]> CyberLeo.Net >> Repos - FreeBSD/FreeBSD.git/blob - contrib/ipfilter/BNF
This commit was generated by cvs2svn to compensate for changes in r50894,
[FreeBSD/FreeBSD.git] / contrib / ipfilter / BNF
1 filter-rule = [ insert ] action in-out [ options ] [ tos ] [ ttl ]
2               [ proto ] [ ip ] [ group ].
3
4 insert  = "@" decnumber .
5 action  = block | "pass" | log | "count" | skip | auth | call .
6 in-out  = "in" | "out" .
7 options = [ log ] [ "quick" ] [ "on" interface-name [ dup ] [ froute ] ] .
8 tos     = "tos" decnumber | "tos" hexnumber .
9 ttl     = "ttl" decnumber .
10 proto   = "proto" protocol .
11 ip      = srcdst [ flags ] [ with withopt ] [ icmp ] [ keep ] .
12 group   = [ "head" decnumber ] [ "group" decnumber ] .
13
14 block   = "block" [ "return-icmp"[return-code] | "return-rst" ] .
15 auth    = "auth" | "preauth" .
16 log     = "log" [ "body" ] [ "first" ] [ "or-block" ] .
17 call    = "call" [ "now" ] function-name .
18 skip    = "skip" decnumber .
19 dup     = "dup-to" interface-name[":"ipaddr] .
20 froute  = "fastroute" | "to" interface-name .
21 protocol = "tcp/udp" | "udp" | "tcp" | "icmp" | decnumber .
22 srcdst  = "all" | fromto .
23 fromto  = "from" object "to" object .
24
25 object  = addr [ port-comp | port-range ] .
26 addr    = "any" | nummask | host-name [ "mask" ipaddr | "mask" hexnumber ] .
27 port-comp = "port" compare port-num .
28 port-range = "port" port-num range port-num .
29 flags   = "flags" flag { flag } [ "/" flag { flag } ] .
30 with    = "with" | "and" .
31 icmp    = "icmp-type" icmp-type [ "code" decnumber ] .
32 return-code = "("icmp-code")" .
33 keep    = "keep" "state" | "keep" "frags" .
34
35 nummask = host-name [ "/" decnumber ] .
36 host-name = ipaddr | hostname | "any" .
37 ipaddr  = host-num "." host-num "." host-num "." host-num .
38 host-num = digit [ digit [ digit ] ] .
39 port-num = service-name | decnumber .
40
41 withopt = [ "not" | "no" ] opttype [ withopt ] .
42 opttype = "ipopts" | "short" | "frag" | "opt" ipopts  .
43 optname = ipopts [ "," optname ] .
44 ipopts  = optlist | "sec-class" [ secname ] .
45 secname = seclvl [ "," secname ] .
46 seclvl  = "unclass" | "confid" | "reserv-1" | "reserv-2" | "reserv-3" |
47           "reserv-4" | "secret" | "topsecret" .
48 icmp-type = "unreach" | "echo" | "echorep" | "squench" | "redir" |
49             "timex" | "paramprob" | "timest" | "timestrep" | "inforeq" |
50             "inforep" | "maskreq" | "maskrep"  | "routerad" |
51             "routersol" | decnumber .
52 icmp-code = decumber | "net-unr" | "host-unr" | "proto-unr" | "port-unr" |
53             "needfrag" | "srcfail" | "net-unk" | "host-unk" | "isolate" |
54             "net-prohib" | "host-prohib" | "net-tos" | "host-tos" .
55 optlist = "nop" | "rr" | "zsu" | "mtup" | "mtur" | "encode" | "ts" | "tr" |
56           "sec" | "lsrr" | "e-sec" | "cipso" | "satid" | "ssrr" | "addext" |
57           "visa" | "imitd" | "eip" | "finn" .
58
59 hexnumber = "0" "x" hexstring .
60 hexstring = hexdigit [ hexstring ] .
61 decnumber = digit [ decnumber ] .
62
63 compare = "=" | "!=" | "<" | ">" | "<=" | ">=" | "eq" | "ne" | "lt" | "gt" |
64           "le" | "ge" .
65 range   = "<>" | "><" .
66 hexdigit = digit | "a" | "b" | "c" | "d" | "e" | "f" .
67 digit   = "0" | "1" | "2" | "3" | "4" | "5" | "6" | "7" | "8" | "9" .
68 flag    = "F" | "S" | "R" | "P" | "A" | "U" .