splitting out from the parent task to deploy phab2001
We need to allow ssh between the phabricator servers for cluster support.
That is between iridium.eqiad.wmnet (CNAME phab1001.eqiad.wmnet) and phab2001.codfw.wmnet
We already added iptables rules via ferm (in parent task), but apparently we need network ACL changes in addition to that.
for example:
@phab2001:~# ssh 10.64.32.150
ssh: connect to host 10.64.32.150 port 22: No route to host