mirror of
https://github.com/trailofbits/algo.git
synced 2025-06-07 07:33:52 +02:00
addtiional fixes
This commit is contained in:
parent
88518240fc
commit
a50a396b94
3 changed files with 12 additions and 2 deletions
|
@ -60,6 +60,7 @@
|
||||||
- sendmail
|
- sendmail
|
||||||
- iptables-persistent
|
- iptables-persistent
|
||||||
- cgroup-tools
|
- cgroup-tools
|
||||||
|
- openssl
|
||||||
tags:
|
tags:
|
||||||
- always
|
- always
|
||||||
|
|
||||||
|
|
|
@ -4,6 +4,13 @@
|
||||||
template: src="{{ item.src }}" dest="{{ item.dest }}" owner=root group=root mode=0640
|
template: src="{{ item.src }}" dest="{{ item.dest }}" owner=root group=root mode=0640
|
||||||
with_items:
|
with_items:
|
||||||
- { src: rules.v4.j2, dest: /etc/iptables/rules.v4 }
|
- { src: rules.v4.j2, dest: /etc/iptables/rules.v4 }
|
||||||
|
notify:
|
||||||
|
- restart iptables
|
||||||
|
|
||||||
|
- name: Iptables configured
|
||||||
|
template: src="{{ item.src }}" dest="{{ item.dest }}" owner=root group=root mode=0640
|
||||||
|
when: ipv6_support is defined and ipv6_support == "yes"
|
||||||
|
with_items:
|
||||||
- { src: rules.v6.j2, dest: /etc/iptables/rules.v6 }
|
- { src: rules.v6.j2, dest: /etc/iptables/rules.v6 }
|
||||||
notify:
|
notify:
|
||||||
- restart iptables
|
- restart iptables
|
||||||
|
|
|
@ -21,6 +21,7 @@
|
||||||
- /usr/lib/ipsec/stroke
|
- /usr/lib/ipsec/stroke
|
||||||
notify:
|
notify:
|
||||||
- restart apparmor
|
- restart apparmor
|
||||||
|
tags: ['apparmor']
|
||||||
|
|
||||||
- name: Enable services
|
- name: Enable services
|
||||||
service: name={{ item }} enabled=yes
|
service: name={{ item }} enabled=yes
|
||||||
|
@ -38,8 +39,9 @@
|
||||||
|
|
||||||
- name: Configure ip6tables so IPSec traffic can traverse the tunnel
|
- name: Configure ip6tables so IPSec traffic can traverse the tunnel
|
||||||
iptables: ip_version=ipv6 table=nat chain=POSTROUTING source="{{ vpn_network_ipv6 }}" jump=MASQUERADE
|
iptables: ip_version=ipv6 table=nat chain=POSTROUTING source="{{ vpn_network_ipv6 }}" jump=MASQUERADE
|
||||||
when: (security_enabled is not defined) or
|
when: ((security_enabled is not defined) or
|
||||||
(security_enabled is defined and security_enabled != "y")
|
(security_enabled is defined and security_enabled != "y")) and
|
||||||
|
ipv6_support is defined and ipv6_support == "yes"
|
||||||
notify:
|
notify:
|
||||||
- save iptables
|
- save iptables
|
||||||
|
|
||||||
|
|
Loading…
Add table
Reference in a new issue