summaryrefslogtreecommitdiff
path: root/manifests/virtual/mail.pp
diff options
context:
space:
mode:
Diffstat (limited to 'manifests/virtual/mail.pp')
-rw-r--r--manifests/virtual/mail.pp29
1 files changed, 16 insertions, 13 deletions
diff --git a/manifests/virtual/mail.pp b/manifests/virtual/mail.pp
index 83589ce..75eec5f 100644
--- a/manifests/virtual/mail.pp
+++ b/manifests/virtual/mail.pp
@@ -1,18 +1,19 @@
-class firewall::virtual::mail($destination, $zone = 'fw') {
+class firewall::virtual::mail($destination) {
shorewall::rule { 'mail-1':
action => 'DNAT',
- source => 'net',
- destination => "$zone:$destination:25",
+ source => 'vm',
+ destination => "fw:$destination:25",
proto => 'tcp',
destinationport => '25',
+ originaldest => hiera('firewall::external_ip', $::ipaddress),
ratelimit => '-',
order => 1000,
}
shorewall::rule { 'mail-2':
action => 'DNAT',
- source => '$FW',
- destination => "$zone:$destination:25",
+ source => 'net',
+ destination => "vm:$destination:25",
proto => 'tcp',
destinationport => '25',
originaldest => hiera('firewall::external_ip', $::ipaddress),
@@ -22,18 +23,19 @@ class firewall::virtual::mail($destination, $zone = 'fw') {
shorewall::rule { 'mail-3':
action => 'DNAT',
- source => 'net',
- destination => "$zone:$destination:993",
+ source => 'vm',
+ destination => "fw:$destination:993",
proto => 'tcp',
destinationport => '993',
+ originaldest => hiera('firewall::external_ip', $::ipaddress),
ratelimit => hiera("firewall::ssl_ratelimit", '-'),
order => 1002,
}
shorewall::rule { 'mail-4':
action => 'DNAT',
- source => '$FW',
- destination => "$zone:$destination:993",
+ source => 'net',
+ destination => "vm:$destination:993",
proto => 'tcp',
destinationport => '993',
originaldest => hiera('firewall::external_ip', $::ipaddress),
@@ -43,18 +45,19 @@ class firewall::virtual::mail($destination, $zone = 'fw') {
shorewall::rule { 'mail-5':
action => 'DNAT',
- source => 'net',
- destination => "$zone:$destination:587",
+ source => 'vm',
+ destination => "fw:$destination:587",
proto => 'tcp',
destinationport => '587',
+ originaldest => hiera('firewall::external_ip', $::ipaddress),
ratelimit => hiera("firewall::ssl_ratelimit", '-'),
order => 1004,
}
shorewall::rule { 'mail-6':
action => 'DNAT',
- source => '$FW',
- destination => "$zone:$destination:587",
+ source => 'net',
+ destination => "vm:$destination:587",
proto => 'tcp',
destinationport => '587',
originaldest => hiera('firewall::external_ip', $::ipaddress),