#!/bin/sh

### BEGIN INIT INFO
# Provides:          openstack-proxy-node-nat
# Required-Start:    $network
# Required-Stop:     $network
# Should-Start:      $local_fs
# Should-Stop:       $local_fs
# Default-Start:     2 3 4 5
# Default-Stop:      0 1 6
# Short-Description: A small script to initialise iptables to allow forwarding and masquerading.
# Description:       A small script to initialise iptables to allow forwarding and masquerading.
### END INIT INFO

MODPROBE=/sbin/modprobe
IPTABLES=/sbin/iptables
EXTIF=`awk '{ if ( $2 == "00000000" ) print $1 }' /proc/net/route | head -n 1`
MGMT_IF=tempestbr
MGMT_NET_CIDR=192.168.100.1/24
OTCI_PXE_SERVER_IP=192.168.100.1
OTCI_PXE_NETMASK=255.255.255.0
PXE_NIC_NAME=tempestnic0
PXE_VM_VIRTAP_NAME=tempesttap
PXE_VM_NIC_USER=root

. /lib/lsb/init-functions

case "$1" in
start|systemd-start)
	echo 1 >/proc/sys/net/ipv4/ip_forward

	$MODPROBE ip_tables
	$MODPROBE ip_conntrack
	$MODPROBE iptable_nat
	$MODPROBE ip_nat_ftp

	$MODPROBE dummy
	ip link set name ${PXE_NIC_NAME} dev dummy0 || true
	ifconfig ${PXE_NIC_NAME} hw ether 00:22:22:ff:ff:ff

	# Create a bridge and bridge that interface to it
	ip tuntap add dev ${PXE_VM_VIRTAP_NAME} mode tap user ${PXE_VM_NIC_USER} || true
	brctl addbr tempestbr || true
	brctl addif tempestbr ${PXE_NIC_NAME} || true
	brctl addif tempestbr ${PXE_VM_VIRTAP_NAME} || true
	ifconfig tempestbr ${OTCI_PXE_SERVER_IP} netmask ${OTCI_PXE_NETMASK} up
	ip link set tempestbr up
	ip link set ${PXE_NIC_NAME} up
	ip link set ${PXE_VM_VIRTAP_NAME} up

	# Allow all connections OUT and only existing and related ones IN
	$IPTABLES -I FORWARD -i ${EXTIF} -o ${MGMT_IF} -m state --state ESTABLISHED,RELATED -j ACCEPT
	$IPTABLES -I FORWARD -i ${MGMT_IF} -s ${MGMT_NET_CIDR} -o ${EXTIF} -j ACCEPT

	#$IPTABLES -t nat -A POSTROUTING -o $EXTIF -j MASQUERADE
	$IPTABLES -t nat -I POSTROUTING -s ${MGMT_NET_CIDR} -o ${EXTIF} -j MASQUERADE
;;
stop)
	brctl delif tempestbr ${PXE_NIC_NAME} || true
	brctl delif tempestbr ${PXE_VM_VIRTAP_NAME} || true
	brctl delbr tempestbr || true
	ip link delete ${PXE_VM_VIRTAP_NAME} || true
;;
restart|reload|force-reload)
	$0 stop
	sleep 1
	$0 start
;;
*)
	echo 'Usage: $0 {start|stop|restart|reload}'
	exit 1
;;
esac
