--- # PURPOSE: Apply bitformer Sophos baseline # DESCRIPTION: Apply the supplied bitformer firewall baseline. Existing policy values and action order are preserved. # TARGETS: sophosxgs # INPUTS (omitted values inherit inventory / role defaults): # aim_debug [bool]: false # AUTH: existing inventory / Vault credentials; no embedded passwords. # CHANGES: Changes firewall management access, objects and rules, including rule removal and a final drop rule. Policy values have NOT been redesigned. # EXAMPLE: ansible-playbook -i inventories//hosts.yml # playbooks/sophos_apply_baseline.yml --limit --vault-id @prompt --ask-pass - name: Grundkonfiguration der Sophos-Firewall nach bitformer Standard hosts: sophosxgs gather_facts: false any_errors_fatal: false vars: network_hosts: - name: bf_spn_network network: 10.242.176.0 subnetmask: 255.255.255.0 - name: rfc_1918_a network: 10.0.0.0 subnetmask: 255.0.0.0 - name: rfc_1918_b network: 172.16.0.0 subnetmask: 255.240.0.0 - name: rfc_1918_c network: 192.168.0.0 subnetmask: 255.255.0.0 - name: rfc_5735 network: 169.254.0.0 subnetmask: 255.255.0.0 firewall_rules_to_remove: - '[example] Traffic to Internal Zones' - '[example] Traffic to WAN' - '[example] Traffic to DMZ' wireless_networks_to_remove: - GuestAP - Sophos tasks: - name: Apply supplied firewall policy ansible.builtin.import_role: name: sophos_apply_baseline tasks_from: main pre_tasks: - name: AIM | Validate diagnostics option ansible.builtin.assert: that: - (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true', 'false'] fail_msg: aim_debug must be a YAML/JSON boolean. quiet: true - name: AIM | Reject mixed platform membership ansible.builtin.assert: that: - (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1 fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups. quiet: true - name: AIM | Execution context ansible.builtin.debug: msg: host: '{{ inventory_hostname }}' diagnostics: Enabled; secret values are never included by this task. when: aim_debug | default(false) | bool