--- # Customer-specific firewall policy preserved from the uploaded source. - name: Update hostname settings sophos.sophos_firewall.sfos_admin_settings: hostname_settings: hostname: '{{ hostname }}' state: updated - name: Netzwerke als IP-Hosts in der Firewall anlegen sophos.sophos_firewall.sfos_ip_host: name: '{{ item.value.name }}' network: '{{ item.value.network }}' mask: '{{ item.value.subnetmask }}' host_type: network state: present loop: '{{ network_objects | dict2items }}' - name: Zonen erstellen sophos.sophos_firewall.sfos_zone: name: '{{ item.value.zone_name }}' description: '{{ item.value.zone_description }}' zone_type: '{{ item.value.zone_type }}' state: present loop: '{{ vlan_interfaces | dict2items }}' when: item.value.name != "LAN" - name: Update Management Zone Admin Services sophos.sophos_firewall.sfos_zone: name: Management https: Enable ssh: Enable ad_sso: Disable captive_portal: Disable radius_sso: Disable client_authen: Disable chromebook_sso: Disable ping: Enable dns: Enable ipsec: Disable sslvpn: Disable vpn_portal: Disable red: Disable wireless_protection: Disable web_proxy: Disable user_portal: Disable smtp_relay: Disable snmp: Disable state: updated - name: Add VLAN Interfaces sophos.sophos_firewall.sfos_xmlapi: xml_tag: VLAN data: | {{ item.value.name }} Port1 Port1 {{ item.value.zone_name }} {{ item.value.vlan_id }} Enable Static {{ item.value.ip_address }} {{ item.value.subnetmask }} state: present loop: '{{ vlan_interfaces | dict2items }}' loop_control: label: '{{ item.key }} -> VLAN {{ item.value.vlan_id }}' - name: Erstelle 'LAN_to_LAN_old' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: LAN_to_LAN_old action: accept description: Erlaubt Zugriff von LAN auf Bestandsnetz log: enable status: enable position: bottom src_zones: - LAN dst_zones: - LAN src_networks: - '{{ network_objects.office.name }}' dst_networks: - '{{ network_objects.lan_old.name }}' service_list: - Any state: present - name: Erstelle 'INTERNAL_to_FHAZUREGWC_LAN' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: INTERNAL_to_FHAZUREGWC_LAN action: accept description: Erlaubt Zugriff von internen Netzen auf Formicon Holding Azure Germany West Central LAN log: enable status: enable position: bottom src_zones: - LAN - Management dst_zones: - VPN src_networks: - '{{ network_objects.lan_old.name }}' - '{{ network_objects.management.name }}' - '{{ network_objects.office.name }}' dst_networks: - '{{ network_objects.azuregwc_lan.name }}' service_list: - Any state: present - name: Erstelle 'LAN_to_WAN' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: LAN_to_WAN action: accept description: Erlaubt Zugriff von LAN auf WAN log: enable status: enable position: bottom src_zones: - LAN dst_zones: - WAN src_networks: - '{{ network_objects.office.name }}' dst_networks: - Any service_list: - Any state: present - name: Erstelle 'LAN_old_to_WAN' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: LAN_old_to_WAN action: accept description: Erlaubt Zugriff von old LAN auf WAN log: enable status: enable position: bottom src_zones: - LAN dst_zones: - WAN src_networks: - '{{ network_objects.lan_old.name }}' dst_networks: - Any service_list: - Any state: present - name: Erstelle 'Management_to_WAN' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: Management_to_WAN action: accept description: Erlaubt Zugriff von Management auf WAN log: enable status: enable position: bottom src_zones: - Management dst_zones: - WAN src_networks: - '{{ network_objects.management.name }}' dst_networks: - Any service_list: - Any state: present - name: Erstelle 'LAN_to_Management' Firewall-Regel sophos.sophos_firewall.sfos_firewall_rule: name: LAN_to_Management action: accept description: Erlaubt Zugriff von LAN auf Management log: enable status: disable position: bottom src_zones: - LAN dst_zones: - Management src_networks: - '{{ network_objects.office.name }}' dst_networks: - '{{ network_objects.management.name }}' service_list: - Any state: present - name: Erstelle 'VPN' Firewall-Regel Gruppe sophos.sophos_firewall.sfos_firewall_rulegroup: name: VPN description: VPN policy_list: - INTERNAL_to_FHAZUREGWC_LAN policy_type: Any source_zones: - VPN dest_zones: - Any state: present - name: Erstelle 'X to Management' Firewall-Regel Gruppe sophos.sophos_firewall.sfos_firewall_rulegroup: name: X to Management description: Zugriff auf Management-Netz policy_list: - LAN_to_Management policy_type: Any source_zones: - Any dest_zones: - Management state: present - name: Erstelle 'X to LAN' Firewall-Regel Gruppe sophos.sophos_firewall.sfos_firewall_rulegroup: name: X to LAN description: Zugriff auf LAN-Netz policy_list: - LAN_to_LAN_old policy_type: Any source_zones: - Any dest_zones: - LAN state: present - name: Erstelle 'X to WAN' Firewall-Regel Gruppe sophos.sophos_firewall.sfos_firewall_rulegroup: name: X to WAN description: X to WAN group policy_list: - LAN_to_WAN - Management_to_WAN - LAN_old_to_WAN policy_type: Any source_zones: - Any dest_zones: - WAN state: present