2 ###############################################################################
4 # IPFire.org - A linux based firewall #
5 # Copyright (C) 2010 Michael Tremer & Christian Schmidt #
7 # This program is free software: you can redistribute it and/or modify #
8 # it under the terms of the GNU General Public License as published by #
9 # the Free Software Foundation, either version 3 of the License, or #
10 # (at your option) any later version. #
12 # This program is distributed in the hope that it will be useful, #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15 # GNU General Public License for more details. #
17 # You should have received a copy of the GNU General Public License #
18 # along with this program. If not, see <http://www.gnu.org/licenses/>. #
20 ###############################################################################
22 # Parse the command line
23 while [ $# -gt 0 ]; do
33 [ -n "${action}" ] && break
36 .
/usr
/lib
/network
/functions
38 function cli_config
() {
39 if cli_help_requested $@
; then
40 cli_show_man network-config
44 if [ -n "${1}" ]; then
52 function cli_device
() {
53 if cli_help_requested $@
; then
54 cli_show_man network-device
62 if ! isset device
; then
63 cli_show_man network-device
67 assert device_exists
${device}
71 cli_device_discover
${device} $@
74 cli_device_status
${device}
77 cli_device_serial_unlock
${device} $@
80 cli_show_man network-device
87 function cli_device_status
() {
89 assert device_exists
${device}
91 # Disable debugging output here.
92 local log_disable_stdout
=${LOG_DISABLE_STDOUT}
93 LOG_DISABLE_STDOUT
="true"
95 # Save the type of the device for later.
96 local type=$
(device_get_type
${device})
98 cli_headline
1 "Device status: ${device}"
99 cli_print_fmt1
1 "Name" "${device}"
101 # Handle serial devices.
102 if [ "${type}" = "serial" ]; then
103 cli_device_status_serial
${device}
107 # Print the device status.
108 device_is_up
${device} &>/dev
/null
113 status
="${COLOUR_GREEN}UP${COLOUR_NORMAL}"
116 status
="${COLOUR_RED}DOWN${COLOUR_NORMAL}"
120 cli_print_fmt1
1 "Status" "${status}"
121 cli_print_fmt1
1 "Type" "${type}"
122 cli_print_fmt1
1 "Address" "$(device_get_address ${device})"
125 # Print the link speed for ethernet devices.
126 if device_is_up
${device} &>/dev
/null
; then
129 cli_print_fmt1
1 "Link" \
130 "$(device_get_speed ${device}) MBit/s $(device_get_duplex ${device}) duplex"
135 cli_print_fmt1
1 "MTU" "$(device_get_mtu ${device})"
138 # Print device statistics.
139 cli_device_stats
2 ${device}
141 # Print some more information.
142 device_has_carrier
${device} &>/dev
/null
143 cli_print_fmt1
1 "Has carrier?" "$(cli_print_bool $?)"
145 device_is_promisc
${device} &>/dev
/null
146 cli_print_fmt1
1 "Promisc" "$(cli_print_bool $?)"
149 # Print all virtual devices.
150 local virtuals
=$
(device_get_virtuals
${device})
151 if [ -n "${virtuals}" ]; then
152 cli_headline
2 "Virtual devices"
155 for virtual
in ${virtuals}; do
156 cli_print
2 "* %-6s - %s" "${virtual}" "$(device_get_address ${virtual})"
161 # Reset the logging level.
162 LOG_DISABLE_STDOUT
=${log_disable_stdout}
165 function cli_device_status_serial
() {
167 assert device_is_serial
${device}
169 serial_is_locked
${device} &>/dev
/null
172 cli_print_fmt1
1 "Locked" "$(cli_print_bool ${locked})"
175 # Cannot go on when the device is locked.
176 [ ${locked} -eq ${EXIT_TRUE} ] && return ${EXIT_OK}
178 cli_print_fmt1
1 "Manufacturer" \
179 "$(modem_get_manufacturer ${device})"
180 cli_print_fmt1
1 "Model" \
181 "$(modem_get_model ${device})"
182 cli_print_fmt1
1 "Software version" \
183 "$(modem_get_software_version ${device})"
185 if modem_is_mobile
${device}; then
186 cli_print_fmt1
1 "IMEI" \
187 "$(modem_get_device_imei ${device})"
190 cli_headline
2 "Network status"
191 modem_sim_status
${device} &>/dev
/null
192 local sim_status_code
=$?
