This commit is contained in:
Jonas Forsberg
2021-10-12 15:00:09 +02:00
parent 1a6f230702
commit fcdda55ed9
6 changed files with 59 additions and 0 deletions

View File

@@ -1,3 +1,9 @@
Configure wireguard service:
firewalld.service:
- name: wireguard
- ports:
- {{ pillar['wireguard']['port'] }}/udp
Configure firewalld for external interface:
firewalld.present:
- name: external
@@ -10,6 +16,7 @@ Configure firewalld for external interface:
- {{ pillar['network']['interface']['external'] }}
- services:
- ssh
- wireguard
Configure firewalld for internal network:
firewalld.present:
@@ -20,6 +27,7 @@ Configure firewalld for internal network:
- prune_sources: True
- interfaces:
- {{ pillar['network']['interface']['internal'] }}
- {{ pillar['wireguard']['iface'] }}
- sources:
- {{ pillar['network']['netaddress'] }}/{{ pillar['network']['netmask'] }}
- services: