}
# firewalling
- ferm::rule::simple { 'dsa-bind-from-third-party-secondaries':
+ ferm::rule::simple { 'dns-from-secondaries':
description => 'Allow additional (such as 3rd party secondary nameserver) access to the primary',
proto => ['udp', 'tcp'],
port => 'domain',