Projet

Général

Profil

Paste
Télécharger au format
Statistiques
| Branche: | Révision:

root / manifests / rules / out / dns.pp @ 31b17627

Historique | Voir | Annoter | Télécharger (1,09 ko)

1
# manage out dns
2
class nftables::rules::out::dns (
3
  Optional[Variant[String,Array[String,1]]] $dns_server = undef,
4
) {
5
  if $dns_server {
6
    any2array($dns_server).each |$index,$dns| {
7
      nftables::rule {
8
        "default_out-dnsudp-${index}":
9
      }
10
      if $dns =~ /:/ {
11
        Nftables::Rule["default_out-dnsudp-${index}"] {
12
          content => "ip6 daddr ${dns} udp dport 53 accept",
13
        }
14
      } else {
15
        Nftables::Rule["default_out-dnsudp-${index}"] {
16
          content => "ip daddr ${dns} udp dport 53 accept",
17
        }
18
      }
19

    
20
      nftables::rule {
21
        "default_out-dnstcp-${index}":
22
      }
23
      if $dns =~ /:/ {
24
        Nftables::Rule["default_out-dnstcp-${index}"] {
25
          content => "ip6 daddr ${dns} tcp dport 53 accept",
26
        }
27
      } else {
28
        Nftables::Rule["default_out-dnstcp-${index}"] {
29
          content => "ip daddr ${dns} tcp dport 53 accept",
30
        }
31
      }
32
    }
33
  } else {
34
    nftables::rule {
35
      'default_out-dnsudp':
36
        content => 'udp dport 53 accept';
37
      'default_out-dnstcp':
38
        content => 'tcp dport 53 accept';
39
    }
40
  }
41
}