2 ###############################################################################
4 # IPFire.org - A linux based firewall #
5 # Copyright (C) 2010 Michael Tremer & Christian Schmidt #
7 # This program is free software: you can redistribute it and/or modify #
8 # it under the terms of the GNU General Public License as published by #
9 # the Free Software Foundation, either version 3 of the License, or #
10 # (at your option) any later version. #
12 # This program is distributed in the hope that it will be useful, #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15 # GNU General Public License for more details. #
17 # You should have received a copy of the GNU General Public License #
18 # along with this program. If not, see <http://www.gnu.org/licenses/>. #
20 ###############################################################################
22 # Parse the command line
23 while [ $# -gt 0 ]; do
33 [ -n "${action}" ] && break
36 .
/usr
/lib
/network
/functions
38 # Read network settings
41 function cli_settings
() {
42 if cli_help_requested $@
; then
43 cli_show_man network-settings
47 if [ -n "${1}" ]; then
49 network_settings_write
51 network_settings_print
55 function cli_device
() {
56 if cli_help_requested $@
; then
57 cli_show_man network-device
65 if ! isset device
; then
66 cli_show_man network-device
70 assert device_exists
${device}
74 cli_device_discover
${device} $@
77 cli_device_monitor
"${device}" $@
80 cli_device_status
${device}
83 cli_device_serial_unlock
${device} $@
86 cli_device_send_ussd_command
"${device}" $@
89 cli_show_man network-device
96 function cli_device_status
() {
98 assert device_exists
${device}
100 # Disable debugging output here.
101 local log_disable_stdout
=${LOG_DISABLE_STDOUT}
102 LOG_DISABLE_STDOUT
="true"
104 # Save the type of the device for later.
105 local type=$
(device_get_type
${device})
107 cli_headline
1 "Device status: ${device}"
108 cli_print_fmt1
1 "Name" "${device}"
110 # Handle serial devices.
111 if [ "${type}" = "serial" ]; then
112 cli_device_status_serial
${device}
116 # Print the device status.
117 device_is_up
${device} &>/dev
/null
122 status
="${CLR_GREEN_B}UP${CLR_RESET}"
125 status
="${CLR_RED_B}DOWN${CLR_RESET}"
129 cli_print_fmt1
1 "Status" "${status}"
130 cli_print_fmt1
1 "Type" "${type}"
131 cli_print_fmt1
1 "Address" "$(device_get_address ${device})"
134 # Print the link speed for ethernet devices.
135 if device_is_up
${device} &>/dev
/null
; then
138 cli_print_fmt1
1 "Link" \
139 "$(device_get_speed ${device}) MBit/s $(device_get_duplex ${device}) duplex"
144 cli_print_fmt1
1 "MTU" "$(device_get_mtu ${device})"
147 # Print device statistics.
148 cli_device_stats
2 ${device}
150 # Print some more information.
151 device_has_carrier
${device} &>/dev
/null
152 cli_print_fmt1
1 "Has carrier?" "$(cli_print_bool $?)"
154 device_is_promisc
${device} &>/dev
/null
155 cli_print_fmt1
1 "Promisc" "$(cli_print_bool $?)"
158 # Print all vlan devices.
159 local vlans
=$
(device_get_vlans
${device})
160 if [ -n "${vlans}" ]; then
161 cli_headline
2 "VLAN devices"
164 for vlan
in ${vlans}; do
165 cli_print
2 "* %-6s - %s" "${vlan}" "$(device_get_address ${vlan})"
170 # Reset the logging level.
171 LOG_DISABLE_STDOUT
=${log_disable_stdout}
174 function cli_device_status_serial
() {
176 assert device_is_serial
${device}
178 serial_is_locked
${device} &>/dev
/null
181 cli_print_fmt1
1 "Locked" "$(cli_print_bool ${locked})"
184 # Cannot go on when the device is locked.
