{
my $ovpndb = esmith::ConfigDB->open_ro('openvpn-s2s');

foreach my $vpn ($ovpndb->get_all_by_prop(type=>('client')),
                 $ovpndb->get_all_by_prop(type=>('server'))){
    $OUT .= "/sbin/iptables -A \$NEW_local_chk --in-interface tun" . $vpn->key .
            " -j denylog\n" if (($vpn->prop('AllowInbound') || 'yes') eq 'no');
}

}
