-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathcloud-nic.sh
92 lines (82 loc) · 2.99 KB
/
cloud-nic.sh
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
#!/usr/bin/env bash
# Licensed to the Apache Software Foundation (ASF) under one
# or more contributor license agreements. See the NOTICE file
# distributed with this work for additional information
# regarding copyright ownership. The ASF licenses this file
# to you under the Apache License, Version 2.0 (the
# "License"); you may not use this file except in compliance
# with the License. You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing,
# software distributed under the License is distributed on an
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
# KIND, either express or implied. See the License for the
# specific language governing permissions and limitations
# under the License.
plug_nic() {
sudo echo "$tableNo $tableName" >> /etc/iproute2/rt_tables 2>/dev/null
sudo ip rule add fwmark $tableNo table $tableName 2>/dev/null
sudo ip route flush table $tableName
sudo ip route flush cache
# sudo -E sed -i "s/^.*$dev.*$//" /etc/udev/rules.d/70-persistent-net.rules
# export INTERFACE=$dev
# export MATCHADDR=`ip addr show $INTERFACE | grep ether | awk '{print $2}'`
# sudo -E /lib/udev/write_net_rules >> /tmp/cloud-nic.log
}
unplug_nic() {
# date >> /temp/cloud-nic.log
# uptime >> /temp/cloud-nic.log
# echo "unplugging $dev" >> /temp/cloud-nic.log
sudo iptables -t mangle -D PREROUTING -i $dev -m state --state NEW -j CONNMARK --set-mark $tableNo 2>/dev/null
sudo ip rule del fwmark $tableNo 2>/dev/null
sudo ip route flush table $tableName
sudo sed -i /"$tableNo $tableName"/d /etc/iproute2/rt_tables 2>/dev/null
sudo ip route flush cache
# remove network usage rules
sudo iptables -F NETWORK_STATS_$dev 2>/dev/null
iptables-save | grep NETWORK_STATS_$dev | grep "\-A" | while read rule
do
rule=$(echo $rule | sed 's/\-A/\-D/')
sudo iptables $rule
done
sudo iptables -X NETWORK_STATS_$dev 2>/dev/null
# remove vpn network usage rules
sudo iptables -t mangle -F VPN_STATS_$dev 2>/dev/null
iptables-save -t mangle | grep VPN_STATS_$dev | grep "\-A" | while read rule
do
rule=$(echo $rule | sed 's/\-A/\-D/')
sudo iptables -t mangle $rule
done
sudo iptables -t mangle -X VPN_STATS_$dev 2>/dev/null
# remove rules on this dev
iptables-save -t mangle | grep $dev | grep "\-A" | while read rule
do
rule=$(echo $rule | sed 's/\-A/\-D/')
sudo iptables -t mangle $rule
done
iptables-save -t nat | grep $dev | grep "\-A" | while read rule
do
rule=$(echo $rule | sed 's/\-A/\-D/')
sudo iptables -t nat $rule
done
iptables-save | grep $dev | grep "\-A" | while read rule
do
rule=$(echo $rule | sed 's/\-A/\-D/')
sudo iptables $rule
done
# remove apache config for this eth
rm -f /etc/apache2/conf.d/vhost$dev.conf
sudo -E sed -i "s/^.*$dev.*$//" /etc/udev/rules.d/70-persistent-net.rules
}
action=$1
dev=$2
tableNo=${dev:3}
tableName="Table_$dev"
if [ $action == 'add' ]
then
plug_nic
else
unplug_nic
fi