From 8e5c279f7cecf29589835e74602155b9afc430d8 Mon Sep 17 00:00:00 2001 From: Christian Pointner Date: Wed, 15 Jun 2022 19:35:36 +0200 Subject: add simple handling for nftable rulesets in base role --- roles/network/nftables/base/defaults/main.yml | 11 +++++++++++ 1 file changed, 11 insertions(+) create mode 100644 roles/network/nftables/base/defaults/main.yml (limited to 'roles/network/nftables/base/defaults') diff --git a/roles/network/nftables/base/defaults/main.yml b/roles/network/nftables/base/defaults/main.yml new file mode 100644 index 00000000..95ec9073 --- /dev/null +++ b/roles/network/nftables/base/defaults/main.yml @@ -0,0 +1,11 @@ +--- +nftables_base_rules: {} + +# nftables_base_rules: +# example: | +# table inet global { +# chain input { +# type filter hook input priority filter; policy drop; +# ct state vmap { established: accept, related: accept, invalid: drop } +# } +# } -- cgit v1.2.3