]> git.ipfire.org Git - people/teissler/ipfire-2.x.git/blobdiff - html/cgi-bin/forwardfw.cgi
Forward Firewall: Edited Backup.pl so that any old backups get converted to new firew...
[people/teissler/ipfire-2.x.git] / html / cgi-bin / forwardfw.cgi
index 6aadb996b428ed02767d02ee16104063600f336a..b2976e1c352b68c695613a6081072390773c52d8 100755 (executable)
@@ -68,6 +68,7 @@ my %icmptypes=();
 my %ovpnsettings=();
 my %ipsecsettings=();
 my %aliases=();
+my @p2ps = ();
 my $color;
 my $confignet          = "${General::swroot}/fwhosts/customnetworks";
 my $confighost         = "${General::swroot}/fwhosts/customhosts";
@@ -81,7 +82,7 @@ my $configipsecrw     = "${General::swroot}/vpn/settings";
 my $configfwdfw                = "${General::swroot}/forward/config";
 my $configinput                = "${General::swroot}/forward/input";
 my $configovpn         = "${General::swroot}/ovpn/settings";
-
+my $p2pfile                    = "${General::swroot}/forward/p2protocols";
 my $errormessage='';
 my $hint='';
 my $ipgrp="${General::swroot}/outgoing/groups";
@@ -112,7 +113,6 @@ if ($fwdfwsettings{'ACTION'} eq 'saverule')
        $errormessage=&checksource;
        if(!$errormessage){&checktarget;}
        if(!$errormessage){&checkrule;}
-
        #check if we change an forward rule to an external access
        if(     $fwdfwsettings{'grp2'} eq 'ipfire' && $fwdfwsettings{'oldgrp2a'} ne 'ipfire' && $fwdfwsettings{'updatefwrule'} eq 'on'){
                $fwdfwsettings{'updatefwrule'}='';
@@ -122,7 +122,6 @@ if ($fwdfwsettings{'ACTION'} eq 'saverule')
                &checkcounter(0,0,$fwdfwsettings{'grp1'},$fwdfwsettings{$fwdfwsettings{'grp1'}});
                &checkcounter(0,0,$fwdfwsettings{'grp3'},$fwdfwsettings{$fwdfwsettings{'grp3'}});
        }
-
        #check if we change an external access rule to an forward
        if(     $fwdfwsettings{'grp2'} ne 'ipfire' && $fwdfwsettings{'oldgrp2a'} eq 'ipfire' && $fwdfwsettings{'updatefwrule'} eq 'on'){
                $fwdfwsettings{'updatefwrule'}='';
@@ -136,13 +135,27 @@ if ($fwdfwsettings{'ACTION'} eq 'saverule')
        if($fwdfwsettings{'grp2'} eq 'ipfire'){
                $fwdfwsettings{'chain'} = 'INPUTFW';
                #check if we have an identical rule already
-               foreach my $key (sort keys %configinputfw){
-                       if ("$fwdfwsettings{'RULE_ACTION'},$fwdfwsettings{'ACTIVE'},$fwdfwsettings{'grp1'},$fwdfwsettings{$fwdfwsettings{'grp1'}},$fwdfwsettings{'grp2'},$fwdfwsettings{$fwdfwsettings{'grp2'}},$fwdfwsettings{'USE_SRC_PORT'},$fwdfwsettings{'PROT'},$fwdfwsettings{'ICMP_TYPES'},$fwdfwsettings{'SRC_PORT'},$fwdfwsettings{'USESRV'},$fwdfwsettings{'TGT_PROT'},$fwdfwsettings{'ICMP_TGT'},$fwdfwsettings{'grp3'},$fwdfwsettings{$fwdfwsettings{'grp3'}},$fwdfwsettings{'ruleremark'},$fwdfwsettings{'LOG'},$fwdfwsettings{'TIME'},$fwdfwsettings{'TIME_MON'},$fwdfwsettings{'TIME_TUE'},$fwdfwsettings{'TIME_WED'},$fwdfwsettings{'TIME_THU'},$fwdfwsettings{'TIME_FRI'},$fwdfwsettings{'TIME_SAT'},$fwdfwsettings{'TIME_SUN'},$fwdfwsettings{'TIME_FROM'},$fwdfwsettings{'TIME_TO'}" 
-                               eq "$configinputfw{$key}[0],$configinputfw{$key}[2],$configinputfw{$key}[3],$configinputfw{$key}[4],$configinputfw{$key}[5],$configinputfw{$key}[6],$configinputfw{$key}[7],$configinputfw{$key}[8],$configinputfw{$key}[9],$configinputfw{$key}[10],$configinputfw{$key}[11],$configinputfw{$key}[12],$configinputfw{$key}[13],$configinputfw{$key}[14],$configinputfw{$key}[15],$configinputfw{$key}[16],$configinputfw{$key}[17],$configinputfw{$key}[18],$configinputfw{$key}[19],$configinputfw{$key}[20],$configinputfw{$key}[21],$configinputfw{$key}[22],$configinputfw{$key}[23],$configinputfw{$key}[24],$configinputfw{$key}[25],$configinputfw{$key}[26],$configinputfw{$key}[27]"){
-                                       $errormessage.=$Lang::tr{'fwdfw err ruleexists'};
+               if($fwdfwsettings{'oldrulenumer'} eq $fwdfwsettings{'rulepos'}){
+                       foreach my $key (sort keys %configinputfw){
+                               if ("$fwdfwsettings{'RULE_ACTION'},$fwdfwsettings{'ACTIVE'},$fwdfwsettings{'grp1'},$fwdfwsettings{$fwdfwsettings{'grp1'}},$fwdfwsettings{'grp2'},$fwdfwsettings{$fwdfwsettings{'grp2'}},$fwdfwsettings{'USE_SRC_PORT'},$fwdfwsettings{'PROT'},$fwdfwsettings{'ICMP_TYPES'},$fwdfwsettings{'SRC_PORT'},$fwdfwsettings{'USESRV'},$fwdfwsettings{'TGT_PROT'},$fwdfwsettings{'ICMP_TGT'},$fwdfwsettings{'grp3'},$fwdfwsettings{$fwdfwsettings{'grp3'}},$fwdfwsettings{'LOG'},$fwdfwsettings{'TIME'},$fwdfwsettings{'TIME_MON'},$fwdfwsettings{'TIME_TUE'},$fwdfwsettings{'TIME_WED'},$fwdfwsettings{'TIME_THU'},$fwdfwsettings{'TIME_FRI'},$fwdfwsettings{'TIME_SAT'},$fwdfwsettings{'TIME_SUN'},$fwdfwsettings{'TIME_FROM'},$fwdfwsettings{'TIME_TO'}" 
