Sfoglia il codice sorgente

set ipv6 policies only if ipv6 is enabled on the host and not explicitly turned off for this service

pull/3/head
Dennis van Dok 7 anni fa
parent
commit
6ad67680cd
2 ha cambiato i file con 3 aggiunte e 3 eliminazioni
  1. +1
    -1
      iptables/rules.sls
  2. +2
    -2
      iptables/service.sls

+ 1
- 1
iptables/rules.sls Vedi File

@@ -10,7 +10,7 @@ iptables_{{ chain_name }}_policy:
- policy: {{ chain.policy }}
- table: filter

{%- if service.ipv6 %}
{%- if grains.ipv6|default(False) and service.ipv6|default(True) %}
iptables_{{ chain_name }}_ipv6_policy:
iptables.set_policy:
- family: ipv6

+ 2
- 2
iptables/service.sls Vedi File

@@ -37,7 +37,7 @@ iptables_{{ chain_name }}_policy:
- require_in:
- iptables: iptables_flush

{%- if service.ipv6 %}
{%- if grains.ipv6|default(False) and service.ipv6|default(True) %}
iptables_{{ chain_name }}_ipv6_policy:
iptables.set_policy:
- chain: {{ chain_name }}
@@ -53,7 +53,7 @@ iptables_{{ chain_name }}_ipv6_policy:
iptables_flush:
iptables.flush

{%- if service.ipv6 %}
{%- if grains.ipv6|default(False) and service.ipv6|default(True) %}
ip6tables_flush:
iptables.flush:
- family: ipv6

Loading…
Annulla
Salva