2 ###############################################################################
4 # IPFire.org - A linux based firewall #
5 # Copyright (C) 2010 Michael Tremer & Christian Schmidt #
7 # This program is free software: you can redistribute it and/or modify #
8 # it under the terms of the GNU General Public License as published by #
9 # the Free Software Foundation, either version 3 of the License, or #
10 # (at your option) any later version. #
12 # This program is distributed in the hope that it will be useful, #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15 # GNU General Public License for more details. #
17 # You should have received a copy of the GNU General Public License #
18 # along with this program. If not, see <http://www.gnu.org/licenses/>. #
20 ###############################################################################
22 # Parse the command line
23 while [ $# -gt 0 ]; do
33 [ -n "${action}" ] && break
36 .
/usr
/lib
/network
/functions
38 # Read network configuration.
41 function cli_config
() {
42 if cli_help_requested $@
; then
43 cli_show_man network-config
47 if [ -n "${1}" ]; then
55 function cli_device
() {
56 if cli_help_requested $@
; then
57 cli_show_man network-device
65 if ! isset device
; then
66 cli_show_man network-device
70 assert device_exists
${device}
74 cli_device_discover
${device} $@
77 cli_device_status
${device}
80 cli_device_serial_unlock
${device} $@
83 cli_device_send_ussd_command
"${device}" $@
86 cli_show_man network-device
93 function cli_device_status
() {
95 assert device_exists
${device}
97 # Disable debugging output here.
98 local log_disable_stdout
=${LOG_DISABLE_STDOUT}
99 LOG_DISABLE_STDOUT
="true"
101 # Save the type of the device for later.
102 local type=$
(device_get_type
${device})
104 cli_headline
1 "Device status: ${device}"
105 cli_print_fmt1
1 "Name" "${device}"
107 # Handle serial devices.
108 if [ "${type}" = "serial" ]; then
109 cli_device_status_serial
${device}
113 # Print the device status.
114 device_is_up
${device} &>/dev
/null
119 status
="${CLR_GREEN_B}UP${CLR_RESET}"
122 status
="${CLR_RED_B}DOWN${CLR_RESET}"
126 cli_print_fmt1
1 "Status" "${status}"
127 cli_print_fmt1
1 "Type" "${type}"
128 cli_print_fmt1
1 "Address" "$(device_get_address ${device})"
131 # Print the link speed for ethernet devices.
132 if device_is_up
${device} &>/dev
/null
; then
135 cli_print_fmt1
1 "Link" \
136 "$(device_get_speed ${device}) MBit/s $(device_get_duplex ${device}) duplex"
141 cli_print_fmt1
1 "MTU" "$(device_get_mtu ${device})"
144 # Print device statistics.
145 cli_device_stats
2 ${device}
147 # Print some more information.
148 device_has_carrier
${device} &>/dev
/null
149 cli_print_fmt1
1 "Has carrier?" "$(cli_print_bool $?)"
151 device_is_promisc
${device} &>/dev
/null
152 cli_print_fmt1
1 "Promisc" "$(cli_print_bool $?)"
155 # Print all vlan devices.
156 local vlans
=$
(device_get_vlans
${device})
157 if [ -n "${vlans}" ]; then
158 cli_headline
2 "VLAN devices"
161 for vlan
in ${vlans}; do
162 cli_print
2 "* %-6s - %s" "${vlan}" "$(device_get_address ${vlan})"
167 # Reset the logging level.
168 LOG_DISABLE_STDOUT
=${log_disable_stdout}
171 function cli_device_status_serial
() {
173 assert device_is_serial
${device}
175 serial_is_locked
${device} &>/dev
/null
178 cli_print_fmt1
1 "Locked" "$(cli_print_bool ${locked})"
181 # Cannot go on when the device is locked.
