2 ###############################################################################
4 # IPFire.org - A linux based firewall #
5 # Copyright (C) 2010 Michael Tremer & Christian Schmidt #
7 # This program is free software: you can redistribute it and/or modify #
8 # it under the terms of the GNU General Public License as published by #
9 # the Free Software Foundation, either version 3 of the License, or #
10 # (at your option) any later version. #
12 # This program is distributed in the hope that it will be useful, #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15 # GNU General Public License for more details. #
17 # You should have received a copy of the GNU General Public License #
18 # along with this program. If not, see <http://www.gnu.org/licenses/>. #
20 ###############################################################################
22 # Parse the command line
23 while [ $# -gt 0 ]; do
33 [ -n "${action}" ] && break
36 .
/usr
/lib
/network
/functions
38 # Read network settings
42 if cli_help_requested $@
; then
43 cli_show_man network-settings
47 if [ -n "${1}" ]; then
48 network_settings_set $@
49 network_settings_write
51 network_settings_print
56 if cli_help_requested $@
; then
57 cli_show_man network-device
69 local device
="${action}"
73 if ! isset device
; then
74 cli_show_man network-device
78 assert device_exists
${device}
82 cli_device_discover
${device} $@
85 device_identify
"${device}" $@
88 cli_device_monitor
"${device}" $@
91 cli_device_status
${device}
94 cli_device_serial_unlock
${device} $@
97 cli_device_send_ussd_command
"${device}" $@
100 cli_show_man network-device
109 cli_device_status
() {
113 # Disable debugging output here.
114 local log_disable_stdout
=${LOG_DISABLE_STDOUT}
115 LOG_DISABLE_STDOUT
="true"
117 # Save the type of the device for later.
118 local type=$
(device_get_type
${device})
120 cli_headline
1 "Device status: ${device}"
121 cli_print_fmt1
1 "Name" "${device}"
123 # Handle special devices
126 cli_device_status_phy
"${device}"
130 cli_device_status_serial
"${device}"
135 # Print the device status.
136 device_is_up
${device} &>/dev
/null
141 status
="${CLR_GREEN_B}UP${CLR_RESET}"
144 status
="${CLR_RED_B}DOWN${CLR_RESET}"
148 cli_print_fmt1
1 "Status" "${status}"
149 cli_print_fmt1
1 "Type" "${type}"
151 # Ethernet-compatible?
152 device_is_ethernet_compatible
"${device}" &>/dev
/null
153 cli_print_fmt1
1 "Ethernet-compatible" "$(cli_print_bool $?)"
155 cli_print_fmt1
1 "Address" "$(device_get_address ${device})"
158 # Print the link speed for ethernet devices.
159 if device_is_up
${device} &>/dev
/null
; then
160 local link
="$(device_get_link_string "${device}")"
162 cli_print_fmt1
1 "Link" "${link}"
166 cli_print_fmt1
1 "MTU" "$(device_get_mtu ${device})"
169 # Print device statistics.
170 cli_device_stats
2 ${device}
172 # Print some more information.
173 device_has_carrier
${device} &>/dev
/null
174 cli_print_fmt1
1 "Has carrier?" "$(cli_print_bool $?)"
176 device_is_promisc
${device} &>/dev
/null
177 cli_print_fmt1
1 "Promisc" "$(cli_print_bool $?)"
180 # Print all vlan devices.
181 local vlans
=$
(device_get_vlans
${device})
182 if [ -n "${vlans}" ]; then
183 cli_headline
2 "VLAN devices"
186 for vlan
in ${vlans}; do
187 cli_print
2 "* %-6s - %s" "${vlan}" "$(device_get_address ${vlan})"
194 local phy
="$(device_get_phy "${device}")"
197 cli_print_fmt1
2 "Name" "${phy}"
198 cli_print_fmt1
2 "Address" "$(phy_get_address "${phy}")"
204 # Reset the logging level.
205 LOG_DISABLE_STDOUT
=${log_disable_stdout}
208 cli_device_status_serial
() {
210 assert device_is_serial
${device}
212 serial_is_locked
${device} &>/dev
/null
215 cli_print_fmt1
1 "Locked" "$(cli_print_bool ${locked})"
218 # Cannot go on when the device is locked.
