Projet

Général

Profil

Paste
Télécharger au format
Statistiques
| Branche: | Révision:

root @ 47ef2987

# Date Auteur Commentaire
47ef2987 2023-12-20 15:09 Tim Meusel

Release 3.6.0

839ee136 2023-12-20 15:05 Tim Meusel

Merge pull request #225 from voxpupuli/nftables

Make "dropping invalid packets" configureable

eac19d14 2023-12-20 14:51 Tim Meusel

Make "dropping invalid packets" configureable

It doesn't make sense to explicitly drop those pakets when the default
policy is already `DROP`. Also some applications, like ceph, are known
to send packets that might be marked as invalid.

e5a1eb78 2023-12-20 13:43 Tim Meusel

Merge pull request #224 from voxpupuli/nftables

simplerule: Add support for outgoing interface filtering

d7d6d5d3 2023-12-20 13:31 Tim Meusel

simplerule: Add support for outgoing interface filtering

545a379b 2023-12-20 08:35 Tim Meusel

Merge pull request #222 from bastelfreak/refactor

rules::out:dns: refactor for better readability

9d1ee648 2023-12-20 04:41 Tim Meusel

rules::out:dns: refactor for better readability

ee2d38a5 2023-12-19 12:55 Tim Meusel

Merge pull request #221 from voxpupuli/nftables

simplerule: Add support for incoming interface filtering

25b3f3f4 2023-12-19 12:36 Tim Meusel

simplerule: Add support for incoming interface filtering

0ec7c23d 2023-12-18 16:52 Tim Meusel

Merge pull request #220 from voxpupuli/modulesync

modulesync 7.2.0

f1d50c1e 2023-12-18 16:40 Tim Meusel

Regenerate REFERENCE.md

3cc3ad1d 2023-12-15 07:24 Tim Meusel

modulesync 7.2.0

4528f390 2023-12-06 11:43 Kenyon Ralph

Merge pull request #219 from Tamerz/document-set-param

Document what the 'auto_merge' set parameter does.

2732318a 2023-12-06 04:19 Tames McTigue

Document what the 'auto_merge' parameter does.

c61ebeb1 2023-12-04 04:16 Tim Meusel

Merge pull request #218 from voxpupuli/modulesync

modulesync 7.1.0

936cde59 2023-12-02 18:38 Tim Meusel

modulesync 7.1.0

c23d8bf1 2023-11-27 04:16 Steve Traylen

[blacksmith] Bump version to 3.5.1-rc0

a30d4510 2023-11-27 04:14 Steve Traylen

Merge pull request #216 from traylenator/release-3.4.1

Release 3.5.0

f301ff5e 2023-11-27 03:56 Steve Traylen

Release 3.5.0

41c988a4 2023-11-24 03:04 Tim Meusel

Merge pull request #215 from traylenator/dnsiface

Support input interface specification to dns server

67cdcf15 2023-11-24 02:52 Steve Traylen

Support input interface specification to dns server

Useful when you want to allow docker/podman containers
access to a hosts dns stub resolver.

```puppet
class{'nftables::rules::dns':
iifname => ['docker0'],
}
```

b5633532 2023-11-23 02:46 Tim Meusel

Merge pull request #189 from tskirvin/master

nftables::simplerule::dport - takes port ranges as part of the array

a7cb6803 2023-11-23 02:38 Steve Traylen

Merge pull request #214 from traylenator/podman

Additional rules for podman root containers

1085e990 2023-11-22 05:50 Steve Traylen

Merge pull request #183 from traylenator/redirect

Example how to redirect one port to another

94285e5f 2023-11-22 04:40 Steve Traylen

Example how to redirect one port to another

Add example how to redirect traffic from one port to another.

08b9f1d0 2023-11-22 03:53 Steve Traylen

Additional rules for podman root containers

This class defines additional forwarding rules to let root containers
reach external networks when using Netavark (since v4.0) or CNI (deprecated).
At the time of writing, Podman supports automatic configuration...

