]>
git.ipfire.org Git - ipfire-2.x.git/blob - html/cgi-bin/connections.cgi
3 # (c) 2001 Jack Beglinger <jackb_guppy@yahoo.com>
5 # (c) 2003 Dave Roberts <countzerouk@hotmail.com> - colour coded netfilter/iptables rewrite for 1.3
7 # (c) 2006 Franck - add sorting+filtering capability
9 # $Id: connections.cgi,v 1.6.2.12 2006/02/27 19:48:46 franck78 Exp $
12 # Setup GREEN, ORANGE, IPCOP, VPN CIDR networks, masklengths and colours only once
18 use Net
::IPv4Addr
qw( :all );
22 # enable only the following on debugging purpose
24 #use CGI::Carp 'fatalsToBrowser';
26 require 'CONFIG_ROOT/general-functions.pl';
27 require "${General::swroot}/lang.pl";
28 require "${General::swroot}/header.pl";
30 #workaround to suppress a warning when a variable is used only once
31 my @dummy = ( ${Header
::table1colour
} );
37 &General
::readhash
("${General::swroot}/ethernet/settings", \
%netsettings);
39 open (ACTIVE
, "/proc/net/ip_conntrack") or die 'Unable to open ip_conntrack';
40 my @active = <ACTIVE
>;
44 open (ACTIVE
, "/proc/net/ipsec_eroute") and @vpn = <ACTIVE
>;
47 my $aliasfile = "${General::swroot}/ethernet/aliases";
48 open(ALIASES
, $aliasfile) or die 'Unable to open aliases file.';
49 my @aliases = <ALIASES
>;
52 # Add Green Firewall Interface
53 push(@network, $netsettings{'GREEN_ADDRESS'});
54 push(@masklen, "255.255.255.255" );
55 push(@colour, ${Header
::colourfw
} );
57 # Add Green Network to Array
58 push(@network, $netsettings{'GREEN_NETADDRESS'});
59 push(@masklen, $netsettings{'GREEN_NETMASK'} );
60 push(@colour, ${Header
::colourgreen
} );
62 # Add Green Routes to Array
63 my @routes = `/sbin/route -n | /bin/grep $netsettings{'GREEN_DEV'}`;
64 foreach my $route (@routes) {
66 my @temp = split(/[\t ]+/, $route);
67 push(@network, $temp[0]);
68 push(@masklen, $temp[2]);
69 push(@colour, ${Header
::colourgreen
} );
72 # Add Firewall Localhost 127.0.0.1
73 push(@network, '127.0.0.1');
74 push(@masklen, '255.255.255.255' );
75 push(@colour, ${Header
::colourfw
} );
77 # Add OpenVPN net and RED/BLUE/ORANGE entry (when appropriate)
78 if (-e
"${General::swroot}/ovpn/settings") {
79 my %ovpnsettings = ();
80 &General
::readhash
("${General::swroot}/ovpn/settings", \
%ovpnsettings);
81 my @tempovpnsubnet = split("\/",$ovpnsettings{'DOVPN_SUBNET'});
84 push(@network, $tempovpnsubnet[0]);
85 push(@masklen, $tempovpnsubnet[1]);
86 push(@colour, ${Header
::colourovpn
} );
88 push(@protocols, '' );
90 if ( ($ovpnsettings{'ENABLED'} eq 'on') && open(IP
, "${General::swroot}/red/local-ipaddress") ) {
91 # add RED:port / proto
95 push(@network, $redip );
96 push(@masklen, '255.255.255.255' );
97 push(@colour, ${Header
::colourovpn
} );
98 push(@ports, $ovpnsettings{'DDEST_PORT'} );
99 push(@protocols, $ovpnsettings{'DPROTOCOL'} );
101 if ( ($ovpnsettings{'ENABLED_BLUE'} eq 'on') && $netsettings{'BLUE_DEV'} ) {
102 # add BLUE:port / proto
