2 * H.323 extension for NAT alteration.
4 * Copyright (c) 2006 Jing Min Zhao <zhaojingmin@users.sourceforge.net>
6 * This source code is licensed under General Public License version 2.
8 * Based on the 'brute force' H.323 NAT module by
9 * Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>
12 #include <linux/module.h>
13 #include <linux/moduleparam.h>
14 #include <linux/tcp.h>
17 #include <net/netfilter/nf_nat.h>
18 #include <net/netfilter/nf_nat_helper.h>
19 #include <net/netfilter/nf_nat_rule.h>
20 #include <net/netfilter/nf_conntrack_helper.h>
21 #include <net/netfilter/nf_conntrack_expect.h>
22 #include <linux/netfilter/nf_conntrack_h323.h>
24 /****************************************************************************/
25 static int set_addr(struct sk_buff
**pskb
,
26 unsigned char **data
, int dataoff
,
27 unsigned int addroff
, __be32 ip
, __be16 port
)
29 enum ip_conntrack_info ctinfo
;
30 struct nf_conn
*ct
= nf_ct_get(*pskb
, &ctinfo
);
34 } __attribute__ ((__packed__
)) buf
;
35 struct tcphdr _tcph
, *th
;
41 if (ip_hdr(*pskb
)->protocol
== IPPROTO_TCP
) {
42 if (!nf_nat_mangle_tcp_packet(pskb
, ct
, ctinfo
,
44 (char *) &buf
, sizeof(buf
))) {
46 printk("nf_nat_h323: nf_nat_mangle_tcp_packet"
51 /* Relocate data pointer */
52 th
= skb_header_pointer(*pskb
, ip_hdrlen(*pskb
),
53 sizeof(_tcph
), &_tcph
);
56 *data
= (*pskb
)->data
+ ip_hdrlen(*pskb
) +
57 th
->doff
* 4 + dataoff
;
59 if (!nf_nat_mangle_udp_packet(pskb
, ct
, ctinfo
,
61 (char *) &buf
, sizeof(buf
))) {
63 printk("nf_nat_h323: nf_nat_mangle_udp_packet"
67 /* nf_nat_mangle_udp_packet uses skb_make_writable() to copy
68 * or pull everything in a linear buffer, so we can safely
69 * use the skb pointers now */
70 *data
= ((*pskb
)->data
+ ip_hdrlen(*pskb
) +
71 sizeof(struct udphdr
));
77 /****************************************************************************/
78 static int set_h225_addr(struct sk_buff
**pskb
,
79 unsigned char **data
, int dataoff
,
80 TransportAddress
*taddr
,
81 union nf_conntrack_address
*addr
, __be16 port
)
83 return set_addr(pskb
, data
, dataoff
, taddr
->ipAddress
.ip
,
87 /****************************************************************************/
88 static int set_h245_addr(struct sk_buff
**pskb
,
89 unsigned char **data
, int dataoff
,
90 H245_TransportAddress
*taddr
,
91 union nf_conntrack_address
*addr
, __be16 port
)
93 return set_addr(pskb
, data
, dataoff
,
94 taddr
->unicastAddress
.iPAddress
.network
,
98 /****************************************************************************/
99 static int set_sig_addr(struct sk_buff
**pskb
, struct nf_conn
*ct
,
100 enum ip_conntrack_info ctinfo
,
101 unsigned char **data
,
102 TransportAddress
*taddr
, int count
)
104 struct nf_ct_h323_master
*info
= &nfct_help(ct
)->help
.ct_h323_info
;
105 int dir
= CTINFO2DIR(ctinfo
);
108 union nf_conntrack_address addr
;
110 for (i
= 0; i
< count
; i
++) {
111 if (get_h225_addr(ct
, *data
, &taddr
[i
], &addr
, &port
)) {
112 if (addr
.ip
== ct
->tuplehash
[dir
].tuple
.src
.u3
.ip
&&
113 port
== info
->sig_port
[dir
]) {
116 /* Fix for Gnomemeeting */
118 get_h225_addr(ct
, *data
, &taddr
[0],
120 (ntohl(addr
.ip
) & 0xff000000) == 0x7f000000)
123 pr_debug("nf_nat_ras: set signal address "
124 "%u.%u.%u.%u:%hu->%u.%u.%u.%u:%hu\n",
125 NIPQUAD(addr
.ip
), port
,
126 NIPQUAD(ct
->tuplehash
[!dir
].tuple
.dst
.u3
.ip
),
127 info
->sig_port
[!dir
]);
128 return set_h225_addr(pskb
, data
, 0, &taddr
[i
],
129 &ct
->tuplehash
[!dir
].
