Actions

Tom Eastep

Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License, Version 1.2 or any later version published by the Free Software Foundation; with no Invariant Sections, with no Front-Cover, and with no Back-Cover Texts. A copy of the license is included in the section entitled GNU Free Documentation License.

2016/03/26


Caution

This article applies to Shorewall 4.3 and later. If you are running a version of Shorewall earlier than Shorewall 4.3.5 then please see the documentation for that release.

What are Shorewall Actions?

Shorewall actions allow a symbolic name to be associated with a series of one or more iptables rules. The symbolic name may appear in the ACTION column of an /etc/shorewall/rules entry, in a macro body and within another action, in which case the traffic matching that rules file entry will be passed to the series of iptables rules named by the action.

Actions can be thought of as templates. When an action is invoked in an /etc/shorewall/rules entry, it may be qualified by a logging specification (log level and optionally a log tag). The presence of the log level/tag causes a modified series of rules to be generated in which each packet/rule match within the action causes a log message to be generated.

For readers familiar with iptables, actions are the way in which you can create your own filter-table chains.

There are three types of Shorewall actions:

  1. Built-in Actions. These actions are known by the Shorewall code itself. They are listed in the comments at the top of the file /usr/share/shorewall/actions.std.

  2. Standard Actions. These actions are released as part of Shorewall. They are listed in the file /usr/share/shorewall/actions.std and are defined in the corresponding action.* files in /usr/share/shorewall. Each action.* file has a comment at the beginning of the file that describes what the action does. As an example, here is the definition of the AllowSMB standard action from Shorewall version 2.2.

    #
    # Shorewall 2.2 /usr/share/shorewall/action.AllowSMB
    #
    #       Allow Microsoft SMB traffic. You need to invoke this action in
    #       both directions.
    #
    ######################################################################################
    #TARGET  SOURCE         DEST            PROTO   DPORT   SPORT           RATE    USER
    ACCEPT   -              -               udp     135,445
    ACCEPT   -              -               udp     137:139
    ACCEPT   -              -               udp     1024:   137
    ACCEPT   -              -               tcp     135,139,445

    If you wish to modify one of the standard actions, do not modify the definition in /usr/share/shorewall. Rather, copy the file to /etc/shorewall (or somewhere else on your CONFIG_PATH) and modify the copy.

    Standard Actions have been largely replaced by macros .

  3. User-defined Actions. These actions are created by end-users. They are listed in the file /etc/shorewall/actions and are defined in action.* files in /etc/shorewall or in another directory listed in your CONFIG_PATH (defined in /etc/shorewall/shorewall.conf).

Default Actions (Formerly Common Actions)

Shorewall allows the association of a default action with policies. A separate default action may be associated with ACCEPT, DROP, REJECT, QUEUE and NFQUEUE policies. Default actions provide a way to invoke a set of common rules just before the policy is enforced. Default actions accomplish two goals:

  1. Relieve log congestion. Default actions typically include rules to silently drop or reject traffic that would otherwise be logged when the policy is enforced.

  2. Ensure correct operation.

Shorewall supports default actions for the ACCEPT, REJECT, DROP, QUEUE and NFQUEUE policies. These default actions are specified in the /etc/shorewall/shorewall.conf file using the ACCEPT_DEFAULT, REJECT_DEFAULT, DROP_DEFAULT, QUEUE_DEFAULT and NFQUEUE_DEFAULT options respectively. Policies whose default is set to a value of none have no default action.

In addition, the default specified in /etc/shorewall/shorewall.conf may be overridden by specifying a different action in the POLICY column of /etc/shorewall/policy.

Important

Entries in the DROP and REJECT default actions ARE NOT THE CAUSE OF CONNECTION PROBLEMS. Remember — default actions are only invoked immediately before the packet is going to be dropped or rejected anyway!!!

Beginning with Shorewall 4.4.21, the standard Drop and Reject options are parameterized. Each has five parameters as follows:

ACTIONPARAMETERVALUEDEFAULT
Drop1Either '-' or 'audit'. 'audit' causes auditing by the builtin actions invoked by Drop-
Drop2Determines what to do with Auth requests-
Drop3Determines what to do with SMBDROP or A_DROP depending on the setting of parameter 1
Reject1Either '-' or 'audit'. 'audit' causes auditing by the builtin actions invoked by Drop-
Reject2Determines what to do with Auth requests-
Reject3Determines what to do with SMBREJECT or A_REJECT depending on the setting of parameter 1
Both4Determines what to do with accepted critical ICMP packets.ACCEPT or A_ACCEPT depending on the setting of parameter 1
Both5Determines what to do with late-arriving DNS replies (source port 53) or UPnP (udp port 1900).DROP or A_DROP depending on the setting of parameter 1.

