<% elsif scope.lookupvar('site::nodeinfo')['misc']['natted'] -%>
# autokey doesn't work behind nat
-# merikanto's and orff's ipv4 IP, hard coded for the benefit of hosts
-# that do not have RTC's (since they won't be able to do DNS until
+# czerny's, bm-bl2's, and dijkstra's ipv4 IP, hard coded for the benefit of
+# hosts that do not have RTC's (since they won't be able to do DNS until
# they have a reasonable clock).
-server 86.59.118.147 iburst
-server 194.177.211.209 iburst
+server 82.195.75.109 iburst
+server 5.153.231.242 iburst
+server 206.12.19.218 iburst
server czerny.debian.org iburst
-server merikanto.debian.org iburst
-server orff.debian.org iburst
-server ravel.debian.org iburst
-server busoni.debian.org iburst
+server clementi.debian.org iburst
+server bm-bl1.debian.org iburst
+server bm-bl2.debian.org iburst
+server dijkstra.debian.org iburst
+server luchesi.debian.org iburst
<% else -%>
server czerny.debian.org iburst autokey
-server merikanto.debian.org iburst autokey
-server orff.debian.org iburst autokey
-server ravel.debian.org iburst autokey
-server busoni.debian.org iburst autokey
+server clementi.debian.org iburst autokey
+server bm-bl1.debian.org iburst autokey
+server bm-bl2.debian.org iburst autokey
+server dijkstra.debian.org iburst autokey
+server luchesi.debian.org iburst autokey
restrict czerny.debian.org notrust nomodify notrap ntpport
-restrict merikanto.debian.org notrust nomodify notrap ntpport
-restrict orff.debian.org notrust nomodify notrap ntpport
-restrict ravel.debian.org notrust nomodify notrap ntpport
-restrict busoni.debian.org notrust nomodify notrap ntpport
+restrict clementi.debian.org notrust nomodify notrap ntpport
+restrict bm-bl1.debian.org notrust nomodify notrap ntpport
+restrict bm-bl2.debian.org notrust nomodify notrap ntpport
+restrict dijkstra.debian.org notrust nomodify notrap ntpport
+restrict luchesi.debian.org notrust nomodify notrap ntpport
<% end -%>
restrict -4 default kod notrap nomodify nopeer noquery