263 lines
28 KiB
HTML
263 lines
28 KiB
HTML
|
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "https://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
|
||
|
<html xmlns="http://www.w3.org/1999/xhtml">
|
||
|
<head>
|
||
|
<meta http-equiv="Content-Type" content="text/xhtml;charset=UTF-8"/>
|
||
|
<meta http-equiv="X-UA-Compatible" content="IE=11"/>
|
||
|
<meta name="generator" content="Doxygen 1.9.4"/>
|
||
|
<meta name="viewport" content="width=device-width, initial-scale=1"/>
|
||
|
<title>ESP32/ESP8266 Firewall: src/Firewall.cpp Source File</title>
|
||
|
<link href="tabs.css" rel="stylesheet" type="text/css"/>
|
||
|
<script type="text/javascript" src="jquery.js"></script>
|
||
|
<script type="text/javascript" src="dynsections.js"></script>
|
||
|
<link href="search/search.css" rel="stylesheet" type="text/css"/>
|
||
|
<script type="text/javascript" src="search/searchdata.js"></script>
|
||
|
<script type="text/javascript" src="search/search.js"></script>
|
||
|
<link href="doxygen.css" rel="stylesheet" type="text/css" />
|
||
|
</head>
|
||
|
<body>
|
||
|
<div id="top"><!-- do not remove this div, it is closed by doxygen! -->
|
||
|
<div id="titlearea">
|
||
|
<table cellspacing="0" cellpadding="0">
|
||
|
<tbody>
|
||
|
<tr id="projectrow">
|
||
|
<td id="projectalign">
|
||
|
<div id="projectname">ESP32/ESP8266 Firewall<span id="projectnumber"> 1.0.0</span>
|
||
|
</div>
|
||
|
<div id="projectbrief">a software firewall for ESP23 or ESP8266</div>
|
||
|
</td>
|
||
|
</tr>
|
||
|
</tbody>
|
||
|
</table>
|
||
|
</div>
|
||
|
<!-- end header part -->
|
||
|
<!-- Generated by Doxygen 1.9.4 -->
|
||
|
<script type="text/javascript">
|
||
|
/* @license magnet:?xt=urn:btih:d3d9a9a6595521f9666a5e94cc830dab83b65699&dn=expat.txt MIT */
|
||
|
var searchBox = new SearchBox("searchBox", "search",'Search','.html');
|
||
|
/* @license-end */
|
||
|
</script>
|
||
|
<script type="text/javascript" src="menudata.js"></script>
|
||
|
<script type="text/javascript" src="menu.js"></script>
|
||
|
<script type="text/javascript">
|
||
|
/* @license magnet:?xt=urn:btih:d3d9a9a6595521f9666a5e94cc830dab83b65699&dn=expat.txt MIT */
|
||
|
$(function() {
|
||
|
initMenu('',true,false,'search.php','Search');
|
||
|
$(document).ready(function() { init_search(); });
|
||
|
});
|
||
|
/* @license-end */
|
||
|
</script>
|
||
|
<div id="main-nav"></div>
|
||
|
<!-- window showing the filter options -->
|
||
|
<div id="MSearchSelectWindow"
|
||
|
onmouseover="return searchBox.OnSearchSelectShow()"
|
||
|
onmouseout="return searchBox.OnSearchSelectHide()"
|
||
|
onkeydown="return searchBox.OnSearchSelectKey(event)">
|
||
|
</div>
|
||
|
|
||
|
<!-- iframe showing the search results (closed by default) -->
|
||
|
<div id="MSearchResultsWindow">
|
||
|
<iframe src="javascript:void(0)" frameborder="0"
|
||
|
name="MSearchResults" id="MSearchResults">
|
||
|
</iframe>
|
||
|
</div>
|
||
|
|
||
|
<div id="nav-path" class="navpath">
|
||
|
<ul>
|
||
|
<li class="navelem"><a class="el" href="dir_68267d1309a1af8e8297ef4c3efbcdba.html">src</a></li> </ul>
|
||
|
</div>
|
||
|
</div><!-- top -->
|
||
|
<div class="header">
|
||
|
<div class="headertitle"><div class="title">Firewall.cpp</div></div>
|
||
|
</div><!--header-->
|
||
|
<div class="contents">
|
||
|
<div class="fragment"><div class="line"><a id="l00001" name="l00001"></a><span class="lineno"> 1</span><span class="preprocessor">#include "Firewall.hpp"</span></div>
|
||
|
<div class="line"><a id="l00002" name="l00002"></a><span class="lineno"> 2</span> </div>
