From 9573afa82f3cd2a6e76da3a32eb625aec559e876 Mon Sep 17 00:00:00 2001 From: Stephen Beaver Date: Mon, 4 Apr 2016 14:40:12 -0400 Subject: [PATCH] Fixed #6049 (cherry picked from commit 4260c32a42c6d0201737730a373e795703ca1141) --- src/usr/local/www/status_ipsec.php | 838 ++++++++++++++++------------- 1 file changed, 450 insertions(+), 388 deletions(-) diff --git a/src/usr/local/www/status_ipsec.php b/src/usr/local/www/status_ipsec.php index 21a6fa93d8..fe49d745b9 100644 --- a/src/usr/local/www/status_ipsec.php +++ b/src/usr/local/www/status_ipsec.php @@ -64,15 +64,16 @@ ##|*MATCH=status_ipsec.php* ##|-PRIV +require("guiconfig.inc"); +require_once("ipsec.inc"); global $g; -$pgtitle = array(gettext("Status"), gettext("IPsec"), gettext("Overview")); -$shortcut_section = "ipsec"; - -require("guiconfig.inc"); -include("head.inc"); -require_once("ipsec.inc"); +// If this is just an AJAX call to update the table body, just generate the body and quit +if ($_REQUEST['ajax']) { + print_ipsec_body(); + exit; +} if ($_GET['act'] == 'connect') { if (ctype_digit($_GET['ikeid'])) { @@ -111,9 +112,379 @@ if (!is_array($config['ipsec']['phase1'])) { $config['ipsec']['phase1'] = array(); } -$a_phase1 = &$config['ipsec']['phase1']; +// Table body is composed here so that it can be more easily updated via AJAX +function print_ipsec_body() { + global $config; -$status = ipsec_list_sa(); + $a_phase1 = &$config['ipsec']['phase1']; + $status = ipsec_list_sa(); + $ipsecconnected = array(); + + if (is_array($status)) { + foreach ($status as $ikeid => $ikesa) { + $con_id = substr($ikeid, 3); + + if ($ikesa['version'] == 1) { + $ph1idx = substr($con_id, 0, strrpos(substr($con_id, 0, -1), '00')); + $ipsecconnected[$ph1idx] = $ph1idx; + } else { + $ipsecconnected[$con_id] = $ph1idx = $con_id; + } + + print("\n"); + print("\n"); + print(htmlspecialchars(ipsec_get_descr($ph1idx))); + print("\n"); + print("\n"); + + if (!empty($ikesa['local-id'])) { + if ($ikesa['local-id'] == '%any') { + print(gettext('Any identifier')); + } else { + print(htmlspecialchars($ikesa['local-id'])); + } + } else { + print(gettext("Unknown")); + } + + print("\n"); + print("\n"); + + if (!empty($ikesa['local-host'])) { + print(htmlspecialchars($ikesa['local-host'])); + } else { + print(gettext("Unknown")); + } + + /* + * XXX: local-nat-t was defined by pfSense + * When strongswan team accepted the change, they changed it to + * nat-local. Keep both for a while and remove local-nat-t in + * the future + */ + if (isset($ikesa['local-nat-t']) || isset($ikesa['nat-local'])) { + print("NAT-T"); + } + + print("\n"); + print("\n"); + + $identity = ""; + if (!empty($ikesa['remote-id'])) { + if ($ikesa['remote-id'] == '%any') { + $identity = htmlspecialchars(gettext('Any identifier')); + } else { + $identity = htmlspecialchars($ikesa['remote-id']); + } + } + + if (!empty($ikesa['remote-xauth-id'])) { + echo htmlspecialchars($ikesa['remote-xauth-id']); + echo "
{$identity}"; + } elseif (!empty($ikesa['remote-eap-id'])) { + echo htmlspecialchars($ikesa['remote-eap-id']); + echo "
{$identity}"; + } else { + if (empty($identity)) { + print(gettext("Unknown")); + } else { + print($identity); + } + } + + print("\n"); + print("\n"); + + if (!empty($ikesa['remote-host'])) { + print(htmlspecialchars($ikesa['remote-host'])); + } else { + print(gettext("Unknown")); + } + /* + * XXX: remote-nat-t was defined by pfSense + * When strongswan team accepted the change, they changed it to + * nat-remote. Keep both for a while and remove remote-nat-t in + * the future + */ + if (isset($ikesa['remote-nat-t']) || isset($ikesa['nat-remote'])) { + print(" NAT-T"); + } + + print("\n"); + print("\n"); + print("IKEv" . htmlspecialchars($ikesa['version'])); + print("
\n"); + + if ($ikesa['initiator'] == 'yes') { + print("initiator"); + } else { + print("responder"); + } + + print("\n"); + print("\n"); + print(htmlspecialchars($ikesa['reauth-time']) . gettext(" seconds (") . convert_seconds_to_hms($ikesa['reauth-time']) . ")"); + print("\n"); + print("\n"); + print(htmlspecialchars($ikesa['encr-alg'])); + print("
"); + print(htmlspecialchars($ikesa['integ-alg'])); + print("
