Files
Ansible/roles/sophos_apply_baseline/tasks/main.yml
T
2026-09-22 19:23:17 +02:00

501 lines
14 KiB
YAML

---
# Policy-preserving extraction from configure_sophos_initial_bitformer_config.yml. Do not change rule values without separate approval.
- name: Erstelle 'bf_wan' IP Liste
sophos.sophos_firewall.sfos_xmlapi:
xml_tag: IPHost
data: |
<IPHost>
<Name>bf_wan</Name>
<Description>WAN-IPs von bitformer</Description>
<HostType>IPList</HostType>
<ListOfIPAddresses>217.13.70.132,87.138.207.238,80.152.155.27,217.13.174.202</ListOfIPAddresses>
</IPHost>
state: present
- name: Erstelle 'bf_wartung' IP-Host
sophos.sophos_firewall.sfos_ip_host:
name: bf_wartung
ip_address: 10.240.0.1
state: present
- name: Netzwerke als IP-Hosts in der Firewall anlegen
sophos.sophos_firewall.sfos_ip_host:
name: '{{ item.name }}'
network: '{{ item.network }}'
mask: '{{ item.subnetmask }}'
host_type: network
state: present
loop: '{{ network_hosts }}'
- name: Erstelle 'rfc_1918_5735' Gruppe
sophos.sophos_firewall.sfos_ip_hostgroup:
name: rfc_1918_5735
description: rfc_1918_5735
host_list:
- rfc_1918_a
- rfc_1918_b
- rfc_1918_c
- rfc_5735
state: present
- name: Erstelle 'OpenVPN' Service
sophos.sophos_firewall.sfos_service:
name: OpenVPN
type: tcporudp
service_list:
- protocol: udp
src_port: 1:65535
dst_port: 1194
state: present
- name: Erstelle 'dgrp_wan_access_guests' Service Group
sophos.sophos_firewall.sfos_servicegroup:
name: dgrp_wan_access_guests
description: WAN Access Guests
service_list:
- PING
- HTTP
- HTTPS
- SMTPS_465
- SMTPS
- IMAP
- IMAPS
- POP3S
- IKE
- OpenVPN
state: present
- name: Erstelle 'dgrp_wan_access_office' Service Group
sophos.sophos_firewall.sfos_servicegroup:
name: dgrp_wan_access_office
description: WAN Access Office
service_list:
- PING
- SSH
- HTTP
- HTTPS
state: present
- name: Erstelle bitformer Management Access ACL Ausnahmeregel
sophos.sophos_firewall.sfos_service_acl_exception:
name: bitformer Management Access
description: Allow Management-Access to Webinterface, PING and SSH
position: bottom
source_zone: WAN
source_list:
- bf_wan
service_list:
- HTTPS
- SSH
- PING
action: accept
state: present
- name: Erstelle bitformer Monitoring ACL Ausnahmeregel
sophos.sophos_firewall.sfos_service_acl_exception:
name: bitformer Monitoring
description: Allow Monitoring-Access
position: bottom
source_zone: VPN
source_list:
- bf_wartung
service_list:
- DNS
- HTTPS
- SSH
- PING
action: accept
state: present
- name: Erstelle UserPortal Country-Restricted ACL Ausnahmeregel
sophos.sophos_firewall.sfos_service_acl_exception:
name: UserPortal Country-Restricted
description: Allow UserPort from Selected Countries
position: bottom
source_zone: WAN
source_list:
- Germany
- Austria
- Switzerland
service_list:
- UserPortal
action: accept
state: present
- name: Erstelle 'bitformer' IPSec Profile
sophos.sophos_firewall.sfos_xmlapi:
xml_tag: VPNProfile
data: |
<VPNProfile>
<Name>bitformer</Name>
<Description>IPSec Policy bitformer Wartungszugang</Description>
<KeyingMethod>Automatic</KeyingMethod>
<AllowReKeying>Enable</AllowReKeying>
<KeyNegotiationTries>0</KeyNegotiationTries>
<AuthenticationMode>MainMode</AuthenticationMode>
<PassDataInCompressedFormat>Disable</PassDataInCompressedFormat>
<UseStrictProfile>Disable</UseStrictProfile>
<Phase1>
<EncryptionAlgorithm1>AES256</EncryptionAlgorithm1>
<AuthenticationAlgorithm1>SHA2_256</AuthenticationAlgorithm1>
<EncryptionAlgorithm2/>
<AuthenticationAlgorithm2/>
<EncryptionAlgorithm3/>
<AuthenticationAlgorithm3/>
<SupportedDHGroups>
<DHGroup>16(DH4096)</DHGroup>
</SupportedDHGroups>
<KeyLife>28800</KeyLife>
<ReKeyMargin>360</ReKeyMargin>
<RandomizeRe-KeyingMarginBy>50</RandomizeRe-KeyingMarginBy>
<DeadPeerDetection>Enable</DeadPeerDetection>
<CheckPeerAfterEvery>10</CheckPeerAfterEvery>
<WaitForResponseUpto>25</WaitForResponseUpto>