185 [ ${locked} -eq ${EXIT_TRUE} ] && return ${EXIT_OK}
187 cli_print_fmt1
1 "Manufacturer" \
188 "$(modem_get_manufacturer ${device})"
189 cli_print_fmt1
1 "Model" \
190 "$(modem_get_model ${device})"
191 cli_print_fmt1
1 "Software version" \
192 "$(modem_get_software_version ${device})"
194 if modem_is_mobile
${device}; then
195 cli_print_fmt1
1 "IMEI" \
196 "$(modem_get_device_imei ${device})"
199 cli_headline
2 "Network status"
200 modem_sim_status
${device} &>/dev
/null
201 local sim_status_code
=$?
203 local sim_status
="unknown"
204 case "${sim_status_code}" in
206 sim_status
="SIM ready"
209 sim_status
="PIN locked"
212 sim_status
="PUK locked"
215 cli_print_fmt1
2 "SIM status" "${sim_status}"
217 if [ ${sim_status_code} -eq ${EXIT_SIM_READY} ]; then
218 cli_print_fmt1
2 "IMSI" \
219 "$(modem_get_sim_imsi ${device})"
220 cli_print_fmt1
2 "Operator" \
221 "$(modem_get_network_operator ${device})"
222 cli_print_fmt1
2 "Mode" \
223 "$(modem_get_network_mode ${device})"
224 cli_print_fmt1
2 "Signal quality" \
225 "$(modem_get_signal_quality ${device}) dBm"
227 local ber
=$
(modem_get_bit_error_rate
${device})
228 isset ber || ber
="unknown"
229 cli_print_fmt1
2 "Bit Error Rate" "${ber}"
235 function cli_device_discover
() {
239 local device_type
=$
(device_get_type
${device})
240 if [ "${device_type}" != "real" ]; then
246 while [ $# -gt 0 ]; do
256 device_is_up
${device} && up
=1
257 device_set_up
${device}
259 enabled raw ||
echo "${device}"
264 for hook
in $
(hook_zone_get_all
); do
265 out
=$
(hook_zone_exec
${hook} discover
${device})
268 [ ${ret} -eq ${DISCOVER_NOT_SUPPORTED} ] && continue
276 echo "${hook}: ${line}"
281 echo "${hook}: FAILED"
287 echo " ${hook} was successful."
295 echo " ${hook} failed."
303 [ "${up}" = "1" ] || device_set_down
${device}
306 function cli_device_serial_unlock
() {
307 if cli_help_requested $@
; then
308 cli_show_man network-device
315 if ! device_is_serial
${device}; then
316 error
"${device} is not a serial device."
317 error
"Unlocking is only supported for serial devices."
321 # Read the current state of the SIM card.
322 modem_sim_status
${device} &>/dev
/null
323 local sim_status_code
=$?
325 # If the SIM card is already unlocked, we don't need to do anything.
326 if [ ${sim_status_code} -eq ${EXIT_SIM_READY} ]; then
327 print
"The SIM card is already unlocked."
330 # If the SIM card is in an unknown state, we cannot do anything.
331 elif [ ${sim_status_code} -eq ${EXIT_SIM_UNKNOWN} ]; then
332 error
"The SIM card is in an unknown state."
338 local require_new_pin
="false"
341 while ! isinteger code
; do
343 case "${sim_status_code}" in
345 message
="Please enter PIN:"
348 message
="Please enter PUK:"
349 require_new_pin
="true"
354 echo -n "${message} "
356 echo # Print newline.
358 if enabled require_new_pin
; then
363 message
="Please enter a new PIN code:"
366 message
="Please confirm the new PIN code:"
370 echo -n "${message} "
372 echo # Print newline.
374 if [ -n "${new_pin}" ]; then
375 if [ "${new_pin}" != "${new_pin2}" ]; then
376 error
"The entered PIN codes did not match."
386 # Trying to unlock the SIM card.
