From eea681dccca659f244fdba0049c06b4b901a6505 Mon Sep 17 00:00:00 2001 From: Kevin Fenzi Date: Jun 14 2020 22:39:10 +0000 Subject: base iptables: drop phx2 from osuosl allowed for ssh networks Signed-off-by: Kevin Fenzi --- diff --git a/roles/base/templates/iptables/iptables.osuosl b/roles/base/templates/iptables/iptables.osuosl index 119ab4a..9741d1a 100644 --- a/roles/base/templates/iptables/iptables.osuosl +++ b/roles/base/templates/iptables/iptables.osuosl @@ -24,8 +24,6 @@ # allow ssh only from needed ips # vpn in from tun0 -A INPUT -m conntrack --ctstate NEW -m tcp -p tcp --dport 22 -s 192.168.0.0/24 -i tun0 -j ACCEPT -# external ip for phx2 --A INPUT -m conntrack --ctstate NEW -m tcp -p tcp --dport 22 -s 209.132.181.0/24 -j ACCEPT # external ip for iad2 -A INPUT -m conntrack --ctstate NEW -m tcp -p tcp --dport 22 -s 38.145.60.0/24 -j ACCEPT