103 push(@network, $netsettings{'BLUE_ADDRESS'} );
104 push(@masklen, '255.255.255.255' );
105 push(@colour, ${Header
::colourovpn
} );
106 push(@ports, $ovpnsettings{'DDEST_PORT'} );
107 push(@protocols, $ovpnsettings{'DPROTOCOL'} );
109 if ( ($ovpnsettings{'ENABLED_ORANGE'} eq 'on') && $netsettings{'ORANGE_DEV'} ) {
110 # add ORANGE:port / proto
111 push(@network, $netsettings{'ORANGE_ADDRESS'} );
112 push(@masklen, '255.255.255.255' );
113 push(@colour, ${Header
::colourovpn
} );
114 push(@ports, $ovpnsettings{'DDEST_PORT'} );
115 push(@protocols, $ovpnsettings{'DPROTOCOL'} );
120 if ($netsettings{'ORANGE_DEV'}) {
121 push(@network, $netsettings{'ORANGE_NETADDRESS'});
122 push(@masklen, $netsettings{'ORANGE_NETMASK'} );
123 push(@colour, ${Header
::colourorange
} );
124 # Add Orange Routes to Array
125 @routes = `/sbin/route -n | /bin/grep $netsettings{'ORANGE_DEV'}`;
126 foreach my $route (@routes) {
128 my @temp = split(/[\t ]+/, $route);
129 push(@network, $temp[0]);
130 push(@masklen, $temp[2]);
131 push(@colour, ${Header
::colourorange
} );
136 if ($netsettings{'BLUE_DEV'}) {
137 push(@network, $netsettings{'BLUE_NETADDRESS'});
138 push(@masklen, $netsettings{'BLUE_NETMASK'} );
139 push(@colour, ${Header
::colourblue
} );
140 # Add Blue Routes to Array
141 @routes = `/sbin/route -n | /bin/grep $netsettings{'BLUE_DEV'}`;
142 foreach my $route (@routes) {
144 my @temp = split(/[\t ]+/, $route);
145 push(@network, $temp[0]);
146 push(@masklen, $temp[2]);
147 push(@colour, ${Header
::colourblue
} );
151 # Add STATIC RED aliases
152 if ($netsettings{'RED_DEV'}) {
153 # We have a RED eth iface
154 if ($netsettings{'RED_TYPE'} eq 'STATIC') {
155 # We have a STATIC RED eth iface
156 foreach my $line (@aliases)
159 my @temp = split(/\,/,$line);
161 push(@network, $temp[0]);
162 push(@masklen, $netsettings{'RED_NETMASK'} );
163 push(@colour, ${Header
::colourfw
} );
170 if ( $vpn[0] ne 'none' ) {
171 foreach my $line (@vpn) {
172 my @temp = split(/[\t ]+/,$line);
173 my @temp1 = split(/[\/:]+/,$temp[3]);
174 push(@network, $temp1[0]);
175 push(@masklen, ipv4_cidr2msk
($temp1[1]));
176 push(@colour, ${Header
::colourvpn
} );
179 if (open(IP
, "${General::swroot}/red/local-ipaddress")) {
183 push(@network, $redip);
184 push(@masklen, '255.255.255.255' );
185 push(@colour, ${Header
::colourfw
} );
189 #Establish simple filtering&sorting boxes on top of table
192 &Header
::getcgihash
(\
%cgiparams);
194 my @list_proto = ($Lang::tr
{'all'}, 'icmp', 'udp', 'tcp');
195 my @list_state = ($Lang::tr
{'all'}, 'SYN_SENT', 'SYN_RECV', 'ESTABLISHED', 'FIN_WAIT',
196 'CLOSE_WAIT', 'LAST_ACK', 'TIME_WAIT', 'CLOSE', 'LISTEN');
197 my @list_mark = ($Lang::tr
{'all'}, '[ASSURED]', '[UNREPLIED]');
198 my @list_sort = ('orgsip','protocol', 'expires', 'status', 'orgdip', 'orgsp',
199 'orgdp', 'exsip', 'exdip', 'exsp', 'exdp');
201 # init or silently correct unknown value...
