when "inet6" then "ip6"
end
- proto = case new_resource.proto
- when "udp" then "udp"
- when "tcp", "tcp:syn" then "tcp"
- end
+ proto = new_resource.proto
if new_resource.source_ports
rule << "#{proto} sport { #{nftables_source_ports} }"
rule << "#{ip} daddr { #{addresses} }"
end
- if new_resource.proto == "tcp:syn"
- rule << "ct state new"
- end
+ rule << "ct state new" if new_resource.proto == "tcp"
if new_resource.connection_limit != "-"
set = "connlimit-#{new_resource.rule}-#{ip}"