aim-web2.1.0rc9
This commit is contained in:
@@ -0,0 +1,3 @@
|
||||
# sophos_customer_gebhardt_stahl
|
||||
|
||||
Policy-preserving extraction from the uploaded production playbooks. Arguments, conditions, operation order, rule names and values were not changed. Invoke through the matching playbook.
|
||||
@@ -0,0 +1,195 @@
|
||||
---
|
||||
# Customer-specific firewall policy preserved from the uploaded source.
|
||||
- name: Update hostname settings
|
||||
sophos.sophos_firewall.sfos_admin_settings:
|
||||
hostname_settings:
|
||||
hostname: '{{ hostname }}'
|
||||
state: updated
|
||||
- name: Netzwerke als IP-Hosts in der Firewall anlegen
|
||||
sophos.sophos_firewall.sfos_ip_host:
|
||||
name: '{{ item.value.name }}'
|
||||
network: '{{ item.value.network }}'
|
||||
mask: '{{ item.value.subnetmask }}'
|
||||
host_type: network
|
||||
state: present
|
||||
loop: '{{ network_objects | dict2items }}'
|
||||
- name: Zonen erstellen
|
||||
sophos.sophos_firewall.sfos_zone:
|
||||
name: '{{ item.value.zone_name }}'
|
||||
description: '{{ item.value.zone_description }}'
|
||||
zone_type: '{{ item.value.zone_type }}'
|
||||
state: present
|
||||
loop: '{{ vlan_interfaces | dict2items }}'
|
||||
when: item.value.name != "LAN"
|
||||
- name: Add VLAN Interfaces
|
||||
sophos.sophos_firewall.sfos_xmlapi:
|
||||
xml_tag: VLAN
|
||||
data: |
|
||||
<VLAN>
|
||||
<Name>{{ item.value.name }}</Name>
|
||||
<Hardware>Port1</Hardware>
|
||||
<Interface>Port1</Interface>
|
||||
<Zone>{{ item.value.zone_name }}</Zone>
|
||||
<VLANID>{{ item.value.vlan_id }}</VLANID>
|
||||
<IPv4Configuration>Enable</IPv4Configuration>
|
||||
<IPv4Assignment>Static</IPv4Assignment>
|
||||
<IPAddress>{{ item.value.ip_address }}</IPAddress>
|
||||
<Netmask>{{ item.value.subnetmask }}</Netmask>
|
||||
</VLAN>
|
||||
state: present
|
||||
loop: '{{ vlan_interfaces | dict2items }}'
|
||||
loop_control:
|
||||
label: '{{ item.key }} -> VLAN {{ item.value.vlan_id }}'
|
||||
- name: Erstelle 'LAN_to_WAN' Firewall-Regel
|
||||
sophos.sophos_firewall.sfos_firewall_rule:
|
||||
name: LAN_to_WAN
|
||||
action: accept
|
||||
description: Erlaubt Zugriff von LAN auf WAN
|
||||
log: enable
|
||||
status: enable
|
||||
position: bottom
|
||||
src_zones:
|
||||
- LAN
|
||||
dst_zones:
|
||||
- WAN
|
||||
src_networks:
|
||||
- '{{ network_objects.office.name }}'
|
||||
dst_networks:
|
||||
- Any
|
||||
service_list:
|
||||
- Any
|
||||
state: present
|
||||
- name: Erstelle 'Guest_to_WAN' Firewall-Regel
|
||||
sophos.sophos_firewall.sfos_firewall_rule:
|
||||
name: Guest_to_WAN
|
||||
action: accept
|
||||
description: Erlaubt Zugriff von Guest auf WAN
|
||||
log: enable
|
||||
status: enable
|
||||
position: bottom
|
||||
src_zones:
|
||||
- Guest
|
||||
dst_zones:
|
||||
- WAN
|
||||
src_networks:
|
||||
- '{{ network_objects.guest.name }}'
|
||||
dst_networks:
|
||||
- Any
|
||||
service_list:
|
||||
- Any
|
||||
state: present
|
||||
- name: Erstelle 'Drucker_to_WAN' Firewall-Regel
|
||||
sophos.sophos_firewall.sfos_firewall_rule:
