Signed-off-by: Stephen Gran <steve@lobefin.net>
case $hoster {
"ubcece", "darmstadt", "ftcollins", "grnet": { include resolv }
}
- case $hostname {
- brahms: { include ferm }
- }
}
path => "/etc/init.d:/usr/bin:/usr/sbin:/bin:/sbin",
refreshonly => true,
}
- ferm::rule { "dsa-munin":
- description => "Allow munin-node from spohr.debian.org",
- rule => 'proto tcp dport 4949 saddr $HOST_MUNIN ACCEPT',
- prio => "02"
- }
}
package {
nagios-nrpe-server: ensure => installed;
}
- ferm::rule { "dsa-nagios":
- description => "Allow nrpe from spohr.debian.org",
- rule => 'proto tcp dport 5666 saddr $HOST_NAGIOS ACCEPT',
- prio => "03"
- }
}
path => "/etc/init.d:/usr/bin:/usr/sbin:/bin:/sbin",
refreshonly => true,
}
- ferm::rule { "dsa-ssh":
- description => "Allow SSH",
- rule => "proto tcp dport ssh ACCEPT",
- domain => "(ip ip6)",
- prio => "01"
- }
}