3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
|
# File 'manifests/pre.pp', line 3
class iptables::pre {
Firewall {
require => undef,
}
firewall { '001 accept related established rules':
proto => 'all',
state => ['RELATED', 'ESTABLISHED'],
action => 'accept',
}
firewall { '001 accept related established rules in forward':
proto => 'all',
state => ['RELATED', 'ESTABLISHED'],
action => 'accept',
chain => 'FORWARD',
}
firewall { '002 accept all icmp':
proto => 'icmp',
action => 'accept',
}
firewall { '003 accept all to lo interface':
proto => 'all',
iniface => 'lo',
action => 'accept',
}
firewall { '004 accept inbound ssh':
dport => 22,
proto => 'tcp',
action => 'accept',
}
firewall { '001 accept related established rules v6':
proto => 'all',
state => ['RELATED', 'ESTABLISHED'],
action => 'accept',
provider => 'ip6tables',
}
firewall { '002 accept all icmp v6':
proto => 'ipv6-icmp',
action => 'accept',
provider => 'ip6tables',
}
firewall { '003 accept all to lo interface v6':
proto => 'all',
iniface => 'lo',
action => 'accept',
provider => 'ip6tables',
}
firewall { '004 accept inbound ssh v6':
dport => 22,
proto => 'tcp',
action => 'accept',
provider => 'ip6tables',
}
}
|