• João Vieira's avatar
    Adds support for tunneling specific port ranges (#144) · c4a41ada
    João Vieira authored
    * Adds support for tunneling specific port ranges
    
    This set of changes implements the ability of specifying a port or port
    range for an IP or subnet to only tunnel those ports for that subnet.
    Also supports excluding a port or port range for a given IP or subnet.
    
    When, for a given subnet, there are intercepting ranges being added and
    excluded, the most specific, i.e., smaller range, takes precedence. In
    case of a tie the exclusion wins.
    
    For different subnets, the most specific, i.e., largest swidth, takes
    precedence independent of any eventual port ranges.
    
    Examples:
    Tunnels all traffic to the 188.0.0.0/8 subnet except those to port 443.
    ```
    sshuttle -r <server> 188.0.0.0/8 -x 188.0.0.0/8:443
    ```
    
    Only tunnels traffic to port 80 of the 188.0.0.0/8 subnet.
    ```
    sshuttle -r <server> 188.0.0.0/8:80
    ```
    
    Tunnels traffic to the 188.0.0.0/8 subnet and the port range that goes
    from 80 to 89.
    ```
    sshuttle -r <server> 188.0.0.0/8:80-89 -x 188.0.0.0/8:80-90
    ```
    
    * Allow subnets to be specified with domain names
    
    Simplifies the implementation of address parsing by using
    socket.getaddrinfo(), which can handle domain resolution, IPv4 and IPv6
    addresses. This was proposed and mostly implemented by @DavidBuchanan314
    in #146.
    Signed-off-by: 's avatarDavid Buchanan <DavidBuchanan314@users.noreply.github.com>
    Signed-off-by: 's avatarJoão Vieira <vieira@yubo.be>
    
    * Also use getaddrinfo for parsing listen addr:port
    
    * Fixes tests for tunneling a port range
    
    * Updates documentation to include port/port range
    
    Adds some examples with subnet:port and subnet:port-port.
    Also clarifies the versions of Python supported on the server while
    maintaining the recommendation for Python 2.7, 3.5 or later.
    Mentions support for pfSense.
    
    * In Py2 only named arguments may follow *expression
    
    Fixes issue in Python 2.7 where *expression may only be followed by
    named arguments.
    
    * Use right regex to extract ip4/6, mask and ports
    
    * Tests for parse_subnetport
    c4a41ada
options.py 6.85 KB