updown: Properly configure ICMP[v6] message type and code in firewall rules
This commit is contained in:
+29
-4
@@ -290,16 +290,41 @@ else
|
|||||||
IPSEC_POLICY_OUT="$IPSEC_POLICY --dir out"
|
IPSEC_POLICY_OUT="$IPSEC_POLICY --dir out"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# use protocol specific options to set ports
|
||||||
|
case "$PLUTO_MY_PROTOCOL" in
|
||||||
|
1) # ICMP
|
||||||
|
ICMP_TYPE_OPTION="--icmp-type"
|
||||||
|
;;
|
||||||
|
58) # ICMPv6
|
||||||
|
ICMP_TYPE_OPTION="--icmpv6-type"
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
|
||||||
# are there port numbers?
|
# are there port numbers?
|
||||||
if [ "$PLUTO_MY_PORT" != 0 ]
|
if [ "$PLUTO_MY_PORT" != 0 ]
|
||||||
then
|
then
|
||||||
S_MY_PORT="--sport $PLUTO_MY_PORT"
|
if [ -n "$ICMP_TYPE_OPTION" ]
|
||||||
D_MY_PORT="--dport $PLUTO_MY_PORT"
|
then
|
||||||
|
S_MY_PORT="$ICMP_TYPE_OPTION $PLUTO_MY_PORT"
|
||||||
|
D_MY_PORT="$ICMP_TYPE_OPTION $PLUTO_MY_PORT"
|
||||||
|
else
|
||||||
|
S_MY_PORT="--sport $PLUTO_MY_PORT"
|
||||||
|
D_MY_PORT="--dport $PLUTO_MY_PORT"
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
if [ "$PLUTO_PEER_PORT" != 0 ]
|
if [ "$PLUTO_PEER_PORT" != 0 ]
|
||||||
then
|
then
|
||||||
S_PEER_PORT="--sport $PLUTO_PEER_PORT"
|
if [ -n "$ICMP_TYPE_OPTION" ]
|
||||||
D_PEER_PORT="--dport $PLUTO_PEER_PORT"
|
then
|
||||||
|
# the syntax is --icmp[v6]-type type[/code], so add it to the existing option
|
||||||
|
S_MY_PORT="$S_MY_PORT/$PLUTO_PEER_PORT"
|
||||||
|
D_MY_PORT="$D_MY_PORT/$PLUTO_PEER_PORT"
|
||||||
|
else
|
||||||
|
S_PEER_PORT="--sport $PLUTO_PEER_PORT"
|
||||||
|
D_PEER_PORT="--dport $PLUTO_PEER_PORT"
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# resolve octal escape sequences
|
# resolve octal escape sequences
|
||||||
|
|||||||
Reference in New Issue
Block a user