]>
git.ipfire.org Git - people/pmueller/ipfire-2.x.git/blob - html/cgi-bin/connections.cgi
8384253505690daf2f3d9f453a621bca5a4e60e7
3 # (c) 2001 Jack Beglinger <jackb_guppy@yahoo.com>
5 # (c) 2003 Dave Roberts <countzerouk@hotmail.com> - colour coded netfilter/iptables rewrite for 1.3
7 # (c) 2006 Franck - add sorting+filtering capability
9 # $Id: connections.cgi,v 1.6.2.12 2006/02/27 19:48:46 franck78 Exp $
12 # Setup GREEN, ORANGE, IPCOP, VPN CIDR networks, masklengths and colours only once
18 use Net
::IPv4Addr
qw( :all );
22 # enable only the following on debugging purpose
24 #use CGI::Carp 'fatalsToBrowser';
26 require 'CONFIG_ROOT/general-functions.pl';
27 require "${General::swroot}/lang.pl";
28 require "${General::swroot}/header.pl";
30 #workaround to suppress a warning when a variable is used only once
31 my @dummy = ( ${Header
::table1colour
} );
37 &General
::readhash
("${General::swroot}/ethernet/settings", \
%netsettings);
39 open (ACTIVE
, "/proc/net/ip_conntrack") or die 'Unable to open ip_conntrack';
40 my @active = <ACTIVE
>;
44 open (ACTIVE
, "/proc/net/ipsec_eroute") and @vpn = <ACTIVE
>;
47 my $aliasfile = "${General::swroot}/ethernet/aliases";
48 open(ALIASES
, $aliasfile) or die 'Unable to open aliases file.';
49 my @aliases = <ALIASES
>;
52 # Add Green Firewall Interface
53 push(@network, $netsettings{'GREEN_ADDRESS'});
54 push(@masklen, "255.255.255.255" );
55 push(@colour, ${Header
::colourfw
} );
57 # Add Green Network to Array
58 push(@network, $netsettings{'GREEN_NETADDRESS'});
59 push(@masklen, $netsettings{'GREEN_NETMASK'} );
60 push(@colour, ${Header
::colourgreen
} );
62 # Add Green Routes to Array
63 my @routes = `/sbin/route -n | /bin/grep $netsettings{'GREEN_DEV'}`;
64 foreach my $route (@routes) {
66 my @temp = split(/[\t ]+/, $route);
67 push(@network, $temp[0]);
68 push(@masklen, $temp[2]);
69 push(@colour, ${Header
::colourgreen
} );
72 # Add Firewall Localhost 127.0.0.1
73 push(@network, '127.0.0.1');
74 push(@masklen, '255.255.255.255' );
75 push(@colour, ${Header
::colourfw
} );
78 if ($netsettings{'ORANGE_DEV'}) {
79 push(@network, $netsettings{'ORANGE_NETADDRESS'});
80 push(@masklen, $netsettings{'ORANGE_NETMASK'} );
81 push(@colour, ${Header
::colourorange
} );
82 # Add Orange Routes to Array
83 @routes = `/sbin/route -n | /bin/grep $netsettings{'ORANGE_DEV'}`;
84 foreach my $route (@routes) {
86 my @temp = split(/[\t ]+/, $route);
87 push(@network, $temp[0]);
88 push(@masklen, $temp[2]);
89 push(@colour, ${Header
::colourorange
} );
94 if ($netsettings{'BLUE_DEV'}) {
95 push(@network, $netsettings{'BLUE_NETADDRESS'});
96 push(@masklen, $netsettings{'BLUE_NETMASK'} );
97 push(@colour, ${Header
::colourblue
} );
98 # Add Blue Routes to Array
99 @routes = `/sbin/route -n | /bin/grep $netsettings{'BLUE_DEV'}`;
100 foreach my $route (@routes) {
102 my @temp = split(/[\t ]+/, $route);
103 push(@network, $temp[0]);
104 push(@masklen, $temp[2]);
105 push(@colour, ${Header
::colourblue
