aboutsummaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2019-12-22modulesync 2.10.0Tim Meusel
2019-12-09Merge pull request #91 from voxpupuli/modulesyncTim Meusel
modulesync 2.9.0
2019-12-06modulesync 2.9.0Dennis Hoppe
2019-10-29[blacksmith] Bump version to 2.7.1-rc0Fabien COMBERNOUS
2019-10-29Merge pull request #89 from Dan33l/release_2.7.0Fabien COMBERNOUS
release 2.7.0
2019-10-29release 2.7.0Fabien COMBERNOUS
2019-10-29Merge pull request #88 from Dan33l/revert-pr81Fabien COMBERNOUS
revert PR81
2019-10-29revert PR81Fabien COMBERNOUS
2019-10-08[blacksmith] Bump version to 2.6.1-rc0Tim Meusel
2019-10-08Merge pull request #86 from bastelfreak/rel260Tim Meusel
release 2.6.0
2019-10-08release 2.6.0Tim Meusel
2019-10-08Merge pull request #85 from bastelfreak/bugfixTim Meusel
ipset: allow multiple instances of defined resource
2019-10-08ipset: allow multiple instances of defined resourceTim Meusel
2019-10-01Merge pull request #80 from bastelfreak/ipsetsTim Meusel
implement ipset support
2019-10-01implement ipset supportTim Meusel
2019-10-01Merge pull request #84 from bastelfreak/docs4Tim Meusel
update docker firewalling example
2019-10-01Merge pull request #81 from bastelfreak/hotifxTim Meusel
disable conntrack filtering in FORWARD/OUTPUT
2019-10-01update docker firewalling exampleTim Meusel
2019-10-01disable conntrack filtering in FORWARD/OUTPUTThore Bödecker
conntrack filtering basically doesn't work in those chains, so we need to disable it.
2019-10-01Merge pull request #83 from bastelfreak/docs3Tim Meusel
delete legacy docs/ folder
2019-10-01delete legacy docs/ folderTim Meusel
We now have a REFERENCE.md in the repository. We don't need the docs/ folder anymore.
2019-09-21Merge pull request #75 from Dan33l/move_common_initTim Meusel
move common from hiera data values to init.pp
2019-09-18move common from hiera data values to init.ppFabien COMBERNOUS
2019-09-13[blacksmith] Bump version to 2.5.1-rc0Tim Meusel
2019-09-13Merge pull request #70 from Dan33l/release-2.5.0Tim Meusel
release 2.5.0
2019-09-13release 2.5.0Fabien COMBERNOUS
2019-09-13Merge pull request #73 from foxxx0/add-more-examplesFabien COMBERNOUS
Add more examples
2019-09-13Merge pull request #72 from foxxx0/fix-kernel-incompatibilitiesTim Meusel
fix kernel incompatibilities
2019-09-13add conntrack/NOTRACK exampleThore Bödecker
2019-09-13fix kernel incompatibilitiesThore Bödecker
Certain kernel modules and thus iptables functionality was introduced at later releases, so we need to properly reflect that in our default chain initialization procedure. `INPUT` chain for `nat` table was introduced with 2.6.36 `ip6table_nat` kernel module for NAT functionality with IPv6 was introduced with 3.17 This commit implements the required conditional constraints and includes the rspec tests to validate it.
2019-09-13Merge pull request #71 from bastelfreak/docs2Tim Meusel
enhance puppet-strings documentation
2019-09-13enhance puppet-strings documentationTim Meusel
2019-09-12Merge pull request #69 from bastelfreak/debianFabien COMBERNOUS
readd Debian 9/10 support
2019-09-12readd Debian 9/10 supportTim Meusel
2019-09-12Merge pull request #68 from foxxx0/collect-chains-from-hieraTim Meusel
expose parameter to initialize custom chains
2019-09-12Merge pull request #67 from foxxx0/allow-proto-arrayTim Meusel
allow using an array for $proto
2019-09-11expose parameter to initialize custom chainsThore Bödecker
Previously it was not possible to define custom chains with parameter, e.g. in order to collect them from hiera. This commit adds this functionality, just like it was already in place for ferm::rules.
2019-09-11allow using an array for $protoThore Bödecker
This enables defining ferm::rule with multiple protocols at once, because using 'all' for $proto does not allow using $dport/$sport.
2019-09-11Merge pull request #58 from voxpupuli/multi-table-supportTim Meusel
add ability to configure rules in tables other than the default "filter" table
2019-09-11add ability to define rules in tables != filterThore Bödecker
Previously it was neither possible to properly define custom chains nor to define rules in tables other than the default filter table. For various legitimate reasons it can be required to define rules in the raw, nat or mangle tables, e.g. to use NOTRACK or to configure DNAT/SNAT/MASQUERADE. Additionally it might come in handy to define custom chains to group certain rules and allow a more efficient evaluation for incoming packets by not cramming all rules into the filter/INPUT chain so that (worst-case) all packets need to traverse and evaluate all rules. I have tried to maintain backwards compatibility and to not change default filenames/paths so that it won't result in leftover obsolete unmaged files from previous versions of this module. In order to improve the naming schema the rule $policy has been renamed to $action, however both parameters are available and optional now, with some sanity checks that require at most one of them and issueing a warning() for users of the now deprecated $policy parameter. All previous tests have been adapted to the changes, a long with an additional set of tests for the new feature. Fixes #61
2019-09-09Merge pull request #59 from Dan33l/enable_acceptanceFabien COMBERNOUS
enable acceptance and drop EOL ubuntu1404
2019-09-09enable acceptanceFabien COMBERNOUS
2019-09-09drop EOL ubuntu1404Fabien COMBERNOUS
2019-09-09Merge pull request #65 from Dan33l/status_optionTim Meusel
add missing status option for CentOS 6 init script
2019-09-09add status optionFabien COMBERNOUS
2019-09-09Merge pull request #62 from Dan33l/drop_debian_from_supported_osesTim Meusel
drop Debian from supported OSes
2019-09-09drop Debian from supported OSesFabien COMBERNOUS
2019-09-02[blacksmith] Bump version to 2.4.1-rc0Tim Meusel
2019-09-02Merge pull request #56 from bastelfreak/rel240Tim Meusel
release 2.4.0
2019-09-02release 2.4.0Tim Meusel