131 info
->sig_port
[!dir
]);
132 } else if (addr
.ip
== ct
->tuplehash
[dir
].tuple
.dst
.u3
.ip
&&
133 port
== info
->sig_port
[dir
]) {
135 pr_debug("nf_nat_ras: set signal address "
136 "%u.%u.%u.%u:%hu->%u.%u.%u.%u:%hu\n",
137 NIPQUAD(addr
.ip
), port
,
138 NIPQUAD(ct
->tuplehash
[!dir
].tuple
.src
.u3
.ip
),
139 info
->sig_port
[!dir
]);
140 return set_h225_addr(pskb
, data
, 0, &taddr
[i
],
141 &ct
->tuplehash
[!dir
].
143 info
->sig_port
[!dir
]);
151 /****************************************************************************/
152 static int set_ras_addr(struct sk_buff
**pskb
, struct nf_conn
*ct
,
153 enum ip_conntrack_info ctinfo
,
154 unsigned char **data
,
155 TransportAddress
*taddr
, int count
)
157 int dir
= CTINFO2DIR(ctinfo
);
160 union nf_conntrack_address addr
;
162 for (i
= 0; i
< count
; i
++) {
163 if (get_h225_addr(ct
, *data
, &taddr
[i
], &addr
, &port
) &&
164 addr
.ip
== ct
->tuplehash
[dir
].tuple
.src
.u3
.ip
&&
165 port
== ct
->tuplehash
[dir
].tuple
.src
.u
.udp
.port
) {
166 pr_debug("nf_nat_ras: set rasAddress "
167 "%u.%u.%u.%u:%hu->%u.%u.%u.%u:%hu\n",
168 NIPQUAD(addr
.ip
), ntohs(port
),
169 NIPQUAD(ct
->tuplehash
[!dir
].tuple
.dst
.u3
.ip
),
170 ntohs(ct
->tuplehash
[!dir
].tuple
.dst
.u
.udp
.port
));
171 return set_h225_addr(pskb
, data
, 0, &taddr
[i
],
172 &ct
->tuplehash
[!dir
].tuple
.dst
.u3
,
173 ct
->tuplehash
[!dir
].tuple
.
181 /****************************************************************************/
182 static int nat_rtp_rtcp(struct sk_buff
**pskb
, struct nf_conn
*ct
,
183 enum ip_conntrack_info ctinfo
,
184 unsigned char **data
, int dataoff
,
185 H245_TransportAddress
*taddr
,
186 __be16 port
, __be16 rtp_port
,
187 struct nf_conntrack_expect
*rtp_exp
,
188 struct nf_conntrack_expect
*rtcp_exp
)
190 struct nf_ct_h323_master
*info
= &nfct_help(ct
)->help
.ct_h323_info
;
191 int dir
= CTINFO2DIR(ctinfo
);
193 u_int16_t nated_port
;
195 /* Set expectations for NAT */
196 rtp_exp
->saved_proto
.udp
.port
= rtp_exp
->tuple
.dst
.u
.udp
.port
;
197 rtp_exp
->expectfn
= nf_nat_follow_master
;
199 rtcp_exp
->saved_proto
.udp
.port
= rtcp_exp
->tuple
.dst
.u
.udp
.port
;
200 rtcp_exp
->expectfn
= nf_nat_follow_master
;
201 rtcp_exp
->dir
= !dir
;
203 /* Lookup existing expects */
204 for (i
= 0; i
< H323_RTP_CHANNEL_MAX
; i
++) {
205 if (info
->rtp_port
[i
][dir
] == rtp_port
) {
208 /* Use allocated ports first. This will refresh
210 rtp_exp
->tuple
.dst
.u
.udp
.port
= info
->rtp_port
[i
][dir
];
211 rtcp_exp
->tuple
.dst
.u
.udp
.port
=
212 htons(ntohs(info
->rtp_port
[i
][dir
]) + 1);
214 } else if (info
->rtp_port
[i
][dir
] == 0) {
220 /* Run out of expectations */
221 if (i
>= H323_RTP_CHANNEL_MAX
) {
223 printk("nf_nat_h323: out of expectations\n");
227 /* Try to get a pair of ports. */
228 for (nated_port
= ntohs(rtp_exp
->tuple
.dst
.u
.udp
.port
);
229 nated_port
!= 0; nated_port
+= 2) {
230 rtp_exp
->tuple
.dst
.u
.udp
.port
= htons(nated_port
);
231 if (nf_ct_expect_related(rtp_exp
) == 0) {
232 rtcp_exp
->tuple
.dst
.u
.udp
.port
=
233 htons(nated_port
+ 1);
234 if (nf_ct_expect_related(rtcp_exp
) == 0)
236 nf_ct_unexpect_related(rtp_exp
);
240 if (nated_port
== 0) { /* No port available */
242 printk("nf_nat_h323: out of RTP ports\n");
247 if (set_h245_addr(pskb
, data
, dataoff
, taddr
,
248 &ct
->tuplehash
[!dir
].tuple
.dst
.u3
,
249 htons((port
& htons(1)) ? nated_port
+ 1 :
252 info
->rtp_port
[i
][dir
] = rtp_port
;
253 info
->rtp_port
[i
][!dir
] = htons(nated_port
);
255 nf_ct_unexpect_related(rtp_exp
);
256 nf_ct_unexpect_related(rtcp_exp
);
261 pr_debug("nf_nat_h323: expect RTP %u.%u.%u.%u:%hu->%u.%u.%u.%u:%hu\n",
262 NIPQUAD(rtp_exp
->tuple
.src
.u3
.ip
),
263 ntohs(rtp_exp
->tuple
.src
.u
.udp
.port
),
264 NIPQUAD(rtp_exp
->tuple
.dst
.u3
.ip
),
265 ntohs(rtp_exp
->tuple
.dst
.u
.udp
.port
));
266 pr_debug("nf_nat_h323: expect RTCP %u.%u.%u.%u:%hu->%u.%u.%u.%u:%hu\n",
267 NIPQUAD(rtcp_exp
->tuple
.src
.u3
.ip
),
268 ntohs(rtcp_exp
->tuple
.src
.u
.udp
.port
),
269 NIPQUAD(rtcp_exp
->tuple
.dst
.u3
.ip
),
270 ntohs(rtcp_exp
->tuple
.dst
.u
.udp
.port
));
275 /****************************************************************************/
276 static int nat_t120(struct sk_buff
**pskb
, struct nf_conn
*ct
,
277 enum ip_conntrack_info ctinfo
,
278 unsigned char **data
, int dataoff
,
279 H245_TransportAddress
*taddr
, __be16 port
,
280 struct nf_conntrack_expect
*exp
)
282 int dir
= CTINFO2DIR(ctinfo
);
283 u_int16_t nated_port
= ntohs(port
);
285 /* Set expectations for NAT */
286 exp
->saved_proto
.tcp
.port
= exp
->tuple
.dst
.u
.tcp
.port
;
287 exp
->expectfn
= nf_nat_follow_master
;
290 /* Try to get same port: if not, try to change it. */
291 for (; nated_port
!= 0; nated_port
++) {
292 exp
->tuple
.dst
.u
.tcp
.port
= htons(nated_port
);
293 if (nf_ct_expect_related(exp
) == 0)
297 if (nated_port
== 0) { /* No port available */
299 printk("nf_nat_h323: out of TCP ports\n");
304 if (set_h245_addr(pskb
, data
, dataoff
, taddr
,
305 &ct
->tuplehash
[!dir
].tuple
.dst
.u3
,
306 htons(nated_port
)) < 0) {
307 nf_ct_unexpect_related(exp
);
311 pr_debug("nf_nat_h323: expect T.120 %u.%u.%u.%u:%hu->%u.%u.%u.%u:%hu\n",
312 NIPQUAD(exp
->tuple
.src
.u3
.ip
),
313 ntohs(exp
->tuple
.src
.u
.tcp
.port
),
314 NIPQUAD(exp
->tuple
.dst
.u3
.ip
),
315 ntohs(exp
->tuple
.dst
.u
.tcp
.port
));
320 /****************************************************************************/
321 static int nat_h245(struct sk_buff
**pskb
, struct nf_conn
*ct
,
322 enum ip_conntrack_info ctinfo
,
323 unsigned char **data
, int dataoff
,
324 TransportAddress
*taddr
, __be16 port
,
325 struct nf_conntrack_expect
*exp
)
327 struct nf_ct_h323_master
*info
= &nfct_help(ct
)->help
.ct_h323_info
;
