X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;f=modules%2Fnagios%2Fmanifests%2Fclient.pp;h=44a6f3254a7064fe819371d22592ca5b89325930;hb=ed9c052bcce0377d8c9f1f7de79fe3114c8f8bf8;hp=7393260ea08bec1d433e849a4435b88b4ae3fe80;hpb=70a9bda9ef6e5fa2cebded47c59a11a2592c5511;p=mirror%2Fdsa-puppet.git diff --git a/modules/nagios/manifests/client.pp b/modules/nagios/manifests/client.pp index 7393260ea..44a6f3254 100644 --- a/modules/nagios/manifests/client.pp +++ b/modules/nagios/manifests/client.pp @@ -47,12 +47,14 @@ class nagios::client inherits nagios { } @ferm::rule { "dsa-nagios-v4": description => "Allow nrpe from nagios master", - rule => "proto tcp mod state state (NEW) dport (5666) @subchain 'nagios' { saddr (\$HOST_NAGIOS_V4) ACCEPT; }" + rule => "proto tcp mod state state (NEW) dport (5666) @subchain 'nagios' { saddr (\$HOST_NAGIOS_V4) ACCEPT; }", + notarule => true, } @ferm::rule { "dsa-nagios-v6": description => "Allow nrpe from nagios master", domain => "ip6", - rule => "proto tcp mod state state (NEW) dport (5666) @subchain 'nagios' { saddr (\$HOST_NAGIOS_V6) ACCEPT; }" + rule => "proto tcp mod state state (NEW) dport (5666) @subchain 'nagios' { saddr (\$HOST_NAGIOS_V6) ACCEPT; }", + notarule => true, } } # vim:set et: