[package] firewall: allow redirecting only destination port (#7197)
authorjow <jow@3c298f89-4303-0410-b956-a3cf2f4a3e73>
Fri, 16 Jul 2010 06:03:15 +0000 (06:03 +0000)
committerjow <jow@3c298f89-4303-0410-b956-a3cf2f4a3e73>
Fri, 16 Jul 2010 06:03:15 +0000 (06:03 +0000)
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@22227 3c298f89-4303-0410-b956-a3cf2f4a3e73

package/firewall/Makefile
package/firewall/files/lib/core_redirect.sh

index b1969d9..c1f3f6e 100644 (file)
@@ -9,7 +9,7 @@ include $(TOPDIR)/rules.mk
 PKG_NAME:=firewall
 
 PKG_VERSION:=2
-PKG_RELEASE:=7
+PKG_RELEASE:=8
 
 include $(INCLUDE_DIR)/package.mk
 
index b51f793..15d01b0 100644 (file)
@@ -26,8 +26,8 @@ fw_load_redirect() {
 
        fw_callback pre redirect
 
-       [ -n "$redirect_src" -a -n "$redirect_dest_ip" ] || {
-               fw_die "redirect ${redirect_name}: needs src and dest_ip"
+       [ -n "$redirect_src" -a -n "$redirect_dest_ip$redirect_dest_port" ] || {
+               fw_die "redirect ${redirect_name}: needs src and dest_ip or dest_port"
        }
 
        list_contains FW_CONNTRACK_ZONES $redirect_src || \
@@ -53,6 +53,7 @@ fw_load_redirect() {
                        --to-destination ${redirect_dest_ip}${redirect_dest_port:+:$nat_dest_port} \
                }
 
+               [ -n "$redirect_dest_ip" ] && \
                fw add $mode f zone_${redirect_src}_forward ACCEPT ^ { $redirect_src_ip $redirect_dest_ip } { \
                        -d $redirect_dest_ip \
                        ${redirect_proto:+-p $redirect_proto} \