Taking this iptables rule as an example:
iptables -A INPUT -p icmp -m length --length 30000:65535 -j DROP
If you manage that sort of thing using puppet, how do you do it?
(The snazzy
http://forge.puppetlabs.com/puppetlabs/firewall doesn't currently do packet length, as near as I can tell. It does everything else I currently want.)