Browse code

Set sane defaults, get config info from localrc

Change-Id: If8f942723c5e796207f3caf15a65c8501cd63d83

Dean Troyer authored on 2011/11/30 08:39:51
Showing 1 changed files
... ...
@@ -11,24 +11,41 @@
11 11
 # --client mode creates a tarball of a client configuration for this server
12 12
 
13 13
 # Get config file
14
-if [ -e localrc.vpn ]; then
15
-    . localrc.vpn
14
+if [ -e localrc ]; then
15
+    . localrc
16 16
 fi
17
+if [ -e vpnrc ]; then
18
+    . vpnrc
19
+fi
20
+
21
+# Do some IP manipulation
22
+function cidr2netmask() {
23
+    set -- $(( 5 - ($1 / 8) )) 255 255 255 255 $(( (255 << (8 - ($1 % 8))) & 255 )) 0 0 0
24
+    if [[ $1 -gt 1 ]]; then
25
+        shift $1
26
+    else
27
+        shift
28
+    fi
29
+    echo ${1-0}.${2-0}.${3-0}.${4-0}
30
+}
31
+
32
+FIXED_NET=`echo $FIXED_RANGE | cut -d'/' -f1`
33
+FIXED_CIDR=`echo $FIXED_RANGE | cut -d'/' -f2`
34
+FIXED_MASK=`cidr2netmask $FIXED_CIDR`
17 35
 
18 36
 # VPN Config
19 37
 VPN_SERVER=${VPN_SERVER:-`ifconfig eth0 | awk "/inet addr:/ { print \$2 }" | cut -d: -f2`}  # 50.56.12.212
20 38
 VPN_PROTO=${VPN_PROTO:-tcp}
21 39
 VPN_PORT=${VPN_PORT:-6081}
22
-VPN_DEV=${VPN_DEV:-tun}
23
-VPN_BRIDGE=${VPN_BRIDGE:-br0}
24
-VPN_CLIENT_NET=${VPN_CLIENT_NET:-172.16.28.0}
25
-VPN_CLIENT_MASK=${VPN_CLIENT_MASK:-255.255.255.0}
26
-VPN_CLIENT_DHCP="${VPN_CLIENT_DHCP:-172.16.28.1 172.16.28.254}"
27
-VPN_LOCAL_NET=${VPN_LOCAL_NET:-10.0.0.0}
28
-VPN_LOCAL_MASK=${VPN_LOCAL_MASK:-255.255.0.0}
40
+VPN_DEV=${VPN_DEV:-tap0}
41
+VPN_BRIDGE=${VPN_BRIDGE:-br100}
42
+VPN_BRIDGE_IF=${VPN_BRIDGE_IF:-$FLAT_INTERFACE}
43
+VPN_CLIENT_NET=${VPN_CLIENT_NET:-$FIXED_NET}
44
+VPN_CLIENT_MASK=${VPN_CLIENT_MASK:-$FIXED_MASK}
45
+VPN_CLIENT_DHCP="${VPN_CLIENT_DHCP:-net.1 net.254}"
29 46
 
30 47
 VPN_DIR=/etc/openvpn
31
-CA_DIR=/etc/openvpn/easy-rsa
48
+CA_DIR=$VPN_DIR/easy-rsa
32 49
 
33 50
 usage() {
34 51
     echo "$0 - OpenVPN install and certificate generation"
... ...
@@ -54,7 +71,16 @@ if [ ! -d $CA_DIR ]; then
54 54
     cp -pR /usr/share/doc/openvpn/examples/easy-rsa/2.0/ $CA_DIR
55 55
 fi
56 56
 
57
-OPWD=`pwd`
57
+# Keep track of the current directory
58
+TOOLS_DIR=$(cd $(dirname "$0") && pwd)
59
+TOP_DIR=$(cd $TOOLS_DIR/.. && pwd)
60
+
61
+WEB_DIR=$TOP_DIR/../vpn
62
+if [[ ! -d $WEB_DIR ]]; then
63
+    mkdir -p $WEB_DIR
64
+fi
65
+WEB_DIR=$(cd $TOP_DIR/../vpn && pwd)
66
+
58 67
 cd $CA_DIR
59 68
 source ./vars
60 69
 
... ...
@@ -87,6 +113,10 @@ do_server() {
87 87
 BR="$VPN_BRIDGE"
88 88
 TAP="\$1"
89 89
 
90
+if [[ ! -d /sys/class/net/\$BR ]]; then
91
+    brctl addbr \$BR
92
+fi
93
+
90 94
 for t in \$TAP; do
91 95
     openvpn --mktun --dev \$t
92 96
     brctl addif \$BR \$t
... ...
@@ -117,10 +147,8 @@ key $NAME.key  # This file should be kept secret
117 117
 ca ca.crt
118 118
 dh dh1024.pem
119 119
 duplicate-cn
120
-#server $VPN_CLIENT_NET $VPN_CLIENT_MASK
121 120
 server-bridge $VPN_CLIENT_NET $VPN_CLIENT_MASK $VPN_CLIENT_DHCP
122 121
 ifconfig-pool-persist ipp.txt
123
-push "route $VPN_LOCAL_NET $VPN_LOCAL_MASK"
124 122
 comp-lzo
125 123
 user nobody
126 124
 group nogroup
... ...
@@ -163,9 +191,9 @@ persist-tun
163 163
 comp-lzo
164 164
 verb 3
165 165
 EOF
166
-    (cd $TMP_DIR; tar cf $OPWD/$NAME.tar *)
166
+    (cd $TMP_DIR; tar cf $WEB_DIR/$NAME.tar *)
167 167
     rm -rf $TMP_DIR
168
-    echo "Client certificate and configuration is in $OPWD/$NAME.tar"
168
+    echo "Client certificate and configuration is in $WEB_DIR/$NAME.tar"
169 169
 }
170 170
 
171 171
 # Process command line args