1 // SoftEther VPN Source Code - Stable Edition Repository
2 // Cedar Communication Module
3 //
4 // SoftEther VPN Server, Client and Bridge are free software under the Apache License, Version 2.0.
5 //
6 // Copyright (c) Daiyuu Nobori.
7 // Copyright (c) SoftEther VPN Project, University of Tsukuba, Japan.
8 // Copyright (c) SoftEther Corporation.
9 // Copyright (c) all contributors on SoftEther VPN project in GitHub.
10 //
11 // All Rights Reserved.
12 //
13 // http://www.softether.org/
14 //
15 // This stable branch is officially managed by Daiyuu Nobori, the owner of SoftEther VPN Project.
16 // Pull requests should be sent to the Developer Edition Master Repository on https://github.com/SoftEtherVPN/SoftEtherVPN
17 //
18 // License: The Apache License, Version 2.0
19 // https://www.apache.org/licenses/LICENSE-2.0
20 //
21 // DISCLAIMER
22 // ==========
23 //
24 // THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
25 // IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
26 // FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
27 // AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
28 // LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
29 // OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
30 // SOFTWARE.
31 //
32 // THIS SOFTWARE IS DEVELOPED IN JAPAN, AND DISTRIBUTED FROM JAPAN, UNDER
33 // JAPANESE LAWS. YOU MUST AGREE IN ADVANCE TO USE, COPY, MODIFY, MERGE, PUBLISH,
34 // DISTRIBUTE, SUBLICENSE, AND/OR SELL COPIES OF THIS SOFTWARE, THAT ANY
35 // JURIDICAL DISPUTES WHICH ARE CONCERNED TO THIS SOFTWARE OR ITS CONTENTS,
36 // AGAINST US (SOFTETHER PROJECT, SOFTETHER CORPORATION, DAIYUU NOBORI OR OTHER
37 // SUPPLIERS), OR ANY JURIDICAL DISPUTES AGAINST US WHICH ARE CAUSED BY ANY KIND
38 // OF USING, COPYING, MODIFYING, MERGING, PUBLISHING, DISTRIBUTING, SUBLICENSING,
39 // AND/OR SELLING COPIES OF THIS SOFTWARE SHALL BE REGARDED AS BE CONSTRUED AND
40 // CONTROLLED BY JAPANESE LAWS, AND YOU MUST FURTHER CONSENT TO EXCLUSIVE
41 // JURISDICTION AND VENUE IN THE COURTS SITTING IN TOKYO, JAPAN. YOU MUST WAIVE
42 // ALL DEFENSES OF LACK OF PERSONAL JURISDICTION AND FORUM NON CONVENIENS.
43 // PROCESS MAY BE SERVED ON EITHER PARTY IN THE MANNER AUTHORIZED BY APPLICABLE
44 // LAW OR COURT RULE.
45 //
46 // USE ONLY IN JAPAN. DO NOT USE THIS SOFTWARE IN ANOTHER COUNTRY UNLESS YOU HAVE
47 // A CONFIRMATION THAT THIS SOFTWARE DOES NOT VIOLATE ANY CRIMINAL LAWS OR CIVIL
48 // RIGHTS IN THAT PARTICULAR COUNTRY. USING THIS SOFTWARE IN OTHER COUNTRIES IS
49 // COMPLETELY AT YOUR OWN RISK. THE SOFTETHER VPN PROJECT HAS DEVELOPED AND
50 // DISTRIBUTED THIS SOFTWARE TO COMPLY ONLY WITH THE JAPANESE LAWS AND EXISTING
51 // CIVIL RIGHTS INCLUDING PATENTS WHICH ARE SUBJECTS APPLY IN JAPAN. OTHER
52 // COUNTRIES' LAWS OR CIVIL RIGHTS ARE NONE OF OUR CONCERNS NOR RESPONSIBILITIES.
