ $IFCONFIG $intf >/dev/null 2>&1 || {
+ echo "# Creating pfsync interface $intf"
+ $FWBDEBUG $IFCONFIG $intf create
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ sync_vlan_interfaces vlan100
+ update_vlans_of_interface "en0 "
+ update_vlans_of_interface "en1 "
+ update_vlans_of_interface "en2 vlan100 "
+ update_vlans_of_interface "lo "
+ update_vlans_of_interface "carp0 "
+ update_vlans_of_interface "carp1 "
+ update_vlans_of_interface "lo0 "
+ update_vlans_of_interface "carp2 "
+
+ sync_carp_interfaces carp0 carp1 lo0 carp2
+ $IFCONFIG carp0 vhid pass "" carpdev en0
+ $IFCONFIG carp1 vhid pass "" carpdev en1
+ $IFCONFIG lo0 vhid pass "" advskew 1 carpdev lo
+ $IFCONFIG carp2 vhid pass "" carpdev vlan100
+
+
+ update_addresses_of_interface "en0 172.24.0.2/0xffffff00" ""
+ update_addresses_of_interface "en1 192.168.1.2/0xffffff00" ""
+ update_addresses_of_interface "lo 127.0.0.1/0xff000000" ""
+ update_addresses_of_interface "vlan100 172.20.0.2/0xffffff00" ""
+ update_addresses_of_interface "carp0 172.24.0.1/0xffffff00" ""
+ update_addresses_of_interface "carp1 192.168.1.1/0xffffff00" ""
+ update_addresses_of_interface "carp2 172.20.0.1/0xffffff00" ""
+
+ sync_pfsync_interfaces
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:55 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/pf_cluster_3_openbsd-3.conf || exit 1
+
+
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pf/pf_cluster_3_openbsd-4.conf.orig b/test/pf/pf_cluster_3_openbsd-4.conf.orig
new file mode 100644
index 000000000..b59652fcb
--- /dev/null
+++ b/test/pf/pf_cluster_3_openbsd-4.conf.orig
@@ -0,0 +1,63 @@
+
+
+
+
+# Tables: (1)
+table { 172.20.0.1 , 172.20.0.3 , 172.24.0.1 , 172.24.0.3 , 192.168.1.1 , 192.168.1.3 }
+
+#
+# Rule -4 CARP (automatic)
+pass quick on vlan100 inet proto carp from any to any label "RULE -4 -- ACCEPT "
+#
+# Rule -3 CARP (automatic)
+pass quick on lo inet proto carp from any to any label "RULE -3 -- ACCEPT "
+#
+# Rule -2 CARP (automatic)
+pass quick on en1 inet proto carp from any to any label "RULE -2 -- ACCEPT "
+#
+# Rule -1 CARP (automatic)
+pass quick on en0 inet proto carp from any to any label "RULE -1 -- ACCEPT "
+#
+# Rule 0 (carp0)
+block in log quick on en0 inet from to any no state label "RULE 0 -- DROP "
+#
+# Rule 1 (carp0)
+pass quick on en0 inet from any to any label "RULE 1 -- ACCEPT "
+#
+# Rule 2 (carp0,carp1)
+pass quick on { en0 en1 } inet proto tcp from any to port 22 label "RULE 2 -- ACCEPT "
+#
+# Rule 3 (cl3 itf)
+pass quick on { en0 en1 } inet proto tcp from any to port 22 label "RULE 3 -- ACCEPT "
+#
+# Rule 4 (carp0)
+pass quick on { en1 en2 vlan100 } inet from any to any label "RULE 4 -- ACCEPT "
+#
+# Rule 5 (carp0,carp1)
+pass quick on { en2 vlan100 } inet from any to any label "RULE 5 -- ACCEPT "
+#
+# Rule 6 (carp0,carp1,carp2)
+pass quick on en2 inet from any to any label "RULE 6 -- ACCEPT "
+#
+# Rule 7 (carp0)
+pass in quick on { en1 en2 vlan100 } inet from any to any label "RULE 7 -- ACCEPT "
+#
+# Rule 8 (carp0,carp1)
+pass in quick on { en2 vlan100 } inet from any to any label "RULE 8 -- ACCEPT "
+#
+# Rule 9 (carp0)
+pass out quick on { en1 en2 vlan100 } inet from any to any label "RULE 9 -- ACCEPT "
+#
+# Rule 10 (carp0,carp1)
+pass out quick on { en2 vlan100 } inet from any to any label "RULE 10 -- ACCEPT "
+#
+# Rule 11 (carp0)
+pass quick on { en1 en2 vlan100 } inet from any to label "RULE 11 -- ACCEPT "
+#
+# Rule 12 (carp0,carp1)
+pass quick on { en2 vlan100 } inet from any to label "RULE 12 -- ACCEPT "
+#
+# Rule fallback rule
+# fallback rule
+block quick inet from any to any no state label "RULE 10000 -- DROP "
+
diff --git a/test/pf/pf_cluster_3_openbsd-4.fw.orig b/test/pf/pf_cluster_3_openbsd-4.fw.orig
new file mode 100755
index 000000000..32b1de6b3
--- /dev/null
+++ b/test/pf/pf_cluster_3_openbsd-4.fw.orig
@@ -0,0 +1,209 @@
+#!/bin/sh
+#
+# This is automatically generated file. DO NOT MODIFY !
+#
+# Firewall Builder fwb_pf v4.2.0.3425-{{build}}
+#
+# Generated Mon Jan 3 12:59:55 2011 PST by vadim
+#
+# files: * pf_cluster_3_openbsd-4.fw
+# files: pf_cluster_3_openbsd-4.conf
+#
+# Compiled for pf 4.6
+#
+
+
+
+
+
+FWDIR=`dirname $0`
+
+IFCONFIG="/sbin/ifconfig"
+PFCTL="/sbin/pfctl"
+SYSCTL="/sbin/sysctl"
+LOGGER="/usr/bin/logger"
+
+log() {
+ echo "$1"
+ test -x "$LOGGER" && $LOGGER -p info "$1"
+}
+
+diff_intf() {
+ func=$1
+ list1=$2
+ list2=$3
+ cmd=$4
+ for intf in $list1
+ do
+ echo $list2 | grep -q $intf || {
+ # $vlan is absent in list 2
+ $func $intf $cmd
+ }
+ done
+}
+
+
+missing_address() {
+ address=$1
+ cmd=$2
+
+ oldIFS=$IFS
+ IFS="@"
+ set $address
+ addr=$1
+ interface=$2
+ IFS=$oldIFS
+
+ if echo "$addr" | grep -q ':'
+ then
+ inet="inet6"
+ addr=$(echo "$addr" | sed 's!/! prefixlen !')
+ else
+ inet="inet"
+ addr=$(echo "$addr" | sed 's!/! netmask !')
+ fi
+
+ parameter=""
+ test "$cmd" = "add" && {
+ echo "# Adding ip address: $interface $addr"
+ parameter="alias"
+ }
+ test "$cmd" = "del" && {
+ echo "# Removing ip address: $interface $addr"
+ parameter="delete"
+ }
+
+ $FWBDEBUG $IFCONFIG $interface $inet $addr $parameter
+ $FWBDEBUG $IFCONFIG $interface up
+}
+
+list_addresses_by_scope() {
+ interface=$1
+ scope=$2
+ ignore_list=$3
+
+ scope_regex="1"
+ if test -n "$scope"; then scope_regex=" \$0 !~ \"$scope\" "; fi
+
+ $IFCONFIG $interface | sed "s/%$interface//" | \
+ awk -v IGNORED="$ignore_list" \
+ "BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
+ }
+ (/inet |inet6 / && $scope_regex && !(\$2 in ignored_dict)) {printf \"%s/%s\n\",\$2,\$4;}" | \
+ while read addr; do
+ echo "${addr}@$interface"
+ done | sort
+
+}
+
+update_addresses_of_interface() {
+ ignore_list=$2
+ set $1
+ interface=$1
+ shift
+
+ FWB_ADDRS=$(
+ for addr in $*; do
+ echo "${addr}@$interface"
+ done | sort
+ )
+
+ CURRENT_ADDRS_ALL_SCOPES=""
+ CURRENT_ADDRS_GLOBAL_SCOPE=""
+
+ $IFCONFIG $interface >/dev/null 2>&1 && {
+ CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface '' "$ignore_list")
+ CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scopeid .*' "$ignore_list")
+ } || {
+ echo "# Interface $interface does not exist"
+ # Stop the script if we are not in test mode
+ test -z "$FWBDEBUG" && exit 1
+ }
+
+ diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
+ diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
+}
+
+
+
+sync_carp_interfaces() {
+ $IFCONFIG -A | awk -v IGNORED="$*" \
+ 'BEGIN {
+ split(IGNORED,ignored_arr);
+ for (a in ignored_arr) {ii=ignored_arr[a]":"; ignored_dict[ii]=1;}
+ }
+ ($1 ~ /^carp[0-9]/ && !($1 in ignored_dict)) {print $1;}' | sed 's/://' |\
+ while read intf; do
+ echo "# Deleting carp interface $intf"
+ $FWBDEBUG $IFCONFIG $intf destroy
+ done
+
+ for intf in $*; do
+ $IFCONFIG $intf >/dev/null 2>&1 || {
+ echo "# Creating carp interface $intf"
+ $SYSCTL -w net.inet.carp.allow=1
+ $FWBDEBUG $IFCONFIG $intf create
+ }
+ done
+}
+
+verify_interfaces() {
+ :
+
+}
+
+set_kernel_vars() {
+ :
+ $SYSCTL -w net.inet.ip.forwarding=1
+}
+
+prolog_commands() {
+ :
+
+}
+
+epilog_commands() {
+ :
+
+}
+
+run_epilog_and_exit() {
+ epilog_commands
+ exit $1
+}
+
+configure_interfaces() {
+ :
+ sync_carp_interfaces carp0 carp1 lo0 carp2
+ $IFCONFIG carp0 vhid pass "" advskew 1 carpdev en0
+ $IFCONFIG carp1 vhid pass "" advskew 1 carpdev en1
+ $IFCONFIG lo0 vhid pass "" advskew 1 carpdev lo
+ $IFCONFIG carp2 vhid pass "" advskew 1 carpdev vlan100
+
+
+ update_addresses_of_interface "en0 172.24.0.3/0xffffff00" ""
+ update_addresses_of_interface "en1 192.168.1.3/0xffffff00" ""
+ update_addresses_of_interface "lo 127.0.0.1/0xff000000" ""
+ update_addresses_of_interface "vlan100 172.20.0.3/0xffffff00" ""
+ update_addresses_of_interface "carp0 172.24.0.1/0xffffff00" ""
+ update_addresses_of_interface "carp1 192.168.1.1/0xffffff00" ""
+ update_addresses_of_interface "carp2 172.20.0.1/0xffffff00" ""
+}
+
+log "Activating firewall script generated Mon Jan 3 12:59:55 2011 by vadim"
+
+set_kernel_vars
+configure_interfaces
+prolog_commands
+
+$PFCTL \
+ -f \
+ ${FWDIR}/pf_cluster_3_openbsd-4.conf || exit 1
+
+
+
+
+
+epilog_commands
\ No newline at end of file
diff --git a/test/pix/cluster1-1_pix1.fw.orig b/test/pix/cluster1-1_pix1.fw.orig
new file mode 100755
index 000000000..c535f2d77
--- /dev/null
+++ b/test/pix/cluster1-1_pix1.fw.orig
@@ -0,0 +1,215 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:22 2011 PST by vadim
+!
+! Compiled for pix 7.0
+! Outbound ACLs: supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: yes
+! Assume firewall is part of any: yes
+!
+!# files: * cluster1-1_pix1.fw
+!
+!
+
+! pix1::: warning: Interface Ethernet0 has vlan subinterfaces, it can not be used for ACL. Marking this interface "unprotected" to exclude it.
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+hostname pix1
+
+interface Ethernet1
+ nameif inside
+ ip address 10.3.14.206 255.255.255.0 standby 10.3.14.207
+ security-level 100
+exit
+
+interface Ethernet0
+ no nameif
+ no ip address
+ no security-level
+exit
+
+interface Ethernet2
+ description LAN/STATE Failover Interface
+ no nameif
+exit
+
+interface Ethernet0.101
+ vlan 101
+ nameif outside
+ ip address 192.0.2.253 255.255.255.0 standby 192.0.2.254
+ security-level 0
+exit
+
+interface Ethernet0.102
+ vlan 102
+ nameif dmz20
+ ip address 10.0.0.253 255.255.255.0 standby 10.0.0.254
+ security-level 20
+exit
+
+
+failover lan unit primary
+failover lan interface failover Ethernet2
+failover lan enable
+failover key super_secret
+failover interface ip failover 172.17.1.253 255.255.255.252 standby 172.17.1.254
+failover link failover Ethernet2
+failover interface ip failover 172.17.1.253 255.255.255.252 standby 172.17.1.254
+failover
+
+
+no logging buffered
+no logging console
+no logging timestamp
+no logging on
+
+
+timeout xlate 0:0:0
+timeout conn 0:0:0
+timeout udp 0:0:0
+timeout sunrpc 0:0:0
+timeout h323 0:0:0
+timeout sip 0:0:0
+timeout sip_media 0:0:0
+timeout half-closed 0:0:0
+timeout uauth 0:0:0
+
+
+clear config ssh
+aaa authentication ssh console LOCAL
+
+clear config snmp-server
+no snmp-server enable traps
+
+clear config ntp
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+
+
+class-map inspection_default
+ match default-inspection-traffic
+
+policy-map global_policy
+ class inspection_default
+
+service-policy global_policy global
+
+
+!################
+clear config access-list
+clear config object-group
+clear config icmp
+clear config telnet
+
+object-group network outside.id56590X61097.src.net.0
+ network-object host 10.3.14.206
+ network-object host 10.3.14.207
+ exit
+
+
+object-group network outside.id56590X61097.src.net.1
+ network-object host 172.17.1.253
+ network-object host 172.17.1.254
+ network-object host 192.0.2.253
+ network-object host 192.0.2.254
+ exit
+
+
+object-group network outside.id56590X61097.src.net.2
+ network-object host 10.0.0.253
+ network-object host 10.0.0.254
+ exit
+
+
+object-group network inside.id56627X61097.src.net.0
+ network-object host 172.17.1.253
+ network-object host 192.0.2.253
+ exit
+
+!
+! Rule 0 (Ethernet0.101)
+! anti spoofing rule
+access-list outside_in deny ip object-group outside.id56590X61097.src.net.0 any log 2 interval 300
+access-list outside_in deny ip object-group outside.id56590X61097.src.net.1 any log 2 interval 300
+access-list outside_in deny ip object-group outside.id56590X61097.src.net.2 any log 2 interval 300
+access-list outside_in deny ip 10.3.14.0 255.255.255.0 any log 2 interval 300
+!
+! Rule 1 (global)
+! SSH Access to firewall is permitted
+! only from internal network
+ssh 10.3.14.0 255.255.255.0 inside
+!
+! Rule 2 (global)
+ssh 10.3.14.0 255.255.255.0 inside
+!
+! Rule 3 (global)
+! Firewall uses one of the machines
+! on internal network for DNS
+access-list inside_out permit udp host 10.3.14.206 10.3.14.0 255.255.255.0 eq 53 log 2 interval 300
+access-list inside_out permit udp object-group inside.id56627X61097.src.net.0 10.3.14.0 255.255.255.0 eq 53 log 2 interval 300
+access-list inside_out permit udp host 10.0.0.253 10.3.14.0 255.255.255.0 eq 53 log 2 interval 300
+!
+! Rule 4 (global)
+! Firewall uses one of the machines
+! on internal network for DNS
+access-list inside_out permit udp object-group outside.id56590X61097.src.net.0 10.3.14.0 255.255.255.0 eq 53 log 2 interval 300
+access-list inside_out permit udp object-group outside.id56590X61097.src.net.1 10.3.14.0 255.255.255.0 eq 53 log 2 interval 300
+access-list inside_out permit udp object-group outside.id56590X61097.src.net.2 10.3.14.0 255.255.255.0 eq 53 log 2 interval 300
+!
+! Rule 5 (global)
+! All other attempts to connect to
+! the firewall are denied and logged
+access-list inside_in deny ip any object-group outside.id56590X61097.src.net.0 log 2 interval 300
+access-list inside_in deny ip any object-group outside.id56590X61097.src.net.1 log 2 interval 300
+access-list inside_in deny ip any object-group outside.id56590X61097.src.net.2 log 2 interval 300
+!
+! Rule 6 (global)
+access-list inside_in permit ip 10.3.14.0 255.255.255.0 any
+access-list inside_out permit ip 10.3.14.0 255.255.255.0 any
+!
+! Rule 7 (global)
+access-list inside_in deny ip any any log 2 interval 300
+access-list inside_out deny ip any any log 2 interval 300
+
+
+access-group inside_in in interface inside
+access-group inside_out out interface inside
+access-group outside_in in interface outside
+
+clear xlate
+clear config static
+clear config global
+clear config nat
+!
+! Rule 0 (NAT)
+global (outside) 1 interface
+access-list id56689X61097.0 permit ip 10.3.14.0 255.255.255.0 any
+nat (inside) 1 access-list id56689X61097.0 tcp 0 0
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/cluster1-1_pix2.fw.orig b/test/pix/cluster1-1_pix2.fw.orig
new file mode 100755
index 000000000..07ea1d018
--- /dev/null
+++ b/test/pix/cluster1-1_pix2.fw.orig
@@ -0,0 +1,215 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:22 2011 PST by vadim
+!
+! Compiled for pix 7.0
+! Outbound ACLs: supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: yes
+! Assume firewall is part of any: yes
+!
+!# files: * cluster1-1_pix2.fw
+!
+!
+
+! pix2::: warning: Interface Ethernet0 has vlan subinterfaces, it can not be used for ACL. Marking this interface "unprotected" to exclude it.
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+hostname pix2
+
+interface Ethernet1
+ nameif inside
+ ip address 10.3.14.207 255.255.255.0 standby 10.3.14.206
+ security-level 100
+exit
+
+interface Ethernet0
+ no nameif
+ no ip address
+ no security-level
+exit
+
+interface Ethernet2
+ description LAN/STATE Failover Interface
+ no nameif
+exit
+
+interface Ethernet0.101
+ vlan 101
+ nameif outside
+ ip address 192.0.2.254 255.255.255.0 standby 192.0.2.253
+ security-level 0
+exit
+
+interface Ethernet0.102
+ vlan 102
+ nameif dmz20
+ ip address 10.0.0.254 255.255.255.0 standby 10.0.0.253
+ security-level 20
+exit
+
+
+failover lan unit secondary
+failover lan interface failover Ethernet2
+failover lan enable
+failover key super_secret
+failover interface ip failover 172.17.1.253 255.255.255.252 standby 172.17.1.254
+failover link failover Ethernet2
+failover interface ip failover 172.17.1.253 255.255.255.252 standby 172.17.1.254
+failover
+
+
+no logging buffered
+no logging console
+no logging timestamp
+no logging on
+
+
+timeout xlate 0:0:0
+timeout conn 0:0:0
+timeout udp 0:0:0
+timeout sunrpc 0:0:0
+timeout h323 0:0:0
+timeout sip 0:0:0
+timeout sip_media 0:0:0
+timeout half-closed 0:0:0
+timeout uauth 0:0:0
+
+
+clear config ssh
+aaa authentication ssh console LOCAL
+
+clear config snmp-server
+no snmp-server enable traps
+
+clear config ntp
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+
+
+class-map inspection_default
+ match default-inspection-traffic
+
+policy-map global_policy
+ class inspection_default
+
+service-policy global_policy global
+
+
+!################
+clear config access-list
+clear config object-group
+clear config icmp
+clear config telnet
+
+object-group network outside.id56590X61097.src.net.3
+ network-object host 10.3.14.206
+ network-object host 10.3.14.207
+ exit
+
+
+object-group network outside.id56590X61097.src.net.4
+ network-object host 172.17.1.253
+ network-object host 172.17.1.254
+ network-object host 192.0.2.253
+ network-object host 192.0.2.254
+ exit
+
+
+object-group network outside.id56590X61097.src.net.5
+ network-object host 10.0.0.253
+ network-object host 10.0.0.254
+ exit
+
+
+object-group network inside.id56627X61097.src.net.1
+ network-object host 172.17.1.253
+ network-object host 192.0.2.253
+ exit
+
+!
+! Rule 0 (Ethernet0.101)
+! anti spoofing rule
+access-list outside_in deny ip object-group outside.id56590X61097.src.net.3 any log 3 interval 300
+access-list outside_in deny ip object-group outside.id56590X61097.src.net.4 any log 3 interval 300
+access-list outside_in deny ip object-group outside.id56590X61097.src.net.5 any log 3 interval 300
+access-list outside_in deny ip 10.3.14.0 255.255.255.0 any log 3 interval 300
+!
+! Rule 1 (global)
+! SSH Access to firewall is permitted
+! only from internal network
+ssh 10.3.14.0 255.255.255.0 inside
+!
+! Rule 2 (global)
+ssh 10.3.14.0 255.255.255.0 inside
+!
+! Rule 3 (global)
+! Firewall uses one of the machines
+! on internal network for DNS
+access-list inside_out permit udp host 10.3.14.206 10.3.14.0 255.255.255.0 eq 53 log 3 interval 300
+access-list inside_out permit udp object-group inside.id56627X61097.src.net.1 10.3.14.0 255.255.255.0 eq 53 log 3 interval 300
+access-list inside_out permit udp host 10.0.0.253 10.3.14.0 255.255.255.0 eq 53 log 3 interval 300
+!
+! Rule 4 (global)
+! Firewall uses one of the machines
+! on internal network for DNS
+access-list inside_out permit udp object-group outside.id56590X61097.src.net.3 10.3.14.0 255.255.255.0 eq 53 log 3 interval 300
+access-list inside_out permit udp object-group outside.id56590X61097.src.net.4 10.3.14.0 255.255.255.0 eq 53 log 3 interval 300
+access-list inside_out permit udp object-group outside.id56590X61097.src.net.5 10.3.14.0 255.255.255.0 eq 53 log 3 interval 300
+!
+! Rule 5 (global)
+! All other attempts to connect to
+! the firewall are denied and logged
+access-list inside_in deny ip any object-group outside.id56590X61097.src.net.3 log 3 interval 300
+access-list inside_in deny ip any object-group outside.id56590X61097.src.net.4 log 3 interval 300
+access-list inside_in deny ip any object-group outside.id56590X61097.src.net.5 log 3 interval 300
+!
+! Rule 6 (global)
+access-list inside_in permit ip 10.3.14.0 255.255.255.0 any
+access-list inside_out permit ip 10.3.14.0 255.255.255.0 any
+!
+! Rule 7 (global)
+access-list inside_in deny ip any any log 3 interval 300
+access-list inside_out deny ip any any log 3 interval 300
+
+
+access-group inside_in in interface inside
+access-group inside_out out interface inside
+access-group outside_in in interface outside
+
+clear xlate
+clear config static
+clear config global
+clear config nat
+!
+! Rule 0 (NAT)
+global (outside) 1 interface
+access-list id56689X61097.0 permit ip 10.3.14.0 255.255.255.0 any
+nat (inside) 1 access-list id56689X61097.0 tcp 0 0
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/cluster1_pix1.fw.orig b/test/pix/cluster1_pix1.fw.orig
new file mode 100755
index 000000000..d560f605e
--- /dev/null
+++ b/test/pix/cluster1_pix1.fw.orig
@@ -0,0 +1,258 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:21 2011 PST by vadim
+!
+! Compiled for pix 7.0
+! Outbound ACLs: supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: yes
+! Assume firewall is part of any: yes
+!
+!# files: * cluster1_pix1.fw
+!
+!
+
+! pix1::: warning: Interface Ethernet0 has vlan subinterfaces, it can not be used for ACL. Marking this interface "unprotected" to exclude it.
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+hostname pix1
+
+interface Ethernet1
+ nameif inside
+ ip address 10.3.14.206 255.255.255.0 standby 10.3.14.207
+ security-level 100
+exit
+
+interface Ethernet0
+ no nameif
+ no ip address
+ no security-level
+exit
+
+interface Ethernet2
+ description LAN/STATE Failover Interface
+ no nameif
+exit
+
+interface Ethernet0.101
+ vlan 101
+ nameif outside
+ ip address 192.0.2.253 255.255.255.0 standby 192.0.2.254
+ security-level 0
+exit
+
+interface Ethernet0.102
+ vlan 102
+ nameif dmz20
+ ip address 10.0.0.253 255.255.255.0 standby 10.0.0.254
+ security-level 20
+exit
+
+
+failover lan unit primary
+failover lan interface failover Ethernet2
+failover lan enable
+failover key super_secret
+failover interface ip failover 172.17.1.253 255.255.255.252 standby 172.17.1.254
+failover link failover Ethernet2
+failover interface ip failover 172.17.1.253 255.255.255.252 standby 172.17.1.254
+failover
+
+
+no logging buffered
+no logging console
+no logging timestamp
+no logging on
+
+
+timeout xlate 0:0:0
+timeout conn 0:0:0
+timeout udp 0:0:0
+timeout sunrpc 0:0:0
+timeout h323 0:0:0
+timeout sip 0:0:0
+timeout sip_media 0:0:0
+timeout half-closed 0:0:0
+timeout uauth 0:0:0
+
+
+clear config ssh
+aaa authentication ssh console LOCAL
+
+clear config snmp-server
+no snmp-server enable traps
+
+clear config ntp
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+
+
+class-map inspection_default
+ match default-inspection-traffic
+
+policy-map global_policy
+ class inspection_default
+
+service-policy global_policy global
+
+
+!################
+clear config access-list
+clear config object-group
+clear config icmp
+clear config telnet
+
+object-group network outside.id2913X78273.src.net.0
+ network-object host 10.3.14.206
+ network-object host 10.3.14.207
+ exit
+
+
+object-group network outside.id2913X78273.src.net.1
+ network-object host 172.17.1.253
+ network-object host 172.17.1.254
+ network-object host 192.0.2.253
+ network-object host 192.0.2.254
+ exit
+
+
+object-group network outside.id2913X78273.src.net.2
+ network-object host 10.0.0.253
+ network-object host 10.0.0.254
+ exit
+
+
+object-group network inside.id55439X897.src.net.0
+ network-object host 172.17.1.253
+ network-object host 192.0.2.253
+ exit
+
+!
+! Rule 0 (Ethernet0.101)
+! anti spoofing rule
+access-list outside_in deny ip object-group outside.id2913X78273.src.net.0 any log 2 interval 300
+access-list outside_in deny ip object-group outside.id2913X78273.src.net.1 any log 2 interval 300
+access-list outside_in deny ip object-group outside.id2913X78273.src.net.2 any log 2 interval 300
+access-list outside_in deny ip 10.3.14.0 255.255.255.0 any log 2 interval 300
+!
+! Rule 1 (global)
+! SSH Access to firewall is permitted
+! only from internal network
+ssh 10.3.14.0 255.255.255.0 inside
+!
+! Rule 2 (global)
+ssh 10.3.14.0 255.255.255.0 inside
+!
+! Rule 3 (global)
+! Firewall uses one of the machines
+! on internal network for DNS
+access-list inside_out permit udp host 10.3.14.206 10.3.14.0 255.255.255.0 eq 53 log 2 interval 300
+access-list inside_out permit udp object-group inside.id55439X897.src.net.0 10.3.14.0 255.255.255.0 eq 53 log 2 interval 300
+access-list inside_out permit udp host 10.0.0.253 10.3.14.0 255.255.255.0 eq 53 log 2 interval 300
+!
+! Rule 4 (global)
+! Firewall uses one of the machines
+! on internal network for DNS
+access-list inside_out permit udp object-group outside.id2913X78273.src.net.0 10.3.14.0 255.255.255.0 eq 53 log 2 interval 300
+access-list inside_out permit udp object-group outside.id2913X78273.src.net.1 10.3.14.0 255.255.255.0 eq 53 log 2 interval 300
+access-list inside_out permit udp object-group outside.id2913X78273.src.net.2 10.3.14.0 255.255.255.0 eq 53 log 2 interval 300
+!
+! Rule 5 (Ethernet0.101,Ethernet0.102)
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+!
+! Rule 6 (cl1 itf)
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+!
+! Rule 7 (Ethernet0.101,Ethernet0.102)
+access-list outside_in permit udp any 10.3.14.0 255.255.255.0 eq 53
+access-list outside_out permit udp any 10.3.14.0 255.255.255.0 eq 53
+access-list dmz20_in permit udp any 10.3.14.0 255.255.255.0 eq 53
+access-list dmz20_out permit udp any 10.3.14.0 255.255.255.0 eq 53
+!
+! Rule 8 (cl1 itf)
+access-list outside_in permit udp any 10.3.14.0 255.255.255.0 eq 53
+access-list outside_out permit udp any 10.3.14.0 255.255.255.0 eq 53
+access-list dmz20_in permit udp any 10.3.14.0 255.255.255.0 eq 53
+access-list dmz20_out permit udp any 10.3.14.0 255.255.255.0 eq 53
+!
