1
0
mirror of https://github.com/fwbuilder/fwbuilder synced 2025-10-16 15:38:43 +02:00
fwbuilder/test/ipt/firewall-ipv6-3.fw.orig
Vadim Kurland 0aa3eac4d4 * Compiler.cpp (expandGroupsInRuleElement): sorting objects in the
rule element by name after group is expanded, this helps ensure
stable ordering of objects in generated configuration.

* Compiler.cpp (replaceClusterInterfaceInItfRE::processNext):
sorting objects in rule element after cluster interfaces have been
replaced, this helps ensure stable ordering of objects in generated
configuration.

* FWObject.h (FWObjectNameCmpPredicate): moved this class from
gui-specific module to libfwbuilder as it is universally useful.
It can compare FWObject objects by name and can optionally can
follow references; it can be used with std::sort() to sort lists
of FWObject pointers or directly sort rule elements.
2011-03-12 19:50:24 -08:00

656 lines
20 KiB
Bash
Executable File

#!/bin/sh
#
# This is automatically generated file. DO NOT MODIFY !
#
# Firewall Builder fwb_ipt v4.2.0.3499
#
# Generated Sat Mar 12 19:42:24 2011 PST by vadim
#
# files: * firewall-ipv6-3.fw /etc/firewall-ipv6-3.fw
#
# Compiled for iptables (any version)
#
# Simple policy that makes sense in ipv4 but translates into a few wide-matching rules in ipv6. Policy is configured as dual address family
# firewall-ipv6-3:fw-ipv6-3:2: error: Rule 'fw-ipv6-3 2 (global)' shadows rule 'fw-ipv6-3 3 (global)' below it
# firewall-ipv6-3:fw-ipv6-3:4: error: Rule 'fw-ipv6-3 4 (global)' shadows rule 'fw-ipv6-3 6 (global)' below it
# firewall-ipv6-3:fw-ipv6-3:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
# firewall-ipv6-3:fw-ipv6-3:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
# firewall-ipv6-3:fw-ipv6-3:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
# firewall-ipv6-3:fw-ipv6-3:2: error: Rule 'fw-ipv6-3 2 (global)' shadows rule 'fw-ipv6-3 3 (global)' below it
# firewall-ipv6-3:fw-ipv6-3:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
# firewall-ipv6-3:fw-ipv6-3:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
# firewall-ipv6-3:fw-ipv6-3:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
FWBDEBUG=""
PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
export PATH
LSMOD="/sbin/lsmod"
MODPROBE="/sbin/modprobe"
IPTABLES="/sbin/iptables"
IP6TABLES="/sbin/ip6tables"
IPTABLES_RESTORE="/sbin/iptables-restore"
IP6TABLES_RESTORE="/sbin/ip6tables-restore"
IP="/sbin/ip"
IFCONFIG="/sbin/ifconfig"
VCONFIG="/sbin/vconfig"
BRCTL="/sbin/brctl"
IFENSLAVE="/sbin/ifenslave"
IPSET="/usr/sbin/ipset"
LOGGER="/usr/bin/logger"
log() {
echo "$1"
command -v "$LOGGER" >/dev/null 2>&1 && $LOGGER -p info "$1"
}
getInterfaceVarName() {
echo $1 | sed 's/\./_/'
}
getaddr_internal() {
dev=$1
name=$2
af=$3
L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
test -z "$L" && {
eval "$name=''"
return
}
eval "${name}_list=\"$L\""
}
getaddr() {
getaddr_internal $1 $2 "-4"
}
getaddr6() {
getaddr_internal $1 $2 "-6"
}
# function getinterfaces is used to process wildcard interfaces
getinterfaces() {
NAME=$1
$IP link show | grep ": $NAME" | while read L; do
OIFS=$IFS
IFS=" :"
set $L
IFS=$OIFS
echo $2
done
}
diff_intf() {
func=$1
list1=$2
list2=$3
cmd=$4
for intf in $list1
do
echo $list2 | grep -q $intf || {
# $vlan is absent in list 2
$func $intf $cmd
}
done
}
find_program() {
PGM=$1
command -v $PGM >/dev/null 2>&1 || {
echo "$PGM not found"
