2 * Copyright (c) 2020 Cisco and/or its affiliates.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at:
7 * http://www.apache.org/licenses/LICENSE-2.0
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
16 #ifndef __CNAT_SNAT_H__
17 #define __CNAT_SNAT_H__
19 #include <cnat/cnat_types.h>
20 #include <cnat/cnat_session.h>
22 /* function to use to decide whether to snat connections in the output
23 * feature. Returns 1 if we should source NAT */
24 typedef int (*cnat_snat_policy_t) (vlib_buffer_t *b, cnat_session_t *session);
26 typedef struct cnat_snat_pfx_table_meta_t_
28 u32 dst_address_length_refcounts[129];
29 u16 *prefix_lengths_in_search_order;
30 uword *non_empty_dst_address_length_bitmap;
31 } cnat_snat_pfx_table_meta_t;
33 typedef struct cnat_snat_exclude_pfx_table_t_
35 /* Stores (ip family, prefix & mask) */
36 clib_bihash_24_8_t ip_hash;
37 /* family dependant cache */
38 cnat_snat_pfx_table_meta_t meta[2];
39 /* Precomputed ip masks (ip4 & ip6) */
40 ip6_address_t ip_masks[129];
41 } cnat_snat_exclude_pfx_table_t;
43 typedef enum cnat_snat_interface_map_type_t_
45 CNAT_SNAT_IF_MAP_INCLUDE_V4 = AF_IP4,
46 CNAT_SNAT_IF_MAP_INCLUDE_V6 = AF_IP6,
48 } cnat_snat_interface_map_type_t;
50 typedef enum cnat_snat_policy_type_t_
52 CNAT_SNAT_POLICY_NONE = 0,
53 CNAT_SNAT_POLICY_IF_PFX = 1,
54 } cnat_snat_policy_type_t;
56 typedef struct cnat_snat_policy_main_t_
58 /* Longest prefix Match table for source NATing */
59 cnat_snat_exclude_pfx_table_t excluded_pfx;
61 /* interface maps including or excluding sw_if_indexes */
62 clib_bitmap_t *interface_maps[CNAT_N_SNAT_IF_MAP];
64 /* SNAT policy for the output feature node */
65 cnat_snat_policy_t snat_policy;
67 /* Ip4 Address to use for source NATing */
68 cnat_endpoint_t snat_ip4;
70 /* Ip6 Address to use for source NATing */
71 cnat_endpoint_t snat_ip6;
73 } cnat_snat_policy_main_t;
75 extern cnat_snat_policy_main_t cnat_snat_policy_main;
77 extern void cnat_set_snat (ip4_address_t *ip4, ip6_address_t *ip6,
79 extern int cnat_snat_policy_add_pfx (ip_prefix_t *pfx);
80 extern int cnat_snat_policy_del_pfx (ip_prefix_t *pfx);
81 extern int cnat_set_snat_policy (cnat_snat_policy_type_t policy);
82 extern int cnat_snat_policy_add_del_if (u32 sw_if_index, u8 is_add,
83 cnat_snat_interface_map_type_t table);
85 int cnat_search_snat_prefix (ip46_address_t *addr, ip_address_family_t af);
88 * fd.io coding-style-patch-verification: ON
91 * eval: (c-set-style "gnu")