]> git.ipfire.org Git - people/stevee/ipfire-2.x.git/blob - src/initscripts/networking/red
Early spring clean: Remove trailing whitespaces, and correct licence headers
[people/stevee/ipfire-2.x.git] / src / initscripts / networking / red
1 #!/bin/sh
2 ###############################################################################
3 # #
4 # IPFire.org - A linux based firewall #
5 # Copyright (C) 2007-2022 IPFire Team <info@ipfire.org> #
6 # #
7 # This program is free software: you can redistribute it and/or modify #
8 # it under the terms of the GNU General Public License as published by #
9 # the Free Software Foundation, either version 3 of the License, or #
10 # (at your option) any later version. #
11 # #
12 # This program is distributed in the hope that it will be useful, #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15 # GNU General Public License for more details. #
16 # #
17 # You should have received a copy of the GNU General Public License #
18 # along with this program. If not, see <http://www.gnu.org/licenses/>. #
19 # #
20 ###############################################################################
21
22 . /etc/sysconfig/rc
23 . ${rc_functions}
24 . /etc/init.d/networking/functions.network
25
26 #Define some defaults
27 INET_VLAN=7
28 IPTV_VLAN=8
29 ATM_DEV=0
30
31 eval $(/usr/local/bin/readhash /var/ipfire/main/settings)
32 if [ "$RRDLOG" == "" ]; then
33 RRDLOG=/var/log/rrd
34 fi
35
36 eval $(/usr/local/bin/readhash /var/ipfire/ethernet/settings)
37 eval $(/usr/local/bin/readhash /var/ipfire/dns/settings)
38 eval $(/usr/local/bin/readhash /var/ipfire/mac/settings)
39
40 MAC=$(tr - : <<<$MAC)
41 MAC1=$(tr - : <<<$MAC1)
42 MAC2=$(tr - : <<<$MAC2)
43
44 TYPE="${RED_TYPE}"
45 DEVICE="${RED_DEV}"
46
47 if [ "$TYPE" == "STATIC" ] || [ "$TYPE" == "DHCP" ]; then
48 if [ "$DEVICE" == "" ]; then
49 boot_mesg "No device for red network. Please run setup." ${FAILURE}
50 echo_failure
51 [ "${1}" == "start" ] && exit 0
52 fi
53 fi
54
55 if [ "${TYPE}" == "STATIC" ]; then
56 if [ "${DEVICE}" != "${GREEN_DEV}" ]; then
57 ADDRESS="${RED_ADDRESS}"
58 NETADDRESS="${RED_NETADDRESS}"
59 NETMASK="${RED_NETMASK}"
60 MTU="${RED_MTU}"
61 else
62 ADDRESS="${GREEN_ADDRESS}"
63 NETADDRESS="${GREEN_NETADDRESS}"
64 NETMASK="${GREEN_NETMASK}"
65 MTU="${GREEN_MTU}"
66 fi
67 GATEWAY="${DEFAULT_GATEWAY}"
68 # DNS1
69 # DNS2
70
71 if [ -n "${ADDRESS}" -a -n "${NETMASK}" ]; then
72 PREFIX=`whatmask ${NETMASK} | grep -e ^CIDR | awk -F': ' '{ print $2 }' | cut -c 2-`
73 args="${args} ${ADDRESS}/${PREFIX}"
74 else
75 boot_mesg "ADDRESS and/or NETMASK variable missing from input, cannot continue." ${FAILURE}
76 echo_failure
77 exit 1
78 fi
79 fi
80
81 case "${1}" in
82 start)
83 if [ "${DEVICE}" != "${GREEN_DEV}" ] && [ "${DEVICE}" != "" ]; then
84 boot_mesg "Bringing up the ${DEVICE} interface..."
85 boot_mesg_flush
86 # Check if an interface is there...
