Skip to content
体验新版
项目
组织
正在加载...
登录
切换导航
打开侧边栏
openeuler
Kernel
提交
ed72d9e2
K
Kernel
项目概览
openeuler
/
Kernel
1 年多 前同步成功
通知
8
Star
0
Fork
0
代码
文件
提交
分支
Tags
贡献者
分支图
Diff
Issue
0
列表
看板
标记
里程碑
合并请求
0
DevOps
流水线
流水线任务
计划
Wiki
0
Wiki
分析
仓库
DevOps
项目成员
Pages
K
Kernel
项目概览
项目概览
详情
发布
仓库
仓库
文件
提交
分支
标签
贡献者
分支图
比较
Issue
0
Issue
0
列表
看板
标记
里程碑
合并请求
0
合并请求
0
Pages
DevOps
DevOps
流水线
流水线任务
计划
分析
分析
仓库分析
DevOps
Wiki
0
Wiki
成员
成员
收起侧边栏
关闭侧边栏
动态
分支图
创建新Issue
流水线任务
提交
Issue看板
提交
ed72d9e2
编写于
12年前
作者:
P
Patrick McHardy
提交者:
Pablo Neira Ayuso
12年前
浏览文件
操作
浏览文件
下载
电子邮件补丁
差异文件
netfilter: ip6tables: add NETMAP target
Signed-off-by:
N
Patrick McHardy
<
kaber@trash.net
>
上级
115e23ac
无相关合并请求
变更
3
隐藏空白更改
内联
并排
Showing
3 changed file
with
105 addition
and
0 deletion
+105
-0
net/ipv6/netfilter/Kconfig
net/ipv6/netfilter/Kconfig
+10
-0
net/ipv6/netfilter/Makefile
net/ipv6/netfilter/Makefile
+1
-0
net/ipv6/netfilter/ip6t_NETMAP.c
net/ipv6/netfilter/ip6t_NETMAP.c
+94
-0
未找到文件。
net/ipv6/netfilter/Kconfig
浏览文件 @
ed72d9e2
...
...
@@ -156,6 +156,16 @@ config IP6_NF_TARGET_MASQUERADE
To compile it as a module, choose M here. If unsure, say N.
config IP6_NF_TARGET_NETMAP
tristate "NETMAP target support"
depends on NF_NAT_IPV6
help
NETMAP is an implementation of static 1:1 NAT mapping of network
addresses. It maps the network address part, while keeping the host
address part intact.
To compile it as a module, choose M here. If unsure, say N.
config IP6_NF_TARGET_REDIRECT
tristate "REDIRECT target support"
depends on NF_NAT_IPV6
...
...
This diff is collapsed.
Click to expand it.
net/ipv6/netfilter/Makefile
浏览文件 @
ed72d9e2
...
...
@@ -35,5 +35,6 @@ obj-$(CONFIG_IP6_NF_MATCH_RT) += ip6t_rt.o
# targets
obj-$(CONFIG_IP6_NF_TARGET_MASQUERADE)
+=
ip6t_MASQUERADE.o
obj-$(CONFIG_IP6_NF_TARGET_NETMAP)
+=
ip6t_NETMAP.o
obj-$(CONFIG_IP6_NF_TARGET_REDIRECT)
+=
ip6t_REDIRECT.o
obj-$(CONFIG_IP6_NF_TARGET_REJECT)
+=
ip6t_REJECT.o
This diff is collapsed.
Click to expand it.
net/ipv6/netfilter/ip6t_NETMAP.c
0 → 100644
浏览文件 @
ed72d9e2
/*
* Copyright (c) 2011 Patrick McHardy <kaber@trash.net>
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License version 2 as
* published by the Free Software Foundation.
*
* Based on Svenning Soerensen's IPv4 NETMAP target. Development of IPv6
* NAT funded by Astaro.
*/
#include <linux/kernel.h>
#include <linux/module.h>
#include <linux/ipv6.h>
#include <linux/netfilter.h>
#include <linux/netfilter_ipv6.h>
#include <linux/netfilter/x_tables.h>
#include <net/netfilter/nf_nat.h>
static
unsigned
int
netmap_tg6
(
struct
sk_buff
*
skb
,
const
struct
xt_action_param
*
par
)
{
const
struct
nf_nat_range
*
range
=
par
->
targinfo
;
struct
nf_nat_range
newrange
;
struct
nf_conn
*
ct
;
enum
ip_conntrack_info
ctinfo
;
union
nf_inet_addr
new_addr
,
netmask
;
unsigned
int
i
;
ct
=
nf_ct_get
(
skb
,
&
ctinfo
);
for
(
i
=
0
;
i
<
ARRAY_SIZE
(
range
->
min_addr
.
ip6
);
i
++
)
netmask
.
ip6
[
i
]
=
~
(
range
->
min_addr
.
ip6
[
i
]
^
range
->
max_addr
.
ip6
[
i
]);
if
(
par
->
hooknum
==
NF_INET_PRE_ROUTING
||
par
->
hooknum
==
NF_INET_LOCAL_OUT
)
new_addr
.
in6
=
ipv6_hdr
(
skb
)
->
daddr
;
else
new_addr
.
in6
=
ipv6_hdr
(
skb
)
->
saddr
;
for
(
i
=
0
;
i
<
ARRAY_SIZE
(
new_addr
.
ip6
);
i
++
)
{
new_addr
.
ip6
[
i
]
&=
~
netmask
.
ip6
[
i
];
new_addr
.
ip6
[
i
]
|=
range
->
min_addr
.
ip6
[
i
]
&
netmask
.
ip6
[
i
];
}
newrange
.
flags
=
range
->
flags
|
NF_NAT_RANGE_MAP_IPS
;
newrange
.
min_addr
=
new_addr
;
newrange
.
max_addr
=
new_addr
;
newrange
.
min_proto
=
range
->
min_proto
;
newrange
.
max_proto
=
range
->
max_proto
;
return
nf_nat_setup_info
(
ct
,
&
newrange
,
HOOK2MANIP
(
par
->
hooknum
));
}
static
int
netmap_tg6_checkentry
(
const
struct
xt_tgchk_param
*
par
)
{
const
struct
nf_nat_range
*
range
=
par
->
targinfo
;
if
(
!
(
range
->
flags
&
NF_NAT_RANGE_MAP_IPS
))
return
-
EINVAL
;
return
0
;
}
static
struct
xt_target
netmap_tg6_reg
__read_mostly
=
{
.
name
=
"NETMAP"
,
.
family
=
NFPROTO_IPV6
,
.
target
=
netmap_tg6
,
.
targetsize
=
sizeof
(
struct
nf_nat_range
),
.
table
=
"nat"
,
.
hooks
=
(
1
<<
NF_INET_PRE_ROUTING
)
|
(
1
<<
NF_INET_POST_ROUTING
)
|
(
1
<<
NF_INET_LOCAL_OUT
)
|
(
1
<<
NF_INET_LOCAL_IN
),
.
checkentry
=
netmap_tg6_checkentry
,
.
me
=
THIS_MODULE
,
};
static
int
__init
netmap_tg6_init
(
void
)
{
return
xt_register_target
(
&
netmap_tg6_reg
);
}
static
void
netmap_tg6_exit
(
void
)
{
xt_unregister_target
(
&
netmap_tg6_reg
);
}
module_init
(
netmap_tg6_init
);
module_exit
(
netmap_tg6_exit
);
MODULE_LICENSE
(
"GPL"
);
MODULE_DESCRIPTION
(
"Xtables: 1:1 NAT mapping of IPv6 subnets"
);
MODULE_AUTHOR
(
"Patrick McHardy <kaber@trash.net>"
);
This diff is collapsed.
Click to expand it.
编辑
预览
Markdown
is supported
0%
请重试
或
添加新附件
.
添加附件
取消
You are about to add
0
people
to the discussion. Proceed with caution.
先完成此消息的编辑!
取消
想要评论请
注册
或
登录
反馈
建议
客服
返回
顶部