exit 1
}
}
check_tools() {
find_program $IPTABLES
find_program $MODPROBE
find_program $IP
}
reset_iptables_v4() {
$IPTABLES -P OUTPUT DROP
$IPTABLES -P INPUT DROP
$IPTABLES -P FORWARD DROP
cat /proc/net/ip_tables_names | while read table; do
$IPTABLES -t $table -L -n | while read c chain rest; do
if test "X$c" = "XChain" ; then
$IPTABLES -t $table -F $chain
fi
done
$IPTABLES -t $table -X
done
}
reset_iptables_v6() {
$IP6TABLES -P OUTPUT DROP
$IP6TABLES -P INPUT DROP
$IP6TABLES -P FORWARD DROP
cat /proc/net/ip6_tables_names | while read table; do
$IP6TABLES -t $table -L -n | while read c chain rest; do
if test "X$c" = "XChain" ; then
$IP6TABLES -t $table -F $chain
fi
done
$IP6TABLES -t $table -X
done
}
P2P_INTERFACE_WARNING=""
missing_address() {
address=$1
cmd=$2
oldIFS=$IFS
IFS="@"
set $address
addr=$1
interface=$2
IFS=$oldIFS
$IP addr show dev $interface | grep -q POINTOPOINT && {
test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
P2P_INTERFACE_WARNING="yes"
return
}
test "$cmd" = "add" && {
echo "# Adding ip address: $interface $addr"
echo $addr | grep -q ':' && {
$FWBDEBUG $IP addr $cmd $addr dev $interface
} || {
$FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
}
}
test "$cmd" = "del" && {
echo "# Removing ip address: $interface $addr"
$FWBDEBUG $IP addr $cmd $addr dev $interface || exit 1
}
$FWBDEBUG $IP link set $interface up
}
list_addresses_by_scope() {
interface=$1
scope=$2
ignore_list=$3
$IP addr ls dev $interface | \
awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
'BEGIN {
split(IGNORED,ignored_arr);
for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
}
(/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
while read addr; do
echo "${addr}@$interface"
done | sort
}
update_addresses_of_interface() {
ignore_list=$2
set $1
interface=$1
shift
FWB_ADDRS=$(
for addr in $*; do
echo "${addr}@$interface"
done | sort
)
CURRENT_ADDRS_ALL_SCOPES=""
CURRENT_ADDRS_GLOBAL_SCOPE=""
$IP link show dev $interface >/dev/null 2>&1 && {
CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
} || {
echo "# Interface $interface does not exist"
# Stop the script if we are not in test mode
test -z "$FWBDEBUG" && exit 1
}
diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
}
clear_addresses_except_known_interfaces() {
$IP link show | sed 's/://g' | awk -v IGNORED="$*" \
'BEGIN {
split(IGNORED,ignored_arr);
for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
}
(/state/ && !($2 in ignored_dict)) {print $2;}' | \
while read intf; do
echo "# Removing addresses not configured in fwbuilder from interface $intf"
$FWBDEBUG $IP addr flush dev $intf scope global
$FWBDEBUG $IP link set $intf down
done
}
check_file() {
test -r "$2" || {
echo "Can not find file $2 referenced by address table object $1"
exit 1
}
}
check_run_time_address_table_files() {
:
}
load_modules() {
:
OPTS=$1
MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
echo $OPTS | grep -q nat && {
MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
}
echo $OPTS | grep -q ipv6 && {
MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
}
for module in $MODULES; do
if $LSMOD | grep ${module} >/dev/null; then continue; fi
$MODPROBE ${module} || exit 1
done
}
verify_interfaces() {
:
echo "Verifying interfaces: eth0 eth1"
for i in eth0 eth1 ; do
$IP link show "$i" > /dev/null 2>&1 || {
log "Interface $i does not exist"
exit 1
}
done
}
prolog_commands() {
echo "Running prolog script"
}
epilog_commands() {
echo "Running epilog script"
}
run_epilog_and_exit() {
epilog_commands
exit $1
}
configure_interfaces() {
:
# Configure interfaces
update_addresses_of_interface "eth0 fe80::21d:9ff:fe8b:8e94/64 1.1.1.1/24" ""
update_addresses_of_interface "eth1 22.22.22.22/24" ""
}
script_body() {
# ================ IPv4
# ================ Table 'filter', automatic rules
# accept established sessions
$IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
$IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
$IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
# drop packets that do not match any valid state and log them
$IPTABLES -N drop_invalid
$IPTABLES -A OUTPUT -m state --state INVALID -j drop_invalid
$IPTABLES -A INPUT -m state --state INVALID -j drop_invalid
$IPTABLES -A FORWARD -m state --state INVALID -j drop_invalid
$IPTABLES -A drop_invalid -j ULOG --ulog-nlgroup 1 --ulog-qthreshold 1 --ulog-prefix "INVALID state -- DENY "
$IPTABLES -A drop_invalid -j DROP
# ================ Table 'nat', rule set NAT
#
# Rule 0 (NAT)
#
echo "Rule 0 (NAT)"
#
$IPTABLES -t nat -A POSTROUTING -o eth1 -s 1.1.1.0/24 -j SNAT --to-source 22.22.22.22
# ================ Table 'filter', rule set fw-ipv6-3
#
# Rule fw-ipv6-3 0 (global)
#
echo "Rule fw-ipv6-3 0 (global)"
#
$IPTABLES -N In_fw-ipv6-3_0
$IPTABLES -A INPUT -m state --state NEW -j In_fw-ipv6-3_0
$IPTABLES -A In_fw-ipv6-3_0 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 0 -- ACCEPT " --ulog-qthreshold 1
$IPTABLES -A In_fw-ipv6-3_0 -j ACCEPT
#
# Rule fw-ipv6-3 1 (global)
#
echo "Rule fw-ipv6-3 1 (global)"
#
$IPTABLES -A INPUT -p icmp -m icmp -s 1.1.1.1 --icmp-type 8/0 -m state --state NEW -j ACCEPT
$IPTABLES -A OUTPUT -p icmp -m icmp -s 1.1.1.1 --icmp-type 8/0 -m state --state NEW -j ACCEPT
#
# Rule fw-ipv6-3 2 (global)
#
echo "Rule fw-ipv6-3 2 (global)"
#
# firewall-ipv6-3:fw-ipv6-3:2: error: Rule 'fw-ipv6-3 2 (global)' shadows rule 'fw-ipv6-3 3 (global)' below it
$IPTABLES -A OUTPUT -p icmp -m icmp --icmp-type any -m state --state NEW -j ACCEPT
$IPTABLES -A INPUT -p icmp -m icmp --icmp-type any -m state --state NEW -j ACCEPT
$IPTABLES -A FORWARD -p icmp -m icmp --icmp-type any -m state --state NEW -j ACCEPT
#
# Rule fw-ipv6-3 3 (global)
#
echo "Rule fw-ipv6-3 3 (global)"
#
$IPTABLES -A OUTPUT -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
$IPTABLES -A INPUT -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
$IPTABLES -A FORWARD -p icmp -m icmp --icmp-type 8/0 -m state --state NEW -j ACCEPT
#
# Rule fw-ipv6-3 4 (global)
#
echo "Rule fw-ipv6-3 4 (global)"
#
# INPUT, OUTPUT, FORWARD
# firewall-ipv6-3:fw-ipv6-3:4: error: Rule 'fw-ipv6-3 4 (global)' shadows rule 'fw-ipv6-3 6 (global)' below it
$IPTABLES -A INPUT -s 1.1.1.0/24 -m state --state NEW -j ACCEPT
$IPTABLES -A OUTPUT -s 1.1.1.0/24 -m state --state NEW -j ACCEPT
$IPTABLES -A FORWARD -s 1.1.1.0/24 -m state --state NEW -j ACCEPT
#
# Rule fw-ipv6-3 5 (global)
#
echo "Rule fw-ipv6-3 5 (global)"
#
# INPUT, OUTPUT, FORWARD
$IPTABLES -A OUTPUT -d 1.1.1.0/24 -m state --state NEW -j ACCEPT
$IPTABLES -A INPUT -d 1.1.1.0/24 -m state --state NEW -j ACCEPT
$IPTABLES -A FORWARD -d 1.1.1.0/24 -m state --state NEW -j ACCEPT
#
# Rule fw-ipv6-3 6 (global)
#
echo "Rule fw-ipv6-3 6 (global)"
#
# for bug 2047082
$IPTABLES -A OUTPUT -m state --state NEW -j ACCEPT
#
# Rule fw-ipv6-3 7 (global)
#
echo "Rule fw-ipv6-3 7 (global)"
