Rev 360 | Rev 376 | Go to most recent revision | Details | Compare with Previous | Last modification | View Log
Rev | Author | Line No. | Line |
---|---|---|---|
308 | richard | 1 | #!/bin/sh |
64 | franck | 2 | # $Id: alcasar-watchdog.sh 363 2010-12-06 23:05:27Z richard $ |
1 | root | 3 | # by rexy |
308 | richard | 4 | # Ce script prévient les usagers de l'indisponibilité de l'accès Internet |
5 | # il déconnecte les usagers dont |
||
1 | root | 6 | # - les équipementis réseau ne répondent plus |
7 | # - les adresses MAC sont usurpées |
||
308 | richard | 8 | # This script tells users that Internet access is down |
9 | # it logs out users whose |
||
1 | root | 10 | # - PCs are quiet |
11 | # - MAC address are in used by other systems (usurped) |
||
12 | |||
308 | richard | 13 | EXTIF="eth0" |
1 | root | 14 | INTIF="eth1" |
15 | PRIVATE_IP="192.168.182.1" |
||
16 | tmp_file="/tmp/watchdog.txt" |
||
316 | richard | 17 | DIR_WEB="/var/www/html" |
360 | richard | 18 | Index_Page="$DIR_WEB/index.php" |
1 | root | 19 | IFS=$'\n' |
308 | richard | 20 | |
21 | # Fonction appelée si un Pb de connectivité Internet |
||
22 | # On fait pointer les usagers sur une page d'erreur |
||
23 | function ext_down_alert () |
||
24 | { |
||
25 | case $EXT_DOWN in |
||
26 | "1") |
||
27 | logger "eth0 link down" |
||
363 | richard | 28 | /bin/sed -i "s?diagnostic =.*?diagnostic = \"eth0 link down\";?g" $Index_Page |
308 | richard | 29 | ;; |
30 | "2") |
||
31 | logger "can't contact the default router" |
||
363 | richard | 32 | /bin/sed -i "s?diagnostic =.*?diagnostic = \"can't contact the default router\";?g" $Index_Page |
308 | richard | 33 | ;; |
34 | "3") |
||
35 | logger "can't contact the Internet DNS" |
||
363 | richard | 36 | /bin/sed -i "s?diagnostic =.*?diagnostic = \"can't contact the Internet DNS\";?g" $Index_Page |
308 | richard | 37 | ;; |
38 | esac |
||
39 | net_pb=`cat /etc/dnsmasq.d/alcasar-dnsmasq.conf|grep "address=/#/"|wc -l` |
||
40 | if [ $net_pb != "1" ] |
||
41 | then |
||
360 | richard | 42 | /bin/sed -i "s?^\$network_pb.*?\$network_pb = True;?g" $Index_Page |
308 | richard | 43 | /bin/sed -i "s?^conf-dir=.*?address=\/#\/$PRIVATE_IP?g" /etc/dnsmasq.d/alcasar-dnsmasq.conf |
44 | /etc/init.d/dnsmasq restart |
||
45 | fi |
||
46 | } |
||
47 | |||
48 | # On teste la connectivité réseau |
||
49 | # On teste l'état d'EXTIF |
||
50 | EXT_DOWN="0" |
||
51 | if [ "`/usr/sbin/ethtool $EXTIF|grep Link|cut -d' ' -f3`" != "yes" ] |
||
52 | then |
||
53 | EXT_DOWN="1" |
||
54 | fi |
||
55 | # si EXTIF ok, on teste la connectivité vers le routeur par défaut (Box FAI) |
||
56 | if [ $EXT_DOWN -eq "0" ] |
||
57 | then |
||
58 | IP_GW=`/sbin/ip route list|grep ^default|cut -d" " -f3` |
||
59 | arp_reply=`/usr/sbin/arping -I$EXTIF -c1 $IP_GW|grep response|cut -d" " -f2` |
||
60 | if [ $arp_reply -eq "0" ] |
||
61 | then |
||
62 | EXT_DOWN="2" |
||
63 | fi |
||
64 | fi |
||
65 | # si routeur OK, on teste la connectivité vers les DNS externes |
||
66 | # + tard (EXT_DOWN=3) |
||
67 | # si Pb réseau, on avertit les usagers |
||
68 | if [ $EXT_DOWN != "0" ] |
||
69 | then |
||
70 | ext_down_alert |
||
71 | else |
||
72 | # sinon, on rebascule en mode normal |
||
73 | net_pb=`cat /etc/dnsmasq.d/alcasar-dnsmasq.conf|grep "address=/#/"|wc -l` |
||
74 | if [ $net_pb -eq "1" ] |
||
75 | then |
||
360 | richard | 76 | /bin/sed -i "s?^\$network_pb.*?\$network_pb = False;?g" $Index_Page |
308 | richard | 77 | /bin/sed -i "s?^address=\/#\/.*?conf-dir=/usr/local/etc/alcasar-dnsfilter-enabled?g" /etc/dnsmasq.d/alcasar-dnsmasq.conf |
78 | /etc/init.d/dnsmasq restart |
||
79 | fi |
||
80 | fi |
||
1 | root | 81 | # lecture du fichier contenant les adresses IP des stations muettes |
82 | if [ -e $tmp_file ]; then |
||
83 | cat $tmp_file | while read noresponse |
||
84 | do |
||
85 | noresponse_ip=`echo $noresponse | cut -d" " -f1` |
||
86 | noresponse_mac=`echo $noresponse | cut -d" " -f2` |
||
109 | richard | 87 | arp_reply=`/usr/sbin/arping -b -I$INTIF -s$PRIVATE_IP -c1 -w4 $noresponse_ip|grep response|cut -d" " -f2` |
1 | root | 88 | if [[ $(expr $arp_reply) -eq 0 ]] |
89 | then |
||
18 | franck | 90 | logger "alcasar-watchdog $noresponse_ip ($noresponse_mac) reste muette. On déconnecte." |
1 | root | 91 | /usr/sbin/chilli_query logout $noresponse_mac |
92 | fi |
||
93 | done |
||
94 | rm $tmp_file |
||
95 | fi |
||
96 | # on traite chaque équipements connus de chilli |
||
97 | for system in `/usr/sbin/chilli_query list` |
||
98 | do |
||
99 | active_ip=`echo $system |cut -d" " -f2` |
||
100 | active_session=`echo $system |cut -d" " -f5` |
||
101 | active_mac=`echo $system | cut -d" " -f1` |
||
109 | richard | 102 | # on ne traite que les équipements exploitées par un usager authentifié (test de 2 réponses en 4 secondes) |
1 | root | 103 | if [[ $(expr $active_session) -eq 1 ]] |
104 | then |
||
109 | richard | 105 | arp_reply=`/usr/sbin/arping -b -I$INTIF -s$PRIVATE_IP -c2 -w4 $active_ip|grep response|cut -d" " -f2` |
1 | root | 106 | # on stocke les adresses IP des stations muettes |
107 | if [[ $(expr $arp_reply) -eq 0 ]] |
||
108 | then |
||
109 | echo "$active_ip $active_mac" >> $tmp_file |
||
110 | fi |
||
111 | # on deconnecte l'usager d'une stations usurpée (@MAC) |
||
112 | if [[ $(expr $arp_reply) -gt 2 ]] |
||
113 | then |
||
18 | franck | 114 | logger "alcasar-watchdog : $active_ip est usurpée ($active_mac). On déconnecte." |
1 | root | 115 | /usr/sbin/chilli_query logout $active_mac |
116 | fi |
||
117 | fi |
||
118 | done |
||
308 | richard | 119 |