diff --git a/ubuntu/roles/firewall-ruleset-deploy/files/uriel.asininetech.net.rules.v4 b/ubuntu/roles/firewall-ruleset-deploy/files/uriel.asininetech.net.rules.v4 new file mode 100644 index 0000000..a36f21b --- /dev/null +++ b/ubuntu/roles/firewall-ruleset-deploy/files/uriel.asininetech.net.rules.v4 @@ -0,0 +1,12 @@ +*filter +:INPUT DROP +:FORWARD DROP +:OUTPUT ACCEPT +-A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT +-A INPUT -i lo -j ACCEPT +-A INPUT -p icmp --icmp-type ping -j ACCEPT +-A INPUT -p tcp --dport 22 -j ACCEPT +-A INPUT -p tcp --dport 5665 -j ACCEPT +-A INPUT -p tcp --dport 80 -j ACCEPT +-A INPUT -p tcp --dport 443 -j ACCEPT +COMMIT diff --git a/ubuntu/roles/firewall-ruleset-deploy/files/uriel.asininetech.net.rules.v6 b/ubuntu/roles/firewall-ruleset-deploy/files/uriel.asininetech.net.rules.v6 new file mode 100644 index 0000000..13f1469 --- /dev/null +++ b/ubuntu/roles/firewall-ruleset-deploy/files/uriel.asininetech.net.rules.v6 @@ -0,0 +1,21 @@ +*filter +:INPUT DROP +:FORWARD DROP +:OUTPUT ACCEPT +:icmp_in - +-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT +-A INPUT -i lo -j ACCEPT +-A INPUT -p tcp --dport 22 -j ACCEPT +-A INPUT -p tcp --dport 5665 -j ACCEPT +-A INPUT -p tcp --dport 80 -j ACCEPT +-A INPUT -p tcp --dport 443 -j ACCEPT +-A INPUT -p ipv6-icmp -j icmp_in +-A icmp_in -p ipv6-icmp -m icmp6 --icmpv6-type 128 -j ACCEPT +-A icmp_in -p ipv6-icmp -m icmp6 --icmpv6-type 134 -j ACCEPT +-A icmp_in -p ipv6-icmp -m icmp6 --icmpv6-type 135 -j ACCEPT +-A icmp_in -p ipv6-icmp -m icmp6 --icmpv6-type 136 -j ACCEPT +-A icmp_in -p ipv6-icmp -m icmp6 --icmpv6-type 1 -j ACCEPT +-A icmp_in -p ipv6-icmp -m icmp6 --icmpv6-type 2 -j ACCEPT +-A icmp_in -p ipv6-icmp -m icmp6 --icmpv6-type 3 -j ACCEPT +-A icmp_in -p ipv6-icmp -m icmp6 --icmpv6-type 4 -j ACCEPT +COMMIT