1 |
7ed0e844
|
Warren Baker
|
<?php
|
2 |
|
|
/*
|
3 |
|
|
services_unbound.php
|
4 |
|
|
*/
|
5 |
df6cb8fe
|
Stephen Beaver
|
/* ====================================================================
|
6 |
|
|
* Copyright (c) 2004-2015 Electric Sheep Fencing, LLC. All rights reserved.
|
7 |
|
|
* Copyright (c) 2014 Warren Baker (warren@pfsense.org)
|
8 |
|
|
*
|
9 |
|
|
* Redistribution and use in source and binary forms, with or without modification,
|
10 |
|
|
* are permitted provided that the following conditions are met:
|
11 |
|
|
*
|
12 |
|
|
* 1. Redistributions of source code must retain the above copyright notice,
|
13 |
|
|
* this list of conditions and the following disclaimer.
|
14 |
|
|
*
|
15 |
|
|
* 2. Redistributions in binary form must reproduce the above copyright
|
16 |
|
|
* notice, this list of conditions and the following disclaimer in
|
17 |
|
|
* the documentation and/or other materials provided with the
|
18 |
|
|
* distribution.
|
19 |
|
|
*
|
20 |
|
|
* 3. All advertising materials mentioning features or use of this software
|
21 |
|
|
* must display the following acknowledgment:
|
22 |
|
|
* "This product includes software developed by the pfSense Project
|
23 |
|
|
* for use in the pfSense software distribution. (http://www.pfsense.org/).
|
24 |
|
|
*
|
25 |
|
|
* 4. The names "pfSense" and "pfSense Project" must not be used to
|
26 |
|
|
* endorse or promote products derived from this software without
|
27 |
|
|
* prior written permission. For written permission, please contact
|
28 |
|
|
* coreteam@pfsense.org.
|
29 |
|
|
*
|
30 |
|
|
* 5. Products derived from this software may not be called "pfSense"
|
31 |
|
|
* nor may "pfSense" appear in their names without prior written
|
32 |
|
|
* permission of the Electric Sheep Fencing, LLC.
|
33 |
|
|
*
|
34 |
|
|
* 6. Redistributions of any form whatsoever must retain the following
|
35 |
|
|
* acknowledgment:
|
36 |
|
|
*
|
37 |
|
|
* "This product includes software developed by the pfSense Project
|
38 |
|
|
* for use in the pfSense software distribution (http://www.pfsense.org/).
|
39 |
|
|
*
|
40 |
|
|
* THIS SOFTWARE IS PROVIDED BY THE pfSense PROJECT ``AS IS'' AND ANY
|
41 |
|
|
* EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
42 |
|
|
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
|
43 |
|
|
* PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE pfSense PROJECT OR
|
44 |
|
|
* ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
|
45 |
|
|
* SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
|
46 |
|
|
* NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
|
47 |
|
|
* LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
48 |
|
|
* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
|
49 |
|
|
* STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
50 |
|
|
* ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
|
51 |
|
|
* OF THE POSSIBILITY OF SUCH DAMAGE.
|
52 |
|
|
*
|
53 |
|
|
* ====================================================================
|
54 |
|
|
*
|
55 |
|
|
*/
|
56 |
7ed0e844
|
Warren Baker
|
|
57 |
|
|
##|+PRIV
|
58 |
0b8328c5
|
jim-p
|
##|*IDENT=page-services-dnsresolver
|
59 |
5230f468
|
jim-p
|
##|*NAME=Services: DNS Resolver
|
60 |
7ed0e844
|
Warren Baker
|
##|*DESCR=Allow access to the 'Services: DNS Resolver' page.
|
61 |
|
|
##|*MATCH=services_unbound.php*
|
62 |
9c8a7b13
|
Stephen Beaver
|
##|-PRIV
|
63 |
7ed0e844
|
Warren Baker
|
|
64 |
|
|
require_once("guiconfig.inc");
|
65 |
|
|
require_once("unbound.inc");
|
66 |
4dbcf2fb
|
Renato Botelho
|
require_once("system.inc");
|
67 |
7ed0e844
|
Warren Baker
|
|
68 |
be11b6f1
|
Warren Baker
|
if (!is_array($config['unbound'])) {
|
69 |
2783e408
|
Renato Botelho
|
$config['unbound'] = array();
|
70 |
be11b6f1
|
Warren Baker
|
}
|
71 |
|
|
|
72 |
7ed0e844
|
Warren Baker
|
$a_unboundcfg =& $config['unbound'];