219 [ ${locked} -eq ${EXIT_TRUE} ] && return ${EXIT_OK}
221 cli_print_fmt1
1 "Manufacturer" \
222 "$(modem_get_manufacturer ${device})"
223 cli_print_fmt1
1 "Model" \
224 "$(modem_get_model ${device})"
225 cli_print_fmt1
1 "Software version" \
226 "$(modem_get_software_version ${device})"
229 if modem_is_mobile
"${device}"; then
230 cli_print_fmt1
1 "IMEI" \
231 "$(modem_get_device_imei ${device})"
235 if modem_is_mobile
"${device}"; then
236 modem_mobile_network_status
"${device}" 2
241 cli_device_status_phy
() {
243 assert phy_exists
"${phy}"
245 local address
="$(phy_get_address "${phy}")"
246 cli_print_fmt1
1 "Address" "${address}"
249 local devices
="$(phy_get_devices "${phy}")"
250 if isset devices
; then
251 cli_headline
2 "Soft interfaces"
254 for device
in ${devices}; do
255 cli_print
2 "* %s" "${device}"
263 cli_device_discover
() {
267 # This can only be executed for ethernet (or compatible) devices
268 if ! device_is_ethernet_compatible
"${device}"; then
274 while [ $# -gt 0 ]; do
284 device_is_up
${device} && up
=1
285 device_set_up
${device}
287 enabled raw ||
echo "${device}"
292 for hook
in $
(hook_zone_get_all
); do
293 out
=$
(hook_zone_exec
${hook} discover
${device})
296 [ ${ret} -eq ${DISCOVER_NOT_SUPPORTED} ] && continue
304 echo "${hook}: ${line}"
309 echo "${hook}: FAILED"
315 echo " ${hook} was successful."
323 echo " ${hook} failed."
331 [ "${up}" = "1" ] || device_set_down
${device}
334 cli_device_serial_unlock
() {
335 if cli_help_requested $@
; then
336 cli_show_man network-device
343 if ! device_is_serial
${device}; then
344 error
"${device} is not a serial device."
345 error
"Unlocking is only supported for serial devices."
349 # Read the current state of the SIM card.
350 modem_sim_status
${device} &>/dev
/null
351 local sim_status_code
=$?
353 # If the SIM card is already unlocked, we don't need to do anything.
354 if [ ${sim_status_code} -eq ${EXIT_SIM_READY} ]; then
355 print
"The SIM card is already unlocked."
358 # If the SIM card is in an unknown state, we cannot do anything.
359 elif [ ${sim_status_code} -eq ${EXIT_SIM_UNKNOWN} ]; then
360 error
"The SIM card is in an unknown state."
366 local require_new_pin
="false"
369 while ! isinteger code
; do
371 case "${sim_status_code}" in
373 message
="Please enter PIN:"
376 message
="Please enter PUK:"
377 require_new_pin
="true"
382 echo -n "${message} "
384 echo # Print newline.
386 if enabled require_new_pin
; then
391 message
="Please enter a new PIN code:"
394 message
="Please confirm the new PIN code:"
398 echo -n "${message} "
400 echo # Print newline.
402 if [ -n "${new_pin}" ]; then
403 if [ "${new_pin}" != "${new_pin2}" ]; then
404 error
"The entered PIN codes did not match."
414 # Trying to unlock the SIM card.
415 modem_sim_unlock
${device} ${code} ${new_pin}
420 cli_device_send_ussd_command
() {
428 while [ $# -gt 0 ]; do
431 timeout
="$(cli_get_val "${1}")"
434 if isset
command; then
435 warning
"Unrecognized argument: ${1}"
444 assert device_is_serial
"${device}"
447 if isset timeout
; then
448 args
="${args} --timeout=${timeout}"
451 modem_ussd_send_command
"${device}" "${command}" ${args}
455 cli_device_monitor() {
459 if ! device_is_wireless "${device}"; then
460 error "This action only works with wireless devices. Exiting.
"
464 wireless_monitor "${device}"
470 for device in $(device_list); do
471 cli_device_status "${device}"
478 if cli_help_requested $@; then
485 if [ -n "${hostname}" ]; then
486 config_hostname ${hostname}
487 log INFO "Hostname was
set to
'${hostname}'.
