summaryrefslogtreecommitdiffstats
path: root/ebtables-restore
diff options
context:
space:
mode:
authorBart De Schuymer <bdschuym@pandora.be>2005-06-14 19:17:48 +0000
committerBart De Schuymer <bdschuym@pandora.be>2005-06-14 19:17:48 +0000
commit865444dd154e06ae67a79bf5c33a00d122296995 (patch)
treebbafa72eb013a767d17ee6533d7b051f42a4bd74 /ebtables-restore
parent9d14e84a8f4104afe75dd732e058819de862c526 (diff)
Rok Papez <rok.papez_at_ames.si>
Diffstat (limited to 'ebtables-restore')
-rw-r--r--ebtables-restore62
1 files changed, 62 insertions, 0 deletions
diff --git a/ebtables-restore b/ebtables-restore
new file mode 100644
index 0000000..171a80c
--- /dev/null
+++ b/ebtables-restore
@@ -0,0 +1,62 @@
+#!/usr/bin/perl -w
+#
+#
+# A script that imports text ebtables rules. Similar to iptables-restore.
+# It can be used to restore configuration from /etc/sysconfig/ebtables.
+#
+
+use strict;
+my $ebtables = "/sbin/ebtables";
+my $table;
+my $rc;
+my $line;
+
+# ==============================
+# Check table
+# Creates user chains.
+# ==============================
+sub check_chain {
+ if ($table eq "filter") {
+ if ($_[1] eq "INPUT") { return; }
+ if ($_[1] eq "FORWARD") { return; }
+ if ($_[1] eq "OUTPUT") { return; }
+ }
+ if ($table eq "nat") {
+ if ($_[1] eq "PREROUTING") { return; }
+ if ($_[1] eq "POSTROUTING") { return; }
+ if ($_[1] eq "OUTPUT") { return; }
+ }
+ if ($table eq "broute") {
+ if ($_[1] eq "BROUTING") { return; }
+ }
+ $rc = `$ebtables -t $_[0] -N $_[1]`;
+ unless($? == 0) {print "ERROR: $rc\n"; exit -1};
+}
+# ==============================
+
+unless (-x $ebtables) { print "ERROR: $ebtables isn't executable\n"; exit -1; };
+$rc = `$ebtables -t filter --init-table`;
+unless($? == 0) { print "ERROR: $rc\n"; exit -1 };
+$rc = `$ebtables -t nat --init-table`;
+unless($? == 0) { print "ERROR: $rc\n"; exit -1 };
+$rc = `$ebtables -t broute --init-table`;
+unless($? == 0) { print "ERROR: $rc\n"; exit -1 };
+
+$line = 0;
+while(<>) {
+ $line++;
+ if(m/^#/) { next; };
+ if(m/^$/) { next; };
+ if(m/^\*(.*)/) {
+ $table = $1;
+ next;
+ }
+ if(m/^\:(.*?)\s(.*)/) {
+ &check_chain($table,$1);
+ $rc = `$ebtables -t $table -P $1 $2`;
+ unless($? == 0) {print "ERROR(line $line): $rc\n"; exit -1};
+ next;
+ }
+ $rc = `$ebtables -t $table $_`;
+ unless($? == 0) {print "ERROR(line $line): $rc\n"; exit -1};
+}