87 if ip link show ${DEVICE} > /dev/null 2>&1; then
88 link_status=`ip link show ${DEVICE} 2> /dev/null`
89 if [ -n "${link_status}" ]; then
90 if ! echo "${link_status}" | grep -q UP; then
91 if [ -n "$MAC" ]; then
92 boot_mesg "Setting mac address on ${DEVICE} to ${MAC}"
93 ip link set dev ${DEVICE} address ${MAC}
94 evaluate_retval
95 fi
96 ip link set ${DEVICE} up
97 fi
98 fi
99 else
100 boot_mesg "Interface ${DEVICE} doesn't exist." ${FAILURE}
101 echo_failure
102 exit 1
103 fi
104 fi
105
106 ## Create & Enable vnstat
107 /usr/bin/vnstat -u -i ${DEVICE} -r --enable --force > /dev/null 2>&1
108
109 if [ "${TYPE}" == "STATIC" ]; then
110 # Set the MTU
111 if [ -n "${MTU}" ]; then
112 if ! ip link set dev "${DEVICE}" mtu "${MTU}" &>/dev/null; then
113 boot_mesg "Could not set MTU of ${MTU} to ${DEVICE}..."
114 echo_warning
115 fi
116 fi
117
118 if [ "$DEVICE" != "${GREEN_DEV}" ]; then
119 boot_mesg "Adding IPv4 address ${ADDRESS} to the ${DEVICE} interface..."
120 ip addr add ${args} dev ${DEVICE}
121 evaluate_retval
122 fi
123 echo -n "${DEVICE}" > /var/ipfire/red/iface
124 echo -n "${ADDRESS}" > /var/ipfire/red/local-ipaddress
125 echo -n "${GATEWAY}" > /var/ipfire/red/remote-ipaddress
126 grep -v -E "\<gateway\>" /etc/hosts > /tmp/hosts
127 echo "$GATEWAY gateway" >> /tmp/hosts
128 mv /tmp/hosts /etc/hosts
129 touch /var/ipfire/red/active
130
131 # Create route to default gateway
132 ip route add ${GATEWAY} dev ${DEVICE}
133
134 boot_mesg "Setting up default gateway ${GATEWAY}..."
135 ip route add default via ${GATEWAY} dev ${DEVICE}
136 evaluate_retval
137
138 if [ -d "/sys/class/net/${DEVICE}" ]; then
139 # has carrier ?
140 if [ ! "$(</sys/class/net/${DEVICE}/carrier)" = "1" ]; then
141 boot_mesg -n "Wait for carrier on ${DEVICE} "
142 for (( i=30; i>1; i-- )) do
143 if [ "$(</sys/class/net/${DEVICE}/carrier)" = "1" ]; then
144 break;
145 fi
146 boot_mesg -n "."
147 sleep 2
148 done
149 boot_mesg ""
150 if [ ! "$(</sys/class/net/${DEVICE}/carrier)" = "1" ]; then
151 echo_failure
152 else
153 echo_ok
154 fi
155 fi
156 fi
157
158 run_subdir ${rc_base}/init.d/networking/red.up/
159
160 # Configure aliases only if red static
161 /usr/local/bin/setaliases
162
163 elif [ "${TYPE}" == "DHCP" ]; then
164 # Add firewall rules to allow comunication with the dhcp server on red.
165 iptables -A REDINPUT -p tcp --source-port 67 --destination-port 68 -i ${DEVICE} -j ACCEPT
166 iptables -A REDINPUT -p udp --source-port 67 --destination-port 68 -i ${DEVICE} -j ACCEPT
167
168 echo -n "${DEVICE}" > /var/ipfire/red/iface
169
170 # Check if the wlan-client is used on red.
171 # To determine this we check if a wpa_supplicant is running.
172 pid="$(pidof wpa_supplicant)"
173
174 if [ -z "${pid}" ]; then
175 # No wpa_supplicant is running. So it's save to start dhcpcd.
176 dhcpcd_start "${DEVICE}"
177 fi
178
179 ## Create & Enable vnstat
180 /usr/bin/vnstat -u -i ${DEVICE} -r --enable --force > /dev/null 2>&1
181
182 elif [ "$TYPE" == "PPPOE" ]; then
183
184 if ( ps ax | grep -q [p]ppd ); then
185 boot_mesg "pppd is still running." ${FAILURE}
186 echo_failure
187 exit 1
188 fi
189
190 eval $(/usr/local/bin/readhash /var/ipfire/ppp/settings)
191
192 [ -c "/dev/ppp" ] || mknod /dev/ppp c 108 0
193
194 # We force the plugin method, anyway.
