2 ###############################################################################
4 # IPFire.org - A linux based firewall #
5 # Copyright (C) 2010 Michael Tremer & Christian Schmidt #
7 # This program is free software: you can redistribute it and/or modify #
8 # it under the terms of the GNU General Public License as published by #
9 # the Free Software Foundation, either version 3 of the License, or #
10 # (at your option) any later version. #
12 # This program is distributed in the hope that it will be useful, #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15 # GNU General Public License for more details. #
17 # You should have received a copy of the GNU General Public License #
18 # along with this program. If not, see <http://www.gnu.org/licenses/>. #
20 ###############################################################################
22 # Parse the command line
23 while [ $# -gt 0 ]; do
33 [ -n "${action}" ] && break
36 .
/usr
/lib
/network
/functions
38 # Read network settings
42 if cli_help_requested $@
; then
43 cli_show_man network-settings
47 if [ -n "${1}" ]; then
49 network_settings_write
51 network_settings_print
56 if cli_help_requested $@
; then
57 cli_show_man network-device
69 local device
="${action}"
73 if ! isset device
; then
74 cli_show_man network-device
78 assert device_exists
${device}
82 cli_device_discover
${device} $@
85 cli_device_monitor
"${device}" $@
88 cli_device_status
${device}
91 cli_device_serial_unlock
${device} $@
94 cli_device_send_ussd_command
"${device}" $@
97 cli_show_man network-device
106 cli_device_status
() {
110 # Disable debugging output here.
111 local log_disable_stdout
=${LOG_DISABLE_STDOUT}
112 LOG_DISABLE_STDOUT
="true"
114 # Save the type of the device for later.
115 local type=$
(device_get_type
${device})
117 cli_headline
1 "Device status: ${device}"
118 cli_print_fmt1
1 "Name" "${device}"
120 # Handle special devices
123 cli_device_status_phy
"${device}"
127 cli_device_status_serial
"${device}"
132 # Print the device status.
133 device_is_up
${device} &>/dev
/null
138 status
="${CLR_GREEN_B}UP${CLR_RESET}"
141 status
="${CLR_RED_B}DOWN${CLR_RESET}"
145 cli_print_fmt1
1 "Status" "${status}"
146 cli_print_fmt1
1 "Type" "${type}"
148 # Ethernet-compatible?
149 device_is_ethernet_compatible
"${device}" &>/dev
/null
150 cli_print_fmt1
1 "Ethernet-compatible" "$(cli_print_bool $?)"
152 cli_print_fmt1
1 "Address" "$(device_get_address ${device})"
155 # Print the link speed for ethernet devices.
156 if device_is_up
${device} &>/dev
/null
; then
157 local link
="$(device_get_link_string "${device}")"
159 cli_print_fmt1
1 "Link" "${link}"
163 cli_print_fmt1
1 "MTU" "$(device_get_mtu ${device})"
166 # Print device statistics.
167 cli_device_stats
2 ${device}
169 # Print some more information.
170 device_has_carrier
${device} &>/dev
/null
171 cli_print_fmt1
1 "Has carrier?" "$(cli_print_bool $?)"
173 device_is_promisc
${device} &>/dev
/null
174 cli_print_fmt1
1 "Promisc" "$(cli_print_bool $?)"
177 # Print all vlan devices.
178 local vlans
=$
(device_get_vlans
${device})
179 if [ -n "${vlans}" ]; then
180 cli_headline
2 "VLAN devices"
183 for vlan
in ${vlans}; do
184 cli_print
2 "* %-6s - %s" "${vlan}" "$(device_get_address ${vlan})"
191 local phy
="$(device_get_phy "${device}")"
194 cli_print_fmt1
2 "Name" "${phy}"
195 cli_print_fmt1
2 "Address" "$(phy_get_address "${phy}")"
201 # Reset the logging level.
202 LOG_DISABLE_STDOUT
=${log_disable_stdout}
205 cli_device_status_serial
() {
207 assert device_is_serial
${device}
209 serial_is_locked
${device} &>/dev
/null
212 cli_print_fmt1
1 "Locked" "$(cli_print_bool ${locked})"
215 # Cannot go on when the device is locked.
