diff options
author | Marcel Haerry <haerry@puzzle.ch> | 2009-09-16 19:13:15 +0200 |
---|---|---|
committer | Micah Anderson <micah@riseup.net> | 2009-12-07 11:33:38 -0500 |
commit | 6e2a713fb4ffb060e614c3de9c7c33f403214d7f (patch) | |
tree | d09e8cccd3c25396dcc11a93affd8f2bcb963c9f /manifests/rules/nfsd.pp | |
parent | 69ffd72ce9e5217ae7d205e04716c40d8c862315 (diff) | |
download | puppet-shorewall-6e2a713fb4ffb060e614c3de9c7c33f403214d7f.tar.gz puppet-shorewall-6e2a713fb4ffb060e614c3de9c7c33f403214d7f.tar.bz2 |
add a lot of default rules
Diffstat (limited to 'manifests/rules/nfsd.pp')
-rw-r--r-- | manifests/rules/nfsd.pp | 82 |
1 files changed, 82 insertions, 0 deletions
diff --git a/manifests/rules/nfsd.pp b/manifests/rules/nfsd.pp new file mode 100644 index 0000000..2719a29 --- /dev/null +++ b/manifests/rules/nfsd.pp @@ -0,0 +1,82 @@ +class shorewall::rules::nfsd { + shorewall::rule { 'net-me-portmap-tcp': + source => 'net', + destination => '$FW', + proto => 'tcp', + destinationport => '111', + order => 240, + action => 'ACCEPT'; + } + shorewall::rule { 'net-me-portmap-udp': + source => 'net', + destination => '$FW', + proto => 'udp', + destinationport => '111', + order => 240, + action => 'ACCEPT'; + } + shorewall::rule { 'net-me-rpc.nfsd-tcp': + source => 'net', + destination => '$FW', + proto => 'tcp', + destinationport => '2049', + order => 240, + action => 'ACCEPT'; + } + shorewall::rule { 'net-me-rpc.nfsd-udp': + source => 'net', + destination => '$FW', + proto => 'udp', + destinationport => '2049', + order => 240, + action => 'ACCEPT'; + } + shorewall::rule { 'net-me-rpc.statd-tcp': + source => 'net', + destination => '$FW', + proto => 'tcp', + destinationport => '4000', + order => 240, + action => 'ACCEPT'; + } + shorewall::rule { 'net-me-rpc.statd-udp': + source => 'net', + destination => '$FW', + proto => 'udp', + destinationport => '4000', + order => 240, + action => 'ACCEPT'; + } + shorewall::rule { 'net-me-rpc.lockd-tcp': + source => 'net', + destination => '$FW', + proto => 'tcp', + destinationport => '4001', + order => 240, + action => 'ACCEPT'; + } + shorewall::rule { 'net-me-rpc.lockd-udp': + source => 'net', + destination => '$FW', + proto => 'udp', + destinationport => '4001', + order => 240, + action => 'ACCEPT'; + } + shorewall::rule { 'net-me-rpc.mountd-tcp': + source => 'net', + destination => '$FW', + proto => 'tcp', + destinationport => '4002', + order => 240, + action => 'ACCEPT'; + } + shorewall::rule { 'net-me-rpc.mountd-udp': + source => 'net', + destination => '$FW', + proto => 'udp', + destinationport => '4002', + order => 240, + action => 'ACCEPT'; + } +} |