Scroll to navigation

KNET_LINK_ADD_ACL(3) Kronosnet Programmer's Manual KNET_LINK_ADD_ACL(3)

NAME

knet_link_add_acl - Add access list entry to an open link.

SYNOPSIS

#include <libknet.h>

int knet_link_add_acl(

knet_handle_t knet_h,
knet_node_id_t host_id,
uint8_t link_id,
struct sockaddr_storage *ss1,
struct sockaddr_storage *ss2,
check_type_t type,
check_acceptreject_t acceptreject );

DESCRIPTION

knet_link_add_acl

knet_h - pointer to knet_handle_t

host_id - see knet_host_add(3)

link_id - see knet_link_set_config(3)

ss1 / ss2 / type / acceptreject - see typedef definitions for details

IMPORTANT: the order in which access lists are added is critical and it is left to the user to add them in the right order. knet will not attempt to logically sort them.

For example: 1 - accept from 10.0.0.0/8 2 - reject from 10.0.0.1/32

is not the same as:

1 - reject from 10.0.0.1/32 2 - accept from 10.0.0.0/8

In the first example, rule number 2 will never match because packets from 10.0.0.1 will be accepted by rule number 1.

STRUCTURES


enum check_type_t {



CHECK_TYPE_ADDRESS;
CHECK_TYPE_MASK;
CHECK_TYPE_RANGE; };


enum check_acceptreject_t {



CHECK_ACCEPT;
CHECK_REJECT; };

RETURN VALUE

knet_link_add_acl returns 0 on success. -1 on error and errno is set.

SEE ALSO

knet_handle_remove_datafd(3), knet_handle_get_stats(3), knet_host_add(3), knet_handle_pmtud_setfreq(3), knet_handle_pmtud_get(3), knet_handle_crypto_use_config(3), knet_host_get_id_by_host_name(3), knet_host_get_status(3), knet_link_get_pong_count(3), knet_link_get_priority(3), knet_handle_free(3), knet_handle_enable_sock_notify(3), knet_handle_get_datafd(3), knet_recv(3), knet_link_get_ping_timers(3), knet_log_get_subsystem_id(3), knet_host_remove(3), knet_host_enable_status_change_notify(3), knet_strtoaddr(3), knet_link_rm_acl(3), knet_send(3), knet_handle_enable_pmtud_notify(3), knet_handle_get_transport_reconnect_interval(3), knet_link_get_enable(3), knet_link_set_priority(3), knet_log_set_loglevel(3), knet_handle_get_channel(3), knet_link_get_config(3), knet_link_get_link_list(3), knet_get_transport_list(3), knet_get_transport_id_by_name(3), knet_log_get_loglevel_id(3), knet_handle_new_ex(3), knet_host_set_name(3), knet_addrtostr(3), knet_handle_setfwd(3), knet_get_compress_list(3), knet_host_set_policy(3), knet_get_transport_name_by_id(3), knet_handle_enable_filter(3), knet_handle_crypto_rx_clear_traffic(3), knet_handle_compress(3), knet_link_get_status(3), knet_handle_add_datafd(3), knet_send_sync(3), knet_log_get_loglevel_name(3), knet_handle_enable_access_lists(3), knet_host_get_host_list(3), knet_host_get_policy(3), knet_link_set_enable(3), knet_link_set_pong_count(3), knet_log_get_subsystem_name(3), knet_host_get_name_by_host_id(3), knet_link_clear_config(3), knet_log_get_loglevel(3), knet_handle_new(3), knet_handle_pmtud_getfreq(3), knet_handle_pmtud_set(3), knet_handle_clear_stats(3), knet_link_set_config(3), knet_handle_crypto_set_config(3), knet_handle_crypto(3), knet_get_crypto_list(3), knet_handle_set_transport_reconnect_interval(3), knet_link_clear_acl(3), knet_link_set_ping_timers(3), knet_link_insert_acl(3)

COPYRIGHT

Copyright (C) 2010-2023 Red Hat, Inc. All rights reserved.

2023-01-04 kronosnet