1 |
52c9f9fa
|
Ermal
|
<?php
|
2 |
|
|
/*
|
3 |
ac24dc24
|
Renato Botelho
|
* ipsec.attributes.php
|
4 |
|
|
*
|
5 |
|
|
* part of pfSense (https://www.pfsense.org)
|
6 |
38809d47
|
Renato Botelho do Couto
|
* Copyright (c) 2011-2013 BSD Perimeter
|
7 |
|
|
* Copyright (c) 2013-2016 Electric Sheep Fencing
|
8 |
a68f7a3d
|
Luiz Otavio O Souza
|
* Copyright (c) 2014-2024 Rubicon Communications, LLC (Netgate)
|
9 |
ac24dc24
|
Renato Botelho
|
* All rights reserved.
|
10 |
|
|
*
|
11 |
b12ea3fb
|
Renato Botelho
|
* Licensed under the Apache License, Version 2.0 (the "License");
|
12 |
|
|
* you may not use this file except in compliance with the License.
|
13 |
|
|
* You may obtain a copy of the License at
|
14 |
ac24dc24
|
Renato Botelho
|
*
|
15 |
b12ea3fb
|
Renato Botelho
|
* http://www.apache.org/licenses/LICENSE-2.0
|
16 |
ac24dc24
|
Renato Botelho
|
*
|
17 |
b12ea3fb
|
Renato Botelho
|
* Unless required by applicable law or agreed to in writing, software
|
18 |
|
|
* distributed under the License is distributed on an "AS IS" BASIS,
|
19 |
|
|
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
20 |
|
|
* See the License for the specific language governing permissions and
|
21 |
|
|
* limitations under the License.
|
22 |
ac24dc24
|
Renato Botelho
|
*/
|
23 |
52c9f9fa
|
Ermal
|
|
24 |
4537e922
|
Viktor G
|
global $attributes;
|
25 |
|
|
|
26 |
52c9f9fa
|
Ermal
|
if (empty($common_name)) {
|
27 |
|
|
$common_name = getenv("common_name");
|
28 |
b37a2e8c
|
Phil Davis
|
if (empty($common_name)) {
|
29 |
52c9f9fa
|
Ermal
|
$common_name = getenv("username");
|
30 |
b37a2e8c
|
Phil Davis
|
}
|
31 |
52c9f9fa
|
Ermal
|
}
|
32 |
|
|
|
33 |
4537e922
|
Viktor G
|
$rules = parse_cisco_acl($attributes, 'enc0');
|
34 |
52c9f9fa
|
Ermal
|
if (!empty($rules)) {
|
35 |
eb7d43c0
|
Ermal
|
$pid = posix_getpid();
|
36 |
10d9290f
|
Ermal
|
@file_put_contents("/tmp/ipsec_{$pid}{$common_name}.rules", $rules);
|
37 |
7b27b18b
|
Renato Botelho
|
mwexec("/sbin/pfctl -a " . escapeshellarg("ipsec/{$common_name}") . " -f {$g['tmp_path']}/ipsec_{$pid}" . escapeshellarg($common_name) . ".rules");
|
38 |
10d9290f
|
Ermal
|
@unlink("{$g['tmp_path']}/ipsec_{$pid}{$common_name}.rules");
|
39 |
52c9f9fa
|
Ermal
|
}
|
40 |
|
|
|
41 |
|
|
?>
|