|
73 |
|
|
|
74 |
932711c7
|
Matt Smith
|
if (!is_array($a_unboundcfg['hosts'])) {
|
75 |
|
|
$a_unboundcfg['hosts'] = array();
|
76 |
be11b6f1
|
Warren Baker
|
}
|
77 |
|
|
|
78 |
932711c7
|
Matt Smith
|
$a_hosts =& $a_unboundcfg['hosts'];
|
79 |
7ed0e844
|
Warren Baker
|
|
80 |
932711c7
|
Matt Smith
|
if (!is_array($a_unboundcfg['domainoverrides'])) {
|
81 |
|
|
$a_unboundcfg['domainoverrides'] = array();
|
82 |
be11b6f1
|
Warren Baker
|
}
|
83 |
|
|
|
84 |
932711c7
|
Matt Smith
|
$a_domainOverrides = &$a_unboundcfg['domainoverrides'];
|
85 |
7ed0e844
|
Warren Baker
|
|
86 |
932711c7
|
Matt Smith
|
if (isset($a_unboundcfg['enable'])) {
|
87 |
fe9d4894
|
Renato Botelho
|
$pconfig['enable'] = true;
|
88 |
be11b6f1
|
Warren Baker
|
}
|
89 |
932711c7
|
Matt Smith
|
if (isset($a_unboundcfg['dnssec'])) {
|
90 |
fe9d4894
|
Renato Botelho
|
$pconfig['dnssec'] = true;
|
91 |
be11b6f1
|
Warren Baker
|
}
|
92 |
932711c7
|
Matt Smith
|
if (isset($a_unboundcfg['forwarding'])) {
|
93 |
fe9d4894
|
Renato Botelho
|
$pconfig['forwarding'] = true;
|
94 |
be11b6f1
|
Warren Baker
|
}
|
95 |
932711c7
|
Matt Smith
|
if (isset($a_unboundcfg['regdhcp'])) {
|
96 |
fe9d4894
|
Renato Botelho
|
$pconfig['regdhcp'] = true;
|
97 |
be11b6f1
|
Warren Baker
|
}
|
98 |
932711c7
|
Matt Smith
|
if (isset($a_unboundcfg['regdhcpstatic'])) {
|
99 |
fe9d4894
|
Renato Botelho
|
$pconfig['regdhcpstatic'] = true;
|
100 |
be11b6f1
|
Warren Baker
|
}
|
101 |
615ae81f
|
Renato Botelho
|
|
102 |
932711c7
|
Matt Smith
|
$pconfig['port'] = $a_unboundcfg['port'];
|
103 |
|
|
$pconfig['custom_options'] = base64_decode($a_unboundcfg['custom_options']);
|
104 |
615ae81f
|
Renato Botelho
|
|
105 |
932711c7
|
Matt Smith
|
if (empty($a_unboundcfg['active_interface'])) {
|
106 |
2783e408
|
Renato Botelho
|
$pconfig['active_interface'] = array();
|
107 |
be11b6f1
|
Warren Baker
|
} else {
|
108 |
932711c7
|
Matt Smith
|
$pconfig['active_interface'] = explode(",", $a_unboundcfg['active_interface']);
|
109 |
be11b6f1
|
Warren Baker
|
}
|
110 |
51c224bc
|
sbeaver
|
|
111 |
932711c7
|
Matt Smith
|
if (empty($a_unboundcfg['outgoing_interface'])) {
|
112 |
2783e408
|
Renato Botelho
|
$pconfig['outgoing_interface'] = array();
|
113 |
be11b6f1
|
Warren Baker
|
} else {
|
114 |
932711c7
|
Matt Smith
|
$pconfig['outgoing_interface'] = explode(",", $a_unboundcfg['outgoing_interface']);
|
115 |
be11b6f1
|
Warren Baker
|
}
|
116 |
615ae81f
|
Renato Botelho
|
|
117 |
ca47c065
|
NOYB
|
if (empty($a_unboundcfg['system_domain_local_zone_type'])) {
|
118 |
|
|
$pconfig['system_domain_local_zone_type'] = "transparent";
|
119 |
|
|
} else {
|
120 |
|
|
$pconfig['system_domain_local_zone_type'] = $a_unboundcfg['system_domain_local_zone_type'];
|
121 |
|
|
}
|
122 |
|
|
|
123 |
7ed0e844
|
Warren Baker
|
if ($_POST) {
|
124 |
2783e408
|
Renato Botelho
|
if ($_POST['apply']) {
|
125 |
|
|
$retval = services_unbound_configure();
|
126 |
|
|
$savemsg = get_std_save_message($retval);
|
127 |
|
|
if ($retval == 0) {
|
128 |
|
|
clear_subsystem_dirty('unbound');
|
129 |
fe9d4894
|
Renato Botelho
|
}
|
130 |
2783e408
|
Renato Botelho
|
/* Update resolv.conf in case the interface bindings exclude localhost. */
|
131 |
|
|
system_resolvconf_generate();
|
132 |
4dbcf2fb
|
Renato Botelho
|
/* Start or restart dhcpleases when it's necessary */
|
133 |
|
|
system_dhcpleases_configure();
|
134 |
2783e408
|
Renato Botelho
|
} else {
|
135 |
7aeae838
|
Matt Smith
|
$pconfig = $_POST;
|
136 |
|
|
unset($input_errors);
|
137 |
|
|
|
138 |
932711c7
|
Matt Smith
|
if (isset($pconfig['enable']) && isset($config['dnsmasq']['enable'])) {
|
139 |
|
|
if ($pconfig['port'] == $config['dnsmasq']['port']) {
|
140 |
4bb7c0d1
|
bruno
|
$input_errors[] = gettext("The DNS Forwarder is enabled using this port. Choose a non-conflicting port, or disable the DNS Forwarder.");
|
141 |
e92ee598
