Browse Source

include policy updates for ipv6

pull/3/head
Dennis van Dok 7 years ago
parent
commit
c5319152de
2 changed files with 21 additions and 0 deletions
  1. +8
    -0
      iptables/rules.sls
  2. +13
    -0
      iptables/service.sls

+ 8
- 0
iptables/rules.sls View File

{%- if chain.policy is defined %} {%- if chain.policy is defined %}
iptables_{{ chain_name }}_policy: iptables_{{ chain_name }}_policy:
iptables.set_policy: iptables.set_policy:
- family: ipv4
- chain: {{ chain_name }}
- policy: {{ chain.policy }}
- table: filter

iptables_{{ chain_name }}_ipv6_policy:
iptables.set_policy:
- family: ipv6
- chain: {{ chain_name }} - chain: {{ chain_name }}
- policy: {{ chain.policy }} - policy: {{ chain.policy }}
- table: filter - table: filter

+ 13
- 0
iptables/service.sls View File

- table: filter - table: filter
- require_in: - require_in:
- iptables: iptables_flush - iptables: iptables_flush

iptables_{{ chain_name }}_ipv6_policy:
iptables.set_policy:
- chain: {{ chain_name }}
- family: ipv6
- policy: ACCEPT
- table: filter
- require_in:
- iptables: ip6tables_flush
{%- endfor %} {%- endfor %}


iptables_flush: iptables_flush:
iptables.flush iptables.flush


ip6tables_flush:
iptables.flush:
- family: ipv6

{%- endif %} {%- endif %}

Loading…
Cancel
Save