class ferm::per-host {
- if $::hostname in [ancina,zandonai,zelenka] {
+ if $::hostname in [zandonai,zelenka] {
include ferm::zivit
}
rule => 'destination 78.8.208.246/32 proto tcp dport 25 jump DROP',
}
}
- lotti,lully: {
+ lotti,lully,loghost-grnet-01: {
@ferm::rule { 'dsa-syslog':
description => 'Allow syslog access',
rule => '&SERVICE_RANGE(tcp, 5140, $HOST_DEBIAN_V4)'
lw07: {
@ferm::rule { 'dsa-postgres-snapshot':
description => 'Allow postgress access',
- rule => '&SERVICE_RANGE(tcp, 5439, ( 185.17.185.176/28 2001:1af8:4020:b030::/64 ))'
+ rule => '&SERVICE_RANGE(tcp, 5439, ( 185.17.185.176/28 ))'
+ }
+ @ferm::rule { 'dsa-postgres-snapshot6':
+ domain => 'ip6',
+ description => 'Allow postgress access',
+ rule => '&SERVICE_RANGE(tcp, 5439, ( 2001:1af8:4020:b030::/64 ))'
}
}
default: {}