summaryrefslogtreecommitdiff
path: root/data/templates/firewall/nftables-zone.j2
diff options
context:
space:
mode:
authorNicolas Fort <nicolasfort1988@gmail.com>2024-01-12 13:52:26 +0000
committerNicolas Fort <nicolasfort1988@gmail.com>2024-01-12 13:52:26 +0000
commit5c4c873f9c36459bc7bad73208450ee802440929 (patch)
tree88829b55a0a1eb1ce10d640d69bfd7eed75b79c1 /data/templates/firewall/nftables-zone.j2
parentbc3cf0a0a18ad70448322f90bdb6bf8292b59ccf (diff)
downloadvyos-1x-5c4c873f9c36459bc7bad73208450ee802440929.tar.gz
vyos-1x-5c4c873f9c36459bc7bad73208450ee802440929.zip
T5922: firewall: fix intra-zone filtering parsing rules; update firewall smoketest
Diffstat (limited to 'data/templates/firewall/nftables-zone.j2')
-rw-r--r--data/templates/firewall/nftables-zone.j213
1 files changed, 3 insertions, 10 deletions
diff --git a/data/templates/firewall/nftables-zone.j2 b/data/templates/firewall/nftables-zone.j2
index 5e55099ca..e78725079 100644
--- a/data/templates/firewall/nftables-zone.j2
+++ b/data/templates/firewall/nftables-zone.j2
@@ -1,13 +1,6 @@
-
-{% macro zone_chains(zone, family, state_policy=False) %}
-{% if family == 'ipv6' %}
-{% set fw_name = 'ipv6_name' %}
-{% set suffix = '6' %}
-{% else %}
-{% set fw_name = 'name' %}
-{% set suffix = '' %}
-{% endif %}
-
+{% macro zone_chains(zone, ipv6=False, state_policy=False) %}
+{% set fw_name = 'ipv6_name' if ipv6 else 'name' %}
+{% set suffix = '6' if ipv6 else '' %}
chain VYOS_ZONE_FORWARD {
type filter hook forward priority 1; policy accept;
{% if state_policy %}