will ferm do the right thing?
authorStephen Gran <steve@lobefin.net>
Sun, 21 Feb 2010 16:49:32 +0000 (16:49 +0000)
committerStephen Gran <steve@lobefin.net>
Sun, 21 Feb 2010 16:49:32 +0000 (16:49 +0000)
Signed-off-by: Stephen Gran <steve@lobefin.net>
modules/munin-node/manifests/init.pp

index ac999ef..a678a66 100644 (file)
@@ -74,9 +74,14 @@ class munin-node {
         path        => "/etc/init.d:/usr/bin:/usr/sbin:/bin:/sbin",
         refreshonly => true,
     }
-    @ferm::rule { "dsa-munin":
+    @ferm::rule { "dsa-munin-v4"
             description     => "Allow munin from munin master",
-            rule            => "proto tcp mod state state (NEW) dport (munin) @subchain 'munin' { saddr (\$HOST_MUNIN) ACCEPT; }"
+            rule            => "proto tcp mod state state (NEW) dport (munin) @subchain 'munin' { saddr (\$HOST_MUNIN_V4) ACCEPT; }"
+    }
+    @ferm::rule { "dsa-munin-v4"
+            description     => "Allow munin from munin master",
+            domain          => "ip6",
+            rule            => "proto tcp mod state state (NEW) dport (munin) @subchain 'munin' { saddr (\$HOST_MUNIN_V6) ACCEPT; }"
     }
 }