Initial Chef repository
This commit is contained in:
1
cookbooks/firewall/attributes/default.rb
Normal file
1
cookbooks/firewall/attributes/default.rb
Normal file
@@ -0,0 +1 @@
|
||||
default['firewall']['allow_ssh'] = false
|
||||
12
cookbooks/firewall/attributes/ufw.rb
Normal file
12
cookbooks/firewall/attributes/ufw.rb
Normal file
@@ -0,0 +1,12 @@
|
||||
default['firewall']['ufw']['defaults'] = {
|
||||
:ipv6 => 'yes',
|
||||
:manage_builtins => 'no',
|
||||
:ipt_sysctl => '/etc/ufw/sysctl.conf',
|
||||
:ipt_modules => 'nf_conntrack_ftp nf_nat_ftp nf_conntrack_netbios_ns',
|
||||
:policy => {
|
||||
:input => 'DROP',
|
||||
:output => 'ACCEPT',
|
||||
:forward => 'DROP',
|
||||
:application => 'SKIP'
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user