]> git.ipfire.org Git - people/teissler/ipfire-2.x.git/blobdiff - html/cgi-bin/forwardfw.cgi
Forward Firewall: set standard config for Firewall
[people/teissler/ipfire-2.x.git] / html / cgi-bin / forwardfw.cgi
index 7b7271d557539e42a9c101b2f01821922ebb114d..37ba41d0b2b4d390f146c28bba3ca2bbbacf3952 100755 (executable)
@@ -112,7 +112,6 @@ if ($fwdfwsettings{'ACTION'} eq 'saverule')
        $errormessage=&checksource;
        if(!$errormessage){&checktarget;}
        if(!$errormessage){&checkrule;}
-
        #check if we change an forward rule to an external access
        if(     $fwdfwsettings{'grp2'} eq 'ipfire' && $fwdfwsettings{'oldgrp2a'} ne 'ipfire' && $fwdfwsettings{'updatefwrule'} eq 'on'){
                $fwdfwsettings{'updatefwrule'}='';
@@ -122,7 +121,6 @@ if ($fwdfwsettings{'ACTION'} eq 'saverule')
                &checkcounter(0,0,$fwdfwsettings{'grp1'},$fwdfwsettings{$fwdfwsettings{'grp1'}});
                &checkcounter(0,0,$fwdfwsettings{'grp3'},$fwdfwsettings{$fwdfwsettings{'grp3'}});
        }
-
        #check if we change an external access rule to an forward
        if(     $fwdfwsettings{'grp2'} ne 'ipfire' && $fwdfwsettings{'oldgrp2a'} eq 'ipfire' && $fwdfwsettings{'updatefwrule'} eq 'on'){
                $fwdfwsettings{'updatefwrule'}='';
@@ -141,9 +139,22 @@ if ($fwdfwsettings{'ACTION'} eq 'saverule')
                                if ("$fwdfwsettings{'RULE_ACTION'},$fwdfwsettings{'ACTIVE'},$fwdfwsettings{'grp1'},$fwdfwsettings{$fwdfwsettings{'grp1'}},$fwdfwsettings{'grp2'},$fwdfwsettings{$fwdfwsettings{'grp2'}},$fwdfwsettings{'USE_SRC_PORT'},$fwdfwsettings{'PROT'},$fwdfwsettings{'ICMP_TYPES'},$fwdfwsettings{'SRC_PORT'},$fwdfwsettings{'USESRV'},$fwdfwsettings{'TGT_PROT'},$fwdfwsettings{'ICMP_TGT'},$fwdfwsettings{'grp3'},$fwdfwsettings{$fwdfwsettings{'grp3'}},$fwdfwsettings{'LOG'},$fwdfwsettings{'TIME'},$fwdfwsettings{'TIME_MON'},$fwdfwsettings{'TIME_TUE'},$fwdfwsettings{'TIME_WED'},$fwdfwsettings{'TIME_THU'},$fwdfwsettings{'TIME_FRI'},$fwdfwsettings{'TIME_SAT'},$fwdfwsettings{'TIME_SUN'},$fwdfwsettings{'TIME_FROM'},$fwdfwsettings{'TIME_TO'}" 
                                        eq "$configinputfw{$key}[0],$configinputfw{$key}[2],$configinputfw{$key}[3],$configinputfw{$key}[4],$configinputfw{$key}[5],$configinputfw{$key}[6],$configinputfw{$key}[7],$configinputfw{$key}[8],$configinputfw{$key}[9],$configinputfw{$key}[10],$configinputfw{$key}[11],$configinputfw{$key}[12],$configinputfw{$key}[13],$configinputfw{$key}[14],$configinputfw{$key}[15],$configinputfw{$key}[17],$configinputfw{$key}[18],$configinputfw{$key}[19],$configinputfw{$key}[20],$configinputfw{$key}[21],$configinputfw{$key}[22],$configinputfw{$key}[23],$configinputfw{$key}[24],$configinputfw{$key}[25],$configinputfw{$key}[26],$configinputfw{$key}[27]"){
                                                $errormessage.=$Lang::tr{'fwdfw err ruleexists'};
+                                               if ($fwdfwsettings{'oldruleremark'} ne $fwdfwsettings{'ruleremark'} && $fwdfwsettings{'updatefwrule'} eq 'on'){
+                                                       $errormessage='';
+                                               }
+                                               if ($fwdfwsettings{'oldruleremark'} eq $fwdfwsettings{'ruleremark'}){
+                                                       $fwdfwsettings{'nosave'} = 'on';
+                                               }
                                }       
                        }       
                }
+               #check if we just close a rule
+               if( $fwdfwsettings{'oldgrp1a'} eq  $fwdfwsettings{'grp1'} && $fwdfwsettings{'oldgrp1b'} eq $fwdfwsettings{$fwdfwsettings{'grp1'}} && $fwdfwsettings{'oldgrp2a'} eq  $fwdfwsettings{'grp2'} && $fwdfwsettings{'oldgrp2b'} eq $fwdfwsettings{$fwdfwsettings{'grp2'}} &&  $fwdfwsettings{'oldgrp3a'} eq $fwdfwsettings{'grp3'} && $fwdfwsettings{'oldgrp3b'} eq  $fwdfwsettings{$fwdfwsettings{'grp3'}} && $fwdfwsettings{'oldusesrv'} eq $fwdfwsettings{'USESRV'} ) {
