OP#561 try new fw settings

This commit is contained in:
2026-04-09 14:56:37 +02:00
parent 5481c36198
commit cf1415ceac

View File

@@ -6,22 +6,20 @@
class confdroid_ssh::firewall::iptables ( class confdroid_ssh::firewall::iptables (
) inherits confdroid_ssh::params { ) inherits confdroid_ssh::params {
if $ssh_use_firewall == true { case $ssh_use_firewall {
true, 'true', 'yes', '1': {
$ssh_fw_ensure = 'present'
}
default: {
$ssh_fw_ensure = 'absent'
}
}
firewall { "${ssh_fw_order}${ssh_fw_port} allow SSH on port ${ssh_fw_port}": firewall { "${ssh_fw_order}${ssh_fw_port} allow SSH on port ${ssh_fw_port}":
ensure => 'present', ensure => $ssh_fw_ensure,
proto => 'tcp', proto => 'tcp',
source => $ssh_source_range, source => $ssh_source_range,
dport => $ssh_fw_port, dport => $ssh_fw_port,
jump => 'accept', jump => 'accept',
} }
}
if $ssh_use_firewall == false {
firewall { "${ssh_fw_order}${ssh_fw_port} remove SSH on port ${ssh_fw_port}":
ensure => 'absent',
proto => 'tcp',
source => $ssh_source_range,
dport => $ssh_fw_port,
jump => 'accept',
}
}
} }