Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
L
linux
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
0
Issues
0
List
Boards
Labels
Milestones
Merge Requests
0
Merge Requests
0
Analytics
Analytics
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Commits
Issue Boards
Open sidebar
Kirill Smelkov
linux
Commits
115e23ac
Commit
115e23ac
authored
Aug 26, 2012
by
Patrick McHardy
Committed by
Pablo Neira Ayuso
Aug 30, 2012
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
netfilter: ip6tables: add REDIRECT target
Signed-off-by:
Patrick McHardy
<
kaber@trash.net
>
parent
b3f644fc
Changes
3
Hide whitespace changes
Inline
Side-by-side
Showing
3 changed files
with
110 additions
and
0 deletions
+110
-0
net/ipv6/netfilter/Kconfig
net/ipv6/netfilter/Kconfig
+11
-0
net/ipv6/netfilter/Makefile
net/ipv6/netfilter/Makefile
+1
-0
net/ipv6/netfilter/ip6t_REDIRECT.c
net/ipv6/netfilter/ip6t_REDIRECT.c
+98
-0
No files found.
net/ipv6/netfilter/Kconfig
View file @
115e23ac
...
@@ -156,6 +156,17 @@ config IP6_NF_TARGET_MASQUERADE
...
@@ -156,6 +156,17 @@ config IP6_NF_TARGET_MASQUERADE
To compile it as a module, choose M here. If unsure, say N.
To compile it as a module, choose M here. If unsure, say N.
config IP6_NF_TARGET_REDIRECT
tristate "REDIRECT target support"
depends on NF_NAT_IPV6
help
REDIRECT is a special case of NAT: all incoming connections are
mapped onto the incoming interface's address, causing the packets to
come to the local machine instead of passing through. This is
useful for transparent proxies.
To compile it as a module, choose M here. If unsure, say N.
config IP6_NF_FILTER
config IP6_NF_FILTER
tristate "Packet filtering"
tristate "Packet filtering"
default m if NETFILTER_ADVANCED=n
default m if NETFILTER_ADVANCED=n
...
...
net/ipv6/netfilter/Makefile
View file @
115e23ac
...
@@ -35,4 +35,5 @@ obj-$(CONFIG_IP6_NF_MATCH_RT) += ip6t_rt.o
...
@@ -35,4 +35,5 @@ obj-$(CONFIG_IP6_NF_MATCH_RT) += ip6t_rt.o
# targets
# targets
obj-$(CONFIG_IP6_NF_TARGET_MASQUERADE)
+=
ip6t_MASQUERADE.o
obj-$(CONFIG_IP6_NF_TARGET_MASQUERADE)
+=
ip6t_MASQUERADE.o
obj-$(CONFIG_IP6_NF_TARGET_REDIRECT)
+=
ip6t_REDIRECT.o
obj-$(CONFIG_IP6_NF_TARGET_REJECT)
+=
ip6t_REJECT.o
obj-$(CONFIG_IP6_NF_TARGET_REJECT)
+=
ip6t_REJECT.o
net/ipv6/netfilter/ip6t_REDIRECT.c
0 → 100644
View file @
115e23ac
/*
* Copyright (c) 2011 Patrick McHardy <kaber@trash.net>
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License version 2 as
* published by the Free Software Foundation.
*
* Based on Rusty Russell's IPv4 REDIRECT target. Development of IPv6
* NAT funded by Astaro.
*/
#include <linux/kernel.h>
#include <linux/module.h>
#include <linux/netfilter.h>
#include <linux/netfilter_ipv6.h>
#include <linux/netfilter/x_tables.h>
#include <net/addrconf.h>
#include <net/netfilter/nf_nat.h>
static
const
struct
in6_addr
loopback_addr
=
IN6ADDR_LOOPBACK_INIT
;
static
unsigned
int
redirect_tg6
(
struct
sk_buff
*
skb
,
const
struct
xt_action_param
*
par
)
{
const
struct
nf_nat_range
*
range
=
par
->
targinfo
;
struct
nf_nat_range
newrange
;
struct
in6_addr
newdst
;
enum
ip_conntrack_info
ctinfo
;
struct
nf_conn
*
ct
;
ct
=
nf_ct_get
(
skb
,
&
ctinfo
);
if
(
par
->
hooknum
==
NF_INET_LOCAL_OUT
)
newdst
=
loopback_addr
;
else
{
struct
inet6_dev
*
idev
;
struct
inet6_ifaddr
*
ifa
;
bool
addr
=
false
;
rcu_read_lock
();
idev
=
__in6_dev_get
(
skb
->
dev
);
if
(
idev
!=
NULL
)
{
list_for_each_entry
(
ifa
,
&
idev
->
addr_list
,
if_list
)
{
newdst
=
ifa
->
addr
;
addr
=
true
;
break
;
}
}
rcu_read_unlock
();
if
(
!
addr
)
return
NF_DROP
;
}
newrange
.
flags
=
range
->
flags
|
NF_NAT_RANGE_MAP_IPS
;
newrange
.
min_addr
.
in6
=
newdst
;
newrange
.
max_addr
.
in6
=
newdst
;
newrange
.
min_proto
=
range
->
min_proto
;
newrange
.
max_proto
=
range
->
max_proto
;
return
nf_nat_setup_info
(
ct
,
&
newrange
,
NF_NAT_MANIP_DST
);
}
static
int
redirect_tg6_checkentry
(
const
struct
xt_tgchk_param
*
par
)
{
const
struct
nf_nat_range
*
range
=
par
->
targinfo
;
if
(
range
->
flags
&
NF_NAT_RANGE_MAP_IPS
)
return
-
EINVAL
;
return
0
;
}
static
struct
xt_target
redirect_tg6_reg
__read_mostly
=
{
.
name
=
"REDIRECT"
,
.
family
=
NFPROTO_IPV6
,
.
checkentry
=
redirect_tg6_checkentry
,
.
target
=
redirect_tg6
,
.
targetsize
=
sizeof
(
struct
nf_nat_range
),
.
table
=
"nat"
,
.
hooks
=
(
1
<<
NF_INET_PRE_ROUTING
)
|
(
1
<<
NF_INET_LOCAL_OUT
),
.
me
=
THIS_MODULE
,
};
static
int
__init
redirect_tg6_init
(
void
)
{
return
xt_register_target
(
&
redirect_tg6_reg
);
}
static
void
__exit
redirect_tg6_exit
(
void
)
{
xt_unregister_target
(
&
redirect_tg6_reg
);
}
module_init
(
redirect_tg6_init
);
module_exit
(
redirect_tg6_exit
);
MODULE_LICENSE
(
"GPL"
);
MODULE_AUTHOR
(
"Patrick McHardy <kaber@trash.net>"
);
MODULE_DESCRIPTION
(
"Xtables: Connection redirection to localhost"
);
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment