2 ###############################################################################
4 # IPFire.org - A linux based firewall #
5 # Copyright (C) 2010 Michael Tremer & Christian Schmidt #
7 # This program is free software: you can redistribute it and/or modify #
8 # it under the terms of the GNU General Public License as published by #
9 # the Free Software Foundation, either version 3 of the License, or #
10 # (at your option) any later version. #
12 # This program is distributed in the hope that it will be useful, #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15 # GNU General Public License for more details. #
17 # You should have received a copy of the GNU General Public License #
18 # along with this program. If not, see <http://www.gnu.org/licenses/>. #
20 ###############################################################################
22 # Parse the command line
23 while [ $# -gt 0 ]; do
33 [ -n "${action}" ] && break
36 .
/usr
/lib
/network
/functions
38 # Read network settings
42 if cli_help_requested
"$@"; then
43 cli_show_man network-settings
47 if [ -n "${1}" ]; then
48 network_settings_set
"$@"
49 network_settings_write
51 network_settings_print
56 if cli_help_requested
"$@"; then
57 cli_show_man network-device
69 local device
="${action}"
73 if ! isset device
; then
74 cli_show_man network-device
78 assert device_exists
${device}
82 cli_device_discover
${device} "$@"
85 device_identify
"${device}" "$@"
88 cli_device_monitor
"${device}" "$@"
91 cli_device_status
${device}
94 cli_device_serial_unlock
${device} "$@"
97 cli_device_send_ussd_command
"${device}" "$@"
100 cli_show_man network-device
109 cli_device_status
() {
113 # Disable debugging output here.
114 local log_disable_stdout
=${LOG_DISABLE_STDOUT}
115 LOG_DISABLE_STDOUT
="true"
117 # Save the type of the device for later.
118 local type=$
(device_get_type
${device})
120 cli_headline
1 "Device status: ${device}"
121 cli_print_fmt1
1 "Name" "${device}"
123 # Handle special devices
126 cli_device_status_phy
"${device}"
130 cli_device_status_serial
"${device}"
135 # Print the device status.
136 device_is_up
${device} &>/dev
/null
141 status
="${CLR_GREEN_B}UP${CLR_RESET}"
144 status
="${CLR_RED_B}DOWN${CLR_RESET}"
148 cli_print_fmt1
1 "Status" "${status}"
149 cli_print_fmt1
1 "Type" "${type}"
151 # Print the driver name
152 local driver
="$(device_get_driver "${device}")"
153 if isset driver
; then
154 cli_print_fmt1
1 "Driver" "${driver}"
157 # Ethernet-compatible?
158 device_is_ethernet_compatible
"${device}" &>/dev
/null
159 cli_print_fmt1
1 "Ethernet-compatible" "$(cli_print_bool $?)"
161 cli_print_fmt1
1 "Address" "$(device_get_address ${device})"
164 # Print the link speed for ethernet devices.
165 if device_is_up
${device} &>/dev
/null
; then
166 local link
="$(device_get_link_string "${device}")"
168 cli_print_fmt1
1 "Link" "${link}"
172 cli_print_fmt1
1 "MTU" "$(device_get_mtu ${device})"
175 # Print device statistics.
176 cli_device_stats
2 ${device}
178 # Print some more information.
179 device_has_carrier
${device} &>/dev
/null
180 cli_print_fmt1
1 "Has carrier?" "$(cli_print_bool $?)"
182 device_is_promisc
${device} &>/dev
/null
183 cli_print_fmt1
1 "Promisc" "$(cli_print_bool $?)"
185 # Supports multiqueue?
186 if device_supports_multiqueue
${device}; then
187 cli_print_fmt1
1 "Multiqueue" "Supported"
191 cli_device_show_queues
2 ${device}
193 # Print all vlan devices.
194 local vlans
=$
(device_get_vlans
${device})
195 if [ -n "${vlans}" ]; then
196 cli_headline
2 "VLAN devices"
199 for vlan
in ${vlans}; do
200 cli_print
2 "* %-6s - %s" "${vlan}" "$(device_get_address ${vlan})"
207 local phy
="$(device_get_phy "${device}")"
210 cli_print_fmt1
2 "Name" "${phy}"
211 cli_print_fmt1
2 "Address" "$(phy_get_address "${phy}")"
217 # Reset the logging level.
218 LOG_DISABLE_STDOUT
=${log_disable_stdout}
221 cli_device_status_serial
() {
223 assert device_is_serial
${device}
225 serial_is_locked
${device} &>/dev
/null
228 cli_print_fmt1
1 "Locked" "$(cli_print_bool ${locked})"
231 # Cannot go on when the device is locked.
232 [ ${locked} -eq ${EXIT_TRUE} ] && return ${EXIT_OK}
234 cli_print_fmt1
1 "Manufacturer" \
235 "$(modem_get_manufacturer ${device})"
236 cli_print_fmt1
1 "Model" \
237 "$(modem_get_model ${device})"
238 cli_print_fmt1
1 "Software version" \
239 "$(modem_get_software_version ${device})"
242 if modem_is_mobile
"${device}"; then
243 cli_print_fmt1
1 "IMEI" \
244 "$(modem_get_device_imei ${device})"
248 if modem_is_mobile
"${device}"; then
249 modem_mobile_network_status
"${device}" 2
254 cli_device_status_phy
() {
256 assert phy_exists
"${phy}"
258 local address
="$(phy_get_address "${phy}")"
259 cli_print_fmt1
1 "Address" "${address}"
262 local driver
="$(phy_get_driver "${phy}")"
263 if isset driver
; then
264 cli_print_fmt1
1 "Driver" "${driver}"
269 local devices
="$(phy_get_devices "${phy}")"
270 if isset devices
; then
271 cli_headline
2 "Soft interfaces"
274 for device
in ${devices}; do
275 cli_print
2 "* %s" "${device}"
280 cli_headline
2 "Features"
282 cli_print_fmt1
2 "Automatic Channel Selection" \
283 "$(phy_supports_acs "${phy}" && print "Supported
" ||Â print "Not Supported
")"
284 cli_print_fmt1
2 "DFS" \
285 "$(phy_supports_dfs "${phy}" && print "Supported
" ||Â print "Not Supported
")"
292 cli_device_discover
() {
296 # This can only be executed for ethernet (or compatible) devices
297 if ! device_is_ethernet_compatible
"${device}"; then
303 while [ $# -gt 0 ]; do
313 device_is_up
${device} && up
=1
314 device_set_up
${device}
316 enabled raw ||
echo "${device}"
321 for hook
in $
(hook_zone_get_all
); do
322 out
=$
(hook_zone_exec
${hook} discover
${device})
325 [ ${ret} -eq ${DISCOVER_NOT_SUPPORTED} ] && continue
333 echo "${hook}: ${line}"
338 echo "${hook}: FAILED"
344 echo " ${hook} was successful."
352 echo " ${hook} failed."
360 [ "${up}" = "1" ] || device_set_down
${device}
363 cli_device_serial_unlock
() {
364 if cli_help_requested
"$@"; then
365 cli_show_man network-device
372 if ! device_is_serial
${device}; then
373 error
"${device} is not a serial device."
374 error
"Unlocking is only supported for serial devices."
378 # Read the current state of the SIM card.
379 modem_sim_status
${device} &>/dev
/null
380 local sim_status_code
=$?
382 # If the SIM card is already unlocked, we don't need to do anything.
383 if [ ${sim_status_code} -eq ${EXIT_SIM_READY} ]; then
384 print
"The SIM card is already unlocked."
387 # If the SIM card is in an unknown state, we cannot do anything.
388 elif [ ${sim_status_code} -eq ${EXIT_SIM_UNKNOWN} ]; then
389 error
"The SIM card is in an unknown state."
395 local require_new_pin
="false"
398 while ! isinteger code
; do
400 case "${sim_status_code}" in
402 message
="Please enter PIN:"
405 message
="Please enter PUK:"
406 require_new_pin
="true"
411 echo -n "${message} "
413 echo # Print newline.
