浏览代码

Merge pull request #332 from apsanz/master

Enable UFW only after setting firewall rules
Alex Payne 10 年前
父节点
当前提交
87e2497fbc
共有 1 个文件被更改,包括 5 次插入2 次删除
  1. 5
    2
      roles/common/tasks/ufw.yml

+ 5
- 2
roles/common/tasks/ufw.yml 查看文件

5
 - name: Install ufw
5
 - name: Install ufw
6
   apt: pkg=ufw state=present
6
   apt: pkg=ufw state=present
7
 
7
 
8
-- name: Deny everything and enable UFW
9
-  ufw: state=enabled policy=deny
8
+- name: Deny everything
9
+  ufw: policy=deny
10
 
10
 
11
 - name: Set firewall rule for DNS
11
 - name: Set firewall rule for DNS
12
   ufw: rule=allow port=domain
12
   ufw: rule=allow port=domain
21
     - https
21
     - https
22
     - ssh
22
     - ssh
23
 
23
 
24
+- name: Enable UFW
25
+  ufw: state=enabled
26
+
24
 - name: Check config of ufw
27
 - name: Check config of ufw
25
   command: cat /etc/ufw/ufw.conf
28
   command: cat /etc/ufw/ufw.conf
26
   register: ufw_config
29
   register: ufw_config

正在加载...
取消
保存