summaryrefslogtreecommitdiff
path: root/roles/firewall/templates
diff options
context:
space:
mode:
authoromnom62 <omnom62@outlook.com>2026-10-05 20:56:05 +1000
committeromnom62 <omnom62@outlook.com>2026-10-05 20:56:05 +1000
commit8ee802e41374942965b6b93cfb4534725ef45145 (patch)
treeef3e5579bd767422caa6fe77cea6a7b5d2d8562c /roles/firewall/templates
parent748df2bc1d35fa285dd3fe46916e1230408778c7 (diff)
downloadvyos.blueprints-main.tar.gz
vyos.blueprints-main.zip
T9393: new rolesmain
Diffstat (limited to 'roles/firewall/templates')
-rw-r--r--roles/firewall/templates/groups.yml.j242
-rw-r--r--roles/firewall/templates/rules.yml.j217
2 files changed, 59 insertions, 0 deletions
diff --git a/roles/firewall/templates/groups.yml.j2 b/roles/firewall/templates/groups.yml.j2
new file mode 100644
index 0000000..5641e2a
--- /dev/null
+++ b/roles/firewall/templates/groups.yml.j2
@@ -0,0 +1,42 @@
+group:
+{% if firewall_groups.network | default([]) %}
+ network_group:
+{% for g in firewall_groups.network %}
+ - name: {{ g.name | to_json }}
+ afi: ipv4
+{% if g.description is defined %}
+ description: {{ g.description | to_json }}
+{% endif %}
+ members:
+{% for n in g.networks %}
+ - address: {{ n | to_json }}
+{% endfor %}
+{% endfor %}
+{% endif %}
+{% if firewall_groups.address | default([]) %}
+ address_group:
+{% for g in firewall_groups.address %}
+ - name: {{ g.name | to_json }}
+ afi: ipv4
+{% if g.description is defined %}
+ description: {{ g.description | to_json }}
+{% endif %}
+ members:
+{% for a in g.addresses %}
+ - address: {{ a | to_json }}
+{% endfor %}
+{% endfor %}
+{% endif %}
+{% if firewall_groups.port | default([]) %}
+ port_group:
+{% for g in firewall_groups.port %}
+ - name: {{ g.name | to_json }}
+{% if g.description is defined %}
+ description: {{ g.description | to_json }}
+{% endif %}
+ members:
+{% for p in g.ports %}
+ - port: {{ p | string | to_json }}
+{% endfor %}
+{% endfor %}
+{% endif %}
diff --git a/roles/firewall/templates/rules.yml.j2 b/roles/firewall/templates/rules.yml.j2
new file mode 100644
index 0000000..f746c84
--- /dev/null
+++ b/roles/firewall/templates/rules.yml.j2
@@ -0,0 +1,17 @@
+{% for afi, filters in [('ipv4', firewall_ipv4), ('ipv6', firewall_ipv6)] if filters %}
+- afi: {{ afi }}
+ rule_sets:
+{% for chain in _firewall_filters if filters[chain] is defined and filters[chain] %}
+{% set f = filters[chain] %}
+ - filter: {{ chain }}
+{% if f.default_action is defined %}
+ default_action: {{ f.default_action }}
+{% endif %}
+{% if f.default_log | default(false) | bool %}
+ enable_default_log: true
+{% endif %}
+{% if f.rules | default([]) %}
+ rules: {{ f.rules | to_json }}
+{% endif %}
+{% endfor %}
+{% endfor %}