diff options
author | Ismaël Bouya <ismael.bouya@normalesup.org> | 2017-08-24 02:22:17 +0200 |
---|---|---|
committer | Ismaël Bouya <ismael.bouya@normalesup.org> | 2017-08-29 22:46:14 +0200 |
commit | 7fed35a408b9ec37454169425823785b5fc8978b (patch) | |
tree | 28371d43ac304f99fb0a5305124858db69ef2137 /modules/base_installation/manifests/firewall.pp | |
parent | ba2cf1b5d938810077b0fd73844faf432e8e8f9d (diff) | |
download | Puppet-7fed35a408b9ec37454169425823785b5fc8978b.tar.gz Puppet-7fed35a408b9ec37454169425823785b5fc8978b.tar.zst Puppet-7fed35a408b9ec37454169425823785b5fc8978b.zip |
Refactor base installation module
Diffstat (limited to 'modules/base_installation/manifests/firewall.pp')
-rw-r--r-- | modules/base_installation/manifests/firewall.pp | 20 |
1 files changed, 20 insertions, 0 deletions
diff --git a/modules/base_installation/manifests/firewall.pp b/modules/base_installation/manifests/firewall.pp new file mode 100644 index 0000000..12eeac2 --- /dev/null +++ b/modules/base_installation/manifests/firewall.pp | |||
@@ -0,0 +1,20 @@ | |||
1 | class base_installation::firewall inherits base_installation { | ||
2 | ensure_packages(["whois"], { 'install_options' => '--asdeps' }) | ||
3 | |||
4 | class { 'fail2ban': | ||
5 | logtarget => 'SYSLOG', | ||
6 | backend => 'systemd' | ||
7 | } | ||
8 | |||
9 | fail2ban::jail { 'sshd': | ||
10 | backend => 'systemd', | ||
11 | port => 'ssh', | ||
12 | filter => 'sshd', | ||
13 | maxretry => 10, | ||
14 | bantime => 86400, | ||
15 | logpath => '', | ||
16 | order => 10 | ||
17 | } | ||
18 | |||
19 | contain "fail2ban" | ||
20 | } | ||