From b5dff507ccd1c666210de51af83fa730d6baf50a Mon Sep 17 00:00:00 2001 From: Arturo Borrero Date: Fri, 7 Nov 2014 12:39:35 +0100 Subject: parser: allow both nat_flags and port specification in redirect This patch changes the parser to permit both nat_flags and port specification in the redirect expression. The resulting syntax is: % nft add rule nat prerouting redirect [port] [nat_flags] The port specification requires a bit of context regardin the transport protocol. Some examples: % nft add rule nat prerouting tcp dport 22 redirect :23 % nft add rule add prerouting udp dport 53 redirect :5353 The nat_flags argument is the last argument: % nft add rule nat prerouting tdp dport 80 redirect :8080 random The port specification can be a range: % nft add rule nat prerouting tcp dport 80 redirect :8080-8090 random While at it, the regression tests files are updated. Suggested-by: Pablo Neira Ayuso Signed-off-by: Arturo Borrero Gonzalez Signed-off-by: Pablo Neira Ayuso --- tests/regression/ip/redirect.t | 14 +++++++++----- tests/regression/ip6/redirect.t | 8 +++++--- 2 files changed, 14 insertions(+), 8 deletions(-) (limited to 'tests') diff --git a/tests/regression/ip/redirect.t b/tests/regression/ip/redirect.t index f69fd07c..cb230e2b 100644 --- a/tests/regression/ip/redirect.t +++ b/tests/regression/ip/redirect.t @@ -24,11 +24,15 @@ tcp dport 39128 redirect :993;ok redirect :1234;fail redirect :12341111;fail -# invalid arguments -tcp dport 9128 redirect :993 random;fail -tcp dport 9128 redirect :993 random-fully;fail -tcp dport 9128 redirect persistent :123;fail -tcp dport 9128 redirect random,persistent :123;fail +# both port and nf_nat flags +tcp dport 9128 redirect :993 random;ok +tcp dport 9128 redirect :993 random-fully;ok +tcp dport 9128 redirect :123 persistent;ok +tcp dport 9128 redirect :123 random,persistent;ok + +# nf_nat flags is the last argument +udp dport 1234 redirect random :123;fail +udp dport 21234 redirect persistent,random-fully :431;fail # redirect is a terminal statement tcp dport 22 redirect counter packets 0 bytes 0 accept;fail diff --git a/tests/regression/ip6/redirect.t b/tests/regression/ip6/redirect.t index d9728714..dce4794a 100644 --- a/tests/regression/ip6/redirect.t +++ b/tests/regression/ip6/redirect.t @@ -25,9 +25,11 @@ tcp dport 39128 redirect :993;ok redirect :1234;fail redirect :12341111;fail -# invalid arguments -tcp dport 9128 redirect :993 random;fail -tcp dport 9128 redirect :993 random-fully;fail +# both port and nf_nat flags +tcp dport 9128 redirect :993 random;ok +tcp dport 9128 redirect :993 random-fully,persistent;ok + +# nf_nat flags are the last argument tcp dport 9128 redirect persistent :123;fail tcp dport 9128 redirect random,persistent :123;fail -- cgit v1.2.3