#!/bin/sh # checks/pf.sh # pf health summary (enabled, state table usage, rule count), plus the # actual active filter and nat/rdr rules listed as rows below. The rule # rows use status "info" (a neutral gray square) rather than "ok" - # they're informational, not a health signal, and a green square there # would wrongly imply each individual rule was itself being health- # checked. set -eu DIR=$(dirname "$0") . "$DIR/../lib/common.sh" INFO=$(pfctl -si 2>/dev/null) || INFO="" ENABLED=$(printf '%s\n' "$INFO" | awk -F'[ :]+' '/^Status:/{print $2; exit}') if [ "$ENABLED" = "Enabled" ]; then json_line "pf" "pf" "" "ok" else json_line "pf" "pf" "${ENABLED:-unknown}" "down" fi CURRENT=$(printf '%s\n' "$INFO" | awk '/current entries/{print $NF; exit}') LIMIT=$(pfctl -sm 2>/dev/null | awk '/^states/{print $NF; exit}') if [ -n "$CURRENT" ] && [ -n "$LIMIT" ] && [ "$LIMIT" -gt 0 ] 2>/dev/null; then PCT=$((CURRENT * 100 / LIMIT)) if [ "$PCT" -ge 90 ]; then SSTATUS=down elif [ "$PCT" -ge 75 ]; then SSTATUS=warn else SSTATUS=ok fi json_line "pf" "state table" "${CURRENT}/${LIMIT} (${PCT}%)" "$SSTATUS" fi RULE_COUNT=$(pfctl -sr 2>/dev/null | grep -c .) || RULE_COUNT=0 json_line "pf" "filter rules loaded" "$RULE_COUNT" "ok" pfctl -sr 2>/dev/null | while IFS= read -r rule; do [ -n "$rule" ] || continue json_line "pf" " $rule" "" "info" done pfctl -sn 2>/dev/null | while IFS= read -r rule; do [ -n "$rule" ] || continue json_line "pf" " nat: $rule" "" "info" done