diff options
author | Micah Anderson <micah@riseup.net> | 2015-05-08 16:07:30 -0400 |
---|---|---|
committer | Micah Anderson <micah@riseup.net> | 2015-05-08 16:07:30 -0400 |
commit | 77ce0b926b7418703223b4a6c489067f9d9bc4f5 (patch) | |
tree | 26892e3f801b3f32444a2bb494823f0e37c305e0 /manifests/rules/libvirt | |
parent | 8a549b74ff01e4b8076f9e183526ba385c9d8f5a (diff) | |
parent | 74ea10a6a1d4f4c1624d85d3d3795eaf819df10c (diff) |
Merge branch 'master' into riseup
Diffstat (limited to 'manifests/rules/libvirt')
-rw-r--r-- | manifests/rules/libvirt/host.pp | 11 |
1 files changed, 11 insertions, 0 deletions
diff --git a/manifests/rules/libvirt/host.pp b/manifests/rules/libvirt/host.pp index dfb753c..c226865 100644 --- a/manifests/rules/libvirt/host.pp +++ b/manifests/rules/libvirt/host.pp @@ -2,6 +2,8 @@ class shorewall::rules::libvirt::host ( $vmz = 'vmz', $masq_iface = 'eth0', $debproxy_port = 8000, + $accept_dhcp = true, + $vmz_iface = 'virbr0', ) { define shorewall::rule::accept::from_vmz ( @@ -49,6 +51,15 @@ class shorewall::rules::libvirt::host ( action => 'ACCEPT'; } + if $accept_dhcp { + shorewall::mangle { 'CHECKSUM:T': + source => '-', + destination => $vmz_iface, + proto => 'udp', + destinationport => '68'; + } + } + if $debproxy_port { shorewall::rule::accept::from_vmz { 'accept_debproxy_from_vmz': proto => 'tcp', |