From 734d124d582024b87bcfd78bf732e82cdfcbc6a1 Mon Sep 17 00:00:00 2001 From: Kavita Vakkund Date: Tue, 29 Jul 2025 04:38:00 +0000 Subject: [PATCH] RDKBNETWOR-76 : Firewall rules to support wireguard tunnel. Reason for change: Firewall rules to forward the traffic and the port for wireguard communications are added. Test Procedure: Check the firewall rules with the respective traffic flow once the connection is established. Testing Done : Results are captured in RDKBNETWOR-76 Risks: None. Change-Id: I13be7e2c1b945778b611c0c19997886fb7705065 Signed-off-by: Kavita Vakkund --- source/firewall/firewall.c | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/source/firewall/firewall.c b/source/firewall/firewall.c index 0e24d5a2..abdec0f3 100644 --- a/source/firewall/firewall.c +++ b/source/firewall/firewall.c @@ -647,6 +647,8 @@ static char transparent_cache_state[10]; // state of the transparent http cache static char byoi_bridge_mode[10]; // whether or not byoi is in bridge mode static char cmdiag_enabled[20]; // If eCM diagnostic Interface Enabled static char firewall_level[20]; // None, Low, Medium, High, or Custom +static char wireguard_enabled[4]; // Wireguard configuration +static char wireguard_port[8]; static char natip4[20]; static char captivePortalEnabled[50]; //to ccheck captive portal is enabled or not @@ -3090,6 +3092,17 @@ static int prepare_globals_from_configuration(void) rc = syscfg_get(NULL, "http_admin_port", reserved_mgmt_port, sizeof(reserved_mgmt_port)); if (0 != rc || '\0' == reserved_mgmt_port[0]) { snprintf(reserved_mgmt_port, sizeof(reserved_mgmt_port), "80"); + } + + wireguard_enabled[0] = '\0'; + rc = syscfg_get(NULL, "wireguard_enabled", wireguard_enabled, sizeof(wireguard_enabled)); + if (0 != rc || '\0' == wireguard_enabled[0]) { + snprintf(wireguard_enabled, sizeof(wireguard_enabled), "0"); + } + wireguard_port[0] = '\0'; + rc = syscfg_get(NULL, "Wireguard_Port", wireguard_port, sizeof(wireguard_port)); + if (0 != rc || '\0' == wireguard_port[0]) { + snprintf(wireguard_port, sizeof(wireguard_port), "53280"); } /* Get DSCP value for gre */ @@ -12428,6 +12441,14 @@ static int prepare_subtables(FILE *raw_fp, FILE *mangle_fp, FILE *nat_fp, FILE * fprintf(filter_fp, "-A FORWARD -j pp_disabled\n"); #endif + if(wireguard_enabled[0] == '1') { + fprintf(filter_fp, "-A FORWARD -o wg0 -j ACCEPT\n"); + fprintf(filter_fp, "-A FORWARD -i wg0 -j ACCEPT\n"); + fprintf(filter_fp, "-A INPUT -i wg0 -j ACCEPT\n"); + fprintf(filter_fp, "-A OUTPUT -o wg0 -j ACCEPT\n"); + fprintf(filter_fp, "-A INPUT -i erouter0 -p udp --dport %s -j ACCEPT\n",wireguard_port); + } + fprintf(filter_fp, ":%s - [0:0]\n", "lan2wan"); #ifdef CONFIG_CISCO_FEATURE_CISCOCONNECT