From d8ba8b9a5e0bfba9ab8c70bf63ff386e4228bf5f Mon Sep 17 00:00:00 2001 From: Peter Palfrader Date: Sun, 12 Sep 2010 10:41:19 +0200 Subject: [PATCH] Try to allow some ports to afs hosts --- manifests/site.pp | 3 +++ modules/afs/manifests/init.pp | 10 ++++++++++ modules/afs/manifests/server.pp | 35 +++++++++++++++++++++++++++++++++ 3 files changed, 48 insertions(+) create mode 100644 modules/afs/manifests/init.pp create mode 100644 modules/afs/manifests/server.pp diff --git a/manifests/site.pp b/manifests/site.pp index a79e32c58..4504a5955 100644 --- a/manifests/site.pp +++ b/manifests/site.pp @@ -113,6 +113,9 @@ node default { case $hostname { byrd,schuetz,draghi,lamb: { include krb } } + case $hostname { + lamb: { include afs::server } + } } # vim:set et: diff --git a/modules/afs/manifests/init.pp b/modules/afs/manifests/init.pp new file mode 100644 index 000000000..9d3a00724 --- /dev/null +++ b/modules/afs/manifests/init.pp @@ -0,0 +1,10 @@ +class afs { + @ferm::rule { "dsa-afs callback": + domain => "(ip ip6)", + description => "afs callback", + rule => "&SERVICE(udp, afs3-callback)" + } +} +# vim:set et: +# vim:set sts=4 ts=4: +# vim:set shiftwidth=4: diff --git a/modules/afs/manifests/server.pp b/modules/afs/manifests/server.pp new file mode 100644 index 000000000..9e663d207 --- /dev/null +++ b/modules/afs/manifests/server.pp @@ -0,0 +1,35 @@ +class afs::server inherits afs { + @ferm::rule { "dsa-afs fileserver": + domain => "(ip ip6)", + description => "afs callback", + rule => "&SERVICE(udp, afs3-fileserver)" + } + @ferm::rule { "dsa-afs prserver": + domain => "(ip ip6)", + description => "afs callback", + rule => "&SERVICE(udp, afs3-prserver)" + } + @ferm::rule { "dsa-afs vlserver": + domain => "(ip ip6)", + description => "afs callback", + rule => "&SERVICE(udp, afs3-vlserver)" + } + @ferm::rule { "dsa-afs kaserver": + domain => "(ip ip6)", + description => "afs callback", + rule => "&SERVICE(udp, afs3-kaserver)" + } + @ferm::rule { "dsa-afs volser": + domain => "(ip ip6)", + description => "afs callback", + rule => "&SERVICE(udp, afs3-volser)" + } + #@ferm::rule { "dsa-afs bos": + # domain => "(ip ip6)", + # description => "afs callback", + # rule => "&SERVICE(udp, afs3-bos)" + #} +} +# vim:set et: +# vim:set sts=4 ts=4: +# vim:set shiftwidth=4: -- 2.20.1