|
||
|
<div class="line"><a id="l00003" name="l00003"></a><span class="lineno"> 3</span><span class="keyword">namespace </span>fw</div>
|
||
|
<div class="line"><a id="l00004" name="l00004"></a><span class="lineno"> 4</span>{</div>
|
||
|
<div class="line"><a id="l00005" name="l00005"></a><span class="lineno"> 5</span> Firewall::Firewall()</div>
|
||
|
<div class="line"><a id="l00006" name="l00006"></a><span class="lineno"> 6</span> {</div>
|
||
|
<div class="line"><a id="l00007" name="l00007"></a><span class="lineno"> 7</span> this->amount_of_rules = retrieve_amount_of_rules();</div>
|
||
|
<div class="line"><a id="l00008" name="l00008"></a><span class="lineno"> 8</span> <span class="keywordflow">for</span> (uint8_t i = 1; i <= this->amount_of_rules; i++)</div>
|
||
|
<div class="line"><a id="l00009" name="l00009"></a><span class="lineno"> 9</span> {</div>
|
||
|
<div class="line"><a id="l00010" name="l00010"></a><span class="lineno"> 10</span> firewall_rule_t *rule_ptr = retrieve_firewall_rule(i);</div>
|
||
|
<div class="line"><a id="l00011" name="l00011"></a><span class="lineno"> 11</span> this->add_rule_to_firewall(rule_ptr, <span class="keyword">false</span>);</div>
|
||
|
<div class="line"><a id="l00012" name="l00012"></a><span class="lineno"> 12</span> }</div>
|
||
|
<div class="line"><a id="l00013" name="l00013"></a><span class="lineno"> 13</span> }</div>
|
||
|
<div class="line"><a id="l00014" name="l00014"></a><span class="lineno"> 14</span> </div>
|
||
|
<div class="line"><a id="l00015" name="l00015"></a><span class="lineno"> 15</span> Firewall::~Firewall()</div>
|
||
|
<div class="line"><a id="l00016" name="l00016"></a><span class="lineno"> 16</span> {</div>
|
||
|
<div class="line"><a id="l00017" name="l00017"></a><span class="lineno"> 17</span> }</div>
|
||
|
<div class="line"><a id="l00018" name="l00018"></a><span class="lineno"> 18</span> </div>
|
||
|
<div class="line"><a id="l00019" name="l00019"></a><span class="lineno"> 19</span> firewall_rule_t *Firewall::get_rule_head()</div>
|
||
|
<div class="line"><a id="l00020" name="l00020"></a><span class="lineno"> 20</span> {</div>
|
||
|
<div class="line"><a id="l00021" name="l00021"></a><span class="lineno"> 21</span> <span class="keywordflow">return</span> this->rule_head;</div>
|
||
|
<div class="line"><a id="l00022" name="l00022"></a><span class="lineno"> 22</span> }</div>
|
||
|
<div class="line"><a id="l00023" name="l00023"></a><span class="lineno"> 23</span> </div>
|
||
|
<div class="line"><a id="l00024" name="l00024"></a><span class="lineno"> 24</span> <span class="keywordtype">void</span> Firewall::add_rule_to_firewall(firewall_rule_t *rule_ptr, <span class="keyword">const</span> <span class="keywordtype">bool</span> save_in_eeprom)</div>
|
||
|
<div class="line"><a id="l00025" name="l00025"></a><span class="lineno"> 25</span> {</div>
|
||
|
<div class="line"><a id="l00026" name="l00026"></a><span class="lineno"> 26</span> store_amount_of_rules(this->amount_of_rules);</div>
|
||
|
<div class="line"><a id="l00027" name="l00027"></a><span class="lineno"> 27</span> <span class="keywordflow">if</span> (save_in_eeprom)</div>
|
||
|
<div class="line"><a id="l00028" name="l00028"></a><span class="lineno"> 28</span> Storage::store_firewall_rule(rule_ptr);</div>
|
||
|
<div class="line"><a id="l00029" name="l00029"></a><span class="lineno"> 29</span> <span class="keywordflow">if</span> (this->rule_head == NULL)</div>
|
||
|
<div class="line"><a id="l00030" name="l00030"></a><span class="lineno"> 30</span> {</div>
|
||
|
<div class="line"><a id="l00031" name="l00031"></a><span class="lineno"> 31</span> this->rule_head = rule_ptr;</div>
|
||
|
<div class="line"><a id="l00032" name="l00032"></a><span class="lineno"> 32</span> rule_ptr->next = NULL;</div>
|
||
|
<div class="line"><a id="l00033" name="l00033"></a><span class="lineno"> 33</span> <span class="keywordflow">return</span>;</div>
|
||
|
<div class="line"><a id="l00034" name="l00034"></a><span class="lineno"> 34</span> }</div>
|
||
|
<div class="line"><a id="l00035" name="l00035"></a><span class="lineno"> 35</span> firewall_rule_t *current_rule;</div>
|
||
|
<div class="line"><a id="l00036" name="l00036"></a><span class="lineno"> 36</span> current_rule = this->rule_head;</div>
|
||
|
<div class="line"><a id="l00037" name="l00037"></a><span class="lineno"> 37</span> <span class="keywordflow">while</span> (current_rule->next != NULL)</div>
|
||
|
<div class="line"><a id="l00038" name="l00038"></a><span class="lineno"> 38</span> current_rule = current_rule->next;</div>
|
||
|
<div class="line"><a id="l00039" name="l00039"></a><span class="lineno"> 39</span> current_rule->next = rule_ptr;</div>
|
||
|
<div class="line"><a id="l00040" name="l00040"></a><span class="lineno"> 40</span> rule_ptr->next = NULL;</div>
|
||
|
<div class="line"><a id="l00041" name="l00041"></a><span class="lineno"> 41</span> }</div>
|
||
|
<div class="line"><a id="l00042" name="l00042"></a><span class="lineno"> 42</span> </div>
|
||
|
<div class="line"><a id="l00043" name="l00043"></a><span class="lineno"> 43</span> firewall_rule_t *Firewall::add_rule_to_firewall(String *args)</div>
|
||
|
<div class="line"><a id="l00044" name="l00044"></a><span class="lineno"> 44</span> {</div>
|
||
|
<div class="line"><a id="l00045" name="l00045"></a><span class="lineno"> 45</span> firewall_rule_t *rule_ptr = (firewall_rule_t *)malloc(<span class="keyword">sizeof</span>(firewall_rule_t));</div>
|
||
|
<div class="line"><a id="l00046" name="l00046"></a><span class="lineno"> 46</span> rule_ptr->key = ++this->amount_of_rules;</div>
|
||
|
<div class="line"><a id="l00047" name="l00047"></a><span class="lineno"> 47</span> </div>
|
||
|
<div class="line"><a id="l00048" name="l00048"></a><span class="lineno"> 48</span> strncpy(rule_ptr->ip, args[IP].c_str(), <span class="keyword">sizeof</span>(rule_ptr->ip));</div>
|
||
|
<div class="line"><a id="l00049" name="l00049"></a><span class="lineno"> 49</span> rule_ptr->port_from = args[PORT_FROM].toInt();</div>
|
||
|
<div class="line"><a id="l00050" name="l00050"></a><span class="lineno"> 50</span> rule_ptr->port_to = args[PORT_TO].toInt();</div>
|
||
|
<div class="line"><a id="l00051" name="l00051"></a><span class="lineno"> 51</span> rule_ptr->protocol = string_to_protocol(args[PROTOCOL]);</div>
|
||
|
<div class="line"><a id="l00052" name="l00052"></a><span class="lineno"> 52</span> rule_ptr->target = string_to_target(args[TARGET]);</div>
|
||
|
<div class="line"><a id="l00053" name="l00053"></a><span class="lineno"> 53</span> </div>
|
||
|
<div class="line"><a id="l00054" name="l00054"></a><span class="lineno"> 54</span> add_rule_to_firewall(rule_ptr);</div>
|
||
|
<div class="line"><a id="l00055" name="l00055"></a><span class="lineno"> 55</span> <span class="keywordflow">return</span> rule_ptr;</div>
|
||
|
<div class="line"><a id="l00056" name="l00056"></a><span class="lineno"> 56</span> }</div>
|
||
|
<div class="line"><a id="l00057" name="l00057"></a><span class="lineno"> 57</span> </div>
|
||
|
