diff options
author | Micah Anderson <micah@leap.se> | 2013-08-20 19:45:56 -0400 |
---|---|---|
committer | Micah Anderson <micah@leap.se> | 2013-08-22 09:43:20 -0400 |
commit | 3cdebf3ebe73cb2859dc852dcc73a8ee2d60e976 (patch) | |
tree | 12ff5dd71a6fab4977abd5587cc949bca2493183 /puppet/modules/site_config/templates/ipv6firewall_up.rules.erb | |
parent | 5229fc7ffc3e804b788b3d25042514806f9a4e9b (diff) |
install a preliminary firewall that blocks everything, except ssh for the cases when shorewall doesn't properly come up, ensuring that it fails safe (#3339)
Change-Id: Id4f0bf6cf25f420aa2ad67635b37ae95f54e3d38
Diffstat (limited to 'puppet/modules/site_config/templates/ipv6firewall_up.rules.erb')
-rw-r--r-- | puppet/modules/site_config/templates/ipv6firewall_up.rules.erb | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/puppet/modules/site_config/templates/ipv6firewall_up.rules.erb b/puppet/modules/site_config/templates/ipv6firewall_up.rules.erb new file mode 100644 index 00000000..e7fae52e --- /dev/null +++ b/puppet/modules/site_config/templates/ipv6firewall_up.rules.erb @@ -0,0 +1,7 @@ +# Generated by ip6tables-save v1.4.20 on Tue Aug 20 12:19:43 2013 +*filter +:INPUT DROP [24:1980] +:FORWARD DROP [0:0] +:OUTPUT DROP [14:8030] +COMMIT +# Completed on Tue Aug 20 12:19:43 2013 |