iptables: fix conditional

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
This commit is contained in:
Kevin Fenzi 2023-08-15 12:23:08 -07:00
parent 5936815f75
commit e524963387

View file

@ -15,7 +15,7 @@
-A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
# if the host is external, block some ips
{% if datacenter != 'iad2' or external == 'true' %}
{% if datacenter != 'iad2' or external %}
-A INPUT -p all -m set --match-set blocklist src -j REJECT
{% endif %}