Great role, would be even better if the firewall opening is optional. I prefer to open omsa port only to a certain subnet or not at all in certain situations, I'm sure you understand :)