firewall: allow connections from master over IPv6

Oops, missed a spot.
This commit is contained in:
Timotej Lazar 2024-12-20 15:18:36 +01:00
parent 1d97ec2cda
commit f57023b0f0

View file

@ -73,7 +73,7 @@ table inet filter {
# allow SSH connections from firewall master’s IPs
{% for iface in hostvars[master].interfaces %}
{% for address in iface.ip_addresses | selectattr('family.value', '==', 4) %}
{% for address in iface.ip_addresses %}
tcp dport ssh {{ 'ip' if address.family.value == 4 else 'ip6' }} saddr {{ address.address | ipaddr('address') }} accept
{% for nat_address in address.nat_outside %}
tcp dport ssh ip saddr {{ nat_address.address | ipaddr('address') }} accept