diff --git a/fwrules/templates/chains.nft.j2 b/fwrules/templates/chains.nft.j2 index 820d1af..59c898e 100755 --- a/fwrules/templates/chains.nft.j2 +++ b/fwrules/templates/chains.nft.j2 @@ -93,6 +93,10 @@ chain usc2_privnet { ip saddr 10.200.0.0/24 accept } +chain int_privnet { + ip saddr 10.100.0.0/23 accept +} + chain vault_private { define ports_tcp = { 8200, # vault diff --git a/fwrules/templates/firewall.nft.j2 b/fwrules/templates/firewall.nft.j2 index 6247b46..d7b4466 100755 --- a/fwrules/templates/firewall.nft.j2 +++ b/fwrules/templates/firewall.nft.j2 @@ -37,6 +37,8 @@ table inet firewall { jump http_public {%- if datacenter == "usc2" %} jump usc2_privnet + {%- elif datacenter == "int" %} + jump int_privnet {%- endif %} {%- if nodetype == "builder" %} jump concourse_worker