Files

Ignoring revisions in .git-blame-ignore-revs. Click here to bypass and see the normal blame view.

147 lines
4.9 KiB
PHP
Raw Permalink Normal View History

<?php
/**
* Nac.php
*
* network access controls module
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
2021-02-09 00:29:04 +01:00
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*
2021-02-09 00:29:04 +01:00
* @link https://www.librenms.org
2021-09-10 20:09:53 +02:00
*
* @copyright 2018 Tony Murray
* @author Tony Murray <murraytony@gmail.com>
*/
namespace LibreNMS\Modules;
2022-09-07 16:53:16 -05:00
use App\Models\Device;
use App\Models\PortsNac;
use App\Observers\ModuleModelObserver;
use Illuminate\Support\Facades\DB;
2023-10-04 10:32:59 -05:00
use LibreNMS\Interfaces\Data\DataStorageInterface;
use LibreNMS\Interfaces\Module;
use LibreNMS\Interfaces\Polling\NacPolling;
use LibreNMS\OS;
2023-10-04 10:32:59 -05:00
use LibreNMS\Polling\ModuleStatus;
class Nac implements Module
{
2022-09-07 16:53:16 -05:00
/**
* @inheritDoc
*/
public function dependencies(): array
{
return ['ports'];
}
2023-10-04 10:32:59 -05:00
public function shouldDiscover(OS $os, ModuleStatus $status): bool
{
return false;
}
/**
* Discover this module. Heavier processes can be run here
* Run infrequently (default 4 times a day)
*
2021-11-17 19:23:55 -06:00
* @param Os $os
*/
2022-09-07 16:53:16 -05:00
public function discover(OS $os): void
{
// not implemented
}
2023-10-04 10:32:59 -05:00
public function shouldPoll(OS $os, ModuleStatus $status): bool
{
2023-10-16 05:03:32 -07:00
return $status->isEnabledAndDeviceUp($os->getDevice()) && $os instanceof NacPolling;
2023-10-04 10:32:59 -05:00
}
/**
* Poll data for this module and update the DB / RRD.
* Try to keep this efficient and only run if discovery has indicated there is a reason to run.
* Run frequently (default every 5 minutes)
*
2021-11-17 19:23:55 -06:00
* @param \LibreNMS\OS $os
*/
2023-10-04 10:32:59 -05:00
public function poll(OS $os, DataStorageInterface $datastore): void
{
if ($os instanceof NacPolling) {
// discovery output (but don't install it twice (testing can can do this)
ModuleModelObserver::observe(PortsNac::class);
$nac_entries = $os->pollNac()->keyBy('mac_address');
//filter out historical entries
2024-08-02 20:44:47 -05:00
$existing_entries = $os->getDevice()->portsNac()
->where('historical', 0)
->get()->keyBy('mac_address');
// update existing models
foreach ($nac_entries as $nac_entry) {
if ($existing = $existing_entries->get($nac_entry->mac_address)) {
// we have the same mac_address once again. Let's decide if we should keep the existing as history or not.
if (($nac_entry->port_id == $existing->port_id) ||
($nac_entry->method == $existing->method) ||
($nac_entry->vlan == $existing->vlan) ||
($nac_entry->authz_by == $existing->authz_by) ||
($nac_entry->authz_status == $existing->authz_status) ||
($nac_entry->ip_address == $existing->ip_address) ||
($nac_entry->username == $existing->username)) {
// if everything is similar, we update current entry. If not, we duplicate+history
$nac_entries->put($nac_entry->mac_address, $existing->fill($nac_entry->attributesToArray()));
}
}
}
// persist to DB
2020-09-18 08:12:07 -05:00
$os->getDevice()->portsNac()->saveMany($nac_entries);
$age = $existing_entries->diffKeys($nac_entries)->pluck('ports_nac_id');
if ($age->isNotEmpty()) {
$count = PortsNac::query()->whereIntegerInRaw('ports_nac_id', $age)->update(['historical' => true, 'updated_at' => DB::raw('updated_at')]);
d_echo('Aged ' . $count, str_repeat('-', $count));
}
}
}
2024-09-09 02:09:19 -05:00
public function dataExists(Device $device): bool
{
return $device->portsNac()->exists();
}
/**
* Remove all DB data for this module.
* This will be run when the module is disabled.
*/
2024-09-09 02:09:19 -05:00
public function cleanup(Device $device): int
2022-09-07 16:53:16 -05:00
{
2024-09-09 02:09:19 -05:00
return $device->portsNac()->delete();
2022-09-07 16:53:16 -05:00
}
/**
* @inheritDoc
*/
public function dump(Device $device, string $type): ?array
{
if ($type == 'discovery') {
return null;
}
2022-09-07 16:53:16 -05:00
return [
'ports_nac' => $device->portsNac()->orderBy('ports.ifIndex')->orderBy('mac_address')
->leftJoin('ports', 'ports_nac.port_id', 'ports.port_id')
->select(['ports_nac.*', 'ifIndex'])
->get()->map->makeHidden(['ports_nac_id', 'device_id', 'port_id', 'updated_at', 'created_at']),
2022-09-07 16:53:16 -05:00
];
}
}