Add iptables support
diff --git a/metadata/service/support.yml b/metadata/service/support.yml
index 3c7b21b..3d4b004 100644
--- a/metadata/service/support.yml
+++ b/metadata/service/support.yml
@@ -11,3 +11,5 @@
         enabled: false
       backupninja:
         enabled: true
+      iptables:
+        enabled: true
diff --git a/mysql/init.sls b/mysql/init.sls
old mode 100755
new mode 100644
diff --git a/mysql/meta/iptables.yml b/mysql/meta/iptables.yml
new file mode 100644
index 0000000..cbee7e4
--- /dev/null
+++ b/mysql/meta/iptables.yml
@@ -0,0 +1,11 @@
+{%- from "mysql/map.jinja" import server with context -%}
+
+iptables:
+  rules:
+    - destination_port: {{ server.bind.port }}
+      protocol: tcp
+      jump: ACCEPT
+
+{#-
+vim: syntax=jinja
+-#}