+
+ firewall_rule "accept-beats-#{forwarder}" do
+ action :accept
+ family interface[:family]
+ source "#{interface[:zone]}:#{interface[:address]}"
+ dest "fw"
+ proto "tcp:syn"
+ dest_ports "5044"
+ source_ports "1024:"
+ end
+ end
+end
+
+gateways = search(:node, "roles:gateway")
+
+gateways.sort_by { |n| n[:fqdn] }.each do |gateway|
+ gateway.interfaces(:role => :external) do |interface|
+ firewall_rule "accept-lumberjack-#{gateway}" do
+ action :accept
+ family interface[:family]
+ source "#{interface[:zone]}:#{interface[:address]}"
+ dest "fw"
+ proto "tcp:syn"
+ dest_ports "5043"
+ source_ports "1024:"
+ end
+
+ firewall_rule "accept-beats-#{gateway}" do
+ action :accept
+ family interface[:family]
+ source "#{interface[:zone]}:#{interface[:address]}"
+ dest "fw"
+ proto "tcp:syn"
+ dest_ports "5044"
+ source_ports "1024:"
+ end