+! Rule 9 (global)
+! All other attempts to connect to
+! the firewall are denied and logged
+access-list inside_in deny ip any object-group outside.id2913X78273.src.net.0 log 2 interval 300
+access-list inside_in deny ip any object-group outside.id2913X78273.src.net.1 log 2 interval 300
+access-list inside_in deny ip any object-group outside.id2913X78273.src.net.2 log 2 interval 300
+!
+! Rule 10 (global)
+access-list inside_in permit ip 10.3.14.0 255.255.255.0 any
+access-list inside_out permit ip 10.3.14.0 255.255.255.0 any
+!
+! Rule 11 (global)
+access-list inside_in deny ip any any log 2 interval 300
+access-list inside_out deny ip any any log 2 interval 300
+
+
+access-group dmz20_in in interface dmz20
+access-group dmz20_out out interface dmz20
+access-group inside_in in interface inside
+access-group inside_out out interface inside
+access-group outside_in in interface outside
+access-group outside_out out interface outside
+
+clear xlate
+clear config static
+clear config global
+clear config nat
+!
+! Rule 0 (NAT)
+global (outside) 1 interface
+access-list id4606X78273.0 permit ip 10.3.14.0 255.255.255.0 any
+nat (inside) 1 access-list id4606X78273.0 tcp 0 0
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/cluster1_pix2.fw.orig b/test/pix/cluster1_pix2.fw.orig
new file mode 100755
index 000000000..18809b102
--- /dev/null
+++ b/test/pix/cluster1_pix2.fw.orig
@@ -0,0 +1,264 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:21 2011 PST by vadim
+!
+! Compiled for pix 7.0
+! Outbound ACLs: supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: yes
+! Assume firewall is part of any: yes
+!
+!# files: * cluster1_pix2.fw
+!
+!
+
+! pix2::: warning: Interface Ethernet0 has vlan subinterfaces, it can not be used for ACL. Marking this interface "unprotected" to exclude it.
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+hostname pix2
+
+interface Ethernet1
+ nameif inside
+ ip address 10.3.14.207 255.255.255.0 standby 10.3.14.206
+ security-level 100
+exit
+
+interface Ethernet0
+ no nameif
+ no ip address
+ no security-level
+exit
+
+interface Ethernet2
+ description LAN/STATE Failover Interface
+ no nameif
+exit
+
+interface Ethernet0.101
+ vlan 101
+ nameif outside
+ ip address 192.0.2.254 255.255.255.0 standby 192.0.2.253
+ security-level 0
+exit
+
+interface Ethernet0.102
+ vlan 102
+ nameif dmz20
+ ip address 10.0.0.254 255.255.255.0 standby 10.0.0.253
+ security-level 20
+exit
+
+
+failover lan unit secondary
+failover lan interface failover Ethernet2
+failover lan enable
+failover key super_secret
+failover interface ip failover 172.17.1.253 255.255.255.252 standby 172.17.1.254
+failover link failover Ethernet2
+failover interface ip failover 172.17.1.253 255.255.255.252 standby 172.17.1.254
+failover
+
+
+no logging buffered
+no logging console
+no logging timestamp
+no logging on
+
+
+timeout xlate 0:0:0
+timeout conn 0:0:0
+timeout udp 0:0:0
+timeout sunrpc 0:0:0
+timeout h323 0:0:0
+timeout sip 0:0:0
+timeout sip_media 0:0:0
+timeout half-closed 0:0:0
+timeout uauth 0:0:0
+
+
+clear config ssh
+aaa authentication ssh console LOCAL
+
+clear config snmp-server
+no snmp-server enable traps
+
+clear config ntp
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+
+
+class-map inspection_default
+ match default-inspection-traffic
+
+policy-map global_policy
+ class inspection_default
+
+service-policy global_policy global
+
+
+!################
+clear config access-list
+clear config object-group
+clear config icmp
+clear config telnet
+
+object-group network outside.id2913X78273.src.net.3
+ network-object host 10.3.14.206
+ network-object host 10.3.14.207
+ exit
+
+
+object-group network outside.id2913X78273.src.net.4
+ network-object host 172.17.1.253
+ network-object host 172.17.1.254
+ network-object host 192.0.2.253
+ network-object host 192.0.2.254
+ exit
+
+
+object-group network outside.id2913X78273.src.net.5
+ network-object host 10.0.0.253
+ network-object host 10.0.0.254
+ exit
+
+
+object-group network inside.id55439X897.src.net.1
+ network-object host 172.17.1.253
+ network-object host 192.0.2.253
+ exit
+
+
+object-group network outside.id3401X82678.dst.net.0
+ network-object host 172.17.1.254
+ network-object host 192.0.2.254
+ exit
+
+!
+! Rule 0 (Ethernet0.101)
+! anti spoofing rule
+access-list outside_in deny ip object-group outside.id2913X78273.src.net.3 any log 3 interval 300
+access-list outside_in deny ip object-group outside.id2913X78273.src.net.4 any log 3 interval 300
+access-list outside_in deny ip object-group outside.id2913X78273.src.net.5 any log 3 interval 300
+access-list outside_in deny ip 10.3.14.0 255.255.255.0 any log 3 interval 300
+!
+! Rule 1 (global)
+! SSH Access to firewall is permitted
+! only from internal network
+ssh 10.3.14.0 255.255.255.0 inside
+!
+! Rule 2 (global)
+ssh 10.3.14.0 255.255.255.0 inside
+!
+! Rule 3 (global)
+! Firewall uses one of the machines
+! on internal network for DNS
+access-list inside_out permit udp host 10.3.14.206 10.3.14.0 255.255.255.0 eq 53 log 3 interval 300
+access-list inside_out permit udp object-group inside.id55439X897.src.net.1 10.3.14.0 255.255.255.0 eq 53 log 3 interval 300
+access-list inside_out permit udp host 10.0.0.253 10.3.14.0 255.255.255.0 eq 53 log 3 interval 300
+!
+! Rule 4 (global)
+! Firewall uses one of the machines
+! on internal network for DNS
+access-list inside_out permit udp object-group outside.id2913X78273.src.net.3 10.3.14.0 255.255.255.0 eq 53 log 3 interval 300
+access-list inside_out permit udp object-group outside.id2913X78273.src.net.4 10.3.14.0 255.255.255.0 eq 53 log 3 interval 300
+access-list inside_out permit udp object-group outside.id2913X78273.src.net.5 10.3.14.0 255.255.255.0 eq 53 log 3 interval 300
+!
+! Rule 5 (Ethernet0.101,Ethernet0.102)
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+!
+! Rule 6 (cl1 itf)
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+ssh 0.0.0.0 0.0.0.0 dmz20
+!
+! Rule 7 (Ethernet0.101,Ethernet0.102)
+access-list outside_in permit udp any 10.3.14.0 255.255.255.0 eq 53
+access-list outside_out permit udp any 10.3.14.0 255.255.255.0 eq 53
+access-list dmz20_in permit udp any 10.3.14.0 255.255.255.0 eq 53
+access-list dmz20_out permit udp any 10.3.14.0 255.255.255.0 eq 53
+!
+! Rule 8 (cl1 itf)
+access-list outside_in permit udp any 10.3.14.0 255.255.255.0 eq 53
+access-list outside_out permit udp any 10.3.14.0 255.255.255.0 eq 53
+access-list dmz20_in permit udp any 10.3.14.0 255.255.255.0 eq 53
+access-list dmz20_out permit udp any 10.3.14.0 255.255.255.0 eq 53
+!
+! Rule 9 (global)
+! All other attempts to connect to
+! the firewall are denied and logged
+access-list inside_in deny ip any object-group outside.id2913X78273.src.net.3 log 3 interval 300
+access-list inside_in deny ip any object-group outside.id2913X78273.src.net.4 log 3 interval 300
+access-list inside_in deny ip any object-group outside.id2913X78273.src.net.5 log 3 interval 300
+!
+! Rule 10 (global)
+access-list inside_in permit ip 10.3.14.0 255.255.255.0 any
+access-list inside_out permit ip 10.3.14.0 255.255.255.0 any
+!
+! Rule 11 (global)
+access-list inside_in deny ip any any log 3 interval 300
+access-list inside_out deny ip any any log 3 interval 300
+
+
+access-group dmz20_in in interface dmz20
+access-group dmz20_out out interface dmz20
+access-group inside_in in interface inside
+access-group inside_out out interface inside
+access-group outside_in in interface outside
+access-group outside_out out interface outside
+
+clear xlate
+clear config static
+clear config global
+clear config nat
+!
+! Rule 0 (NAT)
+global (outside) 1 interface
+access-list id4606X78273.0 permit ip 10.3.14.0 255.255.255.0 any
+nat (inside) 1 access-list id4606X78273.0 tcp 0 0
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall.fw.orig b/test/pix/firewall.fw.orig
new file mode 100755
index 000000000..0ac2849e0
--- /dev/null
+++ b/test/pix/firewall.fw.orig
@@ -0,0 +1,673 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:04 2011 PST by vadim
+!
+! Compiled for pix 6.2
+! Outbound ACLs: not supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: yes
+!
+!# files: * firewall.fw
+!
+! this is simple firewall with two interfaces. Test regular policy rules, including IP_fragments rule
+
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '1 (ethernet1)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '2 (ethernet1)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '3 (ethernet1)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '3 (ethernet1)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '3 (ethernet1)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '3 (ethernet1)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '4 (ethernet0)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '4 (ethernet0)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '4 (ethernet0)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '5 (ethernet0)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '5 (ethernet0)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '5 (ethernet0)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '5 (ethernet0)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '5 (ethernet0)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '5 (ethernet0)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '5 (ethernet0)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '5 (ethernet0)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '5 (ethernet0)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '5 (ethernet0)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '5 (ethernet0)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '5 (ethernet0)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '5 (ethernet0)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '5 (ethernet0)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '6 (ethernet0)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '8 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '8 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '8 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '9 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '9 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '9 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '9 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '9 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '9 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '9 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '9 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '10 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '10 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '10 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '12 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '12 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '12 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '12 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '13 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '14 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '15 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '15 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '15 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '15 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '15 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '15 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '16 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '17 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '17 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '17 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '17 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '17 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '17 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '17 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '17 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '18 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '19 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '19 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '19 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '19 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '19 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '19 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '20 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '23 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '23 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '23 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '23 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '23 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '23 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '23 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '23 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '23 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '24 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '24 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '24 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '24 (global)' below it
+! C firewall:Policy:0: error: Rule '0 (global)' shadows rule '25 (global)' below it
+! C firewall:Policy:13: warning: MAC address matching is not supported. One or several MAC addresses removed from source in the rule
+
+! N firewall:NAT:6: warning: Original destination is ignored in 'nat' NAT rules when compiling for PIX v6.2 and earlier.
+
+! R firewall:Routing:3: error: Interface and gateway rule elements can not be empty in the PIX routing rule
+! R firewall:Routing:4: error: Interface and gateway rule elements can not be empty in the PIX routing rule
+! R firewall:Routing:5: error: Interface and gateway rule elements can not be empty in the PIX routing rule
+! R firewall:Routing:7: error: MultiPath routing not supported by platform
+! R firewall:Routing:8: warning: Two of the sub rules created from the gui routing rules 7 (main) and 8 (main) are identical, skipping the second. Revise them to avoid this warning
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+hostname firewall
+
+nameif ethernet1 outside security0
+
+nameif ethernet0 inside security100
+
+nameif ethernet2 dmz security50
+
+
+
+logging host inside 192.168.1.30
+logging queue 512
+logging facility 16
+logging trap 1
+no logging buffered
+no logging console
+no logging timestamp
+logging on
+
+
+timeout xlate 3:0:0
+timeout conn 1:0:0
+timeout udp 0:2:0
+timeout rpc 0:10:0
+timeout h323 0:5:0
+timeout sip 0:30:0
+timeout sip_media 0:0:0
+timeout half-closed 0:0:0
+timeout uauth 2:0:0 absolute
+
+telnet timeout 5
+
+clear ssh
+aaa authentication ssh console LOCAL
+ssh timeout 5
+
+clear snmp-server
+snmp-server community public
+snmp-server enable traps
+snmp-server host inside 192.168.1.20 poll
+snmp-server host inside 192.168.1.22 trap
+
+clear ntp
+ntp server 192.168.1.20 source inside prefer
+
+
+no service resetinbound
+no service resetoutside
+sysopt connection tcpmss 1380
+sysopt connection timewait
+sysopt security fragguard
+sysopt nodnsalias inbound
+sysopt nodnsalias outbound
+no sysopt route dnat
+floodguard disable
+
+
+fixup protocol ftp 21
+fixup protocol http 80
+fixup protocol h323 h225 1720
+fixup protocol h323 ras 1718-1719
+fixup protocol ils 389
+fixup protocol rsh 514
+fixup protocol rtsp 554
+fixup protocol sip 5060
+fixup protocol skinny 2000
+fixup protocol smtp 25
+fixup protocol sqlnet 1521
+
+
+!################
+
+clear access-list tmp_acl
+access-list tmp_acl permit ip 192.168.1.0 255.255.255.0 any
+access-list tmp_acl deny ip any any
+
+access-group tmp_acl in interface outside
+access-group tmp_acl in interface inside
+
+clear access-list dmz_acl_in
+clear access-list inside_acl_in
+clear access-list outside_acl_in
+clear object-group
+
+clear icmp
+clear telnet
+
+object-group network inside.id3C4E4C38.dst.net.0
+ network-object host 211.11.11.11
+ network-object host 211.22.22.22
+ exit
+
+
+object-group service inside.id3C4E4C38.srv.tcp.0 tcp
+ port-object eq 113
+ port-object eq 80
+ port-object eq 25
+ port-object eq 22
+ port-object eq 540
+ port-object eq 443
+ port-object eq 143
+ exit
+
+
+object-group icmp-type outside.id3D8FCE32.srv.icmp.0
+ icmp-object 11
+ icmp-object 0
+ icmp-object 3
+ exit
+
+
+object-group service outside.pol-firewall2-2.srv.tcp.0 tcp
+ port-object eq 3128
+ port-object eq 70
+ port-object eq 6667
+ port-object eq 23
+ exit
+
+
+object-group service outside.pol-firewall2-2.srv.udp.0 udp
+ port-object eq 161
+ port-object eq 53
+ exit
+
+
+object-group network outside.pol-firewall2-3.dst.net.0
+ network-object host 192.168.1.10
+ network-object host 192.168.1.20
+ exit
+
+
+object-group network inside.id3E155E82.dst.net.0
+ network-object 192.168.1.250 255.255.255.254
+ network-object 192.168.1.252 255.255.255.252
+ exit
+
+
+object-group network outside.id3D0F8031.dst.net.0
+ network-object 192.168.1.250 255.255.255.254
+ network-object 192.168.1.252 255.255.255.252
+ exit
+
+
+object-group network outside.id3CD87B1E.dst.net.0
+ network-object host 192.168.1.11
+ network-object host 192.168.1.12
+ network-object host 192.168.1.13
+ network-object host 192.168.1.14
+ network-object host 192.168.1.15
+ exit
+
+
+object-group service outside.id3CD87B1E.srv.tcp.0 tcp
+ port-object eq 113
+ port-object eq 80
+ port-object eq 25
+ port-object eq 22
+ port-object eq 540
+ port-object eq 443
+ port-object eq 143
+ port-object eq 3128
+ exit
+
+
+object-group network outside.id3CD8770E.dst.net.0
+ network-object 192.168.1.11 255.255.255.255
+ network-object 192.168.1.12 255.255.255.252
+ exit
+
+
+object-group service outside.pol-firewall2-4.srv.tcp.0 tcp
+ port-object eq 3128
+ port-object range 10000 11000
+ port-object eq 6667
+ port-object eq 113
+ port-object eq 53
+ port-object eq 21
+ port-object eq 80
+ port-object eq 119
+ port-object eq 25
+ port-object eq 22
+ port-object eq 23
+ port-object eq 540
+ port-object eq 70
+ port-object eq 13
+ port-object eq 2105
+ port-object eq 443
+ port-object eq 143
+ port-object eq 993
+ port-object eq 6667
+ port-object eq 543
+ port-object eq 544
+ port-object eq 389
+ port-object eq 98
+ port-object eq 3306
+ port-object eq 2049
+ port-object eq 110
+ port-object eq 5432
+ port-object eq 515
+ port-object eq 26000
+ port-object eq 512
+ port-object eq 513
+ port-object eq 514
+ port-object eq 4321
+ port-object eq 465
+ port-object eq 1080
+ port-object eq 111
+ port-object eq 7100
+ exit
+
+!
+! Rule -1 backup ssh access rule (automatic)
+ssh 192.168.1.100 255.255.255.255 inside
+!
+! Rule 0 (global)
+access-list outside_acl_in deny ip any any
+access-list inside_acl_in deny ip any any
+access-list dmz_acl_in deny ip any any
+!
+! Rule 2 (ethernet1)
+! комментарий по-русски
+icmp permit any 3 outside
+access-list outside_acl_in permit icmp any host 22.22.22.22 3
+access-list outside_acl_in permit icmp any any 3
+!
+! Rule 3 (ethernet1)
+! anti-spoofing rule
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 4 (ethernet0)
+ssh 192.168.1.0 255.255.255.0 inside
+!
+! Rule 5 (ethernet0)
+access-list inside_acl_in permit tcp any object-group inside.id3C4E4C38.dst.net.0 object-group inside.id3C4E4C38.srv.tcp.0
+access-list inside_acl_in permit tcp any object-group inside.id3C4E4C38.dst.net.0 object-group inside.id3C4E4C38.srv.tcp.0
+access-list dmz_acl_in permit tcp any object-group inside.id3C4E4C38.dst.net.0 object-group inside.id3C4E4C38.srv.tcp.0
+!
+! Rule 6 (ethernet0)
+access-list inside_acl_in deny ip any host 192.168.1.255
+!
+! Rule 8 (global)
+access-list outside_acl_in permit icmp any host 192.168.1.10 object-group outside.id3D8FCE32.srv.icmp.0
+access-list inside_acl_in permit icmp any host 192.168.1.10 object-group outside.id3D8FCE32.srv.icmp.0
+access-list dmz_acl_in permit icmp any host 192.168.1.10 object-group outside.id3D8FCE32.srv.icmp.0
+!
+! Rule 9 (global)
+access-list outside_acl_in permit icmp any host 192.168.1.10
+access-list inside_acl_in permit icmp any host 192.168.1.10
+access-list dmz_acl_in permit icmp any host 192.168.1.10
+access-list outside_acl_in permit tcp any host 192.168.1.10 object-group outside.pol-firewall2-2.srv.tcp.0
+access-list inside_acl_in permit tcp any host 192.168.1.10 object-group outside.pol-firewall2-2.srv.tcp.0
+access-list dmz_acl_in permit tcp any host 192.168.1.10 object-group outside.pol-firewall2-2.srv.tcp.0
+access-list outside_acl_in permit udp any host 192.168.1.10 object-group outside.pol-firewall2-2.srv.udp.0
+access-list inside_acl_in permit udp any host 192.168.1.10 object-group outside.pol-firewall2-2.srv.udp.0
+access-list dmz_acl_in permit udp any host 192.168.1.10 object-group outside.pol-firewall2-2.srv.udp.0
+access-list outside_acl_in permit 47 any host 192.168.1.10
+access-list inside_acl_in permit 47 any host 192.168.1.10
+access-list dmz_acl_in permit 47 any host 192.168.1.10
+!
+! Rule 10 (global)
+access-list outside_acl_in permit icmp any host 22.22.22.22 3
+icmp permit any 3 inside
+access-list inside_acl_in permit icmp any host 192.168.1.1 3
+icmp permit any 3 dmz
+access-list dmz_acl_in permit icmp any host 192.168.2.1 3
+access-list outside_acl_in permit icmp any any 3
+access-list inside_acl_in permit icmp any any 3
+access-list dmz_acl_in permit icmp any any 3
+access-list outside_acl_in permit 47 any any
+access-list inside_acl_in permit 47 any any
+access-list dmz_acl_in permit 47 any any
+access-list outside_acl_in permit 50 any any
+access-list inside_acl_in permit 50 any any
+access-list dmz_acl_in permit 50 any any
+!
+! Rule 12 (global)
+access-list outside_acl_in permit ip object-group inside.id3C4E4C38.dst.net.0 object-group outside.pol-firewall2-3.dst.net.0
+!
+! Rule 13 (global)
+! firewall:Policy:13: warning: MAC address matching is not supported. One or several MAC addresses removed from source in the rule
+access-list inside_acl_in permit tcp host 192.168.1.10 object-group inside.id3E155E82.dst.net.0 eq 3128
+!
+! Rule 14 (global)
+access-list outside_acl_in permit tcp any object-group outside.id3D0F8031.dst.net.0 eq 3128
+access-list inside_acl_in permit tcp any object-group outside.id3D0F8031.dst.net.0 eq 3128
+access-list dmz_acl_in permit tcp any object-group outside.id3D0F8031.dst.net.0 eq 3128
+!
+! Rule 15 (global)
+access-list outside_acl_in permit icmp any host 22.22.22.22 3
+access-list inside_acl_in permit icmp any host 192.168.1.1 3
+access-list dmz_acl_in permit icmp any host 192.168.2.1 3
+access-list outside_acl_in permit tcp any host 22.22.22.22 eq 80
+access-list inside_acl_in permit tcp any host 192.168.1.1 eq 80
+access-list dmz_acl_in permit tcp any host 192.168.2.1 eq 80
+!
+! Rule 16 (global)
+access-list outside_acl_in permit tcp any object-group outside.id3CD87B1E.dst.net.0 object-group outside.id3CD87B1E.srv.tcp.0
+access-list inside_acl_in permit tcp any object-group outside.id3CD87B1E.dst.net.0 object-group outside.id3CD87B1E.srv.tcp.0
+access-list dmz_acl_in permit tcp any object-group outside.id3CD87B1E.dst.net.0 object-group outside.id3CD87B1E.srv.tcp.0
+!
+! Rule 17 (global)
+access-list outside_acl_in permit tcp any object-group outside.id3CD8770E.dst.net.0 object-group outside.id3CD87B1E.srv.tcp.0
+access-list inside_acl_in permit tcp any object-group outside.id3CD8770E.dst.net.0 object-group outside.id3CD87B1E.srv.tcp.0
+access-list dmz_acl_in permit tcp any object-group outside.id3CD8770E.dst.net.0 object-group outside.id3CD87B1E.srv.tcp.0
+!
+! Rule 18 (global)
+access-list outside_acl_in permit tcp any 192.168.1.0 255.255.255.0 object-group outside.pol-firewall2-4.srv.tcp.0
+access-list inside_acl_in permit tcp any 192.168.1.0 255.255.255.0 object-group outside.pol-firewall2-4.srv.tcp.0
+access-list dmz_acl_in permit tcp any 192.168.1.0 255.255.255.0 object-group outside.pol-firewall2-4.srv.tcp.0
+!
+! Rule 19 (global)
+! objects hostA and hostB are
+! redundant and should be removed by
+! removeRedundantAddressesFromDst
+access-list outside_acl_in permit tcp any 192.168.1.0 255.255.255.0 eq 1494
+access-list inside_acl_in permit tcp any 192.168.1.0 255.255.255.0 eq 1494
+access-list dmz_acl_in permit tcp any 192.168.1.0 255.255.255.0 eq 1494
+access-list outside_acl_in permit udp any 192.168.1.0 255.255.255.0 eq 4000
+access-list inside_acl_in permit udp any 192.168.1.0 255.255.255.0 eq 4000
+access-list dmz_acl_in permit udp any 192.168.1.0 255.255.255.0 eq 4000
+!
+! Rule 20 (global)
+access-list outside_acl_in permit tcp any gt 1024 host 192.168.1.10 eq 80
+access-list inside_acl_in permit tcp any gt 1024 host 192.168.1.10 eq 80
+access-list dmz_acl_in permit tcp any gt 1024 host 192.168.1.10 eq 80
+!
+! Rule 23 (global)
+access-list outside_acl_in permit ip host 22.22.22.22 host 22.22.22.22
+access-list inside_acl_in permit ip host 192.168.1.1 host 192.168.1.1
+access-list dmz_acl_in permit ip host 192.168.2.1 host 192.168.2.1
+!
+! Rule 24 (global)
+access-list outside_acl_in permit ip host 22.22.22.22 any
+access-list inside_acl_in permit ip host 192.168.1.1 any
+access-list dmz_acl_in permit ip host 192.168.2.1 any
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 25 (global)
+access-list outside_acl_in deny ip any any
+access-list inside_acl_in deny ip any any
+access-list dmz_acl_in deny ip any any
+
+
+access-group dmz_acl_in in interface dmz
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+clear xlate
+clear static
+clear global
+clear nat
+!
+! Rule 0 (NAT)
+global (outside) 1 interface
+nat (inside) 1 192.168.1.0 255.255.255.0 0 0
+global (dmz) 1 interface
+!
+!
+! Rule 1 (NAT)
+nat (dmz) 1 0.0.0.0 0.0.0.0 0 0
+!
+! Rule 2 (NAT)
+nat (inside) 1 0.0.0.0 0.0.0.0 0 0
+!
+!
+! Rule 3 (NAT)
+global (outside) 1 22.22.22.0 netmask 255.255.255.0
+!
+!
+! Rule 4 (NAT)
+global (outside) 1 22.22.22.21-22.22.22.25 netmask 255.255.255.0
+!
+!
+! Rule 5 (NAT)
+static (inside,outside) tcp interface 25 192.168.1.10 25 0 0
+!
+! Rule 6 (NAT)
+! firewall:NAT:6: warning: Original destination is ignored in 'nat' NAT rules when compiling for PIX v6.2 and earlier.
+global (inside) 8 interface
+nat (dmz) 8 192.168.2.0 255.255.255.0 outside
+!
+! Rule 7 (NAT)
+
+clear access-list nat0.inside
+access-list nat0.inside permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
+nat (inside) 0 access-list nat0.inside
+!
+! Rule 8 (NAT)
+
+access-list nat0.inside permit ip host 192.168.1.11 192.168.2.0 255.255.255.0
+
+access-list nat0.inside permit ip host 192.168.1.12 192.168.2.0 255.255.255.0
+
+access-list nat0.inside permit ip host 192.168.1.13 192.168.2.0 255.255.255.0
+
+access-list nat0.inside permit ip host 192.168.1.14 192.168.2.0 255.255.255.0
+
+access-list nat0.inside permit ip host 192.168.1.15 192.168.2.0 255.255.255.0
+!
+! Rule 9 (NAT)
+nat (dmz) 0 0 0
+!
+! Rule 10 (NAT)
+static (inside,dmz) 192.168.1.0 192.168.1.0 netmask 255.255.255.0
+!
+! Rule 11 (NAT)
+static (inside,dmz) 192.168.1.10 192.168.1.10 netmask 255.255.255.255
+
+!
+! Rule 0 (main)
+!
+! "Routing rule 0 (main)"
+!
+!
+!
+route outside 0.0.0.0 0.0.0.0 22.22.22.254 1
+!
+! Rule 1 (main)
+!
+! "Routing rule 1 (main)"
+!
+!
+!
+route inside 10.3.14.0 255.255.255.0 192.168.1.254 1
+!
+! Rule 2 (main)
+!
+! "Routing rule 2 (main)"
+!
+!
+!
+route inside 10.1.2.0 255.255.255.0 192.168.1.254 1
+!
+! Rule 3 (main)
+!
+! "Routing rule 3 (main)"
+!
+# firewall:Routing:3: error: Interface and gateway rule elements can not be empty in the PIX routing rule
+!
+!
+route 10.1.3.0 255.255.255.0 192.168.1.254 1
+!
+! Rule 4 (main)
+!
+! "Routing rule 4 (main)"
+!
+# firewall:Routing:4: error: Interface and gateway rule elements can not be empty in the PIX routing rule
+!
+!
+route inside 10.1.4.0 255.255.255.0 1
+!
+! Rule 5 (main)
+!
+! "Routing rule 5 (main)"
+!
+# firewall:Routing:5: error: Interface and gateway rule elements can not be empty in the PIX routing rule
+!
+!
+route 10.1.5.0 255.255.255.0 1
+!
+! Rule 6 (main)
+!
+! "Routing rule 6 (main)"
+!
+!
+!
+route outside 33.33.33.0 255.255.255.0 22.22.22.100 1
+!
+! Rule 7 (main)
+!
+! "Routing rule 7 (main)"
+!
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall1.fw.orig b/test/pix/firewall1.fw.orig
new file mode 100755
index 000000000..d88b091fc
--- /dev/null
+++ b/test/pix/firewall1.fw.orig
@@ -0,0 +1,157 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:05 2011 PST by vadim
+!
+! Compiled for pix 6.1
+! Outbound ACLs: not supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: no
+!
+!# files: * firewall1.fw
+!
+! this object is used to test all kinds of negation in policy rules
+
+! firewall1::: error: Dynamic interface eth1 should not have an IP address object attached to it. This IP address object will be ignored.
+
+! C firewall1:Policy:9: error: Dynamic interface can be used in the policy rule only in v6.3 or later.
+! C firewall1:Policy:9: error: Dynamic interface can be used in the policy rule only in v6.3 or later.
