* IPTImporter.cpp (pushPolicyRule): see #2338 "Empty Mangle Policy

object created on import". Iptables rules in the table mangle
will be imported in the dedicated Policy rule set with name
"Mangle". Rules that use chains FORWARD and POSTROUTING in table
mangle can not be reproduced and will be marked as "bad" (color
red and corresponding comment).
This commit is contained in:
Vadim Kurland
2011-04-13 19:09:30 -07:00
parent 457fcd1660
commit d066f567f5
2 changed files with 47 additions and 16 deletions
+7
View File
@@ -1,5 +1,12 @@
2011-04-13 Vadim Kurland <vadim@netcitadel.com>
* IPTImporter.cpp (pushPolicyRule): see #2338 "Empty Mangle Policy
object created on import". Iptables rules in the table 'mangle'
will be imported in the dedicated Policy rule set with name
"Mangle". Rules that use chains FORWARD and POSTROUTING in table
'mangle' can not be reproduced and will be marked as "bad" (color
red and corresponding comment).
* configlets/fwsm_os/ntp: see #2344 fwbuilder should not generate
any "ntp" commands for FWSM because NTP can not be configured on FWSM.
+40 -16
View File
@@ -1055,22 +1055,42 @@ void IPTImporter::pushPolicyRule()
rule_comment += "Does SRC match one of the firewall's addresses?";
}
if (current_table == "mangle")
{
if (current_chain == "POSTROUTING" || current_chain == "FORWARD")
{
QString err = QObject::tr(
"Fwbuilder can not reproduce iptables rule in "
"the table 'mangle', chain %1")
.arg(current_chain.c_str());
reportError(err);
markCurrentRuleBad();
}
}
// add rule to the right ruleset
RuleSet *ruleset = NULL;
std::string ruleset_name = "";
if (isStandardChain(current_chain))
{
ruleset = RuleSet::cast(
getFirewallObject()->getFirstByType(Policy::TYPENAME));
assert(ruleset!=NULL);
ruleset->add(current_rule);
} else
{
UnidirectionalRuleSet *rs = getUnidirRuleSet(current_chain, Policy::TYPENAME);
assert(rs!=NULL);
rs->ruleset->add(current_rule);
ruleset = rs->ruleset;
}
// if (isStandardChain(current_chain))
// {
// ruleset = RuleSet::cast(
// getFirewallObject()->getFirstByType(Policy::TYPENAME));
// assert(ruleset!=NULL);
// } else
// {
// UnidirectionalRuleSet *rs = getUnidirRuleSet(
// current_chain, Policy::TYPENAME);
// assert(rs!=NULL);
// ruleset = rs->ruleset;
// }
UnidirectionalRuleSet *rs = getUnidirRuleSet(current_chain,
Policy::TYPENAME);
assert(rs!=NULL);
ruleset = rs->ruleset;
ruleset->add(current_rule);
// renumber to clean-up rule positions
ruleset->renumberRules();
@@ -1118,7 +1138,8 @@ void IPTImporter::pushPolicyRule()
re =rule->getItf();
re->addRef(intf);
QString interfaces = QString("-i %1 -o %2").arg(i_intf.c_str()).arg(o_intf.c_str());
QString interfaces =
QString("-i %1 -o %2").arg(i_intf.c_str()).arg(o_intf.c_str());
rule_comment += QString(
" Both inbound and outbound interfaces "
@@ -1128,6 +1149,7 @@ void IPTImporter::pushPolicyRule()
QString("Warning: Creating branch ruleset '%1' to "
"match inbound and outbound interfaces %2")
.arg(branch_ruleset_name.c_str()).arg(interfaces));
} else
{
if ( !i_intf.empty())
@@ -1151,7 +1173,8 @@ void IPTImporter::pushPolicyRule()
processModuleMatches();
addStandardImportComment(current_rule, QString::fromUtf8(rule_comment.c_str()));
addStandardImportComment(
current_rule, QString::fromUtf8(rule_comment.c_str()));
}
if (error_tracker->hasErrors())
@@ -1616,7 +1639,8 @@ UnidirectionalRuleSet* IPTImporter::getUnidirRuleSet(
getFirewallObject()->getFirstByType(NAT::TYPENAME));
else
{
list<FWObject*> policies = getFirewallObject()->getByType(Policy::TYPENAME);
list<FWObject*> policies =
getFirewallObject()->getByType(Policy::TYPENAME);
if (current_table == "mangle")
{