ipfw revision 298514
1#!/bin/sh
2#
3# $FreeBSD: head/etc/rc.d/ipfw 298514 2016-04-23 16:10:54Z lme $
4#
5
6# PROVIDE: ipfw
7# REQUIRE: ppp
8# KEYWORD: nojailvnet
9
10. /etc/rc.subr
11. /etc/network.subr
12
13name="ipfw"
14desc="Firewall, traffic shaper, packet scheduler, in-kernel NAT"
15rcvar="firewall_enable"
16start_cmd="ipfw_start"
17start_precmd="ipfw_prestart"
18start_postcmd="ipfw_poststart"
19stop_cmd="ipfw_stop"
20required_modules="ipfw"
21
22set_rcvar_obsolete ipv6_firewall_enable
23
24ipfw_prestart()
25{
26	if checkyesno dummynet_enable; then
27		required_modules="$required_modules dummynet"
28	fi
29	if checkyesno natd_enable; then
30		required_modules="$required_modules ipdivert"
31	fi
32	if checkyesno firewall_nat_enable; then
33		required_modules="$required_modules ipfw_nat"
34	fi
35}
36
37ipfw_start()
38{
39	local   _firewall_type
40
41	_firewall_type=$1
42
43	# set the firewall rules script if none was specified
44	[ -z "${firewall_script}" ] && firewall_script=/etc/rc.firewall
45
46	if [ -r "${firewall_script}" ]; then
47		/bin/sh "${firewall_script}" "${_firewall_type}"
48		echo 'Firewall rules loaded.'
49	elif [ "`ipfw list 65535`" = "65535 deny ip from any to any" ]; then
50		echo 'Warning: kernel has firewall functionality, but' \
51		    ' firewall rules are not enabled.'
52		echo '           All ip services are disabled.'
53	fi
54
55	# Firewall logging
56	#
57	if checkyesno firewall_logging; then
58		echo 'Firewall logging enabled.'
59		sysctl net.inet.ip.fw.verbose=1 >/dev/null
60	fi
61	if checkyesno firewall_logif; then
62		ifconfig ipfw0 create
63		echo 'Firewall logging pseudo-interface (ipfw0) created.'
64	fi
65}
66
67ipfw_poststart()
68{
69	local	_coscript
70
71	# Start firewall coscripts
72	#
73	for _coscript in ${firewall_coscripts} ; do
74		if [ -f "${_coscript}" ]; then
75			${_coscript} quietstart
76		fi
77	done
78
79	# Enable the firewall
80	#
81	if ! ${SYSCTL} net.inet.ip.fw.enable=1 1>/dev/null 2>&1; then
82		warn "failed to enable IPv4 firewall"
83	fi
84	if afexists inet6; then
85		if ! ${SYSCTL} net.inet6.ip6.fw.enable=1 1>/dev/null 2>&1
86		then
87			warn "failed to enable IPv6 firewall"
88		fi
89	fi
90}
91
92ipfw_stop()
93{
94	local	_coscript
95
96	# Disable the firewall
97	#
98	${SYSCTL} net.inet.ip.fw.enable=0
99	if afexists inet6; then
100		${SYSCTL} net.inet6.ip6.fw.enable=0
101	fi
102
103	# Stop firewall coscripts
104	#
105	for _coscript in `reverse_list ${firewall_coscripts}` ; do
106		if [ -f "${_coscript}" ]; then
107			${_coscript} quietstop
108		fi
109	done
110}
111
112load_rc_config $name
113firewall_coscripts="/etc/rc.d/natd ${firewall_coscripts}"
114
115run_rc_command $*
116