]>
git.ipfire.org Git - people/stevee/network.git/blob - src/functions/functions.ip-tunnel
2 ###############################################################################
4 # IPFire.org - A linux based firewall #
5 # Copyright (C) 2012-2013 IPFire Network Development Team #
7 # This program is free software: you can redistribute it and/or modify #
8 # it under the terms of the GNU General Public License as published by #
9 # the Free Software Foundation, either version 3 of the License, or #
10 # (at your option) any later version. #
12 # This program is distributed in the hope that it will be useful, #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15 # GNU General Public License for more details. #
17 # You should have received a copy of the GNU General Public License #
18 # along with this program. If not, see <http://www.gnu.org/licenses/>. #
20 ###############################################################################
22 IP_TUNNEL_MODES
="gre sit vti"
37 while [ $# -gt 0 ]; do
40 mode
="$(cli_get_val ${1})"
43 ttl
="$(cli_get_val ${1})"
46 remote_address
="$(cli_get_val ${1})"
49 local_address
="$(cli_get_val ${1})"
54 ikey
="$(cli_get_val ${1})"
57 okey
="$(cli_get_val ${1})"
64 error
"--mode= is not set. Must be one of ${IP_TUNNEL_MODES}"
68 if ! isoneof mode
${IP_TUNNEL_MODES}; then
69 error
"Invalid mode: ${mode}"
73 # ikey and okey must be set for VTI devices
74 if [ "${mode}" = "vti" ] && (! isset ikey ||
! isset okey
); then
75 error
"--ikey= and --okey= must be set for VTI device"
79 # If TTL is set, make sure it is an integer.
80 if isset ttl
&& ! isinteger ttl
; then
81 error
"TTL must be an integer: ${ttl}"
87 # Apply TTL if a value has been set.
89 cmd_args
="${cmd_args} ttl ${ttl}"
92 # Apply local address if a value has been set.
93 if isset local_address
; then
94 cmd_args
="${cmd_args} local ${local_address}"
97 # Apply remote address if a value has been set.
98 if isset remote_address
; then
99 cmd_args
="${cmd_args} remote ${remote_address}"
102 # Add ikey and okey for VTI devices
103 if [ "${mode}" = "vti" ]; then
104 cmd_args
="${cmd_args} ikey ${ikey} okey ${okey}"
107 log DEBUG
"Creating tunnel device '${device}' (mode=${mode})..."
110 if ! cmd ip link add name
${device} type ${mode} ${cmd_args}; then
111 error
"Could not create tunnel device ${device}"
115 # Disable policy lookups for VTI devices
116 if [ "${mode}" = "vti" ]; then
117 sysctl_set
"net.ipv4.conf.${device}.disable_policy" "1"
125 assert device_exists
${device}
127 # Make sure the device has been shut down.
128 device_set_down
${device}
130 log DEBUG
"Removing tunnel device '${device}'..."
132 ip link del
${device}
136 ip_tunnel_change_keys
() {
140 if ! isset device
; then
141 error
"No device given"
148 while [ $# -gt 0 ]; do
151 ikey
="$(cli_get_val ${1})"
154 okey
="$(cli_get_val ${1})"
157 error
"Invalid argument: ${1}"
164 if ! isset ikey ||
! isset okey
; then
165 error
"You need to set --ikey= and --okey="
169 if ! device_exists
"${device}"; then
170 error
"No such device: ${device}"
174 if ! cmd ip link change dev
"${device}" \
175 type vti ikey
"${ikey}" okey
"${okey}"; then
176 log ERROR
"Could not change keys of device ${device}"