#!/bin/bash
set -xv

export PATH="/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
#export $(grep -v '^#' /opt/src/vpn.env | xargs)

exiterr()  { echo "Error: $1" >&2; exit 1; }
nospaces() { printf '%s' "$1" | sed -e 's/^[[:space:]]*//' -e 's/[[:space:]]*$//'; }
onespace() { printf '%s' "$1" | tr -s ' '; }
noquotes() { printf '%s' "$1" | sed -e 's/^"\(.*\)"$/\1/' -e "s/^'\(.*\)'$/\1/"; }
noquotes2() { printf '%s' "$1" | sed -e 's/" "/ /g' -e "s/' '/ /g"; }

check_ip() {
  IP_REGEX='^(([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])\.){3}([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])$'
  printf '%s' "$1" | tr -d '\n' | grep -Eq "$IP_REGEX"
}

check_dns_name() {
  FQDN_REGEX='^([a-zA-Z0-9]([a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?\.)+[a-zA-Z]{2,}$'
  printf '%s' "$1" | tr -d '\n' | grep -Eq "$FQDN_REGEX"
}

check_client_name() {
  ! { [ "${#1}" -gt "64" ] || printf '%s' "$1" | LC_ALL=C grep -q '[^A-Za-z0-9_-]\+' \
    || case $1 in -*) true ;; *) false ;; esac; }
}

echo "Checking VPN credentials..."
ls -l /opt/src/vpn.env
if [ -z "$VPN_IPSEC_PSK" ] && [ -z "$VPN_USER" ] && [ -z "$VPN_PASS" ] && [ -z "$VPN_SERVER" ] && [ -z "$VPN_GROUP" ]; then
  echo "Vars not defined"
  exit 1
else
  echo "Retriving..."
fi

# Create IPsec config
cat > /etc/ipsec.conf <<EOF
config setup

conn triara
 aggrmode=yes
 leftid=@$VPN_GROUP
 authby=secret
 left=%defaultroute
 leftmodecfgclient=yes
 right=$VPN_SERVER
 rightmodecfgserver=yes
 modecfgpull=yes
 rightsubnet=0.0.0.0/0
 leftxauthclient=yes
 leftxauthusername=$VPN_USER
 remote_peer_type=cisco
 rightxauthserver=yes
 ike=aes256-sha2_512-ecp384,aes128-sha2_256-ecp384
 phase2alg=aes256-sha2_512,aes128-sha2_256
 ikelifetime=8h
 salifetime=4h
 rekey=yes
 keyingtries=1
 ikev2=never
 nm-configured=no
 auto=start

EOF

cat >> /etc/ipsec.conf <<'EOF'
include /etc/ipsec.d/*.conf
EOF

# Specify IPsec PSK
cat > /etc/ipsec.secrets <<EOF
$VPN_SERVER %any : PSK "$VPN_IPSEC_PSK" 
@$VPN_USER: XAUTH "$VPN_PASS"
EOF

# Update sysctl settings
syt='/sbin/sysctl -e -q -w'
$syt kernel.msgmnb=65536 2>/dev/null
$syt kernel.msgmax=65536 2>/dev/null
$syt net.ipv4.ip_forward=1 2>/dev/null
$syt net.ipv4.conf.all.accept_redirects=0 2>/dev/null
$syt net.ipv4.conf.all.send_redirects=0 2>/dev/null
$syt net.ipv4.conf.all.rp_filter=0 2>/dev/null
$syt net.ipv4.conf.default.accept_redirects=0 2>/dev/null
$syt net.ipv4.conf.default.send_redirects=0 2>/dev/null
$syt net.ipv4.conf.default.rp_filter=0 2>/dev/null
$syt "net.ipv4.conf.$NET_IFACE.send_redirects=0" 2>/dev/null
$syt "net.ipv4.conf.$NET_IFACE.rp_filter=0" 2>/dev/null

# Update file attributes
chmod 600 /etc/ipsec.secrets

echo
echo "Starting IPsec service..."
mkdir -p /run/pluto /var/run/pluto
rm -f /run/pluto/pluto.pid /var/run/pluto/pluto.pid
if [ "$os_type" = "alpine" ]; then
  sed -i '1c\#!/sbin/openrc-run' /etc/init.d/ipsec
  rc-status >/dev/null 2>&1
  rc-service ipsec zap >/dev/null
  rc-service -D ipsec start >/dev/null 2>&1
  mkdir -p /etc/crontabs
  cron_cmd="rc-service -c -D ipsec zap start"
if ! grep -qs "$cron_cmd" /etc/crontabs/root; then
cat >> /etc/crontabs/root <<EOF
* * * * * $cron_cmd
* * * * * sleep 15; $cron_cmd
* * * * * sleep 30; $cron_cmd
* * * * * sleep 45; $cron_cmd
EOF
fi
  /usr/sbin/crond -L /dev/null
else
  service ipsec start
fi
if [ -z "$SOURCE_PORT" ] && [ -z "$DEST_PORT" ] && [ -z "$IP_REDIRECT" ]; then
 echo "Not redirect configured"
  #exit 1
else
  echo "Set redirection :$SOURCE_PORT -> $IP_REDIRECT:$DEST_PORT"
  redir :$SOURCE_PORT $IP_REDIRECT:$DEST_PORT
fi

/usr/sbin/sshd -D