X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;ds=inline;f=modules%2Fferm%2Fmanifests%2Fper-host.pp;h=39514bb7c926d3be435c8cc6629ee835ac46d9ad;hb=aaa71e6c925d3f1dbed34adbb8e4cf9a41af4aab;hp=17b16070429498dc8e9955f1fb0d61d1b1db3523;hpb=27a5af8a0e6334d729407e38c61573b3eae910d0;p=mirror%2Fdsa-puppet.git diff --git a/modules/ferm/manifests/per-host.pp b/modules/ferm/manifests/per-host.pp index 17b160704..39514bb7c 100644 --- a/modules/ferm/manifests/per-host.pp +++ b/modules/ferm/manifests/per-host.pp @@ -19,6 +19,14 @@ class ferm::per-host { } } oyens: { + @ferm::rule { 'dsa-spice': + description => 'Allow spice-console access', + rule => '&SERVICE(tcp, 6082)' + } + @ferm::rule { 'dsa-memcache': + description => 'Allow memcache access', + rule => '&SERVICE_RANGE(tcp, 11211, ( 5.153.231.240/27 172.29.123.0/24 ))' + } @ferm::rule { 'dsa-amqp': description => 'Allow rabbitmq access', rule => '&SERVICE_RANGE(tcp, 5672, ( 5.153.231.240/27 172.29.123.0/24 ))' @@ -173,24 +181,14 @@ class ferm::per-host { rule => 'proto tcp daddr 206.12.19.150 dport 80 REDIRECT to-ports 6081', } } - lw05: { - @ferm::rule { 'dsa-snapshot-varnish': - rule => '&SERVICE(tcp, 6081)', - } - @ferm::rule { 'dsa-nat-snapshot-varnish': - table => 'nat', - chain => 'PREROUTING', - rule => 'proto tcp daddr 185.17.185.181 dport 80 REDIRECT to-ports 6081', - } - } - lw06: { + lw07: { @ferm::rule { 'dsa-snapshot-varnish': rule => '&SERVICE(tcp, 6081)', } @ferm::rule { 'dsa-nat-snapshot-varnish': table => 'nat', chain => 'PREROUTING', - rule => 'proto tcp daddr 185.17.185.182 dport 80 REDIRECT to-ports 6081', + rule => 'proto tcp daddr 185.17.185.185 dport 80 REDIRECT to-ports 6081', } } default: {} @@ -413,13 +411,23 @@ class ferm::per-host { } @ferm::rule { 'dsa-postgres-replication': description => 'Allow postgress access', - rule => '&SERVICE_RANGE(tcp, 5433, ( 185.17.185.180/32 ))' + rule => '&SERVICE_RANGE(tcp, 5433, ( 185.17.185.187/32 ))' + } + @ferm::rule { 'dsa-postgres-replication6': + domain => 'ip6', + description => 'Allow postgress access', + rule => '&SERVICE_RANGE(tcp, 5433, ( 2001:1af8:4020:b030:deb::187/128 ))' } } - lw04: { + lw07: { @ferm::rule { 'dsa-postgres-snapshot': description => 'Allow postgress access', - rule => '&SERVICE_RANGE(tcp, 5439, ( 185.17.185.181/32 185.17.185.182/32 ))' + rule => '&SERVICE_RANGE(tcp, 5439, ( 185.17.185.176/28 ))' + } + @ferm::rule { 'dsa-postgres-snapshot6': + domain => 'ip6', + description => 'Allow postgress access', + rule => '&SERVICE_RANGE(tcp, 5439, ( 2001:1af8:4020:b030::/64 ))' } } default: {} @@ -470,7 +478,7 @@ REJECT reject-with icmp-admin-prohibited master: { @ferm::rule { 'dsa-tftp': description => 'Allow tftp access', - rule => '&SERVICE_RANGE(udp, 69, ( 82.195.75.64/26 ))' + rule => '&SERVICE_RANGE(udp, 69, ( 82.195.75.64/26 192.168.43.0/24 ))' } } }