2022-12-14 17:43:16 +01:00
|
|
|
---
|
|
|
|
|
2023-09-04 14:45:09 +02:00
|
|
|
- name: Install firewalld
|
2022-12-14 17:43:16 +01:00
|
|
|
package:
|
|
|
|
name: firewalld
|
|
|
|
state: present
|
|
|
|
|
|
|
|
- name: "Make sure FirewallD is running"
|
2023-09-04 14:45:09 +02:00
|
|
|
ansible.builtin.systemd:
|
2022-12-14 17:43:16 +01:00
|
|
|
name: firewalld
|
|
|
|
state: started
|
2023-09-04 14:45:09 +02:00
|
|
|
enabled: true
|
2022-12-14 17:43:16 +01:00
|
|
|
|
|
|
|
- name: Open SSH port in firewall
|
|
|
|
ansible.posix.firewalld:
|
|
|
|
service: ssh
|
|
|
|
permanent: yes
|
|
|
|
state: enabled
|
|
|
|
immediate: yes
|
|
|
|
#this is seperate so you don't accidentally remove it
|
|
|
|
|
|
|
|
- name: Open services in firewall
|
|
|
|
ansible.posix.firewalld:
|
|
|
|
service: "{{ item }}"
|
|
|
|
permanent: yes
|
|
|
|
state: enabled
|
|
|
|
immediate: yes
|
|
|
|
with_items: "{{ firewall_services }}"
|
|
|
|
|
|
|
|
- name: Open ports in firewall
|
|
|
|
ansible.posix.firewalld:
|
|
|
|
port: "{{ item }}"
|
|
|
|
permanent: yes
|
|
|
|
state: enabled
|
|
|
|
immediate: yes
|
|
|
|
with_items: "{{ firewall_ports }}"
|
|
|
|
when: firewall_ports is defined
|