|
Phil Davis
|
}
|
142 |
fe9d4894
|
Renato Botelho
|
}
|
143 |
615ae81f
|
Renato Botelho
|
|
144 |
7b03ef63
|
Chris Buechler
|
// forwarding mode requires having valid DNS servers
|
145 |
|
|
if (isset($pconfig['forwarding'])) {
|
146 |
|
|
$founddns = false;
|
147 |
|
|
if (isset($config['system']['dnsallowoverride'])) {
|
148 |
5e946f38
|
Chris Buechler
|
$dns_servers = get_dns_servers();
|
149 |
|
|
if (is_array($dns_servers)) {
|
150 |
|
|
foreach ($dns_servers as $dns_server) {
|
151 |
|
|
if (!ip_in_subnet($dns_server, "127.0.0.0/8")) {
|
152 |
7b03ef63
|
Chris Buechler
|
$founddns = true;
|
153 |
|
|
}
|
154 |
|
|
}
|
155 |
|
|
}
|
156 |
|
|
}
|
157 |
|
|
if (is_array($config['system']['dnsserver'])) {
|
158 |
|
|
foreach ($config['system']['dnsserver'] as $dnsserver) {
|
159 |
|
|
if (is_ipaddr($dnsserver)) {
|
160 |
|
|
$founddns = true;
|
161 |
|
|
}
|
162 |
|
|
}
|
163 |
|
|
}
|
164 |
|
|
if ($founddns == false) {
|
165 |
|
|
$input_errors[] = gettext("At least one DNS server must be specified under System>General Setup to enable Forwarding mode.");
|
166 |
|
|
}
|
167 |
|
|
}
|
168 |
|
|
|
169 |
932711c7
|
Matt Smith
|
if (empty($pconfig['active_interface'])) {
|
170 |
4bb7c0d1
|
bruno
|
$input_errors[] = gettext("One or more Network Interfaces must be selected for binding.");
|
171 |
932711c7
|
Matt Smith
|
} else if (!isset($config['system']['dnslocalhost']) && (!in_array("lo0", $pconfig['active_interface']) && !in_array("all", $pconfig['active_interface']))) {
|
172 |
4bb7c0d1
|
bruno
|
$input_errors[] = gettext("This system is configured to use the DNS Resolver as its DNS server, so Localhost or All must be selected in Network Interfaces.");
|
173 |
fe9d4894
|
Renato Botelho
|
}
|
174 |
7ed0e844
|
Warren Baker
|
|
175 |
932711c7
|
Matt Smith
|
if (empty($pconfig['outgoing_interface'])) {
|
176 |
4bb7c0d1
|
bruno
|
$input_errors[] = gettext("One or more Outgoing Network Interfaces must be selected.");
|
177 |
fe9d4894
|
Renato Botelho
|
}
|
178 |
7ed0e844
|
Warren Baker
|
|
179 |
932711c7
|
Matt Smith
|
if ($pconfig['port'] && !is_port($pconfig['port'])) {
|
180 |
|
|
$input_errors[] = gettext("You must specify a valid port number.");
|
181 |
fe9d4894
|
Renato Botelho
|
}
|
182 |
fff4a9d1
|
Warren Baker
|
|
183 |
932711c7
|
Matt Smith
|
if (is_array($pconfig['active_interface']) && !empty($pconfig['active_interface'])) {
|
184 |
|
|
$display_active_interface = $pconfig['active_interface'];
|
185 |
|
|
$pconfig['active_interface'] = implode(",", $pconfig['active_interface']);
|
186 |
fe9d4894
|
Renato Botelho
|
}
|
187 |
7ed0e844
|
Warren Baker
|
|
188 |
932711c7
|
Matt Smith
|
$display_custom_options = $pconfig['custom_options'];
|
189 |
|
|
$pconfig['custom_options'] = base64_encode(str_replace("\r\n", "\n", $pconfig['custom_options']));
|
190 |
|
|
|
191 |
|
|
if (is_array($pconfig['outgoing_interface']) && !empty($pconfig['outgoing_interface'])) {
|
192 |
|
|
$display_outgoing_interface = $pconfig['outgoing_interface'];
|
193 |
|
|
$pconfig['outgoing_interface'] = implode(",", $pconfig['outgoing_interface']);
|
194 |
fe9d4894
|
Renato Botelho
|
}
|
195 |
188609c6
|
Warren Baker
|
|
196 |
932711c7
|
Matt Smith
|
$test_output = array();
|
197 |
|
|
if (test_unbound_config($pconfig, $test_output)) {
|
198 |
|
|
$input_errors[] = gettext("The generated config file cannot be parsed by unbound. Please correct the following errors:");
|
199 |
|
|
$input_errors = array_merge($input_errors, $test_output);
|
200 |
|
|
}
|
201 |
7ed0e844
|
Warren Baker
|
|
202 |
2783e408
|
Renato Botelho
|
if (!$input_errors) {
|
203 |
932711c7
|
Matt Smith
|
$a_unboundcfg['enable'] = isset($pconfig['enable']);
|
204 |
439ba83c
|
NOYB
|
$a_unboundcfg['port'] = $pconfig['port'];
|
205 |
932711c7
|
Matt Smith
|
$a_unboundcfg['dnssec'] = isset($pconfig['dnssec']);
|
206 |
|
|
