2 ###############################################################################
4 # IPFire.org - A linux based firewall #
5 # Copyright (C) 2010 Michael Tremer & Christian Schmidt #
7 # This program is free software: you can redistribute it and/or modify #
8 # it under the terms of the GNU General Public License as published by #
9 # the Free Software Foundation, either version 3 of the License, or #
10 # (at your option) any later version. #
12 # This program is distributed in the hope that it will be useful, #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15 # GNU General Public License for more details. #
17 # You should have received a copy of the GNU General Public License #
18 # along with this program. If not, see <http://www.gnu.org/licenses/>. #
20 ###############################################################################
22 # Parse the command line
23 while [ $# -gt 0 ]; do
33 [ -n "${action}" ] && break
36 .
/usr
/lib
/network
/functions
38 # Read network configuration.
41 function cli_config
() {
42 if cli_help_requested $@
; then
43 cli_show_man network-config
47 if [ -n "${1}" ]; then
55 function cli_device
() {
56 if cli_help_requested $@
; then
57 cli_show_man network-device
65 if ! isset device
; then
66 cli_show_man network-device
70 assert device_exists
${device}
74 cli_device_discover
${device} $@
77 cli_device_status
${device}
80 cli_device_serial_unlock
${device} $@
83 cli_show_man network-device
90 function cli_device_status
() {
92 assert device_exists
${device}
94 # Disable debugging output here.
95 local log_disable_stdout
=${LOG_DISABLE_STDOUT}
96 LOG_DISABLE_STDOUT
="true"
98 # Save the type of the device for later.
99 local type=$
(device_get_type
${device})
101 cli_headline
1 "Device status: ${device}"
102 cli_print_fmt1
1 "Name" "${device}"
104 # Handle serial devices.
105 if [ "${type}" = "serial" ]; then
106 cli_device_status_serial
${device}
110 # Print the device status.
111 device_is_up
${device} &>/dev
/null
116 status
="${CLR_GREEN_B}UP${CLR_RESET}"
119 status
="${CLR_RED_B}DOWN${CLR_RESET}"
123 cli_print_fmt1
1 "Status" "${status}"
124 cli_print_fmt1
1 "Type" "${type}"
125 cli_print_fmt1
1 "Address" "$(device_get_address ${device})"
128 # Print the link speed for ethernet devices.
129 if device_is_up
${device} &>/dev
/null
; then
132 cli_print_fmt1
1 "Link" \
133 "$(device_get_speed ${device}) MBit/s $(device_get_duplex ${device}) duplex"
138 cli_print_fmt1
1 "MTU" "$(device_get_mtu ${device})"
141 # Print device statistics.
142 cli_device_stats
2 ${device}
144 # Print some more information.
145 device_has_carrier
${device} &>/dev
/null
146 cli_print_fmt1
1 "Has carrier?" "$(cli_print_bool $?)"
148 device_is_promisc
${device} &>/dev
/null
149 cli_print_fmt1
1 "Promisc" "$(cli_print_bool $?)"
152 # Print all vlan devices.
153 local vlans
=$
(device_get_vlans
${device})
154 if [ -n "${vlans}" ]; then
155 cli_headline
2 "VLAN devices"
158 for vlan
in ${vlans}; do
159 cli_print
2 "* %-6s - %s" "${vlan}" "$(device_get_address ${vlan})"
164 # Reset the logging level.
165 LOG_DISABLE_STDOUT
=${log_disable_stdout}
168 function cli_device_status_serial
() {
170 assert device_is_serial
${device}
172 serial_is_locked
${device} &>/dev
/null
175 cli_print_fmt1
1 "Locked" "$(cli_print_bool ${locked})"
178 # Cannot go on when the device is locked.
179 [ ${locked} -eq ${EXIT_TRUE} ] && return ${EXIT_OK}
181 cli_print_fmt1
1 "Manufacturer" \
182 "$(modem_get_manufacturer ${device})"
183 cli_print_fmt1
1 "Model" \
184 "$(modem_get_model ${device})"
185 cli_print_fmt1
1 "Software version" \
186 "$(modem_get_software_version ${device})"
188 if modem_is_mobile
${device}; then
189 cli_print_fmt1
1 "IMEI" \
190 "$(modem_get_device_imei ${device})"
193 cli_headline
2 "Network status"
194 modem_sim_status
${device} &>/dev
/null
195 local sim_status_code
=$?