415 if enabled require_new_pin
; then
420 message
="Please enter a new PIN code:"
423 message
="Please confirm the new PIN code:"
427 echo -n "${message} "
429 echo # Print newline.
431 if [ -n "${new_pin}" ]; then
432 if [ "${new_pin}" != "${new_pin2}" ]; then
433 error
"The entered PIN codes did not match."
443 # Trying to unlock the SIM card.
444 modem_sim_unlock
${device} ${code} ${new_pin}
449 cli_device_send_ussd_command
() {
457 while [ $# -gt 0 ]; do
460 timeout
="$(cli_get_val "${1}")"
463 if isset
command; then
464 warning
"Unrecognized argument: ${1}"
473 assert device_is_serial
"${device}"
476 if isset timeout
; then
477 args
="${args} --timeout=${timeout}"
480 modem_ussd_send_command
"${device}" "${command}" ${args}
484 cli_device_monitor() {
488 if ! device_is_wireless "${device}"; then
489 error "This action only works with wireless devices. Exiting.
"
493 wireless_monitor "${device}"
499 for device in $(device_list); do
500 cli_device_status "${device}"
507 if cli_help_requested "$@
"; then
514 if [ -n "${hostname}" ]; then
515 config_hostname ${hostname}
516 log INFO "Hostname was
set to
'${hostname}'.
"
517 log INFO "Changes
do only take affect after reboot.
"
521 echo "$
(config_hostname
)"
526 if cli_help_requested "$@
"; then
527 cli_show_man network-port
534 if port_exists ${1}; then
540 edit|create|remove|up|down|status|identify)
541 port_${action} "${port}" "$@
"
544 color_cli "port
" "${port}" "$@
"
547 description_cli "port
" "${port}" "$@
"
550 error "Unrecognized argument
: ${action}"
563 error "Unrecognized argument
: ${action}"
571 if cli_help_requested "$@
"; then
572 cli_show_man network-zone
579 if zone_exists ${1}; then
599 cli_zone_port "${zone}" "$@
"
602 cli_zone_rename "${zone}" "$@
"
604 config|disable|down|edit|enable|identify|status|up)
605 zone_${action} ${zone} "$@
"
608 color_cli "zone
" "${zone}" "$@
"
611 description_cli "zone
" ${zone} "$@
"
614 error "Unrecognized argument
: ${action}"
615 cli_show_man network-zone
628 cli_zone_destroy "$@
"
631 if [ -n "${action}" ]; then
632 error "Unrecognized argument
: '${action}'"
636 cli_show_man network-zone
644 if cli_help_requested "$@
" || [ $# -lt 2 ]; then
645 cli_show_man network-zone-new
652 # Removes a zone either immediately, if it is currently down,
653 # or adds a tag that the removal will be done when the zone
654 # is brought down the next time.
656 if cli_help_requested "$@
"; then
657 cli_show_man network-zone
663 # Check if the zone exists
664 if ! zone_exists "${zone}"; then
665 error "Zone
'${zone}' does not exist
"
669 echo "Removing zone
'${zone}'...
"
670 zone_destroy "${zone}" || exit $?