$a_unboundcfg['forwarding'] = isset($pconfig['forwarding']);
|
207 |
|
|
$a_unboundcfg['regdhcp'] = isset($pconfig['regdhcp']);
|
208 |
|
|
$a_unboundcfg['regdhcpstatic'] = isset($pconfig['regdhcpstatic']);
|
209 |
|
|
$a_unboundcfg['active_interface'] = $pconfig['active_interface'];
|
210 |
|
|
$a_unboundcfg['outgoing_interface'] = $pconfig['outgoing_interface'];
|
211 |
ca47c065
|
NOYB
|
$a_unboundcfg['system_domain_local_zone_type'] = $pconfig['system_domain_local_zone_type'];
|
212 |
932711c7
|
Matt Smith
|
$a_unboundcfg['custom_options'] = $pconfig['custom_options'];
|
213 |
|
|
|
214 |
4bb7c0d1
|
bruno
|
write_config(gettext("DNS Resolver configured."));
|
215 |
2783e408
|
Renato Botelho
|
mark_subsystem_dirty('unbound');
|
216 |
|
|
}
|
217 |
932711c7
|
Matt Smith
|
|
218 |
|
|
$pconfig['active_interface'] = $display_active_interface;
|
219 |
|
|
$pconfig['outgoing_interface'] = $display_outgoing_interface;
|
220 |
|
|
$pconfig['custom_options'] = $display_custom_options;
|
221 |
2783e408
|
Renato Botelho
|
}
|
222 |
7ed0e844
|
Warren Baker
|
}
|
223 |
|
|
|
224 |
f2bc186f
|
Warren Baker
|
if ($_GET['act'] == "del") {
|
225 |
2783e408
|
Renato Botelho
|
if ($_GET['type'] == 'host') {
|
226 |
|
|
if ($a_hosts[$_GET['id']]) {
|
227 |
|
|
unset($a_hosts[$_GET['id']]);
|
228 |
|
|
write_config();
|
229 |
|
|
mark_subsystem_dirty('unbound');
|
230 |
|
|
header("Location: services_unbound.php");
|
231 |
|
|
exit;
|
232 |
|
|
}
|
233 |
|
|
} elseif ($_GET['type'] == 'doverride') {
|
234 |
|
|
if ($a_domainOverrides[$_GET['id']]) {
|
235 |
|
|
unset($a_domainOverrides[$_GET['id']]);
|
236 |
|
|
write_config();
|
237 |
|
|
mark_subsystem_dirty('unbound');
|
238 |
|
|
header("Location: services_unbound.php");
|
239 |
|
|
exit;
|
240 |
|
|
}
|
241 |
|
|
}
|
242 |
f2bc186f
|
Warren Baker
|
}
|
243 |
|
|
|
244 |
7aeae838
|
Matt Smith
|
function build_if_list($selectedifs) {
|
245 |
51c224bc
|
sbeaver
|
$interface_addresses = get_possible_listen_ips(true);
|
246 |
|
|
$iflist = array('options' => array(), 'selected' => array());
|
247 |
|
|
|
248 |
4bb7c0d1
|
bruno
|
$iflist['options']['all'] = gettext("All");
|
249 |
7aeae838
|
Matt Smith
|
if (empty($selectedifs) || empty($selectedifs[0]) || in_array("all", $selectedifs)) {
|
250 |
7275a7a2
|
Stephen Beaver
|
array_push($iflist['selected'], "all");
|
251 |
7aeae838
|
Matt Smith
|
}
|
252 |
51c224bc
|
sbeaver
|
|
253 |
|
|
foreach ($interface_addresses as $laddr => $ldescr) {
|
254 |
|
|
$iflist['options'][$laddr] = htmlspecialchars($ldescr);
|
255 |
|
|
|
256 |
20db3e1a
|
Phil Davis
|
if ($selectedifs && in_array($laddr, $selectedifs)) {
|
257 |
51c224bc
|
sbeaver
|
array_push($iflist['selected'], $laddr);
|
258 |
20db3e1a
|
Phil Davis
|
}
|
259 |
51c224bc
|
sbeaver
|
}
|
260 |
|
|
|
261 |
|
|
unset($interface_addresses);
|
262 |
|
|
|
263 |
|
|
return($iflist);
|
264 |
|
|
}
|
265 |
|
|
|
266 |
c8f6b745
|
k-paulius
|
$pgtitle = array(gettext("Services"), gettext("DNS Resolver"), gettext("General Settings"));
|
267 |
db88a3a2
|
Phil Davis
|
$shortcut_section = "resolver";
|
268 |
7ed0e844
|
Warren Baker
|
|
269 |
51c224bc
|
sbeaver
|
include_once("head.inc");
|
270 |
7ed0e844
|
Warren Baker
|
|
271 |
20db3e1a
|
Phil Davis
|
if ($input_errors) {
|
272 |
51c224bc
|
sbeaver
|
print_input_errors($input_errors);
|
273 |
20db3e1a
|
Phil Davis
|
}
|
274 |
51c224bc
|
sbeaver
|
|
275 |
20db3e1a
|
Phil Davis
|
if ($savemsg) {
|
276 |
51c224bc
|
sbeaver
|
print_info_box($savemsg, 'success');
|
277 |
20db3e1a
|
Phil Davis
|
}
|
278 |
51c224bc
|
sbeaver
|
|
279 |
7aeae838
|
Matt Smith
|
if (is_subsystem_dirty('unbound')) {
|
280 |
f4bed461
|
k-paulius
|
print_apply_box(gettext("The DNS resolver configuration has been changed.") . "<br />" . gettext("You must apply the changes in order for them to take effect."));
|
281 |
7aeae838
|
Matt Smith
|
}
|
282 |
|
|
|
283 |
51c224bc
|
sbeaver
|
$tab_array = array();
|
284 |
c8f6b745
|
k-paulius
|
$tab_array[] = array(gettext("General Settings"), true, "services_unbound.php");
|
285 |
|
|
$tab_array[] = array(gettext("Advanced Settings"), false, "services_unbound_advanced.php");
|
286 |
51c224bc
|
sbeaver
|
$tab_array[] = array(gettext("Access Lists"), false, "/services_unbound_acls.php");
|
287 |
|
|
display_top_tabs($tab_array, true);
|
288 |
|
|
|
289 |
|
|
$form = new Form();
|
290 |
|
|
|
291 |
|
|
$section = new Form_Section('General DNS Resolver Options');
|
292 |
|
|
|
293 |
|
|
$section->addInput(new Form_Checkbox(
|
294 |
|
|
'enable',
|
295 |
|
|
'Enable',
|
296 |
|
|
'Enable DNS resolver',
|
297 |
|
|
$pconfig['enable']
|
298 |
|
|
));
|
299 |
|
|
|
300 |
|
|
$section->addInput(new Form_Input(
|
301 |
|
|
'port',
|
302 |
|
|
'Listen Port',
|
303 |
d5a9e030
|
NOYB
|
'number',
|
304 |
3e568739
|
NOYB
|
$pconfig['port'],
|
305 |
|
|
['placeholder' => '53']
|
306 |
51c224bc
|
sbeaver
|
))->setHelp('The port used for responding to DNS queries. It should normally be left blank unless another service needs to bind to TCP/UDP port 53.');
|
307 |
|
|
|
308 |
7aeae838
|
Matt Smith
|
$activeiflist = build_if_list($pconfig['active_interface']);
|
309 |
51c224bc
|
sbeaver
|
|
310 |
|
|
$section->addInput(new Form_Select(
|
311 |
|
|
'active_interface',
|
312 |
|
|
'Network Interfaces',
|
313 |
7aeae838
|
Matt Smith
|
$activeiflist['selected'],
|
314 |
|
|
$activeiflist['options'],
|
315 |
51c224bc
|
sbeaver
|
true
|
316 |
d3a3eef0
|
Francisco Cavalcante
|
))->addClass('general')->setHelp('Interface IPs used by the DNS Resolver for responding to queries from clients. If an interface has both IPv4 and IPv6 IPs, both are used. Queries to other interface IPs not selected below are discarded. ' .
|
317 |
51c224bc
|
sbeaver
|
'The default behavior is to respond to queries on every available IPv4 and IPv6 address.');
|
318 |
|
|
|
319 |
7aeae838
|
Matt Smith
|
$outiflist = build_if_list($pconfig['outgoing_interface']);
|
320 |
|
|
|
321 |
51c224bc
|
sbeaver
|
$section->addInput(new Form_Select(
|
322 |
|
|
'outgoing_interface',
|
323 |
|
|
'Outgoing Network Interfaces',
|
324 |
7aeae838
|
Matt Smith
|
$outiflist['selected'],
|
325 |
|
|
$outiflist['options'],
|
326 |
51c224bc
|
sbeaver
|
true
|
327 |
d3a3eef0
|
Francisco Cavalcante
|
))->addClass('general')->setHelp('Utilize different network interface(s) that the DNS Resolver will use to send queries to authoritative servers and receive their replies. By default all interfaces are used.');
|
328 |
51c224bc
|
sbeaver
|
|
329 |
ca47c065
|
NOYB
|
$section->addInput(new Form_Select(
|
330 |
|
|
'system_domain_local_zone_type',
|
331 |
|
|
'System Domain Local Zone Type',
|
332 |
|
|
$pconfig['system_domain_local_zone_type'],
|
333 |
9a83872f
|
NOYB
|
unbound_local_zone_types()
|
334 |
ca47c065
|
NOYB
|
))->setHelp('The local-zone type used for the pfSense system domain (System | General Setup | Domain). Transparent is the default. Local-Zone type descriptions are available in the unbound.conf(5) manual pages.');
|
335 |
|
|
|
336 |
51c224bc
|
sbeaver
|
$section->addInput(new Form_Checkbox(
|
337 |
|
|
'dnssec',
|
338 |
|
|
'DNSSEC',
|
339 |
|
|
'Enable DNSSEC Support',
|
340 |
|
|
$pconfig['dnssec']
|
341 |
|
|
));
|
342 |
|
|
|
343 |
|
|
$section->addInput(new Form_Checkbox(
|
344 |
|
|
'forwarding',
|
345 |
|
|
'DNS Query Forwarding',
|
346 |
|
|
'Enable Forwarding Mode',
|
347 |
|
|
$pconfig['forwarding']
|
348 |
|
|
));
|
349 |
|
|
|
350 |
|
|
$section->addInput(new Form_Checkbox(
|
351 |
|
|
'regdhcp',
|
352 |
|
|
'DHCP Registration',
|
353 |
|
|
'Register DHCP leases in the DNS Resolver',
|
354 |
|
|
$pconfig['regdhcp']
|
355 |
|
|
))->setHelp(sprintf('If this option is set, then machines that specify their hostname when requesting a DHCP lease will be registered'.
