stroke: Changed how proto/port are specified in left|rightsubnet

Using a colon as separator conflicts with IPv6 addresses.
This commit is contained in:
Tobias Brunner
2013-06-28 15:10:09 +02:00
parent b18a531715
commit b7b5432ff8
2 changed files with 15 additions and 7 deletions
+7 -6
View File
@@ -788,7 +788,7 @@ echoed back. Also supported are address pools expressed as
or the use of an external IP address pool using %\fIpoolname\fR, or the use of an external IP address pool using %\fIpoolname\fR,
where \fIpoolname\fR is the name of the IP address pool used for the lookup. where \fIpoolname\fR is the name of the IP address pool used for the lookup.
.TP .TP
.BR leftsubnet " = <ip subnet>[:<proto/port>][,...]" .BR leftsubnet " = <ip subnet>[[<proto/port>]][,...]"
private subnet behind the left participant, expressed as private subnet behind the left participant, expressed as
\fInetwork\fB/\fInetmask\fR; \fInetwork\fB/\fInetmask\fR;
if omitted, essentially assumed to be \fIleft\fB/32\fR, if omitted, essentially assumed to be \fIleft\fB/32\fR,
@@ -800,15 +800,16 @@ configurations. IKEv2 supports multiple subnets separated by commas. IKEv1 only
interprets the first subnet of such a definition, unless the Cisco Unity interprets the first subnet of such a definition, unless the Cisco Unity
extension plugin is enabled. extension plugin is enabled.
The part in each subnet following an optional colon specifies a protocol/port The optional part after each subnet enclosed in square brackets specifies a
to restrict the selector for that subnet. protocol/port to restrict the selector for that subnet.
Example: Examples:
.BR leftsubnet=10.0.0.1:tcp/http,10.0.0.2:6/80,10.0.0.3:udp,10.0.0.0/16:/53 . .BR leftsubnet=10.0.0.1[tcp/http],10.0.0.2[6/80] " or"
.BR leftsubnet=fec1::1[udp],10.0.0.0/16[/53] .
Instead of omitting either value Instead of omitting either value
.B %any .B %any
can be used to the same effect, e.g. can be used to the same effect, e.g.
.BR leftsubnet=10.0.0.3:udp/%any,10.0.0.0/16=%any/53 . .BR leftsubnet=fec1::1[udp/%any],10.0.0.0/16[%any/53] .
The port value can alternatively take the value The port value can alternatively take the value
.B %opaque .B %opaque
+8 -1
View File
@@ -895,6 +895,13 @@ static bool parse_protoport(char *token, u_int16_t *from_port,
struct servent *svc; struct servent *svc;
long int p; long int p;
sep = strrchr(token, ']');
if (!sep)
{
return FALSE;
}
*sep = '\0';
sep = strchr(token, '/'); sep = strchr(token, '/');
if (sep) if (sep)
{ /* protocol/port */ { /* protocol/port */
@@ -1009,7 +1016,7 @@ static void add_ts(private_stroke_config_t *this,
to_port = end->to_port; to_port = end->to_port;
proto = end->protocol; proto = end->protocol;
pos = strchr(subnet, ':'); pos = strchr(subnet, '[');
if (pos) if (pos)
{ {
*(pos++) = '\0'; *(pos++) = '\0';