[c] bugfixing for firewall
This commit is contained in:
parent
b8500d3dee
commit
d61cf8e414
2 changed files with 4 additions and 2 deletions
|
@ -9,7 +9,8 @@ common_firewall_reject: false # reject all connections by default
|
|||
# Default Firewall Rules
|
||||
common_firewall:
|
||||
- port: 22
|
||||
state: allow
|
||||
rule: allow
|
||||
state: present
|
||||
interface: "{{ common_firewall_lan_interface if common_firewall_lan_interface }}"
|
||||
comment: "Allow incoming connections on {{ common_firewall_lan_interface if common_firewall_lan_interface else 'all interfaces' }}"
|
||||
|
||||
|
|
|
@ -39,7 +39,8 @@
|
|||
- name: Configure firewall rules
|
||||
community.general.ufw:
|
||||
port: "{{ rule.port }}"
|
||||
rule: "{{ rule.state | default('allow') }}"
|
||||
rule: "{{ rule.rule | default('allow') }}"
|
||||
delete: "{{ true if rule.state == 'absent' else false | default(false) }}"
|
||||
proto: "{{ rule.protocol | default('tcp') }}"
|
||||
interface: "{{ rule.interface if rule.interface != 'all' else omit }}"
|
||||
comment: "{{ rule.comment | default('Custom rule for port {{ rule.port }} on {{ rule.interface }}') }}"
|
||||
|
|
Loading…
Reference in a new issue