2 ###############################################################################
4 # VLAN Management for IPFire #
5 # Copyright (C) 2019 Florian Bührle <fbuehrle@ipfire.org> #
7 # This program is free software: you can redistribute it and/or modify #
8 # it under the terms of the GNU General Public License as published by #
9 # the Free Software Foundation, either version 3 of the License, or #
10 # (at your option) any later version. #
12 # This program is distributed in the hope that it will be useful, #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15 # GNU General Public License for more details. #
17 # You should have received a copy of the GNU General Public License #
18 # along with this program. If not, see <http://www.gnu.org/licenses/>. #
20 ###############################################################################
23 use Scalar
::Util
qw(looks_like_number);
25 require '/var/ipfire/general-functions.pl';
26 require "${General::swroot}/lang.pl";
27 require "${General::swroot}/header.pl";
28 require "${General::swroot}/network-functions.pl";
30 ###--- HTML HEAD ---###
35 border-collapse: collapse;
44 #zoneconf tr.half-height {
47 #zoneconf tr.half-height > td {
51 /* section separators */
52 #zoneconf tr.divider-top {
53 border-top: 2px solid $Header::bordercolour;
55 #zoneconf tr.divider-bottom {
56 border-bottom: 2px solid $Header::bordercolour;
62 border-left: 0.5px solid $Header::bordercolour;
66 /* grey header cells */
67 #zoneconf td.heading {
68 background-color: lightgrey;
71 #zoneconf td.heading.bold::first-line {
76 /* narrow left column with background color */
77 #zoneconf tr > td:first-child {
80 #zoneconf tr.nic-row > td:first-child {
81 background-color: darkgray;
83 #zoneconf tr.nic-row {
84 border-bottom: 0.5px solid $Header::bordercolour;
86 #zoneconf tr.option-row > td:first-child {
87 background-color: gray;
90 /* alternating row background color */
92 background-color: $Header::table2colour;
94 #zoneconf tr:nth-child(2n+3) {
95 background-color: $Header::table1colour;
98 /* special cell colors */
100 background-color: $Header::colourgreen;
104 background-color: $Header::colourred;
108 background-color: $Header::colourblue;
111 #zoneconf td.orange {
112 background-color: $Header::colourorange;
115 #zoneconf td.topleft {
116 background-color: $Header::pagecolour;
133 #submit-container.input {
138 <script src="/include/zoneconf.js"></script>
141 ###--- END HTML HEAD ---###
143 ### Read configuration ###
144 my %ethsettings = ();
145 my %vlansettings = ();
148 my $restart_notice = "";
150 &General
::readhash
("${General::swroot}/ethernet/settings",\
%ethsettings);
151 &General
::readhash
("${General::swroot}/ethernet/vlans",\
%vlansettings);
153 &Header
::getcgihash
(\
%cgiparams);
154 &Header
::showhttpheaders
();
156 # Get all network zones that are currently enabled
157 my @zones = Network
::get_available_network_zones
();
159 # Get all physical NICs present
160 opendir(my $dh, "/sys/class/net/");
163 while (my $nic = readdir($dh)) {
164 if (-e
"/sys/class/net/$nic/device") { # Indicates that the NIC is physical
165 push(@nics, [&Network
::get_nic_property
($nic, "address"), $nic, 0]);
171 @nics = sort {$a->[0] cmp $b->[0]} @nics; # Sort nics by their MAC address
173 # Name the physical NICs
174 # Even though they may not be really named like this, we will name them ethX or wlanX
181 if (-e
"/sys/class/net/$nic/wireless") {
182 $_->[1] = "wlan$wlancount";
186 $_->[1] = "eth$ethcount";
192 &Header
::openpage
($Lang::tr
{"zoneconf title"}, 1, $extraHead);
193 &Header
::openbigbox
('100%', 'center');
195 ### Evaluate POST parameters ###
197 if ($cgiparams{"ACTION"} eq $Lang::tr
{"save"}) {