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+nameif eth0 inside security100
+
+nameif eth1 outside security0
+
+nameif eth2 dmz security50
+
+
+no logging buffered
+no logging console
+no logging timestamp
+no logging on
+
+
+
+telnet timeout 5
+
+clear ssh
+aaa authentication ssh console LOCAL
+ssh timeout 5
+
+no snmp-server
+
+
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt security fragguard
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+no sysopt route dnat
+floodguard disable
+
+
+!################
+
+object-group icmp-type outside.id3D50B022.srv.icmp.0
+ icmp-object 8
+ icmp-object 11
+ exit
+
+!
+! Rule 2 (eth1)
+! Anti-spoofing rule
+access-list outside_acl_in deny ip host 192.168.1.1 any
+access-list outside_acl_in deny ip host 192.168.2.1 any
+access-list outside_acl_in deny ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 3 (eth0)
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 4 (eth1)
+icmp permit any 8 outside
+icmp permit any 11 outside
+access-list outside_acl_in permit icmp any interface outside object-group outside.id3D50B022.srv.icmp.0
+!
+! Rule 5 (eth1)
+access-list outside_acl_in permit icmp any any object-group outside.id3D50B022.srv.icmp.0
+!
+! Rule 6 (eth1,eth2)
+access-list outside_acl_in permit icmp any interface outside object-group outside.id3D50B022.srv.icmp.0
+icmp permit any 8 dmz
+icmp permit any 11 dmz
+access-list dmz_acl_in permit icmp any host 192.168.2.1 object-group outside.id3D50B022.srv.icmp.0
+!
+! Rule 9 (global)
+telnet 0.0.0.0 0.0.0.0 inside
+telnet 0.0.0.0 0.0.0.0 dmz
+ssh 0.0.0.0 0.0.0.0 inside
+ssh 0.0.0.0 0.0.0.0 dmz
+!
+! Rule 11 (global)
+! hostF has the same IP address as firewal.
+icmp permit any 8 inside
+access-list inside_acl_in permit icmp any host 192.168.1.1 8
+!
+! Rule 19 (global)
+! 'masquerading' rule
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 20 (global)
+! 'catch all' rule
+access-list inside_acl_in deny ip any any
+access-list outside_acl_in deny ip any any
+access-list dmz_acl_in deny ip any any
+
+
+access-group dmz_acl_in in interface dmz
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+!
+! Rule 0 (NAT)
+
+access-list nat0.inside permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
+nat (inside) 0 access-list nat0.inside
+!
+! Rule 1 (NAT)
+global (outside) 1 interface
+nat (inside) 1 192.168.1.10 255.255.255.255 0 0
+!
+! Rule 4 (NAT)
+global (outside) 2 interface
+nat (inside) 2 192.168.1.0 255.255.255.0 0 0
+global (dmz) 2 interface
+!
+nat (dmz) 2 192.168.2.0 255.255.255.0 0 0
+!
+!
+! Rule 5 (NAT)
+!
+!
+!
+!
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall10.fw.orig b/test/pix/firewall10.fw.orig
new file mode 100755
index 000000000..67ddb9d45
--- /dev/null
+++ b/test/pix/firewall10.fw.orig
@@ -0,0 +1,413 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:06 2011 PST by vadim
+!
+! Compiled for pix 6.3
+! Outbound ACLs: not supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: yes
+!
+!# files: * firewall10.fw
+!
+! big policy. Testing compiler performance
+
+
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+hostname firewall10
+
+nameif ethernet1 outside security0
+
+nameif ethernet0 inside security100
+
+nameif ethernet2 dmz security50
+
+
+
+logging host inside 192.168.1.30
+logging queue 512
+logging facility 16
+no logging buffered
+no logging console
+no logging timestamp
+logging on
+
+
+timeout xlate 3:0:0
+timeout conn 1:0:0
+timeout udp 0:2:0
+timeout rpc 0:10:0
+timeout h323 0:5:0
+timeout sip 0:30:0
+timeout sip_media 0:0:0
+timeout uauth 2:0:0 absolute
+
+telnet timeout 5
+
+clear ssh
+aaa authentication ssh console LOCAL
+ssh timeout 5
+
+snmp-server community public
+snmp-server enable traps
+snmp-server host inside 192.168.1.20 trap
+snmp-server host inside 192.168.1.22 poll
+
+ntp server 192.168.1.20 source inside
+
+
+no service resetinbound
+no service resetoutside
+sysopt connection tcpmss 1380
+sysopt connection timewait
+sysopt nodnsalias inbound
+sysopt nodnsalias outbound
+floodguard disable
+
+
+fixup protocol ftp 21
+fixup protocol h323 h225 1720
+fixup protocol h323 ras 1718-1719
+fixup protocol http 80
+fixup protocol ils 389
+fixup protocol rsh 514
+fixup protocol rtsp 554
+fixup protocol sip 5060
+fixup protocol skinny 2000
+fixup protocol smtp 25
+fixup protocol sqlnet 1521
+
+
+!################
+
+object-group network inside.id3DB0FA90.dst.net.0
+ network-object host 211.11.11.11
+ network-object host 211.22.22.22
+ exit
+
+
+object-group service inside.id3DB0FA90.srv.tcp.0 tcp
+ port-object eq 113
+ port-object eq 80
+ port-object eq 25
+ port-object eq 22
+ port-object eq 540
+ port-object eq 443
+ port-object eq 143
+ exit
+
+
+object-group icmp-type outside.id3DB0F9C7.srv.icmp.0
+ icmp-object 11
+ icmp-object 0
+ icmp-object 3
+ exit
+
+
+object-group service outside.id3DB0F9BD.srv.tcp.0 tcp
+ port-object eq 3128
+ port-object eq 70
+ port-object eq 6667
+ port-object eq 23
+ exit
+
+
+object-group service outside.id3DB0F9BD.srv.udp.0 udp
+ port-object eq 161
+ port-object eq 53
+ exit
+
+
+object-group network outside.id3DB0F9E6.dst.net.0
+ network-object host 192.168.1.10
+ network-object host 192.168.1.20
+ exit
+
+
+object-group network inside.id3DB10695.src.net.0
+ network-object 192.168.1.0 255.255.255.0
+ network-object 192.168.10.0 255.255.255.0
+ network-object 192.168.20.0 255.255.255.0
+ exit
+
+
+object-group network dmz.id3DB10695.src.net.0
+ network-object 192.168.2.0 255.255.255.0
+ network-object 192.168.3.0 255.255.255.0
+ exit
+
+
+object-group network outside.id3DB10695.dst.net.0
+ network-object host 192.168.1.10
+ network-object host 192.168.1.11
+ network-object host 192.168.1.12
+ network-object host 192.168.1.13
+ network-object host 192.168.1.14
+ network-object host 192.168.1.15
+ network-object host 192.168.1.20
+ exit
+
+
+object-group network outside.id3DB0F9F2.dst.net.0
+ network-object 192.168.1.250 255.255.255.254
+ network-object 192.168.1.252 255.255.255.252
+ exit
+
+
+object-group network outside.id3DB0F9FC.dst.net.0
+ network-object host 192.168.1.11
+ network-object host 192.168.1.12
+ network-object host 192.168.1.13
+ network-object host 192.168.1.14
+ network-object host 192.168.1.15
+ exit
+
+
+object-group service outside.id3DB0F9FC.srv.tcp.0 tcp
+ port-object eq 113
+ port-object eq 80
+ port-object eq 25
+ port-object eq 22
+ port-object eq 540
+ port-object eq 443
+ port-object eq 143
+ port-object eq 3128
+ exit
+
+
+object-group network outside.id3DB0FA07.dst.net.0
+ network-object 192.168.1.11 255.255.255.255
+ network-object 192.168.1.12 255.255.255.252
+ exit
+
+
+object-group service outside.id3DB0FA12.srv.tcp.0 tcp
+ port-object eq 3128
+ port-object range 10000 11000
+ port-object eq 6667
+ port-object eq 113
+ port-object eq 53
+ port-object eq 21
+ port-object eq 80
+ port-object eq 119
+ port-object eq 25
+ port-object eq 22
+ port-object eq 23
+ port-object eq 540
+ port-object eq 70
+ port-object eq 13
+ port-object eq 2105
+ port-object eq 443
+ port-object eq 143
+ port-object eq 993
+ port-object eq 6667
+ port-object eq 543
+ port-object eq 544
+ port-object eq 389
+ port-object eq 98
+ port-object eq 3306
+ port-object eq 2049
+ port-object eq 110
+ port-object eq 5432
+ port-object eq 515
+ port-object eq 26000
+ port-object eq 512
+ port-object eq 513
+ port-object eq 514
+ port-object eq 4321
+ port-object eq 465
+ port-object eq 1080
+ port-object eq 111
+ port-object eq 7100
+ exit
+
+!
+! Rule 3 (ethernet1)
+! anti-spoofing rule
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 5 (ethernet0)
+access-list inside_acl_in permit tcp any object-group inside.id3DB0FA90.dst.net.0 object-group inside.id3DB0FA90.srv.tcp.0
+access-list inside_acl_in permit tcp any object-group inside.id3DB0FA90.dst.net.0 object-group inside.id3DB0FA90.srv.tcp.0
+access-list dmz_acl_in permit tcp any object-group inside.id3DB0FA90.dst.net.0 object-group inside.id3DB0FA90.srv.tcp.0
+!
+! Rule 7 (global)
+access-list outside_acl_in permit icmp any host 192.168.1.10 object-group outside.id3DB0F9C7.srv.icmp.0
+access-list inside_acl_in permit icmp any host 192.168.1.10 object-group outside.id3DB0F9C7.srv.icmp.0
+access-list dmz_acl_in permit icmp any host 192.168.1.10 object-group outside.id3DB0F9C7.srv.icmp.0
+!
+! Rule 8 (global)
+access-list outside_acl_in permit icmp any host 192.168.1.10
+access-list inside_acl_in permit icmp any host 192.168.1.10
+access-list dmz_acl_in permit icmp any host 192.168.1.10
+access-list outside_acl_in permit tcp any host 192.168.1.10 object-group outside.id3DB0F9BD.srv.tcp.0
+access-list inside_acl_in permit tcp any host 192.168.1.10 object-group outside.id3DB0F9BD.srv.tcp.0
+access-list dmz_acl_in permit tcp any host 192.168.1.10 object-group outside.id3DB0F9BD.srv.tcp.0
+access-list outside_acl_in permit udp any host 192.168.1.10 object-group outside.id3DB0F9BD.srv.udp.0
+access-list inside_acl_in permit udp any host 192.168.1.10 object-group outside.id3DB0F9BD.srv.udp.0
+access-list dmz_acl_in permit udp any host 192.168.1.10 object-group outside.id3DB0F9BD.srv.udp.0
+access-list outside_acl_in permit 47 any host 192.168.1.10
+access-list inside_acl_in permit 47 any host 192.168.1.10
+access-list dmz_acl_in permit 47 any host 192.168.1.10
+!
+! Rule 9 (global)
+icmp permit any 3 outside
+access-list outside_acl_in permit icmp any host 22.22.22.22 3
+icmp permit any 3 inside
+access-list inside_acl_in permit icmp any host 192.168.1.1 3
+icmp permit any 3 dmz
+access-list dmz_acl_in permit icmp any host 192.168.2.1 3
+access-list outside_acl_in permit icmp any any 3
+access-list inside_acl_in permit icmp any any 3
+access-list dmz_acl_in permit icmp any any 3
+access-list outside_acl_in permit 47 any any
+access-list inside_acl_in permit 47 any any
+access-list dmz_acl_in permit 47 any any
+access-list outside_acl_in permit 50 any any
+access-list inside_acl_in permit 50 any any
+access-list dmz_acl_in permit 50 any any
+!
+! Rule 11 (global)
+access-list outside_acl_in permit ip object-group inside.id3DB0FA90.dst.net.0 object-group outside.id3DB0F9E6.dst.net.0
+!
+! Rule 12 (global)
+access-list outside_acl_in permit ip 192.168.4.0 255.255.255.0 host 192.168.1.1
+access-list inside_acl_in permit ip object-group inside.id3DB10695.src.net.0 host 192.168.1.1
+access-list dmz_acl_in permit ip object-group dmz.id3DB10695.src.net.0 host 192.168.1.1
+access-list outside_acl_in permit ip 192.168.4.0 255.255.255.0 object-group outside.id3DB10695.dst.net.0
+access-list inside_acl_in permit ip object-group inside.id3DB10695.src.net.0 object-group outside.id3DB10695.dst.net.0
+access-list dmz_acl_in permit ip object-group dmz.id3DB10695.src.net.0 object-group outside.id3DB10695.dst.net.0
+!
+! Rule 13 (global)
+access-list outside_acl_in permit tcp any object-group outside.id3DB0F9F2.dst.net.0 eq 3128
+access-list inside_acl_in permit tcp any object-group outside.id3DB0F9F2.dst.net.0 eq 3128
+access-list dmz_acl_in permit tcp any object-group outside.id3DB0F9F2.dst.net.0 eq 3128
+!
+! Rule 14 (global)
+access-list outside_acl_in permit tcp any object-group outside.id3DB0F9FC.dst.net.0 object-group outside.id3DB0F9FC.srv.tcp.0
+access-list inside_acl_in permit tcp any object-group outside.id3DB0F9FC.dst.net.0 object-group outside.id3DB0F9FC.srv.tcp.0
+access-list dmz_acl_in permit tcp any object-group outside.id3DB0F9FC.dst.net.0 object-group outside.id3DB0F9FC.srv.tcp.0
+!
+! Rule 15 (global)
+access-list outside_acl_in permit tcp any object-group outside.id3DB0FA07.dst.net.0 object-group outside.id3DB0F9FC.srv.tcp.0
+access-list inside_acl_in permit tcp any object-group outside.id3DB0FA07.dst.net.0 object-group outside.id3DB0F9FC.srv.tcp.0
+access-list dmz_acl_in permit tcp any object-group outside.id3DB0FA07.dst.net.0 object-group outside.id3DB0F9FC.srv.tcp.0
+!
+! Rule 16 (global)
+access-list outside_acl_in permit tcp any 192.168.1.0 255.255.255.0 object-group outside.id3DB0FA12.srv.tcp.0
+access-list inside_acl_in permit tcp any 192.168.1.0 255.255.255.0 object-group outside.id3DB0FA12.srv.tcp.0
+access-list dmz_acl_in permit tcp any 192.168.1.0 255.255.255.0 object-group outside.id3DB0FA12.srv.tcp.0
+!
+! Rule 19 (global)
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 inside
+ssh 0.0.0.0 0.0.0.0 dmz
+access-list outside_acl_in permit icmp any host 22.22.22.22 3
+access-list inside_acl_in permit icmp any host 192.168.1.1 3
+access-list dmz_acl_in permit icmp any host 192.168.2.1 3
+!
+! Rule 20 (global)
+access-list outside_acl_in permit ip host 22.22.22.22 host 22.22.22.22
+access-list inside_acl_in permit ip host 192.168.1.1 host 192.168.1.1
+access-list dmz_acl_in permit ip host 192.168.2.1 host 192.168.2.1
+!
+! Rule 21 (global)
+access-list outside_acl_in permit ip host 22.22.22.22 any
+access-list inside_acl_in permit ip host 192.168.1.1 any
+access-list dmz_acl_in permit ip host 192.168.2.1 any
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 22 (global)
+access-list outside_acl_in deny ip any any
+access-list inside_acl_in deny ip any any
+access-list dmz_acl_in deny ip any any
+
+
+access-group dmz_acl_in in interface dmz
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+!
+! Rule 0 (NAT)
+global (outside) 1 interface
+access-list id3DB0F916.0 permit ip 192.168.1.0 255.255.255.0 any
+nat (inside) 1 access-list id3DB0F916.0 0 0
+global (dmz) 1 interface
+!
+!
+! Rule 1 (NAT)
+access-list id3DB0F924.0 permit ip 192.168.2.0 255.255.255.0 any
+access-list id3DB0F924.0 permit ip 192.168.3.0 255.255.255.0 any
+nat (dmz) 1 access-list id3DB0F924.0 0 0
+!
+! Rule 2 (NAT)
+global (outside) 1 22.22.22.0 netmask 255.255.255.0
+!
+!
+! Rule 3 (NAT)
+global (outside) 1 22.22.22.21-22.22.22.25 netmask 255.255.255.0
+!
+!
+! Rule 4 (NAT)
+access-list id3DB0F94E.0 permit tcp host 192.168.1.10 eq 25 any
+static (inside,outside) tcp interface 25 access-list id3DB0F94E.0 0 0
+!
+! Rule 5 (NAT)
+! policy NAT
+! rule
+global (inside) 7 interface
+access-list id3DB0F95C.0 permit ip 192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0
+access-list id3DB0F95C.0 permit ip 192.168.3.0 255.255.255.0 192.168.1.0 255.255.255.0
+nat (dmz) 7 access-list id3DB0F95C.0 outside
+!
+! Rule 6 (NAT)
+! policy NAT
+! rule
+access-list id3F9353DD.0 permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
+access-list id3F9353DD.0 permit ip 192.168.1.0 255.255.255.0 192.168.3.0 255.255.255.0
+nat (inside) 1 access-list id3F9353DD.0 0 0
+!
+! Rule 7 (NAT)
+
+access-list nat0.inside permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
+nat (inside) 0 access-list nat0.inside
+
+access-list nat0.inside permit ip 192.168.1.0 255.255.255.0 192.168.3.0 255.255.255.0
+!
+! Rule 8 (NAT)
+
+access-list nat0.inside permit ip host 192.168.1.10 192.168.2.0 255.255.255.0
+
+access-list nat0.inside permit ip host 192.168.1.10 192.168.3.0 255.255.255.0
+!
+! Rule 9 (NAT)
+static (inside,dmz) 192.168.1.0 192.168.1.0 netmask 255.255.255.0
+!
+! Rule 10 (NAT)
+static (inside,dmz) 192.168.1.10 192.168.1.10 netmask 255.255.255.255
+!
+! Rule 11 (NAT)
+static (inside,outside) 192.168.1.10 192.168.1.10 netmask 255.255.255.255
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall11.fw.orig b/test/pix/firewall11.fw.orig
new file mode 100755
index 000000000..bcf96a457
--- /dev/null
+++ b/test/pix/firewall11.fw.orig
@@ -0,0 +1,133 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:06 2011 PST by vadim
+!
+! Compiled for pix 6.2
+! Outbound ACLs: not supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: no
+!
+!# files: * firewall11.fw
+!
+! testing conversion of objects into their natted addresses when outside interface has multiple addresses and nat rule uses ip address which is not the first one under interface. Nat rules 3-4-5 and global policy rule 0
+
+
+
+!
+! Prolog script:
+!
+no sysopt connection timewait
+no sysopt security fragguard
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+!
+! End of prolog script:
+!
+
+
+
+
+nameif eth0 outside security0
+
+nameif eth1 dmz security50
+
+nameif eth2 inside security100
+
+
+no logging buffered
+no logging console
+no logging timestamp
+no logging on
+
+
+timeout xlate 3:0:0
+timeout conn 1:0:0
+timeout udp 0:2:0
+timeout rpc 0:10:0
+timeout h323 0:5:0
+timeout sip 0:30:0
+timeout sip_media 0:2:0
+timeout half-closed 0:0:0
+timeout uauth 2:0:0 absolute
+
+telnet timeout 5
+
+clear ssh
+aaa authentication ssh console LOCAL
+ssh timeout 5
+
+no snmp-server enable traps
+
+
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+sysopt security fragguard
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+sysopt route dnat
+floodguard enable
+
+
+!################
+!
+! Rule 0 (global)
+access-list outside_acl_in permit tcp any host 10.5.80.20 eq 80
+access-list outside_acl_in permit tcp any host 192.168.1.10 eq 80
+access-list dmz_acl_in permit tcp any host 192.168.1.10 eq 80
+access-list inside_acl_in permit tcp any host 192.168.1.10 eq 80
+!
+! Rule 1 (global)
+access-list inside_acl_in permit tcp any host 192.168.1.20 eq 1500
+!
+! Rule 2 (global)
+access-list outside_acl_in deny tcp any any range 1000 10001
+access-list dmz_acl_in deny tcp any any range 1000 10001
+access-list inside_acl_in deny tcp any any range 1000 10001
+!
+! Rule 3 (global)
+access-list outside_acl_in permit ip any 192.168.1.0 255.255.255.0
+access-list dmz_acl_in permit ip any 192.168.1.0 255.255.255.0
+access-list inside_acl_in permit ip any 192.168.1.0 255.255.255.0
+!
+! Rule 4 (global)
+access-list outside_acl_in deny ip any any
+access-list dmz_acl_in deny ip any any
+access-list inside_acl_in deny ip any any
+
+
+access-group dmz_acl_in in interface dmz
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+!
+! Rule 0 (NAT)
+global (dmz) 1 interface
+nat (inside) 1 192.168.1.0 255.255.255.0 0 0
+!
+! Rule 1 (NAT)
+global (outside) 1 interface
+!
+nat (dmz) 1 192.168.2.0 255.255.255.0 0 0
+!
+! Rule 2 (NAT)
+!
+!
+!
+! Rule 3 (NAT)
+static (inside,outside) tcp 10.5.80.20 80 192.168.1.10 80 netmask 255.255.240.0 0 0
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall12.fw.orig b/test/pix/firewall12.fw.orig
new file mode 100755
index 000000000..3eac58d55
--- /dev/null
+++ b/test/pix/firewall12.fw.orig
@@ -0,0 +1,171 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:07 2011 PST by vadim
+!
+! Compiled for pix 6.3
+! Outbound ACLs: not supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: no
+!
+!# files: * firewall12.fw
+!
+! this firewall has DMZ using routable address
+
+
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+hostname firewall12
+
+nameif ethernet0 outside security0
+ip address outside dhcp setroute retry 10
+
+nameif ethernet1 inside security100
+ip address inside 10.3.14.20 255.255.255.0
+
+nameif ethernet2 dmz50 security50
+ip address dmz50 192.0.2.1 255.255.255.0
+
+
+
+logging host inside 10.3.14.10 format emblem
+logging queue 1000
+logging facility 16
+no logging buffered
+no logging console
+no logging timestamp
+logging on
+logging device-id string real_firewall
+
+
+timeout xlate 0:0:0
+timeout conn 0:0:0
+timeout udp 0:0:0
+timeout rpc 0:0:0
+timeout h323 0:0:0
+timeout sip 0:0:0
+timeout sip_media 0:0:0
+timeout half-closed 0:0:0
+timeout uauth 0:0:0 absolute
+
+telnet timeout 5
+
+clear ssh
+aaa authentication ssh console LOCAL
+ssh timeout 5
+
+snmp-server community public
+snmp-server enable traps
+snmp-server host inside 10.3.14.40 poll
+
+ntp server 10.3.14.30 source inside
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+floodguard disable
+
+
+fixup protocol dns maximum-length 65535
+fixup protocol ftp 21
+fixup protocol http 80
+fixup protocol icmp error
+
+
+!################
+
+object-group network outside.id3F8F95CD.dst.net.0
+ network-object host 192.0.2.20
+ network-object host 192.0.2.21
+ network-object host 192.0.2.23
+ exit
+
+!
+! Rule 0 (global)
+access-list inside_acl_in remark 0 (global)
+access-list inside_acl_in permit ip 10.3.14.0 255.255.255.0 any
+!
+! Rule 1 (global)
+ssh 10.3.14.0 255.255.255.0 inside
+!
+! Rule 2 (global)
+icmp permit any 0 outside
+access-list outside_acl_in remark 2 (global)
+access-list outside_acl_in permit icmp any interface outside 0
+icmp permit any 0 inside
+access-list inside_acl_in remark 2 (global)
+access-list inside_acl_in permit icmp any host 10.3.14.20 0
+icmp permit any 0 dmz50
+access-list dmz50_acl_in remark 2 (global)
+access-list dmz50_acl_in permit icmp any host 192.0.2.1 0
+!
+! Rule 3 (global)
+! this comment
+! consists of
+! 3 lines of text
+access-list outside_acl_in remark 3 (global)
+access-list outside_acl_in remark this comment
+access-list outside_acl_in remark consists of
+access-list outside_acl_in remark 3 lines of text
+access-list outside_acl_in permit tcp any interface outside eq 80
+access-list outside_acl_in permit tcp any object-group outside.id3F8F95CD.dst.net.0 eq 80
+access-list inside_acl_in remark 3 (global)
+access-list inside_acl_in remark this comment
+access-list inside_acl_in remark consists of
+access-list inside_acl_in remark 3 lines of text
+access-list inside_acl_in permit tcp any object-group outside.id3F8F95CD.dst.net.0 eq 80
+access-list dmz50_acl_in remark 3 (global)
+access-list dmz50_acl_in remark this comment
+access-list dmz50_acl_in remark consists of
+access-list dmz50_acl_in remark 3 lines of text
+access-list dmz50_acl_in permit tcp any object-group outside.id3F8F95CD.dst.net.0 eq 80
+!
+! Rule 4 (global)
+access-list outside_acl_in remark 4 (global)
+access-list outside_acl_in deny ip any any log 5 interval 120
+access-list inside_acl_in remark 4 (global)
+access-list inside_acl_in deny ip any any log 5 interval 120
+access-list dmz50_acl_in remark 4 (global)
+access-list dmz50_acl_in deny ip any any log 5 interval 120
+
+
+access-group dmz50_acl_in in interface dmz50
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+!
+! Rule 0 (NAT)
+global (outside) 1 interface
+access-list id3F8F9592.0 permit ip 10.3.14.0 255.255.255.0 any
+nat (inside) 1 access-list id3F8F9592.0 0 0
+global (dmz50) 1 interface
+!
+!
+! Rule 1 (NAT)
+access-list id3F8F95A0.0 permit tcp host 10.3.14.30 eq 80 any
+static (inside,outside) tcp interface 80 access-list id3F8F95A0.0 0 0
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall13.fw.orig b/test/pix/firewall13.fw.orig
new file mode 100755
index 000000000..cac177d74
--- /dev/null
+++ b/test/pix/firewall13.fw.orig
@@ -0,0 +1,130 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:07 2011 PST by vadim
+!
+! Compiled for pix 6.3
+! Outbound ACLs: not supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: no
+!
+!# files: * firewall13.fw
+!
+! various policy NAT rules per examples from
+! http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a0080172786.html#1113601
+
+
+
+!
+! Prolog script:
+!
+no sysopt connection timewait
+no sysopt security fragguard
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+!
+! End of prolog script:
+!
+
+
+
+
+nameif eth0 outside security0
+
+nameif eth2 inside security100
+
+
+no logging buffered
+no logging console
+no logging timestamp
+no logging on
+
+
+timeout xlate 3:0:0
+timeout conn 1:0:0
+timeout udp 0:2:0
+timeout rpc 0:10:0
+timeout h323 0:5:0
+timeout sip 0:30:0
+timeout sip_media 0:2:0
+timeout uauth 2:0:0 absolute
+
+telnet timeout 5
+
+clear ssh
+aaa authentication ssh console LOCAL
+ssh timeout 5
+
+no snmp-server enable traps
+
+
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+floodguard enable
+
+
+!################
+!
+! Rule 0 (global)
+access-list outside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 1 (global)
+access-list outside_acl_in deny ip any any
+access-list inside_acl_in deny ip any any
+
+
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+!
+! Rule 0 (NAT)
+global (outside) 1 interface
+access-list id3FA349A3.0 permit ip 10.1.2.0 255.255.255.0 209.165.201.0 255.255.255.224
+!
+! Rule 1 (NAT)
+global (outside) 1 interface
+access-list id3FA34CB5.0 permit ip 10.1.2.0 255.255.255.0 209.165.200.224 255.255.255.224
+!
+! Rule 2 (NAT)
+access-list id3FA349A3.0 permit tcp 10.1.2.0 255.255.255.0 host 209.165.201.11 eq 80
+nat (inside) 1 access-list id3FA349A3.0 0 0
+!
+! Rule 3 (NAT)
+access-list id3FA34CB5.0 permit tcp 10.1.2.0 255.255.255.0 host 209.165.201.11 eq 23
+!
+! Rule 4 (NAT)
+!
+!
+!
+! Rule 5 (NAT)
+access-list id3FA35071.0 permit ip host 10.1.2.27 209.165.201.0 255.255.255.224
+static (inside,outside) interface access-list id3FA35071.0 0 0
+!
+! Rule 6 (NAT)
+access-list id3FA35063.0 permit ip host 10.1.2.27 209.165.200.224 255.255.255.224
+static (inside,outside) interface access-list id3FA35063.0 0 0
+!
+! Rule 7 (NAT)
+access-list id3FA44ABB.0 permit tcp host 10.1.2.27 eq 80 host 209.165.200.225
+access-list id3FA44ABB.1 permit tcp host 10.1.2.27 eq 81 host 209.165.200.225
+access-list id3FA44ABB.0 permit tcp host 10.1.2.27 eq 80 host 209.165.201.11
+static (inside,outside) tcp interface 80 access-list id3FA44ABB.0 0 0
+access-list id3FA44ABB.1 permit tcp host 10.1.2.27 eq 81 host 209.165.201.11
+static (inside,outside) tcp interface 81 access-list id3FA44ABB.1 0 0
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall14.fw.orig b/test/pix/firewall14.fw.orig
new file mode 100755
index 000000000..7d3c9000b
--- /dev/null
+++ b/test/pix/firewall14.fw.orig
@@ -0,0 +1,104 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:08 2011 PST by vadim
+!
