root / manifests / rules / out / dns.pp @ 94a80621
Historique | Voir | Annoter | Télécharger (1,09 ko)
1 |
# manage out dns |
---|---|
2 |
class nftables::rules::out::dns ( |
3 |
Optional[Variant[String,Array[String,1]]] $dns_server = undef, |
4 |
) { |
5 |
if $dns_server { |
6 |
any2array($dns_server).each |$index,$dns| { |
7 |
nftables::rule { |
8 |
"default_out-dnsudp-${index}": |
9 |
} |
10 |
if $dns =~ /:/ { |
11 |
Nftables::Rule["default_out-dnsudp-${index}"] { |
12 |
content => "ip6 daddr ${dns} udp dport 53 accept", |
13 |
} |
14 |
} else { |
15 |
Nftables::Rule["default_out-dnsudp-${index}"] { |
16 |
content => "ip daddr ${dns} udp dport 53 accept", |
17 |
} |
18 |
} |
19 |
|
20 |
nftables::rule { |
21 |
"default_out-dnstcp-${index}": |
22 |
} |
23 |
if $dns =~ /:/ { |
24 |
Nftables::Rule["default_out-dnstcp-${index}"] { |
25 |
content => "ip6 daddr ${dns} tcp dport 53 accept", |
26 |
} |
27 |
} else { |
28 |
Nftables::Rule["default_out-dnstcp-${index}"] { |
29 |
content => "ip daddr ${dns} tcp dport 53 accept", |
30 |
} |
31 |
} |
32 |
} |
33 |
} else { |
34 |
nftables::rule { |
35 |
'default_out-dnsudp': |
36 |
content => 'udp dport 53 accept'; |
37 |
'default_out-dnstcp': |
38 |
content => 'tcp dport 53 accept'; |
39 |
} |
40 |
} |
41 |
} |