X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;ds=sidebyside;f=modules%2Fferm%2Fmanifests%2Fper-host.pp;h=3ab0d631ad6097933996415f1c4a3bdbac29758b;hb=7b062baee2e55c34f6c71a8f10919492de0bb2c5;hp=b96c021fad66bdb4a0eb8c7ac1feda767d698fcb;hpb=96b815ca2a08997b511e94c46ba094186562802c;p=mirror%2Fdsa-puppet.git diff --git a/modules/ferm/manifests/per-host.pp b/modules/ferm/manifests/per-host.pp index b96c021fa..3ab0d631a 100644 --- a/modules/ferm/manifests/per-host.pp +++ b/modules/ferm/manifests/per-host.pp @@ -19,6 +19,10 @@ class ferm::per-host { } } oyens: { + @ferm::rule { 'dsa-memcache': + description => 'Allow memcache access', + rule => '&SERVICE_RANGE(tcp, 11211, ( 5.153.231.240/27 172.29.123.0/24 ))' + } @ferm::rule { 'dsa-amqp': description => 'Allow rabbitmq access', rule => '&SERVICE_RANGE(tcp, 5672, ( 5.153.231.240/27 172.29.123.0/24 ))' @@ -173,26 +177,6 @@ class ferm::per-host { rule => 'proto tcp daddr 206.12.19.150 dport 80 REDIRECT to-ports 6081', } } - lw05: { - @ferm::rule { 'dsa-snapshot-varnish': - rule => '&SERVICE(tcp, 6081)', - } - @ferm::rule { 'dsa-nat-snapshot-varnish': - table => 'nat', - chain => 'PREROUTING', - rule => 'proto tcp daddr 185.17.185.181 dport 80 REDIRECT to-ports 6081', - } - } - lw06: { - @ferm::rule { 'dsa-snapshot-varnish': - rule => '&SERVICE(tcp, 6081)', - } - @ferm::rule { 'dsa-nat-snapshot-varnish': - table => 'nat', - chain => 'PREROUTING', - rule => 'proto tcp daddr 185.17.185.182 dport 80 REDIRECT to-ports 6081', - } - } lw07: { @ferm::rule { 'dsa-snapshot-varnish': rule => '&SERVICE(tcp, 6081)', @@ -423,19 +407,13 @@ class ferm::per-host { } @ferm::rule { 'dsa-postgres-replication': description => 'Allow postgress access', - rule => '&SERVICE_RANGE(tcp, 5433, ( 185.17.185.180/32 185.17.185.187/32 ))' - } - } - lw04: { - @ferm::rule { 'dsa-postgres-snapshot': - description => 'Allow postgress access', - rule => '&SERVICE_RANGE(tcp, 5439, ( 185.17.185.181/32 185.17.185.182/32 ))' + rule => '&SERVICE_RANGE(tcp, 5433, ( 185.17.185.187/32 2001:1af8:4020:b030:deb::187/128 ))' } } lw07: { @ferm::rule { 'dsa-postgres-snapshot': description => 'Allow postgress access', - rule => '&SERVICE_RANGE(tcp, 5439, ( 185.17.185.176/28 ))' + rule => '&SERVICE_RANGE(tcp, 5439, ( 185.17.185.176/28 2001:1af8:4020:b030::/64 ))' } } default: {} @@ -486,7 +464,7 @@ REJECT reject-with icmp-admin-prohibited master: { @ferm::rule { 'dsa-tftp': description => 'Allow tftp access', - rule => '&SERVICE_RANGE(udp, 69, ( 82.195.75.64/26 ))' + rule => '&SERVICE_RANGE(udp, 69, ( 82.195.75.64/26 192.168.43.0/24 ))' } } }