2 ###############################################################################
4 # IPFire.org - A linux based firewall #
5 # Copyright (C) 2010 Michael Tremer & Christian Schmidt #
7 # This program is free software: you can redistribute it and/or modify #
8 # it under the terms of the GNU General Public License as published by #
9 # the Free Software Foundation, either version 3 of the License, or #
10 # (at your option) any later version. #
12 # This program is distributed in the hope that it will be useful, #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15 # GNU General Public License for more details. #
17 # You should have received a copy of the GNU General Public License #
18 # along with this program. If not, see <http://www.gnu.org/licenses/>. #
20 ###############################################################################
22 # Parse the command line
23 while [ $# -gt 0 ]; do
33 [ -n "${action}" ] && break
36 .
/usr
/lib
/network
/functions
38 # Read network settings
42 if cli_help_requested $@
; then
43 cli_show_man network-settings
47 if [ -n "${1}" ]; then
48 network_settings_set $@
49 network_settings_write
51 network_settings_print
56 if cli_help_requested $@
; then
57 cli_show_man network-device
69 local device
="${action}"
73 if ! isset device
; then
74 cli_show_man network-device
78 assert device_exists
${device}
82 cli_device_discover
${device} $@
85 device_identify
"${device}" $@
88 cli_device_monitor
"${device}" $@
91 cli_device_status
${device}
94 cli_device_serial_unlock
${device} $@
97 cli_device_send_ussd_command
"${device}" $@
100 cli_show_man network-device
109 cli_device_status
() {
113 # Disable debugging output here.
114 local log_disable_stdout
=${LOG_DISABLE_STDOUT}
115 LOG_DISABLE_STDOUT
="true"
117 # Save the type of the device for later.
118 local type=$
(device_get_type
${device})
120 cli_headline
1 "Device status: ${device}"
121 cli_print_fmt1
1 "Name" "${device}"
123 # Handle special devices
126 cli_device_status_phy
"${device}"
130 cli_device_status_serial
"${device}"
135 # Print the device status.
136 device_is_up
${device} &>/dev
/null
141 status
="${CLR_GREEN_B}UP${CLR_RESET}"
144 status
="${CLR_RED_B}DOWN${CLR_RESET}"
148 cli_print_fmt1
1 "Status" "${status}"
149 cli_print_fmt1
1 "Type" "${type}"
151 # Ethernet-compatible?
152 device_is_ethernet_compatible
"${device}" &>/dev
/null
153 cli_print_fmt1
1 "Ethernet-compatible" "$(cli_print_bool $?)"
155 cli_print_fmt1
1 "Address" "$(device_get_address ${device})"
158 # Print the link speed for ethernet devices.
159 if device_is_up
${device} &>/dev
/null
; then
160 local link
="$(device_get_link_string "${device}")"
162 cli_print_fmt1
1 "Link" "${link}"
166 cli_print_fmt1
1 "MTU" "$(device_get_mtu ${device})"
169 # Print device statistics.
170 cli_device_stats
2 ${device}
172 # Print some more information.
173 device_has_carrier
${device} &>/dev
/null
174 cli_print_fmt1
1 "Has carrier?" "$(cli_print_bool $?)"
176 device_is_promisc
${device} &>/dev
/null
177 cli_print_fmt1
1 "Promisc" "$(cli_print_bool $?)"
179 # Supports multiqueue?
180 if device_supports_multiqueue
${device}; then
181 cli_print_fmt
1 "Multiqueue" "Supported"
185 cli_device_show_queues
2 ${device}
187 # Print all vlan devices.
188 local vlans
=$
(device_get_vlans
${device})
189 if [ -n "${vlans}" ]; then
190 cli_headline
2 "VLAN devices"
193 for vlan
in ${vlans}; do
194 cli_print
2 "* %-6s - %s" "${vlan}" "$(device_get_address ${vlan})"
201 local phy
="$(device_get_phy "${device}")"
204 cli_print_fmt1
2 "Name" "${phy}"
205 cli_print_fmt1
2 "Address" "$(phy_get_address "${phy}")"
211 # Reset the logging level.
