1 |
3ad6d3bb
|
Bill Marquette
|
<?php
|
2 |
577c9191
|
Bill Marquette
|
/* $Id$ */
|
3 |
3ad6d3bb
|
Bill Marquette
|
/*
|
4 |
17623ab5
|
Bill Marquette
|
vslb.inc
|
5 |
|
|
Copyright (C) 2005-2008 Bill Marquette
|
6 |
|
|
All rights reserved.
|
7 |
3ad6d3bb
|
Bill Marquette
|
|
8 |
17623ab5
|
Bill Marquette
|
Redistribution and use in source and binary forms, with or without
|
9 |
|
|
modification, are permitted provided that the following conditions are met:
|
10 |
3ad6d3bb
|
Bill Marquette
|
|
11 |
17623ab5
|
Bill Marquette
|
1. Redistributions of source code must retain the above copyright notice,
|
12 |
|
|
this list of conditions and the following disclaimer.
|
13 |
3ad6d3bb
|
Bill Marquette
|
|
14 |
17623ab5
|
Bill Marquette
|
2. Redistributions in binary form must reproduce the above copyright
|
15 |
|
|
notice, this list of conditions and the following disclaimer in the
|
16 |
|
|
documentation and/or other materials provided with the distribution.
|
17 |
3ad6d3bb
|
Bill Marquette
|
|
18 |
17623ab5
|
Bill Marquette
|
THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES,
|
19 |
|
|
INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY
|
20 |
|
|
AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
|
21 |
|
|
AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY,
|
22 |
|
|
OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
|
23 |
|
|
SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
|
24 |
|
|
INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
|
25 |
|
|
CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
26 |
|
|
ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
|
27 |
|
|
POSSIBILITY OF SUCH DAMAGE.
|
28 |
3ad6d3bb
|
Bill Marquette
|
|
29 |
17623ab5
|
Bill Marquette
|
*/
|
30 |
3ad6d3bb
|
Bill Marquette
|
|
31 |
523855b0
|
Scott Ullrich
|
/*
|
32 |
|
|
pfSense_BUILDER_BINARIES: /usr/local/sbin/relayd
|
33 |
|
|
pfSense_MODULE: routing
|
34 |
|
|
*/
|
35 |
|
|
|
36 |
50d86c13
|
Bill Marquette
|
/* DISABLE_PHP_LINT_CHECKING */
|
37 |
|
|
|
38 |
3ad6d3bb
|
Bill Marquette
|
/* include all configuration functions */
|
39 |
|
|
|
40 |
50d86c13
|
Bill Marquette
|
class Monitor {
|
41 |
|
|
private $conf = array();
|
42 |
|
|
function __construct($config) {
|
43 |
|
|
$this->conf = $config;
|
44 |
|
|
}
|
45 |
|
|
|
46 |
|
|
public function p() {
|
47 |
|
|
return "check {$this->get('proto')}";
|
48 |
|
|
}
|
49 |
|
|
private function get($var) {
|
50 |
|
|
return isset($this->$var) ? $this->$var : "";
|
51 |
|
|
}
|
52 |
|
|
protected function config($element) {
|
53 |
|
|
return isset($this->conf[$element]) ? $this->conf[$element] : "";
|
54 |
|
|
}
|
55 |
|
|
}
|
56 |
|
|
|
57 |
|
|
class TCPMonitor extends Monitor {
|
58 |
|
|
protected $proto = 'tcp';
|
59 |
|
|
}
|
60 |
|
|
|
61 |
|
|
class SSLMonitor extends Monitor {
|
62 |
|
|
protected $proto = 'ssl';
|
63 |
|
|
}
|
64 |
|
|
|
65 |
|
|
class ICMPMonitor extends Monitor {
|
66 |
|
|
protected $proto = 'icmp';
|
67 |
|
|
}
|
68 |
|
|
|
69 |
|
|
class HTTPMonitor extends Monitor {
|
70 |
|
|
protected $proto = 'http';
|
71 |
|
|
function __construct($config) {
|
72 |
|
|
parent::__construct($config);
|
73 |
|
|
}
|
74 |
|
|
public function p() {
|
75 |
|
|
$method = ($this->code() != "") ? $this->code() : $this->digest();
|
76 |
|
|
return "check {$this->proto} {$this->path()} {$this->host()} {$method}";
|
77 |
|
|
}
|
78 |
|
|
|
79 |
|
|
private function path() {
|
80 |
|
|
return $this->config('path') != "" ? "'{$this->config('path')}'" : "";
|
81 |
|
|
}
|
82 |
|
|
|
83 |
|
|
private function host() {
|
84 |
|
|
return $this->config('host') != "" ? "host {$this->config('host')}" : "";
|
85 |
|
|
}
|
86 |
|
|
|
87 |
|
|
private function code() {
|
88 |
|
|
return $this->config('code') != "" ? "code {$this->config('code')}" : "";
|
89 |
|
|
}
|
90 |
|
|
|
91 |
|
|
private function digest() {
|
92 |
|
|
return $this->config('digest') != "" ? "digest {$this->config('digest')}" : "";
|
93 |
|
|
}
|
94 |
|
|
}
|
95 |
|
|
|
96 |
|
|
class HTTPSMonitor extends HTTPMonitor {
|
97 |
|
|
protected $proto = 'https';
|
98 |
|
|
}
|
99 |
|
|
|
100 |
|
|
class SendMonitor extends Monitor {
|
101 |
|
|
private $proto = 'send';
|
102 |
|
|
function __construct($config) {
|
103 |
|
|
parent::__construct($config);
|
104 |
|
|
}
|
105 |
|
|
public function p() {
|
106 |
|
|
return "check {$this->proto} {$this->data()} expect {$this->pattern()} {$this->ssl()}";
|
107 |
|
|
}
|
108 |
|
|
|
109 |
|
|
|
110 |
|
|
private function data() {
|
111 |
|
|
return $this->config('send') != "" ? "{$this->config('send')}" : "";
|
112 |
|
|
}
|
113 |
|
|
|
114 |
|
|
private function pattern() {
|
115 |
|
|
return $this->config('expect') != "" ? "{$this->config('expect')}" : "";
|
116 |
|
|
}
|
117 |
|
|
|
118 |
|
|
private function ssl() {
|
119 |
|
|
return $this->config('ssl') == true ? "ssl" : "";
|
120 |
|
|
}
|
121 |
|
|
}
|
122 |
|
|
|
123 |
0919224f
|
Bill Marquette
|
function echo_lbaction($action) {
|
124 |
|
|
global $config;
|
125 |
|
|
|
126 |
|
|
// Index actions by name
|
127 |
|
|
$actions_a = array();
|
128 |
|
|
for ($i=0; isset($config['load_balancer']['lbaction'][$i]); $i++)
|
129 |
|
|
$actions_a[$config['load_balancer']['lbaction'][$i]['name']] = $config['load_balancer']['lbaction'][$i];
|
130 |
|
|
|
131 |
|
|
$ret = "";
|
132 |
|
|
$ret .= "{$actions_a[$action]['direction']} {$actions_a[$action]['type']} {$actions_a[$action]['action']}";
|
133 |
|
|
switch($actions_a[$action]['action']) {
|
134 |
|
|
case 'append': {
|
135 |
|
|
$ret .= " \"{$actions_a[$action]['options']['value']}\" to \"{$actions_a[$action]['options']['akey']}\"";
|
136 |
|
|
break;
|
137 |
|
|
}
|
138 |
|
|
case 'change': {
|
139 |
|
|
$ret .= " \"{$actions_a[$action]['options']['akey']}\" to \"{$actions_a[$action]['options']['value']}\"";
|
140 |
|
|
break;
|
141 |
|
|
}
|
142 |
|
|
case 'expect': {
|
143 |
|
|
$ret .= " \"{$actions_a[$action]['options']['value']}\" from \"{$actions_a[$action]['options']['akey']}\"";
|
144 |
|
|
break;
|
145 |
|
|
}
|
146 |
|
|
case 'filter': {
|
147 |
|
|
$ret .= " \"{$actions_a[$action]['options']['value']}\" from \"{$actions_a[$action]['options']['akey']}\"";
|
148 |
|
|
break;
|
149 |
|
|
}
|
150 |
|
|
case 'hash': {
|
151 |
|
|
$ret .= " \"{$actions_a[$action]['options']['akey']}\"";
|
152 |
|
|
break;
|
153 |
|
|
}
|
154 |
|
|
case 'log': {
|
155 |
|
|
$ret .= " \"{$actions_a[$action]['options']['akey']}\"";
|
156 |
|
|
break;
|
157 |
|
|
}
|
158 |
|
|
}
|
159 |
|
|
return $ret;
|
160 |
|
|
}
|
161 |
50d86c13
|
Bill Marquette
|
|
162 |
17623ab5
|
Bill Marquette
|
function relayd_configure() {
|
163 |
|
|
global $config, $g;
|
164 |
|
|
|
165 |
a825c6f7
|
Bill Marquette
|
$vs_a = $config['load_balancer']['virtual_server'];
|
166 |
|
|
$pool_a = $config['load_balancer']['lbpool'];
|
167 |
|
|
$protocol_a = $config['load_balancer']['lbprotocol'];
|
168 |
17623ab5
|
Bill Marquette
|
|
169 |
50d86c13
|
Bill Marquette
|
$check_a = array();
|
170 |
|
|
|
171 |
52bd375c
|
Bill Marquette
|
foreach ((array)$config['load_balancer']['monitor_type'] as $type) {
|
172 |
50d86c13
|
Bill Marquette
|
switch($type['type']) {
|
173 |
|
|
case 'icmp': {
|
174 |
|
|
$mon = new ICMPMonitor($type['options']);
|
175 |
|
|
break;
|
176 |
|
|
}
|
177 |
|
|
case 'tcp': {
|
178 |
|
|
$mon = new TCPMonitor($type['options']);
|
179 |
|
|
break;
|
180 |
|
|
}
|
181 |
|
|
case 'http': {
|
182 |
|
|
$mon = new HTTPMonitor($type['options']);
|
183 |
|
|
break;
|
184 |
|
|
}
|
185 |
|
|
case 'https': {
|
186 |
|
|
$mon = new HTTPSMonitor($type['options']);
|
187 |
|
|
break;
|
188 |
|
|
}
|
189 |
|
|
case 'send': {
|
190 |
|
|
$mon = new SendMonitor($type['options']);
|
191 |
|
|
break;
|
192 |
|
|
}
|
193 |
|
|
}
|
194 |
596a3aba
|
Seth Mos
|
if($mon) {
|
195 |
|
|
$check_a[$type['name']] = $mon->p();
|
196 |
|
|
}
|
197 |
50d86c13
|
Bill Marquette
|
}
|
198 |
|
|
|
199 |
|
|
|
200 |
17623ab5
|
Bill Marquette
|
$fd = fopen("{$g['varetc_path']}/relayd.conf", "w");
|
201 |
|
|
|
202 |
|
|
/* reindex pools by name as we loop through the pools array */
|
203 |
|
|
$pools = array();
|
204 |
|
|
/* Virtual server pools */
|
205 |
|
|
if(is_array($pool_a)) {
|
206 |
|
|
for ($i = 0; isset($pool_a[$i]); $i++) {
|
207 |
|
|
if(is_array($pool_a[$i]['servers'])) {
|
208 |
|
|
$srvtxt = implode(", ", $pool_a[$i]['servers']);
|
209 |
|
|
$conf .= "table <{$pool_a[$i]['name']}> { $srvtxt }\n";
|
210 |
|
|
/* Index by name for easier fetching when we loop through the virtual servers */
|
211 |
|
|
$pools[$pool_a[$i]['name']] = $pool_a[$i];
|
212 |
|
|
}
|
213 |
|
|
}
|
214 |
|
|
}
|
215 |
0919224f
|
Bill Marquette
|
if(is_array($protocol_a)) {
|
216 |
|
|
for ($i = 0; isset($protocol_a[$i]); $i++) {
|
217 |
ab9c7767
|
Bill Marquette
|
$proto = "{$protocol_a[$i]['type']} protocol \"{$protocol_a[$i]['name']}\" {\n";
|
218 |
0919224f
|
Bill Marquette
|
if(is_array($protocol_a[$i]['lbaction'])) {
|
219 |
ab9c7767
|
Bill Marquette
|
if($protocol_a[$i]['lbaction'][0] == "") {
|
220 |
|
|
continue;
|
221 |
|
|
}
|
222 |