+! Compiled for pix 6.3
+! Outbound ACLs: not supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: no
+!
+!# files: * firewall14.fw
+!
+! testing dual NAT per user's request
+
+
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+nameif eth0 outside security0
+
+nameif eth2 inside security100
+
+
+no logging buffered
+no logging console
+no logging timestamp
+no logging on
+
+
+timeout xlate 3:0:0
+timeout conn 1:0:0
+timeout udp 0:2:0
+timeout rpc 0:10:0
+timeout h323 0:5:0
+timeout sip 0:30:0
+timeout sip_media 0:2:0
+timeout uauth 2:0:0 absolute
+
+telnet timeout 5
+
+clear ssh
+aaa authentication ssh console LOCAL
+ssh timeout 5
+
+no snmp-server enable traps
+
+
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+floodguard enable
+
+
+!################
+!
+! Rule 0 (global)
+access-list inside_acl_in permit ip 10.1.2.0 255.255.255.0 any
+!
+! Rule 1 (global)
+access-list outside_acl_in deny ip any any
+access-list inside_acl_in deny ip any any
+
+
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+!
+! Rule 0 (NAT)
+global (outside) 1 interface
+access-list id3FA74FDE.0 permit ip host 10.1.2.27 any
+nat (inside) 1 access-list id3FA74FDE.0 0 0
+!
+! Rule 1 (NAT)
+access-list id3FA74FCE.0 permit ip host 209.165.201.11 any
+static (outside,inside) interface access-list id3FA74FCE.0 0 0
+!
+! Rule 2 (NAT)
+access-list id3FA7502F.0 permit ip host 10.1.2.27 any
+static (inside,outside) interface access-list id3FA7502F.0 0 0
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall2.fw.orig b/test/pix/firewall2.fw.orig
new file mode 100755
index 000000000..a7ef36ab5
--- /dev/null
+++ b/test/pix/firewall2.fw.orig
@@ -0,0 +1,239 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:09 2011 PST by vadim
+!
+! Compiled for pix 6.3
+! Outbound ACLs: not supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: yes
+!
+!# files: * firewall2.fw
+!
+! lots of different combinations of objects in the NAT rules
+
+
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+nameif eth0 inside security100
+
+nameif eth1 outside security0
+
+nameif eth2 dmz security50
+
+
+no logging buffered
+no logging console
+no logging timestamp
+no logging on
+
+
+
+telnet timeout 5
+
+clear ssh
+aaa authentication ssh console LOCAL
+ssh timeout 5
+
+clear snmp-server
+no snmp-server enable traps
+
+clear ntp
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+floodguard disable
+
+
+!################
+clear access-list
+clear object-group
+clear icmp
+clear telnet
+
+object-group service inside.id3D6EF08C.srv.tcp.0 tcp
+ port-object eq 80
+ port-object eq 119
+ exit
+
+
+object-group network inside.id3D8FCCDE.src.net.0
+ network-object host 192.168.1.10
+ network-object host 192.168.1.20
+ exit
+
+!
+! Rule 0 (eth1)
+! Anti-spoofing rule
+access-list outside_acl_in deny ip host 192.168.1.1 any
+access-list outside_acl_in deny ip host 22.22.22.22 any
+access-list outside_acl_in deny ip host 192.168.2.1 any
+access-list outside_acl_in deny ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 1 (eth1)
+! Anti-spoofing rule
+access-list inside_acl_in deny ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 2 (global)
+access-list inside_acl_in permit tcp any host 192.168.1.10 object-group inside.id3D6EF08C.srv.tcp.0
+access-list outside_acl_in permit tcp any host 22.22.22.22 eq 80
+access-list outside_acl_in permit tcp any host 22.22.22.22 eq 119
+access-list outside_acl_in permit tcp any host 192.168.1.10 object-group inside.id3D6EF08C.srv.tcp.0
+access-list dmz_acl_in permit tcp any host 192.168.1.10 object-group inside.id3D6EF08C.srv.tcp.0
+!
+! Rule 3 (global)
+access-list inside_acl_in permit ip object-group inside.id3D8FCCDE.src.net.0 host 200.200.200.200
+!
+! Rule 4 (global)
+access-list outside_acl_in permit ip host 200.200.200.200 object-group inside.id3D8FCCDE.src.net.0
+!
+! Rule 6 (global)
+access-list inside_acl_in deny ip any any
+access-list outside_acl_in deny ip any any
+access-list dmz_acl_in deny ip any any
+
+
+access-group dmz_acl_in in interface dmz
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+clear xlate
+clear static
+clear global
+clear nat
+!
+! Rule 0 (NAT)
+
+access-list nat0.inside permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
+nat (inside) 0 access-list nat0.inside
+!
+! Rule 1 (NAT)
+static (inside,dmz) 192.168.1.0 192.168.1.0 netmask 255.255.255.0
+!
+! Rule 2 (NAT)
+global (outside) 1 interface
+access-list id3AFB66C8.0 permit ip 192.168.1.0 255.255.255.0 any
+global (dmz) 1 interface
+!
+!
+! Rule 3 (NAT)
+access-list id3AFB66C8.0 permit ip host 192.168.1.10 any
+!
+access-list id3AFB66C8.0 permit ip host 192.168.1.20 any
+!
+!
+! Rule 4 (NAT)
+access-list id3AFB66C8.0 permit ip host 192.168.1.11 any
+!
+access-list id3AFB66C8.0 permit ip 192.168.1.12 255.255.255.252 any
+!
+!
+! Rule 5 (NAT)
+access-list id3D1C2292.0 permit ip 192.168.2.0 255.255.255.0 any
+nat (dmz) 1 access-list id3D1C2292.0 0 0
+!
+! Rule 6 (NAT)
+!
+!
+! Rule 7 (NAT)
+global (outside) 1 interface
+!
+!
+! Rule 8 (NAT)
+!
+!
+! Rule 9 (NAT)
+!
+!
+!
+! Rule 10 (NAT)
+global (outside) 1 22.22.22.0 netmask 255.255.255.0
+!
+!
+! Rule 11 (NAT)
+global (outside) 1 22.22.22.21-22.22.22.25 netmask 255.255.255.0
+!
+!
+!
+! Rule 12 (NAT)
+global (dmz) 1 interface
+access-list id3D1C1104.0 permit ip host 192.168.1.10 192.168.2.0 255.255.255.0
+!
+! Rule 13 (NAT)
+access-list id3D1C1D30.0 permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
+nat (inside) 1 access-list id3D1C1D30.0 0 0
+!
+! Rule 14 (NAT)
+!
+!
+! Rule 16 (NAT)
+access-list id3D1BFFA4.0 permit ip host 192.168.1.10 any
+static (inside,outside) interface access-list id3D1BFFA4.0 0 0
+!
+! Rule 17 (NAT)
+access-list id3D1C0835.0 permit tcp host 192.168.1.10 eq 6667 any
+static (inside,outside) tcp interface 6667 access-list id3D1C0835.0 0 0
+!
+! Rule 18 (NAT)
+access-list id16986X27842.0 permit tcp host 192.168.1.1 eq 6667 any
+static (inside,outside) tcp interface 6667 access-list id16986X27842.0 0 0
+!
+! Rule 19 (NAT)
+access-list id414351C7.0 permit tcp host 192.168.1.10 eq 80 any
+!
+! Rule 20 (NAT)
+access-list id414351C7.0 permit tcp host 192.168.1.10 eq 80 any
+static (inside,outside) tcp interface 80 access-list id414351C7.0 0 0
+!
+! Rule 21 (NAT)
+access-list id3AFB69BD.0 permit ip host 192.168.1.10 any
+static (inside,outside) interface access-list id3AFB69BD.0 0 0
+!
+! Rule 22 (NAT)
+access-list id3D1BFFCE.0 permit ip 192.168.1.0 255.255.255.0 any
+static (inside,outside) 22.22.22.0 access-list id3D1BFFCE.0 0 0
+!
+! Rule 24 (NAT)
+access-list id3D1BFFF6.0 permit ip host 192.168.1.10 192.168.2.0 255.255.255.0
+static (inside,dmz) interface access-list id3D1BFFF6.0 0 0
+!
+! Rule 25 (NAT)
+access-list id3BEEF6D2.0 permit tcp host 192.168.1.10 eq 119 any
+static (inside,outside) tcp interface 119 access-list id3BEEF6D2.0 0 0
+!
+! Rule 27 (NAT)
+access-list id3B7313C4.0 permit tcp host 192.168.1.10 eq 3128 any
+static (inside,outside) tcp interface 80 access-list id3B7313C4.0 0 0
+!
+! Rule 28 (NAT)
+access-list id47B6CF3421818.0 permit tcp host 192.168.1.10 eq 3128 any
+!
+! Rule 29 (NAT)
+access-list id47B6CF3421818.0 permit tcp host 192.168.1.10 eq 3128 any
+static (inside,outside) tcp interface 80 access-list id47B6CF3421818.0 0 0
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall20.fw.orig b/test/pix/firewall20.fw.orig
new file mode 100755
index 000000000..acd701065
--- /dev/null
+++ b/test/pix/firewall20.fw.orig
@@ -0,0 +1,163 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:09 2011 PST by vadim
+!
+! Compiled for pix 6.3
+! Outbound ACLs: not supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: no
+!
+!# files: * firewall20.fw
+!
+! testing outbound ACLs
+! v6.3, emulation of outbound ACLs is on
+
+
+
+!
+! Prolog script:
+!
+no sysopt connection timewait
+no sysopt security fragguard
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+!
+! End of prolog script:
+!
+
+
+
+
+nameif eth0 outside security0
+
+nameif eth1 dmz security50
+
+nameif eth2 inside security100
+
+
+no logging buffered
+no logging console
+no logging timestamp
+no logging on
+
+
+timeout xlate 3:0:0
+timeout conn 1:0:0
+timeout udp 0:2:0
+timeout rpc 0:10:0
+timeout h323 0:5:0
+timeout sip 0:30:0
+timeout sip_media 0:2:0
+timeout half-closed 0:0:0
+timeout uauth 2:0:0 absolute
+
+telnet timeout 5
+
+clear ssh
+aaa authentication ssh console LOCAL
+ssh timeout 5
+
+no snmp-server enable traps
+
+
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+floodguard enable
+
+
+fixup protocol ftp 21
+
+
+!################
+!
+! Rule 0 (global)
+access-list outside_acl_in permit ip any host 192.168.1.10
+access-list dmz_acl_in permit ip any host 192.168.1.10
+access-list inside_acl_in permit ip any host 192.168.1.10
+!
+! Rule 1 (global)
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 2 (global)
+access-list dmz_acl_in permit ip 192.168.2.0 255.255.255.0 any
+!
+! Rule 3 (eth1)
+! dmz -> intnet
+access-list dmz_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 4 (eth2)
+! dmz -> intnet
+access-list dmz_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 5 (eth1,eth2)
+! dmz -> intnet
+access-list dmz_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+access-list inside_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+access-list dmz_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 6 (eth0,eth1)
+access-list outside_acl_in deny ip host 10.5.70.20 any log 0 interval 300
+access-list outside_acl_in deny ip host 192.168.2.20 any log 0 interval 300
+access-list outside_acl_in deny ip host 192.168.1.20 any log 0 interval 300
+access-list outside_acl_in deny ip 192.168.1.0 255.255.255.0 any log 0 interval 300
+access-list dmz_acl_in deny ip host 10.5.70.20 any log 0 interval 300
+access-list dmz_acl_in deny ip host 192.168.2.20 any log 0 interval 300
+access-list dmz_acl_in deny ip host 192.168.1.20 any log 0 interval 300
+access-list dmz_acl_in deny ip 192.168.1.0 255.255.255.0 any log 0 interval 300
+!
+! Rule 7 (eth0,eth1)
+access-list dmz_acl_in permit ip 192.168.2.0 255.255.255.0 any
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 8 (global)
+access-list outside_acl_in deny ip any any
+access-list dmz_acl_in deny ip any any
+access-list inside_acl_in deny ip any any
+
+
+access-group dmz_acl_in in interface dmz
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+!
+! Rule 0 (NAT)
+global (outside) 1 interface
+access-list id4528A51F20039.0 permit ip 192.168.1.0 255.255.255.0 any
+nat (inside) 1 access-list id4528A51F20039.0 0 0
+!
+! Rule 1 (NAT)
+access-list id4528A54A20039.0 permit ip 192.168.2.0 255.255.255.0 any
+nat (dmz) 1 access-list id4528A54A20039.0 0 0
+!
+! Rule 2 (NAT)
+access-list id4528A55820039.0 permit ip host 192.168.2.100 any
+static (dmz,outside) interface access-list id4528A55820039.0 0 0
+!
+! Rule 3 (NAT)
+global (inside) 3 interface
+access-list id4528A56620039.0 permit ip 192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0
+nat (dmz) 3 access-list id4528A56620039.0 outside
+!
+! Rule 4 (NAT)
+global (dmz) 4 interface
+access-list id4528A57420039.0 permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
+nat (inside) 4 access-list id4528A57420039.0 0 0
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall21-1.fw.orig b/test/pix/firewall21-1.fw.orig
new file mode 100755
index 000000000..69f8f82df
--- /dev/null
+++ b/test/pix/firewall21-1.fw.orig
@@ -0,0 +1,210 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:10 2011 PST by vadim
+!
+! Compiled for pix 6.3
+! Outbound ACLs: not supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: no
+!
+!# files: * firewall21-1.fw
+!
+! testing outbound ACLs
+
+! this is a copy of firewall21 except with different version
+
+! v6.3, outbound ACLs are not supported
+
+
+
+!
+! Prolog script:
+!
+no sysopt connection timewait
+no sysopt security fragguard
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+!
+! End of prolog script:
+!
+
+
+
+
+nameif eth0 outside security0
+
+nameif eth1 dmz security50
+
+nameif eth2 inside security100
+
+
+no logging buffered
+no logging console
+no logging timestamp
+no logging on
+
+
+timeout xlate 3:0:0
+timeout conn 1:0:0
+timeout udp 0:2:0
+timeout rpc 0:10:0
+timeout h323 0:5:0
+timeout sip 0:30:0
+timeout sip_media 0:2:0
+timeout half-closed 0:0:0
+timeout uauth 2:0:0 absolute
+
+telnet timeout 5
+
+clear ssh
+aaa authentication ssh console LOCAL
+ssh timeout 5
+
+no snmp-server enable traps
+
+
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+floodguard enable
+
+
+fixup protocol ftp 21
+
+
+!################
+!
+! Rule 0 (global)
+access-list outside_acl_in permit ip any host 192.168.1.10
+access-list dmz_acl_in permit ip any host 192.168.1.10
+access-list inside_acl_in permit ip any host 192.168.1.10
+!
+! Rule 1 (global)
+access-list outside_acl_in permit ip any host 192.168.1.10
+access-list dmz_acl_in permit ip any host 192.168.1.10
+access-list inside_acl_in permit ip any host 192.168.1.10
+!
+! Rule 2 (global)
+access-list outside_acl_in permit ip any host 192.168.1.10
+access-list dmz_acl_in permit ip any host 192.168.1.10
+access-list inside_acl_in permit ip any host 192.168.1.10
+!
+! Rule 3 (global)
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 4 (global)
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 5 (global)
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 6 (global)
+access-list dmz_acl_in permit ip 192.168.2.0 255.255.255.0 any
+!
+! Rule 7 (global)
+access-list dmz_acl_in permit ip 192.168.2.0 255.255.255.0 any
+!
+! Rule 8 (global)
+access-list dmz_acl_in permit ip 192.168.2.0 255.255.255.0 any
+!
+! Rule 9 (global)
+access-list dmz_acl_in permit ip 192.168.2.0 255.255.255.0 host 192.168.1.10
+!
+! Rule 10 (global)
+access-list dmz_acl_in permit ip 192.168.2.0 255.255.255.0 host 192.168.1.10
+!
+! Rule 11 (global)
+access-list dmz_acl_in permit ip 192.168.2.0 255.255.255.0 host 192.168.1.10
+!
+! Rule 12 (eth1)
+! dmz -> intnet
+access-list dmz_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 13 (eth1)
+! dmz -> intnet
+access-list dmz_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 15 (eth2)
+! dmz -> intnet
+access-list inside_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+access-list dmz_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 16 (eth2)
+! dmz -> intnet
+access-list inside_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 17 (eth2)
+! dmz -> intnet
+access-list dmz_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 18 (eth1,eth2)
+! dmz -> intnet
+access-list dmz_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+access-list inside_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+access-list dmz_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 19 (eth0,eth1)
+access-list outside_acl_in deny ip host 10.5.70.20 any log 0 interval 300
+access-list outside_acl_in deny ip host 192.168.2.20 any log 0 interval 300
+access-list outside_acl_in deny ip host 192.168.1.20 any log 0 interval 300
+access-list outside_acl_in deny ip 192.168.1.0 255.255.255.0 any log 0 interval 300
+access-list dmz_acl_in deny ip host 10.5.70.20 any log 0 interval 300
+access-list dmz_acl_in deny ip host 192.168.2.20 any log 0 interval 300
+access-list dmz_acl_in deny ip host 192.168.1.20 any log 0 interval 300
+access-list dmz_acl_in deny ip 192.168.1.0 255.255.255.0 any log 0 interval 300
+!
+! Rule 20 (eth0,eth1)
+access-list dmz_acl_in permit ip 192.168.2.0 255.255.255.0 any
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 21 (global)
+access-list outside_acl_in deny ip any any
+access-list dmz_acl_in deny ip any any
+access-list inside_acl_in deny ip any any
+
+
+access-group dmz_acl_in in interface dmz
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+!
+! Rule 0 (NAT)
+global (outside) 1 interface
+access-list id4529FE6016799.0 permit ip 192.168.1.0 255.255.255.0 any
+nat (inside) 1 access-list id4529FE6016799.0 0 0
+!
+! Rule 1 (NAT)
+access-list id4529FE6E16799.0 permit ip 192.168.2.0 255.255.255.0 any
+nat (dmz) 1 access-list id4529FE6E16799.0 0 0
+!
+! Rule 2 (NAT)
+access-list id4529FE7C16799.0 permit ip host 192.168.2.100 any
+static (dmz,outside) interface access-list id4529FE7C16799.0 0 0
+!
+! Rule 3 (NAT)
+global (inside) 3 interface
+access-list id4529FE8A16799.0 permit ip 192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0
+nat (dmz) 3 access-list id4529FE8A16799.0 outside
+!
+! Rule 4 (NAT)
+global (dmz) 4 interface
+access-list id4529FE9816799.0 permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
+nat (inside) 4 access-list id4529FE9816799.0 0 0
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall21.fw.orig b/test/pix/firewall21.fw.orig
new file mode 100755
index 000000000..702fb4306
--- /dev/null
+++ b/test/pix/firewall21.fw.orig
@@ -0,0 +1,225 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:10 2011 PST by vadim
+!
+! Compiled for pix 7.0
+! Outbound ACLs: supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: no
+!
+!# files: * firewall21.fw
+!
+! testing outbound ACLs
+
+! v7.0, outbound ACLs are supported
+
+! option 'generate outbound acls' is OFF
+
+
+
+!
+! Prolog script:
+!
+no sysopt connection timewait
+no sysopt security fragguard
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+!
+! End of prolog script:
+!
+
+
+
+
+interface eth0
+ nameif outside
+ security-level 0
+exit
+
+interface eth1
+ nameif dmz
+ security-level 50
+exit
+
+interface eth2
+ nameif inside
+ security-level 100
+exit
+
+
+no logging buffered
+no logging console
+no logging timestamp
+no logging on
+
+
+timeout xlate 3:0:0
+timeout conn 1:0:0
+timeout udp 0:2:0
+timeout sunrpc 0:10:0
+timeout h323 0:5:0
+timeout sip 0:30:0
+timeout sip_media 0:2:0
+timeout half-closed 0:0:0
+timeout uauth 2:0:0 absolute
+
+telnet timeout 5
+
+clear config ssh
+aaa authentication ssh console LOCAL
+ssh timeout 5
+
+no snmp-server enable traps
+
+
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+
+
+class-map inspection_default
+ match default-inspection-traffic
+
+policy-map global_policy
+ class inspection_default
+ inspect ftp
+
+service-policy global_policy global
+
+
+!################
+!
+! Rule 0 (global)
+access-list outside_acl_in permit ip any host 192.168.1.10
+access-list dmz_acl_in permit ip any host 192.168.1.10
+access-list inside_acl_in permit ip any host 192.168.1.10
+!
+! Rule 1 (global)
+access-list outside_acl_in permit ip any host 192.168.1.10
+access-list dmz_acl_in permit ip any host 192.168.1.10
+access-list inside_acl_in permit ip any host 192.168.1.10
+!
+! Rule 2 (global)
+access-list outside_acl_in permit ip any host 192.168.1.10
+access-list dmz_acl_in permit ip any host 192.168.1.10
+access-list inside_acl_in permit ip any host 192.168.1.10
+!
+! Rule 3 (global)
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 4 (global)
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 5 (global)
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 6 (global)
+access-list dmz_acl_in permit ip 192.168.2.0 255.255.255.0 any
+!
+! Rule 7 (global)
+access-list dmz_acl_in permit ip 192.168.2.0 255.255.255.0 any
+!
+! Rule 8 (global)
+access-list dmz_acl_in permit ip 192.168.2.0 255.255.255.0 any
+!
+! Rule 9 (global)
+access-list dmz_acl_in permit ip 192.168.2.0 255.255.255.0 host 192.168.1.10
+!
+! Rule 10 (global)
+access-list dmz_acl_in permit ip 192.168.2.0 255.255.255.0 host 192.168.1.10
+!
+! Rule 11 (global)
+access-list dmz_acl_in permit ip 192.168.2.0 255.255.255.0 host 192.168.1.10
+!
+! Rule 12 (eth1)
+! dmz -> intnet
+access-list dmz_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 13 (eth1)
+! dmz -> intnet
+access-list dmz_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 15 (eth2)
+! dmz -> intnet
+access-list inside_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+access-list dmz_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 16 (eth2)
+! dmz -> intnet
+access-list inside_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 17 (eth2)
+! dmz -> intnet
+access-list dmz_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 18 (eth1,eth2)
+! dmz -> intnet
+access-list dmz_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+access-list inside_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+access-list dmz_acl_in permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 19 (eth0,eth1)
+access-list outside_acl_in deny ip host 10.5.70.20 any log 0 interval 300
+access-list outside_acl_in deny ip host 192.168.2.20 any log 0 interval 300
+access-list outside_acl_in deny ip host 192.168.1.20 any log 0 interval 300
+access-list outside_acl_in deny ip 192.168.1.0 255.255.255.0 any log 0 interval 300
+access-list dmz_acl_in deny ip host 10.5.70.20 any log 0 interval 300
+access-list dmz_acl_in deny ip host 192.168.2.20 any log 0 interval 300
+access-list dmz_acl_in deny ip host 192.168.1.20 any log 0 interval 300
+access-list dmz_acl_in deny ip 192.168.1.0 255.255.255.0 any log 0 interval 300
+!
+! Rule 20 (eth0,eth1)
+access-list dmz_acl_in permit ip 192.168.2.0 255.255.255.0 any
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 21 (global)
+access-list outside_acl_in deny ip any any
+access-list dmz_acl_in deny ip any any
+access-list inside_acl_in deny ip any any
+
+
+access-group dmz_acl_in in interface dmz
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+!
+! Rule 0 (NAT)
+global (outside) 1 interface
+access-list id45293EF520039.0 permit ip 192.168.1.0 255.255.255.0 any
+nat (inside) 1 access-list id45293EF520039.0 tcp 0 0
+!
+! Rule 1 (NAT)
+access-list id45293F0320039.0 permit ip 192.168.2.0 255.255.255.0 any
+nat (dmz) 1 access-list id45293F0320039.0 tcp 0 0
+!
+! Rule 2 (NAT)
+access-list id45293F1120039.0 permit ip host 192.168.2.100 any
+static (dmz,outside) interface access-list id45293F1120039.0 tcp 0 0
+!
+! Rule 3 (NAT)
+global (inside) 3 interface
+access-list id45293F1F20039.0 permit ip 192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0
+nat (dmz) 3 access-list id45293F1F20039.0 outside
+!
+! Rule 4 (NAT)
+global (dmz) 4 interface
+access-list id45293F2D20039.0 permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
+nat (inside) 4 access-list id45293F2D20039.0 tcp 0 0
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall22.fw.orig b/test/pix/firewall22.fw.orig
new file mode 100755
index 000000000..273dc8940
--- /dev/null
+++ b/test/pix/firewall22.fw.orig
@@ -0,0 +1,258 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:11 2011 PST by vadim
+!
+! Compiled for pix 7.0
+! Outbound ACLs: supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: yes
+! Assume firewall is part of any: no
+!
+!# files: * firewall22.fw
+!
+! testing outbound ACLs
+! v7.0, outbound ACLs are supported
+! option 'generate outbound acls' is ON
+
+
+
+!
+! Prolog script:
+!
+no sysopt connection timewait
+no sysopt security fragguard
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+!
+! End of prolog script:
+!
+
+
+
+
+interface eth0
+ nameif outside
+ security-level 0
+exit
+
+interface eth1
+ nameif dmz
+ security-level 50
+exit
+
+interface eth2
+ nameif inside
+ security-level 100
+exit
+
+
+no logging buffered
+no logging console
+no logging timestamp
+no logging on
+
+
+timeout xlate 3:0:0
+timeout conn 1:0:0
+timeout udp 0:2:0
+timeout sunrpc 0:10:0
+timeout h323 0:5:0
+timeout sip 0:30:0
+timeout sip_media 0:2:0
+timeout half-closed 0:0:0
+timeout uauth 2:0:0 absolute
+
+telnet timeout 5
+
+clear config ssh
+aaa authentication ssh console LOCAL
+ssh timeout 5
+
+no snmp-server enable traps
+
+
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+
+
+class-map inspection_default
+ match default-inspection-traffic
+
+policy-map global_policy
+ class inspection_default
+ inspect ftp
+
+service-policy global_policy global
+
+
+!################
+!
+! Rule 0 (global)
+access-list outside_in permit ip any host 192.168.1.10
+access-list dmz_in permit ip any host 192.168.1.10
+access-list inside_in permit ip any host 192.168.1.10
+access-list inside_out permit ip any host 192.168.1.10
+!
+! Rule 1 (global)
+access-list outside_in permit ip any host 192.168.1.10
+access-list dmz_in permit ip any host 192.168.1.10
+access-list inside_in permit ip any host 192.168.1.10
+!
+! Rule 2 (global)
+access-list outside_out permit ip any host 192.168.1.10
+access-list dmz_out permit ip any host 192.168.1.10
+access-list inside_out permit ip any host 192.168.1.10
+!
+! Rule 3 (global)
+access-list inside_in permit ip 192.168.1.0 255.255.255.0 any
+access-list outside_out permit ip 192.168.1.0 255.255.255.0 any
+access-list dmz_out permit ip 192.168.1.0 255.255.255.0 any
+access-list inside_out permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 4 (global)
+access-list outside_in permit ip 192.168.1.0 255.255.255.0 any
+access-list dmz_in permit ip 192.168.1.0 255.255.255.0 any
+access-list inside_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 5 (global)
+access-list outside_out permit ip 192.168.1.0 255.255.255.0 any
+access-list dmz_out permit ip 192.168.1.0 255.255.255.0 any
+access-list inside_out permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 6 (global)
+access-list dmz_in permit ip 192.168.2.0 255.255.255.0 any
+access-list outside_out permit ip 192.168.2.0 255.255.255.0 any
+access-list dmz_out permit ip 192.168.2.0 255.255.255.0 any
+access-list inside_out permit ip 192.168.2.0 255.255.255.0 any
+!
+! Rule 7 (global)
+access-list outside_in permit ip 192.168.2.0 255.255.255.0 any
+access-list dmz_in permit ip 192.168.2.0 255.255.255.0 any
+access-list inside_in permit ip 192.168.2.0 255.255.255.0 any
+!
+! Rule 8 (global)
+access-list outside_out permit ip 192.168.2.0 255.255.255.0 any
+access-list dmz_out permit ip 192.168.2.0 255.255.255.0 any
+access-list inside_out permit ip 192.168.2.0 255.255.255.0 any
+!
+! Rule 9 (global)
+access-list dmz_in permit ip 192.168.2.0 255.255.255.0 host 192.168.1.10
+access-list inside_out permit ip 192.168.2.0 255.255.255.0 host 192.168.1.10
+!
+! Rule 10 (global)
+access-list outside_in permit ip 192.168.2.0 255.255.255.0 host 192.168.1.10
+access-list dmz_in permit ip 192.168.2.0 255.255.255.0 host 192.168.1.10
+access-list inside_in permit ip 192.168.2.0 255.255.255.0 host 192.168.1.10
+!