+                                       eq "$configinputfw{$key}[0],$configinputfw{$key}[2],$configinputfw{$key}[3],$configinputfw{$key}[4],$configinputfw{$key}[5],$configinputfw{$key}[6],$configinputfw{$key}[7],$configinputfw{$key}[8],$configinputfw{$key}[9],$configinputfw{$key}[10],$configinputfw{$key}[11],$configinputfw{$key}[12],$configinputfw{$key}[13],$configinputfw{$key}[14],$configinputfw{$key}[15],$configinputfw{$key}[17],$configinputfw{$key}[18],$configinputfw{$key}[19],$configinputfw{$key}[20],$configinputfw{$key}[21],$configinputfw{$key}[22],$configinputfw{$key}[23],$configinputfw{$key}[24],$configinputfw{$key}[25],$configinputfw{$key}[26],$configinputfw{$key}[27]"){
+                                               $errormessage.=$Lang::tr{'fwdfw err ruleexists'};
+                                               if ($fwdfwsettings{'oldruleremark'} ne $fwdfwsettings{'ruleremark'} && $fwdfwsettings{'updatefwrule'} eq 'on'){
+                                                       $errormessage='';
+                                               }
+                                               if ($fwdfwsettings{'oldruleremark'} eq $fwdfwsettings{'ruleremark'}){
+                                                       $fwdfwsettings{'nosave'} = 'on';
+                                               }
+                               }       
                        }       
-               }       
-
+               }
+               #check if we just close a rule
+               if( $fwdfwsettings{'oldgrp1a'} eq  $fwdfwsettings{'grp1'} && $fwdfwsettings{'oldgrp1b'} eq $fwdfwsettings{$fwdfwsettings{'grp1'}} && $fwdfwsettings{'oldgrp2a'} eq  $fwdfwsettings{'grp2'} && $fwdfwsettings{'oldgrp2b'} eq $fwdfwsettings{$fwdfwsettings{'grp2'}} &&  $fwdfwsettings{'oldgrp3a'} eq $fwdfwsettings{'grp3'} && $fwdfwsettings{'oldgrp3b'} eq  $fwdfwsettings{$fwdfwsettings{'grp3'}} && $fwdfwsettings{'oldusesrv'} eq $fwdfwsettings{'USESRV'} ) {
+                       if($fwdfwsettings{'nosave'} eq 'on' && $fwdfwsettings{'updatefwrule'} eq 'on'){
+                               $errormessage='';
+                               $fwdfwsettings{'nosave2'} = 'on';
+                       }
+               }
                &checkcounter($fwdfwsettings{'oldgrp1a'},$fwdfwsettings{'oldgrp1b'},$fwdfwsettings{'grp1'},$fwdfwsettings{$fwdfwsettings{'grp1'}});
                if ($fwdfwsettings{'nobase'} ne 'on'){
                        &checkcounter($fwdfwsettings{'oldgrp2a'},$fwdfwsettings{'oldgrp2b'},$fwdfwsettings{'grp2'},$fwdfwsettings{$fwdfwsettings{'grp2'}});
@@ -154,8 +167,9 @@ if ($fwdfwsettings{'ACTION'} eq 'saverule')
                }elsif ($fwdfwsettings{'oldusesrv'} eq $fwdfwsettings{'USESRV'} && $fwdfwsettings{'oldgrp3b'} ne $fwdfwsettings{$fwdfwsettings{'grp3'}} && $fwdfwsettings{'updatefwrule'} eq 'on'){
                        &checkcounter($fwdfwsettings{'oldgrp3a'},$fwdfwsettings{'oldgrp3b'},$fwdfwsettings{'grp3'},$fwdfwsettings{$fwdfwsettings{'grp3'}});
                }
-
-               &saverule(\%configinputfw,$configinput);
+               if($fwdfwsettings{'nosave2'} ne 'on'){
+                       &saverule(\%configinputfw,$configinput);
+               }
                #print "Source: $fwdfwsettings{'grp1'} -> $fwdfwsettings{$fwdfwsettings{'grp1'}}<br>";
                #print "Sourceport: $fwdfwsettings{'USE_SRC_PORT'}, $fwdfwsettings{'PROT'}, $fwdfwsettings{'ICMP_TYPES'}, $fwdfwsettings{'SRC_PORT'}<br>";
                #print "Target: $fwdfwsettings{'grp2'} -> $fwdfwsettings{$fwdfwsettings{'grp2'}}<br>";
@@ -178,20 +192,33 @@ if ($fwdfwsettings{'ACTION'} eq 'saverule')
                #print"ALT: $fwdfwsettings{'oldgrp3a'} $fwdfwsettings{'oldgrp3b'}       NEU:    $fwdfwsettings{'grp3'} $fwdfwsettings{$fwdfwsettings{'grp3'}}<br>";
                #print"DIENSTE Checkalt:$fwdfwsettings{'oldusesrv'}  DIENSTE Checkneu:$fwdfwsettings{'USESRV'}    DIENST ALT:$fwdfwsettings{'oldgrp3a'},$fwdfwsettings{'oldgrp3b'}   DIENST NEU:$fwdfwsettings{'grp3'},$fwdfwsettings{$fwdfwsettings{'grp3'}}<br>";
        }else{
+               #FORWARD PART
                $fwdfwsettings{'chain'} = 'FORWARDFW';
-               #check if we have an identical rule already
-               foreach my $key (sort keys %configfwdfw){
-                                       
-                       if ("$fwdfwsettings{'RULE_ACTION'},$fwdfwsettings{'ACTIVE'},$fwdfwsettings{'grp1'},$fwdfwsettings{$fwdfwsettings{'grp1'}},$fwdfwsettings{'grp2'},$fwdfwsettings{$fwdfwsettings{'grp2'}},$fwdfwsettings{'USE_SRC_PORT'},$fwdfwsettings{'PROT'},$fwdfwsettings{'ICMP_TYPES'},$fwdfwsettings{'SRC_PORT'},$fwdfwsettings{'USESRV'},$fwdfwsettings{'TGT_PROT'},$fwdfwsettings{'ICMP_TGT'},$fwdfwsettings{'grp3'},$fwdfwsettings{$fwdfwsettings{'grp3'}},$fwdfwsettings{'ruleremark'},$fwdfwsettings{'LOG'},$fwdfwsettings{'TIME'},$fwdfwsettings{'TIME_MON'},$fwdfwsettings{'TIME_TUE'},$fwdfwsettings{'TIME_WED'},$fwdfwsettings{'TIME_THU'},$fwdfwsettings{'TIME_FRI'},$fwdfwsettings{'TIME_SAT'},$fwdfwsettings{'TIME_SUN'},$fwdfwsettings{'TIME_FROM'},$fwdfwsettings{'TIME_TO'}" 
