-
Notifications
You must be signed in to change notification settings - Fork 61
/
Copy pathpillar.example
43 lines (33 loc) · 839 Bytes
/
pillar.example
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
ufw:
enabled: True
services:
# Allow 80/tcp (http) traffic from only two remote addresses.
http:
protocol: tcp
from_addr:
- 10.0.2.15
- 10.0.2.16
# Allow 443/tcp (https) traffic from network 10.0.0.0/8 to an specific local ip.
https:
protocol: tcp
from_addr:
- 10.0.0.0/8
to_addr: 10.0.2.1
# Allow from a service port.
smtp:
protocol: tcp
# Allow from an specific port, by number.
139:
protocol: tcp
# Allow from a range of ports, udp.
"10000:20000":
protocol: udp
# Allow from two specific ports, udp.
"30000,40000":
protocol: udp
# Allow an application defined at /etc/ufw/applications.d/
applications:
- OpenSSH
# Allow all traffic in on the specified interface
interfaces:
- eth1