adeck / ansible-deployments

3 stars 0 forks source link

add default-drop ferm output policy #11

Open adeck opened 9 years ago

adeck commented 9 years ago

Naturally, accept ESTABLISHED,RELATED, and accept anything root does (because root must fetch updates, etc., and besides root can just reset iptables, anyway, so it'd just be security theater either way).