1 Testing that a source NAT rewrite range is accepted for proto icmp, where it 2 maps the ICMP identifier rather than a port. MAP-E portsets rely on this to 3 keep translated identifiers within the assigned port set (RFC 7597), with 4 one nat spec per proto in icmp/tcp/udp published by map.sh through the 5 per-interface ubus data.firewall array, and firewall3 accepted the same. 6 An ipv6-icmp rewrite implies the IPv6 family, and port match options still 7 require a UDP or TCP protocol. 8 9 -- Testcase -- 10 {% 11 include("./root/usr/share/firewall4/main.uc", { 12 getenv: function(varname) { 13 switch (varname) { 14 case 'ACTION': 15 return 'print'; 16 } 17 } 18 }) 19 %} 20 -- End -- 21 22 -- File uci/helpers.json -- 23 {} 24 -- End -- 25 26 -- File fs/open~_sys_class_net_br-lan_flags.txt -- 27 0x1103 28 -- End -- 29 30 -- File fs/open~_sys_class_net_eth1_flags.txt -- 31 0x1103 32 -- End -- 33 34 -- File fs/open~_sys_class_net_map-wan_4_flags.txt -- 35 0x1103 36 -- End -- 37 38 -- File ubus/network.interface~dump.json -- 39 { 40 "interface": [ 41 { 42 "interface": "lan", 43 "up": true, 44 "l3_device": "br-lan", 45 "proto": "static", 46 "device": "br-lan", 47 "ipv4-address": [ { "address": "192.168.1.1", "mask": 24 } ], 48 "data": {} 49 }, 50 { 51 "interface": "wan", 52 "up": true, 53 "l3_device": "eth1", 54 "proto": "dhcp", 55 "device": "eth1", 56 "ipv4-address": [ { "address": "10.11.12.194", "mask": 24 } ], 57 "data": {} 58 }, 59 { 60 "interface": "wan_4", 61 "up": true, 62 "l3_device": "map-wan_4", 63 "proto": "map", 64 "device": "map-wan_4", 65 "data": { 66 "zone": "wan", 67 "firewall": [ 68 { 69 "type": "nat", 70 "target": "SNAT", 71 "family": "inet", 72 "proto": "icmp", 73 "connlimit_ports": true, 74 "snat_ip": "192.0.2.66", 75 "snat_port": "2048-2079" 76 }, 77 { 78 "type": "nat", 79 "target": "SNAT", 80 "family": "inet", 81 "proto": "tcp", 82 "connlimit_ports": true, 83 "snat_ip": "192.0.2.66", 84 "snat_port": "2048-2079" 85 }, 86 { 87 "type": "nat", 88 "target": "SNAT", 89 "family": "inet", 90 "proto": "udp", 91 "connlimit_ports": true, 92 "snat_ip": "192.0.2.66", 93 "snat_port": "2048-2079" 94 } 95 ] 96 } 97 } 98 ] 99 } 100 -- End -- 101 102 -- File uci/firewall.json -- 103 { 104 "defaults": [ 105 { 106 "input": "ACCEPT", 107 "output": "ACCEPT", 108 "forward": "REJECT" 109 } 110 ], 111 "zone": [ 112 { 113 "name": "lan", 114 "input": "ACCEPT", 115 "output": "ACCEPT", 116 "forward": "ACCEPT", 117 "network": "lan" 118 }, 119 { 120 "name": "wan", 121 "input": "REJECT", 122 "output": "ACCEPT", 123 "forward": "REJECT", 124 "network": "wan" 125 } 126 ], 127 "nat": [ 128 { 129 "name": "ICMP id range", 130 "src": "wan", 131 "proto": "icmp", 132 "target": "SNAT", 133 "snat_ip": "192.0.2.67", 134 "snat_port": "4096-4127" 135 }, 136 { 137 "name": "ICMPv6 id range", 138 "src": "wan", 139 "proto": "icmpv6", 140 "target": "SNAT", 141 "snat_ip": "2001:db8::1", 142 "snat_port": "4096-4127" 143 }, 144 { 145 "name": "ICMP port match", 146 "src": "wan", 147 "proto": "icmp", 148 "target": "SNAT", 149 "snat_ip": "192.0.2.68", 150 "src_port": "1024-2047" 151 } 152 ] 153 } 154 -- End -- 155 156 -- Expect stderr -- 157 [!] Section @nat[2] (ICMP port match) specifies ports but no UDP/TCP protocol, ignoring section 158 -- End -- 159 160 -- Expect stdout -- 161 table inet fw4 162 flush table inet fw4 163 164 table inet fw4 { 165 # 166 # Defines 167 # 168 169 define lan_devices = { "br-lan" } 170 define lan_subnets = { 192.168.1.0/24 } 171 172 define wan_devices = { "eth1", "map-wan_4" } 173 define wan_subnets = { 10.11.12.0/24 } 174 175 176 # 177 # User includes 178 # 179 180 include "/etc/nftables.d/*.nft" 181 182 183 # 184 # Filter rules 185 # 186 187 chain input { 188 type filter hook input priority filter; policy accept; 189 190 iif "lo" accept comment "!fw4: Accept traffic from loopback" 191 192 ct state vmap { established : accept, related : accept } comment "!fw4: Handle inbound flows" 193 iifname "br-lan" jump input_lan comment "!fw4: Handle lan IPv4/IPv6 input traffic" 194 iifname { "eth1", "map-wan_4" } jump input_wan comment "!fw4: Handle wan IPv4/IPv6 input traffic" 195 } 196 197 chain forward { 198 type filter hook forward