Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 25 additions & 1 deletion source/firewall/firewall.c
Original file line number Diff line number Diff line change
Expand Up @@ -647,6 +647,9 @@ static char transparent_cache_state[10]; // state of the transparent http cache
static char byoi_bridge_mode[10]; // whether or not byoi is in bridge mode
static char cmdiag_enabled[20]; // If eCM diagnostic Interface Enabled
static char firewall_level[20]; // None, Low, Medium, High, or Custom
char wireguard_enabled[4]; // Wireguard configuration
char wireguard_port[8];
char wireguard_local_ipv6[128];
static char natip4[20];
static char captivePortalEnabled[50]; //to ccheck captive portal is enabled or not

Expand Down Expand Up @@ -3098,7 +3101,20 @@ static int prepare_globals_from_configuration(void)
rc = syscfg_get(NULL, "http_admin_port", reserved_mgmt_port, sizeof(reserved_mgmt_port));
if (0 != rc || '\0' == reserved_mgmt_port[0]) {
snprintf(reserved_mgmt_port, sizeof(reserved_mgmt_port), "80");
}
}

wireguard_enabled[0] = '\0';
rc = syscfg_get(NULL, "wireguard_enabled", wireguard_enabled, sizeof(wireguard_enabled));
if (0 != rc || '\0' == wireguard_enabled[0]) {
snprintf(wireguard_enabled, sizeof(wireguard_enabled), "0");
}
wireguard_port[0] = '\0';
rc = syscfg_get(NULL, "Wireguard_Port", wireguard_port, sizeof(wireguard_port));
if (0 != rc || '\0' == wireguard_port[0]) {
snprintf(wireguard_port, sizeof(wireguard_port), "53280");
}
Comment on lines +3111 to +3115
wireguard_local_ipv6[0] = '\0';
syscfg_get(NULL, "wireguard_local_ipv6", wireguard_local_ipv6, sizeof(wireguard_local_ipv6));

/* Get DSCP value for gre */
if(bus_handle != NULL){
Expand Down Expand Up @@ -12475,6 +12491,14 @@ static int prepare_subtables(FILE *raw_fp, FILE *mangle_fp, FILE *nat_fp, FILE *
fprintf(filter_fp, "-A FORWARD -j pp_disabled\n");
#endif

if(wireguard_enabled[0] == '1') {
fprintf(filter_fp, "-A FORWARD -o wg0 -j ACCEPT\n");
fprintf(filter_fp, "-A FORWARD -i wg0 -j ACCEPT\n");
fprintf(filter_fp, "-A INPUT -i wg0 -j ACCEPT\n");
fprintf(filter_fp, "-A OUTPUT -o wg0 -j ACCEPT\n");
fprintf(filter_fp, "-A INPUT -i erouter0 -p udp --dport %s -j ACCEPT\n",wireguard_port);
}

fprintf(filter_fp, ":%s - [0:0]\n", "lan2wan");

#ifdef CONFIG_CISCO_FEATURE_CISCOCONNECT
Expand Down
3 changes: 3 additions & 0 deletions source/firewall/firewall.h
Original file line number Diff line number Diff line change
Expand Up @@ -963,6 +963,9 @@ extern token_t sysevent_token;
extern char *sysevent_name;
extern int syslog_level;
extern char firewall_levelv6[20];
extern char wireguard_enabled[4];
extern char wireguard_port[8];
extern char wireguard_local_ipv6[128];
extern int isWanPingDisableV6;
extern int isHttpBlockedV6;
extern int isP2pBlockedV6;
Expand Down
14 changes: 14 additions & 0 deletions source/firewall/firewall_ipv6.c
Original file line number Diff line number Diff line change
Expand Up @@ -553,6 +553,14 @@ void do_ipv6_filter_table(FILE *fp){
fprintf(fp, "-A FORWARD -i a-mux -j ACCEPT\n");
#endif

/* WireGuard IPv6 (mirror IPv4): handshake + tunnel forward.
* INPUT UDP must beat wan2self's "-p udp -j DROP". */
if (wireguard_enabled[0] == '1') {
fprintf(fp, "-I FORWARD -i wg0 -j ACCEPT\n");
fprintf(fp, "-I FORWARD -o wg0 -j ACCEPT\n");
fprintf(fp, "-I INPUT -i erouter0 -p udp --dport %s -j ACCEPT\n", wireguard_port);
}
Comment on lines +559 to +562

fprintf(fp, ":%s - [0:0]\n", "LOG_INPUT_DROP");
fprintf(fp, ":%s - [0:0]\n", "LOG_FORWARD_DROP");
if(isComcastImage) {
Expand Down Expand Up @@ -2376,6 +2384,12 @@ void do_ipv6_nat_table(FILE* fp)
fprintf(fp, "-A POSTROUTING -o %s -j MASQUERADE\n", current_wan_ifname);
#endif

/* WireGuard: NAT tunnel traffic to WAN so full-tunnel clients reach internet */
if (wireguard_enabled[0] == '1' && wireguard_local_ipv6[0] != '\0') {
fprintf(fp, "-I POSTROUTING -o erouter0 -s %s/64 -j MASQUERADE\n",
wireguard_local_ipv6);
}
Comment on lines +2387 to +2391

FIREWALL_DEBUG("Exiting do_ipv6_nat_table \n");
}

Expand Down
Loading