-                               eq "$configfwdfw{$key}[0],$configfwdfw{$key}[2],$configfwdfw{$key}[3],$configfwdfw{$key}[4],$configfwdfw{$key}[5],$configfwdfw{$key}[6],$configfwdfw{$key}[7],$configfwdfw{$key}[8],$configfwdfw{$key}[9],$configfwdfw{$key}[10],$configfwdfw{$key}[11],$configfwdfw{$key}[12],$configfwdfw{$key}[13],$configfwdfw{$key}[14],$configfwdfw{$key}[15],$configfwdfw{$key}[16],$configfwdfw{$key}[17],$configfwdfw{$key}[18],$configfwdfw{$key}[19],$configfwdfw{$key}[20],$configfwdfw{$key}[21],$configfwdfw{$key}[22],$configfwdfw{$key}[23],$configfwdfw{$key}[24],$configfwdfw{$key}[25],$configfwdfw{$key}[26],$configfwdfw{$key}[27]"){
-                                       $errormessage.=$Lang::tr{'fwdfw err ruleexists'};
-                       }               
+               if($fwdfwsettings{'oldrulenumber'} eq $fwdfwsettings{'rulepos'}){
+                       #check if we have an identical rule already
+                       foreach my $key (sort keys %configfwdfw){
+                               if ("$fwdfwsettings{'RULE_ACTION'},$fwdfwsettings{'ACTIVE'},$fwdfwsettings{'grp1'},$fwdfwsettings{$fwdfwsettings{'grp1'}},$fwdfwsettings{'grp2'},$fwdfwsettings{$fwdfwsettings{'grp2'}},$fwdfwsettings{'USE_SRC_PORT'},$fwdfwsettings{'PROT'},$fwdfwsettings{'ICMP_TYPES'},$fwdfwsettings{'SRC_PORT'},$fwdfwsettings{'USESRV'},$fwdfwsettings{'TGT_PROT'},$fwdfwsettings{'ICMP_TGT'},$fwdfwsettings{'grp3'},$fwdfwsettings{$fwdfwsettings{'grp3'}},$fwdfwsettings{'LOG'},$fwdfwsettings{'TIME'},$fwdfwsettings{'TIME_MON'},$fwdfwsettings{'TIME_TUE'},$fwdfwsettings{'TIME_WED'},$fwdfwsettings{'TIME_THU'},$fwdfwsettings{'TIME_FRI'},$fwdfwsettings{'TIME_SAT'},$fwdfwsettings{'TIME_SUN'},$fwdfwsettings{'TIME_FROM'},$fwdfwsettings{'TIME_TO'}" 
+                                       eq "$configfwdfw{$key}[0],$configfwdfw{$key}[2],$configfwdfw{$key}[3],$configfwdfw{$key}[4],$configfwdfw{$key}[5],$configfwdfw{$key}[6],$configfwdfw{$key}[7],$configfwdfw{$key}[8],$configfwdfw{$key}[9],$configfwdfw{$key}[10],$configfwdfw{$key}[11],$configfwdfw{$key}[12],$configfwdfw{$key}[13],$configfwdfw{$key}[14],$configfwdfw{$key}[15],$configfwdfw{$key}[17],$configfwdfw{$key}[18],$configfwdfw{$key}[19],$configfwdfw{$key}[20],$configfwdfw{$key}[21],$configfwdfw{$key}[22],$configfwdfw{$key}[23],$configfwdfw{$key}[24],$configfwdfw{$key}[25],$configfwdfw{$key}[26],$configfwdfw{$key}[27]"){
+                                               $errormessage.=$Lang::tr{'fwdfw err ruleexists'};
+                                               if ($fwdfwsettings{'oldruleremark'} ne $fwdfwsettings{'ruleremark'} && $fwdfwsettings{'updatefwrule'} eq 'on'){
+                                                       $errormessage='';
+                                               }
+                                               if ($fwdfwsettings{'oldruleremark'} eq $fwdfwsettings{'ruleremark'}){
+                                                       $fwdfwsettings{'nosave'} = 'on';
+                                               }
+                               }               
+                       }
                }       
+               #check if we just close a rule
+               if( $fwdfwsettings{'oldgrp1a'} eq  $fwdfwsettings{'grp1'} && $fwdfwsettings{'oldgrp1b'} eq $fwdfwsettings{$fwdfwsettings{'grp1'}} && $fwdfwsettings{'oldgrp2a'} eq  $fwdfwsettings{'grp2'} && $fwdfwsettings{'oldgrp2b'} eq $fwdfwsettings{$fwdfwsettings{'grp2'}} &&  $fwdfwsettings{'oldgrp3a'} eq $fwdfwsettings{'grp3'} && $fwdfwsettings{'oldgrp3b'} eq  $fwdfwsettings{$fwdfwsettings{'grp3'}} && $fwdfwsettings{'oldusesrv'} eq $fwdfwsettings{'USESRV'} ) {
+                       if($fwdfwsettings{'nosave'} eq 'on' && $fwdfwsettings{'updatefwrule'} eq 'on'){
+                               $fwdfwsettings{'nosave2'} = 'on';
+                               $errormessage='';
+                       }
+               }
                #increase counters
                &checkcounter($fwdfwsettings{'oldgrp1a'},$fwdfwsettings{'oldgrp1b'},$fwdfwsettings{'grp1'},$fwdfwsettings{$fwdfwsettings{'grp1'}});
-
                &checkcounter($fwdfwsettings{'oldgrp2a'},$fwdfwsettings{'oldgrp2b'},$fwdfwsettings{'grp2'},$fwdfwsettings{$fwdfwsettings{'grp2'}});
-
                if($fwdfwsettings{'oldusesrv'} eq '' &&  $fwdfwsettings{'USESRV'} eq 'ON'){
                        &checkcounter(0,0,$fwdfwsettings{'grp3'},$fwdfwsettings{$fwdfwsettings{'grp3'}});