328 int dir
= CTINFO2DIR(ctinfo
);
329 u_int16_t nated_port
= ntohs(port
);
331 /* Set expectations for NAT */
332 exp
->saved_proto
.tcp
.port
= exp
->tuple
.dst
.u
.tcp
.port
;
333 exp
->expectfn
= nf_nat_follow_master
;
336 /* Check existing expects */
337 if (info
->sig_port
[dir
] == port
)
338 nated_port
= ntohs(info
->sig_port
[!dir
]);
340 /* Try to get same port: if not, try to change it. */
341 for (; nated_port
!= 0; nated_port
++) {
342 exp
->tuple
.dst
.u
.tcp
.port
= htons(nated_port
);
343 if (nf_ct_expect_related(exp
) == 0)
347 if (nated_port
== 0) { /* No port available */
349 printk("nf_nat_q931: out of TCP ports\n");
354 if (set_h225_addr(pskb
, data
, dataoff
, taddr
,
355 &ct
->tuplehash
[!dir
].tuple
.dst
.u3
,
356 htons(nated_port
)) == 0) {
358 info
->sig_port
[dir
] = port
;
359 info
->sig_port
[!dir
] = htons(nated_port
);
361 nf_ct_unexpect_related(exp
);
365 pr_debug("nf_nat_q931: expect H.245 %u.%u.%u.%u:%hu->%u.%u.%u.%u:%hu\n",
366 NIPQUAD(exp
->tuple
.src
.u3
.ip
),
367 ntohs(exp
->tuple
.src
.u
.tcp
.port
),
368 NIPQUAD(exp
->tuple
.dst
.u3
.ip
),
369 ntohs(exp
->tuple
.dst
.u
.tcp
.port
));
374 /****************************************************************************
375 * This conntrack expect function replaces nf_conntrack_q931_expect()
376 * which was set by nf_conntrack_h323.c.
377 ****************************************************************************/
378 static void ip_nat_q931_expect(struct nf_conn
*new,
379 struct nf_conntrack_expect
*this)
381 struct nf_nat_range range
;
383 if (this->tuple
.src
.u3
.ip
!= 0) { /* Only accept calls from GK */
384 nf_nat_follow_master(new, this);
388 /* This must be a fresh one. */
389 BUG_ON(new->status
& IPS_NAT_DONE_MASK
);
391 /* Change src to where master sends to */
392 range
.flags
= IP_NAT_RANGE_MAP_IPS
;
393 range
.min_ip
= range
.max_ip
= new->tuplehash
[!this->dir
].tuple
.src
.u3
.ip
;
395 /* hook doesn't matter, but it has to do source manip */
396 nf_nat_setup_info(new, &range
, NF_IP_POST_ROUTING
);
398 /* For DST manip, map port here to where it's expected. */
399 range
.flags
= (IP_NAT_RANGE_MAP_IPS
| IP_NAT_RANGE_PROTO_SPECIFIED
);
400 range
.min
= range
.max
= this->saved_proto
;
401 range
.min_ip
= range
.max_ip
=
402 new->master
->tuplehash
[!this->dir
].tuple
.src
.u3
.ip
;
404 /* hook doesn't matter, but it has to do destination manip */
405 nf_nat_setup_info(new, &range
, NF_IP_PRE_ROUTING
);
408 /****************************************************************************/
409 static int nat_q931(struct sk_buff
**pskb
, struct nf_conn
*ct
,
410 enum ip_conntrack_info ctinfo
,
411 unsigned char **data
, TransportAddress
*taddr
, int idx
,
412 __be16 port
, struct nf_conntrack_expect
*exp
)
414 struct nf_ct_h323_master
*info
= &nfct_help(ct
)->help
.ct_h323_info
;
415 int dir
= CTINFO2DIR(ctinfo
);
416 u_int16_t nated_port