|
356 |
|
|
' in the DNS Resolver, so that their name can be resolved.'.
|
357 |
|
|
' You should also set the domain in %sSystem: General setup%s to the proper value.','<a href="system.php">','</a>'));
|
358 |
|
|
|
359 |
|
|
$section->addInput(new Form_Checkbox(
|
360 |
|
|
'regdhcpstatic',
|
361 |
|
|
'Static DHCP',
|
362 |
|
|
'Register DHCP static mappings in the DNS Resolver',
|
363 |
|
|
$pconfig['regdhcpstatic']
|
364 |
|
|
))->setHelp(sprintf('If this option is set, then DHCP static mappings will be registered in the DNS Resolver, so that their name can be '.
|
365 |
|
|
'resolved. You should also set the domain in %s'.
|
366 |
|
|
'System: General setup%s to the proper value.','<a href="system.php">','</a>'));
|
367 |
|
|
|
368 |
|
|
$btnadvdns = new Form_Button(
|
369 |
|
|
'btnadvdns',
|
370 |
932711c7
|
Matt Smith
|
'Custom options'
|
371 |
51c224bc
|
sbeaver
|
);
|
372 |
|
|
|
373 |
|
|
$btnadvdns->removeClass('btn-primary')->addClass('btn-default btn-sm');
|
374 |
|
|
|
375 |
|
|
$section->addInput(new Form_StaticText(
|
376 |
932711c7
|
Matt Smith
|
'Custom options',
|
377 |
|
|
$btnadvdns . ' ' . 'Show custom options'
|
378 |
51c224bc
|
sbeaver
|
));
|
379 |
|
|
|
380 |
1fcfea39
|
Stephen Beaver
|
$section->addInput(new Form_Textarea (
|
381 |
51c224bc
|
sbeaver
|
'custom_options',
|
382 |
|
|
'Custom options',
|
383 |
|
|
$pconfig['custom_options']
|
384 |
|
|
))->setHelp('Enter any additional configuration parameters to add to the DNS Resolver configuration here, separated by a newline');
|
385 |
|
|
|
386 |
|
|
$form->add($section);
|
387 |
|
|
print($form);
|
388 |
|
|
?>
|
389 |
932711c7
|
Matt Smith
|
|
390 |
8fd9052f
|
Colin Fleming
|
<script type="text/javascript">
|
391 |
51c224bc
|
sbeaver
|
//<![CDATA[
|
392 |
20db3e1a
|
Phil Davis
|
events.push(function() {
|
393 |
51c224bc
|
sbeaver
|
|
394 |
d3a3eef0
|
Francisco Cavalcante
|
// If the enable checkbox is not checked, hide all inputs
|
395 |
|
|
function hideGeneral() {
|
396 |
51c224bc
|
sbeaver
|
var hide = ! $('#enable').prop('checked');
|
397 |
|
|
|
398 |
d3a3eef0
|
Francisco Cavalcante
|
hideMultiClass('general', hide);
|
399 |
|
|
hideInput('port', hide);
|
400 |
|
|
hideSelect('system_domain_local_zone_type', hide);
|
401 |
|
|
hideCheckbox('dnssec', hide);
|
402 |
|
|
hideCheckbox('forwarding', hide);
|
403 |
|
|
hideCheckbox('regdhcp', hide);
|
404 |
|
|
hideCheckbox('regdhcpstatic', hide);
|
405 |
|
|
hideInput('btnadvdns', hide);
|
406 |
51c224bc
|
sbeaver
|
}
|
407 |
|
|
|
408 |
520ee1d0
|
Phil Davis
|
// Make the 'additional options' button a plain button, not a submit button
|
409 |
51c224bc
|
sbeaver
|
$("#btnadvdns").prop('type','button');
|
410 |
|
|
|
411 |
520ee1d0
|
Phil Davis
|
// Un-hide additional controls
|
412 |
51c224bc
|
sbeaver
|
$("#btnadvdns").click(function() {
|
413 |
|
|
hideInput('custom_options', false);
|
414 |
|
|
});
|
415 |
|
|
|
416 |
d3a3eef0
|
Francisco Cavalcante
|
// When 'enable' is clicked, disable/enable the following hide inputs
|
417 |
51c224bc
|
sbeaver
|
$('#enable').click(function() {
|
418 |
d3a3eef0
|
Francisco Cavalcante
|
hideGeneral();
|
419 |
51c224bc
|
sbeaver
|
});
|
420 |
|
|
|
421 |
|
|
// On initial load
|
422 |
20db3e1a
|
Phil Davis
|
if ($('#custom_options').val().length == 0) {
|
423 |
df6cb8fe
|
Stephen Beaver
|
hideInput('custom_options', true);
|
424 |
