routing revision 243212
1#!/bin/sh
2#
3# Configure routing and miscellaneous network tunables
4#
5# $FreeBSD: head/etc/rc.d/routing 243212 2012-11-18 11:22:15Z hrs $
6#
7
8# PROVIDE: routing
9# REQUIRE: faith netif ppp stf
10# KEYWORD: nojail
11
12. /etc/rc.subr
13. /etc/network.subr
14
15name="routing"
16start_cmd="routing_start doall"
17stop_cmd="routing_stop"
18extra_commands="options static"
19static_cmd="routing_start static"
20options_cmd="routing_start options"
21
22afcheck()
23{
24	case $_af in
25	""|inet|inet6|ipx|atm)
26		;;
27	*)
28		err 1 "Unsupported address family: $_af."
29		;;
30	esac
31}
32
33routing_start()
34{
35	local _cmd _af _a
36	_cmd=$1
37	_af=$2
38
39	afcheck
40
41	case $_af in
42	inet|inet6|ipx|atm)
43		setroutes $_cmd $_af
44		;;
45	"")
46		for _a in inet inet6 ipx atm; do
47			afexists $_a && setroutes $_cmd $_a
48		done
49		;;
50	esac
51}
52
53routing_stop()
54{
55	local _af _a
56	_af=$1
57
58	afcheck
59
60	case $_af in
61	inet|inet6|ipx|atm)
62		eval static_${_af} delete
63		eval routing_stop_${_af}
64		;;
65	"")
66		for _a in inet inet6 ipx atm; do
67			afexists $_a || continue
68			eval static_${_a} delete
69			eval routing_stop_${_a}
70		done
71		;;
72	esac
73}
74
75setroutes()
76{
77	case $1 in
78	static)
79		static_$2 add
80		;;
81	options)
82		options_$2
83		;;
84	doall)
85		static_$2 add
86		options_$2
87		;;
88	esac
89}
90
91routing_stop_inet()
92{
93	route -n flush -inet
94}
95
96routing_stop_inet6()
97{
98	local i
99
100	route -n flush -inet6
101	for i in `list_net_interfaces`; do
102		if ipv6if $i; then
103			ifconfig $i inet6 -defaultif
104		fi
105	done
106}
107
108routing_stop_atm()
109{
110	return 0
111}
112
113routing_stop_ipx()
114{
115	return 0
116}
117
118static_inet()
119{
120	local _action
121	_action=$1
122
123	case ${defaultrouter} in
124	[Nn][Oo] | '')
125		;;
126	*)
127		static_routes="default ${static_routes}"
128		route_default="default ${defaultrouter}"
129		;;
130	esac
131
132	if [ -n "${static_routes}" ]; then
133		for i in ${static_routes}; do
134			route_args=`get_if_var $i route_IF`
135			route ${_action} ${route_args}
136		done
137	fi
138}
139
140static_inet6()
141{
142	local _action fibmod fibs
143	_action=$1
144
145	# get the number of FIBs supported.
146	fibs=$((`${SYSCTL_N} net.fibs` - 1))
147	if [ "$fibs" -gt 0 ]; then
148		fibmod="-fib 0-$fibs"
149	else
150		fibmod=
151	fi
152
153	# disallow "internal" addresses to appear on the wire
154	route ${_action} -inet6 ::ffff:0.0.0.0 -prefixlen 96 ::1 -reject ${fibmod}
155	route ${_action} -inet6 ::0.0.0.0 -prefixlen 96 ::1 -reject ${fibmod}
156
157	case ${ipv6_defaultrouter} in
158	[Nn][Oo] | '')
159		;;
160	*)
161		ipv6_static_routes="default ${ipv6_static_routes}"
162		ipv6_route_default="default ${ipv6_defaultrouter}"
163		;;
164	esac
165
166	if [ -n "${ipv6_static_routes}" ]; then
167		for i in ${ipv6_static_routes}; do
168			ipv6_route_args=`get_if_var $i ipv6_route_IF`
169			route ${_action} -inet6 ${ipv6_route_args}
170		done
171	fi
172
173	# Fixup $ipv6_network_interfaces
174	case ${ipv6_network_interfaces} in
175	[Nn][Oo][Nn][Ee])
176		ipv6_network_interfaces=''
177		;;
178	esac
179
180	if checkyesno ipv6_gateway_enable; then
181		for i in ${ipv6_network_interfaces}; do
182
183			laddr=`network6_getladdr $i exclude_tentative`
184			case ${laddr} in
185			'')
186				;;
187			*)
188				ipv6_working_interfaces="$i \
189				    ${ipv6_working_interfaces}"
190				;;
191			esac
192		done
193		ipv6_network_interfaces=${ipv6_working_interfaces}
194	fi
195
196	# Install the "default interface" to kernel, which will be used
197	# as the default route when there's no router.
