diff options
author | Russell Teague <rteague@redhat.com> | 2016-11-28 14:43:47 -0500 |
---|---|---|
committer | Russell Teague <rteague@redhat.com> | 2016-12-14 14:43:02 -0500 |
commit | 05e189a039dada5edc4f9afb700b594c4dea4c9b (patch) | |
tree | efa63c5b2a61ebf6a84a2533ea5249c94a6469be /roles/os_firewall/README.md | |
parent | 002fdef1769baccdd6c90a4caa8c0028ec9559db (diff) | |
download | openshift-05e189a039dada5edc4f9afb700b594c4dea4c9b.tar.gz openshift-05e189a039dada5edc4f9afb700b594c4dea4c9b.tar.bz2 openshift-05e189a039dada5edc4f9afb700b594c4dea4c9b.tar.xz openshift-05e189a039dada5edc4f9afb700b594c4dea4c9b.zip |
Enable firewalld by default
Diffstat (limited to 'roles/os_firewall/README.md')
-rw-r--r-- | roles/os_firewall/README.md | 7 |
1 files changed, 5 insertions, 2 deletions
diff --git a/roles/os_firewall/README.md b/roles/os_firewall/README.md index c13c5dfc9..43db3cc74 100644 --- a/roles/os_firewall/README.md +++ b/roles/os_firewall/README.md @@ -4,6 +4,9 @@ OS Firewall OS Firewall manages firewalld and iptables firewall settings for a minimal use case (Adding/Removing rules based on protocol and port number). +Note: firewalld is not supported on Atomic Host +https://bugzilla.redhat.com/show_bug.cgi?id=1403331 + Requirements ------------ @@ -14,7 +17,7 @@ Role Variables | Name | Default | | |---------------------------|---------|----------------------------------------| -| os_firewall_use_firewalld | False | If false, use iptables | +| os_firewall_use_firewalld | True | If false, use iptables | | os_firewall_allow | [] | List of service,port mappings to allow | | os_firewall_deny | [] | List of service, port mappings to deny | @@ -31,6 +34,7 @@ Use iptables and open tcp ports 80 and 443: --- - hosts: servers vars: + os_firewall_use_firewalld: false os_firewall_allow: - service: httpd port: 80/tcp @@ -45,7 +49,6 @@ Use firewalld and open tcp port 443 and close previously open tcp port 80: --- - hosts: servers vars: - os_firewall_use_firewalld: true os_firewall_allow: - service: https port: 443/tcp |