182 [ ${locked} -eq ${EXIT_TRUE} ] && return ${EXIT_OK}
184 cli_print_fmt1
1 "Manufacturer" \
185 "$(modem_get_manufacturer ${device})"
186 cli_print_fmt1
1 "Model" \
187 "$(modem_get_model ${device})"
188 cli_print_fmt1
1 "Software version" \
189 "$(modem_get_software_version ${device})"
191 if modem_is_mobile
${device}; then
192 cli_print_fmt1
1 "IMEI" \
193 "$(modem_get_device_imei ${device})"
196 cli_headline
2 "Network status"
197 modem_sim_status
${device} &>/dev
/null
198 local sim_status_code
=$?
200 local sim_status
="unknown"
201 case "${sim_status_code}" in
203 sim_status
="SIM ready"
206 sim_status
="PIN locked"
209 sim_status
="PUK locked"
212 cli_print_fmt1
2 "SIM status" "${sim_status}"
214 if [ ${sim_status_code} -eq ${EXIT_SIM_READY} ]; then
215 cli_print_fmt1
2 "IMSI" \
216 "$(modem_get_sim_imsi ${device})"
217 cli_print_fmt1
2 "Operator" \
218 "$(modem_get_network_operator ${device})"
219 cli_print_fmt1
2 "Mode" \
220 "$(modem_get_network_mode ${device})"
221 cli_print_fmt1
2 "Signal quality" \
222 "$(modem_get_signal_quality ${device}) dBm"
224 local ber
=$
(modem_get_bit_error_rate
${device})
225 isset ber || ber
="unknown"
226 cli_print_fmt1
2 "Bit Error Rate" "${ber}"
232 function cli_device_discover
() {
236 local device_type
=$
(device_get_type
${device})
237 if [ "${device_type}" != "real" ]; then
243 while [ $# -gt 0 ]; do
253 device_is_up
${device} && up
=1
254 device_set_up
${device}
256 enabled raw ||
echo "${device}"
261 for hook
in $
(hook_zone_get_all
); do
262 out
=$
(hook_zone_exec
${hook} discover
${device})
265 [ ${ret} -eq ${DISCOVER_NOT_SUPPORTED} ] && continue
273 echo "${hook}: ${line}"
278 echo "${hook}: FAILED"
284 echo " ${hook} was successful."
292 echo " ${hook} failed."
300 [ "${up}" = "1" ] || device_set_down
${device}
303 function cli_device_serial_unlock
() {
304 if cli_help_requested $@
; then
305 cli_show_man network-device
312 if ! device_is_serial
${device}; then
313 error
"${device} is not a serial device."
314 error
"Unlocking is only supported for serial devices."
318 # Read the current state of the SIM card.
319 modem_sim_status
${device} &>/dev
/null
320 local sim_status_code
=$?
322 # If the SIM card is already unlocked, we don't need to do anything.
323 if [ ${sim_status_code} -eq ${EXIT_SIM_READY} ]; then
324 print
"The SIM card is already unlocked."
327 # If the SIM card is in an unknown state, we cannot do anything.
328 elif [ ${sim_status_code} -eq ${EXIT_SIM_UNKNOWN} ]; then
329 error
"The SIM card is in an unknown state."
335 local require_new_pin
="false"
338 while ! isinteger code
; do
340 case "${sim_status_code}" in
342 message
="Please enter PIN:"
345 message
="Please enter PUK:"
346 require_new_pin
="true"
351 echo -n "${message} "
353 echo # Print newline.
355 if enabled require_new_pin
; then
360 message
="Please enter a new PIN code:"
363 message
="Please confirm the new PIN code:"
367 echo -n "${message} "
369 echo # Print newline.
371 if [ -n "${new_pin}" ]; then
372 if [ "${new_pin}" != "${new_pin2}" ]; then
373 error
"The entered PIN codes did not match."
383 # Trying to unlock the SIM card.
