232 lines
6.1 KiB
YAML
232 lines
6.1 KiB
YAML
---
|
|
# Customer-specific firewall policy preserved from the uploaded source.
|
|
- name: Update hostname settings
|
|
sophos.sophos_firewall.sfos_admin_settings:
|
|
hostname_settings:
|
|
hostname: '{{ hostname }}'
|
|
state: updated
|
|
- name: Netzwerke als IP-Hosts in der Firewall anlegen
|
|
sophos.sophos_firewall.sfos_ip_host:
|
|
name: '{{ item.value.name }}'
|
|
network: '{{ item.value.network }}'
|
|
mask: '{{ item.value.subnetmask }}'
|
|
host_type: network
|
|
state: present
|
|
loop: '{{ network_objects | dict2items }}'
|
|
- name: Zonen erstellen
|
|
sophos.sophos_firewall.sfos_zone:
|
|
name: '{{ item.value.zone_name }}'
|
|
description: '{{ item.value.zone_description }}'
|
|
zone_type: '{{ item.value.zone_type }}'
|
|
state: present
|
|
loop: '{{ vlan_interfaces | dict2items }}'
|
|
when: item.value.name != "LAN"
|
|
- name: Update Management Zone Admin Services
|
|
sophos.sophos_firewall.sfos_zone:
|
|
name: Management
|
|
https: Enable
|
|
ssh: Enable
|
|
ad_sso: Disable
|
|
captive_portal: Disable
|
|
radius_sso: Disable
|
|
client_authen: Disable
|
|
chromebook_sso: Disable
|
|
ping: Enable
|
|
dns: Enable
|
|
ipsec: Disable
|
|
sslvpn: Disable
|
|
vpn_portal: Disable
|
|
red: Disable
|
|
wireless_protection: Disable
|
|
web_proxy: Disable
|
|
user_portal: Disable
|
|
smtp_relay: Disable
|
|
snmp: Disable
|
|
state: updated
|
|
- name: Add VLAN Interfaces
|
|
sophos.sophos_firewall.sfos_xmlapi:
|
|
xml_tag: VLAN
|
|
data: |
|
|
<VLAN>
|
|
<Name>{{ item.value.name }}</Name>
|
|
<Hardware>Port1</Hardware>
|
|
<Interface>Port1</Interface>
|
|
<Zone>{{ item.value.zone_name }}</Zone>
|
|
<VLANID>{{ item.value.vlan_id }}</VLANID>
|
|
<IPv4Configuration>Enable</IPv4Configuration>
|
|
<IPv4Assignment>Static</IPv4Assignment>
|
|
<IPAddress>{{ item.value.ip_address }}</IPAddress>
|
|
<Netmask>{{ item.value.subnetmask }}</Netmask>
|
|
</VLAN>
|
|
state: present
|
|
loop: '{{ vlan_interfaces | dict2items }}'
|
|
loop_control:
|
|
label: '{{ item.key }} -> VLAN {{ item.value.vlan_id }}'
|
|
- name: Erstelle 'LAN_to_LAN_old' Firewall-Regel
|
|
sophos.sophos_firewall.sfos_firewall_rule:
|
|
name: LAN_to_LAN_old
|
|
action: accept
|
|
description: Erlaubt Zugriff von LAN auf Bestandsnetz
|
|
log: enable
|
|
status: enable
|
|
position: bottom
|
|
src_zones:
|
|
- LAN
|
|
dst_zones:
|
|
- LAN
|
|
src_networks:
|
|
- '{{ network_objects.office.name }}'
|
|
dst_networks:
|
|
- '{{ network_objects.lan_old.name }}'
|
|
service_list:
|
|
- Any
|
|
state: present
|
|
- name: Erstelle 'INTERNAL_to_FHAZUREGWC_LAN' Firewall-Regel
|
|
sophos.sophos_firewall.sfos_firewall_rule:
|
|
name: INTERNAL_to_FHAZUREGWC_LAN
|
|
action: accept
|
|
description: Erlaubt Zugriff von internen Netzen auf Formicon Holding Azure Germany West Central LAN
|
|
log: enable
|
|
status: enable
|
|
position: bottom
|
|
src_zones:
|
|
- LAN
|
|
- Management
|
|
dst_zones:
|
|
- VPN
|
|
src_networks:
|
|
- '{{ network_objects.lan_old.name }}'
|
|
- '{{ network_objects.management.name }}'
|
|
- '{{ network_objects.office.name }}'
|
|
dst_networks:
|
|
