diff options
author | Nicolas Fort <nicolasfort1988@gmail.com> | 2023-10-13 14:12:58 +0000 |
---|---|---|
committer | Nicolas Fort <nicolasfort1988@gmail.com> | 2023-10-13 14:12:58 +0000 |
commit | c74ecbaaccde377653d2a9daa07556f3b8f7cd3e (patch) | |
tree | 62688d64183a6d15efa7a1425da6dbd79da89457 /data/templates/firewall/nftables.j2 | |
parent | e65117532b486253e6417c4e0e047a04de767dc3 (diff) | |
download | vyos-1x-c74ecbaaccde377653d2a9daa07556f3b8f7cd3e.tar.gz vyos-1x-c74ecbaaccde377653d2a9daa07556f3b8f7cd3e.zip |
T5541: firewall zone: re add firewall zone-base firewall
Diffstat (limited to 'data/templates/firewall/nftables.j2')
-rw-r--r-- | data/templates/firewall/nftables.j2 | 9 |
1 files changed, 9 insertions, 0 deletions
diff --git a/data/templates/firewall/nftables.j2 b/data/templates/firewall/nftables.j2 index 75800ee3d..af3ade869 100644 --- a/data/templates/firewall/nftables.j2 +++ b/data/templates/firewall/nftables.j2 @@ -3,6 +3,7 @@ {% import 'firewall/nftables-defines.j2' as group_tmpl %} {% import 'firewall/nftables-bridge.j2' as bridge_tmpl %} {% import 'firewall/nftables-offload.j2' as offload_tmpl %} +{% import 'firewall/nftables-zone.j2' as zone_tmpl %} flush chain raw vyos_global_rpfilter flush chain ip6 raw vyos_global_rpfilter @@ -152,6 +153,10 @@ table ip vyos_filter { {% endif %} {% endif %} {{ group_tmpl.groups(group, False, True) }} + +{% if zone is vyos_defined %} +{{ zone_tmpl.zone_chains(zone, False) }} +{% endif %} } {% if first_install is not vyos_defined %} @@ -261,6 +266,9 @@ table ip6 vyos_filter { {% endif %} {% endif %} {{ group_tmpl.groups(group, True, True) }} +{% if zone is vyos_defined %} +{{ zone_tmpl.zone_chains(zone, True) }} +{% endif %} } ## Bridge Firewall @@ -270,4 +278,5 @@ delete table bridge vyos_filter table bridge vyos_filter { {{ bridge_tmpl.bridge(bridge) }} {{ group_tmpl.groups(group, False, False) }} + } |