diff options
author | Fabien COMBERNOUS <Dan33l@users.noreply.github.com> | 2019-10-29 15:46:19 +0100 |
---|---|---|
committer | GitHub <noreply@github.com> | 2019-10-29 15:46:19 +0100 |
commit | 051451183fac7ef3950a413f0a40ca5fdcb9cbd6 (patch) | |
tree | 95a274f3a94d327e882467b88d40994067784ed8 | |
parent | 10115d3f0409eb5d36ddeb45d772f29ffeb97e96 (diff) | |
parent | 78841a0852cb77e30c41aaf72cc672e736895f67 (diff) | |
download | puppet-ferm-051451183fac7ef3950a413f0a40ca5fdcb9cbd6.tar.gz puppet-ferm-051451183fac7ef3950a413f0a40ca5fdcb9cbd6.tar.bz2 |
Merge pull request #88 from Dan33l/revert-pr81
revert PR81
-rw-r--r-- | manifests/config.pp | 4 | ||||
-rw-r--r-- | spec/acceptance/ferm_spec.rb | 4 |
2 files changed, 4 insertions, 4 deletions
diff --git a/manifests/config.pp b/manifests/config.pp index 16ecd9e..7dae7a5 100644 --- a/manifests/config.pp +++ b/manifests/config.pp @@ -49,12 +49,12 @@ class ferm::config { } ferm::chain{'FORWARD': policy => $ferm::forward_policy, - disable_conntrack => true, + disable_conntrack => $ferm::disable_conntrack, log_dropped_packets => $ferm::forward_log_dropped_packets, } ferm::chain{'OUTPUT': policy => $ferm::output_policy, - disable_conntrack => true, + disable_conntrack => $ferm::disable_conntrack, log_dropped_packets => $ferm::output_log_dropped_packets, } diff --git a/spec/acceptance/ferm_spec.rb b/spec/acceptance/ferm_spec.rb index f827dc2..c5018da 100644 --- a/spec/acceptance/ferm_spec.rb +++ b/spec/acceptance/ferm_spec.rb @@ -32,7 +32,7 @@ basic_manifest = %( manage_configfile => true, manage_initfile => #{manage_initfile}, # CentOS-6 does not provide init script forward_policy => 'DROP', - output_policy => 'ACCEPT', + output_policy => 'DROP', input_policy => 'DROP', rules => { 'allow_acceptance_tests' => { @@ -66,7 +66,7 @@ describe 'ferm' do end describe command('iptables-save') do - its(:stdout) { is_expected.to match %r{.*filter.*:INPUT DROP.*:FORWARD DROP.*:OUTPUT ACCEPT.*}m } + its(:stdout) { is_expected.to match %r{.*filter.*:INPUT DROP.*:FORWARD DROP.*:OUTPUT DROP.*}m } end describe iptables do |