} );
109 # Add STATIC RED aliases
110 if ($netsettings{'RED_DEV'}) {
111 # We have a RED eth iface
112 if ($netsettings{'RED_TYPE'} eq 'STATIC') {
113 # We have a STATIC RED eth iface
114 foreach my $line (@aliases)
117 my @temp = split(/\,/,$line);
119 push(@network, $temp[0]);
120 push(@masklen, $netsettings{'RED_NETMASK'} );
121 push(@colour, ${Header
::colourfw
} );
128 if ( $vpn[0] ne 'none' ) {
129 foreach my $line (@vpn) {
130 my @temp = split(/[\t ]+/,$line);
131 my @temp1 = split(/[\/:]+/,$temp[3]);
132 push(@network, $temp1[0]);
133 push(@masklen, ipv4_cidr2msk
($temp1[1]));
134 push(@colour, ${Header
::colourvpn
} );
137 if (open(IP
, "${General::swroot}/red/local-ipaddress")) {
141 push(@network, $redip);
142 push(@masklen, '255.255.255.255' );
143 push(@colour, ${Header
::colourfw
} );
147 #Establish simple filtering&sorting boxes on top of table
150 &Header
::getcgihash
(\
%cgiparams);
152 my @list_proto = ($Lang::tr
{'all'}, 'icmp', 'udp', 'tcp');
153 my @list_state = ($Lang::tr
{'all'}, 'SYN_SENT', 'SYN_RECV', 'ESTABLISHED', 'FIN_WAIT',
154 'CLOSE_WAIT', 'LAST_ACK', 'TIME_WAIT', 'CLOSE', 'LISTEN');
155 my @list_mark = ($Lang::tr
{'all'}, '[ASSURED]', '[UNREPLIED]');
156 my @list_sort = ('orgsip','protocol', 'expires', 'status', 'orgdip', 'orgsp',
157 'orgdp', 'exsip', 'exdip', 'exsp', 'exdp');
159 # init or silently correct unknown value...
160 if ( ! grep ( /^$cgiparams{'SEE_PROTO'}$/ , @list_proto )) { $cgiparams{'SEE_PROTO'} = $list_proto[0] };
161 if ( ! grep ( /^$cgiparams{'SEE_STATE'}$/ , @list_state )) { $cgiparams{'SEE_STATE'} = $list_state[0] };
162 if ( ! grep ( /^$cgiparams{'SEE_MARK'}$/ , @list_mark )) { $cgiparams{'SEE_MARK'} = $list_mark[0] };
163 if ( ! grep ( /^$cgiparams{'SEE_SORT'}$/ , @list_sort )) { $cgiparams{'SEE_SORT'} = $list_sort[0] };
164 # *.*.*.* or a valid IP
165 if ( $cgiparams{'SEE_SRC'} !~ /^(\*\.\*\.\*\.\*\.|\d+\.\d+\.\d+\.\d+)$/) { $cgiparams{'SEE_SRC'} = '*.*.*.*' };
166 if ( $cgiparams{'SEE_DEST'} !~ /^(\*\.\*\.\*\.\*\.|\d+\.\d+\.\d+\.\d+)$/) { $cgiparams{'SEE_DEST'} = '*.*.*.*' };
169 our %entries = (); # will hold the lines analyzed correctly
170 my $unknownlines = ''; # should be empty all the time...
171 my $index = 0; # just a counter to make unique entryies in entries
173 foreach my $line (@active) {
189 my @temp = split(' ',$line);
191 if ($temp[0] eq 'icmp') {
192 $protocol = $temp[0];
193 $status = $Lang::tr
{'all'};
194 $orgsip = substr $temp[3], 4;
195 $orgdip = substr $temp[4], 4;
196 $marked = $temp[8] eq '[UNREPLIED]' ?
'[UNREPLIED]' : ' ';
198 if ($temp[0] eq 'udp') {
199 $protocol = $temp[0];
200 $status = $Lang::tr
{'all'};
201 $orgsip = substr $temp[3], 4;
202 $orgdip = substr $temp[4], 4;
203 $marked = $temp[7] eq '[UNREPLIED]' ?
'[UNREPLIED]' : defined ($temp[12]) ?
$temp[11] : ' ';
205 if ($temp[0] eq 'tcp') {
206 $protocol = $temp[0];
208 $orgsip = substr $temp[4], 4;
209 $orgdip = substr $temp[5], 4;
210 $marked = $temp[8] eq '[UNREPLIED]' ?
