瀏覽代碼

Allow custom chains to be present, other than the INPUT, FORWARD, OUTPUT default chains.

pull/12/head
Michel Nederlof 7 年之前
父節點
當前提交
8a1ce21f73
共有 2 個檔案被更改,包括 21 行新增0 行删除
  1. +2
    -0
      iptables/_rule.sls
  2. +19
    -0
      iptables/rules.sls

+ 2
- 0
iptables/_rule.sls 查看文件

@@ -57,4 +57,6 @@ iptables_{{ chain_name }}_{{ rule_name }}:
- require_in:
- iptables: iptables_{{ chain_name }}_policy
{%- endif %}
- require:
- iptables: iptables_{{ chain_name }}{% if rule.family is defined %}_{{ rule.family }}{% endif %}
- save: True

+ 19
- 0
iptables/rules.sls 查看文件

@@ -2,6 +2,21 @@

{%- for chain_name, chain in service.get('chain', {}).iteritems() %}

iptables_{{ chain_name }}:
iptables.chain_present:
- family: ipv4
- name: {{ chain_name }}
- table: filter

{%- if grains.ipv6|default(False) and service.ipv6|default(True) %}
iptables_{{ chain_name }}_ipv6:
iptables.chain_present:
- family: ipv6
- name: {{ chain_name }}
- table: filter
- require_in:
- iptables: iptables_{{ chain_name }}_ipv6_policy

{%- if chain.policy is defined %}
iptables_{{ chain_name }}_policy:
iptables.set_policy:
@@ -9,6 +24,8 @@ iptables_{{ chain_name }}_policy:
- chain: {{ chain_name }}
- policy: {{ chain.policy }}
- table: filter
- require:
- iptables: iptables_{{ chain_name }}

{%- if grains.ipv6|default(False) and service.ipv6|default(True) %}
iptables_{{ chain_name }}_ipv6_policy:
@@ -17,6 +34,8 @@ iptables_{{ chain_name }}_ipv6_policy:
- chain: {{ chain_name }}
- policy: {{ chain.policy }}
- table: filter
- require:
- iptables: iptables_{{ chain_name }}_ipv6
{%- endif %}
{%- endif %}


Loading…
取消
儲存