202 if ( ! grep ( /^$cgiparams{'SEE_PROTO'}$/ , @list_proto )) { $cgiparams{'SEE_PROTO'} = $list_proto[0] };
203 if ( ! grep ( /^$cgiparams{'SEE_STATE'}$/ , @list_state )) { $cgiparams{'SEE_STATE'} = $list_state[0] };
204 if ( ! grep ( /^$cgiparams{'SEE_MARK'}$/ , @list_mark )) { $cgiparams{'SEE_MARK'} = $list_mark[0] };
205 if ( ! grep ( /^$cgiparams{'SEE_SORT'}$/ , @list_sort )) { $cgiparams{'SEE_SORT'} = $list_sort[0] };
206 # *.*.*.* or a valid IP
207 if ( $cgiparams{'SEE_SRC'} !~ /^(\*\.\*\.\*\.\*\.|\d+\.\d+\.\d+\.\d+)$/) { $cgiparams{'SEE_SRC'} = '*.*.*.*' };
208 if ( $cgiparams{'SEE_DEST'} !~ /^(\*\.\*\.\*\.\*\.|\d+\.\d+\.\d+\.\d+)$/) { $cgiparams{'SEE_DEST'} = '*.*.*.*' };
211 our %entries = (); # will hold the lines analyzed correctly
212 my $unknownlines = ''; # should be empty all the time...
213 my $index = 0; # just a counter to make unique entryies in entries
215 foreach my $line (@active) {
231 my @temp = split(' ',$line);
233 if ($temp[0] eq 'icmp') {
234 $protocol = $temp[0];
235 $status = $Lang::tr
{'all'};
236 $orgsip = substr $temp[3], 4;
237 $orgdip = substr $temp[4], 4;
238 $marked = $temp[8] eq '[UNREPLIED]' ?
'[UNREPLIED]' : ' ';
240 if ($temp[0] eq 'udp') {
241 $protocol = $temp[0];
242 $status = $Lang::tr
{'all'};
243 $orgsip = substr $temp[3], 4;
244 $orgdip = substr $temp[4], 4;
245 $marked = $temp[7] eq '[UNREPLIED]' ?
'[UNREPLIED]' : defined ($temp[12]) ?
$temp[11] : ' ';
247 if ($temp[0] eq 'tcp') {
248 $protocol = $temp[0];
250 $orgsip = substr $temp[4], 4;
251 $orgdip = substr $temp[5], 4;
252 $marked = $temp[8] eq '[UNREPLIED]' ?
'[UNREPLIED]' : defined ($temp[13]) ?
$temp[12] : ' ';
255 # filter the line if we found a known proto
257 (($cgiparams{'SEE_PROTO'} eq $Lang::tr
{'all'}) || ($protocol eq $cgiparams{'SEE_PROTO'} ))
258 && (($cgiparams{'SEE_STATE'} eq $Lang::tr
{'all'}) || ($status eq $cgiparams{'SEE_STATE'} ))
259 && (($cgiparams{'SEE_MARK'} eq $Lang::tr
{'all'}) || ($marked eq $cgiparams{'SEE_MARK'} ))
260 && (($cgiparams{'SEE_SRC'} eq "*.*.*.*") || ($orgsip eq $cgiparams{'SEE_SRC'} ))
261 && (($cgiparams{'SEE_DEST'} eq "*.*.*.*") || ($orgdip eq $cgiparams{'SEE_DEST'} ))
264 if ($temp[0] eq 'icmp') {
266 $protocol = $temp[0] . " (" . $temp[1] . ")";
269 if ($temp[8] eq '[UNREPLIED]' ) {
272 $orgsip = substr $temp[3], 4;
273 $orgdip = substr $temp[4], 4;
274 $orgsp = &General
::GetIcmpDescription
(substr( $temp[5], 5)) . "/" . substr( $temp[6], 5);;
275 $orgdp = 'id=' . substr( $temp[7], 3);
276 $exsip = substr $temp[8 + $offset], 4;
277 $exdip = substr $temp[9 + $offset], 4;
278 $exsp = &General
::GetIcmpDescription
(substr( $temp[10 + $offset], 5)). "/" . substr( $temp[11 + $offset], 5);
279 $exdp = 'id=' . substr( $temp[11 + $offset], 5);
280 $marked = $temp[8] eq '[UNREPLIED]' ?
