Projet

Général

Profil

Paste
Télécharger au format
Statistiques
| Branche: | Révision:

root / manifests / rules / out / dns.pp @ 2e704fc9

Historique | Voir | Annoter | Télécharger (1,09 ko)

1
# manage out dns
2
class nftables::rules::out::dns (
3
  Optional[Variant[String,Array[String,1]]]
4
    $dns_server = undef,
5
) {
6
  if $dns_server {
7
    any2array($dns_server).each |$index,$dns| {
8

    
9
      nftables::rule{
10
        "default_out-dnsudp-${index}":
11
      }
12
      if $dns =~ /:/ {
13
        Nftables::Rule["default_out-dnsudp-${index}"]{
14
          content => "ip6 daddr ${dns} udp dport 53 accept",
15
        }
16
      } else {
17
        Nftables::Rule["default_out-dnsudp-${index}"]{
18
          content => "ip daddr ${dns} udp dport 53 accept",
19
        }
20
      }
21

    
22
      nftables::rule{
23
        "default_out-dnstcp-${index}":
24
      }
25
      if $dns =~ /:/ {
26
        Nftables::Rule["default_out-dnstcp-${index}"]{
27
          content => "ip6 daddr ${dns} tcp dport 53 accept",
28
        }
29
      } else {
30
        Nftables::Rule["default_out-dnstcp-${index}"]{
31
          content => "ip daddr ${dns} tcp dport 53 accept",
32
        }
33
      }
34
    }
35
  } else {
36
    nftables::rule{
37
      'default_out-dnsudp':
38
        content => 'udp dport 53 accept';
39
      'default_out-dnstcp':
40
        content => 'tcp dport 53 accept';
41
    }
42
  }
43
}