<ActionWhenPeerUnreachable>ReInitiate</ActionWhenPeerUnreachable>
</Phase1>
<Phase2>
<EncryptionAlgorithm1>AES256</EncryptionAlgorithm1>
<AuthenticationAlgorithm1>SHA2_256</AuthenticationAlgorithm1>
<EncryptionAlgorithm2/>
<AuthenticationAlgorithm2/>
<EncryptionAlgorithm3/>
<AuthenticationAlgorithm3/>
<PFSGroup>SameasPhase-I</PFSGroup>
<KeyLife>3600</KeyLife>
</Phase2>
<sha2_96_truncate>no</sha2_96_truncate>
<keyexchange>ikev2</keyexchange>
</VPNProfile>
state: present
- name: Erstelle 'Mitarbeiter IPSec VPN' IPSec Profile
sophos.sophos_firewall.sfos_xmlapi:
xml_tag: VPNProfile
data: |
<VPNProfile transactionid="">
<Name>Mitarbeiter IPSec VPN</Name>
<Description>IPSec VPN für Mitarbeiter</Description>
<KeyingMethod>Automatic</KeyingMethod>
<AllowReKeying>Enable</AllowReKeying>
<KeyNegotiationTries>0</KeyNegotiationTries>
<AuthenticationMode>MainMode</AuthenticationMode>
<PassDataInCompressedFormat>Disable</PassDataInCompressedFormat>
<Phase1>
<EncryptionAlgorithm1>AES256</EncryptionAlgorithm1>
<AuthenticationAlgorithm1>SHA2_256</AuthenticationAlgorithm1>
<EncryptionAlgorithm2>AES256</EncryptionAlgorithm2>
<AuthenticationAlgorithm2>SHA2_384</AuthenticationAlgorithm2>
<EncryptionAlgorithm3/>
<AuthenticationAlgorithm3/>
<SupportedDHGroups>
<DHGroup>14(DH2048)</DHGroup>
<DHGroup>16(DH4096)</DHGroup>
<DHGroup>18(DH8192)</DHGroup>
<DHGroup>19(ecp256)</DHGroup>
<DHGroup>21(ecp521)</DHGroup>
<DHGroup>31(curve25519)</DHGroup>
</SupportedDHGroups>
<KeyLife>36000</KeyLife>
<ReKeyMargin>360</ReKeyMargin>
<RandomizeRe-KeyingMarginBy>100</RandomizeRe-KeyingMarginBy>
<DeadPeerDetection>Enable</DeadPeerDetection>
<CheckPeerAfterEvery>60</CheckPeerAfterEvery>
<WaitForResponseUpto>240</WaitForResponseUpto>
<ActionWhenPeerUnreachable>Disconnect</ActionWhenPeerUnreachable>
</Phase1>
<Phase2>
<EncryptionAlgorithm1>AES256</EncryptionAlgorithm1>
<AuthenticationAlgorithm1>SHA2_256</AuthenticationAlgorithm1>
<EncryptionAlgorithm2>AES256</EncryptionAlgorithm2>
<AuthenticationAlgorithm2>SHA2_384</AuthenticationAlgorithm2>
<EncryptionAlgorithm3/>
<AuthenticationAlgorithm3/>
<PFSGroup>SameasPhase-I</PFSGroup>
<KeyLife>32400</KeyLife>
</Phase2>
<sha2_96_truncate>no</sha2_96_truncate>
<keyexchange>ikev1</keyexchange>
</VPNProfile>
state: present
- name: Update LAN Zone Admin Services
sophos.sophos_firewall.sfos_zone:
name: LAN
https: Enable
ssh: Enable
ad_sso: Enable
captive_portal: Enable
radius_sso: Disable
client_authen: Enable
chromebook_sso: Disable
ping: Enable
dns: Enable
ipsec: Disable
sslvpn: Disable
vpn_portal: Enable
red: Disable
wireless_protection: Disable
web_proxy: Disable
user_portal: Enable
smtp_relay: Disable
snmp: Disable
state: updated
- name: Update WAN Zone Admin Services
sophos.sophos_firewall.sfos_zone:
name: WAN
https: Disable
ssh: Disable
ad_sso: Disable
captive_portal: Disable
radius_sso: Disable
client_authen: Disable
chromebook_sso: Disable
ping: Enable
dns: Disable
ipsec: Enable
sslvpn: Disable
vpn_portal: Disable
red: Disable
wireless_protection: Disable
web_proxy: Disable
user_portal: Disable
smtp_relay: Disable
snmp: Disable
state: updated
- name: Update DMZ Zone Admin Services
sophos.sophos_firewall.sfos_zone:
name: DMZ
https: Disable
ssh: Enable
ad_sso: Disable
captive_portal: Disable
radius_sso: Disable
client_authen: Disable
chromebook_sso: Disable
ping: Enable
dns: Disable
ipsec: Disable
sslvpn: Disable
vpn_portal: Disable
red: Disable
wireless_protection: Disable
web_proxy: Disable
user_portal: Disable
smtp_relay: Disable
snmp: Disable
state: updated
- name: Update VPN Zone Admin Services
sophos.sophos_firewall.sfos_zone:
name: VPN
https: Enable
ssh: Enable
ad_sso: Disable
captive_portal: Enable
radius_sso: Disable
client_authen: Disable
chromebook_sso: Disable
ping: Enable
dns: Enable
ipsec: Disable
sslvpn: Disable
vpn_portal: Enable
red: Disable
