This commit is contained in:
Jonas Forsberg 2021-09-23 11:23:59 +02:00
parent 64aeef94d9
commit dbae346799
2 changed files with 18 additions and 2 deletions

View File

@ -1,2 +1,2 @@
local stratum 10 local stratum 10
allow {{ pillar['network']['address'] }}/{{ pillar['network']['netmask'] }} allow {{ pillar['network']['netaddress'] }}/{{ pillar['network']['netmask'] }}

View File

@ -10,7 +10,7 @@ Configure firewalld for external interface:
- services: - services:
- ssh - ssh
Configure firewalld for internal networks: Configure firewalld for internal network:
firewalld.present: firewalld.present:
- name: internal - name: internal
- prune_ports: True - prune_ports: True
@ -18,6 +18,22 @@ Configure firewalld for internal networks:
- prune_interfaces: True - prune_interfaces: True
- interfaces: - interfaces:
- {{ pillar['network']['interface']['internal'] }} - {{ pillar['network']['interface']['internal'] }}
- services:
- ssh
- dhcp
- tftp
- http
- https
- dns
- ntp
Configure firewalld for vlan networks:
firewalld.present:
- name: internal
- prune_ports: True
- prune_services: True
- prune_interfaces: True
- interfaces:
{% for vlan in pillar['network']['vlan'] -%} {% for vlan in pillar['network']['vlan'] -%}
- vlan.{{ vlan['id'] }} - vlan.{{ vlan['id'] }}
{% endfor %} {% endfor %}