'[UNREPLIED]' : defined ($temp[13]) ?
$temp[12] : ' ';
213 # filter the line if we found a known proto
215 (($cgiparams{'SEE_PROTO'} eq $Lang::tr
{'all'}) || ($protocol eq $cgiparams{'SEE_PROTO'} ))
216 && (($cgiparams{'SEE_STATE'} eq $Lang::tr
{'all'}) || ($status eq $cgiparams{'SEE_STATE'} ))
217 && (($cgiparams{'SEE_MARK'} eq $Lang::tr
{'all'}) || ($marked eq $cgiparams{'SEE_MARK'} ))
218 && (($cgiparams{'SEE_SRC'} eq "*.*.*.*") || ($orgsip eq $cgiparams{'SEE_SRC'} ))
219 && (($cgiparams{'SEE_DEST'} eq "*.*.*.*") || ($orgdip eq $cgiparams{'SEE_DEST'} ))
222 if ($temp[0] eq 'icmp') {
224 $protocol = $temp[0] . " (" . $temp[1] . ")";
227 if ($temp[8] eq '[UNREPLIED]' ) {
230 $orgsip = substr $temp[3], 4;
231 $orgdip = substr $temp[4], 4;
232 $orgsp = &General
::GetIcmpDescription
(substr( $temp[5], 5)) . "/" . substr( $temp[6], 5);;
233 $orgdp = 'id=' . substr( $temp[7], 3);
234 $exsip = substr $temp[8 + $offset], 4;
235 $exdip = substr $temp[9 + $offset], 4;
236 $exsp = &General
::GetIcmpDescription
(substr( $temp[10 + $offset], 5)). "/" . substr( $temp[11 + $offset], 5);
237 $exdp = 'id=' . substr( $temp[11 + $offset], 5);
238 $marked = $temp[8] eq '[UNREPLIED]' ?
'[UNREPLIED]' : ' ';
239 $use = substr( $temp[13 + $offset], 4 );
241 if ($temp[0] eq 'udp') {
244 $protocol = $temp[0] . " (" . $temp[1] . ")";
247 $orgsip = substr $temp[3], 4;
248 $orgdip = substr $temp[4], 4;
249 $orgsp = substr $temp[5], 6;
250 $orgdp = substr $temp[6], 6;
251 if ($temp[7] eq '[UNREPLIED]') {
254 $use = substr $temp[12], 4;
256 if ((substr $temp[11], 0, 3) eq 'use' ) {
258 $use = substr $temp[11], 4;
261 $use = substr $temp[12], 4;
264 $exsip = substr $temp[7 + $offset], 4;
265 $exdip = substr $temp[8 + $offset], 4;
266 $exsp = substr $temp[9 + $offset], 6;
267 $exdp = substr $temp[10 + $offset], 6;
269 if ($temp[0] eq 'tcp') {
271 $protocol = $temp[0] . " (" . $temp[1] . ")";
274 $orgsip = substr $temp[4], 4;
275 $orgdip = substr $temp[5], 4;
276 $orgsp = substr $temp[6], 6;
277 $orgdp = substr $temp[7], 6;
278 if ($temp[8] eq '[UNREPLIED]') {
284 $exsip = substr $temp[8 + $offset], 4;
285 $exdip = substr $temp[9 + $offset], 4;
286 $exsp = substr $temp[10 + $offset], 6;
287 $exdp = substr $temp[11 + $offset], 6;
288 $use = substr $temp[13], 4;
290 if ($temp[0] eq 'unknown') {
292 $protocol = "??? (" . $temp[1] . ")";
293 $protocol = "esp (" . $temp[1] . ")" if ($temp[1] == 50);
294 $protocol = "ah (" . $temp[1] . ")" if ($temp[1] == 51);
297 $orgsip = substr $temp[3], 4;
298 $orgdip = substr $temp[4], 4;
301 $exsip = substr $temp[5], 4;
302 $exdip = substr $temp[6], 4;
308 if ($temp[0] eq 'gre') {
310 $protocol = $temp[0] . " (" . $temp[1] . ")";
312 $orgsip = substr $temp[5], 4;
313 $orgdip = substr $temp[6], 4;
316 $exsip = substr $temp[11], 4;
317 $exdip = substr $temp[12], 4;
323 # Only from this point, lines have the same known format/field
324 # The floating fields [UNREPLIED] [ASSURED] etc are ok.
326 # Store the line in a hash array for sorting
327 if ( $protocol ) { # line is decoded ?
328 my @record = ( 'index', $index++,
329 'protocol', $protocol,
342 my $record = {}; # create a reference to empty hash
343 %{$record} = @record; # populate that hash with @record
344 $entries{$record->{index}} = $record; # add this to a hash of hashes
345 } else { # it was not a known line
346 $unknownlines .= "<tr bgcolor='${Header::table1colour}'>";
347 $unknownlines .= "<td colspan='9'> unknown:$line></td></tr>";
351 # Build listbox objects
352 my $menu_proto = &make_select
('SEE_PROTO', $cgiparams{'SEE_PROTO'}, @list_proto);
353 my $menu_state = &make_select
('SEE_STATE', $cgiparams{'SEE_STATE'}, @list_state);
354 my $menu_src = &make_select
('SEE_SRC', $cgiparams{'SEE_SRC'}, &get_known_ips
('orgsip'));
355 my $menu_dest = &make_select
('SEE_DEST', $cgiparams{'SEE_DEST'}, &get_known_ips
('orgdip'));
356 my $menu_mark = &make_select
('SEE_MARK', $cgiparams{'SEE_MARK'}, @list_mark);
357 my $menu_sort = &make_select
('SEE_SORT', $cgiparams{'SEE_SORT'}, @list_sort);
359 &Header
::showhttpheaders
();
360 &Header
::openpage
($Lang::tr
{'connections'}, 1, '');
361 &Header
::openbigbox
('100%', 'left');
362 &Header
::openbox
('100%', 'left', $Lang::tr
{'connection tracking'});
366 <tr><td align='center'><b>$Lang::tr{'legend'} : </b></td>
367 <td align='center' bgcolor='${Header::colourgreen}'><b><font color='#FFFFFF'>$Lang::tr{'lan'}</font></b></td>
368 <td align='center' bgcolor='${Header::colourred}'><b><font color='#FFFFFF'>$Lang::tr{'internet'}</font></b></td>
369 <td align='center' bgcolor='${Header::colourorange}'><b><font color='#FFFFFF'>$Lang::tr{'dmz'}</font></b></td>
370 <td align='center' bgcolor='${Header::colourblue}'><b><font color='#FFFFFF'>$Lang::tr{'wireless'}</font></b></td>
371 <td align='center' bgcolor='${Header::colourfw}'><b><font color='#FFFFFF'>IPCop</font></b></td>
372 <td align='center' bgcolor='${Header::colourvpn}'><b><font color='#FFFFFF'>$Lang::tr{'vpn'}</font></b></td>
376 <table cellpadding='2'>
377 <tr><td align='center'><b>$Lang::tr{'protocol'}</b></td>
378 <td align='center'><b>$Lang::tr{'expires'}<br />($Lang::tr{'seconds'})</b></td>
379 <td align='center'><b>$Lang::tr{'connection'}<br />$Lang::tr{'status'}</b></td>
380 <td align='center'><b>$Lang::tr{'original'}<br />$Lang::tr{'source ip and port'}</b></td>
381 <td align='center'><b>$Lang::tr{'original'}<br />$Lang::tr{'dest ip and port'}</b></td>
382 <td align='center'><b>$Lang::tr{'expected'}<br />$Lang::tr{'source ip and port'}</b></td>
383 <td align='center'><b>$Lang::tr{'expected'}<br />$Lang::tr{'dest ip and port'}</b></td>
384 <td align='center'><b>$Lang::tr{'marked'}</b></td>
385 <td align='center'><b>$Lang::tr{'use'}</b></td>
387 <tr><form method='post' action='$ENV{'SCRIPT_NAME'}'>
388 <td align='center'>$menu_proto</td>
390 <td align='center'>$menu_state</td>
391 <td align='center'>$menu_src</td>
392 <td align='center'>$menu_dest</td>
393 <td align='center'colspan='2'>$Lang::tr{'sort ascending'}:$menu_sort </td>
394 <td align='center'>$menu_mark</td>
395 <td align='center'><input type='submit' value='!' /></td>
