diff --git a/dicos/29_one-master.xml b/dicos/29_one-master.xml
index 0f6619f..7657de7 100644
--- a/dicos/29_one-master.xml
+++ b/dicos/29_one-master.xml
@@ -7,6 +7,7 @@
+
opennebula
opennebula-scheduler
@@ -233,6 +234,7 @@
one_vip
one_vip_mask
sunstone_xmlrpc
+ one_ha
diff --git a/tmpl/60-one b/tmpl/60-one
new file mode 100644
index 0000000..24d4dfc
--- /dev/null
+++ b/tmpl/60-one
@@ -0,0 +1,5 @@
+#!/bin/bash
+
+%for %%host in %%one_nodes
+/sbin/iptables -A eth%%{one_node_int}-root -s %%host -p tcp --syn -j ACCEPT
+%end for