File tree Expand file tree Collapse file tree 4 files changed +32
-0
lines changed Expand file tree Collapse file tree 4 files changed +32
-0
lines changed Original file line number Diff line number Diff line change
1
+ ---
2
+ - name : restart netfilter-persistent
3
+ systemd : daemon_reload=yes name=netfilter-persistent.service state=restarted
Original file line number Diff line number Diff line change
1
+ ---
2
+ - name : Install iptables-persistent
3
+ package : name=iptables-persistent
4
+ - name : Configure iptables-persistent
5
+ template :
6
+ dest : /etc/iptables/rules.v4
7
+ src : rules.v4.j2
8
+ notify : restart netfilter-persistent
Original file line number Diff line number Diff line change
1
+ *nat
2
+ :PREROUTING ACCEPT [0:0]
3
+ :POSTROUTING ACCEPT [0:0]
4
+ :OUTPUT ACCEPT [0:0]
5
+ # Send the web interface to scripts
6
+ #-A PREROUTING -p tcp -m tcp -m multiport --dports 80,443,444 -j DNAT --to-destination 18.4.86.46 -i vlan486
7
+ #-A PREROUTING -p tcp -m tcp -m multiport --dports 80,443,444 -j DNAT --to-destination 172.21.0.46 -i vlan461
8
+ #-A POSTROUTING -p tcp -m tcp -m multiport --dports 80,443,444 -j SNAT --to-source {{ vlan486_address }} -o vlan486
9
+ #-A POSTROUTING -p tcp -m tcp -m multiport --dports 80,443,444 -j SNAT --to-source {{ vlan461_address }} -o vlan461
10
+ # Send the web interface to s-b
11
+ -A PREROUTING -p tcp -m tcp -m multiport --dports 80,443,444 -j DNAT --to-destination 18.4.86.47 -i vlan486
12
+ -A PREROUTING -p tcp -m tcp -m multiport --dports 80,443,444 -j DNAT --to-destination 172.21.0.47 -i vlan461
13
+ -A POSTROUTING -p tcp -m tcp -m multiport --dports 80,443,444 -j SNAT --to-source {{ vlan486_address }} -o vlan486
14
+ -A POSTROUTING -p tcp -m tcp -m multiport --dports 80,443,444 -j SNAT --to-source {{ vlan461_address }} -o vlan461
15
+ COMMIT
16
+ *filter
17
+ :INPUT ACCEPT [0:0]
18
+ :FORWARD ACCEPT [0:0]
19
+ :OUTPUT ACCEPT [0:0]
20
+ COMMIT
Original file line number Diff line number Diff line change 31
31
- sql-remctl
32
32
- sql-backup-ng
33
33
- sql-nrpe
34
+ - sql-iptables
34
35
- afs
35
36
tasks :
36
37
- name : Disable rpcbind
You can’t perform that action at this time.
0 commit comments