387 modem_sim_unlock
${device} ${code} ${new_pin}
392 function cli_device_send_ussd_command
() {
400 while [ $# -gt 0 ]; do
403 timeout
="$(cli_get_val "${1}")"
406 if isset
command; then
407 warning
"Unrecognized argument: ${1}"
416 assert device_is_serial
"${device}"
419 if isset timeout
; then
420 args
="${args} --timeout=${timeout}"
423 modem_ussd_send_command
"${device}" "${command}" ${args}
427 function cli_device_monitor() {
431 if ! device_is_wireless "${device}"; then
432 error "This action only works with wireless devices. Exiting.
"
436 wireless_monitor "${device}"
440 function cli_hostname() {
441 if cli_help_requested $@; then
448 if [ -n "${hostname}" ]; then
449 config_hostname ${hostname}
450 log INFO "Hostname was
set to
'${hostname}'.
"
451 log INFO "Changes
do only take affect after reboot.
"
455 echo "$
(config_hostname
)"
459 function cli_port() {
460 if cli_help_requested $@; then
461 cli_show_man network-port
468 if port_exists ${1}; then
488 port_${action} ${port} $@
491 error "Unrecognized argument
: ${action}"
504 error "Unrecognized argument
: ${action}"
511 function cli_zone() {
512 if cli_help_requested $@; then
513 cli_show_man network-zone
520 if zone_name_is_valid ${1}; then
539 config|disable|down|edit|enable|port|status|up)
540 zone_${action} ${zone} $@
543 error "Unrecognized argument
: ${action}"
544 cli_show_man network-zone
560 cli_list_hooks zone $@
563 if [ -n "${action}" ]; then
564 error "Unrecognized argument
: '${action}'"
568 cli_show_man network-zone
575 # Removes a zone either immediately, if it is currently down,
576 # or adds a tag that the removal will be done when the zone
577 # is brought down the next time.
578 function cli_zone_remove() {
579 if cli_help_requested $@; then
580 cli_show_man network-zone
585 assert zone_exists ${zone}
587 if zone_is_up ${zone}; then
588 echo "Zone
'${zone}' is up and will be removed when it goes down the next
time.
"
591 echo "Removing zone
'${zone}' now...
"
592 zone_remove_now ${zone}
598 function cli_list_hooks() {
602 if cli_help_requested $@; then
603 cli_show_man network-zone
607 local hook_dir=$(hook_dir ${type})
610 for hook in ${hook_dir}/*; do
611 hook=$(basename ${hook})
612 if hook_exists ${type} ${hook}; then
618 function cli_route() {
619 if cli_help_requested $@; then
620 cli_show_man network-route
632 # Remove an existing route.
642 error "Unrecognized action
: ${action}"
643 cli_run_help network route
649 # Applying all routes.
655 function cli_dhcpd() {
659 if cli_help_requested $@; then
660 cli_show_man network-dhcp
669 dhcpd_edit ${proto} $@
678 dhcpd_reload ${proto}
681 cli_dhcpd_subnet ${proto} $@
684 cli_dhcpd_show ${proto} $@
687 error "Unrecognized action
: ${action}"
688 cli_run_help network dhcpvN
697 function cli_dhcpd_show() {
701 local settings=$(dhcpd_settings ${proto})
702 assert isset settings
705 dhcpd_global_settings_read ${proto}
707 cli_headline 1 "Dynamic Host Configuration Protocol Daemon
for ${proto/ip/IP}"
711 cli_headline 2 "Lease
times"
712 if isinteger VALID_LIFETIME; then
713 cli_print_fmt1 2 "Valid lifetime
" "${VALID_LIFETIME}s
"
716 if isinteger PREFERRED_LIFETIME; then
717 cli_print_fmt1 2 "Preferred lifetime
" "${PREFERRED_LIFETIME}s
"
723 cli_print_fmt1 1 "Authoritative
" $(cli_print_enabled AUTHORITATIVE)
726 cli_headline 2 "Lease
times"
727 cli_print_fmt1 2 "Default lease
time" "${DEFAULT_LEASE_TIME}s
"
728 cli_print_fmt1 2 "Max. lease
time" "${MAX_LEASE_TIME}s
"
730 if isset MIN_LEASE_TIME; then
731 cli_print_fmt1 2 "Min. lease
time" "${MIN_LEASE_TIME}s
"
740 dhcpd_global_options_read ${proto} ${subnet_id}
742 # Print the options if any.
743 if [ ${#options[*]} -gt 0 ]; then
744 cli_headline 2 "Options
"
747 for option in $(dhcpd_options ${proto}); do
748 [ -n "${options[${option}]}" ] || continue
751 "${option}" "${options[${option}]}"
757 local subnets=$(dhcpd_subnet_list ${proto})
758 if [ -n "${subnets}" ]; then
759 cli_headline 2 "Subnets
"
761 for subnet_id in ${subnets}; do
762 cli_dhcpd_subnet_show ${proto} ${subnet_id} 2
767 function cli_dhcpd_subnet() {
771 if cli_help_requested $@; then
772 cli_show_man network-dhcp-subnet
781 dhcpd_subnet_new ${proto} $@
784 dhcpd_subnet_remove ${proto} $@
787 local subnet_id=${action}
789 if ! dhcpd_subnet_exists ${proto} ${subnet_id}; then
790 error "The given subnet with ID
${subnet_id} does not exist.
"
800 dhcpd_subnet_edit ${proto} ${subnet_id} $@
803 if [ ${ret} -eq ${EXIT_OK} ]; then
804 dhcpd_reload ${proto}
809 cli_dhcpd_subnet_range ${proto} ${subnet_id} $@
813 cli_dhcpd_subnet_show ${proto} ${subnet_id} $@
817 cli_dhcpd_subnet_options ${proto} ${subnet_id} $@
821 error "Unrecognized action
: ${action}"
822 cli_run_help network dhcpvN subnet
829 for subnet_id in $(dhcpd_subnet_list ${proto}); do
830 cli_dhcpd_subnet_show ${proto} ${subnet_id}
834 error "Unrecognized action
: ${action}"
835 cli_run_help network dhcpvN subnet
844 function cli_dhcpd_subnet_range() {
850 assert isset subnet_id
858 dhcpd_subnet_range_new ${proto} ${subnet_id} $@
862 dhcpd_subnet_range_remove ${proto} ${subnet_id} $@
866 error "Unrecognized action
: ${action}"
867 cli_run_help network dhcpvN subnet range
873 function cli_dhcpd_subnet_show() {
878 assert isset subnet_id
881 isset level || level=0
883 local $(dhcpd_subnet_settings ${proto})
885 # Read in configuration settings.
886 dhcpd_subnet_read ${proto} ${subnet_id}
888 cli_headline $(( ${level} + 1 )) \
889 "DHCP
${proto/ip/} subnet declaration
#${subnet_id}"
890 cli_print_fmt1 $
(( ${level} + 1 )) \
891 "Subnet" "${ADDRESS}/${PREFIX}"
896 dhcpd_subnet_options_read
${proto} ${subnet_id}
898 # Print the options if any.
899 if [ ${#options[*]} -gt 0 ]; then
900 cli_headline $
(( ${level} + 2 )) "Options"
903 for option
in $
(dhcpd_subnet_options
${proto}); do
904 [ -n "${options[${option}]}" ] ||
continue
906 cli_print_fmt1 $
(( ${level} + 2 )) \
907 "${option}" "${options[${option}]}"
913 cli_headline $
(( ${level} + 2 )) "Ranges"
915 local ranges
=$
(dhcpd_subnet_range_list
${proto} ${subnet_id})
916 if isset ranges
; then
917 local range_id $
(dhcpd_subnet_range_settings
${proto})
918 for range_id
in ${ranges}; do
919 dhcpd_subnet_range_read
${proto} ${subnet_id} ${range_id}
921 cli_print $
(( ${level} + 2 )) \
922 "#%d: %s - %s" ${range_id} ${START} ${END}
925 cli_print $
(( ${level} + 2 )) "No ranges have been defined."