|
|
}
|
425 |
|
|
|
426 |
d3a3eef0
|
Francisco Cavalcante
|
hideGeneral();
|
427 |
51c224bc
|
sbeaver
|
|
428 |
|
|
});
|
429 |
|
|
//]]>
|
430 |
|
|
</script>
|
431 |
|
|
|
432 |
|
|
<div class="panel panel-default">
|
433 |
f17594c7
|
Sjon Hortensius
|
<div class="panel-heading"><h2 class="panel-title"><?=gettext("Host Overrides")?></h2></div>
|
434 |
51c224bc
|
sbeaver
|
<div class="panel-body table-responsive">
|
435 |
10fe1eb5
|
Stephen Beaver
|
<table class="table table-striped table-hover table-condensed sortable-theme-bootstrap" data-sortable>
|
436 |
51c224bc
|
sbeaver
|
<thead>
|
437 |
2783e408
|
Renato Botelho
|
<tr>
|
438 |
51c224bc
|
sbeaver
|
<th><?=gettext("Host")?></th>
|
439 |
|
|
<th><?=gettext("Domain")?></th>
|
440 |
|
|
<th><?=gettext("IP")?></th>
|
441 |
|
|
<th><?=gettext("Description")?></th>
|
442 |
|
|
<th></th>
|
443 |
2783e408
|
Renato Botelho
|
</tr>
|
444 |
51c224bc
|
sbeaver
|
</thead>
|
445 |
|
|
<tbody>
|
446 |
|
|
<?php
|
447 |
|
|
$i = 0;
|
448 |
|
|
foreach ($a_hosts as $hostent):
|
449 |
|
|
?>
|
450 |
2783e408
|
Renato Botelho
|
<tr>
|
451 |
51c224bc
|
sbeaver
|
<td>
|
452 |
c8a7d17c
|
NOYB
|
<?=$hostent['host']?>
|
453 |
51c224bc
|
sbeaver
|
</td>
|
454 |
|
|
<td>
|
455 |
c8a7d17c
|
NOYB
|
<?=$hostent['domain']?>
|
456 |
51c224bc
|
sbeaver
|
</td>
|
457 |
|
|
<td>
|
458 |
de038a27
|
Stephen Beaver
|
<?=$hostent['ip']?>
|
459 |
51c224bc
|
sbeaver
|
</td>
|
460 |
|
|
<td>
|
461 |
|
|
<?=htmlspecialchars($hostent['descr'])?>
|
462 |
|
|
</td>
|
463 |
|
|
<td>
|
464 |
33f0b0d5
|
Stephen Beaver
|
<a class="fa fa-pencil" title="<?=gettext('Edit host override')?>" href="services_unbound_host_edit.php?id=<?=$i?>"></a>
|
465 |
|
|
<a class="fa fa-trash" title="<?=gettext('Delete host override')?>" href="services_unbound.php?type=host&act=del&id=<?=$i?>"></a>
|
466 |
51c224bc
|
sbeaver
|
</td>
|
467 |
2783e408
|
Renato Botelho
|
</tr>
|
468 |
51c224bc
|
sbeaver
|
|
469 |
|
|
<?php
|
470 |
|
|
if ($hostent['aliases']['item'] && is_array($hostent['aliases']['item'])):
|
471 |
|
|
foreach ($hostent['aliases']['item'] as $alias):
|
472 |
|
|
?>
|
473 |
2783e408
|
Renato Botelho
|
<tr>
|
474 |
51c224bc
|
sbeaver
|
<td>
|
475 |
c8a7d17c
|
NOYB
|
<?=$alias['host']?>
|
476 |
51c224bc
|
sbeaver
|
</td>
|
477 |
|
|
<td>
|
478 |
c8a7d17c
|
NOYB
|
<?=$alias['domain']?>
|
479 |
51c224bc
|
sbeaver
|
</td>
|
480 |
|
|
<td>
|
481 |
4bb7c0d1
|
bruno
|
<?=gettext("Alias for ");?><?=$hostent['host'] ? $hostent['host'] . '.' . $hostent['domain'] : $hostent['domain']?>
|
482 |
51c224bc
|
sbeaver
|
</td>
|
483 |
|
|
<td>
|
484 |
39bd0b51
|
Stephen Beaver
|
<i class="fa fa-angle-double-right text-info"></i>
|
485 |
51c224bc
|
sbeaver
|
<?=htmlspecialchars($alias['description'])?>
|
486 |
|
|
</td>
|
487 |
|
|
<td>
|
488 |
2b36a04b
|
heper
|
<a a class="fa fa-pencil" title="<?=gettext('Edit host override')?>" href="services_unbound_host_edit.php?id=<?=$i?>"></a>
|
489 |
51c224bc
|
sbeaver
|
</td>
|
490 |
2783e408
|
Renato Botelho
|
</tr>
|
491 |
51c224bc
|
sbeaver
|
<?php
|
492 |
|
|
endforeach;
|
493 |
|
|
endif;
|
494 |
|
|
$i++;
|
495 |
|
|
endforeach;
|
496 |
|
|
?>
|
497 |
|
|
</tbody>
|
498 |
|
|
</table>
|
499 |
|
|
</div>
|
500 |
|
|
</div>
|
501 |
|
|
|
502 |
c10cb196
|
Stephen Beaver
|
<nav class="action-buttons">
|
503 |
782922c2
|
Stephen Beaver
|
<a href="services_unbound_host_edit.php" class="btn btn-sm btn-success">
