Firewall Module - Fix Rules

This commit is contained in:
Mike Reeves
2018-07-10 16:11:31 -04:00
parent 27f7aa779d
commit bac651e0e6
2 changed files with 10 additions and 13 deletions

View File

@@ -50,11 +50,16 @@ enable_reject_policy:
- iptables: iptables_allow_ssh
- iptables: iptables_allow_pings
# Delete the RETURN rule
del_return_rule:
iptables.delete:
# Enable global DOCKER-USER block rule
enable_docker_user_fw_policy:
iptables.insert:
- table: filter
- chain: DOCKER-USER
- jump: RETURN
- jump: DROP
- in-interface: '!docker0'
- out-interface: docker0
- position: 1
- save: true
# Rules if you are a Master
{% if grains['role'] == 'so-master' %}
@@ -154,11 +159,4 @@ enable_standard_beats_5044_{{ip}}:
# Rules if you are a Warm Node
# Some Fixer upper type rules
# Enable global DOCKER-USER block rule
enable_docker_user_fw_policy:
iptables.append:
- table: filter
- chain: DOCKER-USER
- jump: DROP
# Some Fixer upper type rules

View File

@@ -21,4 +21,3 @@ health:
threshold: 3
proxy:
remoteurl: https://registry-1.docker.io