'[UNREPLIED]' : ' ';
281 $use = substr( $temp[13 + $offset], 4 );
283 if ($temp[0] eq 'udp') {
286 $protocol = $temp[0] . " (" . $temp[1] . ")";
289 $orgsip = substr $temp[3], 4;
290 $orgdip = substr $temp[4], 4;
291 $orgsp = substr $temp[5], 6;
292 $orgdp = substr $temp[6], 6;
293 if ($temp[7] eq '[UNREPLIED]') {
296 $use = substr $temp[12], 4;
298 if ((substr $temp[11], 0, 3) eq 'use' ) {
300 $use = substr $temp[11], 4;
303 $use = substr $temp[12], 4;
306 $exsip = substr $temp[7 + $offset], 4;
307 $exdip = substr $temp[8 + $offset], 4;
308 $exsp = substr $temp[9 + $offset], 6;
309 $exdp = substr $temp[10 + $offset], 6;
311 if ($temp[0] eq 'tcp') {
313 $protocol = $temp[0] . " (" . $temp[1] . ")";
316 $orgsip = substr $temp[4], 4;
317 $orgdip = substr $temp[5], 4;
318 $orgsp = substr $temp[6], 6;
319 $orgdp = substr $temp[7], 6;
320 if ($temp[8] eq '[UNREPLIED]') {
326 $exsip = substr $temp[8 + $offset], 4;
327 $exdip = substr $temp[9 + $offset], 4;
328 $exsp = substr $temp[10 + $offset], 6;
329 $exdp = substr $temp[11 + $offset], 6;
330 $use = substr $temp[13], 4;
332 if ($temp[0] eq 'unknown') {
334 $protocol = "??? (" . $temp[1] . ")";
335 $protocol = "esp (" . $temp[1] . ")" if ($temp[1] == 50);
336 $protocol = "ah (" . $temp[1] . ")" if ($temp[1] == 51);
339 $orgsip = substr $temp[3], 4;
340 $orgdip = substr $temp[4], 4;
343 $exsip = substr $temp[5], 4;
344 $exdip = substr $temp[6], 4;
350 if ($temp[0] eq 'gre') {
352 $protocol = $temp[0] . " (" . $temp[1] . ")";
354 $orgsip = substr $temp[5], 4;
355 $orgdip = substr $temp[6], 4;
358 $exsip = substr $temp[11], 4;
359 $exdip = substr $temp[12], 4;
365 # Only from this point, lines have the same known format/field
366 # The floating fields [UNREPLIED] [ASSURED] etc are ok.
368 # Store the line in a hash array for sorting
369 if ( $protocol ) { # line is decoded ?
