Pārlūkot izejas kodu
Add support for using ipsets as sources in a zone
I wanted to be able to add an ipset as a source in the zone without using a rich rule. I believe this change accomplishes that. Tested and working on CentOS 7 (salt master and minion).
tags/v0.6.2
Paul Williams
pirms 7 gadiem
vecāks
revīzija
2fd70c9f41
Revīzijas autora e-pasta adrese nav piesaistīta nevienam kontam
1 mainītis faili ar
10 papildinājumiem un
0 dzēšanām
-
firewalld/files/zone.xml
|
|
@@ -23,6 +23,16 @@ |
|
|
|
{%- endif %} |
|
|
|
{%- endfor %} |
|
|
|
{%- endif %} |
|
|
|
{%- if 'ipsets' in zone %} |
|
|
|
{%- for v in zone.ipsets %} |
|
|
|
{%- if 'comment' in v %} |
|
|
|
<!-- {{ v.comment }} --> |
|
|
|
<source ipset="{{ v.ipset }}" /> |
|
|
|
{%- else %} |
|
|
|
<source ipset="{{ v }}" /> |
|
|
|
{%- endif %} |
|
|
|
{%- endfor %} |
|
|
|
{%- endif %} |
|
|
|
{%- if 'services' in zone %} |
|
|
|
{%- for v in zone.services %} |
|
|
|
<service name="{{ v }}" /> |