mirror of
https://git.lapiole.org/dani/ansible-roles.git
synced 2025-08-04 07:37:20 +02:00
Update to 2021-12-01 19:13
This commit is contained in:
15
roles/crowdsec/tasks/iptables.yml
Normal file
15
roles/crowdsec/tasks/iptables.yml
Normal file
@@ -0,0 +1,15 @@
|
||||
---
|
||||
|
||||
- name: Handle crowdsec port in the firewall
|
||||
iptables_raw:
|
||||
name: "{{ item.name }}"
|
||||
state: "{{ (item.src_ip | length > 0) | ternary('present','absent') }}"
|
||||
rules: "-A INPUT -m state --state NEW -p tcp --dport {{ item.port }} -s {{ item.src_ip | join(',') }} -j ACCEPT"
|
||||
loop:
|
||||
- name: cs_lapi_port
|
||||
port: "{{ cs_lapi_port }}"
|
||||
src_ip: "{{ cs_lapi_src_ip }}"
|
||||
- name: cs_prometheus_port
|
||||
port: "{{ cs_prometheus_port }}"
|
||||
src_ip: "{{ cs_prometheus_src_ip }}"
|
||||
tags: firewall,cs
|
Reference in New Issue
Block a user