+! Rule 11 (global)
+access-list outside_out permit ip 192.168.2.0 255.255.255.0 host 192.168.1.10
+access-list dmz_out permit ip 192.168.2.0 255.255.255.0 host 192.168.1.10
+access-list inside_out permit ip 192.168.2.0 255.255.255.0 host 192.168.1.10
+!
+! Rule 12 (eth1)
+! dmz -> intnet
+access-list dmz_in permit ip host 192.168.2.23 host 192.168.1.10
+access-list dmz_out permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 13 (eth1)
+! dmz -> intnet
+access-list dmz_in permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 14 (eth1)
+! dmz -> intnet
+access-list dmz_out permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 15 (eth2)
+! dmz -> intnet
+access-list inside_in permit ip host 192.168.2.23 host 192.168.1.10
+access-list inside_out permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 16 (eth2)
+! dmz -> intnet
+access-list inside_in permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 17 (eth2)
+! dmz -> intnet
+access-list inside_out permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 18 (eth1,eth2)
+! dmz -> intnet
+access-list dmz_in permit ip host 192.168.2.23 host 192.168.1.10
+access-list dmz_out permit ip host 192.168.2.23 host 192.168.1.10
+access-list inside_in permit ip host 192.168.2.23 host 192.168.1.10
+access-list inside_out permit ip host 192.168.2.23 host 192.168.1.10
+!
+! Rule 19 (eth0,eth1)
+access-list outside_in deny ip host 10.5.70.20 any log 0 interval 300
+access-list outside_in deny ip host 192.168.2.20 any log 0 interval 300
+access-list outside_in deny ip host 192.168.1.20 any log 0 interval 300
+access-list outside_in deny ip 192.168.1.0 255.255.255.0 any log 0 interval 300
+access-list dmz_in deny ip host 10.5.70.20 any log 0 interval 300
+access-list dmz_in deny ip host 192.168.2.20 any log 0 interval 300
+access-list dmz_in deny ip host 192.168.1.20 any log 0 interval 300
+access-list dmz_in deny ip 192.168.1.0 255.255.255.0 any log 0 interval 300
+!
+! Rule 20 (eth0,eth1)
+access-list outside_out permit ip host 10.5.70.20 any
+access-list outside_out permit ip 192.168.2.0 255.255.255.0 any
+access-list outside_out permit ip 192.168.1.0 255.255.255.0 any
+access-list dmz_out permit ip host 192.168.2.20 any
+access-list dmz_out permit ip 192.168.2.0 255.255.255.0 any
+access-list dmz_out permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 21 (global)
+access-list outside_in deny ip any any
+access-list dmz_in deny ip any any
+access-list inside_in deny ip any any
+access-list outside_out deny ip any any
+access-list dmz_out deny ip any any
+access-list inside_out deny ip any any
+
+
+access-group dmz_in in interface dmz
+access-group dmz_out out interface dmz
+access-group inside_in in interface inside
+access-group inside_out out interface inside
+access-group outside_in in interface outside
+access-group outside_out out interface outside
+
+!
+! Rule 0 (NAT)
+global (outside) 1 interface
+access-list id4529E45516799.0 permit ip 192.168.1.0 255.255.255.0 any
+nat (inside) 1 access-list id4529E45516799.0 tcp 0 0
+!
+! Rule 1 (NAT)
+access-list id4529E46316799.0 permit ip 192.168.2.0 255.255.255.0 any
+nat (dmz) 1 access-list id4529E46316799.0 tcp 0 0
+!
+! Rule 2 (NAT)
+access-list id4529E47116799.0 permit ip host 192.168.2.100 any
+static (dmz,outside) interface access-list id4529E47116799.0 tcp 0 0
+!
+! Rule 3 (NAT)
+global (inside) 3 interface
+access-list id4529E47F16799.0 permit ip 192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0
+nat (dmz) 3 access-list id4529E47F16799.0 outside
+!
+! Rule 4 (NAT)
+global (dmz) 4 interface
+access-list id4529E48D16799.0 permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
+nat (inside) 4 access-list id4529E48D16799.0 tcp 0 0
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall3.fw.orig b/test/pix/firewall3.fw.orig
new file mode 100755
index 000000000..6f71a1c91
--- /dev/null
+++ b/test/pix/firewall3.fw.orig
@@ -0,0 +1,170 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:11 2011 PST by vadim
+!
+! Compiled for pix 6.2
+! Outbound ACLs: not supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: yes
+!
+!# files: * firewall3.fw
+!
+! testing icmp and ssh/telnet commands
+
+
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+nameif eth0 inside security100
+
+nameif eth1 outside security0
+
+nameif eth2 dmz security50
+
+
+no logging buffered
+no logging console
+no logging timestamp
+no logging on
+
+
+timeout xlate 3:0:0
+timeout conn 1:0:0
+timeout udp 0:2:0
+timeout rpc 0:10:0
+timeout h323 0:5:0
+timeout sip 0:30:0
+timeout sip_media 0:0:0
+timeout uauth 2:0:0 absolute
+
+telnet timeout 5
+
+clear ssh
+aaa authentication ssh console LOCAL
+ssh timeout 5
+
+clear snmp-server
+no snmp-server enable traps
+
+clear ntp
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt security fragguard
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+no sysopt route dnat
+floodguard disable
+
+
+!################
+clear access-list
+clear object-group
+clear icmp
+clear telnet
+!
+! Rule 0 (eth0)
+ssh 0.0.0.0 0.0.0.0 inside
+access-list inside_acl_in permit tcp any any eq 22
+!
+! Rule 1 (eth0)
+ssh 0.0.0.0 0.0.0.0 inside
+!
+! Rule 2 (eth0)
+icmp permit any 3 inside
+access-list inside_acl_in permit icmp any host 192.168.1.1 3
+access-list inside_acl_in permit icmp any any 3
+!
+! Rule 3 (eth0)
+access-list inside_acl_in permit icmp any host 192.168.1.1 3
+!
+! Rule 4 (eth1)
+ssh 0.0.0.0 0.0.0.0 outside
+access-list outside_acl_in permit tcp any any eq 22
+!
+! Rule 5 (eth1)
+ssh 0.0.0.0 0.0.0.0 outside
+!
+! Rule 6 (eth1)
+icmp permit any 3 outside
+access-list outside_acl_in permit icmp any host 22.22.22.22 3
+access-list outside_acl_in permit icmp any any 3
+!
+! Rule 7 (eth1)
+access-list outside_acl_in permit icmp any host 22.22.22.22 3
+!
+! Rule 8 (global)
+access-list inside_acl_in permit icmp any host 192.168.1.1 3
+access-list outside_acl_in permit icmp any host 22.22.22.22 3
+icmp permit any 3 dmz
+access-list dmz_acl_in permit icmp any host 192.168.2.1 3
+access-list inside_acl_in permit icmp any any 3
+access-list outside_acl_in permit icmp any any 3
+access-list dmz_acl_in permit icmp any any 3
+!
+! Rule 9 (global)
+access-list inside_acl_in permit icmp any host 192.168.1.1 3
+access-list outside_acl_in permit icmp any host 22.22.22.22 3
+access-list dmz_acl_in permit icmp any host 192.168.2.1 3
+!
+! Rule 10 (global)
+ssh 0.0.0.0 0.0.0.0 inside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 dmz
+access-list inside_acl_in permit tcp any any eq 22
+access-list outside_acl_in permit tcp any any eq 22
+access-list dmz_acl_in permit tcp any any eq 22
+!
+! Rule 11 (global)
+ssh 0.0.0.0 0.0.0.0 inside
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 dmz
+!
+! Rule 12 (global)
+telnet 0.0.0.0 0.0.0.0 inside
+telnet 0.0.0.0 0.0.0.0 outside
+telnet 0.0.0.0 0.0.0.0 dmz
+access-list inside_acl_in permit tcp any any eq 23
+access-list outside_acl_in permit tcp any any eq 23
+access-list dmz_acl_in permit tcp any any eq 23
+!
+! Rule 13 (global)
+telnet 0.0.0.0 0.0.0.0 inside
+telnet 0.0.0.0 0.0.0.0 outside
+telnet 0.0.0.0 0.0.0.0 dmz
+!
+! Rule 14 (global)
+access-list inside_acl_in deny ip any any
+access-list outside_acl_in deny ip any any
+access-list dmz_acl_in deny ip any any
+
+
+access-group dmz_acl_in in interface dmz
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall33.fw.orig b/test/pix/firewall33.fw.orig
new file mode 100755
index 000000000..d556e6239
--- /dev/null
+++ b/test/pix/firewall33.fw.orig
@@ -0,0 +1,144 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:12 2011 PST by vadim
+!
+! Compiled for pix 6.3
+! Outbound ACLs: not supported
+! Emulate outbound ACLs: no
+! Generating outbound ACLs: no
+! Assume firewall is part of any: no
+!
+!# files: * firewall33.fw
+!
+! testing DNSName object
+
+! C firewall33:Policy:3: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+! C firewall33:Policy:7: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+! C firewall33:Policy:7: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+nameif eth0.100 outside security0
+
+nameif eth1 inside security100
+
+
+no logging buffered
+no logging console
+no logging timestamp
+no logging on
+
+
+
+telnet timeout -1
+
+clear ssh
+aaa authentication ssh console LOCAL
+ssh timeout -1
+
+no snmp-server enable traps
+
+
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+floodguard disable
+
+
+!################
+
+object-group network outside.id43867C2418346.src.net.0
+ network-object host 157.166.224.25
+ network-object host 157.166.224.26
+ network-object host 157.166.226.25
+ network-object host 157.166.226.26
+ network-object host 157.166.255.18
+ network-object host 157.166.255.19
+ exit
+
+
+object-group network outside.id438728A918346.dst.net.0
+ network-object host 74.125.19.99
+ network-object host 74.125.19.103
+ network-object host 74.125.19.104
+ network-object host 74.125.19.147
+ network-object host 157.166.224.25
+ network-object host 157.166.224.26
+ network-object host 157.166.226.25
+ network-object host 157.166.226.26
+ network-object host 157.166.255.18
+ network-object host 157.166.255.19
+ exit
+
+!
+! Rule 0 (eth0.100)
+access-list outside_acl_in deny ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 1 (global)
+access-list outside_acl_in permit ip object-group outside.id43867C2418346.src.net.0 any
+!
+! Rule 3 (global)
+! firewall33:Policy:3: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+access-list outside_acl_in permit ip host 192.0.2.1 any
+!
+! Rule 5 (global)
+access-list outside_acl_in deny ip any object-group outside.id43867C2418346.src.net.0
+access-list inside_acl_in deny ip any object-group outside.id43867C2418346.src.net.0
+!
+! Rule 7 (global)
+! firewall33:Policy:7: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+access-list outside_acl_in permit ip any host 192.0.2.1
+! firewall33:Policy:7: error: DNSName object "buildmaster (ct)" (compile time) can not resolve dns name "buildmaster" (AF_INET): Host or network 'buildmaster' not found; last error: Unknown error Using dummy address in test mode
+access-list inside_acl_in permit ip any host 192.0.2.1
+!
+! Rule 9 (global)
+access-list outside_acl_in permit ip any object-group outside.id438728A918346.dst.net.0
+access-list inside_acl_in permit ip any object-group outside.id438728A918346.dst.net.0
+!
+! Rule 11 (global)
+access-list outside_acl_in deny ip any any
+access-list inside_acl_in deny ip any any
+
+
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+!
+! Rule 0 (NAT)
+access-list id43867C4918346.0 permit ip host 192.168.1.10 any
+static (inside,outside) interface access-list id43867C4918346.0 0 0
+!
+! Rule 1 (NAT)
+global (outside) 1 interface
+access-list id43876E2618346.0 permit ip any host 157.166.224.25
+access-list id43876E2618346.0 permit ip any host 157.166.224.26
+access-list id43876E2618346.0 permit ip any host 157.166.226.25
+access-list id43876E2618346.0 permit ip any host 157.166.226.26
+access-list id43876E2618346.0 permit ip any host 157.166.255.18
+access-list id43876E2618346.0 permit ip any host 157.166.255.19
+nat (outside) 1 access-list id43876E2618346.0 0 0
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall34.fw.orig b/test/pix/firewall34.fw.orig
new file mode 100755
index 000000000..0f69d85fd
--- /dev/null
+++ b/test/pix/firewall34.fw.orig
@@ -0,0 +1,240 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:13 2011 PST by vadim
+!
+! Compiled for pix 6.3
+! Outbound ACLs: not supported
+! Emulate outbound ACLs: no
+! Generating outbound ACLs: no
+! Assume firewall is part of any: no
+!
+!# files: * firewall34.fw
+!
+! testing AddressTable object
+
+! C firewall34:Policy:1: error: File not found for Address Table: missing table (file_does_not_exist.tbl) Using dummy address in test mode
+! C firewall34:Policy:1: error: File not found for Address Table: missing table (file_does_not_exist.tbl) Using dummy address in test mode
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+nameif eth0.100 outside security0
+
+nameif eth1 inside security100
+
+
+no logging buffered
+no logging console
+no logging timestamp
+no logging on
+
+
+
+telnet timeout -1
+
+clear ssh
+aaa authentication ssh console LOCAL
+ssh timeout -1
+
+no snmp-server enable traps
+
+
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+floodguard disable
+
+
+!################
+
+object-group network outside.id16988X10208.dst.net.0
+ network-object 192.168.1.1 255.255.255.255
+ network-object 192.168.1.2 255.255.255.255
+ network-object 192.168.1.3 255.255.255.252
+ network-object 192.168.1.200 255.255.255.255
+ network-object 192.168.1.201 255.255.255.255
+ exit
+
+
+object-group network outside.id4390C25825682.dst.net.0
+ network-object 58.33.181.83 255.255.255.255
+ network-object 58.53.82.190 255.255.255.255
+ network-object 58.231.13.78 255.255.255.255
+ network-object host 61.150.47.112
+ network-object 61.150.47.112 255.255.255.255
+ network-object 61.184.14.102 255.255.255.255
+ network-object 64.106.85.186 255.255.255.255
+ network-object 70.228.60.100 255.255.255.255
+ network-object 80.51.236.6 255.255.255.255
+ network-object 80.243.72.149 255.255.255.255
+ network-object 80.249.77.34 255.255.255.255
+ network-object 81.2.36.254 255.255.255.255
+ network-object 81.196.74.125 255.255.255.255
+ network-object 82.77.37.174 255.255.255.255
+ network-object 82.117.221.205 255.255.255.255
+ network-object 82.143.196.17 255.255.255.255
+ network-object 84.90.8.198 255.255.255.255
+ network-object 151.8.224.178 255.255.255.255
+ network-object 168.156.76.20 255.255.255.255
+ network-object 193.207.126.36 255.255.255.255
+ network-object 195.136.186.35 255.255.255.255
+ network-object 196.15.136.15 255.255.255.255
+ network-object 201.10.180.138 255.255.255.255
+ network-object 201.17.93.16 255.255.255.255
+ network-object 201.36.156.121 255.255.255.255
+ network-object 202.96.112.93 255.255.255.255
+ network-object 202.103.25.253 255.255.255.255
+ network-object 203.162.3.209 255.255.255.255
+ network-object 203.209.124.144 255.255.255.255
+ network-object 210.106.193.237 255.255.255.255
+ network-object 210.222.114.102 255.255.255.255
+ network-object 211.144.143.143 255.255.255.255
+ network-object 211.172.218.237 255.255.255.255
+ network-object 211.250.16.132 255.255.255.255
+ network-object 212.21.241.31 255.255.255.255
+ network-object 212.100.212.100 255.255.255.255
+ network-object 218.18.72.252 255.255.255.255
+ network-object 218.39.114.122 255.255.255.255
+ network-object 218.55.115.43 255.255.255.255
+ network-object 218.104.138.146 255.255.255.255
+ network-object 219.132.104.160 255.255.255.255
+ network-object 220.71.17.86 255.255.255.255
+ network-object 220.81.50.105 255.255.255.255
+ network-object 220.91.99.46 255.255.255.255
+ network-object 221.14.249.242 255.255.255.255
+ network-object 221.166.177.135 255.255.255.255
+ network-object 221.198.33.38 255.255.255.255
+ network-object 221.202.160.233 255.255.255.255
+ network-object 221.205.54.125 255.255.255.255
+ network-object 221.217.44.248 255.255.255.255
+ network-object 222.100.212.223 255.255.255.255
+ network-object 222.121.118.144 255.255.255.255
+ network-object 222.174.113.2 255.255.255.255
+ exit
+
+
+object-group network outside.id4388CFF8674.src.net.0
+ network-object 58.33.181.83 255.255.255.255
+ network-object 58.53.82.190 255.255.255.255
+ network-object 58.231.13.78 255.255.255.255
+ network-object 61.150.47.112 255.255.255.255
+ network-object 61.184.14.102 255.255.255.255
+ network-object 64.106.85.186 255.255.255.255
+ network-object 70.228.60.100 255.255.255.255
+ network-object 80.51.236.6 255.255.255.255
+ network-object 80.243.72.149 255.255.255.255
+ network-object 80.249.77.34 255.255.255.255
+ network-object 81.2.36.254 255.255.255.255
+ network-object 81.196.74.125 255.255.255.255
+ network-object 82.77.37.174 255.255.255.255
+ network-object 82.117.221.205 255.255.255.255
+ network-object 82.143.196.17 255.255.255.255
+ network-object 84.90.8.198 255.255.255.255
+ network-object 151.8.224.178 255.255.255.255
+ network-object 168.156.76.20 255.255.255.255
+ network-object 193.207.126.36 255.255.255.255
+ network-object 195.136.186.35 255.255.255.255
+ network-object 196.15.136.15 255.255.255.255
+ network-object 201.10.180.138 255.255.255.255
+ network-object 201.17.93.16 255.255.255.255
+ network-object 201.36.156.121 255.255.255.255
+ network-object 202.96.112.93 255.255.255.255
+ network-object 202.103.25.253 255.255.255.255
+ network-object 203.162.3.209 255.255.255.255
+ network-object 203.209.124.144 255.255.255.255
+ network-object 210.106.193.237 255.255.255.255
+ network-object 210.222.114.102 255.255.255.255
+ network-object 211.144.143.143 255.255.255.255
+ network-object 211.172.218.237 255.255.255.255
+ network-object 211.250.16.132 255.255.255.255
+ network-object 212.21.241.31 255.255.255.255
+ network-object 212.100.212.100 255.255.255.255
+ network-object 218.18.72.252 255.255.255.255
+ network-object 218.39.114.122 255.255.255.255
+ network-object 218.55.115.43 255.255.255.255
+ network-object 218.104.138.146 255.255.255.255
+ network-object 219.132.104.160 255.255.255.255
+ network-object 220.71.17.86 255.255.255.255
+ network-object 220.81.50.105 255.255.255.255
+ network-object 220.91.99.46 255.255.255.255
+ network-object 221.14.249.242 255.255.255.255
+ network-object 221.166.177.135 255.255.255.255
+ network-object 221.198.33.38 255.255.255.255
+ network-object 221.202.160.233 255.255.255.255
+ network-object 221.205.54.125 255.255.255.255
+ network-object 221.217.44.248 255.255.255.255
+ network-object 222.100.212.223 255.255.255.255
+ network-object 222.121.118.144 255.255.255.255
+ network-object 222.174.113.2 255.255.255.255
+ exit
+
+!
+! Rule 0 (global)
+access-list outside_acl_in permit ip any 192.168.2.128 255.255.255.128
+access-list inside_acl_in permit ip any 192.168.2.128 255.255.255.128
+access-list outside_acl_in permit ip any object-group outside.id16988X10208.dst.net.0
+access-list inside_acl_in permit ip any object-group outside.id16988X10208.dst.net.0
+!
+! Rule 1 (global)
+! firewall34:Policy:1: error: File not found for Address Table: missing table (file_does_not_exist.tbl) Using dummy address in test mode
+access-list outside_acl_in permit ip any 192.0.2.0 255.255.255.0
+! firewall34:Policy:1: error: File not found for Address Table: missing table (file_does_not_exist.tbl) Using dummy address in test mode
+access-list inside_acl_in permit ip any 192.0.2.0 255.255.255.0
+!
+! Rule 2 (global)
+access-list outside_acl_in deny ip any object-group outside.id4390C25825682.dst.net.0
+access-list inside_acl_in deny ip any object-group outside.id4390C25825682.dst.net.0
+!
+! Rule 3 (global)
+access-list outside_acl_in deny tcp any object-group outside.id4390C25825682.dst.net.0 eq 25
+access-list inside_acl_in deny tcp any object-group outside.id4390C25825682.dst.net.0 eq 25
+!
+! Rule 5 (global)
+access-list outside_acl_in deny ip object-group outside.id4388CFF8674.src.net.0 any
+!
+! Rule 6 (global)
+access-list outside_acl_in deny ip object-group outside.id4390C25825682.dst.net.0 any
+!
+! Rule 7 (global)
+access-list outside_acl_in permit ip object-group outside.id4390C25825682.dst.net.0 any
+!
+! Rule 9 (global)
+access-list outside_acl_in permit tcp any host 192.168.1.10 eq 25
+access-list inside_acl_in permit tcp any host 192.168.1.10 eq 25
+!
+! Rule 10 (global)
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 11 (global)
+access-list outside_acl_in deny ip any any
+access-list inside_acl_in deny ip any any
+
+
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall4.fw.orig b/test/pix/firewall4.fw.orig
new file mode 100755
index 000000000..35c66bec7
--- /dev/null
+++ b/test/pix/firewall4.fw.orig
@@ -0,0 +1,157 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:14 2011 PST by vadim
+!
+! Compiled for pix 6.2
+! Outbound ACLs: not supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: yes
+!
+!# files: * firewall4.fw
+!
+! this object is used to test "Replace NAT'ted objects with their translations" option
+
+
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+nameif eth0 inside security100
+
+nameif eth1 dmz1 security40
+
+nameif eth2 dmz2 security50
+
+nameif eth3 outside security0
+
+
+no logging buffered
+no logging console
+no logging timestamp
+no logging on
+
+
+timeout xlate 3:0:0
+timeout conn 1:0:0
+timeout udp 0:2:0
+timeout rpc 0:10:0
+timeout h323 0:5:0
+timeout sip 0:30:0
+timeout sip_media 0:0:0
+timeout uauth 2:0:0 absolute
+
+telnet timeout -1
+
+clear ssh
+aaa authentication ssh console LOCAL
+ssh timeout -1
+
+clear snmp-server
+no snmp-server enable traps
+
+clear ntp
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt security fragguard
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+no sysopt route dnat
+floodguard disable
+
+
+!################
+clear access-list
+clear object-group
+clear icmp
+clear telnet
+
+object-group service inside.id3D79A1C2.srv.tcp.0 tcp
+ port-object eq 22
+ port-object eq 80
+ exit
+
+
+object-group network inside.id3D79A1E4.dst.net.0
+ network-object host 192.168.1.10
+ network-object host 192.168.1.20
+ exit
+
+!
+! Rule 0 (global)
+access-list inside_acl_in permit tcp any host 192.168.1.10 eq 22
+access-list dmz1_acl_in permit tcp any host 192.168.1.10 eq 22
+access-list dmz2_acl_in permit tcp any host 192.168.2.1 eq 22
+access-list dmz2_acl_in permit tcp any host 192.168.1.10 eq 22
+access-list outside_acl_in permit tcp any host 222.222.222.222 eq 22
+access-list outside_acl_in permit tcp any host 192.168.1.10 eq 22
+!
+! Rule 1 (global)
+access-list inside_acl_in permit tcp any host 192.168.1.10 object-group inside.id3D79A1C2.srv.tcp.0
+access-list dmz1_acl_in permit tcp any host 192.168.1.10 object-group inside.id3D79A1C2.srv.tcp.0
+access-list dmz2_acl_in permit tcp any host 192.168.2.1 eq 22
+access-list dmz2_acl_in permit tcp any host 192.168.1.10 object-group inside.id3D79A1C2.srv.tcp.0
+access-list outside_acl_in permit tcp any host 222.222.222.222 eq 22
+access-list outside_acl_in permit tcp any host 192.168.1.10 object-group inside.id3D79A1C2.srv.tcp.0
+!
+! Rule 2 (global)
+access-list inside_acl_in permit tcp any object-group inside.id3D79A1E4.dst.net.0 eq 22
+access-list dmz1_acl_in permit tcp any object-group inside.id3D79A1E4.dst.net.0 eq 22
+access-list dmz2_acl_in permit tcp any host 192.168.2.1 eq 22
+access-list dmz2_acl_in permit tcp any object-group inside.id3D79A1E4.dst.net.0 eq 22
+access-list outside_acl_in permit tcp any host 222.222.222.222 eq 22
+access-list outside_acl_in permit tcp any object-group inside.id3D79A1E4.dst.net.0 eq 22
+!
+! Rule 3 (global)
+! 'masquerading' rule
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 4 (global)
+! 'catch all' rule
+access-list inside_acl_in deny ip any any
+access-list dmz1_acl_in deny ip any any
+access-list dmz2_acl_in deny ip any any
+access-list outside_acl_in deny ip any any
+
+
+access-group dmz1_acl_in in interface dmz1
+access-group dmz2_acl_in in interface dmz2
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+clear xlate
+clear static
+clear global
+clear nat
+!
+! Rule 0 (NAT)
+static (inside,outside) tcp interface 22 192.168.1.10 22 0 0
+!
+! Rule 1 (NAT)
+static (inside,dmz2) tcp interface 22 192.168.1.10 22 0 0
+!
+! Rule 2 (NAT)
+static (inside,dmz2) tcp interface 22 192.168.1.10 22 0 0
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall50.fw.orig b/test/pix/firewall50.fw.orig
new file mode 100755
index 000000000..378cd3036
--- /dev/null
+++ b/test/pix/firewall50.fw.orig
@@ -0,0 +1,475 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:15 2011 PST by vadim
+!
+! Compiled for pix 7.0
+! Outbound ACLs: supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: yes
+!
+!# files: * firewall50.fw
+!
+! this is simple firewall with two interfaces. Test regular policy rules, including IP_fragments rule. PIX 7.0
+
+! C firewall50:Policy:15: warning: MAC address matching is not supported. One or several MAC addresses removed from source in the rule
+! C firewall50:Policy:29: error: PIX does not support checking for IP options in ACLs.
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+hostname firewall50
+
+interface ethernet1
+ nameif outside
+ security-level 0
+exit
+
+interface ethernet0
+ nameif inside
+ security-level 100
+exit
+
+interface ethernet2
+ nameif dmz
+ security-level 50
+exit
+
+
+
+logging host inside 192.168.1.30
+logging queue 512
+logging facility 16
+logging trap 0
+no logging buffered
+no logging console
+no logging timestamp
+logging on
+
+
+timeout xlate 3:0:0
+timeout conn 1:0:0
+timeout udp 0:2:0
+timeout sunrpc 0:10:0
+timeout h323 0:5:0
+timeout sip 0:30:0
+timeout sip_media 0:0:0
+timeout half-closed 0:0:0
+timeout uauth 2:0:0 absolute
+
+telnet timeout 5
+
+clear config ssh
+aaa authentication ssh console LOCAL
+ssh timeout 5
+
+clear config snmp-server
+snmp-server community public
+snmp-server enable traps
+snmp-server host inside 192.168.1.20 poll
+snmp-server host inside 192.168.1.22 trap
+
+clear config ntp
+ntp server 192.168.1.20 source inside prefer
+
+
+no service resetinbound
+no service resetoutside
+sysopt connection tcpmss 1380
+sysopt connection timewait
+sysopt nodnsalias inbound
+sysopt nodnsalias outbound
+
+
+class-map inspection_default
+ match default-inspection-traffic
+
+policy-map global_policy
+ class inspection_default
+ inspect ftp
+ inspect h323 h225
+ inspect h323 ras
+ inspect http
+ inspect ils
+ inspect rsh
+ inspect rtsp
+ inspect sip
+ inspect skinny
+ inspect esmtp
+ inspect sqlnet
+
+service-policy global_policy global
+
+
+!################
+
+clear config access-list tmp_acl
+access-list tmp_acl permit ip 192.168.1.0 255.255.255.0 any
+access-list tmp_acl deny ip any any
+
+access-group tmp_acl in interface outside
+access-group tmp_acl in interface inside
+
+clear config access-list dmz_acl_in
+clear config access-list inside_acl_in
+clear config access-list outside_acl_in
+clear config object-group
+
+clear config icmp
+clear config telnet
+
+object-group network inside.id45142FA628543.dst.net.0
+ network-object host 211.11.11.11
+ network-object host 211.22.22.22
+ exit
+
+
+object-group service inside.id45142FA628543.srv.tcp.0 tcp
+ port-object eq 113
+ port-object eq 80
+ port-object eq 25
+ port-object eq 22
+ port-object eq 540
+ port-object eq 443
+ port-object eq 143
+ exit
+
+
+object-group icmp-type outside.id45142FCB28543.srv.icmp.0
+ icmp-object 11
+ icmp-object 0
+ icmp-object 3
+ exit
+
+
+object-group service outside.id45142FD728543.srv.tcp.0 tcp
+ port-object eq 3128
+ port-object eq 70
+ port-object eq 6667
+ port-object eq 23
+ exit
+
+
+object-group service outside.id45142FD728543.srv.udp.0 udp
+ port-object eq 161
+ port-object eq 53
+ exit
+
+
+object-group network outside.id45142FFC28543.dst.net.0
+ network-object host 192.168.1.10
+ network-object host 192.168.1.20
+ exit
+
+
+object-group network inside.id4514300A28543.dst.net.0
+ network-object 192.168.1.250 255.255.255.254
+ network-object 192.168.1.252 255.255.255.252
+ exit
+
+
+object-group network outside.id4514301628543.dst.net.0
+ network-object 192.168.1.250 255.255.255.254
+ network-object 192.168.1.252 255.255.255.252
+ exit
+
+
+object-group network outside.id4514302F28543.dst.net.0
+ network-object host 192.168.1.11
+ network-object host 192.168.1.12
+ network-object host 192.168.1.13
+ network-object host 192.168.1.14
+ network-object host 192.168.1.15
+ exit
+
+
+object-group service outside.id4514302F28543.srv.tcp.0 tcp
+ port-object eq 113
+ port-object eq 80
+ port-object eq 25
+ port-object eq 22
+ port-object eq 540
+ port-object eq 443
+ port-object eq 143
+ port-object eq 3128
+ exit
+
+
+object-group network outside.id4514303C28543.dst.net.0
+ network-object 192.168.1.11 255.255.255.255
+ network-object 192.168.1.12 255.255.255.252
+ exit
+
+
+object-group service outside.id4514304928543.srv.tcp.0 tcp
+ port-object eq 3128
+ port-object range 10000 11000
+ port-object eq 6667
+ port-object eq 113
+ port-object eq 53
+ port-object eq 21
+ port-object eq 80
+ port-object eq 119
+ port-object eq 25
+ port-object eq 22
+ port-object eq 23
+ port-object eq 540
+ port-object eq 70
+ port-object eq 13
+ port-object eq 2105
+ port-object eq 443
+ port-object eq 143
+ port-object eq 993
+ port-object eq 6667
+ port-object eq 543
+ port-object eq 544
+ port-object eq 389
+ port-object eq 98
+ port-object eq 3306
+ port-object eq 2049
+ port-object eq 110
+ port-object eq 5432
+ port-object eq 515
+ port-object eq 26000
+ port-object eq 512
+ port-object eq 513
+ port-object eq 514
+ port-object eq 4321
+ port-object eq 465
+ port-object eq 1080
+ port-object eq 111
+ port-object eq 7100
+ exit
+
+!
+! Rule 2 (ethernet1)
+icmp permit any 3 outside
+access-list outside_acl_in permit icmp any host 22.22.22.22 3
+access-list outside_acl_in permit icmp any any 3
+!
+! Rule 3 (ethernet1)
+! anti-spoofing rule
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any log 0 interval 300
+!
+! Rule 4 (ethernet0)
+ssh 192.168.1.0 255.255.255.0 inside
+!
+! Rule 5 (ethernet0)
+access-list inside_acl_in permit tcp any object-group inside.id45142FA628543.dst.net.0 object-group inside.id45142FA628543.srv.tcp.0
+access-list inside_acl_in permit tcp any object-group inside.id45142FA628543.dst.net.0 object-group inside.id45142FA628543.srv.tcp.0
+access-list dmz_acl_in permit tcp any object-group inside.id45142FA628543.dst.net.0 object-group inside.id45142FA628543.srv.tcp.0
+!
+! Rule 6 (ethernet0)
+access-list inside_acl_in deny ip any host 192.168.1.255
+!
+! Rule 8 (global)
+access-list dmz_acl_in permit tcp host 192.168.2.10 host 192.168.1.10 eq 22
+!
+! Rule 9 (ethernet2,ethernet0)
+access-list dmz_acl_in permit tcp host 192.168.2.10 host 192.168.1.10 eq 22
+access-list inside_acl_in permit tcp host 192.168.2.10 host 192.168.1.10 eq 22
+access-list dmz_acl_in permit tcp host 192.168.2.10 host 192.168.1.10 eq 22
+!
+! Rule 10 (global)
+access-list outside_acl_in permit icmp any host 192.168.1.10 object-group outside.id45142FCB28543.srv.icmp.0
+access-list inside_acl_in permit icmp any host 192.168.1.10 object-group outside.id45142FCB28543.srv.icmp.0
+access-list dmz_acl_in permit icmp any host 192.168.1.10 object-group outside.id45142FCB28543.srv.icmp.0
+!
+! Rule 11 (global)
+access-list outside_acl_in permit icmp any host 192.168.1.10
+access-list inside_acl_in permit icmp any host 192.168.1.10
+access-list dmz_acl_in permit icmp any host 192.168.1.10
+access-list outside_acl_in permit tcp any host 192.168.1.10 object-group outside.id45142FD728543.srv.tcp.0
+access-list inside_acl_in permit tcp any host 192.168.1.10 object-group outside.id45142FD728543.srv.tcp.0
+access-list dmz_acl_in permit tcp any host 192.168.1.10 object-group outside.id45142FD728543.srv.tcp.0
+access-list outside_acl_in permit udp any host 192.168.1.10 object-group outside.id45142FD728543.srv.udp.0
+access-list inside_acl_in permit udp any host 192.168.1.10 object-group outside.id45142FD728543.srv.udp.0
+access-list dmz_acl_in permit udp any host 192.168.1.10 object-group outside.id45142FD728543.srv.udp.0
+access-list outside_acl_in permit 47 any host 192.168.1.10
+access-list inside_acl_in permit 47 any host 192.168.1.10
+access-list dmz_acl_in permit 47 any host 192.168.1.10
+!
+! Rule 12 (global)
+access-list outside_acl_in permit icmp any host 22.22.22.22 3 log 0 interval 300
+icmp permit any 3 inside
+access-list inside_acl_in permit icmp any host 192.168.1.1 3 log 0 interval 300
+icmp permit any 3 dmz
+access-list dmz_acl_in permit icmp any host 192.168.2.1 3 log 0 interval 300
+access-list outside_acl_in permit icmp any any 3 log 0 interval 300
+access-list inside_acl_in permit icmp any any 3 log 0 interval 300
+access-list dmz_acl_in permit icmp any any 3 log 0 interval 300
+access-list outside_acl_in permit 47 any any log 0 interval 300
+access-list inside_acl_in permit 47 any any log 0 interval 300
+access-list dmz_acl_in permit 47 any any log 0 interval 300
+access-list outside_acl_in permit 50 any any log 0 interval 300
+access-list inside_acl_in permit 50 any any log 0 interval 300
+access-list dmz_acl_in permit 50 any any log 0 interval 300
+!
+! Rule 14 (global)
+access-list outside_acl_in permit ip object-group inside.id45142FA628543.dst.net.0 object-group outside.id45142FFC28543.dst.net.0
+!
+! Rule 15 (global)
+! firewall50:Policy:15: warning: MAC address matching is not supported. One or several MAC addresses removed from source in the rule
+access-list inside_acl_in permit tcp host 192.168.1.10 object-group inside.id4514300A28543.dst.net.0 eq 3128
+!
+! Rule 16 (global)
+access-list outside_acl_in permit tcp any object-group outside.id4514301628543.dst.net.0 eq 3128
+access-list inside_acl_in permit tcp any object-group outside.id4514301628543.dst.net.0 eq 3128
+access-list dmz_acl_in permit tcp any object-group outside.id4514301628543.dst.net.0 eq 3128
+!
+! Rule 17 (global)
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 inside
+ssh 0.0.0.0 0.0.0.0 dmz
+access-list outside_acl_in permit icmp any host 22.22.22.22 3
+access-list inside_acl_in permit icmp any host 192.168.1.1 3
+access-list dmz_acl_in permit icmp any host 192.168.2.1 3
+!
+! Rule 18 (global)
+access-list outside_acl_in permit tcp any object-group outside.id4514302F28543.dst.net.0 object-group outside.id4514302F28543.srv.tcp.0
+access-list inside_acl_in permit tcp any object-group outside.id4514302F28543.dst.net.0 object-group outside.id4514302F28543.srv.tcp.0
+access-list dmz_acl_in permit tcp any object-group outside.id4514302F28543.dst.net.0 object-group outside.id4514302F28543.srv.tcp.0
+!
+! Rule 19 (global)
+access-list outside_acl_in permit tcp any object-group outside.id4514303C28543.dst.net.0 object-group outside.id4514302F28543.srv.tcp.0
+access-list inside_acl_in permit tcp any object-group outside.id4514303C28543.dst.net.0 object-group outside.id4514302F28543.srv.tcp.0
+access-list dmz_acl_in permit tcp any object-group outside.id4514303C28543.dst.net.0 object-group outside.id4514302F28543.srv.tcp.0
+!
+! Rule 20 (global)
+access-list outside_acl_in permit tcp any 192.168.1.0 255.255.255.0 object-group outside.id4514304928543.srv.tcp.0
+access-list inside_acl_in permit tcp any 192.168.1.0 255.255.255.0 object-group outside.id4514304928543.srv.tcp.0
+access-list dmz_acl_in permit tcp any 192.168.1.0 255.255.255.0 object-group outside.id4514304928543.srv.tcp.0
+!
+! Rule 21 (global)
+! objects hostA and hostB are
+! redundant and should be removed by
+! removeRedundantAddressesFromDst
+access-list outside_acl_in permit tcp any 192.168.1.0 255.255.255.0 eq 1494
+access-list inside_acl_in permit tcp any 192.168.1.0 255.255.255.0 eq 1494
+access-list dmz_acl_in permit tcp any 192.168.1.0 255.255.255.0 eq 1494
+!
+! Rule 22 (global)
+access-list outside_acl_in permit tcp any gt 1024 host 192.168.1.10 eq 80
+access-list inside_acl_in permit tcp any gt 1024 host 192.168.1.10 eq 80
+access-list dmz_acl_in permit tcp any gt 1024 host 192.168.1.10 eq 80
+!
+! Rule 25 (global)
+access-list outside_acl_in permit ip host 22.22.22.22 host 22.22.22.22 log 0 interval 300
+access-list inside_acl_in permit ip host 192.168.1.1 host 192.168.1.1 log 0 interval 300
+access-list dmz_acl_in permit ip host 192.168.2.1 host 192.168.2.1 log 0 interval 300
+!
+! Rule 26 (global)
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 27 (global)
+access-list outside_acl_in permit ip host 22.22.22.22 any
+access-list inside_acl_in permit ip host 192.168.1.1 any
+access-list dmz_acl_in permit ip host 192.168.2.1 any
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 28 (global)
+access-list outside_acl_in deny ip any any log 0 interval 300
+access-list inside_acl_in deny ip any any log 0 interval 300
+access-list dmz_acl_in deny ip any any log 0 interval 300
+
+
+access-group dmz_acl_in in interface dmz
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+clear xlate
+clear config static
+clear config global
+clear config nat
+!
+! Rule 0 (NAT)
+global (outside) 1 interface
+clear config access-list id451430AE28543.0
+access-list id451430AE28543.0 permit ip 192.168.1.0 255.255.255.0 any
+nat (inside) 1 access-list id451430AE28543.0 tcp 0 0
+global (dmz) 1 interface
+!
+!
+! Rule 1 (NAT)
+nat (dmz) 1 0.0.0.0 0.0.0.0 tcp 0 0
+!
+! Rule 2 (NAT)
+nat (inside) 1 0.0.0.0 0.0.0.0 tcp 0 0
+!
+!
+! Rule 3 (NAT)
+global (outside) 1 22.22.22.0 netmask 255.255.255.0
+!
+!
+! Rule 4 (NAT)
+global (outside) 1 22.22.22.21-22.22.22.25 netmask 255.255.255.0
+!
+!
+! Rule 5 (NAT)
+clear config access-list id451430F428543.0
+access-list id451430F428543.0 permit tcp host 192.168.1.10 eq 25 any
+static (inside,outside) tcp interface 25 access-list id451430F428543.0 tcp 0 0
+!
+! Rule 6 (NAT)
+clear config access-list id47B71DF021818.0
+access-list id47B71DF021818.0 permit tcp host 192.168.1.10 eq 25 any
+!
+! Rule 7 (NAT)
+access-list id47B71DF021818.0 permit tcp host 192.168.1.10 eq 25 any
+!
+! Rule 8 (NAT)
+access-list id47B71DF021818.0 permit tcp host 192.168.1.10 eq 25 any
+static (inside,outside) tcp interface 2525 access-list id47B71DF021818.0 tcp 0 0
+!
+! Rule 9 (NAT)
+global (inside) 8 interface
+clear config access-list id4514310228543.0
+access-list id4514310228543.0 permit ip 192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0
+nat (dmz) 8 access-list id4514310228543.0 outside
+!
+! Rule 10 (NAT)
+
+clear config access-list nat0.inside
+access-list nat0.inside permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
+nat (inside) 0 access-list nat0.inside
+!
+! Rule 11 (NAT)
+
+access-list nat0.inside permit ip host 192.168.1.11 192.168.2.0 255.255.255.0
+
+access-list nat0.inside permit ip host 192.168.1.12 192.168.2.0 255.255.255.0
+
+access-list nat0.inside permit ip host 192.168.1.13 192.168.2.0 255.255.255.0
+
+access-list nat0.inside permit ip host 192.168.1.14 192.168.2.0 255.255.255.0
+
+access-list nat0.inside permit ip host 192.168.1.15 192.168.2.0 255.255.255.0
+!
+! Rule 12 (NAT)
+nat (dmz) 0 0 0
+!
+! Rule 13 (NAT)
+static (inside,dmz) 192.168.1.0 192.168.1.0 netmask 255.255.255.0
+!
+! Rule 14 (NAT)
+static (inside,dmz) 192.168.1.10 192.168.1.10 netmask 255.255.255.255
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall6.fw.orig b/test/pix/firewall6.fw.orig
new file mode 100755
index 000000000..2e359a47f
--- /dev/null
+++ b/test/pix/firewall6.fw.orig
@@ -0,0 +1,120 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:15 2011 PST by vadim
+!
+! Compiled for pix 6.2
+! Outbound ACLs: not supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: yes
+!
+!# files: * firewall6.fw
+!
+! testing rule with firewall in dst and negation
+
+
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+nameif eth0 inside security100
+
+nameif eth1 outside security0
+
+nameif eth2 dmz security50
+
+
+
+logging host outside 10.3.14.30
+logging queue 512
+logging facility 20
+logging trap 4
+logging buffered 5
+logging console 0
+logging timestamp
+logging on
+
+
+timeout xlate 3:0:0
+timeout conn 1:0:0
+timeout udp 0:2:0
+timeout rpc 0:10:0
+timeout h323 0:5:0
+timeout sip 0:30:0
+timeout sip_media 0:0:0
+timeout uauth 2:0:0 absolute
+
+
+clear ssh
+aaa authentication ssh console LOCAL
+
+clear snmp-server
+no snmp-server enable traps
+
+clear ntp
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt security fragguard
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+no sysopt route dnat
+floodguard disable
+
+
+!################
+clear access-list
+clear object-group
+clear icmp
+clear telnet
+!
+! Rule 0 (eth1)
+access-list outside_acl_in deny ip any host 22.22.22.22
+!
+! Rule 1 (global)
+access-list inside_acl_in deny ip any host 192.168.1.1
+access-list outside_acl_in deny ip any host 22.22.22.22
+access-list dmz_acl_in deny ip any host 192.168.2.1
+
+
+access-group dmz_acl_in in interface dmz
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+clear xlate
+clear static
+clear global
+clear nat
+!
+! Rule 0 (NAT)
+static (inside,dmz) 192.168.10.0 192.168.10.0 netmask 255.255.255.0
+static (inside,dmz) 192.168.20.0 192.168.20.0 netmask 255.255.255.0
+!
+! Rule 1 (NAT)
+static (inside,outside) 192.168.1.1 192.168.1.1 netmask 255.255.255.255
+!
+! Rule 2 (NAT)
+global (outside) 1 interface
+nat (inside) 1 192.168.1.10 255.255.255.255 0 0
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall8.fw.orig b/test/pix/firewall8.fw.orig
new file mode 100755
index 000000000..ea4884f40
--- /dev/null
+++ b/test/pix/firewall8.fw.orig
@@ -0,0 +1,139 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:16 2011 PST by vadim
+!
+! Compiled for pix 6.2
+! Outbound ACLs: not supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: no
+!
+!# files: * firewall8.fw
+!
+
+! N firewall8:NAT:5: warning: Original destination is ignored in 'nat' NAT rules when compiling for PIX v6.2 and earlier.
+! N firewall8:NAT:6: warning: Original destination is ignored in 'nat' NAT rules when compiling for PIX v6.2 and earlier.
+
+!
+! Prolog script:
+!
+no sysopt connection timewait
+no sysopt security fragguard
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+!
+! End of prolog script:
+!
+
+
+
+
+nameif eth0 outside security0
+
+nameif eth1 dmz security50
+
+nameif eth2 inside security100
+
+
+no logging buffered
+no logging console
+no logging timestamp
+no logging on
+
+
+timeout xlate 3:0:0
+timeout conn 1:0:0
+timeout udp 0:2:0
+timeout rpc 0:10:0
+timeout h323 0:5:0
+timeout sip 0:30:0
+timeout sip_media 0:2:0
+timeout half-closed 0:0:0
+timeout uauth 2:0:0 absolute
+
+telnet timeout 5
+
+clear ssh
+aaa authentication ssh console LOCAL
+ssh timeout 5
+
+no snmp-server enable traps
+
+
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+sysopt security fragguard
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+sysopt route dnat
+floodguard enable
+
+
+fixup protocol ftp 21
+
+
+!################
+!
+! Rule 0 (global)
+access-list outside_acl_in permit ip any host 192.168.1.10
+access-list dmz_acl_in permit ip any host 192.168.1.10
+access-list inside_acl_in permit ip any host 192.168.1.10
+!
+! Rule 1 (global)
+access-list outside_acl_in permit ip any 192.168.1.0 255.255.255.0
+access-list dmz_acl_in permit ip any 192.168.1.0 255.255.255.0
+access-list inside_acl_in permit ip any 192.168.1.0 255.255.255.0
+!
+! Rule 2 (global)
+access-list outside_acl_in deny ip any any
+access-list dmz_acl_in deny ip any any
+access-list inside_acl_in deny ip any any
+
+
+access-group dmz_acl_in in interface dmz
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+!
+! Rule 0 (NAT)
+global (outside) 1 interface
+nat (inside) 1 192.168.1.0 255.255.255.0 0 0
+global (outside) 1 interface
+!
+!
+! Rule 1 (NAT)
+!
+!
+! Rule 2 (NAT)
+!
+!
+! Rule 3 (NAT)
+nat (dmz) 1 192.168.2.0 255.255.255.0 0 0
+!
+! Rule 4 (NAT)
+static (dmz,outside) interface 192.168.2.100 0 0
+!
+! Rule 5 (NAT)
+! firewall8:NAT:5: warning: Original destination is ignored in 'nat' NAT rules when compiling for PIX v6.2 and earlier.
+global (inside) 1 interface
+!
+!
+! Rule 6 (NAT)
+! firewall8:NAT:6: warning: Original destination is ignored in 'nat' NAT rules when compiling for PIX v6.2 and earlier.
+global (dmz) 1 interface
+!
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/firewall9.fw.orig b/test/pix/firewall9.fw.orig
new file mode 100755
index 000000000..bfaf096a0
--- /dev/null
+++ b/test/pix/firewall9.fw.orig
@@ -0,0 +1,108 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:17 2011 PST by vadim
+!
+! Compiled for pix 6.3
+! Outbound ACLs: not supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: no
+!
+!# files: * firewall9.fw
+!
+! this firewall has no rules at all.
+
+
+
+!
+! Prolog script:
+!
+no sysopt connection timewait
+no sysopt security fragguard
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+!
+! End of prolog script:
+!
+
+
+
+
+nameif eth0 outside security0
+
+nameif eth1 dmz security50
+
+nameif eth2 inside security100
+
+
+no logging buffered
+no logging console
+no logging timestamp
+no logging on
+
+
+timeout xlate 0:0:0
+timeout conn 0:0:0
+timeout udp 0:0:0
+timeout rpc 0:0:0
+timeout h323 0:0:0
+timeout sip 0:0:0
+timeout sip_media 0:0:0
+timeout half-closed 0:0:0
+timeout uauth 0:0:0 absolute
+
+telnet timeout 5
+
+clear ssh
+aaa authentication ssh console LOCAL
+ssh timeout 5
+
+no snmp-server enable traps
+
+
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+floodguard disable
+
+
+fixup protocol ctiqbe 2748
+fixup protocol dns maximum-length 65535
+fixup protocol ftp 21
+fixup protocol h323 h225 1720
+fixup protocol h323 ras 1718-1719
+fixup protocol http 80
+fixup protocol icmp error
+fixup protocol ils 389
+fixup protocol mgcp 2427
+fixup protocol mgcp 2727
+fixup protocol pptp 1723
+fixup protocol rsh
+fixup protocol rtsp 554
+fixup protocol sip 5060
+fixup protocol sip udp
+fixup protocol skinny 2000
+fixup protocol smtp 25
+fixup protocol sqlnet 1521
+fixup protocol tftp 69
+
+
+!################
+
+
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/fwsm1.fw.orig b/test/pix/fwsm1.fw.orig
new file mode 100755
index 000000000..a115538c8
--- /dev/null
+++ b/test/pix/fwsm1.fw.orig
@@ -0,0 +1,431 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:17 2011 PST by vadim
+!
+! Compiled for fwsm 2.3
+! Outbound ACLs: supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: yes
+!
+!# files: * fwsm1.fw
+!
+
+! C fwsm1:Policy:18: error: Rule '18 (global)' shadows rule '20 (global)' below it
+! C fwsm1:Policy:13: warning: MAC address matching is not supported. One or several MAC addresses removed from source in the rule
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+hostname fwsm1
+
+nameif ethernet1 outside security0
+
+nameif ethernet0 inside security100
+
+nameif ethernet2 dmz security50
+
+
+
+logging host inside 192.168.1.30
+logging queue 512
+logging facility 16
+logging trap 0
+no logging buffered
+no logging console
+no logging timestamp
+logging on
+
+
+timeout xlate 3:0:0
+timeout conn 1:0:0
+timeout udp 0:2:0
+timeout rpc 0:10:0
+timeout h323 0:5:0
+timeout sip 0:30:0
+timeout sip_media 0:0:0
+timeout half-closed 0:0:0
+timeout uauth 2:0:0 absolute
+
+telnet timeout 5
+
+clear ssh
+aaa authentication ssh console LOCAL
+ssh timeout 5
+
+clear snmp-server
+snmp-server community public
+snmp-server enable traps
+snmp-server host inside 192.168.1.20 poll
+snmp-server host inside 192.168.1.22 trap
+
+clear ntp
+ntp server 192.168.1.20 source inside prefer
+
+
+no service resetinbound
+no service resetoutside
+sysopt connection tcpmss 1380
+sysopt nodnsalias inbound
+sysopt nodnsalias outbound
+floodguard disable
+
+
+fixup protocol ftp 21
+fixup protocol h323 h225 1720
+fixup protocol h323 ras 1718-1719
+fixup protocol http 80
+fixup protocol ils 389
+fixup protocol rsh 514
+fixup protocol rtsp 554
+fixup protocol sip 5060
+fixup protocol skinny 2000
+fixup protocol smtp 25
+fixup protocol sqlnet 1521
+
+
+!################
+access-list mode auto
+
+clear access-list tmp_acl
+access-list tmp_acl permit ip 192.168.1.0 255.255.255.0 any
+access-list tmp_acl deny ip any any
+
+access-group tmp_acl in interface outside
+access-group tmp_acl in interface inside
+
+clear access-list dmz_acl_in
+clear access-list inside_acl_in
+clear access-list outside_acl_in
+clear object-group
+
+clear icmp
+clear telnet
+
+object-group network inside.id444A03DE9567.dst.net.0
+ network-object host 211.11.11.11
+ network-object host 211.22.22.22
+ exit
+
+
+object-group service inside.id444A03DE9567.srv.tcp.0 tcp
+ port-object eq 113
+ port-object eq 80
+ port-object eq 25
+ port-object eq 22
+ port-object eq 540
+ port-object eq 443
+ port-object eq 143
+ exit
+
+
+object-group icmp-type outside.id444A04039567.srv.icmp.0
+ icmp-object 11
+ icmp-object 0
+ icmp-object 3
+ exit
+
+
+object-group service outside.id444A040F9567.srv.tcp.0 tcp
+ port-object eq 3128
+ port-object eq 70
+ port-object eq 6667
+ port-object eq 23
+ exit
+
+
+object-group service outside.id444A040F9567.srv.udp.0 udp
+ port-object eq 161
+ port-object eq 53
+ exit
+
+
+object-group network outside.id444A04349567.dst.net.0
+ network-object host 192.168.1.10
+ network-object host 192.168.1.20
+ exit
+
+
+object-group network inside.id444A04429567.dst.net.0
+ network-object 192.168.1.250 255.255.255.254
+ network-object 192.168.1.252 255.255.255.252
+ exit
+
+
+object-group network outside.id444A044E9567.dst.net.0
+ network-object 192.168.1.250 255.255.255.254
+ network-object 192.168.1.252 255.255.255.252
+ exit
+
+
+object-group network outside.id444A04679567.dst.net.0
+ network-object host 192.168.1.11
+ network-object host 192.168.1.12
+ network-object host 192.168.1.13
+ network-object host 192.168.1.14
+ network-object host 192.168.1.15
+ exit
+
+
+object-group service outside.id444A04679567.srv.tcp.0 tcp
+ port-object eq 113
+ port-object eq 80
+ port-object eq 25
+ port-object eq 22
+ port-object eq 540
+ port-object eq 443
+ port-object eq 143
+ port-object eq 3128
+ exit
+
+
+object-group network outside.id444A04749567.dst.net.0
+ network-object 192.168.1.11 255.255.255.255
+ network-object 192.168.1.12 255.255.255.252
+ exit
+
+
+object-group service outside.id444A04819567.srv.tcp.0 tcp
+ port-object eq 3128
+ port-object range 10000 11000
+ port-object eq 6667
+ port-object eq 113
+ port-object eq 53
+ port-object eq 21
+ port-object eq 80
+ port-object eq 119
+ port-object eq 25
+ port-object eq 22
+ port-object eq 23
+ port-object eq 540
+ port-object eq 70
+ port-object eq 13
+ port-object eq 2105
+ port-object eq 443
+ port-object eq 143
+ port-object eq 993
+ port-object eq 6667
+ port-object eq 543
+ port-object eq 544
+ port-object eq 389
+ port-object eq 98
+ port-object eq 3306
+ port-object eq 2049
+ port-object eq 110
+ port-object eq 5432
+ port-object eq 515
+ port-object eq 26000
+ port-object eq 512
+ port-object eq 513
+ port-object eq 514
+ port-object eq 4321
+ port-object eq 465
+ port-object eq 1080
+ port-object eq 111
+ port-object eq 7100
+ exit
+
+!
+! Rule 2 (ethernet1)
+icmp permit any 3 outside
+access-list outside_acl_in permit icmp any host 22.22.22.22 3
+access-list outside_acl_in permit icmp any any 3
+!
+! Rule 3 (ethernet1)
+! anti-spoofing rule
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any log 0 interval 300
+!
+! Rule 4 (ethernet0)
+ssh 192.168.1.0 255.255.255.0 inside
+!
+! Rule 5 (ethernet0)
+access-list inside_acl_in permit tcp any object-group inside.id444A03DE9567.dst.net.0 object-group inside.id444A03DE9567.srv.tcp.0
+access-list inside_acl_in permit tcp any object-group inside.id444A03DE9567.dst.net.0 object-group inside.id444A03DE9567.srv.tcp.0
+access-list dmz_acl_in permit tcp any object-group inside.id444A03DE9567.dst.net.0 object-group inside.id444A03DE9567.srv.tcp.0
+!
+! Rule 6 (ethernet0)
+access-list inside_acl_in deny ip any host 192.168.1.255
+!
+! Rule 8 (global)
+access-list outside_acl_in permit icmp any host 192.168.1.10 object-group outside.id444A04039567.srv.icmp.0
+access-list inside_acl_in permit icmp any host 192.168.1.10 object-group outside.id444A04039567.srv.icmp.0
+access-list dmz_acl_in permit icmp any host 192.168.1.10 object-group outside.id444A04039567.srv.icmp.0
+!
