]> gitweb.fluxo.info Git - puppet-shorewall.git/commitdiff
add ipsec_nat rule port 4500
authorAndreas <andreas@immerda.ch>
Wed, 3 Oct 2012 01:28:05 +0000 (20:28 -0500)
committerAndreas <andreas@immerda.ch>
Wed, 3 Oct 2012 01:28:05 +0000 (20:28 -0500)
manifests/rules/ipsec_nat.pp [new file with mode: 0644]

diff --git a/manifests/rules/ipsec_nat.pp b/manifests/rules/ipsec_nat.pp
new file mode 100644 (file)
index 0000000..6c0d507
--- /dev/null
@@ -0,0 +1,18 @@
+class shorewall::rules::ipsec_nat {
+    shorewall::rule {
+      'net-me-ipsec-nat-udp':
+        source          => 'net',
+        destination     => '$FW',
+        proto           => 'udp',
+        destinationport => '4500',
+        order           => 240,
+        action          => 'ACCEPT';
+      'me-net-ipsec-nat-udp':
+        source          => '$FW',
+        destination     => 'net',
+        proto           => 'udp',
+        destinationport => '4500',
+        order           => 240,
+        action          => 'ACCEPT';
+    }
+}