+
+ exec { "ssh restart":
+ path => "/etc/init.d:/usr/bin:/usr/sbin:/bin:/sbin",
+ refreshonly => true,
+ }
+
+ @ferm::rule { "dsa-ssh":
+ description => "Allow SSH from DSA",
+ rule => "&SERVICE_RANGE(tcp, ssh, \$SSH_SOURCES)"
+ }
+ @ferm::rule { "dsa-ssh-v6":
+ description => "Allow SSH from DSA",
+ domain => "ip6",
+ rule => "&SERVICE_RANGE(tcp, ssh, \$SSH_V6_SOURCES)"
+ }