xoxys.iptables/README.md

93 lines
1.7 KiB
Markdown
Raw Normal View History

2019-10-17 21:03:55 +02:00
# xoxys.iptables
[![Build Status](https://drone.rknet.org/api/badges/ansible/xoxys.iptables/status.svg)](https://drone.rknet.org/ansible/xoxys.iptables)
2017-05-18 00:49:43 +02:00
2019-10-17 21:03:55 +02:00
2019-11-06 21:08:49 +01:00
Role to manage iptables
2019-10-17 21:03:55 +02:00
## Table of content
* [Default Variables](#default-variables)
2019-10-28 20:45:49 +01:00
* [iptables_app_rules](#iptables_app_rules)
* [iptables_app_rules_extra](#iptables_app_rules_extra)
2019-11-23 00:11:22 +01:00
* [iptables_custom_rules](#iptables_custom_rules)
* [iptables_default_head](#iptables_default_head)
* [iptables_default_tail](#iptables_default_tail)
2019-10-17 21:03:55 +02:00
* [iptables_keep_unmanaged](#iptables_keep_unmanaged)
* [Dependencies](#dependencies)
* [License](#license)
* [Author](#author)
---
## Default Variables
2019-11-23 00:11:22 +01:00
### iptables_app_rules
2019-10-17 21:03:55 +02:00
#### Default value
```YAML
2019-11-23 00:11:22 +01:00
iptables_app_rules: []
2019-10-17 21:03:55 +02:00
```
2019-11-23 00:11:22 +01:00
### iptables_app_rules_extra
2019-10-17 21:03:55 +02:00
#### Default value
```YAML
2019-11-23 00:11:22 +01:00
iptables_app_rules_extra: []
2019-10-17 21:03:55 +02:00
```
### iptables_custom_rules
#### Default value
```YAML
iptables_custom_rules: []
```
2019-11-23 00:11:22 +01:00
### iptables_default_head
Default head (allow) rules.
2019-10-28 20:33:45 +01:00
#### Default value
```YAML
2019-11-23 00:11:22 +01:00
iptables_default_head: "-P INPUT ACCEPT\n-P FORWARD ACCEPT\n-P OUTPUT ACCEPT\n-A INPUT\
\ -m state --state RELATED,ESTABLISHED -j ACCEPT\n-A INPUT -i lo -j ACCEPT\n-A INPUT\
\ -p icmp --icmp-type echo-request -j ACCEPT\n-A INPUT -p tcp -m tcp --dport 22\
\ -j ACCEPT\n"
2019-10-28 20:45:49 +01:00
```
2019-11-23 00:11:22 +01:00
### iptables_default_tail
Default tail (deny) rules.
2019-10-28 20:45:49 +01:00
#### Default value
```YAML
2019-11-23 00:11:22 +01:00
iptables_default_tail: "-A INPUT -j REJECT\n-A FORWARD -j REJECT\n"
2019-10-28 20:33:45 +01:00
```
2019-10-17 21:03:55 +02:00
### iptables_keep_unmanaged
By default this role deletes all iptables rules which are not managed by Ansible. Set this to 'yes', if you want the role to keep unmanaged rules.
#### Default value
```YAML
iptables_keep_unmanaged: no
```
## Dependencies
None.
## License
MIT
## Author
2019-11-07 09:37:21 +01:00
[xoxys](https://gitea.rknet.org/xoxys)