添加安全组对http(s)的控制,并添加安全规则的默认配置
This commit is contained in:
@@ -179,7 +179,7 @@ export default {
|
||||
rule: '规则内容',
|
||||
passType: '放行类型',
|
||||
priority: '优先级',
|
||||
ruleConfig: '规则配置',
|
||||
ruleConfig: '配置规则',
|
||||
portMappingBindSecurityGroup: '绑定安全组',
|
||||
securityGroupBindPortMapping: '端口映射绑定',
|
||||
bind: '绑定',
|
||||
|
||||
@@ -47,10 +47,10 @@
|
||||
<el-table-column align="center" :label="$t('table.actions')" class-name="small-padding fixed-width" style="display:flex;justify-content:center">
|
||||
<template slot-scope="scope">
|
||||
<div >
|
||||
<el-link :underline="false" type="primary" size="mini" @click="handleGoRulePage(scope.row)" style="font-size: 12px">{{$t('table.ruleConfig')}}</el-link>
|
||||
<el-link :underline="false" type="primary" size="mini" @click="handleUpdate(scope.row)" style="font-size: 12px">{{$t('table.edit')}}</el-link>
|
||||
<el-link :underline="false" v-if="scope.row.enable =='启用'" size="mini" type="warning" @click="handleDisableStatus(scope.row)" style="font-size: 12px">{{$t('table.disable')}}</el-link>
|
||||
<el-link :underline="false" v-if="scope.row.enable =='禁用'" size="mini" type="success" @click="handleEnableStatus(scope.row)" style="font-size: 12px">{{$t('table.enable')}}</el-link>
|
||||
<el-link :underline="false" type="primary" size="mini" @click="handleGoRulePage(scope.row)" style="font-size: 12px">{{$t('table.ruleConfig')}}</el-link>
|
||||
</div>
|
||||
<el-dropdown>
|
||||
<span class="el-dropdown-link" style="font-size: 12px">
|
||||
@@ -80,10 +80,12 @@
|
||||
</el-form-item>
|
||||
|
||||
<el-form-item :label="$t('table.defaultPassType')" prop="defaultPassType">
|
||||
<el-select style="width: 380px" class="filter-item" v-model="temp.defaultPassType">
|
||||
<el-option v-for="item in passTypeList" :key="item.key" :label="item.key" :value="item.value">
|
||||
</el-option>
|
||||
</el-select>
|
||||
<el-tooltip class="item" effect="dark" content="当IP地址不能匹配任何规则时,默认执行的放行类型" placement="bottom">
|
||||
<el-select style="width: 380px" class="filter-item" v-model="temp.defaultPassType">
|
||||
<el-option v-for="item in passTypeList" :key="item.key" :label="item.key" :value="item.value">
|
||||
</el-option>
|
||||
</el-select>
|
||||
</el-tooltip>
|
||||
</el-form-item>
|
||||
|
||||
</el-form>
|
||||
|
||||
@@ -96,10 +96,14 @@
|
||||
|
||||
|
||||
<el-form-item :label="$t('table.passType')" prop="passType">
|
||||
<el-select class="filter-item" v-model="temp.passType">
|
||||
<el-option v-for="item in passTypeList" :key="item.key" :label="item.key" :value="item.value">
|
||||
</el-option>
|
||||
</el-select>
|
||||
<el-tooltip class="item" effect="dark" :content="temp.passTypeTooltip" placement="right">
|
||||
<!-- <el-button>右边</el-button> -->
|
||||
<el-select class="filter-item" v-model="temp.passType" disabled>
|
||||
<el-option v-for="item in passTypeList" :key="item.key" :label="item.key" :value="item.value">
|
||||
</el-option>
|
||||
</el-select>
|
||||
</el-tooltip>
|
||||
|
||||
</el-form-item>
|
||||
|
||||
<el-form-item :label="$t('table.priority')" prop="priority">
|
||||
@@ -155,6 +159,7 @@ import LinkPopover from '../../components/Link/linkPopover'
|
||||
description: '',
|
||||
rule: '',
|
||||
passType: undefined,
|
||||
passTypeTooltip: '',
|
||||
priority: 1
|
||||
},
|
||||
dialogFormVisible: false,
|
||||
@@ -169,7 +174,7 @@ import LinkPopover from '../../components/Link/linkPopover'