53 // WE HAVE NEVER INVESTIGATED ANY CRIMINAL REGULATIONS, CIVIL LAWS OR
54 // INTELLECTUAL PROPERTY RIGHTS INCLUDING PATENTS IN ANY OF OTHER 200+ COUNTRIES
55 // AND TERRITORIES. BY NATURE, THERE ARE 200+ REGIONS IN THE WORLD, WITH
56 // DIFFERENT LAWS. IT IS IMPOSSIBLE TO VERIFY EVERY COUNTRIES' LAWS, REGULATIONS
57 // AND CIVIL RIGHTS TO MAKE THE SOFTWARE COMPLY WITH ALL COUNTRIES' LAWS BY THE
58 // PROJECT. EVEN IF YOU WILL BE SUED BY A PRIVATE ENTITY OR BE DAMAGED BY A
59 // PUBLIC SERVANT IN YOUR COUNTRY, THE DEVELOPERS OF THIS SOFTWARE WILL NEVER BE
60 // LIABLE TO RECOVER OR COMPENSATE SUCH DAMAGES, CRIMINAL OR CIVIL
61 // RESPONSIBILITIES. NOTE THAT THIS LINE IS NOT LICENSE RESTRICTION BUT JUST A
62 // STATEMENT FOR WARNING AND DISCLAIMER.
63 //
64 // READ AND UNDERSTAND THE 'WARNING.TXT' FILE BEFORE USING THIS SOFTWARE.
65 // SOME SOFTWARE PROGRAMS FROM THIRD PARTIES ARE INCLUDED ON THIS SOFTWARE WITH
66 // LICENSE CONDITIONS WHICH ARE DESCRIBED ON THE 'THIRD_PARTY.TXT' FILE.
67 //
68 //
69 // SOURCE CODE CONTRIBUTION
70 // ------------------------
71 //
72 // Your contribution to SoftEther VPN Project is much appreciated.
73 // Please send patches to us through GitHub.
74 // Read the SoftEther VPN Patch Acceptance Policy in advance:
75 // http://www.softether.org/5-download/src/9.patch
76 //
77 //
78 // DEAR SECURITY EXPERTS
79 // ---------------------
80 //
81 // If you find a bug or a security vulnerability please kindly inform us
82 // about the problem immediately so that we can fix the security problem
83 // to protect a lot of users around the world as soon as possible.
84 //
85 // Our e-mail address for security reports is:
86 // softether-vpn-security [at] softether.org
87 //
88 // Please note that the above e-mail address is not a technical support
89 // inquiry address. If you need technical assistance, please visit
90 // http://www.softether.org/ and ask your question on the users forum.
91 //
92 // Thank you for your cooperation.
93 //
94 //
95 // NO MEMORY OR RESOURCE LEAKS
96 // ---------------------------
97 //
98 // The memory-leaks and resource-leaks verification under the stress
99 // test has been passed before release this source code.
