Move the single ipsec tunnel we have to my new system.
[mirror/dsa-puppet.git] / modules / ipsec / templates / ferm.erb
diff --git a/modules/ipsec/templates/ferm.erb b/modules/ipsec/templates/ferm.erb
deleted file mode 100644 (file)
index 82b8a6b..0000000
+++ /dev/null
@@ -1,28 +0,0 @@
-##
-## THIS FILE IS UNDER PUPPET CONTROL. DON'T EDIT IT HERE.
-##
-
-<%
-config = YAML.load(@ipsec_config)
-
-unless config.keys.include?(@fqdn) then
-       fail("Host #{@fqdn} not found in ipsec config.")
-end
-
-peers = []
-config.keys.each do |host|
-       next if @fqdn == host
-       peers << config[host]['address']
-end
-%>
-
-domain ip table filter {
-  chain ipsec-peers {
-    saddr (<%= peers.join(" ")  %>) ACCEPT;
-  }
-
-  chain INPUT {
-    proto udp dport (isakmp) jump ipsec-peers;
-    proto esp                jump ipsec-peers;
-  }
-}