"
488 log INFO "Changes
do only take affect after reboot.
"
492 echo "$
(config_hostname
)"
497 if cli_help_requested $@; then
498 cli_show_man network-port
505 if port_exists ${1}; then
511 edit|create|remove|up|down|status|identify)
512 port_${action} "${port}" $@
515 error "Unrecognized argument
: ${action}"
528 error "Unrecognized argument
: ${action}"
536 if cli_help_requested $@; then
537 cli_show_man network-zone
544 if zone_name_is_valid ${1}; then
564 cli_zone_port "${zone}" $@
567 cli_zone_rename "${zone}" $@
569 config|disable|down|edit|enable|identify|status|up)
570 zone_${action} ${zone} $@
573 error "Unrecognized argument
: ${action}"
574 cli_show_man network-zone
590 cli_list_hooks zone $@
593 if [ -n "${action}" ]; then
594 error "Unrecognized argument
: '${action}'"
598 cli_show_man network-zone
606 if cli_help_requested $@ || [ $# -lt 2 ]; then
607 cli_show_man network-zone-new
614 # Removes a zone either immediately, if it is currently down,
615 # or adds a tag that the removal will be done when the zone
616 # is brought down the next time.
618 if cli_help_requested $@; then
619 cli_show_man network-zone
624 assert zone_exists "${zone}"
626 if zone_is_up ${zone}; then
627 echo "Zone
'${zone}' is up and will be removed when it goes down the next
time.
"
628 zone_destroy "${zone}"
630 echo "Removing zone
'${zone}' now...
"
631 zone_destroy_now "${zone}"
638 if cli_help_requested $@; then
639 cli_show_man network-zone-port
644 assert zone_exists "${zone}"
646 if port_exists "${2}"; then
653 zone_port_edit "${zone}" "${port}" $@
656 error "Unrecognised argument
: ${action}"
666 zone_port_attach "${zone}" $@
669 zone_port_detach "${zone}" $@
672 error "Unrecognised argument
: ${action}"
682 if cli_help_requested $@; then
683 cli_show_man network-zone
691 if ! isset name; then
692 error "You need to pass a new name
"
696 if ! zone_name_is_valid "${name}"; then
697 error "Invalid new zone name
: ${name}"
701 # Check if the zone exists
702 if ! zone_exists "${zone}"; then
703 error "Zone
${zone} does not exist
"
707 # Destroyed zones cannot be renamed
708 if zone_has_destroy_tag "${zone}"; then
709 error "Zone
${zone} is about to be destroyed and cannot be renamed
"
713 # Check if a zone with the new name already exists
714 if zone_exists "${name}"; then
715 error "Zone
${name} already exists
"
720 if ! zone_rename "${zone}" "${name}"; then
721 error "Could not rename zone
${zone} to
${name}"
732 if cli_help_requested $@; then
733 cli_show_man network-zone
737 local hook_dir=$(hook_dir ${type})
740 for hook in ${hook_dir}/*; do
741 hook=$(basename ${hook})
742 if hook_exists ${type} ${hook}; then
749 if cli_help_requested $@; then
750 cli_show_man network-route
762 # Remove an existing route.
772 error "Unrecognized action
: ${action}"
773 cli_run_help network route
779 # Applying all routes.
789 if cli_help_requested $@; then
790 cli_show_man network-dhcp
799 dhcpd_edit ${proto} $@
808 dhcpd_reload ${proto}
811 cli_dhcpd_subnet ${proto} $@
814 cli_dhcpd_show ${proto} $@
817 error "Unrecognized action
: ${action}"
818 cli_run_help network dhcpvN
831 local settings=$(dhcpd_settings ${proto})
832 assert isset settings
835 dhcpd_global_settings_read ${proto}
837 cli_headline 1 "Dynamic Host Configuration Protocol Daemon
for ${proto/ip/IP}"
841 cli_headline 2 "Lease
times"
842 if isinteger VALID_LIFETIME; then
843 cli_print_fmt1 2 "Valid lifetime
" "${VALID_LIFETIME}s
"
846 if isinteger PREFERRED_LIFETIME; then
847 cli_print_fmt1 2 "Preferred lifetime
" "${PREFERRED_LIFETIME}s
"
853 cli_print_fmt1 1 "Authoritative
" $(cli_print_enabled AUTHORITATIVE)
856 cli_headline 2 "Lease
times"
857 cli_print_fmt1 2 "Default lease
time" "${DEFAULT_LEASE_TIME}s
"
858 cli_print_fmt1 2 "Max. lease
time" "${MAX_LEASE_TIME}s
"
860 if isset MIN_LEASE_TIME; then
861 cli_print_fmt1 2 "Min. lease
time" "${MIN_LEASE_TIME}s
"
870 dhcpd_global_options_read ${proto} ${subnet_id}
872 # Print the options if any.
