aim-web2.1.0rc9
This commit is contained in:
@@ -0,0 +1,3 @@
|
||||
# sophos_apply_baseline
|
||||
|
||||
Policy-preserving extraction from the uploaded production playbooks. Arguments, conditions, operation order, rule names and values were not changed. Invoke through the matching playbook.
|
||||
@@ -0,0 +1,500 @@
|
||||
---
|
||||
# Policy-preserving extraction from configure_sophos_initial_bitformer_config.yml. Do not change rule values without separate approval.
|
||||
- name: Erstelle 'bf_wan' IP Liste
|
||||
sophos.sophos_firewall.sfos_xmlapi:
|
||||
xml_tag: IPHost
|
||||
data: |
|
||||
<IPHost>
|
||||
<Name>bf_wan</Name>
|
||||
<Description>WAN-IPs von bitformer</Description>
|
||||
<HostType>IPList</HostType>
|
||||
<ListOfIPAddresses>217.13.70.132,87.138.207.238,80.152.155.27,217.13.174.202</ListOfIPAddresses>
|
||||
</IPHost>
|
||||
state: present
|
||||
- name: Erstelle 'bf_wartung' IP-Host
|
||||
sophos.sophos_firewall.sfos_ip_host:
|
||||
name: bf_wartung
|
||||
ip_address: 10.240.0.1
|
||||
state: present
|
||||
- name: Netzwerke als IP-Hosts in der Firewall anlegen
|
||||
sophos.sophos_firewall.sfos_ip_host:
|
||||
name: '{{ item.name }}'
|
||||
network: '{{ item.network }}'
|
||||
mask: '{{ item.subnetmask }}'
|
||||
host_type: network
|
||||
state: present
|
||||
loop: '{{ network_hosts }}'
|
||||
- name: Erstelle 'rfc_1918_5735' Gruppe
|
||||
sophos.sophos_firewall.sfos_ip_hostgroup:
|
||||
name: rfc_1918_5735
|
||||
description: rfc_1918_5735
|
||||
host_list:
|
||||
- rfc_1918_a
|
||||
- rfc_1918_b
|
||||
- rfc_1918_c
|
||||
- rfc_5735
|
||||
state: present
|
||||
- name: Erstelle 'OpenVPN' Service
|
||||
sophos.sophos_firewall.sfos_service:
|
||||
name: OpenVPN
|
||||
type: tcporudp
|
||||
service_list:
|
||||
- protocol: udp
|
||||
src_port: 1:65535
|
||||
dst_port: 1194
|
||||
state: present
|
||||
- name: Erstelle 'dgrp_wan_access_guests' Service Group
|
||||
sophos.sophos_firewall.sfos_servicegroup:
|
||||
name: dgrp_wan_access_guests
|
||||
description: WAN Access Guests
|
||||
service_list:
|
||||
- PING
|
||||
- HTTP
|
||||
- HTTPS
|
||||
- SMTPS_465
|
||||
- SMTPS
|
||||
- IMAP
|
||||
- IMAPS
|
||||
- POP3S
|
||||
- IKE
|
||||
- OpenVPN
|
||||
state: present
|
||||
- name: Erstelle 'dgrp_wan_access_office' Service Group
|
||||
sophos.sophos_firewall.sfos_servicegroup:
|
||||
name: dgrp_wan_access_office
|
||||
description: WAN Access Office
|
||||
service_list:
|
||||
- PING
|
||||
- SSH
|
||||
- HTTP
|
||||
- HTTPS
|
||||
state: present
|
||||
- name: Erstelle bitformer Management Access ACL Ausnahmeregel
|
||||
sophos.sophos_firewall.sfos_service_acl_exception:
|
||||
name: bitformer Management Access
|
||||
description: Allow Management-Access to Webinterface, PING and SSH
|
||||
position: bottom
|
||||
source_zone: WAN
|
||||
source_list:
|
||||
- bf_wan
|
||||
service_list:
|
||||
- HTTPS
|
||||
- SSH
|
||||
- PING
|
||||
action: accept
|
||||
state: present
|
||||
- name: Erstelle bitformer Monitoring ACL Ausnahmeregel
|
||||
sophos.sophos_firewall.sfos_service_acl_exception:
