firewall_settings.yml 1.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960
  1. # Copyright 2021 Dell Inc. or its subsidiaries. All Rights Reserved.
  2. #
  3. # Licensed under the Apache License, Version 2.0 (the "License");
  4. # you may not use this file except in compliance with the License.
  5. # You may obtain a copy of the License at
  6. #
  7. # http://www.apache.org/licenses/LICENSE-2.0
  8. #
  9. # Unless required by applicable law or agreed to in writing, software
  10. # distributed under the License is distributed on an "AS IS" BASIS,
  11. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. # See the License for the specific language governing permissions and
  13. # limitations under the License.
  14. ---
  15. - name: Install firewalld
  16. package:
  17. name: firewalld
  18. state: present
  19. tags: firewalld
  20. - name: Start and enable firewalld
  21. service:
  22. name: firewalld
  23. state: started
  24. enabled: yes
  25. tags: firewalld
  26. - name: Firewall ports addition - tcp/udp ports
  27. firewalld:
  28. zone: public
  29. port: "{{ item }}"
  30. permanent: true
  31. state: enabled
  32. with_items:
  33. - "{{ https_port1 }}"
  34. - "{{ https_port2 }}"
  35. - "{{ ldap_port1 }}"
  36. - "{{ ldap_port2 }}"
  37. - "{{ kerberos_port1 }}"
  38. - "{{ kerberos_port2 }}"
  39. - "{{ kerberos_port3 }}"
  40. - "{{ kerberos_port4 }}"
  41. - "{{ dns_port1 }}"
  42. - "{{ dns_port2 }}"
  43. - "{{ ntp_port1 }}"
  44. - "{{ dt_port1 }}"
  45. tags: firewalld
  46. - name: Reload firewalld
  47. command: firewall-cmd --reload
  48. changed_when: true
  49. tags: firewalld
  50. - name: Stop and disable firewalld
  51. service:
  52. name: firewalld
  53. state: stopped
  54. enabled: no
  55. tags: firewalld