stroke: Changed how proto/port are specified in left|rightsubnet
Using a colon as separator conflicts with IPv6 addresses.
This commit is contained in:
+7
-6
@@ -788,7 +788,7 @@ echoed back. Also supported are address pools expressed as
|
|||||||
or the use of an external IP address pool using %\fIpoolname\fR,
|
or the use of an external IP address pool using %\fIpoolname\fR,
|
||||||
where \fIpoolname\fR is the name of the IP address pool used for the lookup.
|
where \fIpoolname\fR is the name of the IP address pool used for the lookup.
|
||||||
.TP
|
.TP
|
||||||
.BR leftsubnet " = <ip subnet>[:<proto/port>][,...]"
|
.BR leftsubnet " = <ip subnet>[[<proto/port>]][,...]"
|
||||||
private subnet behind the left participant, expressed as
|
private subnet behind the left participant, expressed as
|
||||||
\fInetwork\fB/\fInetmask\fR;
|
\fInetwork\fB/\fInetmask\fR;
|
||||||
if omitted, essentially assumed to be \fIleft\fB/32\fR,
|
if omitted, essentially assumed to be \fIleft\fB/32\fR,
|
||||||
@@ -800,15 +800,16 @@ configurations. IKEv2 supports multiple subnets separated by commas. IKEv1 only
|
|||||||
interprets the first subnet of such a definition, unless the Cisco Unity
|
interprets the first subnet of such a definition, unless the Cisco Unity
|
||||||
extension plugin is enabled.
|
extension plugin is enabled.
|
||||||
|
|
||||||
The part in each subnet following an optional colon specifies a protocol/port
|
The optional part after each subnet enclosed in square brackets specifies a
|
||||||
to restrict the selector for that subnet.
|
protocol/port to restrict the selector for that subnet.
|
||||||
|
|
||||||
Example:
|
Examples:
|
||||||
.BR leftsubnet=10.0.0.1:tcp/http,10.0.0.2:6/80,10.0.0.3:udp,10.0.0.0/16:/53 .
|
.BR leftsubnet=10.0.0.1[tcp/http],10.0.0.2[6/80] " or"
|
||||||
|
.BR leftsubnet=fec1::1[udp],10.0.0.0/16[/53] .
|
||||||
Instead of omitting either value
|
Instead of omitting either value
|
||||||
.B %any
|
.B %any
|
||||||
can be used to the same effect, e.g.
|
can be used to the same effect, e.g.
|
||||||
.BR leftsubnet=10.0.0.3:udp/%any,10.0.0.0/16=%any/53 .
|
.BR leftsubnet=fec1::1[udp/%any],10.0.0.0/16[%any/53] .
|
||||||
|
|
||||||
The port value can alternatively take the value
|
The port value can alternatively take the value
|
||||||
.B %opaque
|
.B %opaque
|
||||||
|
|||||||
@@ -895,6 +895,13 @@ static bool parse_protoport(char *token, u_int16_t *from_port,
|
|||||||
struct servent *svc;
|
struct servent *svc;
|
||||||
long int p;
|
long int p;
|
||||||
|
|
||||||
|
sep = strrchr(token, ']');
|
||||||
|
if (!sep)
|
||||||
|
{
|
||||||
|
return FALSE;
|
||||||
|
}
|
||||||
|
*sep = '\0';
|
||||||
|
|
||||||
sep = strchr(token, '/');
|
sep = strchr(token, '/');
|
||||||
if (sep)
|
if (sep)
|
||||||
{ /* protocol/port */
|
{ /* protocol/port */
|
||||||
@@ -1009,7 +1016,7 @@ static void add_ts(private_stroke_config_t *this,
|
|||||||
to_port = end->to_port;
|
to_port = end->to_port;
|
||||||
proto = end->protocol;
|
proto = end->protocol;
|
||||||
|
|
||||||
pos = strchr(subnet, ':');
|
pos = strchr(subnet, '[');
|
||||||
if (pos)
|
if (pos)
|
||||||
{
|
{
|
||||||
*(pos++) = '\0';
|
*(pos++) = '\0';
|
||||||
|
|||||||
Reference in New Issue
Block a user