401 foreach my $entry (sort sort_entries
keys %entries) {
403 print "<tr bgcolor='${Header::table1colour}'>";
404 my $orgsipcolour = &ipcolour
( $entries{$entry}->{orgsip
} );
405 my $orgdipcolour = &ipcolour
( $entries{$entry}->{orgdip
} );
406 my $exsipcolour = &ipcolour
( $entries{$entry}->{exsip
} );
407 my $exdipcolour = &ipcolour
( $entries{$entry}->{exdip
} );
409 <td align='center'>$entries{$entry}->{protocol}</td>
410 <td align='center'>$entries{$entry}->{expires}</td>
411 <td align='center'>$entries{$entry}->{status}</td>
412 <td align='center' bgcolor='$orgsipcolour'>
413 <a href='/cgi-bin/ipinfo.cgi?ip=$entries{$entry}->{orgsip}'>
414 <font color='#FFFFFF'>$entries{$entry}->{orgsip}</font>
415 </a><font color='#FFFFFF'>:$entries{$entry}->{orgsp}</font></td>
416 <td align='center' bgcolor='$orgdipcolour'>
417 <a href='/cgi-bin/ipinfo.cgi?ip=$entries{$entry}->{orgdip}'>
418 <font color='#FFFFFF'>$entries{$entry}->{orgdip}</font>
419 </a><font color='#FFFFFF'>:$entries{$entry}->{orgdp}</font></td>
420 <td align='center' bgcolor='$exsipcolour'>
421 <a href='/cgi-bin/ipinfo.cgi?ip=$entries{$entry}->{exsip}'>
422 <font color='#FFFFFF'>$entries{$entry}->{exsip}</font>
423 </a><font color='#FFFFFF'>:$entries{$entry}->{exsp}</font></td>
424 <td align='center' bgcolor='$exdipcolour'>
425 <a href='/cgi-bin/ipinfo.cgi?ip=$entries{$entry}->{exdip}'>
426 <font color='#FFFFFF'>$entries{$entry}->{exdip}</font>
427 </a><font color='#FFFFFF'>:$entries{$entry}->{exdp}</font></td>
428 <td align='center'>$entries{$entry}->{marked}</td>
429 <td align='center'>$entries{$entry}->{use}</td>
435 print "$unknownlines</table>";
438 &Header
::closebigbox
();
439 &Header
::closepage
();
444 my $colour = ${Header
::colourred
};
447 foreach $line (@network) {
448 if (!$found && ipv4_in_network
( $network[$id] , $masklen[$id], $ip) ) {
450 $colour = $colour[$id];
457 # Create a string containing a complete SELECT html object
459 # param2: current value selected
461 sub make_select
($,$,$) {
462 my $select_name = shift;
463 my $selected = shift;
464 my $select = "<select name='$select_name'>";
466 foreach my $value (@_) {
467 my $check = $selected eq $value ?
"selected='selected'" : '';
468 $select .= "<option $check value='$value'>$value";
470 $select .= "</select>";
474 # Build a list of IP obtained from the %entries hash
475 # param1: IP field name
476 sub get_known_ips
($) {
478 my $qs = $cgiparams{'SEE_SORT'}; # switch the sort order
479 $cgiparams{'SEE_SORT'} = $field;
481 my @liste=('*.*.*.*');
482 foreach my $entry ( sort sort_entries
keys %entries) {
483 push (@liste, $entries{$entry}->{$field}) if (! grep (/^$entries{$entry}->{$field}$/,@liste) );
486 $cgiparams{'SEE_SORT'} = $qs; #restore sort order
490 # Used to sort the table containing the lines displayed.
491 sub sort_entries
{ #Reverse is not implemented
492 my $qs=$cgiparams{'SEE_SORT'};
493 if ($qs =~ /orgsip|orgdip|exsip|exdip/) {
494 my @a = split(/\./,$entries{$a}->{$qs});
495 my @b = split(/\./,$entries{$b}->{$qs});
500 } elsif ($qs =~ /expire|orgsp|orgdp|exsp|exdp/) {
501 $entries{$a}->{$qs} <=> $entries{$b}->{$qs};
503 $entries{$a}->{$qs} cmp $entries{$b}->{$qs};