* Fri Mar 5 2004 David Parrish <david@dparrish.com> 1.1.0

- Change all strcpy() calls to strncpy() to avoid buffer overflow potential
- Add ICMP host unreachable support
- Logging to syslog if log_file = "syslog:facility"
- Now requires libcli 1.5
- All configuration moves to a config structure
- Ability to modify and write config on the fly through command-line interface
- Config file support is removed, and now handled by the cli
- Show hostname in cli prompt
- Keep current state type for tunnels
- Add uptime command do CLI, which also shows real-time bandwidth utilisation
- Add goodbye command to cluster master, which forces droppping a slave
- Cache IP address allocation, so that reconnecting users get the same address
- Fix tunnel resend timeouts, so that dead tunnels will be cleaned up
- Allocate tunnels and radius without using a linked list which had issues
- Fix some off-by-one errors in tunnel and session and radius arrays
- Save and reload ip address pool when dieing
- Check version and size of reloaded data when restarting
- Remove plugin_config support
- Remove old support for TBF which didn't work anyway. HTB is required to do throttling now.
- Add COPYING and Changes files
This commit is contained in:
fred_nerk 2004-03-05 00:09:03 +00:00
parent b8ae54f127
commit b43583c01d
22 changed files with 1731 additions and 1248 deletions

View file

@ -1,5 +1,5 @@
// L2TPNS Throttle Stuff
// $Id: throttle.c,v 1.1 2003/12/16 07:07:39 fred_nerk Exp $
// $Id: throttle.c,v 1.2 2004/03/05 00:09:03 fred_nerk Exp $
#include <stdio.h>
#include <sys/file.h>
@ -16,22 +16,17 @@
#include "l2tpns.h"
#include "util.h"
extern char *radiussecret;
extern radiust *radius;
extern sessiont *session;
extern ipt radiusserver[MAXRADSERVER]; // radius servers
extern u32 sessionid;
extern u8 radiusfree;
extern int radfd;
extern u8 numradiusservers;
extern char debug;
extern unsigned long rl_rate;
extern tbft *filter_buckets;
extern struct configt *config;
// Throttle or Unthrottle a session
int throttle_session(sessionidt s, int throttle)
{
if (!rl_rate) return 0;
if (!config->rl_rate) return 0;
if (!*session[s].user)
return 0; // User not logged in
@ -40,9 +35,15 @@ int throttle_session(sessionidt s, int throttle)
{
// Throttle them
char cmd[2048] = {0};
log(2, 0, s, session[s].tunnel, "Throttling session %d for user %s\n", s, session[s].user);
if (!session[s].tbf) session[s].tbf = rl_get_tbf();
snprintf(cmd, 2048, "iptables -t mangle -A throttle -d %s -j MARK --set-mark %d", inet_toa(ntohl(session[s].ip)),
if (!session[s].tbf)
{
log(1, 0, s, session[s].tunnel, "Error creating a filtering bucket for user %s\n", session[s].user);
return 0;
}
log(2, 0, s, session[s].tunnel, "Throttling session %d for user %s\n", s, session[s].user);
snprintf(cmd, 2048, "iptables -t mangle -A throttle -d %s -j MARK --set-mark %d",
inet_toa(ntohl(session[s].ip)),
session[s].tbf);
log(4, 0, s, session[s].tunnel, "Running %s\n", cmd);
system(cmd);