--- # Customer-specific firewall policy preserved from the uploaded source. - name: Update hostname settings sophos.sophos_firewall.sfos_admin_settings: hostname_settings: hostname: '{{ hostname }}' state: updated - name: Netzwerke als IP-Hosts in der Firewall anlegen sophos.sophos_firewall.sfos_ip_host: name: '{{ item.value.name }}' network: '{{ item.value.network }}' mask: '{{ item.value.subnetmask }}' host_type: network state: present loop: '{{ network_objects | dict2items }}' - name: Zonen erstellen sophos.sophos_firewall.sfos_zone: name: '{{ item.value.zone_name }}' description: '{{ item.value.zone_description }}' zone_type: '{{ item.value.zone_type }}' state: present loop: '{{ vlan_interfaces | dict2items }}' when: item.value.name != "LAN" - name: Update Management Zone Admin Services sophos.sophos_firewall.sfos_zone: name: Management https: Enable ssh: Enable ad_sso: Disable captive_portal: Disable radius_sso: Disable client_authen: Disable chromebook_sso: Disable ping: Enable dns: Enable ipsec: Disable sslvpn: Disable vpn_portal: Disable red: Disable wireless_protection: Disable web_proxy: Disable user_portal: Disable smtp_relay: Disable snmp: Disable state: updated - name: Update Server Zone Admin Services sophos.sophos_firewall.sfos_zone: name: Server https: Enable ssh: Disable ad_sso: Disable captive_portal: Disable radius_sso: Disable client_authen: Disable chromebook_sso: Disable ping: Enable dns: Enable ipsec: Disable sslvpn: Disable vpn_portal: Disable red: Disable wireless_protection: Disable web_proxy: Disable user_portal: Disable smtp_relay: Disable snmp: Disable state: updated - name: Update Guest Zone Admin Services sophos.sophos_firewall.sfos_zone: name: Guest https: Disable ssh: Disable ad_sso: Disable captive_portal: Disable radius_sso: Disable client_authen: Disable chromebook_sso: Disable ping: Enable dns: Enable ipsec: Disable sslvpn: Disable vpn_portal: Disable red: Disable wireless_protection: Disable web_proxy: Disable user_portal: Disable smtp_relay: Disable snmp: Disable state: updated - name: Update Facility Zone Admin Services sophos.sophos_firewall.sfos_zone: name: Facility https: Disable ssh: Disable ad_sso: Disable captive_portal: Disable radius_sso: Disable client_authen: Disable chromebook_sso: Disable ping: Enable dns: Enable ipsec: Disable sslvpn: Disable vpn_portal: Disable red: Disable wireless_protection: Disable web_proxy: Disable user_portal: Disable smtp_relay: Disable snmp: Disable state: updated - name: Update VOIP Zone Admin Services sophos.sophos_firewall.sfos_zone: name: VOIP https: Disable ssh: Disable ad_sso: Disable captive_portal: Disable radius_sso: Disable client_authen: Disable chromebook_sso: Disable ping: Enable dns: Enable ipsec: Disable sslvpn: Disable vpn_portal: Disable red: Disable wireless_protection: Disable web_proxy: Disable user_portal: Disable smtp_relay: Disable snmp: Disable state: updated - name: Add VLAN Interfaces sophos.sophos_firewall.sfos_xmlapi: xml_tag: VLAN data: | {{ item.value.name }} Port1 Port1 {{ item.value.zone_name }} {{ item.value.vlan_id }} Enable Static {{ item.value.ip_address }} {{ item.value.subnetmask }} state: present loop: '{{ vlan_interfaces | dict2items }}' loop_control: label: '{{ item.key }} -> VLAN {{ item.value.vlan_id }}' - name: Erstelle 'LAN_to_LAN_old' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: LAN_to_LAN_old action: accept description: Erlaubt Zugriff von LAN auf Bestandsnetz log: enable status: enable position: bottom src_zones: - LAN dst_zones: - LAN src_networks: - '{{ network_objects.office.name }}' dst_networks: - '{{ network_objects.lan_old.name }}' service_list: - Any state: present - name: Erstelle 'INTERNAL_to_bu_RZ' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: INTERNAL_to_bu_RZ action: accept description: Erlaubt Zugriff von internen Netzen auf bluu unit Rechenzentrum log: enable status: enable position: bottom src_zones: - Facility - Guest - LAN - Management - Server - VOIP dst_zones: - VPN src_networks: - '{{ network_objects.facility.name }}' - '{{ network_objects.guest.name }}' - '{{ network_objects.lan_old.name }}' - '{{ network_objects.management.name }}' - '{{ network_objects.office.name }}' - '{{ network_objects.server.name }}' - '{{ network_objects.voip.name }}' dst_networks: - '{{ network_objects.derz_lan.name }}' service_list: - Any state: present - name: Erstelle 'SSLVPN_to_INTERNAL' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: SSLVPN_to_INTERNAL action: accept description: Erlaubt Zugriff von DERZ SSLVPN auf internen Netzen log: enable status: enable position: bottom src_zones: - VPN dst_zones: - Facility - LAN - Server - VOIP src_networks: - '{{ network_objects.derz_sslvpn.name }}' dst_networks: - '{{ network_objects.facility.name }}' - '{{ network_objects.lan_old.name }}' - '{{ network_objects.office.name }}' - '{{ network_objects.server.name }}' - '{{ network_objects.voip.name }}' service_list: - Any state: present - name: Erstelle 'LAN_to_WAN' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: LAN_to_WAN action: accept description: Erlaubt Zugriff von LAN auf WAN log: enable status: enable position: bottom src_zones: - LAN dst_zones: - WAN src_networks: - '{{ network_objects.office.name }}' dst_networks: - Any service_list: - Any state: present - name: Erstelle 'LAN_old_to_WAN' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: LAN_old_to_WAN action: accept description: Erlaubt Zugriff von old LAN auf WAN log: enable status: enable position: bottom src_zones: - LAN dst_zones: - WAN src_networks: - '{{ network_objects.lan_old.name }}' dst_networks: - Any service_list: - Any state: present - name: Erstelle 'Server_to_WAN' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: Server_to_WAN action: accept description: Erlaubt Zugriff von Server auf WAN log: enable status: enable position: bottom src_zones: - Server dst_zones: - WAN src_networks: - '{{ network_objects.server.name }}' dst_networks: - Any service_list: - Any state: present - name: Erstelle 'Management_to_WAN' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: Management_to_WAN action: accept description: Erlaubt Zugriff von Management auf WAN log: enable status: enable position: bottom src_zones: - Management dst_zones: - WAN src_networks: - '{{ network_objects.management.name }}' dst_networks: - Any service_list: - Any state: present - name: Erstelle 'Guest_to_WAN' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: Guest_to_WAN action: accept description: Erlaubt Zugriff von Guest auf WAN log: enable status: enable position: bottom src_zones: - Guest dst_zones: - WAN src_networks: - '{{ network_objects.guest.name }}' dst_networks: - Any service_list: - Any state: present - name: Erstelle 'Facility_to_WAN' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: Facility_to_WAN action: accept description: Erlaubt Zugriff von Facility auf WAN log: enable status: enable position: bottom src_zones: - Facility dst_zones: - WAN src_networks: - '{{ network_objects.facility.name }}' dst_networks: - Any service_list: - Any state: present - name: Erstelle 'VOIP_to_WAN' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: VOIP_to_WAN action: accept description: Erlaubt Zugriff von VOIP auf WAN log: enable status: enable position: bottom src_zones: - VOIP dst_zones: - WAN src_networks: - '{{ network_objects.voip.name }}' dst_networks: - Any service_list: - Any state: present - name: Erstelle 'LAN_to_Management' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: LAN_to_Management action: accept description: Erlaubt Zugriff von LAN auf Management log: enable status: disable position: bottom src_zones: - LAN dst_zones: - Management src_networks: - '{{ network_objects.office.name }}' dst_networks: - '{{ network_objects.management.name }}' service_list: - Any state: present - name: Erstelle 'LAN_to_Server' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: LAN_to_Server action: accept description: Erlaubt Zugriff von LAN auf Server log: enable status: enable position: bottom src_zones: - LAN dst_zones: - Server src_networks: - '{{ network_objects.office.name }}' dst_networks: - '{{ network_objects.server.name }}' service_list: - Any state: present - name: Erstelle 'LAN_to_Facility' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: LAN_to_Facility action: accept description: Erlaubt Zugriff von LAN auf Facility log: enable status: enable position: bottom src_zones: - LAN dst_zones: - Facility src_networks: - '{{ network_objects.office.name }}' dst_networks: - '{{ network_objects.facility.name }}' service_list: - Any state: present - name: Erstelle 'LAN_to_VOIP' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: LAN_to_VOIP action: accept description: Erlaubt Zugriff von LAN auf VOIP log: enable status: enable position: bottom src_zones: - LAN dst_zones: - VOIP src_networks: - '{{ network_objects.office.name }}' dst_networks: - '{{ network_objects.voip.name }}' service_list: - Any state: present - name: Erstelle 'VPN' Firewall-Regel Gruppe sophos.sophos_firewall.sfos_firewall_rulegroup: name: VPN description: VPN policy_list: - INTERNAL_to_bu_RZ - SSLVPN_to_INTERNAL policy_type: Any source_zones: - VPN dest_zones: - Any state: present - name: Erstelle 'X to Management' Firewall-Regel Gruppe sophos.sophos_firewall.sfos_firewall_rulegroup: name: X to Management description: Zugriff auf Management-Netz policy_list: - LAN_to_Management policy_type: Any source_zones: - Any dest_zones: - Management state: present - name: Erstelle 'X to Server' Firewall-Regel Gruppe sophos.sophos_firewall.sfos_firewall_rulegroup: name: X to Server description: Zugriff auf Server-Netz policy_list: - LAN_to_Server policy_type: Any source_zones: - Any dest_zones: - Server state: present - name: Erstelle 'X to LAN' Firewall-Regel Gruppe sophos.sophos_firewall.sfos_firewall_rulegroup: name: X to LAN description: Zugriff auf LAN-Netz policy_list: - LAN_to_LAN_old policy_type: Any source_zones: - Any dest_zones: - LAN state: present - name: Erstelle 'X to Facility' Firewall-Regel Gruppe sophos.sophos_firewall.sfos_firewall_rulegroup: name: X to Facility description: Zugriff auf Facility-Netz policy_list: - LAN_to_Facility policy_type: Any source_zones: - Any dest_zones: - Facility state: present - name: Erstelle 'X to VOIP' Firewall-Regel Gruppe sophos.sophos_firewall.sfos_firewall_rulegroup: name: X to VOIP description: Zugriff auf VOIP-Netz policy_list: - LAN_to_VOIP policy_type: Any source_zones: - Any dest_zones: - VOIP state: present - name: Erstelle 'X to WAN' Firewall-Regel Gruppe sophos.sophos_firewall.sfos_firewall_rulegroup: name: X to WAN description: X to WAN group policy_list: - LAN_to_WAN - Server_to_WAN - Management_to_WAN - LAN_old_to_WAN - Guest_to_WAN - Facility_to_WAN - VOIP_to_WAN policy_type: Any source_zones: - Any dest_zones: - WAN state: present