<div class="line"><a id="l00058" name="l00058"></a><span class="lineno"> 58</span> firewall_rule_t *Firewall::update_rule_of_firewall(String *args, <span class="keyword">const</span> uint8_t key)</div>
|
||
|
<div class="line"><a id="l00059" name="l00059"></a><span class="lineno"> 59</span> {</div>
|
||
|
<div class="line"><a id="l00060" name="l00060"></a><span class="lineno"> 60</span> firewall_rule_t *rule_ptr = get_rule_from_firewall(key);</div>
|
||
|
<div class="line"><a id="l00061" name="l00061"></a><span class="lineno"> 61</span> <span class="keywordflow">if</span> (rule_ptr == NULL)</div>
|
||
|
<div class="line"><a id="l00062" name="l00062"></a><span class="lineno"> 62</span> <span class="keywordflow">return</span> rule_ptr;</div>
|
||
|
<div class="line"><a id="l00063" name="l00063"></a><span class="lineno"> 63</span> strncpy(rule_ptr->ip, args[IP].c_str(), <span class="keyword">sizeof</span>(rule_ptr->ip));</div>
|
||
|
<div class="line"><a id="l00064" name="l00064"></a><span class="lineno"> 64</span> rule_ptr->port_from = args[PORT_FROM].toInt();</div>
|
||
|
<div class="line"><a id="l00065" name="l00065"></a><span class="lineno"> 65</span> rule_ptr->port_to = args[PORT_TO].toInt();</div>
|
||
|
<div class="line"><a id="l00066" name="l00066"></a><span class="lineno"> 66</span> rule_ptr->protocol = string_to_protocol(args[PROTOCOL]);</div>
|
||
|
<div class="line"><a id="l00067" name="l00067"></a><span class="lineno"> 67</span> rule_ptr->target = string_to_target(args[TARGET]);</div>
|
||
|
<div class="line"><a id="l00068" name="l00068"></a><span class="lineno"> 68</span> </div>
|
||
|
<div class="line"><a id="l00069" name="l00069"></a><span class="lineno"> 69</span> Storage::store_firewall_rule(rule_ptr);</div>
|
||
|
<div class="line"><a id="l00070" name="l00070"></a><span class="lineno"> 70</span> <span class="keywordflow">return</span> rule_ptr;</div>
|
||
|
<div class="line"><a id="l00071" name="l00071"></a><span class="lineno"> 71</span> }</div>
|
||
|
<div class="line"><a id="l00072" name="l00072"></a><span class="lineno"> 72</span> </div>
|
||
|
<div class="line"><a id="l00073" name="l00073"></a><span class="lineno"> 73</span> firewall_rule_t *Firewall::get_rule_from_firewall(<span class="keyword">const</span> uint8_t key)</div>
|
||
|
<div class="line"><a id="l00074" name="l00074"></a><span class="lineno"> 74</span> {</div>
|
||
|
<div class="line"><a id="l00075" name="l00075"></a><span class="lineno"> 75</span> firewall_rule_t *rule_ptr = this->rule_head;</div>
|
||
|
<div class="line"><a id="l00076" name="l00076"></a><span class="lineno"> 76</span> <span class="keywordflow">if</span> (this->rule_head == NULL)</div>
|
||
|
<div class="line"><a id="l00077" name="l00077"></a><span class="lineno"> 77</span> <span class="keywordflow">return</span> NULL;</div>
|
||
|
<div class="line"><a id="l00078" name="l00078"></a><span class="lineno"> 78</span> <span class="keywordflow">while</span> (rule_ptr->key != key)</div>
|
||
|
<div class="line"><a id="l00079" name="l00079"></a><span class="lineno"> 79</span> {</div>
|
||
|
<div class="line"><a id="l00080" name="l00080"></a><span class="lineno"> 80</span> <span class="keywordflow">if</span> (rule_ptr->next == NULL)</div>
|
||
|
<div class="line"><a id="l00081" name="l00081"></a><span class="lineno"> 81</span> <span class="keywordflow">return</span> NULL;</div>
|
||
|
<div class="line"><a id="l00082" name="l00082"></a><span class="lineno"> 82</span> <span class="keywordflow">else</span></div>
|
||
|