194 local sim_status
="unknown"
195 case "${sim_status_code}" in
197 sim_status
="SIM ready"
200 sim_status
="PIN locked"
203 sim_status
="PUK locked"
206 cli_print_fmt1
2 "SIM status" "${sim_status}"
208 if [ ${sim_status_code} -eq ${EXIT_SIM_READY} ]; then
209 cli_print_fmt1
2 "IMSI" \
210 "$(modem_get_sim_imsi ${device})"
211 cli_print_fmt1
2 "Operator" \
212 "$(modem_get_network_operator ${device})"
213 cli_print_fmt1
2 "Mode" \
214 "$(modem_get_network_mode ${device})"
215 cli_print_fmt1
2 "Signal quality" \
216 "$(modem_get_signal_quality ${device}) dBm"
218 local ber
=$
(modem_get_bit_error_rate
${device})
219 isset ber || ber
="unknown"
220 cli_print_fmt1
2 "Bit Error Rate" "${ber}"
226 function cli_device_discover
() {
230 local device_type
=$
(device_get_type
${device})
231 if [ "${device_type}" != "real" ]; then
237 while [ $# -gt 0 ]; do
247 device_is_up
${device} && up
=1
248 device_set_up
${device}
250 enabled raw ||
echo "${device}"
255 for hook
in $
(hook_zone_get_all
); do
256 out
=$
(hook_zone_exec
${hook} discover
${device})
259 [ ${ret} -eq ${DISCOVER_NOT_SUPPORTED} ] && continue
267 echo "${hook}: ${line}"
272 echo "${hook}: FAILED"
278 echo " ${hook} was successful."
286 echo " ${hook} failed."
294 [ "${up}" = "1" ] || device_set_down
${device}
297 function cli_device_serial_unlock
() {
298 if cli_help_requested $@
; then
299 cli_show_man network-device
306 if ! device_is_serial
${device}; then
307 error
"${device} is not a serial device."
308 error
"Unlocking is only supported for serial devices."
312 # Read the current state of the SIM card.
313 modem_sim_status
${device} &>/dev
/null
314 local sim_status_code
=$?
316 # If the SIM card is already unlocked, we don't need to do anything.
317 if [ ${sim_status_code} -eq ${EXIT_SIM_READY} ]; then
318 print
"The SIM card is already unlocked."
321 # If the SIM card is in an unknown state, we cannot do anything.
322 elif [ ${sim_status_code} -eq ${EXIT_SIM_UNKNOWN} ]; then
323 error
"The SIM card is in an unknown state."
329 local require_new_pin
="false"
332 while ! isinteger code
; do
334 case "${sim_status_code}" in
336 message
="Please enter PIN:"
339 message
="Please enter PUK:"
340 require_new_pin
="true"
345 echo -n "${message} "
347 echo # Print newline.
349 if enabled require_new_pin
; then
354 message
="Please enter a new PIN code:"
357 message
="Please confirm the new PIN code:"
361 echo -n "${message} "
363 echo # Print newline.
365 if [ -n "${new_pin}" ]; then
366 if [ "${new_pin}" != "${new_pin2}" ]; then
367 error
"The entered PIN codes did not match."
377 # Trying to unlock the SIM card.
378 modem_sim_unlock
${device} ${code} ${new_pin}
383 function cli_hostname
() {
384 if cli_help_requested $@
; then
391 if [ -n "${hostname}" ]; then
392 config_hostname
${hostname}
393 log INFO
"Hostname was set to '${hostname}'."
394 log INFO
"Changes do only take affect after reboot."
398 echo "$(config_hostname)"
402 function cli_port
() {
403 if cli_help_requested $@
; then
404 cli_show_man network-port
411 if port_exists
${1}; then
431 port_
${action} ${port} $@
434 error
"Unrecognized argument: ${action}"
447 error
"Unrecognized argument: ${action}"
454 function cli_zone
() {
455 if cli_help_requested $@
; then
456 cli_show_man network-zone
463 if zone_name_is_valid
${1}; then
482 config|down|edit|port|status|up
)
483 zone_
${action} ${zone} $@
486 error
"Unrecognized argument: ${action}"
487 cli_show_man network-zone
503 cli_list_hooks zone $@
506 if [ -n "${action}" ]; then
507 error
"Unrecognized argument: '${action}'"
511 cli_show_man network-zone
518 # Removes a zone either immediately, if it is currently down,
519 # or adds a tag that the removal will be done when the zone
520 # is brought down the next time.
521 function cli_zone_remove
() {
522 if cli_help_requested $@
; then
523 cli_show_man network-zone
528 assert zone_exists
${zone}
530 if zone_is_up
${zone}; then
531 echo "Zone '${zone}' is up and will be removed when it goes down the next time."
534 echo "Removing zone '${zone}' now..."
