summaryrefslogtreecommitdiff
path: root/manifests
diff options
context:
space:
mode:
authorHugo Hörnquist <hugo@hornquist.se>2021-06-29 22:43:52 +0200
committerHugo Hörnquist <hugo@hornquist.se>2021-06-29 22:43:52 +0200
commit2a079dc90f6e67e2124ea8dada3fcd4c5d539da7 (patch)
tree9f194ed534bff63d99baf7d7fd8d440d9461bb05 /manifests
downloadprofiles-2a079dc90f6e67e2124ea8dada3fcd4c5d539da7.tar.gz
profiles-2a079dc90f6e67e2124ea8dada3fcd4c5d539da7.tar.xz
Firewall.
Diffstat (limited to 'manifests')
-rw-r--r--manifests/firewall.pp19
1 files changed, 19 insertions, 0 deletions
diff --git a/manifests/firewall.pp b/manifests/firewall.pp
new file mode 100644
index 0000000..6c9d7e6
--- /dev/null
+++ b/manifests/firewall.pp
@@ -0,0 +1,19 @@
+class profiles::firewall {
+ ensure_packages ([
+ 'iptables-persistent',
+ 'fail2ban',
+ ], { ensure => installed })
+
+ file { '/etc/iptables/rules.v4':
+ source => 'puppet:///modules/profiles/firewall/rules.v4',
+ } ~> exec { 'reload firewall':
+ command => '/usr/share/netfilter-persistent/plugins.d/15-ip4tables restart',
+ refreshonly => true,
+ }
+
+ service { 'fail2ban':
+ ensure => running,
+ enable => true,
+ }
+
+}