cache.ipaddresses(:family => :inet, :role => :external).sort.each do |address|
firewall_rule "accept-squid" do
action :accept
+ family "inet"
source "net:#{address}"
dest "fw"
proto "tcp:syn"
end
firewall_rule "accept-squid-icp" do
action :accept
+ family "inet"
source "net:#{address}"
dest "fw"
proto "udp"