Saltstack Official FirewallD Formula
您最多选择25个主题 主题必须以字母或数字开头,可以包含连字符 (-),并且长度不得超过35个字符

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566
  1. # == State: firewalld
  2. #
  3. # This state installs/runs firewalld.
  4. #
  5. {% from "firewalld/map.jinja" import firewalld with context %}
  6. {% if salt['grains.get']('osfullname') == "SLES" and salt['grains.get']('osmajorrelease')|int < 15 %}
  7. firewalld-unsupported:
  8. test.show_notification:
  9. - text: |
  10. Firewalld is not supported on {{ grains['os'] }}
  11. See https://www.suse.com/releasenotes/x86_64/SUSE-SLES/15/#fate-323460
  12. {% elif firewalld.enabled %}
  13. include:
  14. {% if grains.get('osfinger', '') == 'Debian-10' %}
  15. - firewalld.debian10
  16. {% endif %}
  17. - firewalld.config
  18. - firewalld.ipsets
  19. - firewalld.backend
  20. - firewalld.services
  21. - firewalld.zones
  22. - firewalld.policies
  23. - firewalld.direct
  24. # iptables service that comes with rhel/centos
  25. iptables:
  26. service.disabled:
  27. - enable: False
  28. ip6tables:
  29. service.disabled:
  30. - enable: False
  31. package_firewalld:
  32. pkg.installed:
  33. - name: {{ firewalld.package }}
  34. service_firewalld:
  35. service.running:
  36. - name: {{ firewalld.service }}
  37. - enable: True # start on boot
  38. - require:
  39. - pkg: package_firewalld
  40. - file: config_firewalld
  41. - service: iptables # ensure it's stopped
  42. - service: ip6tables # ensure it's stopped
  43. reload_firewalld:
  44. cmd.wait: # noqa: 213
  45. - name: 'firewall-cmd --reload'
  46. - require:
  47. - service: service_firewalld
  48. {% else %}
  49. service_firewalld:
  50. service.dead:
  51. - name: {{ firewalld.service }}
  52. - enable: False # don't start on boot
  53. {% endif %}