]> review.fuel-infra Code Review - puppet-modules/puppetlabs-firewall.git/commitdiff
Added quickstart not on how to make firewall rules persistent.
authorKen Barber <ken@bob.sh>
Sun, 10 Jul 2011 22:42:25 +0000 (23:42 +0100)
committerKen Barber <ken@bob.sh>
Sun, 10 Jul 2011 22:42:25 +0000 (23:42 +0100)
README.markdown

index abf5a6ba7cf8a75dbbb5d8f03fcacadbbeb94388..707eeedb425badefa369cbc37eaa79d2e05d87c4 100644 (file)
@@ -55,6 +55,19 @@ Source NAT example (perfect for a virtualization host):
       table  => 'nat',
     }
 
+You can make firewall rules persistent with the following iptables example:
+
+    exec { "persist-firewall":
+      command => $operatingsystem ? {
+        "debian" => "/sbin/iptables > /etc/iptables/rules.v4",
+        /(RedHat|CentOS)/ => "/sbin/iptables > /etc/sysconfig/iptables",
+      }
+      refreshonly => true,
+    }
+    Firewall {
+      notify => Exec["persist-firewall"]
+    }
+
 ### Supported firewalls
 
 Currently we support: