notify => Exec['bacula-sd restart-when-idle']
}
- ferm::rule { 'dsa-bacula-sd-v4':
- domain => '(ip)',
- description => 'Allow bacula-sd access from director and clients',
- rule => 'proto tcp mod state state (NEW) dport (bacula-sd) @subchain \'bacula-sd\' { saddr ($HOST_DEBIAN_V4 5.153.231.125 5.153.231.126) ACCEPT; }',
- notarule => true,
- }
-
- ferm::rule { 'dsa-bacula-sd-v6':
- domain => '(ip6)',
- description => 'Allow bacula-sd access from director and clients',
- rule => 'proto tcp mod state state (NEW) dport (bacula-sd) @subchain \'bacula-sd\' { saddr ($HOST_DEBIAN_V6) ACCEPT; }',
+ ferm::rule { 'dsa-bacula-sd':
+ domain => '(ip ip6)',
+ description => 'Allow bacula-sd access from director and clients (i.e. all of Debian)',
+ rule => 'proto tcp mod state state (NEW) dport (bacula-sd) @subchain \'bacula-sd\' { saddr ($HOST_DEBIAN 5.153.231.125 5.153.231.126) ACCEPT; }',
notarule => true,
}