Files
Ansible/roles/sophos_customer_gebhardt_stahl/tasks/main.yml
T
2026-09-22 19:23:17 +02:00

196 lines
5.1 KiB
YAML

---
# Customer-specific firewall policy preserved from the uploaded source.
- name: Update hostname settings
sophos.sophos_firewall.sfos_admin_settings:
hostname_settings:
hostname: '{{ hostname }}'
state: updated
- name: Netzwerke als IP-Hosts in der Firewall anlegen
sophos.sophos_firewall.sfos_ip_host:
name: '{{ item.value.name }}'
network: '{{ item.value.network }}'
mask: '{{ item.value.subnetmask }}'
host_type: network
state: present
loop: '{{ network_objects | dict2items }}'
- name: Zonen erstellen
sophos.sophos_firewall.sfos_zone:
name: '{{ item.value.zone_name }}'
description: '{{ item.value.zone_description }}'
zone_type: '{{ item.value.zone_type }}'
state: present
loop: '{{ vlan_interfaces | dict2items }}'
when: item.value.name != "LAN"
- name: Add VLAN Interfaces
sophos.sophos_firewall.sfos_xmlapi:
xml_tag: VLAN
data: |
<VLAN>
<Name>{{ item.value.name }}</Name>
<Hardware>Port1</Hardware>
<Interface>Port1</Interface>
<Zone>{{ item.value.zone_name }}</Zone>
<VLANID>{{ item.value.vlan_id }}</VLANID>
<IPv4Configuration>Enable</IPv4Configuration>
<IPv4Assignment>Static</IPv4Assignment>
<IPAddress>{{ item.value.ip_address }}</IPAddress>
<Netmask>{{ item.value.subnetmask }}</Netmask>
</VLAN>
state: present
loop: '{{ vlan_interfaces | dict2items }}'
loop_control:
label: '{{ item.key }} -> VLAN {{ item.value.vlan_id }}'
- name: Erstelle 'LAN_to_WAN' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: LAN_to_WAN
action: accept
description: Erlaubt Zugriff von LAN auf WAN
log: enable
status: enable
position: bottom
src_zones:
- LAN
dst_zones:
- WAN
src_networks:
- '{{ network_objects.office.name }}'
dst_networks:
- Any
service_list:
- Any
state: present
- name: Erstelle 'Guest_to_WAN' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: Guest_to_WAN
action: accept
description: Erlaubt Zugriff von Guest auf WAN
log: enable
status: enable
position: bottom
src_zones:
- Guest
dst_zones:
- WAN
src_networks:
- '{{ network_objects.guest.name }}'
dst_networks:
- Any
service_list:
- Any
state: present
- name: Erstelle 'Drucker_to_WAN' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: Drucker_to_WAN
action: accept
description: Erlaubt Zugriff von Drucker auf WAN
log: enable
status: enable
position: bottom
src_zones:
- Drucker
dst_zones:
- WAN
src_networks:
- '{{ network_objects.drucker.name }}'
dst_networks:
- Any
service_list:
- Any
state: present
- name: Erstelle 'WLAN_to_WAN' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: WLAN_to_WAN
action: accept
description: Erlaubt Zugriff von WLAN auf WAN
log: enable
status: enable
position: bottom
src_zones:
- WLAN
dst_zones:
- WAN
src_networks:
- '{{ network_objects.wlan.name }}'
dst_networks:
- Any
service_list:
- Any
state: present
- name: Erstelle 'LAN_to_Drucker' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: LAN_to_Drucker
action: accept
description: Erlaubt Zugriff von LAN auf Drucker
log: enable
status: enable
position: bottom
src_zones:
- LAN
dst_zones:
- Drucker
src_networks:
- '{{ network_objects.office.name }}'
dst_networks:
- '{{ network_objects.drucker.name }}'
service_list:
- Any
state: present
- name: Erstelle 'LAN_to_WLAN' Firewall-Regel
sophos.sophos_firewall.sfos_firewall_rule:
name: LAN_to_WLAN
action: accept
description: Erlaubt Zugriff von LAN auf WLAN
log: enable
status: enable
position: bottom
src_zones:
- LAN
dst_zones:
- WLAN
src_networks:
- '{{ network_objects.office.name }}'
dst_networks:
- '{{ network_objects.wlan.name }}'
service_list:
- Any
state: present
- name: Erstelle 'X to Drucker' Firewall-Regel Gruppe
sophos.sophos_firewall.sfos_firewall_rulegroup:
name: X to Drucker
description: Zugriff auf Drucker-Netz
policy_list:
- LAN_to_Drucker
policy_type: Any
source_zones:
- Any
dest_zones:
- Drucker
state: present
- name: Erstelle 'X to WLAN' Firewall-Regel Gruppe
sophos.sophos_firewall.sfos_firewall_rulegroup:
name: X to WLAN
description: Zugriff auf WLAN-Netz
policy_list:
- LAN_to_WLAN
policy_type: Any
source_zones:
- Any
dest_zones:
- WLAN
state: present
- name: Erstelle 'X to WAN' Firewall-Regel Gruppe
sophos.sophos_firewall.sfos_firewall_rulegroup:
name: X to WAN
description: X to WAN group
policy_list:
- LAN_to_WAN
- Guest_to_WAN
- Drucker_to_WAN
- WLAN_to_WAN
policy_type: Any
source_zones:
- Any
dest_zones:
- WAN
state: present