197 local sim_status
="unknown"
198 case "${sim_status_code}" in
200 sim_status
="SIM ready"
203 sim_status
="PIN locked"
206 sim_status
="PUK locked"
209 cli_print_fmt1
2 "SIM status" "${sim_status}"
211 if [ ${sim_status_code} -eq ${EXIT_SIM_READY} ]; then
212 cli_print_fmt1
2 "IMSI" \
213 "$(modem_get_sim_imsi ${device})"
214 cli_print_fmt1
2 "Operator" \
215 "$(modem_get_network_operator ${device})"
216 cli_print_fmt1
2 "Mode" \
217 "$(modem_get_network_mode ${device})"
218 cli_print_fmt1
2 "Signal quality" \
219 "$(modem_get_signal_quality ${device}) dBm"
221 local ber
=$
(modem_get_bit_error_rate
${device})
222 isset ber || ber
="unknown"
223 cli_print_fmt1
2 "Bit Error Rate" "${ber}"
229 function cli_device_discover
() {
233 local device_type
=$
(device_get_type
${device})
234 if [ "${device_type}" != "real" ]; then
240 while [ $# -gt 0 ]; do
250 device_is_up
${device} && up
=1
251 device_set_up
${device}
253 enabled raw ||
echo "${device}"
258 for hook
in $
(hook_zone_get_all
); do
259 out
=$
(hook_zone_exec
${hook} discover
${device})
262 [ ${ret} -eq ${DISCOVER_NOT_SUPPORTED} ] && continue
270 echo "${hook}: ${line}"
275 echo "${hook}: FAILED"
281 echo " ${hook} was successful."
289 echo " ${hook} failed."
297 [ "${up}" = "1" ] || device_set_down
${device}
300 function cli_device_serial_unlock
() {
301 if cli_help_requested $@
; then
302 cli_show_man network-device
309 if ! device_is_serial
${device}; then
310 error
"${device} is not a serial device."
311 error
"Unlocking is only supported for serial devices."
315 # Read the current state of the SIM card.
316 modem_sim_status
${device} &>/dev
/null
317 local sim_status_code
=$?
319 # If the SIM card is already unlocked, we don't need to do anything.
320 if [ ${sim_status_code} -eq ${EXIT_SIM_READY} ]; then
321 print
"The SIM card is already unlocked."
324 # If the SIM card is in an unknown state, we cannot do anything.
325 elif [ ${sim_status_code} -eq ${EXIT_SIM_UNKNOWN} ]; then
326 error
"The SIM card is in an unknown state."
332 local require_new_pin
="false"
335 while ! isinteger code
; do
337 case "${sim_status_code}" in
339 message
="Please enter PIN:"
342 message
="Please enter PUK:"
343 require_new_pin
="true"
348 echo -n "${message} "
350 echo # Print newline.
352 if enabled require_new_pin
; then
357 message
="Please enter a new PIN code:"
360 message
="Please confirm the new PIN code:"
364 echo -n "${message} "
366 echo # Print newline.
368 if [ -n "${new_pin}" ]; then
369 if [ "${new_pin}" != "${new_pin2}" ]; then
370 error
"The entered PIN codes did not match."
380 # Trying to unlock the SIM card.
381 modem_sim_unlock
${device} ${code} ${new_pin}
386 function cli_hostname
() {
387 if cli_help_requested $@
; then
394 if [ -n "${hostname}" ]; then
395 config_hostname
${hostname}
396 log INFO
"Hostname was set to '${hostname}'."
397 log INFO
"Changes do only take affect after reboot."
401 echo "$(config_hostname)"
405 function cli_port
() {
406 if cli_help_requested $@
; then
407 cli_show_man network-port
414 if port_exists
${1}; then
434 port_
${action} ${port} $@
437 error
"Unrecognized argument: ${action}"
450 error
"Unrecognized argument: ${action}"
457 function cli_zone
() {
458 if cli_help_requested $@
; then
459 cli_show_man network-zone
466 if zone_name_is_valid
${1}; then
485 config|down|edit|port|status|up
)
486 zone_
${action} ${zone} $@
489 error
"Unrecognized argument: ${action}"
490 cli_show_man network-zone
506 cli_list_hooks zone $@
509 if [ -n "${action}" ]; then
510 error
"Unrecognized argument: '${action}'"
514 cli_show_man network-zone
521 # Removes a zone either immediately, if it is currently down,
522 # or adds a tag that the removal will be done when the zone
523 # is brought down the next time.
524 function cli_zone_remove
() {
525 if cli_help_requested $@
; then
526 cli_show_man network-zone
531 assert zone_exists
${zone}
533 if zone_is_up
${zone}; then
534 echo "Zone '${zone}' is up and will be removed when it goes down the next time."
537 echo "Removing zone '${zone}' now..."
538 zone_remove_now
${zone}
544 function cli_list_hooks
() {
548 if cli_help_requested $@
; then
549 cli_show_man network-zone
553 local hook_dir
=$
(hook_dir
${type})
556 for hook
in ${hook_dir}/*; do
557 hook
=$
(basename ${hook})
558 if hook_exists
${type} ${hook}; then
564 function cli_route
() {
565 if cli_help_requested $@
; then
566 cli_show_man network-route
578 # Remove an existing route.
