
This converts the config for elasticsearch cluster client firewall rules to use the new puppet-iptables iptables_allowed_hosts feature. This works around an issue with netfilter-persistent starting before dns resolution is working on boot. Change-Id: I81b7598cb32d498b219ee00f0589e6bf0dc8c242