]>
Commit | Line | Data |
---|---|---|
52b7d2ce A |
1 | /* |
2 | * Copyright (C) 2004 SuSE Linux AG, Nuernberg, Germany. | |
3 | * Contributed by: Michal Ludvig <mludvig@suse.cz>, SUSE Labs | |
4 | * All rights reserved. | |
5 | * | |
6 | * Redistribution and use in source and binary forms, with or without | |
7 | * modification, are permitted provided that the following conditions | |
8 | * are met: | |
9 | * 1. Redistributions of source code must retain the above copyright | |
10 | * notice, this list of conditions and the following disclaimer. | |
11 | * 2. Redistributions in binary form must reproduce the above copyright | |
12 | * notice, this list of conditions and the following disclaimer in the | |
13 | * documentation and/or other materials provided with the distribution. | |
14 | * 3. Neither the name of the project nor the names of its contributors | |
15 | * may be used to endorse or promote products derived from this software | |
16 | * without specific prior written permission. | |
17 | * | |
18 | * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND | |
19 | * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE | |
20 | * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE | |
21 | * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE | |
22 | * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL | |
23 | * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS | |
24 | * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) | |
25 | * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT | |
26 | * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY | |
27 | * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF | |
28 | * SUCH DAMAGE. | |
29 | */ | |
30 | ||
31 | #ifndef _NATTRAVERSAL_H | |
32 | #define _NATTRAVERSAL_H | |
33 | ||
34 | #include "vendorid.h" | |
35 | ||
36 | #ifdef __APPLE__ | |
37 | #define UDP_ENCAP_ESPINUDP 2 /* to make it compile - we don't use this */ | |
38 | #endif | |
39 | ||
40 | #define NAT_ANNOUNCED (1L<<0) | |
41 | #define NAT_DETECTED_ME (1L<<1) | |
42 | #define NAT_DETECTED_PEER (1L<<2) | |
43 | #define NAT_PORTS_CHANGED (1L<<3) | |
44 | #define NAT_KA_QUEUED (1L<<4) | |
45 | #define NAT_ADD_NON_ESP_MARKER (1L<<5) | |
46 | ||
47 | #define NATT_AVAILABLE(ph1) ((iph1)->natt_flags & NAT_ANNOUNCED) | |
48 | ||
49 | #define NAT_DETECTED (NAT_DETECTED_ME | NAT_DETECTED_PEER) | |
50 | ||
51 | #define NON_ESP_MARKER_LEN sizeof(u_int32_t) | |
52 | #define NON_ESP_MARKER_USE(iph1) ((iph1)->natt_flags & NAT_ADD_NON_ESP_MARKER) | |
53 | ||
d1e348cf A |
54 | #ifdef ENABLE_NATT |
55 | #ifdef ENABLE_FRAG | |
56 | #define PH1_NON_ESP_EXTRA_LEN(iph1) ((iph1->frag && iph1->sendbuf->l > ISAKMP_FRAG_MAXLEN) ? 0: (NON_ESP_MARKER_USE(iph1) ? NON_ESP_MARKER_LEN : 0)) | |
57 | #define PH2_NON_ESP_EXTRA_LEN(iph2) ((iph2->ph1->frag && iph2->sendbuf->l > ISAKMP_FRAG_MAXLEN) ? 0: (NON_ESP_MARKER_USE(iph2->ph1) ? NON_ESP_MARKER_LEN : 0)) | |
58 | #else | |
59 | #define PH1_NON_ESP_EXTRA_LEN(iph1) (NON_ESP_MARKER_USE(iph1) ? NON_ESP_MARKER_LEN : 0) | |
60 | #define PH2_NON_ESP_EXTRA_LEN(iph2) (NON_ESP_MARKER_USE(iph2->ph1) ? NON_ESP_MARKER_LEN : 0) | |
61 | #endif | |
62 | #else | |
63 | #define PH1_NON_ESP_EXTRA_LEN(iph1) 0 | |
64 | #define PH2_NON_ESP_EXTRA_LEN(iph2) 0 | |
65 | #endif | |
66 | ||
52b7d2ce A |
67 | /* These are the values from parsing "remote {}" |
68 | block of the config file. */ | |
69 | #define NATT_OFF FALSE /* = 0 */ | |
70 | #define NATT_ON TRUE /* = 1 */ | |
71 | #define NATT_FORCE 2 | |
72 | ||
73 | struct ph1natt_options { | |
74 | int version; | |
75 | u_int16_t float_port; | |
76 | u_int16_t mode_udp_tunnel; | |
77 | u_int16_t mode_udp_transport; | |
78 | u_int16_t encaps_type; /* ESPINUDP / ESPINUDP_NON_IKE */ | |
79 | u_int16_t mode_udp_diff; | |
80 | u_int16_t payload_nat_d; | |
81 | u_int16_t payload_nat_oa; | |
82 | }; | |
83 | ||
84 | struct ph2natt { | |
85 | u_int8_t type; | |
86 | u_int16_t sport; | |
87 | u_int16_t dport; | |
88 | struct sockaddr *oa; | |
89 | u_int16_t frag; | |
90 | }; | |
91 | ||
92 | int natt_vendorid (int vid); | |
93 | vchar_t *natt_hash_addr (struct ph1handle *iph1, struct sockaddr *addr); | |
94 | int natt_compare_addr_hash (struct ph1handle *iph1, vchar_t *natd_received, int natd_seq); | |
95 | int natt_udp_encap (int encmode); | |
96 | int natt_fill_options (struct ph1natt_options *opts, int version); | |
97 | void natt_float_ports (struct ph1handle *iph1); | |
98 | void natt_handle_vendorid (struct ph1handle *iph1, int vid_numeric); | |
52b7d2ce | 99 | int create_natoa_payloads(struct ph2handle *iph2, vchar_t **, vchar_t **); |
d1e348cf | 100 | struct sockaddr * process_natoa_payload(vchar_t *buf); |
52b7d2ce A |
101 | |
102 | struct payload_list * | |
103 | isakmp_plist_append_natt_vids (struct payload_list *plist, vchar_t *vid_natt[MAX_NATT_VID_COUNT]); | |
104 | ||
105 | #ifndef __APPLE__ | |
106 | /* NAT keepalive functions */ | |
107 | void natt_keepalive_init (void); | |
108 | int natt_keepalive_add (struct sockaddr *src, struct sockaddr *dst); | |
109 | int natt_keepalive_add_ph1 (struct ph1handle *iph1); | |
110 | void natt_keepalive_remove (struct sockaddr *src, struct sockaddr *dst); | |
111 | #endif | |
112 | ||
113 | /* Walk through all rmconfigs and tell if NAT-T is enabled in at least one. */ | |
114 | int natt_enabled_in_rmconf (void); | |
115 | ||
116 | #endif /* _NATTRAVERSAL_H */ |