1*a71a9546SAutomerger Merge Worker /* Shared library add-on to iptables to add static NAT support.
2*a71a9546SAutomerger Merge Worker Author: Svenning Soerensen <[email protected]>
3*a71a9546SAutomerger Merge Worker */
4*a71a9546SAutomerger Merge Worker #include <stdio.h>
5*a71a9546SAutomerger Merge Worker #include <netdb.h>
6*a71a9546SAutomerger Merge Worker #include <string.h>
7*a71a9546SAutomerger Merge Worker #include <stdlib.h>
8*a71a9546SAutomerger Merge Worker #include <getopt.h>
9*a71a9546SAutomerger Merge Worker #include <xtables.h>
10*a71a9546SAutomerger Merge Worker #include <linux/netfilter/nf_nat.h>
11*a71a9546SAutomerger Merge Worker
12*a71a9546SAutomerger Merge Worker #define MODULENAME "NETMAP"
13*a71a9546SAutomerger Merge Worker
14*a71a9546SAutomerger Merge Worker enum {
15*a71a9546SAutomerger Merge Worker O_TO = 0,
16*a71a9546SAutomerger Merge Worker };
17*a71a9546SAutomerger Merge Worker
18*a71a9546SAutomerger Merge Worker static const struct xt_option_entry NETMAP_opts[] = {
19*a71a9546SAutomerger Merge Worker {.name = "to", .id = O_TO, .type = XTTYPE_HOSTMASK,
20*a71a9546SAutomerger Merge Worker .flags = XTOPT_MAND},
21*a71a9546SAutomerger Merge Worker XTOPT_TABLEEND,
22*a71a9546SAutomerger Merge Worker };
23*a71a9546SAutomerger Merge Worker
NETMAP_help(void)24*a71a9546SAutomerger Merge Worker static void NETMAP_help(void)
25*a71a9546SAutomerger Merge Worker {
26*a71a9546SAutomerger Merge Worker printf(MODULENAME" target options:\n"
27*a71a9546SAutomerger Merge Worker " --%s address[/mask]\n"
28*a71a9546SAutomerger Merge Worker " Network address to map to.\n\n",
29*a71a9546SAutomerger Merge Worker NETMAP_opts[0].name);
30*a71a9546SAutomerger Merge Worker }
31*a71a9546SAutomerger Merge Worker
32*a71a9546SAutomerger Merge Worker static int
netmask2bits(uint32_t netmask)33*a71a9546SAutomerger Merge Worker netmask2bits(uint32_t netmask)
34*a71a9546SAutomerger Merge Worker {
35*a71a9546SAutomerger Merge Worker uint32_t bm;
36*a71a9546SAutomerger Merge Worker int bits;
37*a71a9546SAutomerger Merge Worker
38*a71a9546SAutomerger Merge Worker netmask = ntohl(netmask);
39*a71a9546SAutomerger Merge Worker for (bits = 0, bm = 0x80000000; netmask & bm; netmask <<= 1)
40*a71a9546SAutomerger Merge Worker bits++;
41*a71a9546SAutomerger Merge Worker if (netmask)
42*a71a9546SAutomerger Merge Worker return -1; /* holes in netmask */
43*a71a9546SAutomerger Merge Worker return bits;
44*a71a9546SAutomerger Merge Worker }
45*a71a9546SAutomerger Merge Worker
NETMAP_init(struct xt_entry_target * t)46*a71a9546SAutomerger Merge Worker static void NETMAP_init(struct xt_entry_target *t)
47*a71a9546SAutomerger Merge Worker {
48*a71a9546SAutomerger Merge Worker struct nf_nat_ipv4_multi_range_compat *mr = (struct nf_nat_ipv4_multi_range_compat *)t->data;
49*a71a9546SAutomerger Merge Worker
50*a71a9546SAutomerger Merge Worker /* Actually, it's 0, but it's ignored at the moment. */
51*a71a9546SAutomerger Merge Worker mr->rangesize = 1;
52*a71a9546SAutomerger Merge Worker }
53*a71a9546SAutomerger Merge Worker
NETMAP_parse(struct xt_option_call * cb)54*a71a9546SAutomerger Merge Worker static void NETMAP_parse(struct xt_option_call *cb)
55*a71a9546SAutomerger Merge Worker {
56*a71a9546SAutomerger Merge Worker struct nf_nat_ipv4_multi_range_compat *mr = cb->data;
57*a71a9546SAutomerger Merge Worker struct nf_nat_ipv4_range *range = &mr->range[0];
58*a71a9546SAutomerger Merge Worker
59*a71a9546SAutomerger Merge Worker xtables_option_parse(cb);
60*a71a9546SAutomerger Merge Worker range->flags |= NF_NAT_RANGE_MAP_IPS;
