Merge "Initial firewall config causes temporary packet loss"
This commit is contained in:
commit
15e100430f
|
@ -1,2 +1,2 @@
|
||||||
SRC_DIR="src"
|
SRC_DIR="src"
|
||||||
TIS_PATCH_VER=78
|
TIS_PATCH_VER=79
|
||||||
|
|
|
@ -298,38 +298,38 @@ class platform::firewall::oam (
|
||||||
version => 'ipv4',
|
version => 'ipv4',
|
||||||
}
|
}
|
||||||
|
|
||||||
platform::firewall::common { 'platform:firewall:ipv6':
|
-> platform::firewall::common { 'platform:firewall:ipv6':
|
||||||
interface => $interface_name,
|
interface => $interface_name,
|
||||||
version => 'ipv6',
|
version => 'ipv6',
|
||||||
}
|
}
|
||||||
|
|
||||||
platform::firewall::services { 'platform:firewall:services':
|
-> platform::firewall::services { 'platform:firewall:services':
|
||||||
version => $version,
|
version => $version,
|
||||||
}
|
}
|
||||||
|
|
||||||
# Set default table policies
|
# Set default table policies
|
||||||
firewallchain { 'INPUT:filter:IPv4':
|
-> firewallchain { 'INPUT:filter:IPv4':
|
||||||
ensure => present,
|
ensure => present,
|
||||||
policy => drop,
|
policy => drop,
|
||||||
before => undef,
|
before => undef,
|
||||||
purge => false,
|
purge => false,
|
||||||
}
|
}
|
||||||
|
|
||||||
firewallchain { 'INPUT:filter:IPv6':
|
-> firewallchain { 'INPUT:filter:IPv6':
|
||||||
ensure => present,
|
ensure => present,
|
||||||
policy => drop,
|
policy => drop,
|
||||||
before => undef,
|
before => undef,
|
||||||
purge => false,
|
purge => false,
|
||||||
}
|
}
|
||||||
|
|
||||||
firewallchain { 'FORWARD:filter:IPv4':
|
-> firewallchain { 'FORWARD:filter:IPv4':
|
||||||
ensure => present,
|
ensure => present,
|
||||||
policy => drop,
|
policy => drop,
|
||||||
before => undef,
|
before => undef,
|
||||||
purge => false,
|
purge => false,
|
||||||
}
|
}
|
||||||
|
|
||||||
firewallchain { 'FORWARD:filter:IPv6':
|
-> firewallchain { 'FORWARD:filter:IPv6':
|
||||||
ensure => present,
|
ensure => present,
|
||||||
policy => drop,
|
policy => drop,
|
||||||
before => undef,
|
before => undef,
|
||||||
|
|
Loading…
Reference in New Issue