<div class="line"><a id="l00083" name="l00083"></a><span class="lineno"> 83</span> rule_ptr = rule_ptr->next;</div>
|
||
|
<div class="line"><a id="l00084" name="l00084"></a><span class="lineno"> 84</span> }</div>
|
||
|
<div class="line"><a id="l00085" name="l00085"></a><span class="lineno"> 85</span> <span class="keywordflow">return</span> rule_ptr;</div>
|
||
|
<div class="line"><a id="l00086" name="l00086"></a><span class="lineno"> 86</span> }</div>
|
||
|
<div class="line"><a id="l00087" name="l00087"></a><span class="lineno"> 87</span> </div>
|
||
|
<div class="line"><a id="l00088" name="l00088"></a><span class="lineno"> 88</span> ok_t Firewall::delete_rule_from_firewall(<span class="keyword">const</span> uint8_t key)</div>
|
||
|
<div class="line"><a id="l00089" name="l00089"></a><span class="lineno"> 89</span> {</div>
|
||
|
<div class="line"><a id="l00090" name="l00090"></a><span class="lineno"> 90</span> <span class="keywordflow">if</span> (this->rule_head == NULL)</div>
|
||
|
<div class="line"><a id="l00091" name="l00091"></a><span class="lineno"> 91</span> <span class="keywordflow">return</span> NO_ACTION;</div>
|
||
|
<div class="line"><a id="l00092" name="l00092"></a><span class="lineno"> 92</span> firewall_rule_t *current_rule = this->rule_head;</div>
|
||
|
<div class="line"><a id="l00093" name="l00093"></a><span class="lineno"> 93</span> firewall_rule_t *previous_rule = NULL;</div>
|
||
|
<div class="line"><a id="l00094" name="l00094"></a><span class="lineno"> 94</span> firewall_rule_t *temp = NULL;</div>
|
||
|
<div class="line"><a id="l00095" name="l00095"></a><span class="lineno"> 95</span> <span class="keywordflow">while</span> (current_rule->key != key)</div>
|
||
|
<div class="line"><a id="l00096" name="l00096"></a><span class="lineno"> 96</span> {</div>
|
||
|
<div class="line"><a id="l00097" name="l00097"></a><span class="lineno"> 97</span> <span class="keywordflow">if</span> (current_rule->next == NULL)</div>
|
||
|
<div class="line"><a id="l00098" name="l00098"></a><span class="lineno"> 98</span> <span class="keywordflow">return</span> NO_ACTION;</div>
|
||
|
<div class="line"><a id="l00099" name="l00099"></a><span class="lineno"> 99</span> <span class="keywordflow">else</span></div>
|
||
|
<div class="line"><a id="l00100" name="l00100"></a><span class="lineno"> 100</span> {</div>
|
||
|
<div class="line"><a id="l00101" name="l00101"></a><span class="lineno"> 101</span> previous_rule = current_rule;</div>
|
||
|
<div class="line"><a id="l00102" name="l00102"></a><span class="lineno"> 102</span> current_rule = current_rule->next;</div>
|
||
|
<div class="line"><a id="l00103" name="l00103"></a><span class="lineno"> 103</span> }</div>
|
||
|
<div class="line"><a id="l00104" name="l00104"></a><span class="lineno"> 104</span> }</div>
|
||
|
<div class="line"><a id="l00105" name="l00105"></a><span class="lineno"> 105</span> <span class="keywordflow">if</span> (current_rule == this->rule_head)</div>
|
||
|
<div class="line"><a id="l00106" name="l00106"></a><span class="lineno"> 106</span> {</div>
|
||
|
<div class="line"><a id="l00107" name="l00107"></a><span class="lineno"> 107</span> this->rule_head = rule_head->next;</div>
|
||
|
<div class="line"><a id="l00108" name="l00108"></a><span class="lineno"> 108</span> temp = this->rule_head;</div>
|
||
|
<div class="line"><a id="l00109" name="l00109"></a><span class="lineno"> 109</span> }</div>
|
||
|
<div class="line"><a id="l00110" name="l00110"></a><span class="lineno"> 110</span> <span class="keywordflow">else</span></div>
|
||
|