"); + print(htmlspecialchars($ikesa['prf-alg'])); + print("
\n"); + print(htmlspecialchars($ikesa['dh-group'])); + print("\n"); + print("\n"); + + if ($ikesa['state'] == 'ESTABLISHED') { + print(''); + } else { + print(''); + } + + print(ucfirst(htmlspecialchars($ikesa['state']))); + print("
" . htmlspecialchars($ikesa['established']) . gettext(" seconds (" . convert_seconds_to_hms($ikesa['established']) . ") ago")); + print("
"); + print("\n"); + print("\n"); + + if ($ikesa['state'] != 'ESTABLISHED') { + + print(''); + print(''); + print(gettext("Connect VPN")); + print("\n"); + + } else { + + print(''); + print(''); + print(gettext("Disconnect")); + print("
\n"); + + } + + print("\n"); + print("\n"); + print("\n"); + print("\n"); + + if (is_array($ikesa['child-sas']) && (count($ikesa['child-sas']) > 0)) { + + print('\n"); + + print(''); + print("\n"); + print(''); + print(''); + print(''); + print(''); + print(''); + print(''); + print(''); + print(''); + print("\n"); + print("\n"); + + foreach ($ikesa['child-sas'] as $childid => $childsa) { + print(""); + print("\n"); + print("\n"); + print("\n"); + print("\n"); + print("\n"); + print("\n"); + print("\n"); + print("\n"); + + } + + print("\n"); + print(" \n"); + print("\n"); + print(" /tr>\n"); + + } + + unset($con_id); + } + + } + + $rgmap = array(); + foreach ($a_phase1 as $ph1ent) { + if (isset($ph1ent['disabled'])) { + continue; + } + + $rgmap[$ph1ent['remote-gateway']] = $ph1ent['remote-gateway']; + + if ($ipsecconnected[$ph1ent['ikeid']]) { + continue; + } + + print("\n"); + print("\n"); + + print(htmlspecialchars($ph1ent['descr'])); + print("\n"); + print("\n"); + list ($myid_type, $myid_data) = ipsec_find_id($ph1ent, "local"); + + if (empty($myid_data)) { + print(gettext("Unknown")); + } else { + print(htmlspecialchars($myid_data)); + } + + print("\n"); + print("\n"); + $ph1src = ipsec_get_phase1_src($ph1ent); + + if (empty($ph1src)) { + print(gettext("Unknown")); + } else { + print(htmlspecialchars($ph1src)); + } + + print("\n"); + print("\n"); + + list ($peerid_type, $peerid_data) = ipsec_find_id($ph1ent, "peer", $rgmap); + + if (empty($peerid_data)) { + print(gettext("Unknown")); + } else { + print(htmlspecialchars($peerid_data)); + } + print(" \n"); + print(" \n"); + $ph1src = ipsec_get_phase1_dst($ph1ent); + + if (empty($ph1src)) { + print(gettext("Unknown")); + } else { + print(htmlspecialchars($ph1src)); + } + + print("\n"); + print("\n"); + print("\n"); + print("\n"); + print("\n"); + print("\n"); + print("\n"); + + if (isset($ph1ent['mobile'])) { + + print("\n"); + print(gettext("Awaiting connections")); + print("\n"); + print("\n"); + print("\n"); + print("\n"); + } else { + + print("\n"); + print(gettext("Disconnected")); + print("\n"); + print("\n"); + print(''); + print(''); + print(gettext("Connect VPN")); + print("\n"); + print("\n"); + + } + print("\n"); + } + + unset($ipsecconnected, $phase1, $rgmap); +} + +$pgtitle = array(gettext("Status"), gettext("IPsec"), gettext("Overview")); +$shortcut_section = "ipsec"; + +include("head.inc"); $tab_array = array(); $tab_array[] = array(gettext("Overview"), true, "status_ipsec.php"); @@ -141,400 +512,91 @@ display_top_tabs($tab_array); - - $ikesa) { - $con_id = substr($ikeid, 3); - - if ($ikesa['version'] == 1) { - $ph1idx = substr($con_id, 0, strrpos(substr($con_id, 0, -1), '00')); - $ipsecconnected[$ph1idx] = $ph1idx; - } else { - $ipsecconnected[$con_id] = $ph1idx = $con_id; - } -?> + - - - - - - - - - - -{$identity}"; - } elseif (!empty($ikesa['remote-eap-id'])) { - echo htmlspecialchars($ikesa['remote-eap-id']); - echo "
{$identity}"; - } else { - if (empty($identity)) { - print(gettext("Unknown")); - } else { - print($identity); - } - } -?> - - - - - - IKEv -
- - - - - - - -
- -
- -
- - - -'); - } else { - print(''); - } -?> - -
-
- - - - " > - - - - - "> - - -
- + + - - - 0)) { -?> - - - - - - - - - - - - - - - - $childsa) { -?> - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +'); +} else { + print('
'); +} + +print_info_box(sprintf(gettext('IPsec can be configured %1$shere%2$s.'), '', ''), 'info', false); +?> +
+ - -
- -
-', ''), 'info', false); -?> -