#!/bin/sh
set -e
[ "$script_type" ]
[ "$dev" ]

case "$script_type" in
up)
  ip route add "$trusted_ip" via "$route_net_gateway"
  ip route add 0.0.0.0/1 via "$route_vpn_gateway"
  ip route add 128.0.0.0/1 via "$route_vpn_gateway"
  iptables -t nat -A POSTROUTING -s 10.13.0.0/24 -o "$dev" -j SNAT --to-source "$ifconfig_local"
;;
down)
  iptables -t nat -D POSTROUTING -s 10.13.0.0/24 -o "$dev" -j SNAT --to-source "$ifconfig_local"
  ip route del 0.0.0.0/1 via "$route_vpn_gateway"
  ip route del 128.0.0.0/1 via "$route_vpn_gateway"
  ip route del "$trusted_ip" via "$route_net_gateway"
;;
esac