= ntohs(port
);
417 union nf_conntrack_address addr
;
419 /* Set expectations for NAT */
420 exp
->saved_proto
.tcp
.port
= exp
->tuple
.dst
.u
.tcp
.port
;
421 exp
->expectfn
= ip_nat_q931_expect
;
424 /* Check existing expects */
425 if (info
->sig_port
[dir
] == port
)
426 nated_port
= ntohs(info
->sig_port
[!dir
]);
428 /* Try to get same port: if not, try to change it. */
429 for (; nated_port
!= 0; nated_port
++) {
430 exp
->tuple
.dst
.u
.tcp
.port
= htons(nated_port
);
431 if (nf_ct_expect_related(exp
) == 0)
435 if (nated_port
== 0) { /* No port available */
437 printk("nf_nat_ras: out of TCP ports\n");
442 if (set_h225_addr(pskb
, data
, 0, &taddr
[idx
],
443 &ct
->tuplehash
[!dir
].tuple
.dst
.u3
,
444 htons(nated_port
)) == 0) {
446 info
->sig_port
[dir
] = port
;
447 info
->sig_port
[!dir
] = htons(nated_port
);
449 /* Fix for Gnomemeeting */
451 get_h225_addr(ct
, *data
, &taddr
[0], &addr
, &port
) &&
452 (ntohl(addr
.ip
) & 0xff000000) == 0x7f000000) {
453 set_h225_addr(pskb
, data
, 0, &taddr
[0],
454 &ct
->tuplehash
[!dir
].tuple
.dst
.u3
,
455 info
->sig_port
[!dir
]);
458 nf_ct_unexpect_related(exp
);
463 pr_debug("nf_nat_ras: expect Q.931 %u.%u.%u.%u:%hu->%u.%u.%u.%u:%hu\n",
464 NIPQUAD(exp
->tuple
.src
.u3
.ip
),
465 ntohs(exp
->tuple
.src
.u
.tcp
.port
),
466 NIPQUAD(exp
->tuple
.dst
.u3
.ip
),
467 ntohs(exp
->tuple
.dst
.u
.tcp
.port
));
472 /****************************************************************************/
473 static void ip_nat_callforwarding_expect(struct nf_conn
*new,
474 struct nf_conntrack_expect
*this)
476 struct nf_nat_range range
;
478 /* This must be a fresh one. */
479 BUG_ON(new->status
& IPS_NAT_DONE_MASK
);
481 /* Change src to where master sends to */
482 range
.flags
= IP_NAT_RANGE_MAP_IPS
;
483 range
.min_ip
= range
.max_ip
= new->tuplehash
[!this->dir
].tuple
.src
.u3
.ip
;
485 /* hook doesn't matter, but it has to do source manip */
486 nf_nat_setup_info(new, &range
, NF_IP_POST_ROUTING
);
488 /* For DST manip, map port here to where it's expected. */
489 range
.flags
= (IP_NAT_RANGE_MAP_IPS
| IP_NAT_RANGE_PROTO_SPECIFIED
);
490 range
.min
= range
.max
= this->saved_proto
;
491 range
.min_ip
= range
.max_ip
= this->saved_ip
;
493 /* hook doesn't matter, but it has to do destination manip */
494 nf_nat_setup_info(new, &range
, NF_IP_PRE_ROUTING
);
497 /****************************************************************************/
498 static int nat_callforwarding(struct sk_buff
**pskb
, struct nf_conn
*ct
,
499 enum ip_conntrack_info ctinfo
,
500 unsigned char **data
, int dataoff
,
501 TransportAddress
*taddr
, __be16 port
,
502 struct nf_conntrack_expect
*exp
)
504 int dir
= CTINFO2DIR(ctinfo
);
505 u_int16_t nated_port
;
507 /* Set expectations for NAT */
508 exp
->saved_ip
= exp
->tuple
.dst
.u3
.ip
;
509 exp
->tuple
.dst
.u3
.ip
= ct
->tuplehash
[!dir
].tuple
