用于iptables输出链redirect的Puppet语法

使用iptables puppet模块我需要什么语法来允许从本地主机上的端口443到端口8443redirect?

它看起来应该是语法应该是以下,但我不知道如何将其翻译成清单。

iptables -t nat -I OUTPUT -p tcp -d 127.0.0.1 --dport 443 -j REDIRECT --to-ports 8443 

现有的木偶规则:

 firewall { '100 tomcat rewrite 443 to 8443': table => 'nat', chain => 'PREROUTING', jump => 'REDIRECT', proto => 'tcp', dport => '443', toports => '8443', } firewall { '100 allow access to tomcat 8443 https': proto => 'tcp', state => ['NEW'], dport => '8443', action => 'accept', } 

 firewall {'XXX rule': destination => '127.0.0.1', dport => '443', proto => 'tcp', chain => 'OUTPUT', table => 'nat', jump => 'REDIRECT', toports => '8443' }