I think this ferm rule is no longer needed
[mirror/dsa-puppet.git] / modules / ferm / manifests / per-host.pp
index b9dbbc0..dc8dfbd 100644 (file)
@@ -87,11 +87,11 @@ class ferm::per-host {
            }
         }
        draghi: {
-            @ferm::rule { "dsa-bind":
-                    domain          => "(ip ip6)",
-                    description     => "Allow nameserver access",
-                    rule            => "&TCP_UDP_SERVICE(53)"
-            }
+            #@ferm::rule { "dsa-bind":
+            #        domain          => "(ip ip6)",
+            #        description     => "Allow nameserver access",
+            #        rule            => "&TCP_UDP_SERVICE(53)"
+            #}
             @ferm::rule { "dsa-finger":
                     domain          => "(ip ip6)",
                     description     => "Allow finger access",
@@ -111,7 +111,7 @@ class ferm::per-host {
        cilea: {
             file {
                 "/etc/ferm/conf.d/load_sip_conntrack.conf":
-                    source => "puppet:///ferm/conntrack_sip.conf",
+                    source => "puppet:///modules/ferm/conntrack_sip.conf",
                     require => Package["ferm"],
                     notify  => Exec["ferm restart"];
             }
@@ -200,7 +200,7 @@ class ferm::per-host {
     case $hostname {
         sibelius: {
             @ferm::rule { "dsa-snapshot-varnish":
-                rule            => '&SERVICE(tcp, 11371)',
+                rule            => '&SERVICE(tcp, 6081)',
             }
             @ferm::rule { "dsa-nat-snapshot-varnish":
                 table           => 'nat',
@@ -208,6 +208,16 @@ class ferm::per-host {
                 rule            => 'proto tcp daddr 193.62.202.28 dport 80 REDIRECT to-ports 6081',
             }
         }
+        stabile: {
+            @ferm::rule { "dsa-snapshot-varnish":
+                rule            => '&SERVICE(tcp, 6081)',
+            }
+            @ferm::rule { "dsa-nat-snapshot-varnish":
+                table           => 'nat',
+                chain           => 'PREROUTING',
+                rule            => 'proto tcp daddr 206.12.19.150 dport 80 REDIRECT to-ports 6081',
+            }
+        }
     }
 }