}
ferm::chain{'FORWARD':
policy => $ferm::forward_policy,
- disable_conntrack => $ferm::disable_conntrack,
+ disable_conntrack => true,
log_dropped_packets => $ferm::forward_log_dropped_packets,
}
ferm::chain{'OUTPUT':
policy => $ferm::output_policy,
- disable_conntrack => $ferm::disable_conntrack,
+ disable_conntrack => true,
log_dropped_packets => $ferm::output_log_dropped_packets,
}
manage_configfile => true,
manage_initfile => #{manage_initfile}, # CentOS-6 does not provide init script
forward_policy => 'DROP',
- output_policy => 'DROP',
+ output_policy => 'ACCEPT',
input_policy => 'DROP',
rules => {
'allow_acceptance_tests' => {
end
describe command('iptables-save') do
- its(:stdout) { is_expected.to match %r{.*filter.*:INPUT DROP.*:FORWARD DROP.*:OUTPUT DROP.*}m }
+ its(:stdout) { is_expected.to match %r{.*filter.*:INPUT DROP.*:FORWARD DROP.*:OUTPUT ACCEPT.*}m }
end
describe iptables do