212 LOG_DISABLE_STDOUT
=${log_disable_stdout}
215 cli_device_status_serial
() {
217 assert device_is_serial
${device}
219 serial_is_locked
${device} &>/dev
/null
222 cli_print_fmt1
1 "Locked" "$(cli_print_bool ${locked})"
225 # Cannot go on when the device is locked.
226 [ ${locked} -eq ${EXIT_TRUE} ] && return ${EXIT_OK}
228 cli_print_fmt1
1 "Manufacturer" \
229 "$(modem_get_manufacturer ${device})"
230 cli_print_fmt1
1 "Model" \
231 "$(modem_get_model ${device})"
232 cli_print_fmt1
1 "Software version" \
233 "$(modem_get_software_version ${device})"
236 if modem_is_mobile
"${device}"; then
237 cli_print_fmt1
1 "IMEI" \
238 "$(modem_get_device_imei ${device})"
242 if modem_is_mobile
"${device}"; then
243 modem_mobile_network_status
"${device}" 2
248 cli_device_status_phy
() {
250 assert phy_exists
"${phy}"
252 local address
="$(phy_get_address "${phy}")"
253 cli_print_fmt1
1 "Address" "${address}"
256 local devices
="$(phy_get_devices "${phy}")"
257 if isset devices
; then
258 cli_headline
2 "Soft interfaces"
261 for device
in ${devices}; do
262 cli_print
2 "* %s" "${device}"
270 cli_device_discover
() {
274 # This can only be executed for ethernet (or compatible) devices
275 if ! device_is_ethernet_compatible
"${device}"; then
281 while [ $# -gt 0 ]; do
291 device_is_up
${device} && up
=1
292 device_set_up
${device}
294 enabled raw ||
echo "${device}"
299 for hook
in $
(hook_zone_get_all
); do
300 out
=$
(hook_zone_exec
${hook} discover
${device})
303 [ ${ret} -eq ${DISCOVER_NOT_SUPPORTED} ] && continue
311 echo "${hook}: ${line}"
316 echo "${hook}: FAILED"
322 echo " ${hook} was successful."
330 echo " ${hook} failed."
338 [ "${up}" = "1" ] || device_set_down
${device}
341 cli_device_serial_unlock
() {
342 if cli_help_requested $@
; then
343 cli_show_man network-device
350 if ! device_is_serial
${device}; then
351 error
"${device} is not a serial device."
352 error
"Unlocking is only supported for serial devices."
356 # Read the current state of the SIM card.
357 modem_sim_status
${device} &>/dev
/null
358 local sim_status_code
=$?
360 # If the SIM card is already unlocked, we don't need to do anything.
361 if [ ${sim_status_code} -eq ${EXIT_SIM_READY} ]; then
362 print
"The SIM card is already unlocked."
365 # If the SIM card is in an unknown state, we cannot do anything.
366 elif [ ${sim_status_code} -eq ${EXIT_SIM_UNKNOWN} ]; then
367 error
"The SIM card is in an unknown state."
373 local require_new_pin
="false"
376 while ! isinteger code
; do
378 case "${sim_status_code}" in
380 message
="Please enter PIN:"
383 message
="Please enter PUK:"
384 require_new_pin
="true"
389 echo -n "${message} "
391 echo # Print newline.
393 if enabled require_new_pin
; then
398 message
="Please enter a new PIN code:"
401 message
="Please confirm the new PIN code:"
405 echo -n "${message} "
407 echo # Print newline.
409 if [ -n "${new_pin}" ]; then
410 if [ "${new_pin}" != "${new_pin2}" ]; then
411 error
"The entered PIN codes did not match."
421 # Trying to unlock the SIM card.
422 modem_sim_unlock
${device} ${code} ${new_pin}
427 cli_device_send_ussd_command
() {
435 while [ $# -gt 0 ]; do
438 timeout
="$(cli_get_val "${1}")"
441 if isset
command; then
442 warning
"Unrecognized argument: ${1}"
451 assert device_is_serial
"${device}"
454 if isset timeout
; then
455 args
="${args} --timeout=${timeout}"
458 modem_ussd_send_command
"${device}" "${command}" ${args}
462 cli_device_monitor() {
466 if ! device_is_wireless "${device}"; then
467 error "This action only works with wireless devices. Exiting.
"
471 wireless_monitor "${device}"
477 for device in $(device_list); do
478 cli_device_status "${device}"
485 if cli_help_requested $@; then
492 if [ -n "${hostname}" ]; then
493 config_hostname ${hostname}
494 log INFO "Hostname was
set to
'${hostname}'.
"
495 log INFO "Changes
do only take affect after reboot.
"
499 echo "$
(config_hostname
)"
504 if cli_help_requested $@; then
505 cli_show_man network-port
512 if port_exists ${1}; then
518 edit|create|remove|up|down|status|identify)
519 port_${action} "${port}" $@
522 color_cli "port
" "${port}" $@
525 description_cli "port
" "${port}" $@
528 error "Unrecognized argument
: ${action}"
541 error "Unrecognized argument
: ${action}"
549 if cli_help_requested $@; then
550 cli_show_man network-zone
557 if zone_exists ${1}; then
577 cli_zone_port "${zone}" $@
580 cli_zone_rename "${zone}" $@
582 config|disable|down|edit|enable|identify|status|up)
583 zone_${action} ${zone} $@
586 color_cli "zone
" "${zone}" $@
589 description_cli "zone
" ${zone} $@
592 error "Unrecognized argument
: ${action}"
593 cli_show_man network-zone
609 if [ -n "${action}" ]; then
610 error "Unrecognized argument
: '${action}'"
614 cli_show_man network-zone
622 if cli_help_requested $@ || [ $# -lt 2 ]; then
623 cli_show_man network-zone-new
630 # Removes a zone either immediately, if it is currently down,
631 # or adds a tag that the removal will be done when the zone
632 # is brought down the next time.
634 if cli_help_requested $@; then
635 cli_show_man network-zone
640 assert zone_exists "${zone}"
642 if zone_is_up ${zone}; then
643 echo "Zone
'${zone}' is up and will be removed when it goes down the next
time.
"
644 zone_destroy "${zone}"
646 echo "Removing zone
'${zone}' now...
"
647 zone_destroy_now "${zone}"
654 if cli_help_requested $@; then
655 cli_show_man network-zone-port
660 assert zone_exists "${zone}"
662 if port_exists "${2}"; then
669 zone_port_edit "${zone}" "${port}" $@
672 error "Unrecognised argument
: ${action}"
682 zone_port_attach "${zone}" $@
685 zone_port_detach "${zone}" $@
688 error "Unrecognised argument
: ${action}"
698 if cli_help_requested $@; then
699 cli_show_man network-zone
707 if ! isset name; then
708 error "You need to pass a new name
"
712 if ! zone_name_is_valid "${name}"; then
713 error "Invalid new zone name
: ${name}"
717 # Check if the zone exists
718 if ! zone_exists "${zone}"; then
719 error "Zone
${zone} does not exist
"
723 # Destroyed zones cannot be renamed
724 if zone_has_destroy_tag "${zone}"; then
725 error "Zone
${zone} is about to be destroyed and cannot be renamed
"
729 # Check if a zone with the new name already exists
730 if zone_exists "${name}"; then
731 error "Zone
${name} already exists
"
736 if ! zone_rename "${zone}" "${name}"; then
737 error "Could not rename zone
${zone} to
${name}"
748 if cli_help_requested $@; then
749 cli_show_man network-zone
753 local hook_dir=$(hook_dir ${type})
756 for hook in ${hook_dir}/*; do
757 hook=$(basename ${hook})
758 if hook_exists ${type} ${hook}; then
765 if cli_help_requested $@; then
766 cli_show_man network-route
778 error "Unrecognized action
: ${action}"
779 cli_run_help network route
791 if cli_help_requested $@; then
792 cli_show_man network-route-static
804 # Remove an existing route.
