Saltstack Official FirewallD Formula
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117
  1. <?xml version="1.0" encoding="utf-8"?>
  2. <!--
  3. This file is managed/generated by salt.
  4. Do not edit this file manually, it will be overwritten!
  5. Modify the salt pillar for firewalld instead
  6. -->
  7. <zone{%- if 'target' in zone %} target="{{ zone.target }}"{%- endif %}>
  8. {% if 'short' in zone %}<short>{{ zone.short }}</short>{% else %}<short>{{ name }}</short>{% endif %}
  9. {% if 'description' in zone %}<description>{{ zone.description }}</description>{% endif %}
  10. {%- if 'interfaces' in zone %}
  11. {%- for v in zone.interfaces %}
  12. <interface name="{{ v }}" />
  13. {%- endfor %}
  14. {%- endif %}
  15. {%- if 'sources' in zone %}
  16. {%- for v in zone.sources %}
  17. {%- if 'comment' in v %}
  18. <!-- {{ v.comment }} -->
  19. <source address="{{ v.source }}" />
  20. {%- else %}
  21. <source address="{{ v }}" />
  22. {%- endif %}
  23. {%- endfor %}
  24. {%- endif %}
  25. {%- if 'services' in zone %}
  26. {%- for v in zone.services %}
  27. <service name="{{ v }}" />
  28. {%- endfor %}
  29. {%- endif %}
  30. {%- if 'ports' in zone %}
  31. {%- for v in zone.ports %}
  32. {%- if 'comment' in v %}
  33. <!-- {{ v.comment }} -->
  34. {%- endif %}
  35. <port port="{{ v.port }}" protocol="{{ v.protocol }}"/>
  36. {%- endfor %}
  37. {%- endif %}
  38. {%- if 'icmp_blocks' in zone %}
  39. {%- for v in zone.icmp_blocks %}
  40. <icmp-block name="{{ v }}" />
  41. {%- endfor %}
  42. {%- endif %}
  43. {%- if 'masquerade' in zone %}
  44. {%- if zone.masquerade %}
  45. <masquerade/>
  46. {%- endif %}
  47. {%- endif %}
  48. {%- if 'forward_ports' in zone %}
  49. {%- for v in zone.forward_ports %}
  50. {%- if 'comment' in v %}
  51. <!-- {{ v.comment }} -->
  52. {%- endif %}
  53. <forward-port port="{{ v.portid }}" protocol="{{ v.protocol }}"{%- if 'to_port' in v %} to-port="{{ v.to_port }}"{%- endif %}{%- if 'to_addr' in v %} to-addr="{{ v.to_addr }}"{%- endif %} />
  54. {%- endfor %}
  55. {%- endif %}
  56. {%- if 'rich_rules' in zone %}
  57. {%- for rule in zone.rich_rules %}
  58. {%- if 'family' in rule %}
  59. <rule family="{{ rule.family }}">
  60. {%- else %}
  61. <rule>
  62. {%- endif %}
  63. {%- if 'ipset' in rule %}
  64. <source ipset="{{ rule.ipset.name }}"/>
  65. {%- endif %}
  66. {%- if 'source' in rule %}
  67. <source address="{{ rule.source.address }}" {%- if 'invert' in rule.source %}invert="{{ rule.source.invert }}"{%- endif %}/>
  68. {%- endif %}
  69. {%- if 'destination' in rule %}
  70. <destination address="{{ rule.destination.address }}" {%- if 'invert' in rule.destination %}invert="{{ rule.destination.invert }}"{%- endif %}/>
  71. {%- endif %}
  72. {%- if 'service' in rule %}
  73. <service name="{{ rule.service }}"/>
  74. {%- endif %}
  75. {%- if 'port' in rule %}
  76. <port port="{{ rule.port.portid }}" protocol="{{ rule.port.protocol }}"/>
  77. {%- endif %}
  78. {%- if 'protocol' in rule %}
  79. <protocol value="{{ rule.protocol }}"/>
  80. {%- endif %}
  81. {%- if 'icmp_block' in rule %}
  82. <icmp_block name="{{ rule.icmp_block }}"/>
  83. {%- endif %}
  84. {%- if 'masquerade' in rule %}
  85. {%- if rule.masquerade %}<masquerade/>{%- endif %}
  86. {%- endif %}
  87. {%- if 'forward_port' in rule %}
  88. {%- if 'comment' in rule.forward_port %}
  89. <!-- {{ rule.forward_port.comment }} -->
  90. {%- endif %}
  91. <forward-port port="{{ rule.forward_port.portid }}" protocol="{{ rule.forward_port.protocol }}"{%- if 'to_port' in rule.forward_port %} to-port="{{ rule.forward_port.to_port }}"{%- endif %}{%- if 'to_addr' in rule.forward_port %} to-addr="{{ rule.forward_port.to_addr }}"{%- endif %} />
  92. {%- endif %}
  93. {%- if 'log' in rule %}
  94. <log{%- if 'prefix' in rule.log %} prefix="{{ rule.log.prefix }}"{%- endif %}{%- if 'level' in rule.log %} level="{{ rule.log.level }}"{%- endif %}>
  95. {%- if 'limit' in rule.log %}
  96. <limit value="{{ rule.log.limit }}"/>
  97. {%- endif %}
  98. </log>
  99. {%- endif %}
  100. {%- if 'audit' in rule %}
  101. <audit>{%- if 'limit' in rule.audit %} <limit value="{{ rule.audit.limit }}"/>{%- endif %}</audit>
  102. {%- endif %}
  103. {%- if 'accept' in rule %}
  104. <accept/>
  105. {%- endif %}
  106. {%- if 'reject' in rule %}
  107. <reject{%- if 'type' in rule.reject %} type="{{ rule.reject.type }}"{%- endif %}/>
  108. {%- endif %}
  109. {%- if 'drop' in rule %}
  110. <drop/>
  111. {%- endif %}
  112. </rule>
  113. {%- endfor %}
  114. {%- endif %}
  115. </zone>