mirror of
https://github.com/vincentmli/bpfire.git
synced 2026-04-27 03:07:43 +02:00
This bridge mode is supposed to be used for virtual environments to create a network zone as a bridge and have virtual machines inside it. Other physical interfaces can also be added to the bridge. This is very similar to the MACVTAP bridge feature but still works when the link of any (or all) physical interfaces is down. Fixes: #11252 Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org> Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
97 lines
3.0 KiB
Bash
97 lines
3.0 KiB
Bash
#!/bin/bash
|
|
###############################################################################
|
|
# #
|
|
# IPFire.org - A linux based firewall #
|
|
# Copyright (C) 2015 IPFire Team <info@ipfire.org> #
|
|
# #
|
|
# This program is free software: you can redistribute it and/or modify #
|
|
# it under the terms of the GNU General Public License as published by #
|
|
# the Free Software Foundation, either version 3 of the License, or #
|
|
# (at your option) any later version. #
|
|
# #
|
|
# This program is distributed in the hope that it will be useful, #
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of #
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
|
|
# GNU General Public License for more details. #
|
|
# #
|
|
# You should have received a copy of the GNU General Public License #
|
|
# along with this program. If not, see <http://www.gnu.org/licenses/>. #
|
|
# #
|
|
###############################################################################
|
|
|
|
# Check if all appropriate variables are set
|
|
[ -n "${INTERFACE}" ] || exit 2
|
|
|
|
# Ignore virtual interfaces, etc.
|
|
case "${INTERFACE}" in
|
|
lo)
|
|
exit 0
|
|
;;
|
|
tun*)
|
|
exit 0
|
|
;;
|
|
ppp*)
|
|
exit 0
|
|
;;
|
|
esac
|
|
|
|
# Check if INTERFACE actually exists
|
|
[ -d "/sys/class/net/${INTERFACE}" ] || exit 1
|
|
|
|
# If the network configuration is not readable,
|
|
# we cannot go on.
|
|
if [ ! -r "/var/ipfire/ethernet/settings" ]; then
|
|
exit 1
|
|
fi
|
|
|
|
# Read network settings
|
|
eval $(/usr/local/bin/readhash /var/ipfire/ethernet/settings)
|
|
|
|
# Standard zones
|
|
ZONES="RED GREEN ORANGE BLUE"
|
|
|
|
# Determine the address of INTERFACE
|
|
ADDRESS="$(</sys/class/net/${INTERFACE}/address)"
|
|
|
|
# Walk through all zones and find the matching interface
|
|
for zone in ${ZONES}; do
|
|
address="${zone}_MACADDR"
|
|
device="${zone}_DEV"
|
|
mode="${zone}_MODE"
|
|
|
|
# Skip if address or device is unset
|
|
[ -n "${!address}" -a -n "${!device}" ] || continue
|
|
|
|
# Compare MAC addresses
|
|
[ "${ADDRESS}" = "${!address}" ] || continue
|
|
|
|
# If a matching interface has been found we will
|
|
# print the name to which udev will rename it.
|
|
case "${!mode}" in
|
|
bridge)
|
|
echo "${!device}phys"
|
|
;;
|
|
|
|
macvtap)
|
|
# MACVTAP mode doesn't work for WiFi devices
|
|
if [ -d "/sys/class/net/${INTERFACE}/phy80211" ]; then
|
|
logger -t network "MACVTAP mode is not supported for wireless devices"
|
|
echo "${!device}"
|
|
else
|
|
echo "${!device}phys"
|
|
fi
|
|
;;
|
|
|
|
*)
|
|
echo "${!device}"
|
|
;;
|
|
esac
|
|
|
|
exit 0
|
|
done
|
|
|
|
# If we get here we have not found a matching device,
|
|
# but we won't return an error any way. The new device
|
|
# will remain with the previous name.
|
|
exit 0
|