2015-08-23 12:06:25 +03:00
|
|
|
---
|
2021-07-28 14:18:41 +03:00
|
|
|
# Ubuntu 20.04 will use nftables directly, with no firewalld.
|
2015-08-23 12:06:25 +03:00
|
|
|
|
2025-01-27 22:30:50 +03:00
|
|
|
- name: Install Ubuntu firewall packages
|
|
|
|
when: ansible_distribution_version is version('20.04', '>=')
|
|
|
|
ansible.builtin.package:
|
|
|
|
name:
|
|
|
|
- libnet-ip-perl # for aggregate-cidr-addresses.pl
|
|
|
|
- nftables
|
|
|
|
- curl # for nftables update scripts
|
|
|
|
state: present
|
|
|
|
cache_valid_time: 3600
|
2018-04-26 16:58:35 +03:00
|
|
|
|
2025-01-27 22:30:50 +03:00
|
|
|
- name: Remove ufw
|
|
|
|
ansible.builtin.package:
|
|
|
|
name: ufw
|
|
|
|
state: absent
|
2020-04-25 13:54:50 +03:00
|
|
|
|
2025-01-27 22:40:29 +03:00
|
|
|
- name: Configure nftables
|
|
|
|
ansible.builtin.include_tasks: nftables.yml
|
2025-01-27 22:30:50 +03:00
|
|
|
when: ansible_distribution_version is version('20.04', '>=')
|
2021-07-29 10:05:15 +03:00
|
|
|
|
2025-01-27 22:30:50 +03:00
|
|
|
- ansible.builtin.include_tasks: fail2ban.yml
|
|
|
|
when:
|
|
|
|
- ansible_distribution_version is version('16.04', '>=')
|
2018-04-25 18:55:22 +03:00
|
|
|
|
|
|
|
# vim: set sw=2 ts=2:
|