|
From: Steve R. <Ste...@sa...> - 2010-05-04 18:04:41
|
Hi,
I have just submitted a mantis-patch for "/etc/init.d/network" that calls nameif to name network interfaces based on MAC addresses. The call is only made if the required "/etc/mactab" file exists and is readable. Nameif is called on a per-interface basis after the module has been modprob'ed into place.
Please note that the version of "/etc/init.d/network" that was used as a starting point was "# $Revision: 1.44 $" which is has been patched for interface aliases and has a higher revision number than version 1.43 that ships with DL-1.4-RC3.
There are two distinct but linked patches contained in the one file. They could be separated quite easily, if required.
The first patch that calls nameif/mactab is:
@@ -162,8 +163,18 @@
if [ "$MODULE" != "UNKNOWN" ] && [ "$MODULE" != "autoselect" ] ; then
modprobe $MODULE $MODULE_OPTS > /dev/null
fi
fi
+ # Using /etc/mactab (may have been created from /etc/mactable.conf
+ # Process IF for active Media Access Control (Ethernet MAC) Address.
+ # Only process interfaces which DON'T have a :-_. (Colon/dash/underscore/dot) in them.
+ #
+ if [ -r /etc/mactab ]; then
+ if [ `expr index "$IF" ":-_."` == 0 ]; then
+ UseIFMac=`/bin/grep --ignore-case "^$IF" /etc/mactab`
+ /sbin/nameif -s $UseIFMac
+ fi
+ fi
if [ "$WIRELESS" = "yes" ]; then
setup_wireless $DEVICE
The format for the optional configuration file "/etc/mactab" may be taken from my proposed "/etc/mactab.sample":
#--- /etc/mactab.sample
#
# Example format for /etc/mactab.
# Used by nameif to name network interfaces based on MAC addresses
#
eth0 00:40:f4:b8:db:2f
eth1 00:40:f4:b8:db:2e
eth2 00:40:f4:b8:db:2d
#
#--- End
I believe this implements standard functionality to control network interfaces names based on MAC addresses.
If implemented, this would prevent udev shuffling interface names across a system reboot.
The second part of the patch introduces new functionality with the specific aim to allow a single DL-etc-mods.tar.bz2 config to be moved onto a cold-standby unit, and automatically receive the correct (preconfigured) interface assignments.
The patch is a follows:
@@ -376,8 +387,16 @@
# if vlan tools are installed set vlan naming shema
#
test -x $VLAN && $VLAN set_name_type VLAN_PLUS_VID_NO_PAD &> /dev/null
+ # if /etc/mactable.conf is readable then
+ # extract lines for each available MAC Address we have
+ # and create/overwrite /etc/mactab
+ if [ -r /etc/mactable.conf ]; then
+ MacList=`/sbin/ip addr show | /bin/grep "link/ether" | /bin/sed "s#.*link\/ether \| brd #\|#ig" | /usr/bin/cut -f2 -d'|'`
+ /bin/grep -F "$MacList" /etc/mactable.conf | /usr/bin/cut -f-2 -d'|' | /bin/sed "s#|# #" >/etc/mactab
+ fi
+
#
# physical interfaces are brought up first
#
for interface in $(cd ${CONFIG_DIR}; ls -1 ${CONFIG_FILE}* 2>/dev/null | sed \
The key here is the use of a new "/etc/mactable.conf " config file which is preconfigured with interface and MAC details for both the production and the standby hardware.
Again, the format for the optional configuration file "/etc/mactable.conf" may be taken from my proposed "/etc/mactable.conf.sample":
#--- /etc/mactable.conf.sample
#
# Interface name | MAC Address | Comment
#
eth0|00:40:f4:b8:db:2f| Gannet01 (Production fw) lan1
eth1|00:40:f4:b8:db:2e| Gannet01 (Production fw) lan2
eth2|00:40:f4:b8:db:2d| Gannet01 (Production fw) lan3
#
eth0|00:30:18:49:5f:08| Gannet02 (Cold Standby fw) lan1
eth1|00:30:18:49:5f:07| Gannet02 (Cold Standby fw) lan2
eth2|00:30:18:49:5f:06| Gannet02 (Cold Standby fw) lan3
#
eth0|00:11:85:10:be:f9| Hippopotamus (Development/testbed) eth0
eth1|00:10:5a:28:51:36| Hippopotamus (Development/testbed) eth1
eth2|00:50:04:3a:aa:5b| Hippopotamus (Development/testbed) eth2
#
#--- End
Here three systems have their interface and mac details catalogued. When the patched "/etc/init.d/network" file is run, it extracts mac-addresses from "/etc/mactable.conf " that match the physically identified interfaces, and repopulates "/etc/mactab" ready for nameif to use, but containing only details appropriate for (in the sample) "Gannet01", "Gannet02", or "Hippopotamus".
If the first "/etc/mactab" patch is rejected, then the second "/etc/mactable.conf" automatically falls, as it depends on nameif being run against the newly created " /etc/mactab" file.
This will, I believe, give Stefan [ma...@en...] the ability to have a replacement firewall on cold-standby.
Much of the above code must be credited to my colleague Roy Barnard.
Regards - Steve.
Stephen H F Ralph
Principal Computer Officer | Integration Team | ICT Services | Transform Sandwell
Sandwell MBC | Freeth Street | Oldbury | West Midlands | B69 3DE
Tel: 0121 569 3132 | Fax: 0121 569 3493
Email: ste...@sa...<mailto:ste...@sa...>
|