198 my %VALIDATE_nic_check = (); # array of flags (assigned, restricted/pppoe, vlan, ...) per NIC
199 my $VALIDATE_error = ""; # contains an error message if the config validation failed
201 # Loop trough all known zones to ensure a complete configuration file is created
202 foreach (@Network::known_network_zones
) {
204 my $slave_string = ""; # list of interfaces attached to the bridge
205 my $zone_mode = $cgiparams{"MODE $uc"};
206 my $VALIDATE_vlancount = 0;
207 my $VALIDATE_zoneslaves = 0;
209 # Each zone can contain up to one bridge and up to one VLAN,
210 # cache their mac addresses to prevent unnecessary changes
211 my $bridge_mac = $ethsettings{"${uc}_MACADDR"};
212 my $vlan_mac = $vlansettings{"${uc}_MAC_ADDRESS"};
214 # Clear old configuration
215 $ethsettings{"${uc}_MACADDR"} = "";
216 $ethsettings{"${uc}_MODE"} = "";
217 $ethsettings{"${uc}_SLAVES"} = "";
218 $vlansettings{"${uc}_PARENT_DEV"} = "";
219 $vlansettings{"${uc}_VLAN_ID"} = "";
220 $vlansettings{"${uc}_MAC_ADDRESS"} = "";
222 # If RED is not in DHCP or static mode, we only set its MACADDR property
223 if ($uc eq "RED" && ! $cgiparams{"PPPACCESS"} eq "") {
227 if ($mac eq $cgiparams{"PPPACCESS"}) {
228 $ethsettings{"${uc}_MACADDR"} = $mac;
230 # Check if this interface is already accessed by any other zone
231 # If this is the case, show an error message
232 if ($VALIDATE_nic_check{"ACC $mac"}) {
233 $VALIDATE_error = $Lang::tr
{"zoneconf val ppp assignment error"};
236 $VALIDATE_nic_check{"RESTRICT $mac"} = 1;
241 # skip NIC/VLAN assignment and additional zone options for RED in PPP mode
245 # Zone in bridge mode: Always assign a MAC to the bridge
246 if($zone_mode eq "BRIDGE") {
247 # Ensure that the bridge's cached MAC does not come from a real NIC
248 # (this could happen if the zone was in default mode before)
250 my $nic_mac = $_->[0];
251 if(Network
::is_mac_equal
($bridge_mac, $nic_mac)) {
257 # Generate random MAC if none was configured
258 if(! Network
::valid_mac
($bridge_mac)) {
259 $bridge_mac = Network
::random_mac
();
262 # Assign the address to the bridge
263 $ethsettings{"${uc}_MACADDR"} = $bridge_mac;
268 my $nic_access = $cgiparams{"ACCESS $uc $mac"};
270 next unless ($nic_access);
272 # This NIC is to be assigned: check preconditions
273 if ($nic_access ne "NONE") {
274 if ($VALIDATE_nic_check{"RESTRICT $mac"}) { # If this interface is already assigned to RED in PPP mode, throw an error
275 $VALIDATE_error = $Lang::tr
{"zoneconf val ppp assignment error"};
279 # Enforce bridge mode when you try to assign multiple NICs to a zone
280 if ($zone_mode ne "BRIDGE" && $VALIDATE_zoneslaves > 0 && $nic_access ne "") {
281 $VALIDATE_error = $Lang::tr
{"zoneconf val zoneslave amount error"};
285 # Mark this NIC as "accessed by zone"
286 $VALIDATE_nic_check{"ACC $mac"} = 1;
287 $VALIDATE_zoneslaves++;
290 if ($nic_access eq "NATIVE") {
291 if ($VALIDATE_nic_check{"NATIVE $mac"}) {
292 $VALIDATE_error = $Lang::tr
{"zoneconf val native assignment error"};
296 $VALIDATE_nic_check{"NATIVE $mac"} = 1;
298 # Zone in bridge mode: Add NIC to slave list. Otherwise access NIC directly
299 if ($zone_mode eq "BRIDGE") {
300 $slave_string = "${slave_string}${mac} ";
302 $ethsettings{"${uc}_MACADDR"} = $mac;
304 } elsif ($nic_access eq "VLAN") {
305 my $vlan_tag = $cgiparams{"TAG $uc $mac"};
307 if ($VALIDATE_nic_check{"VLAN $mac $vlan_tag"}) {
308 $VALIDATE_error = $Lang::tr
{"zoneconf val vlan tag assignment error"};
312 $VALIDATE_nic_check{"VLAN $mac $vlan_tag"} = 1;
314 # check VLAN tag range: 1..4094 (0, 4095 are reserved)
315 unless (looks_like_number
($vlan_tag) && ($vlan_tag >= 1) && ($vlan_tag <= 4094)) {
316 $VALIDATE_error = $Lang::tr
{"zoneconf val vlan tag range error"};
