3 # Configure routing and miscellaneous network tunables
9 # REQUIRE: netif ppp stf
17 start_cmd="routing_start doall"
18 stop_cmd="routing_stop"
19 extra_commands="options static"
20 static_cmd="routing_start static"
21 options_cmd="routing_start options"
23 ROUTE_CMD="/sbin/route"
27 local _cmd _af _if _a _ret
34 ""|[Aa][Ll][Ll]|[Aa][Nn][Yy]) _if="" ;;
38 ""|[Aa][Ll][Ll]|[Aa][Nn][Yy])
39 for _a in inet inet6; do
40 afexists $_a || continue
41 setroutes $_cmd $_a $_if || _ret=1
45 if afexists $_af; then
46 setroutes $_cmd $_af $_if || _ret=1
48 err 1 "Unsupported address family: $_af."
63 ""|[Aa][Ll][Ll]|[Aa][Nn][Yy]) _if="" ;;
67 ""|[Aa][Ll][Ll]|[Aa][Nn][Yy])
68 for _a in inet inet6; do
69 afexists $_a || continue
70 eval static_${_a} delete $_if
71 # When $_if is specified, do not flush routes.
72 if ! [ -n "$_if" ]; then
73 eval routing_stop_${_a}
78 if afexists $_af; then
79 eval static_${_af} delete $_if
80 # When $_if is specified, do not flush routes.
81 if ! [ -n "$_if" ]; then
82 eval routing_stop_${_af}
85 err 1 "Unsupported address family: $_af."
114 ${ROUTE_CMD} -n flush -inet
121 ${ROUTE_CMD} -n flush -inet6
122 for i in `list_net_interfaces`; do
124 ifconfig $i inet6 -defaultif
133 _fibs=$((`${SYSCTL_N} net.fibs` - 1))
134 if [ ${_fibs} -gt 0 ]; then
135 echo "-fib 0-${_fibs}"
143 local _action _if _skip _fibmod
149 # Provide loopback route in all routing tables. This has to come
150 # first so that any following routes can be added.
151 static_routes="_loopback ${static_routes}"
152 route__loopback="-inet 127.0.0.1 -iface lo0 ${_fibmod}"
155 case ${defaultrouter} in
159 static_routes="${static_routes} _default"
160 route__default="default ${defaultrouter}"
164 # Install configured routes.
165 if [ -n "${static_routes}" ]; then
166 for i in ${static_routes}; do
168 if [ -n "$_if" ]; then
174 if [ $_skip = 0 ]; then
175 route_args=`get_if_var ${i%:*} route_IF`
176 if [ -n "$route_args" ]; then
177 ${ROUTE_CMD} ${_action} ${route_args}
179 warn "route_${i%:*} not found."
188 local _action _if _skip fibmod allfibs
194 # Add pre-defined static routes first.
195 ipv6_static_routes="_v4mapped _v4compat ${ipv6_static_routes}"
196 ipv6_static_routes="_lla _llma ${ipv6_static_routes}"
197 ipv6_static_routes="_loopback ${ipv6_static_routes}"
199 # disallow "internal" addresses to appear on the wire
200 ipv6_route__v4mapped="::ffff:0.0.0.0 -prefixlen 96 ::1 -reject ${fibmod}"
201 ipv6_route__v4compat="::0.0.0.0 -prefixlen 96 ::1 -reject ${fibmod}"
203 # Create a loopback route in every fib
204 ipv6_route__loopback="::1 -prefixlen 128 -iface lo0 ${fibmod}"
206 # Disallow link-local unicast packets without outgoing scope
207 # identifiers. However, if you set "ipv6_default_interface",
208 # for the host case, you will allow to omit the identifiers.
209 # Under this configuration, the packets will go to the default
211 ipv6_route__lla="fe80:: -prefixlen 10 ::1 -reject ${fibmod}"
212 ipv6_route__llma="ff02:: -prefixlen 16 ::1 -reject ${fibmod}"
215 case ${ipv6_defaultrouter} in
219 ipv6_static_routes="${ipv6_static_routes} _default"
220 ipv6_route__default="default ${ipv6_defaultrouter}"
224 # Install configured routes.
