aboutsummaryrefslogtreecommitdiff
path: root/manifests/rules/nfsd.pp
diff options
context:
space:
mode:
authorMarcel Haerry <haerry@puzzle.ch>2009-09-16 19:13:15 +0200
committerMicah Anderson <micah@riseup.net>2009-12-07 11:33:38 -0500
commit6e2a713fb4ffb060e614c3de9c7c33f403214d7f (patch)
treed09e8cccd3c25396dcc11a93affd8f2bcb963c9f /manifests/rules/nfsd.pp
parent69ffd72ce9e5217ae7d205e04716c40d8c862315 (diff)
downloadpuppet-shorewall-6e2a713fb4ffb060e614c3de9c7c33f403214d7f.tar.gz
puppet-shorewall-6e2a713fb4ffb060e614c3de9c7c33f403214d7f.tar.bz2
add a lot of default rules
Diffstat (limited to 'manifests/rules/nfsd.pp')
-rw-r--r--manifests/rules/nfsd.pp82
1 files changed, 82 insertions, 0 deletions
diff --git a/manifests/rules/nfsd.pp b/manifests/rules/nfsd.pp
new file mode 100644
index 0000000..2719a29
--- /dev/null
+++ b/manifests/rules/nfsd.pp
@@ -0,0 +1,82 @@
+class shorewall::rules::nfsd {
+ shorewall::rule { 'net-me-portmap-tcp':
+ source => 'net',
+ destination => '$FW',
+ proto => 'tcp',
+ destinationport => '111',
+ order => 240,
+ action => 'ACCEPT';
+ }
+ shorewall::rule { 'net-me-portmap-udp':
+ source => 'net',
+ destination => '$FW',
+ proto => 'udp',
+ destinationport => '111',
+ order => 240,
+ action => 'ACCEPT';
+ }
+ shorewall::rule { 'net-me-rpc.nfsd-tcp':
+ source => 'net',
+ destination => '$FW',
+ proto => 'tcp',
+ destinationport => '2049',
+ order => 240,
+ action => 'ACCEPT';
+ }
+ shorewall::rule { 'net-me-rpc.nfsd-udp':
+ source => 'net',
+ destination => '$FW',
+ proto => 'udp',
+ destinationport => '2049',
+ order => 240,
+ action => 'ACCEPT';
+ }
+ shorewall::rule { 'net-me-rpc.statd-tcp':
+ source => 'net',
+ destination => '$FW',
+ proto => 'tcp',
+ destinationport => '4000',
+ order => 240,
+ action => 'ACCEPT';
+ }
+ shorewall::rule { 'net-me-rpc.statd-udp':
+ source => 'net',
+ destination => '$FW',
+ proto => 'udp',
+ destinationport => '4000',
+ order => 240,
+ action => 'ACCEPT';
+ }
+ shorewall::rule { 'net-me-rpc.lockd-tcp':
+ source => 'net',
+ destination => '$FW',
+ proto => 'tcp',
+ destinationport => '4001',
+ order => 240,
+ action => 'ACCEPT';
+ }
+ shorewall::rule { 'net-me-rpc.lockd-udp':
+ source => 'net',
+ destination => '$FW',
+ proto => 'udp',
+ destinationport => '4001',
+ order => 240,
+ action => 'ACCEPT';
+ }
+ shorewall::rule { 'net-me-rpc.mountd-tcp':
+ source => 'net',
+ destination => '$FW',
+ proto => 'tcp',
+ destinationport => '4002',
+ order => 240,
+ action => 'ACCEPT';
+ }
+ shorewall::rule { 'net-me-rpc.mountd-udp':
+ source => 'net',
+ destination => '$FW',
+ proto => 'udp',
+ destinationport => '4002',
+ order => 240,
+ action => 'ACCEPT';
+ }
+}