mirror of
https://git.lapiole.org/dani/ansible-roles.git
synced 2025-07-31 19:55:42 +02:00
Update to 2021-12-01 19:13
This commit is contained in:
20
roles/graylog/tasks/iptables.yml
Normal file
20
roles/graylog/tasks/iptables.yml
Normal file
@@ -0,0 +1,20 @@
|
||||
---
|
||||
|
||||
- name: Handle graylog ports
|
||||
iptables_raw:
|
||||
name: "{{ item.name }}"
|
||||
state: "{{ (item.src_ip | length > 0) | ternary('present','absent') }}"
|
||||
rules: "-A INPUT -m state --state NEW -p {{ item.proto | default('tcp') }} -m multiport --dports {{ item.port }} -s {{ item.src_ip | join(',') }} -j ACCEPT"
|
||||
when: iptables_manage | default(True)
|
||||
loop:
|
||||
- port: "{{ graylog_http_ports | join(',') }}"
|
||||
name: graylog_http_ports
|
||||
src_ip: "{{ graylog_http_src_ip }}"
|
||||
- port: "{{ graylog_listeners_tcp_ports | join(',') }}"
|
||||
name: graylog_listeners_tcp_ports
|
||||
src_ip: "{{ graylog_listeners_src_ip }}"
|
||||
- port: "{{ graylog_listeners_udp_ports | join(',') }}"
|
||||
proto: udp
|
||||
name: graylog_listeners_udp_ports
|
||||
src_ip: "{{ graylog_listeners_src_ip }}"
|
||||
tags: firewall,graylog
|
Reference in New Issue
Block a user