diff options
Diffstat (limited to 'manifests/virtual/https.pp')
-rw-r--r-- | manifests/virtual/https.pp | 22 |
1 files changed, 22 insertions, 0 deletions
diff --git a/manifests/virtual/https.pp b/manifests/virtual/https.pp new file mode 100644 index 0000000..ea900d8 --- /dev/null +++ b/manifests/virtual/https.pp @@ -0,0 +1,22 @@ +class firewall::virtual::https($destination, $zone = 'vm') { + shorewall::rule { 'https-route-1': + action => 'DNAT', + source => 'net', + destination => "$zone:$destination:443", + proto => 'tcp', + destinationport => '443', + ratelimit => hiera("firewall::ssl_ratelimit", '-'), + order => 602, + } + + shorewall::rule { 'https-route-2': + action => 'DNAT', + source => '$FW', + destination => "fw:$destination:443", + proto => 'tcp', + destinationport => '443', + originaldest => hiera('firewall::external_ip', $::ipaddress), + ratelimit => hiera("firewall::ssl_ratelimit", '-'), + order => 602, + } +} |