asked 2014-03-05 16:24:30 -0600

fm82503

updated 2014-03-06 09:21:50 -0600

This is for puppet 3.4.3 and firewall module 1.0.2.

I'm getting started setting up puppet on our servers so I'm still pretty new at this. I've managed to configure most of our services and customized files with few problems.

I'm working on our firewall access right now. I've set up the firewall rules in puppet and that is working fine. We have various ports that need to be open in various servers for customers to use. We also have administrators and developers that need access to the servers to do their ... (more)

Apparently, the firewall module does support unmanaged rules, but there is no documentation on it short of digging through the source code. I really wish people documented things better.

fm82503 ( 2014-03-06 12:54:56 -0600 )

answered 2014-03-06 13:40:16 -0600

I want to try the same with firewall rule and not sure how it will behave with auto-auditing, please help.

Kumar Parab

answered 2014-03-07 06:49:59 -0600

robrwo

I've had similar problems using the firewall module with fail2ban. If something else is managing a port, then the firewall module cannot manage that port. I'm not sure of a workaround if puppet changes are regularly applied. Perhaps you can open port 22 and notify the service that manages the firewall, so that every time Puppet changes the settings for that port, the service that managed it will make the necessary changes afterwards.

Asked: 2014-03-05 16:24:30 -0600

Seen: 65 times

Last updated: Mar 07 '14