Files
Ansible/playbooks/sophos_apply_baseline.yml
T
2026-09-22 19:23:17 +02:00

64 lines
2.4 KiB
YAML

---
# PURPOSE: Apply bitformer Sophos baseline
# DESCRIPTION: Apply the supplied bitformer firewall baseline. Existing policy values and action order are preserved.
# TARGETS: sophosxgs
# INPUTS (omitted values inherit inventory / role defaults):
# aim_debug [bool]: false
# AUTH: existing inventory / Vault credentials; no embedded passwords.
# CHANGES: Changes firewall management access, objects and rules, including rule removal and a final drop rule. Policy values have NOT been redesigned.
# EXAMPLE: ansible-playbook -i inventories/<customer>/hosts.yml
# playbooks/sophos_apply_baseline.yml --limit <host> --vault-id <customer>@prompt --ask-pass
- name: Grundkonfiguration der Sophos-Firewall nach bitformer Standard
hosts: sophosxgs
gather_facts: false
any_errors_fatal: false
vars:
network_hosts:
- name: bf_spn_network
network: 10.242.176.0
subnetmask: 255.255.255.0
- name: rfc_1918_a
network: 10.0.0.0
subnetmask: 255.0.0.0
- name: rfc_1918_b
network: 172.16.0.0
subnetmask: 255.240.0.0
- name: rfc_1918_c
network: 192.168.0.0
subnetmask: 255.255.0.0
- name: rfc_5735
network: 169.254.0.0
subnetmask: 255.255.0.0
firewall_rules_to_remove:
- '[example] Traffic to Internal Zones'
- '[example] Traffic to WAN'
- '[example] Traffic to DMZ'
wireless_networks_to_remove:
- GuestAP
- Sophos
tasks:
- name: Apply supplied firewall policy
ansible.builtin.import_role:
name: sophos_apply_baseline
tasks_from: main
pre_tasks:
- name: AIM | Validate diagnostics option
ansible.builtin.assert:
that:
- (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true',
'false']
fail_msg: aim_debug must be a YAML/JSON boolean.
quiet: true
- name: AIM | Reject mixed platform membership
ansible.builtin.assert:
that:
- (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1
fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups.
quiet: true
- name: AIM | Execution context
ansible.builtin.debug:
msg:
host: '{{ inventory_hostname }}'
diagnostics: Enabled; secret values are never included by this task.
when: aim_debug | default(false) | bool