diff options
author | Hugo Hörnquist <hugo@hornquist.se> | 2021-06-29 22:43:52 +0200 |
---|---|---|
committer | Hugo Hörnquist <hugo@hornquist.se> | 2021-06-29 22:43:52 +0200 |
commit | 916b1f0f97288db063cc8cec23a54d4253940d0d (patch) | |
tree | 8c4fcfcc2841b982d4fb65d218642a30084b51f2 /modules/profiles/manifests | |
parent | Blog working. (diff) | |
download | webdav_server-916b1f0f97288db063cc8cec23a54d4253940d0d.tar.gz webdav_server-916b1f0f97288db063cc8cec23a54d4253940d0d.tar.xz |
Firewall.
Diffstat (limited to 'modules/profiles/manifests')
-rw-r--r-- | modules/profiles/manifests/firewall.pp | 19 |
1 files changed, 19 insertions, 0 deletions
diff --git a/modules/profiles/manifests/firewall.pp b/modules/profiles/manifests/firewall.pp new file mode 100644 index 0000000..6c9d7e6 --- /dev/null +++ b/modules/profiles/manifests/firewall.pp @@ -0,0 +1,19 @@ +class profiles::firewall { + ensure_packages ([ + 'iptables-persistent', + 'fail2ban', + ], { ensure => installed }) + + file { '/etc/iptables/rules.v4': + source => 'puppet:///modules/profiles/firewall/rules.v4', + } ~> exec { 'reload firewall': + command => '/usr/share/netfilter-persistent/plugins.d/15-ip4tables restart', + refreshonly => true, + } + + service { 'fail2ban': + ensure => running, + enable => true, + } + +} |