61*a71a9546SAutomerger Merge Worker range->min_ip = cb->val.haddr.ip & cb->val.hmask.ip;
62*a71a9546SAutomerger Merge Worker range->max_ip = range->min_ip | ~cb->val.hmask.ip;
63*a71a9546SAutomerger Merge Worker }
64*a71a9546SAutomerger Merge Worker
__NETMAP_print(const void * ip,const struct xt_entry_target * target,int numeric)65*a71a9546SAutomerger Merge Worker static void __NETMAP_print(const void *ip, const struct xt_entry_target *target,
66*a71a9546SAutomerger Merge Worker int numeric)
67*a71a9546SAutomerger Merge Worker {
68*a71a9546SAutomerger Merge Worker const struct nf_nat_ipv4_multi_range_compat *mr = (const void *)target->data;
69*a71a9546SAutomerger Merge Worker const struct nf_nat_ipv4_range *r = &mr->range[0];
70*a71a9546SAutomerger Merge Worker struct in_addr a;
71*a71a9546SAutomerger Merge Worker int bits;
72*a71a9546SAutomerger Merge Worker
73*a71a9546SAutomerger Merge Worker a.s_addr = r->min_ip;
74*a71a9546SAutomerger Merge Worker printf("%s", xtables_ipaddr_to_numeric(&a));
75*a71a9546SAutomerger Merge Worker a.s_addr = ~(r->min_ip ^ r->max_ip);
76*a71a9546SAutomerger Merge Worker bits = netmask2bits(a.s_addr);
77*a71a9546SAutomerger Merge Worker if (bits < 0)
78*a71a9546SAutomerger Merge Worker printf("/%s", xtables_ipaddr_to_numeric(&a));
79*a71a9546SAutomerger Merge Worker else
80*a71a9546SAutomerger Merge Worker printf("/%d", bits);
81*a71a9546SAutomerger Merge Worker }
82*a71a9546SAutomerger Merge Worker
NETMAP_print(const void * ip,const struct xt_entry_target * target,int numeric)83*a71a9546SAutomerger Merge Worker static void NETMAP_print(const void *ip, const struct xt_entry_target *target,
84*a71a9546SAutomerger Merge Worker int numeric)
85*a71a9546SAutomerger Merge Worker {
86*a71a9546SAutomerger Merge Worker printf(" to:");
87*a71a9546SAutomerger Merge Worker __NETMAP_print(ip, target, numeric);
88*a71a9546SAutomerger Merge Worker }
89*a71a9546SAutomerger Merge Worker
NETMAP_save(const void * ip,const struct xt_entry_target * target)90*a71a9546SAutomerger Merge Worker static void NETMAP_save(const void *ip, const struct xt_entry_target *target)
91*a71a9546SAutomerger Merge Worker {
92*a71a9546SAutomerger Merge Worker printf(" --%s ", NETMAP_opts[0].name);
93*a71a9546SAutomerger Merge Worker __NETMAP_print(ip, target, 0);
94*a71a9546SAutomerger Merge Worker }
95*a71a9546SAutomerger Merge Worker
96*a71a9546SAutomerger Merge Worker static struct xtables_target netmap_tg_reg = {
97*a71a9546SAutomerger Merge Worker .name = MODULENAME,
98*a71a9546SAutomerger Merge Worker .version = XTABLES_VERSION,
99*a71a9546SAutomerger Merge Worker .family = NFPROTO_IPV4,
100*a71a9546SAutomerger Merge Worker .size = XT_ALIGN(sizeof(struct nf_nat_ipv4_multi_range_compat)),
101*a71a9546SAutomerger Merge Worker .userspacesize = XT_ALIGN(sizeof(struct nf_nat_ipv4_multi_range_compat)),
102*a71a9546SAutomerger Merge Worker .help = NETMAP_help,
103*a71a9546SAutomerger Merge Worker .init = NETMAP_init,
104*a71a9546SAutomerger Merge Worker .x6_parse = NETMAP_parse,
105*a71a9546SAutomerger Merge Worker .print = NETMAP_print,
106*a71a9546SAutomerger Merge Worker .save = NETMAP_save,
107*a71a9546SAutomerger Merge Worker .x6_options = NETMAP_opts,
108*a71a9546SAutomerger Merge Worker };
109*a71a9546SAutomerger Merge Worker
_init(void)110*a71a9546SAutomerger Merge Worker void _init(void)
111*a71a9546SAutomerger Merge Worker {
112*a71a9546SAutomerger Merge Worker xtables_register_target(&netmap_tg_reg);
113*a71a9546SAutomerger Merge Worker }
114