summaryrefslogtreecommitdiffstats
path: root/src/plugins/ifw/ipset.c
blob: 15221483f757ab087cc9e81f429afe88c46363f2 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
#include "ipset.h"

#include <stdio.h>
#include <stdlib.h>
#include <netinet/in.h>

#define CMD_MAX_SIZE 1024

#ifdef IPSET_DEBUG
#define DPRINTF(s) printf("%s\n", s)
#else
#define DPRINTF(s)
#endif

void ipset_init() {
    char cmd[CMD_MAX_SIZE];
    snprintf(cmd, CMD_MAX_SIZE, IPSET_CMD " add " IPSET_BLACKLIST_NAME " hash:ip --timeout " IPSET_BLACKLIST_TIMEOUT);
    DPRINTF(cmd);
    system(cmd);
    snprintf(cmd, CMD_MAX_SIZE, IPSET_CMD " add " IPSET_WHITELIST_NAME " hash:ip");
    DPRINTF(cmd);
    system(cmd);
}

void ipset_destroy() {
    char cmd[CMD_MAX_SIZE];
    snprintf(cmd, CMD_MAX_SIZE, IPSET_CMD " destroy " IPSET_BLACKLIST_NAME);
    DPRINTF(cmd);
    system(cmd);
    snprintf(cmd, CMD_MAX_SIZE, IPSET_CMD " destroy " IPSET_WHITELIST_NAME);
    DPRINTF(cmd);
    system(cmd);
}

/* void ipset_blacklist_load(char *filename) { */
/*     char cmd[CMD_MAX_SIZE]; */
/*     snprintf(cmd, CMD_MAX_SIZE, IPSET_CMD " -R < %s", filename); */
/*     DPRINTF(cmd); */
/*     system(cmd); */
/* } */

/* void ipset_blacklist_save(char *filename) { */
/*     char cmd[CMD_MAX_SIZE]; */
/*     snprintf(cmd, CMD_MAX_SIZE, IPSET_CMD " -S " IPSET_BLACKLIST_NAME " > %s", filename); */
/*     DPRINTF(cmd); */
/*     system(cmd); */
/* } */

/* void ipset_whitelist_load(char *filename) { */
/*     char cmd[CMD_MAX_SIZE]; */
/*     snprintf(cmd, CMD_MAX_SIZE, IPSET_CMD " -R < %s", filename); */
/*     DPRINTF(cmd); */
/*     system(cmd); */
/* } */

/* void ipset_whitelist_save(char *filename) { */
/*     char cmd[CMD_MAX_SIZE]; */
/*     snprintf(cmd, CMD_MAX_SIZE, IPSET_CMD " -S " IPSET_WHITELIST_NAME " > %s", filename); */
/*     DPRINTF(cmd); */
/*     system(cmd); */
/* } */

void ipset_blacklist_add(u_int32_t addr) {
    char cmd[CMD_MAX_SIZE];
    snprintf(cmd, CMD_MAX_SIZE, IPSET_CMD " add " IPSET_BLACKLIST_NAME " %u", ntohl(addr));
    DPRINTF(cmd);
    system(cmd);
}

void ipset_blacklist_remove(u_int32_t addr) {
    char cmd[CMD_MAX_SIZE];
    snprintf(cmd, CMD_MAX_SIZE, IPSET_CMD " del " IPSET_BLACKLIST_NAME " %u", ntohl(addr));
    DPRINTF(cmd);
    system(cmd);
}

void ipset_whitelist_add(u_int32_t addr) {
    char cmd[CMD_MAX_SIZE];
    snprintf(cmd, CMD_MAX_SIZE, IPSET_CMD " add " IPSET_WHITELIST_NAME " %u", ntohl(addr));
    DPRINTF(cmd);
    system(cmd);
}

void ipset_whitelist_remove(u_int32_t addr) {
    char cmd[CMD_MAX_SIZE];
    snprintf(cmd, CMD_MAX_SIZE, IPSET_CMD " del " IPSET_WHITELIST_NAME " %u", ntohl(addr));
    DPRINTF(cmd);
    system(cmd);
}