320 # Generate random MAC if none was configured
321 if(! Network
::valid_mac
($vlan_mac)) {
322 $vlan_mac = Network
::random_mac
();
325 $vlansettings{"${uc}_PARENT_DEV"} = $mac;
326 $vlansettings{"${uc}_VLAN_ID"} = $vlan_tag;
327 $vlansettings{"${uc}_MAC_ADDRESS"} = $vlan_mac; # Generated MAC
329 # Zone in bridge mode: Add VLAN to slave list
330 if ($zone_mode eq "BRIDGE") {
331 $slave_string = "${slave_string}${vlan_mac} ";
334 $VALIDATE_vlancount++; # We can't allow more than one VLAN per zone
338 if ($VALIDATE_vlancount > 1) {
339 $VALIDATE_error = $Lang::tr
{"zoneconf val vlan amount assignment error"};
345 if ($zone_mode eq "BRIDGE") {
346 $ethsettings{"${uc}_MODE"} = "bridge";
347 $ethsettings{"${uc}_SLAVES"} = $slave_string;
348 } elsif ($zone_mode eq "MACVTAP") {
349 $ethsettings{"${uc}_MODE"} = "macvtap";
353 # (this has already been skipped when RED is in PPP mode, so we don't need to check for PPP here)
354 $ethsettings{"${uc}_STP"} = "";
355 my $stp_enabled = $cgiparams{"STP-$uc"} eq "on";
356 my $stp_priority = $cgiparams{"STP-PRIORITY-$uc"};
359 unless($ethsettings{"${uc}_MODE"} eq "bridge") { # STP is only available in bridge mode
360 $VALIDATE_error = $Lang::tr
{"zoneconf val stp zone mode error"};
363 unless (looks_like_number
($stp_priority) && ($stp_priority >= 1) && ($stp_priority <= 65535)) { # STP bridge priority range: 1..65535
364 $VALIDATE_error = $Lang::tr
{"zoneconf val stp priority range error"};
367 $ethsettings{"${uc}_STP"} = "on"; # network-hotplug-bridges expects "on"
368 $ethsettings{"${uc}_STP_PRIORITY"} = $stp_priority;
372 # validation failed, show error message and exit
373 if ($VALIDATE_error) {
374 &Header
::openbox
('100%', 'left', $Lang::tr
{"error"});
376 print "$VALIDATE_error<br><br><a href='$ENV{'SCRIPT_NAME'}'>$Lang::tr{'back'}</a>\n";
379 &Header
::closebigbox
();
380 &Header
::closepage
();
385 # new settings are valid, write configuration files
386 &General
::writehash
("${General::swroot}/ethernet/settings",\
%ethsettings);
387 &General
::writehash
("${General::swroot}/ethernet/vlans",\
%vlansettings);
389 $restart_notice = $Lang::tr
{'zoneconf notice reboot'};
392 ### START OF TABLE ###
394 &Header
::openbox
('100%', 'left', $Lang::tr
{"zoneconf nic assignment"});
397 <form method='post' enctype='multipart/form-data'>
398 <table id="zoneconf">
399 <tr class="divider-bottom">
400 <td class="topleft"></td>
404 # Fill the table header with all activated zones
408 # If the red zone is in PPP mode, don't show a mode dropdown
410 my $red_type = $ethsettings{"RED_TYPE"};
412 unless (Network
::is_red_mode_ip
()) {
413 print "\t\t<td class='heading bold $_'>$uc ($red_type)</td>\n";
415 next; # We're done here
419 my %mode_selected = ();
420 my $zone_mode = $ethsettings{"${uc}_MODE"};
422 if ($zone_mode eq "") {
423 $mode_selected{"DEFAULT"} = "selected";
424 } elsif ($zone_mode eq "bridge") {
425 $mode_selected{"BRIDGE"} = "selected";
426 } elsif ($zone_mode eq "macvtap") {
427 $mode_selected{"MACVTAP"} = "selected";
431 <td class='heading bold $_'>$uc<br>
432 <select name="MODE $uc" data-zone="$uc" onchange="changeZoneMode(this)">
433 <option value="DEFAULT" $mode_selected{"DEFAULT"}>$Lang::tr{"zoneconf nicmode default"}</option>
434 <option value="BRIDGE" $mode_selected{"BRIDGE"}>$Lang::tr{"zoneconf nicmode bridge"}</option>
435 <option value="MACVTAP" $mode_selected{"MACVTAP"}>$Lang::tr{"zoneconf nicmode macvtap"}</option>
444 # NIC assignment matrix
450 print "\t<tr class='nic-row'>\n";
451 print "\t\t<td class='heading bold'>$nic<br>$mac</td>\n";
453 # Iterate through all zones and check if the current NIC is assigned to it
459 # VLANs/Bridging is not possible if the RED interface is set to PPP, PPPoE, VDSL, ...
