• source navigation  • diff markup  • identifier search  • freetext search  • 

Sources/firewall4/tests/03_rules/15_snat_icmp_range

  1 Testing that a source NAT rewrite range is accepted for proto icmp, where it
  2 maps the ICMP identifier rather than a port. MAP-E portsets rely on this to
  3 keep translated identifiers within the assigned port set (RFC 7597), with
  4 one nat spec per proto in icmp/tcp/udp published by map.sh through the
  5 per-interface ubus data.firewall array, and firewall3 accepted the same.
  6 An ipv6-icmp rewrite implies the IPv6 family, and port match options still
  7 require a UDP or TCP protocol.
  8 
  9 -- Testcase --
 10 {%
 11         include("./root/usr/share/firewall4/main.uc", {
 12                 getenv: function(varname) {
 13                         switch (varname) {
 14                         case 'ACTION':
 15                                 return 'print';
 16                         }
 17                 }
 18         })
 19 %}
 20 -- End --
 21 
 22 -- File uci/helpers.json --
 23 {}
 24 -- End --
 25 
 26 -- File fs/open~_sys_class_net_br-lan_flags.txt --
 27 0x1103
 28 -- End --
 29 
 30 -- File fs/open~_sys_class_net_eth1_flags.txt --
 31 0x1103
 32 -- End --
 33 
 34 -- File fs/open~_sys_class_net_map-wan_4_flags.txt --
 35 0x1103
 36 -- End --
 37 
 38 -- File ubus/network.interface~dump.json --
 39 {
 40         "interface": [
 41                 {
 42                         "interface": "lan",
 43                         "up": true,
 44                         "l3_device": "br-lan",
 45                         "proto": "static",
 46                         "device": "br-lan",
 47                         "ipv4-address": [ { "address": "192.168.1.1", "mask": 24 } ],
 48                         "data": {}
 49                 },
 50                 {
 51                         "interface": "wan",
 52                         "up": true,
 53                         "l3_device": "eth1",
 54                         "proto": "dhcp",
 55                         "device": "eth1",
 56                         "ipv4-address": [ { "address": "10.11.12.194", "mask": 24 } ],
 57                         "data": {}
 58                 },
 59                 {
 60                         "interface": "wan_4",
 61                         "up": true,
 62                         "l3_device": "map-wan_4",
 63                         "proto": "map",
 64                         "device": "map-wan_4",
 65                         "data": {
 66                                 "zone": "wan",
 67                                 "firewall": [
 68                                         {
 69                                                 "type": "nat",
 70                                                 "target": "SNAT",
 71                                                 "family": "inet",
 72                                                 "proto": "icmp",
 73                                                 "connlimit_ports": true,
 74                                                 "snat_ip": "192.0.2.66",
 75                                                 "snat_port": "2048-2079"
 76                                         },
 77                                         {
 78                                                 "type": "nat",
 79                                                 "target": "SNAT",
 80                                                 "family": "inet",
 81                                                 "proto": "tcp",
 82                                                 "connlimit_ports": true,
 83                                                 "snat_ip": "192.0.2.66",
 84                                                 "snat_port": "2048-2079"
 85                                         },
 86                                         {
 87                                                 "type": "nat",
 88                                                 "target": "SNAT",
 89                                                 "family": "inet",
 90                                                 "proto": "udp",
 91                                                 "connlimit_ports": true,
 92                                                 "snat_ip": "192.0.2.66",
 93                                                 "snat_port": "2048-2079"
