# include ferm
#
class ferm {
- # realize (i.e. enable) all @ferm::rule virtual resources
- Ferm::Rule <| |>
- Ferm::Conf <| |>
-
File { mode => '0400' }
package { 'ferm':
content => template('ferm/conf.d-munin-interfaces.conf.erb'),
notify => Exec['ferm reload'],
}
- @ferm::rule { 'dsa-munin-interfaces-in':
+ ferm::rule { 'dsa-munin-interfaces-in':
prio => '001',
description => 'munin accounting',
chain => 'INPUT',
domain => '(ip ip6)',
rule => 'daddr ($MUNIN_IPS) NOP'
}
- @ferm::rule { 'dsa-munin-interfaces-out':
+ ferm::rule { 'dsa-munin-interfaces-out':
prio => '001',
description => 'munin accounting',
chain => 'OUTPUT',