diff options
author | Thore Bödecker <me@foxxx0.de> | 2019-09-24 16:35:19 +0200 |
---|---|---|
committer | Tim Meusel <tim@bastelfreak.de> | 2019-10-01 15:39:18 +0200 |
commit | 19c71d9abd269d88450f54ddb95e036c804a8fe8 (patch) | |
tree | fe643419b2d7ea32661cec188e88b2dd420bf9fe /spec/acceptance | |
parent | 936d5f7c4b41ae8249f432827370815f2ec88dae (diff) | |
download | puppet-ferm-19c71d9abd269d88450f54ddb95e036c804a8fe8.tar.gz puppet-ferm-19c71d9abd269d88450f54ddb95e036c804a8fe8.tar.bz2 |
disable conntrack filtering in FORWARD/OUTPUT
conntrack filtering basically doesn't work in those chains, so we need
to disable it.
Diffstat (limited to 'spec/acceptance')
-rw-r--r-- | spec/acceptance/ferm_spec.rb | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/spec/acceptance/ferm_spec.rb b/spec/acceptance/ferm_spec.rb index c5018da..f827dc2 100644 --- a/spec/acceptance/ferm_spec.rb +++ b/spec/acceptance/ferm_spec.rb @@ -32,7 +32,7 @@ basic_manifest = %( manage_configfile => true, manage_initfile => #{manage_initfile}, # CentOS-6 does not provide init script forward_policy => 'DROP', - output_policy => 'DROP', + output_policy => 'ACCEPT', input_policy => 'DROP', rules => { 'allow_acceptance_tests' => { @@ -66,7 +66,7 @@ describe 'ferm' do end describe command('iptables-save') do - its(:stdout) { is_expected.to match %r{.*filter.*:INPUT DROP.*:FORWARD DROP.*:OUTPUT DROP.*}m } + its(:stdout) { is_expected.to match %r{.*filter.*:INPUT DROP.*:FORWARD DROP.*:OUTPUT ACCEPT.*}m } end describe iptables do |