 94                                         }
 95                                 ]
 96                         }
 97                 }
 98         ]
 99 }
100 -- End --
101 
102 -- File uci/firewall.json --
103 {
104         "defaults": [
105                 {
106                         "input": "ACCEPT",
107                         "output": "ACCEPT",
108                         "forward": "REJECT"
109                 }
110         ],
111         "zone": [
112                 {
113                         "name": "lan",
114                         "input": "ACCEPT",
115                         "output": "ACCEPT",
116                         "forward": "ACCEPT",
117                         "network": "lan"
118                 },
119                 {
120                         "name": "wan",
121                         "input": "REJECT",
122                         "output": "ACCEPT",
123                         "forward": "REJECT",
124                         "network": "wan"
125                 }
126         ],
127         "nat": [
128                 {
129                         "name": "ICMP id range",
130                         "src": "wan",
131                         "proto": "icmp",
132                         "target": "SNAT",
133                         "snat_ip": "192.0.2.67",
134                         "snat_port": "4096-4127"
135                 },
136                 {
137                         "name": "ICMPv6 id range",
138                         "src": "wan",
139                         "proto": "icmpv6",
140                         "target": "SNAT",
141                         "snat_ip": "2001:db8::1",
142                         "snat_port": "4096-4127"
143                 },
144                 {
145                         "name": "ICMP port match",
146                         "src": "wan",
147                         "proto": "icmp",
148                         "target": "SNAT",
149                         "snat_ip": "192.0.2.68",
150                         "src_port": "1024-2047"
151                 }
152         ]
153 }
154 -- End --
155 
156 -- Expect stderr --
157 [!] Section @nat[2] (ICMP port match) specifies ports but no UDP/TCP protocol, ignoring section
158 -- End --
159 
160 -- Expect stdout --
161 table inet fw4
162 flush table inet fw4
163 
164 table inet fw4 {
165         #
166         # Defines
167         #
168 
169         define lan_devices = { "br-lan" }
170         define lan_subnets = { 192.168.1.0/24 }
171 
172         define wan_devices = { "eth1", "map-wan_4" }
173         define wan_subnets = { 10.11.12.0/24 }
174 
175 
176         #
177         # User includes
178         #
179 
180         include "/etc/nftables.d/*.nft"
181 
182 
183         #
184         # Filter rules
185         #
186 
187         chain input {
188                 type filter hook input priority filter; policy accept;
189 
190                 iif "lo" accept comment "!fw4: Accept traffic from loopback"
191 
192                 ct state vmap { established : accept, related : accept } comment "!fw4: Handle inbound flows"
193                 iifname "br-lan" jump input_lan comment "!fw4: Handle lan IPv4/IPv6 input traffic"
194                 iifname { "eth1", "map-wan_4" } jump input_wan comment "!fw4: Handle wan IPv4/IPv6 input traffic"
195         }
196 
197         chain forward {
198                 type filter hook forward priority filter; policy drop;
199 
200                 ct state vmap { established : accept, related : accept } comment "!fw4: Handle forwarded flows"
201                 iifname "br-lan" jump forward_lan comment "!fw4: Handle lan IPv4/IPv6 forward traffic"
202                 iifname { "eth1", "map-wan_4" } jump forward_wan comment "!fw4: Handle wan IPv4/IPv6 forward traffic"
203                 jump handle_reject
204         }
205 
206         chain output {
207                 type filter hook output priority filter; policy accept;
208 
209                 oif "lo" accept comment "!fw4: Accept traffic towards loopback"
210 
211                 ct state vmap { established : accept, related : accept } comment "!fw4: Handle outbound flows"
212                 oifname "br-lan" jump output_lan comment "!fw4: Handle lan IPv4/IPv6 output traffic"
213                 oifname { "eth1", "map-wan_4" } jump output_wan comment "!fw4: Handle wan IPv4/IPv6 output traffic"
214         }
215 
216         chain prerouting {
217                 type filter hook prerouting priority filter; policy accept;
218                 iifname "br-lan" jump helper_lan comment "!fw4: Handle lan IPv4/IPv6 helper assignment"
219                 iifname { "eth1", "map-wan_4" } jump helper_wan comment "!fw4: Handle wan IPv4/IPv6 helper assignment"
220         }
221 
222         chain handle_reject {
223                 meta l4proto tcp reject with tcp reset comment "!fw4: Reject TCP traffic"
224                 reject with icmpx type port-unreachable comment "!fw4: Reject any other traffic"
225         }
226 
227         chain input_lan {
228                 jump accept_from_lan
229         }
230 
231         chain output_lan {
232                 jump accept_to_lan
233         }
234 
235         chain forward_lan {
236                 jump accept_to_lan
237         }
238 
239         chain helper_lan {
240         }
241 
242         chain accept_from_lan {
243                 iifname "br-lan" counter accept comment "!fw4: accept lan IPv4/IPv6 traffic"
244         }
245 
246         chain accept_to_lan {
247                 oifname "br-lan" counter accept comment "!fw4: accept lan IPv4/IPv6 traffic"
248         }
249 
250         chain input_wan {
251                 jump reject_from_wan
252         }
253 
254         chain output_wan {
255                 jump accept_to_wan
256         }
257 
258         chain forward_wan {
259                 jump reject_to_wan
260         }
261 
262         chain helper_wan {
263         }
264 
265         chain accept_to_wan {
266                 oifname { "eth1", "map-wan_4" } counter accept comment "!fw4: accept wan IPv4/IPv6 traffic"
267         }
268 
269         chain reject_from_wan {
270                 iifname { "eth1", "map-wan_4" } counter jump handle_reject comment "!fw4: reject wan IPv4/IPv6 traffic"
271         }
272 
273         chain reject_to_wan {
274                 oifname { "eth1", "map-wan_4" } counter jump handle_reject comment "!fw4: reject wan IPv4/IPv6 traffic"
275         }
276 
277 
278         #
279         # NAT rules
280         #
281 
282         chain dstnat {
283                 type nat hook prerouting priority dstnat; policy accept;
284         }
285 
286         chain srcnat {
287                 type nat hook postrouting priority srcnat; policy accept;
288                 meta nfproto ipv4 meta l4proto icmp oifname "map-wan_4" counter snat 192.0.2.66:2048-2079 comment "!fw4: ubus:wan_4[map] nat 0"
289                 meta nfproto ipv4 meta l4proto tcp oifname "map-wan_4" counter snat 192.0.2.66:2048-2079 comment "!fw4: ubus:wan_4[map] nat 1"
290                 meta nfproto ipv4 meta l4proto udp oifname "map-wan_4" counter snat 192.0.2.66:2048-2079 comment "!fw4: ubus:wan_4[map] nat 2"
291                 oifname { "eth1", "map-wan_4" } jump srcnat_wan comment "!fw4: Handle wan IPv4/IPv6 srcnat traffic"
292         }
293 
294         chain srcnat_wan {
295                 meta nfproto ipv4 meta l4proto icmp counter snat 192.0.2.67:4096-4127 comment "!fw4: ICMP id range"
296                 meta nfproto ipv6 meta l4proto ipv6-icmp counter snat [2001:db8::1]:4096-4127 comment "!fw4: ICMPv6 id range"
297         }
298 
299 
300         #
301         # Raw rules (notrack)
302         #
303 
304         chain raw_prerouting {
305                 type filter hook prerouting priority raw; policy accept;
306         }
307 
308         chain raw_output {
309                 type filter hook output priority raw; policy accept;
310         }
311 
312 
313         #
314         # Mangle rules
315         #
316 
317         chain mangle_prerouting {
318                 type filter hook prerouting priority mangle; policy accept;
319         }
320 
321         chain mangle_postrouting {
322                 type filter hook postrouting priority mangle; policy accept;
323         }
324 
325         chain mangle_input {
326                 type filter hook input priority mangle; policy accept;
327         }
328 
329         chain mangle_output {
330                 type route hook output priority mangle; policy accept;
331         }
332 
333         chain mangle_forward {
334                 type filter hook forward priority mangle; policy accept;
335         }
336 }
337 -- End --

This page was automatically generated by LXR 0.3.1.  •  OpenWrt