48c2a3f7ce
When including this element we empty the stock /etc/sysconfig/iptables file as shipped by the iptables rpm package. The reason for this is that puppet firewall has a hard time to cope with exiting rules when /etc/sysconfig/iptables is populated and the iptables service is not active. The referenced bug has a full explanation for the problem. Partial-Bug: #1657108 Change-Id: Iddc21316a1a3d42a1a43cbb4b9c178adba8f8db3 |
||
---|---|---|
.. | ||
bin | ||
install.d | ||
pre-install.d | ||
README.md | ||
svc-map |
README.md
##iptables
This element installs a single script that consolidates the logic required to handle inserting iptables rules. This script uses the check (-C) argument to check whether a rule matching the specification does exist in the selected chain before inserting it.
RULE: The rule to insert into iptables