                }elsif ($fwdfwsettings{'USESRV'} eq '' && $fwdfwsettings{'oldusesrv'} eq 'ON') {
@@ -202,8 +229,9 @@ if ($fwdfwsettings{'ACTION'} eq 'saverule')
                if ($fwdfwsettings{'nobase'} eq 'on'){
                        &checkcounter(0,0,$fwdfwsettings{'grp3'},$fwdfwsettings{$fwdfwsettings{'grp3'}});
                }
-               &saverule(\%configfwdfw,$configfwdfw);
-
+               if ($fwdfwsettings{'nosave2'} ne 'on'){
+                       &saverule(\%configfwdfw,$configfwdfw);
+               }       
                #print "Source: $fwdfwsettings{'grp1'} -> $fwdfwsettings{$fwdfwsettings{'grp1'}}<br>";
                #print "Sourceport: $fwdfwsettings{'USE_SRC_PORT'}, $fwdfwsettings{'PROT'}, $fwdfwsettings{'ICMP_TYPES'}, $fwdfwsettings{'SRC_PORT'}<br>";
                #print "Target: $fwdfwsettings{'grp2'} -> $fwdfwsettings{$fwdfwsettings{'grp2'}}<br>";
@@ -229,7 +257,9 @@ if ($fwdfwsettings{'ACTION'} eq 'saverule')
        if ($errormessage){
                &newrule;
        }else{
-               &rules;
+               if($fwdfwsettings{'nosave2'} ne 'on'){
+                       &rules;
+               }
                &base;
        }
 }
@@ -317,6 +347,29 @@ if ($fwdfwsettings{'ACTION'} eq 'copyrule')
        #$fwdfwsettings{'updatefwrule'}='on';
        &newrule;
 }
+if ($fwdfwsettings{'ACTION'} eq 'togglep2p')
+{
+       #$errormessage="Toggle $fwdfwsettings{'P2PROT'}<br>";
+       open( FILE, "< $p2pfile" ) or die "Unable to read $p2pfile";
+       @p2ps = <FILE>;
+       close FILE;
+       open( FILE, "> $p2pfile" ) or die "Unable to write $p2pfile";
+       foreach my $p2pentry (sort @p2ps)
+       {
+               my @p2pline = split( /\;/, $p2pentry );
+               if ($p2pline[1] eq $fwdfwsettings{'P2PROT'}) {
+                       if($p2pline[2] eq 'on'){
+                               $p2pline[2]='off';
+                       }else{
+                               $p2pline[2]='on';
+                       }
+               }
+               print FILE "$p2pline[0];$p2pline[1];$p2pline[2];\n";
+       }
+       close FILE;
+       &rules;
+       &base;
+}
 if ($fwdfwsettings{'ACTION'} eq '')
 {
        &base;
@@ -453,6 +506,9 @@ sub base
                #print"<td bgcolor='$color{$i}'>$_</td>";
        #}
        #print"</tr></table>";
+       if ($fwdfwsettings{'POLICY'} eq 'MODE1' || $fwdfwsettings{'POLICY'} eq 'MODE2' ) {
+               &p2pblock;
+       }
        &Header::openbox('100%', 'center', 'Policy');
 print <<END;
        <form method='post' action='$ENV{'SCRIPT_NAME'}'>
@@ -462,13 +518,13 @@ print <<END;
                <tr><td width='10%' align='left'><b>$Lang::tr{'mode'} 2:</b><td width='90%' align='left' colspan='2'>$Lang::tr{'outgoing firewall mode2'}</td></tr>
                <tr><td colspan='3'><hr /></td></tr>
                <tr><td width='10%' align='left'>       <select name='POLICY' style="width: 85px"><option value='MODE0' $selected{'POLICY'}{'MODE0'}>$Lang::tr{'mode'} 0</option><option value='MODE1' $selected{'POLICY'}{'MODE1'}>$Lang::tr{'mode'} 1</option><option value='MODE2' $selected{'POLICY'}{'MODE2'}>$Lang::tr{'mode'} 2</option></select>
-                   <td width='45%' align='left'><input type='submit' name='ACTION' value=$Lang::tr{'save'} />
-                   <td width='45%' align='left'>
+           <td width='45%' align='left'><input type='submit' name='ACTION' value=$Lang::tr{'save'} />
+           <td width='45%' align='left'>
 END
        if ($fwdfwsettings{'POLICY'} ne 'MODE0'&& $fwdfwsettings{'POLICY'} ne '' ) {
                print "$Lang::tr{'outgoing firewall reset'}: <input type='submit' name='ACTION' value='$Lang::tr{'reset'}' />";
        }
-print "</table></form>";
+       print "</table></form>";
        &Header::closebox();
 }
 sub addrule
@@ -491,9 +547,8 @@ sub deleterule
 {
        my %delhash=();
        &General::readhasharray($fwdfwsettings{'config'}, \%delhash);
-       foreach my $key (sort keys %delhash){
-               
-               if ($key eq $fwdfwsettings{'key'}){
+       foreach my $key (sort {$a <=> $b} keys %delhash){
+               if ($key == $fwdfwsettings{'key'}){
                        #check hosts/net and groups
                        &checkcounter($delhash{$key}[3],$delhash{$key}[4],,);
                        &checkcounter($delhash{$key}[5],$delhash{$key}[6],,);
@@ -502,7 +557,7 @@ sub deleterule
                                &checkcounter($delhash{$key}[14],$delhash{$key}[15],,);
                        }
                }
-               if ($key ge $fwdfwsettings{'key'}) {
+               if ($key >= $fwdfwsettings{'key'}) {
                        my $next = $key + 1;
                        if (exists $delhash{$next}) {
                                foreach my $i (0 .. $#{$delhash{$next}}) {
@@ -512,7 +567,7 @@ sub deleterule
                }
        }
        # Remove the very last entry.
-       my $last_key = (sort keys %delhash)[-1];
+       my $last_key = (sort {$a <=> $b} keys %delhash)[-1];
        delete $delhash{$last_key};
 
        &General::writehasharray($fwdfwsettings{'config'}, \%delhash);
@@ -537,31 +592,42 @@ sub disable_rule
 sub checksource
 {
        my ($ip,$subnet);
-       
+
        #check ip-address if manual
        if ($fwdfwsettings{'src_addr'} eq $fwdfwsettings{$fwdfwsettings{'grp1'}} && $fwdfwsettings{'src_addr'} ne ''){
                #check if ip with subnet
                if ($fwdfwsettings{'src_addr'} =~ /^(.*?)\/(.*?)$/) {
                        ($ip,$subnet)=split (/\//,$fwdfwsettings{'src_addr'});
                        $subnet = &General::iporsubtocidr($subnet);
+                       $fwdfwsettings{'isip'}='on';
                }
                #check if only ip
                if($fwdfwsettings{'src_addr'}=~/^(\d{1,3})\.(\d{1,3})\.(\d{1,3})\.(\d{1,3})$/){
                        $ip=$fwdfwsettings{'src_addr'};
                        $subnet = '32';
+                       $fwdfwsettings{'isip'}='on';
                }
-               #check and form valid IP
-               $ip=&General::ip2dec($ip);
-               $ip=&General::dec2ip($ip);
-               #check if net or broadcast
-               my @tmp= split (/\./,$ip);
-               if (($tmp[3] eq "0") || ($tmp[3] eq "255"))
-               {
-                       $errormessage=$Lang::tr{'fwhost err hostip'}."<br>";
+
+               if ($fwdfwsettings{'isip'} ne 'on'){
+                       if (&General::validmac($fwdfwsettings{'src_addr'})){$fwdfwsettings{'ismac'}='on';}
                }
-               $fwdfwsettings{'src_addr'}="$ip/$subnet";
-                               
-               if(!&General::validipandmask($fwdfwsettings{'src_addr'})){
+               if ($fwdfwsettings{'isip'} eq 'on'){
+                       #check and form valid IP
+                       $ip=&General::ip2dec($ip);
+                       $ip=&General::dec2ip($ip);
+                       #check if net or broadcast
+                       my @tmp= split (/\./,$ip);
+                       if (($tmp[3] eq "0") || ($tmp[3] eq "255"))
+                       {
+                               $errormessage=$Lang::tr{'fwhost err hostip'}."<br>";
+                       }
+                       $fwdfwsettings{'src_addr'}="$ip/$subnet";
+
+                       if(!&General::validipandmask($fwdfwsettings{'src_addr'})){
+                               $errormessage.=$Lang::tr{'fwdfw err src_addr'}."<br>";
+                       }
+               }
+               if ($fwdfwsettings{'isip'} ne 'on' && $fwdfwsettings{'ismac'} ne 'on'){
                        $errormessage.=$Lang::tr{'fwdfw err src_addr'}."<br>";
                }
        }elsif($fwdfwsettings{'src_addr'} eq $fwdfwsettings{$fwdfwsettings{'grp1'}} && $fwdfwsettings{'src_addr'} eq ''){
@@ -586,6 +652,9 @@ sub checksource
                }elsif($fwdfwsettings{'USE_SRC_PORT'} eq 'ON' && $fwdfwsettings{'PROT'} eq 'ESP'){
                        $fwdfwsettings{'SRC_PORT'}='';
                        $fwdfwsettings{'ICMP_TYPES'}='';
+               }elsif($fwdfwsettings{'USE_SRC_PORT'} eq 'ON' && $fwdfwsettings{'PROT'} eq 'AH'){
+                       $fwdfwsettings{'SRC_PORT'}='';
+                       $fwdfwsettings{'ICMP_TYPES'}='';        
                }elsif($fwdfwsettings{'USE_SRC_PORT'} eq 'ON' && $fwdfwsettings{'PROT'} ne 'ICMP'){
                        $fwdfwsettings{'ICMP_TYPES'}='';
                }else{
@@ -630,7 +699,7 @@ sub checktarget
                #check and form valid IP
                $ip=&General::ip2dec($ip);
                $ip=&General::dec2ip($ip);
-               
+
                #check if net or broadcast
                my @tmp= split (/\./,$ip);
                if (($tmp[3] eq "0") || ($tmp[3] eq "255"))
@@ -666,7 +735,7 @@ sub checktarget
                        }
                }
                if ($fwdfwsettings{'grp3'} eq 'TGT_PORT'){
-                       if ($fwdfwsettings{'TGT_PROT'} ne 'ICMP' && $fwdfwsettings{'TGT_PROT'} ne 'GRE'){
+                       if ($fwdfwsettings{'TGT_PROT'} eq 'TCP' || $fwdfwsettings{'TGT_PROT'} eq 'UDP'){
                                if ($fwdfwsettings{'TGT_PORT'} ne ''){
                                        #change dashes with :
                                        $fwdfwsettings{'TGT_PORT'}=~ tr/-/:/;
@@ -682,12 +751,19 @@ sub checktarget
                                        $errormessage .= &General::validportrange($fwdfwsettings{'TGT_PORT'}, 'destination');
                                }
                        }elsif ($fwdfwsettings{'TGT_PROT'} eq 'GRE'){
+                                       $fwdfwsettings{$fwdfwsettings{'grp3'}} = '';
                                        $fwdfwsettings{'TGT_PORT'} = '';
                                        $fwdfwsettings{'ICMP_TGT'} = '';
-                       }elsif($fwdfwsettings{'TGT_PORT'} eq 'ESP'){
-                                       $fwdfwsettings{'TGT_PORT'}='';
+                       }elsif($fwdfwsettings{'TGT_PROT'} eq 'ESP'){
+                                       $fwdfwsettings{$fwdfwsettings{'grp3'}} = '';
+                                       $fwdfwsettings{'TGT_PORT'} = '';
+                                       $fwdfwsettings{'ICMP_TGT'}='';
+                       }elsif($fwdfwsettings{'TGT_PROT'} eq 'AH'){
+                                       $fwdfwsettings{$fwdfwsettings{'grp3'}} = '';
+                                       $fwdfwsettings{'TGT_PORT'} = '';
                                        $fwdfwsettings{'ICMP_TGT'}='';
                        }elsif ($fwdfwsettings{'TGT_PROT'} eq 'ICMP'){
+                               $fwdfwsettings{$fwdfwsettings{'grp3'}} = '';
                                $fwdfwsettings{'TGT_PORT'} = '';
                                &General::readhasharray("${General::swroot}/fwhosts/icmp-types", \%icmptypes);
                                foreach my $key (keys %icmptypes){
@@ -706,6 +782,7 @@ sub checktarget
                $fwdfwsettings{$fwdfwsettings{'grp3'}}='';
                $fwdfwsettings{'TGT_PROT'}='';
                $fwdfwsettings{'ICMP_TGT'}='';
+
        }
        #check timeframe
        if($fwdfwsettings{'TIME'} eq 'ON'){
@@ -722,7 +799,7 @@ sub checkrule
                $errormessage.=$Lang::tr{'fwdfw err remark'}."<br>";
        }
        #check if source and target identical
-       if ($fwdfwsettings{$fwdfwsettings{'grp1'}} eq $fwdfwsettings{$fwdfwsettings{'grp2'}}){
+       if ($fwdfwsettings{$fwdfwsettings{'grp1'}} eq $fwdfwsettings{$fwdfwsettings{'grp2'}} && $fwdfwsettings{$fwdfwsettings{'grp1'}} ne 'ALL'){
                $errormessage.=$Lang::tr{'fwdfw err same'};
                return $errormessage;
        }
@@ -839,6 +916,7 @@ sub newrule
        &General::get_aliases(\%aliases);
        my %checked=();
        my $helper;
+       my $sum=0;
        if($fwdfwsettings{'config'} eq ''){$fwdfwsettings{'config'}=$configfwdfw;}
        my $config=$fwdfwsettings{'config'};
        my %hash=();
@@ -864,7 +942,9 @@ sub newrule
        if($fwdfwsettings{'updatefwrule'} eq 'on' || $fwdfwsettings{'copyfwrule'} eq 'on' && !$errormessage){
                &General::readhasharray("$config", \%hash);
                foreach my $key (sort keys %hash){
+                       $sum++;
                        if ($key eq $fwdfwsettings{'key'}){
+                               $fwdfwsettings{'oldrulenumber'}                 = $key;
                                $fwdfwsettings{'RULE_ACTION'}                   = $hash{$key}[0];
                                $fwdfwsettings{'ACTIVE'}                                = $hash{$key}[2];
                                $fwdfwsettings{'grp1'}                                  = $hash{$key}[3];   
@@ -919,6 +999,7 @@ sub newrule
                $fwdfwsettings{'oldgrp3a'}=$fwdfwsettings{'grp3'};
                $fwdfwsettings{'oldgrp3b'}=$fwdfwsettings{$fwdfwsettings{'grp3'}};
                $fwdfwsettings{'oldusesrv'}=$fwdfwsettings{'USESRV'};
+               $fwdfwsettings{'oldruleremark'}=$fwdfwsettings{'ruleremark'};
        }else{
                $fwdfwsettings{'ACTIVE'}='ON';
                $checked{'ACTIVE'}{$fwdfwsettings{'ACTIVE'}} = 'CHECKED';
@@ -933,24 +1014,28 @@ print <<END;
 END
        foreach ("ACCEPT","DROP","REJECT")
        {
-               if($fwdfwsettings{'POLICY'} eq 'MODE2'){
-                       $fwdfwsettings{'RULE_ACTION'} = 'DROP';
-               }
-
-               if ($_ eq $fwdfwsettings{'RULE_ACTION'})
-               {
-                       print"<option selected>$_</option>";
+               if($fwdfwsettings{'updatefwrule'} eq 'on'){
+                       print"<option ";
+                       print "selected='selected'" if ($fwdfwsettings{'RULE_ACTION'} eq $_);
+                       print">$_</option>";
                }else{
-                       print"<option>$_</option>";
+                       if($fwdfwsettings{'POLICY'} eq 'MODE2'){
+                               $fwdfwsettings{'RULE_ACTION'} = 'DROP';
+                       }
+       
+                       if ($_ eq $fwdfwsettings{'RULE_ACTION'})
+                       {
+                               print"<option selected>$_</option>";
+                       }else{
+                               print"<option>$_</option>";
+                       }
                }
        }
        print"</select></td></tr></table><hr>"; 
 
-
        &Header::closebox();
        &Header::openbox('100%', 'left', $Lang::tr{'fwdfw source'});
 
-
        #------SOURCE-------------------------------------------------------
        print<<END;
                <table width='100%' border='0'>
@@ -1046,7 +1131,7 @@ END
                <tr><td width='1%'><input type='checkbox' name='USE_SRC_PORT' value='ON' $checked{'USE_SRC_PORT'}{'ON'}></td><td width='51%' colspan='3'>$Lang::tr{'fwdfw use srcport'}</td>
                <td width='15%' nowrap='nowrap'>$Lang::tr{'fwdfw man port'}</td><td><select name='PROT'>
 END
-               foreach ("TCP","UDP","GRE","ESP","ICMP")
+               foreach ("TCP","UDP","GRE","ESP","AH","ICMP")
                {
                        if ($_ eq $fwdfwsettings{'PROT'})
                        {
@@ -1200,7 +1285,7 @@ END
                </select></td></tr>
                <tr><td colspan='2'></td><td><input type='radio' name='grp3' value='TGT_PORT' $checked{'grp3'}{'TGT_PORT'}></td><td>$Lang::tr{'fwdfw man port'}</td><td><select name='TGT_PROT'>
 END
-               foreach ("TCP","UDP","GRE","ESP","ICMP")
+               foreach ("TCP","UDP","GRE","ESP","AH","ICMP")
                {
                        if ($_ eq $fwdfwsettings{'TGT_PROT'})
                        {
@@ -1231,7 +1316,20 @@ END