+                       if($fwdfwsettings{'nosave'} eq 'on' && $fwdfwsettings{'updatefwrule'} eq 'on'){
+                               $errormessage='';
+                               $fwdfwsettings{'nosave2'} = 'on';
+                       }
+               }
                &checkcounter($fwdfwsettings{'oldgrp1a'},$fwdfwsettings{'oldgrp1b'},$fwdfwsettings{'grp1'},$fwdfwsettings{$fwdfwsettings{'grp1'}});
                if ($fwdfwsettings{'nobase'} ne 'on'){
                        &checkcounter($fwdfwsettings{'oldgrp2a'},$fwdfwsettings{'oldgrp2b'},$fwdfwsettings{'grp2'},$fwdfwsettings{$fwdfwsettings{'grp2'}});
@@ -155,8 +166,9 @@ if ($fwdfwsettings{'ACTION'} eq 'saverule')
                }elsif ($fwdfwsettings{'oldusesrv'} eq $fwdfwsettings{'USESRV'} && $fwdfwsettings{'oldgrp3b'} ne $fwdfwsettings{$fwdfwsettings{'grp3'}} && $fwdfwsettings{'updatefwrule'} eq 'on'){
                        &checkcounter($fwdfwsettings{'oldgrp3a'},$fwdfwsettings{'oldgrp3b'},$fwdfwsettings{'grp3'},$fwdfwsettings{$fwdfwsettings{'grp3'}});
                }
-
-               &saverule(\%configinputfw,$configinput);
+               if($fwdfwsettings{'nosave2'} ne 'on'){
+                       &saverule(\%configinputfw,$configinput);
+               }
                #print "Source: $fwdfwsettings{'grp1'} -> $fwdfwsettings{$fwdfwsettings{'grp1'}}<br>";
                #print "Sourceport: $fwdfwsettings{'USE_SRC_PORT'}, $fwdfwsettings{'PROT'}, $fwdfwsettings{'ICMP_TYPES'}, $fwdfwsettings{'SRC_PORT'}<br>";
                #print "Target: $fwdfwsettings{'grp2'} -> $fwdfwsettings{$fwdfwsettings{'grp2'}}<br>";
@@ -186,9 +198,22 @@ if ($fwdfwsettings{'ACTION'} eq 'saverule')
                                if ("$fwdfwsettings{'RULE_ACTION'},$fwdfwsettings{'ACTIVE'},$fwdfwsettings{'grp1'},$fwdfwsettings{$fwdfwsettings{'grp1'}},$fwdfwsettings{'grp2'},$fwdfwsettings{$fwdfwsettings{'grp2'}},$fwdfwsettings{'USE_SRC_PORT'},$fwdfwsettings{'PROT'},$fwdfwsettings{'ICMP_TYPES'},$fwdfwsettings{'SRC_PORT'},$fwdfwsettings{'USESRV'},$fwdfwsettings{'TGT_PROT'},$fwdfwsettings{'ICMP_TGT'},$fwdfwsettings{'grp3'},$fwdfwsettings{$fwdfwsettings{'grp3'}},$fwdfwsettings{'LOG'},$fwdfwsettings{'TIME'},$fwdfwsettings{'TIME_MON'},$fwdfwsettings{'TIME_TUE'},$fwdfwsettings{'TIME_WED'},$fwdfwsettings{'TIME_THU'},$fwdfwsettings{'TIME_FRI'},$fwdfwsettings{'TIME_SAT'},$fwdfwsettings{'TIME_SUN'},$fwdfwsettings{'TIME_FROM'},$fwdfwsettings{'TIME_TO'}" 
                                        eq "$configfwdfw{$key}[0],$configfwdfw{$key}[2],$configfwdfw{$key}[3],$configfwdfw{$key}[4],$configfwdfw{$key}[5],$configfwdfw{$key}[6],$configfwdfw{$key}[7],$configfwdfw{$key}[8],$configfwdfw{$key}[9],$configfwdfw{$key}[10],$configfwdfw{$key}[11],$configfwdfw{$key}[12],$configfwdfw{$key}[13],$configfwdfw{$key}[14],$configfwdfw{$key}[15],$configfwdfw{$key}[17],$configfwdfw{$key}[18],$configfwdfw{$key}[19],$configfwdfw{$key}[20],$configfwdfw{$key}[21],$configfwdfw{$key}[22],$configfwdfw{$key}[23],$configfwdfw{$key}[24],$configfwdfw{$key}[25],$configfwdfw{$key}[26],$configfwdfw{$key}[27]"){
                                                $errormessage.=$Lang::tr{'fwdfw err ruleexists'};
+                                               if ($fwdfwsettings{'oldruleremark'} ne $fwdfwsettings{'ruleremark'} && $fwdfwsettings{'updatefwrule'} eq 'on'){
+                                                       $errormessage='';
+                                               }
+                                               if ($fwdfwsettings{'oldruleremark'} eq $fwdfwsettings{'ruleremark'}){
+                                                       $fwdfwsettings{'nosave'} = 'on';
+                                               }
                                }               
                        }
                }       
+               #check if we just close a rule
