mirror of
https://git.FreeBSD.org/src.git
synced 2024-12-18 10:35:55 +00:00
e248dc09a8
for each address family. Replace AF_static() with static_AF() for consistency. - Display a message only if the user sets a non-default value, and set a sysctl explicitly even if it is the default value.
338 lines
6.3 KiB
Bash
Executable File
338 lines
6.3 KiB
Bash
Executable File
#!/bin/sh
|
|
#
|
|
# Configure routing and miscellaneous network tunables
|
|
#
|
|
# $FreeBSD$
|
|
#
|
|
|
|
# PROVIDE: routing
|
|
# REQUIRE: faith netif ppp stf
|
|
# KEYWORD: nojail
|
|
|
|
. /etc/rc.subr
|
|
. /etc/network.subr
|
|
|
|
name="routing"
|
|
start_cmd="routing_start"
|
|
stop_cmd="routing_stop"
|
|
extra_commands="options static"
|
|
static_cmd="static_start"
|
|
options_cmd="options_start"
|
|
|
|
routing_start()
|
|
{
|
|
static_start "$@"
|
|
options_start "$@"
|
|
}
|
|
|
|
routing_stop()
|
|
{
|
|
local _af
|
|
|
|
static_stop "$@"
|
|
for _af in inet inet6; do
|
|
afexists ${_af} && eval routing_stop_${_af}
|
|
done
|
|
}
|
|
|
|
routing_stop_inet()
|
|
{
|
|
route -n flush -inet
|
|
}
|
|
|
|
routing_stop_inet6()
|
|
{
|
|
local i
|
|
|
|
route -n flush -inet6
|
|
for i in ${ipv6_network_interfaces}; do
|
|
ifconfig $i inet6 -defaultif
|
|
done
|
|
}
|
|
|
|
static_start()
|
|
{
|
|
local _af
|
|
_af=$1
|
|
|
|
case ${_af} in
|
|
inet|inet6|atm)
|
|
do_static add ${_af}
|
|
;;
|
|
"")
|
|
do_static add inet inet6 atm
|
|
;;
|
|
esac
|
|
}
|
|
|
|
static_stop()
|
|
{
|
|
local _af
|
|
_af=$1
|
|
|
|
case ${_af} in
|
|
inet|inet6|atm)
|
|
do_static delete ${_af}
|
|
;;
|
|
"")
|
|
do_static delete inet inet6 atm
|
|
;;
|
|
esac
|
|
}
|
|
|
|
do_static()
|
|
{
|
|
local _af _action
|
|
_action=$1
|
|
|
|
shift
|
|
for _af in "$@"; do
|
|
afexists ${_af} && eval static_${_af} ${_action}
|
|
done
|
|
}
|
|
|
|
static_inet()
|
|
{
|
|
local _action
|
|
_action=$1
|
|
|
|
case ${defaultrouter} in
|
|
[Nn][Oo] | '')
|
|
;;
|
|
*)
|
|
static_routes="default ${static_routes}"
|
|
route_default="default ${defaultrouter}"
|
|
;;
|
|
esac
|
|
|
|
if [ -n "${static_routes}" ]; then
|
|
for i in ${static_routes}; do
|
|
route_args=`get_if_var $i route_IF`
|
|
route ${_action} ${route_args}
|
|
done
|
|
fi
|
|
}
|
|
|
|
static_inet6()
|
|
{
|
|
local _action i
|
|
_action=$1
|
|
|
|
# disallow "internal" addresses to appear on the wire
|
|
route ${_action} -inet6 ::ffff:0.0.0.0 -prefixlen 96 ::1 -reject
|
|
route ${_action} -inet6 ::0.0.0.0 -prefixlen 96 ::1 -reject
|
|
|
|
case ${ipv6_defaultrouter} in
|
|
[Nn][Oo] | '')
|
|
;;
|
|
*)
|
|
ipv6_static_routes="default ${ipv6_static_routes}"
|
|
ipv6_route_default="default ${ipv6_defaultrouter}"
|
|
;;
|
|
esac
|
|
|
|
if [ -n "${ipv6_static_routes}" ]; then
|
|
for i in ${ipv6_static_routes}; do
|
|
