Allow all from vlan20
authorPeter Palfrader <peter@palfrader.org>
Sat, 13 Apr 2013 12:39:40 +0000 (14:39 +0200)
committerPeter Palfrader <peter@palfrader.org>
Sat, 13 Apr 2013 12:39:40 +0000 (14:39 +0200)
modules/ferm/manifests/per-host.pp

index bb40a0a..575050f 100644 (file)
@@ -307,4 +307,12 @@ REJECT reject-with icmp-admin-prohibited
                }
                default: {}
        }
+       case $::hostname {
+               bm-bl1,bm-bl2,bm-bl3,bm-bl4,bm-bl5,bm-bl6,bm-bl7,bm-bl8,bm-bl9,bm-bl10,bm-bl11,bm-bl12,bm-bl13,bm-bl14: {
+                       @ferm::rule { 'dsa-hwnet-vlan20':
+                               rule            => 'interface vlan20 jump ACCEPT',
+                       }
+               }
+               default: {}
+       }
 }