+               if( $fwdfwsettings{'oldgrp1a'} eq  $fwdfwsettings{'grp1'} && $fwdfwsettings{'oldgrp1b'} eq $fwdfwsettings{$fwdfwsettings{'grp1'}} && $fwdfwsettings{'oldgrp2a'} eq  $fwdfwsettings{'grp2'} && $fwdfwsettings{'oldgrp2b'} eq $fwdfwsettings{$fwdfwsettings{'grp2'}} &&  $fwdfwsettings{'oldgrp3a'} eq $fwdfwsettings{'grp3'} && $fwdfwsettings{'oldgrp3b'} eq  $fwdfwsettings{$fwdfwsettings{'grp3'}} && $fwdfwsettings{'oldusesrv'} eq $fwdfwsettings{'USESRV'} ) {
+                       if($fwdfwsettings{'nosave'} eq 'on' && $fwdfwsettings{'updatefwrule'} eq 'on'){
+                               $fwdfwsettings{'nosave2'} = 'on';
+                               $errormessage='';
+                       }
+               }
                #increase counters
                &checkcounter($fwdfwsettings{'oldgrp1a'},$fwdfwsettings{'oldgrp1b'},$fwdfwsettings{'grp1'},$fwdfwsettings{$fwdfwsettings{'grp1'}});
                &checkcounter($fwdfwsettings{'oldgrp2a'},$fwdfwsettings{'oldgrp2b'},$fwdfwsettings{'grp2'},$fwdfwsettings{$fwdfwsettings{'grp2'}});
@@ -202,7 +227,9 @@ if ($fwdfwsettings{'ACTION'} eq 'saverule')
                if ($fwdfwsettings{'nobase'} eq 'on'){
                        &checkcounter(0,0,$fwdfwsettings{'grp3'},$fwdfwsettings{$fwdfwsettings{'grp3'}});
                }
-               &saverule(\%configfwdfw,$configfwdfw);
+               if ($fwdfwsettings{'nosave2'} ne 'on'){
+                       &saverule(\%configfwdfw,$configfwdfw);
+               }       
                #print "Source: $fwdfwsettings{'grp1'} -> $fwdfwsettings{$fwdfwsettings{'grp1'}}<br>";
                #print "Sourceport: $fwdfwsettings{'USE_SRC_PORT'}, $fwdfwsettings{'PROT'}, $fwdfwsettings{'ICMP_TYPES'}, $fwdfwsettings{'SRC_PORT'}<br>";
                #print "Target: $fwdfwsettings{'grp2'} -> $fwdfwsettings{$fwdfwsettings{'grp2'}}<br>";
@@ -228,7 +255,9 @@ if ($fwdfwsettings{'ACTION'} eq 'saverule')
        if ($errormessage){
                &newrule;
        }else{
-               &rules;
+               if($fwdfwsettings{'nosave2'} ne 'on'){
+                       &rules;
+               }
                &base;
        }
 }
@@ -491,7 +520,7 @@ sub deleterule
        my %delhash=();
        &General::readhasharray($fwdfwsettings{'config'}, \%delhash);
        foreach my $key (sort {$a <=> $b} keys %delhash){
-               if ($key eq $fwdfwsettings{'key'}){
+               if ($key == $fwdfwsettings{'key'}){
                        #check hosts/net and groups
                        &checkcounter($delhash{$key}[3],$delhash{$key}[4],,);
                        &checkcounter($delhash{$key}[5],$delhash{$key}[6],,);
@@ -500,7 +529,7 @@ sub deleterule
                                &checkcounter($delhash{$key}[14],$delhash{$key}[15],,);
                        }
                }
-               if ($key ge $fwdfwsettings{'key'}) {
+               if ($key >= $fwdfwsettings{'key'}) {
                        my $next = $key + 1;
                        if (exists $delhash{$next}) {
                                foreach my $i (0 .. $#{$delhash{$next}}) {
@@ -595,6 +624,9 @@ sub checksource
                }elsif($fwdfwsettings{'USE_SRC_PORT'} eq 'ON' && $fwdfwsettings{'PROT'} eq 'ESP'){
                        $fwdfwsettings{'SRC_PORT'}='';
                        $fwdfwsettings{'ICMP_TYPES'}='';
+               }elsif($fwdfwsettings{'USE_SRC_PORT'} eq 'ON' && $fwdfwsettings{'PROT'} eq 'AH'){
+                       $fwdfwsettings{'SRC_PORT'}='';
+                       $fwdfwsettings{'ICMP_TYPES'}='';        
                }elsif($fwdfwsettings{'USE_SRC_PORT'} eq 'ON' && $fwdfwsettings{'PROT'} ne 'ICMP'){
                        $fwdfwsettings{'ICMP_TYPES'}='';
                }else{
@@ -691,13 +723,16 @@ sub checktarget
                                        $errormessage .= &General::validportrange($fwdfwsettings{'TGT_PORT'}, 'destination');
                                }
                        }elsif ($fwdfwsettings{'TGT_PROT'} eq 'GRE'){
-                                       $fwdfwsettings{'TGT_PORT'} = '';
+                                       $fwdfwsettings{$fwdfwsettings{'grp3'}} = '';