873 if [ ${#options[*]} -gt 0 ]; then
874 cli_headline 2 "Options
"
877 for option in $(dhcpd_options ${proto}); do
878 [ -n "${options[${option}]}" ] || continue
881 "${option}" "${options[${option}]}"
887 local subnets=$(dhcpd_subnet_list ${proto})
888 if [ -n "${subnets}" ]; then
889 cli_headline 2 "Subnets
"
891 for subnet_id in ${subnets}; do
892 cli_dhcpd_subnet_show ${proto} ${subnet_id} 2
901 if cli_help_requested $@; then
902 cli_show_man network-dhcp-subnet
911 dhcpd_subnet_new ${proto} $@
914 dhcpd_subnet_remove ${proto} $@
917 local subnet_id=${action}
919 if ! dhcpd_subnet_exists ${proto} ${subnet_id}; then
920 error "The given subnet with ID
${subnet_id} does not exist.
"
930 dhcpd_subnet_edit ${proto} ${subnet_id} $@
933 if [ ${ret} -eq ${EXIT_OK} ]; then
934 dhcpd_reload ${proto}
939 cli_dhcpd_subnet_range ${proto} ${subnet_id} $@
943 cli_dhcpd_subnet_show ${proto} ${subnet_id} $@
947 cli_dhcpd_subnet_options ${proto} ${subnet_id} $@
951 error "Unrecognized action
: ${action}"
952 cli_run_help network dhcpvN subnet
959 for subnet_id in $(dhcpd_subnet_list ${proto}); do
960 cli_dhcpd_subnet_show ${proto} ${subnet_id}
964 error "Unrecognized action
: ${action}"
965 cli_run_help network dhcpvN subnet
974 cli_dhcpd_subnet_range() {
980 assert isset subnet_id
988 dhcpd_subnet_range_new ${proto} ${subnet_id} $@
992 dhcpd_subnet_range_remove ${proto} ${subnet_id} $@
996 error "Unrecognized action
: ${action}"
997 cli_run_help network dhcpvN subnet range
1003 cli_dhcpd_subnet_show() {
1007 local subnet_id=${2}
1008 assert isset subnet_id
1011 isset level || level=0
1013 local $(dhcpd_subnet_settings ${proto})
1015 # Read in configuration settings.
1016 dhcpd_subnet_read ${proto} ${subnet_id}
1018 cli_headline $(( ${level} + 1 )) "DHCP Subnet Declaration
"
1019 cli_print_fmt1 $(( ${level} + 1 )) \
1020 "Subnet
" "${ADDRESS}/${PREFIX}"
1025 dhcpd_subnet_options_read "${proto}" "${subnet_id}"
1027 # Print the options if any.
1028 if [ ${#options[*]} -gt 0 ]; then
1029 cli_headline $(( ${level} + 2 )) "Options
"
1032 for option in $(dhcpd_subnet_options_list ${proto}); do
1033 [ -n "${options[${option}]}" ] || continue
1035 cli_print_fmt1 $(( ${level} + 2 )) \
1036 "${option}" "${options[${option}]}"
1042 cli_headline $(( ${level} + 2 )) "Ranges
"
1044 local ranges=$(dhcpd_subnet_range_list ${proto} ${subnet_id})
1045 if isset ranges; then
1046 local range $(dhcpd_subnet_range_settings ${proto})
1047 for range in ${ranges}; do
1048 dhcpd_subnet_range_read ${proto} ${subnet_id} ${range}
1050 cli_print $(( ${level} + 2 )) "%s - %s" ${START} ${END}
1053 cli_print $(( ${level} + 2 )) "No ranges have been defined.