+! Rule 9 (global)
+access-list outside_acl_in permit icmp any host 192.168.1.10
+access-list inside_acl_in permit icmp any host 192.168.1.10
+access-list dmz_acl_in permit icmp any host 192.168.1.10
+access-list outside_acl_in permit tcp any host 192.168.1.10 object-group outside.id444A040F9567.srv.tcp.0
+access-list inside_acl_in permit tcp any host 192.168.1.10 object-group outside.id444A040F9567.srv.tcp.0
+access-list dmz_acl_in permit tcp any host 192.168.1.10 object-group outside.id444A040F9567.srv.tcp.0
+access-list outside_acl_in permit udp any host 192.168.1.10 object-group outside.id444A040F9567.srv.udp.0
+access-list inside_acl_in permit udp any host 192.168.1.10 object-group outside.id444A040F9567.srv.udp.0
+access-list dmz_acl_in permit udp any host 192.168.1.10 object-group outside.id444A040F9567.srv.udp.0
+access-list outside_acl_in permit 47 any host 192.168.1.10
+access-list inside_acl_in permit 47 any host 192.168.1.10
+access-list dmz_acl_in permit 47 any host 192.168.1.10
+!
+! Rule 10 (global)
+access-list outside_acl_in permit icmp any host 22.22.22.22 3 log 0 interval 300
+icmp permit any 3 inside
+access-list inside_acl_in permit icmp any host 192.168.1.1 3 log 0 interval 300
+icmp permit any 3 dmz
+access-list dmz_acl_in permit icmp any host 192.168.2.1 3 log 0 interval 300
+access-list outside_acl_in permit icmp any any 3 log 0 interval 300
+access-list inside_acl_in permit icmp any any 3 log 0 interval 300
+access-list dmz_acl_in permit icmp any any 3 log 0 interval 300
+access-list outside_acl_in permit 47 any any log 0 interval 300
+access-list inside_acl_in permit 47 any any log 0 interval 300
+access-list dmz_acl_in permit 47 any any log 0 interval 300
+access-list outside_acl_in permit 50 any any log 0 interval 300
+access-list inside_acl_in permit 50 any any log 0 interval 300
+access-list dmz_acl_in permit 50 any any log 0 interval 300
+!
+! Rule 12 (global)
+access-list outside_acl_in permit ip object-group inside.id444A03DE9567.dst.net.0 object-group outside.id444A04349567.dst.net.0
+!
+! Rule 13 (global)
+! fwsm1:Policy:13: warning: MAC address matching is not supported. One or several MAC addresses removed from source in the rule
+access-list inside_acl_in permit tcp host 192.168.1.10 object-group inside.id444A04429567.dst.net.0 eq 3128
+!
+! Rule 14 (global)
+access-list outside_acl_in permit tcp any object-group outside.id444A044E9567.dst.net.0 eq 3128
+access-list inside_acl_in permit tcp any object-group outside.id444A044E9567.dst.net.0 eq 3128
+access-list dmz_acl_in permit tcp any object-group outside.id444A044E9567.dst.net.0 eq 3128
+!
+! Rule 15 (global)
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 inside
+ssh 0.0.0.0 0.0.0.0 dmz
+access-list outside_acl_in permit icmp any host 22.22.22.22 3
+access-list inside_acl_in permit icmp any host 192.168.1.1 3
+access-list dmz_acl_in permit icmp any host 192.168.2.1 3
+!
+! Rule 16 (global)
+access-list outside_acl_in permit tcp any object-group outside.id444A04679567.dst.net.0 object-group outside.id444A04679567.srv.tcp.0
+access-list inside_acl_in permit tcp any object-group outside.id444A04679567.dst.net.0 object-group outside.id444A04679567.srv.tcp.0
+access-list dmz_acl_in permit tcp any object-group outside.id444A04679567.dst.net.0 object-group outside.id444A04679567.srv.tcp.0
+!
+! Rule 17 (global)
+access-list outside_acl_in permit tcp any object-group outside.id444A04749567.dst.net.0 object-group outside.id444A04679567.srv.tcp.0
+access-list inside_acl_in permit tcp any object-group outside.id444A04749567.dst.net.0 object-group outside.id444A04679567.srv.tcp.0
+access-list dmz_acl_in permit tcp any object-group outside.id444A04749567.dst.net.0 object-group outside.id444A04679567.srv.tcp.0
+!
+! Rule 18 (global)
+access-list outside_acl_in permit tcp any 192.168.1.0 255.255.255.0 object-group outside.id444A04819567.srv.tcp.0
+access-list inside_acl_in permit tcp any 192.168.1.0 255.255.255.0 object-group outside.id444A04819567.srv.tcp.0
+access-list dmz_acl_in permit tcp any 192.168.1.0 255.255.255.0 object-group outside.id444A04819567.srv.tcp.0
+!
+! Rule 19 (global)
+! objects hostA and hostB are
+! redundant and should be removed by
+! removeRedundantAddressesFromDst
+access-list outside_acl_in permit tcp any 192.168.1.0 255.255.255.0 eq 1494
+access-list inside_acl_in permit tcp any 192.168.1.0 255.255.255.0 eq 1494
+access-list dmz_acl_in permit tcp any 192.168.1.0 255.255.255.0 eq 1494
+!
+! Rule 20 (global)
+access-list outside_acl_in permit tcp any gt 1024 host 192.168.1.10 eq 80
+access-list inside_acl_in permit tcp any gt 1024 host 192.168.1.10 eq 80
+access-list dmz_acl_in permit tcp any gt 1024 host 192.168.1.10 eq 80
+!
+! Rule 23 (global)
+access-list outside_acl_in permit ip host 22.22.22.22 host 22.22.22.22 log 0 interval 300
+access-list inside_acl_in permit ip host 192.168.1.1 host 192.168.1.1 log 0 interval 300
+access-list dmz_acl_in permit ip host 192.168.2.1 host 192.168.2.1 log 0 interval 300
+!
+! Rule 24 (global)
+access-list outside_acl_in permit ip host 22.22.22.22 any
+access-list inside_acl_in permit ip host 192.168.1.1 any
+access-list dmz_acl_in permit ip host 192.168.2.1 any
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 25 (global)
+access-list outside_acl_in deny ip any any log 0 interval 300
+access-list inside_acl_in deny ip any any log 0 interval 300
+access-list dmz_acl_in deny ip any any log 0 interval 300
+
+
+access-group dmz_acl_in in interface dmz
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+clear xlate
+clear static
+clear global
+clear nat
+!
+! Rule 0 (NAT)
+global (outside) 1 interface
+nat (inside) 1 192.168.1.0 255.255.255.0 0 0
+global (dmz) 1 interface
+!
+!
+! Rule 1 (NAT)
+nat (dmz) 1 0.0.0.0 0.0.0.0 0 0
+!
+! Rule 2 (NAT)
+nat (inside) 1 0.0.0.0 0.0.0.0 0 0
+!
+!
+! Rule 3 (NAT)
+global (outside) 1 22.22.22.0 netmask 255.255.255.0
+!
+!
+! Rule 4 (NAT)
+global (outside) 1 22.22.22.21-22.22.22.25 netmask 255.255.255.0
+!
+!
+! Rule 5 (NAT)
+static (inside,outside) tcp interface 25 192.168.1.10 25 0 0
+!
+! Rule 6 (NAT)
+global (inside) 8 interface
+nat (dmz) 8 192.168.2.0 255.255.255.0 outside
+!
+! Rule 7 (NAT)
+
+clear access-list nat0.inside
+access-list nat0.inside permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
+nat (inside) 0 access-list nat0.inside
+!
+! Rule 8 (NAT)
+
+access-list nat0.inside permit ip host 192.168.1.11 192.168.2.0 255.255.255.0
+
+access-list nat0.inside permit ip host 192.168.1.12 192.168.2.0 255.255.255.0
+
+access-list nat0.inside permit ip host 192.168.1.13 192.168.2.0 255.255.255.0
+
+access-list nat0.inside permit ip host 192.168.1.14 192.168.2.0 255.255.255.0
+
+access-list nat0.inside permit ip host 192.168.1.15 192.168.2.0 255.255.255.0
+!
+! Rule 9 (NAT)
+nat (dmz) 0 0 0
+!
+! Rule 10 (NAT)
+static (inside,dmz) 192.168.1.0 192.168.1.0 netmask 255.255.255.0
+!
+! Rule 11 (NAT)
+static (inside,dmz) 192.168.1.10 192.168.1.10 netmask 255.255.255.255
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/fwsm2.fw.orig b/test/pix/fwsm2.fw.orig
new file mode 100755
index 000000000..80dc054f2
--- /dev/null
+++ b/test/pix/fwsm2.fw.orig
@@ -0,0 +1,431 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:18 2011 PST by vadim
+!
+! Compiled for fwsm 4.x
+! Outbound ACLs: supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: yes
+!
+!# files: * fwsm2.fw
+!
+
+! C fwsm2:Policy:18: error: Rule '18 (global)' shadows rule '20 (global)' below it
+! C fwsm2:Policy:13: warning: MAC address matching is not supported. One or several MAC addresses removed from source in the rule
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+hostname fwsm2
+
+nameif ethernet1 outside security0
+
+nameif ethernet0 inside security100
+
+nameif ethernet2 dmz security50
+
+
+
+logging host inside 192.168.1.30
+logging queue 512
+logging facility 16
+logging trap 0
+no logging buffered
+no logging console
+no logging timestamp
+logging on
+
+
+timeout xlate 3:0:0
+timeout conn 1:0:0
+timeout udp 0:2:0
+timeout rpc 0:10:0
+timeout h323 0:5:0
+timeout sip 0:30:0
+timeout sip_media 0:0:0
+timeout half-closed 0:0:0
+timeout uauth 2:0:0 absolute
+
+telnet timeout 5
+
+clear ssh
+aaa authentication ssh console LOCAL
+ssh timeout 5
+
+clear snmp-server
+snmp-server community public
+snmp-server enable traps
+snmp-server host inside 192.168.1.20 poll
+snmp-server host inside 192.168.1.22 trap
+
+clear ntp
+ntp server 192.168.1.20 source inside prefer
+
+
+no service resetinbound
+no service resetoutside
+sysopt connection tcpmss 1380
+sysopt nodnsalias inbound
+sysopt nodnsalias outbound
+floodguard disable
+
+
+fixup protocol ftp 21
+fixup protocol h323 h225 1720
+fixup protocol h323 ras 1718-1719
+fixup protocol http 80
+fixup protocol ils 389
+fixup protocol rsh 514
+fixup protocol rtsp 554
+fixup protocol sip 5060
+fixup protocol skinny 2000
+fixup protocol smtp 25
+fixup protocol sqlnet 1521
+
+
+!################
+access-list mode auto
+
+clear config access-list tmp_acl
+access-list tmp_acl permit ip 192.168.1.0 255.255.255.0 any
+access-list tmp_acl deny ip any any
+
+access-group tmp_acl in interface outside
+access-group tmp_acl in interface inside
+
+clear config access-list dmz_acl_in
+clear config access-list inside_acl_in
+clear config access-list outside_acl_in
+clear config object-group
+
+clear config icmp
+clear config telnet
+
+object-group network inside.id17298X54624.dst.net.0
+ network-object host 211.11.11.11
+ network-object host 211.22.22.22
+ exit
+
+
+object-group service inside.id17298X54624.srv.tcp.0 tcp
+ port-object eq 113
+ port-object eq 80
+ port-object eq 25
+ port-object eq 22
+ port-object eq 540
+ port-object eq 443
+ port-object eq 143
+ exit
+
+
+object-group icmp-type outside.id17335X54624.srv.icmp.0
+ icmp-object 11
+ icmp-object 0
+ icmp-object 3
+ exit
+
+
+object-group service outside.id17347X54624.srv.tcp.0 tcp
+ port-object eq 3128
+ port-object eq 70
+ port-object eq 6667
+ port-object eq 23
+ exit
+
+
+object-group service outside.id17347X54624.srv.udp.0 udp
+ port-object eq 161
+ port-object eq 53
+ exit
+
+
+object-group network outside.id17384X54624.dst.net.0
+ network-object host 192.168.1.10
+ network-object host 192.168.1.20
+ exit
+
+
+object-group network inside.id17398X54624.dst.net.0
+ network-object 192.168.1.250 255.255.255.254
+ network-object 192.168.1.252 255.255.255.252
+ exit
+
+
+object-group network outside.id17410X54624.dst.net.0
+ network-object 192.168.1.250 255.255.255.254
+ network-object 192.168.1.252 255.255.255.252
+ exit
+
+
+object-group network outside.id17435X54624.dst.net.0
+ network-object host 192.168.1.11
+ network-object host 192.168.1.12
+ network-object host 192.168.1.13
+ network-object host 192.168.1.14
+ network-object host 192.168.1.15
+ exit
+
+
+object-group service outside.id17435X54624.srv.tcp.0 tcp
+ port-object eq 113
+ port-object eq 80
+ port-object eq 25
+ port-object eq 22
+ port-object eq 540
+ port-object eq 443
+ port-object eq 143
+ port-object eq 3128
+ exit
+
+
+object-group network outside.id17448X54624.dst.net.0
+ network-object 192.168.1.11 255.255.255.255
+ network-object 192.168.1.12 255.255.255.252
+ exit
+
+
+object-group service outside.id17461X54624.srv.tcp.0 tcp
+ port-object eq 3128
+ port-object range 10000 11000
+ port-object eq 6667
+ port-object eq 113
+ port-object eq 53
+ port-object eq 21
+ port-object eq 80
+ port-object eq 119
+ port-object eq 25
+ port-object eq 22
+ port-object eq 23
+ port-object eq 540
+ port-object eq 70
+ port-object eq 13
+ port-object eq 2105
+ port-object eq 443
+ port-object eq 143
+ port-object eq 993
+ port-object eq 6667
+ port-object eq 543
+ port-object eq 544
+ port-object eq 389
+ port-object eq 98
+ port-object eq 3306
+ port-object eq 2049
+ port-object eq 110
+ port-object eq 5432
+ port-object eq 515
+ port-object eq 26000
+ port-object eq 512
+ port-object eq 513
+ port-object eq 514
+ port-object eq 4321
+ port-object eq 465
+ port-object eq 1080
+ port-object eq 111
+ port-object eq 7100
+ exit
+
+!
+! Rule 2 (ethernet1)
+icmp permit any 3 outside
+access-list outside_acl_in permit icmp any host 22.22.22.22 3
+access-list outside_acl_in permit icmp any any 3
+!
+! Rule 3 (ethernet1)
+! anti-spoofing rule
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any log 0 interval 300
+!
+! Rule 4 (ethernet0)
+ssh 192.168.1.0 255.255.255.0 inside
+!
+! Rule 5 (ethernet0)
+access-list inside_acl_in permit tcp any object-group inside.id17298X54624.dst.net.0 object-group inside.id17298X54624.srv.tcp.0
+access-list inside_acl_in permit tcp any object-group inside.id17298X54624.dst.net.0 object-group inside.id17298X54624.srv.tcp.0
+access-list dmz_acl_in permit tcp any object-group inside.id17298X54624.dst.net.0 object-group inside.id17298X54624.srv.tcp.0
+!
+! Rule 6 (ethernet0)
+access-list inside_acl_in deny ip any host 192.168.1.255
+!
+! Rule 8 (global)
+access-list outside_acl_in permit icmp any host 192.168.1.10 object-group outside.id17335X54624.srv.icmp.0
+access-list inside_acl_in permit icmp any host 192.168.1.10 object-group outside.id17335X54624.srv.icmp.0
+access-list dmz_acl_in permit icmp any host 192.168.1.10 object-group outside.id17335X54624.srv.icmp.0
+!
+! Rule 9 (global)
+access-list outside_acl_in permit icmp any host 192.168.1.10
+access-list inside_acl_in permit icmp any host 192.168.1.10
+access-list dmz_acl_in permit icmp any host 192.168.1.10
+access-list outside_acl_in permit tcp any host 192.168.1.10 object-group outside.id17347X54624.srv.tcp.0
+access-list inside_acl_in permit tcp any host 192.168.1.10 object-group outside.id17347X54624.srv.tcp.0
+access-list dmz_acl_in permit tcp any host 192.168.1.10 object-group outside.id17347X54624.srv.tcp.0
+access-list outside_acl_in permit udp any host 192.168.1.10 object-group outside.id17347X54624.srv.udp.0
+access-list inside_acl_in permit udp any host 192.168.1.10 object-group outside.id17347X54624.srv.udp.0
+access-list dmz_acl_in permit udp any host 192.168.1.10 object-group outside.id17347X54624.srv.udp.0
+access-list outside_acl_in permit 47 any host 192.168.1.10
+access-list inside_acl_in permit 47 any host 192.168.1.10
+access-list dmz_acl_in permit 47 any host 192.168.1.10
+!
+! Rule 10 (global)
+access-list outside_acl_in permit icmp any host 22.22.22.22 3 log 0 interval 300
+icmp permit any 3 inside
+access-list inside_acl_in permit icmp any host 192.168.1.1 3 log 0 interval 300
+icmp permit any 3 dmz
+access-list dmz_acl_in permit icmp any host 192.168.2.1 3 log 0 interval 300
+access-list outside_acl_in permit icmp any any 3 log 0 interval 300
+access-list inside_acl_in permit icmp any any 3 log 0 interval 300
+access-list dmz_acl_in permit icmp any any 3 log 0 interval 300
+access-list outside_acl_in permit 47 any any log 0 interval 300
+access-list inside_acl_in permit 47 any any log 0 interval 300
+access-list dmz_acl_in permit 47 any any log 0 interval 300
+access-list outside_acl_in permit 50 any any log 0 interval 300
+access-list inside_acl_in permit 50 any any log 0 interval 300
+access-list dmz_acl_in permit 50 any any log 0 interval 300
+!
+! Rule 12 (global)
+access-list outside_acl_in permit ip object-group inside.id17298X54624.dst.net.0 object-group outside.id17384X54624.dst.net.0
+!
+! Rule 13 (global)
+! fwsm2:Policy:13: warning: MAC address matching is not supported. One or several MAC addresses removed from source in the rule
+access-list inside_acl_in permit tcp host 192.168.1.10 object-group inside.id17398X54624.dst.net.0 eq 3128
+!
+! Rule 14 (global)
+access-list outside_acl_in permit tcp any object-group outside.id17410X54624.dst.net.0 eq 3128
+access-list inside_acl_in permit tcp any object-group outside.id17410X54624.dst.net.0 eq 3128
+access-list dmz_acl_in permit tcp any object-group outside.id17410X54624.dst.net.0 eq 3128
+!
+! Rule 15 (global)
+ssh 0.0.0.0 0.0.0.0 outside
+ssh 0.0.0.0 0.0.0.0 inside
+ssh 0.0.0.0 0.0.0.0 dmz
+access-list outside_acl_in permit icmp any host 22.22.22.22 3
+access-list inside_acl_in permit icmp any host 192.168.1.1 3
+access-list dmz_acl_in permit icmp any host 192.168.2.1 3
+!
+! Rule 16 (global)
+access-list outside_acl_in permit tcp any object-group outside.id17435X54624.dst.net.0 object-group outside.id17435X54624.srv.tcp.0
+access-list inside_acl_in permit tcp any object-group outside.id17435X54624.dst.net.0 object-group outside.id17435X54624.srv.tcp.0
+access-list dmz_acl_in permit tcp any object-group outside.id17435X54624.dst.net.0 object-group outside.id17435X54624.srv.tcp.0
+!
+! Rule 17 (global)
+access-list outside_acl_in permit tcp any object-group outside.id17448X54624.dst.net.0 object-group outside.id17435X54624.srv.tcp.0
+access-list inside_acl_in permit tcp any object-group outside.id17448X54624.dst.net.0 object-group outside.id17435X54624.srv.tcp.0
+access-list dmz_acl_in permit tcp any object-group outside.id17448X54624.dst.net.0 object-group outside.id17435X54624.srv.tcp.0
+!
+! Rule 18 (global)
+access-list outside_acl_in permit tcp any 192.168.1.0 255.255.255.0 object-group outside.id17461X54624.srv.tcp.0
+access-list inside_acl_in permit tcp any 192.168.1.0 255.255.255.0 object-group outside.id17461X54624.srv.tcp.0
+access-list dmz_acl_in permit tcp any 192.168.1.0 255.255.255.0 object-group outside.id17461X54624.srv.tcp.0
+!
+! Rule 19 (global)
+! objects hostA and hostB are
+! redundant and should be removed by
+! removeRedundantAddressesFromDst
+access-list outside_acl_in permit tcp any 192.168.1.0 255.255.255.0 eq 1494
+access-list inside_acl_in permit tcp any 192.168.1.0 255.255.255.0 eq 1494
+access-list dmz_acl_in permit tcp any 192.168.1.0 255.255.255.0 eq 1494
+!
+! Rule 20 (global)
+access-list outside_acl_in permit tcp any gt 1024 host 192.168.1.10 eq 80
+access-list inside_acl_in permit tcp any gt 1024 host 192.168.1.10 eq 80
+access-list dmz_acl_in permit tcp any gt 1024 host 192.168.1.10 eq 80
+!
+! Rule 23 (global)
+access-list outside_acl_in permit ip host 22.22.22.22 host 22.22.22.22 log 0 interval 300
+access-list inside_acl_in permit ip host 192.168.1.1 host 192.168.1.1 log 0 interval 300
+access-list dmz_acl_in permit ip host 192.168.2.1 host 192.168.2.1 log 0 interval 300
+!
+! Rule 24 (global)
+access-list outside_acl_in permit ip host 22.22.22.22 any
+access-list inside_acl_in permit ip host 192.168.1.1 any
+access-list dmz_acl_in permit ip host 192.168.2.1 any
+access-list inside_acl_in permit ip 192.168.1.0 255.255.255.0 any
+!
+! Rule 25 (global)
+access-list outside_acl_in deny ip any any log 0 interval 300
+access-list inside_acl_in deny ip any any log 0 interval 300
+access-list dmz_acl_in deny ip any any log 0 interval 300
+
+
+access-group dmz_acl_in in interface dmz
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+clear xlate
+clear config static
+clear config global
+clear config nat
+!
+! Rule 0 (NAT)
+global (outside) 1 interface
+nat (inside) 1 192.168.1.0 255.255.255.0 0 0
+global (dmz) 1 interface
+!
+!
+! Rule 1 (NAT)
+nat (dmz) 1 0.0.0.0 0.0.0.0 0 0
+!
+! Rule 2 (NAT)
+nat (inside) 1 0.0.0.0 0.0.0.0 0 0
+!
+!
+! Rule 3 (NAT)
+global (outside) 1 22.22.22.0 netmask 255.255.255.0
+!
+!
+! Rule 4 (NAT)
+global (outside) 1 22.22.22.21-22.22.22.25 netmask 255.255.255.0
+!
+!
+! Rule 5 (NAT)
+static (inside,outside) tcp interface 25 192.168.1.10 25 0 0
+!
+! Rule 6 (NAT)
+global (inside) 8 interface
+nat (dmz) 8 192.168.2.0 255.255.255.0 outside
+!
+! Rule 7 (NAT)
+
+clear config access-list nat0.inside
+access-list nat0.inside permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
+nat (inside) 0 access-list nat0.inside
+!
+! Rule 8 (NAT)
+
+access-list nat0.inside permit ip host 192.168.1.11 192.168.2.0 255.255.255.0
+
+access-list nat0.inside permit ip host 192.168.1.12 192.168.2.0 255.255.255.0
+
+access-list nat0.inside permit ip host 192.168.1.13 192.168.2.0 255.255.255.0
+
+access-list nat0.inside permit ip host 192.168.1.14 192.168.2.0 255.255.255.0
+
+access-list nat0.inside permit ip host 192.168.1.15 192.168.2.0 255.255.255.0
+!
+! Rule 9 (NAT)
+nat (dmz) 0 0 0
+!
+! Rule 10 (NAT)
+static (inside,dmz) 192.168.1.0 192.168.1.0 netmask 255.255.255.0
+!
+! Rule 11 (NAT)
+static (inside,dmz) 192.168.1.10 192.168.1.10 netmask 255.255.255.255
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/pix515.fw.orig b/test/pix/pix515.fw.orig
new file mode 100755
index 000000000..eeeaea219
--- /dev/null
+++ b/test/pix/pix515.fw.orig
@@ -0,0 +1,170 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:19 2011 PST by vadim
+!
+! Compiled for pix 7.0
+! Outbound ACLs: supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: yes
+!
+!# files: * pix515.fw
+!
+! Similar to fw 1, but the firewall is used as DHCP and DNS server for internal network.
+! This firewall has two interfaces. Eth0 faces outside and has a dynamic address; eth1 faces inside.
+! Policy includes basic rules to permit unrestricted outbound access and anti-spoofing rules. Access to the firewall is permitted only from internal network and only using SSH. The firewall can send DNS queries to servers out on the Internet. Another rule permits DNS queries from internal network to the firewall. Special rules permit DHCP requests from internal network and replies sent by the firewall.
+
+
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+interface ethernet0
+ nameif outside
+ security-level 0
+exit
+
+interface ethernet1
+ nameif inside
+ security-level 100
+exit
+
+
+logging buffered 6
+no logging console
+logging timestamp
+logging on
+logging device-id hostname
+
+
+timeout xlate 0:0:0
+timeout conn 0:0:0
+timeout udp 0:0:0
+timeout sunrpc 0:0:0
+timeout h323 0:0:0
+timeout sip 0:0:0
+timeout sip_media 0:0:0
+timeout half-closed 0:0:0
+timeout uauth 0:0:0
+
+
+clear config ssh
+aaa authentication ssh console LOCAL
+
+clear config snmp-server
+no snmp-server enable traps
+
+clear config ntp
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+
+
+class-map inspection_default
+ match default-inspection-traffic
+
+policy-map global_policy
+ class inspection_default
+
+service-policy global_policy global
+
+
+!################
+
+clear config access-list tmp_acl
+access-list tmp_acl permit ip 10.3.14.42 255.255.255.255 any
+access-list tmp_acl deny ip any any
+
+access-group tmp_acl in interface outside
+access-group tmp_acl in interface inside
+
+clear config access-list inside_acl_in
+clear config access-list outside_acl_in
+clear config object-group
+
+clear config icmp
+clear config telnet
+!
+! Rule -1 backup ssh access rule (automatic)
+ssh 10.3.14.42 255.255.255.255 inside
+!
+! Rule 0 (global)
+ssh 10.3.14.0 255.255.255.0 inside
+access-list inside_acl_in remark 0 (global)
+access-list inside_acl_in permit tcp 10.3.14.0 255.255.255.0 host 10.3.14.206 eq 53
+access-list inside_acl_in permit udp 10.3.14.0 255.255.255.0 host 10.3.14.206 eq 53
+!
+! Rule 1 (global)
+access-list outside_acl_in remark 1 (global)
+access-list outside_acl_in permit tcp any host 192.168.1.1 eq 2525
+access-list outside_acl_in permit tcp any host 10.3.14.50 eq 25
+access-list inside_acl_in remark 1 (global)
+access-list inside_acl_in permit tcp any host 10.3.14.50 eq 25
+!
+! Rule 3 (global)
+access-list outside_acl_in remark 3 (global)
+access-list outside_acl_in permit ip host 192.168.1.1 any
+access-list inside_acl_in remark 3 (global)
+access-list inside_acl_in permit ip host 10.3.14.206 any
+!
+! Rule 4 (global)
+access-list inside_acl_in remark 4 (global)
+access-list inside_acl_in permit ip 10.3.14.0 255.255.255.0 any
+!
+! Rule 5 (global)
+access-list outside_acl_in remark 5 (global)
+access-list outside_acl_in deny ip any any
+access-list inside_acl_in remark 5 (global)
+access-list inside_acl_in deny ip any any
+
+
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+clear xlate
+clear config static
+clear config global
+clear config nat
+!
+! Rule 0 (NAT)
+global (outside) 1 interface
+clear config access-list id47B7A71421818.0
+access-list id47B7A71421818.0 permit ip 10.3.14.0 255.255.255.0 any
+nat (inside) 1 access-list id47B7A71421818.0 tcp 0 0
+!
+! Rule 1 (NAT)
+clear config access-list id47B7C22E21818.0
+access-list id47B7C22E21818.0 permit tcp host 10.3.14.50 eq 25 any
+static (inside,outside) tcp interface 2525 access-list id47B7C22E21818.0 tcp 0 0
+
+!
+! Rule 0 (main)
+!
+! "Routing rule 0 (main)"
+!
+! The default metric on PIX is 1, so the GUI default value of 0 becomes 1 in
+! the compiled rules.
+!
+route inside 192.168.10.0 255.255.255.0 10.3.14.254 1
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/pix/real.fw.orig b/test/pix/real.fw.orig
new file mode 100755
index 000000000..573432f72
--- /dev/null
+++ b/test/pix/real.fw.orig
@@ -0,0 +1,144 @@
+!
+! This is automatically generated file. DO NOT MODIFY !
+!
+! Firewall Builder fwb_pix v4.2.0.3425-{{build}}
+!
+! Generated Mon Jan 3 12:50:20 2011 PST by vadim
+!
+! Compiled for pix 6.3
+! Outbound ACLs: not supported
+! Emulate outbound ACLs: yes
+! Generating outbound ACLs: no
+! Assume firewall is part of any: no
+!
+!# files: * real.fw
+!
+
+
+
+!
+! Prolog script:
+!
+
+!
+! End of prolog script:
+!
