Примеры автоматизации **pfSense** через консоль с использованием **PHP shell** Поместить файлы в директорию /etc/phpshellsessions/ \\ Использование /usr/local/sbin/pfSsh.php playback <сценарий> ====== Генерация лимитеров ====== require_once("config.inc"); require_once("util.inc"); require_once("service-utils.inc"); global $g, $config, $argv, $command_split; $s_list = array('1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '15', '20', '25', '30', '40', '50', '60', '70', '80', '90', '100', '150', '200', '250', '300', '500', '1000'); $config['dnshaper'] = array('queue' => array()); for($i = 0; $i < count($s_list); $i++) { $config['dnshaper']['queue'][] = Array ( 'name' => $s_list[$i] . 'mbit_up', 'number' => ($i+1), 'qlimit' => '', 'plr' => '', 'description' =>'', 'bandwidth' => Array ( 'item' => Array ( '0' => Array ( 'bw' => $s_list[$i], 'burst' => '', 'bwscale' => 'Mb', 'bwsched' => 'none' ) ) ), 'enabled' => 'on', 'buckets' => '', 'mask' => 'srcaddress', 'maskbits' => '32', 'maskbitsv6' => '128', 'delay' => '0', 'sched' => 'wf2q+', 'aqm' => 'droptail', 'ecn' => '' ); } for($i = 27; $i < (count($s_list)+27); $i++) { $config['dnshaper']['queue'][] = Array ( 'name' => $s_list[($i-27)] . 'mbit_down', 'number' => ($i), 'qlimit' => '', 'plr' => '', 'description' =>'', 'bandwidth' => Array ( 'item' => Array ( '0' => Array ( 'bw' => $s_list[($i-27)], 'burst' => '', 'bwscale' => 'Mb', 'bwsched' => 'none' ) ) ), 'enabled' => 'on', 'buckets' => '', 'mask' => 'dstaddress', 'maskbits' => '32', 'maskbitsv6' => '128', 'delay' => '0', 'sched' => 'wf2q+', 'aqm' => 'droptail', 'ecn' => '' ); } write_config(); print_r($config['dnshaper']); ====== Генерация списка алиасов ====== require_once("config.inc"); require_once("util.inc"); require_once("service-utils.inc"); function usage() { echo "Usage: /usr/local/sbin/pfSsh.php playback maker_als \n"; } global $g, $config, $argv, $command_split; if (is_array($command_split)) { $args = array_slice($command_split, 2); } else { $args = array_slice($argv, 3); } if (empty($args[0])) { die(usage()); } $ip = $args[0]; preg_match('/^\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}$/', $ip) or die(usage()); $config['aliases'] = array('alias' => array()); $s_list = array('1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '15', '20', '25', '30', '40', '50', '60', '70', '80', '90', '100', '150', '200', '250', '300', '500', '1000'); foreach ($s_list as &$e) { $config['aliases']['alias'][] = Array ( 'name' => 's' . $e . 'mbit', 'type' => urltable, 'url' => 'http://' . $ip . '/shapers/s' . $e . 'mbit.txt', 'updatefreq' => 1, 'address' => 'http://' . $ip . '/shapers/s' . $e . 'mbit.txt', 'descr' => '', 'detail' => '' ); } write_config(); print_r($config['aliases']); ====== Генерация правил firewall ====== require_once("config.inc"); require_once("util.inc"); require_once("service-utils.inc"); function usage() { echo "Usage: /usr/local/sbin/pfSsh.php playback maker_fw \n"; } global $g, $config, $argv, $command_split; if (is_array($command_split)) { $args = array_slice($command_split, 2); } else { $args = array_slice($argv, 3); } if (empty($args[0])) { die(usage()); } $interface = $args[0]; preg_match('/^[A-z0-9]+$/', $interface) or die(usage()); #$config['filter'] = array('rule' => array()); $s_list = array('1', '2', '3', '4', '5', '6', '7', '8', '9', '10', '15', '20', '25', '30', '40', '50', '60', '70', '80', '90', '100', '150', '200', '250', '300', '500', '1000'); foreach ($s_list as &$e) { $config['filter']['rule'][] = Array ( 'id' => '', 'tracker' => time(), 'type' => 'pass', 'interface' => $interface, 'ipprotocol' => 'inet', 'tag' => '', 'tagged' => '', 'max' => '', 'max-src-nodes' => '', 'max-src-conn' => '', 'max-src-states' => '', 'statetimeout' => '', 'statetype' => 'keep state', 'os' => '', 'source' => Array ( 'address' => 's' . $e . 'mbit', ), 'destination' => Array ( 'any' => '' ), 'descr' => '', 'dnpipe' => $e . 'mbit_up', 'pdnpipe' => $e . 'mbit_down', 'created' => Array ( 'time' => time(), 'username' => '' ), 'updated' => Array ( 'time' => time(), 'username' => '' ) ); sleep(1); } write_config(); print_r($config['filter']); ====== Статическая запись DHCP ====== Добавить/удалить статическую запись DHCP require_once("config.inc"); require_once("util.inc"); require_once("service-utils.inc"); function usage() { echo "Usage: playback static_list \n"; echo "or\n"; echo "Usage: playback static_list \n"; echo "or\n"; echo "Usage: playback static_list \n"; } global $g, $config, $argv, $command_split; if (is_array($command_split)) { $args = array_slice($command_split, 2); } else { $args = array_slice($argv, 3); } if (empty($args[0])) { usage(); } $action = $args[0]; $interface = $args[1]; $ip = $args[2]; $mac = $args[3]; $hostname = $args[4]; $description = $args[5]; $mac = strtolower($mac); preg_match('/^(add|del)$/', $action) or die(usage()); preg_match('/^[A-z0-9]+$/', $interface) or die(usage()); preg_match('/^\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}$/', $ip) or die(usage()); preg_match('/^[a-f0-9]{2}\:[a-f0-9]{2}\:[a-f0-9]{2}\:[a-f0-9]{2}\:[a-f0-9]{2}\:[a-f0-9]{2}$/', $mac) or die(usage()); if(!empty($hostname)) preg_match('/^[A-z0-9\_]+$/', $hostname) or die(usage()); if(!strcmp($action, 'add')) { $arr_size = count($config['dhcpd'][$interface]['staticmap']); for($i = 0; $i < $arr_size; $i++) { if(!strcasecmp($config['dhcpd'][$interface]['staticmap'][$i]['mac'], $mac)) { die; } } $config['dhcpd'][$interface]['staticmap'][] = array ( 'mac' => $mac, 'ipaddr' => $ip, 'hostname' => $hostname, 'descr' => $description, 'arp_table_static_entry' => '', 'filename' => '', 'rootpath' => '', 'defaultleasetime' => '', 'maxleasetime' => '', 'gateway' => '', 'domain' => '', 'domainsearchlist' => '', 'ddnsdomain' => '', 'ddnsdomainprimary' => '', 'ddnsdomainsecondary' => '', 'ddnsdomainkeyname' => '', 'ddnsdomainkeyalgorithm' => '', 'ddnsdomainkey' => '', 'tftp' => '', 'ldap' => '', 'nextserver' => '', 'filename32' => '', 'filename64' => '', 'filename32arm' => '', 'filename64arm' => '', 'uefihttpboot' => '', 'numberoptions' => '' ); system("/usr/sbin/arp -S " . escapeshellarg($ip) . " " . escapeshellarg($mac)); } if(!strcmp($action, 'del')) { $arr_size = count($config['dhcpd'][$interface]['staticmap']); for($i = 0; $i < $arr_size; $i++) { if(!strcmp($config['dhcpd'][$interface]['staticmap'][$i]['ipaddr'], $ip) and !strcasecmp($config['dhcpd'][$interface]['staticmap'][$i]['mac'], $mac)) { unset($config['dhcpd'][$interface]['staticmap'][$i]); system("/usr/sbin/arp -d " . escapeshellarg($ip)); break; } } } parse_config(true); write_config();