.dst
.u3
.ip
;
510 exp
->saved_proto
.tcp
.port
= exp
->tuple
.dst
.u
.tcp
.port
;
511 exp
->expectfn
= ip_nat_callforwarding_expect
;
514 /* Try to get same port: if not, try to change it. */
515 for (nated_port
= ntohs(port
); nated_port
!= 0; nated_port
++) {
516 exp
->tuple
.dst
.u
.tcp
.port
= htons(nated_port
);
517 if (nf_ct_expect_related(exp
) == 0)
521 if (nated_port
== 0) { /* No port available */
523 printk("nf_nat_q931: out of TCP ports\n");
528 if (!set_h225_addr(pskb
, data
, dataoff
, taddr
,
529 &ct
->tuplehash
[!dir
].tuple
.dst
.u3
,
530 htons(nated_port
)) == 0) {
531 nf_ct_unexpect_related(exp
);
536 pr_debug("nf_nat_q931: expect Call Forwarding "
537 "%u.%u.%u.%u:%hu->%u.%u.%u.%u:%hu\n",
538 NIPQUAD(exp
->tuple
.src
.u3
.ip
),
539 ntohs(exp
->tuple
.src
.u
.tcp
.port
),
540 NIPQUAD(exp
->tuple
.dst
.u3
.ip
),
541 ntohs(exp
->tuple
.dst
.u
.tcp
.port
));
546 /****************************************************************************/
547 static int __init
init(void)
549 BUG_ON(rcu_dereference(set_h245_addr_hook
) != NULL
);
550 BUG_ON(rcu_dereference(set_h225_addr_hook
) != NULL
);
551 BUG_ON(rcu_dereference(set_sig_addr_hook
) != NULL
);
552 BUG_ON(rcu_dereference(set_ras_addr_hook
) != NULL
);
553 BUG_ON(rcu_dereference(nat_rtp_rtcp_hook
) != NULL
);
554 BUG_ON(rcu_dereference(nat_t120_hook
) != NULL
);
555 BUG_ON(rcu_dereference(nat_h245_hook
) != NULL
);
556 BUG_ON(rcu_dereference(nat_callforwarding_hook
) != NULL
);
557 BUG_ON(rcu_dereference(nat_q931_hook
) != NULL
);
559 rcu_assign_pointer(set_h245_addr_hook
, set_h245_addr
);
560 rcu_assign_pointer(set_h225_addr_hook
, set_h225_addr
);
561 rcu_assign_pointer(set_sig_addr_hook
, set_sig_addr
);
562 rcu_assign_pointer(set_ras_addr_hook
, set_ras_addr
);
563 rcu_assign_pointer(nat_rtp_rtcp_hook
, nat_rtp_rtcp
);
564 rcu_assign_pointer(nat_t120_hook
, nat_t120
);
565 rcu_assign_pointer(nat_h245_hook
, nat_h245
);
566 rcu_assign_pointer(nat_callforwarding_hook
, nat_callforwarding
);
567 rcu_assign_pointer(nat_q931_hook
, nat_q931
);
571 /****************************************************************************/
572 static void __exit
fini(void)
574 rcu_assign_pointer(set_h245_addr_hook
, NULL
);
575 rcu_assign_pointer(set_h225_addr_hook
, NULL
);
576 rcu_assign_pointer(set_sig_addr_hook
, NULL
);
577 rcu_assign_pointer(set_ras_addr_hook
, NULL
);
578 rcu_assign_pointer(nat_rtp_rtcp_hook
, NULL
);
579 rcu_assign_pointer(nat_t120_hook
, NULL
);
580 rcu_assign_pointer(nat_h245_hook
, NULL
);
581 rcu_assign_pointer(nat_callforwarding_hook
, NULL
);
582 rcu_assign_pointer(nat_q931_hook
, NULL
);
586 /****************************************************************************/
590 MODULE_AUTHOR("Jing Min Zhao <zhaojingmin@users.sourceforge.net>");
591 MODULE_DESCRIPTION("H.323 NAT helper");
592 MODULE_LICENSE("GPL");
593 MODULE_ALIAS("ip_nat_h323");