diff options
author | varac <varacanero@zeromail.org> | 2012-10-30 22:25:08 +0100 |
---|---|---|
committer | varac <varacanero@zeromail.org> | 2012-10-30 22:25:08 +0100 |
commit | b9141fa98a3d22ee738ad7add3fed445a9576346 (patch) | |
tree | 0caf061f829f2db8e2b0586c85792754f6e9a74a /puppet/modules/site_shorewall/manifests/dnat_rule.pp | |
parent | b4a32c98e5bd2184f6fc5fef1300e35ab36dbb99 (diff) |
add dnat rule to redirect other ports to port 1194
Diffstat (limited to 'puppet/modules/site_shorewall/manifests/dnat_rule.pp')
-rw-r--r-- | puppet/modules/site_shorewall/manifests/dnat_rule.pp | 25 |
1 files changed, 25 insertions, 0 deletions
diff --git a/puppet/modules/site_shorewall/manifests/dnat_rule.pp b/puppet/modules/site_shorewall/manifests/dnat_rule.pp new file mode 100644 index 00000000..4fc62f85 --- /dev/null +++ b/puppet/modules/site_shorewall/manifests/dnat_rule.pp @@ -0,0 +1,25 @@ +define site_shorewall::dnat_rule { + + $port = $name + if $port != 1194 { + shorewall::rule { + "dnat_tcp_port_$port": + action => 'DNAT', + source => 'net', + destination => "\$FW:${site_config::eip::openvpn_gateway_address}:1194", + proto => 'tcp', + destinationport => $port, + order => 100; + } + + shorewall::rule { + "dnat_udp_port_$port": + action => 'DNAT', + source => 'net', + destination => "\$FW:${site_config::eip::openvpn_gateway_address}:1194", + proto => 'udp', + destinationport => $port, + order => 100; + } + } +} |