diff options
Diffstat (limited to 'manifests/virtual/mail.pp')
-rw-r--r-- | manifests/virtual/mail.pp | 29 |
1 files changed, 16 insertions, 13 deletions
diff --git a/manifests/virtual/mail.pp b/manifests/virtual/mail.pp index 83589ce..75eec5f 100644 --- a/manifests/virtual/mail.pp +++ b/manifests/virtual/mail.pp @@ -1,18 +1,19 @@ -class firewall::virtual::mail($destination, $zone = 'fw') { +class firewall::virtual::mail($destination) { shorewall::rule { 'mail-1': action => 'DNAT', - source => 'net', - destination => "$zone:$destination:25", + source => 'vm', + destination => "fw:$destination:25", proto => 'tcp', destinationport => '25', + originaldest => hiera('firewall::external_ip', $::ipaddress), ratelimit => '-', order => 1000, } shorewall::rule { 'mail-2': action => 'DNAT', - source => '$FW', - destination => "$zone:$destination:25", + source => 'net', + destination => "vm:$destination:25", proto => 'tcp', destinationport => '25', originaldest => hiera('firewall::external_ip', $::ipaddress), @@ -22,18 +23,19 @@ class firewall::virtual::mail($destination, $zone = 'fw') { shorewall::rule { 'mail-3': action => 'DNAT', - source => 'net', - destination => "$zone:$destination:993", + source => 'vm', + destination => "fw:$destination:993", proto => 'tcp', destinationport => '993', + originaldest => hiera('firewall::external_ip', $::ipaddress), ratelimit => hiera("firewall::ssl_ratelimit", '-'), order => 1002, } shorewall::rule { 'mail-4': action => 'DNAT', - source => '$FW', - destination => "$zone:$destination:993", + source => 'net', + destination => "vm:$destination:993", proto => 'tcp', destinationport => '993', originaldest => hiera('firewall::external_ip', $::ipaddress), @@ -43,18 +45,19 @@ class firewall::virtual::mail($destination, $zone = 'fw') { shorewall::rule { 'mail-5': action => 'DNAT', - source => 'net', - destination => "$zone:$destination:587", + source => 'vm', + destination => "fw:$destination:587", proto => 'tcp', destinationport => '587', + originaldest => hiera('firewall::external_ip', $::ipaddress), ratelimit => hiera("firewall::ssl_ratelimit", '-'), order => 1004, } shorewall::rule { 'mail-6': action => 'DNAT', - source => '$FW', - destination => "$zone:$destination:587", + source => 'net', + destination => "vm:$destination:587", proto => 'tcp', destinationport => '587', originaldest => hiera('firewall::external_ip', $::ipaddress), |