370 my @record = ( 'index', $index++,
371 'protocol', $protocol,
384 my $record = {}; # create a reference to empty hash
385 %{$record} = @record; # populate that hash with @record
386 $entries{$record->{index}} = $record; # add this to a hash of hashes
387 } else { # it was not a known line
388 $unknownlines .= "<tr bgcolor='${Header::table1colour}'>";
389 $unknownlines .= "<td colspan='9'> unknown:$line></td></tr>";
393 # Build listbox objects
394 my $menu_proto = &make_select
('SEE_PROTO', $cgiparams{'SEE_PROTO'}, @list_proto);
395 my $menu_state = &make_select
('SEE_STATE', $cgiparams{'SEE_STATE'}, @list_state);
396 my $menu_src = &make_select
('SEE_SRC', $cgiparams{'SEE_SRC'}, &get_known_ips
('orgsip'));
397 my $menu_dest = &make_select
('SEE_DEST', $cgiparams{'SEE_DEST'}, &get_known_ips
('orgdip'));
398 my $menu_mark = &make_select
('SEE_MARK', $cgiparams{'SEE_MARK'}, @list_mark);
399 my $menu_sort = &make_select
('SEE_SORT', $cgiparams{'SEE_SORT'}, @list_sort);
401 &Header
::showhttpheaders
();
402 &Header
::openpage
($Lang::tr
{'connections'}, 1, '');
403 &Header
::openbigbox
('100%', 'left');
404 &Header
::openbox
('100%', 'left', $Lang::tr
{'connection tracking'});
408 <tr><td align='center'><b>$Lang::tr{'legend'} : </b></td>
409 <td align='center' bgcolor='${Header::colourgreen}'><b><font color='#FFFFFF'>$Lang::tr{'lan'}</font></b></td>
410 <td align='center' bgcolor='${Header::colourred}'><b><font color='#FFFFFF'>$Lang::tr{'internet'}</font></b></td>
411 <td align='center' bgcolor='${Header::colourorange}'><b><font color='#FFFFFF'>$Lang::tr{'dmz'}</font></b></td>
412 <td align='center' bgcolor='${Header::colourblue}'><b><font color='#FFFFFF'>$Lang::tr{'wireless'}</font></b></td>
413 <td align='center' bgcolor='${Header::colourfw}'><b><font color='#FFFFFF'>IPFire</font></b></td>
414 <td align='center' bgcolor='${Header::colourvpn}'><b><font color='#FFFFFF'>$Lang::tr{'vpn'}</font></b></td>
415 <td align='center' bgcolor='${Header::colourovpn}'><b><font color='#FFFFFF'>$Lang::tr{'OpenVPN'}</font></b></td>
419 <table cellpadding='2'>
420 <tr><td align='center'><b>$Lang::tr{'protocol'}</b></td>
421 <td align='center'><b>$Lang::tr{'expires'}<br />($Lang::tr{'seconds'})</b></td>
422 <td align='center'><b>$Lang::tr{'connection'}<br />$Lang::tr{'status'}</b></td>
423 <td align='center'><b>$Lang::tr{'original'}<br />$Lang::tr{'source ip and port'}</b></td>
424 <td align='center'><b>$Lang::tr{'original'}<br />$Lang::tr{'dest ip and port'}</b></td>
425 <td align='center'><b>$Lang::tr{'expected'}<br />$Lang::tr{'source ip and port'}</b></td>
426 <td align='center'><b>$Lang::tr{'expected'}<br />$Lang::tr{'dest ip and port'}</b></td>
427 <td align='center'><b>$Lang::tr{'marked'}</b></td>
428 <td align='center'><b>$Lang::tr{'use'}</b></td>
430 <tr><form method='post' action='$ENV{'SCRIPT_NAME'}'>
431 <td align='center'>$menu_proto</td>
433 <td align='center'>$menu_state</td>
434 <td align='center'>$menu_src</td>
435 <td align='center'>$menu_dest</td>
436 <td align='center'colspan='2'>$Lang::tr{'sort ascending'}:$menu_sort </td>
437 <td align='center'>$menu_mark</td>
438 <td align='center'><input type='submit' value='!' /></td>
