mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
Firewall Module - Allow Minions to connect to salt
This commit is contained in:
@@ -1,2 +1,2 @@
|
|||||||
minion_ips:
|
minions:
|
||||||
- 127.0.0.1
|
- 127.0.0.1
|
||||||
@@ -52,10 +52,10 @@ enable_reject_policy:
|
|||||||
|
|
||||||
# Rules if you are a Master
|
# Rules if you are a Master
|
||||||
{% if grains['role'] == 'so-master' %}
|
{% if grains['role'] == 'so-master' %}
|
||||||
{% set minions = salt['pillar.get']('firewall.minions', {}) %}
|
|
||||||
{% for ip in minions.get('minion_ips', []) %}
|
|
||||||
|
|
||||||
enable_salt_minions_4505:
|
{% for ip in pillar.get('minions') %}
|
||||||
|
|
||||||
|
enable_salt_minions_4505_{{ip}}:
|
||||||
iptables.append:
|
iptables.append:
|
||||||
- table: filter
|
- table: filter
|
||||||
- chain: INPUT
|
- chain: INPUT
|
||||||
@@ -65,7 +65,7 @@ enable_salt_minions_4505:
|
|||||||
- dport: 4505
|
- dport: 4505
|
||||||
- save: True
|
- save: True
|
||||||
|
|
||||||
enable_salt_minions_4506:
|
enable_salt_minions_4506_{{ip}}:
|
||||||
iptables.append:
|
iptables.append:
|
||||||
- table: filter
|
- table: filter
|
||||||
- chain: INPUT
|
- chain: INPUT
|
||||||
|
|||||||
Reference in New Issue
Block a user