Allow setting iptables chain policy
diff --git a/README.rst b/README.rst
index 1a2d8e1..19e037c 100644
--- a/README.rst
+++ b/README.rst
@@ -18,6 +18,7 @@
           chain:
             INPUT:
               enabled: true
+              policy: DROP
               rule:
                 httpd:
                   position: 1