Skip to content

Commit c597268

Browse files
author
David Vølker
committed
firewall: T7452: update rule generation for Zone-based firewall
1 parent 5724001 commit c597268

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

data/templates/firewall/nftables-zone.j2

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@
1313
{% endif %}
1414
{% if 'vrf' in zone_conf.member %}
1515
{% for vrf_name in zone_conf.member.vrf %}
16-
oifname { {{ zone_conf['vrf_interfaces'][vrf_name] }} } counter jump VZONE_{{ zone_name }}
16+
oifname { {{ zone[from_zone].member.vrf | join(",") }} } counter jump VZONE_{{ zone_name }}
1717
{% endfor %}
1818
{% endif %}
1919
{% endif %}
@@ -70,8 +70,8 @@
7070
{% endif %}
7171
{% if 'vrf' in zone[from_zone].member %}
7272
{% for vrf_name in zone[from_zone].member.vrf %}
73-
oifname { {{ zone[from_zone]['vrf_interfaces'][vrf_name] }} } counter jump NAME{{ suffix }}_{{ from_conf.firewall[fw_name] }}
74-
oifname { {{ zone[from_zone]['vrf_interfaces'][vrf_name] }} } counter return
73+
oifname { {{ zone[from_zone].member.vrf | join(",") }} } counter jump NAME{{ suffix }}_{{ from_conf.firewall[fw_name] }}
74+
oifname { {{ zone[from_zone].member.vrf | join(",") }} }} } counter return
7575
{% endfor %}
7676
{% endif %}
7777
{% endfor %}
@@ -112,4 +112,4 @@
112112
}
113113
{% endif %}
114114
{% endfor %}
115-
{% endmacro %}
115+
{% endmacro %}

0 commit comments

Comments
 (0)