674 if cli_help_requested "$@
"; then
675 cli_show_man network-zone-port
680 assert zone_exists "${zone}"
682 if port_exists "${2}"; then
689 zone_port_edit "${zone}" "${port}" "$@
"
692 error "Unrecognised argument
: ${action}"
702 zone_port_attach "${zone}" "$@
"
705 zone_port_detach "${zone}" "$@
"
708 error "Unrecognised argument
: ${action}"
718 if cli_help_requested "$@
"; then
719 cli_show_man network-zone
727 if ! isset name; then
728 error "You need to pass a new name
"
732 if ! zone_name_is_valid "${name}"; then
733 error "Invalid new zone name
: ${name}"
737 # Check if the zone exists
738 if ! zone_exists "${zone}"; then
739 error "Zone
${zone} does not exist
"
743 # Check if a zone with the new name already exists
744 if zone_exists "${name}"; then
745 error "Zone
${name} already exists
"
750 if ! zone_rename "${zone}" "${name}"; then
751 error "Could not rename zone
${zone} to
${name}"
762 if cli_help_requested "$@
"; then
763 cli_show_man network-zone
767 local hook_dir=$(hook_dir ${type})
770 for hook in ${hook_dir}/*; do
771 hook=$(basename ${hook})
772 if hook_exists ${type} ${hook}; then
782 if cli_help_requested "$@
"; then
783 cli_show_man network-dhcp
792 dhcpd_edit ${proto} "$@
"
797 # Make this permanent
798 dhcpd_enable ${proto}
803 # Make this permanent
804 dhcpd_disable ${proto}
807 dhcpd_reload ${proto}
810 cli_dhcpd_subnet ${proto} "$@
"
813 cli_dhcpd_show ${proto} "$@
"
816 error "Unrecognized action
: ${action}"
817 cli_run_help network dhcpvN
830 local settings=$(dhcpd_settings ${proto})
831 assert isset settings
834 dhcpd_global_settings_read ${proto}
836 cli_headline 1 "Dynamic Host Configuration Protocol Daemon
for ${proto/ip/IP}"
840 cli_headline 2 "Lease
times"
841 if isinteger VALID_LIFETIME; then
842 cli_print_fmt1 2 "Valid lifetime
" "$
(format_time
${VALID_LIFETIME})"
845 if isinteger PREFERRED_LIFETIME; then
846 cli_print_fmt1 2 "Preferred lifetime
" "$
(format_time
${PREFERRED_LIFETIME})"
852 cli_print_fmt1 1 "Authoritative
" $(cli_print_enabled AUTHORITATIVE)
855 cli_headline 2 "Lease
times"
856 cli_print_fmt1 2 "Default lease
time" "$
(format_time
${DEFAULT_LEASE_TIME})"
857 cli_print_fmt1 2 "Max. lease
time" "$
(format_time
${MAX_LEASE_TIME})"
859 if isset MIN_LEASE_TIME; then
860 cli_print_fmt1 2 "Min. lease
time" "$
(format_time
${MIN_LEASE_TIME})"
869 dhcpd_global_options_read ${proto}
871 # Print the options if any.
872 if [ ${#options[*]} -gt 0 ]; then
873 cli_headline 2 "Options
"
876 for option in $(dhcpd_options ${proto}); do
877 [ -n "${options[${option}]}" ] || continue
880 "${option}" "${options[${option}]}"
886 local subnets=$(dhcpd_subnet_list ${proto})
887 if [ -n "${subnets}" ]; then
888 cli_headline 2 "Subnets
"
890 for subnet in ${subnets}; do
891 cli_dhcpd_subnet_show ${proto} ${subnet} 2
902 if cli_help_requested "$@
"; then
903 cli_show_man network-dhcp-subnet
912 dhcpd_subnet_new ${proto} "$@
"
915 dhcpd_subnet_remove ${proto} "$@
"
918 local subnet=${action}
920 if ! dhcpd_subnet_exists ${proto} ${subnet}; then
921 error "Subnet
${subnet} does not exist
"
931 dhcpd_subnet_edit ${proto} ${subnet} "$@
"
934 if [ ${ret} -eq ${EXIT_OK} ]; then
935 dhcpd_reload ${proto}
940 cli_dhcpd_subnet_range ${proto} ${subnet} "$@
"
944 cli_dhcpd_subnet_show ${proto} ${subnet} "$@
"
948 cli_dhcpd_subnet_options ${proto} ${subnet} "$@
"
952 error "Unrecognized action
: ${action}"
953 cli_run_help network dhcpvN subnet
960 for subnet in $(dhcpd_subnet_list ${proto}); do
961 cli_dhcpd_subnet_show ${proto} ${subnet}
965 error "Unrecognized action
: ${action}"
966 cli_run_help network dhcpvN subnet
975 cli_dhcpd_subnet_range() {
985 dhcpd_subnet_range_new ${proto} ${subnet} "$@" || exit ${EXIT_ERROR}
988 dhcpd_subnet_range_remove ${proto} ${subnet} "$@" || exit ${EXIT_ERROR}
991 error "Unrecognized action
: ${action}"
992 cli_run_help network dhcpvN subnet range
997 dhcpd_reload ${proto}
1001 cli_dhcpd_subnet_show() {
1002 assert [ $# -ge 2 -a $# -le 3 ]
1008 isset level || level=0
1010 local $(dhcpd_subnet_settings ${proto})
1012 # Read in configuration settings.
