{%- if chain.policy is defined %} | {%- if chain.policy is defined %} | ||||
iptables_{{ chain_name }}_policy: | iptables_{{ chain_name }}_policy: | ||||
iptables.set_policy: | iptables.set_policy: | ||||
- family: ipv4 | |||||
- chain: {{ chain_name }} | |||||
- policy: {{ chain.policy }} | |||||
- table: filter | |||||
iptables_{{ chain_name }}_ipv6_policy: | |||||
iptables.set_policy: | |||||
- family: ipv6 | |||||
- chain: {{ chain_name }} | - chain: {{ chain_name }} | ||||
- policy: {{ chain.policy }} | - policy: {{ chain.policy }} | ||||
- table: filter | - table: filter |
- table: filter | - table: filter | ||||
- require_in: | - require_in: | ||||
- iptables: iptables_flush | - iptables: iptables_flush | ||||
iptables_{{ chain_name }}_ipv6_policy: | |||||
iptables.set_policy: | |||||
- chain: {{ chain_name }} | |||||
- family: ipv6 | |||||
- policy: ACCEPT | |||||
- table: filter | |||||
- require_in: | |||||
- iptables: ip6tables_flush | |||||
{%- endfor %} | {%- endfor %} | ||||
iptables_flush: | iptables_flush: | ||||
iptables.flush | iptables.flush | ||||
ip6tables_flush: | |||||
iptables.flush: | |||||
- family: ipv6 | |||||
{%- endif %} | {%- endif %} |