1 /* Shared library add-on to iptables to add TTL matching support
2 * (C) 2000 by Harald Welte <laforge@gnumonks.org>
4 * $Id: libipt_ttl.c 4544 2005-11-18 17:59:56Z /C=DE/ST=Berlin/L=Berlin/O=Netfilter Project/OU=Development/CN=kaber/emailAddress=kaber@netfilter.org $
6 * This program is released under the terms of GNU GPL */
14 #include <linux/netfilter_ipv4/ip_tables.h>
15 #include <linux/netfilter_ipv4/ipt_ttl.h>
17 static void help(void)
20 "TTL match v%s options:\n"
21 " --ttl-eq value Match time to live value\n"
22 " --ttl-lt value Match TTL < value\n"
23 " --ttl-gt value Match TTL > value\n"
27 static int parse(int c
, char **argv
, int invert
, unsigned int *flags
,
28 const struct ipt_entry
*entry
, unsigned int *nfcache
,
29 struct ipt_entry_match
**match
)
31 struct ipt_ttl_info
*info
= (struct ipt_ttl_info
*) (*match
)->data
;
34 check_inverse(optarg
, &invert
, &optind
, 0);
38 if (string_to_number(optarg
, 0, 255, &value
) == -1)
39 exit_error(PARAMETER_PROBLEM
,
40 "ttl: Expected value between 0 and 255");
43 info
->mode
= IPT_TTL_NE
;
45 info
->mode
= IPT_TTL_EQ
;
51 if (string_to_number(optarg
, 0, 255, &value
) == -1)
52 exit_error(PARAMETER_PROBLEM
,
53 "ttl: Expected value between 0 and 255");
56 exit_error(PARAMETER_PROBLEM
,
57 "ttl: unexpected `!'");
59 info
->mode
= IPT_TTL_LT
;
63 if (string_to_number(optarg
, 0, 255, &value
) == -1)
64 exit_error(PARAMETER_PROBLEM
,
65 "ttl: Expected value between 0 and 255");
68 exit_error(PARAMETER_PROBLEM
,
69 "ttl: unexpected `!'");
71 info
->mode
= IPT_TTL_GT
;
80 exit_error(PARAMETER_PROBLEM
,
81 "Can't specify TTL option twice");
87 static void final_check(unsigned int flags
)
90 exit_error(PARAMETER_PROBLEM
,
91 "TTL match: You must specify one of "
92 "`--ttl-eq', `--ttl-lt', `--ttl-gt");
95 static void print(const struct ipt_ip
*ip
,
96 const struct ipt_entry_match
*match
,
99 const struct ipt_ttl_info
*info
=
100 (struct ipt_ttl_info
*) match
->data
;
102 printf("TTL match ");
103 switch (info
->mode
) {
117 printf("%u ", info
->ttl
);
120 static void save(const struct ipt_ip
*ip
,
121 const struct ipt_entry_match
*match
)
123 const struct ipt_ttl_info
*info
=
124 (struct ipt_ttl_info
*) match
->data
;
126 switch (info
->mode
) {
131 printf("! --ttl-eq ");
143 printf("%u ", info
->ttl
);
146 static struct option opts
[] = {
147 { "ttl", 1, 0, '2' },
148 { "ttl-eq", 1, 0, '2'},
149 { "ttl-lt", 1, 0, '3'},
150 { "ttl-gt", 1, 0, '4'},
154 static struct iptables_match ttl
= {
157 .version
= IPTABLES_VERSION
,
158 .size
= IPT_ALIGN(sizeof(struct ipt_ttl_info
)),
159 .userspacesize
= IPT_ALIGN(sizeof(struct ipt_ttl_info
)),
162 .final_check
= &final_check
,
171 register_match(&ttl
);