diff --git a/source/firewall/firewall.c b/source/firewall/firewall.c index 950a7d9d..670bb54d 100644 --- a/source/firewall/firewall.c +++ b/source/firewall/firewall.c @@ -647,6 +647,9 @@ static char transparent_cache_state[10]; // state of the transparent http cache static char byoi_bridge_mode[10]; // whether or not byoi is in bridge mode static char cmdiag_enabled[20]; // If eCM diagnostic Interface Enabled static char firewall_level[20]; // None, Low, Medium, High, or Custom +char wireguard_enabled[4]; // Wireguard configuration +char wireguard_port[8]; +char wireguard_local_ipv6[128]; static char natip4[20]; static char captivePortalEnabled[50]; //to ccheck captive portal is enabled or not @@ -3098,7 +3101,20 @@ static int prepare_globals_from_configuration(void) rc = syscfg_get(NULL, "http_admin_port", reserved_mgmt_port, sizeof(reserved_mgmt_port)); if (0 != rc || '\0' == reserved_mgmt_port[0]) { snprintf(reserved_mgmt_port, sizeof(reserved_mgmt_port), "80"); - } + } + + wireguard_enabled[0] = '\0'; + rc = syscfg_get(NULL, "wireguard_enabled", wireguard_enabled, sizeof(wireguard_enabled)); + if (0 != rc || '\0' == wireguard_enabled[0]) { + snprintf(wireguard_enabled, sizeof(wireguard_enabled), "0"); + } + wireguard_port[0] = '\0'; + rc = syscfg_get(NULL, "Wireguard_Port", wireguard_port, sizeof(wireguard_port)); + if (0 != rc || '\0' == wireguard_port[0]) { + snprintf(wireguard_port, sizeof(wireguard_port), "53280"); + } + wireguard_local_ipv6[0] = '\0'; + syscfg_get(NULL, "wireguard_local_ipv6", wireguard_local_ipv6, sizeof(wireguard_local_ipv6)); /* Get DSCP value for gre */ if(bus_handle != NULL){ @@ -12475,6 +12491,14 @@ static int prepare_subtables(FILE *raw_fp, FILE *mangle_fp, FILE *nat_fp, FILE * fprintf(filter_fp, "-A FORWARD -j pp_disabled\n"); #endif + if(wireguard_enabled[0] == '1') { + fprintf(filter_fp, "-A FORWARD -o wg0 -j ACCEPT\n"); + fprintf(filter_fp, "-A FORWARD -i wg0 -j ACCEPT\n"); + fprintf(filter_fp, "-A INPUT -i wg0 -j ACCEPT\n"); + fprintf(filter_fp, "-A OUTPUT -o wg0 -j ACCEPT\n"); + fprintf(filter_fp, "-A INPUT -i erouter0 -p udp --dport %s -j ACCEPT\n",wireguard_port); + } + fprintf(filter_fp, ":%s - [0:0]\n", "lan2wan"); #ifdef CONFIG_CISCO_FEATURE_CISCOCONNECT diff --git a/source/firewall/firewall.h b/source/firewall/firewall.h index abfd63c3..da5bd960 100644 --- a/source/firewall/firewall.h +++ b/source/firewall/firewall.h @@ -963,6 +963,9 @@ extern token_t sysevent_token; extern char *sysevent_name; extern int syslog_level; extern char firewall_levelv6[20]; +extern char wireguard_enabled[4]; +extern char wireguard_port[8]; +extern char wireguard_local_ipv6[128]; extern int isWanPingDisableV6; extern int isHttpBlockedV6; extern int isP2pBlockedV6; diff --git a/source/firewall/firewall_ipv6.c b/source/firewall/firewall_ipv6.c index 830e9f73..0783c482 100644 --- a/source/firewall/firewall_ipv6.c +++ b/source/firewall/firewall_ipv6.c @@ -553,6 +553,14 @@ void do_ipv6_filter_table(FILE *fp){ fprintf(fp, "-A FORWARD -i a-mux -j ACCEPT\n"); #endif + /* WireGuard IPv6 (mirror IPv4): handshake + tunnel forward. + * INPUT UDP must beat wan2self's "-p udp -j DROP". */ + if (wireguard_enabled[0] == '1') { + fprintf(fp, "-I FORWARD -i wg0 -j ACCEPT\n"); + fprintf(fp, "-I FORWARD -o wg0 -j ACCEPT\n"); + fprintf(fp, "-I INPUT -i erouter0 -p udp --dport %s -j ACCEPT\n", wireguard_port); + } + fprintf(fp, ":%s - [0:0]\n", "LOG_INPUT_DROP"); fprintf(fp, ":%s - [0:0]\n", "LOG_FORWARD_DROP"); if(isComcastImage) { @@ -2376,6 +2384,12 @@ void do_ipv6_nat_table(FILE* fp) fprintf(fp, "-A POSTROUTING -o %s -j MASQUERADE\n", current_wan_ifname); #endif + /* WireGuard: NAT tunnel traffic to WAN so full-tunnel clients reach internet */ + if (wireguard_enabled[0] == '1' && wireguard_local_ipv6[0] != '\0') { + fprintf(fp, "-I POSTROUTING -o erouter0 -s %s/64 -j MASQUERADE\n", + wireguard_local_ipv6); + } + FIREWALL_DEBUG("Exiting do_ipv6_nat_table \n"); }