931 function cli_dhcpd_options
() {
937 assert isset subnet_id
940 local valid_options
=$
(dhcpd_subnet_options
${proto})
943 while [ $# -gt 0 ]; do
946 key
=$
(cli_get_key
${1})
947 val
=$
(cli_get_val
${1})
949 dhcpd_subnet_option_set
${proto} ${subnet_id} ${key} ${val}
954 function cli_start
() {
955 if cli_help_requested $@
; then
960 local zones
=$
(zones_get $@
)
963 for zone
in ${zones}; do
967 wait # until everything is settled
970 function cli_stop
() {
971 if cli_help_requested $@
; then
976 local zones
=$
(zones_get $@
)
979 for zone
in ${zones}; do
983 wait # until everything is settled
986 function cli_restart
() {
987 if cli_help_requested $@
; then
994 # Give the system some time to calm down
995 sleep ${TIMEOUT_RESTART}
1000 function cli_status
() {
1001 if cli_help_requested $@
; then
1002 cli_show_man network
1006 # When dumping status information, the debug
1007 # mode clutters the console which is not what we want.
1008 # Logging on the console is disabled for a short time.
1009 local log_disable_stdout
=${LOG_DISABLE_STDOUT}
1010 LOG_DISABLE_STDOUT
="true"
1012 local zones
=$
(zones_get $@
)
1015 for zone
in ${zones}; do
1020 LOG_DISABLE_STDOUT
=${log_disable_stdout}
1023 function cli_reset
() {
1024 if cli_help_requested $@
; then
1025 cli_show_man network
1029 warning_log
"Will reset the whole network configuration!!!"
1031 # Force mode is disabled by default
1034 while [ $# -gt 0 ]; do
1043 # If we are not running in force mode, we ask the user if he does know
1045 if ! enabled force
; then
1046 if ! cli_yesno
"Do you really want to reset the whole network configuration?"; then
1052 for zone
in $
(zones_get
--all); do
1057 for port
in $
(ports_get
--all); do
1061 # Flush all DNS servers.
1064 # Re-run the initialization functions
1070 # Help function: will show the default man page to the user.
1071 # Optionally, there are two arguments taken, the type of hook
1072 # and which hook should be shown.
1073 function cli_help
() {
1077 # Remove unknown types.
1078 if ! listmatch
${type} zone port config
; then
1082 # If no arguments were given, we will show the default page.
1083 if [ -z "${type}" ]; then
1084 cli_show_man network
1088 if ! hook_exists
${type} ${what}; then
1089 error
"Hook of type '${type}' and name '${what}' could not be found."
1090 exit "${EXIT_ERROR}"
1093 hook_exec
${type} ${what} help
1096 function cli_dns_server
() {
1097 if cli_help_requested $@
; then
1098 cli_show_man network-dns-server
1103 local cmd
=${1}; shift
1104 if [ -z "${cmd}" ]; then
1105 cli_show_man network-dns-server
1109 # Get the new server to process (if any).
1119 if dns_server_exists
${server}; then
1120 error
"DNS server '${server}' already exists!"
1124 log INFO
"Adding new DNS server: ${server}"
1125 dns_server_add
${server} ${priority}
1128 if ! dns_server_exists
${server}; then
1129 error
"DNS server '${server}' does not exist!"
1133 log INFO
"Removing DNS server: ${server}"
1134 dns_server_remove
${server} ${priority}
1137 # Just run the update afterwards.
1140 error
"No such command: ${cmd}"
1144 # Update the local DNS configuration after changes have been made.
1145 dns_generate_resolvconf
1151 # Process the given action
1157 settings|hostname|port|device|zone|start|stop|restart|status|
reset|route
)
1161 # DHCP server configuration (automatically detects which protocol to use).
1163 cli_dhcpd
${action/dhcp/ip} $@
1166 # DNS server configuration.
1176 error
"Invalid command given: ${action}"
1177 cli_usage
"network help"
1178 exit ${EXIT_CONF_ERROR}