firewall pkgs to masked as default

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
This commit is contained in:
Mark Bolwell 2022-04-05 13:07:36 +01:00
parent bb7869adad
commit e9d212437a
No known key found for this signature in database
GPG key ID: F734FDFC154B83FB

View file

@ -485,13 +485,13 @@ rhel9cis_default_zone: public
rhel9cis_firewalld_nftables_state: masked # Note if absent removes the firewalld pkg dependancy
#### nftables
rhel9cis_nftables_firewalld_state: absent
rhel9cis_nftables_firewalld_state: masked
rhel9cis_nft_tables_autonewtable: true
rhel9cis_nft_tables_tablename: filter
rhel9cis_nft_tables_autochaincreate: true
#### iptables
rhel9cis_iptables_firewalld_state: absent
rhel9cis_iptables_firewalld_state: masked
# Warning Banner Content (issue, issue.net, motd)
rhel9cis_warning_banner: |