This repository has been archived on 2023-12-29. You can view files and clone it, but cannot push or open issues or pull requests.
pi-ansible/roles/os_config/tasks/firewall.yml
2023-01-03 22:30:22 +01:00

21 lines
437 B
YAML

# vim: ft=yaml.ansible
---
- name: Allow necessary ports in UFW
ufw:
rule: allow
port: "{{ item.port }}"
proto: "{{ item.proto | default('tcp') }}"
loop:
- port: '22' # SSH
- port: '80' # HTTP
- port: '443' # HTTPS
- port: '18080' # monerod P2P
- port: '18089' # monerod RPC
- port: '51820' # Wireguard
proto: udp
- name: Enable UFW
ufw:
state: enabled
policy: deny