blob: 1733db281da6f3def1af598ee5d6389019a93b22 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
|
#!/bin/bash
# source application-specific settings
[ -f /etc/conf.d/iptables ] && . /etc/conf.d/iptables
# Set defaults if settings are missing
[ -z "$IP6TABLES" ] && IP6TABLES=/usr/sbin/ip6tables
[ -z "$IP6TABLES_CONF" ] && IP6TABLES_CONF=/etc/iptables/ip6tables.rules
. /etc/rc.conf
. /etc/rc.d/functions
case "$1" in
start)
if [ ! -f $IP6TABLES_CONF ]; then
echo "Cannot load iptables rules: $IP6TABLES_CONF is missing!" >&2
exit 1
fi
stat_busy "Starting IP6 Tables"
if [ "$IPTABLES_FORWARD" = "1" ]; then
echo 1 >/proc/sys/net/ipv6/conf/default/forwarding
echo 1 >/proc/sys/net/ipv6/conf/all/forwarding
fi
if ck_daemon ip6tables; then
/usr/sbin/ip6tables-restore < $IP6TABLES_CONF
if [ $? -gt 0 ]; then
stat_fail
else
add_daemon ip6tables
stat_done
fi
else
stat_fail
fi
;;
stop)
stat_busy "Stopping IP6 Tables"
echo 0 >/proc/sys/net/ipv6/conf/all/forwarding
echo 0 >/proc/sys/net/ipv6/conf/default/forwarding
if ! ck_daemon ip6tables; then
fail=0
for table in $(cat /proc/net/ip6_tables_names); do
$IP6TABLES -t $table -F &>/dev/null && \
$IP6TABLES -t $table -X &>/dev/null && \
$IP6TABLES -t $table -Z &>/dev/null
[ $? -gt 0 ] && fail=1
done
if [ $fail -gt 0 ]; then
stat_fail
else
rm_daemon ip6tables
# reset policies
for table in filter mangle raw; do
if grep -qw $table /proc/net/ip6_tables_names; then
$IP6TABLES -t $table -P OUTPUT ACCEPT
fi
done
for table in filter mangle; do
if grep -qw $table /proc/net/ip6_tables_names; then
$IP6TABLES -t $table -P INPUT ACCEPT
$IP6TABLES -t $table -P FORWARD ACCEPT
fi
done
for table in mangle raw; do
if grep -qw $table /proc/net/ip6_tables_names; then
$IP6TABLES -t $table -P PREROUTING ACCEPT
fi
done
for table in mangle; do
if grep -qw $table /proc/net/ip6_tables_names; then
$IP6TABLES -t $table -P POSTROUTING ACCEPT
fi
done
stat_done
fi
else
stat_fail
fi
;;
restart)
$0 stop
sleep 2
$0 start
;;
save)
stat_busy "Saving IP6 Tables"
/usr/sbin/ip6tables-save >$IP6TABLES_CONF
if [ $? -gt 0 ]; then
stat_fail
else
stat_done
fi
;;
*)
echo "usage: $0 {start|stop|restart|save}"
esac
exit 0
|