216 [ ${locked} -eq ${EXIT_TRUE} ] && return ${EXIT_OK}
218 cli_print_fmt1
1 "Manufacturer" \
219 "$(modem_get_manufacturer ${device})"
220 cli_print_fmt1
1 "Model" \
221 "$(modem_get_model ${device})"
222 cli_print_fmt1
1 "Software version" \
223 "$(modem_get_software_version ${device})"
225 if modem_is_mobile
${device}; then
226 cli_print_fmt1
1 "IMEI" \
227 "$(modem_get_device_imei ${device})"
230 cli_headline
2 "Network status"
231 modem_sim_status
${device} &>/dev
/null
232 local sim_status_code
=$?
234 local sim_status
="unknown"
235 case "${sim_status_code}" in
237 sim_status
="SIM ready"
240 sim_status
="PIN locked"
243 sim_status
="PUK locked"
246 cli_print_fmt1
2 "SIM status" "${sim_status}"
248 if [ ${sim_status_code} -eq ${EXIT_SIM_READY} ]; then
249 cli_print_fmt1
2 "IMSI" \
250 "$(modem_get_sim_imsi ${device})"
251 cli_print_fmt1
2 "Operator" \
252 "$(modem_get_network_operator ${device})"
253 cli_print_fmt1
2 "Mode" \
254 "$(modem_get_network_mode ${device})"
255 cli_print_fmt1
2 "Signal quality" \
256 "$(modem_get_signal_quality ${device}) dBm"
258 local ber
=$
(modem_get_bit_error_rate
${device})
259 isset ber || ber
="unknown"
260 cli_print_fmt1
2 "Bit Error Rate" "${ber}"
266 cli_device_status_phy
() {
268 assert phy_exists
"${phy}"
270 local address
="$(phy_get_address "${phy}")"
271 cli_print_fmt1
1 "Address" "${address}"
274 local devices
="$(phy_get_devices "${phy}")"
275 if isset devices
; then
276 cli_headline
2 "Soft interfaces"
279 for device
in ${devices}; do
280 cli_print
2 "* %s" "${device}"
288 cli_device_discover
() {
292 # This can only be executed for ethernet (or compatible) devices
293 if ! device_is_ethernet_compatible
"${device}"; then
299 while [ $# -gt 0 ]; do
309 device_is_up
${device} && up
=1
310 device_set_up
${device}
312 enabled raw ||
echo "${device}"
317 for hook
in $
(hook_zone_get_all
); do
318 out
=$
(hook_zone_exec
${hook} discover
${device})
321 [ ${ret} -eq ${DISCOVER_NOT_SUPPORTED} ] && continue
329 echo "${hook}: ${line}"
334 echo "${hook}: FAILED"
340 echo " ${hook} was successful."
348 echo " ${hook} failed."
356 [ "${up}" = "1" ] || device_set_down
${device}
359 cli_device_serial_unlock
() {
360 if cli_help_requested $@
; then
361 cli_show_man network-device
368 if ! device_is_serial
${device}; then
369 error
"${device} is not a serial device."
370 error
"Unlocking is only supported for serial devices."
374 # Read the current state of the SIM card.
375 modem_sim_status
${device} &>/dev
/null
376 local sim_status_code
=$?
378 # If the SIM card is already unlocked, we don't need to do anything.
379 if [ ${sim_status_code} -eq ${EXIT_SIM_READY} ]; then
380 print
"The SIM card is already unlocked."
383 # If the SIM card is in an unknown state, we cannot do anything.
384 elif [ ${sim_status_code} -eq ${EXIT_SIM_UNKNOWN} ]; then
385 error
"The SIM card is in an unknown state."
391 local require_new_pin
="false"
394 while ! isinteger code
; do
396 case "${sim_status_code}" in
398 message
="Please enter PIN:"
401 message
="Please enter PUK:"
402 require_new_pin
="true"
407 echo -n "${message} "
409 echo # Print newline.
411 if enabled require_new_pin
; then
416 message
="Please enter a new PIN code:"
419 message
="Please confirm the new PIN code:"
423 echo -n "${message} "
425 echo # Print newline.
427 if [ -n "${new_pin}" ]; then
428 if [ "${new_pin}" != "${new_pin2}" ]; then
429 error
"The entered PIN codes did not match."
439 # Trying to unlock the SIM card.