|
||||
name: bitformer Monitoring
|
||||
description: Allow Monitoring-Access
|
||||
position: bottom
|
||||
source_zone: VPN
|
||||
source_list:
|
||||
- bf_wartung
|
||||
service_list:
|
||||
- DNS
|
||||
- HTTPS
|
||||
- SSH
|
||||
- PING
|
||||
action: accept
|
||||
state: present
|
||||
- name: Erstelle UserPortal Country-Restricted ACL Ausnahmeregel
|
||||
sophos.sophos_firewall.sfos_service_acl_exception:
|
||||
name: UserPortal Country-Restricted
|
||||
description: Allow UserPort from Selected Countries
|
||||
position: bottom
|
||||
source_zone: WAN
|
||||
source_list:
|
||||
- Germany
|
||||
- Austria
|
||||
- Switzerland
|
||||
service_list:
|
||||
- UserPortal
|
||||
action: accept
|
||||
state: present
|
||||
- name: Erstelle 'bitformer' IPSec Profile
|
||||
sophos.sophos_firewall.sfos_xmlapi:
|
||||
xml_tag: VPNProfile
|
||||
data: |
|
||||
<VPNProfile>
|
||||
<Name>bitformer</Name>
|
||||
<Description>IPSec Policy bitformer Wartungszugang</Description>
|
||||
<KeyingMethod>Automatic</KeyingMethod>
|
||||
<AllowReKeying>Enable</AllowReKeying>
|
||||
<KeyNegotiationTries>0</KeyNegotiationTries>
|
||||
<AuthenticationMode>MainMode</AuthenticationMode>
|
||||
<PassDataInCompressedFormat>Disable</PassDataInCompressedFormat>
|
||||
<UseStrictProfile>Disable</UseStrictProfile>
|
||||
<Phase1>
|
||||
<EncryptionAlgorithm1>AES256</EncryptionAlgorithm1>
|
||||
<AuthenticationAlgorithm1>SHA2_256</AuthenticationAlgorithm1>
|
||||
<EncryptionAlgorithm2/>
|
||||
<AuthenticationAlgorithm2/>
|
||||
<EncryptionAlgorithm3/>
|
||||
<AuthenticationAlgorithm3/>
|
||||
<SupportedDHGroups>
|
||||
<DHGroup>16(DH4096)</DHGroup>
|
||||
</SupportedDHGroups>
|
||||
<KeyLife>28800</KeyLife>
|
||||
<ReKeyMargin>360</ReKeyMargin>
|
||||
<RandomizeRe-KeyingMarginBy>50</RandomizeRe-KeyingMarginBy>
|
||||
<DeadPeerDetection>Enable</DeadPeerDetection>
|
||||
<CheckPeerAfterEvery>10</CheckPeerAfterEvery>
|
||||
<WaitForResponseUpto>25</WaitForResponseUpto>
|
||||
<ActionWhenPeerUnreachable>ReInitiate</ActionWhenPeerUnreachable>
|
||||
</Phase1>
|
||||
<Phase2>
|
||||
<EncryptionAlgorithm1>AES256</EncryptionAlgorithm1>
|
||||
<AuthenticationAlgorithm1>SHA2_256</AuthenticationAlgorithm1>
|
||||
<EncryptionAlgorithm2/>
|
||||
<AuthenticationAlgorithm2/>
|
||||
<EncryptionAlgorithm3/>
|
||||
<AuthenticationAlgorithm3/>
|
||||
<PFSGroup>SameasPhase-I</PFSGroup>
|
||||
<KeyLife>3600</KeyLife>
|
||||
</Phase2>
|
||||
<sha2_96_truncate>no</sha2_96_truncate>
|
||||
<keyexchange>ikev2</keyexchange>
|
||||
</VPNProfile>
|
||||
state: present
|
||||
- name: Erstelle 'Mitarbeiter IPSec VPN' IPSec Profile
|
||||
sophos.sophos_firewall.sfos_xmlapi:
|
||||
xml_tag: VPNProfile
|
||||
data: |
|
||||
<VPNProfile transactionid="">
|
||||
<Name>Mitarbeiter IPSec VPN</Name>
|
||||
<Description>IPSec VPN für Mitarbeiter</Description>
|
||||
<KeyingMethod>Automatic</KeyingMethod>
|
||||
<AllowReKeying>Enable</AllowReKeying>
|
||||
<KeyNegotiationTries>0</KeyNegotiationTries>
|
||||
<AuthenticationMode>MainMode</AuthenticationMode>
|
||||
