blob: a9a69f73c49c11a29f257dfdcf916fd87a003793 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
|
---
- name: Install firewalld packages
package:
name: firewalld
state: present
- name: Ensure iptables services are not enabled
systemd:
name: "{{ item }}"
state: stopped
enabled: no
masked: yes
with_items:
- iptables
- ip6tables
register: task_result
failed_when: "task_result|failed and 'could not' not in task_result.msg|lower"
- name: Wait 10 seconds after disabling iptables
pause:
seconds: 10
when: task_result | changed
- name: Start and enable firewalld service
systemd:
name: firewalld
state: started
enabled: yes
masked: no
daemon_reload: yes
register: result
- name: need to pause here, otherwise the firewalld service starting can sometimes cause ssh to fail
pause: seconds=10
when: result | changed
- name: Add firewalld allow rules
firewalld:
port: "{{ item.port }}"
permanent: true
immediate: true
state: enabled
with_items: "{{ os_firewall_allow }}"
- name: Remove firewalld allow rules
firewalld:
port: "{{ item.port }}"
permanent: true
immediate: true
state: disabled
with_items: "{{ os_firewall_deny }}"
|