225 if [ -n "${ipv6_static_routes}" ]; then
226 for i in ${ipv6_static_routes}; do
228 if [ -n "$_if" ]; then
234 if [ $_skip = 0 ]; then
235 ipv6_route_args=`get_if_var ${i%:*} ipv6_route_IF`
236 if [ -n "$ipv6_route_args" ]; then
237 ${ROUTE_CMD} ${_action} \
238 -inet6 ${ipv6_route_args}
240 warn "route_${i%:*} not found"
246 # Install the "default interface" to kernel, which will be used
247 # as the default route when there's no router.
249 # Disable installing the default interface when we act
250 # as router to avoid conflict between the default
251 # router list and the manual configured default route.
252 if checkyesno ipv6_gateway_enable; then
256 case "${ipv6_default_interface}" in
257 [Nn][Oo] | [Nn][Oo][Nn][Ee])
260 [Aa][Uu][Tt][Oo] | "")
261 for i in ${ipv6_network_interfaces}; do
270 laddr=`network6_getladdr $i exclude_tentative`
275 ipv6_default_interface=$i
283 ifconfig ${ipv6_default_interface} inet6 defaultif
284 ${SYSCTL} net.inet6.ip6.use_defaultzone=1 > /dev/null
289 if [ -z "${_ropts_initdone}" ]; then
290 echo -n "Additional $1 routing options:"
295 _check_dynamicrouting()
297 local skip file name rcvar
299 # copied from /etc/rc
301 if [ `/sbin/sysctl -n security.jail.jailed` -eq 1 ]; then
302 skip="$skip -s nojail"
304 [ -n "$local_startup" ] && find_local_scripts_new
306 for file in $( rcorder ${skip} /etc/rc.d/* ${local_rc} 2>/dev/null |
307 xargs grep -lE '^# PROVIDE:.*\<dynamicrouting\>' ); do
308 (set -- enabled; . $file) && return 0;
316 local _icmp_drop_redirect
319 if checkyesno icmp_bmcastecho; then
321 echo -n ' broadcast ping responses=YES'
322 ${SYSCTL} net.inet.icmp.bmcastecho=1 > /dev/null
324 ${SYSCTL} net.inet.icmp.bmcastecho=0 > /dev/null
327 _icmp_drop_redirect="${icmp_drop_redirect}"
328 case "${_icmp_drop_redirect}" in
329 [Aa][Uu][Tt][Oo] | "")
330 if _check_dynamicrouting; then
331 _icmp_drop_redirect="yes"
333 _icmp_drop_redirect="no"
337 if checkyesno _icmp_drop_redirect; then
339 echo -n ' ignore ICMP redirect=YES'
340 ${SYSCTL} net.inet.icmp.drop_redirect=1 > /dev/null
342 ${SYSCTL} net.inet.icmp.drop_redirect=0 > /dev/null
345 if checkyesno icmp_log_redirect; then
347 echo -n ' log ICMP redirect=YES'
348 ${SYSCTL} net.inet.icmp.log_redirect=1 > /dev/null
350 ${SYSCTL} net.inet.icmp.log_redirect=0 > /dev/null
353 if checkyesno gateway_enable; then
355 echo -n ' gateway=YES'
356 ${SYSCTL} net.inet.ip.forwarding=1 > /dev/null
358 ${SYSCTL} net.inet.ip.forwarding=0 > /dev/null
361 if checkyesno forward_sourceroute; then
363 echo -n ' do source routing=YES'
364 ${SYSCTL} net.inet.ip.sourceroute=1 > /dev/null
366 ${SYSCTL} net.inet.ip.sourceroute=0 > /dev/null
369 if checkyesno accept_sourceroute; then
371 echo -n ' accept source routing=YES'
372 ${SYSCTL} net.inet.ip.accept_sourceroute=1 > /dev/null
374 ${SYSCTL} net.inet.ip.accept_sourceroute=0 > /dev/null
377 if checkyesno arpproxy_all; then
379 echo -n ' ARP proxyall=YES'
380 ${SYSCTL} net.link.ether.inet.proxyall=1 > /dev/null
382 ${SYSCTL} net.link.ether.inet.proxyall=0 > /dev/null
385 [ -n "${_ropts_initdone}" ] && echo '.'
392 if checkyesno ipv6_gateway_enable; then
394 echo -n ' gateway=YES'
395 ${SYSCTL} net.inet6.ip6.forwarding=1 > /dev/null
397 ${SYSCTL} net.inet6.ip6.forwarding=0 > /dev/null
400 [ -n "${_ropts_initdone}" ] && echo '.'