allow ssh access to ubc-node-arm* from ubc-bulwark (internal)
[mirror/dsa-puppet.git] / modules / ferm / manifests / rule.pp
index 8965c48..945f3dc 100644 (file)
@@ -4,14 +4,17 @@ define ferm::rule (
        $table='filter',
        $chain='INPUT',
        $description='',
-       $prio='00',
+       $prio='10',
        $notarule=false
 ) {
+
+       include ferm
+
        file {
                "/etc/ferm/dsa.d/${prio}_${name}":
                        ensure  => present,
                        mode    => '0400',
-                       content => template('ferm/ferm-rule.erb'),
-                       notify  => Service['ferm'],
+                       content => template('ferm/ferm_rule.erb'),
+                       notify  => Exec['ferm reload'],
        }
 }