Commit graph

12 commits

Author SHA1 Message Date
Fabio Alessandro Locati
cbe3f4e5e1 Make main() calls conditional - system (#3652) 2016-12-08 11:35:15 -05:00
Fabio Alessandro Locati
cc25f24475 Native YAML - system (#3625)
* Native YAML - system

* Remove comment that is not applicable to the code
2016-12-08 11:35:14 -05:00
ovcharenko
3e31eaf419 ufw fails asking for a direction for rules without an interface specified [#2758] (#2759) 2016-12-08 11:34:42 -05:00
ovcharenko
3c0a946f2d "Invalid interface clause" error in UFW module (#2559) (#2666)
Fixes GH-2559
2016-12-08 11:34:40 -05:00
Onni Hakala
e863dcc92a Added example to add a port range (#2712)
I tried to google for this a bit and then figured out how it actually works.
2016-12-08 11:34:40 -05:00
ovcharenko
bdf1a087cb Bug report: ufw: interface option causes an error (1.9.4) (#1491) (#2668) 2016-12-08 11:34:38 -05:00
Chris Lamb
c0787b12ce system/ufw.py: Add security warning re. removing ufw application prof…
It's not particularly obvious that removing an application will remove it
from ufw's own state, potentially leaving ports open on your box if you
upload your configuration.

Whilst this applies to a lot of things in Ansible, firewall rules might
cross some sort of line that justifies such a warning in his instance.

Signed-off-by: Chris Lamb <chris@chris-lamb.co.uk>
2016-12-08 11:34:08 -05:00
Greg DeKoenigsberg
c65a612d1f Changes to author formatting, remove emails 2016-12-08 11:32:51 -05:00
Nicolas Brisac
bcfd5772e4 Allow filtering of routed/forwarded packets
MAN page states the following :

    Rules for traffic not destined for the  host  itself  but  instead  for
    traffic  that  should  be  routed/forwarded through the firewall should
    specify the  route  keyword  before  the  rule  (routing  rules  differ
    significantly  from  PF  syntax and instead take into account netfilter
    FORWARD chain conventions). For example:

        ufw route allow in on eth1 out on eth2

This commit introduces a new parameter "route=yes/no" to allow just that.
2016-12-08 11:32:45 -05:00
Toshio Kuratomi
4f07e8b256 Many more doc fixes 2016-12-08 11:32:40 -05:00
Chris West
4176c3b500 Enable "ufw default allow routed"
* The policy is shown in `status verbose`, so all the check mode stuff should keep working.
 * `--dry-run` works as expected.
 * No idea whether it's legal as an argument to `interface`
2016-12-08 11:32:19 -05:00
Michael DeHaan
5879c503bb File extensions! 2016-12-08 11:32:18 -05:00
Renamed from lib/ansible/modules/extras/system/ufw (Browse further)