                &Header::openbox('100%', 'left', $Lang::tr{'fwdfw additional'});
                print<<END;
                <table width='100%' border='0'>
-               <tr><td colspan='2' >$Lang::tr{'remark'}:<input type='text' name='ruleremark' size='40' maxlength='255' value='$fwdfwsettings{'ruleremark'}'></td></tr>
+               <tr><td width='12%'>$Lang::tr{'remark'}:</td><td align='left'><input type='text' name='ruleremark' size='40' maxlength='255' value='$fwdfwsettings{'ruleremark'}'></td></tr>
+END
+               if($fwdfwsettings{'updatefwrule'} eq 'on' || $fwdfwsettings{'copyfwrule'} eq 'on'){
+                       print "<tr><td width='12%'>$Lang::tr{'fwdfw rulepos'}:</td><td><select name='rulepos' >";
+                       for (my $count =1; $count <= $sum; $count++){ 
+                               print"<option value='$count' ";
+                               print"selected='selected'" if($fwdfwsettings{'oldrulenumber'} eq $count);
+                               print">$count</option>";
+                       }
+                       print"</select></td></tr>";
+               }
+
+               print<<END;
+               </table><table width='100%'>
                <tr><td width='1%'><input type='checkbox' name='ACTIVE' value='ON' $checked{'ACTIVE'}{'ON'}></td><td>$Lang::tr{'fwdfw rule activate'}</td></tr>
                <tr><td width='1%'><input type='checkbox' name='LOG' value='ON'  $checked{'LOG'}{'ON'}  ></td><td>$Lang::tr{'fwdfw log rule'}</td></tr>
                </table><hr><br>
@@ -1258,7 +1356,7 @@ END
                                <input type='checkbox' name='TIME_THU' value='on' $checked{'TIME_THU'}{'on'} />
                                <input type='checkbox' name='TIME_FRI' value='on' $checked{'TIME_FRI'}{'on'} />
                                <input type='checkbox' name='TIME_SAT' value='on' $checked{'TIME_SAT'}{'on'} />
-                               <input type='checkbox' name='TIME_SUN' value='on' $checked{'TIME_SUN'}{$Lang::tr{'fwdfw wd_sun'}} />
+                               <input type='checkbox' name='TIME_SUN' value='on' $checked{'TIME_SUN'}{'on'} />
                        </td>
                        <td><select name='TIME_FROM'>
 END
@@ -1307,6 +1405,8 @@ END
                        <input type='hidden' name='oldgrp3a' value='$fwdfwsettings{'oldgrp3a'}' />
                        <input type='hidden' name='oldgrp3b' value='$fwdfwsettings{'oldgrp3b'}' />
                        <input type='hidden' name='oldusesrv' value='$fwdfwsettings{'oldusesrv'}' />
+                       <input type='hidden' name='oldrulenumber' value='$fwdfwsettings{'oldrulenumber'}' />
+                       <input type='hidden' name='rulenumber' value='$fwdfwsettings{'rulepos'}' />
                        <input type='hidden' name='ACTION' value='saverule' ></form><form method='post' style='display:inline'><input type='submit' value='$Lang::tr{'fwhost back'}' style='min-width:100px;'><input type='hidden' name='ACTION' value'reset'></td></td>
                        </table></form>
 END
@@ -1319,7 +1419,7 @@ sub saverule
        my $config=shift;
        &General::readhasharray("$config", $hash);
        if (!$errormessage){
-               if ($fwdfwsettings{'updatefwrule'} ne 'on' ){
+               if ($fwdfwsettings{'updatefwrule'} ne 'on'){
                        my $key = &General::findhasharraykey ($hash);
                        $$hash{$key}[0]  = $fwdfwsettings{'RULE_ACTION'};
                        $$hash{$key}[1]  = $fwdfwsettings{'chain'};
@@ -1351,7 +1451,7 @@ sub saverule
                        $$hash{$key}[27] = $fwdfwsettings{'TIME_TO'};
                        &General::writehasharray("$config", $hash);
                }else{
-                       foreach my $key (sort keys %$hash){
+                       foreach my $key (sort {$a <=> $b} keys %$hash){
                                if($key eq $fwdfwsettings{'key'}){
                                        $$hash{$key}[0]  = $fwdfwsettings{'RULE_ACTION'};
                                        $$hash{$key}[1]  = $fwdfwsettings{'chain'};
@@ -1384,7 +1484,62 @@ sub saverule
                                        last;
                                }
                        }
+               }
+               &General::writehasharray("$config", $hash);
+               if($fwdfwsettings{'oldrulenumber'} gt $fwdfwsettings{'rulepos'}){
+                       my %tmp=();
+                       my $val=$fwdfwsettings{'oldrulenumber'}-$fwdfwsettings{'rulepos'};
+                       for (my $z=0;$z<$val;$z++){
+                               foreach my $key (sort {$a <=> $b} keys %$hash){
+                                       if ($key eq $fwdfwsettings{'oldrulenumber'}) {
+                                               my $last = $key -1;
+                                               if (exists $$hash{$last}){
+                                                       #save rule last
+                                                       foreach my $y (0 .. $#{$$hash{$last}}) {
+                                                               $tmp{0}[$y] = $$hash{$last}[$y];
+                                                       }
+                                                       #copy active rule to last
+                                                       foreach my $i (0 .. $#{$$hash{$last}}) {
+                                                               $$hash{$last}[$i] = $$hash{$key}[$i];
+                                                       }
