Project

General

Profile

Download (6.26 KB) Statistics
| Branch: | Tag: | Revision:
1
#!/usr/local/bin/php -f
2
<?php
3
/*
4
	rc.newwanip
5
	Copyright (C) 2006 Scott Ullrich (sullrich@gmail.com)
6
	part of pfSense (http://www.pfsense.com)
7

    
8
	Originally part of m0n0wall (http://m0n0.ch)
9
	Copyright (C) 2003-2005 Manuel Kasper <mk@neon1.net>.
10
	All rights reserved.
11

    
12
	Redistribution and use in source and binary forms, with or without
13
	modification, are permitted provided that the following conditions are met:
14

    
15
	1. Redistributions of source code must retain the above copyright notice,
16
	this list of conditions and the following disclaimer.
17

    
18
	2. Redistributions in binary form must reproduce the above copyright
19
	notice, this list of conditions and the following disclaimer in the
20
	documentation and/or other materials provided with the distribution.
21

    
22
	THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES,
23
	INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY
24
	AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
25
	AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY,
26
	OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
27
	SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
28
	INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
29
	CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
30
	ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
31
	POSSIBILITY OF SUCH DAMAGE.
32
*/
33

    
34
/* parse the configuration and include all functions used below */
35
require_once("globals.inc");
36
require_once("config.inc");
37
require_once("functions.inc");
38
require_once("filter.inc");
39
require_once("shaper.inc");
40
require_once("ipsec.inc");
41
require_once("vpn.inc");
42
require_once("openvpn.inc");
43
require_once("rrd.inc");
44

    
45
// Do not process while booting
46
if($g['booting'])
47
	exit;
48

    
49
function restart_packages() {
50
	global $oldip, $curwanip, $g;
51

    
52
	/* restart packages */
53
	system_ntp_configure(false);
54
	mwexec_bg("/usr/local/sbin/ntpdate_sync_once.sh", true);
55
	log_error("{$g['product_name']} package system has detected an ip change $oldip ->  $curwanip ... Restarting packages.");
56
	send_event("service reload packages");
57
}
58

    
59
/* Interface IP address has changed */
60
$argument = str_replace("\n", "", $argv[1]);
61

    
62
log_error("rc.newwanip: Informational is starting {$argument}.");
63

    
64
if(empty($argument)) {
65
	$curwanip = get_interface_ip();
66
	$interface = "wan";
67
	$interface_real = get_real_interface();
68
} else {
69
	$interface = convert_real_interface_to_friendly_interface_name($argument);
70
	$interface_real = $argument;
71
	$curwanip = find_interface_ip($interface_real, true);
72
	if($curwanip == "")
73
		$curwanip = get_interface_ip($interface);
74
}
75

    
76
log_error("rc.newwanip: on (IP address: {$curwanip}) (interface: {$interface}) (real interface: {$interface_real}).");
77

    
78
if($curwanip == "0.0.0.0" || !is_ipaddr($curwanip)) {
79
	log_error("rc.newwanip: Failed to update {$interface} IP, restarting...");
80
	send_event("interface reconfigure {$interface}");
81
	exit;
82
}
83

    
84
if (empty($interface)) {
85
	filter_configure();
86
	restart_packages();
87
	exit;
88
}
89

    
90
$oldip = "0.0.0.0";
91
if (file_exists("{$g['vardb_path']}/{$interface}_cacheip"))
92
	$oldip = file_get_contents("{$g['vardb_path']}/{$interface}_cacheip");
93

    
94
/* regenerate resolv.conf if DNS overrides are allowed */
95
system_resolvconf_generate(true);
96

    
97
/* write current WAN IP to file */
98
file_put_contents("{$g['vardb_path']}/{$interface}_ip", $curwanip);
99

    
100
link_interface_to_vips($interface, "update");
101

    
102
unset($gre);
103
$gre = link_interface_to_gre($interface);
104
if (!empty($gre))
105
	array_walk($gre, 'interface_gre_configure');
106
unset($gif);
107
$gif = link_interface_to_gif($interface);
108
if (!empty($gif))
109
	array_walk($gif, 'interface_gif_configure');
110

    
111
$grouptmp = link_interface_to_group($interface);
112
if (!empty($grouptmp))
113
	array_walk($grouptmp, 'interface_group_add_member');
114

    
115
if ($linkupevent == false || substr($interface_real, 0, 4) == "ovpn") {
116
	unset($bridgetmp);
117
	$bridgetmp = link_interface_to_bridge($interface);
118
	if (!empty($bridgetmp))
119
		interface_bridge_add_member($bridgetmp, $interface_real);
120
}
121

    
122
/* make new hosts file */
123
if ($interface == "lan")
124
	system_hosts_generate();
125

    
126
/* check tunneled IPv6 interface tracking */
127
switch($config['interfaces'][$interface]['ipaddrv6']) {
128
	case "slaac":
129
	case "dhcp6":
130
		interface_dhcpv6_configure($interface, $config['interfaces'][$interface]);
131
		break;
132
	case "6to4":
133
		interface_6to4_configure($interface, $config['interfaces'][$interface]);
134
		break;
135
	case "6rd":
136
		interface_6rd_configure($interface, $config['interfaces'][$interface]);
137
		break;
138
}
139

    
140
/* Check Gif tunnels */
141
if(is_array($config['gifs']['gif'])){
142
	foreach($config['gifs']['gif'] as $gif) {
143
		if($gif['if'] == $interface) {
144
			foreach($config['interfaces'] as $ifname => $ifparent) {
145
				// echo "interface $ifparent, ifname $ifname, gif {$gif['gifif']}\n";
146
				if(($ifparent['if'] == $gif['gifif']) && (isset($ifparent['enable']))) {
147
					// echo "Running routing configure for $ifname\n";
148
					$gif['gifif'] = interface_gif_configure($gif);
149
					$confif = convert_real_interface_to_friendly_interface_name($gif['gifif']);
150
					if ($confif <> "")
151
						interface_configure($confif);
152
					system_routing_configure($ifname);
153
				}
154
			}
155
		}
156
	}
157
}
158

    
159
/*
160
 * We need to force sync VPNs on such even when the IP is the same for dynamic interfaces.
161
 * Even with the same IP the VPN software is unhappy with the IP disappearing, and we
162
 * could be failing back in which case we need to switch IPs back anyhow.
163
 */
164
if (!is_ipaddr($oldip) || $curwanip != $oldip || !is_ipaddrv4($config['interfaces'][$interface]['ipaddr'])) {
165
	/* reconfigure static routes (kernel may have deleted them) */
166
	system_routing_configure($interface);
167

    
168
	/* reconfigure our gateway monitor */
169
	setup_gateways_monitor();
170

    
171
	file_put_contents("{$g['vardb_path']}/{$interface}_cacheip", $curwanip);
172

    
173
	/* perform RFC 2136 DNS update */
174
	services_dnsupdate_process($interface);
175

    
176
	/* signal dyndns update */
177
	services_dyndns_configure($interface);
178

    
179
	/* reconfigure IPsec tunnels */
180
	vpn_ipsec_force_reload($interface);
181

    
182
	/* start OpenVPN server & clients */
183
	if (substr($interface_real, 0, 4) != "ovpn")
184
		openvpn_resync_all($interface);
185

    
186
	/* reload graphing functions */
187
	enable_rrd_graphing();
188

    
189
	/* reload igmpproxy */
190
	services_igmpproxy_configure();
191

    
192
	/* restart snmp */
193
	services_snmpd_configure();
194

    
195
	restart_packages();
196
}
197

    
198
/* signal filter reload */
199
filter_configure();
200

    
201
?>
(78-78/109)