<PassDataInCompressedFormat>Disable</PassDataInCompressedFormat>
|
||||
<Phase1>
|
||||
<EncryptionAlgorithm1>AES256</EncryptionAlgorithm1>
|
||||
<AuthenticationAlgorithm1>SHA2_256</AuthenticationAlgorithm1>
|
||||
<EncryptionAlgorithm2>AES256</EncryptionAlgorithm2>
|
||||
<AuthenticationAlgorithm2>SHA2_384</AuthenticationAlgorithm2>
|
||||
<EncryptionAlgorithm3/>
|
||||
<AuthenticationAlgorithm3/>
|
||||
<SupportedDHGroups>
|
||||
<DHGroup>14(DH2048)</DHGroup>
|
||||
<DHGroup>16(DH4096)</DHGroup>
|
||||
<DHGroup>18(DH8192)</DHGroup>
|
||||
<DHGroup>19(ecp256)</DHGroup>
|
||||
<DHGroup>21(ecp521)</DHGroup>
|
||||
<DHGroup>31(curve25519)</DHGroup>
|
||||
</SupportedDHGroups>
|
||||
<KeyLife>36000</KeyLife>
|
||||
<ReKeyMargin>360</ReKeyMargin>
|
||||
<RandomizeRe-KeyingMarginBy>100</RandomizeRe-KeyingMarginBy>
|
||||
<DeadPeerDetection>Enable</DeadPeerDetection>
|
||||
<CheckPeerAfterEvery>60</CheckPeerAfterEvery>
|
||||
<WaitForResponseUpto>240</WaitForResponseUpto>
|
||||
<ActionWhenPeerUnreachable>Disconnect</ActionWhenPeerUnreachable>
|
||||
</Phase1>
|
||||
<Phase2>
|
||||
<EncryptionAlgorithm1>AES256</EncryptionAlgorithm1>
|
||||
<AuthenticationAlgorithm1>SHA2_256</AuthenticationAlgorithm1>
|
||||
<EncryptionAlgorithm2>AES256</EncryptionAlgorithm2>
|
||||
<AuthenticationAlgorithm2>SHA2_384</AuthenticationAlgorithm2>
|
||||
<EncryptionAlgorithm3/>
|
||||
<AuthenticationAlgorithm3/>
|
||||
<PFSGroup>SameasPhase-I</PFSGroup>
|
||||
<KeyLife>32400</KeyLife>
|
||||
</Phase2>
|
||||
<sha2_96_truncate>no</sha2_96_truncate>
|
||||
<keyexchange>ikev1</keyexchange>
|
||||
</VPNProfile>
|
||||
state: present
|
||||
- name: Update LAN Zone Admin Services
|
||||
sophos.sophos_firewall.sfos_zone:
|
||||
name: LAN
|
||||
https: Enable
|
||||
ssh: Enable
|
||||
ad_sso: Enable
|
||||
captive_portal: Enable
|
||||
radius_sso: Disable
|
||||
client_authen: Enable
|
||||
chromebook_sso: Disable
|
||||
ping: Enable
|
||||
dns: Enable
|
||||
ipsec: Disable
|
||||
sslvpn: Disable
|
||||
vpn_portal: Enable
|
||||
red: Disable
|
||||
wireless_protection: Disable
|
||||
web_proxy: Disable
|
||||
user_portal: Enable
|
||||
smtp_relay: Disable
|
||||
snmp: Disable
|
||||
state: updated
|
||||
- name: Update WAN Zone Admin Services
|
||||
sophos.sophos_firewall.sfos_zone:
|
||||
name: WAN
|
||||
https: Disable
|
||||
ssh: Disable
|
||||
ad_sso: Disable
|
||||
captive_portal: Disable
|
||||
radius_sso: Disable
|
||||
client_authen: Disable
|
||||
chromebook_sso: Disable
|
||||
ping: Enable
|
||||
dns: Disable
|
||||
ipsec: Enable
|
||||
sslvpn: Disable
|
||||
vpn_portal: Disable
|
||||
red: Disable
|
||||
wireless_protection: Disable
|
||||
web_proxy: Disable
|
||||
user_portal: Disable
|
||||
smtp_relay: Disable
|
||||
snmp: Disable
|
||||
state: updated
|
||||
- name: Update DMZ Zone Admin Services
|
||||
sophos.sophos_firewall.sfos_zone:
|
||||
name: DMZ
|
||||
https: Disable
|
||||
ssh: Enable
|
||||
ad_sso: Disable
|
||||
captive_portal: Disable
|
||||
radius_sso: Disable
|
||||
client_authen: Disable
|
||||
chromebook_sso: Disable