100 
101 
102 // IPsec.h
103 // Header of IPsec.c
104 
105 #ifndef	IPSEC_H
106 #define	IPSEC_H
107 
108 //// Constants
109 
110 // UDP port number
111 #define	IPSEC_PORT_L2TP					1701		// L2TP
112 #define	IPSEC_PORT_IPSEC_ISAKMP			500			// ISAKMP
113 #define	IPSEC_PORT_IPSEC_ESP_UDP		4500		// IPsec ESP over UDP
114 #define	IPSEC_PORT_IPSEC_ESP_RAW		MAKE_SPECIAL_PORT(50)	// Raw mode ESP Protocol No: 50
115 #define	IPSEC_PORT_IPSEC_ESP_RAW_WPF	MAKE_SPECIAL_PORT(52)	// Raw mode ESP Protocol No: 52 (WPF)
116 #define	IPSEC_PORT_L2TPV3_VIRTUAL		1000001		// L2TPv3 virtual port
117 
118 // IP protocol number
119 #define	IPSEC_IP_PROTO_ETHERIP			IP_PROTO_ETHERIP	// EtherIP
120 #define	IPSEC_IP_PROTO_L2TPV3			IP_PROTO_L2TPV3		// L2TPv3
121 
122 // WFP tag
123 #define	WFP_ESP_PACKET_TAG_1		0x19841117
124 #define	WFP_ESP_PACKET_TAG_2		0x1accafe1
125 
126 // Monitoring interval of OS service
127 #define	IPSEC_CHECK_OS_SERVICE_INTERVAL_INITIAL	1024
128 #define	IPSEC_CHECK_OS_SERVICE_INTERVAL_MAX		(5 * 60 * 1000)
129 
130 // Default IPsec pre-shared key
131 #define	IPSEC_DEFAULT_SECRET			"vpn"
132 
133 
134 //// Type
135 
136 // List of services provided by IPsec server
137 struct IPSEC_SERVICES
138 {
139 	bool L2TP_Raw;								// Raw L2TP
140 	bool L2TP_IPsec;							// L2TP over IPsec
141 	bool EtherIP_IPsec;							// EtherIP over IPsec
142 
143 	char IPsec_Secret[MAX_SIZE];				// IPsec pre-shared key
144 	char L2TP_DefaultHub[MAX_SIZE];				// Default Virtual HUB name for L2TP connection
145 };
146 
147 // EtherIP key list entry
148 struct ETHERIP_ID
149 {
150 	char Id[MAX_SIZE];							// ID
151 	char HubName[MAX_HUBNAME_LEN + 1];			// Virtual HUB name
152 	char UserName[MAX_USERNAME_LEN + 1];		// User name
153 	char Password[MAX_USERNAME_LEN + 1];		// Password
154 };
155 
156 // IPsec server
157 struct IPSEC_SERVER
158 {
159 	CEDAR *Cedar;
160 	UDPLISTENER *UdpListener;
161 	bool Halt;
162 	bool NoMoreChangeSettings;
163 	LOCK *LockSettings;
164 	IPSEC_SERVICES Services;
165 	L2TP_SERVER *L2TP;							// L2TP server
166 	IKE_SERVER *Ike;							// IKE server
167 	LIST *EtherIPIdList;						// EtherIP setting list
168 	UINT EtherIPIdListSettingVerNo;				// EtherIP setting list version number
169 	THREAD *OsServiceCheckThread;				// OS Service monitoring thread
170 	EVENT *OsServiceCheckThreadEvent;			// Event for OS Service monitoring thread
171 	IPSEC_WIN7 *Win7;							// Helper module for Windows Vista / 7
172 	bool Check_LastEnabledStatus;
173 	bool HostIPAddressListChanged;
174 	bool OsServiceStoped;
175 };
176 
177 
178 //// Function prototype
179 IPSEC_SERVER *NewIPsecServer(CEDAR *cedar);
180 void FreeIPsecServer(IPSEC_SERVER *s);
181 void IPsecServerUdpPacketRecvProc(UDPLISTENER *u, LIST *packet_list);
182 void IPsecServerSetServices(IPSEC_SERVER *s, IPSEC_SERVICES *sl);
183 void IPsecNormalizeServiceSetting(IPSEC_SERVER *s);
184 void IPsecServerGetServices(IPSEC_SERVER *s, IPSEC_SERVICES *sl);
185 void IPsecProcPacket(IPSEC_SERVER *s, UDPPACKET *p);
186 int CmpEtherIPId(void *p1, void *p2);
187 bool SearchEtherIPId(IPSEC_SERVER *s, ETHERIP_ID *id, char *id_str);
188 void AddEtherIPId(IPSEC_SERVER *s, ETHERIP_ID *id);
189 bool DeleteEtherIPId(IPSEC_SERVER *s, char *id_str);
190 void IPsecOsServiceCheckThread(THREAD *t, void *p);
191 bool IPsecCheckOsService(IPSEC_SERVER *s);
192 void IPSecSetDisable(bool b);
193 
194 
195 #endif	// IPSEC_H
196 
197