195 METHOD="PPPOE_PLUGIN"
196
197 PPP_NIC=${DEVICE}
198
199 if [ "$TYPE" == "pppoeatm" ] || [ "$TYPE" == "pptpatm" ]; then
200 PPP_NIC=nas${ATM_DEV}
201 DEVICE=nas${ATM_DEV}
202 boot_mesg "Creating ATM-Bridge as $PPP_NIC ..."
203 br2684ctl -c${ATM_DEV} -e${ENCAP} -a${ATM_DEV}.${VPI}.${VCI} >/dev/null 2>&1 &
204 sleep 1
205
206 # use user-defined or green mac address for nas0
207 if [ -n "$MAC" ]; then
208 ip link set dev nas${ATM_DEV} address ${MAC}
209 else
210 ip link set dev nas${ATM_DEV} address $(cat /sys/class/net/green0/address)
211 fi
212
213 if [ "$TYPE" == "pppoeatm" ]; then
214 TYPE="pppoe"
215 fi
216 if [ "$TYPE" == "pptpatm" ]; then
217 TYPE="pptp"
218 fi
219 fi
220
221 if [ "$TYPE" == "vdsl" ]; then
222 boot_mesg "Creating VLAN Interface ${DEVICE}.${INET_VLAN} ..."
223 modprobe 8021q
224 vconfig add ${DEVICE} ${INET_VLAN}
225 if [ -n "$MAC1" ]; then
226 boot_mesg "Setting mac address on ${DEVICE}.${INET_VLAN} to ${MAC1}"
227 ip link set dev ${DEVICE}.${INET_VLAN} address ${MAC1}
228 evaluate_retval
229 fi
230 PPP_NIC=${DEVICE}.${INET_VLAN}
231 sleep 0.2
232 ip link set ${PPP_NIC} up
233 TYPE="pppoe"
234 fi
235 if [ "${IPTV}" == "enable" ]; then
236 PIDFILE="/var/run/dhcpcd/${DEVICE}.${IPTV_VLAN}.pid"
237 LEASEINFO="/var/ipfire/dhcpc/dhcpcd-${DEVICE}.${IPTV_VLAN}.info"
238 # Test to see if there is a stale pid file
239 if [ -f "$PIDFILE" ]; then
240 ps `cat "$PIDFILE"` | grep dhcpcd > /dev/null
241 if [ $? != 0 ]; then
242 rm -f /var/run/dhcpcd/${DEVICE}.${IPTV_VLAN}.pid > /dev/null
243 fi
244 fi
245
246 if [ ! -f "$PIDFILE" ]; then
247 boot_mesg "Creating VLAN Interface ${DEVICE}.${IPTV_VLAN} ..."
248 modprobe 8021q
249 vconfig add ${DEVICE} ${IPTV_VLAN}
250 if [ -n "$MAC2" ]; then
251 boot_mesg "Setting mac address on ${DEVICE}.${IPTV_VLAN} to ${MAC2}"
252 ip link set dev ${DEVICE}.${IPTV_VLAN} address ${MAC2}
253 evaluate_retval
254 fi
255 boot_mesg -n "Starting dhcpcd on the ${DEVICE}.${IPTV_VLAN} interface..."