460 unless (Network
::is_red_mode_ip
()) {
463 if ($mac eq $ethsettings{"${uc}_MACADDR"}) {
464 $checked = "checked";
469 <td class="$highlight">
470 <input type="radio" name="PPPACCESS" value="$mac" data-zone="RED" data-mac="$mac" onchange="highlightAccess(this)" $checked>
474 next; # We're done here
478 my %access_selected = ();
479 my $zone_mode = $ethsettings{"${uc}_MODE"};
480 my $zone_parent_dev = $vlansettings{"${uc}_PARENT_DEV"}; # ZONE_PARENT_DEV is set if this zone accesses any interface via a VLAN
481 my $field_disabled = "disabled"; # Only enable the VLAN ID input field if the current access mode is VLAN
482 my $zone_vlan_id = "";
484 # If ZONE_PARENT_DEV is set to a NICs name (e.g. green0 or eth0) instead of a MAC address, we have to find out this NICs MAC address
485 $zone_parent_dev = &Network
::get_mac_by_name
($zone_parent_dev);
487 # If the current NIC is accessed by the current zone via a VLAN, the ZONE_PARENT_DEV option corresponds to the current NIC
488 if ($mac eq $zone_parent_dev) {
489 $access_selected{"VLAN"} = "selected";
490 $field_disabled = "";
491 $zone_vlan_id = $vlansettings{"${uc}_VLAN_ID"};
492 } elsif ($zone_mode eq "bridge") { # If the current zone is in bridge mode, all corresponding NICs (Native as well as VLAN) are set via the ZONE_SLAVES option
493 my @slaves = split(/ /, $ethsettings{"${uc}_SLAVES"});
496 # Slaves can be set to a NICs name so we have to find out its MAC address
497 $_ = &Network
::get_mac_by_name
($_);
500 $access_selected{"NATIVE"} = "selected";
504 } elsif ($mac eq $ethsettings{"${uc}_MACADDR"}) { # Native access via ZONE_MACADDR is only set if the zone does not access a NIC via a VLAN and the zone is not in bridge mode
505 $access_selected{"NATIVE"} = "selected";
508 $access_selected{"NONE"} = ($access_selected{"NATIVE"} eq "") && ($access_selected{"VLAN"} eq "") ?
"selected" : "";
509 my $vlan_disabled = ($wlan) ?
"disabled" : "";
511 # If the interface is assigned, hightlight table cell
512 if ($access_selected{"NONE"} eq "") {
517 <td class="$highlight">
518 <select name="ACCESS $uc $mac" data-zone="$uc" data-mac="$mac" onchange="highlightAccess(this)">
519 <option value="NONE" $access_selected{"NONE"}>- $Lang::tr{"zoneconf access none"} -</option>
520 <option value="NATIVE" $access_selected{"NATIVE"}>$Lang::tr{"zoneconf access native"}</option>
521 <option value="VLAN" $access_selected{"VLAN"} $vlan_disabled>$Lang::tr{"zoneconf access vlan"}</option>
523 <input type="number" class="vlanid" id="TAG-$uc-$mac" name="TAG $uc $mac" min="1" max="4094" value="$zone_vlan_id" required $field_disabled>
533 my @stp_html = (); # form fields buffer (two rows)
535 foreach (@zones) { # load settings and prepare form elements for each zone
538 # STP is not available if the RED interface is set to PPP, PPPoE, VDSL, ...
540 unless (Network
::is_red_mode_ip
()) {
541 push(@stp_html, ["\t\t<td></td>\n", "\t\t<td></td>\n"]); # print empty cell
547 my $stp_available = $ethsettings{"${uc}_MODE"} eq "bridge"; # STP is only available in bridge mode
548 my $stp_enabled = $ethsettings{"${uc}_STP"} eq "on";
549 my $stp_priority = $ethsettings{"${uc}_STP_PRIORITY"};
551 # set priority to default value if no numerical value is configured
552 $stp_priority = 32768 unless looks_like_number
($stp_priority);
554 # form element modifiers
557 $checked = "checked" if ($stp_available && $stp_enabled);
558 $disabled = "disabled" unless $stp_available;
560 # enable checkbox HTML
563 <input type="checkbox" id="STP-$uc" name="STP-$uc" data-zone="$uc" onchange="changeEnableSTP(this)" $disabled $checked>
567 $disabled = "disabled" unless $stp_enabled; # STP priority can't be entered if STP is disabled
569 # priority input box HTML
572 <input type="number" class="stp-priority" id="STP-PRIORITY-$uc" name="STP-PRIORITY-$uc" min="1" max="65535" value="$stp_priority" required $disabled>
576 # add fields to buffer
577 push(@stp_html, [$row_1, $row_2]);
580 # print two rows of prepared form elements
582 <tr class="half-height divider-top option-row">
583 <td class="heading bold">$Lang::tr{"zoneconf stp enable"}</td>
586 foreach (@stp_html) {
587 print $_->[0]; # row 1
591 <tr class="half-height option-row">
592 <td class="heading">$Lang::tr{"zoneconf stp priority"}</td>
595 foreach (@stp_html) {
596 print $_->[1]; # row 2
600 # footer and submit button
604 <div id="submit-container">
606 <input type="submit" name="ACTION" value="$Lang::tr{"save"}">
615 &Header
::closebigbox
();
616 &Header
::closepage
();