![]() ![]() |
sedlo |
Subversion Repositories: |
Compare with Previous - Blame - Download
#!/bin/bash# author : Petr Simandl www.simandl.cz# release date : 26/01/2006# name : sedlo# description : dynamic side routing tables tool# license : GPLsl_version="0.0.4pre1"PATH=$PATH:/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbinsl_nmcnf="sedlo.conf"sl_sedlocnf="/etc/$sl_nmcnf"sl_sedlocache="/var/cache/sedlo"sl_rttab="/etc/iproute2/rt_tables"sl_rtnmin=110sl_rtnmax=200sl_ipnodef="10.0.0.0/8"slm_unknown="Nezname parametry : "sl_ipcmd=`which ip`sl_trcmd=`which tr`sl_wgetcmd=`which wget`sl_hnmcmd=`which hostname`sl_awkcmd=`which awk`sl_catcmd=`which cat`sl_grepcmd=`which grep`sl_diffcmd=`which diff`if [ -e $sl_sedlocnf ]thensl_nop=1elseecho "$sl_sedlocnf not found"exit 1fiif [ -e $sl_rttab ]thensl_nop=1elseecho "$sl_rttab not found"exit 1fisl_murlcfg=`cat $sl_sedlocnf | grep "^mcnf" | uniq | awk '{print $2" "$3" "$4}'`######################################################################s_maru(){if [ $scm_info -gt 0 ]; then echo "Managing rules" ; fisl_rules=`($sl_ipcmd ru ls | $sl_grepcmd -v "from all lookup" | $sl_awkcmd '{print $3"*ru"}' ; \$sl_catcmd $sl_sedlocache/$sl_nmcnf | $sl_grepcmd "^ip" | $sl_awkcmd '{print $2"*ip"}') | sort | uniq`sl_merged=`echo $sl_rules $sl_ips | sort | uniq`echo $sl_merged} # s_maru######################################################################s_flru(){if [ $scm_info -gt 0 ]; then echo "Flushing all rules" ; fisl_rules=`$sl_ipcmd ru ls | $sl_grepcmd -v "from all lookup" | $sl_grepcmd " 10." | $sl_trcmd '[:blank:]' '*'`for sl_rule in $sl_rulesdo# sl_ipn=`echo $sl_rule | $sl_awkcmd -F '*' '{print $2}'`sl_ipgws=`echo $sl_rule | $sl_awkcmd -F '*' '{print $2,$3,$4,$5,$6,$7}'`$sl_ipcmd ru del $sl_ipgwsdone#this should make faster applying of new routing tables$sl_ipcmd ro flush cache} # s_flru####################################################################### here we get each ip and we create a rule to send this ip to a# certain table# this routine can be skipped when the number of ips and ip directions# are still the same = old and new configs are the sames_fillrules(){#flush old rules before filling new ones#not so nice solution - it is planned to change just what's necessary#by s_marus_flruif [ $scm_info -gt 0 ]; then echo "Creating rules for ips" ; fisl_ips=`$sl_catcmd $sl_sedlocache/$sl_nmcnf | $sl_grepcmd "^ip" | $sl_awkcmd '{print $2"*"$4"*"$5"*"$6}'`for sl_ip in $sl_ipsdosl_ipn=`echo $sl_ip | $sl_awkcmd -F '*' '{print $1}'`sl_ipgws=`echo $sl_ip | $sl_awkcmd -F '*' '{print $2,$3,$4}'`sl_ok="no"for sl_ipgw in $sl_ipgwsdosl_tbl=`$sl_ipcmd ro ls ta $sl_ipgw`if [ "$sl_tbl x" != " x" ] && [ "$sl_ok" = "no" ]thenif [ $scm_info -gt 1 ]; then echo "Creating new rules to send $sl_ipn to table $sl_ipgw" ; fi$sl_ipcmd ru add from $sl_ipn lookup $sl_ipgwsl_ok="yes"elseif [ "$sl_ok" = "no" ]thenif [ $scm_info -gt 1 ]; then echo "For $sl_ipn table $sl_ipgw not used because it is empty" ; fielseif [ $scm_info -gt 1 ]; then echo "For $sl_ipn table $sl_ipgw not used because it has lower priority" ; fififidonedone$sl_ipcmd ru add from $sl_ipnodef to $sl_ipnodef lookup main#this should make faster applying of new routing tables$sl_ipcmd ro flush cache} # s_fillrules####################################################################### here we look into the main routing table for path to our iGWs# and we fill these tables with two halves default nets that# point to appropriate direction# this routine can be skipped when the routing table is the sames_filltables(){if [ $scm_info -gt 0 ]; then echo "Checking main routing table" ; fiif [ $scm_info -gt 0 ]; then