818 error "Unrecognized action
: ${action}"
819 cli_run_help network route
825 # Applying all routes.
835 if cli_help_requested $@; then
836 cli_show_man network-dhcp
845 dhcpd_edit ${proto} $@
850 # Make this permanent
851 dhcpd_enable ${proto}
856 # Make this permanent
857 dhcpd_disable ${proto}
860 dhcpd_reload ${proto}
863 cli_dhcpd_subnet ${proto} $@
866 cli_dhcpd_show ${proto} $@
869 error "Unrecognized action
: ${action}"
870 cli_run_help network dhcpvN
883 local settings=$(dhcpd_settings ${proto})
884 assert isset settings
887 dhcpd_global_settings_read ${proto}
889 cli_headline 1 "Dynamic Host Configuration Protocol Daemon
for ${proto/ip/IP}"
893 cli_headline 2 "Lease
times"
894 if isinteger VALID_LIFETIME; then
895 cli_print_fmt1 2 "Valid lifetime
" "$
(format_time
${VALID_LIFETIME})"
898 if isinteger PREFERRED_LIFETIME; then
899 cli_print_fmt1 2 "Preferred lifetime
" "$
(format_time
${PREFERRED_LIFETIME})"
905 cli_print_fmt1 1 "Authoritative
" $(cli_print_enabled AUTHORITATIVE)
908 cli_headline 2 "Lease
times"
909 cli_print_fmt1 2 "Default lease
time" "$
(format_time
${DEFAULT_LEASE_TIME})"
910 cli_print_fmt1 2 "Max. lease
time" "$
(format_time
${MAX_LEASE_TIME})"
912 if isset MIN_LEASE_TIME; then
913 cli_print_fmt1 2 "Min. lease
time" "$
(format_time
${MIN_LEASE_TIME})"
922 dhcpd_global_options_read ${proto}
924 # Print the options if any.
925 if [ ${#options[*]} -gt 0 ]; then
926 cli_headline 2 "Options
"
929 for option in $(dhcpd_options ${proto}); do
930 [ -n "${options[${option}]}" ] || continue
933 "${option}" "${options[${option}]}"
939 local subnets=$(dhcpd_subnet_list ${proto})
940 if [ -n "${subnets}" ]; then
941 cli_headline 2 "Subnets
"
943 for subnet in ${subnets}; do
944 cli_dhcpd_subnet_show ${proto} ${subnet} 2
955 if cli_help_requested $@; then
956 cli_show_man network-dhcp-subnet
965 dhcpd_subnet_new ${proto} $@
968 dhcpd_subnet_remove ${proto} $@
971 local subnet=${action}
973 if ! dhcpd_subnet_exists ${proto} ${subnet}; then
974 error "Subnet
${subnet} does not exist
"
984 dhcpd_subnet_edit ${proto} ${subnet} $@
987 if [ ${ret} -eq ${EXIT_OK} ]; then
988 dhcpd_reload ${proto}
993 cli_dhcpd_subnet_range ${proto} ${subnet} $@
997 cli_dhcpd_subnet_show ${proto} ${subnet} $@
1001 cli_dhcpd_subnet_options ${proto} ${subnet} $@
1005 error "Unrecognized action
: ${action}"
1006 cli_run_help network dhcpvN subnet
1013 for subnet in $(dhcpd_subnet_list ${proto}); do
1014 cli_dhcpd_subnet_show ${proto} ${subnet}
1018 error "Unrecognized action
: ${action}"
1019 cli_run_help network dhcpvN subnet
1028 cli_dhcpd_subnet_range() {
1038 dhcpd_subnet_range_new ${proto} ${subnet} $@ || exit ${EXIT_ERROR}
1041 dhcpd_subnet_range_remove ${proto} ${subnet} $@ || exit ${EXIT_ERROR}
1044 error "Unrecognized action
: ${action}"
1045 cli_run_help network dhcpvN subnet range
1050 dhcpd_reload ${proto}
1054 cli_dhcpd_subnet_show() {
1055 assert [ $# -ge 2 -a $# -le 3 ]
1061 isset level || level=0
1063 local $(dhcpd_subnet_settings ${proto})
1065 # Read in configuration settings.