198	case "${ipv6_default_interface}" in
199	[Nn][Oo] | [Nn][Oo][Nn][Ee])
200		ipv6_default_interface=""
201		;;
202	[Aa][Uu][Tt][Oo] | "")
203		for i in ${ipv6_network_interfaces}; do
204			case $i in
205			lo0|faith[0-9]*)
206				continue
207				;;
208			esac
209			laddr=`network6_getladdr $i exclude_tentative`
210			case ${laddr} in
211			'')
212				;;
213			*)
214				ipv6_default_interface=$i
215				break
216				;;
217			esac
218		done
219		;;
220	esac
221
222	# Disallow link-local unicast packets without outgoing scope
223	# identifiers.  However, if you set "ipv6_default_interface",
224	# for the host case, you will allow to omit the identifiers.
225	# Under this configuration, the packets will go to the default
226	# interface.
227	route ${_action} -inet6 fe80:: -prefixlen 10 ::1 -reject ${fibmod}
228	route ${_action} -inet6 ff02:: -prefixlen 16 ::1 -reject ${fibmod}
229
230	case ${ipv6_default_interface} in
231	'')
232		;;
233	*)
234		# Disable installing the default interface when we act
235		# as router to avoid conflict between the default
236		# router list and the manual configured default route.
237		if ! checkyesno ipv6_gateway_enable; then
238			ifconfig ${ipv6_default_interface} inet6 defaultif
239			sysctl net.inet6.ip6.use_defaultzone=1
240		fi
241		;;
242	esac
243}
244
245static_atm()
246{
247	local _action i route_args
248	_action=$1
249
250	if [ -n "${natm_static_routes}" ]; then
251		for i in ${natm_static_routes}; do
252			route_args=`get_if_var $i route_IF`
253			atmconfig natm ${_action} ${route_args}
254		done
255	fi
256}
257
258static_ipx()
259{
260	:
261}
262
263ropts_init()
264{
265	if [ -z "${_ropts_initdone}" ]; then
266		echo -n "Additional $1 routing options:"
267		_ropts_initdone=yes
268	fi
269}
270
271options_inet()
272{
273	_ropts_initdone=
274	if checkyesno icmp_bmcastecho; then
275		ropts_init inet
276		echo -n ' broadcast ping responses=YES'
277		${SYSCTL} net.inet.icmp.bmcastecho=1 > /dev/null
278	else
279		${SYSCTL} net.inet.icmp.bmcastecho=0 > /dev/null
280	fi
281
282	if checkyesno icmp_drop_redirect; then
283		ropts_init inet
284		echo -n ' ignore ICMP redirect=YES'
285		${SYSCTL} net.inet.icmp.drop_redirect=1 > /dev/null
286	else
287		${SYSCTL} net.inet.icmp.drop_redirect=0 > /dev/null
288	fi
289
290	if checkyesno icmp_log_redirect; then
291		ropts_init inet
292		echo -n ' log ICMP redirect=YES'
293		${SYSCTL} net.inet.icmp.log_redirect=1 > /dev/null
294	else
295		${SYSCTL} net.inet.icmp.log_redirect=0 > /dev/null
296	fi
297
298	if checkyesno gateway_enable; then
299		ropts_init inet
300		echo -n ' gateway=YES'
301		${SYSCTL} net.inet.ip.forwarding=1 > /dev/null
302	else
303		${SYSCTL} net.inet.ip.forwarding=0 > /dev/null
304	fi
305
306	if checkyesno forward_sourceroute; then
307		ropts_init inet
308		echo -n ' do source routing=YES'
309		${SYSCTL} net.inet.ip.sourceroute=1 > /dev/null
310	else
311		${SYSCTL} net.inet.ip.sourceroute=0 > /dev/null
312	fi
313
314	if checkyesno accept_sourceroute; then
315		ropts_init inet
316		echo -n ' accept source routing=YES'
317		${SYSCTL} net.inet.ip.accept_sourceroute=1 > /dev/null
318	else
319		${SYSCTL} net.inet.ip.accept_sourceroute=0 > /dev/null
320	fi
321
322	if checkyesno arpproxy_all; then
323		ropts_init inet
324		echo -n ' ARP proxyall=YES'
325		${SYSCTL} net.link.ether.inet.proxyall=1 > /dev/null
326	else
327		${SYSCTL} net.link.ether.inet.proxyall=0 > /dev/null
328	fi
329
330	[ -n "${_ropts_initdone}" ] && echo '.'
331}
332
333options_inet6()
334{
335	_ropts_initdone=
336
337	if checkyesno ipv6_gateway_enable; then
338		ropts_init inet6
339		echo -n ' gateway=YES'
340		${SYSCTL} net.inet6.ip6.forwarding=1 > /dev/null
341	else
342		${SYSCTL} net.inet6.ip6.forwarding=0 > /dev/null
343	fi
344
345	[ -n "${_ropts_initdone}" ] && echo '.'
346}
347
348options_atm()
349{
350	_ropts_initdone=
351
352	[ -n "${_ropts_initdone}" ] && echo '.'
353}
354
355options_ipx()
356{
357	_ropts_initdone=
358
359	if checkyesno ipxgateway_enable; then
360		ropts_init ipx
361		echo -n ' gateway=YES'
362		${SYSCTL} net.ipx.ipx.ipxforwarding=1 > /dev/null
363	else
364		${SYSCTL} net.ipx.ipx.ipxforwarding=0 > /dev/null
365	fi
366
367	[ -n "${_ropts_initdone}" ] && echo '.'
368}
369
370load_rc_config $name
371run_rc_command "$@"
372