X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;f=modules%2Fferm%2Fmanifests%2Fper-host.pp;h=6d73b4a05c2d7ff0bf0644a15552a8f19b141f41;hb=5e6d9dff0b2445ea867131e13d7a793cd8649e48;hp=7164206c2a1acf7fd86a0ff43daead3d313fe4e8;hpb=f9cd82915b4f9db0e26a33578dfe021acf0a5655;p=mirror%2Fdsa-puppet.git diff --git a/modules/ferm/manifests/per-host.pp b/modules/ferm/manifests/per-host.pp index 7164206c2..6d73b4a05 100644 --- a/modules/ferm/manifests/per-host.pp +++ b/modules/ferm/manifests/per-host.pp @@ -82,12 +82,6 @@ class ferm::per-host { rule => 'destination 78.8.208.246/32 proto tcp dport 25 jump DROP', } } - abel,rietz,jenkins: { - @ferm::rule { 'dsa-tftp': - description => 'Allow tftp access', - rule => '&SERVICE(udp, 69)' - } - } lotti,lully: { @ferm::rule { 'dsa-syslog': description => 'Allow syslog access', @@ -179,24 +173,14 @@ class ferm::per-host { rule => 'proto tcp daddr 206.12.19.150 dport 80 REDIRECT to-ports 6081', } } - lw05: { + lw07: { @ferm::rule { 'dsa-snapshot-varnish': rule => '&SERVICE(tcp, 6081)', } @ferm::rule { 'dsa-nat-snapshot-varnish': table => 'nat', chain => 'PREROUTING', - rule => 'proto tcp daddr 185.17.185.181 dport 80 REDIRECT to-ports 6081', - } - } - lw06: { - @ferm::rule { 'dsa-snapshot-varnish': - rule => '&SERVICE(tcp, 6081)', - } - @ferm::rule { 'dsa-nat-snapshot-varnish': - table => 'nat', - chain => 'PREROUTING', - rule => 'proto tcp daddr 185.17.185.182 dport 80 REDIRECT to-ports 6081', + rule => 'proto tcp daddr 185.17.185.185 dport 80 REDIRECT to-ports 6081', } } default: {} @@ -419,13 +403,13 @@ class ferm::per-host { } @ferm::rule { 'dsa-postgres-replication': description => 'Allow postgress access', - rule => '&SERVICE_RANGE(tcp, 5433, ( 185.17.185.180/32 ))' + rule => '&SERVICE_RANGE(tcp, 5433, ( 185.17.185.187/32 2001:1af8:4020:b030:deb::187/128 ))' } } - lw04: { + lw07: { @ferm::rule { 'dsa-postgres-snapshot': description => 'Allow postgress access', - rule => '&SERVICE_RANGE(tcp, 5439, ( 185.17.185.181/32 185.17.185.182/32 ))' + rule => '&SERVICE_RANGE(tcp, 5439, ( 185.17.185.176/28 2001:1af8:4020:b030::/64 ))' } } default: {} @@ -459,4 +443,25 @@ REJECT reject-with icmp-admin-prohibited } default: {} } + # tftp + case $::hostname { + abel: { + @ferm::rule { 'dsa-tftp': + description => 'Allow tftp access', + rule => '&SERVICE_RANGE(udp, 69, ( 172.28.17.0/24 ))' + } + } + jenkins: { + @ferm::rule { 'dsa-tftp': + description => 'Allow tftp access', + rule => '&SERVICE_RANGE(udp, 69, ( 192.168.2.0/24 206.12.19.0/24 ))' + } + } + master: { + @ferm::rule { 'dsa-tftp': + description => 'Allow tftp access', + rule => '&SERVICE_RANGE(udp, 69, ( 82.195.75.64/26 192.168.43.0/24 ))' + } + } + } }