|
||||
ping: Enable
|
||||
dns: Disable
|
||||
ipsec: Disable
|
||||
sslvpn: Disable
|
||||
vpn_portal: Disable
|
||||
red: Disable
|
||||
wireless_protection: Disable
|
||||
web_proxy: Disable
|
||||
user_portal: Disable
|
||||
smtp_relay: Disable
|
||||
snmp: Disable
|
||||
state: updated
|
||||
- name: Update VPN Zone Admin Services
|
||||
sophos.sophos_firewall.sfos_zone:
|
||||
name: VPN
|
||||
https: Enable
|
||||
ssh: Enable
|
||||
ad_sso: Disable
|
||||
captive_portal: Enable
|
||||
radius_sso: Disable
|
||||
client_authen: Disable
|
||||
chromebook_sso: Disable
|
||||
ping: Enable
|
||||
dns: Enable
|
||||
ipsec: Disable
|
||||
sslvpn: Disable
|
||||
vpn_portal: Enable
|
||||
red: Disable
|
||||
wireless_protection: Disable
|
||||
web_proxy: Disable
|
||||
user_portal: Enable
|
||||
smtp_relay: Disable
|
||||
snmp: Enable
|
||||
state: updated
|
||||
- name: Update WiFi Zone Admin Services
|
||||
sophos.sophos_firewall.sfos_zone:
|
||||
name: WiFi
|
||||
https: Disable
|
||||
ssh: Disable
|
||||
ad_sso: Disable
|
||||
captive_portal: Disable
|
||||
radius_sso: Disable
|
||||
client_authen: Disable
|
||||
chromebook_sso: Disable
|
||||
ping: Disable
|
||||
dns: Disable
|
||||
ipsec: Disable
|
||||
sslvpn: Disable
|
||||
vpn_portal: Disable
|
||||
red: Disable
|
||||
wireless_protection: Disable
|
||||
web_proxy: Disable
|
||||
user_portal: Disable
|
||||
smtp_relay: Disable
|
||||
snmp: Disable
|
||||
state: updated
|
||||
- name: Entferne 'Auto added firewall policy for MTA' Firewall-Regel
|
||||
sophos.sophos_firewall.sfos_firewall_rule:
|
||||
name: Auto added firewall policy for MTA
|
||||
state: absent
|
||||
- name: Erstelle 'LAN_to_WAN' Firewall-Regel
|
||||
sophos.sophos_firewall.sfos_firewall_rule:
|
||||
name: LAN_to_WAN
|
||||
action: accept
|
||||
description: Lan > WAN Regel
|
||||
log: enable
|
||||
status: enable
|
||||
position: bottom
|
||||
src_zones:
|
||||
- LAN
|
||||
dst_zones:
|
||||
- Any
|
||||
src_networks:
|
||||
- Any
|
||||
dst_networks:
|
||||
- Any
|
||||
service_list:
|
||||
- Any
|
||||
state: present
|
||||
- name: Erstelle 'LAN > WAN' Firewall-Regel Gruppe
|
||||
sophos.sophos_firewall.sfos_firewall_rulegroup:
|
||||
name: LAN > WAN
|
||||
description: Lan to WAN group
|
||||
policy_list:
|
||||
- LAN_to_WAN
|
||||
policy_type: Any
|
||||
source_zones:
|
||||
- LAN
|
||||
dest_zones:
|
||||
- WAN
|
||||
state: present
|
||||
- name: Erstelle 'bitformer Wartungszugang' Firewall-Regel
|
||||
sophos.sophos_firewall.sfos_firewall_rule:
|
||||
name: bitformer Wartungszugang
|
||||
action: accept
|
||||
description: bitconnect Zugriff
|
||||
log: enable
|
||||
status: enable
|
||||
position: bottom
|
||||
src_zones:
|
||||
- VPN
|
||||
dst_zones:
|
||||
- Any
|
||||
src_networks:
|
||||
- bf_wartung
|
||||
dst_networks:
|
||||
- Any
|
||||
service_list:
|
||||
- Any
|
||||
state: present
|
||||
- name: Erstelle 'bitformer SPN' Firewall-Regel
|
||||
sophos.sophos_firewall.sfos_firewall_rule:
|
||||
name: bitformer SPN
|
||||
action: accept
|
||||
description: Zugriff auf bitformer SPN
|
||||
log: enable
|
||||
status: enable
|
||||
position: bottom
|
||||
src_zones:
|
||||
- VPN
|
||||
dst_zones:
|
||||
- Any
|
||||
src_networks:
|
||||
- bf_spn_network
|
||||
dst_networks:
|
||||
- Any
|
||||
service_list:
|
||||
- Any
|
||||
state: present
|
||||
- name: Erstelle 'LAN_to_bitformer_SPN' Firewall-Regel
|
||||
sophos.sophos_firewall.sfos_firewall_rule:
|
||||
name: LAN_to_bitformer_SPN
|
||||
action: accept
|
||||
description: Zugriff auf bitformer SPN
|
||||
log: enable
|
||||
status: enable
|
||||
position: bottom
|
||||
src_zones:
|
||||
- LAN
|
||||
dst_zones:
|
||||
- VPN
|
||||
src_networks:
|
||||
- Any
|
||||
dst_networks:
|
||||
- bf_spn_network
|
||||
service_list:
|
||||
- Any
|
||||
state: present
|
||||
- name: Erstelle 'bitformer' Firewall Regel Gruppe
|
||||
sophos.sophos_firewall.sfos_firewall_rulegroup:
|
||||
name: bitformer
|
||||
description: bitformer group
|
||||
policy_list:
|
||||
- bitformer Wartungszugang
|
||||
- bitformer SPN
|
||||
- LAN_to_bitformer_SPN
|
||||
policy_type: Any
|
||||
source_zones:
|
||||
- Any
|
||||
dest_zones:
|
||||
- Any
|
||||
state: present
|
||||
- name: Erstelle 'VPN_to_WAN' Firewall-Regel
|
||||
sophos.sophos_firewall.sfos_firewall_rule:
|
||||
name: VPN_to_WAN
|
||||
action: accept
|
||||
description: Zugriff von VPN
|
||||
log: enable
|
||||
status: disable
|
||||
position: bottom
|
||||
src_zones:
|
||||
- VPN
|
||||
dst_zones:
|
||||
- LAN
|
||||
src_networks:
|
||||
- Any
|
||||
dst_networks:
|
||||
- Any
|
||||
service_list:
|
||||
- Any
|
||||
state: present
|
||||
- name: Erstelle 'VPN' Firewall Regel Gruppe
|
||||
sophos.sophos_firewall.sfos_firewall_rulegroup:
|
||||
name: VPN
|
||||
description: VPN group
|
||||
policy_list:
|
||||
- VPN_to_WAN
|
||||
policy_type: Any
|
||||
source_zones:
|
||||
- Any
|
||||
dest_zones:
|
||||
- Any
|
||||
state: present
|
||||
- name: Entferne [example] Firewallregeln
|
||||
sophos.sophos_firewall.sfos_firewall_rule:
|
||||
name: '{{ item }}'
|
||||
state: absent
|
||||
loop: '{{ firewall_rules_to_remove }}'
|
||||
- name: Erstelle 'DROP_ALL_LOG' Firewall-Regel
|
||||
sophos.sophos_firewall.sfos_firewall_rule:
|
||||
name: DROP_ALL_LOG
|
||||
action: drop
|
||||
description: Verwirft alle Pakete mit Log
|
||||
log: enable
|
||||
status: enable
|
||||
position: bottom
|
||||
src_zones:
|
||||
- Any
|
||||
dst_zones:
|
||||
- Any
|
||||
src_networks:
|
||||
- Any
|
||||
dst_networks:
|
||||
- Any
|
||||
service_list:
|
||||
- Any
|
||||
state: present
|
||||
- name: Aktiviere 'Vordefinierten NTP-Server verwenden'
|
||||
sophos.sophos_firewall.sfos_xmlapi:
|
||||
xml_tag: Time
|
||||
data: |
|
||||
<Time>
|
||||
<TimeZone>Europe/Berlin</TimeZone>
|
||||
<SetDateTime>
|
||||
<Date>
|
||||
<Year/>
|
||||
<Month/>
|
||||
<Day/>
|
||||
</Date>
|
||||
<Time>
|
||||
<HH/>
|
||||
<MM/>
|
||||
<SS>0</SS>
|
||||
</Time>
|
||||
</SetDateTime>
|
||||
<PredefinedNTPServer>Enable</PredefinedNTPServer>
|
||||
</Time>
|
||||
state: updated
|
||||
Reference in New Issue
Block a user