summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authormh <mh@immerda.ch>2011-04-26 03:08:37 +0200
committerMicah Anderson <micah@riseup.net>2011-06-21 12:16:27 -0400
commitb67bb6c1571506ae4b1d49feab06e73b75515f29 (patch)
treee292dfd5a636a930ac2eb5119d6db8618c8e74da
parente27f9a83ed912eeef399878e7a8a3c77035b53de (diff)
allow esp traffic from and to me
-rw-r--r--manifests/rules/ipsec.pp18
1 files changed, 15 insertions, 3 deletions
diff --git a/manifests/rules/ipsec.pp b/manifests/rules/ipsec.pp
index c609d0a..3e9db55 100644
--- a/manifests/rules/ipsec.pp
+++ b/manifests/rules/ipsec.pp
@@ -1,18 +1,30 @@
class shorewall::rules::ipsec {
- shorewall::rule { 'net-me-ipsec-udp':
+ shorewall::rule {
+ 'net-me-ipsec-udp':
source => 'net',
destination => '$FW',
proto => 'udp',
destinationport => '500',
order => 240,
action => 'ACCEPT';
- }
- shorewall::rule { 'me-net-ipsec-udp':
+ 'me-net-ipsec-udp':
source => '$FW',
destination => 'net',
proto => 'udp',
destinationport => '500',
order => 240,
action => 'ACCEPT';
+ 'net-me-ipsec':
+ source => 'net',
+ destination => '$FW',
+ proto => 'esp',
+ order => 240,
+ action => 'ACCEPT';
+ 'me-net-ipsec':
+ source => '$FW',
+ destination => 'net',
+ proto => 'esp',
+ order => 240,
+ action => 'ACCEPT';
}
}