a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#!/sbin/sh
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# CDDL HEADER START
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# The contents of this file are subject to the terms of the
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# Common Development and Distribution License (the "License").
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# You may not use this file except in compliance with the License.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# or http://www.opensolaris.org/os/licensing.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# See the License for the specific language governing permissions
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# and limitations under the License.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# When distributing Covered Code, include this CDDL HEADER in each
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# file and include the License file at usr/src/OPENSOLARIS.LICENSE.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# If applicable, add the following below this CDDL HEADER, with the
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# fields enclosed by brackets "[]" replaced with your own identifying
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# information: Portions Copyright [yyyy] [name of copyright owner]
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# CDDL HEADER END
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
9b5bf10ab04b9be5564d70a57980cfb68b6372e7Mark Haywood# Copyright (c) 1999, 2010, Oracle and/or its affiliates. All rights reserved.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# This script configures IP routing.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire. /lib/svc/share/smf_include.sh
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
f4b3ec61df05330d25f55a36b975b4d7519fdeb1dh# In a shared-IP zone we need this service to be up, but all of the work
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# it tries to do is irrelevant (and will actually lead to the service
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# failing if we try to do it), so just bail out.
f4b3ec61df05330d25f55a36b975b4d7519fdeb1dh# In the global zone and exclusive-IP zones we proceed.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
f4b3ec61df05330d25f55a36b975b4d7519fdeb1dhsmf_configure_ip || exit $SMF_EXIT_OK
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# If routing.conf file is in place, and has not already been read in
ceb97a6a3232437e1f0b4c6b8604bc1b4245ccc5amaguire# by previous invokation of routeadm, legacy configuration is upgraded
ceb97a6a3232437e1f0b4c6b8604bc1b4245ccc5amaguire# by this call to "routeadm -u". This call is also needed when
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# a /var/svc/profile/upgrade file is found, as it may contain routeadm commands
ceb97a6a3232437e1f0b4c6b8604bc1b4245ccc5amaguire# which need to be applied. Finally, routeadm starts in.ndpd by
ceb97a6a3232437e1f0b4c6b8604bc1b4245ccc5amaguire# enabling the ndp service (in.ndpd), which is required for IPv6 address
ceb97a6a3232437e1f0b4c6b8604bc1b4245ccc5amaguire# autoconfiguration. It would be nice if we could do this in
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# network/loopback, but since the SMF backend is read-only at that
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# point in boot, we cannot.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
ceb97a6a3232437e1f0b4c6b8604bc1b4245ccc5amaguire/sbin/routeadm -u
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# Are we routing dynamically? routeadm(1M) reports this in the
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# "current" values of ipv4/6-routing - if either are true, we are running
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# routing daemons (or at least they are enabled to run).
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguiredynamic_routing_test=`/sbin/routeadm -p | \
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguirenawk '/^ipv[46]-routing [.]*/ { print $2 }' | /usr/bin/grep "current=enabled"`
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguireif [ -n "$dynamic_routing_test" ]; then
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire dynamic_routing="true"
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguirefi
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# Configure default IPv4 routers using the local "/etc/defaultrouter"
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# configuration file. The file can contain the hostnames or IP
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# addresses of one or more default routers. If hostnames are used,
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# each hostname must also be listed in the local "/etc/hosts" file
36e852a172cba914383d7341c988128b2c667fbdRaja Andra# because NIS is not running at the time that this script is
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# run. Each router name or address is listed on a single line by
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# itself in the file. Anything else on that line after the router's
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# name or address is ignored. Lines that begin with "#" are
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# considered comments and ignored.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# The default routes listed in the "/etc/defaultrouter" file will
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# replace those added by the kernel during diskless booting. An
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# empty "/etc/defaultrouter" file will cause the default route
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# added by the kernel to be deleted.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# Note that the default router file is ignored if we received routes
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# from a DHCP server. Our policy is to always trust DHCP over local
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# administration.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguiresmf_netstrategy
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguireif [ "$_INIT_NET_STRATEGY" = "dhcp" ] && \
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire [ -n "`/sbin/dhcpinfo Router`" ]; then
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire defrouters=`/sbin/dhcpinfo Router`
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguireelif [ -f /etc/defaultrouter ]; then
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire defrouters=`/usr/bin/grep -v \^\# /etc/defaultrouter | \
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire /usr/bin/awk '{print $1}'`
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire if [ -n "$defrouters" ]; then
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire #
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # We want the default router(s) listed in
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # /etc/defaultrouter to replace the one added from the
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # BOOTPARAMS WHOAMI response but we must avoid flushing
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # the last route between the running system and its
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # /usr file system.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire #
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # First, remember the original route.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire shift $#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire set -- `/usr/bin/netstat -rn -f inet | \
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire /usr/bin/grep '^default'`
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire route_IP="$2"
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire #
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # Next, add those from /etc/defaultrouter. While doing
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # this, if one of the routes we add is for the route
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # previously added as a result of the BOOTPARAMS
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # response, we will see a message of the form:
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # "add net default: gateway a.b.c.d: entry exists"
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire #
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire do_delete=yes
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire for router in $defrouters; do
e7ad388adbf175c15b5cb11584f1b92685ed77fcamaguire route_added=`/usr/sbin/route -n add default \
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire -gateway $router`
e7ad388adbf175c15b5cb11584f1b92685ed77fcamaguire res=$?
