3 # Configure routing and miscellaneous network tunables
9 # REQUIRE: faith netif ppp stf
16 start_cmd="routing_start doall"
17 stop_cmd="routing_stop"
18 extra_commands="options static"
19 static_cmd="routing_start static"
20 options_cmd="routing_start options"
25 ""|inet|inet6|ipx|atm)
28 err 1 "Unsupported address family: $_af."
46 for _a in inet inet6 ipx atm; do
47 afexists $_a && setroutes $_cmd $_a
62 eval static_${_af} delete
63 eval routing_stop_${_af}
66 for _a in inet inet6 ipx atm; do
67 afexists $_a || continue
68 eval static_${_a} delete
69 eval routing_stop_${_a}
100 route -n flush -inet6
101 for i in ${ipv6_network_interfaces}; do
102 ifconfig $i inet6 -defaultif
121 case ${defaultrouter} in
125 static_routes="default ${static_routes}"
126 route_default="default ${defaultrouter}"
130 if [ -n "${static_routes}" ]; then
131 for i in ${static_routes}; do
132 route_args=`get_if_var $i route_IF`
133 route ${_action} ${route_args}
143 # get the number of FIBs supported.
144 fibs=`sysctl -n net.fibs`
147 # disallow "internal" addresses to appear on the wire
148 route ${_action} -inet6 ::ffff:0.0.0.0 -prefixlen 96 ::1 -reject
149 route ${_action} -inet6 ::0.0.0.0 -prefixlen 96 ::1 -reject
151 if test ${i} -lt ${fibs}; then
152 printf "Also installing reject routes for FIBs"
153 while test ${i} -lt ${fibs}; do
154 setfib -F ${i} route -q ${_action} \
155 -inet6 ::ffff:0.0.0.0 -prefixlen 96 ::1 -reject
156 setfib -F ${i} route -q ${_action} \
157 -inet6 ::0.0.0.0 -prefixlen 96 ::1 -reject
164 case ${ipv6_defaultrouter} in
168 ipv6_static_routes="default ${ipv6_static_routes}"
169 ipv6_route_default="default ${ipv6_defaultrouter}"
173 if [ -n "${ipv6_static_routes}" ]; then
174 for i in ${ipv6_static_routes}; do
175 ipv6_route_args=`get_if_var $i ipv6_route_IF`
176 route ${_action} -inet6 ${ipv6_route_args}
180 # Fixup $ipv6_network_interfaces
181 case ${ipv6_network_interfaces} in
183 ipv6_network_interfaces=''
187 if checkyesno ipv6_gateway_enable; then
188 for i in ${ipv6_network_interfaces}; do
190 laddr=`network6_getladdr $i exclude_tentative`
195 ipv6_working_interfaces="$i \
196 ${ipv6_working_interfaces}"
200 ipv6_network_interfaces=${ipv6_working_interfaces}
203 # Install the "default interface" to kernel, which will be used
204 # as the default route when there's no router.
205 case "${ipv6_default_interface}" in
206 [Nn][Oo] | [Nn][Oo][Nn][Ee])
207 ipv6_default_interface=""
209 [Aa][Uu][Tt][Oo] | "")
210 for i in ${ipv6_network_interfaces}; do
216 laddr=`network6_getladdr $i exclude_tentative`
221 ipv6_default_interface=$i
229 # Disallow link-local unicast packets without outgoing scope
230 # identifiers. However, if you set "ipv6_default_interface",
231 # for the host case, you will allow to omit the identifiers.
232 # Under this configuration, the packets will go to the default
234 route ${_action} -inet6 fe80:: -prefixlen 10 ::1 -reject
235 route ${_action} -inet6 ff02:: -prefixlen 16 ::1 -reject
237 if test ${i} -lt ${fibs}; then
238 printf "Also installing reject routes for FIBs"
239 while test ${i} -lt ${fibs}; do
240 setfib -F ${i} route -q ${_action} \
241 -inet6 fe80:: -prefixlen 10 ::1 -reject
242 setfib -F ${i} route -q ${_action} \
243 -inet6 ff02:: -prefixlen 16 ::1 -reject
250 case ${ipv6_default_interface} in
254 # Disable installing the default interface when we act
255 # as router to avoid conflict between the default
256 # router list and the manual configured default route.
257 if ! checkyesno ipv6_gateway_enable; then
258 ifconfig ${ipv6_default_interface} inet6 defaultif
259 sysctl net.inet6.ip6.use_defaultzone=1
267 local _action i route_args
270 if [ -n "${natm_static_routes}" ]; then
271 for i in ${natm_static_routes}; do
272 route_args=`get_if_var $i route_IF`
273 atmconfig natm ${_action} ${route_args}
284 if [ -z "${_ropts_initdone}" ]; then
285 echo -n "Additional $1 routing options:"
293 if checkyesno icmp_bmcastecho; then
295 echo -n ' broadcast ping responses=YES'
296 ${SYSCTL} net.inet.icmp.bmcastecho=1 > /dev/null
298 ${SYSCTL} net.inet.icmp.bmcastecho=0 > /dev/null
301 if checkyesno icmp_drop_redirect; then
303 echo -n ' ignore ICMP redirect=YES'
304 ${SYSCTL} net.inet.icmp.drop_redirect=1 > /dev/null
306 ${SYSCTL} net.inet.icmp.drop_redirect=0 > /dev/null
309 if checkyesno icmp_log_redirect; then
311 echo -n ' log ICMP redirect=YES'
312 ${SYSCTL} net.inet.icmp.log_redirect=1 > /dev/null
314 ${SYSCTL} net.inet.icmp.log_redirect=0 > /dev/null
317 if checkyesno gateway_enable; then
319 echo -n ' gateway=YES'
320 ${SYSCTL} net.inet.ip.forwarding=1 > /dev/null
322 ${SYSCTL} net.inet.ip.forwarding=0 > /dev/null
325 if checkyesno forward_sourceroute; then
327 echo -n ' do source routing=YES'
328 ${SYSCTL} net.inet.ip.sourceroute=1 > /dev/null
330 ${SYSCTL} net.inet.ip.sourceroute=0 > /dev/null
333 if checkyesno accept_sourceroute; then
335 echo -n ' accept source routing=YES'
336 ${SYSCTL} net.inet.ip.accept_sourceroute=1 > /dev/null
338 ${SYSCTL} net.inet.ip.accept_sourceroute=0 > /dev/null
341 if checkyesno arpproxy_all; then
343 echo -n ' ARP proxyall=YES'
344 ${SYSCTL} net.link.ether.inet.proxyall=1 > /dev/null
346 ${SYSCTL} net.link.ether.inet.proxyall=0 > /dev/null
349 [ -n "${_ropts_initdone}" ] && echo '.'
356 if checkyesno ipv6_gateway_enable; then
358 echo -n ' gateway=YES'
359 ${SYSCTL} net.inet6.ip6.forwarding=1 > /dev/null
361 ${SYSCTL} net.inet6.ip6.forwarding=0 > /dev/null
364 [ -n "${_ropts_initdone}" ] && echo '.'
371 [ -n "${_ropts_initdone}" ] && echo '.'
378 if checkyesno ipxgateway_enable; then
380 echo -n ' gateway=YES'
381 ${SYSCTL} net.ipx.ipx.ipxforwarding=1 > /dev/null
383 ${SYSCTL} net.ipx.ipx.ipxforwarding=0 > /dev/null
386 [ -n "${_ropts_initdone}" ] && echo '.'