After the reboot of some eqsin hosts as described in the parent task, ferm failed to start on bast5001 and dns5001 due to a DNS lookup failure. The problem is that Puppet didn't restart it in any of the following runs, I had to manually do sudo systemctl start ferm and as a result the 2 hosts have been for ~1h without ferm rules applied.
We should improve this behaviour to ensure to minimize the potential exposure of a host without ferm rules applied on reboot, if ferm fails to start for any transient reason.