Skip to content

策略路由 ​

策略路由的组件名称为 policy_routing, 相关内核选项为

ini
# Networking support
# -> Networking options
# -> TCP/IP networking
# -> IP: advanced router
CONFIG_IP_ADVANCED_ROUTER=y

# Networking support
# -> Networking options
# -> TCP/IP networking
# -> IP: advanced router
# -> IP: policy routing
CONFIG_IP_MULTIPLE_TABLES=y

# Networking support
# -> Networking options
# -> TCP/IP networking
# -> The IPv6 protocol
# -> IPv6: Multiple Routing Tables
CONFIG_IPV6_MULTIPLE_TABLES=y

检查工具为

bash
#!/bin/bash

source ./cmd_utils.sh
source ./kernel_config_utils.sh
source ./net_utils.sh

policy_routing_check_helper() {
    local rule=$@
    ${IP_CMD} rule add $rule
    local s=$(${IP_CMD} rule show $rule)
    ${IP_CMD} rule del $rule
    
    if [ "$s" != "" ]; then
        return 0
    else
        return 1
    fi
}
policy_routing_check() {
    is_error=false
    if ! kernel_config_check CONFIG_IP_ADVANCED_ROUTER; then
        is_error=true
    fi
    if ! kernel_config_check CONFIG_IP_MULTIPLE_TABLES; then
        is_error=true
    fi
    if ! kernel_config_check CONFIG_IPV6_MULTIPLE_TABLES; then
        is_error=true
    fi
    if [ "$is_error" == "true" ]; then
        return 1
    fi

    if ! policy_routing_check_helper from all lookup main pref 666; then
        return 1
    fi
    if ! policy_routing_check_helper from 192.168.0.1 lookup main pref 666; then
        return 1
    fi
    if ! policy_routing_check_helper from all iif lo lookup main pref 666; then
        return 1
    fi
    if ! policy_routing_check_helper from all fwmark 0x66 lookup main pref 666; then
        return 1
    fi
}