535 zone_remove_now
${zone}
541 function cli_list_hooks
() {
545 if cli_help_requested $@
; then
546 cli_show_man network-zone
550 local hook_dir
=$
(hook_dir
${type})
553 for hook
in ${hook_dir}/*; do
554 hook
=$
(basename ${hook})
555 if hook_exists
${type} ${hook}; then
561 function cli_route
() {
562 if cli_help_requested $@
; then
563 cli_show_man network-route
575 # Remove an existing route.
585 error
"Unrecognized action: ${action}"
586 cli_run_help network route
592 # Applying all routes.
598 function cli_dhcpd
() {
602 if cli_help_requested $@
; then
603 cli_show_man network-dhcp
612 dhcpd_edit
${proto} $@
621 dhcpd_reload
${proto}
624 cli_dhcpd_subnet
${proto} $@
627 cli_dhcpd_show
${proto} $@
630 error
"Unrecognized action: ${action}"
631 cli_run_help network dhcpvN
640 function cli_dhcpd_show
() {
644 local settings
=$
(dhcpd_settings
${proto})
645 assert isset settings
648 dhcpd_global_settings_read
${proto}
650 cli_headline
1 "Dynamic Host Configuration Protocol Daemon for ${proto/ip/IP}"
654 cli_headline
2 "Lease times"
655 if isinteger VALID_LIFETIME
; then
656 cli_print_fmt1
2 "Valid lifetime" "${VALID_LIFETIME}s"
659 if isinteger PREFERRED_LIFETIME
; then
660 cli_print_fmt1
2 "Preferred lifetime" "${PREFERRED_LIFETIME}s"
666 cli_print_fmt1
1 "Authoritative" $
(cli_print_enabled AUTHORITATIVE
)
669 cli_headline
2 "Lease times"
670 cli_print_fmt1
2 "Default lease time" "${DEFAULT_LEASE_TIME}s"
671 cli_print_fmt1
2 "Max. lease time" "${MAX_LEASE_TIME}s"
673 if isset MIN_LEASE_TIME
; then
674 cli_print_fmt1
2 "Min. lease time" "${MIN_LEASE_TIME}s"
683 dhcpd_global_options_read
${proto} ${subnet_id}
685 # Print the options if any.
686 if [ ${#options[*]} -gt 0 ]; then
687 cli_headline
2 "Options"
690 for option
in $
(dhcpd_options
${proto}); do
691 [ -n "${options[${option}]}" ] ||
continue
694 "${option}" "${options[${option}]}"
700 local subnets
=$
(dhcpd_subnet_list
${proto})
701 if [ -n "${subnets}" ]; then
702 cli_headline
2 "Subnets"
704 for subnet_id
in ${subnets}; do
705 cli_dhcpd_subnet_show
${proto} ${subnet_id} 2
710 function cli_dhcpd_subnet
() {
714 if cli_help_requested $@
; then
715 cli_show_man network-dhcp-subnet
724 dhcpd_subnet_new
${proto} $@
727 dhcpd_subnet_remove
${proto} $@
730 local subnet_id
=${action}
732 if ! dhcpd_subnet_exists
${proto} ${subnet_id}; then
733 error
"The given subnet with ID ${subnet_id} does not exist."
743 dhcpd_subnet_edit
${proto} ${subnet_id} $@
746 if [ ${ret} -eq ${EXIT_OK} ]; then
747 dhcpd_reload
${proto}
752 cli_dhcpd_subnet_range
${proto} ${subnet_id} $@
756 cli_dhcpd_subnet_show
${proto} ${subnet_id} $@
760 cli_dhcpd_subnet_options
${proto} ${subnet_id} $@
764 error
"Unrecognized action: ${action}"
765 cli_run_help network dhcpvN subnet
772 for subnet_id
in $
(dhcpd_subnet_list
${proto}); do
773 cli_dhcpd_subnet_show
${proto} ${subnet_id}
777 error
"Unrecognized action: ${action}"
778 cli_run_help network dhcpvN subnet
787 function cli_dhcpd_subnet_range
() {
793 assert isset subnet_id
801 dhcpd_subnet_range_new
${proto} ${subnet_id} $@
805 dhcpd_subnet_range_remove
${proto} ${subnet_id} $@
809 error
"Unrecognized action: ${action}"
810 cli_run_help network dhcpvN subnet range
816 function cli_dhcpd_subnet_show
() {
821 assert isset subnet_id
824 isset level || level
=0
826 local $
(dhcpd_subnet_settings
${proto})
828 # Read in configuration settings.
829 dhcpd_subnet_read
${proto} ${subnet_id}
831 cli_headline $
(( ${level} + 1 )) \
832 "DHCP${proto/ip/} subnet declaration #${subnet_id}"
833 cli_print_fmt1 $
(( ${level} + 1 )) \
834 "Subnet" "${ADDRESS}/${PREFIX}"
839 dhcpd_subnet_options_read
${proto} ${subnet_id}
841 # Print the options if any.
