Projet

Général

Profil

Paste
Télécharger au format
Statistiques
| Branche: | Révision:

root / templates / simplerule.epp @ 77abc10b

Historique | Voir | Annoter | Télécharger (1,63 ko)

1
<%- | String                  $action,
2
      Optional[String]        $comment,
3
      Optional[Variant[Array[Stdlib::Port, 1], Stdlib::Port, String]] $dport,
4
      Optional[String]        $proto,
5
      Optional[Variant[Stdlib::IP::Address::V6, Stdlib::IP::Address::V4, Pattern[/^@[-a-zA-Z0-9_]+$/]]] $daddr,
6
      Enum['ip', 'ip6']       $set_type,
7
      Optional[Variant[Array[Stdlib::Port, 1], Stdlib::Port, String]] $sport,
8
      Boolean                 $counter,
9
| -%>
10
<%- if $proto {
11
  $_proto = $proto ? {
12
    /tcp(4|6)?/ => 'tcp',
13
    /udp(4|6)?/ => 'udp',
14
  }
15
  $_ip_version_filter = $proto ? {
16
    /(tcp4|udp4)/ => 'ip version 4',
17
    /(tcp6|udp6)/ => 'ip version 6',
18
    default       => undef,
19
  }
20
} else {
21
  $_ip_version_filter = undef
22
} -%>
23
<%- if $daddr {
24
  if $daddr =~ Stdlib::IP::Address::V6 {
25
    $_dst_hosts = "ip6 daddr ${daddr}"
26
  } elsif $daddr =~ Stdlib::IP::Address::V4 {
27
    $_dst_hosts = "ip daddr ${daddr}"
28
  } else {
29
    $_dst_hosts = $set_type ? {
30
      'ip'  => "ip daddr ${daddr}",
31
      'ip6' => "ip6 daddr ${daddr}",
32
    }
33
  }
34
} else {
35
  $_dst_hosts = undef
36
} -%>
37
<%- if $proto and $dport {
38
  $_dst_port = "${_proto} dport {${Array($dport, true).join(', ')}}"
39
} else {
40
  $_dst_port = undef
41
} -%>
42
<%- if $comment {
43
  $_comment = "comment \"${comment}\""
44
} else {
45
  $_comment = undef
46
} -%>
47
<%- if $proto and $sport {
48
  $_src_port = "${_proto} sport {${Array($sport, true).join(', ')}}"
49
} else {
50
  $_src_port = undef
51
} -%>
52
<%- if $counter {
53
  $_counter = "counter"
54
} else {
55
  $_counter = undef
56
} -%>
57
<%= regsubst(strip([$_ip_version_filter, $_src_port, $_dst_port, $_dst_hosts, $_counter, $action, $_comment].join(' ')), '\s+', ' ', 'G') -%>