exim needs to listen on 2025 for even more stupid firewalls
[mirror/dsa-nagios.git] / config / nagios-master.cfg
index 5e0bfdc..b46e373 100644 (file)
@@ -160,6 +160,10 @@ servers:
     address: 147.215.2.249
     parents: gw-HP-ftc
     hostgroups: routing-infrastructure
+  gw-ghent:
+    address: 193.191.17.50
+    parents: gw-HP-ftc
+    hostgroups: routing-infrastructure
 
   global:
     hostgroups: notacomputer
@@ -420,16 +424,6 @@ servers:
     parents: gw-xandros
     hostgroups: deadslow
 
-  kullervo:
-    address: 217.114.76.82
-    parents: gw-nmmn
-    hostgroups: deadslow
-    contacts: luk
-  crest:
-    address: 217.114.76.83
-    parents: gw-nmmn
-    hostgroups: deadslow
-    contacts: luk
   pescetti:
     address: 217.114.76.85
     parents: gw-nmmn
@@ -454,9 +448,14 @@ servers:
 
   allegri:
     address: 157.193.39.233
-    parents: gw-HP-ftc
+    parents: gw-ghent
     hostgroups: computers, buildd, postfix-hosts, sw-raid, single-cpu, lenny, puppet, hassrvfs
     contacts: luk
+  ancina:
+    address: 157.193.39.13
+    parents: gw-ghent
+    hostgroups: computers, buildd, single-cpu, lenny, puppet, hassrvfs, hasbootfs, incomingmailrelayed2025
+    contacts: luk
 
   agnesi:
     address: 65.173.90.83
@@ -532,7 +531,7 @@ servers:
   schein:
     address: 149.20.20.6
     parents: gw-isc
-    hostgroups: computers, service, apache2-hosts, ftpd-hosts, rsyncd-hosts, acpid-hosts, lenny, rsyslog-hosts, puppet, dl360
+    hostgroups: computers, service, apache2-hosts, ftpd-hosts, rsyncd-hosts, acpid-hosts, lenny, rsyslog-hosts, puppet, dl360, bind9-hosts
 
   praetorius:
     address: 130.239.18.121
@@ -542,7 +541,7 @@ servers:
   lafayette:
     address: 147.215.7.160
     parents: gw-esiee
-    hostgroups: computers, buildd, lenny, puppet, sw-raid, hassrvfs, hasbootfs
+    hostgroups: computers, buildd, lenny, puppet, sw-raid, hassrvfs, hasbootfs, incomingmailrelayed
 
 #############################
 # host groups
@@ -699,6 +698,14 @@ hostgroups:
     alias: hosts with a /srv
     private: 1
 
+  incomingmailrelayed:
+    alias: incoming mail needs to go through a mail relay
+    # i.e. no port 25
+    private: 1
+  incomingmailrelayed2025:
+    alias: incoming mail needs to go through a mail relay
+    # i.e. no port 25
+    private: 1
 
 #############################
 # servicegroups
@@ -971,15 +978,8 @@ services:
     check: "dsa_check_ssh_port_version!22!OpenSSH_4.3p2 Debian-9etch3"
     depends: network service - sshd
     hostgroups: computers, deadslow
-    excludehosts: crest, kullervo
     excludehostgroups: lenny
     normal_check_interval:  60
-  -
-    name: "network service - sshd - version"
-    check: "dsa_check_ssh_port_version!22!OpenSSH_4.3p2 Debian-9etch2+m68k1"
-    depends: network service - sshd
-    hosts: crest, kullervo
-    normal_check_interval:  60
   -
     name: "network service - sshd - version"
     check: "dsa_check_ssh_port_version!22!OpenSSH_5.1p1 Debian-5"
@@ -1309,8 +1309,7 @@ services:
     name: network service - smtp
     check: dsa_check_smtp
     hostgroups: computers
-    excludehostgroups: postfix-hosts
-    excludehosts: lafayette
+    excludehostgroups: postfix-hosts, incomingmailrelayed, incomingmailrelayed2025
     depends: process - exim
 
   -
@@ -1322,7 +1321,12 @@ services:
   -
     name: network service - submission
     check: dsa_check_smtp_port!587
-    hosts: lafayette
+    hostgroups: incomingmailrelayed
+    depends: process - exim
+  -
+    name: network service - smtp 2025
+    check: dsa_check_smtp_port!2025
+    hostgroups: incomingmailrelayed2025
     depends: process - exim
   -
     name: network service - smtp - port 2025
@@ -1420,6 +1424,12 @@ services:
     nrpe: "/usr/lib/nagios/plugins/dsa-check-raid-sw"
     hostgroups: sw-raid
 
+ ###
+  -
+    name: process - monit
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C monit -a '/usr/sbin/monit -d 300 -c /etc/monit/monitrc -s /var/lib/monit/monit.state'"
+    hostgroups: lenny
+    excludehosts: agnesi
  ###
   -
     name: process - cpqarrayd