}
case $::hostname {
- casulana: {
- @ferm::rule { 'dsa-cloud-builds-br1-in':
- description => 'br1 virtual machines - in',
- table => 'filter',
- chain => 'INPUT',
- rule => 'interface br1 ACCEPT'
- }
- @ferm::rule { 'dsa-cloud-builds-br1-nat':
- description => 'br1 virtual machines - nat',
- table => 'nat',
- chain => 'POSTROUTING',
- rule => 'saddr 172.16.1.0/24 outerface bond0.21 MASQUERADE'
- }
- }
czerny,clementi: {
@ferm::rule { 'dsa-upsmon':
description => 'Allow upsmon access',
}
@ferm::rule { 'dsa-postgres-replication':
description => 'Allow postgress access',
- rule => '&SERVICE_RANGE(tcp, 5433, ( 185.17.185.187/32 ))'
+ rule => '&SERVICE_RANGE(tcp, 5433, ( 185.17.185.187/32 193.62.202.26/32 ))'
}
@ferm::rule { 'dsa-postgres-replication6':
domain => 'ip6',
description => 'Allow postgress access',
- rule => '&SERVICE_RANGE(tcp, 5433, ( 2001:1af8:4020:b030:deb::187/128 ))'
+ rule => '&SERVICE_RANGE(tcp, 5433, ( 2001:1af8:4020:b030:deb::187/128 2001:630:206:4000:1a1a:0:c13e:ca1a/128 ))'
}
}
lw07: {