#
$IPTABLES -A OUTPUT -d 6bone.net -m state --state NEW -j ACCEPT
$IPTABLES -A OUTPUT -d ny6ix.net -m state --state NEW -j ACCEPT
$IPTABLES -A FORWARD -d 6bone.net -m state --state NEW -j ACCEPT
$IPTABLES -A FORWARD -d ny6ix.net -m state --state NEW -j ACCEPT
#
# Rule fw-ipv6-3 8 (global)
#
echo "Rule fw-ipv6-3 8 (global)"
#
# firewall-ipv6-3:fw-ipv6-3:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
$IPTABLES -N fw-ipv6-3_8
$IPTABLES -A OUTPUT -d 192.0.2.1 -j fw-ipv6-3_8
$IPTABLES -A OUTPUT -d 207.251.84.150 -j fw-ipv6-3_8
$IPTABLES -A FORWARD -d 192.0.2.1 -j fw-ipv6-3_8
$IPTABLES -A FORWARD -d 207.251.84.150 -j fw-ipv6-3_8
$IPTABLES -A fw-ipv6-3_8 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 8 -- DENY " --ulog-qthreshold 1
$IPTABLES -A fw-ipv6-3_8 -j DROP
#
# Rule fw-ipv6-3 9 (global)
#
echo "Rule fw-ipv6-3 9 (global)"
#
# ipv4 address range for bug 2820152
$IPTABLES -N fw-ipv6-3_9
$IPTABLES -A OUTPUT -d 192.168.1.1 -j fw-ipv6-3_9
$IPTABLES -A OUTPUT -d 192.168.1.2/31 -j fw-ipv6-3_9
$IPTABLES -A OUTPUT -d 192.168.1.4/30 -j fw-ipv6-3_9
$IPTABLES -A OUTPUT -d 192.168.1.8/29 -j fw-ipv6-3_9
$IPTABLES -A OUTPUT -d 192.168.1.16/28 -j fw-ipv6-3_9
$IPTABLES -A OUTPUT -d 192.168.1.32/27 -j fw-ipv6-3_9
$IPTABLES -A OUTPUT -d 192.168.1.64/27 -j fw-ipv6-3_9
$IPTABLES -A OUTPUT -d 192.168.1.96/30 -j fw-ipv6-3_9
$IPTABLES -A OUTPUT -d 192.168.1.100 -j fw-ipv6-3_9
$IPTABLES -A FORWARD -d 192.168.1.1 -j fw-ipv6-3_9
$IPTABLES -A FORWARD -d 192.168.1.2/31 -j fw-ipv6-3_9
$IPTABLES -A FORWARD -d 192.168.1.4/30 -j fw-ipv6-3_9
$IPTABLES -A FORWARD -d 192.168.1.8/29 -j fw-ipv6-3_9
$IPTABLES -A FORWARD -d 192.168.1.16/28 -j fw-ipv6-3_9
$IPTABLES -A FORWARD -d 192.168.1.32/27 -j fw-ipv6-3_9
$IPTABLES -A FORWARD -d 192.168.1.64/27 -j fw-ipv6-3_9
$IPTABLES -A FORWARD -d 192.168.1.96/30 -j fw-ipv6-3_9
$IPTABLES -A FORWARD -d 192.168.1.100 -j fw-ipv6-3_9
$IPTABLES -A fw-ipv6-3_9 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 9 -- DENY " --ulog-qthreshold 1
$IPTABLES -A fw-ipv6-3_9 -j DROP
#
# Rule fw-ipv6-3 10 (global)
#
echo "Rule fw-ipv6-3 10 (global)"
#
# ipv4 address range for bug 2820152
$IPTABLES -N fw-ipv6-3_10
$IPTABLES -A OUTPUT -d 255.255.255.255 -j fw-ipv6-3_10
$IPTABLES -A INPUT -d 255.255.255.255 -j fw-ipv6-3_10
$IPTABLES -A fw-ipv6-3_10 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 10 -- DENY " --ulog-qthreshold 1
$IPTABLES -A fw-ipv6-3_10 -j DROP
#
# Rule fw-ipv6-3 11 (global)
#
echo "Rule fw-ipv6-3 11 (global)"
#
$IPTABLES -N fw-ipv6-3_11
$IPTABLES -A OUTPUT -j fw-ipv6-3_11
$IPTABLES -A INPUT -j fw-ipv6-3_11
$IPTABLES -A FORWARD -j fw-ipv6-3_11
$IPTABLES -A fw-ipv6-3_11 -j ULOG --ulog-nlgroup 1 --ulog-prefix "RULE 11 -- DENY " --ulog-qthreshold 1
$IPTABLES -A fw-ipv6-3_11 -j DROP
# ================ IPv6
# ================ Table 'filter', automatic rules
# accept established sessions
$IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
$IP6TABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
$IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
# drop packets that do not match any valid state and log them
$IP6TABLES -N drop_invalid
$IP6TABLES -A OUTPUT -m state --state INVALID -j drop_invalid
$IP6TABLES -A INPUT -m state --state INVALID -j drop_invalid
$IP6TABLES -A FORWARD -m state --state INVALID -j drop_invalid
$IP6TABLES -A drop_invalid -j LOG --log-level debug --log-prefix "INVALID state -- DENY "
$IP6TABLES -A drop_invalid -j DROP
# ================ Table 'filter', rule set fw-ipv6-3
#
# Rule fw-ipv6-3 0 (global)
#
echo "Rule fw-ipv6-3 0 (global)"
#
$IP6TABLES -N In_fw-ipv6-3_0
$IP6TABLES -A INPUT -m state --state NEW -j In_fw-ipv6-3_0
$IP6TABLES -A In_fw-ipv6-3_0 -j LOG --log-level info --log-prefix "RULE 0 -- ACCEPT "
$IP6TABLES -A In_fw-ipv6-3_0 -j ACCEPT
#
# Rule fw-ipv6-3 6 (global)
#
echo "Rule fw-ipv6-3 6 (global)"
#
# for bug 2047082
$IP6TABLES -A OUTPUT -m state --state NEW -j ACCEPT
#
# Rule fw-ipv6-3 7 (global)
#
echo "Rule fw-ipv6-3 7 (global)"
#
$IP6TABLES -A OUTPUT -d 6bone.net -m state --state NEW -j ACCEPT
$IP6TABLES -A OUTPUT -d ny6ix.net -m state --state NEW -j ACCEPT
$IP6TABLES -A FORWARD -d 6bone.net -m state --state NEW -j ACCEPT
$IP6TABLES -A FORWARD -d ny6ix.net -m state --state NEW -j ACCEPT
#
# Rule fw-ipv6-3 8 (global)
#
echo "Rule fw-ipv6-3 8 (global)"
#
# firewall-ipv6-3:fw-ipv6-3:8: error: DNSName object "6bone.net (ct)" (compile time) can not resolve dns name "6bone.net" (AF_INET6): Host or network '6bone.net' not found; last error: Unknown error Using dummy address in test mode
$IP6TABLES -N fw-ipv6-3_8
$IP6TABLES -A OUTPUT -d 2001:db8::1 -j fw-ipv6-3_8
$IP6TABLES -A FORWARD -d 2001:db8::1 -j fw-ipv6-3_8
$IP6TABLES -A fw-ipv6-3_8 -j LOG --log-level info --log-prefix "RULE 8 -- DENY "
$IP6TABLES -A fw-ipv6-3_8 -j DROP
#
# Rule fw-ipv6-3 11 (global)
#
echo "Rule fw-ipv6-3 11 (global)"
#
$IP6TABLES -N fw-ipv6-3_11
$IP6TABLES -A OUTPUT -j fw-ipv6-3_11
$IP6TABLES -A INPUT -j fw-ipv6-3_11
$IP6TABLES -A FORWARD -j fw-ipv6-3_11
$IP6TABLES -A fw-ipv6-3_11 -j LOG --log-level info --log-prefix "RULE 11 -- DENY "
$IP6TABLES -A fw-ipv6-3_11 -j DROP
}
ip_forward() {
:
echo 1 > /proc/sys/net/ipv4/ip_forward
echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
}
reset_all() {
:
reset_iptables_v4
reset_iptables_v6
}
block_action() {
reset_all
}
stop_action() {
reset_all
$IPTABLES -P OUTPUT ACCEPT
$IPTABLES -P INPUT ACCEPT
$IPTABLES -P FORWARD ACCEPT
$IP6TABLES -P OUTPUT ACCEPT
$IP6TABLES -P INPUT ACCEPT
$IP6TABLES -P FORWARD ACCEPT
}
check_iptables() {
IP_TABLES="$1"
[ ! -e $IP_TABLES ] && return 151
NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
[ -z "$NF_TABLES" ] && return 152
return 0
}
status_action() {
check_iptables "/proc/net/ip_tables_names"
ret_ipv4=$?
check_iptables "/proc/net/ip6_tables_names"
ret_ipv6=$?
[ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
[ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
echo "iptables modules are not loaded"
}
[ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
echo "Firewall is not configured"
}
exit 3
}
# See how we were called.
# For backwards compatibility missing argument is equivalent to 'start'
cmd=$1
test -z "$cmd" && {
cmd="start"
}
case "$cmd" in
start)
log "Activating firewall script generated Sat Mar 12 19:42:24 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files
load_modules "nat ipv6"
configure_interfaces
verify_interfaces
reset_all
script_body
ip_forward
epilog_commands
RETVAL=$?
;;
stop)
stop_action
RETVAL=$?
;;
status)
status_action
RETVAL=$?
;;
block)
block_action
RETVAL=$?
;;
reload)
$0 stop
$0 start
RETVAL=$?
;;
interfaces)
configure_interfaces
RETVAL=$?
;;
test_interfaces)
FWBDEBUG="echo"
configure_interfaces
RETVAL=$?
;;
*)
echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
;;
esac
exit $RETVAL