444 foreach my $entry (sort sort_entries
keys %entries) {
446 print "<tr bgcolor='${Header::table1colour}'>";
447 my $orgsipcolour = &ipcolour
( $entries{$entry}->{orgsip
} );
448 my $orgdipcolour = &ipcolour
( $entries{$entry}->{orgdip
} );
449 my $exsipcolour = &ipcolour
( $entries{$entry}->{exsip
} );
450 my $exdipcolour = &ipcolour
( $entries{$entry}->{exdip
} );
452 <td align='center'>$entries{$entry}->{protocol}</td>
453 <td align='center'>$entries{$entry}->{expires}</td>
454 <td align='center'>$entries{$entry}->{status}</td>
455 <td align='center' bgcolor='$orgsipcolour'>
456 <a href='/cgi-bin/ipinfo.cgi?ip=$entries{$entry}->{orgsip}'>
457 <font color='#FFFFFF'>$entries{$entry}->{orgsip}</font>
458 </a><font color='#FFFFFF'>:$entries{$entry}->{orgsp}</font></td>
459 <td align='center' bgcolor='$orgdipcolour'>
460 <a href='/cgi-bin/ipinfo.cgi?ip=$entries{$entry}->{orgdip}'>
461 <font color='#FFFFFF'>$entries{$entry}->{orgdip}</font>
462 </a><font color='#FFFFFF'>:$entries{$entry}->{orgdp}</font></td>
463 <td align='center' bgcolor='$exsipcolour'>
464 <a href='/cgi-bin/ipinfo.cgi?ip=$entries{$entry}->{exsip}'>
465 <font color='#FFFFFF'>$entries{$entry}->{exsip}</font>
466 </a><font color='#FFFFFF'>:$entries{$entry}->{exsp}</font></td>
467 <td align='center' bgcolor='$exdipcolour'>
468 <a href='/cgi-bin/ipinfo.cgi?ip=$entries{$entry}->{exdip}'>
469 <font color='#FFFFFF'>$entries{$entry}->{exdip}</font>
470 </a><font color='#FFFFFF'>:$entries{$entry}->{exdp}</font></td>
471 <td align='center'>$entries{$entry}->{marked}</td>
472 <td align='center'>$entries{$entry}->{use}</td>
478 print "$unknownlines</table>";
481 &Header
::closebigbox
();
482 &Header
::closepage
();
487 my $colour = ${Header
::colourred
};
490 foreach $line (@network) {
491 if (!$found && ipv4_in_network
( $network[$id] , $masklen[$id], $ip) ) {
493 $colour = $colour[$id];
500 # Create a string containing a complete SELECT html object
502 # param2: current value selected
504 sub make_select
($,$,$) {
505 my $select_name = shift;
506 my $selected = shift;
507 my $select = "<select name='$select_name'>";
509 foreach my $value (@_) {
510 my $check = $selected eq $value ?
"selected='selected'" : '';
511 $select .= "<option $check value='$value'>$value";
513 $select .= "</select>";
517 # Build a list of IP obtained from the %entries hash
518 # param1: IP field name
519 sub get_known_ips
($) {
521 my $qs = $cgiparams{'SEE_SORT'}; # switch the sort order
522 $cgiparams{'SEE_SORT'} = $field;
524 my @liste=('*.*.*.*');
525 foreach my $entry ( sort sort_entries
keys %entries) {
526 push (@liste, $entries{$entry}->{$field}) if (! grep (/^$entries{$entry}->{$field}$/,@liste) );
529 $cgiparams{'SEE_SORT'} = $qs; #restore sort order
533 # Used to sort the table containing the lines displayed.
534 sub sort_entries
{ #Reverse is not implemented
535 my $qs=$cgiparams{'SEE_SORT'};
536 if ($qs =~ /orgsip|orgdip|exsip|exdip/) {
537 my @a = split(/\./,$entries{$a}->{$qs});
538 my @b = split(/\./,$entries{$b}->{$qs});
543 } elsif ($qs =~ /expire|orgsp|orgdp|exsp|exdp/) {
544 $entries{$a}->{$qs} <=> $entries{$b}->{$qs};
546 $entries{$a}->{$qs} cmp $entries{$b}->{$qs};