Signed-off-by: Stephen Gran <steve@lobefin.net>
command => "/etc/init.d/apache2 force-reload",
refreshonly => true,
}
+ ferm::rule { "dsa-apache":
+ description => "Allow web access",
+ rule => "proto tcp mod state state (NEW) dport (80) ACCEPT"
+ }
}
path => "/etc/init.d:/usr/bin:/usr/sbin:/bin:/sbin",
refreshonly => true,
}
+ ferm::rule { "dsa-exim":
+ description => "Allow smtp access",
+ rule => "proto tcp mod state state (NEW) dport (25) ACCEPT"
+ }
}
mode => 775,
;
}
+ ferm::rule { "dsa-bind":
+ description => "Allow nameserver access",
+ rule => "proto (udp tcp) mod state state (NEW) dport (53) ACCEPT"
+ }
}
# vim: set fdm=marker ts=8 sw=8 et:
path => "/etc/init.d:/usr/bin:/usr/sbin:/bin:/sbin",
refreshonly => true,
}
+ ferm::rule { "dsa-ntp":
+ description => "Allow ntp access",
+ rule => "proto udp mod state state (NEW) dport (123) ACCEPT"
+ }
}