"
1059 cli_dhcpd_subnet_options() {
1064 local subnet_id=${1}
1065 assert isset subnet_id
1069 while [ $# -gt 0 ]; do
1072 key=$(cli_get_key ${1})
1073 val=$(cli_get_val ${1})
1075 dhcpd_subnet_option_set ${proto} ${subnet_id} ${key} ${val}
1081 if cli_help_requested $@; then
1082 cli_show_man network
1086 local zones=$(zones_get $@)
1089 for zone in ${zones}; do
1090 zone_start ${zone} &
1093 wait # until everything is settled
1097 if cli_help_requested $@; then
1098 cli_show_man network
1102 local zones=$(zones_get $@)
1105 for zone in ${zones}; do
1109 wait # until everything is settled
1113 if cli_help_requested $@; then
1114 cli_show_man network
1120 # Give the system some time to calm down
1121 sleep ${TIMEOUT_RESTART}
1127 if cli_help_requested $@; then
1128 cli_show_man network
1132 # When dumping status information, the debug
1133 # mode clutters the console which is not what we want.
1134 # Logging on the console is disabled for a short time.
1135 local log_disable_stdout=${LOG_DISABLE_STDOUT}
1136 LOG_DISABLE_STDOUT="true
"
1138 local zones=$(zones_get $@)
1141 for zone in ${zones}; do
1146 LOG_DISABLE_STDOUT=${log_disable_stdout}
1150 if cli_help_requested $@; then
1151 cli_show_man network
1155 warning_log "Will
reset the whole network configuration
!!!"
1157 # Force mode is disabled by default
1160 while [ $# -gt 0 ]; do
1169 # If we are not running in force mode, we ask the user if he does know
1171 if ! enabled force; then
1172 if ! cli_yesno "Do you really want to
reset the whole network configuration?
"; then
1178 for zone in $(zones_get --all); do
1179 zone_destroy_now "${zone}"
1183 for port in $(ports_get --all); do
1184 port_destroy "${port}"
1187 # Flush all DNS servers.
1190 # Re-run the initialization functions
1196 # Help function: will show the default man page to the user.
1197 # Optionally, there are two arguments taken, the type of hook
1198 # and which hook should be shown.
1203 # Remove unknown types.
1204 if ! listmatch ${type} zone port config; then
1208 # If no arguments were given, we will show the default page.
1209 if [ -z "${type}" ]; then
1210 cli_show_man network
1214 if ! hook_exists ${type} ${what}; then
1215 error "Hook of
type '${type}' and name
'${what}' could not be found.
"
1216 exit "${EXIT_ERROR}"
1219 hook_exec ${type} ${what} help
1223 if cli_help_requested $@; then
1224 cli_show_man network-dns-server
1229 local cmd=${1}; shift
1230 if [ -z "${cmd}" ]; then
1231 cli_show_man network-dns-server
1235 # Get the new server to process (if any).
1245 if dns_server_exists ${server}; then
1246 error "DNS server
'${server}' already exists
!"
1250 log INFO "Adding new DNS server
: ${server}"
1251 dns_server_add ${server} ${priority}
1254 if ! dns_server_exists ${server}; then
1255 error "DNS server
'${server}' does not exist
!"
1259 log INFO "Removing DNS server
: ${server}"
1260 dns_server_remove ${server} ${priority}
1263 # Just run the update afterwards.
1266 error "No such
command: ${cmd}"
1270 # Update the local DNS configuration after changes have been made.
1288 list-dhcpd-ranges-of-subnet)
1289 dhcpd_subnet_range_list $@
1291 list-dhcpd-settings)
1292 dhcpd_global_settings_list $@
1295 dhcpd_subnet_list $@
1297 list-dhcpd-subnet-options)
1298 dhcpd_subnet_options_list $@
1316 network_settings_list
1322 error "No such
command: ${cmd}"
1330 # Process the given action
1336 settings|hostname|port|device|zone|start|stop|restart|status|reset|route)
1340 # DHCP server configuration (automatically detects which protocol to use).
1342 cli_dhcpd ${action/dhcp/ip} $@
1345 # DNS server configuration.
1359 error "Invalid
command given
: ${action}"
1360 cli_usage "network
help"
1361 exit ${EXIT_CONF_ERROR}