384 modem_sim_unlock
${device} ${code} ${new_pin}
389 function cli_device_send_ussd_command
() {
397 while [ $# -gt 0 ]; do
400 timeout
="$(cli_get_val "${1}")"
403 if isset
command; then
404 warning
"Unrecognized argument: ${1}"
413 assert device_is_serial
"${device}"
416 if isset timeout
; then
417 args
="${args} --timeout=${timeout}"
420 modem_ussd_send_command
"${device}" "${command}" ${args}
424 function cli_hostname() {
425 if cli_help_requested $@; then
432 if [ -n "${hostname}" ]; then
433 config_hostname ${hostname}
434 log INFO "Hostname was
set to
'${hostname}'.
"
435 log INFO "Changes
do only take affect after reboot.
"
439 echo "$
(config_hostname
)"
443 function cli_port() {
444 if cli_help_requested $@; then
445 cli_show_man network-port
452 if port_exists ${1}; then
472 port_${action} ${port} $@
475 error "Unrecognized argument
: ${action}"
488 error "Unrecognized argument
: ${action}"
495 function cli_zone() {
496 if cli_help_requested $@; then
497 cli_show_man network-zone
504 if zone_name_is_valid ${1}; then
523 config|disable|down|edit|enable|port|status|up)
524 zone_${action} ${zone} $@
527 error "Unrecognized argument
: ${action}"
528 cli_show_man network-zone
544 cli_list_hooks zone $@
547 if [ -n "${action}" ]; then
548 error "Unrecognized argument
: '${action}'"
552 cli_show_man network-zone
559 # Removes a zone either immediately, if it is currently down,
560 # or adds a tag that the removal will be done when the zone
561 # is brought down the next time.
562 function cli_zone_remove() {
563 if cli_help_requested $@; then
564 cli_show_man network-zone
569 assert zone_exists ${zone}
571 if zone_is_up ${zone}; then
572 echo "Zone
'${zone}' is up and will be removed when it goes down the next
time.
"
575 echo "Removing zone
'${zone}' now...
"
576 zone_remove_now ${zone}
582 function cli_list_hooks() {
586 if cli_help_requested $@; then
587 cli_show_man network-zone
591 local hook_dir=$(hook_dir ${type})
594 for hook in ${hook_dir}/*; do
595 hook=$(basename ${hook})
596 if hook_exists ${type} ${hook}; then
602 function cli_route() {
603 if cli_help_requested $@; then
604 cli_show_man network-route
616 # Remove an existing route.
626 error "Unrecognized action
: ${action}"
627 cli_run_help network route
633 # Applying all routes.
639 function cli_dhcpd() {
643 if cli_help_requested $@; then
644 cli_show_man network-dhcp
653 dhcpd_edit ${proto} $@
662 dhcpd_reload ${proto}
665 cli_dhcpd_subnet ${proto} $@
668 cli_dhcpd_show ${proto} $@
671 error "Unrecognized action
: ${action}"
672 cli_run_help network dhcpvN
681 function cli_dhcpd_show() {
685 local settings=$(dhcpd_settings ${proto})
686 assert isset settings
689 dhcpd_global_settings_read ${proto}
691 cli_headline 1 "Dynamic Host Configuration Protocol Daemon
for ${proto/ip/IP}"
695 cli_headline 2 "Lease
times"
696 if isinteger VALID_LIFETIME; then
697 cli_print_fmt1 2 "Valid lifetime
" "${VALID_LIFETIME}s
"
700 if isinteger PREFERRED_LIFETIME; then
701 cli_print_fmt1 2 "Preferred lifetime
" "${PREFERRED_LIFETIME}s
"
707 cli_print_fmt1 1 "Authoritative
" $(cli_print_enabled AUTHORITATIVE)
710 cli_headline 2 "Lease
times"
711 cli_print_fmt1 2 "Default lease
time" "${DEFAULT_LEASE_TIME}s
"
712 cli_print_fmt1 2 "Max. lease
time" "${MAX_LEASE_TIME}s
"
714 if isset MIN_LEASE_TIME; then
715 cli_print_fmt1 2 "Min. lease
time" "${MIN_LEASE_TIME}s
"
724 dhcpd_global_options_read ${proto} ${subnet_id}
726 # Print the options if any.
