port => '7', # overridden on collecting
saddr => $bacula::public_addresses,
}
+ @@ferm::rule::simple { "bacula::director-to-storage::${::fqdn}":
+ tag => 'bacula::director-to-storage',
+ description => 'Allow bacula-storage access from the bacula-director',
+ port => '7', # overridden on collecting
+ saddr => $bacula::public_addresses,
+ }
}
rule => 'proto tcp mod state state (NEW) dport (bacula-sd) @subchain \'bacula-sd\' { saddr ($HOST_DEBIAN) ACCEPT; }',
notarule => true,
}
+ # allow access from director
+ Ferm::Rule::Simple <<| tag == 'bacula::director-to-storage' |>> {
+ port => $bacula::bacula_storage_port,
+ }
file { '/etc/bacula/storage-conf.d/empty.conf':
content => '',