wireless_protection: Disable
web_proxy: Disable
user_portal: Enable
smtp_relay: Disable
snmp: Enable
state: updated
- name: Update WiFi Zone Admin Services
sophos.sophos_firewall.sfos_zone:
name: WiFi
https: Disable
ssh: Disable
ad_sso: Disable
captive_portal: Disable
radius_sso: Disable
client_authen: Disable
chromebook_sso: Disable
ping: Disable
dns: Disable
ipsec: Disable
sslvpn: Disable
vpn_portal: Disable
red: Disable
wireless_protection: Disable
web_proxy: Disable
user_portal: Disable
smtp_relay: Disable
snmp: Disable
state: updated
- name: Entferne 'Auto added firewall policy for MTA' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: Auto added firewall policy for MTA
state: absent
- name: Erstelle 'LAN_to_WAN' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: LAN_to_WAN
action: accept
description: Lan > WAN Regel
log: enable
status: enable
position: bottom
src_zones:
- LAN
dst_zones:
- Any
src_networks:
- Any
dst_networks:
- Any
service_list:
- Any
state: present
- name: Erstelle 'LAN > WAN' Firewall-Regel Gruppe
sophos.sophos_firewall.sfos_firewall_rulegroup:
name: LAN > WAN
description: Lan to WAN group
policy_list:
- LAN_to_WAN
policy_type: Any
source_zones:
- LAN
dest_zones:
- WAN
state: present
- name: Erstelle 'bitformer Wartungszugang' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: bitformer Wartungszugang
action: accept
description: bitconnect Zugriff
log: enable
status: enable
position: bottom
src_zones:
- VPN
dst_zones:
- Any
src_networks:
- bf_wartung
dst_networks:
- Any
service_list:
- Any
state: present
- name: Erstelle 'bitformer SPN' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: bitformer SPN
action: accept
description: Zugriff auf bitformer SPN
log: enable
status: enable
position: bottom
src_zones:
- VPN
dst_zones:
- Any
src_networks:
- bf_spn_network
dst_networks:
- Any
service_list:
- Any
state: present
- name: Erstelle 'LAN_to_bitformer_SPN' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: LAN_to_bitformer_SPN
action: accept
description: Zugriff auf bitformer SPN
log: enable
status: enable
position: bottom
src_zones:
- LAN
dst_zones:
- VPN
src_networks:
- Any
dst_networks:
- bf_spn_network
service_list:
- Any
state: present
- name: Erstelle 'bitformer' Firewall Regel Gruppe
sophos.sophos_firewall.sfos_firewall_rulegroup:
name: bitformer
description: bitformer group
policy_list:
- bitformer Wartungszugang
- bitformer SPN
- LAN_to_bitformer_SPN
policy_type: Any
source_zones:
- Any
dest_zones:
- Any
state: present
- name: Erstelle 'VPN_to_WAN' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: VPN_to_WAN
action: accept
description: Zugriff von VPN
log: enable
status: disable
position: bottom
src_zones:
- VPN
dst_zones:
- LAN
src_networks:
- Any
dst_networks:
- Any
service_list:
- Any
state: present
- name: Erstelle 'VPN' Firewall Regel Gruppe
sophos.sophos_firewall.sfos_firewall_rulegroup:
name: VPN
description: VPN group
policy_list:
- VPN_to_WAN
policy_type: Any
source_zones:
- Any
dest_zones:
- Any
state: present
- name: Entferne [example] Firewallregeln
sophos.sophos_firewall.sfos_firewall_rule:
name: '{{ item }}'
state: absent
loop: '{{ firewall_rules_to_remove }}'
- name: Erstelle 'DROP_ALL_LOG' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: DROP_ALL_LOG
action: drop
description: Verwirft alle Pakete mit Log
log: enable
status: enable
position: bottom
src_zones:
- Any
dst_zones:
- Any
src_networks:
- Any
dst_networks:
- Any
service_list:
- Any
state: present
- name: Aktiviere 'Vordefinierten NTP-Server verwenden'
sophos.sophos_firewall.sfos_xmlapi:
xml_tag: Time
data: |
<Time>
<TimeZone>Europe/Berlin</TimeZone>
<SetDateTime>
<Date>
<Year/>
<Month/>
<Day/>
</Date>
<Time>
<HH/>
<MM/>
<SS>0</SS>
</Time>
</SetDateTime>
<PredefinedNTPServer>Enable</PredefinedNTPServer>
</Time>
state: updated