geekoops-next/tasks/firewall.yml
felix.niederwanger@suse.com be38529589 Working prototype
2021-03-25 11:09:16 +01:00

39 lines
942 B
YAML

---
# Configure firewall
- name: Ensure tftp is open in firewall
firewalld:
zone: "{{firewall_zone}}"
service: tftp
permanent: true
state: enabled
notify: reload firewalld
tags: ['firewall', 'tftp', 'dnsmasq']
- name: Ensure dns is open in firewall
firewalld:
zone: "{{firewall_zone}}"
service: dns
permanent: true
state: enabled
notify: reload firewalld
when: dns_port != 0
tags: ['firewall', 'dns', 'dnsmasq']
- name: Ensure dhcp is open in firewall
firewalld:
zone: "{{firewall_zone}}"
service: dhcp
permanent: true
state: enabled
notify: reload firewalld
when: dhcp_range != ""
tags: ['firewall', 'dhcp', 'dnsmasq']
- name: Ensure proxy-dhcp is open in firewall
firewalld:
zone: "{{firewall_zone}}"
service: proxy-dhcp
permanent: true
state: enabled
notify: reload firewalld
when: "'proxy' in dhcp_range"
tags: ['firewall', 'dhcp', 'dnsmasq']