diff options
author | mh <mh@immerda.ch> | 2011-04-26 03:08:37 +0200 |
---|---|---|
committer | Micah Anderson <micah@riseup.net> | 2011-06-21 12:16:27 -0400 |
commit | b67bb6c1571506ae4b1d49feab06e73b75515f29 (patch) | |
tree | e292dfd5a636a930ac2eb5119d6db8618c8e74da /manifests/rules | |
parent | e27f9a83ed912eeef399878e7a8a3c77035b53de (diff) | |
download | puppet-shorewall-b67bb6c1571506ae4b1d49feab06e73b75515f29.tar.gz puppet-shorewall-b67bb6c1571506ae4b1d49feab06e73b75515f29.tar.bz2 |
allow esp traffic from and to me
Diffstat (limited to 'manifests/rules')
-rw-r--r-- | manifests/rules/ipsec.pp | 18 |
1 files changed, 15 insertions, 3 deletions
diff --git a/manifests/rules/ipsec.pp b/manifests/rules/ipsec.pp index c609d0a..3e9db55 100644 --- a/manifests/rules/ipsec.pp +++ b/manifests/rules/ipsec.pp @@ -1,18 +1,30 @@ class shorewall::rules::ipsec { - shorewall::rule { 'net-me-ipsec-udp': + shorewall::rule { + 'net-me-ipsec-udp': source => 'net', destination => '$FW', proto => 'udp', destinationport => '500', order => 240, action => 'ACCEPT'; - } - shorewall::rule { 'me-net-ipsec-udp': + 'me-net-ipsec-udp': source => '$FW', destination => 'net', proto => 'udp', destinationport => '500', order => 240, action => 'ACCEPT'; + 'net-me-ipsec': + source => 'net', + destination => '$FW', + proto => 'esp', + order => 240, + action => 'ACCEPT'; + 'me-net-ipsec': + source => '$FW', + destination => 'net', + proto => 'esp', + order => 240, + action => 'ACCEPT'; } } |