root / manifests / rules / out / dns.pp @ de3e7bb0
Historique | Voir | Annoter | Télécharger (1,14 ko)
1 |
# @summary manage out dns |
---|---|
2 |
# @param dns_server specify dns_server name |
3 |
class nftables::rules::out::dns ( |
4 |
Optional[Variant[String,Array[String,1]]] $dns_server = undef, |
5 |
) { |
6 |
if $dns_server { |
7 |
any2array($dns_server).each |$index,$dns| { |
8 |
nftables::rule { |
9 |
"default_out-dnsudp-${index}": |
10 |
} |
11 |
if $dns =~ /:/ { |
12 |
Nftables::Rule["default_out-dnsudp-${index}"] { |
13 |
content => "ip6 daddr ${dns} udp dport 53 accept", |
14 |
} |
15 |
} else { |
16 |
Nftables::Rule["default_out-dnsudp-${index}"] { |
17 |
content => "ip daddr ${dns} udp dport 53 accept", |
18 |
} |
19 |
} |
20 |
|
21 |
nftables::rule { |
22 |
"default_out-dnstcp-${index}": |
23 |
} |
24 |
if $dns =~ /:/ { |
25 |
Nftables::Rule["default_out-dnstcp-${index}"] { |
26 |
content => "ip6 daddr ${dns} tcp dport 53 accept", |
27 |
} |
28 |
} else { |
29 |
Nftables::Rule["default_out-dnstcp-${index}"] { |
30 |
content => "ip daddr ${dns} tcp dport 53 accept", |
31 |
} |
32 |
} |
33 |
} |
34 |
} else { |
35 |
nftables::rule { |
36 |
'default_out-dnsudp': |
37 |
content => 'udp dport 53 accept'; |
38 |
'default_out-dnstcp': |
39 |
content => 'tcp dport 53 accept'; |
40 |
} |
41 |
} |
42 |
} |