3413220c 2023-11-17 13:07 Tim Meusel

[blacksmith] Bump version to 3.4.1-rc0

b5b49a36 2023-11-17 13:07 Tim Meusel

Merge pull request #212 from bastelfreak/rel340

Release 3.4.0

54b5cf0b 2023-11-17 12:47 Tim Meusel

Release 3.4.0

ab464b23 2023-11-17 12:45 Tim Meusel

Merge pull request #213 from vchepkov/systemd

allow puppet/systemd v6

8d384ffe 2023-11-17 07:18 Vadym Chepkov

allow puppet/systemd v6

42bd5407 2023-11-17 04:11 Tim Meusel

Merge pull request #211 from bastelfreak/debian12

Add Debian 12 support

0bdf751a 2023-11-17 03:55 Tim Meusel

Add Debian 12 support

50c78d9b 2023-11-17 03:54 Tim Meusel

Merge pull request #208 from vchepkov/ftp

add ftp helper

baad986e 2023-11-16 19:10 Vadym Chepkov

add ftp helper

This adds ability to enable a connection tracker helper and provides typical ftp rules

Co-authored-by: Vadym Chepkov <>
Co-authored-by: Yury Bushmelev <>

825f4eb1 2023-11-08 13:37 Tim Skirvin

trying out a spec to mix port arrays and ranges

d7bd6638 2023-11-07 17:28 Tim Skirvin

spec update to confirm that port ranges work

5a7b1fc1 2023-11-07 17:27 Tim Skirvin

Merge branch 'voxpupuli:master' into master

ba8b99ba 2023-10-28 09:44 Tim Meusel

Merge pull request #209 from vchepkov/rejects

provide an option to disable logging rejected packets

a9bbb10d 2023-10-28 09:05 Vadym Chepkov

provide an option to disable logging rejected packets

34cbd618 2023-08-28 05:06 Tim Meusel

[blacksmith] Bump version to 3.3.1-rc0

8e417835 2023-08-28 05:06 Tim Meusel

Merge pull request #205 from bastelfreak/rel330

Release 3.3.0

c723df84 2023-08-28 04:37 Tim Meusel

Release 3.3.0

ec5b5f0c 2023-08-27 16:32 Tim Meusel

Merge pull request #204 from voxpupuli/netbios

samba: Add option to drop traffic

b575ab23 2023-08-27 06:44 Ewoud Kohl van Wijngaarden

Merge pull request #203 from voxpupuli/wsd

Add nftables rules for ws-discovery

64404839 2023-08-27 05:09 Tim Meusel

samba: Add option to drop traffic

ffc8b86f 2023-08-26 18:20 Tim Meusel

Add nftables rules for ws-discovery

a5d1955b 2023-08-26 18:18 Tim Meusel

Merge pull request #202 from voxpupuli/ssdp

Add rule for incoming SSDP

50a5be8b 2023-08-26 18:05 Tim Meusel

Add rule for incoming SSDP

91c5635b 2023-08-26 18:04 Tim Meusel

Merge pull request #201 from voxpupuli/llmnr

Add rule for incoming LLMNR

d7e26575 2023-08-26 17:47 Tim Meusel

init.pp: disable check_unsafe_interpolations

3b26826f 2023-08-25 19:07 Tim Meusel

Add rule for incoming LLMNR

fbe7e2b4 2023-08-21 12:07 Tim Skirvin

Merge branch 'master' into master

7da42ef1 2023-08-19 18:00 Tim Meusel

[blacksmith] Bump version to 3.2.1-rc0

4105b0a8 2023-08-19 18:00 Tim Meusel

Merge pull request #200 from bastelfreak/rel320

Release 3.2.0

3e3f3c50 2023-08-19 16:40 Tim Meusel

Release 3.2.0

28fe8e40 2023-08-19 16:37 Tim Meusel

Merge pull request #199 from bastelfreak/omcast

Add rule for outgoing multicast DNS

6b350264 2023-08-19 16:22 Tim Meusel

Add rule for outgoing multicast DNS

52453e85 2023-08-19 16:09 Sebastian Rakel

Merge pull request #198 from bastelfreak/mlds

Add rule for multicast listener requests (MLDv2)

e499cece 2023-08-19 15:52 Tim Meusel

Add rule for multicast listener requests (MLDv2)

330e6171 2023-08-19 15:48 Tim Meusel

Merge pull request #197 from ekohl/mdns-v6

Rewrite mdns rules to limit to multicast and allow IPv6

ad3dbd7d 2023-08-18 10:40 Ewoud Kohl van Wijngaarden

Rewrite mdns rules to limit to multicast and allow IPv6

This limits the mdns listener to only listen on multicast addresses with
port 5353. One rule for IPv4 and one for IPv6, each controllable with a
parameter.

The generic 5353 to 5353 rule is dropped since it's redundant when I...

