aim-web2.1.0rc9

This commit is contained in:
admin_rb
2026-09-22 19:23:17 +02:00
parent d095887d2e
commit 3dfc80b782
438 changed files with 31613 additions and 1510 deletions
@@ -0,0 +1,268 @@
---
# Customer-specific firewall policy preserved from the uploaded source.
- name: Update hostname settings
sophos.sophos_firewall.sfos_admin_settings:
hostname_settings:
hostname: '{{ hostname }}'
state: updated
- name: Netzwerke als IP-Hosts in der Firewall anlegen
sophos.sophos_firewall.sfos_ip_host:
name: '{{ item.value.name }}'
network: '{{ item.value.network }}'
mask: '{{ item.value.subnetmask }}'
host_type: network
state: present
loop: '{{ network_objects | dict2items }}'
- name: Zonen erstellen
sophos.sophos_firewall.sfos_zone:
name: '{{ item.value.zone_name }}'
description: '{{ item.value.zone_description }}'
zone_type: '{{ item.value.zone_type }}'
state: present
loop: '{{ vlan_interfaces | dict2items }}'
when: item.value.name != "LAN"
- name: Update Management Zone Admin Services
sophos.sophos_firewall.sfos_zone:
name: Management
https: Enable
ssh: Enable
ad_sso: Disable
captive_portal: Disable
radius_sso: Disable
client_authen: Disable
chromebook_sso: Disable
ping: Enable
dns: Enable
ipsec: Disable
sslvpn: Disable
vpn_portal: Disable
red: Disable
wireless_protection: Disable
web_proxy: Disable
user_portal: Disable
smtp_relay: Disable
snmp: Disable
state: updated
- name: Add VLAN Interfaces
sophos.sophos_firewall.sfos_xmlapi:
xml_tag: VLAN
data: |
<VLAN>
<Name>{{ item.value.name }}</Name>
<Hardware>Port1</Hardware>
<Interface>Port1</Interface>
<Zone>{{ item.value.zone_name }}</Zone>
<VLANID>{{ item.value.vlan_id }}</VLANID>
<IPv4Configuration>Enable</IPv4Configuration>
<IPv4Assignment>Static</IPv4Assignment>
<IPAddress>{{ item.value.ip_address }}</IPAddress>
<Netmask>{{ item.value.subnetmask }}</Netmask>
</VLAN>
state: present
loop: '{{ vlan_interfaces | dict2items }}'
loop_control:
label: '{{ item.key }} -> VLAN {{ item.value.vlan_id }}'
- name: Erstelle 'LAN_to_WAN' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: LAN_to_WAN
action: accept
description: Erlaubt Zugriff von LAN auf WAN
log: enable
status: enable
position: bottom
src_zones:
- LAN
dst_zones:
- WAN
src_networks:
- '{{ network_objects.office.name }}'
dst_networks:
- Any
service_list:
- Any
state: present
- name: Erstelle 'Management_to_WAN' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: Management_to_WAN
action: accept
description: Erlaubt Zugriff von Management auf WAN
log: enable
status: enable
position: bottom
src_zones:
- Management
dst_zones:
- WAN
src_networks:
- '{{ network_objects.management.name }}'
dst_networks:
- Any
service_list:
- Any
state: present
- name: Erstelle 'Guest_to_WAN' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: Guest_to_WAN
action: accept
description: Erlaubt Zugriff von Guest auf WAN
log: enable
status: enable
position: bottom
src_zones:
- Guest
dst_zones:
- WAN
src_networks:
- '{{ network_objects.guest.name }}'
dst_networks:
- Any
service_list:
- Any
state: present
- name: Erstelle 'Facility_to_WAN' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: Facility_to_WAN
action: accept
description: Erlaubt Zugriff von Facility auf WAN
log: enable
status: enable
position: bottom
src_zones:
- Facility
dst_zones:
- WAN
src_networks:
- '{{ network_objects.facility.name }}'
dst_networks:
- Any
service_list:
- Any
state: present
- name: Erstelle 'VOIP_to_WAN' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: VOIP_to_WAN
action: accept
description: Erlaubt Zugriff von VOIP auf WAN
log: enable
status: enable
position: bottom
src_zones:
- VOIP
dst_zones:
- WAN
src_networks:
- '{{ network_objects.voip.name }}'
dst_networks:
- Any
service_list:
- Any
state: present
- name: Erstelle 'LAN_to_Management' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: LAN_to_Management
action: accept
description: Erlaubt Zugriff von LAN auf Management
log: enable
status: disable
position: bottom
src_zones:
- LAN
dst_zones:
- Management
src_networks:
- '{{ network_objects.office.name }}'
dst_networks:
- '{{ network_objects.management.name }}'
service_list:
- Any
state: present
- name: Erstelle 'LAN_to_Facility' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: LAN_to_Facility
action: accept
description: Erlaubt Zugriff von LAN auf Facility
log: enable
status: enable
position: bottom
src_zones:
- LAN
dst_zones:
- Facility
src_networks:
- '{{ network_objects.office.name }}'
dst_networks:
- '{{ network_objects.facility.name }}'
service_list:
- Any
state: present
- name: Erstelle 'LAN_to_VOIP' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: LAN_to_VOIP
action: accept
description: Erlaubt Zugriff von LAN auf VOIP
log: enable
status: enable
position: bottom
src_zones:
- LAN
dst_zones:
- VOIP
src_networks:
- '{{ network_objects.office.name }}'
dst_networks:
- '{{ network_objects.voip.name }}'
service_list:
- Any
state: present
- name: Erstelle 'X to Management' Firewall-Regel Gruppe
sophos.sophos_firewall.sfos_firewall_rulegroup:
name: X to Management
description: Zugriff auf Management-Netz
policy_list:
- LAN_to_Management
policy_type: Any
source_zones:
- Any
dest_zones:
- Management
state: present
- name: Erstelle 'X to Facility' Firewall-Regel Gruppe
sophos.sophos_firewall.sfos_firewall_rulegroup:
name: X to Facility
description: Zugriff auf Facility-Netz
policy_list:
- LAN_to_Facility
policy_type: Any
source_zones:
- Any
dest_zones:
- Facility
state: present
- name: Erstelle 'X to VOIP' Firewall-Regel Gruppe
sophos.sophos_firewall.sfos_firewall_rulegroup:
name: X to VOIP
description: Zugriff auf VOIP-Netz
policy_list:
- LAN_to_VOIP
policy_type: Any
source_zones:
- Any
dest_zones:
- VOIP
state: present
- name: Erstelle 'X to WAN' Firewall-Regel Gruppe
sophos.sophos_firewall.sfos_firewall_rulegroup:
name: X to WAN
description: X to WAN group
policy_list:
- LAN_to_WAN
- Management_to_WAN
- Guest_to_WAN
- Facility_to_WAN
- VOIP_to_WAN
policy_type: Any
source_zones:
- Any
dest_zones:
- WAN
state: present