1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
|
'use strict';
'require form';
'require uci';
'require view';
'require tools.widgets as widgets';
function addLogLevel(o) {
o.value('', _('Use daemon default'));
o.value('-1', _('Absolutely silent'));
o.value('0', _('Very basic auditing logs'));
o.value('1', _('Generic control flow with errors (default)'));
o.value('2', _('More detailed debugging control flow'));
o.value('3', _('Including RAW data dumps in hex'));
o.value('4', _('Also include sensitive material in dumps, e.g. keys'));
o.default = '';
}
return view.extend({
load: function () {
return uci.load('ipsec').then(function () {
let save = false;
if (uci.get('ipsec', 'globals') == null) {
uci.add('ipsec', 'globals', 'globals');
save = true;
}
if (uci.get('ipsec', 'syslog') == null) {
uci.add('ipsec', 'syslog', 'syslog');
save = true;
}
if (uci.get('ipsec', 'netlink') == null) {
uci.add('ipsec', 'netlink', 'netlink');
save = true;
}
if (save)
uci.save();
});
},
render: function (result) {
let m, s, o;
m = new form.Map('ipsec', _('Service configuration'),
_('On this page, you can configure the IPsec service.'));
m.tabbed = true;
// general settings
s = m.section(form.NamedSection, 'globals', 'globals', _('General Settings'),
_('Configure global service parameters.'));
o = s.option(widgets.NetworkSelect, 'interface', _('Listening Interfaces'),
_('Interfaces that accept VPN traffic.') + '<br /> ' +
_('Select an interface or leave empty for all interfaces.'));
o.multiple = true;
o.nocreate = true;
o.optional = true;
// syslog plugin settings
s = m.section(form.NamedSection, 'syslog', 'syslog', _('Syslog Settings'),
_('Configure how strongswan logs events, errors, and debug information.'));
o = s.option(form.ListValue, 'app', 'app', _('Applications other than daemons'));
addLogLevel(o);
o = s.option(form.ListValue, 'asn', 'asn', _('Low-level encoding/decoding (ASN.1, X.509 etc.)'));
addLogLevel(o);
o = s.option(form.ListValue, 'cfg', 'cfg', _('Configuration management and plugins'));
addLogLevel(o);
o = s.option(form.ListValue, 'chd', 'chd', _('CHILD_SA/IPsec_SA'));
addLogLevel(o);
o = s.option(form.ListValue, 'dmn', 'dmn', _('Main daemon setup/cleanup/signal handling'));
addLogLevel(o);
o = s.option(form.ListValue, 'enc', 'enc', _('Packet encoding/decoding encryption/decryption operations'));
addLogLevel(o);
o = s.option(form.ListValue, 'esp', 'esp', '%s (%s)'.format(_('Library messages'), 'libipsec'));
addLogLevel(o);
o = s.option(form.ListValue, 'ike', 'ike', _('IKE_SA / ISAKMP SA'));
addLogLevel(o);
o = s.option(form.ListValue, 'imc', 'imc', _('Integrity Measurement Collector'));
addLogLevel(o);
o = s.option(form.ListValue, 'imv', 'imv', _('Integrity Measurement Verifier'));
addLogLevel(o);
o = s.option(form.ListValue, 'job', 'job', _('Jobs queuing/processing and thread pool management'));
addLogLevel(o);
o = s.option(form.ListValue, 'wch', 'wch', _('File descriptor watcher'));
addLogLevel(o);
o = s.option(form.ListValue, 'knl', 'knl', _('IPsec/Networking kernel interface'));
addLogLevel(o);
o = s.option(form.ListValue, 'lib', 'lib', '%s (%s)'.format(_('Library messages'), 'libstrongswan'));
addLogLevel(o);
o = s.option(form.ListValue, 'mgr', 'mgr', _('IKE_SA manager, handling synchronization for IKE_SA access'));
addLogLevel(o);
o = s.option(form.ListValue, 'net', 'net', _('IKE network communication'));
addLogLevel(o);
o = s.option(form.ListValue, 'pts', 'pts', _('Platform Trust Service'));
addLogLevel(o);
o = s.option(form.ListValue, 'tls', 'tls', '%s (%s)'.format(_('Library messages'), 'libtls'));
addLogLevel(o);
o = s.option(form.ListValue, 'tnc', 'tnc', _('Trusted Network Connect'));
addLogLevel(o);
// kernel-netlink plugin settings
s = m.section(form.NamedSection, 'netlink', 'netlink', _('Netlink Settings'),
_('Configure the kernel-netlink plugin options.'));
o = s.option(form.Flag, 'install_routes_xfrmi', _('Install routes via XFRM interfaces'),
_('When this is enabled, the routes for all XFRM interfaces are set automatically.'));
o.default = '0';
return m.render();
}
});
|