727 if [ ${#options[*]} -gt 0 ]; then
728 cli_headline 2 "Options
"
731 for option in $(dhcpd_options ${proto}); do
732 [ -n "${options[${option}]}" ] || continue
735 "${option}" "${options[${option}]}"
741 local subnets=$(dhcpd_subnet_list ${proto})
742 if [ -n "${subnets}" ]; then
743 cli_headline 2 "Subnets
"
745 for subnet_id in ${subnets}; do
746 cli_dhcpd_subnet_show ${proto} ${subnet_id} 2
751 function cli_dhcpd_subnet() {
755 if cli_help_requested $@; then
756 cli_show_man network-dhcp-subnet
765 dhcpd_subnet_new ${proto} $@
768 dhcpd_subnet_remove ${proto} $@
771 local subnet_id=${action}
773 if ! dhcpd_subnet_exists ${proto} ${subnet_id}; then
774 error "The given subnet with ID
${subnet_id} does not exist.
"
784 dhcpd_subnet_edit ${proto} ${subnet_id} $@
787 if [ ${ret} -eq ${EXIT_OK} ]; then
788 dhcpd_reload ${proto}
793 cli_dhcpd_subnet_range ${proto} ${subnet_id} $@
797 cli_dhcpd_subnet_show ${proto} ${subnet_id} $@
801 cli_dhcpd_subnet_options ${proto} ${subnet_id} $@
805 error "Unrecognized action
: ${action}"
806 cli_run_help network dhcpvN subnet
813 for subnet_id in $(dhcpd_subnet_list ${proto}); do
814 cli_dhcpd_subnet_show ${proto} ${subnet_id}
818 error "Unrecognized action
: ${action}"
819 cli_run_help network dhcpvN subnet
828 function cli_dhcpd_subnet_range() {
834 assert isset subnet_id
842 dhcpd_subnet_range_new ${proto} ${subnet_id} $@
846 dhcpd_subnet_range_remove ${proto} ${subnet_id} $@
850 error "Unrecognized action
: ${action}"
851 cli_run_help network dhcpvN subnet range
857 function cli_dhcpd_subnet_show() {
862 assert isset subnet_id
865 isset level || level=0
867 local $(dhcpd_subnet_settings ${proto})
869 # Read in configuration settings.
870 dhcpd_subnet_read ${proto} ${subnet_id}
872 cli_headline $(( ${level} + 1 )) \
873 "DHCP
${proto/ip/} subnet declaration
#${subnet_id}"
874 cli_print_fmt1 $
(( ${level} + 1 )) \
875 "Subnet" "${ADDRESS}/${PREFIX}"
880 dhcpd_subnet_options_read
${proto} ${subnet_id}
882 # Print the options if any.
883 if [ ${#options[*]} -gt 0 ]; then
884 cli_headline $
(( ${level} + 2 )) "Options"
887 for option
in $
(dhcpd_subnet_options
${proto}); do
888 [ -n "${options[${option}]}" ] ||
continue
890 cli_print_fmt1 $
(( ${level} + 2 )) \
891 "${option}" "${options[${option}]}"
897 cli_headline $
(( ${level} + 2 )) "Ranges"
899 local ranges
=$
(dhcpd_subnet_range_list
${proto} ${subnet_id})
900 if isset ranges
; then
901 local range_id $
(dhcpd_subnet_range_settings
${proto})
902 for range_id
in ${ranges}; do
903 dhcpd_subnet_range_read
${proto} ${subnet_id} ${range_id}
905 cli_print $
(( ${level} + 2 )) \
906 "#%d: %s - %s" ${range_id} ${START} ${END}
909 cli_print $
(( ${level} + 2 )) "No ranges have been defined."
