Commit 810b11fd authored by Julien Muchembled's avatar Julien Muchembled

playbook: do not touch the firewall

parent 875561ff
Pipeline #2257 skipped
#!/bin/bash
if [ -f /sbin/ip6tables ]; then
if [ 0 -ne `ip6tables -L | grep -E "(DROP|REJECT)" | wc -l` ]; then
ip6tables -P FORWARD ACCEPT
ip6tables -I OUTPUT 1 -p udp --dport 6696 -j ACCEPT
ip6tables -I OUTPUT 2 -p udp --dport 326 -j ACCEPT
ip6tables -I INPUT 1 -p udp --dport 6696 -j ACCEPT
ip6tables -I INPUT 2 -p udp --dport 326 -j ACCEPT
echo "Updated firewall, openned ports 6696 and 326."
else
echo "OK (firewall is disabled)"
fi
else
echo "OK (no ip6tables found)"
fi
...@@ -39,14 +39,8 @@ ...@@ -39,14 +39,8 @@
copy: src=centos_6_init_d dest=/etc/init.d/re6stnet mode=755 copy: src=centos_6_init_d dest=/etc/init.d/re6stnet mode=755
when: ansible_distribution == 'CentOS' and ansible_distribution_major_version == '6' and recheck_re6stnet_conf.stat.exists == True when: ansible_distribution == 'CentOS' and ansible_distribution_major_version == '6' and recheck_re6stnet_conf.stat.exists == True
- name: Add script for check ip6tables well configured - file: path=/usr/bin/re6stnet-ip6tables-check state=absent
copy: src=ip6tables dest=/usr/bin/re6stnet-ip6tables-check mode=755 - cron: name="ip6tables at reboot" state=absent
- name: Run re6stnet-ip6tables-check
shell: /usr/bin/re6stnet-ip6tables-check
- name: Include re6stnet-ip6tables-check at reboot on cron
cron: name="ip6tables at reboot" special_time=reboot job="sleep 20 && /usr/bin/re6stnet-ip6tables-check"
- include: tcp_nodelay.yml - include: tcp_nodelay.yml
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment