|
|
|
@ -4,9 +4,9 @@ table inet forward {
|
|
|
|
|
|
|
|
|
|
chain conntrack {
|
|
|
|
|
ct state vmap {
|
|
|
|
|
established: counter accept,
|
|
|
|
|
related: counter accept,
|
|
|
|
|
invalid: counter drop,
|
|
|
|
|
established: accept,
|
|
|
|
|
related: accept,
|
|
|
|
|
invalid: drop,
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
@ -27,11 +27,11 @@ table inet forward {
|
|
|
|
|
udp dport 514 counter accept
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
ip6 saddr $prom_infra_v6 tcp dport 9100 counter accept
|
|
|
|
|
ip saddr $prom_infra_v4 udp dport 161 counter accept
|
|
|
|
|
ip6 saddr $prom_infra_ipv6 tcp dport 9100 counter accept
|
|
|
|
|
ip saddr $prom_infra_ipv4 udp dport 161 counter accept
|
|
|
|
|
|
|
|
|
|
ip6 saddr $bastion_ipv6 dport ssh accept
|
|
|
|
|
ip saddr $bastion_ipv4 dport ssh accept
|
|
|
|
|
ip6 saddr $bastion_ipv6 tcp dport ssh accept
|
|
|
|
|
ip saddr $bastion_ipv4 tcp dport ssh accept
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
chain forward_to_backbone {
|
|
|
|
@ -40,21 +40,21 @@ table inet forward {
|
|
|
|
|
chain forward_to_ups {
|
|
|
|
|
jump conntrack
|
|
|
|
|
|
|
|
|
|
ip6 saddr $prom_infra_v6 udp dport 161 counter accept
|
|
|
|
|
ip saddr $prom_infra_v4 udp dport 161 counter accept
|
|
|
|
|
ip6 saddr $prom_infra_ipv6 udp dport 161 counter accept
|
|
|
|
|
ip saddr $prom_infra_ipv4 udp dport 161 counter accept
|
|
|
|
|
|
|
|
|
|
ip6 saddr $bastion_ipv6 dport ssh accept
|
|
|
|
|
ip saddr $bastion_ipv4 dport ssh accept
|
|
|
|
|
ip6 saddr $bastion_ipv6 tcp dport ssh accept
|
|
|
|
|
ip saddr $bastion_ipv4 tcp dport ssh accept
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
chain forward_to_bmc {
|
|
|
|
|
jump conntrack
|
|
|
|
|
|
|
|
|
|
ip6 saddr $prom_infra_v6 udp dport 161 counter accept
|
|
|
|
|
ip saddr $prom_infra_v4 udp dport 161 counter accept
|
|
|
|
|
ip6 saddr $prom_infra_ipv6 udp dport 161 counter accept
|
|
|
|
|
ip saddr $prom_infra_ipv4 udp dport 161 counter accept
|
|
|
|
|
|
|
|
|
|
ip6 saddr $bastion_ipv6 dport ssh accept
|
|
|
|
|
ip saddr $bastion_ipv4 dport ssh accept
|
|
|
|
|
ip6 saddr $bastion_ipv6 tcp dport ssh accept
|
|
|
|
|
ip saddr $bastion_ipv4 tcp dport ssh accept
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
chain forward_to_pve {
|
|
|
|
@ -63,8 +63,8 @@ table inet forward {
|
|
|
|
|
ip6 saddr $prom_infra_ipv6 tcp dport 9100 counter accept
|
|
|
|
|
ip saddr $prom_infra_ipv4 tcp dport 9100 counter accept
|
|
|
|
|
|
|
|
|
|
ip6 saddr $bastion_ipv6 dport ssh accept
|
|
|
|
|
ip saddr $bastion_ipv4 dport ssh accept
|
|
|
|
|
ip6 saddr $bastion_ipv6 tcp dport ssh accept
|
|
|
|
|
ip saddr $bastion_ipv4 tcp dport ssh accept
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
chain forward_to_router {
|
|
|
|
@ -73,8 +73,8 @@ table inet forward {
|
|
|
|
|
ip6 saddr $prom_infra_ipv6 tcp dport 9100 counter accept
|
|
|
|
|
ip saddr $prom_infra_ipv4 tcp dport 9100 counter accept
|
|
|
|
|
|
|
|
|
|
ip6 saddr $bastion_ipv6 dport ssh accept
|
|
|
|
|
ip saddr $bastion_ipv4 dport ssh accept
|
|
|
|
|
ip6 saddr $bastion_ipv6 tcp dport ssh accept
|
|
|
|
|
ip saddr $bastion_ipv4 tcp dport ssh accept
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
chain forward_to_internet {
|
|
|
|
|