class firewall::rules::out::vault ( String $ipset = 'vault', Array[Stdlib::Port] $ports = [8200], ) { $ports.each |$port| { nftables::rule { "default_out-vault_${port}": content => "tcp dport ${port} ip daddr @${ipset} accept", } } }