<div class="line"><a id="l00111" name="l00111"></a><span class="lineno"> 111</span> {</div>
|
||
|
<div class="line"><a id="l00112" name="l00112"></a><span class="lineno"> 112</span> previous_rule->next = current_rule->next;</div>
|
||
|
<div class="line"><a id="l00113" name="l00113"></a><span class="lineno"> 113</span> temp = previous_rule->next;</div>
|
||
|
<div class="line"><a id="l00114" name="l00114"></a><span class="lineno"> 114</span> }</div>
|
||
|
<div class="line"><a id="l00115" name="l00115"></a><span class="lineno"> 115</span> <span class="keywordflow">while</span> (temp != NULL)</div>
|
||
|
<div class="line"><a id="l00116" name="l00116"></a><span class="lineno"> 116</span> {</div>
|
||
|
<div class="line"><a id="l00117" name="l00117"></a><span class="lineno"> 117</span> temp->key--;</div>
|
||
|
<div class="line"><a id="l00118" name="l00118"></a><span class="lineno"> 118</span> temp = temp->next;</div>
|
||
|
<div class="line"><a id="l00119" name="l00119"></a><span class="lineno"> 119</span> }</div>
|
||
|
<div class="line"><a id="l00120" name="l00120"></a><span class="lineno"> 120</span> free(current_rule);</div>
|
||
|
<div class="line"><a id="l00121" name="l00121"></a><span class="lineno"> 121</span> this->amount_of_rules--;</div>
|
||
|
<div class="line"><a id="l00122" name="l00122"></a><span class="lineno"> 122</span> Storage::store_amount_of_rules(this->amount_of_rules);</div>
|
||
|
<div class="line"><a id="l00123" name="l00123"></a><span class="lineno"> 123</span> <span class="keywordflow">if</span> (this->amount_of_rules != 0)</div>
|
||
|
<div class="line"><a id="l00124" name="l00124"></a><span class="lineno"> 124</span> Storage::store_all_firewall_rules(rule_head);</div>
|
||
|
<div class="line"><a id="l00125" name="l00125"></a><span class="lineno"> 125</span> <span class="keywordflow">return</span> SUCCESS;</div>
|
||
|
<div class="line"><a id="l00126" name="l00126"></a><span class="lineno"> 126</span> }</div>
|
||
|
<div class="line"><a id="l00127" name="l00127"></a><span class="lineno"> 127</span> </div>
|
||
|
<div class="line"><a id="l00128" name="l00128"></a><span class="lineno"> 128</span> my_packet_t *Firewall::get_packet_information(<span class="keyword">struct</span> pbuf *pbuf)</div>
|
||
|
<div class="line"><a id="l00129" name="l00129"></a><span class="lineno"> 129</span> {</div>
|
||
|
<div class="line"><a id="l00130" name="l00130"></a><span class="lineno"> 130</span> my_packet_t *packet = (my_packet_t *)malloc(<span class="keyword">sizeof</span>(my_packet_t));</div>
|
||
|
<div class="line"><a id="l00131" name="l00131"></a><span class="lineno"> 131</span> <span class="keyword">const</span> <span class="keyword">struct </span>ip_hdr *iphdr = (<span class="keyword">struct </span>ip_hdr *)pbuf->payload;</div>
|
||
|
<div class="line"><a id="l00132" name="l00132"></a><span class="lineno"> 132</span> u16_t iphdr_hlen = IPH_HL_BYTES(iphdr);</div>
|
||
|
<div class="line"><a id="l00133" name="l00133"></a><span class="lineno"> 133</span> </div>
|
||
|
<div class="line"><a id="l00134" name="l00134"></a><span class="lineno"> 134</span> packet->protocol = (firewall_protocol_t)IPH_PROTO(iphdr);</div>
|
||
|
<div class="line"><a id="l00135" name="l00135"></a><span class="lineno"> 135</span> sprintf(packet->ip, <span class="stringliteral">"%d.%d.%d.%d"</span>, ip4_addr1_16_val(iphdr->src), ip4_addr2_16_val(iphdr->src), ip4_addr3_16_val(iphdr->src), ip4_addr4_16_val(iphdr->src));</div>
|
||
|
<div class="line"><a id="l00136" name="l00136"></a><span class="lineno"> 136</span> </div>
