Projet

Général

Profil

Paste
Télécharger au format
Statistiques
| Branche: | Révision:

root / templates / config / puppet.nft.epp @ 82d10659

Historique | Voir | Annoter | Télécharger (505 octets)

1
# puppet-preflight.nft is only used by puppet for validating new configs
2
# puppet.nft is real configuration that the nftables services uses.
3
# To process either the -I flag must be specified.
4
# nft -c -I /etc/nftables/puppet -f /etc/nftables/puppet.nft
5
# nft -c -I /etc/nftables/puppet-preflight -f /etc/nftables/puppet-preflight.nft
6

    
7
# drop any existing nftables ruleset
8
flush ruleset
9

    
10
include "custom-*.nft"
11
include "inet-filter.nft"
12
<% if $nat { -%>
13
include "ip-nat.nft"
14
include "ip6-nat.nft"
15
<% } -%>