1*b525cd90Schristos /* $NetBSD: pf.c,v 1.3 2016/12/10 05:43:11 christos Exp $ */
2f90aa792Speter
3f90aa792Speter /*
4f90aa792Speter * pf.c - NAT lookup code for pf.
5f90aa792Speter *
6f90aa792Speter * This software is in the public domain.
7f90aa792Speter * Written by Peter Postma <peter@NetBSD.org>
8f90aa792Speter */
9f90aa792Speter
10f1cc4662Speter #include <sys/cdefs.h>
11*b525cd90Schristos __RCSID("$NetBSD: pf.c,v 1.3 2016/12/10 05:43:11 christos Exp $");
12f1cc4662Speter
13f90aa792Speter #include <sys/types.h>
14f90aa792Speter #include <sys/socket.h>
15f90aa792Speter #include <sys/ioctl.h>
16f90aa792Speter #include <sys/fcntl.h>
17f90aa792Speter
18f90aa792Speter #include <net/if.h>
19f90aa792Speter #include <netinet/in.h>
20f90aa792Speter #include <net/pfvar.h>
21f90aa792Speter
22f90aa792Speter #include <stdlib.h>
23f90aa792Speter #include <string.h>
24f90aa792Speter #include <syslog.h>
25f90aa792Speter #include <unistd.h>
26f90aa792Speter
27f90aa792Speter #include "identd.h"
28f90aa792Speter
29f90aa792Speter int
pf_natlookup(const struct sockaddr_storage * ss,struct sockaddr_storage * nat_addr,in_port_t * nat_lport)30*b525cd90Schristos pf_natlookup(const struct sockaddr_storage *ss,
31*b525cd90Schristos struct sockaddr_storage *nat_addr, in_port_t *nat_lport)
32f90aa792Speter {
33f90aa792Speter struct pfioc_natlook nl;
34f90aa792Speter int dev;
35f90aa792Speter
36f90aa792Speter (void)memset(&nl, 0, sizeof(nl));
37f90aa792Speter
38f90aa792Speter /* Build the pf natlook structure. */
39f90aa792Speter switch (ss[0].ss_family) {
40f90aa792Speter case AF_INET:
41*b525cd90Schristos (void)memcpy(&nl.daddr.v4, &csatosin(&ss[0])->sin_addr,
42f90aa792Speter sizeof(struct in_addr));
43*b525cd90Schristos (void)memcpy(&nl.saddr.v4, &csatosin(&ss[1])->sin_addr,
44f90aa792Speter sizeof(struct in_addr));
45*b525cd90Schristos nl.dport = csatosin(&ss[0])->sin_port;
46*b525cd90Schristos nl.sport = csatosin(&ss[1])->sin_port;
47f90aa792Speter nl.af = AF_INET;
48f90aa792Speter nl.proto = IPPROTO_TCP;
49f90aa792Speter nl.direction = PF_IN;
50f90aa792Speter break;
51f90aa792Speter case AF_INET6:
52*b525cd90Schristos (void)memcpy(&nl.daddr.v6, &csatosin6(&ss[0])->sin6_addr,
53f90aa792Speter sizeof(struct in6_addr));
54*b525cd90Schristos (void)memcpy(&nl.saddr.v6, &csatosin6(&ss[1])->sin6_addr,
55f90aa792Speter sizeof(struct in6_addr));
56*b525cd90Schristos nl.dport = csatosin6(&ss[0])->sin6_port;
57*b525cd90Schristos nl.sport = csatosin6(&ss[1])->sin6_port;
58f90aa792Speter nl.af = AF_INET6;
59f90aa792Speter nl.proto = IPPROTO_TCP;
60f90aa792Speter nl.direction = PF_IN;
61f90aa792Speter break;
62f90aa792Speter default:
63f90aa792Speter maybe_syslog(LOG_ERR, "Unsupported protocol for NAT lookup "
64f90aa792Speter "(no. %d)", ss[0].ss_family);
65f90aa792Speter return 0;
66f90aa792Speter }
67f90aa792Speter
68f90aa792Speter /* Open the /dev/pf device and do the lookup. */
69f90aa792Speter if ((dev = open("/dev/pf", O_RDWR)) == -1) {
70f90aa792Speter maybe_syslog(LOG_ERR, "Cannot open /dev/pf: %m");
71f90aa792Speter return 0;
72f90aa792Speter }
73f90aa792Speter if (ioctl(dev, DIOCNATLOOK, &nl) == -1) {
74f90aa792Speter maybe_syslog(LOG_ERR, "NAT lookup failure: %m");
75f90aa792Speter (void)close(dev);
76f90aa792Speter return 0;
77f90aa792Speter }
78f90aa792Speter (void)close(dev);
79f90aa792Speter
80f90aa792Speter /*
81f90aa792Speter * Put the originating address into nat_addr and fill
82f90aa792Speter * the port with the ident port, 113.
83f90aa792Speter */
84f90aa792Speter switch (ss[0].ss_family) {
85f90aa792Speter case AF_INET:
86f90aa792Speter (void)memcpy(&satosin(nat_addr)->sin_addr, &nl.rsaddr.v4,
87f90aa792Speter sizeof(struct in_addr));
88f90aa792Speter satosin(nat_addr)->sin_port = htons(113);
89f90aa792Speter satosin(nat_addr)->sin_len = sizeof(struct sockaddr_in);
90f90aa792Speter satosin(nat_addr)->sin_family = AF_INET;
91f90aa792Speter break;
92f90aa792Speter case AF_INET6:
93f90aa792Speter (void)memcpy(&satosin6(nat_addr)->sin6_addr, &nl.rsaddr.v6,
94f90aa792Speter sizeof(struct in6_addr));
95f90aa792Speter satosin6(nat_addr)->sin6_port = htons(113);
96f90aa792Speter satosin6(nat_addr)->sin6_len = sizeof(struct sockaddr_in6);
97f90aa792Speter satosin6(nat_addr)->sin6_family = AF_INET6;
98f90aa792Speter break;
99f90aa792Speter }
100f90aa792Speter /* Put the originating port into nat_lport. */
101f90aa792Speter *nat_lport = nl.rsport;
102f90aa792Speter
103f90aa792Speter return 1;
104f90aa792Speter }
105