ipv6_route_args=`get_if_var $i ipv6_route_IF`
|
|
route ${_action} -inet6 ${ipv6_route_args}
|
|
done
|
|
fi
|
|
|
|
# Fixup $ipv6_network_interfaces
|
|
case ${ipv6_network_interfaces} in
|
|
[Nn][Oo][Nn][Ee])
|
|
ipv6_network_interfaces=''
|
|
;;
|
|
esac
|
|
|
|
if checkyesno ipv6_gateway_enable; then
|
|
for i in ${ipv6_network_interfaces}; do
|
|
|
|
laddr=`network6_getladdr $i exclude_tentative`
|
|
case ${laddr} in
|
|
'')
|
|
;;
|
|
*)
|
|
ipv6_working_interfaces="$i \
|
|
${ipv6_working_interfaces}"
|
|
;;
|
|
esac
|
|
done
|
|
ipv6_network_interfaces=${ipv6_working_interfaces}
|
|
fi
|
|
|
|
# Install the "default interface" to kernel, which will be used
|
|
# as the default route when there's no router.
|
|
case "${ipv6_default_interface}" in
|
|
[Nn][Oo] | [Nn][Oo][Nn][Ee])
|
|
ipv6_default_interface=""
|
|
;;
|
|
[Aa][Uu][Tt][Oo] | "")
|
|
for i in ${ipv6_network_interfaces}; do
|
|
case $i in
|
|
lo0|faith[0-9]*)
|
|
continue
|
|
;;
|
|
esac
|
|
laddr=`network6_getladdr $i exclude_tentative`
|
|
case ${laddr} in
|
|
'')
|
|
;;
|
|
*)
|
|
ipv6_default_interface=$i
|
|
break
|
|
;;
|
|
esac
|
|
done
|
|
;;
|
|
esac
|
|
|
|
# Disallow unicast packets without outgoing scope identifiers,
|
|
# or route such packets to a "default" interface, if it is specified.
|
|
route ${_action} -inet6 fe80:: -prefixlen 10 ::1 -reject
|
|
|
|
case ${ipv6_default_interface} in
|
|
'')
|
|
route ${_action} -inet6 ff02:: -prefixlen 16 ::1 -reject
|
|
;;
|
|
*)
|
|
laddr=`network6_getladdr ${ipv6_default_interface}`
|
|
route ${_action} -inet6 ff02:: ${laddr} -prefixlen 16 -interface
|
|
|
|
# Disable installing the default interface with the
|
|
# case net.inet6.ip6.forwarding=0 and
|
|
# the interface with no ND6_IFF_ACCEPT_RTADV
|
|
# to avoid conflict between the default router list and
|
|
# the manual configured default route.
|
|
if ! checkyesno ipv6_gateway_enable; then
|
|
ifconfig ${ipv6_default_interface} nd6 | \
|
|
while read proto options
|
|
do
|
|
case "${proto}:${options}" in
|
|
nd6:*ACCEPT_RTADV*)
|
|
ifconfig ${ipv6_default_interface} inet6 defaultif
|
|
break
|
|
;;
|
|
esac
|
|
done
|
|
fi
|
|
;;
|
|
esac
|
|
}
|
|
|
|
static_atm()
|
|
{
|
|
local _action i route_args
|
|
_action=$1
|
|
|
|
if [ -n "${natm_static_routes}" ]; then
|
|
for i in ${natm_static_routes}; do
|
|
route_args=`get_if_var $i route_IF`
|
|
atmconfig natm ${_action} ${route_args}
|
|
done
|
|
fi
|
|
}
|
|
|
|
_ropts_initdone=
|
|
ropts_init()
|
|
{
|
|
if [ -z "${_ropts_initdone}" ]; then
|
|
echo -n 'Additional routing options:'
|
|
_ropts_initdone=yes
|
|
fi
|
|
}
|
|
|
|
options_start()
|
|
{
|
|
local _af
|
|
|
|
for _af in inet inet6 ipx; do
|
|
afexists ${_af} && eval options_${_af}
|
|
done
|
|
[ -n "${_ropts_initdone}" ] && echo '.'
