define iptables::snippet ($order = "10", $ensure = "present") {
file {"/etc/iptables.d/snippets/${order}-${name}":
owner => root,
group => root,
mode => 600,
ensure => "${ensure}",
require => File["/etc/iptables.d/snippets"],
notify => Exec["rebuildiptables.sh"],
source => ["puppet://puppet/iptables/snippets/${name}.${fqdn}",
"puppet://puppet/iptables/snippets/${name}"]
}
}
iptables::snippet{"std-prefix":
order => "00"
}
iptables::snippet{"std-suffix":
order => "999"
}
iptables::snippet{["junkfilter",
"backup_access",
"monitor_access",
"admin_access"]:
order => "01"
}
iptables::snippet{"globalrules":
order => "02"
}
service{"iptables":
enable => true,
hasrestart => true,
hasstatus => true,
ensure => running,
require => Package["iptables"]
}