2017-05-17 22:54:43 +00:00
|
|
|
---
|
2018-07-06 21:18:11 +00:00
|
|
|
- name: Setup iptables
|
|
|
|
block:
|
2019-01-12 13:29:51 +00:00
|
|
|
- name: Set custom iptables rules
|
|
|
|
iptables_raw:
|
2019-10-30 21:36:33 +00:00
|
|
|
name: "iptables_custom_rules_{{ item.name }}"
|
|
|
|
rules: "{{ item.rules }}"
|
|
|
|
state: "{{ item.state | default('present') }}"
|
|
|
|
weight: "{{ item.weight | default(omit) }}"
|
|
|
|
table: "{{ item.table | default(omit) }}"
|
|
|
|
loop: "{{ iptables_custom_rules }}"
|
2019-01-12 13:29:51 +00:00
|
|
|
loop_control:
|
2019-01-12 13:47:03 +00:00
|
|
|
label: "{{ item.name }}"
|
2017-05-17 22:54:43 +00:00
|
|
|
|
2019-10-28 19:38:54 +00:00
|
|
|
- name: Set applications iptables rules
|
|
|
|
iptables_raw:
|
2019-10-30 21:36:33 +00:00
|
|
|
name: "{{ item.name }}"
|
|
|
|
rules: "{{ item.rules }}"
|
|
|
|
state: "{{ item.state | default('present') }}"
|
|
|
|
weight: "{{ item.weight | default(omit) }}"
|
|
|
|
table: "{{ item.table | default(omit) }}"
|
|
|
|
loop: "{{ iptables_app_rules + iptables_app_rules_extra }}"
|
2019-10-28 19:38:54 +00:00
|
|
|
loop_control:
|
|
|
|
label: "{{ item.name }}"
|
|
|
|
|
2019-01-12 13:29:51 +00:00
|
|
|
- name: Set default iptables head rules
|
|
|
|
iptables_raw:
|
|
|
|
name: iptables_default_head
|
|
|
|
weight: 10
|
2019-10-30 21:36:33 +00:00
|
|
|
keep_unmanaged: "{{ iptables_keep_unmanaged }}"
|
2019-01-12 13:29:51 +00:00
|
|
|
state: present
|
2019-10-30 21:36:33 +00:00
|
|
|
rules: "{{ iptables_default_head }}"
|
2017-07-13 19:27:26 +00:00
|
|
|
|
2019-01-12 13:29:51 +00:00
|
|
|
- name: Set default iptables tail rules
|
|
|
|
iptables_raw:
|
|
|
|
name: iptables_default_tail
|
|
|
|
weight: 99
|
2019-10-30 21:36:33 +00:00
|
|
|
keep_unmanaged: "{{ iptables_keep_unmanaged }}"
|
|
|
|
state: "{{ (not iptables_default_tail) | ternary('absent', 'present') }}"
|
|
|
|
rules: "{{ iptables_default_tail }}"
|
2018-07-06 21:18:11 +00:00
|
|
|
become: True
|
2019-01-12 13:29:51 +00:00
|
|
|
become_user: root
|