From 25ee5c21273774a790bbf019ce95eb6b1e73f6d6 Mon Sep 17 00:00:00 2001 From: Egor Tensin Date: Wed, 6 Mar 2024 09:27:43 +0100 Subject: firewall: align directives --- roles/firewall/templates/rules.v4.j2 | 2 +- roles/firewall/templates/rules.v6.j2 | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/roles/firewall/templates/rules.v4.j2 b/roles/firewall/templates/rules.v4.j2 index 1bfeb94..ff77f59 100644 --- a/roles/firewall/templates/rules.v4.j2 +++ b/roles/firewall/templates/rules.v4.j2 @@ -12,7 +12,7 @@ -A INPUT -i lo -j ACCEPT # Accept any packet for an open connection: --A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT +-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT # The SSH port is always open: diff --git a/roles/firewall/templates/rules.v6.j2 b/roles/firewall/templates/rules.v6.j2 index 2e94e25..5e46ce1 100644 --- a/roles/firewall/templates/rules.v6.j2 +++ b/roles/firewall/templates/rules.v6.j2 @@ -12,7 +12,7 @@ -A INPUT -i lo -j ACCEPT # Accept any packet for an open connection: --A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT +-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT # The SSH port is always open: @@ -49,10 +49,10 @@ # # https://github.com/trailofbits/algo/blob/master/roles/common/templates/rules.v6.j2 # --A INPUT -p icmpv6 --icmpv6-type router-advertisement -m hl --hl-eq 255 -j ACCEPT --A INPUT -p icmpv6 --icmpv6-type neighbor-solicitation -m hl --hl-eq 255 -j ACCEPT +-A INPUT -p icmpv6 --icmpv6-type router-advertisement -m hl --hl-eq 255 -j ACCEPT +-A INPUT -p icmpv6 --icmpv6-type neighbor-solicitation -m hl --hl-eq 255 -j ACCEPT -A INPUT -p icmpv6 --icmpv6-type neighbor-advertisement -m hl --hl-eq 255 -j ACCEPT --A INPUT -p icmpv6 --icmpv6-type redirect -m hl --hl-eq 255 -j ACCEPT +-A INPUT -p icmpv6 --icmpv6-type redirect -m hl --hl-eq 255 -j ACCEPT # Log denies (this must be at the bottom of the file): -A INPUT -m limit --limit 3/min -j LOG --log-prefix "iptables denied: " --log-level 4 -- cgit v1.2.3