|
||
|
<div class="line"><a id="l00137" name="l00137"></a><span class="lineno"> 137</span> <span class="keywordflow">if</span> (packet->protocol == PROTOCOL_UDP)</div>
|
||
|
<div class="line"><a id="l00138" name="l00138"></a><span class="lineno"> 138</span> {</div>
|
||
|
<div class="line"><a id="l00139" name="l00139"></a><span class="lineno"> 139</span> <span class="keyword">const</span> <span class="keyword">struct </span>udp_hdr *udphdr = (<span class="keyword">const</span> <span class="keyword">struct </span>udp_hdr *)((<span class="keyword">const</span> u8_t *)iphdr + iphdr_hlen);</div>
|
||
|
<div class="line"><a id="l00140" name="l00140"></a><span class="lineno"> 140</span> packet->port = lwip_ntohs(udphdr->dest);</div>
|
||
|
<div class="line"><a id="l00141" name="l00141"></a><span class="lineno"> 141</span> }</div>
|
||
|
<div class="line"><a id="l00142" name="l00142"></a><span class="lineno"> 142</span> <span class="keywordflow">else</span> <span class="keywordflow">if</span> (packet->protocol == PROTOCOL_TCP)</div>
|
||
|
<div class="line"><a id="l00143" name="l00143"></a><span class="lineno"> 143</span> {</div>
|
||
|
<div class="line"><a id="l00144" name="l00144"></a><span class="lineno"> 144</span> <span class="keyword">const</span> <span class="keyword">struct </span>tcp_hdr *tcphdr = (<span class="keyword">const</span> <span class="keyword">struct </span>tcp_hdr *)((<span class="keyword">const</span> u8_t *)iphdr + iphdr_hlen);</div>
|
||
|
<div class="line"><a id="l00145" name="l00145"></a><span class="lineno"> 145</span> packet->port = lwip_ntohs(tcphdr->dest);</div>
|
||
|
<div class="line"><a id="l00146" name="l00146"></a><span class="lineno"> 146</span> }</div>
|
||
|
<div class="line"><a id="l00147" name="l00147"></a><span class="lineno"> 147</span> </div>
|
||
|
<div class="line"><a id="l00148" name="l00148"></a><span class="lineno"> 148</span> <span class="keywordflow">return</span> packet;</div>
|
||
|
<div class="line"><a id="l00149" name="l00149"></a><span class="lineno"> 149</span> }</div>
|
||
|
<div class="line"><a id="l00150" name="l00150"></a><span class="lineno"> 150</span> </div>
|
||
|
<div class="line"><a id="l00151" name="l00151"></a><span class="lineno"> 151</span> <span class="keywordtype">bool</span> Firewall::rule_allows_packet(firewall_rule_t *rule_ptr, my_packet_t *packet)</div>
|
||
|
<div class="line"><a id="l00152" name="l00152"></a><span class="lineno"> 152</span> {</div>
|
||
|
<div class="line"><a id="l00153" name="l00153"></a><span class="lineno"> 153</span> <span class="keywordflow">if</span> (strncmp(rule_ptr->ip, packet->ip, IPV4ADDRESS_LENGTH) == 0)</div>
|
||
|
<div class="line"><a id="l00154" name="l00154"></a><span class="lineno"> 154</span> {</div>
|
||
|
<div class="line"><a id="l00155" name="l00155"></a><span class="lineno"> 155</span> <span class="keywordflow">if</span> ((rule_ptr->protocol == PROTOCOL_ALL || packet->protocol == rule_ptr->protocol) &&</div>
|
||
|
<div class="line"><a id="l00156" name="l00156"></a><span class="lineno"> 156</span> is_in_range(packet->port, rule_ptr->port_from, rule_ptr->port_to) &&</div>
|
||
|
<div class="line"><a id="l00157" name="l00157"></a><span class="lineno"> 157</span> rule_ptr->target == TARGET_ACCEPT)</div>
|
||
|
<div class="line"><a id="l00158" name="l00158"></a><span class="lineno"> 158</span> {</div>
|
||
|
<div class="line"><a id="l00159" name="l00159"></a><span class="lineno"> 159</span> free(packet);</div>
|
||
|
