rule => 'destination 78.8.208.246/32 proto tcp dport 25 jump DROP',
}
}
- abel,rietz,jenkins: {
- @ferm::rule { 'dsa-tftp':
- description => 'Allow tftp access',
- rule => '&SERVICE(udp, 69)'
- }
- }
lotti,lully: {
@ferm::rule { 'dsa-syslog':
description => 'Allow syslog access',
}
@ferm::rule { 'dsa-postgres-replication':
description => 'Allow postgress access',
- rule => '&SERVICE_RANGE(tcp, 5433, ( 185.17.185.180/32 ))'
+ rule => '&SERVICE_RANGE(tcp, 5433, ( 185.17.185.180/32 185.17.185.187/32 ))'
}
}
lw04: {
rule => '&SERVICE_RANGE(tcp, 5439, ( 185.17.185.181/32 185.17.185.182/32 ))'
}
}
+ lw07: {
+ @ferm::rule { 'dsa-postgres-snapshot':
+ description => 'Allow postgress access',
+ rule => '&SERVICE_RANGE(tcp, 5439, ( 185.17.185.176/28 ))'
+ }
+ }
default: {}
}
# vpn fu
}
default: {}
}
+ # tftp
+ case $::hostname {
+ abel: {
+ @ferm::rule { 'dsa-tftp':
+ description => 'Allow tftp access',
+ rule => '&SERVICE_RANGE(udp, 69, ( 172.28.17.0/24 ))'
+ }
+ }
+ jenkins: {
+ @ferm::rule { 'dsa-tftp':
+ description => 'Allow tftp access',
+ rule => '&SERVICE_RANGE(udp, 69, ( 192.168.2.0/24 206.12.19.0/24 ))'
+ }
+ }
+ master: {
+ @ferm::rule { 'dsa-tftp':
+ description => 'Allow tftp access',
+ rule => '&SERVICE_RANGE(udp, 69, ( 82.195.75.64/26 ))'
+ }
+ }
+ }
}