mirror of
https://git.lapiole.org/dani/ansible-roles.git
synced 2025-08-07 00:57:00 +02:00
Update to 2021-12-01 19:13
This commit is contained in:
27
roles/samba/tasks/iptables.yml
Normal file
27
roles/samba/tasks/iptables.yml
Normal file
@@ -0,0 +1,27 @@
|
||||
---
|
||||
|
||||
- name: Handle DNS ports
|
||||
iptables_raw:
|
||||
name: samba_dns_ports
|
||||
state: "{{ (samba_dns_src_ip | length > 0) | ternary('present','absent') }}"
|
||||
rules: "-A INPUT -m state --state NEW -p tcp -m multiport --dports {{ samba_dns_ports | join(',') }} -s {{ samba_dns_src_ip | join(',') }} -j ACCEPT\n
|
||||
-A INPUT -m state --state NEW -p udp -m multiport --dports {{ samba_dns_ports | join(',') }} -s {{ samba_dns_src_ip | join(',') }} -j ACCEPT"
|
||||
when: samba_role == 'dc' or samba_role == 'rodc'
|
||||
tags: samba,firewall
|
||||
|
||||
- name: Handle DC services ports
|
||||
iptables_raw:
|
||||
name: samba_dc_ports
|
||||
state: "{{ (samba_dc_src_ip | length > 0) | ternary('present','absent') }}"
|
||||
rules: "-A INPUT -m state --state NEW -p tcp -m multiport --dports {{ samba_dc_tcp_ports | join(',') }} -s {{ samba_dc_src_ip | join(',') }} -j ACCEPT\n
|
||||
-A INPUT -m state --state NEW -p udp -m multiport --dports {{ samba_dc_udp_ports | join(',') }} -s {{ samba_dc_src_ip | join(',') }} -j ACCEPT"
|
||||
when: samba_role == 'dc' or samba_role == 'rodc'
|
||||
tags: samba,firewall
|
||||
|
||||
- name: Handle other ports
|
||||
iptables_raw:
|
||||
name: samba_file_ports
|
||||
state: "{{ (samba_file_src_ip | length > 0) | ternary('present','absent') }}"
|
||||
rules: "-A INPUT -m state --state NEW -p tcp -m multiport --dports {{ samba_file_tcp_ports | join(',') }} -s {{ samba_file_src_ip | join(',') }} -j ACCEPT\n
|
||||
-A INPUT -m state --state NEW -p udp -m multiport --dports {{ samba_file_udp_ports | join(',') }} -s {{ samba_file_src_ip | join(',') }} -j ACCEPT"
|
||||
tags: samba,firewall
|
Reference in New Issue
Block a user