summaryrefslogtreecommitdiff
path: root/modules/profiles/manifests
diff options
context:
space:
mode:
authorHugo Hörnquist <hugo@hornquist.se>2021-06-29 22:43:52 +0200
committerHugo Hörnquist <hugo@hornquist.se>2021-06-29 22:43:52 +0200
commit916b1f0f97288db063cc8cec23a54d4253940d0d (patch)
tree8c4fcfcc2841b982d4fb65d218642a30084b51f2 /modules/profiles/manifests
parentBlog working. (diff)
downloadwebdav_server-916b1f0f97288db063cc8cec23a54d4253940d0d.tar.gz
webdav_server-916b1f0f97288db063cc8cec23a54d4253940d0d.tar.xz
Firewall.
Diffstat (limited to 'modules/profiles/manifests')
-rw-r--r--modules/profiles/manifests/firewall.pp19
1 files changed, 19 insertions, 0 deletions
diff --git a/modules/profiles/manifests/firewall.pp b/modules/profiles/manifests/firewall.pp
new file mode 100644
index 0000000..6c9d7e6
--- /dev/null
+++ b/modules/profiles/manifests/firewall.pp
@@ -0,0 +1,19 @@
+class profiles::firewall {
+ ensure_packages ([
+ 'iptables-persistent',
+ 'fail2ban',
+ ], { ensure => installed })
+
+ file { '/etc/iptables/rules.v4':
+ source => 'puppet:///modules/profiles/firewall/rules.v4',
+ } ~> exec { 'reload firewall':
+ command => '/usr/share/netfilter-persistent/plugins.d/15-ip4tables restart',
+ refreshonly => true,
+ }
+
+ service { 'fail2ban':
+ ensure => running,
+ enable => true,
+ }
+
+}