|
||||
rules: {
|
||||
name: [{ required: true, message: '安全组名称必填', trigger: 'blur' }],
|
||||
rule: [{ required: true, message: '规则内容必填', trigger: 'blur' }],
|
||||
passType: [{ required: true, message: '放行类型必选', trigger: 'blur' }],
|
||||
// passType: [{ required: true, message: '放行类型必选', trigger: 'blur' }],
|
||||
priority: [{ required: true, message: '优先级必填', trigger: 'blur' }]
|
||||
},
|
||||
downloadLoading: false,
|
||||
@@ -269,9 +274,13 @@ import LinkPopover from '../../components/Link/linkPopover'
|
||||
resetTemp() {
|
||||
this.temp = {
|
||||
id: undefined,
|
||||
groupId: this.groupId,
|
||||
name: '',
|
||||
description: '',
|
||||
defaultPassType: undefined
|
||||
rule: '',
|
||||
passType: this.group.defaultPassType == 'allow' ? 0 : 1,
|
||||
passTypeTooltip: `安全组已设置默认${(this.group.defaultPassType == 'allow' ? '允许' : '拒绝')}`,
|
||||
priority: 1
|
||||
}
|
||||
},
|
||||
handleCreate() {
|
||||
@@ -304,6 +313,7 @@ import LinkPopover from '../../components/Link/linkPopover'
|
||||
handleUpdate(row) {
|
||||
this.temp = Object.assign({}, row) // copy obj
|
||||
this.temp.passType = row.passType == 'allow' ? 1 : 0
|
||||
this.temp.passTypeTooltip = `安全组已设置默认${(this.group.defaultPassType == 'allow' ? '允许' : '拒绝')}`,
|
||||
this.temp.timestamp = new Date(this.temp.timestamp)
|
||||
this.dialogStatus = 'update'
|
||||
this.dialogFormVisible = true
|
||||
|
||||
+17
@@ -10,12 +10,16 @@ import lombok.extern.slf4j.Slf4j;
|
||||
import org.apache.commons.lang3.StringUtils;
|
||||
import org.dromara.neutrinoproxy.core.Constants;
|
||||
import org.dromara.neutrinoproxy.core.ProxyMessage;
|
||||
import org.dromara.neutrinoproxy.core.util.IpUtil;
|
||||
import org.dromara.neutrinoproxy.server.constant.NetworkProtocolEnum;
|
||||
import org.dromara.neutrinoproxy.server.proxy.domain.ProxyAttachment;
|
||||
import org.dromara.neutrinoproxy.server.proxy.domain.VisitorChannelAttachInfo;
|
||||
import org.dromara.neutrinoproxy.server.service.FlowReportService;
|
||||
import org.dromara.neutrinoproxy.server.service.PortMappingService;
|
||||
import org.dromara.neutrinoproxy.server.service.SecurityGroupService;
|
||||
import org.dromara.neutrinoproxy.server.util.ProxyUtil;
|
||||
import org.noear.solon.Solon;
|
||||
import org.noear.solon.annotation.Inject;
|
||||
|
||||
import java.net.InetSocketAddress;
|
||||
|
||||
@@ -25,6 +29,11 @@ import java.net.InetSocketAddress;
|
||||
*/
|
||||
@Slf4j
|
||||
public class HttpVisitorChannelHandler extends SimpleChannelInboundHandler<ByteBuf> {
|
||||
|
||||
private final SecurityGroupService securityGroupService = Solon.context().getBean(SecurityGroupService.class);
|
||||
|
||||
private final PortMappingService portMappingService = Solon.context().getBean(PortMappingService.class);
|
||||
|
||||
/**
|
||||
* 域名
|
||||
*/
|
||||
@@ -87,6 +96,14 @@ public class HttpVisitorChannelHandler extends SimpleChannelInboundHandler<ByteB
|
||||
ctx.channel().close();
|
||||
return;
|
||||
}
|
||||
|
||||
// 判断IP是否在该端口绑定的安全组允许的规则内
|
||||
if (!securityGroupService.judgeAllow(IpUtil.getRemoteIp(ctx), portMappingService.getSecurityGroupIdByMappingPort(serverPort))) {
|
||||
// 不在安全组规则放行范围内
|
||||
ctx.channel().close();
|
||||
return;
|
||||
}
|
||||
|
||||
Channel cmdChannel = ProxyUtil.getCmdChannelByServerPort(serverPort);
|
||||
if (null == cmdChannel) {
|
||||
ctx.channel().close();
|
||||
|
||||
Reference in New Issue
Block a user