]> git.donarmstrong.com Git - dsa-puppet.git/blobdiff - modules/ssh/manifests/init.pp
reshuffle things around
[dsa-puppet.git] / modules / ssh / manifests / init.pp
index b3e32e34c57ec9470c7857131664b4356c8f16e9..452ce5dfbaaa24e91e047650d03b00e9dc4aceee 100644 (file)
@@ -5,7 +5,7 @@ class ssh {
         }
 
         case $hostname {
-                bartok: {
+                bartok, beethoven: {
                     $keyinfo = allnodeinfo("sshRSAHostKey", "ipHostNumber")
                 }
         }
@@ -37,11 +37,14 @@ class ssh {
             path        => "/etc/init.d:/usr/bin:/usr/sbin:/bin:/sbin",
             refreshonly => true,
         }
+
         ferm::rule { "dsa-ssh":
-               description     => "Allow SSH",
-               rule            => "proto tcp dport ssh ACCEPT",
-               domain          => "(ip ip6)",
-               prio            => "01"
+                description     => "Allow SSH from DSA",
+                rule            => "proto tcp mod state state (NEW) dport (ssh) @subchain 'ssh' { saddr (\$SSH_SOURCES) ACCEPT; }"
+        }
+        ferm::rule { "dsa-ssh-v6":
+                description     => "Allow SSH from DSA",
+                domain          => "ip6",
+                rule            => "proto tcp mod state state (NEW) dport (ssh) @subchain 'ssh' { saddr (\$SSH_V6_SOURCES) ACCEPT; }"
         }
-
 }