]> git.donarmstrong.com Git - dsa-puppet.git/blobdiff - modules/ntp/manifests/init.pp
this should virtually work
[dsa-puppet.git] / modules / ntp / manifests / init.pp
index f46173556ee23ee64a7ba28566ed31d4d6c02ebc..ace2f8f8dbb886e257aa06668bf33a54b655c124 100644 (file)
@@ -25,4 +25,9 @@ class ntp {
                path        => "/etc/init.d:/usr/bin:/usr/sbin:/bin:/sbin",
                refreshonly => true,
        }
+        @ferm::rule { "dsa-ntp":
+                domain          => "(ip ip6)",
+                description     => "Allow ntp access",
+                rule            => "proto udp mod state state (NEW) dport (123) ACCEPT"
+        }
 }