Projet

Général

Profil

Paste
Télécharger au format
Statistiques
| Branche: | Révision:

root / templates / simplerule.epp @ aaa37172

Historique | Voir | Annoter | Télécharger (1,36 ko)

1
<%- | String                  $action,
2
      Optional[String]        $comment,
3
      Optional[Variant[Array[Stdlib::Port, 1], Stdlib::Port, String]] $dport,
4
      Optional[String]        $proto,
5
      Optional[Variant[Stdlib::IP::Address::V6, Stdlib::IP::Address::V4, Pattern[/^@[-a-zA-Z0-9_]+$/]]] $daddr,
6
      Enum['ip', 'ip6']       $set_type,
7
| -%>
8
<%- if $proto {
9
  $_proto = $proto ? {
10
    /tcp(4|6)?/ => 'tcp',
11
    /udp(4|6)?/ => 'udp',
12
  }
13
  $_ip_version_filter = $proto ? {
14
    /(tcp4|udp4)/ => 'ip version 4',
15
    /(tcp6|udp6)/ => 'ip version 6',
16
    default       => undef,
17
  }
18
} else {
19
  $_ip_version_filter = undef
20
} -%>
21
<%- if $daddr {
22
  if $daddr =~ Stdlib::IP::Address::V6 {
23
    $_dst_hosts = "ip6 daddr ${daddr}"
24
  } elsif $daddr =~ Stdlib::IP::Address::V4 {
25
    $_dst_hosts = "ip daddr ${daddr}"
26
  } else {
27
    $_dst_hosts = $set_type ? {
28
      'ip'  => "ip daddr ${daddr}",
29
      'ip6' => "ip6 daddr ${daddr}",
30
    }
31
  }
32
} else {
33
  $_dst_hosts = undef
34
} -%>
35
<%- if $proto and $dport {
36
  if $dport =~ Array {
37
    $_dst_port = "${_proto} dport {${dport.join(', ')}}"
38
  } else {
39
    $_dst_port = "${_proto} dport $dport"
40
  }
41
} else {
42
  $_dst_port = undef
43
} -%>
44
<%- if $comment {
45
  $_comment = "comment \"${comment}\""
46
} else {
47
  $_comment = undef
48
} -%>
49
<%= regsubst(strip([$_ip_version_filter, $_dst_port, $_dst_hosts, $action, $_comment].join(' ')), '\s+', ' ', 'G') -%>