diff options
author | varac <varacanero@zeromail.org> | 2013-02-12 13:26:42 +0100 |
---|---|---|
committer | varac <varacanero@zeromail.org> | 2013-02-12 13:26:42 +0100 |
commit | 102af94df02decef888bac09748dbac6773dedd6 (patch) | |
tree | e4f92fd7390f02745d576f5573acc7bf88adba0a /puppet/modules/site_shorewall | |
parent | b754c9f3412441c58e90fa57dc236fab74cee167 (diff) |
fixed shorewall is blocking api port (Bug #1735)
Diffstat (limited to 'puppet/modules/site_shorewall')
-rw-r--r-- | puppet/modules/site_shorewall/manifests/service/webapp_api.pp | 21 | ||||
-rw-r--r-- | puppet/modules/site_shorewall/manifests/webapp.pp | 1 |
2 files changed, 22 insertions, 0 deletions
diff --git a/puppet/modules/site_shorewall/manifests/service/webapp_api.pp b/puppet/modules/site_shorewall/manifests/service/webapp_api.pp new file mode 100644 index 00000000..9d4296e5 --- /dev/null +++ b/puppet/modules/site_shorewall/manifests/service/webapp_api.pp @@ -0,0 +1,21 @@ +class site_shorewall::service::webapp_api { + + $api = hiera('api') + $api_port = $api['port'] + + # define macro for incoming services + file { '/etc/shorewall/macro.leap_webapp_api': + content => "PARAM - - tcp $api_port ", + notify => Service['shorewall'] + } + + + shorewall::rule { + 'net2fw-webapp_api': + source => 'net', + destination => '$FW', + action => 'leap_webapp_api(ACCEPT)', + order => 200; + } + +} diff --git a/puppet/modules/site_shorewall/manifests/webapp.pp b/puppet/modules/site_shorewall/manifests/webapp.pp index 31a65b1b..d12bbc8f 100644 --- a/puppet/modules/site_shorewall/manifests/webapp.pp +++ b/puppet/modules/site_shorewall/manifests/webapp.pp @@ -2,4 +2,5 @@ class site_shorewall::webapp { include site_shorewall::defaults include site_shorewall::service::https + include site_shorewall::service::webapp_api } |