440 modem_sim_unlock
${device} ${code} ${new_pin}
445 cli_device_send_ussd_command
() {
453 while [ $# -gt 0 ]; do
456 timeout
="$(cli_get_val "${1}")"
459 if isset
command; then
460 warning
"Unrecognized argument: ${1}"
469 assert device_is_serial
"${device}"
472 if isset timeout
; then
473 args
="${args} --timeout=${timeout}"
476 modem_ussd_send_command
"${device}" "${command}" ${args}
480 cli_device_monitor() {
484 if ! device_is_wireless "${device}"; then
485 error "This action only works with wireless devices. Exiting.
"
489 wireless_monitor "${device}"
495 for device in $(device_list); do
496 cli_device_status "${device}"
503 if cli_help_requested $@; then
510 if [ -n "${hostname}" ]; then
511 config_hostname ${hostname}
512 log INFO "Hostname was
set to
'${hostname}'.
"
513 log INFO "Changes
do only take affect after reboot.
"
517 echo "$
(config_hostname
)"
522 if cli_help_requested $@; then
523 cli_show_man network-port
530 if port_exists ${1}; then
536 edit|create|remove|up|down|status)
537 port_${action} "${port}" $@
540 error "Unrecognized argument
: ${action}"
553 error "Unrecognized argument
: ${action}"
561 if cli_help_requested $@; then
562 cli_show_man network-zone
569 if zone_name_is_valid ${1}; then
589 cli_zone_port "${zone}" $@
591 config|disable|down|edit|enable|status|up)
592 zone_${action} ${zone} $@
595 error "Unrecognized argument
: ${action}"
596 cli_show_man network-zone
612 cli_list_hooks zone $@
615 if [ -n "${action}" ]; then
616 error "Unrecognized argument
: '${action}'"
620 cli_show_man network-zone
627 # Removes a zone either immediately, if it is currently down,
628 # or adds a tag that the removal will be done when the zone
629 # is brought down the next time.
631 if cli_help_requested $@; then
632 cli_show_man network-zone
637 assert zone_exists "${zone}"
639 if zone_is_up ${zone}; then
640 echo "Zone
'${zone}' is up and will be removed when it goes down the next
time.
"
641 zone_destroy "${zone}"
643 echo "Removing zone
'${zone}' now...
"
644 zone_destroy_now "${zone}"
651 if cli_help_requested $@; then
652 cli_show_man network-zone-port
657 assert zone_exists "${zone}"
659 if port_exists "${2}"; then
666 zone_port_edit "${zone}" "${port}" $@
669 error "Unrecognised argument
: ${action}"
679 zone_port_attach "${zone}" $@
682 zone_port_detach "${zone}" $@
685 error "Unrecognised argument
: ${action}"
698 if cli_help_requested $@; then
699 cli_show_man network-zone
703 local hook_dir=$(hook_dir ${type})
706 for hook in ${hook_dir}/*; do
707 hook=$(basename ${hook})
708 if hook_exists ${type} ${hook}; then
715 if cli_help_requested $@; then
716 cli_show_man network-route
728 # Remove an existing route.
738 error "Unrecognized action
: ${action}"
739 cli_run_help network route
745 # Applying all routes.
755 if cli_help_requested $@; then
756 cli_show_man network-dhcp
765 dhcpd_edit ${proto} $@
774 dhcpd_reload ${proto}
777 cli_dhcpd_subnet ${proto} $@
780 cli_dhcpd_show ${proto} $@
783 error "Unrecognized action
: ${action}"
784 cli_run_help network dhcpvN
797 local settings=$(dhcpd_settings ${proto})
798 assert isset settings
801 dhcpd_global_settings_read ${proto}
803 cli_headline 1 "Dynamic Host Configuration Protocol Daemon
for ${proto/ip/IP}"
807 cli_headline 2 "Lease
times"
808 if isinteger VALID_LIFETIME; then
809 cli_print_fmt1 2 "Valid lifetime
" "${VALID_LIFETIME}s
"
812 if isinteger PREFERRED_LIFETIME; then
813 cli_print_fmt1 2 "Preferred lifetime
" "${PREFERRED_LIFETIME}s
"
819 cli_print_fmt1 1 "Authoritative
" $(cli_print_enabled AUTHORITATIVE)
822 cli_headline 2 "Lease
times"
823 cli_print_fmt1 2 "Default lease
time" "${DEFAULT_LEASE_TIME}s
"
824 cli_print_fmt1 2 "Max. lease
time" "${MAX_LEASE_TIME}s
"
826 if isset MIN_LEASE_TIME; then
827 cli_print_fmt1 2 "Min. lease
time" "${MIN_LEASE_TIME}s
"
836 dhcpd_global_options_read ${proto} ${subnet_id}
838 # Print the options if any.
