diff options
author | Niklas Yann Wettengel <niyawe@niyawe.de> | 2018-05-02 13:57:37 +0200 |
---|---|---|
committer | Niklas Yann Wettengel <niyawe@niyawe.de> | 2018-05-02 13:57:37 +0200 |
commit | dfc02c3178f0075adf671d7450c71c1b75f67b93 (patch) | |
tree | 051fd0c640398d171f8b9b04e5c9756f5068abdf /roles/configure_iptables/templates/ip6tables.rules | |
parent | c17cedcf1bb78b21c06837e46bf23451f7738026 (diff) |
babel mesh between uplinks
Diffstat (limited to 'roles/configure_iptables/templates/ip6tables.rules')
-rw-r--r-- | roles/configure_iptables/templates/ip6tables.rules | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/roles/configure_iptables/templates/ip6tables.rules b/roles/configure_iptables/templates/ip6tables.rules index bee7c48..8ee9f91 100644 --- a/roles/configure_iptables/templates/ip6tables.rules +++ b/roles/configure_iptables/templates/ip6tables.rules @@ -19,6 +19,9 @@ {% for peer in groups['fastd'] %} -A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} ! -s fe80::/64 ! -d fe80::/64 -j MARK --set-xmark 0x1/0xffffffff {% endfor %} +{% for peer in groups['uplink'] | difference([inventory_hostname]) %} +-A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} ! -s fe80::/64 ! -d fe80::/64 -j MARK --set-xmark 0x1/0xffffffff +{% endfor %} {% endif %} COMMIT *filter @@ -65,6 +68,10 @@ COMMIT -A INPUT -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -p udp --dport 6696 -j ACCEPT -A INPUT -p udp --dport {{ hostvars[peer]['wireguard_bb_port'] }} -j ACCEPT {% endfor %} +{% for peer in groups['uplink'] | difference([inventory_hostname]) %} +-A INPUT -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -p udp --dport 6696 -j ACCEPT +-A INPUT -p udp --dport {{ hostvars[peer]['wireguard_bb_port'] }} -j ACCEPT +{% endfor %} {% for peer in wireguard_bb_peers|default([]) %} -A INPUT -i bb{{ peer.name }} -p udp --dport 6696 -j ACCEPT -A INPUT -p udp --dport {{ peer.port }} -j ACCEPT |