diff --git a/REFERENCE.md b/REFERENCE.md index 8780e87..c28111a 100644 --- a/REFERENCE.md +++ b/REFERENCE.md @@ -15,8 +15,8 @@ * `observium::apache`: Class: observium::apache inherits observium Configure apache server with virtual host for observium * `observium::config`: Class: observium::config Configure observium configuration files lint:ignore:140chars lint:ignore:arrow_alignment * `observium::database_init`: Class: obversium Init the observium database after install. lint:ignore:140chars +* `observium::firewall`: Class: observium::firewall Manage UFW on ubuntu * `observium::firewalld`: Class: observium::firewall Manages firewall and opens ports for observium -* `observium::firewallufw`: Class: observium::firewallufw Manage UFW on ubuntu * `observium::install`: Class: observium::install Creates folder structure for Observium, and install from tar * `observium::mariadb`: Class: observium::mariadb Install mysql or mariadb - OS dependant * `observium::packages`: Class: observium::packages Installs required packges for observium diff --git a/manifests/firewall.pp b/manifests/firewall.pp index 70dd547..56690e5 100644 --- a/manifests/firewall.pp +++ b/manifests/firewall.pp @@ -52,4 +52,11 @@ proto => 'tcp', jump => 'accept', } + + # ensure we drop all other traffic + firewall { '999 drop all': + proto => 'all', + jump => 'drop', + before => undef, + } }