diff options
author | Silvio Rhatto <rhatto@riseup.net> | 2011-08-11 14:37:32 -0300 |
---|---|---|
committer | Silvio Rhatto <rhatto@riseup.net> | 2011-08-11 14:37:32 -0300 |
commit | 7f7d3cab9c4b4fc1bdc3827e8ea4c680c73da48d (patch) | |
tree | 36d470b1d000b89295c595f8f27d5cc89df46a59 /manifests/subsystems/firewall/wifi.pp | |
parent | fb4b9946ac9adeda2da07d80e65b56a0cf897339 (diff) | |
download | puppet-nodo-7f7d3cab9c4b4fc1bdc3827e8ea4c680c73da48d.tar.gz puppet-nodo-7f7d3cab9c4b4fc1bdc3827e8ea4c680c73da48d.tar.bz2 |
Spliting firewall classes along files and separating rules for vservers and routers
Diffstat (limited to 'manifests/subsystems/firewall/wifi.pp')
-rw-r--r-- | manifests/subsystems/firewall/wifi.pp | 50 |
1 files changed, 50 insertions, 0 deletions
diff --git a/manifests/subsystems/firewall/wifi.pp b/manifests/subsystems/firewall/wifi.pp new file mode 100644 index 0000000..d59ce50 --- /dev/null +++ b/manifests/subsystems/firewall/wifi.pp @@ -0,0 +1,50 @@ +class firewall::wifi { + $rfc1918 = $shorewall_local_net ? { + true => true, + false => false, + default => false, + } + + # Default device depends if madwifi or + # built-in kernel driver is being used + $wifi_default_device = $lsbdistcodename ? { + 'lenny' => 'ath0', + default => 'wlan0', + } + + $wifi_dev = $wifi_device ? { + '' => $wifi_default_device, + default => $wifi_device, + } + + # + # Interfaces + # + shorewall::interface { "$wifi_dev": + zone => '-', + rfc1918 => $rfc1918, + } + + # + # Hosts + # + shorewall::host { "$wifi_dev-subnet": + name => "$wifi_dev:192.168.0.0/24", + zone => 'vm', + options => '', + order => '1', + } + + shorewall::host { "$wifi_dev": + name => "$wifi_dev:0.0.0.0/0", + zone => 'net', + options => '', + order => '2', + } + + shorewall::masq { "$wifi_dev": + interface => "$wifi_dev:!192.168.0.0/24", + source => '192.168.0.0/24', + order => '1', + } +} |