The parameters may be specified in either shorewall.conf (e.g., DROP_DEFAULT=Drop(-,DROP) or in the POLICY column of shorewall-policy(5) (e.g., DROP:Drop(audit):audit).

Defining your own Actions

Before defining a new action, you should evaluate whether your goal can be best accomplished using an action or a macro. See this article for details.

To define a new action:

  1. Add a line to /etc/shorewall/actions that names your new action. Action names must be valid shell variable names (must begin with a letter and be composed of letters, digits and underscore characters) as well as valid Netfilter chain names. If you intend to log from the action, the name must have a maximum of 11 characters. It is recommended that the name you select for a new action begins with a capital letter; that way, the name won't conflict with a Shorewall-defined chain name.

    Normally. the rules in an action are placed in a separate chain. Beginning with Shorewall 4.5.10, the action rules can be expanded inline in a manner similar to a macro by specifying inline in the OPTIONS column of /etc/shorewall/actions.

    Beginning in Shorewall 4.5.11, the nolog option may be specified; see the logging section below for details.

    Shorewall includes pre-defined actions for DROP and REJECT -- see above.

  2. Once you have defined your new action name (ActionName), then copy /usr/share/shorewall/action.template to /etc/shorewall/action.ActionName (for example, if your new action name is Foo then copy /usr/share/shorewall/action.template to /etc/shorewall/action.Foo).

  3. Now modify the new file to define the new action.

Shorewall 5.0.0 and Later.

In Shorewall 5.0, the columns in action.template are the same as those in shorewall-rules (5). There are no restrictions regarding which targets can be used within your action.

The SOURCE and DEST columns in the action file may not include zone names; those are given when the action is invoked.

Additionally, it is possible to pass parameters to an action, when it is invoked in the rules file or in another action.

Here's a trivial example:

/etc/shorewall/action.A:

#TARGET        SOURCE  DEST    PROTO   Dport   SPORT   ORIGDEST
$1             -       -       tcp     80      -       1.2.3.4

/etc/shorewall/rules:

#TARGET        SOURCE  DEST    PROTO   DPORT   SPORT   ORIGDEST

A(REDIRECT)    net     fw

The above is equivalent to this rule:

#TARGET        SOURCE  DEST    PROTO   DPORT   SPORT   ORIGDEST
REDIRECT       net     -       tcp     80      -       1.2.3.4

You can 'omit' parameters by using '-'.

Example: ACTION(REDIRECT,-,info)

In the above example, $2 would expand to nothing.

Beginning with Shorewall 4.5.13, completely omitting a arameter is equivalent to passing '-'.

Example: ACTION(REDIRECT,,info)

This example behaves the same as the one shown above.

If you refer to a parameter $n in the body of the action, then the nth paramer must either be passed to all action invocations or it's default value must be established via a DEFAULTS line.

If you want to make '-' a parameter value, use '--' (e.g., ACTION(REDIRECT,--.info)).

Beginning with Shorewall 4.4.21, you can specify the default values of your FORMAT-2 actions:

DEFAULTS def1,def2,...

where def1 is the default value for the first parameter, def2 is the default value for the second parameter and so on. You can specify an empty default using '-' (e.g. DEFAULTS DROP,-,audit).

For additional information about actions, see the Action Variables section of the Configuration Basics article.

Mangle Actions

Beginning with Shorewall 5.0.7, actions may be used in shorewall-mangle(5) and shorewall6-mangle(5). Because the rules and mangle files have different column layouts, actions can be defined to be used in one file or the other but not in both. To designate an action to be used in the mangle file, specify the mangle option in the action's entry in shorewall-actions(5) or shorewall6-actions(5).

To create a mangle action, follow the steps in the preceding section, but use the /usr/share/shorewall/action.mangletemplate file.

Actions and Logging

Specifying a log level in a rule that specifies a user-defined or Shorewall-defined action will cause each rule in the action to be logged with the specified level (and tag), unless the nolog option is specified in the action's entry in /etc/shorewall/actions.

The extent to which logging of action rules occur is governed by the following:

  1. When you invoke an action and specify a log level, only those rules in the action that have no log level will be changed to log at the level specified at the action invocation.

    Example:

    /etc/shorewall/action.foo

    #TARGET      SOURCE     DEST     PROTO    DPORT
    ACCEPT       -          -        tcp      22
    bar:info

    /etc/shorewall/rules:

    #ACTION      SOURCE     DEST     PROTO    DPORT
    foo:debug    $FW         net

    Logging in the invoke foo action will be as if foo had been defined as:

    #TARGET      SOURCE     DEST     PROTO    DPORT
    ACCEPT:debug -          -        tcp      22
    bar:info
  2. If you follow the log level with ! then logging will be set at that level for all rules recursively invoked by the action.

    Example:

    /etc/shorewall/action.foo

    #TARGET      SOURCE     DEST     PROTO    DPORT
    ACCEPT       -          -        tcp      22
    bar:info

    /etc/shorewall/rules:

    #ACTION      SOURCE     DEST     PROTO    DPORT
    foo:debug!   $FW        net

    Logging in the invoke foo action will be as if foo had been defined as:

    #TARGET      SOURCE     DEST     PROTO    DPORT
    ACCEPT:debug -          -        tcp      22
    bar:debug

Using Embedded Perl in an Action

There may be cases where you wish to create a chain with rules that can't be constructed using the tools defined in the action.template. Such rules can be constructed using Embedded Perl. For those who are comfortable using Perl, embedded Perl is more efficient that using complicated conditional entries. The Perl compiler is invoked only once for a BEGIN PERL...END PERL block; it is invoked most times that an expression is evaluated in an ?IF, ?ELSEIF or ?SET directive.

The Shorewall compiler provides a set of services that are available to Perl code embedded in an action file. These services are not available in in-line actions when running Shorewall 4.5.12 or earlier.

Shorewall::Config::get_action_params( $howmany )

This function returns an array containing the functions parameters. The scalar argument $howmany is the number of parameters that you expect to be passed. You can ensure that at least this many parameters are passed by including a DEFAULTS line prior to the embedded Perl.

Shorewall::Config::set_action_param( $ordinal, $value )

Set the value of parameter $ordinal to $value. Care must be take when using this function such that for a given set of parameters actually passed to the action, the same rules are created. That is because the compiler assumes that all invocations of an action with the same parameters, log level and log tag can share the same action chain.

Shorewall::Config::get_action_chain()

This function returns a reference to the chain table entry for the current action chain.

Shorewall::Config::get_action_logging()

Returns a two-element list containing the the log level and log tag specified when the action was invoked. Note that you must use this function rather than @loglevel and @logtag within embedded Perl, as the compiler does not expand Shorewall Variables within embedded Perl (or embedded shell).

Shorewall::Config::push_comment()

Prior to Shorewall 4.5.21, this required:

use Shorewall::Config (:DEFAULT :internal);

Returns the current rule comment to the caller and clears the comment. The returned comment may be restored by calling either pop_comment() or set_comment().

Shorewall::Config::pop_comment($comment) and Shorewall::Config::set_comment($comment).

The set_comment() function was added in Shorewall 4.5.21. Prior to that release, accessing pop_comment() required:

use Shorewall::Config (:DEFAULT :internal);

These functions are identical and set the current rule comment to the contents of the passed simple variable.

Shorewall::Chains::add_rule( $chainref, $rule [, $expandports ] )

This function adds a rule to a chain. As of Shoreall 4.5.13, it is deprecated in favor of Shorewall::Rules::perl_action_helper(). Arguments are:

$chainref

Normally, you get this from get_action_chain() described above.

$rule

The matches and target for the rule that you want added.

$expandports (optional)

This optional argument is for compiler-internal use only. Either omit it or pass a false value.

Warning

Do not call this function in a inline action. Use perl_action_helper() instead (see below).

Shorewall::Chains::log_rule_limit( $level, $chainref, $chain, $disposition, $limit, $tag, $command, $matches )

This function adds a logging rule to a chain. As of Shoreall 4.5.13, it is deprecated in favor of Shorewall::Rules::perl_action_helper(). Arguments are:

$level

Either a syslog level or a ULOG or NFLOG target expression (e.g., "NFLOG(1,0,1)"). Specifies how you want the logging done.

$chainref

Normally, you get this from get_action_chain() described above.

$chain

The value you want substituted for the first %s formatting directive in the LOGFORMAT setting in /etc/shorewall/shorewall.conf.

$disposition

This is the value substituted for the second '%s' formatting directive in the LOGFORMAT setting in /etc/shorewall/shorewall.conf.

$limit

If you want to use the default limit set in LOGLIMIT (/etc/shorewall/shorewall.conf), you can specify your own '-limit' match. Otherwise, if you want to use the default, pass 0 or "". If you want the rule to be unlimited, pass '-'.

$tag

Log tag.

$command

Pass 'add' here, unless you want the rule to be inserted at the front of the chain.

$matches

Zero or more iptables matches that limit when logging will occur. If this parameter is other than the empty string, the last character must be a space.

Shorewall::Chains::allow::optimize( $chainref )

This allows the passed action chain to be optimized away (jumps to the chain are replaced by the chain's rule(s)). The chainref argument is usually obtained from get_action_chain() described above.

Shorewall::Rules::perl_action_helper( $target, $matches )

This function adds a rule to the current chain. For a regular action, the chain will be an action chain; for an inline action, the chain is determined by the invoking rule.

To use this function, you must include:

use Shorewall::Rules;

Arguments are:

$target

The target of the rule. Legal values are anything that can appear in the TARGET column of in an action body and may include log level, tag, and parameters.

$matches

ip[6]tables matches to be included in the rule. When called in an inline action, these matches are augmented by matches generated by the invoking rule.

Note

This function has additional optional arguments which are used internally by Shorewall standard actions. Their number and behavior is likely to change in future Shorewall releases.

Shorewall::Rules::perl_action_tcp_helper( $target, $proto )

This function is similar to Shorewall::Rules::perl_action_helper but is taylored for specifying options to "-p tcp".

To use this function, you must include:

use Shorewall::Rules;

Arguments are:

$target

The target of the rule. Legal values are anything that can appear in the TARGET column of in an action body and may include log level, tag, and parameters.

$proto

The '-p' part of the rule to be generated (e.g., "-p tcp --tcp-flags RST RST").

For examples of using these services, look at the standard actions in /usr/share/shorewall/action.*.

Creating an Action using an Extension Script (deprecated in favor of BEGIN PERL ... END PERL)

There may be cases where you wish to create a chain with rules that can't be constructed using the tools defined in the action.template. In that case, you can use an extension script. Beginning with Shorewall 4.5.16, such scripts require CHAIN_SCRIPTS=Yes in shorewall.conf (5)

Note

If you actually need an action to drop broadcast packets, use the dropBcast standard action rather than create one like this.

Example 1. An action to drop all broadcast packets

If you define an action acton and you have an /etc/shorewall/acton script, the rules compiler sets lexical variables as follows:

  • $chainref is a reference to the chain-table entry for the chain where your rules are to be placed.

  • $level is the log level. If false, no logging was specified.

  • $tag is the log tag.

  • @params is the list of parameter values (Shorewall 4.4.16 and later). 'Omitted' parameters contain '-'.

Example:

/etc/shorewall/actions

DropBcasts

/etc/shorewall/action.DropBcasts

# This file is empty

/etc/shorewall/DropBcasts

use Shorewall::Chains;

if ( $level ne '' ) {
    log_rule_limit $level, $chainref, 'dropBcast' , 'DROP', '', $tag, 'add', ' -m addrtype --dst-type BROADCAST ';
    log_rule_limit $level, $chainref, 'dropBcast' , 'DROP', '', $tag, 'add', ' -d 224.0.0.0/4 ';
}

add_rule $chainref, '-m addrtype --dst-type BROADCAST -j DROP';
add_rule $chainref, '-d 224.0.0.0/4 -j DROP';

1;

For a richer example, see the next section.

Limiting Per-IP Connection Rate using the Limit Action

Shorewall supports a Limit built-in action. Prior to Shorewall 4.4.16, Limit is invoked with a comma-separated list in place of a logging tag. Beginning in Shorewall 4.4.16, it may also be invoked with a list of three parameters enclosed in parentheses. The list has three elements:

  1. The name of a recent list. You select the list name which must conform to the rules for a valid chain name. Different rules that specify the same list name will use the same set of counters.

  2. The number of connections permitted in a specified time period.

  3. The time period, expressed in seconds.

Connections that exceed the specified rate are dropped.

For example, to use a recent list name of SSHA, and to limit SSH connections to 3 per minute, use this entry in /etc/shorewall/rules:

#ACTION                SOURCE            DEST           PROTO       DPORT
Limit:none:SSHA,3,60   net               $FW            tcp         22

Using Shorewall 4.4.16 or later, you can also invoke the action this way:

#ACTION                SOURCE            DEST           PROTO       DPORT
Limit(SSHA,3,60):none  net               $FW            tcp         22

If you want dropped connections to be logged at the info level, use this rule instead:

#ACTION                SOURCE            DEST           PROTO       DPORT
Limit:info:SSHA,3,60   net               $FW            tcp         22

Shorewall 4.4.16 and later:

#ACTION                SOURCE            DEST           PROTO       DPORT
Limit(SSH,3,60):info   net               $FW            tcp         22

To summarize, you pass four pieces of information to the Limit action:

  • The log level. If you don't want to log, specify none.

