X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;f=modules%2Fferm%2Fmanifests%2Fftp_conntrack.pp;h=87e1b0c8bdddadec2afe89bbde8e89516dda68af;hb=0bb17a25732535255cd66b25fe2406ead83d6388;hp=45e060b62f42a975397f74987acc8b89301bdb1d;hpb=15811369946e05646a4743712dd8a58a3bd37038;p=mirror%2Fdsa-puppet.git diff --git a/modules/ferm/manifests/ftp_conntrack.pp b/modules/ferm/manifests/ftp_conntrack.pp index 45e060b62..87e1b0c8b 100644 --- a/modules/ferm/manifests/ftp_conntrack.pp +++ b/modules/ferm/manifests/ftp_conntrack.pp @@ -2,7 +2,7 @@ class ferm::ftp_conntrack { # This also works for jessie hosts, but requires a reboot if (versioncmp($::lsbmajdistrelease, '9') >= 0) { # Allow non-passive connections to an FTP server - @ferm::rule { 'dsa-ftp-conntrack-client': + ferm::rule { 'dsa-ftp-conntrack-client': domain => '(ip ip6)', description => 'ftp client connection tracking', table => 'raw', @@ -11,7 +11,7 @@ class ferm::ftp_conntrack { } # Allow passive connections from an FTP client - @ferm::rule { 'dsa-ftp-conntrack-server': + ferm::rule { 'dsa-ftp-conntrack-server': domain => '(ip ip6)', description => 'ftp server connection tracking', table => 'raw',