915 function cli_dhcpd_options
() {
921 assert isset subnet_id
924 local valid_options
=$
(dhcpd_subnet_options
${proto})
927 while [ $# -gt 0 ]; do
930 key
=$
(cli_get_key
${1})
931 val
=$
(cli_get_val
${1})
933 dhcpd_subnet_option_set
${proto} ${subnet_id} ${key} ${val}
938 function cli_start
() {
939 if cli_help_requested $@
; then
944 local zones
=$
(zones_get $@
)
947 for zone
in ${zones}; do
951 wait # until everything is settled
954 function cli_stop
() {
955 if cli_help_requested $@
; then
960 local zones
=$
(zones_get $@
)
963 for zone
in ${zones}; do
967 wait # until everything is settled
970 function cli_restart
() {
971 if cli_help_requested $@
; then
978 # Give the system some time to calm down
979 sleep ${TIMEOUT_RESTART}
984 function cli_status
() {
985 if cli_help_requested $@
; then
990 # When dumping status information, the debug
991 # mode clutters the console which is not what we want.
992 # Logging on the console is disabled for a short time.
993 local log_disable_stdout
=${LOG_DISABLE_STDOUT}
994 LOG_DISABLE_STDOUT
="true"
996 local zones
=$
(zones_get $@
)
999 for zone
in ${zones}; do
1004 LOG_DISABLE_STDOUT
=${log_disable_stdout}
1007 function cli_reset
() {
1008 if cli_help_requested $@
; then
1009 cli_show_man network
1013 warning_log
"Will reset the whole network configuration!!!"
1015 # Force mode is disabled by default
1018 while [ $# -gt 0 ]; do
1027 # If we are not running in force mode, we ask the user if he does know
1029 if ! enabled force
; then
1030 if ! cli_yesno
"Do you really want to reset the whole network configuration?"; then
1036 for zone
in $
(zones_get
--all); do
1041 for port
in $
(ports_get
--all); do
1045 # Flush all DNS servers.
1048 # Re-run the initialization functions
1054 # Help function: will show the default man page to the user.
1055 # Optionally, there are two arguments taken, the type of hook
1056 # and which hook should be shown.
1057 function cli_help
() {
1061 # Remove unknown types.
1062 if ! listmatch
${type} zone port config
; then
1066 # If no arguments were given, we will show the default page.
1067 if [ -z "${type}" ]; then
1068 cli_show_man network
1072 if ! hook_exists
${type} ${what}; then
1073 error
"Hook of type '${type}' and name '${what}' could not be found."
1074 exit "${EXIT_ERROR}"
1077 hook_exec
${type} ${what} help
1080 function cli_dns_server
() {
1081 if cli_help_requested $@
; then
1082 cli_show_man network-dns-server
1087 local cmd
=${1}; shift
1088 if [ -z "${cmd}" ]; then
1089 cli_show_man network-dns-server
1093 # Get the new server to process (if any).
1103 if dns_server_exists
${server}; then
1104 error
"DNS server '${server}' already exists!"
1108 log INFO
"Adding new DNS server: ${server}"
1109 dns_server_add
${server} ${priority}
1112 if ! dns_server_exists
${server}; then
1113 error
"DNS server '${server}' does not exist!"
1117 log INFO
"Removing DNS server: ${server}"
1118 dns_server_remove
${server} ${priority}
1121 # Just run the update afterwards.
1124 error
"No such command: ${cmd}"
1128 # Update the local DNS configuration after changes have been made.
1129 dns_generate_resolvconf
1135 # Process the given action
1141 config|hostname|port|device|zone|start|stop|restart|status|
reset|route
)
1145 # DHCP server configuration (automatically detects which protocol to use).
1147 cli_dhcpd
${action/dhcp/ip} $@
1150 # DNS server configuration.
1160 error
"Invalid command given: ${action}"
1161 cli_usage
"network help"
1162 exit ${EXIT_CONF_ERROR}