Projet

Général

Profil

Paste
Télécharger au format
Statistiques
| Branche: | Révision:

root / manifests / rules / out / dns.pp @ ea29e235

Historique | Voir | Annoter | Télécharger (1,14 ko)

1
# @summary manage out dns
2
# @param dns_server specify dns_server name
3
class nftables::rules::out::dns (
4
  Optional[Variant[String,Array[String,1]]] $dns_server = undef,
5
) {
6
  if $dns_server {
7
    any2array($dns_server).each |$index,$dns| {
8
      nftables::rule {
9
        "default_out-dnsudp-${index}":
10
      }
11
      if $dns =~ /:/ {
12
        Nftables::Rule["default_out-dnsudp-${index}"] {
13
          content => "ip6 daddr ${dns} udp dport 53 accept",
14
        }
15
      } else {
16
        Nftables::Rule["default_out-dnsudp-${index}"] {
17
          content => "ip daddr ${dns} udp dport 53 accept",
18
        }
19
      }
20

    
21
      nftables::rule {
22
        "default_out-dnstcp-${index}":
23
      }
24
      if $dns =~ /:/ {
25
        Nftables::Rule["default_out-dnstcp-${index}"] {
26
          content => "ip6 daddr ${dns} tcp dport 53 accept",
27
        }
28
      } else {
29
        Nftables::Rule["default_out-dnstcp-${index}"] {
30
          content => "ip daddr ${dns} tcp dport 53 accept",
31
        }
32
      }
33
    }
34
  } else {
35
    nftables::rule {
36
      'default_out-dnsudp':
37
        content => 'udp dport 53 accept';
38
      'default_out-dnstcp':
39
        content => 'tcp dport 53 accept';
40
    }
41
  }
42
}