  • The name of the recent list that you want to use (SSHA in this example).

  • The maximum number of connections to accept (3 in this example).

  • The number of seconds over which you are willing to accept that many connections (60 in this example).

How Limit is Implemented

For those who are curious, the Limit action in Shorewall 4.4.16 is implemented as follows:

use Shorewall::Chains;

@params = split( /,/, $tag ), $tag='' unless @params;

fatal_error 'Limit rules must include <list name>,<max connections>,<interval> as the log tag or params' unless @params == 3;

my $list = $params[0];

for ( @params[1,2] ) {
    fatal_error 'Max connections and interval in Limit rules must be numeric (' . $_ . ')' unless /^\d+$/
}

my $count = $params[1] + 1;

add_rule $chainref, "-m recent --name $list --set";

if ( $level ) {
    my $xchainref = new_chain 'filter' , "$chainref->{name}%";
    log_rule_limit $level, $xchainref, $params[0], 'DROP', $tag, '', 'add', '';
    add_rule $xchainref, '-j DROP';
    add_rule $chainref,  "-m recent --name $list --update --seconds $params[2] --hitcount $count -j $xchainref->{name}";
} else {
    add_rule $chainref, "-m recent --update --name $list --seconds $params[2] --hitcount $count -j DROP";
}

add_rule $chainref, '-j ACCEPT';

1; 

Documentation


Frequently Used Articles

- FAQs - IPv4 Manpages - IPv6 Manpages - Configuration File Basics - Beginner Documentation - Troubleshooting

Shorewall 4.4/4.5/4.6 Documentation

Shorewall 4.0/4.2 Documentation


Shorewall 5.0 HOWTOs and Other Articles

- 6to4 and 6in4 Tunnels - Accounting - Actions - Aliased (virtual) Interfaces (e.g., eth0:0) - Anatomy of Shorewall - Anti-Spoofing Measures - AUDIT Target support - Bandwidth Control - Blacklisting/Whitelisting - Bridge/Firewall - Building Shorewall from GIT - Commands - Compiled Programs - Configuration File Basics - DHCP - DNAT - Docker - Dynamic Zones - ECN Disabling by host or subnet - Events - Extension Scripts - Fallback/Uninstall - FAQs - Features - Fool's Firewall - Forwarding Traffic on the Same Interface - FTP and Shorewall - Helpers/Helper Modules - Installation/Upgrade - IPP2P - IPSEC - Ipsets - IPv6 Support - ISO 3661 Country Codes - Kazaa Filtering - Kernel Configuration - KVM (Kernel-mode Virtual Machine) - Limiting Connection Rates - Linux Containers (LXC) - Linux-vserver - Logging - Macros - MAC Verification - Manpages (IPv4) (IPv6) - Manual Chains - Masquerading - Multiple Internet Connections from a Single Firewall - Multiple Zones Through One Interface - My Shorewall Configuration - Netfilter Overview - Network Mapping - No firewalling of traffic between bridge port - One-to-one NAT - Operating Shorewall - OpenVPN - OpenVZ - Packet Marking - Packet Processing in a Shorewall-based Firewall - 'Ping' Management - Port Forwarding - Port Information - Port Knocking (deprecated) - Port Knocking, Auto Blacklisting and Other Uses of the 'Recent Match' - PPTP - Proxy ARP - QuickStart Guides - Release Model - Requirements - Routing and Shorewall - Routing on One Interface - Samba - Shorewall Events - Shorewall Init - Shorewall Lite - Shorewall on a Laptop - Shorewall Perl - Shorewall Setup Guide - SMB - SNAT - Split DNS the Easy Way - Squid with Shorewall - Starting/stopping the Firewall - Static (one-to-one) NAT - Support - Tips and Hints - Traffic Shaping/QOS - Simple - Traffic Shaping/QOS - Complex - Transparent Proxy - UPnP - Upgrade Issues - Upgrading to Shorewall 4.4 (Upgrading Debian Lenny to Squeeze) - VPN - VPN Passthrough - White List Creation - Xen - Shorewall in a Bridged Xen DomU - Xen - Shorewall in Routed Xen Dom0

Top of Page