256 /sbin/dhcpcd ${DEVICE}.${IPTV_VLAN} ${DHCP_START} >/dev/null 2>&1
257 RET="$?"
258
259 if [ "$RET" = "0" ]; then
260 . /var/ipfire/dhcpc/dhcpcd-${DEVICE}.${IPTV_VLAN}.info
261 echo ""
262 echo_ok
263 boot_mesg " DHCP Assigned Settings for ${DEVICE}.${IPTV_VLAN}:"
264 boot_mesg_flush
265 boot_mesg " IP Address: $ip_address"
266 boot_mesg_flush
267 boot_mesg " Hostname: $RED_DHCP_HOSTNAME"
268 boot_mesg_flush
269 boot_mesg " Subnet Mask: $subnet_mask"
270 boot_mesg_flush
271 boot_mesg " Default Gateway: $routers"
272 boot_mesg_flush
273 boot_mesg " DNS Server: $domain_name_servers"
274 boot_mesg_flush
275
276 else
277 echo ""
278 $(exit "$RET")
279 evaluate_retval
280 fi
281 fi
282 fi
283 if [ "$TYPE" == "pppoe" ] || [ "$TYPE" == "pptp" ]; then
284 if [ "$PPP_NIC" == "" ]; then
285 boot_mesg "No device for red interface given. Check netsetup or dialprofile!" ${FAILURE}
286 echo_failure
287 exit 0
288 fi
289 boot_mesg "Bringing up the $TYPE interface on $PPP_NIC ..."
290 ip addr flush dev $PPP_NIC >/dev/null 2>&1
291 if [ "$TYPE" == "pptp" ]; then
292 if [ "$PPTP_NICCFG" == "dhcp" ]; then
293 # Test to see if there is a stale pid file
294 if [ -f "$PIDFILE" ]; then
295 ps `cat "$PIDFILE"` | grep dhcpcd > /dev/null
296 if [ $? != 0 ]; then
297 rm -f /var/run/dhcpcd/${DEVICE}.pid > /dev/null
298 fi
299 fi
300
301 if [ ! -f "$PIDFILE" ]; then
302 boot_mesg -n "Starting dhcpcd on the ${DEVICE} interface..."
303 /sbin/dhcpcd ${DEVICE} ${DHCP_START} >/dev/null 2>&1
304 RET="$?"
305
306 if [ "$RET" = "0" ]; then
307 . /var/ipfire/dhcpc/dhcpcd-${DEVICE}.info
308 echo ""
309 echo_ok
310 boot_mesg " DHCP Assigned Settings for ${DEVICE}:"
311 boot_mesg_flush
312 boot_mesg " IP Address: $ip_address"
313 boot_mesg_flush
314 boot_mesg " Hostname: $RED_DHCP_HOSTNAME"
315 boot_mesg_flush
316 boot_mesg " Subnet Mask: $subnet_mask"
317 boot_mesg_flush
318 boot_mesg " Default Gateway: $routers"
319 boot_mesg_flush
320 boot_mesg " DNS Server: $domain_name_servers"
321 boot_mesg_flush
322 /sbin/route add $PPTP_PEER gw $routers $PPP_NIC
323 else
324 echo ""
325 $(exit "$RET")
326 evaluate_retval
327 fi
328 fi
329 else
330 ip addr add $PPTP_NICCFG dev $PPP_NIC
331 fi
332 fi
333 ip link set ${PPP_NIC} up
334 if [ -n "${PPTP_ROUTE}" ]; then
335 boot_mesg "Set route ${PPTP_ROUTE} to pptp server..."
336 route add ${PPTP_ROUTE}
337 fi
338 else
339 boot_mesg "Bringing up the PPP via ${TYPE} on ${COMPORT}..."
