]> git.donarmstrong.com Git - dsa-puppet.git/commitdiff
allow netnod to reach denis on 53/tcp and 53/udp
authorLuca Filipozzi <lfilipoz@emyr.net>
Wed, 19 Nov 2014 23:38:44 +0000 (23:38 +0000)
committerLuca Filipozzi <lfilipoz@emyr.net>
Wed, 19 Nov 2014 23:38:44 +0000 (23:38 +0000)
modules/ferm/templates/defs.conf.erb
modules/named/manifests/init.pp

index f539f51aacac8fe3538270472216c7a0070bed8d..c7e28b41bb839d93ba4f8607884d5627f901d075 100644 (file)
@@ -71,6 +71,7 @@
 @def $HOST_EASYDNS_V4 = (64.68.200.91);
 @def $HOST_RCODE0_V4 = (83.136.34.0/27);
 @def $HOST_RCODE0_V6 = (2A02:850:8::/47);
+@def $HOST_NETNOD_V4 = (192.71.80.0/24 192.36.144.222 192.36.144.218);
 
 @def $HOST_DEBIAN_V4 = (<%= scope.function_filter_ipv4([dbs]).uniq.join(' ') %>);
 @def $HOST_DEBIAN_V6 = (<%= scope.function_filter_ipv6([dbs]).uniq.join(' ') %>);
index c09a272dc39e609b1df4cbe635b2a0b64ba796cc..41cec9a8796a506017deeb303f6a2776d774d3be 100644 (file)
@@ -26,7 +26,7 @@ class named {
                @ferm::rule { '01-dsa-bind-4':
                        domain      => '(ip)',
                        description => 'Allow nameserver access',
-                       rule        => '&TCP_UDP_SERVICE_RANGE(53, ( $HOST_DNS_GEO_V4 $HOST_NAGIOS_V4 $HOST_RCODE0_V4 $HOST_EASYDNS_V4 5.153.231.21 ) )',
+                       rule        => '&TCP_UDP_SERVICE_RANGE(53, ( $HOST_DNS_GEO_V4 $HOST_NAGIOS_V4 $HOST_RCODE0_V4 $HOST_EASYDNS_V4 $HOST_NETNOD_V4 5.153.231.21 ) )',
                }
                @ferm::rule { '01-dsa-bind-6':
                        domain      => '(ip6)',