Skip to content
Extraits de code Groupes Projets
Valider 954f227a rédigé par Fanch's avatar Fanch
Parcourir les fichiers

try to fix nftables and systemd-resolved but it is not working

parent c6b528fc
Aucune branche associée trouvée
Aucune étiquette associée trouvée
Aucune requête de fusion associée trouvée
......@@ -14,7 +14,7 @@
ctstate: INVALID
jump: DROP
ip_version: "{{ ip_version }}"
loop: ['INPUT', 'OUTPUT', 'FORWARD']
loop: ['INPUT', 'OUTPUT']
- name: Allow Loopback In
ansible.builtin.iptables:
......@@ -56,6 +56,16 @@
ip_version: "{{ ip_version }}"
loop: ['tcp', 'udp']
# for dnsmasq, systemd-resolved, ...
#- name: Allow Dns In
# ansible.builtin.iptables:
# chain: INPUT
# protocol: "{{ item }}"
# source_port: 53
# jump: ACCEPT
# ip_version: "{{ ip_version }}"
# loop: ['tcp', 'udp']
- name: Allow Ntp Out
ansible.builtin.iptables:
chain: OUTPUT
......
---
- name: Remove Packages iptables Packages
ansible.builtin.package:
name: iptables
state: absent
force: true # as it is a systemd deps
when:
- '"iptables-nft" in iptables_packages'
- name: Install Packages
ansible.builtin.package:
......
---
# tasks file for iptables
# todo : should create another role for nftables
- name: Install Iptables
include_tasks: install.yml
......
0% Chargement en cours ou .
You are about to add 0 people to the discussion. Proceed with caution.
Terminez d'abord l'édition de ce message.
Veuillez vous inscrire ou vous pour commenter