Add nftables rule for ip6tnl packets
This commit is contained in:
parent
bd055b1ac8
commit
0b3e9c48ff
|
@ -91,11 +91,16 @@ class cdn::cache(
|
|||
refreshonly => true,
|
||||
}
|
||||
|
||||
# Allow tunnel packets arriving from l4lb nodes
|
||||
# Allow IPv4 tunnel packets arriving from l4lb nodes
|
||||
sunet::nftables::rule { 'sunet_cdn_tunnel4':
|
||||
rule => 'add rule inet filter input ip saddr { 130.242.64.233, 130.242.64.235 } ip protocol ipencap counter accept comment "sunet-cdn-tunnel4"'
|
||||
}
|
||||
|
||||
# Allow IPv6 tunnel packets arriving from l4lb nodes
|
||||
sunet::nftables::rule { 'sunet_cdn_tunnel4':
|
||||
rule => 'add rule inet filter input ip6 saddr { 2001:6b0:2006:74::1, 2001:6b0:2006:75::1 } ip6 nexthdr ipv6 counter accept comment "sunet-cdn-tunnel6"'
|
||||
}
|
||||
|
||||
# Allow decapsulated tunnel packets targeting the service IP range to reach
|
||||
# local service ports
|
||||
sunet::nftables::rule { 'sunet_cdn_service4':
|
||||
|
|
Loading…
Reference in a new issue