3 # Configure routing and miscellaneous network tunables
9 # REQUIRE: faith netif ppp stf
16 start_cmd="routing_start doall"
17 stop_cmd="routing_stop"
18 extra_commands="options static"
19 static_cmd="routing_start static"
20 options_cmd="routing_start options"
25 ""|inet|inet6|ipx|atm)
28 err 1 "Unsupported address family: $_af."
46 for _a in inet inet6 ipx atm; do
47 afexists $_a && setroutes $_cmd $_a
51 [ -n "${_ropts_initdone}" ] && echo '.'
63 eval static_${_af} delete
64 eval routing_stop_${_af}
67 for _a in inet inet6 ipx atm; do
68 afexists $_a || continue
69 eval static_${_a} delete
70 eval routing_stop_${_a}
101 route -n flush -inet6
102 for i in ${ipv6_network_interfaces}; do
103 ifconfig $i inet6 -defaultif
122 case ${defaultrouter} in
126 static_routes="default ${static_routes}"
127 route_default="default ${defaultrouter}"
131 if [ -n "${static_routes}" ]; then
132 for i in ${static_routes}; do
133 route_args=`get_if_var $i route_IF`
134 route ${_action} ${route_args}
144 # disallow "internal" addresses to appear on the wire
145 route ${_action} -inet6 ::ffff:0.0.0.0 -prefixlen 96 ::1 -reject
146 route ${_action} -inet6 ::0.0.0.0 -prefixlen 96 ::1 -reject
148 case ${ipv6_defaultrouter} in
152 ipv6_static_routes="default ${ipv6_static_routes}"
153 ipv6_route_default="default ${ipv6_defaultrouter}"
157 if [ -n "${ipv6_static_routes}" ]; then
158 for i in ${ipv6_static_routes}; do
159 ipv6_route_args=`get_if_var $i ipv6_route_IF`
160 route ${_action} -inet6 ${ipv6_route_args}
164 # Fixup $ipv6_network_interfaces
165 case ${ipv6_network_interfaces} in
167 ipv6_network_interfaces=''
171 if checkyesno ipv6_gateway_enable; then
172 for i in ${ipv6_network_interfaces}; do
174 laddr=`network6_getladdr $i exclude_tentative`
179 ipv6_working_interfaces="$i \
180 ${ipv6_working_interfaces}"
184 ipv6_network_interfaces=${ipv6_working_interfaces}
187 # Install the "default interface" to kernel, which will be used
188 # as the default route when there's no router.
189 case "${ipv6_default_interface}" in
190 [Nn][Oo] | [Nn][Oo][Nn][Ee])
191 ipv6_default_interface=""
193 [Aa][Uu][Tt][Oo] | "")
194 for i in ${ipv6_network_interfaces}; do
200 laddr=`network6_getladdr $i exclude_tentative`
205 ipv6_default_interface=$i
213 # Disallow link-local unicast packets without outgoing scope
214 # identifiers. However, if you set "ipv6_default_interface",
215 # for the host case, you will allow to omit the identifiers.
216 # Under this configuration, the packets will go to the default
218 route ${_action} -inet6 fe80:: -prefixlen 10 ::1 -reject
219 route ${_action} -inet6 ff02:: -prefixlen 16 ::1 -reject
221 case ${ipv6_default_interface} in
225 # Disable installing the default interface when we act
226 # as router to avoid conflict between the default
227 # router list and the manual configured default route.
228 if ! checkyesno ipv6_gateway_enable; then
229 ifconfig ${ipv6_default_interface} inet6 defaultif
230 sysctl net.inet6.ip6.use_defaultzone=1
238 local _action i route_args
241 if [ -n "${natm_static_routes}" ]; then
242 for i in ${natm_static_routes}; do
243 route_args=`get_if_var $i route_IF`
244 atmconfig natm ${_action} ${route_args}
256 if [ -z "${_ropts_initdone}" ]; then
257 echo -n 'Additional routing options:'
264 if checkyesno icmp_bmcastecho; then
266 echo -n ' broadcast ping responses=YES'
267 ${SYSCTL} net.inet.icmp.bmcastecho=1 > /dev/null
269 ${SYSCTL} net.inet.icmp.bmcastecho=0 > /dev/null
272 if checkyesno icmp_drop_redirect; then
274 echo -n ' ignore ICMP redirect=YES'
275 ${SYSCTL} net.inet.icmp.drop_redirect=1 > /dev/null
277 ${SYSCTL} net.inet.icmp.drop_redirect=0 > /dev/null
280 if checkyesno icmp_log_redirect; then
282 echo -n ' log ICMP redirect=YES'
283 ${SYSCTL} net.inet.icmp.log_redirect=1 > /dev/null
285 ${SYSCTL} net.inet.icmp.log_redirect=0 > /dev/null
288 if checkyesno gateway_enable; then
290 echo -n ' IPv4 gateway=YES'
291 ${SYSCTL} net.inet.ip.forwarding=1 > /dev/null
293 ${SYSCTL} net.inet.ip.forwarding=0 > /dev/null
296 if checkyesno forward_sourceroute; then
298 echo -n ' do source routing=YES'
299 ${SYSCTL} net.inet.ip.sourceroute=1 > /dev/null
301 ${SYSCTL} net.inet.ip.sourceroute=0 > /dev/null
304 if checkyesno accept_sourceroute; then
306 echo -n ' accept source routing=YES'
307 ${SYSCTL} net.inet.ip.accept_sourceroute=1 > /dev/null
309 ${SYSCTL} net.inet.ip.accept_sourceroute=0 > /dev/null
312 if checkyesno arpproxy_all; then
314 echo -n ' ARP proxyall=YES'
315 ${SYSCTL} net.link.ether.inet.proxyall=1 > /dev/null
317 ${SYSCTL} net.link.ether.inet.proxyall=0 > /dev/null
323 if checkyesno ipv6_gateway_enable; then
325 echo -n ' IPv6 gateway=YES'
326 ${SYSCTL} net.inet6.ip6.forwarding=1 > /dev/null
328 ${SYSCTL} net.inet6.ip6.forwarding=0 > /dev/null
338 if checkyesno ipxgateway_enable; then
340 echo -n ' IPX gateway=YES'
341 ${SYSCTL} net.ipx.ipx.ipxforwarding=1 > /dev/null
343 ${SYSCTL} net.ipx.ipx.ipxforwarding=0 > /dev/null