<div class="line"><a id="l00160" name="l00160"></a><span class="lineno"> 160</span> <span class="keywordflow">return</span> <span class="keyword">true</span>;</div>
|
||
|
<div class="line"><a id="l00161" name="l00161"></a><span class="lineno"> 161</span> }</div>
|
||
|
<div class="line"><a id="l00162" name="l00162"></a><span class="lineno"> 162</span> }</div>
|
||
|
<div class="line"><a id="l00163" name="l00163"></a><span class="lineno"> 163</span> <span class="keywordflow">return</span> <span class="keyword">false</span>;</div>
|
||
|
<div class="line"><a id="l00164" name="l00164"></a><span class="lineno"> 164</span> }</div>
|
||
|
<div class="line"><a id="l00165" name="l00165"></a><span class="lineno"> 165</span> </div>
|
||
|
<div class="line"><a id="l00166" name="l00166"></a><span class="lineno"> 166</span> <span class="keywordtype">bool</span> Firewall::is_packet_allowed(<span class="keyword">struct</span> pbuf *pbuf)</div>
|
||
|
<div class="line"><a id="l00167" name="l00167"></a><span class="lineno"> 167</span> {</div>
|
||
|
<div class="line"><a id="l00168" name="l00168"></a><span class="lineno"> 168</span> <span class="comment">// no rules -> no action</span></div>
|
||
|
<div class="line"><a id="l00169" name="l00169"></a><span class="lineno"> 169</span> <span class="keywordflow">if</span> (this->amount_of_rules == 0)</div>
|
||
|
<div class="line"><a id="l00170" name="l00170"></a><span class="lineno"> 170</span> <span class="keywordflow">return</span> <span class="keyword">true</span>;</div>
|
||
|
<div class="line"><a id="l00171" name="l00171"></a><span class="lineno"> 171</span> </div>
|
||
|
<div class="line"><a id="l00172" name="l00172"></a><span class="lineno"> 172</span> my_packet_t *packet = get_packet_information(pbuf);</div>
|
||
|
<div class="line"><a id="l00173" name="l00173"></a><span class="lineno"> 173</span> firewall_rule_t *rule_ptr = this->rule_head;</div>
|
||
|
<div class="line"><a id="l00174" name="l00174"></a><span class="lineno"> 174</span> <span class="keywordflow">while</span> (rule_ptr != NULL)</div>
|
||
|
<div class="line"><a id="l00175" name="l00175"></a><span class="lineno"> 175</span> {</div>
|
||
|
<div class="line"><a id="l00176" name="l00176"></a><span class="lineno"> 176</span> <span class="keywordflow">if</span> (rule_allows_packet(rule_ptr, packet))</div>
|
||
|
<div class="line"><a id="l00177" name="l00177"></a><span class="lineno"> 177</span> <span class="keywordflow">return</span> <span class="keyword">true</span>;</div>
|
||
|
<div class="line"><a id="l00178" name="l00178"></a><span class="lineno"> 178</span> rule_ptr = rule_ptr->next;</div>
|
||
|
<div class="line"><a id="l00179" name="l00179"></a><span class="lineno"> 179</span> }</div>
|
||
|
<div class="line"><a id="l00180" name="l00180"></a><span class="lineno"> 180</span> free(packet);</div>
|
||
|
<div class="line"><a id="l00181" name="l00181"></a><span class="lineno"> 181</span> <span class="keywordflow">return</span> <span class="keyword">false</span>;</div>
|
||
|
<div class="line"><a id="l00182" name="l00182"></a><span class="lineno"> 182</span> }</div>
|
||
|
<div class="line"><a id="l00183" name="l00183"></a><span class="lineno"> 183</span>}</div>
|
||
|
</div><!-- fragment --></div><!-- contents -->
|
||
|
<!-- start footer part -->
|
||
|
<hr class="footer"/><address class="footer"><small>
|
||
|
Generated by <a href="https://www.doxygen.org/index.html"><img class="footer" src="doxygen.svg" width="104" height="31" alt="doxygen"/></a> 1.9.4
|
||
|
</small></address>
|
||
|
</body>
|
||
|
</html>
|