瀏覽代碼

include policy updates for ipv6

pull/3/head
Dennis van Dok 7 年之前
父節點
當前提交
c5319152de
共有 2 個檔案被更改,包括 21 行新增0 行删除
  1. +8
    -0
      iptables/rules.sls
  2. +13
    -0
      iptables/service.sls

+ 8
- 0
iptables/rules.sls 查看文件

@@ -5,6 +5,14 @@
{%- if chain.policy is defined %}
iptables_{{ chain_name }}_policy:
iptables.set_policy:
- family: ipv4
- chain: {{ chain_name }}
- policy: {{ chain.policy }}
- table: filter

iptables_{{ chain_name }}_ipv6_policy:
iptables.set_policy:
- family: ipv6
- chain: {{ chain_name }}
- policy: {{ chain.policy }}
- table: filter

+ 13
- 0
iptables/service.sls 查看文件

@@ -36,9 +36,22 @@ iptables_{{ chain_name }}_policy:
- table: filter
- require_in:
- iptables: iptables_flush

iptables_{{ chain_name }}_ipv6_policy:
iptables.set_policy:
- chain: {{ chain_name }}
- family: ipv6
- policy: ACCEPT
- table: filter
- require_in:
- iptables: ip6tables_flush
{%- endfor %}

iptables_flush:
iptables.flush

ip6tables_flush:
iptables.flush:
- family: ipv6

{%- endif %}

Loading…
取消
儲存