case $::hostname {
casulana: {
- @ferm::rule { 'dsa-cloud-builds-nat':
- description => 'masquerade br1 virtual machines',
+ @ferm::rule { 'dsa-cloud-builds-br1-in':
+ description => 'br1 virtual machines - in',
+ table => 'filter',
+ chain => 'INPUT',
+ rule => 'interface br1 ACCEPT'
+ }
+ @ferm::rule { 'dsa-cloud-builds-br1-nat':
+ description => 'br1 virtual machines - nat',
table => 'nat',
chain => 'POSTROUTING',
rule => 'saddr 172.16.1.0/24 outerface bond0.21 MASQUERADE'