340 fi
341
342 ### ###
343 ### Configuring the pppd ###
344 ### ###
345
346 ### Plugin Options
347 #
348 if [ "$TYPE" == "pppoe" ]; then
349 [ "${METHOD}" == "PPPOE_PLUGIN" ] && \
350 PLUGOPTS="plugin rp-pppoe.so"
351 fi
352
353 ### Synchronous Mode
354 #
355 #PPPOE_SYNC=-s
356 #PPPD_SYNC=sync
357
358 ### Access Concentrator Name
359 #
360 if [ -n "${CONCENTRATORNAME}" ]; then
361 ACNAME="-C ${CONCENTRATORNAME}"
362 fi
363
364 ### Service Name
365 #
366 if [ -n "${SERVICENAME}" ]; then
367 if [ "${METHOD}" == "PPPOE_PLUGIN" ]; then
368 PLUGOPTS+=" rp_pppoe_service ${SERVICENAME}"
369 else
370 SERVICENAME="-S ${SERVICENAME}"
371 fi
372 fi
373
374 ### Authentication Types
375 #
376 if [ "${AUTH}" == "pap" ]; then
377 AUTH="-chap"
378 elif [ "${AUTH}" == "chap" ]; then
379 AUTH="-pap"
380 else
381 AUTH=""
382 fi
383
384 ### Dial On Demand
385 #
386 if [ "${RECONNECTION}" != "persistent" ]; then
387 if [ "${TIMEOUT}" != "0" ] && [ "${TIMEOUT}" != "" ]; then
388 SECONDS=$[${TIMEOUT} * 60]
389 else
390 SECONDS=300
391 fi
392 if [ "${RECONNECTION}" == "dialondemand" ]; then
393 touch /var/ipfire/red/dial-on-demand
394 DEMAND="demand persist idle ${SECONDS} 10.112.112.112:10.112.112.113"
395 DEMAND+=" ipcp-accept-remote ipcp-accept-local noipdefault ktune"
396 fi
397 fi
398
399 if [ "$TYPE" == "pppoe" ]; then
400 ### When using pppoe-plugin the device has to be the last option
401 #
402 [ "${METHOD}" == "PPPOE_PLUGIN" ] && PLUGOPTS+=" $PPP_NIC"
403 fi
404
405 if [ "$TYPE" == "modem" ]; then
406 PLUGOPTS=" /dev/${COMPORT} ${DTERATE} connect /etc/ppp/dialer lock modem crtscts"
407 METHOD="PPPOE_PLUGIN"
408 elif [ "$TYPE" == "serial" ]; then
409 PLUGOPTS=" /dev/${COMPORT} ${DTERATE} connect /bin/true lock modem crtscts"
410 METHOD="PPPOE_PLUGIN"
411 fi
412
413 ### Standard PPP options we always use
414 #
415 PPP_STD_OPTIONS="$PLUGOPTS usepeerdns defaultroute noipdefault noauth"
416 PPP_STD_OPTIONS+=" default-asyncmap hide-password nodetach noipv6"
417 PPP_STD_OPTIONS+=" noaccomp nodeflate nopcomp novj novjccomp"
418 PPP_STD_OPTIONS+=" nobsdcomp user ${USERNAME} lcp-echo-interval 20"
419 PPP_STD_OPTIONS+=" lcp-echo-failure 5 ${AUTH}"
420
421 if [ -n "${MTU}" ]; then
422 PPP_STD_OPTIONS="${PPP_STD_OPTIONS} mtu ${MTU}"
423 fi
424
425 if [ -n "${MRU}" ]; then
426 PPP_STD_OPTIONS="${PPP_STD_OPTIONS} mru ${MRU}"
427 fi
428
429 ### Debugging
430 #
431 if [ "${DEBUG}" == "on" ]; then
432 DEBUG="debug"
433 else
434 DEBUG=""
435 fi
436
437 ### PPPoE invocation
438 #
439 if [ "$TYPE" == "pppoe" ]; then
440 PPPOE_CMD="/usr/sbin/pppoe -p /var/run/ppp-ipfire.pid.pppoe -I $PPP_NIC"
441 PPPOE_CMD+=" -T 80 -U $PPPOE_SYNC $ACNAME $SERVICENAMEOPT"
442 fi
443
444 ### PPTP ###
445 #
446 if [ "$TYPE" == "pptp" ]; then
447 PPPOE_CMD="pptp $PPTP_PEER --nolaunchpppd"
448 METHOD=""
449 fi
450
451 ### Run everything
452 #
453 if [ "$METHOD" == "PPPOE_PLUGIN" ]; then
454 /usr/sbin/pppd $PPP_STD_OPTIONS $DEBUG $DEMAND >/dev/null 2>&1 &
455 evaluate_retval
456 # echo PLUGIN: /usr/sbin/pppd $PPP_STD_OPTIONS $DEBUG $DEMAND
457 else
458 /usr/sbin/pppd pty "$PPPOE_CMD" $PPP_STD_OPTIONS $DEBUG $DEMAND $PPPD_SYNC >/dev/null 2>&1 &
459 evaluate_retval
460 # echo PPP: /usr/sbin/pppd pty "$PPPOE_CMD" $PPP_STD_OPTIONS $DEBUG $DEMAND $PPPD_SYNC
461 fi
462 ## Create & Enable vnstat
463 /usr/bin/vnstat -u -i ppp0 -r --enable --force > /dev/null 2>&1
464 /etc/rc.d/init.d/connectd start
465 # Add a NaN value to ppp0 rrd to supress spikes at reconnect
466 rrdtool update $RRDLOG/collectd/localhost/interface/if_octets-ppp0.rrd \
467 $(date +%s):: > /dev/null 2>&1
468 exit 0
469 fi
470 ;;
471
472 stop)
473 rm -f /var/ipfire/red/{active,device,dial-on-demand,dns1,dns2,local-ipaddress,remote-ipaddress,resolv.conf}
474
475 if [ "$TYPE" == "STATIC" ]; then
476 boot_mesg "Stopping default gateway ${GATEWAY}..."