                                        $fwdfwsettings{'ICMP_TGT'} = '';
                        }elsif($fwdfwsettings{'TGT_PORT'} eq 'ESP'){
-                                       $fwdfwsettings{'TGT_PORT'}='';
+                                       $fwdfwsettings{$fwdfwsettings{'grp3'}} = '';
+                                       $fwdfwsettings{'ICMP_TGT'}='';
+                       }elsif($fwdfwsettings{'TGT_PORT'} eq 'AH'){
+                                       $fwdfwsettings{$fwdfwsettings{'grp3'}} = '';
                                        $fwdfwsettings{'ICMP_TGT'}='';
                        }elsif ($fwdfwsettings{'TGT_PROT'} eq 'ICMP'){
-                               $fwdfwsettings{'TGT_PORT'} = '';
+                               $fwdfwsettings{$fwdfwsettings{'grp3'}} = '';
                                &General::readhasharray("${General::swroot}/fwhosts/icmp-types", \%icmptypes);
                                foreach my $key (keys %icmptypes){
                                        
@@ -931,6 +966,7 @@ sub newrule
                $fwdfwsettings{'oldgrp3a'}=$fwdfwsettings{'grp3'};
                $fwdfwsettings{'oldgrp3b'}=$fwdfwsettings{$fwdfwsettings{'grp3'}};
                $fwdfwsettings{'oldusesrv'}=$fwdfwsettings{'USESRV'};
+               $fwdfwsettings{'oldruleremark'}=$fwdfwsettings{'ruleremark'};
        }else{
                $fwdfwsettings{'ACTIVE'}='ON';
                $checked{'ACTIVE'}{$fwdfwsettings{'ACTIVE'}} = 'CHECKED';
@@ -1058,7 +1094,7 @@ END
                <tr><td width='1%'><input type='checkbox' name='USE_SRC_PORT' value='ON' $checked{'USE_SRC_PORT'}{'ON'}></td><td width='51%' colspan='3'>$Lang::tr{'fwdfw use srcport'}</td>
                <td width='15%' nowrap='nowrap'>$Lang::tr{'fwdfw man port'}</td><td><select name='PROT'>
 END
-               foreach ("TCP","UDP","GRE","ESP","ICMP")
+               foreach ("TCP","UDP","GRE","ESP","AH","ICMP")
                {
                        if ($_ eq $fwdfwsettings{'PROT'})
                        {
@@ -1212,7 +1248,7 @@ END
                </select></td></tr>
                <tr><td colspan='2'></td><td><input type='radio' name='grp3' value='TGT_PORT' $checked{'grp3'}{'TGT_PORT'}></td><td>$Lang::tr{'fwdfw man port'}</td><td><select name='TGT_PROT'>
 END
-               foreach ("TCP","UDP","GRE","ESP","ICMP")
+               foreach ("TCP","UDP","GRE","ESP","AH","ICMP")
                {
                        if ($_ eq $fwdfwsettings{'TGT_PROT'})
                        {
@@ -1378,97 +1414,95 @@ sub saverule
                        $$hash{$key}[27] = $fwdfwsettings{'TIME_TO'};
                        &General::writehasharray("$config", $hash);
                }else{
-                       #ruleposition check
-                       if($fwdfwsettings{'oldrulenumber'} gt $fwdfwsettings{'rulepos'}){
-                               my %tmp=();
-                               my $val=$fwdfwsettings{'oldrulenumber'}-$fwdfwsettings{'rulepos'};
-                               for ($a=0;$a<$val;$a++){
-                                       $fwdfwsettings{'oldrulenumber'}=$fwdfwsettings{'oldrulenumber'}-$a;
-                                       foreach my $key (sort {$a <=> $b} keys %$hash){
-                                               if ($key eq $fwdfwsettings{'oldrulenumber'}) {
-                                                       my $last = $key -1;
-                                                       if (exists $$hash{$last}){
-                                                               #save rule last
-                                                               foreach my $y (0 .. $#{$$hash{$last}}) {
-                                                                       $tmp{0}[$y] = $$hash{$last}[$y];
-                                                               }
-                                                               #copy active rule to last
-                                                               foreach my $i (0 .. $#{$$hash{$last}}) {
-                                                                       $$hash{$last}[$i] = $$hash{$key}[$i];
-                                                               }
-                                                               #copy saved rule to actual position
-                                                               foreach my $x (0 .. $#{$tmp{0}}) {
-                                                                       $$hash{$key}[$x] = $tmp{0}[$x];
-                                                               }
+                       foreach my $key (sort {$a <=> $b} keys %$hash){
+                               if($key eq $fwdfwsettings{'key'}){
+                                       $$hash{$key}[0]  = $fwdfwsettings{'RULE_ACTION'};
+                                       $$hash{$key}[1]  = $fwdfwsettings{'chain'};
+                                       $$hash{$key}[2]  = $fwdfwsettings{'ACTIVE'};
+                                       $$hash{$key}[3]  = $fwdfwsettings{'grp1'};
+                                       $$hash{$key}[4]  = $fwdfwsettings{$fwdfwsettings{'grp1'}};
+                                       $$hash{$key}[5]  = $fwdfwsettings{'grp2'};
+                                       $$hash{$key}[6]  = $fwdfwsettings{$fwdfwsettings{'grp2'}};
+                                       $$hash{$key}[7]  = $fwdfwsettings{'USE_SRC_PORT'};
+                                       $$hash{$key}[8]  = $fwdfwsettings{'PROT'};
+                                       $$hash{$key}[9]  = $fwdfwsettings{'ICMP_TYPES'};
+                                       $$hash{$key}[10] = $fwdfwsettings{'SRC_PORT'};
+                                       $$hash{$key}[11] = $fwdfwsettings{'USESRV'};
+                                       $$hash{$key}[12] = $fwdfwsettings{'TGT_PROT'};
+                                       $$hash{$key}[13] = $fwdfwsettings{'ICMP_TGT'};
+                                       $$hash{$key}[14] = $fwdfwsettings{'grp3'};
+                                       $$hash{$key}[15] = $fwdfwsettings{$fwdfwsettings{'grp3'}};
+                                       $$hash{$key}[16] = $fwdfwsettings{'ruleremark'};
+                                       $$hash{$key}[17] = $fwdfwsettings{'LOG'};
+                                       $$hash{$key}[18] = $fwdfwsettings{'TIME'};
+                                       $$hash{$key}[19] = $fwdfwsettings{'TIME_MON'};
+                                       $$hash{$key}[20] = $fwdfwsettings{'TIME_TUE'};
+                                       $$hash{$key}[21] = $fwdfwsettings{'TIME_WED'};
+                                       $$hash{$key}[22] = $fwdfwsettings{'TIME_THU'};
+                                       $$hash{$key}[23] = $fwdfwsettings{'TIME_FRI'};
+                                       $$hash{$key}[24] = $fwdfwsettings{'TIME_SAT'};
+                                       $$hash{$key}[25] = $fwdfwsettings{'TIME_SUN'};
+                                       $$hash{$key}[26] = $fwdfwsettings{'TIME_FROM'};
+                                       $$hash{$key}[27] = $fwdfwsettings{'TIME_TO'};
+                                       last;
+                               }
+                       }
+               }
+               &General::writehasharray("$config", $hash);
+               if($fwdfwsettings{'oldrulenumber'} gt $fwdfwsettings{'rulepos'}){
+                       my %tmp=();
+                       my $val=$fwdfwsettings{'oldrulenumber'}-$fwdfwsettings{'rulepos'};
+                       for (my $z=0;$z<$val;$z++){
+                               foreach my $key (sort {$a <=> $b} keys %$hash){
+                                       if ($key eq $fwdfwsettings{'oldrulenumber'}) {
+                                               my $last = $key -1;
+                                               if (exists $$hash{$last}){
+                                                       #save rule last
+                                                       foreach my $y (0 .. $#{$$hash{$last}}) {
