root / manifests / rules / out / dns.pp @ 2e704fc9
Historique | Voir | Annoter | Télécharger (1,09 ko)
1 |
# manage out dns |
---|---|
2 |
class nftables::rules::out::dns ( |
3 |
Optional[Variant[String,Array[String,1]]] |
4 |
$dns_server = undef, |
5 |
) { |
6 |
if $dns_server { |
7 |
any2array($dns_server).each |$index,$dns| { |
8 |
|
9 |
nftables::rule{ |
10 |
"default_out-dnsudp-${index}": |
11 |
} |
12 |
if $dns =~ /:/ { |
13 |
Nftables::Rule["default_out-dnsudp-${index}"]{ |
14 |
content => "ip6 daddr ${dns} udp dport 53 accept", |
15 |
} |
16 |
} else { |
17 |
Nftables::Rule["default_out-dnsudp-${index}"]{ |
18 |
content => "ip daddr ${dns} udp dport 53 accept", |
19 |
} |
20 |
} |
21 |
|
22 |
nftables::rule{ |
23 |
"default_out-dnstcp-${index}": |
24 |
} |
25 |
if $dns =~ /:/ { |
26 |
Nftables::Rule["default_out-dnstcp-${index}"]{ |
27 |
content => "ip6 daddr ${dns} tcp dport 53 accept", |
28 |
} |
29 |
} else { |
30 |
Nftables::Rule["default_out-dnstcp-${index}"]{ |
31 |
content => "ip daddr ${dns} tcp dport 53 accept", |
32 |
} |
33 |
} |
34 |
} |
35 |
} else { |
36 |
nftables::rule{ |
37 |
'default_out-dnsudp': |
38 |
content => 'udp dport 53 accept'; |
39 |
'default_out-dnstcp': |
40 |
content => 'tcp dport 53 accept'; |
41 |
} |
42 |
} |
43 |
} |