4e9b7fa3 2023-08-18 04:23 Tim Meusel

Merge pull request #195 from voxpupuli/modulesync

modulesync 7.0.0

a8bf4ad5 2023-08-17 22:02 Romain Tartière

Regenerate REFERENCE.md

b0b538e0 2023-08-17 10:39 Tim Meusel

modulesync 7.0.0

4acda787 2023-08-10 12:13 Tim Skirvin

REFERENCE.md changes to match

68824413 2023-08-09 20:00 Tim Meusel

Merge pull request #194 from bastelfreak/multicast

Add rules for IGMP

020842af 2023-08-09 20:00 Tim Meusel

Add rules for IGMP

e1a299d6 2023-08-09 19:43 Tim Meusel

Merge pull request #193 from bastelfreak/mdns

mDNS: Allow udp port 5353

a6e14e83 2023-08-09 19:23 Tim Meusel

Merge pull request #191 from bastelfreak/multicast

Add rule to allow multicast DNS

c2e342b2 2023-08-09 19:21 Tim Meusel

mDNS: Allow udp port 5353

c8e7e2ba 2023-08-09 19:20 Tim Meusel

mDNS: Allow udp port 5353

5ffd0328 2023-08-09 19:11 Tim Meusel

Add rule to allow multicast DNS

ba1710dc 2023-08-09 19:10 Tim Meusel

Merge pull request #192 from bastelfreak/spot

Add rule to allow incoming spotify broadcast

8b131276 2023-08-09 18:53 Tim Meusel

Add rule to allow incoming spotify broadcast

3b20932f 2023-08-09 18:11 Tim Meusel

Merge pull request #190 from bastelfreak/multicast

Add rule to allow incoming multicast traffic

80b384c8 2023-08-09 17:57 Tim Meusel

Add rule to allow incoming multicast traffic

664d2bb0 2023-08-08 13:25 Tim Skirvin

nftables::simplerule::dport - takes port ranges as part of the array

addresses issue 188

2ba59bcc 2023-07-31 17:38 Romain Tartière

Merge pull request #187 from javier-angulo/fix/184

5b13f220 2023-07-31 17:16 Javier Angulo

change parameters order: required before optional

13616b81 2023-07-31 17:00 Romain Tartière

Merge pull request #180 from traylenator/upper

861169e5 2023-07-31 16:45 Javier Angulo

fix #184: Add unit string for timeout,gc-interval

dda21763 2023-07-30 13:59 Tim Meusel

[blacksmith] Bump version to 3.1.1-rc0

7d56467e 2023-07-30 13:56 Tim Meusel

Merge pull request #186 from bastelfreak/rel310

Release 3.1.0

cedfa7db 2023-07-29 17:40 Tim Meusel

Release 3.1.0

7fb92f9d 2023-07-29 16:50 Tim Meusel

Merge pull request #185 from bastelfreak/concat

puppetlabs/concat: Allow 9.x

e85cdb12 2023-07-29 16:28 Tim Meusel

puppetlabs/concat: Allow 9.x

54acd67e 2023-07-26 02:26 Romain Tartière

Merge pull request #182 from voxpupuli/stdlib9_20230723

b677c2c1 2023-07-01 09:49 Tim Meusel

puppetlabs/stdlib: Allow 9.x

7d2b280c 2023-06-26 02:12 Steve Traylen

Declare stdlib v9 support

22fe53aa 2023-06-25 17:16 Romain Tartière

Merge pull request #181 from traylenator/p8

Declare puppet v8 support

4a99271b 2023-06-25 15:40 Steve Traylen

Declare puppet v8 support

303471a3 2023-06-20 08:40 Simon Hoenscheid

[blacksmith] Bump version to 3.0.2-rc0

e64d0b62 2023-06-20 08:01 Simon Hönscheid

Merge pull request #179 from SimonHoenscheid/release-3.0.1

Release 3.0.1

b09c1fa4 2023-06-20 05:28 Simon Hoenscheid

Release 3.0.1

5a0bbe00 2023-06-19 17:34 Simon Hönscheid

Merge pull request #177 from SimonHoenscheid/ldap_ad_out_rulesets

add ldap and active directory rules

ea29e235 2023-06-19 12:58 Simon Hoenscheid

add ldap and active directory rules

8d1d49a8 2023-06-03 14:55 Steve Traylen

Merge pull request #176 from canihavethisone/master

Increased puppet/systemd upper limit to < 6.0.0

a61fdf1e 2023-06-02 23:45 canihavethisone

Increased puppet/systemd upper limit to < 6.0.0

644b182e 2023-05-25 11:00 Steve Traylen

[blacksmith] Bump version to 3.0.1-rc0