1013 dhcpd_subnet_read ${proto} ${subnet}
1015 cli_headline $(( ${level} + 1 )) "DHCP Subnet Declaration
"
1016 cli_print_fmt1 $(( ${level} + 1 )) \
1017 "Subnet
" "${ADDRESS}/${PREFIX}"
1022 dhcpd_subnet_options_read "${proto}" "${subnet}"
1024 # Print the options if any.
1025 if [ ${#options[*]} -gt 0 ]; then
1026 cli_headline $(( ${level} + 2 )) "Options
"
1029 for option in $(dhcpd_subnet_options_list ${proto}); do
1030 [ -n "${options[${option}]}" ] || continue
1032 cli_print_fmt1 $(( ${level} + 2 )) \
1033 "${option}" "${options[${option}]}"
1039 cli_headline $(( ${level} + 2 )) "Ranges
"
1041 local ranges=$(dhcpd_subnet_range_list ${proto} ${subnet})
1042 if isset ranges; then
1043 local range $(dhcpd_subnet_range_settings ${proto})
1044 for range in ${ranges}; do
1045 dhcpd_subnet_range_read ${proto} ${subnet} ${range}
1047 cli_print $(( ${level} + 2 )) "%s - %s" ${START} ${END}
1050 cli_print $(( ${level} + 2 )) "No ranges have been defined.
"
1056 cli_dhcpd_subnet_options() {
1063 while [ $# -gt 0 ]; do
1066 key=$(cli_get_key ${1})
1067 val=$(cli_get_val "${1}")
1069 dhcpd_subnet_option_set ${proto} ${subnet} ${key} ${val}
1076 if cli_help_requested "$@
"; then
1077 cli_show_man network
1081 local zones=$(zones_get "$@
")
1084 for zone in ${zones}; do
1085 zone_start ${zone} &
1088 wait # until everything is settled
1092 if cli_help_requested "$@
"; then
1093 cli_show_man network
1097 local zones=$(zones_get "$@
")
1100 for zone in ${zones}; do
1104 wait # until everything is settled
1108 if cli_help_requested "$@
"; then
1109 cli_show_man network
1115 # Give the system some time to calm down
1116 sleep ${TIMEOUT_RESTART}
1122 if cli_help_requested "$@
"; then
1123 cli_show_man network
1127 # When dumping status information, the debug
1128 # mode clutters the console which is not what we want.
1129 # Logging on the console is disabled for a short time.
1130 local log_disable_stdout=${LOG_DISABLE_STDOUT}
1131 LOG_DISABLE_STDOUT="true
"
1133 local arguments=( $@ )
1135 # Show all zones when no arguments are given
1136 if ! isset arguments; then
1138 for zone in $(zones_get_all); do
1139 zone_status "${zone}"
1146 for arg in ${arguments[@]}; do
1148 if zone_exists "${arg}"; then
1149 zone_status "${arg}"
1152 elif port_exists "${arg}"; then
1153 port_status "${arg}"
1156 elif phy_exists "${arg}"; then
1157 cli_device_status "${arg}"
1160 elif device_exists "${arg}"; then
1161 cli_device_status "${arg}"
1165 error "Unknown argument
: ${arg}"
1170 LOG_DISABLE_STDOUT=${log_disable_stdout}
1174 if cli_help_requested "$@
"; then
1175 cli_show_man network
1179 warning_log "Will
reset the whole network configuration
!!!"
1180 # Force mode is disabled by default
1183 while [ $# -gt 0 ]; do
1192 # If we are not running in force mode, we ask the user if he does know
1194 if ! enabled force; then
1195 if ! cli_yesno "Do you really want to
reset the whole network configuration?
