{% load conntrackt %} # iptables rules generated by conntrackt for {{entity}} *filter :INPUT ACCEPT [0:0] {% for interface in entity.interface_set.all %} {% for communication in interface.destination_set.all %} {% ifchanged communication.description %} {% if communication.description %} # {{communication.description}} {% endif %} {% endifchanged %} {% iptables communication %} {% endfor %} {% endfor %} :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [0:0] COMMIT *nat :PREROUTING ACCEPT [0:0] :INPUT ACCEPT [0:0] :OUTPUT ACCEPT [0:0] :POSTROUTING ACCEPT [0:0] COMMIT