class firewall::virtual::https($destination) { shorewall::rule { 'https-route-1': action => 'DNAT', source => 'vm', destination => "fw:$destination:443", proto => 'tcp', destinationport => '443', originaldest => hiera('firewall::external_ip', $::ipaddress), ratelimit => hiera("firewall::ssl_ratelimit", '-'), order => 602, } shorewall::rule { 'https-route-2': action => 'DNAT', source => 'net', destination => "vm:$destination:443", proto => 'tcp', destinationport => '443', originaldest => hiera('firewall::external_ip', $::ipaddress), ratelimit => hiera("firewall::ssl_ratelimit", '-'), order => 602, } }