|
||||
name: Drucker_to_WAN
|
||||
action: accept
|
||||
description: Erlaubt Zugriff von Drucker auf WAN
|
||||
log: enable
|
||||
status: enable
|
||||
position: bottom
|
||||
src_zones:
|
||||
- Drucker
|
||||
dst_zones:
|
||||
- WAN
|
||||
src_networks:
|
||||
- '{{ network_objects.drucker.name }}'
|
||||
dst_networks:
|
||||
- Any
|
||||
service_list:
|
||||
- Any
|
||||
state: present
|
||||
- name: Erstelle 'WLAN_to_WAN' Firewall-Regel
|
||||
sophos.sophos_firewall.sfos_firewall_rule:
|
||||
name: WLAN_to_WAN
|
||||
action: accept
|
||||
description: Erlaubt Zugriff von WLAN auf WAN
|
||||
log: enable
|
||||
status: enable
|
||||
position: bottom
|
||||
src_zones:
|
||||
- WLAN
|
||||
dst_zones:
|
||||
- WAN
|
||||
src_networks:
|
||||
- '{{ network_objects.wlan.name }}'
|
||||
dst_networks:
|
||||
- Any
|
||||
service_list:
|
||||
- Any
|
||||
state: present
|
||||
- name: Erstelle 'LAN_to_Drucker' Firewall-Regel
|
||||
sophos.sophos_firewall.sfos_firewall_rule:
|
||||
name: LAN_to_Drucker
|
||||
action: accept
|
||||
description: Erlaubt Zugriff von LAN auf Drucker
|
||||
log: enable
|
||||
status: enable
|
||||
position: bottom
|
||||
src_zones:
|
||||
- LAN
|
||||
dst_zones:
|
||||
- Drucker
|
||||
src_networks:
|
||||
- '{{ network_objects.office.name }}'
|
||||
dst_networks:
|
||||
- '{{ network_objects.drucker.name }}'
|
||||
service_list:
|
||||
- Any
|
||||
state: present
|
||||
- name: Erstelle 'LAN_to_WLAN' Firewall-Regel
|
||||
sophos.sophos_firewall.sfos_firewall_rule:
|
||||
name: LAN_to_WLAN
|
||||
action: accept
|
||||
description: Erlaubt Zugriff von LAN auf WLAN
|
||||
log: enable
|
||||
status: enable
|
||||
position: bottom
|
||||
src_zones:
|
||||
- LAN
|
||||
dst_zones:
|
||||
- WLAN
|
||||
src_networks:
|
||||
- '{{ network_objects.office.name }}'
|
||||
dst_networks:
|
||||
- '{{ network_objects.wlan.name }}'
|
||||
service_list:
|
||||
- Any
|
||||
state: present
|
||||
- name: Erstelle 'X to Drucker' Firewall-Regel Gruppe
|
||||
sophos.sophos_firewall.sfos_firewall_rulegroup:
|
||||
name: X to Drucker
|
||||
description: Zugriff auf Drucker-Netz
|
||||
policy_list:
|
||||
- LAN_to_Drucker
|
||||
policy_type: Any
|
||||
source_zones:
|
||||
- Any
|
||||
dest_zones:
|
||||
- Drucker
|
||||
state: present
|
||||
- name: Erstelle 'X to WLAN' Firewall-Regel Gruppe
|
||||
sophos.sophos_firewall.sfos_firewall_rulegroup:
|
||||
name: X to WLAN
|
||||
description: Zugriff auf WLAN-Netz
|
||||
policy_list:
|
||||
- LAN_to_WLAN
|
||||
policy_type: Any
|
||||
source_zones:
|
||||
- Any
|
||||
dest_zones:
|
||||
- WLAN
|
||||
state: present
|
||||
- name: Erstelle 'X to WAN' Firewall-Regel Gruppe
|
||||
sophos.sophos_firewall.sfos_firewall_rulegroup:
|
||||
name: X to WAN
|
||||
description: X to WAN group
|
||||
policy_list:
|
||||
- LAN_to_WAN
|
||||
- Guest_to_WAN
|
||||
- Drucker_to_WAN
|
||||
- WLAN_to_WAN
|
||||
policy_type: Any
|
||||
source_zones:
|
||||
- Any
|
||||
dest_zones:
|
||||
- WAN
|
||||
state: present
|
||||
Reference in New Issue
Block a user