priority filter; policy drop; 199 200 ct state vmap { established : accept, related : accept } comment "!fw4: Handle forwarded flows" 201 iifname "br-lan" jump forward_lan comment "!fw4: Handle lan IPv4/IPv6 forward traffic" 202 iifname { "eth1", "map-wan_4" } jump forward_wan comment "!fw4: Handle wan IPv4/IPv6 forward traffic" 203 jump handle_reject 204 } 205 206 chain output { 207 type filter hook output priority filter; policy accept; 208 209 oif "lo" accept comment "!fw4: Accept traffic towards loopback" 210 211 ct state vmap { established : accept, related : accept } comment "!fw4: Handle outbound flows" 212 oifname "br-lan" jump output_lan comment "!fw4: Handle lan IPv4/IPv6 output traffic" 213 oifname { "eth1", "map-wan_4" } jump output_wan comment "!fw4: Handle wan IPv4/IPv6 output traffic" 214 } 215 216 chain prerouting { 217 type filter hook prerouting priority filter; policy accept; 218 iifname "br-lan" jump helper_lan comment "!fw4: Handle lan IPv4/IPv6 helper assignment" 219 iifname { "eth1", "map-wan_4" } jump helper_wan comment "!fw4: Handle wan IPv4/IPv6 helper assignment" 220 } 221 222 chain handle_reject { 223 meta l4proto tcp reject with tcp reset comment "!fw4: Reject TCP traffic" 224 reject with icmpx type port-unreachable comment "!fw4: Reject any other traffic" 225 } 226 227 chain input_lan { 228 jump accept_from_lan 229 } 230 231 chain output_lan { 232 jump accept_to_lan 233 } 234 235 chain forward_lan { 236 jump accept_to_lan 237 } 238 239 chain helper_lan { 240 } 241 242 chain accept_from_lan { 243 iifname "br-lan" counter accept comment "!fw4: accept lan IPv4/IPv6 traffic" 244 } 245 246 chain accept_to_lan { 247 oifname "br-lan" counter accept comment "!fw4: accept lan IPv4/IPv6 traffic" 248 } 249 250 chain input_wan { 251 jump reject_from_wan 252 } 253 254 chain output_wan { 255 jump accept_to_wan 256 } 257 258 chain forward_wan { 259 jump reject_to_wan 260 } 261 262 chain helper_wan { 263 } 264 265 chain accept_to_wan { 266 oifname { "eth1", "map-wan_4" } counter accept comment "!fw4: accept wan IPv4/IPv6 traffic" 267 } 268 269 chain reject_from_wan { 270 iifname { "eth1", "map-wan_4" } counter jump handle_reject comment "!fw4: reject wan IPv4/IPv6 traffic" 271 } 272 273 chain reject_to_wan { 274 oifname { "eth1", "map-wan_4" } counter jump handle_reject comment "!fw4: reject wan IPv4/IPv6 traffic" 275 } 276 277 278 # 279 # NAT rules 280 # 281 282 chain dstnat { 283 type nat hook prerouting priority dstnat; policy accept; 284 } 285 286 chain srcnat { 287 type nat hook postrouting priority srcnat; policy accept; 288 meta nfproto ipv4 meta l4proto icmp oifname "map-wan_4" counter snat 192.0.2.66:2048-2079 comment "!fw4: ubus:wan_4[map] nat 0" 289 meta nfproto ipv4 meta l4proto tcp oifname "map-wan_4" counter snat 192.0.2.66:2048-2079 comment "!fw4: ubus:wan_4[map] nat 1" 290 meta nfproto ipv4 meta l4proto udp oifname "map-wan_4" counter snat 192.0.2.66:2048-2079 comment "!fw4: ubus:wan_4[map] nat 2" 291 oifname { "eth1", "map-wan_4" } jump srcnat_wan comment "!fw4: Handle wan IPv4/IPv6 srcnat traffic" 292 } 293 294 chain srcnat_wan { 295 meta nfproto ipv4 meta l4proto icmp counter snat 192.0.2.67:4096-4127 comment "!fw4: ICMP id range" 296 meta nfproto ipv6 meta l4proto ipv6-icmp counter snat [2001:db8::1]:4096-4127 comment "!fw4: ICMPv6 id range" 297 } 298 299 300 # 301 # Raw rules (notrack) 302 # 303 304 chain raw_prerouting { 305 type filter hook prerouting priority raw; policy accept; 306 } 307 308 chain raw_output { 309 type filter hook output priority raw; policy accept; 310 } 311 312 313 # 314 # Mangle rules 315 # 316 317 chain mangle_prerouting { 318 type filter hook prerouting priority mangle; policy accept; 319 } 320 321 chain mangle_postrouting { 322 type filter hook postrouting priority mangle; policy accept; 323 } 324 325 chain mangle_input { 326 type filter hook input priority mangle; policy accept; 327 } 328 329 chain mangle_output { 330 type route hook output priority mangle; policy accept; 331 } 332 333 chain mangle_forward { 334 type filter hook forward priority mangle; policy accept; 335 } 336 } 337 -- End --
This page was automatically generated by LXR 0.3.1. • OpenWrt