]> git.donarmstrong.com Git - dsa-puppet.git/commitdiff
cleanup a bit
authorStephen Gran <steve@lobefin.net>
Sun, 21 Feb 2010 00:57:40 +0000 (00:57 +0000)
committerStephen Gran <steve@lobefin.net>
Sun, 21 Feb 2010 00:58:00 +0000 (00:58 +0000)
Signed-off-by: Stephen Gran <steve@lobefin.net>
modules/ferm/files/defs.conf
modules/ferm/files/ferm.conf
modules/ferm/manifests/init.pp

index 3c3bc30eb6905b0190cb2b07ae69b5b17afd42da..608e89fbf7e8fa72558be35a0b7ec56acc321474 100644 (file)
@@ -12,8 +12,7 @@
 }
 
 @def &TCP_UDP_SERVICE($port) = {
- proto tcp mod state state (NEW) dport $port ACCEPT;
- proto udp mod state state (NEW) dport $port ACCEPT;
+ proto (tcp udp) mod state state (NEW) dport $port ACCEPT;
 }
 
 @def $HOST_MUNIN  = (192.25.206.33);
index 8229ff80d36bd40734729198f92cafc806e78f44..f761b01e82ed39cc3cbd2e4d7da1d57b0ef6404b 100644 (file)
@@ -51,3 +51,9 @@ domain (ip ip6) {
 }
 
 @include 'dsa.d/';
+
+domain (ip ip6) {
+        chain INPUT {
+                jump log_or_drop;
+        }
+}
index a083892b699dd3729c06952caf7d3e54e3eab9c9..3d35bae0c97df9a55a548219ba47e7bb362cc828 100644 (file)
@@ -43,14 +43,6 @@ class ferm {
                         notify  => Exec["ferm restart"];
         }
 
-        ferm::rule { "dsa-drop":
-                domain          => "(ip ip6)",
-                description     => "Drop everything else",
-                prio            => "99",
-                rule            => "jump log_or_drop"
-        }
-
-
         exec { "ferm restart":
                 command     => "/etc/init.d/ferm restart",
                 refreshonly => true,