echo "Filling tables" ; fisl_igws=`$sl_catcmd $sl_sedlocache/$sl_nmcnf | $sl_grepcmd -E "^igw|^myigw" | $sl_awkcmd '{print $3"*"$2"*"$1}'`for sl_igw in $sl_igwsdosl_igwn=`echo $sl_igw | $sl_awkcmd -F '*' '{print $1}'`sl_igwip=`echo $sl_igw | $sl_awkcmd -F '*' '{print $2}'`sl_igwtype=`echo $sl_igw | $sl_awkcmd -F '*' '{print $3}'`sl_igwgt=`$sl_ipcmd ro ls | $sl_grepcmd "^$sl_igwip " | $sl_awkcmd '{print $3}'`# equal cost multipath detection - just first IP is taken as way to igwif [ "$sl_igwgt x" = "zebra x" ]thensl_igwgt=`$sl_ipcmd ro ls | $sl_grepcmd -A 1 "^$sl_igwip " | $sl_grepcmd "nexthop" | $sl_awkcmd '{print $3}'`fi#if myigw then fill table for local gateway with single ip from configif [ "$sl_igwtype x" = "myigw x" ]thensl_igwgt=$sl_igwipfiif [ "$sl_igwgt x" = " x" ]thenif [ $scm_info -gt 1 ]; then echo "Route not found for igw $sl_igwn - leaving table as is" ; fielsesl_tbl=`$sl_ipcmd ro ls ta $sl_igwn`if [ "$sl_tbl x" != " x" ]then$sl_ipcmd ro fl ta $sl_igwnfi$sl_ipcmd ro add 0.0.0.0/1 via $sl_igwgt ta $sl_igwn$sl_ipcmd ro add 128.0.0.0/1 via $sl_igwgt ta $sl_igwnif [ "$sl_igwtype x" = "myigw x" ]thenif [ $scm_info -gt 1 ]; then echo "Table filled for myigw $sl_igwn" ; fielseif [ $scm_info -gt 1 ]; then echo "Table filled for igw $sl_igwn" ; fififidone} # s_filltables####################################################################### filling rttab with tables from config# only new tables are created with a new uniq number that is not important because# usually we handle tables just by their names# this routine acts only when a new iGW appears - only adding a table is supported# no deleting is implemented because it seems to be not necessary to delete an old table# because there is space enough and after reboot table will not be createds_mktables(){if [ $scm_info -gt 0 ]; then echo "Checking tables" ; fiif [ $scm_info -gt 0 ]; then echo "Creating tables" ; fisl_igws=`$sl_catcmd $sl_sedlocache/$sl_nmcnf | $sl_grepcmd -E "^igw|^myigw" | $sl_awkcmd '{print $3}'`for sl_igw in $sl_igwsdosl_igwrttb=`$sl_catcmd $sl_rttab | $sl_awkcmd '{print $2}' | $sl_grepcmd $sl_igw `if [ "$sl_igwrttb x" = " x" ]thenif [ $scm_info -gt 1 ]; then echo "Creating table for $sl_igw" ; fisl_cnt="$sl_rtnmax"sl_ok="no"until [ "$sl_cnt" -eq "$sl_rtnmin" ] || [ "$sl_ok" = "yes" ]do#space is used to recognized two and three digit numberssl_igwrttb=`cat $sl_rttab | awk '{print $1" "}' | grep "$sl_cnt " `if [ "$sl_igwrttb x" = " x" ]thensl_ok="yes"echo "$sl_cnt $sl_igw" >> $sl_rttabfisl_cnt=$(($sl_cnt - 1 ))doneelseif [ $scm_info -gt 1 ]; then echo "Table found for $sl_igw no action taken" ; fifidone} # s_mktables######################################################################s_getcfg(){if [ $scm_info -gt 0 ]; then echo "Getting config" ; fiif [ $scm_info -gt 1 ]; then echo "Using main config $sl_murlcfg" ; fiif [ $scm_info -gt 1 ]; then echo "Using local config $sl_sedlocnf" ; firm -f "$sl_sedlocache/$sl_nmcnf.main.tmp"$sl_wgetcmd -q -t 3 $sl_murlcfg -O "$sl_sedlocache/$sl_nmcnf.main.tmp"if [ -s $sl_sedlocache/$sl_nmcnf.main.tmp ]thendate > $sl_sedlocache/last_getcnf.txtcp $sl_sedlocache/$sl_nmcnf.main.tmp $sl_sedlocache/$sl_nmcnf.mainif [ $scm_info -gt 1 ]; then echo "Main config downloaded and accepted" ; fielseif [ $scm_info -gt 1 ]; then echo "Main config not downloaded - cached config will be used" ; fiecho -n "Main config not downloaded " > $sl_sedlocache/last_getcnf.txtdate >> $sl_sedlocache/last_getcnf.txtfi# before generating a new cached config we store the old one for# comparison with the new onerm -f "$sl_sedlocache/$sl_nmcnf.old"if [ -s $sl_sedlocache/$sl_nmcnf ]thencp $sl_sedlocache/$sl_nmcnf $sl_sedlocache/$sl_nmcnf.oldelsetouch $sl_sedlocache/$sl_nmcnf.oldfi# preparing cached config from local and main# the local config should be processed as the second to have# higher priority for rules from local configecho "# generated file" > $sl_sedlocache/$sl_nmcnffor sl_file in `ls $sl_sedlocache/$sl_nmcnf.main ; ls $sl_sedlocnf`docat $sl_file | grep "^mcnf" | $sl_trcmd ';' '#' | awk '{print $1"\t"$2}' >> $sl_sedlocache/$sl_nmcnfcat $sl_file | grep "^igw" | $sl_trcmd ';' '#' | awk '{print $1"\t"$2"\t"$3}' >> $sl_sedlocache/$sl_nmcnfcat $sl_file | grep "^ip" | $sl_trcmd ';' '#' | awk '{print $1"\t"$2"\t"$3"\t"$4"\t"$5"\t"$6}' >> $sl_sedlocache/$sl_nmcnfdone#local gateways taken from local configcat $sl_sedlocnf | grep "^myigw" | $sl_trcmd ';' '#' | awk '{print $1"\t"$2"\t"$3}' >> $sl_sedlocache/$sl_nmcnf#cat $sl_sedlocache/$sl_nmcnf | sort | uniq > $sl_sedlocache/$sl_nmcnf.uniq#mv $sl_sedlocache/$sl_nmcnf.uniq $sl_sedlocache/$sl_nmcnfsl_diffcfg=`diff $sl_sedlocache/$sl_nmcnf $sl_sedlocache/$sl_nmcnf.old | grep -c .`if [ $sl_diffcfg -gt 0 ]thenif [ $scm_info -gt 0 ]; then echo "New config is different than the old one" ; fielseif [ $scm_info -gt 0 ]; then echo "New config is the same as the old one" ; fifi# to detect first start after reboot or rule flushig we compare config with rule number# when we have less rules than ips in config thensl_numru=`ip ru ls | grep -c lookup`sl_numip=`grep -c ^ip $sl_sedlocache/$sl_nmcnf`sl_numru=$(($sl_numru - 3 ))if [ $sl_numip -gt $sl_numru ]thenif [ $scm_info -gt 0 ]; then echo "We have less rules ($sl_numru) than new config has ips ($sl_numip)" ; fisl_diffcfg="1"elseif [ $scm_info -gt 0 ]; then echo "We have $sl_numru rules and $sl_numip ips" ; fifi}######################################################################s_version(){echo sedlo $sl_version} # s_version######################################################################s_report(){echo Content-type: text/htmlechoecho "Sedlo na routeru `hostname`"echo "<pre>"echo "##### SEDLO #####"echo "date : `date`"echo "version : $sl_version"echo "local_config : $sl_sedlocnf"echo "main_config : <a href=\"$sl_murlcfg\">$sl_murlcfg</a>"echo "last update : `cat $sl_sedlocache/last_getcnf.txt`"echo "##### TABLES #####"cat $sl_rttabecho ; echo "##### DEFAULT ROUTES IN TABLES #####"$sl_ipcmd ro ls ta all | $sl_grepcmd table | $sl_grepcmd -v local | $sl_trcmd " " "\t"echo ; echo "##### RULES FOR IPS #####"$sl_ipcmd ru ls | $sl_trcmd " " "\t"echo "</pre>"} # s_report######################################################################s_help(){echo Pouziti: sedlo [param]echo param:echo -V vypise verziecho -help vypise napoveduecho -v malo upovidanyecho -vv hodne upovidanyecho -nogetcfg zajisti ze se nedude znovu nacitat konfigurace a pouzije se predchozi z cacheecho -report vypise prehled pravidel a tabulekecho -flru odstrani vsechny pravidla} # s_help############################################################################################################################################sl_unknown=""scm_nogetcfg=0scm_flru=0scm_info=0# parsing input parameterswhile [ "a$1" != "a" ]docase $1 in-V)s_versionexit 0;;-h)s_helpexit 0;;-report)s_reportexit 0;;-flru)scm_flru=1shift;;-help)s_helpexit 0;;-nogetcfg)scm_nogetcfg=1shift;;-v)scm_info=1shift;;-vv)scm_info=2shift;;*)sl_unknown="$sl_unknown$1 "shiftesacdone# printing the list of bad parameters (if there are some)if [ "a$sl_unknown" != "a" ]thenecho "$slm_unknown $sl_unknown"s_helpexit 0fiif [ $scm_flru -eq 1 ]thens_flruexit 0fiif [ $scm_nogetcfg -eq 0 ]thens_getcfgfis_mktabless_filltablesif [ $sl_diffcfg -gt 0 ]thens_fillrulesfiexit 0