|
|
|
|
|
|
|
|
{%- if rule.destination_port is defined %} |
|
|
{%- if rule.destination_port is defined %} |
|
|
- dport: {{ rule.destination_port }} |
|
|
- dport: {{ rule.destination_port }} |
|
|
{%- endif %} |
|
|
{%- endif %} |
|
|
|
|
|
{%- if rule.destination_ports is defined %} |
|
|
|
|
|
- dports: |
|
|
|
|
|
{%- for port in rule.destination_ports %} |
|
|
|
|
|
- {{ port }} |
|
|
|
|
|
{% endfor %} |
|
|
|
|
|
{%- endif %} |
|
|
{%- if rule.source_port is defined %} |
|
|
{%- if rule.source_port is defined %} |
|
|
- sport: {{ rule.source_port }} |
|
|
- sport: {{ rule.source_port }} |
|
|
{%- endif %} |
|
|
{%- endif %} |
|
|
|
|
|
|
|
|
{%- if rule.destination_network is defined %} |
|
|
{%- if rule.destination_network is defined %} |
|
|
- destination: {{ rule.destination_network }} |
|
|
- destination: {{ rule.destination_network }} |
|
|
{%- endif %} |
|
|
{%- endif %} |
|
|
|
|
|
{%- if rule.log_prefix is defined %} |
|
|
|
|
|
- log-prefix: '{{ rule.log_prefix }}' |
|
|
|
|
|
{%- endif %} |
|
|
|
|
|
{%- if rule.log_level is defined %} |
|
|
|
|
|
- log-level: {{ rule.log_level }} |
|
|
|
|
|
{%- endif %} |
|
|
|
|
|
{%- if rule.limit is defined %} |
|
|
|
|
|
- limit: '{{ rule.limit }}' |
|
|
|
|
|
{%- endif %} |
|
|
{%- if chain.policy is defined %} |
|
|
{%- if chain.policy is defined %} |
|
|
- require_in: |
|
|
- require_in: |
|
|
- iptables: iptables_{{ chain_name }}_policy |
|
|
- iptables: iptables_{{ chain_name }}_policy |