1*a71a9546SAutomerger Merge Worker /*
2*a71a9546SAutomerger Merge Worker * Copyright (c) 2011 Patrick McHardy <[email protected]>
3*a71a9546SAutomerger Merge Worker *
4*a71a9546SAutomerger Merge Worker * Based on Svenning Soerensen's IPv4 NETMAP target. Development of IPv6 NAT
5*a71a9546SAutomerger Merge Worker * funded by Astaro.
6*a71a9546SAutomerger Merge Worker */
7*a71a9546SAutomerger Merge Worker
8*a71a9546SAutomerger Merge Worker #include <stdio.h>
9*a71a9546SAutomerger Merge Worker #include <netdb.h>
10*a71a9546SAutomerger Merge Worker #include <string.h>
11*a71a9546SAutomerger Merge Worker #include <stdlib.h>
12*a71a9546SAutomerger Merge Worker #include <getopt.h>
13*a71a9546SAutomerger Merge Worker #include <xtables.h>
14*a71a9546SAutomerger Merge Worker #include <libiptc/libip6tc.h>
15*a71a9546SAutomerger Merge Worker #include <linux/netfilter/nf_nat.h>
16*a71a9546SAutomerger Merge Worker
17*a71a9546SAutomerger Merge Worker #define MODULENAME "NETMAP"
18*a71a9546SAutomerger Merge Worker
19*a71a9546SAutomerger Merge Worker enum {
20*a71a9546SAutomerger Merge Worker O_TO = 0,
21*a71a9546SAutomerger Merge Worker };
22*a71a9546SAutomerger Merge Worker
23*a71a9546SAutomerger Merge Worker static const struct xt_option_entry NETMAP_opts[] = {
24*a71a9546SAutomerger Merge Worker {.name = "to", .id = O_TO, .type = XTTYPE_HOSTMASK,
25*a71a9546SAutomerger Merge Worker .flags = XTOPT_MAND},
26*a71a9546SAutomerger Merge Worker XTOPT_TABLEEND,
27*a71a9546SAutomerger Merge Worker };
28*a71a9546SAutomerger Merge Worker
NETMAP_help(void)29*a71a9546SAutomerger Merge Worker static void NETMAP_help(void)
30*a71a9546SAutomerger Merge Worker {
31*a71a9546SAutomerger Merge Worker printf(MODULENAME" target options:\n"
32*a71a9546SAutomerger Merge Worker " --%s address[/mask]\n"
33*a71a9546SAutomerger Merge Worker " Network address to map to.\n\n",
34*a71a9546SAutomerger Merge Worker NETMAP_opts[0].name);
35*a71a9546SAutomerger Merge Worker }
36*a71a9546SAutomerger Merge Worker
NETMAP_parse(struct xt_option_call * cb)37*a71a9546SAutomerger Merge Worker static void NETMAP_parse(struct xt_option_call *cb)
38*a71a9546SAutomerger Merge Worker {
39*a71a9546SAutomerger Merge Worker struct nf_nat_range *range = cb->data;
40*a71a9546SAutomerger Merge Worker unsigned int i;
41*a71a9546SAutomerger Merge Worker
42*a71a9546SAutomerger Merge Worker xtables_option_parse(cb);
43*a71a9546SAutomerger Merge Worker range->flags |= NF_NAT_RANGE_MAP_IPS;
44*a71a9546SAutomerger Merge Worker for (i = 0; i < 4; i++) {
45*a71a9546SAutomerger Merge Worker range->min_addr.ip6[i] = cb->val.haddr.ip6[i] &
46*a71a9546SAutomerger Merge Worker cb->val.hmask.ip6[i];
47*a71a9546SAutomerger Merge Worker range->max_addr.ip6[i] = range->min_addr.ip6[i] |
48*a71a9546SAutomerger Merge Worker ~cb->val.hmask.ip6[i];
49*a71a9546SAutomerger Merge Worker }
50*a71a9546SAutomerger Merge Worker }
51*a71a9546SAutomerger Merge Worker
__NETMAP_print(const void * ip,const struct xt_entry_target * target,int numeric)52*a71a9546SAutomerger Merge Worker static void __NETMAP_print(const void *ip, const struct xt_entry_target *target,
53*a71a9546SAutomerger Merge Worker int numeric)