"; then
1200 # Destroy all IPsec VPN connections
1202 for connection in $(ipsec_list_connections); do
1203 ipsec_connection_destroy "${connection}"
1207 for pool in $(ipsec_list_pools); do
1208 ipsec_pool_destroy "${pool}"
1212 ipsec_strongswan_autostart
1214 # Destroy all user-defined security policies
1216 for secpol in $(vpn_security_policies_list_user); do
1217 vpn_security_policies_destroy "${secpol}"
1221 for zone in $(zones_get_all); do
1222 zone_destroy "${zone}"
1226 for port in $(ports_get_all); do
1227 port_destroy "${port}"
1230 # Flush all DNS servers.
1233 # Trigger udev to re-add all physical network devices
1234 cmd_quiet udevadm trigger --action=add --subsystem-match=net
1239 # Help function: will show the default man page to the user.
1240 # Optionally, there are two arguments taken, the type of hook
1241 # and which hook should be shown.
1251 # List all hooks if requested
1252 if [ "${hook}" = "list-hooks
" ]; then
1253 cli_list_hooks ${type}
1257 if ! hook_exists ${type} ${hook}; then
1258 error "No hook with name
'${hook}' could be found
"
1259 exit "${EXIT_ERROR}"
1262 hook_exec ${type} ${hook} help
1265 # In all other cases show the default man page
1267 cli_show_man network
1272 return ${EXIT_ERROR}
1276 if cli_help_requested "$@
"; then
1277 cli_show_man network-dns-server
1282 local cmd=${1}; shift
1283 if [ -z "${cmd}" ]; then
1284 cli_show_man network-dns-server
1288 # Get the new server to process (if any).
1298 if dns_server_exists ${server}; then
1299 error "DNS server
'${server}' already exists
!"
1303 log INFO "Adding new DNS server
: ${server}"
1304 dns_server_add ${server} ${priority}
1307 if ! dns_server_exists ${server}; then
1308 error "DNS server
'${server}' does not exist
!"
1312 log INFO "Removing DNS server
: ${server}"
1313 dns_server_remove ${server} ${priority}
1316 # Just run the update afterwards.
1319 error "No such
command: ${cmd}"
1323 # Update the local DNS configuration after changes have been made.
1338 device-get-by-mac-address)
1339 device_get_by_mac_address "$@
"
1341 ipsec-connection-exists)
1342 ipsec_connection_exists "$@
"
1347 list-dhcpd-ranges-of-subnet)
1348 dhcpd_subnet_range_list "$@
"
1350 list-dhcpd-settings)
1351 dhcpd_global_settings_list "$@
"
1354 dhcpd_subnet_list "$@
"
1356 list-dhcpd-subnet-options)
1357 dhcpd_subnet_options_list "$@
"
1368 list-ipsec-connections)
1369 ipsec_list_connections
1377 list-vpn-security-policies-all)
1378 vpn_security_policies_list_all
1381 network_settings_list
1386 list-next-free-zones)
1389 list-zone-config-ids)
1390 zone_config_list_ids "$@
"
1392 list-zone-config-hids)
1393 zone_config_list_hids "$@
"
1395 vpn-security-policy-exists)
1396 vpn_security_policy_exists "$@
"
1399 zone_name_is_valid "$@
"
1401 zone-config-id-is-valid)
1402 zone_config_id_is_valid "$@
"
1404 zone-config-hid-is-valid)
1405 zone_config_hid_is_valid "$@
"
1408 error "No such
command: ${cmd}"
1416 # Process the given action
1419 # Update resolv.conf(5) when initializing the network
1420 dns_generate_resolvconf
1422 # Update bird configuration
1423 bird_generate_config
1425 # Also execute all triggers
1426 triggers_execute_all "init
"
1429 settings|hostname|port|device|zone|start|stop|restart|status|reset|route|vpn|wireless)
1433 # DHCP server configuration (automatically detects which protocol to use).
1435 cli_dhcpd ${action/dhcp/ip} "$@
"
1438 # DNS server configuration.
1452 error "Invalid
command given
: ${action}"
1453 cli_usage "network
help"
1454 exit ${EXIT_CONF_ERROR}