X-Git-Url: https://git.openstreetmap.org/chef.git/blobdiff_plain/7735d1ca60575ffdbc9be0b33e3df049ac4d2f6f..c30bf38a3bc31371fd5a9da3ebc383bd6236b4d3:/cookbooks/networking/recipes/default.rb diff --git a/cookbooks/networking/recipes/default.rb b/cookbooks/networking/recipes/default.rb index 116d90c72..4fc08a61b 100644 --- a/cookbooks/networking/recipes/default.rb +++ b/cookbooks/networking/recipes/default.rb @@ -460,9 +460,15 @@ firewall_rule "limit-icmp-echo" do end if node[:networking][:wireguard][:enabled] + wireguard_source = if node[:roles].include?("gateway") + "net" + else + "osm" + end + firewall_rule "accept-wireguard" do action :accept - source "net" + source wireguard_source dest "fw" proto "udp" dest_ports "51820"