588 error
"Unrecognized action: ${action}"
589 cli_run_help network route
595 # Applying all routes.
601 function cli_dhcpd
() {
605 if cli_help_requested $@
; then
606 cli_show_man network-dhcp
615 dhcpd_edit
${proto} $@
624 dhcpd_reload
${proto}
627 cli_dhcpd_subnet
${proto} $@
630 cli_dhcpd_show
${proto} $@
633 error
"Unrecognized action: ${action}"
634 cli_run_help network dhcpvN
643 function cli_dhcpd_show
() {
647 local settings
=$
(dhcpd_settings
${proto})
648 assert isset settings
651 dhcpd_global_settings_read
${proto}
653 cli_headline
1 "Dynamic Host Configuration Protocol Daemon for ${proto/ip/IP}"
657 cli_headline
2 "Lease times"
658 if isinteger VALID_LIFETIME
; then
659 cli_print_fmt1
2 "Valid lifetime" "${VALID_LIFETIME}s"
662 if isinteger PREFERRED_LIFETIME
; then
663 cli_print_fmt1
2 "Preferred lifetime" "${PREFERRED_LIFETIME}s"
669 cli_print_fmt1
1 "Authoritative" $
(cli_print_enabled AUTHORITATIVE
)
672 cli_headline
2 "Lease times"
673 cli_print_fmt1
2 "Default lease time" "${DEFAULT_LEASE_TIME}s"
674 cli_print_fmt1
2 "Max. lease time" "${MAX_LEASE_TIME}s"
676 if isset MIN_LEASE_TIME
; then
677 cli_print_fmt1
2 "Min. lease time" "${MIN_LEASE_TIME}s"
686 dhcpd_global_options_read
${proto} ${subnet_id}
688 # Print the options if any.
689 if [ ${#options[*]} -gt 0 ]; then
690 cli_headline
2 "Options"
693 for option
in $
(dhcpd_options
${proto}); do
694 [ -n "${options[${option}]}" ] ||
continue
697 "${option}" "${options[${option}]}"
703 local subnets
=$
(dhcpd_subnet_list
${proto})
704 if [ -n "${subnets}" ]; then
705 cli_headline
2 "Subnets"
707 for subnet_id
in ${subnets}; do
708 cli_dhcpd_subnet_show
${proto} ${subnet_id} 2
713 function cli_dhcpd_subnet
() {
717 if cli_help_requested $@
; then
718 cli_show_man network-dhcp-subnet
727 dhcpd_subnet_new
${proto} $@
730 dhcpd_subnet_remove
${proto} $@
733 local subnet_id
=${action}
735 if ! dhcpd_subnet_exists
${proto} ${subnet_id}; then
736 error
"The given subnet with ID ${subnet_id} does not exist."
746 dhcpd_subnet_edit
${proto} ${subnet_id} $@
749 if [ ${ret} -eq ${EXIT_OK} ]; then
750 dhcpd_reload
${proto}
755 cli_dhcpd_subnet_range
${proto} ${subnet_id} $@
759 cli_dhcpd_subnet_show
${proto} ${subnet_id} $@
763 cli_dhcpd_subnet_options
${proto} ${subnet_id} $@
767 error
"Unrecognized action: ${action}"
768 cli_run_help network dhcpvN subnet
775 for subnet_id
in $
(dhcpd_subnet_list
${proto}); do
776 cli_dhcpd_subnet_show
${proto} ${subnet_id}
780 error
"Unrecognized action: ${action}"
781 cli_run_help network dhcpvN subnet
790 function cli_dhcpd_subnet_range
() {
796 assert isset subnet_id
804 dhcpd_subnet_range_new
${proto} ${subnet_id} $@
808 dhcpd_subnet_range_remove
${proto} ${subnet_id} $@
812 error
"Unrecognized action: ${action}"
813 cli_run_help network dhcpvN subnet range
819 function cli_dhcpd_subnet_show
() {
824 assert isset subnet_id
827 isset level || level
=0
829 local $
(dhcpd_subnet_settings
${proto})
831 # Read in configuration settings.
832 dhcpd_subnet_read
${proto} ${subnet_id}
834 cli_headline $
(( ${level} + 1 )) \
835 "DHCP${proto/ip/} subnet declaration #${subnet_id}"
836 cli_print_fmt1 $
(( ${level} + 1 )) \
837 "Subnet" "${ADDRESS}/${PREFIX}"
842 dhcpd_subnet_options_read
${proto} ${subnet_id}
844 # Print the options if any.
