]> git.donarmstrong.com Git - dsa-puppet.git/commitdiff
add dns and finger rules for draghi
authorMartin Zobel-Helas <zobel@debian.org>
Sun, 25 Jul 2010 21:37:38 +0000 (23:37 +0200)
committerMartin Zobel-Helas <zobel@debian.org>
Sun, 25 Jul 2010 21:37:38 +0000 (23:37 +0200)
modules/ferm/manifests/per-host.pp

index 2a29a17c7c782c38bbe272a7d3786e334dcbf06c..4ed687f72aee1973bf61d06c8f1a18136a59d7fe 100644 (file)
@@ -82,5 +82,17 @@ class ferm::per-host {
                    rule            => "&SERVICE(tcp, 25)"
            }
         }
+       draghi: {
+            @ferm::rule { "dsa-bind":
+                    domain          => "(ip ip6)",
+                    description     => "Allow nameserver access",
+                    rule            => "&TCP_UDP_SERVICE(53)"
+            }
+            @ferm::rule { "dsa-finger":
+                    domain          => "(ip ip6)",
+                    description     => "Allow finger access",
+                    rule            => "&SERVICE(tcp, 79)"
+           }
+        }
     }
 }