diff options
Diffstat (limited to 'roles/zone_firewall/templates')
| -rw-r--r-- | roles/zone_firewall/templates/firewall_rules.yml.j2 | 47 | ||||
| -rw-r--r-- | roles/zone_firewall/templates/zones.yml.j2 | 28 |
2 files changed, 75 insertions, 0 deletions
diff --git a/roles/zone_firewall/templates/firewall_rules.yml.j2 b/roles/zone_firewall/templates/firewall_rules.yml.j2 new file mode 100644 index 0000000..0e083f3 --- /dev/null +++ b/roles/zone_firewall/templates/firewall_rules.yml.j2 @@ -0,0 +1,47 @@ +{%- macro rule_family(r) -%} +{%- set addrs = [r.source.address | default('') if r.source is defined and r.source else '', + r.destination.address | default('') if r.destination is defined and r.destination else ''] | select | list -%} +{%- if r.family is defined and r.family -%}{{ r.family }} +{%- elif addrs | select('search', ':') | list -%}ipv6 +{%- elif addrs -%}ipv4 +{%- else -%}both +{%- endif -%} +{%- endmacro -%} +{% for afi in _zone_firewall_families %} +- afi: {{ afi }} + rule_sets: +{% for p in _zone_firewall_policies %} + - name: {{ (p['from'] ~ '-' ~ p['to'] ~ ('-6' if afi == 'ipv6' else '')) | to_json }} + default_action: {{ p.default_action | default('drop') }} + enable_default_log: true + rules: +{% if zone_firewall_base_rules | bool %} + - number: 1 + action: accept + state: {established: true, related: true} + - number: 2 + action: drop + log: enable + state: {invalid: true} +{% endif %} +{% for r in p.rules | default([]) if rule_family(r) in [afi, 'both'] %} + - number: {{ r.number | int }} + action: {{ r.action | default('accept') }} +{% if r.description is defined %} + description: {{ r.description | to_json }} +{% endif %} +{% if r.protocol is defined %} + protocol: {{ ('ipv6-icmp' if (afi == 'ipv6' and r.protocol == 'icmp') else r.protocol) | to_json }} +{% endif %} +{% if r.log | default(zone_firewall_log_rules) | bool %} + log: enable +{% endif %} +{% for side in ['source', 'destination'] if r[side] is defined and r[side] %} + {{ side }}: +{% for k in ['address', 'port'] if r[side][k] is defined %} + {{ k }}: {{ r[side][k] | string | to_json }} +{% endfor %} +{% endfor %} +{% endfor %} +{% endfor %} +{% endfor %} diff --git a/roles/zone_firewall/templates/zones.yml.j2 b/roles/zone_firewall/templates/zones.yml.j2 new file mode 100644 index 0000000..3af0e99 --- /dev/null +++ b/roles/zone_firewall/templates/zones.yml.j2 @@ -0,0 +1,28 @@ +zone: +{% for z in zone_firewall_zones %} + - name: {{ z.name | to_json }} + default_action: {{ z.default_action | default('drop') }} +{% if z.default_log | default(true) | bool %} + default_log: true +{% endif %} +{% if z.description is defined %} + description: {{ z.description | to_json }} +{% endif %} +{% if z.local | default(false) | bool %} + local_zone: true +{% else %} + interfaces: {{ z.interfaces | default([]) | to_json }} +{% endif %} +{% set srcs = _zone_firewall_policies | selectattr('to', 'equalto', z.name) | list %} +{% if srcs %} + sources: +{% for p in srcs %} + - zone: {{ p['from'] | to_json }} + firewall: + name: {{ (p['from'] ~ '-' ~ z.name) | to_json }} +{% if zone_firewall_ipv6 | bool %} + ipv6_name: {{ (p['from'] ~ '-' ~ z.name ~ '-6') | to_json }} +{% endif %} +{% endfor %} +{% endif %} +{% endfor %} |
