2011-08-22 18:05:40 +02:00
|
|
|
#!/bin/sh
|
|
|
|
#
|
|
|
|
# Shorewall init script
|
|
|
|
#
|
|
|
|
# chkconfig: - 28 90
|
|
|
|
# description: Packet filtering firewall
|
|
|
|
|
|
|
|
### BEGIN INIT INFO
|
|
|
|
# Provides: shorewall6
|
|
|
|
# Required-Start: $local_fs $remote_fs $syslog $network
|
|
|
|
# Should-Start: VMware $time $named
|
|
|
|
# Required-Stop:
|
|
|
|
# Default-Start:
|
|
|
|
# Default-Stop: 0 1 2 3 4 5 6
|
|
|
|
# Short-Description: Packet filtering firewall
|
|
|
|
# Description: The Shoreline Firewall, more commonly known as "Shorewall", is a
|
|
|
|
# Netfilter (iptables) based firewall
|
|
|
|
### END INIT INFO
|
|
|
|
|
|
|
|
# Source function library.
|
|
|
|
. /etc/rc.d/init.d/functions
|
|
|
|
|
2012-03-31 01:21:37 +02:00
|
|
|
#
|
|
|
|
# The installer may alter this
|
|
|
|
#
|
|
|
|
. /usr/share/shorewall/shorewallrc
|
|
|
|
|
2016-11-21 19:00:55 +01:00
|
|
|
prog="shorewall -6"
|
2012-03-26 16:20:31 +02:00
|
|
|
shorewall="${SBINDIR}/$prog"
|
2011-08-22 18:05:40 +02:00
|
|
|
logger="logger -i -t $prog"
|
|
|
|
lockfile="/var/lock/subsys/$prog"
|
|
|
|
|
|
|
|
# Get startup options (override default)
|
|
|
|
OPTIONS=
|
|
|
|
|
2012-03-26 16:20:31 +02:00
|
|
|
if [ -f ${SYSCONFDIR}/$prog ]; then
|
|
|
|
. ${SYSCONFDIR}/$prog
|
2011-08-22 18:05:40 +02:00
|
|
|
fi
|
|
|
|
|
|
|
|
start() {
|
|
|
|
echo -n $"Starting Shorewall: "
|
2014-10-30 18:22:39 +01:00
|
|
|
$shorewall $OPTIONS start $STARTOPTIONS 2>&1 | $logger
|
2011-08-22 18:05:40 +02:00
|
|
|
retval=${PIPESTATUS[0]}
|
2012-04-24 23:52:57 +02:00
|
|
|
if [[ $retval == 0 ]]; then
|
2011-08-22 18:05:40 +02:00
|
|
|
touch $lockfile
|
|
|
|
success
|
2012-04-24 23:52:57 +02:00
|
|
|
else
|
2011-08-22 18:05:40 +02:00
|
|
|
failure
|
|
|
|
fi
|
|
|
|
echo
|
|
|
|
return $retval
|
|
|
|
}
|
|
|
|
|
|
|
|
stop() {
|
|
|
|
echo -n $"Stopping Shorewall: "
|
|
|
|
$shorewall $OPTIONS stop 2>&1 | $logger
|
|
|
|
retval=${PIPESTATUS[0]}
|
2012-04-24 23:52:57 +02:00
|
|
|
if [[ $retval == 0 ]]; then
|
2011-08-22 18:05:40 +02:00
|
|
|
rm -f $lockfile
|
|
|
|
success
|
2012-04-24 23:52:57 +02:00
|
|
|
else
|
2011-08-22 18:05:40 +02:00
|
|
|
failure
|
|
|
|
fi
|
|
|
|
echo
|
|
|
|
return $retval
|
|
|
|
}
|
|
|
|
|
|
|
|
restart() {
|
|
|
|
# Note that we don't simply stop and start since shorewall has a built in
|
|
|
|
# restart which stops the firewall if running and then starts it.
|
|
|
|
echo -n $"Restarting Shorewall: "
|
2014-10-30 18:22:39 +01:00
|
|
|
$shorewall $OPTIONS restart $RESTARTOPTIONS 2>&1 | $logger
|
2011-08-22 18:05:40 +02:00
|
|
|
retval=${PIPESTATUS[0]}
|
2012-04-24 23:52:57 +02:00
|
|
|
if [[ $retval == 0 ]]; then
|
2011-08-22 18:05:40 +02:00
|
|
|
touch $lockfile
|
|
|
|
success
|
|
|
|
else # Failed to start, clean up lock file if present
|
|
|
|
rm -f $lockfile
|
|
|
|
failure
|
|
|
|
fi
|
|
|
|
echo
|
|
|
|
return $retval
|
|
|
|
}
|
|
|
|
|
|
|
|
status(){
|
|
|
|
$shorewall status
|
|
|
|
return $?
|
|
|
|
}
|
|
|
|
|
|
|
|
status_q() {
|
|
|
|
status > /dev/null 2>&1
|
|
|
|
}
|
|
|
|
|
|
|
|
case "$1" in
|
|
|
|
start)
|
|
|
|
status_q && exit 0
|
|
|
|
$1
|
|
|
|
;;
|
|
|
|
stop)
|
|
|
|
status_q || exit 0
|
|
|
|
$1
|
|
|
|
;;
|
|
|
|
restart|reload|force-reload)
|
|
|
|
restart
|
|
|
|
;;
|
|
|
|
condrestart|try-restart)
|
|
|
|
status_q || exit 0
|
|
|
|
restart
|
|
|
|
;;
|
|
|
|
status)
|
|
|
|
$1
|
|
|
|
;;
|
|
|
|
*)
|
|
|
|
echo "Usage: $0 start|stop|reload|restart|force-reload|status"
|
|
|
|
exit 1
|
|
|
|
;;
|
|
|
|
esac
|