|
|
}
|
|
|
|
options_inet()
|
|
{
|
|
if checkyesno icmp_bmcastecho; then
|
|
ropts_init
|
|
echo -n ' broadcast ping responses=YES'
|
|
${SYSCTL_W} net.inet.icmp.bmcastecho=1 > /dev/null
|
|
else
|
|
${SYSCTL_W} net.inet.icmp.bmcastecho=0 > /dev/null
|
|
fi
|
|
|
|
if checkyesno icmp_drop_redirect; then
|
|
ropts_init
|
|
echo -n ' ignore ICMP redirect=YES'
|
|
${SYSCTL_W} net.inet.icmp.drop_redirect=1 > /dev/null
|
|
else
|
|
${SYSCTL_W} net.inet.icmp.drop_redirect=0 > /dev/null
|
|
fi
|
|
|
|
if checkyesno icmp_log_redirect; then
|
|
ropts_init
|
|
echo -n ' log ICMP redirect=YES'
|
|
${SYSCTL_W} net.inet.icmp.log_redirect=1 > /dev/null
|
|
else
|
|
${SYSCTL_W} net.inet.icmp.log_redirect=0 > /dev/null
|
|
fi
|
|
|
|
if checkyesno gateway_enable; then
|
|
ropts_init
|
|
echo -n ' IPv4 gateway=YES'
|
|
${SYSCTL_W} net.inet.ip.forwarding=1 > /dev/null
|
|
else
|
|
${SYSCTL_W} net.inet.ip.forwarding=0 > /dev/null
|
|
fi
|
|
|
|
if checkyesno forward_sourceroute; then
|
|
ropts_init
|
|
echo -n ' do source routing=YES'
|
|
${SYSCTL_W} net.inet.ip.sourceroute=1 > /dev/null
|
|
else
|
|
${SYSCTL_W} net.inet.ip.sourceroute=0 > /dev/null
|
|
fi
|
|
|
|
if checkyesno accept_sourceroute; then
|
|
ropts_init
|
|
echo -n ' accept source routing=YES'
|
|
${SYSCTL_W} net.inet.ip.accept_sourceroute=1 > /dev/null
|
|
else
|
|
${SYSCTL_W} net.inet.ip.accept_sourceroute=0 > /dev/null
|
|
fi
|
|
|
|
if checkyesno arpproxy_all; then
|
|
ropts_init
|
|
echo -n ' ARP proxyall=YES'
|
|
${SYSCTL_W} net.link.ether.inet.proxyall=1 > /dev/null
|
|
else
|
|
${SYSCTL_W} net.link.ether.inet.proxyall=0 > /dev/null
|
|
fi
|
|
}
|
|
|
|
options_inet6()
|
|
{
|
|
if checkyesno ipv6_gateway_enable; then
|
|
ropts_init
|
|
echo -n ' IPv6 gateway=YES'
|
|
${SYSCTL_W} net.inet6.ip6.forwarding=1 > /dev/null
|
|
else
|
|
${SYSCTL_W} net.inet6.ip6.forwarding=0 > /dev/null
|
|
fi
|
|
}
|
|
|
|
options_ipx()
|
|
{
|
|
if checkyesno ipxgateway_enable; then
|
|
ropts_init
|
|
echo -n ' IPX gateway=YES'
|
|
${SYSCTL_W} net.ipx.ipx.ipxforwarding=1 > /dev/null
|
|
else
|
|
${SYSCTL_W} net.ipx.ipx.ipxforwarding=0 > /dev/null
|
|
fi
|
|
}
|
|
|
|
load_rc_config $name
|
|
run_rc_command "$@"
|