+                                                               $tmp{0}[$y] = $$hash{$last}[$y];
+                                                       }
+                                                       #copy active rule to last
+                                                       foreach my $i (0 .. $#{$$hash{$last}}) {
+                                                               $$hash{$last}[$i] = $$hash{$key}[$i];
+                                                       }
+                                                       #copy saved rule to actual position
+                                                       foreach my $x (0 .. $#{$tmp{0}}) {
+                                                               $$hash{$key}[$x] = $tmp{0}[$x];
                                                        }
                                                }
                                        }
                                }
-                               &General::writehasharray("$config", $hash);
-                               &rules;
-                       }elsif($fwdfwsettings{'rulepos'} gt $fwdfwsettings{'oldrulenumber'}){
-                               my %tmp=();
-                               my $val=$fwdfwsettings{'rulepos'}-$fwdfwsettings{'oldrulenumber'};
-                               for ($a=0;$a<$val;$a++){
-                                       $fwdfwsettings{'oldrulenumber'}=$fwdfwsettings{'oldrulenumber'}+$a;
+                               $fwdfwsettings{'oldrulenumber'}--;
+                       }
+                       &General::writehasharray("$config", $hash);
+                       &rules;
+               }elsif($fwdfwsettings{'rulepos'} gt $fwdfwsettings{'oldrulenumber'}){
+                       my %tmp=();
+                       my $val=$fwdfwsettings{'rulepos'}-$fwdfwsettings{'oldrulenumber'};
+                               for (my $z=0;$z<$val;$z++){
                                        foreach my $key (sort {$a <=> $b} keys %$hash){
-                                               if ($key eq $fwdfwsettings{'oldrulenumber'}) {
-                                                       my $next = $key + 1;
-                                                       if (exists $$hash{$next}){
-                                                               #save rule next
-                                                               foreach my $y (0 .. $#{$$hash{$next}}) {
-                                                                       $tmp{0}[$y] = $$hash{$next}[$y];
-                                                               }
-                                                               #copy active rule to next
-                                                               foreach my $i (0 .. $#{$$hash{$next}}) {
-                                                                       $$hash{$next}[$i] = $$hash{$key}[$i];
-                                                               }
-                                                               #copy saved rule to actual position
-                                                               foreach my $x (0 .. $#{$tmp{0}}) {
-                                                                       $$hash{$key}[$x] = $tmp{0}[$x];
-                                                               }
+                                       if ($key eq $fwdfwsettings{'oldrulenumber'}) {
+                                               my $next = $key + 1;
+                                               if (exists $$hash{$next}){
+                                                       #save rule next
+                                                       foreach my $y (0 .. $#{$$hash{$next}}) {
+                                                               $tmp{0}[$y] = $$hash{$next}[$y];
+                                                       }
+                                                       #copy active rule to next
