From 9461723adb6a8e1bf725a8466a11c9508ec2e6a8 Mon Sep 17 00:00:00 2001 From: Sergio Oliveira Date: Mon, 20 Apr 2015 16:57:58 -0300 Subject: [PATCH] Removed unnecessary lines from iptables config --- cookbooks/reverse_proxy/templates/iptables.erb | 16 +++------------- 1 file changed, 3 insertions(+), 13 deletions(-) diff --git a/cookbooks/reverse_proxy/templates/iptables.erb b/cookbooks/reverse_proxy/templates/iptables.erb index 1548e08..a660bef 100644 --- a/cookbooks/reverse_proxy/templates/iptables.erb +++ b/cookbooks/reverse_proxy/templates/iptables.erb @@ -1,17 +1,7 @@ -# Generated by iptables-save v1.4.21 on Thu Apr 16 20:28:15 2015 *nat -:PREROUTING ACCEPT [5:493] -:INPUT ACCEPT [5:493] -:OUTPUT ACCEPT [2:138] -:POSTROUTING ACCEPT [2:138] + +# Forward reverseproxy:22 to integration:22. Required to enable git pushes over SSH -A PREROUTING -d <%= node['peers']['reverseproxy'] %>/32 -p tcp -m tcp --dport 22 -j DNAT --to-destination <%= node['peers']['integration'] %>:22 -A POSTROUTING -d <%= node['peers']['integration'] %>/32 -p tcp -m tcp --dport 22 -j SNAT --to-source <%= node['peers']['reverseproxy'] %> + COMMIT -# Completed on Thu Apr 16 20:28:15 2015 -# Generated by iptables-save v1.4.21 on Thu Apr 16 20:28:15 2015 -*filter -:INPUT ACCEPT [5675:7406907] -:FORWARD ACCEPT [66:13348] -:OUTPUT ACCEPT [3901:279969] -COMMIT -# Completed on Thu Apr 16 20:28:15 2015 -- libgit2 0.21.2