1066 dhcpd_subnet_read ${proto} ${subnet}
1068 cli_headline $(( ${level} + 1 )) "DHCP Subnet Declaration
"
1069 cli_print_fmt1 $(( ${level} + 1 )) \
1070 "Subnet
" "${ADDRESS}/${PREFIX}"
1075 dhcpd_subnet_options_read "${proto}" "${subnet}"
1077 # Print the options if any.
1078 if [ ${#options[*]} -gt 0 ]; then
1079 cli_headline $(( ${level} + 2 )) "Options
"
1082 for option in $(dhcpd_subnet_options_list ${proto}); do
1083 [ -n "${options[${option}]}" ] || continue
1085 cli_print_fmt1 $(( ${level} + 2 )) \
1086 "${option}" "${options[${option}]}"
1092 cli_headline $(( ${level} + 2 )) "Ranges
"
1094 local ranges=$(dhcpd_subnet_range_list ${proto} ${subnet})
1095 if isset ranges; then
1096 local range $(dhcpd_subnet_range_settings ${proto})
1097 for range in ${ranges}; do
1098 dhcpd_subnet_range_read ${proto} ${subnet} ${range}
1100 cli_print $(( ${level} + 2 )) "%s - %s" ${START} ${END}
1103 cli_print $(( ${level} + 2 )) "No ranges have been defined.
"
1109 cli_dhcpd_subnet_options() {
1116 while [ $# -gt 0 ]; do
1119 key=$(cli_get_key ${1})
1120 val=$(cli_get_val ${1})
1122 dhcpd_subnet_option_set ${proto} ${subnet} ${key} ${val}
1128 if cli_help_requested $@; then
1129 cli_show_man network
1133 local zones=$(zones_get $@)
1136 for zone in ${zones}; do
1137 zone_start ${zone} &
1140 wait # until everything is settled
1144 if cli_help_requested $@; then
1145 cli_show_man network
1149 local zones=$(zones_get $@)
1152 for zone in ${zones}; do
1156 wait # until everything is settled
1160 if cli_help_requested $@; then
1161 cli_show_man network
1167 # Give the system some time to calm down
1168 sleep ${TIMEOUT_RESTART}
1174 if cli_help_requested $@; then
1175 cli_show_man network
1179 # When dumping status information, the debug
1180 # mode clutters the console which is not what we want.
1181 # Logging on the console is disabled for a short time.
1182 local log_disable_stdout=${LOG_DISABLE_STDOUT}
1183 LOG_DISABLE_STDOUT="true
"
1185 local zones=$(zones_get $@)
1188 for zone in ${zones}; do
1193 LOG_DISABLE_STDOUT=${log_disable_stdout}
1197 if cli_help_requested $@; then
1198 cli_show_man network
1202 warning_log "Will
reset the whole network configuration
!!!"
1203 # Force mode is disabled by default
1206 while [ $# -gt 0 ]; do
1215 # If we are not running in force mode, we ask the user if he does know
1217 if ! enabled force; then
1218 if ! cli_yesno "Do you really want to
reset the whole network configuration?
"; then
1224 for zone in $(zones_get --all); do
1225 zone_destroy_now "${zone}"
1229 for port in $(ports_get --all); do
1230 port_destroy "${port}"
1233 # Flush all DNS servers.
1236 # Re-run the initialization functions
1242 # Help function: will show the default man page to the user.
1243 # Optionally, there are two arguments taken, the type of hook
1244 # and which hook should be shown.
1254 # List all hooks if requested
1255 if [ "${hook}" = "list-hooks
" ]; then
1256 cli_list_hooks ${type}
1260 if ! hook_exists ${type} ${hook}; then
1261 error "No hook with name
'${hook}' could be found
"
1262 exit "${EXIT_ERROR}"
1265 hook_exec ${type} ${hook} help
1268 # In all other cases show the default man page
1270 cli_show_man network
1275 return ${EXIT_ERROR}
1279 if cli_help_requested $@; then
1280 cli_show_man network-dns-server
1285 local cmd=${1}; shift
1286 if [ -z "${cmd}" ]; then
1287 cli_show_man network-dns-server
1291 # Get the new server to process (if any).
1301 if dns_server_exists ${server}; then
1302 error "DNS server
'${server}' already exists
!"
1306 log INFO "Adding new DNS server
: ${server}"
1307 dns_server_add ${server} ${priority}
1310 if ! dns_server_exists ${server}; then
1311 error "DNS server
'${server}' does not exist
!"
1315 log INFO "Removing DNS server
: ${server}"
1316 dns_server_remove ${server} ${priority}
1319 # Just run the update afterwards.
1322 error "No such
command: ${cmd}"
1326 # Update the local DNS configuration after changes have been made.
1344 list-dhcpd-ranges-of-subnet)
1345 dhcpd_subnet_range_list $@
1347 list-dhcpd-settings)
1348 dhcpd_global_settings_list $@
1351 dhcpd_subnet_list $@
1353 list-dhcpd-subnet-options)
1354 dhcpd_subnet_options_list $@
1372 network_settings_list
1377 list-next-free-zones)
1380 list-zone-config-ids)
1381 zone_config_list_ids $@
1383 list-zone-config-hids)
1384 zone_config_list_hids $@
1387 zone_name_is_valid $@
1389 zone-config-id-is-valid)
1390 zone_config_id_is_valid $@
1392 zone-config-hid-is-valid)
1393 zone_config_hid_is_valid $@
1396 error "No such
command: ${cmd}"
1410 cli_vpn_security_policies $@
1416 error "Unrecognized argument
: ${action}"
1428 cli_vpn_ipsec_connection $@
1431 error "Unrecognized argument
: ${action}"
1437 cli_vpn_ipsec_connection() {
1438 if ipsec_connection_exists ${1}; then
1439 local connection=${1}
1445 authentication|inactivity-timout|local|mode|peer|remote|security-policy)
1446 ipsec_connection_${key} ${connection} $@
1449 error "Unrecognized argument
: ${key}"
1459 ipsec_connection_new $@
1462 ipsec_connection_destroy $@
1465 if [ -n "${action}" ]; then
1466 error "Unrecognized argument
: '${action}'"
1474 cli_vpn_security_policies() {
1477 local security_policy
1479 if vpn_security_policy_exists ${1}; then
1481 security_policy=${1}
1486 cipher|compression|integrity|lifetime|pfs|show)
1487 vpn_security_policies_${key} ${security_policy} $@
1490 vpn_security_policies_group_type ${security_policy} $@
1493 vpn_security_policies_key_exchange ${security_policy} $@
1496 error "Unrecognized argument
: ${key}"
1506 vpn_security_policies_new $@
1509 vpn_security_policies_destroy $@
1512 if [ -n "${action}" ]; then
1513 error "Unrecognized argument
: '${action}'"
1521 # Process the given action
1527 settings|hostname|port|device|zone|start|stop|restart|status|reset|route|vpn)
1531 # DHCP server configuration (automatically detects which protocol to use).
1533 cli_dhcpd ${action/dhcp/ip} $@
1536 # DNS server configuration.
1550 error "Invalid
command given
: ${action}"
1551 cli_usage "network
help"
1552 exit ${EXIT_CONF_ERROR}