]> git.donarmstrong.com Git - dsa-puppet.git/blobdiff - modules/ferm/templates/me.conf.erb
Revert "unrestrict geo2,3, take 2"
[dsa-puppet.git] / modules / ferm / templates / me.conf.erb
index fcf73741c7c223768a3e22b8fbc69051e8570396..765363d1579fa6d5a7e209538456beacf111ab5d 100644 (file)
@@ -4,9 +4,32 @@
 ##
 
 
-@def $SSH_SOURCES = <%=
-sshallowed = case hostname
-  when 'logtest01' then '0.0.0.0/0'
+@def $SSH_SOURCES = (<%=
+
+sshallowed = []
+
+case hostname
+  when 'logtest01', 'geo1', then sshallowed << [ '$DSA_IPS', '$HOST_NAGIOS_V4', '$HOST_DB_V4' ]
+end
+
+if sshallowed.length == 0
+  sshallowed = [ '0.0.0.0/0' ]
+end
+
+sshallowed.join(' ')
+%>);
+
+@def $SSH_V6_SOURCES = (<%=
+
+sshallowed = []
+
+case hostname
+  when 'logtest01', 'geo1', 'geo2', 'geo3' then sshallowed << [ '$DSA_V6_IPS', '$HOST_NAGIOS_V6', '$HOST_DB_V6' ]
 end
-sshallowed
-%>
+
+if sshallowed.length == 0
+  sshallowed = [ '::' ]
+end
+
+sshallowed.join(' ')
+%>);