Only run includes and set sysctls if either v4 or v6 firewall was actually started
[project/firewall3.git] / redirects.c
index 51c764f..23dc034 100644 (file)
 
 
 const struct fw3_option fw3_redirect_opts[] = {
-       FW3_OPT("name",                string,   redirect,     name),
-       FW3_OPT("family",              family,   redirect,     family),
+       FW3_OPT("enabled",             bool,      redirect,     enabled),
 
-       FW3_OPT("src",                 device,   redirect,     src),
-       FW3_OPT("dest",                device,   redirect,     dest),
+       FW3_OPT("name",                string,    redirect,     name),
+       FW3_OPT("family",              family,    redirect,     family),
 
-       FW3_OPT("ipset",               device,   redirect,     ipset),
+       FW3_OPT("src",                 device,    redirect,     src),
+       FW3_OPT("dest",                device,    redirect,     dest),
 
-       FW3_LIST("proto",              protocol, redirect,     proto),
+       FW3_OPT("ipset",               device,    redirect,     ipset),
 
-       FW3_OPT("src_ip",              address,  redirect,     ip_src),
-       FW3_LIST("src_mac",            mac,      redirect,     mac_src),
-       FW3_OPT("src_port",            port,     redirect,     port_src),
+       FW3_LIST("proto",              protocol,  redirect,     proto),
 
-       FW3_OPT("src_dip",             address,  redirect,     ip_dest),
-       FW3_OPT("src_dport",           port,     redirect,     port_dest),
+       FW3_OPT("src_ip",              address,   redirect,     ip_src),
+       FW3_LIST("src_mac",            mac,       redirect,     mac_src),
+       FW3_OPT("src_port",            port,      redirect,     port_src),
 
-       FW3_OPT("dest_ip",             address,  redirect,     ip_redir),
-       FW3_OPT("dest_port",           port,     redirect,     port_redir),
+       FW3_OPT("src_dip",             address,   redirect,     ip_dest),
+       FW3_OPT("src_dport",           port,      redirect,     port_dest),
 
-       FW3_OPT("extra",               string,   redirect,     extra),
+       FW3_OPT("dest_ip",             address,   redirect,     ip_redir),
+       FW3_OPT("dest_port",           port,      redirect,     port_redir),
 
-       FW3_OPT("reflection",          bool,     redirect,     reflection),
+       FW3_OPT("extra",               string,    redirect,     extra),
 
-       FW3_OPT("target",              target,   redirect,     target),
+       FW3_OPT("utc_time",            bool,      redirect,     time.utc),
+       FW3_OPT("start_date",          date,      redirect,     time.datestart),
+       FW3_OPT("stop_date",           date,      redirect,     time.datestop),
+       FW3_OPT("start_time",          time,      redirect,     time.timestart),
+       FW3_OPT("stop_time",           time,      redirect,     time.timestop),
+       FW3_OPT("weekdays",            weekdays,  redirect,     time.weekdays),
+       FW3_OPT("monthdays",           monthdays, redirect,     time.monthdays),
+
+       FW3_OPT("reflection",          bool,      redirect,     reflection),
+
+       FW3_OPT("target",              target,    redirect,     target),
 
        { }
 };
@@ -123,10 +133,17 @@ fw3_load_redirects(struct fw3_state *state, struct uci_package *p)
                INIT_LIST_HEAD(&redir->proto);
                INIT_LIST_HEAD(&redir->mac_src);
 
+               redir->enabled = true;
                redir->reflection = true;
 
                fw3_parse_options(redir, fw3_redirect_opts, s);
 
+               if (!redir->enabled)
+               {
+                       fw3_free_redirect(redir);
+                       continue;
+               }
+
                if (redir->src.invert)
                {
                        warn_elem(e, "must not have an inverted source");
@@ -186,16 +203,16 @@ fw3_load_redirects(struct fw3_state *state, struct uci_package *p)
                                warn_elem(e, "has no source specified");
                        else
                        {
-                               setbit(redir->_src->dst_flags, redir->target);
+                               setbit(redir->_src->flags, redir->target);
                                redir->_src->conntrack = true;
                                valid = true;
                        }
 
                        if (redir->reflection && redir->_dest && redir->_src->masq)
                        {
-                               setbit(redir->_dest->dst_flags, FW3_TARGET_ACCEPT);
-                               setbit(redir->_dest->dst_flags, FW3_TARGET_DNAT);
-                               setbit(redir->_dest->dst_flags, FW3_TARGET_SNAT);
+                               setbit(redir->_dest->flags, FW3_TARGET_ACCEPT);
+                               setbit(redir->_dest->flags, FW3_TARGET_DNAT);
+                               setbit(redir->_dest->flags, FW3_TARGET_SNAT);
                        }
                }
                else
@@ -208,7 +225,7 @@ fw3_load_redirects(struct fw3_state *state, struct uci_package *p)
                                warn_elem(e, "has no src_dip option specified");
                        else
                        {
-                               setbit(redir->_dest->dst_flags, redir->target);
+                               setbit(redir->_dest->flags, redir->target);
                                redir->_dest->conntrack = true;
                                valid = true;
                        }
@@ -364,6 +381,7 @@ print_redirect(enum fw3_table table, enum fw3_family family,
                        }
 
                        fw3_format_mac(mac);
+                       fw3_format_time(&redir->time);
                        fw3_format_extra(redir->extra);
                        fw3_format_comment(redir->name);
                        print_target_nat(redir);
@@ -376,6 +394,7 @@ print_redirect(enum fw3_table table, enum fw3_family family,
                        fw3_format_src_dest(&redir->ip_src, &redir->ip_redir);
                        fw3_format_sport_dport(&redir->port_src, &redir->port_redir);
                        fw3_format_mac(mac);
+                       fw3_format_time(&redir->time);
                        fw3_format_extra(redir->extra);
                        fw3_format_comment(redir->name);
                        print_target_filter(redir);
@@ -422,6 +441,7 @@ print_redirect(enum fw3_table table, enum fw3_family family,
                                        fw3_format_protocol(proto, family);
                                        fw3_format_src_dest(int_addr, ext_addr);
                                        fw3_format_sport_dport(NULL, &redir->port_dest);
+                                       fw3_format_time(&redir->time);
                                        fw3_format_comment(redir->name, " (reflection)");
                                        print_snat_dnat(FW3_TARGET_DNAT,
                                                        &redir->ip_redir, &redir->port_redir);
@@ -430,6 +450,7 @@ print_redirect(enum fw3_table table, enum fw3_family family,
                                        fw3_format_protocol(proto, family);
                                        fw3_format_src_dest(int_addr, &redir->ip_redir);
                                        fw3_format_sport_dport(NULL, &redir->port_redir);
+                                       fw3_format_time(&redir->time);
                                        fw3_format_comment(redir->name, " (reflection)");
                                        print_snat_dnat(FW3_TARGET_SNAT, ext_addr, NULL);
                                }
@@ -439,6 +460,7 @@ print_redirect(enum fw3_table table, enum fw3_family family,
                                        fw3_format_protocol(proto, family);
                                        fw3_format_src_dest(int_addr, &redir->ip_redir);
                                        fw3_format_sport_dport(NULL, &redir->port_redir);
+                                       fw3_format_time(&redir->time);
                                        fw3_format_comment(redir->name, " (reflection)");
                                        fw3_pr(" -j zone_%s_dest_ACCEPT\n", redir->dest.name);
                                }