+
+
+
+
+hostname real
+
+nameif ethernet0 outside security0
+ip address outside dhcp setroute retry 10
+
+nameif ethernet1 inside security100
+ip address inside 10.3.14.204 255.255.255.0
+
+
+
+logging host inside 10.3.14.10 format emblem
+logging queue 1000
+logging facility 16
+logging trap 0
+no logging buffered
+no logging console
+no logging timestamp
+logging on
+logging device-id string real_firewall
+
+
+timeout xlate 0:0:0
+timeout conn 0:0:0
+timeout udp 0:0:0
+timeout rpc 0:0:0
+timeout h323 0:0:0
+timeout sip 0:0:0
+timeout sip_media 0:0:0
+timeout half-closed 0:0:0
+timeout uauth 0:0:0 absolute
+
+telnet timeout 5
+
+clear ssh
+aaa authentication ssh console LOCAL
+ssh timeout 5
+
+clear snmp-server
+snmp-server community public
+snmp-server enable traps
+snmp-server host inside 10.3.14.40 poll
+
+clear ntp
+ntp server 10.3.14.30 source inside
+
+
+no service resetinbound
+no service resetoutside
+no sysopt connection timewait
+no sysopt nodnsalias inbound
+no sysopt nodnsalias outbound
+floodguard disable
+
+
+fixup protocol dns maximum-length 65535
+fixup protocol ftp 21
+fixup protocol http 80
+fixup protocol icmp error
+
+
+!################
+clear access-list
+clear object-group
+clear icmp
+clear telnet
+!
+! Rule 0 (global)
+access-list inside_acl_in remark 0 (global)
+access-list inside_acl_in permit ip 10.3.14.0 255.255.255.0 any
+!
+! Rule 1 (global)
+ssh 10.3.14.0 255.255.255.0 inside
+!
+! Rule 2 (global)
+icmp permit any 0 outside
+access-list outside_acl_in remark 2 (global)
+access-list outside_acl_in permit icmp any interface outside 0
+icmp permit any 0 inside
+access-list inside_acl_in remark 2 (global)
+access-list inside_acl_in permit icmp any host 10.3.14.204 0
+!
+! Rule 3 (global)
+access-list outside_acl_in remark 3 (global)
+access-list outside_acl_in permit tcp any host 10.3.14.30 eq 80
+access-list inside_acl_in remark 3 (global)
+access-list inside_acl_in permit tcp any host 10.3.14.30 eq 80
+!
+! Rule 4 (global)
+access-list outside_acl_in remark 4 (global)
+access-list outside_acl_in deny ip any any log 5 interval 120
+access-list inside_acl_in remark 4 (global)
+access-list inside_acl_in deny ip any any log 5 interval 120
+
+
+access-group inside_acl_in in interface inside
+access-group outside_acl_in in interface outside
+
+clear xlate
+clear static
+clear global
+clear nat
+!
+! Rule 0 (NAT)
+global (outside) 1 interface
+access-list id3D385E43.0 permit ip 10.3.14.0 255.255.255.0 any
+nat (inside) 1 access-list id3D385E43.0 0 0
+
+
+
+!
+! Epilog script:
+!
+
+! End of epilog script:
+!
diff --git a/test/procurve_acl/testhp1.fw.orig b/test/procurve_acl/testhp1.fw.orig
new file mode 100755
index 000000000..ce5292f7c
--- /dev/null
+++ b/test/procurve_acl/testhp1.fw.orig
@@ -0,0 +1,1089 @@
+;
+; This is automatically generated file. DO NOT MODIFY !
+;
+; Firewall Builder fwb_procurve_acl v4.2.0.3425-{{build}}
+;
+; Generated Mon Jan 3 13:00:18 2011 PST by vadim
+;
+; Compiled for procurve_acl K.13
+;
+;# files: * testhp1.fw
+;
+
+
+
+;
+; Prolog script:
+;
+
+;
+; End of prolog script:
+;
+
+
+
+
+
+; ================ IPv4
+
+
+interface a1
+ no ip access-group a1_in in
+exit
+no ip access-list extended a1_in
+
+interface a1
+ no ip access-group a1_out out
+exit
+no ip access-list extended a1_out
+
+interface a2
+ no ip access-group a2_in in
+exit
+no ip access-list extended a2_in
+
+interface a2
+ no ip access-group a2_out out
+exit
+no ip access-list extended a2_out
+
+interface b1
+ no ip access-group b1_in in
+exit
+no ip access-list extended b1_in
+
+interface b1
+ no ip access-group b1_out out
+exit
+no ip access-list extended b1_out
+
+interface b2
+ no ip access-group b2_in in
+exit
+no ip access-list extended b2_in
+
+interface b2
+ no ip access-group b2_out out
+exit
+no ip access-list extended b2_out
+
+no vlan 10 ip access-group vlan_10_in in
+no ip access-list extended vlan_10_in
+
+no vlan 10 ip access-group vlan_10_out out
+no ip access-list extended vlan_10_out
+
+no vlan 20 ip access-group vlan_20_in in
+no ip access-list extended vlan_20_in
+
+no vlan 20 ip access-group vlan_20_out out
+no ip access-list extended vlan_20_out
+
+no vlan 401 ip access-group vlan_401_in in
+no ip access-list extended vlan_401_in
+
+no vlan 401 ip access-group vlan_401_out out
+no ip access-list extended vlan_401_out
+
+no vlan 402 ip access-group vlan_402_in in
+no ip access-list extended vlan_402_in
+
+no vlan 402 ip access-group vlan_402_out out
+no ip access-list extended vlan_402_out
+
+no vlan 40 ip access-group vlan_40_in in
+no ip access-list extended vlan_40_in
+
+no vlan 40 ip access-group vlan_40_out out
+no ip access-list extended vlan_40_out
+
+
+
+ip access-list extended a1_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 1 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 21 (a1)
+ permit ip any 10.10.10.0 0.0.0.255
+;
+; Rule 22 (a1,a2)
+ permit ip any 10.10.10.0 0.0.0.255
+;
+; Rule 23 (global)
+ deny ip any any log
+exit
+
+ip access-list extended a1_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 23 (global)
+ deny ip any any log
+exit
+
+ip access-list extended a2_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 1 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 22 (a1,a2)
+ permit ip any 10.10.10.0 0.0.0.255
+;
+; Rule 23 (global)
+ deny ip any any log
+exit
+
+ip access-list extended a2_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 23 (global)
+ deny ip any any log
+exit
+
+ip access-list extended b1_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 1 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 23 (global)
+ deny ip any any log
+exit
+
+ip access-list extended b1_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 23 (global)
+ deny ip any any log
+exit
+
+ip access-list extended b2_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 1 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 23 (global)
+ deny ip any any log
+exit
+
+ip access-list extended b2_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 23 (global)
+ deny ip any any log
+exit
+
+ip access-list extended vlan_10_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 0 (vlan 10)
+; anti-spoofing
+ deny ip 10.10.10.0 0.0.0.255 any log
+ deny ip 10.10.11.0 0.0.0.255 any log
+ deny ip 10.10.12.0 0.0.0.255 any log
+;
+; Rule 1 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 2 (vlan 20,vlan 10)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 3 (testhp1 itf)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 4 (vlan 10)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 7 (vlan 10)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 10 (vlan 10)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 23 (global)
+ deny ip any any log
+exit
+
+ip access-list extended vlan_10_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 2 (vlan 20,vlan 10)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 3 (testhp1 itf)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 4 (vlan 10)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 10 (vlan 10)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 23 (global)
+ deny ip any any log
+exit
+
+ip access-list extended vlan_20_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 1 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 2 (vlan 20,vlan 10)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 3 (testhp1 itf)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 5 (vlan 20)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 8 (vlan 20)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 11 (vlan 20)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 23 (global)
+ deny ip any any log
+exit
+
+ip access-list extended vlan_20_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 2 (vlan 20,vlan 10)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 3 (testhp1 itf)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 5 (vlan 20)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 11 (vlan 20)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 23 (global)
+ deny ip any any log
+exit
+
+ip access-list extended vlan_401_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 1 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 23 (global)
+ deny ip any any log
+exit
+
+ip access-list extended vlan_401_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 23 (global)
+ deny ip any any log
+exit
+
+ip access-list extended vlan_402_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 1 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 23 (global)
+ deny ip any any log
+exit
+
+ip access-list extended vlan_402_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 1 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 23 (global)
+ deny ip any any log
+exit
+
+ip access-list extended vlan_40_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 1 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 23 (global)
+ deny ip any any log
+exit
+
+ip access-list extended vlan_40_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 23 (global)
+ deny ip any any log
+exit
+
+
+interface a1
+ ip access-group a1_in in
+exit
+interface a1
+ ip access-group a1_out out
+exit
+interface a2
+ ip access-group a2_in in
+exit
+interface a2
+ ip access-group a2_out out
+exit
+interface b1
+ ip access-group b1_in in
+exit
+interface b1
+ ip access-group b1_out out
+exit
+interface b2
+ ip access-group b2_in in
+exit
+interface b2
+ ip access-group b2_out out
+exit
+vlan 10 ip access-group vlan_10_in in
+vlan 10 ip access-group vlan_10_out out
+vlan 20 ip access-group vlan_20_in in
+vlan 20 ip access-group vlan_20_out out
+vlan 401 ip access-group vlan_401_in in
+vlan 401 ip access-group vlan_401_out out
+vlan 402 ip access-group vlan_402_in in
+vlan 402 ip access-group vlan_402_out out
+vlan 40 ip access-group vlan_40_in in
+vlan 40 ip access-group vlan_40_out out
+
+
+
+
+
+;
+; Epilog script:
+;
+
+; End of epilog script:
+;
diff --git a/test/procurve_acl/testhp2.fw.orig b/test/procurve_acl/testhp2.fw.orig
new file mode 100755
index 000000000..4be273db1
--- /dev/null
+++ b/test/procurve_acl/testhp2.fw.orig
@@ -0,0 +1,411 @@
+;
+; This is automatically generated file. DO NOT MODIFY !
+;
+; Firewall Builder fwb_procurve_acl v4.2.0.3425-{{build}}
+;
+; Generated Mon Jan 3 13:00:19 2011 PST by vadim
+;
+; Compiled for procurve_acl K.13
+;
+;# files: * testhp2.fw
+;
+; Using "no clear acl" script option
+
+
+
+;
+; Prolog script:
+;
+
+;
+; End of prolog script:
+;
+
+
+
+
+
+; ================ IPv4
+
+
+
+ip access-list extended vlan_10_in
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+ deny ip 10.10.10.0 0.0.0.255 any log
+ deny ip 10.10.11.0 0.0.0.255 any log
+ deny ip 10.10.12.0 0.0.0.255 any log
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ deny ip any any log
+exit
+
+ip access-list extended vlan_10_out
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+ deny ip any any log
+exit
+
+ip access-list extended vlan_20_in
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ deny ip any any log
+exit
+
+ip access-list extended vlan_20_out
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+ deny ip any any log
+exit
+
+ip access-list extended vlan_401_in
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ deny ip any any log
+exit
+
+ip access-list extended vlan_401_out
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+ deny ip any any log
+exit
+
+ip access-list extended vlan_402_in
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ deny ip any any log
+exit
+
+ip access-list extended vlan_402_out
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ deny ip any any log
+exit
+
+ip access-list extended vlan_40_in
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ deny ip any any log
+exit
+
+ip access-list extended vlan_40_out
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+ deny ip any any log
+exit
+
+
+vlan 10 ip access-group vlan_10_in in
+vlan 10 ip access-group vlan_10_out out
+vlan 20 ip access-group vlan_20_in in
+vlan 20 ip access-group vlan_20_out out
+vlan 401 ip access-group vlan_401_in in
+vlan 401 ip access-group vlan_401_out out
+vlan 402 ip access-group vlan_402_in in
+vlan 402 ip access-group vlan_402_out out
+vlan 40 ip access-group vlan_40_in in
+vlan 40 ip access-group vlan_40_out out
+
+
+
+
+
+;
+; Epilog script:
+;
+
+; End of epilog script:
+;
diff --git a/test/procurve_acl/testhp3.fw.orig b/test/procurve_acl/testhp3.fw.orig
new file mode 100755
index 000000000..adbb8fcd6
--- /dev/null
+++ b/test/procurve_acl/testhp3.fw.orig
@@ -0,0 +1,688 @@
+;
+; This is automatically generated file. DO NOT MODIFY !
+;
+; Firewall Builder fwb_procurve_acl v4.2.0.3425-{{build}}
+;
+; Generated Mon Jan 3 13:00:19 2011 PST by vadim
+;
+; Compiled for procurve_acl K.13
+;
+;# files: * testhp3.fw
+;
+; Using "safety net" script option
+
+
+
+;
+; Prolog script:
+;
+
+;
+; End of prolog script:
+;
+
+
+
+; temporary access list for "safety net install"
+no vlan 40 ip access-group tmp_acl in
+no ip access-list extended tmp_acl
+ip access-list extended tmp_acl
+ permit ip 10.10.11.10 0.0.0.0 any
+ deny ip any any
+exit
+vlan 40 ip access-group tmp_acl in
+
+; ================ IPv4
+
+
+no vlan 10 ip access-group vlan_10_in in
+no ip access-list extended vlan_10_in
+
+no vlan 10 ip access-group vlan_10_out out
+no ip access-list extended vlan_10_out
+
+no vlan 20 ip access-group vlan_20_in in
+no ip access-list extended vlan_20_in
+
+no vlan 20 ip access-group vlan_20_out out
+no ip access-list extended vlan_20_out
+
+no vlan 401 ip access-group vlan_401_in in
+no ip access-list extended vlan_401_in
+
+no vlan 401 ip access-group vlan_401_out out
+no ip access-list extended vlan_401_out
+
+no vlan 402 ip access-group vlan_402_in in
+no ip access-list extended vlan_402_in
+
+no vlan 402 ip access-group vlan_402_out out
+no ip access-list extended vlan_402_out
+
+no vlan 40 ip access-group vlan_40_in in
+no ip access-list extended vlan_40_in
+
+no vlan 40 ip access-group vlan_40_out out
+no ip access-list extended vlan_40_out
+
+
+
+ip access-list extended vlan_10_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 0 (vlan 10)
+; anti-spoofing
+ deny ip 10.10.10.0 0.0.0.255 any log
+ deny ip 10.10.11.0 0.0.0.255 any log
+ deny ip 10.10.12.0 0.0.0.255 any log
+;
+; Rule 1 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 2 (vlan 20,vlan 10)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 3 (testhp1 itf)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 4 (vlan 10)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 7 (vlan 10)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 10 (vlan 10)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 21 (global)
+ deny ip any any log
+exit
+
+ip access-list extended vlan_10_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 2 (vlan 20,vlan 10)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 3 (testhp1 itf)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 4 (vlan 10)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 10 (vlan 10)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 21 (global)
+ deny ip any any log
+exit
+
+ip access-list extended vlan_20_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 1 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 2 (vlan 20,vlan 10)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 3 (testhp1 itf)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 5 (vlan 20)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 8 (vlan 20)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 11 (vlan 20)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 21 (global)
+ deny ip any any log
+exit
+
+ip access-list extended vlan_20_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 2 (vlan 20,vlan 10)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 3 (testhp1 itf)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 5 (vlan 20)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 11 (vlan 20)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 21 (global)
+ deny ip any any log
+exit
+
+ip access-list extended vlan_401_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 1 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 21 (global)
+ deny ip any any log
+exit
+
+ip access-list extended vlan_401_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 21 (global)
+ deny ip any any log
+exit
+
+ip access-list extended vlan_402_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 1 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 21 (global)
+ deny ip any any log
+exit
+
+ip access-list extended vlan_402_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 1 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 21 (global)
+ deny ip any any log
+exit
+
+ip access-list extended vlan_40_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 1 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 21 (global)
+ deny ip any any log
+exit
+
+ip access-list extended vlan_40_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 21 (global)
+ deny ip any any log
+exit
+
+
+vlan 10 ip access-group vlan_10_in in
+vlan 10 ip access-group vlan_10_out out
+vlan 20 ip access-group vlan_20_in in
+vlan 20 ip access-group vlan_20_out out
+vlan 401 ip access-group vlan_401_in in
+vlan 401 ip access-group vlan_401_out out
+vlan 402 ip access-group vlan_402_in in
+vlan 402 ip access-group vlan_402_out out
+vlan 40 ip access-group vlan_40_in in
+vlan 40 ip access-group vlan_40_out out
+
+
+
+
+
+;
+; Epilog script:
+;
+
+; End of epilog script:
+;
diff --git a/test/procurve_acl/testhp4.fw.orig b/test/procurve_acl/testhp4.fw.orig
new file mode 100755
index 000000000..889e93548
--- /dev/null
+++ b/test/procurve_acl/testhp4.fw.orig
@@ -0,0 +1,952 @@
+;
+; This is automatically generated file. DO NOT MODIFY !
+;
+; Firewall Builder fwb_procurve_acl v4.2.0.3425-{{build}}
+;
+; Generated Mon Jan 3 13:00:19 2011 PST by vadim
+;
+; Compiled for procurve_acl K.13
+;
+;# files: * testhp4.fw
+;
+; Using "safety net" script option, management interface is not a vlan
+
+
+
+;
+; Prolog script:
+;
+
+;
+; End of prolog script:
+;
+
+
+
+; temporary access list for "safety net install"
+interface a1
+ no ip access-group tmp_acl in
+exit
+no ip access-list extended tmp_acl
+ip access-list extended tmp_acl
+ permit ip 10.10.11.10 0.0.0.0 any
+ deny ip any any
+exit
+interface a1
+ ip access-group tmp_acl in
+exit
+
+; ================ IPv4
+
+
+interface a1
+ no ip access-group a1_in in
+exit
+no ip access-list extended a1_in
+
+interface a1
+ no ip access-group a1_out out
+exit
+no ip access-list extended a1_out
+
+no vlan 10 ip access-group vlan_10_in in
+no ip access-list extended vlan_10_in
+
+no vlan 10 ip access-group vlan_10_out out
+no ip access-list extended vlan_10_out
+
+no vlan 20 ip access-group vlan_20_in in
+no ip access-list extended vlan_20_in
+
+no vlan 20 ip access-group vlan_20_out out
+no ip access-list extended vlan_20_out
+
+no vlan 401 ip access-group vlan_401_in in
+no ip access-list extended vlan_401_in
+
+no vlan 401 ip access-group vlan_401_out out
+no ip access-list extended vlan_401_out
+
+no vlan 402 ip access-group vlan_402_in in
+no ip access-list extended vlan_402_in
+
+no vlan 402 ip access-group vlan_402_out out
+no ip access-list extended vlan_402_out
+
+no vlan 40 ip access-group vlan_40_in in
+no ip access-list extended vlan_40_in
+
+no vlan 40 ip access-group vlan_40_out out
+no ip access-list extended vlan_40_out
+
+
+
+ip access-list extended a1_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ remark "-1 backup ssh access rule (automatic)"
+ permit tcp host 10.10.11.10 host 10.10.1.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 1 (global)
+ remark "1 (global)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ remark "6 (global)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ remark "9 (global)"
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ remark "12 (global)"
+ remark "interface ethernet1 has address on network 10.10.10.0/24,"
+ remark "therefore net-10.10.10 is behind the router and we do"
+ remark "not need to put rules 12-18 in outbound acl of eth0"
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ remark "13 (global)"
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ remark "14 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ remark "15 (global)"
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ remark "16 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ remark "17 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ remark "18 (global)"
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ remark "19 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ remark "20 (global)"
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 21 (global)
+ remark "21 (global)"
+ deny ip any any log
+exit
+
+ip access-list extended a1_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ remark "-2 backup ssh access rule (out) (automatic)"
+ permit tcp host 10.10.1.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 21 (global)
+ remark "21 (global)"
+ deny ip any any log
+exit
+
+ip access-list extended vlan_10_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ remark "-1 backup ssh access rule (automatic)"
+ permit tcp host 10.10.11.10 host 10.10.1.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 0 (vlan 10)
+; anti-spoofing
+ remark "0 (vlan 10)"
+ remark anti-spoofing
+ deny ip 10.10.10.0 0.0.0.255 any log
+ deny ip 10.10.11.0 0.0.0.255 any log
+ deny ip 10.10.12.0 0.0.0.255 any log
+;
+; Rule 1 (global)
+ remark "1 (global)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 2 (vlan 20,vlan 10)
+ remark "2 (vlan 20,vlan 10)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 3 (testhp1 itf)
+ remark "3 (testhp1 itf)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 4 (vlan 10)
+ remark "4 (vlan 10)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ remark "6 (global)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 7 (vlan 10)
+ remark "7 (vlan 10)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ remark "9 (global)"
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 10 (vlan 10)
+ remark "10 (vlan 10)"
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ remark "12 (global)"
+ remark "interface ethernet1 has address on network 10.10.10.0/24,"
+ remark "therefore net-10.10.10 is behind the router and we do"
+ remark "not need to put rules 12-18 in outbound acl of eth0"
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ remark "13 (global)"
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ remark "14 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ remark "15 (global)"
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ remark "16 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ remark "17 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ remark "18 (global)"
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ remark "19 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ remark "20 (global)"
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 21 (global)
+ remark "21 (global)"
+ deny ip any any log
+exit
+
+ip access-list extended vlan_10_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ remark "-2 backup ssh access rule (out) (automatic)"
+ permit tcp host 10.10.1.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 2 (vlan 20,vlan 10)
+ remark "2 (vlan 20,vlan 10)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 3 (testhp1 itf)
+ remark "3 (testhp1 itf)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 4 (vlan 10)
+ remark "4 (vlan 10)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 10 (vlan 10)
+ remark "10 (vlan 10)"
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 21 (global)
+ remark "21 (global)"
+ deny ip any any log
+exit
+
+ip access-list extended vlan_20_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ remark "-1 backup ssh access rule (automatic)"
+ permit tcp host 10.10.11.10 host 10.10.1.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 1 (global)
+ remark "1 (global)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 2 (vlan 20,vlan 10)
+ remark "2 (vlan 20,vlan 10)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 3 (testhp1 itf)
+ remark "3 (testhp1 itf)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 5 (vlan 20)
+ remark "5 (vlan 20)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ remark "6 (global)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 8 (vlan 20)
+ remark "8 (vlan 20)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ remark "9 (global)"
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 11 (vlan 20)
+ remark "11 (vlan 20)"
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ remark "12 (global)"
+ remark "interface ethernet1 has address on network 10.10.10.0/24,"
+ remark "therefore net-10.10.10 is behind the router and we do"
+ remark "not need to put rules 12-18 in outbound acl of eth0"
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ remark "13 (global)"
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ remark "14 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ remark "15 (global)"
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ remark "16 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ remark "17 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ remark "18 (global)"
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ remark "19 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ remark "20 (global)"
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 21 (global)
+ remark "21 (global)"
+ deny ip any any log
+exit
+
+ip access-list extended vlan_20_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ remark "-2 backup ssh access rule (out) (automatic)"
+ permit tcp host 10.10.1.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 2 (vlan 20,vlan 10)
+ remark "2 (vlan 20,vlan 10)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 3 (testhp1 itf)
+ remark "3 (testhp1 itf)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 5 (vlan 20)
+ remark "5 (vlan 20)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 11 (vlan 20)
+ remark "11 (vlan 20)"
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 21 (global)
+ remark "21 (global)"
+ deny ip any any log
+exit
+
+ip access-list extended vlan_401_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ remark "-1 backup ssh access rule (automatic)"
+ permit tcp host 10.10.11.10 host 10.10.1.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 1 (global)
+ remark "1 (global)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ remark "6 (global)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ remark "9 (global)"
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ remark "12 (global)"
+ remark "interface ethernet1 has address on network 10.10.10.0/24,"
+ remark "therefore net-10.10.10 is behind the router and we do"
+ remark "not need to put rules 12-18 in outbound acl of eth0"
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ remark "13 (global)"
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ remark "14 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ remark "15 (global)"
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ remark "16 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ remark "17 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ remark "18 (global)"
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ remark "19 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ remark "20 (global)"
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 21 (global)
+ remark "21 (global)"
+ deny ip any any log
+exit
+
+ip access-list extended vlan_401_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ remark "-2 backup ssh access rule (out) (automatic)"
+ permit tcp host 10.10.1.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 21 (global)
+ remark "21 (global)"
+ deny ip any any log
+exit
+
+ip access-list extended vlan_402_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ remark "-1 backup ssh access rule (automatic)"
+ permit tcp host 10.10.11.10 host 10.10.1.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 1 (global)
+ remark "1 (global)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ remark "6 (global)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ remark "9 (global)"
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ remark "12 (global)"
+ remark "interface ethernet1 has address on network 10.10.10.0/24,"
+ remark "therefore net-10.10.10 is behind the router and we do"
+ remark "not need to put rules 12-18 in outbound acl of eth0"
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ remark "13 (global)"
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ remark "14 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ remark "15 (global)"
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ remark "16 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ remark "17 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ remark "18 (global)"
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ remark "19 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ remark "20 (global)"
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 21 (global)
+ remark "21 (global)"
+ deny ip any any log
+exit
+
+ip access-list extended vlan_402_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ remark "-2 backup ssh access rule (out) (automatic)"
+ permit tcp host 10.10.1.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 1 (global)
+ remark "1 (global)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ remark "9 (global)"
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ remark "12 (global)"
+ remark "interface ethernet1 has address on network 10.10.10.0/24,"
+ remark "therefore net-10.10.10 is behind the router and we do"
+ remark "not need to put rules 12-18 in outbound acl of eth0"
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ remark "13 (global)"
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ remark "14 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ remark "15 (global)"
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ remark "16 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ remark "17 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ remark "18 (global)"
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ remark "19 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ remark "20 (global)"
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 21 (global)
+ remark "21 (global)"
+ deny ip any any log
+exit
+
+ip access-list extended vlan_40_in
+;
+; Rule -1 backup ssh access rule (automatic)
+ remark "-1 backup ssh access rule (automatic)"
+ permit tcp host 10.10.11.10 host 10.10.1.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.10.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.11.1 eq 22
+ permit tcp host 10.10.11.10 host 10.10.12.1 eq 22
+;
+; Rule 1 (global)
+ remark "1 (global)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 6 (global)
+ remark "6 (global)"
+ permit ip any 10.10.10.0 0.0.0.255
+ permit ip any 10.10.11.0 0.0.0.255
+ permit ip any 10.10.12.0 0.0.0.255
+;
+; Rule 9 (global)
+ remark "9 (global)"
+ permit ip 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.21.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.22.0 0.0.0.255 10.10.12.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.11.0 0.0.0.255
+ permit ip 22.22.23.0 0.0.0.255 10.10.12.0 0.0.0.255
+;
+; Rule 12 (global)
+; interface ethernet1 has address on network 10.10.10.0/24,
+; therefore net-10.10.10 is behind the router and we do
+; not need to put rules 12-18 in outbound acl of eth0
+ remark "12 (global)"
+ remark "interface ethernet1 has address on network 10.10.10.0/24,"
+ remark "therefore net-10.10.10 is behind the router and we do"
+ remark "not need to put rules 12-18 in outbound acl of eth0"
+ permit 47 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+ permit 51 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 13 (global)
+ remark "13 (global)"
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 3
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 11
+;
+; Rule 14 (global)
+ remark "14 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 21
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 80
+;
+; Rule 15 (global)
+ remark "15 (global)"
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 4000
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 500
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 53
+;
+; Rule 16 (global)
+ remark "16 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 established
+;
+; Rule 17 (global)
+ remark "17 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 eq 80 10.10.10.0 0.0.0.255 established
+;
+; Rule 18 (global)
+ remark "18 (global)"
+ permit icmp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 0
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 179
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 79
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 123
+ permit udp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255 eq 26000
+;
+; Rule 19 (global)
+ remark "19 (global)"
+ permit tcp 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 20 (global)
+ remark "20 (global)"
+ permit 50 22.22.21.0 0.0.0.255 10.10.10.0 0.0.0.255
+;
+; Rule 21 (global)
+ remark "21 (global)"
+ deny ip any any log
+exit
+
+ip access-list extended vlan_40_out
+;
+; Rule -2 backup ssh access rule (out) (automatic)
+ remark "-2 backup ssh access rule (out) (automatic)"
+ permit tcp host 10.10.1.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.10.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.11.1 eq 22 host 10.10.11.10
+ permit tcp host 10.10.12.1 eq 22 host 10.10.11.10
+;
+; Rule 21 (global)
+ remark "21 (global)"
+ deny ip any any log
+exit
+
+
+interface a1
+ ip access-group a1_in in
+exit
+interface a1
+ ip access-group a1_out out
+exit
+vlan 10 ip access-group vlan_10_in in
+vlan 10 ip access-group vlan_10_out out
+vlan 20 ip access-group vlan_20_in in
+vlan 20 ip access-group vlan_20_out out
+vlan 401 ip access-group vlan_401_in in
+vlan 401 ip access-group vlan_401_out out
+vlan 402 ip access-group vlan_402_in in
+vlan 402 ip access-group vlan_402_out out
+vlan 40 ip access-group vlan_40_in in
+vlan 40 ip access-group vlan_40_out out
+
+
+
+
+
+;
+; Epilog script:
+;
+
+; End of epilog script:
+;