+                                                       #copy saved rule to actual position
+                                                       foreach my $x (0 .. $#{$tmp{0}}) {
+                                                               $$hash{$key}[$x] = $tmp{0}[$x];
+                                                       }
+                                               }
+                                       }
+                               }
+                               $fwdfwsettings{'oldrulenumber'}--;
+                       }
+                       &General::writehasharray("$config", $hash);
+                       &rules;
+               }elsif($fwdfwsettings{'rulepos'} gt $fwdfwsettings{'oldrulenumber'}){
+                       my %tmp=();
+                       my $val=$fwdfwsettings{'rulepos'}-$fwdfwsettings{'oldrulenumber'};
+                               for (my $z=0;$z<$val;$z++){
+                                       foreach my $key (sort {$a <=> $b} keys %$hash){
+                                       if ($key eq $fwdfwsettings{'oldrulenumber'}) {
+                                               my $next = $key + 1;
+                                               if (exists $$hash{$next}){
+                                                       #save rule next
+                                                       foreach my $y (0 .. $#{$$hash{$next}}) {
+                                                               $tmp{0}[$y] = $$hash{$next}[$y];
+                                                       }
+                                                       #copy active rule to next
+                                                       foreach my $i (0 .. $#{$$hash{$next}}) {
+                                                               $$hash{$next}[$i] = $$hash{$key}[$i];
+                                                       }
+                                                       #copy saved rule to actual position
+                                                       foreach my $x (0 .. $#{$tmp{0}}) {
+                                                               $$hash{$key}[$x] = $tmp{0}[$x];
+                                                       }
+                                               }
+                                       }
+                               }
+                               $fwdfwsettings{'oldrulenumber'}++;
+                       }
                        &General::writehasharray("$config", $hash);
+                       &rules;
                }
        }
 }
@@ -1427,7 +1582,7 @@ sub validremark
        if (length ($remark) < 1 || length ($remark) > 255) {
                return 0;}
        # Only valid characters are a-z, A-Z, 0-9 and -
-       if ($remark !~ /^[a-zäöüA-ZÖÄÜ0-9-.:\/\s]*$/) {
+       if ($remark !~ /^[a-zäöüA-ZÖÄÜ0-9-.:_\/\s]*$/) {
                return 0;}
        # First character can only be a letter or a digit
        if (substr ($remark, 0, 1) !~ /^[a-zäöüA-ZÖÄÜ0-9]*$/) {
@@ -1678,7 +1833,7 @@ END
                                if($$hash{$key}[25] ne ''){push (@days,$Lang::tr{'fwdfw wd_sun'});}
                                my $weekdays=join(",",@days);
                                if (@days){
-                                       print"<tr bgcolor='#FFE4B5'><td colspan='4'>$Lang::tr{'fwdfw time'} ";
+                                       print"<tr bgcolor='#FFE4B5'><td colspan='6'>$Lang::tr{'fwdfw time'} ";
                                        print"$weekdays";
                                        print "&nbsp $Lang::tr{'fwdfw from'} $$hash{$key}[26] &nbsp $Lang::tr{'fwdfw till'} $$hash{$key}[27]</td><td colspan='8'></d></tr>";
                                }
@@ -1688,6 +1843,35 @@ END
                &Header::closebox();
        }
 }
+sub p2pblock
+{
+       my $gif;
+       open( FILE, "< $p2pfile" ) or die "Unable to read $p2pfile";
+       @p2ps = <FILE>;
+       close FILE;
+       &Header::openbox('100%', 'center', 'P2P-Block');
+       print <<END;
+       <table width='40%' border='0'>
+       <tr bgcolor='$color{'color22'}'><td align=center colspan='2' width='30%'><b>$Lang::tr{'protocol'}</b><td width='10%' align=center><b>$Lang::tr{'status'}</b>
+END
+       foreach my $p2pentry (sort @p2ps)
+       {
+               my @p2pline = split( /\;/, $p2pentry );
+               if($p2pline[2] eq 'on'){
+                       $gif="/images/on.gif"
+               }else{
+                       $gif="/images/off.gif"
+               }
+               print <<END;
+               <form method='post' action='$ENV{'SCRIPT_NAME'}'>
+               <tr bgcolor='$color{'color20'}'>
+               <td width='66%' align='center' colspan='2'>$p2pline[0]:</td><td width='33%' align='center'><input type='hidden' name='P2PROT' value='$p2pline[1]' /><input type='image' img src='$gif' alt='$Lang::tr{'click to disable'}' title='$Lang::tr{'fwdfw toggle'}' style='padding-top: 0px; padding-left: 0px; padding-bottom: 0px ;padding-right: 0px ;display: block;' ><input type='hidden' name='ACTION' value='togglep2p'></td></tr></form>
+END
+       }
+       print"<tr><td width='10%'><input type='image' img src='/images/on.gif'></td><td>$Lang::tr{'outgoing firewall p2p deny'}</td><td></td></tr>";
+       print"<tr><td width='10%'><input type='image' img src='/images/off.gif'></td><td>$Lang::tr{'outgoing firewall p2p allow'}</td><td></td></tr></table>";
+       &Header::closebox();
+}
 sub fillselect
 {
        my %hash=%{(shift)};