+                                                       foreach my $i (0 .. $#{$$hash{$next}}) {
+                                                               $$hash{$next}[$i] = $$hash{$key}[$i];
+                                                       }
+                                                       #copy saved rule to actual position
+                                                       foreach my $x (0 .. $#{$tmp{0}}) {
+                                                               $$hash{$key}[$x] = $tmp{0}[$x];
                                                        }
                                                }
                                        }
                                }
-                               &General::writehasharray("$config", $hash);
-                               &rules;
-                       }else{
-                               foreach my $key (sort {$a <=> $b} keys %$hash){
-                                       if($key eq $fwdfwsettings{'key'}){
-                                               $$hash{$key}[0]  = $fwdfwsettings{'RULE_ACTION'};
-                                               $$hash{$key}[1]  = $fwdfwsettings{'chain'};
-                                               $$hash{$key}[2]  = $fwdfwsettings{'ACTIVE'};
-                                               $$hash{$key}[3]  = $fwdfwsettings{'grp1'};
-                                               $$hash{$key}[4]  = $fwdfwsettings{$fwdfwsettings{'grp1'}};
-                                               $$hash{$key}[5]  = $fwdfwsettings{'grp2'};
-                                               $$hash{$key}[6]  = $fwdfwsettings{$fwdfwsettings{'grp2'}};
-                                               $$hash{$key}[7]  = $fwdfwsettings{'USE_SRC_PORT'};
-                                               $$hash{$key}[8]  = $fwdfwsettings{'PROT'};
-                                               $$hash{$key}[9]  = $fwdfwsettings{'ICMP_TYPES'};
-                                               $$hash{$key}[10] = $fwdfwsettings{'SRC_PORT'};
-                                               $$hash{$key}[11] = $fwdfwsettings{'USESRV'};
-                                               $$hash{$key}[12] = $fwdfwsettings{'TGT_PROT'};
-                                               $$hash{$key}[13] = $fwdfwsettings{'ICMP_TGT'};
-                                               $$hash{$key}[14] = $fwdfwsettings{'grp3'};
-                                               $$hash{$key}[15] = $fwdfwsettings{$fwdfwsettings{'grp3'}};
-                                               $$hash{$key}[16] = $fwdfwsettings{'ruleremark'};
-                                               $$hash{$key}[17] = $fwdfwsettings{'LOG'};
-                                               $$hash{$key}[18] = $fwdfwsettings{'TIME'};
-                                               $$hash{$key}[19] = $fwdfwsettings{'TIME_MON'};
-                                               $$hash{$key}[20] = $fwdfwsettings{'TIME_TUE'};
-                                               $$hash{$key}[21] = $fwdfwsettings{'TIME_WED'};
-                                               $$hash{$key}[22] = $fwdfwsettings{'TIME_THU'};
-                                               $$hash{$key}[23] = $fwdfwsettings{'TIME_FRI'};
-                                               $$hash{$key}[24] = $fwdfwsettings{'TIME_SAT'};
-                                               $$hash{$key}[25] = $fwdfwsettings{'TIME_SUN'};
-                                               $$hash{$key}[26] = $fwdfwsettings{'TIME_FROM'};
-                                               $$hash{$key}[27] = $fwdfwsettings{'TIME_TO'};
-                                               last;
-                                       }
-                               }
+                               $fwdfwsettings{'oldrulenumber'}++;
                        }
                        &General::writehasharray("$config", $hash);
+                       &rules;
                }
        }
 }