845 if [ ${#options[*]} -gt 0 ]; then
846 cli_headline $
(( ${level} + 2 )) "Options"
849 for option
in $
(dhcpd_subnet_options
${proto}); do
850 [ -n "${options[${option}]}" ] ||
continue
852 cli_print_fmt1 $
(( ${level} + 2 )) \
853 "${option}" "${options[${option}]}"
859 cli_headline $
(( ${level} + 2 )) "Ranges"
861 local ranges
=$
(dhcpd_subnet_range_list
${proto} ${subnet_id})
862 if isset ranges
; then
863 local range_id $
(dhcpd_subnet_range_settings
${proto})
864 for range_id
in ${ranges}; do
865 dhcpd_subnet_range_read
${proto} ${subnet_id} ${range_id}
867 cli_print $
(( ${level} + 2 )) \
868 "#%d: %s - %s" ${range_id} ${START} ${END}
871 cli_print $
(( ${level} + 2 )) "No ranges have been defined."
877 function cli_dhcpd_options
() {
883 assert isset subnet_id
886 local valid_options
=$
(dhcpd_subnet_options
${proto})
889 while [ $# -gt 0 ]; do
892 key
=$
(cli_get_key
${1})
893 val
=$
(cli_get_val
${1})
895 dhcpd_subnet_option_set
${proto} ${subnet_id} ${key} ${val}
900 function cli_start
() {
901 if cli_help_requested $@
; then
906 local zones
=$
(zones_get $@
)
909 for zone
in ${zones}; do
913 wait # until everything is settled
916 function cli_stop
() {
917 if cli_help_requested $@
; then
922 local zones
=$
(zones_get $@
)
925 for zone
in ${zones}; do
929 wait # until everything is settled
932 function cli_restart
() {
933 if cli_help_requested $@
; then
940 # Give the system some time to calm down
941 sleep ${TIMEOUT_RESTART}
946 function cli_status
() {
947 if cli_help_requested $@
; then
952 # When dumping status information, the debug
953 # mode clutters the console which is not what we want.
954 # Logging on the console is disabled for a short time.
955 local log_disable_stdout
=${LOG_DISABLE_STDOUT}
956 LOG_DISABLE_STDOUT
="true"
958 local zones
=$
(zones_get $@
)
961 for zone
in ${zones}; do
966 LOG_DISABLE_STDOUT
=${log_disable_stdout}
969 function cli_reset
() {
970 if cli_help_requested $@
; then
975 warning_log
"Will reset the whole network configuration!!!"
977 # Force mode is disabled by default
980 while [ $# -gt 0 ]; do
989 # If we are not running in force mode, we ask the user if he does know
991 if ! enabled force
; then
992 if ! cli_yesno
"Do you really want to reset the whole network configuration?"; then
998 for zone
in $
(zones_get
--all); do
1003 for port
in $
(ports_get
--all); do
1007 # Flush all DNS servers.
1010 # Re-run the initialization functions
1016 # Help function: will show the default man page to the user.
1017 # Optionally, there are two arguments taken, the type of hook
1018 # and which hook should be shown.
1019 function cli_help
() {
1023 # Remove unknown types.
1024 if ! listmatch
${type} zone port config
; then
1028 # If no arguments were given, we will show the default page.
1029 if [ -z "${type}" ]; then
1030 cli_show_man network
1034 if ! hook_exists
${type} ${what}; then
1035 error
"Hook of type '${type}' and name '${what}' could not be found."
1036 exit "${EXIT_ERROR}"
1039 hook_exec
${type} ${what} help
1042 function cli_dns_server
() {
1043 if cli_help_requested $@
; then
1044 cli_show_man network-dns-server
1049 local cmd
=${1}; shift
1050 if [ -z "${cmd}" ]; then
1051 cli_show_man network-dns-server
1055 # Get the new server to process (if any).
1065 if dns_server_exists
${server}; then
1066 error
"DNS server '${server}' already exists!"
1070 log INFO
"Adding new DNS server: ${server}"
1071 dns_server_add
${server} ${priority}
1074 if ! dns_server_exists
${server}; then
1075 error
"DNS server '${server}' does not exist!"
1079 log INFO
"Removing DNS server: ${server}"
1080 dns_server_remove
${server} ${priority}
1083 # Just run the update afterwards.
1086 error
"No such command: ${cmd}"
1090 # Update the local DNS configuration after changes have been made.
1091 dns_generate_resolvconf
1097 # Process the given action
1103 config|hostname|port|device|zone|start|stop|restart|status|
reset|route
)
1107 # DHCP server configuration (automatically detects which protocol to use).
1109 cli_dhcpd
${action/dhcp/ip} $@
1112 # DNS server configuration.
1122 error
"Invalid command given: ${action}"
1123 cli_usage
"network help"
1124 exit ${EXIT_CONF_ERROR}