class firewall::printer {
  shorewall::rule { "cups-tcp":
    action          => 'ACCEPT',
    source          => 'net',
    destination     => '$FW',
    proto           => 'tcp',
    destinationport => "631",
    ratelimit       => '-',
    order           => 200,
  }

  shorewall::rule { "cups-udp":
    action          => 'ACCEPT',
    source          => 'net',
    destination     => '$FW',
    proto           => 'udp',
    destinationport => "631",
    ratelimit       => '-',
    order           => 201,
  }
}