e7ad388adbf175c15b5cb11584f1b92685ed77fcamaguire set -- $route_added
e7ad388adbf175c15b5cb11584f1b92685ed77fcamaguire [ $res -ne 0 -a "$5" = "$route_IP:" ] && do_delete=no
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire done
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire #
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # Finally, delete the original default route unless it
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # was also listed in the defaultrouter file.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire #
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire if [ -n "$route_IP" -a $do_delete = yes ]; then
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire /usr/sbin/route -n delete default \
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire -gateway $route_IP >/dev/null
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire fi
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire else
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire /usr/sbin/route -fn > /dev/null
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire fi
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguireelse
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire defrouters=
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguirefi
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# Use routeadm(1M) to configure forwarding and launch routing daemons
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# for IPv4 and IPv6 based on preset values. These settings only apply
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# to the global zone. For IPv4 dynamic routing, the system will default
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# to disabled if a default route was previously added via BOOTP, DHCP,
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# or the /etc/defaultrouter file. routeadm also starts in.ndpd.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguireif [ "$dynamic_routing" != "true" ] && [ -z "$defrouters" ]; then
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire #
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # No default routes were setup by "route" command above.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # Check the kernel routing table for any other default
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # routes.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire #
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire /usr/bin/netstat -rn -f inet | \
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire /usr/bin/grep default >/dev/null 2>&1 && defrouters=yes
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguirefi
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# The routeadm/ipv4-routing-set property is true if the administrator
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# has run "routeadm -e/-d ipv4-routing". If not, we revert to the
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# appropriate defaults. We no longer run "routeadm -u" on every boot
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# however, as persistent daemon state is now controlled by SMF.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguireipv4_routing_set=`/usr/bin/svcprop -p routeadm/ipv4-routing-set $SMF_FMRI`
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguireif [ -z "$defrouters" ]; then
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire #
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # Set default value for ipv4-routing to enabled. If routeadm -e/-d
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # has not yet been run by the administrator, we apply this default.
ef2c19a1d5242688ccc42f46886fcc495f8e1141amaguire # The -b option is project-private and informs routeadm not
ef2c19a1d5242688ccc42f46886fcc495f8e1141amaguire # to treat the enable as administrator-driven.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire #
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire /usr/sbin/svccfg -s $SMF_FMRI \
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire setprop routeadm/default-ipv4-routing = true
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire if [ "$ipv4_routing_set" = "false" ]; then
ef2c19a1d5242688ccc42f46886fcc495f8e1141amaguire /sbin/routeadm -b -e ipv4-routing -u
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire fi
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguireelse
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire #
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # Default router(s) have been found, so ipv4-routing default value
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire # should be disabled. If routaedm -e/d has not yet been run by
ef2c19a1d5242688ccc42f46886fcc495f8e1141amaguire # the administrator, we apply this default. The -b option is
ef2c19a1d5242688ccc42f46886fcc495f8e1141amaguire # project-private and informs routeadm not to treat the disable as
ef2c19a1d5242688ccc42f46886fcc495f8e1141amaguire # administrator-driven.
ef2c19a1d5242688ccc42f46886fcc495f8e1141amaguire #
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire /usr/sbin/svccfg -s $SMF_FMRI \
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire setprop routeadm/default-ipv4-routing = false
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire if [ "$ipv4_routing_set" = "false" ]; then
ef2c19a1d5242688ccc42f46886fcc495f8e1141amaguire /sbin/routeadm -b -d ipv4-routing -u
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire fi
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguirefi
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire
9b5bf10ab04b9be5564d70a57980cfb68b6372e7Mark Haywood#
9b5bf10ab04b9be5564d70a57980cfb68b6372e7Mark Haywood# See if static routes were created by install. If so, they were created
9b5bf10ab04b9be5564d70a57980cfb68b6372e7Mark Haywood# under /etc/svc/volatile. Copy them into their proper place.
9b5bf10ab04b9be5564d70a57980cfb68b6372e7Mark Haywood#
9b5bf10ab04b9be5564d70a57980cfb68b6372e7Mark Haywoodif [ -f /etc/svc/volatile/etc/inet/static_routes ]; then
9b5bf10ab04b9be5564d70a57980cfb68b6372e7Mark Haywood echo "Installing persistent routes"
9b5bf10ab04b9be5564d70a57980cfb68b6372e7Mark Haywood if [ -f /etc/inet/static_routes ]; then
9b5bf10ab04b9be5564d70a57980cfb68b6372e7Mark Haywood cat /etc/svc/volatile/etc/inet/static_routes | grep -v '^#' \
9b5bf10ab04b9be5564d70a57980cfb68b6372e7Mark Haywood >> /etc/inet/static_routes
9b5bf10ab04b9be5564d70a57980cfb68b6372e7Mark Haywood else
9b5bf10ab04b9be5564d70a57980cfb68b6372e7Mark Haywood cp /etc/svc/volatile/etc/inet/static_routes \
9b5bf10ab04b9be5564d70a57980cfb68b6372e7Mark Haywood /etc/inet/static_routes
9b5bf10ab04b9be5564d70a57980cfb68b6372e7Mark Haywood fi
9b5bf10ab04b9be5564d70a57980cfb68b6372e7Mark Haywood /usr/bin/rm /etc/svc/volatile/etc/inet/static_routes
9b5bf10ab04b9be5564d70a57980cfb68b6372e7Mark Haywood
9b5bf10ab04b9be5564d70a57980cfb68b6372e7Mark Haywoodfi
9b5bf10ab04b9be5564d70a57980cfb68b6372e7Mark Haywood
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# Read /etc/inet/static_routes and add each route.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire#
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguireif [ -f /etc/inet/static_routes ]; then
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire echo "Adding persistent routes:"
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire /usr/bin/egrep -v "^(#|$)" /etc/inet/static_routes | while read line; do
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire /usr/sbin/route add $line
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire done
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguirefi
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguire# Clear exit status.
a192e900f6d2b0e1a822e3252c0dfd795ed49d76amaguireexit $SMF_EXIT_OK