ansible/roles/firewall/templates/ipset.v6.j2

18 lines
633 B
Django/Jinja

{% macro render_ipset(ipset, name, type="hash:net", family="inet6", timeout=None) %}
create {{ name }} {{ type | default('hash:net') }} family {{ family }} counters {% if timeout %}timeout {{ timeout }}{% endif %} -exist
flush {{ name }}
{% if ipset | length %}
{% for ip_or_net in ipset | ipv6 %}
add {{ name }} {{ ip_or_net }}
{% endfor %}
{% endif %}
{% endmacro %}
{{ render_ipset(firewall_ipset_mgmt, 'mgmt_v6') }}
{{ render_ipset(firewall_ipset_blacklist, 'blacklist_v6') }}
{{ render_ipset(firewall_ipset_bogons, 'bogons_v6') }}
{{ render_ipset([], 'cooloff_v6', type="hash:ip", timeout=firewall_ipset_cooloff_timeout) }}