From bd593fb9df033dfff27a581874580fc295f05bdd Mon Sep 17 00:00:00 2001 From: Tom Hughes Date: Thu, 2 Aug 2018 10:09:02 +0100 Subject: [PATCH] Disable tracking of loopback connections --- cookbooks/networking/recipes/default.rb | 16 ++++++++++++++++ .../templates/default/shorewall-conntrack.erb | 7 +++++++ 2 files changed, 23 insertions(+) create mode 100644 cookbooks/networking/templates/default/shorewall-conntrack.erb diff --git a/cookbooks/networking/recipes/default.rb b/cookbooks/networking/recipes/default.rb index 86792ea99..51f3f4389 100644 --- a/cookbooks/networking/recipes/default.rb +++ b/cookbooks/networking/recipes/default.rb @@ -179,6 +179,14 @@ template "/etc/shorewall/hosts" do notifies :restart, "service[shorewall]" end +template "/etc/shorewall/conntrack" do + source "shorewall-conntrack.erb" + owner "root" + group "root" + mode 0o644 + notifies :restart, "service[shorewall]" +end + template "/etc/shorewall/policy" do source "shorewall-policy.erb" owner "root" @@ -291,6 +299,14 @@ unless node.interfaces(:family => :inet6).empty? notifies :restart, "service[shorewall6]" end + template "/etc/shorewall6/conntrack" do + source "shorewall-conntrack.erb" + owner "root" + group "root" + mode 0o644 + notifies :restart, "service[shorewall6]" + end + template "/etc/shorewall6/policy" do source "shorewall-policy.erb" owner "root" diff --git a/cookbooks/networking/templates/default/shorewall-conntrack.erb b/cookbooks/networking/templates/default/shorewall-conntrack.erb new file mode 100644 index 000000000..4d5e726d3 --- /dev/null +++ b/cookbooks/networking/templates/default/shorewall-conntrack.erb @@ -0,0 +1,7 @@ +# DO NOT EDIT - This file is being maintained by Chef + +?FORMAT 3 + +# ACTION SOURCE DEST PROTO DPORT SPORT USER SWITCH +NOTRACK:P lo - - - - - - +NOTRACK:O - lo - - - - - -- 2.39.5