54*a71a9546SAutomerger Merge Worker {
55*a71a9546SAutomerger Merge Worker const struct nf_nat_range *r = (const void *)target->data;
56*a71a9546SAutomerger Merge Worker struct in6_addr a;
57*a71a9546SAutomerger Merge Worker unsigned int i;
58*a71a9546SAutomerger Merge Worker int bits;
59*a71a9546SAutomerger Merge Worker
60*a71a9546SAutomerger Merge Worker a = r->min_addr.in6;
61*a71a9546SAutomerger Merge Worker printf("%s", xtables_ip6addr_to_numeric(&a));
62*a71a9546SAutomerger Merge Worker for (i = 0; i < 4; i++)
63*a71a9546SAutomerger Merge Worker a.s6_addr32[i] = ~(r->min_addr.ip6[i] ^ r->max_addr.ip6[i]);
64*a71a9546SAutomerger Merge Worker bits = xtables_ip6mask_to_cidr(&a);
65*a71a9546SAutomerger Merge Worker if (bits < 0)
66*a71a9546SAutomerger Merge Worker printf("/%s", xtables_ip6addr_to_numeric(&a));
67*a71a9546SAutomerger Merge Worker else
68*a71a9546SAutomerger Merge Worker printf("/%d", bits);
69*a71a9546SAutomerger Merge Worker }
70*a71a9546SAutomerger Merge Worker
NETMAP_print(const void * ip,const struct xt_entry_target * target,int numeric)71*a71a9546SAutomerger Merge Worker static void NETMAP_print(const void *ip, const struct xt_entry_target *target,
72*a71a9546SAutomerger Merge Worker int numeric)
73*a71a9546SAutomerger Merge Worker {
74*a71a9546SAutomerger Merge Worker printf(" to:");
75*a71a9546SAutomerger Merge Worker __NETMAP_print(ip, target, numeric);
76*a71a9546SAutomerger Merge Worker }
77*a71a9546SAutomerger Merge Worker
NETMAP_save(const void * ip,const struct xt_entry_target * target)78*a71a9546SAutomerger Merge Worker static void NETMAP_save(const void *ip, const struct xt_entry_target *target)
79*a71a9546SAutomerger Merge Worker {
80*a71a9546SAutomerger Merge Worker printf(" --%s ", NETMAP_opts[0].name);
81*a71a9546SAutomerger Merge Worker __NETMAP_print(ip, target, 0);
82*a71a9546SAutomerger Merge Worker }
83*a71a9546SAutomerger Merge Worker
84*a71a9546SAutomerger Merge Worker static struct xtables_target netmap_tg_reg = {
85*a71a9546SAutomerger Merge Worker .name = MODULENAME,
86*a71a9546SAutomerger Merge Worker .version = XTABLES_VERSION,
87*a71a9546SAutomerger Merge Worker .family = NFPROTO_IPV6,
88*a71a9546SAutomerger Merge Worker .size = XT_ALIGN(sizeof(struct nf_nat_range)),
89*a71a9546SAutomerger Merge Worker .userspacesize = XT_ALIGN(sizeof(struct nf_nat_range)),
90*a71a9546SAutomerger Merge Worker .help = NETMAP_help,
91*a71a9546SAutomerger Merge Worker .x6_parse = NETMAP_parse,
92*a71a9546SAutomerger Merge Worker .print = NETMAP_print,
93*a71a9546SAutomerger Merge Worker .save = NETMAP_save,
94*a71a9546SAutomerger Merge Worker .x6_options = NETMAP_opts,
95*a71a9546SAutomerger Merge Worker };
96*a71a9546SAutomerger Merge Worker
_init(void)97*a71a9546SAutomerger Merge Worker void _init(void)
98*a71a9546SAutomerger Merge Worker {
99*a71a9546SAutomerger Merge Worker xtables_register_target(&netmap_tg_reg);
100*a71a9546SAutomerger Merge Worker }
101