- '{{ network_objects.azuregwc_lan.name }}'
|
|
service_list:
|
|
- Any
|
|
state: present
|
|
- name: Erstelle 'LAN_to_WAN' Firewall-Regel
|
|
sophos.sophos_firewall.sfos_firewall_rule:
|
|
name: LAN_to_WAN
|
|
action: accept
|
|
description: Erlaubt Zugriff von LAN auf WAN
|
|
log: enable
|
|
status: enable
|
|
position: bottom
|
|
src_zones:
|
|
- LAN
|
|
dst_zones:
|
|
- WAN
|
|
src_networks:
|
|
- '{{ network_objects.office.name }}'
|
|
dst_networks:
|
|
- Any
|
|
service_list:
|
|
- Any
|
|
state: present
|
|
- name: Erstelle 'LAN_old_to_WAN' Firewall-Regel
|
|
sophos.sophos_firewall.sfos_firewall_rule:
|
|
name: LAN_old_to_WAN
|
|
action: accept
|
|
description: Erlaubt Zugriff von old LAN auf WAN
|
|
log: enable
|
|
status: enable
|
|
position: bottom
|
|
src_zones:
|
|
- LAN
|
|
dst_zones:
|
|
- WAN
|
|
src_networks:
|
|
- '{{ network_objects.lan_old.name }}'
|
|
dst_networks:
|
|
- Any
|
|
service_list:
|
|
- Any
|
|
state: present
|
|
- name: Erstelle 'Management_to_WAN' Firewall-Regel
|
|
sophos.sophos_firewall.sfos_firewall_rule:
|
|
name: Management_to_WAN
|
|
action: accept
|
|
description: Erlaubt Zugriff von Management auf WAN
|
|
log: enable
|
|
status: enable
|
|
position: bottom
|
|
src_zones:
|
|
- Management
|
|
dst_zones:
|
|
- WAN
|
|
src_networks:
|
|
- '{{ network_objects.management.name }}'
|
|
dst_networks:
|
|
- Any
|
|
service_list:
|
|
- Any
|
|
state: present
|
|
- name: Erstelle 'LAN_to_Management' Firewall-Regel
|
|
sophos.sophos_firewall.sfos_firewall_rule:
|
|
name: LAN_to_Management
|
|
action: accept
|
|
description: Erlaubt Zugriff von LAN auf Management
|
|
log: enable
|
|
status: disable
|
|
position: bottom
|
|
src_zones:
|
|
- LAN
|
|
dst_zones:
|
|
- Management
|
|
src_networks:
|
|
- '{{ network_objects.office.name }}'
|
|
dst_networks:
|
|
- '{{ network_objects.management.name }}'
|
|
service_list:
|
|
- Any
|
|
state: present
|
|
- name: Erstelle 'VPN' Firewall-Regel Gruppe
|
|
sophos.sophos_firewall.sfos_firewall_rulegroup:
|
|
name: VPN
|
|
description: VPN
|
|
policy_list:
|
|
- INTERNAL_to_FHAZUREGWC_LAN
|
|
policy_type: Any
|
|
source_zones:
|
|
- VPN
|
|
dest_zones:
|
|
- Any
|
|
state: present
|
|
- name: Erstelle 'X to Management' Firewall-Regel Gruppe
|
|
sophos.sophos_firewall.sfos_firewall_rulegroup:
|
|
name: X to Management
|
|
description: Zugriff auf Management-Netz
|
|
policy_list:
|
|
- LAN_to_Management
|
|
policy_type: Any
|
|
source_zones:
|
|
- Any
|
|
dest_zones:
|
|
- Management
|
|
state: present
|
|
- name: Erstelle 'X to LAN' Firewall-Regel Gruppe
|
|
sophos.sophos_firewall.sfos_firewall_rulegroup:
|
|
name: X to LAN
|
|
description: Zugriff auf LAN-Netz
|
|
policy_list:
|
|
- LAN_to_LAN_old
|
|
policy_type: Any
|
|
source_zones:
|
|
- Any
|
|
dest_zones:
|
|
- LAN
|
|
state: present
|
|
- name: Erstelle 'X to WAN' Firewall-Regel Gruppe
|
|
sophos.sophos_firewall.sfos_firewall_rulegroup:
|
|
name: X to WAN
|
|
description: X to WAN group
|
|
policy_list:
|
|
- LAN_to_WAN
|
|
- Management_to_WAN
|
|
- LAN_old_to_WAN
|
|
policy_type: Any
|
|
source_zones:
|
|
- Any
|
|
dest_zones:
|
|
- WAN
|
|
state: present
|