aim-web2.1.0rc9

This commit is contained in:
admin_rb
2026-09-22 19:23:17 +02:00
parent d095887d2e
commit 3dfc80b782
438 changed files with 31613 additions and 1510 deletions
+3
View File
@@ -0,0 +1,3 @@
# sophos_customer_formicon
Policy-preserving extraction from the uploaded production playbooks. Arguments, conditions, operation order, rule names and values were not changed. Invoke through the matching playbook.
@@ -0,0 +1,231 @@
---
# Customer-specific firewall policy preserved from the uploaded source.
- name: Update hostname settings
sophos.sophos_firewall.sfos_admin_settings:
hostname_settings:
hostname: '{{ hostname }}'
state: updated
- name: Netzwerke als IP-Hosts in der Firewall anlegen
sophos.sophos_firewall.sfos_ip_host:
name: '{{ item.value.name }}'
network: '{{ item.value.network }}'
mask: '{{ item.value.subnetmask }}'
host_type: network
state: present
loop: '{{ network_objects | dict2items }}'
- name: Zonen erstellen
sophos.sophos_firewall.sfos_zone:
name: '{{ item.value.zone_name }}'
description: '{{ item.value.zone_description }}'
zone_type: '{{ item.value.zone_type }}'
state: present
loop: '{{ vlan_interfaces | dict2items }}'
when: item.value.name != "LAN"
- name: Update Management Zone Admin Services
sophos.sophos_firewall.sfos_zone:
name: Management
https: Enable
ssh: Enable
ad_sso: Disable
captive_portal: Disable
radius_sso: Disable
client_authen: Disable
chromebook_sso: Disable
ping: Enable
dns: Enable
ipsec: Disable
sslvpn: Disable
vpn_portal: Disable
red: Disable
wireless_protection: Disable
web_proxy: Disable
user_portal: Disable
smtp_relay: Disable
snmp: Disable
state: updated
- name: Add VLAN Interfaces
sophos.sophos_firewall.sfos_xmlapi:
xml_tag: VLAN
data: |
<VLAN>
<Name>{{ item.value.name }}</Name>
<Hardware>Port1</Hardware>
<Interface>Port1</Interface>
<Zone>{{ item.value.zone_name }}</Zone>
<VLANID>{{ item.value.vlan_id }}</VLANID>
<IPv4Configuration>Enable</IPv4Configuration>
<IPv4Assignment>Static</IPv4Assignment>
<IPAddress>{{ item.value.ip_address }}</IPAddress>
<Netmask>{{ item.value.subnetmask }}</Netmask>
</VLAN>
state: present
loop: '{{ vlan_interfaces | dict2items }}'
loop_control:
label: '{{ item.key }} -> VLAN {{ item.value.vlan_id }}'
- name: Erstelle 'LAN_to_LAN_old' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: LAN_to_LAN_old
action: accept
description: Erlaubt Zugriff von LAN auf Bestandsnetz
log: enable
status: enable
position: bottom
src_zones:
- LAN
dst_zones:
- LAN
src_networks:
- '{{ network_objects.office.name }}'
dst_networks:
- '{{ network_objects.lan_old.name }}'
service_list:
- Any
state: present
- name: Erstelle 'INTERNAL_to_FHAZUREGWC_LAN' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: INTERNAL_to_FHAZUREGWC_LAN
action: accept
description: Erlaubt Zugriff von internen Netzen auf Formicon Holding Azure Germany West Central LAN
log: enable
status: enable
position: bottom
src_zones:
- LAN
- Management
dst_zones:
- VPN
src_networks:
- '{{ network_objects.lan_old.name }}'
- '{{ network_objects.management.name }}'
- '{{ network_objects.office.name }}'
dst_networks:
- '{{ network_objects.azuregwc_lan.name }}'
service_list:
- Any
state: present
- name: Erstelle 'LAN_to_WAN' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: LAN_to_WAN
action: accept
description: Erlaubt Zugriff von LAN auf WAN
log: enable
status: enable
position: bottom
src_zones:
- LAN
dst_zones:
- WAN
src_networks:
- '{{ network_objects.office.name }}'
dst_networks:
- Any
service_list:
- Any
state: present
- name: Erstelle 'LAN_old_to_WAN' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: LAN_old_to_WAN
action: accept
description: Erlaubt Zugriff von old LAN auf WAN
log: enable
status: enable
position: bottom
src_zones:
- LAN
dst_zones:
- WAN
src_networks:
- '{{ network_objects.lan_old.name }}'
dst_networks:
- Any
service_list:
- Any
state: present
- name: Erstelle 'Management_to_WAN' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: Management_to_WAN
action: accept
description: Erlaubt Zugriff von Management auf WAN
log: enable
status: enable
position: bottom
src_zones:
- Management
dst_zones:
- WAN
src_networks:
- '{{ network_objects.management.name }}'
dst_networks:
- Any
service_list:
- Any
state: present
- name: Erstelle 'LAN_to_Management' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: LAN_to_Management
action: accept
description: Erlaubt Zugriff von LAN auf Management
log: enable
status: disable
position: bottom
src_zones:
- LAN
dst_zones:
- Management
src_networks:
- '{{ network_objects.office.name }}'
dst_networks:
- '{{ network_objects.management.name }}'
service_list:
- Any
state: present
- name: Erstelle 'VPN' Firewall-Regel Gruppe
sophos.sophos_firewall.sfos_firewall_rulegroup:
name: VPN
description: VPN
policy_list:
- INTERNAL_to_FHAZUREGWC_LAN
policy_type: Any
source_zones:
- VPN
dest_zones:
- Any
state: present
- name: Erstelle 'X to Management' Firewall-Regel Gruppe
sophos.sophos_firewall.sfos_firewall_rulegroup:
name: X to Management
description: Zugriff auf Management-Netz
policy_list:
- LAN_to_Management
policy_type: Any
source_zones:
- Any
dest_zones:
- Management
state: present
- name: Erstelle 'X to LAN' Firewall-Regel Gruppe
sophos.sophos_firewall.sfos_firewall_rulegroup:
name: X to LAN
description: Zugriff auf LAN-Netz
policy_list:
- LAN_to_LAN_old
policy_type: Any
source_zones:
- Any
dest_zones:
- LAN
state: present
- name: Erstelle 'X to WAN' Firewall-Regel Gruppe
sophos.sophos_firewall.sfos_firewall_rulegroup:
name: X to WAN
description: X to WAN group
policy_list:
- LAN_to_WAN
- Management_to_WAN
- LAN_old_to_WAN
policy_type: Any
source_zones:
- Any
dest_zones:
- WAN
state: present