Allow decapsulated ip6ip6 packets

This commit is contained in:
Patrik Lundin 2024-10-30 09:25:12 +01:00
parent 41298df063
commit 196c1403e6
Signed by: patlu
GPG key ID: A0A812BA2249F294

View file

@ -122,6 +122,9 @@ class cdn::cache(
sunet::nftables::rule { 'sunet_cdn_service4': sunet::nftables::rule { 'sunet_cdn_service4':
rule => 'add rule inet filter input meta iifname tunl0 ip daddr 188.240.152.0/24 tcp dport { 80, 443 } counter accept comment "sunet-cdn-service4"' rule => 'add rule inet filter input meta iifname tunl0 ip daddr 188.240.152.0/24 tcp dport { 80, 443 } counter accept comment "sunet-cdn-service4"'
} }
sunet::nftables::rule { 'sunet_cdn_service6':
rule => 'add rule inet filter input meta iifname ip6tnl0 ip6 daddr 2001:6b0:2100::/48 tcp dport { 80, 443 } counter accept comment "sunet-cdn-service6"'
}
if $cache_secrets { if $cache_secrets {
$customers.each |String $customer, Integer $customer_uid| { $customers.each |String $customer, Integer $customer_uid| {