0919224f
|
Bill Marquette
|
for ($a = 0; isset($protocol_a[$i]['lbaction'][$a]); $a++) {
|
223 |
ab9c7767
|
Bill Marquette
|
$proto .= " " . echo_lbaction($protocol_a[$i]['lbaction'][$a]) . "\n";
|
224 |
0919224f
|
Bill Marquette
|
}
|
225 |
|
|
}
|
226 |
ab9c7767
|
Bill Marquette
|
$proto .= "}\n";
|
227 |
|
|
$conf .= $proto;
|
228 |
0919224f
|
Bill Marquette
|
}
|
229 |
|
|
}
|
230 |
17623ab5
|
Bill Marquette
|
if(is_array($vs_a)) {
|
231 |
|
|
for ($i = 0; isset($vs_a[$i]); $i++) {
|
232 |
0919224f
|
Bill Marquette
|
switch($vs_a[$i]['mode']) {
|
233 |
|
|
case 'redirect': {
|
234 |
|
|
$conf .= "redirect \"{$vs_a[$i]['name']}\" {\n";
|
235 |
|
|
$conf .= " listen on {$vs_a[$i]['ipaddr']} port {$vs_a[$i]['port']}\n";
|
236 |
|
|
$conf .= " forward to <{$vs_a[$i]['pool']}> port {$pools[$vs_a[$i]['pool']]['port']} {$check_a[$pools[$vs_a[$i]['pool']]['monitor']]} timeout 1000\n";
|
237 |
|
|
|
238 |
43b01df4
|
Bill Marquette
|
# sitedown MUST use the same port as the primary pool - sucks, but it's a relayd thing
|
239 |
9c426e33
|
Scott Ullrich
|
if (isset($vs_a[$i]['sitedown']) && strlen($vs_a[$i]['sitedown']) > 0)
|
240 |
aeb90d90
|
Bill Marquette
|
$conf .= " forward to <{$vs_a[$i]['sitedown']}> port {$pools[$vs_a[$i]['pool']]['port']} {$check_a[$pools[$vs_a[$i]['pool']]['monitor']]} timeout 1000\n";
|
241 |
9c426e33
|
Scott Ullrich
|
|
242 |
0919224f
|
Bill Marquette
|
$conf .= "}\n";
|
243 |
|
|
break;
|
244 |
|
|
}
|
245 |
|
|
case 'relay': {
|
246 |
|
|
$conf .= "relay \"{$vs_a[$i]['name']}\" {\n";
|
247 |
|
|
$conf .= " listen on {$vs_a[$i]['ipaddr']} port {$vs_a[$i]['port']}\n";
|
248 |
|
|
$conf .= " protocol \"{$vs_a[$i]['relay_protocol']}\"\n";
|
249 |
|
|
$conf .= " forward to <{$vs_a[$i]['pool']}> port {$pools[$vs_a[$i]['pool']]['port']} {$check_a[$pools[$vs_a[$i]['pool']]['monitor']]} timeout 1000\n";
|
250 |
|
|
|
251 |
9c426e33
|
Scott Ullrich
|
if (isset($vs_a[$i]['sitedown']) && strlen($vs_a[$i]['sitedown']) > 0)
|
252 |
0919224f
|
Bill Marquette
|
$conf .= " forward to <{$vs_a[$i]['sitedown']}> port {$pools[$vs_a[$i]['pool']]['port']} {$check_a[$pools[$vs_a[$i]['pool']]['monitor']]} timeout 1000\n";
|
253 |
|
|
$conf .= "}\n";
|
254 |
|
|
break;
|
255 |
|
|
}
|
256 |
|
|
}
|
257 |
17623ab5
|
Bill Marquette
|
}
|
258 |
|
|
}
|
259 |
|
|
fwrite($fd, $conf);
|
260 |
|
|
fclose($fd);
|
261 |
|
|
|
262 |
651d99c5
|
Bill Marquette
|
if (is_process_running('relayd: parent')) {
|
263 |
a32a06ad
|
Bill Marquette
|
/*
|
264 |
|
|
* XXX: Something breaks our control connection with relayd and makes relayctl stop working
|
265 |
|
|
* rule reloads are the current suspect
|
266 |
|
|
* mwexec('/usr/local/bin/relayctl stop');
|
267 |
|
|
*/
|
268 |
|
|
mwexec('pkill relayd');
|
269 |
17623ab5
|
Bill Marquette
|
}
|
270 |
3eb583e6
|
Seth Mos
|
if (! empty($vs_a)) {
|
271 |
|
|
mwexec("/usr/local/sbin/relayd -f {$g['varetc_path']}/relayd.conf");
|
272 |
|
|
}
|
273 |
3ad6d3bb
|
Bill Marquette
|
}
|
274 |
|
|
|
275 |
483e6de8
|
Scott Ullrich
|
?>
|