842 if [ ${#options[*]} -gt 0 ]; then
843 cli_headline $
(( ${level} + 2 )) "Options"
846 for option
in $
(dhcpd_subnet_options
${proto}); do
847 [ -n "${options[${option}]}" ] ||
continue
849 cli_print_fmt1 $
(( ${level} + 2 )) \
850 "${option}" "${options[${option}]}"
856 cli_headline $
(( ${level} + 2 )) "Ranges"
858 local ranges
=$
(dhcpd_subnet_range_list
${proto} ${subnet_id})
859 if isset ranges
; then
860 local range_id $
(dhcpd_subnet_range_settings
${proto})
861 for range_id
in ${ranges}; do
862 dhcpd_subnet_range_read
${proto} ${subnet_id} ${range_id}
864 cli_print $
(( ${level} + 2 )) \
865 "#%d: %s - %s" ${range_id} ${START} ${END}
868 cli_print $
(( ${level} + 2 )) "No ranges have been defined."
874 function cli_dhcpd_options
() {
880 assert isset subnet_id
883 local valid_options
=$
(dhcpd_subnet_options
${proto})
886 while [ $# -gt 0 ]; do
889 key
=$
(cli_get_key
${1})
890 val
=$
(cli_get_val
${1})
892 dhcpd_subnet_option_set
${proto} ${subnet_id} ${key} ${val}
897 function cli_start
() {
898 if cli_help_requested $@
; then
903 local zones
=$
(zones_get $@
)
906 for zone
in ${zones}; do
910 wait # until everything is settled
913 function cli_stop
() {
914 if cli_help_requested $@
; then
919 local zones
=$
(zones_get $@
)
922 for zone
in ${zones}; do
926 wait # until everything is settled
929 function cli_restart
() {
930 if cli_help_requested $@
; then
937 # Give the system some time to calm down
938 sleep ${TIMEOUT_RESTART}
943 function cli_status
() {
944 if cli_help_requested $@
; then
949 # When dumping status information, the debug
950 # mode clutters the console which is not what we want.
951 # Logging on the console is disabled for a short time.
952 local log_disable_stdout
=${LOG_DISABLE_STDOUT}
953 LOG_DISABLE_STDOUT
="true"
955 local zones
=$
(zones_get $@
)
958 for zone
in ${zones}; do
963 LOG_DISABLE_STDOUT
=${log_disable_stdout}
966 function cli_reset
() {
967 if cli_help_requested $@
; then
972 warning_log
"Will reset the whole network configuration!!!"
974 # Force mode is disabled by default
977 while [ $# -gt 0 ]; do
986 # If we are not running in force mode, we ask the user if he does know
988 if ! enabled force
; then
989 if ! cli_yesno
"Do you really want to reset the whole network configuration?"; then
995 for zone
in $
(zones_get
--all); do
1000 for port
in $
(ports_get
--all); do
1004 # Flush all DNS servers.
1007 # Re-run the initialization functions
1013 # Help function: will show the default man page to the user.
1014 # Optionally, there are two arguments taken, the type of hook
1015 # and which hook should be shown.
1016 function cli_help
() {
1020 # Remove unknown types.
1021 if ! listmatch
${type} zone port config
; then
1025 # If no arguments were given, we will show the default page.
1026 if [ -z "${type}" ]; then
1027 cli_show_man network
1031 if ! hook_exists
${type} ${what}; then
1032 error
"Hook of type '${type}' and name '${what}' could not be found."
1033 exit "${EXIT_ERROR}"
1036 hook_exec
${type} ${what} help
1039 function cli_dns
() {
1040 if cli_help_requested $@
; then
1041 cli_show_man network-dns
1046 local cmd
=${1}; shift
1047 if [ -z "${cmd}" ]; then
1048 cli_show_man network-dns
1052 # Get the new server to process (if any).
1058 __dns_server_println
"SERVER" "PRIORITY"
1063 log INFO
"Adding new DNS server: ${server}"
1064 dns_server_add
${server} ${priority}
1067 log INFO
"Removing DNS server: ${server}"
1068 dns_server_remove
${server} ${priority}
1071 # Just run the update afterwards.
1074 error
"No such command: ${cmd}"
1078 # Update the local DNS configuration after changes have been made.
1079 dns_generate_resolvconf
1085 # Process the given action
1091 config|hostname|port|device|zone|start|stop|restart|status|
reset|dns|route
)
1095 # DHCP server configuration (automatically detects which protocol to use).
1097 cli_dhcpd
${action/dhcp/ip} $@
1105 error
"Invalid command given: ${action}"
1106 cli_usage
"network help"
1107 exit ${EXIT_CONF_ERROR}