diff options
author | Micah Anderson <micah@leap.se> | 2013-09-04 22:46:56 -0400 |
---|---|---|
committer | Micah Anderson <micah@leap.se> | 2013-09-04 22:46:56 -0400 |
commit | f9ee40f2fca2396c1ef7d85a9c44b97fe834671a (patch) | |
tree | 042007ee145e33e4083784bdb11f333858b6613b /puppet | |
parent | c8488a381071aba3ebe88f8b84185d7b6ad8a625 (diff) |
fix initial firewall to allow outgoing lo traffic and outgoing port 443 (#3736)
this allows nameserver queries to the local resolver to work and clones to the
leap https repository to work
Change-Id: I575d08405a0c28e12c8d201a8dbc79585a5a9a48
Diffstat (limited to 'puppet')
-rw-r--r-- | puppet/modules/site_config/templates/ipv4firewall_up.rules.erb | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/puppet/modules/site_config/templates/ipv4firewall_up.rules.erb b/puppet/modules/site_config/templates/ipv4firewall_up.rules.erb index c03716f3..524ae308 100644 --- a/puppet/modules/site_config/templates/ipv4firewall_up.rules.erb +++ b/puppet/modules/site_config/templates/ipv4firewall_up.rules.erb @@ -10,10 +10,12 @@ -A INPUT -p icmp -m icmp --icmp-type 8 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT -A INPUT -p icmp -m icmp --icmp-type 0 -m state --state RELATED,ESTABLISHED -j ACCEPT -A INPUT -m limit --limit 5/min -j LOG --log-prefix "iptables denied: " --log-level 7 +-A OUTPUT -o lo -j ACCEPT -A OUTPUT -p icmp -m icmp --icmp-type 0 -m state --state RELATED,ESTABLISHED -j ACCEPT -A OUTPUT -p icmp -m icmp --icmp-type 8 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT -A OUTPUT -p tcp -m state --state NEW,ESTABLISHED --sport <%= @ssh_port %> -j ACCEPT -A OUTPUT -p tcp -m state --state NEW,ESTABLISHED --dport 80 -j ACCEPT +-A OUTPUT -p tcp -m state --state NEW,ESTABLISHED --dport 443 -j ACCEPT -A OUTPUT -p udp -m udp --dport 53 -j ACCEPT -A OUTPUT -p udp -m udp --dport 123 -j ACCEPT -A OUTPUT -m limit --limit 5/min -j LOG --log-prefix "iptables denied: " --log-level 7 |