this should virtually work
[mirror/dsa-puppet.git] / modules / exim / manifests / init.pp
index 6193cb4..8585279 100644 (file)
@@ -146,7 +146,7 @@ class exim {
           ;
         "/var/log/exim4":
           mode    => 2750,
-          ensure  => directory
+          ensure  => directory,
           owner   => Debian-exim,
           group   => maillog
           ;
@@ -156,4 +156,9 @@ class exim {
         path        => "/etc/init.d:/usr/bin:/usr/sbin:/bin:/sbin",
         refreshonly => true,
     }
+    @ferm::rule { "dsa-exim":
+            domain          => "(ip ip6)",
+            description     => "Allow smtp access",
+            rule            => "proto tcp mod state state (NEW) dport (25) ACCEPT"
+    }
 }