class firewall::router::gobby($destination, $zone = 'loc', $originaldest = $ipaddress) { shorewall::rule { 'gobby-route-1': action => 'DNAT', source => 'net', destination => "$zone:$destination:6523", proto => 'tcp', destinationport => '6523', ratelimit => '-', order => 600, } shorewall::rule { 'gobby-route-2': action => 'DNAT', source => '$FW', destination => "fw:$destination:6523", proto => 'tcp', destinationport => '6523', originaldest => "$originaldest", ratelimit => '-', order => 601, } }