|
504 |
9d5a20cf
|
heper
|
<i class="fa fa-plus icon-embed-btn"></i>
|
505 |
782922c2
|
Stephen Beaver
|
<?=gettext('Add')?>
|
506 |
|
|
</a>
|
507 |
51c224bc
|
sbeaver
|
</nav>
|
508 |
|
|
|
509 |
|
|
<div class="panel panel-default">
|
510 |
f17594c7
|
Sjon Hortensius
|
<div class="panel-heading"><h2 class="panel-title"><?=gettext("Domain Overrides")?></h2></div>
|
511 |
51c224bc
|
sbeaver
|
<div class="panel-body table-responsive">
|
512 |
10fe1eb5
|
Stephen Beaver
|
<table class="table table-striped table-hover table-condensed sortable-theme-bootstrap" data-sortable>
|
513 |
51c224bc
|
sbeaver
|
<thead>
|
514 |
2783e408
|
Renato Botelho
|
<tr>
|
515 |
51c224bc
|
sbeaver
|
<th><?=gettext("Domain")?></th>
|
516 |
|
|
<th><?=gettext("IP")?></th>
|
517 |
|
|
<th><?=gettext("Description")?></th>
|
518 |
|
|
<th></th>
|
519 |
2783e408
|
Renato Botelho
|
</tr>
|
520 |
51c224bc
|
sbeaver
|
</thead>
|
521 |
|
|
|
522 |
|
|
<tbody>
|
523 |
|
|
<?php
|
524 |
|
|
$i = 0;
|
525 |
|
|
foreach ($a_domainOverrides as $doment):
|
526 |
|
|
?>
|
527 |
2783e408
|
Renato Botelho
|
<tr>
|
528 |
51c224bc
|
sbeaver
|
<td>
|
529 |
c8a7d17c
|
NOYB
|
<?=$doment['domain']?>
|
530 |
51c224bc
|
sbeaver
|
</td>
|
531 |
|
|
<td>
|
532 |
|
|
<?=$doment['ip']?>
|
533 |
|
|
</td>
|
534 |
|
|
<td>
|
535 |
|
|
<?=htmlspecialchars($doment['descr'])?>
|
536 |
|
|
</td>
|
537 |
|
|
<td>
|
538 |
33f0b0d5
|
Stephen Beaver
|
<a class="fa fa-pencil" title="<?=gettext('Edit domain override')?>" href="services_unbound_domainoverride_edit.php?id=<?=$i?>"></a>
|
539 |
|
|
<a class="fa fa-trash" title="<?=gettext('Delete domain override')?>" href="services_unbound.php?act=del&type=doverride&id=<?=$i?>"></a>
|
540 |
51c224bc
|
sbeaver
|
</td>
|
541 |
2783e408
|
Renato Botelho
|
</tr>
|
542 |
51c224bc
|
sbeaver
|
<?php
|
543 |
|
|
$i++;
|
544 |
|
|
endforeach;
|
545 |
|
|
?>
|
546 |
|
|
</tbody>
|
547 |
|
|
</table>
|
548 |
|
|
</div>
|
549 |
|
|
</div>
|
550 |
|
|
|
551 |
c10cb196
|
Stephen Beaver
|
<nav class="action-buttons">
|
552 |
782922c2
|
Stephen Beaver
|
<a href="services_unbound_domainoverride_edit.php" class="btn btn-sm btn-success">
|
553 |
9d5a20cf
|
heper
|
<i class="fa fa-plus icon-embed-btn"></i>
|
554 |
782922c2
|
Stephen Beaver
|
<?=gettext('Add')?>
|
555 |
|
|
</a>
|
556 |
51c224bc
|
sbeaver
|
</nav>
|
557 |
782922c2
|
Stephen Beaver
|
|
558 |
35681930
|
Stephen Beaver
|
<div class="infoblock">
|
559 |
f6aebbcc
|
NewEraCracker
|
<?php print_info_box(sprintf(gettext("If the DNS Resolver is enabled, the DHCP".
|
560 |
782922c2
|
Stephen Beaver
|
" service (if enabled) will automatically serve the LAN IP".
|
561 |
|
|
" address as a DNS server to DHCP clients so they will use".
|
562 |
520ee1d0
|
Phil Davis
|
" the DNS Resolver. If Forwarding is enabled, the DNS Resolver will use the DNS servers".
|
563 |
782922c2
|
Stephen Beaver
|
" entered in %sSystem: General setup%s".
|
564 |
520ee1d0
|
Phil Davis
|
" or those obtained via DHCP or PPP on WAN if "Allow".
|
565 |
782922c2
|
Stephen Beaver
|
" DNS server list to be overridden by DHCP/PPP on WAN"".
|
566 |
f6aebbcc
|
NewEraCracker
|
" is checked."), '<a href="system.php">', '</a>'), 'info', false); ?>
|
567 |
782922c2
|
Stephen Beaver
|
</div>
|
568 |
82afb104
|
Stephen Beaver
|
|
569 |
6f65dc19
|
Chris Buechler
|
<?php include("foot.inc");
|