839 if [ ${#options[*]} -gt 0 ]; then
840 cli_headline 2 "Options
"
843 for option in $(dhcpd_options ${proto}); do
844 [ -n "${options[${option}]}" ] || continue
847 "${option}" "${options[${option}]}"
853 local subnets=$(dhcpd_subnet_list ${proto})
854 if [ -n "${subnets}" ]; then
855 cli_headline 2 "Subnets
"
857 for subnet_id in ${subnets}; do
858 cli_dhcpd_subnet_show ${proto} ${subnet_id} 2
867 if cli_help_requested $@; then
868 cli_show_man network-dhcp-subnet
877 dhcpd_subnet_new ${proto} $@
880 dhcpd_subnet_remove ${proto} $@
883 local subnet_id=${action}
885 if ! dhcpd_subnet_exists ${proto} ${subnet_id}; then
886 error "The given subnet with ID
${subnet_id} does not exist.
"
896 dhcpd_subnet_edit ${proto} ${subnet_id} $@
899 if [ ${ret} -eq ${EXIT_OK} ]; then
900 dhcpd_reload ${proto}
905 cli_dhcpd_subnet_range ${proto} ${subnet_id} $@
909 cli_dhcpd_subnet_show ${proto} ${subnet_id} $@
913 cli_dhcpd_subnet_options ${proto} ${subnet_id} $@
917 error "Unrecognized action
: ${action}"
918 cli_run_help network dhcpvN subnet
925 for subnet_id in $(dhcpd_subnet_list ${proto}); do
926 cli_dhcpd_subnet_show ${proto} ${subnet_id}
930 error "Unrecognized action
: ${action}"
931 cli_run_help network dhcpvN subnet
940 cli_dhcpd_subnet_range() {
946 assert isset subnet_id
954 dhcpd_subnet_range_new ${proto} ${subnet_id} $@
958 dhcpd_subnet_range_remove ${proto} ${subnet_id} $@
962 error "Unrecognized action
: ${action}"
963 cli_run_help network dhcpvN subnet range
969 cli_dhcpd_subnet_show() {
974 assert isset subnet_id
977 isset level || level=0
979 local $(dhcpd_subnet_settings ${proto})
981 # Read in configuration settings.
982 dhcpd_subnet_read ${proto} ${subnet_id}
984 cli_headline $(( ${level} + 1 )) \
985 "DHCP
${proto/ip/} subnet declaration
#${subnet_id}"
986 cli_print_fmt1 $
(( ${level} + 1 )) \
987 "Subnet" "${ADDRESS}/${PREFIX}"
992 dhcpd_subnet_options_read
${proto} ${subnet_id}
994 # Print the options if any.
995 if [ ${#options[*]} -gt 0 ]; then
996 cli_headline $
(( ${level} + 2 )) "Options"
999 for option
in $
(dhcpd_subnet_options_list
${proto}); do
1000 [ -n "${options[${option}]}" ] ||
continue
1002 cli_print_fmt1 $
(( ${level} + 2 )) \
1003 "${option}" "${options[${option}]}"
1009 cli_headline $
(( ${level} + 2 )) "Ranges"
1011 local ranges
=$
(dhcpd_subnet_range_list
${proto} ${subnet_id})
1012 if isset ranges
; then
1013 local range_id $
(dhcpd_subnet_range_settings
${proto})
1014 for range_id
in ${ranges}; do
1015 dhcpd_subnet_range_read
${proto} ${subnet_id} ${range_id}
1017 cli_print $
(( ${level} + 2 )) \
1018 "#%d: %s - %s" ${range_id} ${START} ${END}
1021 cli_print $
(( ${level} + 2 )) "No ranges have been defined."
