2 ssl::service { 'www.debian.org':
4 @ferm::rule { 'dsa-sip-ws-ip4':
6 description => 'SIP connections (WebSocket; for WebRTC)',
7 rule => 'proto tcp dport (443) ACCEPT'
9 @ferm::rule { 'dsa-sip-ws-ip6':
11 description => 'SIP connections (WebSocket; for WebRTC)',
12 rule => 'proto tcp dport (443) ACCEPT'
14 @ferm::rule { 'dsa-sip-tls-ip4':
16 description => 'SIP connections (TLS)',
17 rule => 'proto tcp dport (5061) ACCEPT'
19 @ferm::rule { 'dsa-sip-tls-ip6':
21 description => 'SIP connections (TLS)',
22 rule => 'proto tcp dport (5061) ACCEPT'
24 @ferm::rule { 'dsa-turn-ip4':
26 description => 'TURN connections',
27 rule => 'proto udp dport (3478) ACCEPT'
29 @ferm::rule { 'dsa-turn-ip6':
31 description => 'TURN connections',
32 rule => 'proto udp dport (3478) ACCEPT'
34 @ferm::rule { 'dsa-turn-tls-ip4':
36 description => 'TURN connections (TLS)',
37 rule => 'proto tcp dport (5349) ACCEPT'
39 @ferm::rule { 'dsa-turn-tls-ip6':
41 description => 'TURN connections (TLS)',
42 rule => 'proto tcp dport (5349) ACCEPT'
44 @ferm::rule { 'dsa-rtp-ip4':
46 description => 'RTP streams',
47 rule => 'proto udp dport (49152:65535) ACCEPT'
49 @ferm::rule { 'dsa-rtp-ip6':
51 description => 'RTP streams',
52 rule => 'proto udp dport (49152:65535) ACCEPT'