477 ip route del default via ${GATEWAY} >/dev/null 2>&1
478 echo_ok
479 if [ "$DEVICE" != "${GREEN_DEV}" ]; then
480 boot_mesg "Removing IPv4 addresses from the ${DEVICE} interface..."
481 ip addr flush dev ${DEVICE}
482 evaluate_retval
483 fi
484 run_subdir ${rc_base}/init.d/networking/red.down/
485
486 elif [ "$TYPE" == "PPPOE" ]; then
487 boot_mesg "Bringing down the PPP interface ..."
488 ## Disable vnstat collection
489 /usr/bin/vnstat -u -i ppp0 -r --disable > /dev/null 2>&1
490 rm -f /var/ipfire/red/keepconnected
491 killall -w -s TERM /usr/sbin/pppd 2>/dev/null
492 evaluate_retval
493 # Add a NaN value to ppp0 rrd to supress spikes at reconnect
494 rrdtool update $RRDLOG/collectd/localhost/interface/if_octets-ppp0.rrd \
495 $(date +%s):: > /dev/null 2>&1
496
497 elif [ "$TYPE" == "DHCP" ]; then
498 # Check if the wlan-client is used on red.
499 # To determine this we check if a wpa_supplicant is running.
500 pid="$(pidof wpa_supplicant)"
501
502 if [ -z "${pid}" ]; then
503 # Stop dhcpcd.
504 dhcpcd_stop "${DEVICE}"
505 fi
506 fi
507
508 if [ -n "${PPTP_ROUTE}" ]; then
509 route del ${PPTP_ROUTE}
510 fi
511
512 if [ "$DEVICE" != "${GREEN_DEV}" ] && [ "$DEVICE" != "" ]; then
513 link_status=`ip link show $DEVICE.${INET_VLAN} 2> /dev/null`
514 if [ -n "${link_status}" ]; then
515 if echo "${link_status}" | grep -q UP; then
516 boot_mesg "Bringing down the ${DEVICE}.${INET_VLAN} interface..."
517 ip link set ${DEVICE}.${INET_VLAN} down
518 vconfig rem ${DEVICE}.${INET_VLAN}
519 evaluate_retval
520 fi
521 else
522 link_status=`ip link show $DEVICE 2> /dev/null`
523 if [ -n "${link_status}" ]; then
524 if echo "${link_status}" | grep -q UP; then
525 boot_mesg "Bringing down the ${DEVICE} interface..."
526 ip link set ${DEVICE} down
527 evaluate_retval
528 fi
529 fi
530 fi
531 fi
532 killall -w -s KILL /usr/sbin/pppd >/dev/null 2>&1
533 killall -w -s KILL pptp >/dev/null 2>&1
534 killall -w -s KILL br2684ctl >/dev/null 2>&1
535
536 ## Disable vnstat collection
537 /usr/bin/vnstat -u -i ${DEVICE} -r --disable > /dev/null 2>&1
538
539 exit 0;
540 ;;
541 esac