1027 cli_dhcpd_subnet_options
() {
1032 local subnet_id
=${1}
1033 assert isset subnet_id
1037 while [ $# -gt 0 ]; do
1040 key
=$
(cli_get_key
${1})
1041 val
=$
(cli_get_val
${1})
1043 dhcpd_subnet_option_set
${proto} ${subnet_id} ${key} ${val}
1049 if cli_help_requested $@
; then
1050 cli_show_man network
1054 local zones
=$
(zones_get $@
)
1057 for zone
in ${zones}; do
1058 zone_start
${zone} &
1061 wait # until everything is settled
1065 if cli_help_requested $@
; then
1066 cli_show_man network
1070 local zones
=$
(zones_get $@
)
1073 for zone
in ${zones}; do
1077 wait # until everything is settled
1081 if cli_help_requested $@
; then
1082 cli_show_man network
1088 # Give the system some time to calm down
1089 sleep ${TIMEOUT_RESTART}
1095 if cli_help_requested $@
; then
1096 cli_show_man network
1100 # When dumping status information, the debug
1101 # mode clutters the console which is not what we want.
1102 # Logging on the console is disabled for a short time.
1103 local log_disable_stdout
=${LOG_DISABLE_STDOUT}
1104 LOG_DISABLE_STDOUT
="true"
1106 local zones
=$
(zones_get $@
)
1109 for zone
in ${zones}; do
1114 LOG_DISABLE_STDOUT
=${log_disable_stdout}
1118 if cli_help_requested $@
; then
1119 cli_show_man network
1123 warning_log
"Will reset the whole network configuration!!!"
1125 # Force mode is disabled by default
1128 while [ $# -gt 0 ]; do
1137 # If we are not running in force mode, we ask the user if he does know
1139 if ! enabled force
; then
1140 if ! cli_yesno
"Do you really want to reset the whole network configuration?"; then
1146 for zone
in $
(zones_get
--all); do
1147 zone_destroy_now
"${zone}"
1151 for port
in $
(ports_get
--all); do
1152 port_destroy
"${port}"
1155 # Flush all DNS servers.
1158 # Re-run the initialization functions
1164 # Help function: will show the default man page to the user.
1165 # Optionally, there are two arguments taken, the type of hook
1166 # and which hook should be shown.
1171 # Remove unknown types.
1172 if ! listmatch
${type} zone port config
; then
1176 # If no arguments were given, we will show the default page.
1177 if [ -z "${type}" ]; then
1178 cli_show_man network
1182 if ! hook_exists
${type} ${what}; then
1183 error
"Hook of type '${type}' and name '${what}' could not be found."
1184 exit "${EXIT_ERROR}"
1187 hook_exec
${type} ${what} help
1191 if cli_help_requested $@
; then
1192 cli_show_man network-dns-server
1197 local cmd
=${1}; shift
1198 if [ -z "${cmd}" ]; then
1199 cli_show_man network-dns-server
1203 # Get the new server to process (if any).
1213 if dns_server_exists
${server}; then
1214 error
"DNS server '${server}' already exists!"
1218 log INFO
"Adding new DNS server: ${server}"
1219 dns_server_add
${server} ${priority}
1222 if ! dns_server_exists
${server}; then
1223 error
"DNS server '${server}' does not exist!"
1227 log INFO
"Removing DNS server: ${server}"
1228 dns_server_remove
${server} ${priority}
1231 # Just run the update afterwards.
1234 error
"No such command: ${cmd}"
1238 # Update the local DNS configuration after changes have been made.
1239 dns_generate_resolvconf
1257 list-dhcpd-ranges-of-subnet
)
1258 dhcpd_subnet_range_list $@
1260 list-dhcpd-settings
)
1261 dhcpd_global_settings_list $@
1264 dhcpd_subnet_list $@
1266 list-dhcpd-subnet-options
)
1267 dhcpd_subnet_options_list $@
1285 network_settings_list
1291 error
"No such command: ${cmd}"
1299 # Process the given action
1305 settings|hostname|port|device|zone|start|stop|restart|status|
reset|route
)
1309 # DHCP server configuration (automatically detects which protocol to use).
1311 cli_dhcpd
${action/dhcp/ip} $@
1314 # DNS server configuration.
1328 error
"Invalid command given: ${action}"
1329 cli_usage
"network help"
1330 exit ${EXIT_CONF_ERROR}