projects
/
mirror
/
dsa-puppet.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
manually create the subchain
[mirror/dsa-puppet.git]
/
modules
/
fail2ban
/
manifests
/
init.pp
diff --git
a/modules/fail2ban/manifests/init.pp
b/modules/fail2ban/manifests/init.pp
index
74a650b
..
81b020e
100644
(file)
--- a/
modules/fail2ban/manifests/init.pp
+++ b/
modules/fail2ban/manifests/init.pp
@@
-19,14
+19,21
@@
class fail2ban {
| EOF
}
| EOF
}
- @ferm::rule { 'dsa-f2b-setup':
+ @ferm::rule { 'dsa-f2b-setup
1
':
prio => '005',
description => 'f2b master rule',
prio => '005',
description => 'f2b master rule',
- chain => '
INPUT
',
+ chain => '
dsa-f2b
',
domain => '(ip ip6)',
domain => '(ip ip6)',
- rule => '
saddr 0/0 @subchain "dsa-f2b" {}
',
+ rule => '',
notarule => true,
}
notarule => true,
}
+ @ferm::rule { 'dsa-f2b-setup2':
+ prio => '005',
+ description => 'f2b master rule',
+ chain => 'INPUT',
+ domain => '(ip ip6)',
+ rule => 'jump dsa-f2b',
+ }
# XXX Maybe this will be automatically done in buster, it is certainly needed in stretch. So maybe: versioncmp($::lsbmajdistrelease, '9') <= 0
concat::fragment { 'dsa-puppet-stuff--fail2ban-cleanup':
# XXX Maybe this will be automatically done in buster, it is certainly needed in stretch. So maybe: versioncmp($::lsbmajdistrelease, '9') <= 0
concat::fragment { 'dsa-puppet-stuff--fail2ban-cleanup':